Skip to content

Bump datatables.net-colreorder from 1.6.2 to 2.0.3 in /components#10296

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/components/dev/datatables.net-colreorder-2.0.3
Closed

Bump datatables.net-colreorder from 1.6.2 to 2.0.3 in /components#10296
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/components/dev/datatables.net-colreorder-2.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 29, 2024

Copy link
Copy Markdown
Contributor

Bumps datatables.net-colreorder from 1.6.2 to 2.0.3.

Release notes

Sourced from datatables.net-colreorder's releases.

2.0.3

ColReorder 2.0.3

2.0.2

ColReorder 2.0.2

2.0.1

ColReorder 2.0.1

2.0.0

ColReorder 2.0.0

1.7.0

ColReorder 1.7.0

Commits
  • a147d31 Sync tag release - 2.0.3
  • 086e58c 79d1104abcb6cd4272ee0f0338119e4f61f2f93f Release 2.0.3
  • c2cfb51 01e4e45f60cdcbea93f8adddb080068d2dab3ef4 Fix: Stop JS error if the order pa...
  • eeaa7b0 9ed3906a51d9ea388bcae3b2a3fd8fa53e649c86 Fix: An error would be thrown if col...
  • df2b9b9 Sync tag release - 2.0.2
  • 4653ba6 bf132c0d79dba9ba6ccbaef700329b4593cc5ab7 Release 2.0.2
  • 24802d1 8452a1e1e7489a425dae7eddbd8a572071485808 Fix: Error when the first cell in a ...
  • 8488f06 23fb4c6564a77111d65125827a81806622fdcd36 Fix: ColReorder would throw an error...
  • d8cf138 Sync tag release - 2.0.1
  • 8ec6d12 13d70d5737091072327efc90f99fdb01cfc3a00b Dev: Attempt to optimise the width g...
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [datatables.net-colreorder](https://github.com/DataTables/Dist-DataTables-ColReorder) from 1.6.2 to 2.0.3.
- [Release notes](https://github.com/DataTables/Dist-DataTables-ColReorder/releases)
- [Commits](DataTables/Dist-DataTables-ColReorder@1.6.2...2.0.3)

---
updated-dependencies:
- dependency-name: datatables.net-colreorder
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 29, 2024
@dryrunsecurity

dryrunsecurity Bot commented May 29, 2024

Copy link
Copy Markdown

Hi there 👋, @DryRunSecurity here, below is a summary of our analysis and findings.

DryRun Security Status Findings
Configured Codepaths Analyzer 0 findings
Sensitive Files Analyzer 1 finding
AppSec Analyzer 0 findings
Authn/Authz Analyzer 0 findings
Secrets Analyzer 0 findings

Note

🟢 Risk threshold not exceeded.

Change Summary (click to expand)

The following is a summary of changes in this pull request made by me, your security buddy 🤖. Note that this summary is auto-generated and not meant to be a definitive list of security issues but rather a helpful summary from a security perspective.

Summary:

The code changes in this pull request involve updating the versions of the datatables.net-colreorder and datatables.net dependencies used in the application. From an application security perspective, these updates are generally positive as they allow the application to benefit from the latest security fixes and improvements made to these libraries.

Keeping dependencies up-to-date is an important security practice, as it helps mitigate the risk of known vulnerabilities in the libraries being exploited. However, it is crucial to thoroughly test the application after the dependency updates to ensure that the changes do not introduce any regressions or unintended behavior. Additionally, the application should be monitored for any security advisories or updates related to the new versions of the dependencies, and updates should be applied in a timely manner to maintain the application's security posture.

Files Changed:

  1. components/package.json: The datatables.net-colreorder dependency has been updated from version ^1.6.1 to ^2.0.3.
  2. components/yarn.lock: The datatables.net-colreorder dependency has been updated from version 1.6.2 to 2.0.3, and the datatables.net dependency has been updated from version 1.13.4 to 2.0.8.

Powered by DryRun Security

@mtesauro

Copy link
Copy Markdown
Contributor

Related to #10152

@dependabot @github

dependabot Bot commented on behalf of github Aug 15, 2024

Copy link
Copy Markdown
Contributor Author

Superseded by #10765.

@dependabot dependabot Bot closed this Aug 15, 2024
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/components/dev/datatables.net-colreorder-2.0.3 branch August 15, 2024 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant