You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@datalab.apache.org by GitBox <gi...@apache.org> on 2022/11/22 00:11:42 UTC

[GitHub] [incubator-datalab] dependabot[bot] opened a new pull request, #1797: Bump loader-utils and @angular-devkit/build-angular in /services/self-service/src/main/resources/webapp

dependabot[bot] opened a new pull request, #1797:
URL: https://github.com/apache/incubator-datalab/pull/1797

   Bumps [loader-utils](https://github.com/webpack/loader-utils) to 3.2.1 and updates ancestor dependency [@angular-devkit/build-angular](https://github.com/angular/angular-cli). These dependencies need to be updated together.
   
   Updates `loader-utils` from 1.2.3 to 3.2.1
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a href="https://github.com/webpack/loader-utils/releases">loader-utils's releases</a>.</em></p>
   <blockquote>
   <h2>v3.2.1</h2>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.2.0...v3.2.1">3.2.1</a> (2022-11-11)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>ReDoS problem (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/224">#224</a>) (<a href="https://github.com/webpack/loader-utils/commit/d2d752d59629daee38f34b24307221349c490eb1">d2d752d</a>)</li>
   </ul>
   <h2>v3.2.0</h2>
   <h2><a href="https://github.com/webpack/loader-utils/compare/v3.1.3...v3.2.0">3.2.0</a> (2021-11-11)</h2>
   <h3>Features</h3>
   <ul>
   <li>hash uniformity for base digests (<a href="https://github.com/webpack/loader-utils/commit/451858b0bb33911d52d2f03a6470fd2b86493b84">451858b</a>)</li>
   </ul>
   <h2>v3.1.3</h2>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.1.2...v3.1.3">3.1.3</a> (2021-11-04)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>crash with md4 hash (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/198">#198</a>) (<a href="https://github.com/webpack/loader-utils/commit/ef084d43ba29ebf3c3c0ea0939a5c58adad0bba2">ef084d4</a>)</li>
   </ul>
   <h2>v3.1.2</h2>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.1.1...v3.1.2">3.1.2</a> (2021-11-04)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>bug with unicode characters (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/196">#196</a>) (<a href="https://github.com/webpack/loader-utils/commit/04264056f951514955af7302510631f942276eec">0426405</a>)</li>
   </ul>
   <h2>v3.1.1</h2>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.1.0...v3.1.1">3.1.1</a> (2021-11-04)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>base64 and unicode characters (<a href="https://github.com/webpack/loader-utils/commit/02b1f3fe6d718870b5ee7abc64519a1b2b5b8531">02b1f3f</a>)</li>
   </ul>
   <h2>v3.1.0</h2>
   <h2><a href="https://github.com/webpack/loader-utils/compare/v3.0.0...v3.1.0">3.1.0</a> (2021-10-29)</h2>
   <h3>Features</h3>
   <ul>
   <li>added <code>md4</code> (wasm version) and <code>md4-native</code> (<code>crypto</code> module version) algorithms (<a href="https://github.com/webpack/loader-utils/commit/cbf9d1dac866be50971d294c3baacda45527fb8e">cbf9d1d</a>)</li>
   </ul>
   <h2>v3.0.0</h2>
   <h2><a href="https://github.com/webpack/loader-utils/compare/v2.0.0...v3.0.0">3.0.0</a> (2021-10-20)</h2>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a href="https://github.com/webpack/loader-utils/blob/master/CHANGELOG.md">loader-utils's changelog</a>.</em></p>
   <blockquote>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.2.0...v3.2.1">3.2.1</a> (2022-11-11)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>ReDoS problem (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/224">#224</a>) (<a href="https://github.com/webpack/loader-utils/commit/d2d752d59629daee38f34b24307221349c490eb1">d2d752d</a>)</li>
   </ul>
   <h2><a href="https://github.com/webpack/loader-utils/compare/v3.1.3...v3.2.0">3.2.0</a> (2021-11-11)</h2>
   <h3>Features</h3>
   <ul>
   <li>hash uniformity for base digests (<a href="https://github.com/webpack/loader-utils/commit/451858b0bb33911d52d2f03a6470fd2b86493b84">451858b</a>)</li>
   </ul>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.1.2...v3.1.3">3.1.3</a> (2021-11-04)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>crash with md4 hash (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/198">#198</a>) (<a href="https://github.com/webpack/loader-utils/commit/ef084d43ba29ebf3c3c0ea0939a5c58adad0bba2">ef084d4</a>)</li>
   </ul>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.1.1...v3.1.2">3.1.2</a> (2021-11-04)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>bug with unicode characters (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/196">#196</a>) (<a href="https://github.com/webpack/loader-utils/commit/04264056f951514955af7302510631f942276eec">0426405</a>)</li>
   </ul>
   <h3><a href="https://github.com/webpack/loader-utils/compare/v3.1.0...v3.1.1">3.1.1</a> (2021-11-04)</h3>
   <h3>Bug Fixes</h3>
   <ul>
   <li>base64 and unicode characters (<a href="https://github.com/webpack/loader-utils/commit/02b1f3fe6d718870b5ee7abc64519a1b2b5b8531">02b1f3f</a>)</li>
   </ul>
   <h2><a href="https://github.com/webpack/loader-utils/compare/v3.0.0...v3.1.0">3.1.0</a> (2021-10-29)</h2>
   <h3>Features</h3>
   <ul>
   <li>added <code>md4</code> (wasm version) and <code>md4-native</code> (<code>crypto</code> module version) algorithms (<a href="https://github.com/webpack/loader-utils/commit/cbf9d1dac866be50971d294c3baacda45527fb8e">cbf9d1d</a>)</li>
   </ul>
   <h2><a href="https://github.com/webpack/loader-utils/compare/v2.0.0...v3.0.0">3.0.0</a> (2021-10-20)</h2>
   <h3>⚠ BREAKING CHANGES</h3>
   <ul>
   <li>minimum supported Node.js version is <code>12.13.0</code> (<a href="https://github.com/webpack/loader-utils/commit/93a87cefd41cc69de0bc1f9099f7d753ed8cd557">93a87ce</a>)</li>
   <li>use <code>xxhash64</code> by default for <code>[hash]</code>/<code>[contenthash]</code> and <code>getHashDigest</code> API</li>
   <li><code>[emoji]</code> was removed without replacements, please use custom function if you need this</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a href="https://github.com/webpack/loader-utils/commit/a3fd3ca1a5287d217a2370b0902997544e6b9aa9"><code>a3fd3ca</code></a> chore(release): 3.2.1</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/d2d752d59629daee38f34b24307221349c490eb1"><code>d2d752d</code></a> fix: ReDoS problem (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/224">#224</a>)</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/52cd134fc94721f62c9c882651aad24f33e6d6a8"><code>52cd134</code></a> chore(deps): bump minimist from 1.2.5 to 1.2.6 (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/209">#209</a>)</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/9fe238119274581649b78e5a4d9d8e4c76229e91"><code>9fe2381</code></a> chore: add .gitattributes for normalizing end of lines - fixes <a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/203">#203</a> (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/204">#204</a>)</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/a282654ddfa0a8c9c770db1adfa064e671bcf471"><code>a282654</code></a> chore(release): 3.2.0</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/f2a524b5e7e15a2becc61c500c9eccdc329e10c8"><code>f2a524b</code></a> chore(deps): update (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/200">#200</a>)</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/451858b0bb33911d52d2f03a6470fd2b86493b84"><code>451858b</code></a> feat: hash uniformity for base digests</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/f7dbfe105094027e2a7fe5e8babb016ecab16239"><code>f7dbfe1</code></a> chore(release): 3.1.3</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/ef084d43ba29ebf3c3c0ea0939a5c58adad0bba2"><code>ef084d4</code></a> fix: crash with md4 hash (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/198">#198</a>)</li>
   <li><a href="https://github.com/webpack/loader-utils/commit/097f5c3b2ce1bdffac5c74f9a8be34461da319f2"><code>097f5c3</code></a> chore(release): 3.1.2</li>
   <li>Additional commits viewable in <a href="https://github.com/webpack/loader-utils/compare/v1.2.3...v3.2.1">compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `@angular-devkit/build-angular` from 0.1002.0 to 15.0.0
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a href="https://github.com/angular/angular-cli/releases"><code>@​angular-devkit/build-angular</code>'s releases</a>.</em></p>
   <blockquote>
   <h2>v15.0.0</h2>
   <p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
   <h1>15.0.0 (2022-11-16)</h1>
   <h2>Breaking Changes</h2>
   <h3><code>@​angular/cli</code></h3>
   <ul>
   <li>The Angular CLI  no longer supports <code>16.10.x</code>, <code>16.11.x</code> and <code>16.12.x</code>. Current supported versions of Node.js are <code>14.20.x</code>, <code>16.13.x</code> and <code>18.10.x</code>.</li>
   <li>Node.js versions older than 14.20 are no longer supported.</li>
   <li>The 'path' option in schematics schema no longer has a special meaning. Use 'workingDirectory' smart default provider should be used instead.</li>
   </ul>
   <h3><code>@​schematics/angular</code></h3>
   <ul>
   <li>Removed unused<code>appDir</code> option from Universal and App-Shell schematic. This option can safely be removed  if present since it no longer has effect.</li>
   </ul>
   <h3></h3>
   <ul>
   <li>
   <p><code>analyticsSharing</code> option in the global angular configuration has been
   removed without replacement. This option was used to configure the Angular CLI to  access to your own users' CLI usage data.</p>
   <p>If this option is used, it can be removed using <code>ng config --global cli.analyticsSharing undefined</code>.</p>
   </li>
   <li>
   <p>analytics APIs have been removed without replacement from <code>@angular-devkit/core</code> and <code>@angular-devkit/architect</code>.</p>
   </li>
   </ul>
   <h3><code>@​angular-devkit/build-angular</code></h3>
   <ul>
   <li>
   <p>TypeScript versions older than 4.8.2 are no longer supported.</p>
   </li>
   <li>
   <p>The server builder <code>bundleDependencies</code> option has been removed. This option was used pre Ivy. Currently, using this option is unlikely to produce working server bundles.</p>
   <p>The <code>externalDependencies</code> option can be used instead to exclude specific node_module packages from the final bundle.</p>
   </li>
   <li>
   <ul>
   <li>Deprecated support for tilde import has been removed. Please update the imports by removing the <code>~</code>.</li>
   </ul>
   <p>Before</p>
   <pre lang="scss"><code>@import &quot;~font-awesome/scss/font-awesome&quot;;
   </code></pre>
   <p>After</p>
   <pre lang="scss"><code>@import &quot;font-awesome/scss/font-awesome&quot;;
   </code></pre>
   <ul>
   <li>By default the CLI will use Sass modern API, While not recommended, users can still opt to use legacy API by setting <code>NG_BUILD_LEGACY_SASS=1</code>.</li>
   </ul>
   </li>
   <li>
   <p>Internally the Angular CLI now always set the TypeScript <code>target</code> to <code>ES2022</code> and <code>useDefineForClassFields</code> to <code>false</code> unless the target is set to <code>ES2022</code> or later in the TypeScript configuration. To control ECMA version and features use the Browerslist configuration.</p>
   </li>
   <li>
   <p><code>require.context</code> are no longer parsed. Webpack specific features are not supported nor guaranteed to work in the future.</p>
   </li>
   <li>
   <p>Producing ES5 output is no longer possible. This was needed for Internet Explorer which is no longer supported. All browsers that Angular supports work with ES2015+</p>
   </li>
   <li>
   <p>server builder <code>bundleDependencies</code> option now only accept a boolean value.</p>
   </li>
   <li>
   <p>Deprecated support for Stylus has been removed. The Stylus package has never reached a stable version and its usage in the Angular CLI is minimal. It's recommended to migrate to another CSS preprocessor that the Angular CLI supports.</p>
   </li>
   </ul>
   <h3><code>@​angular-devkit/core</code></h3>
   <ul>
   <li>Workspace projects with missing <code>root</code> is now an error.</li>
   </ul>
   <h3><code>@​ngtools/webpack</code></h3>
   <ul>
   <li>TypeScript versions older than 4.8.2 are no longer supported.</li>
   </ul>
   <h3><code>@​schematics/angular</code></h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a href="https://github.com/angular/angular-cli/commit/766d4a0895e7895211e93bc73ff131c6e47613a7"><img src="https://img.shields.io/badge/766d4a089-feat-blue" alt="feat - 766d4a089" /></a></td>
   <td>add migration to remove require calls from karma builder main file</td>
   </tr>
   <tr>
   <td><a href="https://github.com/angular/angular-cli/commit/d8bff4f1e68a76da1983f9d0774f415e73dfd8c3"><img src="https://img.shields.io/badge/d8bff4f1e-feat-blue" alt="feat - d8bff4f1e" /></a></td>
   <td>Added --project-root option to the library schematics</td>
   </tr>
   <tr>
   <td><a href="https://github.com/angular/angular-cli/commit/597bfea1b29cc7b25d1f466eb313cbeeb6dffc98"><img src="https://img.shields.io/badge/597bfea1b-feat-blue" alt="feat - 597bfea1b" /></a></td>
   <td>drop <code>polyfills.ts</code> file from new templates</td>
   </tr>
   <tr>
   <td><a href="https://github.com/angular/angular-cli/commit/1c21e470c76d69d08e5096b46b952dbce330f7ef"><img src="https://img.shields.io/badge/1c21e470c-feat-blue" alt="feat - 1c21e470c" /></a></td>
   <td>enable error on unknown properties and elements in tests</td>
   </tr>
   </tbody>
   </table>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a href="https://github.com/angular/angular-cli/blob/main/CHANGELOG.md"><code>@​angular-devkit/build-angular</code>'s changelog</a>.</em></p>
   <blockquote>
   <h1>15.0.0 (2022-11-16)</h1>
   <h2>Breaking Changes</h2>
   <h3><code>@​angular/cli</code></h3>
   <ul>
   <li>The Angular CLI no longer supports <code>16.10.x</code>, <code>16.11.x</code> and <code>16.12.x</code>. Current minimum versions of Node.js are <code>14.20.0</code>, <code>16.13.0</code> and <code>18.10.0</code>.</li>
   <li>Node.js versions older than 14.20 are no longer supported.</li>
   <li>The 'path' option in schematics schema no longer has a special meaning. Use 'workingDirectory' smart default provider should be used instead.</li>
   </ul>
   <h3><code>@​schematics/angular</code></h3>
   <ul>
   <li>Removed unused <code>appDir</code> option from Universal and App-Shell schematic. This option can safely be removed if present since it no longer has effect.</li>
   </ul>
   <h3></h3>
   <ul>
   <li>
   <p><code>analyticsSharing</code> option in the global angular configuration has been
   removed without replacement. This option was used to configure the Angular CLI to access to your own users' CLI usage data.</p>
   <p>If this option is used, it can be removed using <code>ng config --global cli.analyticsSharing undefined</code>.</p>
   </li>
   <li>
   <p>analytics APIs have been removed without replacement from <code>@angular-devkit/core</code> and <code>@angular-devkit/architect</code>.</p>
   </li>
   </ul>
   <h3><code>@​angular-devkit/build-angular</code></h3>
   <ul>
   <li>
   <p>TypeScript versions older than 4.8.2 are no longer supported.</p>
   </li>
   <li>
   <p>The server builder <code>bundleDependencies</code> option has been removed. This option was used pre Ivy. Currently, using this option is unlikely to produce working server bundles.</p>
   <p>The <code>externalDependencies</code> option can be used instead to exclude specific node_module packages from the final bundle.</p>
   </li>
   <li>
   <ul>
   <li>Deprecated support for tilde import has been removed. Please update the imports by removing the <code>~</code>.</li>
   </ul>
   <p>Before</p>
   <pre lang="scss"><code>@import '~font-awesome/scss/font-awesome';
   </code></pre>
   <p>After</p>
   <pre lang="scss"><code>@import 'font-awesome/scss/font-awesome';
   </code></pre>
   <ul>
   <li>By default the CLI will use Sass modern API, While not recommended, users can still opt to use legacy API by setting <code>NG_BUILD_LEGACY_SASS=1</code>.</li>
   </ul>
   </li>
   <li>
   <p>Internally the Angular CLI now always set the TypeScript <code>target</code> to <code>ES2022</code> and <code>useDefineForClassFields</code> to <code>false</code> unless the target is set to <code>ES2022</code> or later in the TypeScript configuration. To control ECMA version and features use the Browerslist configuration.</p>
   </li>
   <li>
   <p><code>require.context</code> are no longer parsed. Webpack specific features are not supported nor guaranteed to work in the future.</p>
   </li>
   <li>
   <p>Producing ES5 output is no longer possible. This was needed for Internet Explorer which is no longer supported. All browsers that Angular supports work with ES2015+</p>
   </li>
   <li>
   <p>server builder <code>bundleDependencies</code> option now only accept a boolean value.</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a href="https://github.com/angular/angular-cli/commits/15.0.0">compare view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
   - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
   - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
   - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
   - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
   
   You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/incubator-datalab/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscribe@datalab.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@datalab.apache.org
For additional commands, e-mail: dev-help@datalab.apache.org


[GitHub] [incubator-datalab] dependabot[bot] commented on pull request #1797: Bump loader-utils and @angular-devkit/build-angular in /services/self-service/src/main/resources/webapp

Posted by GitBox <gi...@apache.org>.
dependabot[bot] commented on PR #1797:
URL: https://github.com/apache/incubator-datalab/pull/1797#issuecomment-1339665459

   Looks like these dependencies are updatable in another way, so this is no longer needed.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscribe@datalab.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@datalab.apache.org
For additional commands, e-mail: dev-help@datalab.apache.org


[GitHub] [incubator-datalab] dependabot[bot] closed pull request #1797: Bump loader-utils and @angular-devkit/build-angular in /services/self-service/src/main/resources/webapp

Posted by GitBox <gi...@apache.org>.
dependabot[bot] closed pull request #1797: Bump loader-utils and @angular-devkit/build-angular in /services/self-service/src/main/resources/webapp
URL: https://github.com/apache/incubator-datalab/pull/1797


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscribe@datalab.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@datalab.apache.org
For additional commands, e-mail: dev-help@datalab.apache.org