Skip to content
This repository has been archived by the owner on May 4, 2024. It is now read-only.

deps: bump glob from 8.1.0 to 9.3.0 #162

Merged
merged 2 commits into from Mar 21, 2023

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 14, 2023

Bumps glob from 8.1.0 to 9.3.0.

Changelog

Sourced from glob's changelog.

changeglob

9.3

  • Add aliases for methods. glob.sync, glob.stream, glob.stream.sync, etc.

9.2

  • Support using a custom fs object, which is passed to PathScurry
  • add maxDepth option
  • add stat option
  • add custom Ignore support

9.1

  • Bring back the root option, albeit with slightly different semantics than in v8 and before.
  • Support { absolute:false } option to explicitly always return relative paths. An unset absolute setting will still return absolute or relative paths based on whether the pattern is absolute.
  • Add magicalBraces option to treat brace expansion as "magic" in the hasMagic function.
  • Add dotRelative option
  • Add escape() and unescape() methods

9.0

This is a full rewrite, with significant API and algorithm changes.

High-Level Feature and API Surface Changes

  • Only support node 16 and higher.
  • Promise API instead of callbacks.
  • Exported function names have changed, as have the methods on the Glob class. See API documentation for details.
  • Accept pattern as string or array of strings.
  • Hybrid module distribution.
  • Full TypeScript support.
  • Exported Glob class is no longer an event emitter.
  • Exported Glob class has walk(), walkSync(), stream(), streamSync(), iterate(), iterateSync() methods, and is both an async and sync Generator.
  • First class support for UNC paths and drive letters on Windows. Note that glob patterns must still use / as a path separator, unless the windowsPathsNoEscape option is set, in which case glob patterns cannot be escaped with \.
  • Paths are returned in the canonical formatting for the platform

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [glob](https://github.com/isaacs/node-glob) from 8.1.0 to 9.3.0.
- [Release notes](https://github.com/isaacs/node-glob/releases)
- [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md)
- [Commits](isaacs/node-glob@v8.1.0...v9.3.0)

---
updated-dependencies:
- dependency-name: glob
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner March 14, 2023 16:09
@dependabot dependabot bot requested review from wraithgar and removed request for a team March 14, 2023 16:09
@dependabot dependabot bot added the Dependencies Pull requests that update a dependency file label Mar 14, 2023
@dependabot dependabot bot requested review from fritzy and lukekarrys March 14, 2023 16:09
@wraithgar
Copy link
Member

@dependabot ignore this major version

@dependabot dependabot bot closed this Mar 21, 2023
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 21, 2023

OK, I won't notify you about version 9.x.x again, unless you re-open this PR. 😢

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/glob-9.3.0 branch March 21, 2023 16:27
@wraithgar wraithgar restored the dependabot/npm_and_yarn/glob-9.3.0 branch March 21, 2023 16:31
@wraithgar wraithgar reopened this Mar 21, 2023
lib/read-json.js Outdated Show resolved Hide resolved
Copy link
Contributor

@nlf nlf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

given that we can't get rid of the glob dep i'm approving this as-is

we should, at some point, make the checks that can be simpler be simpler but that is absolutely not within the scope of this pull request

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 21, 2023

A newer version of glob exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@wraithgar wraithgar force-pushed the dependabot/npm_and_yarn/glob-9.3.0 branch from 10b6b81 to 77e000e Compare March 21, 2023 17:18
@wraithgar wraithgar merged commit bd925f0 into main Mar 21, 2023
23 checks passed
@wraithgar wraithgar deleted the dependabot/npm_and_yarn/glob-9.3.0 branch March 21, 2023 17:26
@github-actions github-actions bot mentioned this pull request Mar 21, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants