Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merge main from dependabot/dependabot-core #277

Merged
merged 682 commits into from
Jun 14, 2021
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
682 commits
Select commit Hold shift + click to select a range
9911abf
Update CHANGELOG.md
feelepxyz May 25, 2021
d6633a3
Merge pull request #3787 from dependabot/v0.148.7-release-notes
feelepxyz May 25, 2021
6be4061
v0.148.8
jurre May 25, 2021
e8a67df
Merge pull request #3788 from dependabot/v0.148.8-release-notes
jurre May 25, 2021
8e75fe9
Check version is correct before filtering ignored
feelepxyz May 25, 2021
76d338a
npm: handle latest version requirement
feelepxyz May 24, 2021
36da2d4
Merge remote-tracking branch 'up/main' into updates-1480-source-addre…
xlgmokha May 25, 2021
04d3f60
fix: remove duplicate method definition
xlgmokha May 25, 2021
1095425
test: check if version constraint is fixed
xlgmokha May 25, 2021
9c2f1dc
fix: use nil version for pessimistic constraints
xlgmokha May 25, 2021
e502a03
test: detect resolved version from the lockfile
xlgmokha May 25, 2021
58cf033
fix: parse version from terraform lock file
xlgmokha May 25, 2021
1fe0a2e
refactor: collapse methods
xlgmokha May 25, 2021
a54a5e3
style: fix linter errors
xlgmokha May 25, 2021
f54970a
style: collapse lines
xlgmokha May 25, 2021
d58b553
test: add spec to parse provider metadata from a custom registry
xlgmokha May 25, 2021
5890926
fix: remove check for public hostname
xlgmokha May 25, 2021
f07b690
style: remove unused let
xlgmokha May 25, 2021
18298e7
test: fetch providers versions from a custom registry
xlgmokha May 25, 2021
226f7e8
fix: remove restriction to use registry.terraform.io
xlgmokha May 25, 2021
31bf1cc
test: fetch module versions from a custom registry
xlgmokha May 25, 2021
0e4494c
style: fix linter errors
xlgmokha May 25, 2021
ef331ef
fix: remove restriction to use registry.terraform.io
xlgmokha May 25, 2021
6cd3480
refactor: make registry.terraform.io the default
xlgmokha May 25, 2021
6156b33
refactor: forward credentials to the registry client
xlgmokha May 25, 2021
552a463
fix: inject Authorization header
xlgmokha May 25, 2021
53c631e
Merge pull request #3756 from xlgmokha/updates-1480-source-address-ho…
xlgmokha May 25, 2021
cc286b1
Merge remote-tracking branch 'up/main' into updates-1480-metadata
xlgmokha May 25, 2021
654b025
test: remove test that has been replaced
xlgmokha May 25, 2021
902d8d5
build(deps-dev): bump jest in /npm_and_yarn/helpers
dependabot[bot] May 26, 2021
e5db5d1
Merge pull request #3789 from dependabot/feelepxyz/check-version-corr…
feelepxyz May 26, 2021
a116247
Merge pull request #3791 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz May 26, 2021
c6b31ac
Terraform: Do not set dependency.version for version ranges
jurre May 26, 2021
25600ab
Merge pull request #3781 from dependabot/feelepxyz/fix-npm-latest-req…
feelepxyz May 26, 2021
095237d
Merge pull request #3792 from dependabot/jurre/handle-provider-versio…
jurre May 26, 2021
a3872c4
v0.148.9
jurre May 26, 2021
15f0751
Merge pull request #3794 from dependabot/v0.148.9-release-notes
jurre May 26, 2021
076137f
Composer: fix git clone error in lockfile updater
feelepxyz May 26, 2021
3eb5273
Yarn: use .yarnrc file if present
feelepxyz May 26, 2021
897d622
Merge pull request #3796 from dependabot/feelepxyz/yarn-use-yarnrc-fi…
feelepxyz May 26, 2021
b6cab7e
v0.148.10
feelepxyz May 26, 2021
ec8224f
Merge pull request #3797 from dependabot/v0.148.10-release-notes
feelepxyz May 26, 2021
3e076e6
Merge pull request #3790 from xlgmokha/updates-1480-metadata
xlgmokha May 26, 2021
8bf0487
v0.149.0
xlgmokha May 26, 2021
f573c82
Merge pull request #3799 from xlgmokha/v0.149.0-release-notes
xlgmokha May 26, 2021
71c125c
Bundler: Update bundler to 2.2.18
jurre May 26, 2021
66f207a
Bundler: Fix ruby version patch for 2.2.18
jurre May 26, 2021
4e2f3ff
Merge pull request #3798 from dependabot/jurre/bundler-2.2.18
jurre May 27, 2021
2489ae6
v0.149.1
jurre May 27, 2021
fdb58bf
Merge pull request #3801 from dependabot/v0.149.1-release-notes
jurre May 27, 2021
36c7fb4
Tests: avoid squatted repositories
jurre May 27, 2021
2be3d7c
Merge pull request #3802 from dependabot/jurre/fix-npm-test-failures
jurre May 27, 2021
ecd5697
gomod: UpdateChecker - handle invalid module path error on update
mctofu May 27, 2021
80ddffb
Bump eslint from 7.26.0 to 7.27.0 in /npm_and_yarn/helpers
dependabot[bot] May 27, 2021
bd9236c
v0.149.2
jurre May 27, 2021
d324221
Merge pull request #3803 from dependabot/v0.149.2-release-notes
jurre May 27, 2021
0578be9
Merge pull request #3800 from dependabot/mctofu/module-path-change-on…
mctofu May 27, 2021
74cfc11
bump elixir version from 1.10.4 -> 1.11.4
baseballlover723 May 27, 2021
a1a32f9
Bump to latest ruby versions
cetinajero May 27, 2021
ac3da53
poetry: support pyproject.toml indentation
mctofu May 28, 2021
6e69882
Merge pull request #3804 from baseballlover723/pr/elixir_1.11.4
feelepxyz May 28, 2021
361b8fd
Merge pull request #3795 from dependabot/feelepxyz/composer-fix-git-c…
feelepxyz May 28, 2021
359d48a
Merge pull request #3774 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz May 28, 2021
89fcb95
Tests: Rename non-existent go package name to domain we own
jurre May 28, 2021
ee30f3f
Merge pull request #3805 from cetinajero/feature/bump-ruby-versions
feelepxyz May 28, 2021
b345023
Merge pull request #3808 from dependabot/jurre/clean-up-squattable-repos
jurre May 28, 2021
3ad028d
Bundler: handle gemspec req ruby version ranges
feelepxyz May 28, 2021
5ddce41
Merge pull request #3809 from dependabot/feelepxyz/handle-ruby-versio…
feelepxyz May 28, 2021
f22bb22
v0.149.3
feelepxyz May 28, 2021
6c851af
Merge pull request #3810 from dependabot/v0.149.3-release-notes
feelepxyz May 28, 2021
955ecce
Merge pull request #3807 from dependabot/mctofu/poetry-indentation
mctofu May 28, 2021
e15578c
test: ensure terraform HTTP API service discovery is performed
xlgmokha May 28, 2021
3522282
fix: perform service discovery
xlgmokha May 28, 2021
8d67cb2
chore: update vcr fixtures to include service discovery requests
xlgmokha May 28, 2021
d4288a8
fix: perform service discovery for provider API
xlgmokha May 28, 2021
5825ea4
fix: use service discovery to find metadata
xlgmokha May 28, 2021
9ddd3df
style: fix linter errors
xlgmokha May 28, 2021
9c1086d
chore: remove unused code
xlgmokha May 28, 2021
bcabf6c
refactor: delegate to instance method instead of variable
xlgmokha May 28, 2021
360d66e
test: add service discovery to fixtures
xlgmokha May 28, 2021
59cfa0d
test: stub service discovery lookup
xlgmokha May 28, 2021
cac5c0f
build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers
dependabot[bot] May 31, 2021
3bafa7a
build(deps-dev): bump jest in /npm_and_yarn/helpers
dependabot[bot] May 31, 2021
67fc6d5
Bump composer/composer from 2.0.12 to 2.0.14 in /composer/helpers/v2
dependabot[bot] May 31, 2021
d75b655
refactor: extract method to build url
xlgmokha May 31, 2021
7d253a4
refactor: raise a DependabotError instead of RuntimeError
xlgmokha May 31, 2021
816bf2a
Update terraform/lib/dependabot/terraform/registry_client.rb
xlgmokha May 31, 2021
290b6c1
fix: expand absolute urls in service discovery
xlgmokha May 31, 2021
1493409
test: relative and missing service urls
xlgmokha May 31, 2021
e8455c7
fix: raise error for unsupported schemes
xlgmokha May 31, 2021
1c9dcc1
refactor: replace usages of RuntimeError with DependabotError
xlgmokha May 31, 2021
632d720
test: collapse subject and before blocks
xlgmokha May 31, 2021
879a190
test: metadata endpoint is not found
xlgmokha May 31, 2021
01ccda8
test: follow redirect to metadata endpoint
xlgmokha May 31, 2021
5f075f3
Merge remote-tracking branch 'up/main' into updates-1480-service-disc…
xlgmokha May 31, 2021
aae8f55
test: reproduce bug that occurs when updating a module
xlgmokha May 31, 2021
67bd570
fix: update regex to match on optional hostname declaration
xlgmokha May 31, 2021
e55124a
style: fix linter errors
xlgmokha May 31, 2021
9598a68
test: remove non-essential elements from fixture
xlgmokha May 31, 2021
f63fc26
fix: match provider source addresses with optional hostname
xlgmokha May 31, 2021
82c783d
style: fix linter errors
xlgmokha May 31, 2021
ee23c07
Merge pull request #3777 from dependabot/dependabot/composer/composer…
jurre Jun 1, 2021
fe446a3
Bundler tests: Use git sources for organizations that we own
jurre May 31, 2021
06b8320
Merge pull request #3819 from dependabot/jurre/bundler-git-fixtures
jurre Jun 1, 2021
aea8f0c
Update terraform/lib/dependabot/terraform/file_updater.rb
xlgmokha Jun 1, 2021
a1daf71
Merge pull request #3811 from xlgmokha/updates-1480-service-discovery
xlgmokha Jun 1, 2021
49da540
Merge pull request #3821 from dependabot/updates-1480-private-modules
xlgmokha Jun 1, 2021
fee1246
v0.149.4
xlgmokha Jun 1, 2021
aad2d27
Merge pull request #3825 from xlgmokha/v0.149.4-release-notes
xlgmokha Jun 1, 2021
4277f55
refactor: raise PrivateSourceAuthenticationFailure instead of Dependa…
xlgmokha Jun 1, 2021
4f6bf22
chore(deps-dev): update rubocop requirement from ~> 1.15.0 to ~> 1.16.0
dependabot[bot] Jun 2, 2021
51aa83d
chore(deps): bump composer/composer in /composer/helpers/v2
dependabot[bot] Jun 2, 2021
11aeac4
Merge pull request #3831 from dependabot/dependabot/composer/composer…
feelepxyz Jun 2, 2021
9f51799
Enable automerge on dependabot pull requests
feelepxyz Jun 2, 2021
f8afaa6
Merge pull request #3830 from dependabot/dependabot/bundler/common/ru…
feelepxyz Jun 2, 2021
bf6e230
Merge pull request #3816 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz Jun 2, 2021
eb81057
Merge pull request #3815 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz Jun 2, 2021
3b04258
Update .github/workflows/dependabot-automerge.yml
feelepxyz Jun 2, 2021
1b3f188
Update .github/workflows/dependabot-automerge.yml
feelepxyz Jun 2, 2021
bb2d3b0
Merge pull request #3832 from dependabot/feelepxyz/enable-automerge-o…
feelepxyz Jun 2, 2021
a5cc303
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
c346181
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
be6bd38
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
c2db3ef
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
2d22f0a
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
bb24c30
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
aa692f5
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
4ce9f03
Update dependabot-automerge.yml
feelepxyz Jun 2, 2021
e82714a
build(deps): bump detect-indent in /npm_and_yarn/helpers
dependabot[bot] Jun 2, 2021
fac45d1
Merge pull request #3814 from dependabot/dependabot/npm_and_yarn/npm_…
github-actions[bot] Jun 2, 2021
918af67
Hex tests: Use git dependencies of repositories we own
jurre Jun 2, 2021
1951378
Merge pull request #3827 from xlgmokha/updates-1480-raise-authenticat…
xlgmokha Jun 2, 2021
6e4a793
v0.149.5
xlgmokha Jun 2, 2021
83c7f99
Merge pull request #3836 from dependabot/v0.149.5-release-notes
xlgmokha Jun 2, 2021
546ee09
build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers
dependabot[bot] Jun 3, 2021
cc8709d
Merge pull request #3839 from dependabot/dependabot/npm_and_yarn/npm_…
github-actions[bot] Jun 3, 2021
365b717
Merge pull request #3835 from dependabot/jurre/hex-git-deps
jurre Jun 3, 2021
9f4c014
build(deps): bump dependabot/fetch-metadata from 1.0.2 to 1.0.3
dependabot[bot] Jun 4, 2021
0a9377f
Merge pull request #3848 from dependabot/dependabot/github_actions/de…
github-actions[bot] Jun 4, 2021
af4ac7e
Install Terraform in docker shell
Nishnha Jun 2, 2021
d11df17
Ignore .terraform and .terraform.lock.hcl
Nishnha Jun 2, 2021
4bad08f
Add file selectors for lockfiles
Nishnha Jun 2, 2021
b4bff69
Create lockfile fixture
Nishnha Jun 2, 2021
b8ef01e
Update all lockfile dependencies with `terraform init -upgrade`
Nishnha Jun 2, 2021
8d1463a
Create test for lockfile update
Nishnha Jun 2, 2021
2dd5e4e
Update lockfile dependencies one at a time using `terraform providers…
Nishnha Jun 4, 2021
b18ff00
Fix FileUpdater test
Nishnha Jun 2, 2021
0e7fcf7
Create versions.tf, remove versioning from main.tf
Nishnha Jun 2, 2021
f6f0973
Pin lockfile version and constraint, add provider dependency
Nishnha Jun 2, 2021
b6fa35d
Add expected lockfile for hashicorp/random
Nishnha Jun 3, 2021
85b5b40
Parse provider source strings
Nishnha Jun 3, 2021
f26e9c9
Update lockfiles when provider dependencies are updated
Nishnha Jun 3, 2021
deaf4fa
Add lockfile to the fetched_files array in FileFetcher
Nishnha May 25, 2021
c33bc91
Add lockfile to updated_dependency_files array in FileUpdater
Nishnha May 25, 2021
07da980
Add codepath for source type 'lockfile' in FileUpdater
Nishnha Jun 4, 2021
b632de2
Add tests for versions.tf dependency updates with and without a lockfile
Nishnha May 25, 2021
d650ff2
fix: support github urls that are not pinned
xlgmokha Jun 1, 2021
9e0ceb7
Update hashicorp/aws to a valid version in file_parser_spec test
Nishnha May 25, 2021
9d070b7
Run shell commands with escaped arguments
Nishnha May 26, 2021
596305a
Inline expected values for lockfile tests
Nishnha May 27, 2021
5e5ac94
Fix FileUpdater test version and name issues
Nishnha May 27, 2021
2435577
Update FileFetcher#lock_file and FileSelector#lock_file to use FileSe…
Nishnha May 27, 2021
3a4f5d8
Add UpdateChecker#lockfile_dependency?
Nishnha Jun 4, 2021
dd497da
Add test for lockfile parsing to FileParser
Nishnha May 27, 2021
189cf9d
Pass filename to update_lockfile_declaration
Nishnha May 27, 2021
a8a5f25
Modify FileParser#build_lockfile_dependency to update context in place
Nishnha May 27, 2021
5b19e1c
Fix line endings for version.tf test
Nishnha May 27, 2021
f5aba51
Patch invalid registry source FileParser test
Nishnha May 28, 2021
4ee98b3
Update FileSelector#terragrunt_file? to use the lock_file? method
Nishnha May 28, 2021
9ca79a4
Modify registry_source_details_from
Nishnha Jun 4, 2021
ca9d493
Do not include lockfile in directory when updating a lockfile dependency
Nishnha Jun 2, 2021
ba62445
Update tests to new provider version, reflect prefer_lockfile_source
Nishnha Jun 2, 2021
831fbfc
Ensure the lockfile version changes
Nishnha Jun 4, 2021
b1dd70c
Check lockfile exists before adding to updated_files, fix short-circu…
Nishnha Jun 3, 2021
760775f
Merge get(endpoint:) function from main
Nishnha Jun 4, 2021
3929aa4
Update tests to reflect latest version
Nishnha Jun 4, 2021
189b27c
Rubocop linting
Nishnha Jun 4, 2021
08d6eca
build(deps-dev): bump prettier in /npm_and_yarn/helpers
dependabot[bot] Jun 7, 2021
a452b2c
build(deps-dev): bump eslint in /npm_and_yarn/helpers
dependabot[bot] Jun 7, 2021
b76bb08
build(deps): bump composer/composer in /composer/helpers/v2
dependabot[bot] Jun 7, 2021
023e695
Delete automerge until PR state issue is fixed
feelepxyz Jun 7, 2021
28e574a
Merge pull request #3853 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz Jun 7, 2021
16e556a
Merge pull request #3852 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz Jun 7, 2021
3818c3e
build(deps-dev): bump jest in /npm_and_yarn/helpers
dependabot[bot] Jun 7, 2021
794a7e0
Fix error message matches
feelepxyz Jun 7, 2021
bd080dd
Merge pull request #3846 from dependabot/dependabot/npm_and_yarn/npm_…
feelepxyz Jun 7, 2021
cea8a73
Merge pull request #3854 from dependabot/dependabot/composer/composer…
github-actions[bot] Jun 7, 2021
6506f6d
v0.150.0
feelepxyz Jun 7, 2021
35ead46
Fix nuget spec
feelepxyz Jun 7, 2021
8283fd8
Merge pull request #3858 from dependabot/v0.150.0-release-notes
feelepxyz Jun 7, 2021
b06a085
build(deps-dev): bump friendsofphp/php-cs-fixer in /composer/helpers/v2
dependabot[bot] Jun 3, 2021
2dd7f82
Rename config file
feelepxyz Jun 7, 2021
8f4c00c
Merge pull request #3840 from dependabot/dependabot/composer/composer…
github-actions[bot] Jun 7, 2021
3aa82ed
Pin erlang to OTP 23 until we can resolve OTP 24 warning issues
mctofu Jun 7, 2021
9612adf
test: pin assertions to the latest HEAD commit
xlgmokha Jun 7, 2021
5a9db62
Remove copy_dir_to_temp_directory, use SharedHelpers inline
Nishnha Jun 7, 2021
df088a9
Revert dependabot/FileUpdaters/base changes, reimplement in terraform…
Nishnha Jun 7, 2021
8431a27
Revert changes to registry_source_details_from
Nishnha Jun 7, 2021
dd2f3d9
Merge pull request #3862 from dependabot/mctofu/pin-erlang
mctofu Jun 7, 2021
80987f7
v0.151.0
mctofu Jun 7, 2021
69a10e5
Merge pull request #3863 from dependabot/v0.151.0-release-notes
mctofu Jun 7, 2021
41930ef
Memoize update_lockfile_declaration method by dependency
Nishnha Jun 7, 2021
9df3cda
Merge pull request #3837 from xlgmokha/core-3813
xlgmokha Jun 7, 2021
be5764f
Rubocop
Nishnha Jun 7, 2021
be76efd
v0.151.1
xlgmokha Jun 7, 2021
11d5c51
Merge pull request #3864 from xlgmokha/v0.151.1-release-notes
xlgmokha Jun 7, 2021
ced6061
build(deps): bump composer/composer in /composer/helpers/v2
dependabot[bot] Jun 8, 2021
6c760a9
Merge pull request #3866 from dependabot/dependabot/composer/composer…
jurre Jun 8, 2021
4280002
Add retry for Azure client POST
Jun 3, 2021
90adeb8
Use double quotes to avoid extra backslashes for escaping.
Jun 3, 2021
f5d81dc
Merge pull request #3843 from AlekhyaYalla/alekhyayalla/retry_azure_p…
jurre Jun 8, 2021
0f999e0
Remove lockfile_dependency? from UpdateChecker
Nishnha Jun 8, 2021
ec8a1b6
Revert consul/aws invalid module test
Nishnha Jun 8, 2021
780bcdb
Revert splitting case statement
Nishnha Jun 8, 2021
ec23d3f
Remove dependency argument from update_lockfile_declaration
Nishnha Jun 8, 2021
de29f5d
Remove checks for lockfile in updated_dependency_files
Nishnha Jun 8, 2021
a7a1ba1
Remove lockfile_changed? method
Nishnha Jun 8, 2021
3bfcc37
Remove memoization for update_lockfile_declaration
Nishnha Jun 8, 2021
52a2c80
Move lock_file.empty? check to update_lockfile_declaration method
Nishnha Jun 8, 2021
257de2a
build(deps): bump pipenv from 2018.11.26 to 2021.5.29 in /python/helpers
dependabot[bot] May 31, 2021
8d3cea5
Replace FileSelector#lock_file select with find
Nishnha Jun 8, 2021
b3c7742
Refactor FileFetcher#lock_file
Nishnha Jun 8, 2021
0b7ac50
Remove RegistryClient#get
Nishnha Jun 8, 2021
4ed618c
Invert updated_content guard
Nishnha Jun 8, 2021
234640f
Add a test to check updated_dependency_files doesn't return a lockfil…
Nishnha Jun 8, 2021
db8974a
Rubocop, remove commented out code
Nishnha Jun 8, 2021
b6ae9d3
Drop python 2.x support and fix pipenv 2021.5.29 tests and
jurre Jun 8, 2021
d7baa54
Merge pull request #3817 from dependabot/dependabot/pip/python/helper…
jurre Jun 9, 2021
81a424e
Pin Terraform version
Nishnha Jun 9, 2021
b930756
Merge pull request #3766 from dependabot/nishnha/terraform-lockfile-s…
Nishnha Jun 9, 2021
f1e60c6
Upgrade pip to 21.1.2 and pip-tools to 6.1.0
jurre Jun 9, 2021
3518e04
Add lockfile as an array to file_fetcher
Nishnha Jun 9, 2021
bcb7fde
Add lockfile test to FileFetcher
Nishnha Jun 9, 2021
d40dc23
Merge pull request #3871 from dependabot/jurre/pip21-pip-tools-6.1
jurre Jun 9, 2021
e425a28
Merge pull request #3872 from dependabot/nishnha/terraform-lockfile-fix
Nishnha Jun 9, 2021
5d4616e
v0.152.0
jurre Jun 10, 2021
56f339e
Merge pull request #3879 from dependabot/v0.152.0-release-notes
jurre Jun 10, 2021
5c32cd7
Add instruction to checkout new branch
Nishnha Jun 10, 2021
c3001f3
DependencyFileNotParseable error with useful message for old terrafor…
Nishnha Jun 10, 2021
1cb49dc
Check if old provider syntax using is_a? instead of respond_to?
Nishnha Jun 10, 2021
3e45ba4
Add test case for hcl1 provider syntax
Nishnha Jun 10, 2021
a93168b
Terraform: patch up tests
jurre Jun 11, 2021
169a8a6
Merge pull request #3885 from dependabot/jurre/patch-tf-tests
jurre Jun 11, 2021
0be4294
Tests: Allow profiling tests with stackprof when tagged
jurre Jun 11, 2021
522beaa
Merge pull request #3884 from dependabot/jurre/rspec-profile
jurre Jun 11, 2021
a55f8d4
Modify fixture name
Nishnha Jun 11, 2021
6faf9e4
Merge pull request #3882 from dependabot/update-bump-version
Nishnha Jun 11, 2021
c4a28e9
Merge pull request #3883 from dependabot/nishnha/terraform-depricated…
Nishnha Jun 11, 2021
a6d70fe
v0.152.1
Nishnha Jun 11, 2021
c25a331
Merge pull request #3886 from dependabot/v0.152.1-release-notes
Nishnha Jun 11, 2021
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
43 changes: 43 additions & 0 deletions .github/ISSUE_TEMPLATE/migration-issue.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
name: "Dependabot Preview migration issue"
about: Having issues migrating from Dependabaot Preview? Here's the place to get help!
title: ''
labels: 'E: preview-migration'
assignees: '@dependabot/preview-migration-reviewers'

---

<!--
Please search existing issues to avoid creating duplicates. Several issues for common feature requests already exist, including:
- `live` schedule support: https://github.com/dependabot/dependabot-core/issues/3488
- `automerge` support: https://github.com/dependabot/dependabot-core/issues/2268
-->

<!-- If your issue is unrelated to the above, please provide us as much information as possible to help us provide a quick fix -->

## Basic info:

**Package ecosystem**
<!-- npm, docker, bundler, etc. -->
**Package manager version**
<!-- If applicable, specify the package manager version you're using (e.g., npm 7.1, pip-compile 5.0, etc.) -->
**Language version**
<!-- If applicable, specify the language version you're using (e.g., node 14.1, Ruby 2.7, etc. ) -->
**Manifest location and content prior to update**
<!-- If applicable, specify the path to each manifest file (/client/package.json, /Gemfile, etc.) -->
<!-- If applicable, attach each manifest file or provide a link to each manifest file -->
**Updated dependency**
<!-- If applicable, the dependency name and to and from versions -->
**Native package manager behavior**
<!-- If applicable, what output do you see when you update the dependency using the native package manager (e.g., bundler, npm, etc.)? -->
**Images of the diff or a link to the PR, issue or logs**
<!-- If applicable, add links to public PR's or Issues that Dependabot opened, and/or paste in any related logs -->

## Previous behavior in Dependabot Preview:

<!-- Please include your `.dependabot/config.yml` as well as logs, etc. -->

## Current behavior in GitHub-native Dependabot:

<!-- Please include your `.github/dependabot.yml` as well as logs, etc. -->

4 changes: 4 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,3 +28,7 @@ updates:
directory: "/go_modules/helpers"
schedule:
interval: "daily"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
2 changes: 2 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ on:
pull_request:
branches:
- "**"
permissions:
contents: read
jobs:
ci:
name: CI
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@ on:
- main
tags:
- v[0-9]+.[0-9]+.[0-9]+

permissions:
contents: read
jobs:
push-core-image:
name: Push dependabot-core image to docker hub
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/gems.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,8 @@ on:
push:
tags:
- v[0-9]+.[0-9]+.[0-9]+

permissions:
contents: read
jobs:
release-gems:
name: Release gems to rubygems.org
Expand Down
6 changes: 6 additions & 0 deletions .rubocop.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ Layout/DotPosition:
Layout/EmptyLinesAroundAttributeAccessor:
Enabled: false

Layout/FirstArrayElementIndentation:
EnforcedStyle: consistent

Layout/FirstHashElementIndentation:
EnforcedStyle: consistent

Layout/LineLength:
Max: 120

Expand Down
258 changes: 258 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,261 @@
## v0.152.1, 11 June 2021

- Tests: Allow profiling tests with stackprof when tagged
- Throw an error when using the deprecated terraform provider syntax, include upgrade instructions
- Update `bump-version` with instructions to checkout the new branch

## v0.152.0, 10 June 2021

- Python: Upgrade pip to 21.1.2
- Python: Upgrade pip-tools to 6.1.0
- Python: Drop python 2.x support
- Python: Upgrade pipenv to 2021.5.29
- Terraform: Add support for lockfiles
- Terraform: Upgrade and pin Terraform to version 1.0.0

## v0.151.1, 7 June 2021

fix(npm): Prevent unnecessary hash pinning in lock file constraint

## v0.151.0, 7 June 2021

- Pin erlang to OTP 23 until we can resolve OTP 24 warning issues
- build(deps-dev): bump friendsofphp/php-cs-fixer in /composer/helpers/v2

## v0.150.0, 7 June 2021

- build(deps): bump composer/composer from 2.0.14 to 2.1.1 in /composer/helpers/v2
- build(deps-dev): bump jest in /npm_and_yarn/helpers
- build(deps-dev): bump eslint in /npm_and_yarn/helpers
- build(deps-dev): bump prettier in /npm_and_yarn/helpers
- build(deps): bump dependabot/fetch-metadata from 1.0.2 to 1.0.3
- build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers

## v0.149.5, 2 June 2021

- build(deps): bump detect-indent in /npm_and_yarn/helpers
- chore(deps): bump composer/composer in /composer/helpers/v2
- chore(deps-dev): update rubocop requirement from ~> 1.15.0 to ~> 1.16.0
- refactor(Terraform): raise PrivateSourceAuthenticationFailure instead of DependabotError
- build(deps-dev): bump jest in /npm_and_yarn/helpers
- build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers

## v0.149.4, 1 June 2021

- fix(Terraform): use service discovery protocol
- fix(Terraform): parse optional hostname from module/provider source address
- Bump composer/composer from 2.0.12 to 2.0.14 in /composer/helpers/v2
- poetry: support pyproject.toml indentation

## v0.149.3, 28 May 2021

- Bundler: handle required ruby version ranges in gemspecs
- Bundler: Bump to latest ruby versions
- Elixir: Bump version from 1.10.4 -> 1.11.4
- gomod: UpdateChecker - handle invalid module path error on update
- Composer: handle git clone error in lockfile updater
- Bump eslint from 7.26.0 to 7.27.0 in /npm_and_yarn/helpers

## v0.149.2, 27 May 2021

- Tests: avoid squatted repositories

## v0.149.1, 27 May 2021

- Bundler: Fix ruby version patch for 2.2.18
- Bundler: Update bundler to 2.2.18

## v0.149.0, 26 May 2021

- Terraform: Use registry credentials

## v0.148.10, 26 May 2021

- Yarn: use .yarnrc file if present
- npm: handle latest version requirement

## v0.148.9, 26 May 2021

- Terraform: Do not set dependency.version for version ranges
- Terraform: Parse lockfiles to get exact version when present

## v0.148.8, 25 May 2021

- Composer: handle unreachable git vcs source
- Terraform: handle implicit (v0.12 style) provider sources

## v0.148.7, 25 May 2021

- npm: Handle multiple sources in the update checker
- Composer: Handle invalid composer.json

## v0.148.6, 21 May 2021

- Handle nil dependency version when raising AllVersionsIgnored

## v0.148.5, 21 May 2021

- Terraform: Fix updating multiple providers
- Dockerfile: split up native helper build steps

## v0.148.4, 21 May 2021

- Terraform: Improve updating provider requirements
- Bundler 2: No longer bump yanked gems when updating dependency
- Upgrade bundler to 2.2.17
- Bump @npmcli/arborist from 2.5.0 to 2.6.0 in /npm_and_yarn/helpers

## v0.148.3, 19 May 2021

- fix(common): skip validation on non-git sources
- fix(npm/yarn): prefer private registries over public ones

## v0.148.2, 19 May 2021

- Terraform: Fix finding metadata for providers

## v0.148.1, 19 May 2021

- npm: Handle nested workspace dependencies installed in the top-level
`node_modules` folder

## v0.148.0, 19 May 2021

- Terraform: Support provider updates
- Terraform: Extract RegistryClient for communicating with terraform registry
- Go modules: Replace custom helper with `go get -d lib@version` @jeffwidman

## v0.147.1, 18 May 2021

- Terraform: remove legacy terraform feature flag
- Terraform: Clean up support for legacy terragrunt files
- Hex: Fix version resolver specs
- Update rubocop requirement from ~> 1.14.0 to ~> 1.15.0 in /common
- Bump phpstan/phpstan from 0.12.85 to 0.12.88 in /composer/helpers/v1
- Bump phpstan/phpstan from 0.12.85 to 0.12.88 in /composer/helpers/v2
- build(deps-dev): bump eslint in /npm_and_yarn/helpers
- build(deps-dev): bump prettier in /npm_and_yarn/helpers
- build(deps): bump flake8 from 3.9.1 to 3.9.2 in /python/helpers
- build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers

## v0.147.0, 13 May 2021

- Switch HCL2 parser to be the default for Terraform. Supports Terraform v0.12+ [(#3716)](https://github.com/dependabot/dependabot-core/pull/3716)

## v0.146.1, 12 May 2021

- Actions: skip equivalent shorter semver tags, such as `v2` and `v2.1.0`
- Python: Run all pip-compile commands with options @JimNero009
- Terraform (prerelease): Handle terragrunt HCL files

## v0.146.0, 10 May 2021

- go_modules: Refactor go module version finder specs
- all: Filter lower versions when checking ignored versions
- Terraform: Document and improve coverage for RequirementsUpdater
- Revert "docker: FileParser consider image prefix/suffixes as unique"

## v0.145.4, 10 May 2021

- Actions: accept semver versions
- Actions: detect workflow steps pinned to semver versions

## v0.145.3, 7 May 2021

- go_modules: Gracefully handle +incompatible versions when checking for updates

## v0.145.2, 7 May 2021

- Nuget: Handle paginated v2 nuget api responses
- maven: allow security updates to multi-dependency properties
- build(deps): bump lodash
- build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers
- build(deps-dev): update rubocop requirement from ~> 1.13.0 to ~> 1.14.0

## v0.145.1, 5 May 2021

- go_modules: don't filter the current version
- terraform: move fixtures to project folders
## v0.145.0, 5 May 2021

- go_modules: support version ignores
- Dev env: mount go helper source in dev shell
- docker: FileParser unique suffixes
- go_modules: helper updates
- GitHub PullRequestCreator: prepend refs/
- build(deps): bump github.com/dependabot/gomodules-extracted

## v0.144.0, 5 May 2021

- Elm: Drop support for Elm 0.18
- Commom: Handle nil dependency version when generating ignored versions
- Python: allow comments when parsing setup.cfg
- go_modules: stub consistently and ignore invalid modules
- build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers
- build(deps-dev): bump friendsofphp/php-cs-fixer in /composer/helpers/v1
- build(deps-dev): bump friendsofphp/php-cs-fixer in /composer/helpers/v2

## v0.143.6, 30 April 2021

- Common: version-update:semver-major ignores all major version updates
- Document how to run tests within the dev docker container
- go_modules: Make error output more idiomatic
- Create CODE_OF_CONDUCT.md
- Common: IgnoreCondition: handle multi-length semver ranges
- Common: IgnoreCondition: don't ignore current version when ignoring patches

## v0.143.5, 29 April 2021

- gradle: only treat commit-like versions as git repositories
- dry-run: change SECURITY_ADVISORIES to kebab-case
- go_modules: helper improvements @jeffwidman
- go_modules: require go.16 for helpers @jeffwidman
- go_modules: use go1.16.3 @jeffwidman
- docker: handle versions generated with `git describe --tags --long` @kd7lxl
- build(deps): bump composer/composer in /composer/helpers/v1
- build(deps-dev): bump phpstan/phpstan in /composer/helpers

## v0.143.4, 26 April 2021

- Common: Add IgnoreCondition.security_updates_only, which disables version updates filtering
- build(deps-dev): bump eslint-config-prettier in /npm_and_yarn/helpers
- build(deps-dev): bump eslint in /npm_and_yarn/helpers

## v0.143.3, 23 April 2021

- Common: Do not transform update_types in IgnoreCondition
- build(deps): bump @npmcli/arborist in /npm_and_yarn/helpers

## v0.143.2, 22 April 2021

- Dependabot::Config::IgnoreCondition support dependency wildcards
- Dependabot::Config::IgnoreCondition support `update-types`
- go_modules: clarify comment @jeffwidman

## v0.143.1, 21 April 2021

- Gradle/Maven: Handle ruby style requirements with maven version
- Bundler: Add missing requirement_class for bundler latest version checker
- Add IgnoreCondition#dependency_name
- Dependabot::Config::File parse ignore_conditions
- Dependabot::Config::File parse commit_message_options

## v0.143.0, 21 April 2021

- Python: Add support for updating `setup.cfg` files @honnix
- Gomod: Run `go mod tidy` with flag to allow errors
- Handle ruby and package manager specific version requirements from ignore conditions
- build(deps): bump poetry from 1.1.4 to 1.1.6 in /python/helpers
- build(deps-dev): update rubocop requirement from ~> 1.12.0 to ~> 1.13.0
- build(deps-dev): bump friendsofphp/php-cs-fixer in /composer/helpers/v1
- build(deps-dev): bump friendsofphp/php-cs-fixer in /composer/helpers/v2
- build(deps-dev): bump phpstan/phpstan in /composer/helpers/v1
- build(deps-dev): bump phpstan/phpstan in /composer/helpers/v2
- dry-run: fetch ignore conditions and commit_message_options from `dependabot.yml` config file
- dry-run: set ignore conditions from `IGNORE_CONDITIONS` env
- Chore: Refactor `new_branch_name` function in branch_namer @milind009
- Bundler: Remove unused `using_bundler2` arg from v1 helpers

## v0.142.1, 16 April 2021

- Update npm from 7.7.4 to 7.10.0
Expand Down
Loading