Skip to content

Bump cspell from 5.12.6 to 5.19.7#66

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/cspell-5.19.7
Closed

Bump cspell from 5.12.6 to 5.19.7#66
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/cspell-5.19.7

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Apr 12, 2022

Bumps cspell from 5.12.6 to 5.19.7.

Release notes

Sourced from cspell's releases.

v5.19.7

Changes

Fixes

fix: Ignore directories when checking files (#2680)

The following would cause an error when there was a subdirectory.

ls -1 | cspell "**" --cache --file-list=stdin

v5.19.6

Changes

  • Improved caching
    • Improved detection of stale dependencies (ensures that a file is checked if a related dictionary is changed).
    • Reduce the size of the cache file by consolidating results.
  • Added --cache-reset option to the cli

Fixes

Pin actions to a full length commit SHA (#2670)

Pin actions to a full length commit SHA

Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps mitigate the risk of a bad actor adding a backdoor to the action's repository, as they would need to generate a SHA-1 collision for a valid Git object payload.

https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions

How do I validate these pinned actions?

Also, dependabot supports upgrading based on SHA. ossf/scorecard#1700

GitHub's own repository pin's their checkout actions by SHA and doesn't use the version tag https://github.com/github/docs/blob/ea7f218c91ecbae9a700a8702b51a7d2736e0d2c/.github/workflows/docs-review-collect.yml#L23

Signed-off-by: naveensrinivasan 172697+naveensrinivasan@users.noreply.github.com

... (truncated)

Changelog

Sourced from cspell's changelog.

5.19.7 (2022-04-09)

Bug Fixes

5.19.6 (2022-04-08)

Bug Fixes

5.19.5 (2022-04-01)

Bug Fixes

  • Be able to disable the default configuration (#2643) (46c1e4f)

5.19.4 (2022-04-01)

Bug Fixes

  • Performance - only serialize config if in debug mode (#2640) (d16c4f9)

5.19.3 (2022-03-24)

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cspell](https://github.com/streetsidesoftware/cspell) from 5.12.6 to 5.19.7.
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/CHANGELOG.md)
- [Commits](streetsidesoftware/cspell@v5.12.6...v5.19.7)

---
updated-dependencies:
- dependency-name: cspell
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Apr 12, 2022
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Apr 12, 2022

Dependabot tried to add @XhmikosR as a reviewer to this PR, but received the following error from GitHub:

POST https://api.github.com/repos/Schweitzer-Engineering-Laboratories/bootstrap/pulls/66/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the Schweitzer-Engineering-Laboratories/bootstrap repository. // See: https://docs.github.com/rest/reference/pulls#request-reviewers-for-a-pull-request

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Apr 12, 2022

The following labels could not be found: v5.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github May 3, 2022

Superseded by #75.

@dependabot dependabot bot closed this May 3, 2022
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/cspell-5.19.7 branch May 3, 2022 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants