Skip to content

Bump web-ext from 2.6.0 to 5.2.0#154

Closed
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/web-ext-5.2.0
Closed

Bump web-ext from 2.6.0 to 5.2.0#154
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/web-ext-5.2.0

Conversation

@dependabot-preview

Copy link
Copy Markdown

Bumps web-ext from 2.6.0 to 5.2.0.

Release notes

Sourced from web-ext's releases.

5.2.0

Feature

  • web-ext lint: updated to use addons-linter v2.7.0 (#2032):
    • Updated banned libraries and versions (DOMPurify <= v2.1.0)
    • Updated Firefox for Android WebExtensions API compat data
    • See all addons-linter changes: 2.5.0...2.7.0

Bug Fixes

Various dependencies updated to their last released versions:

  • Updated firefox-profile to v4 (#2030)
    • the new version does also include a fix for a security advisory related to one of the firefox-profile dependencies (#2026)
  • Updated open to v7.3.0 (#2004)
  • Updated update-notifier to v5 (#2036)
  • Switched from adbkit to @devicefarmer/adbkit (#2039)
    • the new package does also include a fix for a security advisory related to one of the adbkit dependencies (#2025)

See all changes: 5.1.0...5.2.0

5.1.0

Features

  • web-ext run: Android build variants do not require anymore a fully qualified apk component value in the --apk-component flag (#1935, #1941) (c083c07), as an example the following command can now be used to run an extension on the Fenix performancetest build variant: web-ext run -t firefox-android ... --firefox-apk=org.mozilla.fenix.performancetest --firefox-apk-component=HomeActivity (instead of ... --firefox-apk-component=org.mozilla.fenix.HomeActivity)

  • web-ext lint: updated to use addons-linter v2.5.0 (#2019 and #2028):

    • Imported Firefox 80 and Firefox 81 APIs Schema
    • Fixed optional_permissions validations to match the validation rules already applied to the manifest permissions (#3060)
    • Added new banned libraries and versions (e.g. DOMPurify <= 2.0.16) due to security vulnerabilities (#3336, #3347 and 5c7dc87)
    • See all addons-linter changes: 2.1.0...2.5.0

Bug Fixes

  • Various dependencies updated to their last released versions: @babel/runtime to v7.11.2 (#1989), node-notifier to v8 (#1997), sign-addon updated to v3.1.0 (5cf782b, 05dd260) update-notifier updated to v4.1.1 (#2001)

See all changes: 5.0.0...5.1.0

5.0.0

⚠ BREAKING CHANGES ⚠

In previous web-ext versions, the directory passed to --chromium-profile would be modified while using web-ext run. As of 5.0.0, a copy of the profile is used instead, unless --keep-profile-changes is passed.

Features

  • web-ext run:

    • Support keep profile changes while running Chrome on an existing profile-directory and fixed selection of non-Default chrome profiles (#1920), closes #1909
  • web-ext lint: updated to use addons-linter v2.1.0 (#1946, #1967):

    • Imported firefox 79 APIs Schema
Commits
  • 82c4250 chore: Bump package version for release 5.2.0
  • 411a366 fix(deps): Switch from adbkit to @devicefarmer/adbkit npm package (#2039)
  • 5492a0b fix(deps): update dependency update-notifier to v5 (#2036)
  • 7631e11 chore(deps): update dependency git-rev-sync to v3 (#2013)
  • 7372540 fix(deps): update dependency open to v7.3.0 (#2004)
  • 4b55ba7 fix(deps): update dependency addons-linter to v2.7.0 (#2032)
  • 35938e9 fix(deps): update dependency firefox-profile to v4 (#2030)
  • 0d9145b chore(deps): update dependency sinon to v9.1.0 (#2037)
  • 429fd91 chore(deps): update dependency eslint-plugin-import to v2.22.1 (#2034)
  • ec765c1 chore(deps): update dependency eslint to v7.10.0 (#2033)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [web-ext](https://github.com/mozilla/web-ext) from 2.6.0 to 5.2.0.
- [Release notes](https://github.com/mozilla/web-ext/releases)
- [Commits](mozilla/web-ext@2.6.0...5.2.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview Bot added the dependencies Pull requests that update a dependency file label Oct 6, 2020
@dependabot-preview

Copy link
Copy Markdown
Author

Superseded by #162.

@dependabot-preview dependabot-preview Bot deleted the dependabot/npm_and_yarn/web-ext-5.2.0 branch October 20, 2020 14:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants