Skip to content

Upgrade: Bump loofah from 2.7.0 to 2.9.0 - #1914

Closed
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/loofah-2.9.0
Closed

Upgrade: Bump loofah from 2.7.0 to 2.9.0#1914
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/loofah-2.9.0

Conversation

@dependabot-preview

Copy link
Copy Markdown
Contributor

Bumps loofah from 2.7.0 to 2.9.0.

Release notes

Sourced from loofah's releases.

2.8.0 / 2020-11-25

  • Allow CSS properties order, flex-direction, flex-grow, flex-wrap, flex-shrink, flex-flow, flex-basis, flex, justify-content, align-self, align-items, and align-content. [#197] (Thanks, @miguelperez!)
Changelog

Sourced from loofah's changelog.

2.9.0 / 2021-01-14

  • Handle CSS functions in a CSS shorthand property (like background). [#199, #200]

2.8.0 / 2020-11-25

  • Allow CSS properties order, flex-direction, flex-grow, flex-wrap, flex-shrink, flex-flow, flex-basis, flex, justify-content, align-self, align-items, and align-content. [#197] (Thanks, @miguelperez!)
Commits
  • b18e3dc version bump to v2.9.0
  • 8ed486d Merge pull request #200 from flavorjones/199-css-functions-not-handled-properly
  • bf13d48 fix: handle CSS functions in a CSS shorthand property
  • 253bedf fix: update test to handle behavior of latest Nokogiri
  • fbe0846 ci: remove max-in-flight constraint
  • e051fe8 version bump to v2.8.0
  • a3dbbf4 perf: use require_relative where we can
  • d0a729c style: fix indentation
  • 324640c ci: separate rubocop and test tasks; make default task do both
  • 3ad9607 Merge pull request #198 from miguelperez/add-flex-properties
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [loofah](https://github.com/flavorjones/loofah) from 2.7.0 to 2.9.0.
- [Release notes](https://github.com/flavorjones/loofah/releases)
- [Changelog](https://github.com/flavorjones/loofah/blob/master/CHANGELOG.md)
- [Commits](flavorjones/loofah@v2.7.0...v2.9.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview Bot added the dependencies Pull requests that update a dependency file label Jan 14, 2021
@dependabot-preview

Copy link
Copy Markdown
Contributor Author

Superseded by #1977.

@dependabot-preview
dependabot-preview Bot deleted the dependabot/bundler/loofah-2.9.0 branch April 7, 2021 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants