Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump mocha package from ^10.2.0 to ^10.6.0 #1951

Merged
merged 2 commits into from
Mar 14, 2025
Merged

Conversation

Shinomix
Copy link
Contributor

What this PR does

In this PR we bump the mocha JS dependency from its current v10.2.0 to v10.6.0. This version bumps the sub-dependency serialize-javascript to v6.0.2 which solves a security issue blocking the deploy of new gem versions.

Reviewer's guide to testing

Mocha is a development dependency, if tests are successful we should be able to assume the bump is valid.

Checklist

Before submitting the PR, please consider if any of the following are needed:

  • Update CHANGELOG.md if the changes would impact users
  • Update README.md, if appropriate.
  • Update any relevant pages in /docs, if necessary
  • For security fixes, the Disclosure Policy must be followed.

@Shinomix Shinomix requested a review from a team as a code owner March 14, 2025 18:03
@Shinomix Shinomix requested a review from lizkenyon March 14, 2025 18:04
@Shinomix Shinomix force-pushed the bump-mocha-js-package branch from d3aee02 to d166c4d Compare March 14, 2025 18:22
@Shinomix Shinomix merged commit f3389a9 into main Mar 14, 2025
8 checks passed
@Shinomix Shinomix deleted the bump-mocha-js-package branch March 14, 2025 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants