Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

An in-range update of bower is breaking the build 🚨 #208

Open
greenkeeper bot opened this issue Jan 17, 2019 · 2 comments
Open

An in-range update of bower is breaking the build 🚨 #208

greenkeeper bot opened this issue Jan 17, 2019 · 2 comments

Comments

@greenkeeper
Copy link
Contributor

greenkeeper bot commented Jan 17, 2019

The devDependency bower was updated from 1.8.4 to 1.8.6.

🚨 View failing branch.

This version is covered by your current version range and after updating it in your project the build failed.

bower is a devDependency of this project. It might not break your production code or affect downstream projects, but probably breaks your build or test tools, which may prevent deploying or publishing.

Status Details
  • ci/circleci: checkout_code: Your tests passed on CircleCI! (Details).
  • ci/circleci: install_dependencies: Your tests passed on CircleCI! (Details).
  • ci/circleci: test-beta: Your tests passed on CircleCI! (Details).
  • ci/circleci: test-default: Your tests passed on CircleCI! (Details).
  • ci/circleci: test-lts-2.16: Your tests passed on CircleCI! (Details).
  • ci/circleci: test-lts-2.12: CircleCI is running your tests (Details).
  • ci/circleci: test-lts-2.18: CircleCI is running your tests (Details).
  • ci/circleci: test-canary: Your tests passed on CircleCI! (Details).
  • ci/circleci: test-1-13: Your tests passed on CircleCI! (Details).
  • ci/circleci: test-release: Your tests failed on CircleCI (Details).

Release Notes for v1.8.6

Fix Zip Slip Vulnerability of decompress-zip package: https://snyk.io/research/zip-slip-vulnerability

Note: v1.8.5 has been unpublished because of missing files

FAQ and help

There is a collection of frequently asked questions. If those don’t help, you can always ask the humans behind Greenkeeper.


Your Greenkeeper Bot 🌴

@greenkeeper
Copy link
Contributor Author

greenkeeper bot commented Jan 17, 2019

After pinning to 1.8.4 your tests are passing again. Downgrade this dependency 📌.

@greenkeeper
Copy link
Contributor Author

greenkeeper bot commented Jan 18, 2019

  • The devDependency bower was updated from 1.8.6 to 1.8.7.

Your tests are passing again with this update. Explicitly upgrade to this version 🚀

Release Notes for v1.8.7

Fixes side effect of fix from v1.8.6 that caused improper permissions for extracted folders

#2532

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

0 participants