Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency Updates: Bump the dependencies group across 1 directory with 3 updates #201

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 11, 2024

Bumps the dependencies group with 3 updates in the / directory: dotenv, firebase-admin and zod.

Updates dotenv from 16.4.5 to 16.4.7

Changelog

Sourced from dotenv's changelog.

16.4.7 (2024-12-03)

Changed

  • Ignore .tap folder when publishing. (oops, sorry about that everyone. - @​motdotla) #848

16.4.6 (2024-12-02)

Changed

  • Clean up stale dev dependencies #847
  • Various README updates clarifying usage and alternative solutions using dotenvx
Commits

Updates firebase-admin from 12.7.0 to 13.0.1

Release notes

Sourced from firebase-admin's releases.

Firebase Admin Node.js SDK v13.0.1

Bug Fixes

  • fix: Fix the property names when initializing the SDK with ServiceAccount type (#2779)

Miscellaneous

  • [chore] Release 13.0.1 (#2780)
  • build(deps-dev): bump @​firebase/auth-compat from 0.5.15 to 0.5.16 (#2776)
  • build(deps): bump google-auth-library from 9.14.2 to 9.15.0 (#2773)
  • build(deps): bump @​firebase/database-compat from 2.0.0 to 2.0.1 (#2774)
  • build(deps-dev): bump @​firebase/auth-types from 0.12.2 to 0.12.3 (#2775)

Firebase Admin Node.js SDK v13.0.0

Breaking Changes

  • change(rc): Update Remote Config condition evaluation hashing (#2760)
  • change(fcm): Remove deprecated FCM APIs (#2759)
  • change: Update Node support to 18 (#2756)
  • change: Migrate credentials to use google-auth-library (#2466)

New Features

  • feat(fcm): Add directBootOk field to AndroidConfig (#2745)

Bug Fixes

  • fix: Set the Quota Project ID only for ADC human accounts (#2761)

Miscellaneous

  • [chore] Release 13.0.0 (#2764)
  • build(deps): bump uuid from 11.0.2 to 11.0.3 (#2767)
  • build(deps-dev): bump nock from 13.5.5 to 13.5.6 (#2766)
  • chore: Add X-Goog-Api-Client metric header to outgoing authorized http requests (#2763)
  • chore: Upgrade dependencies (#2757)
  • Request timeout const name correction (#2743)
  • build(deps-dev): bump @​firebase/app-compat from 0.2.43 to 0.2.45 (#2746)
Commits
  • 90a8e5e [chore] Release 13.0.1 (#2780)
  • ef8b701 build(deps-dev): bump @​firebase/auth-compat from 0.5.15 to 0.5.16 (#2776)
  • cc78a4a build(deps): bump google-auth-library from 9.14.2 to 9.15.0 (#2773)
  • 7249cd3 build(deps): bump @​firebase/database-compat from 2.0.0 to 2.0.1 (#2774)
  • 2b6a373 build(deps-dev): bump @​firebase/auth-types from 0.12.2 to 0.12.3 (#2775)
  • 380ef0a fix: Fix the property names when initializing the SDK with ServiceAccount typ...
  • a6a930c [chore] Release 13.0.0 (#2764)
  • 8b978e0 build(deps): bump uuid from 11.0.2 to 11.0.3 (#2767)
  • 49a8e0b build(deps-dev): bump nock from 13.5.5 to 13.5.6 (#2766)
  • 4ee1bb2 fix: Set the Quota Project ID only for ADC human accounts (#2761)
  • Additional commits viewable in compare view

Updates zod from 3.23.8 to 3.24.1

Release notes

Sourced from zod's releases.

v3.24.1

Commits:

  • 0c6cbbdd1315683dd3d589fbdc5765c26431dcc9 Undeprecate .nonempty()
  • 4e219d6ad9d5e56e20afd7423092f506400a29e4 Bump min TS version to 5.0
  • 65adeeacef0274abbda5438470a3d2bfd376256d v3.24.1

v3.24.0

Implement @standard-schema/spec

This is the first version of Zod to implement the Standard Schema spec. This is a new community effort among several validation library authors to implement a common interface, with the goal of simplifying the process of integrating schema validators with the rest of the ecosystem. Read more about the project and goals here.

z.string().jwt()

Thanks to @​Mokshit06 and @​Cognition-Labs for this contribution!

To verify that a string is a valid 3-part JWT.

z.string().jwt();

⚠️ This does not verify your JWT cryptographically! It merely ensures its in the proper format. Use a library like jsonwebtoken to verify the JWT signature, parse the token, and read the claims.

To constrain the JWT to a specific algorithm:

z.string().jwt({ alg: "RS256" });

z.string().base64url()

Thank you to @​marvinruder!

To complement the JWT validation, Zod 3.24 implements a standalone .base64url() string validation API. (The three elements of JWTs are base64url-encoded JSON strings.)

z.string().base64url()

This functionality is available along the standard z.string().base64() validator added in Zod 3.23.

z.string().cidr()

Thanks to @​wataryooou for their work on this!

A validator for CIDR notation for specifying IP address ranges, e.g. 192.24.12.0/22.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by colinhacks, a new releaser for zod since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 3 updates

Bumps the dependencies group with 3 updates in the / directory: [dotenv](https://github.com/motdotla/dotenv), [firebase-admin](https://github.com/firebase/firebase-admin-node) and [zod](https://github.com/colinhacks/zod).


Updates `dotenv` from 16.4.5 to 16.4.7
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v16.4.5...v16.4.7)

Updates `firebase-admin` from 12.7.0 to 13.0.1
- [Release notes](https://github.com/firebase/firebase-admin-node/releases)
- [Changelog](https://github.com/firebase/firebase-admin-node/blob/master/CHANGELOG.md)
- [Commits](firebase/firebase-admin-node@v12.7.0...v13.0.1)

Updates `zod` from 3.23.8 to 3.24.1
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Changelog](https://github.com/colinhacks/zod/blob/main/CHANGELOG.md)
- [Commits](colinhacks/zod@v3.23.8...v3.24.1)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: firebase-admin
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: zod
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Dec 11, 2024
Copy link

Dependency Review

The following issues were found:

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.

View full job summary

Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 20, 2024

Superseded by #211.

@dependabot dependabot bot closed this Dec 20, 2024
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/dependencies-ef96c66450 branch December 20, 2024 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants