Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump json from 2.2.0 to 2.3.1 #292

Closed
wants to merge 1 commit into from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 28, 2020

Bumps json from 2.2.0 to 2.3.1.

Changelog

Sourced from json's changelog.

2020-06-30 (2.3.1)

  • Spelling and grammar fixes for comments. Pull request #191 by Josh Kline.
  • Enhance generic JSON and #generate docs. Pull request #347 by Victor Shepelev.
  • Add :nodoc: for GeneratorMethods. Pull request #349 by Victor Shepelev.
  • Baseline changes to help (JRuby) development. Pull request #371 by Karol Bucek.
  • Add metadata for rubygems.org. Pull request #379 by Alexandre ZANNI.
  • Remove invalid JSON.generate description from JSON module rdoc. Pull request #384 by Jeremy Evans.
  • Test with TruffleRuby in CI. Pull request #402 by Benoit Daloze.
  • Rdoc enhancements. Pull request #413 by Burdette Lamar.
  • Fixtures/ are not being tested... Pull request #416 by Marc-André Lafortune.
  • Use frozen string for hash key. Pull request #420 by Marc-André Lafortune.
  • Added :call-seq: to RDoc for some methods. Pull request #422 by Burdette Lamar.
  • Small typo fix. Pull request #423 by Marc-André Lafortune.

2019-12-11 (2.3.0)

  • Fix default of create_additions to always be false for JSON(user_input) and JSON.parse(user_input, nil). Note that JSON.load remains with default true and is meant for internal serialization of trusted data. [CVE-2020-10663]
  • Fix passing args all #to_json in json/add/*.
  • Fix encoding issues
  • Fix issues of keyword vs positional parameter
  • Fix JSON::Parser against bigdecimal updates
  • Bug fixes to JRuby port
Commits
  • 0951d77 Bump version to 2.3.1
  • ddc29e2 Merge pull request #429 from flori/remove-generate-task-for-gemspec
  • cee8020 Removed gemspec task from default task on Rakefile
  • 9fd6371 Use VERSION file instead of hard-coded value
  • dc90bcf Removed explicitly date field in gemspec, it will assign by rubygems.org
  • 4c11a40 Removed task for json_pure.gemspec
  • e794ec9 Merge pull request #426 from marcandre/indent
  • 7cc9301 Merge pull request #428 from marcandre/change_fix
  • 9e2a1fb Make changes more precise #424
  • f8fa987 Merge pull request #424 from marcandre/update_changes
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jul 28, 2020
@0crat
Copy link
Collaborator

0crat commented Jul 28, 2020

@dependabot/z[bot] this pull request is too small, just 2 lines changed (less than 10), there will be no formal code review, see §53 and §28; in the future, try to make sure your pull requests are not too small; @yegor256/z please review this and merge or reject

@codecov-commenter
Copy link

codecov-commenter commented Jul 28, 2020

Codecov Report

Merging #292 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #292   +/-   ##
=======================================
  Coverage   36.04%   36.04%           
=======================================
  Files          34       34           
  Lines         860      860           
=======================================
  Hits          310      310           
  Misses        550      550           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update aed2ebd...d9d475e. Read the comment docs.

@dependabot dependabot bot force-pushed the dependabot/bundler/json-2.3.1 branch from c125dc8 to d9d475e Compare August 5, 2020 07:18
@yegor256
Copy link
Owner

yegor256 commented Dec 1, 2020

@rultor merge

@rultor
Copy link
Collaborator

rultor commented Dec 1, 2020

@rultor merge

@yegor256 OK, I'll try to merge now. You can check the progress of the merge here

@rultor
Copy link
Collaborator

rultor commented Dec 1, 2020

@rultor merge

@dependabot[bot] @yegor256 Oops, I failed. You can see the full log here (spent 2min)

-rw-rw-r--  1 rultor rultor   6292 Dec  1 18:56 stdout
++ pwd
++ pwd
+ docker run -t --rm -v /tmp/rultor-d2TW:/main [email protected]:yegor256/0pdd.git --env=pull_id=292 [email protected]:yegor256/0pdd.git --env=fork_branch=dependabot/bundler/json-2.3.1 --env=head_branch=master '--env=pull_title=Bump json from 2.2.0 to 2.3.1' --env=author=yegor256 '--env=scripts=( '\''export '\''\'\'''\''[email protected]:yegor256/0pdd.git'\''\'\'''\'''\'' '\'';'\'' '\''export '\''\'\'''\''pull_id=292'\''\'\'''\'''\'' '\'';'\'' '\''export '\''\'\'''\''[email protected]:yegor256/0pdd.git'\''\'\'''\'''\'' '\'';'\'' '\''export '\''\'\'''\''fork_branch=dependabot/bundler/json-2.3.1'\''\'\'''\'''\'' '\'';'\'' '\''export '\''\'\'''\''head_branch=master'\''\'\'''\'''\'' '\'';'\'' '\''export '\''\'\'''\''pull_title=Bump json from 2.2.0 to 2.3.1'\''\'\'''\'''\'' '\'';'\'' '\''export '\''\'\'''\''author=yegor256'\''\'\'''\'''\'' '\'';'\'' '\''sudo gem install pdd -v 0.20.5'\'' '\'';'\'' '\''git config --global user.email "[email protected]"'\'' '\'';'\'' '\''git config --global user.name "0pdd.com"'\'' '\'';'\'' '\''export GEM_HOME=~/.ruby'\'' '\'';'\'' '\''export GEM_PATH=$GEM_HOME:$GEM_PATH'\'' '\'';'\'' '\''ruby -v'\'' '\'';'\'' '\''bundle install --no-color'\'' '\'';'\'' '\''pdd -f /dev/null'\'' '\'';'\'' '\''bundle exec rake'\'' '\'';'\'' )' --hostname=docker --privileged --memory=6g --memory-swap=16g --oom-kill-disable --cidfile=/tmp/rultor-d2TW/cid -w=/main -v /var/run/docker.sock:/var/run/docker.sock --name=yegor256_0pdd_292 yegor256/rultor-image /main/entry.sh
+ set -e
+ set -o pipefail
+ shopt -s dotglob
+ useradd -m -G sudo r
+ usermod -s /bin/bash r
+ echo '%sudo ALL=(ALL) NOPASSWD:ALL'
+ cp -R /root/.bashrc /root/.cache /root/.composer /root/.gem /root/.gnupg /root/.m2 /root/.profile /root/texmf /home/r
+ cp -R ./cid ./config.yml ./end.sh ./entry.sh ./id_rsa ./id_rsa.pub ./pid ./repo ./run.sh ./script.sh ./stdout /home/r
+ rm -rf repo
+ chown -R r:r /home/r
+ chmod a+x /home/r/script.sh
+ su --login r --command /home/r/script.sh
mesg: cannot open /dev/pts/0: Permission denied
+ set -e
+ set -o pipefail
+ shopt -s expand_aliases
+ alias 'sudo=sudo -i'
+ export HOME=/home/r
+ HOME=/home/r
+ cd /home/r/repo
+ export [email protected]:yegor256/0pdd.git
+ [email protected]:yegor256/0pdd.git
+ export pull_id=292
+ pull_id=292
+ export [email protected]:yegor256/0pdd.git
+ [email protected]:yegor256/0pdd.git
+ export fork_branch=dependabot/bundler/json-2.3.1
+ fork_branch=dependabot/bundler/json-2.3.1
+ export head_branch=master
+ head_branch=master
+ export 'pull_title=Bump json from 2.2.0 to 2.3.1'
+ pull_title='Bump json from 2.2.0 to 2.3.1'
+ export author=yegor256
+ author=yegor256
+ sudo -i gem install pdd -v 0.20.5
Successfully installed pdd-0.20.5
Parsing documentation for pdd-0.20.5
Done installing documentation for pdd after 0 seconds
1 gem installed
+ git config --global user.email [email protected]
+ git config --global user.name 0pdd.com
+ export GEM_HOME=/home/r/.ruby
+ GEM_HOME=/home/r/.ruby
+ export GEM_PATH=/home/r/.ruby:/usr/local/rvm/gems/ruby-2.6.0:/usr/local/rvm/gems/ruby-2.6.0@global
+ GEM_PATH=/home/r/.ruby:/usr/local/rvm/gems/ruby-2.6.0:/usr/local/rvm/gems/ruby-2.6.0@global
+ ruby -v
ruby 2.6.0p0 (2018-12-25 revision 66547) [x86_64-linux]
+ bundle install --no-color
Fetching gem metadata from https://rubygems.org/..........
Your bundle is locked to codecov (0.1.14), but that version could not be found
in any of the sources listed in your Gemfile. If you haven't changed sources,
that means the author of codecov (0.1.14) has removed it. You'll need to update
your bundle to a version other than codecov (0.1.14) that hasn't been removed in
order to install.
container 3ab100a5f726eae5ffc309c1478986b39c10837116dc126fb062ab9c84ba6271 is dead
Tue Dec  1 18:58:05 CET 2020

@yegor256
Copy link
Owner

yegor256 commented Dec 1, 2020

@rultor merge

yegor256 added a commit that referenced this pull request Dec 1, 2020
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 1, 2020

Looks like json is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Dec 1, 2020
@dependabot dependabot bot deleted the dependabot/bundler/json-2.3.1 branch December 1, 2020 19:29
@rultor
Copy link
Collaborator

rultor commented Dec 1, 2020

@rultor merge

@dependabot[bot] @yegor256 The pull request is closed already, so I can't merge it

@rultor
Copy link
Collaborator

rultor commented Dec 1, 2020

@rultor merge

@yegor256 I'm sorry, I don't understand you :( Check this page and try again please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0crat/new dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants