1271 Commits

Author SHA1 Message Date
dependabot[bot]
2a9cfbbe25 Bump follow-redirects from 1.13.0 to 1.14.7 in /client
Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects) from 1.13.0 to 1.14.7.
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)
- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.13.0...v1.14.7)

---
updated-dependencies:
- dependency-name: follow-redirects
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-01-25 10:17:21 +00:00
dependabot[bot]
d187d2aaa2 Bump tmpl from 1.0.4 to 1.0.5 in /client
Bumps [tmpl](https://github.com/daaku/nodejs-tmpl) from 1.0.4 to 1.0.5.
- [Release notes](https://github.com/daaku/nodejs-tmpl/releases)
- [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5)

---
updated-dependencies:
- dependency-name: tmpl
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-10-08 09:53:33 +00:00
dependabot[bot]
92b91f7a2c Bump tar from 4.4.15 to 4.4.19 in /client
Bumps [tar](https://github.com/npm/node-tar) from 4.4.15 to 4.4.19.
- [Release notes](https://github.com/npm/node-tar/releases)
- [Changelog](https://github.com/npm/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/npm/node-tar/compare/v4.4.15...v4.4.19)

---
updated-dependencies:
- dependency-name: tar
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-09-03 07:57:19 +00:00
dependabot[bot]
16bc95bb50 Bump path-parse from 1.0.6 to 1.0.7 in /client
Bumps [path-parse](https://github.com/jbgutierrez/path-parse) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/jbgutierrez/path-parse/releases)
- [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7)

---
updated-dependencies:
- dependency-name: path-parse
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-08-11 14:45:56 +00:00
dependabot[bot]
b5d08d597e Bump tar from 4.4.8 to 4.4.15 in /client
Bumps [tar](https://github.com/npm/node-tar) from 4.4.8 to 4.4.15.
- [Release notes](https://github.com/npm/node-tar/releases)
- [Changelog](https://github.com/npm/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/npm/node-tar/compare/v4.4.8...v4.4.15)

---
updated-dependencies:
- dependency-name: tar
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-08-09 12:53:32 +00:00
Daniel Holbach
3da265e402 update jest and babel-jest
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-09 09:36:33 +02:00
Daniel Holbach
2aac2395e1 update webpack-cli
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-09 09:34:23 +02:00
Daniel Holbach
70485ee871 update eslint-loader
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-09 09:32:25 +02:00
Daniel Holbach
13dec00efc update ui-components
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-09 09:06:43 +02:00
Daniel Holbach
0ff2a8a514 update rc-slider and react-router
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-07 12:46:22 +02:00
Daniel Holbach
b75106d734 update jest and jest-cli
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-07 12:36:26 +02:00
Daniel Holbach
e2aa0d4b96 update babel/cli, eslint, watchpack, webpack to get rid of old glob-parent
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-07 12:26:32 +02:00
Daniel Holbach
44c745e49d update stylelint and stylelint-declaration-use-variable
Signed-off-by: Daniel Holbach <daniel@weave.works>
2021-07-07 12:16:26 +02:00
Daniel Holbach
a065b5d65a Merge pull request #3869 from weaveworks/dependabot/npm_and_yarn/client/browserslist-4.16.6
Bump browserslist from 4.9.1 to 4.16.6 in /client
2021-07-07 10:42:14 +02:00
dependabot[bot]
86ae351151 Bump ws from 7.1.2 to 7.5.2 in /client
Bumps [ws](https://github.com/websockets/ws) from 7.1.2 to 7.5.2.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/7.1.2...7.5.2)

---
updated-dependencies:
- dependency-name: ws
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 08:26:19 +00:00
Daniel Holbach
8503c5b6a4 Merge pull request #3871 from weaveworks/dependabot/npm_and_yarn/client/postcss-7.0.36
Bump postcss from 7.0.17 to 7.0.36 in /client
2021-07-07 10:25:37 +02:00
Daniel Holbach
4e2ac89ab6 Merge pull request #3870 from weaveworks/dependabot/npm_and_yarn/client/hosted-git-info-2.8.9
Bump hosted-git-info from 2.5.0 to 2.8.9 in /client
2021-07-07 10:23:42 +02:00
Daniel Holbach
4ddd898829 Merge pull request #3866 from weaveworks/dependabot/npm_and_yarn/client/lodash-4.17.21
Bump lodash from 4.17.20 to 4.17.21 in /client
2021-07-07 10:11:27 +02:00
Daniel Holbach
e81a3c71f0 Merge pull request #3867 from weaveworks/dependabot/npm_and_yarn/client/ua-parser-js-0.7.28
Bump ua-parser-js from 0.7.17 to 0.7.28 in /client
2021-07-07 10:08:19 +02:00
dependabot[bot]
d285a6c3a0 Bump postcss from 7.0.17 to 7.0.36 in /client
Bumps [postcss](https://github.com/postcss/postcss) from 7.0.17 to 7.0.36.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/7.0.17...7.0.36)

---
updated-dependencies:
- dependency-name: postcss
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 08:07:43 +00:00
dependabot[bot]
f488dc6b61 Bump hosted-git-info from 2.5.0 to 2.8.9 in /client
Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.5.0 to 2.8.9.
- [Release notes](https://github.com/npm/hosted-git-info/releases)
- [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md)
- [Commits](https://github.com/npm/hosted-git-info/compare/v2.5.0...v2.8.9)

---
updated-dependencies:
- dependency-name: hosted-git-info
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 08:07:42 +00:00
dependabot[bot]
aad36e0f5b Bump browserslist from 4.9.1 to 4.16.6 in /client
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.9.1 to 4.16.6.
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](https://github.com/browserslist/browserslist/compare/4.9.1...4.16.6)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 08:07:37 +00:00
dependabot[bot]
d956fd6cbf Bump ssri from 6.0.1 to 6.0.2 in /client
Bumps [ssri](https://github.com/npm/ssri) from 6.0.1 to 6.0.2.
- [Release notes](https://github.com/npm/ssri/releases)
- [Changelog](https://github.com/npm/ssri/blob/v6.0.2/CHANGELOG.md)
- [Commits](https://github.com/npm/ssri/compare/v6.0.1...v6.0.2)

---
updated-dependencies:
- dependency-name: ssri
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 07:55:27 +00:00
dependabot[bot]
1e3d59c2a0 Bump ua-parser-js from 0.7.17 to 0.7.28 in /client
Bumps [ua-parser-js](https://github.com/faisalman/ua-parser-js) from 0.7.17 to 0.7.28.
- [Release notes](https://github.com/faisalman/ua-parser-js/releases)
- [Commits](https://github.com/faisalman/ua-parser-js/compare/0.7.17...0.7.28)

---
updated-dependencies:
- dependency-name: ua-parser-js
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 07:55:25 +00:00
dependabot[bot]
fefe5caa62 Bump lodash from 4.17.20 to 4.17.21 in /client
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.20 to 4.17.21.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.20...4.17.21)

---
updated-dependencies:
- dependency-name: lodash
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-07-07 07:55:22 +00:00
Daniel Holbach
e4c4b2b52f update dependencies
update y18n, elliptic, ini, args-parser
	run "yarn-deduplicate"
2021-04-12 10:40:38 +02:00
Bryan Boreham
29b954d0cb Stop creating a NodeJS build image
All it does is set some environment variables so just set those on the command-line
2021-04-04 11:16:13 +01:00
Piotr Kiełkowicz
4628ff8d54 fix CVE-2020-8203 (lodash vulnerability) 2021-02-10 09:15:20 +01:00
dependabot[bot]
a32ce1a019 build(deps-dev): bump http-proxy from 1.16.2 to 1.18.1 in /client
Bumps [http-proxy](https://github.com/http-party/node-http-proxy) from 1.16.2 to 1.18.1.
- [Release notes](https://github.com/http-party/node-http-proxy/releases)
- [Changelog](https://github.com/http-party/node-http-proxy/blob/master/CHANGELOG.md)
- [Commits](https://github.com/http-party/node-http-proxy/compare/1.16.2...1.18.1)

Signed-off-by: dependabot[bot] <support@github.com>
2020-09-07 13:15:46 +00:00
Daniel Holbach
2b71e780ae update webpack and terser-webpack-plugin 2020-08-19 11:05:36 +02:00
Daniel Holbach
eab0b149e3 update dot-prop 2020-08-19 10:58:50 +02:00
dependabot[bot]
8de130a436 build(deps): bump elliptic from 6.4.0 to 6.5.3 in /client
Bumps [elliptic](https://github.com/indutny/elliptic) from 6.4.0 to 6.5.3.
- [Release notes](https://github.com/indutny/elliptic/releases)
- [Commits](https://github.com/indutny/elliptic/compare/v6.4.0...v6.5.3)

Signed-off-by: dependabot[bot] <support@github.com>
2020-07-31 11:00:53 +00:00
dependabot[bot]
470f3d62f5 build(deps): bump lodash from 4.17.15 to 4.17.19 in /client
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.15 to 4.17.19.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.15...4.17.19)

Signed-off-by: dependabot[bot] <support@github.com>
2020-07-20 09:19:32 +00:00
Daniel Holbach
df07c894a7 update to most recent weaveworks-ui-components 2020-06-08 11:17:17 +02:00
Bryan Boreham
1a8dc90633 ui: update kind-of module to 6.0.3
We got a warning about a vulnerability in 6.0.2
2020-05-07 15:14:08 +00:00
Daniel Holbach
8e51bbaba7 security(js-dependency) update html-webpack-plugin to most recent stable 2020-03-30 12:32:09 +02:00
Filip Barl
3fbc1a9ec5 Remove unused JS deps from package.json 2020-03-20 14:53:13 +01:00
Bryan Boreham
c37e21ed14 security(js-dependency): update minimist to 1.2.2 2020-03-19 12:25:39 +00:00
Bryan Boreham
20227f2cd0 security(js-dependency): update acorn to 7.1.1 2020-03-19 12:25:39 +00:00
Bryan Boreham
c6ec844711 security(js-dependency): update set-value to 2.0.1 2020-03-19 12:25:16 +00:00
Bryan Boreham
ef165af823 security(js-dependency): update mixin-deep to 1.3.2 2020-03-19 12:20:06 +00:00
Bryan Boreham
487769fd11 security(js-dependency): update sshpk to 1.13.2 2020-03-19 12:19:27 +00:00
Bryan Boreham
9d5b395bf4 UI build: removed unused older versions from yarn.lock 2020-03-19 12:05:29 +00:00
Bryan Boreham
6c9c8c88e3 UI-build: deduplicate yarn.lock 2020-03-19 11:54:53 +00:00
Sara Taha
7ef0008b4f fix linting issue for trailing spaces 2020-03-13 05:19:20 +02:00
Sara Taha
70a818bff8 remove trailing space 2020-03-13 05:15:08 +02:00
Sara Taha
112fd5616b remove trailing zeros in large numbers in UI
Added ~ option to d3Format which trims trailing zeros across format types.

Fixes #3741
2020-03-13 04:51:44 +02:00
Daniel Holbach
d224674b89 sync deps between ui-components, service-ui and scope 2020-03-11 14:17:06 +01:00
Daniel Holbach
8dfd0abbc9 Update babel, jest, webpack bits
This should fix the handlebars and serialize-javascript
	security alerts on GH at least.

	It also updates the node requirement (I think through the
	jest update this was necessary) - somebody should check
	if we can actually make	the jump.
2020-03-10 12:22:35 +01:00
Filip Barl
c6d5fe1ec6 build(client): Ran yarn install to update yarn.lock 2019-12-05 11:18:07 +01:00