Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump undici and hardhat in /contracts #431

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Feb 16, 2023

Bumps undici to 5.19.1 and updates ancestor dependency hardhat. These dependencies need to be updated together.

Updates undici from 5.5.1 to 5.19.1

Release notes

Sourced from undici's releases.

v5.19.1

⚠️ Security Release ⚠️

This release is part of the Node.js security release train: https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/

v5.19.0

What's Changed

New Contributors

Full Changelog: nodejs/undici@v5.18.0...v5.19.0

v5.18.0

What's Changed

Full Changelog: nodejs/undici@v5.17.1...v5.18.0

v5.17.1

What's Changed

Full Changelog: nodejs/undici@v5.17.0...v5.17.1

v5.17.0

What's Changed

... (truncated)

Commits

Updates hardhat from 2.9.7 to 2.12.7

Release notes

Sourced from hardhat's releases.

[email protected]

Changes

  • e443b3667: Added an option in Hardhat Network to allow mining blocks with the same timestamp

  • c23a1cac4: Added support for the http_proxy environment variable. When this variable is set, Hardhat will send its requests through the given proxy for things like JSON-RPC requests, mainnet forking and downloading compilers.

    We also removed support for the HTTP_PROXY and HTTPS_PROXY environment variables, since http_proxy is the most commonly used environment variable for this kind of thing. Those variables could only be used for downloading compilers.

    Finally, we also added support for no_proxy, which accepts a comma separated list of hosts or "*". Any host included in this list will not be proxied.

    Note that requests to "localhost" or "127.0.0.1" are never proxied.

  • 69546655e: Added support for sending batch requests through WebSocket to the Hardhat node (thanks @​tenbits!)

  • 6bf1673bb: Added a config validation for the number of optimizer runs used (thanks @​konarshankar07!)

Hardhat v2.12.6

Features

  • Added support for pnpm during project creation (thanks @​Hopsken!)
  • Added a version field to the Hardhat Runtime Environment (thanks @​konarshankar07!)

Bug fixes

  • Fixed a problem with impersonated-sender transactions sometimes resulting in duplicate transaction hashes (issue #1963)

Other changes

  • Added a minor clarification to the help output of the flatten task
  • Upgraded the versions of mocha and @types/mocha used by Hardhat
  • Upgraded the version of undici used by Hardhat.
  • Removed the message linking to the 2022 Solidity Survey
  • Added a new subtask to the compile task that will be used by the hardhat-foundry plugin.

Hardhat v2.12.5

  • The full return data of unrecognized custom errors is now shown in error messages
  • Fixed a bug that was causing the flatten task to produce non-deterministic results
  • Fixed a bug when gasPrice was set to "auto", which is the default configuration when connecting to a JSON-RPC network. This bug was preventing the results from eth_feeHistory from being used when they should.
  • Added an experimental environment variable flag to disable the local installation check (thanks @​arijoon!)

Hardhat v2.12.4

This release fixes a small issue that was affecting our VSCode extension in some edge cases.

It also includes a non-intrusive message promoting this year's Solidity Developer Survey.

Hardhat v2.12.3

  • Added a new hardhat_metadata RPC method
  • Trim leading and trailing spaces in mnemonics (thanks @​winor30!)
  • Pending blocks now include the bloom field (thanks @​InoMurko!)
  • A better error is shown if a Solidity file makes an import through its own package name (thanks @​KaanKC!)
  • Added a getBuildInfoSync function to the hre.artifacts object (thanks @​emretepedev!)

... (truncated)

Commits
  • 6baf30a Version Packages
  • ccf8841 Merge pull request #3658 from NomicFoundation/plugin-error-eslint
  • 5a9b9a3 remove unnecessary line
  • 471a70f Update packages/eslint-plugin/onlyHardhatErrorRule.js
  • 0edcf75 Merge pull request #2976 from NomicFoundation/francovictorio/hh-937/improve-w...
  • 337456b Create cyan-knives-study.md
  • 4256068 add eslint rule for hardhat plugin errors
  • 95328cc Merge pull request #3432 from NomicFoundation/improve-proxy-support
  • 6a3c6ec Add docs about http_proxy
  • 42d8481 Update .changeset/few-flies-drum.md
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 5.19.1 and updates ancestor dependency [hardhat](https://github.com/nomiclabs/hardhat). These dependencies need to be updated together.


Updates `undici` from 5.5.1 to 5.19.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v5.5.1...v5.19.1)

Updates `hardhat` from 2.9.7 to 2.12.7
- [Release notes](https://github.com/nomiclabs/hardhat/releases)
- [Commits](https://github.com/nomiclabs/hardhat/compare/[email protected]@2.12.7)

---
updated-dependencies:
- dependency-name: undici
  dependency-type: indirect
- dependency-name: hardhat
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 16, 2023
@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@codecov-commenter
Copy link

Codecov Report

Merging #431 (e28fa87) into main (d2fd551) will decrease coverage by 2.27%.
The diff coverage is 27.33%.

@@            Coverage Diff             @@
##             main     #431      +/-   ##
==========================================
- Coverage   56.86%   54.60%   -2.27%     
==========================================
  Files         117      115       -2     
  Lines        3264     3315      +51     
  Branches      546      557      +11     
==========================================
- Hits         1856     1810      -46     
- Misses       1408     1505      +97     
Flag Coverage Δ
common 84.61% <100.00%> (+0.32%) ⬆️
core-sdk 52.29% <23.23%> (-1.37%) ⬇️
eth-connect-sdk 18.57% <ø> (ø)
ethers-sdk 66.12% <ø> (ø)
ipfs-storage 94.02% <ø> (ø)
metadata ?
unittests 54.60% <27.33%> (-2.27%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Impacted Files Coverage Δ
packages/core-sdk/src/meta-tx/biconomy.ts 15.90% <0.00%> (-0.76%) ⬇️
packages/core-sdk/src/native-meta-tx/handler.ts 24.00% <ø> (ø)
packages/core-sdk/src/native-meta-tx/mixin.ts 37.50% <ø> (ø)
packages/core-sdk/src/utils/signature.ts 17.39% <0.00%> (ø)
packages/core-sdk/src/meta-tx/handler.ts 21.97% <11.32%> (-3.61%) ⬇️
packages/core-sdk/src/forwarder/handler.ts 16.00% <14.28%> (-17.34%) ⬇️
packages/core-sdk/src/meta-tx/mixin.ts 31.62% <15.78%> (-2.72%) ⬇️
packages/core-sdk/src/voucher/handler.ts 28.00% <20.00%> (-2.00%) ⬇️
packages/core-sdk/src/voucher/mixin.ts 24.00% <22.22%> (-0.40%) ⬇️
packages/core-sdk/src/voucher/interface.ts 54.16% <50.00%> (-1.39%) ⬇️
... and 11 more

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 15, 2023

Superseded by #451.

@dependabot dependabot bot closed this Mar 15, 2023
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/contracts/undici-and-hardhat-5.19.1 branch March 15, 2023 08:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants