Skip to content

Commit 18e1384

Browse files
build(deps-dev): bump @vscode/vsce from 3.3.2 to 3.4.2 (#322)
Bumps [@vscode/vsce](https://github.com/Microsoft/vsce) from 3.3.2 to 3.4.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Microsoft/vsce/releases"><code>@​vscode/vsce</code>'s releases</a>.</em></p> <blockquote> <h2>v3.4.2</h2> <h2>Changes:</h2> <ul> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1152">#1152</a>: Only scan secrets when .env is ignored and vice versa</li> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1155">#1155</a>: Fix npm token scanning false positives</li> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1151">#1151</a>: Do not scan node modules and improve error messages for secret scanning</li> </ul> <p>This list of changes was <a href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339366&amp;view=logs">auto generated</a>.</p> <h2>v3.4.2-2</h2> <h2>Changes:</h2> <ul> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1152">#1152</a>: Only scan secrets when .env is ignored and vice versa</li> </ul> <p>This list of changes was <a href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339335&amp;view=logs">auto generated</a>.</p> <h2>v3.4.2-1</h2> <h2>Changes:</h2> <ul> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1155">#1155</a>: Fix npm token scanning false positives</li> </ul> <p>This list of changes was <a href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339327&amp;view=logs">auto generated</a>.</p> <h2>v3.4.2-0</h2> <h2>Changes:</h2> <ul> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1151">#1151</a>: Do not scan node modules and improve error messages for secret scanning</li> </ul> <p>This list of changes was <a href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339154&amp;view=logs">auto generated</a>.</p> <h2>v3.4.1</h2> <h2>Changes:</h2> <ul> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1149">#1149</a>: Fix false positives in private key scanning</li> <li><a href="https://redirect.github.com/Microsoft/vsce/issues/1148">#1148</a>: Clarify unpublish command description</li> </ul> <p>This list of changes was <a href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=338557&amp;view=logs">auto generated</a>.</p> <h2>v3.4.1-1</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/vscode-vsce/commit/07897379337697cf531d570b77a0fc700397815e"><code>0789737</code></a> Merge pull request <a href="https://redirect.github.com/Microsoft/vsce/issues/1152">#1152</a> from microsoft/benibenj/handsome-stoat</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/80fdafeca92ebc841c232ce8298aa30cfabd4b8b"><code>80fdafe</code></a> Merge remote-tracking branch 'origin/main' into benibenj/handsome-stoat</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/18221d1c63443fbdf386436b2dc2d138af89cbb8"><code>18221d1</code></a> Merge pull request <a href="https://redirect.github.com/Microsoft/vsce/issues/1155">#1155</a> from microsoft/benibenj/visible-slug</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/2ec3bb2da1675378b9c7aaeb06dbedfb47c47625"><code>2ec3bb2</code></a> fix npm token scanning false positives</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/2bc74a95e8b3b19d4d9ed4284d4141f6d333c452"><code>2bc74a9</code></a> Merge pull request <a href="https://redirect.github.com/Microsoft/vsce/issues/1151">#1151</a> from microsoft/benibenj/aggressive-parrotfish</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/5f6ed8257772218ec6cd94b12d840c3d723fa578"><code>5f6ed82</code></a> only scan secrets when dot env is ignored and vice versa</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/1e77be9684009231e81540fec4046c0b663e04ac"><code>1e77be9</code></a> Do not scan node modules and better error message for secret scanning</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/5e2323f040b02b99d08ee0087adcff8e58e92288"><code>5e2323f</code></a> Merge pull request <a href="https://redirect.github.com/Microsoft/vsce/issues/1149">#1149</a> from microsoft/benibenj/latin-junglefowl</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/649ca03d4bd23c9e786c84d9d7c6a2eb13a655e9"><code>649ca03</code></a> To many false positives for private key scanning</li> <li><a href="https://github.com/microsoft/vscode-vsce/commit/efd9d4ea822b76603d73138663818c3e06d3d343"><code>efd9d4e</code></a> Merge pull request <a href="https://redirect.github.com/Microsoft/vsce/issues/1148">#1148</a> from microsoft/benibenj/fellow-xerinae</li> <li>Additional commits viewable in <a href="https://github.com/Microsoft/vsce/compare/v3.3.2...v3.4.2">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@vscode/vsce&package-manager=npm_and_yarn&previous-version=3.3.2&new-version=3.4.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 90b5784 commit 18e1384

File tree

2 files changed

+1169
-20
lines changed

2 files changed

+1169
-20
lines changed

0 commit comments

Comments
 (0)