-
Notifications
You must be signed in to change notification settings - Fork 5
Commit 18e1384
authored
build(deps-dev): bump @vscode/vsce from 3.3.2 to 3.4.2 (#322)
Bumps [@vscode/vsce](https://github.com/Microsoft/vsce) from 3.3.2 to
3.4.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Microsoft/vsce/releases"><code>@vscode/vsce</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.4.2</h2>
<h2>Changes:</h2>
<ul>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1152">#1152</a>:
Only scan secrets when .env is ignored and vice versa</li>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1155">#1155</a>:
Fix npm token scanning false positives</li>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1151">#1151</a>:
Do not scan node modules and improve error messages for secret
scanning</li>
</ul>
<p>This list of changes was <a
href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339366&view=logs">auto
generated</a>.</p>
<h2>v3.4.2-2</h2>
<h2>Changes:</h2>
<ul>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1152">#1152</a>:
Only scan secrets when .env is ignored and vice versa</li>
</ul>
<p>This list of changes was <a
href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339335&view=logs">auto
generated</a>.</p>
<h2>v3.4.2-1</h2>
<h2>Changes:</h2>
<ul>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1155">#1155</a>:
Fix npm token scanning false positives</li>
</ul>
<p>This list of changes was <a
href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339327&view=logs">auto
generated</a>.</p>
<h2>v3.4.2-0</h2>
<h2>Changes:</h2>
<ul>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1151">#1151</a>:
Do not scan node modules and improve error messages for secret
scanning</li>
</ul>
<p>This list of changes was <a
href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=339154&view=logs">auto
generated</a>.</p>
<h2>v3.4.1</h2>
<h2>Changes:</h2>
<ul>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1149">#1149</a>:
Fix false positives in private key scanning</li>
<li><a
href="https://redirect.github.com/Microsoft/vsce/issues/1148">#1148</a>:
Clarify unpublish command description</li>
</ul>
<p>This list of changes was <a
href="https://dev.azure.com/monacotools/Monaco/_build/results?buildId=338557&view=logs">auto
generated</a>.</p>
<h2>v3.4.1-1</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/07897379337697cf531d570b77a0fc700397815e"><code>0789737</code></a>
Merge pull request <a
href="https://redirect.github.com/Microsoft/vsce/issues/1152">#1152</a>
from microsoft/benibenj/handsome-stoat</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/80fdafeca92ebc841c232ce8298aa30cfabd4b8b"><code>80fdafe</code></a>
Merge remote-tracking branch 'origin/main' into
benibenj/handsome-stoat</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/18221d1c63443fbdf386436b2dc2d138af89cbb8"><code>18221d1</code></a>
Merge pull request <a
href="https://redirect.github.com/Microsoft/vsce/issues/1155">#1155</a>
from microsoft/benibenj/visible-slug</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/2ec3bb2da1675378b9c7aaeb06dbedfb47c47625"><code>2ec3bb2</code></a>
fix npm token scanning false positives</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/2bc74a95e8b3b19d4d9ed4284d4141f6d333c452"><code>2bc74a9</code></a>
Merge pull request <a
href="https://redirect.github.com/Microsoft/vsce/issues/1151">#1151</a>
from microsoft/benibenj/aggressive-parrotfish</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/5f6ed8257772218ec6cd94b12d840c3d723fa578"><code>5f6ed82</code></a>
only scan secrets when dot env is ignored and vice versa</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/1e77be9684009231e81540fec4046c0b663e04ac"><code>1e77be9</code></a>
Do not scan node modules and better error message for secret
scanning</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/5e2323f040b02b99d08ee0087adcff8e58e92288"><code>5e2323f</code></a>
Merge pull request <a
href="https://redirect.github.com/Microsoft/vsce/issues/1149">#1149</a>
from microsoft/benibenj/latin-junglefowl</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/649ca03d4bd23c9e786c84d9d7c6a2eb13a655e9"><code>649ca03</code></a>
To many false positives for private key scanning</li>
<li><a
href="https://github.com/microsoft/vscode-vsce/commit/efd9d4ea822b76603d73138663818c3e06d3d343"><code>efd9d4e</code></a>
Merge pull request <a
href="https://redirect.github.com/Microsoft/vsce/issues/1148">#1148</a>
from microsoft/benibenj/fellow-xerinae</li>
<li>Additional commits viewable in <a
href="https://github.com/Microsoft/vsce/compare/v3.3.2...v3.4.2">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent 90b5784 commit 18e1384Copy full SHA for 18e1384
File tree
Expand file treeCollapse file tree
2 files changed
+1169
-20
lines changedOpen diff view settings
Filter options
Expand file treeCollapse file tree
2 files changed
+1169
-20
lines changedOpen diff view settings
0 commit comments