gmailui icon indicating copy to clipboard operation
gmailui copied to clipboard

An in-range update of bower is breaking the build 🚨

Open greenkeeper[bot] opened this issue 8 years ago β€’ 7 comments

Version 1.8.1 of bower just got published.

Branch Build failing 🚨
Dependency bower
Current Version 1.8.0
Type devDependency

This version is covered by your current version range and after updating it in your project the build failed.

As bower is β€œonly” a devDependency of this project it might not break production or downstream projects, but β€œonly” your build or test tools – preventing new deploys or publishes.

I recommend you give this issue a high priority. I’m sure you can resolve this :muscle:

Status Details
  • ❌ continuous-integration/travis-ci/push The Travis CI build could not complete due to an error Details

Not sure how things should work exactly?

There is a collection of frequently asked questions and of course you may always ask my humans.


Your Greenkeeper Bot :palm_tree:

greenkeeper[bot] avatar Sep 13 '17 16:09 greenkeeper[bot]

After pinning to 1.8.0 your tests are passing again. Downgrade this dependency πŸ“Œ.

greenkeeper[bot] avatar Sep 13 '17 16:09 greenkeeper[bot]

Version 1.8.2 just got published.

Your tests are passing again with this version. Explicitly upgrade to this version πŸš€

greenkeeper[bot] avatar Sep 13 '17 16:09 greenkeeper[bot]

Version 1.8.3 just got published.

Your tests are passing again with this version. Explicitly upgrade to this version πŸš€

greenkeeper[bot] avatar Mar 28 '18 18:03 greenkeeper[bot]

Version 1.8.4 just got published.

Your tests are passing again with this version. Explicitly upgrade to this version πŸš€

greenkeeper[bot] avatar Mar 28 '18 19:03 greenkeeper[bot]

  • The devDependency bower was updated from 1.8.4 to 1.8.6.

Your tests are still failing with this version. Compare changes

greenkeeper[bot] avatar Jan 17 '19 13:01 greenkeeper[bot]

  • The devDependency bower was updated from 1.8.6 to 1.8.7.

Your tests are still failing with this version. Compare changes

Release Notes for v1.8.7

Fixes side effect of fix from v1.8.6 that caused improper permissions for extracted folders

#2532

greenkeeper[bot] avatar Jan 18 '19 09:01 greenkeeper[bot]

  • The devDependency bower was updated from 1.8.7 to 1.8.8.

Your tests are still failing with this version. Compare changes

Release Notes for v1.8.8

Fix vulnerability related to extracting .tar.gz files that has similar effect to Zip Slip

Vulnerability is similar to Zip Slip allows for overriding and creating arbitrary files on filesystem

Needlessly to say, please upgrade this this version of Bower

greenkeeper[bot] avatar Jan 23 '19 21:01 greenkeeper[bot]