Skip to content

Bump dependabot-omnibus from 0.115.0 to 0.125.6

NipaNipa requested to merge dependabot/bundler/dependabot-omnibus-0.125.6 into master

Bumps dependabot-omnibus from 0.115.0 to 0.125.6.

Changelog

Sourced from dependabot-omnibus's changelog.

v0.125.6, 27 November 2020

  • Pip compile: raise DependencyFileNotRqesolvable error when initial manifest files are unresolvable
  • JS: Handle rate limited npm package requests
  • Go mod: verify Dependabot::GitDependenciesNotReachable from versioned
  • dry-run: add exception handling and re-raise on unknown errors

v0.125.5, 25 November 2020

  • go_modules: raise Dependabot::GitDependenciesNotReachable for dependencies missing from github.com
  • JS: Prefer the npm conflicting dependency parser
  • Clean go_modules build cache in dependabot/dependabot-core docker image
  • Check Azure PR description against utf-16 encoded length
  • Bump @npmcli/arborist from 1.0.10 to 1.0.12 in /npm_and_yarn/helpers
  • Bump npm from 6.14.8 to 6.14.9 in /npm_and_yarn/helpers
  • Bump eslint from 7.12.1 to 7.14.0 in /npm_and_yarn/helpers

v0.125.4, 17 November 2020

  • Yarn: Explain conflicting top-level dependency

v0.125.3, 16 November 2020

  • Bundler: Add top-level dependency to conflict explanation
  • Use conflicting deps explanation in the dry-run script
  • Bundler: Add explanation message to conflicting dependencies
  • Add js helper README with debugging tips.
  • JS: Include the top-level npm dependency for conflicting dependencies
  • Hex: support reading files in elixir supporting files like in mixfiles (@​baseballlover723)
  • Update simplecov-console requirement from ~> 0.7.2 to ~> 0.8.0
  • Bump @npmcli/arborist from 1.0.9 to 1.0.10 in /npm_and_yarn/helpers
  • Hex: support elixir Code.require_file like Code.eval_file (@​baseballlover723)

v0.125.2, 11 November 2020

  • Update CI jobs env variable assignment (@​baseballlover723)
  • Hex: Support elixir Code.eval_file without specifying a relative directory (@​baseballlover723)
  • JS: Explain update not possible for yarn and npm
  • Extract DependencyFileBuilder to remove duplication

v0.125.1, 5 November 2020

  • Escape SharedHelpers.run_shell_command with shellwords

v0.125.0, 5 November 2020

  • Bundler: Explain why security update was not possible
  • Raise descriptive error when update is not possible
  • Go mod: Handle post-v0 module path updates
... (truncated)
Commits
  • 4ddc1bc v0.125.6
  • ec00de0 Merge pull request #2797 from dependabot/feelepxyz/pip-compile-handle-unresol...
  • 4ff9a8e Pip compile: handle unresolvable projects
  • c85373a Spec helper: add a project dependency files helper
  • b473aca dry-run: add exception handling and re-raise on unknown errors
  • f739132 Merge pull request #2791 from dependabot/go-unreachable-git-versioned
  • 355939c Merge pull request #2796 from dependabot/feelepxyz/handle-rate-limited-npm-pa...
  • 9945d02 JS: Handle rate limited npm package requests
  • 241e48c Merge pull request #2795 from dependabot/feelepxyz/increase-docker-mem
  • 3b406e4 Set docker memory to 4g
  • Additional commits viewable in compare view

Merge request reports