Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

test(deps): bump otpauth from 9.3.4 to 9.3.5 in the npm group #646

Merged
merged 1 commit into from
Nov 18, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 18, 2024

Bumps the npm group with 1 update: otpauth.

Updates otpauth from 9.3.4 to 9.3.5

Release notes

Sourced from otpauth's releases.

v9.3.5

What's Changed

Full Changelog: hectorm/otpauth@v9.3.4...v9.3.5

Commits
  • 8ad3aa4 9.3.5
  • 68e5d04 Reorder scripts
  • 9601d9a Regenerate package-lock.json
  • 0cb50f1 Bump the npm-development-minor-patch group with 2 updates (#563)
  • b89693a Bump github/codeql-action in the github-actions-all group (#564)
  • dcbf02e Initialize the OTP object at each iteration to avoid an error in the tests af...
  • 5aeef0c Bump the npm-development-minor-patch group across 1 directory with 9 updates ...
  • fe3f19b Bump the github-actions-all group with 5 updates (#560)
  • 6af28fd Add test commands for QuickJS
  • 76940fd Expand wildcards in script commands
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm group with 1 update: [otpauth](https://github.com/hectorm/otpauth).


Updates `otpauth` from 9.3.4 to 9.3.5
- [Release notes](https://github.com/hectorm/otpauth/releases)
- [Commits](hectorm/otpauth@v9.3.4...v9.3.5)

---
updated-dependencies:
- dependency-name: otpauth
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot requested a review from a team as a code owner November 18, 2024 09:11
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Nov 18, 2024
Copy link
Contributor

Compressed layer size comparison

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:latest to ghcr.io/philips-software/amp-devcontainer-cpp@sha256:45788c28ba8241e9df11f0ad4d9fc5f824e441700645d6b56830193fab023465

OS/Platform Previous Size Current Size Delta
linux/amd64 650.48M 651.16M 697.63K (+0.10%)
linux/arm64 643.16M 643.87M 723.98K (+0.11%)

Copy link
Contributor

Compressed layer size comparison

Comparing ghcr.io/philips-software/amp-devcontainer-rust:latest to ghcr.io/philips-software/amp-devcontainer-rust@sha256:45f5923567fe81e3ab86abeeec9a119202fef2c0d98ffb67beae341dab7541d0

OS/Platform Previous Size Current Size Delta
linux/amd64 459.82M 459.82M 0.00 (+0.00%)
linux/arm64 599.31M 599.31M 0.00 (+0.00%)

Copy link
Contributor

github-actions bot commented Nov 18, 2024

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 16 0 0.08s
✅ DOCKERFILE hadolint 2 0 0.57s
✅ GHERKIN gherkin-lint 2 0 0.76s
✅ JSON npm-package-json-lint yes no 0.37s
✅ JSON prettier 15 1 0 0.42s
✅ JSON v8r 14 0 13.33s
✅ MARKDOWN markdownlint 8 0 0 0.68s
✅ MARKDOWN markdown-table-formatter 8 0 0 0.22s
✅ REPOSITORY checkov yes no 16.83s
✅ REPOSITORY gitleaks yes no 0.24s
✅ REPOSITORY git_diff yes no 0.01s
✅ REPOSITORY grype yes no 9.38s
✅ REPOSITORY secretlint yes no 0.98s
✅ REPOSITORY syft yes no 1.19s
✅ REPOSITORY trivy yes no 4.02s
✅ REPOSITORY trivy-sbom yes no 0.1s
✅ REPOSITORY trufflehog yes no 4.43s
✅ SPELL lychee 57 0 1.27s
✅ YAML prettier 21 0 0 0.76s
✅ YAML v8r 21 0 12.76s
✅ YAML yamllint 21 0 0.41s

See detailed report in MegaLinter reports

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

MegaLinter is graciously provided by OX Security

Copy link
Contributor

Test Results

 2 files  ±0   2 suites  ±0   1m 21s ⏱️ -3s
29 tests ±0  29 ✅ ±0  0 💤 ±0  0 ❌ ±0 
31 runs  ±0  31 ✅ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit a30f262. ± Comparison against base commit 032db2a.

@rjaegers rjaegers enabled auto-merge November 18, 2024 11:44
@rjaegers rjaegers added this pull request to the merge queue Nov 18, 2024
Merged via the queue into main with commit 7b241e5 Nov 18, 2024
20 checks passed
@rjaegers rjaegers deleted the dependabot/npm_and_yarn/npm-a64af0e59c branch November 18, 2024 11:52
Copy link
Contributor

Pull Request Report (#646)

Static measures

Description Value
Number of added lines 5
Number of deleted lines 5
Number of changed files 2
Number of commits 1
Number of reviews 1
Number of comments (w/o review comments) 5
Number of reviews that contains a comment to resolve 0
Number of reviews that requested a change from the author 0
Number of reviews that approved the Pull Request 1
Get the total number of participants of a Pull Request 4

Time related measures

Description Value
PR lead time (from creation to close of PR) 2.7 Hours
Time that was spend on the branch before the PR was created 1 Sec
Time that was spend on the branch before the PR was merged 2.7 Hours
Time to merge after last review 8.3 Min

Status check related measures

Description Value
Total runtime for last status check run (Workflow for PR) 18.4 Min
Total time spend in last status check run on PR 2.6 Hours

Copy link
Contributor

🎉 Hooray! The changes in this pull request went live with the release of v5.5.1 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant