cofacts

Month: 2022-02

2022-02-01

github2 01:14:29

<https://github.com/cofacts/takedowns/pull/39|#39 Convert old spammers to new blocking mechanism>

This announcement will convert old spammers to new blocking mechanism, so that new posts of these spammers will be directly hidden as sonn as they are posted. After this we no longer need to monitor these spammers.

這個 PR 處理過去這些 yegogo 在內的舊 spammer,把原本「看到就刪掉」的機制改成新的「設成 blocked user」唷
Approve 之後我們就不用 monitor 他們的回應了,因為可以直接走新的自動隱藏
https://github.com/cofacts/takedowns/pull/39/files?short_path=f078e9b#diff-f078e9b8bcbe618a71d8226ca84b1194fc27b049ac5052eff8f732ec33411fcb
github2 01:14:29

<https://github.com/cofacts/takedowns/pull/39|#39 Convert old spammers to new blocking mechanism>

This announcement will convert old spammers to new <https://www.facebook.com/groups/cofacts/posts/3111789079052900/|blocking mechanism>, so that new posts of these spammers will be directly hidden as soon as they are posted. After this we no longer need to <https://docs.google.com/spreadsheets/d/1BBObfTO7bLWERQ3nq3S1iBs3xt2o2TgOxikXqixOdYI/edit#gid=0|monitor> these spammers.

這個 PR 處理過去這些 yegogo 在內的舊 spammer,把原本「看到就刪掉」的機制改成新的「設成 blocked user」唷
Approve 之後我們就不用 monitor 他們的回應了,因為可以直接走新的自動隱藏
https://github.com/cofacts/takedowns/pull/39/files?short_path=f078e9b#diff-f078e9b8bcbe618a71d8226ca84b1194fc27b049ac5052eff8f732ec33411fcb
mrorz 01:16:35
這個 PR 處理過去這些 yegogo 在內的舊 spammer,把原本「看到就刪掉」的機制改成新的「設成 blocked user」唷
Approve 之後我們就不用 monitor 他們的回應了,因為可以直接走新的自動隱藏
https://github.com/cofacts/takedowns/pull/39/files?short_path=f078e9b#diff-f078e9b8bcbe618a71d8226ca84b1194fc27b049ac5052eff8f732ec33411fcb
1
mrorz 11:00:06
明天大年初二
不會開會唷~~~
mrorz 11:00:06
明天大年初二
不會開會唷~~~

2022-02-03

cai 21:49:12
雞蛋那篇默默地上升了,但是農委會應該等到開工才會澄清?
kidstarkenny 2022-02-05 12:51:58
傳消息的熱情民眾快點覺醒啊啊
https://ai.gov.tw/index.php
認真來講,今年至今禽流感有被撲殺的是中部,不是南部
kidstarkenny 2022-02-05 14:42:18
我個人目前也沒看到有什麼南部雞場
kidstarkenny 2022-02-05 14:42:25
除非跟臺北市一樣沒疫情消息都是蓋牌(X ,
(反串文我有標註謝謝)
這個我昨天也查不到 QQ
我已經拿上面陳吉仲說法回完了,懶得改 XD
只能說這個謠言挑年假期間傳播
跟 Omicron 相比有過之而無不及 XD
等官網有再放,fb 沒預覽麻煩
明天會有新一波的喔 (福島核食開放)
為什麼新聞要 frame 在生長激素 XDDD
1. 原訊息只說「藥」,沒有指定事「生長激素」
2. 原訊息提到「乳癌」,與「乳癌」有關係的是「抗生素」,而人服用抗生素確實與乳癌,確實在很久以前就開始有所連結
所以把主題鎖在「生長激素」其實是偷換概念
cai 21:49:12
雞蛋那篇默默地上升了,但是農委會應該等到開工才會澄清?
kidstarkenny 2022-02-05 12:51:58
傳消息的熱情民眾快點覺醒啊啊
https://ai.gov.tw/index.php
認真來講,今年至今禽流感有被撲殺的是中部,不是南部
kidstarkenny 2022-02-05 14:42:18
我個人目前也沒看到有什麼南部雞場
kidstarkenny 2022-02-05 14:42:25
除非跟臺北市一樣沒疫情消息都是蓋牌(X ,
(反串文我有標註謝謝)
這個我昨天也查不到 QQ
我已經拿上面陳吉仲說法回完了,懶得改 XD
只能說這個謠言挑年假期間傳播
跟 Omicron 相比有過之而無不及 XD
等官網有再放,fb 沒預覽麻煩
明天會有新一波的喔 (福島核食開放)
為什麼新聞要 frame 在生長激素 XDDD
1. 原訊息只說「藥」,沒有指定事「生長激素」
2. 原訊息提到「乳癌」,與「乳癌」有關係的是「抗生素」,而人服用抗生素確實與乳癌,確實在很久以前就開始有所連結
所以把主題鎖在「生長激素」其實是偷換概念
😲 1

2022-02-05

cai 12:50:07
全家串也默默攀升
https://cofacts.tw/article/2mf138tshqcq
可是數字好怪,網頁瀏覽 6269 次,Line 詢問 395 次,回報只有6
https://cofacts.tw/article/2mf138tshqcq
可是數字好怪,line詢問395次,回報只有6
因為有人回應之後,LINE 詢問就會直接回傳結果,而不會再新增 reply request 唷
cai 12:50:07
全家串也默默攀升
https://cofacts.tw/article/2mf138tshqcq
可是數字好怪,網頁瀏覽 6269 次,Line 詢問 395 次,回報只有6
https://cofacts.tw/article/2mf138tshqcq
可是數字好怪,line詢問395次,回報只有6
因為有人回應之後,LINE 詢問就會直接回傳結果,而不會再新增 reply request 唷
cai 13:02:53
https://cofacts.tw/article/2mf138tshqcq
可是數字好怪,網頁瀏覽 6269 次,Line 詢問 395 次,回報只有6
cai 14:37:48
這帳號過幾天會變成正妹圖嗎 😆
Screenshot 2022-02-05 at 14-28-49 新年快樂 LINE 官方帳號.png
也可能變成飆股老師
日新月異呢
累積了4個帳號了
然後有2個帳號大頭貼變黑色,名字改掉
賣得好快喔
貼圖詐騙整個捲土重來耶
元宵節版本,做假的line hub網頁
https://cofacts.tw/article/17jz8cgj9jkpn
好熱門喔
新聞口吻模仿得不錯耶
去年固定都假貼圖,今年一直翻新手法欸
外部網站這招也是一陣子了
https://www.mygopen.com/2018/05/line_4.html
一直都是連到外部網站再加入啊,只是頁面長不同
這次手法比較像之前假投資會出現的假新聞網站
喔喔對,之前那個郭台銘投資數位貨幣的假網頁 XD
2

2022-02-06

2022-02-07

Lee Yvonne 15:02:08
@yvonnewww19981227 has joined the channel
Lee Yvonne 15:06:05
@yvonnewww19981227 has left the channel
mrorz 16:41:08
今天一直出現這個
原來是有新影片 https://www.facebook.com/watch/?v=640578477059862
image.png

Facebook Watch

Johnhow Fan on Facebook Watch

我的媽啊!! 莫德納疫苗發明人這樣說!!

Hmmm 看起來也沒很新呀,去年 12 月中就有
https://cofacts.tw/article/v7lik4k8i49a
😮 1

2022-02-08

2022-02-09

2022-02-10

Ivan 07:06:22
@lsn123666 has joined the channel
github2 07:20:27

<https://github.com/cofacts/rumors-site/pull/474|#474 Bump systeminformation from 4.21.1 to 4.34.23>

Bumps <https://github.com/sebhildebrandt/systeminformation|systeminformation> from 4.21.1 to 4.34.23. Changelog _Sourced from <https://github.com/sebhildebrandt/systeminformation/blob/v4.34.23/CHANGELOG.md|systeminformation's changelog>._ &gt; *Changelog* &gt; *Major Changes - Version 4* &gt; &gt; *New Functions* &gt; &gt; • `chassis()`: chassis information &gt; &gt; *Breaking Changes* &gt; &gt; • `networkStats()`: will provide an *array* of stats for all given interfaces. In previous versions only one interface was provided as a parameter. Pass '*' for all interfaces &gt; • `networkStats()`: `rx` and `tx` changed to `rx_bytes` and `tx_bytes` &gt; • `dockerContainerStats()`: will provide an *array* of stats for all given docker containers. In previous versions only one interface was provided as a parameter. Pass '*' for all docker containers &gt; &gt; *Other Changes* &gt; &gt; • `system()` optimized system detection (e.g. new Raspberry Pi models, ...), additional flags &gt; • `system()`, `bios()`, `baseboard()` information also as non-root (linux) &gt; • `graphics()` better controller and display detection, fixes &gt; • `versions()` optimization, fixes &gt; • `networkInterfaces()` added `operstate`, `type`, `duplex`, `mtu`, `speed`, `carrierChanges` &gt; • `networkStats()` added stats for `errors`, `dropped` &gt; • added TypeScript definitions &gt; &gt; *Be aware*, that the new version 4.x is *NOT fully backward compatible* to version 3.x ... &gt; &gt; For major (breaking) changes - version 3 and 2 see end of page. &gt; &gt; *Version history* ... (truncated) Commits • <https://github.com/sebhildebrandt/systeminformation/commit/49c85e0697f4473be302f273ea12cb63b1697450|`49c85e0`> 4.34.23 • <https://github.com/sebhildebrandt/systeminformation/commit/f8addf67d266e0b775f0a34f74ff20f6cf2769b7|`f8addf6`> networkInterfaces() fixed Windows XP bug (WMIC NetEnabled) • <https://github.com/sebhildebrandt/systeminformation/commit/2fba3e9ebeada2b05d70b11d266f25189798c226|`2fba3e9`> 4.34.22 • <https://github.com/sebhildebrandt/systeminformation/commit/b76764b68a5272b58ce97ca013483b4a197edbad|`b76764b`> restored Node 4.x compatibility • <https://github.com/sebhildebrandt/systeminformation/commit/fe5f3a261f7129519944357e43641fc9c957b7a0|`fe5f3a2`> 4.34.21 • <https://github.com/sebhildebrandt/systeminformation/commit/ffb99f2da3791fe8edbc1eb11ef0c293c82d93d6|`ffb99f2`> dockerContainerInspect(), dockerContainerProcesses() parameter validation fix • <https://github.com/sebhildebrandt/systeminformation/commit/4c970c37429629194fe5f3db7d06e8c16a967d9c|`4c970c3`> 4.34.20 • <https://github.com/sebhildebrandt/systeminformation/commit/9ca91ece0f8973d23f7e3af40d36da83a52a89b8|`9ca91ec`> versions() parameter sanitation • <https://github.com/sebhildebrandt/systeminformation/commit/e752c6bceeb85f253f6af5a88eaa82d095de4237|`e752c6b`> 4.34.19 • <https://github.com/sebhildebrandt/systeminformation/commit/ba58ee15339e0bb2d53884c9a3bcc91422dc8a38|`ba58ee1`> inetLatency() ineChecksite() schema validation • Additional commits viewable in <https://github.com/sebhildebrandt/systeminformation/compare/v4.21.1...v4.34.23|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

:white_check_mark: All checks have passed

github2 07:20:27

<https://github.com/cofacts/rumors-site/pull/474|#474 Bump systeminformation from 4.21.1 to 4.34.23>

Bumps <https://github.com/sebhildebrandt/systeminformation|systeminformation> from 4.21.1 to 4.34.23. Changelog _Sourced from <https://github.com/sebhildebrandt/systeminformation/blob/v4.34.23/CHANGELOG.md|systeminformation's changelog>._ &gt; *Changelog* &gt; *Major Changes - Version 4* &gt; &gt; *New Functions* &gt; &gt; • `chassis()`: chassis information &gt; &gt; *Breaking Changes* &gt; &gt; • `networkStats()`: will provide an *array* of stats for all given interfaces. In previous versions only one interface was provided as a parameter. Pass '*' for all interfaces &gt; • `networkStats()`: `rx` and `tx` changed to `rx_bytes` and `tx_bytes` &gt; • `dockerContainerStats()`: will provide an *array* of stats for all given docker containers. In previous versions only one interface was provided as a parameter. Pass '*' for all docker containers &gt; &gt; *Other Changes* &gt; &gt; • `system()` optimized system detection (e.g. new Raspberry Pi models, ...), additional flags &gt; • `system()`, `bios()`, `baseboard()` information also as non-root (linux) &gt; • `graphics()` better controller and display detection, fixes &gt; • `versions()` optimization, fixes &gt; • `networkInterfaces()` added `operstate`, `type`, `duplex`, `mtu`, `speed`, `carrierChanges` &gt; • `networkStats()` added stats for `errors`, `dropped` &gt; • added TypeScript definitions &gt; &gt; *Be aware*, that the new version 4.x is *NOT fully backward compatible* to version 3.x ... &gt; &gt; For major (breaking) changes - version 3 and 2 see end of page. &gt; &gt; *Version history* ... (truncated) Commits • <https://github.com/sebhildebrandt/systeminformation/commit/49c85e0697f4473be302f273ea12cb63b1697450|`49c85e0`> 4.34.23 • <https://github.com/sebhildebrandt/systeminformation/commit/f8addf67d266e0b775f0a34f74ff20f6cf2769b7|`f8addf6`> networkInterfaces() fixed Windows XP bug (WMIC NetEnabled) • <https://github.com/sebhildebrandt/systeminformation/commit/2fba3e9ebeada2b05d70b11d266f25189798c226|`2fba3e9`> 4.34.22 • <https://github.com/sebhildebrandt/systeminformation/commit/b76764b68a5272b58ce97ca013483b4a197edbad|`b76764b`> restored Node 4.x compatibility • <https://github.com/sebhildebrandt/systeminformation/commit/fe5f3a261f7129519944357e43641fc9c957b7a0|`fe5f3a2`> 4.34.21 • <https://github.com/sebhildebrandt/systeminformation/commit/ffb99f2da3791fe8edbc1eb11ef0c293c82d93d6|`ffb99f2`> dockerContainerInspect(), dockerContainerProcesses() parameter validation fix • <https://github.com/sebhildebrandt/systeminformation/commit/4c970c37429629194fe5f3db7d06e8c16a967d9c|`4c970c3`> 4.34.20 • <https://github.com/sebhildebrandt/systeminformation/commit/9ca91ece0f8973d23f7e3af40d36da83a52a89b8|`9ca91ec`> versions() parameter sanitation • <https://github.com/sebhildebrandt/systeminformation/commit/e752c6bceeb85f253f6af5a88eaa82d095de4237|`e752c6b`> 4.34.19 • <https://github.com/sebhildebrandt/systeminformation/commit/ba58ee15339e0bb2d53884c9a3bcc91422dc8a38|`ba58ee1`> inetLatency() ineChecksite() schema validation • Additional commits viewable in <https://github.com/sebhildebrandt/systeminformation/compare/v4.21.1...v4.34.23|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

github2 07:23:02

<https://github.com/cofacts/rumors-site/pull/474#issuecomment-1034302941|Comment on #474 Bump systeminformation from 4.21.1 to 4.34.23>

<https://coveralls.io/builds/46395403|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/5bbc613f05bed6072de1be8fcbdfd814b0e364d3|5bbc613> on dependabot/npm_and_yarn/systeminformation-4.34.23* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

github2 07:23:02

<https://github.com/cofacts/rumors-site/pull/474#issuecomment-1034302941|Comment on #474 Bump systeminformation from 4.21.1 to 4.34.23>

<https://coveralls.io/builds/46395403|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/5bbc613f05bed6072de1be8fcbdfd814b0e364d3|5bbc613> on dependabot/npm_and_yarn/systeminformation-4.34.23* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

2022-02-11

github2 12:57:12

<https://github.com/cofacts/rumors-site/pull/475|#475 Bump ajv from 6.10.2 to 6.12.3>

Bumps <https://github.com/ajv-validator/ajv|ajv> from 6.10.2 to 6.12.3. Release notes _Sourced from <https://github.com/ajv-validator/ajv/releases|ajv's releases>._ &gt; *v6.12.3* &gt; &gt; Pass schema object to processCode function Option for strictNumbers (<https://github.com/issacgerges|`@​issacgerges`>, <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1128|#1128>) Fixed vulnerability related to untrusted schemas (<https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE-2020-15366|CVE-2020-15366>) &gt; &gt; *v6.12.2* &gt; &gt; Removed post-install script &gt; &gt; *v6.12.1* &gt; &gt; Docs and dependency updates &gt; &gt; *v6.12.0* &gt; &gt; Improved hostname validation (<https://github.com/sambauers|`@​sambauers`>, <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1143|#1143>) Option `keywords` to add custom keywords (<https://github.com/franciscomorais|`@​franciscomorais`>, <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1137|#1137>) Types fixes (<https://github.com/boenrobot|`@​boenrobot`>, <https://github.com/MattiAstedrone|`@​MattiAstedrone`>) Docs: &gt; &gt; • <https://github.com/epoberezkin/ajv#error-logging|error logging> example (<https://github.com/RadiationSickness|`@​RadiationSickness`>) &gt; • TypeScript usage notes (<https://github.com/thetric|`@​thetric`>) &gt; &gt; *v6.11.0* &gt; &gt; Time formats support two digit and colon-less variants of timezone offset (<https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1061|#1061> , <https://github.com/cjpillsbury|`@​cjpillsbury`>) Docs: RegExp related security considerations Tests: Disabled failing typescript test Commits • <https://github.com/ajv-validator/ajv/commit/521c3a53f15f5502fb4a734194932535d311267c|`521c3a5`> 6.12.3 • <https://github.com/ajv-validator/ajv/commit/bd7107b54166a4ca67555ba37829375e31649bf8|`bd7107b`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1229|#1229> from ajv-validator/dependabot/npm_and_yarn/mocha-8.0.1 • <https://github.com/ajv-validator/ajv/commit/9c26bb28f839a1cde853b64f7f6d035e4b3afd1e|`9c26bb2`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1234|#1234> from ajv-validator/dependabot/npm_and_yarn/eslint-7.3.1 • <https://github.com/ajv-validator/ajv/commit/c6a6daaf9e2739f4e50a33c3aed647b7629d1fc4|`c6a6daa`> Merge branch 'master' into dependabot/npm_and_yarn/mocha-8.0.1 • <https://github.com/ajv-validator/ajv/commit/15eda23010c8b2d1353ebf7afc8e27d818b149ac|`15eda23`> Merge branch 'master' into dependabot/npm_and_yarn/eslint-7.3.1 • <https://github.com/ajv-validator/ajv/commit/d6aabb8e97029130cdb607dcd2e78a6d567e10d5|`d6aabb8`> test: remove node 8 from travis test • <https://github.com/ajv-validator/ajv/commit/c4801ca7771eef5cf7ad8c1adb7cce83c16f065f|`c4801ca`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1242|#1242> from ajv-validator/refactor • <https://github.com/ajv-validator/ajv/commit/988982d3fde08e3ea074e8942442834e78c45587|`988982d`> ignore proto properties • <https://github.com/ajv-validator/ajv/commit/f2b1e3d2c89288561ee68d7459a41b7222cc520d|`f2b1e3d`> whitespace • <https://github.com/ajv-validator/ajv/commit/65e3678146e63b0c8ec80d66e05e146dff68a15d|`65e3678`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1239|#1239> from GrahamLea/patch-1 • Additional commits viewable in <https://github.com/ajv-validator/ajv/compare/v6.10.2...v6.12.3|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

github2 12:57:12

<https://github.com/cofacts/rumors-site/pull/475|#475 Bump ajv from 6.10.2 to 6.12.3>

Bumps <https://github.com/ajv-validator/ajv|ajv> from 6.10.2 to 6.12.3. Release notes _Sourced from <https://github.com/ajv-validator/ajv/releases|ajv's releases>._ &gt; *v6.12.3* &gt; &gt; Pass schema object to processCode function Option for strictNumbers (<https://github.com/issacgerges|`@​issacgerges`>, <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1128|#1128>) Fixed vulnerability related to untrusted schemas (<https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE-2020-15366|CVE-2020-15366>) &gt; &gt; *v6.12.2* &gt; &gt; Removed post-install script &gt; &gt; *v6.12.1* &gt; &gt; Docs and dependency updates &gt; &gt; *v6.12.0* &gt; &gt; Improved hostname validation (<https://github.com/sambauers|`@​sambauers`>, <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1143|#1143>) Option `keywords` to add custom keywords (<https://github.com/franciscomorais|`@​franciscomorais`>, <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1137|#1137>) Types fixes (<https://github.com/boenrobot|`@​boenrobot`>, <https://github.com/MattiAstedrone|`@​MattiAstedrone`>) Docs: &gt; &gt; • <https://github.com/epoberezkin/ajv#error-logging|error logging> example (<https://github.com/RadiationSickness|`@​RadiationSickness`>) &gt; • TypeScript usage notes (<https://github.com/thetric|`@​thetric`>) &gt; &gt; *v6.11.0* &gt; &gt; Time formats support two digit and colon-less variants of timezone offset (<https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1061|#1061> , <https://github.com/cjpillsbury|`@​cjpillsbury`>) Docs: RegExp related security considerations Tests: Disabled failing typescript test Commits • <https://github.com/ajv-validator/ajv/commit/521c3a53f15f5502fb4a734194932535d311267c|`521c3a5`> 6.12.3 • <https://github.com/ajv-validator/ajv/commit/bd7107b54166a4ca67555ba37829375e31649bf8|`bd7107b`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1229|#1229> from ajv-validator/dependabot/npm_and_yarn/mocha-8.0.1 • <https://github.com/ajv-validator/ajv/commit/9c26bb28f839a1cde853b64f7f6d035e4b3afd1e|`9c26bb2`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1234|#1234> from ajv-validator/dependabot/npm_and_yarn/eslint-7.3.1 • <https://github.com/ajv-validator/ajv/commit/c6a6daaf9e2739f4e50a33c3aed647b7629d1fc4|`c6a6daa`> Merge branch 'master' into dependabot/npm_and_yarn/mocha-8.0.1 • <https://github.com/ajv-validator/ajv/commit/15eda23010c8b2d1353ebf7afc8e27d818b149ac|`15eda23`> Merge branch 'master' into dependabot/npm_and_yarn/eslint-7.3.1 • <https://github.com/ajv-validator/ajv/commit/d6aabb8e97029130cdb607dcd2e78a6d567e10d5|`d6aabb8`> test: remove node 8 from travis test • <https://github.com/ajv-validator/ajv/commit/c4801ca7771eef5cf7ad8c1adb7cce83c16f065f|`c4801ca`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1242|#1242> from ajv-validator/refactor • <https://github.com/ajv-validator/ajv/commit/988982d3fde08e3ea074e8942442834e78c45587|`988982d`> ignore proto properties • <https://github.com/ajv-validator/ajv/commit/f2b1e3d2c89288561ee68d7459a41b7222cc520d|`f2b1e3d`> whitespace • <https://github.com/ajv-validator/ajv/commit/65e3678146e63b0c8ec80d66e05e146dff68a15d|`65e3678`> Merge pull request <https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1239|#1239> from GrahamLea/patch-1 • Additional commits viewable in <https://github.com/ajv-validator/ajv/compare/v6.10.2...v6.12.3|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

:white_check_mark: All checks have passed

github2 12:59:56

<https://github.com/cofacts/rumors-site/pull/475#issuecomment-1035885355|Comment on #475 Bump ajv from 6.10.2 to 6.12.3>

<https://coveralls.io/builds/46444227|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/60c3e9c0fa6dcd363d5e7fd626ce543cad1d682b|60c3e9c> on dependabot/npm_and_yarn/ajv-6.12.3* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

github2 12:59:56

<https://github.com/cofacts/rumors-site/pull/475#issuecomment-1035885355|Comment on #475 Bump ajv from 6.10.2 to 6.12.3>

<https://coveralls.io/builds/46444227|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/60c3e9c0fa6dcd363d5e7fd626ce543cad1d682b|60c3e9c> on dependabot/npm_and_yarn/ajv-6.12.3* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

Jay Lo 17:47:07
@loujay60606 has joined the channel
cai 22:25:10
趨勢科技的linebot 丟line的邀請連結可以直接判定是不是灰色盾牌 😮
沒看過這種 API
有可能是爬 invite 網頁、或者是從 invite 網頁挖到某些非公開 API、或者是有跟 LINE 談合作~
cai 22:25:10
趨勢科技的linebot 丟line的邀請連結可以直接判定是不是灰色盾牌,是怎樣做到的 🤔
沒看過這種 API
有可能是爬 invite 網頁、或者是從 invite 網頁挖到某些非公開 API、或者是有跟 LINE 談合作~

2022-02-12

github2 10:48:08

<https://github.com/cofacts/rumors-fb-bot/pull/30|#30 Bump follow-redirects from 1.5.5 to 1.14.8>

Bumps <https://github.com/follow-redirects/follow-redirects|follow-redirects> from 1.5.5 to 1.14.8. Commits • <https://github.com/follow-redirects/follow-redirects/commit/3d81dc3237b4ffe8b722bb3d1c70a7866657166e|`3d81dc3`> Release version 1.14.8 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445|`62e546a`> Drop confidential headers across schemes. • <https://github.com/follow-redirects/follow-redirects/commit/2ede36d7c60d3acdcd324dcd99a9dbd52e4fb3a6|`2ede36d`> Release version 1.14.7 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22|`8b347cb`> Drop Cookie header across domains. • <https://github.com/follow-redirects/follow-redirects/commit/6f5029ae1a0fdab4dc25f6379a5ee303c2319070|`6f5029a`> Release version 1.14.6 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/af706bee57de954414c0bde0a9f33e62beea3e52|`af706be`> Ignore null headers. • <https://github.com/follow-redirects/follow-redirects/commit/d01ab7a5c5df3617c7a40a03de7af6427fdfac55|`d01ab7a`> Release version 1.14.5 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/40052ea8aa13559becee5795715c1d45b1f0eb76|`40052ea`> Make compatible with Node 17. • <https://github.com/follow-redirects/follow-redirects/commit/86f7572f9365dadc39f85916259b58973819617f|`86f7572`> Fix: clear internal timer on request abort to avoid leakage • <https://github.com/follow-redirects/follow-redirects/commit/2e1eaf0218c5315a2ab27f53964d0535d4dafb51|`2e1eaf0`> Keep Authorization header on subdomain redirects. • Additional commits viewable in <https://github.com/follow-redirects/follow-redirects/compare/v1.5.5...v1.14.8|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-fb-bot/network/alerts|Security Alerts page>.

github2 10:48:08

<https://github.com/cofacts/rumors-fb-bot/pull/30|#30 Bump follow-redirects from 1.5.5 to 1.14.8>

Bumps <https://github.com/follow-redirects/follow-redirects|follow-redirects> from 1.5.5 to 1.14.8. Commits • <https://github.com/follow-redirects/follow-redirects/commit/3d81dc3237b4ffe8b722bb3d1c70a7866657166e|`3d81dc3`> Release version 1.14.8 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445|`62e546a`> Drop confidential headers across schemes. • <https://github.com/follow-redirects/follow-redirects/commit/2ede36d7c60d3acdcd324dcd99a9dbd52e4fb3a6|`2ede36d`> Release version 1.14.7 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22|`8b347cb`> Drop Cookie header across domains. • <https://github.com/follow-redirects/follow-redirects/commit/6f5029ae1a0fdab4dc25f6379a5ee303c2319070|`6f5029a`> Release version 1.14.6 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/af706bee57de954414c0bde0a9f33e62beea3e52|`af706be`> Ignore null headers. • <https://github.com/follow-redirects/follow-redirects/commit/d01ab7a5c5df3617c7a40a03de7af6427fdfac55|`d01ab7a`> Release version 1.14.5 of the npm package. • <https://github.com/follow-redirects/follow-redirects/commit/40052ea8aa13559becee5795715c1d45b1f0eb76|`40052ea`> Make compatible with Node 17. • <https://github.com/follow-redirects/follow-redirects/commit/86f7572f9365dadc39f85916259b58973819617f|`86f7572`> Fix: clear internal timer on request abort to avoid leakage • <https://github.com/follow-redirects/follow-redirects/commit/2e1eaf0218c5315a2ab27f53964d0535d4dafb51|`2e1eaf0`> Keep Authorization header on subdomain redirects. • Additional commits viewable in <https://github.com/follow-redirects/follow-redirects/compare/v1.5.5...v1.14.8|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-fb-bot/network/alerts|Security Alerts page>.

2022-02-15

ichieh 19:50:46
想問 @mrorz 有一次有看到闢謠的儀表板(查核幾則會跳一句好笑話的那個頁面)那個網址在哪裡找的到嗎
時間可以是過去的時間唷,例如說 https://cofacts.github.io/community-builder/#/bignum?start=2022-02-15T00%3A00&panels=replied&panels=feedback

時區是瀏覽器所在時區。
ichieh 19:50:46
想問 @mrorz 有一次有看到闢謠的儀表板(查核幾則會跳一句好笑話的那個頁面)那個網址在哪裡找的到嗎
時間可以是過去的時間唷,例如說 https://cofacts.github.io/community-builder/#/bignum?start=2022-02-15T00%3A00&panels=replied&panels=feedback

時區是瀏覽器所在時區。

2022-02-16

github2 13:51:16

Review on #273 Multimedia support phase 0

LGTM! Thanks for the update :pray:

github2 13:51:16

Review on #273 Multimedia support phase 0

LGTM! Thanks for the update :pray:

2022-02-17

kidstarkenny 16:18:57

幾乎同步,可信度通常不高
Image from iOS
軍政速遞應該不是台灣網紅 XDD
後面有貼台灣的應徵文啦,還有受訓
cai 22:33:11
對新手最簡單的查核應該是到165查網址然後說是詐騙網站吧 😆

我都從我的 sheet 來查
不知道有沒有更友善的查法
發現165的假投資部分沒放opendata.....
line id 又很難 google
關於 165 假投資的 opendata
其實我有試過:https://data.gov.tw/suggests/136373

詐騙 LINE ID 倒是有 opendata 無誤 https://data.gov.tw/dataset/78432
👍 1
cai 22:33:11
對新手最簡單的查核應該是到165查網址然後說是詐騙網站吧 😆

我都從我的 sheet 來查
不知道有沒有更友善的查法
發現165的假投資部分沒放opendata.....
line id 又很難 google
關於 165 假投資的 opendata
其實我有試過:https://data.gov.tw/suggests/136373

詐騙 LINE ID 倒是有 opendata 無誤 https://data.gov.tw/dataset/78432

2022-02-18

cai 11:22:12
https://tfc-taiwan.org.tw/articles/6953
今天 13:30-16:30 台灣事實查核中心有論壇
Facebook 會有直播,不過現在還沒看到預告?

台灣事實查核中心

【假訊息年度大調查】台灣首次針對假訊息現象與事實查核成效大調查 學術報告出爐

cai 11:22:12
https://tfc-taiwan.org.tw/articles/6953
今天 13:30-16:30 台灣事實查核中心有論壇
Facebook 會有直播,不過現在還沒看到預告?
cai 18:07:13
回報廣告 機器填寫那頁有沒有辦法自動跳下一頁啊?
有人試過把 prefill field 放在會被跳過的頁面上,但實測結果是那些(被跳過的) prefill value 不會送出
https://stackoverflow.com/a/20355294
如果真的要再往下研究的話
可能直接做一個會 submit form 給 google form 的 HTML 比較快
cai 18:07:13
回報廣告 機器填寫那頁有沒有辦法自動跳下一頁啊?
有人試過把 prefill field 放在會被跳過的頁面上,但實測結果是那些(被跳過的) prefill value 不會送出
https://stackoverflow.com/a/20355294
如果真的要再往下研究的話
可能直接做一個會 submit form 給 google form 的 HTML 比較快
cai 19:06:23
https://cofacts.tw/article/2cjkjyk27n2b0
https://cofacts.tw/article/2vvv1cr517fpr
https://cofacts.tw/article/1qyu7xoq72j20
這三個網址好像是交友詐騙,不過查到的新聞蠻舊的
https://www.banqiao.police.ntpc.gov.tw/cp-73-56171-11.html
第一個我昨天查,165 也還沒有
就借用了 Asdfgh 的現成回應
cai 19:06:23
https://cofacts.tw/article/2cjkjyk27n2b0
https://cofacts.tw/article/2vvv1cr517fpr
https://cofacts.tw/article/1qyu7xoq72j20
https://cofacts.tw/article/36e6d8n5o8dez
好像是交友詐騙,不過查到的新聞蠻舊的
https://www.banqiao.police.ntpc.gov.tw/cp-73-56171-11.html

banqiao.police.ntpc.gov.tw

交友APP暗藏陷阱,男砸70萬換一場空。

桃園1名27歲李姓職業軍人透過交友APP「外緣」與陌生女網友聊天,對方主動贈送高價虛擬禮物,向

第一個我昨天查,165 也還沒有
就借用了 Asdfgh 的現成回應

2022-02-19

chihao 10:51:56
不要去全家 + 不要吃蛋 = 不要去全家吃蛋?
😂 2 1
chihao 10:51:56
不要去全家 + 不要吃蛋 = 不要去全家吃蛋?
ballfish 14:05:43
@lili668668 has joined the channel
github2 16:09:39

<https://github.com/cofacts/rumors-line-bot/pull/297|#297 Add API that monitors queue status>

1. Fixes <https://github.com/cofacts/rumors-line-bot/issues/260|#260> 2. Add `queue` open API that returns queue stats for monitor • Dunno know how to test "completed" queue QQ • Just added test case for "waiting" Deployed to staging: <https://user-images.githubusercontent.com/108608/154792646-56a06df0-396d-48f1-80d5-3b54c59020c1.png|圖片>

今天黑客松我把 line bot queue 的一些 API 接出來

這樣之後可以接 spreadsheet 觀察 queue 會不會壞掉

另外也修掉老 bug https://github.com/cofacts/rumors-line-bot/issues/260
test 跑不完
哭ㄚ
@acerxp511 我把 Bull queue instance 抽出來到獨立的 module 之後,不管有沒有好好 close 它,unit test 在 Github action 上都跑不完
但我在本機端是跑得完的
對這個有什麼想法嗎 QQ
可能 queue 沒完全 close 完?

我記得當初好像也是 local 都 ok, remote 就 不行..
Local 不 close queue, test 能結束嗎?
> Local 不 close queue, test 能結束嗎?
沒有加 `--runInBand` 的時候可以,加了之後就能重現 Github action 上的行為(也就是無法結束)
我也有試過直接在 setup 時設定 `afterAll` ,讓每個 test case 跑完都去 close 一下

但在 local 上這麼做,就跑出一堆無法解釋的 error
我完全不知道關 Bull 跟 redis 的 connection 跟這一堆 test fail 的關聯是什麼 ._.
github2 16:09:39

<https://github.com/cofacts/rumors-line-bot/pull/297|#297 Add API that monitors queue status>

Related: TODO items in broken group chat <https://g0v.hackmd.io/bhL6csQ8T1e81E2De7ZS5Q#%E7%BE%A4%E7%B5%84%E5%8A%9F%E8%83%BD%E5%A3%9E%E6%8E%89-update|https://g0v.hackmd.io/bhL6csQ8T1e81E2De7ZS5Q#%E7%BE%A4%E7%B5%84%E5%8A%9F%E8%83%BD%E5%A3%9E%E6%8E%89-update> 1. Fixes <https://github.com/cofacts/rumors-line-bot/issues/260|#260> 2. Moves queue instance to `src/lib/queues.js` so that it can be shared across webhook &amp; GraphQL resolvers 3. Add `queue` open API that returns queue stats for monitor • Dunno know how to test "completed" queue QQ • Just added test case for "waiting" Deployed to staging: <https://user-images.githubusercontent.com/108608/154792646-56a06df0-396d-48f1-80d5-3b54c59020c1.png|圖片>

:white_check_mark: 1 other check has passed

今天黑客松我把 line bot queue 的一些 API 接出來

這樣之後可以接 spreadsheet 觀察 queue 會不會壞掉

另外也修掉老 bug https://github.com/cofacts/rumors-line-bot/issues/260
test 跑不完
哭ㄚ
@acerxp511 我把 Bull queue instance 抽出來到獨立的 module 之後,不管有沒有好好 close 它,unit test 在 Github action 上都跑不完
但我在本機端是跑得完的
對這個有什麼想法嗎 QQ
可能 queue 沒完全 close 完?

我記得當初好像也是 local 都 ok, remote 就 不行..
Local 不 close queue, test 能結束嗎?
> Local 不 close queue, test 能結束嗎?
沒有加 `--runInBand` 的時候可以,加了之後就能重現 Github action 上的行為(也就是無法結束)
我也有試過直接在 setup 時設定 `afterAll` ,讓每個 test case 跑完都去 close 一下

但在 local 上這麼做,就跑出一堆無法解釋的 error
我完全不知道關 Bull 跟 redis 的 connection 跟這一堆 test fail 的關聯是什麼 ._.
github2 20:09:34

<https://github.com/cofacts/rumors-site/pull/476|#476 Bump url-parse from 1.4.7 to 1.5.7>

Bumps <https://github.com/unshiftio/url-parse|url-parse> from 1.4.7 to 1.5.7. Commits • <https://github.com/unshiftio/url-parse/commit/8b3f5f2c88a4cfc2880f2319c307994cb25bb10a|`8b3f5f2`> 1.5.7 • <https://github.com/unshiftio/url-parse/commit/ef45a1355375a8244063793a19059b4f62fc8788|`ef45a13`> [fix] Readd the empty userinfo to `url.href` (<https://github-redirect.dependabot.com/unshiftio/url-parse/issues/226|#226>) • <https://github.com/unshiftio/url-parse/commit/88df2346855f70cec9713b362ca32a4691dc271a|`88df234`> [doc] Add soft deprecation notice • <https://github.com/unshiftio/url-parse/commit/78e9f2f41285d83e7d91706be5bd439656fe3bc3|`78e9f2f`> [security] Fix nits • <https://github.com/unshiftio/url-parse/commit/e6fa43422c52f34c73146552ec9916125dc59525|`e6fa434`> [security] Add credits for incorrect handling of userinfo vulnerability • <https://github.com/unshiftio/url-parse/commit/4c9fa234c01dca52698666378360ad2fdfb05470|`4c9fa23`> 1.5.6 • <https://github.com/unshiftio/url-parse/commit/7b0b8a6671f806458e88b1f44feb0fdd742cdf06|`7b0b8a6`> Merge pull request <https://github-redirect.dependabot.com/unshiftio/url-parse/issues/223|#223> from unshiftio/fix/at-sign-handling-in-userinfo • <https://github.com/unshiftio/url-parse/commit/e4a5807d95b971577e4d888f5b99d64a40851386|`e4a5807`> 1.5.5 • <https://github.com/unshiftio/url-parse/commit/193b44baf3d203560735e05eedc99d8244c9e16c|`193b44b`> [minor] Simplify whitespace regex • <https://github.com/unshiftio/url-parse/commit/319851bf1c294796fc73e29ff31b14d9084e4a0d|`319851b`> [fix] Remove CR, HT, and LF • Additional commits viewable in <https://github.com/unshiftio/url-parse/compare/1.4.7...1.5.7|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

:white_check_mark: No checks have passed

github2 20:09:34

<https://github.com/cofacts/rumors-site/pull/476|#476 Bump url-parse from 1.4.7 to 1.5.7>

Bumps <https://github.com/unshiftio/url-parse|url-parse> from 1.4.7 to 1.5.7. Commits • <https://github.com/unshiftio/url-parse/commit/8b3f5f2c88a4cfc2880f2319c307994cb25bb10a|`8b3f5f2`> 1.5.7 • <https://github.com/unshiftio/url-parse/commit/ef45a1355375a8244063793a19059b4f62fc8788|`ef45a13`> [fix] Readd the empty userinfo to `url.href` (<https://github-redirect.dependabot.com/unshiftio/url-parse/issues/226|#226>) • <https://github.com/unshiftio/url-parse/commit/88df2346855f70cec9713b362ca32a4691dc271a|`88df234`> [doc] Add soft deprecation notice • <https://github.com/unshiftio/url-parse/commit/78e9f2f41285d83e7d91706be5bd439656fe3bc3|`78e9f2f`> [security] Fix nits • <https://github.com/unshiftio/url-parse/commit/e6fa43422c52f34c73146552ec9916125dc59525|`e6fa434`> [security] Add credits for incorrect handling of userinfo vulnerability • <https://github.com/unshiftio/url-parse/commit/4c9fa234c01dca52698666378360ad2fdfb05470|`4c9fa23`> 1.5.6 • <https://github.com/unshiftio/url-parse/commit/7b0b8a6671f806458e88b1f44feb0fdd742cdf06|`7b0b8a6`> Merge pull request <https://github-redirect.dependabot.com/unshiftio/url-parse/issues/223|#223> from unshiftio/fix/at-sign-handling-in-userinfo • <https://github.com/unshiftio/url-parse/commit/e4a5807d95b971577e4d888f5b99d64a40851386|`e4a5807`> 1.5.5 • <https://github.com/unshiftio/url-parse/commit/193b44baf3d203560735e05eedc99d8244c9e16c|`193b44b`> [minor] Simplify whitespace regex • <https://github.com/unshiftio/url-parse/commit/319851bf1c294796fc73e29ff31b14d9084e4a0d|`319851b`> [fix] Remove CR, HT, and LF • Additional commits viewable in <https://github.com/unshiftio/url-parse/compare/1.4.7...1.5.7|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

:white_check_mark: All checks have passed

github2 20:12:21

<https://github.com/cofacts/rumors-site/pull/476#issuecomment-1046004268|Comment on #476 Bump url-parse from 1.4.7 to 1.5.7>

<https://coveralls.io/builds/46705252|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/ff3c854ef0b87b97936a62b9c3bbb1a30c059185|ff3c854> on dependabot/npm_and_yarn/url-parse-1.5.7* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

github2 20:12:21

<https://github.com/cofacts/rumors-site/pull/476#issuecomment-1046004268|Comment on #476 Bump url-parse from 1.4.7 to 1.5.7>

<https://coveralls.io/builds/46705252|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/ff3c854ef0b87b97936a62b9c3bbb1a30c059185|ff3c854> on dependabot/npm_and_yarn/url-parse-1.5.7* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

2022-02-21

github2 13:57:19

<https://github.com/cofacts/rumors-line-bot/pull/297#issuecomment-1046499956|Comment on #297 Add API that monitors queue status>

On localhost, `src/graphql/__tests__/queue.js` runs first, and `src/webhook/__tests__/index.js` silently fails with the following error: ``` console.error src/webhook/handlers/groupHandler.js:107 TypeError: Cannot read properties of undefined (reading 'timestamp') at _default.processJob (/Users/johnsonliang/workspace/rumors-line-bot/src/webhook/handlers/groupHandler.js:53:47) at processTicksAndRejections (node:internal/process/task_queues:96:5) ``` On github actions, `src/webhook/__tests__/index.js` runs first without this error, and there is open handles left after test.

github2 13:57:19

<https://github.com/cofacts/rumors-line-bot/pull/297#issuecomment-1046499956|Comment on #297 Add API that monitors queue status>

On localhost, `src/graphql/__tests__/queue.js` runs first, and `src/webhook/__tests__/index.js` silently fails with the following error: ``` console.error src/webhook/handlers/groupHandler.js:107 TypeError: Cannot read properties of undefined (reading 'timestamp') at _default.processJob (/Users/johnsonliang/workspace/rumors-line-bot/src/webhook/handlers/groupHandler.js:53:47) at processTicksAndRejections (node:internal/process/task_queues:96:5) ``` In `groupHandler:53`, it is trying to read `job.data.otherFields.timestamp`. However, `job.data` is actually `{ foo: 'bar' }`, the fixture inserted in `returns waiting job info`. On github actions, `src/webhook/__tests__/index.js` runs first without this error, and there is open handles left after test.

github2 14:11:09

<https://github.com/cofacts/rumors-line-bot/pull/297#issuecomment-1046507884|Comment on #297 Add API that monitors queue status>

If `src/webhook/__tests__/index.js` happened to run before `src/graphql/__tests__/queue.js` on localhost, there will be snapshot error: ``` ● returns waiting job info expect(received).toMatchInlineSnapshot(snapshot) Snapshot name: `returns waiting job info 1` - Snapshot + Received Object { "data": Object { "queue": Array [ Object { "jobCounts": Object { - "waiting": 1, + "waiting": 0, }, - "lastWaitingAt": 1989-06-04T00:00:00.000Z, + "lastWaitingAt": null, "queueName": "groupEventQueue", }, Object { "jobCounts": Object { - "waiting": 1, + "waiting": 0, }, - "lastWaitingAt": 1989-06-04T00:00:00.000Z, + "lastWaitingAt": null, "queueName": "expiredGroupEventQueue", }, ], }, } 88 | MockDate.reset(); 89 | &gt; 90 | expect(resultQueued).toMatchInlineSnapshot(` | ^ 91 | Object { 92 | "data": Object { 93 | "queue": Array [ at Object.&lt;anonymous&gt; (src/graphql/__tests__/queue.js:90:24) at processTicksAndRejections (node:internal/process/task_queues:96:5) ``` Seems that the processor attached in `src/webhook/__tests__/index` kicks in.

github2 14:11:09

<https://github.com/cofacts/rumors-line-bot/pull/297#issuecomment-1046507884|Comment on #297 Add API that monitors queue status>

If `src/webhook/__tests__/index.js` happened to run before `src/graphql/__tests__/queue.js` on localhost, there will be snapshot error: ``` ● returns waiting job info expect(received).toMatchInlineSnapshot(snapshot) Snapshot name: `returns waiting job info 1` - Snapshot + Received Object { "data": Object { "queue": Array [ Object { "jobCounts": Object { - "waiting": 1, + "waiting": 0, }, - "lastWaitingAt": 1989-06-04T00:00:00.000Z, + "lastWaitingAt": null, "queueName": "groupEventQueue", }, Object { "jobCounts": Object { - "waiting": 1, + "waiting": 0, }, - "lastWaitingAt": 1989-06-04T00:00:00.000Z, + "lastWaitingAt": null, "queueName": "expiredGroupEventQueue", }, ], }, } 88 | MockDate.reset(); 89 | &gt; 90 | expect(resultQueued).toMatchInlineSnapshot(` | ^ 91 | Object { 92 | "data": Object { 93 | "queue": Array [ at Object.&lt;anonymous&gt; (src/graphql/__tests__/queue.js:90:24) at processTicksAndRejections (node:internal/process/task_queues:96:5) ``` Seems that the processor attached in `src/webhook/__tests__/index` kicks in.

2022-02-22

2022-02-23

github2 04:19:13

<https://github.com/cofacts/rumors-line-bot/pull/297#issuecomment-1048177540|Comment on #297 Add API that monitors queue status>

*Pull Request Test Coverage Report for <https://coveralls.io/builds/46779197|Build 1883147809>* • *13* of *14* *(92.86%)* changed or added relevant lines in *5* files are covered. • No unchanged relevant lines lost coverage. • Overall coverage increased (+*0.03%*) to *87.365%* * * * * * * *:yellow_heart: - <https://coveralls.io|Coveralls>*

test 終於 pass 了 😭
github2 04:19:13

<https://github.com/cofacts/rumors-line-bot/pull/297#issuecomment-1048177540|Comment on #297 Add API that monitors queue status>

*Pull Request Test Coverage Report for <https://coveralls.io/builds/46779197|Build 1883147809>* • *13* of *14* *(92.86%)* changed or added relevant lines in *5* files are covered. • No unchanged relevant lines lost coverage. • Overall coverage increased (+*0.03%*) to *87.365%* * * * * * * *:yellow_heart: - <https://coveralls.io|Coveralls>*

test 終於 pass 了 😭
mrorz 08:55:15
test 終於 pass 了 😭
💪 1 🎉 1
github2 20:25:08

<https://github.com/cofacts/rumors-line-bot/issues/260#issuecomment-1048730162|Comment on #260 "Missing process handler for job type __default__" when JOBQUEUE_CONCURRENCY is set>

<https://github.com/MrOrz|@MrOrz> , i do not have any unnamed processor but i'm still getting the error in my logs. `(GLOBAL) on queue failed: job 99 - with job name : __default__ -&gt; HAS FAILED: Missing process handler for job type __default__`

github2 20:25:08

<https://github.com/cofacts/rumors-line-bot/issues/260#issuecomment-1048730162|Comment on #260 "Missing process handler for job type __default__" when JOBQUEUE_CONCURRENCY is set>

<https://github.com/MrOrz|@MrOrz> , i do not have any unnamed processor but i'm still getting the error in my logs. `(GLOBAL) on queue failed: job 99 - with job name : __default__ -&gt; HAS FAILED: Missing process handler for job type __default__`

2022-02-24

4000 11:57:36
我被前陣子很活躍的詐騙集團告了✌️😆
Screenshot_20220223-195854~2.png
3
kidstarkenny 11:58:48
我怎麼覺得有點帥
kidstarkenny 11:58:48
我怎麼覺得有點帥
cai 12:52:24
為什麼你是留本名啦XD
cai 12:52:24
為什麼你是留本名啦XD
4000 12:59:02
因為我的賴就已經是本名了沒有留不留的問題😄
4000 12:59:02
因為我的賴就已經是本名了沒有留不留的問題😄
mrorz 13:51:17
委託方是什麼 XDDDD
mrorz 13:51:17
委託方是什麼 XDDDD
mrorz 13:52:17
在當地法院開庭好貼心ㄛ
我們寫合約什麼的都約台北地方法院 XD
背後的原因令人暖心🥰
mrorz 13:52:17
在當地法院開庭好貼心ㄛ
我們寫合約什麼的都約台北地方法院 XD
背後的原因令人暖心🥰
mrorz 13:52:50
話說為什麼對方有你的 LINE 呀
mrorz 13:52:50
話說為什麼對方有你的 LINE 呀
cai 13:58:13
突然發現他發過來的是簡訊欸
cai 13:58:13
突然發現他發過來的是簡訊欸
4000 13:58:17
因為我主動找對方玩🤣
😂 1
4000 13:58:17
因為我主動找對方玩🤣
ronnywang 13:59:00
錯字好多,感覺是找人裝律師事務所嚇人 XD
ronnywang 13:59:00
錯字好多,感覺是找人裝律師事務所嚇人 XD
4000 13:59:32
1645682354820.jpg
😆 3 👍 1
cai 14:01:17
這是盜誰的形象照啊?
cai 14:01:17
這是盜誰的形象照啊?
ronnywang 14:01:32
這個號碼有很多類似的簡訊
👍 3
ronnywang 14:01:32
這個號碼有很多類似的簡訊
ronnywang 14:02:58
一邊用簡訊嚇你,另一邊跟你談和解方式
ronnywang 14:02:58
一邊用簡訊嚇你,另一邊跟你談和解方式
ronnywang 14:04:31
有空有閒的話可以跟他繼續下去,然後想辦法問出他的匯款帳號,匯個1元去然後報警凍結帳號,現在他們取得一個人頭帳號的平均成本應該都 3000 起跳
1 1
ronnywang 14:04:31
有空有閒的話可以跟他繼續下去,然後想辦法問出他的匯款帳號,匯個1元去然後報警凍結帳號,現在他們取得一個人頭帳號的平均成本應該都 3000 起跳
4000 14:05:16
好喔
4000 14:05:16
好喔
4000 14:06:53
過程中唯一比較意外的是,她剛開始看我沒有讀居然主動通話
4000 14:06:53
過程中唯一比較意外的是,她剛開始看我沒有讀居然主動通話
Analeigh 15:27:44
@analeigh.jothon has joined the channel
cai 19:41:39
https://tfc-taiwan.org.tw/articles/6971
cofacts 資料庫再度起作用 😆

https://cofacts.tw/article/1kulpb3tqgw9
https://cofacts.tw/article/2c4psz2jcyb7w
網頁瀏覽次數有上升,也有人問

台灣事實查核中心

【錯誤】網傳「彰化市的三民市場、大台中五金百貨彰新店、建國陸橋的楓康超市、金馬路的全國電子,這暫子先不要去」?

【報告將隨時更新 2022/2/24版】 一、經查,此資訊為兩年前曾流傳過的舊訊息,彰化近期並無本土案例。 二、彰化縣政府表示,若有最新確診者足跡會公告在網站上,疫調足跡會標示確診者在公共場所出入的日期、時間區段、地點及地址等資訊。 傳言為過時的訊息,與近期現況並不相符合,因此,為「錯誤」訊息。

1
cai 19:41:39
https://tfc-taiwan.org.tw/articles/6971
cofacts 資料庫再度起作用 😆

https://cofacts.tw/article/1kulpb3tqgw9
https://cofacts.tw/article/2c4psz2jcyb7w
網頁瀏覽次數有上升,也有人問

2022-02-26

github2 10:12:01

<https://github.com/cofacts/rumors-fb-bot/pull/31|#31 Bump urijs from 1.19.1 to 1.19.8>

Bumps <https://github.com/medialize/URI.js|urijs> from 1.19.1 to 1.19.8. Release notes _Sourced from <https://github.com/medialize/URI.js/releases|urijs's releases>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) &gt; &gt; *1.19.6 (February 13th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to rewrite `\` in scheme delimiter to `/` as Node and Browsers do - disclosed privately by <https://twitter.com/ynizry|Yaniv Nizry> from the CxSCA AppSec team at Checkmarx &gt; &gt; *1.19.5 (December 30th 2020)* &gt; &gt; • dropping jquery.URI.js from minified bundle accidentally added since v1.19.3 - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/404|#404>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/404|medialize/URI.js#404>) &gt; &gt; *1.19.4 (December 23rd 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - followed up to by <https://github.com/alesandroortiz|alesandroortiz> in [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/403|#403>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/403|medialize/URI.js#403>), relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.3 (December 20th 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - disclosed privately by <https://github.com/alesandroortiz|alesandroortiz>, relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.2 (October 20th 2019)* &gt; &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-build|`URI.build()`> to properly handle relative paths when a scheme is given - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/387|#387>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/387|medialize/URI.js#387>) &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-buildQuery|`URI.buildQuery()`> to properly handle empty param name - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/243|#243>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/243|medialize/URI.js#243>), [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/383|#383>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/383|medialize/URI.js#383>) &gt; • support Composer [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/386|#386>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/386|medialize/URI.js#386>) Changelog _Sourced from <https://github.com/medialize/URI.js/blob/gh-pages/CHANGELOG.md|urijs's changelog>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) &gt; &gt; *1.19.6 (February 13th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to rewrite `\` in scheme delimiter to `/` as Node and Browsers do - disclosed privately by <https://twitter.com/ynizry|Yaniv Nizry> from the CxSCA AppSec team at Checkmarx &gt; &gt; *1.19.5 (December 30th 2020)* &gt; &gt; • dropping jquery.URI.js from minified bundle accidentally added since v1.19.3 - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/404|#404>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/404|medialize/URI.js#404>) &gt; &gt; *1.19.4 (December 23rd 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - followed up to by <https://github.com/alesandroortiz|alesandroortiz> in [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/403|#403>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/403|medialize/URI.js#403>), relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.3 (December 20th 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - disclosed privately by <https://github.com/alesandroortiz|alesandroortiz>, relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.2 (October 20th 2019)* &gt; &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-build|`URI.build()`> to properly handle relative paths when a scheme is given - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/387|#387>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/387|medialize/URI.js#387>) &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-buildQuery|`URI.buildQuery()`> to properly handle empty param name - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/243|#243>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/243|medialize/URI.js#243>), [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/383|#383>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/383|medialize/URI.js#383>) &gt; • support Composer [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/386|#386>](<https://github-red…

github2 10:12:01

<https://github.com/cofacts/rumors-fb-bot/pull/31|#31 Bump urijs from 1.19.1 to 1.19.8>

Bumps <https://github.com/medialize/URI.js|urijs> from 1.19.1 to 1.19.8. Release notes _Sourced from <https://github.com/medialize/URI.js/releases|urijs's releases>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) &gt; &gt; *1.19.6 (February 13th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to rewrite `\` in scheme delimiter to `/` as Node and Browsers do - disclosed privately by <https://twitter.com/ynizry|Yaniv Nizry> from the CxSCA AppSec team at Checkmarx &gt; &gt; *1.19.5 (December 30th 2020)* &gt; &gt; • dropping jquery.URI.js from minified bundle accidentally added since v1.19.3 - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/404|#404>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/404|medialize/URI.js#404>) &gt; &gt; *1.19.4 (December 23rd 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - followed up to by <https://github.com/alesandroortiz|alesandroortiz> in [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/403|#403>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/403|medialize/URI.js#403>), relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.3 (December 20th 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - disclosed privately by <https://github.com/alesandroortiz|alesandroortiz>, relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.2 (October 20th 2019)* &gt; &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-build|`URI.build()`> to properly handle relative paths when a scheme is given - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/387|#387>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/387|medialize/URI.js#387>) &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-buildQuery|`URI.buildQuery()`> to properly handle empty param name - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/243|#243>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/243|medialize/URI.js#243>), [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/383|#383>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/383|medialize/URI.js#383>) &gt; • support Composer [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/386|#386>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/386|medialize/URI.js#386>) Changelog _Sourced from <https://github.com/medialize/URI.js/blob/gh-pages/CHANGELOG.md|urijs's changelog>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) &gt; &gt; *1.19.6 (February 13th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to rewrite `\` in scheme delimiter to `/` as Node and Browsers do - disclosed privately by <https://twitter.com/ynizry|Yaniv Nizry> from the CxSCA AppSec team at Checkmarx &gt; &gt; *1.19.5 (December 30th 2020)* &gt; &gt; • dropping jquery.URI.js from minified bundle accidentally added since v1.19.3 - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/404|#404>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/404|medialize/URI.js#404>) &gt; &gt; *1.19.4 (December 23rd 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - followed up to by <https://github.com/alesandroortiz|alesandroortiz> in [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/403|#403>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/403|medialize/URI.js#403>), relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.3 (December 20th 2020)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseAuthority|`URI.parseAuthority()`> to rewrite `\` to `/` as Node and Browsers do - disclosed privately by <https://github.com/alesandroortiz|alesandroortiz>, relates to [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/233|#233>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/233|medialize/URI.js#233>) &gt; &gt; *1.19.2 (October 20th 2019)* &gt; &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-build|`URI.build()`> to properly handle relative paths when a scheme is given - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/387|#387>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/387|medialize/URI.js#387>) &gt; • fixing <http://medialize.github.io/URI.js/docs.html#static-buildQuery|`URI.buildQuery()`> to properly handle empty param name - [Issue <https://github-redirect.dependabot.com/medialize/URI.js/issues/243|#243>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/243|medialize/URI.js#243>), [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/383|#383>](<https://github-redirect.dependabot.com/medialize/URI.js/issues/383|medialize/URI.js#383>) &gt; • support Composer [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/386|#386>](<https://github-red…

github2 10:54:56

<https://github.com/cofacts/rumors-site/pull/477|#477 Bump urijs from 1.19.6 to 1.19.8>

Bumps <https://github.com/medialize/URI.js|urijs> from 1.19.6 to 1.19.8. Release notes _Sourced from <https://github.com/medialize/URI.js/releases|urijs's releases>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) Changelog _Sourced from <https://github.com/medialize/URI.js/blob/gh-pages/CHANGELOG.md|urijs's changelog>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) Commits • <https://github.com/medialize/URI.js/commit/efae1e56bd80d78478ffb8bcb8a75ee2c0f1031b|`efae1e5`> chore(build): bumping to version 1.19.8 • <https://github.com/medialize/URI.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f|`6ea641c`> fix(parse): case insensitive scheme - <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412> • <https://github.com/medialize/URI.js/commit/19e54c78d5864aec43986e8f96be8d15998daa80|`19e54c7`> chore(build): bumping to version 1.19.7 • <https://github.com/medialize/URI.js/commit/547d4b69d45d435eed88b04ec0a74cc8080c8694|`547d4b6`> build: update jquery • <https://github.com/medialize/URI.js/commit/aab4a43e0c0cab5bde140edcb73d29f77365ad02|`aab4a43`> build: remove obsolete build tools • <https://github.com/medialize/URI.js/commit/ac43ca8f80c042f0256fb551ea5203863dec4481|`ac43ca8`> fix(parse): more backslash galore <https://github-redirect.dependabot.com/medialize/URI.js/issues/410|#410> • <https://github.com/medialize/URI.js/commit/622db6d8d6e650d6de4300c97779de50e3331095|`622db6d`> docs: add security policy • <https://github.com/medialize/URI.js/commit/8e51b00911ba0f6e90949e2c4516b945c35021f7|`8e51b00`> fix(parse): prevent overwriting *proto* in parseQuery() • See full diff in <https://github.com/medialize/URI.js/compare/v1.19.6...v1.19.8|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

:white_check_mark: All checks have passed

github2 10:54:56

<https://github.com/cofacts/rumors-site/pull/477|#477 Bump urijs from 1.19.6 to 1.19.8>

Bumps <https://github.com/medialize/URI.js|urijs> from 1.19.6 to 1.19.8. Release notes _Sourced from <https://github.com/medialize/URI.js/releases|urijs's releases>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) Changelog _Sourced from <https://github.com/medialize/URI.js/blob/gh-pages/CHANGELOG.md|urijs's changelog>._ &gt; *1.19.8 (February 15th 2022)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> treat scheme case-insenstivie when handling excessive slackes and backslashes - [PR <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412>](<https://github-redirect.dependabot.com/medialize/URI.js/pull/412|medialize/URI.js#412>) by <https://github.com/r0hanSH|r0hanSH> &gt; &gt; *1.19.7 (July 14th 2021)* &gt; &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parseQuery|`URI.parseQuery()`> to prevent overwriting `__proto__` in parseQuery() - disclosed privately by <https://github.com/NewEraCracker|`@​NewEraCracker`> &gt; • *SECURITY* fixing <http://medialize.github.io/URI.js/docs.html#static-parse|`URI.parse()`> to handle variable amounts of `\` and `/` in scheme delimiter as Node and Browsers do - disclosed privately by <https://github.com/ready-research|ready-research> via <https://huntr.dev/|https://huntr.dev/> &gt; • removed obsolete build tools &gt; • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0) Commits • <https://github.com/medialize/URI.js/commit/efae1e56bd80d78478ffb8bcb8a75ee2c0f1031b|`efae1e5`> chore(build): bumping to version 1.19.8 • <https://github.com/medialize/URI.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f|`6ea641c`> fix(parse): case insensitive scheme - <https://github-redirect.dependabot.com/medialize/URI.js/issues/412|#412> • <https://github.com/medialize/URI.js/commit/19e54c78d5864aec43986e8f96be8d15998daa80|`19e54c7`> chore(build): bumping to version 1.19.7 • <https://github.com/medialize/URI.js/commit/547d4b69d45d435eed88b04ec0a74cc8080c8694|`547d4b6`> build: update jquery • <https://github.com/medialize/URI.js/commit/aab4a43e0c0cab5bde140edcb73d29f77365ad02|`aab4a43`> build: remove obsolete build tools • <https://github.com/medialize/URI.js/commit/ac43ca8f80c042f0256fb551ea5203863dec4481|`ac43ca8`> fix(parse): more backslash galore <https://github-redirect.dependabot.com/medialize/URI.js/issues/410|#410> • <https://github.com/medialize/URI.js/commit/622db6d8d6e650d6de4300c97779de50e3331095|`622db6d`> docs: add security policy • <https://github.com/medialize/URI.js/commit/8e51b00911ba0f6e90949e2c4516b945c35021f7|`8e51b00`> fix(parse): prevent overwriting *proto* in parseQuery() • See full diff in <https://github.com/medialize/URI.js/compare/v1.19.6...v1.19.8|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

github2 10:57:31

<https://github.com/cofacts/rumors-site/pull/477#issuecomment-1051509933|Comment on #477 Bump urijs from 1.19.6 to 1.19.8>

<https://coveralls.io/builds/46902174|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/0d7f4ca053f82ea1d0fa5ba62454ebc5deb9592e|0d7f4ca> on dependabot/npm_and_yarn/urijs-1.19.8* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

github2 10:57:31

<https://github.com/cofacts/rumors-site/pull/477#issuecomment-1051509933|Comment on #477 Bump urijs from 1.19.6 to 1.19.8>

<https://coveralls.io/builds/46902174|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/0d7f4ca053f82ea1d0fa5ba62454ebc5deb9592e|0d7f4ca> on dependabot/npm_and_yarn/urijs-1.19.8* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

cai 13:36:06
筆記 日本食品代號的
* 食藥署專區,有說明怎麼看 https://www.fda.gov.tw/TC/site.aspx?sid=4341&r=1305042548
* 全聯公告 https://www.pxmart.com.tw/#/news/82?newsTpye=2
cai 13:36:06
筆記 日本食品代號的
• 食藥署專區,有說明怎麼看 https://www.fda.gov.tw/TC/site.aspx?sid=4341&r=1305042548
• 全聯公告 https://www.pxmart.com.tw/#/news/82?newsTpye=2

fda.gov.tw

衛生福利部食品藥物管理署

衛生福利部食品藥物管理署

pxmart.com.tw

來全聯 買進美好生活

提供您更即時、更迅速的購物環境,讓您隨時隨地都能省!

2022-02-27

cai 01:32:54
https://cofacts.tw/article/24l90fe3dtu8f
開頭:台南市新營區 台灣人民共產黨(最近被拆廟的)
旗子寫76週年 那大概是2021?
但是大遊行好像是75週年?
新營小北是2020/1 開幕所以確定時間在之後
https://www.chinatimes.com/newspapers/20201019000100-260302

中間有一段是統一促進黨的 https://tfc-taiwan.org.tw/articles/6471

後面那段有人講話的是應該是2019年5月去AIT抗議的,女生聲音好像有被重配音? 新聞有報的是4月份的,但影片有下雨大概是5月的 https://i.imgur.com/PGGRPMW.png
cai 01:32:54
https://cofacts.tw/article/24l90fe3dtu8f
開頭:台南市新營區 台灣人民共產黨(最近被拆廟的)
旗子寫76週年 那大概是2021?
但是大遊行好像是75週年?
新營小北是2020/1 開幕所以確定時間在之後
https://www.chinatimes.com/newspapers/20201019000100-260302

中間有一段是統一促進黨的 https://tfc-taiwan.org.tw/articles/6471

後面那段有人講話的是應該是2019年5月去AIT抗議的,女生聲音好像有被重配音? 新聞有報的是4月份的,但影片有下雨大概是5月的 https://i.imgur.com/PGGRPMW.png

中時新聞網

700人聚集台南 提前紀念光復75年 - 兩岸新聞

今年是台灣光復75周年,10月18日上午,約700多位來自全台各地的民眾,在台灣人民共產黨總理林德旺的號召下,群聚於台南市新營區太南里舊廍遊行,提前慶祝台灣光復節。與會民眾感念中國的先烈先賢浴血抗戰,最終打敗

台灣事實查核中心

【錯誤】網傳影片「2021年10月12日,台北民眾遊行,要求台灣與大陸統一。台灣媒體完全在綠媒控制下,這種消息是不會報導的」?

【報告將隨時更新 2021/10/20版】 網傳影片是中華統一促進黨在2017年10月1日的遊行活動,當時有多家媒體報導。且2021年10月12日台北車站附近並未有統促黨的遊行。 因此,傳言宣稱「2021年10月12日遊行」、「媒體不會報導」,為「錯誤」訊息。

👍 1

2022-02-28

cai 00:43:37
二次詐騙又出現了,兩個帳號刷好多篇
感謝回報 m(_ _)m
Takedown announcement 已經發出,請大家審閱
清潔溜溜囉 🧼
cai 00:43:37
二次詐騙又出現了,兩個帳號刷好多篇
感謝回報 m(_ _)m
Takedown announcement 已經發出,請大家審閱
清潔溜溜囉 🧼
github2 06:56:28

<https://github.com/cofacts/rumors-site/pull/478|#478 Bump url-parse from 1.4.7 to 1.5.10>

Bumps <https://github.com/unshiftio/url-parse|url-parse> from 1.4.7 to 1.5.10. Commits • <https://github.com/unshiftio/url-parse/commit/8cd4c6c6435c1ea32243ec20c9cfe535251ec524|`8cd4c6c`> 1.5.10 • <https://github.com/unshiftio/url-parse/commit/ce7a01f2e10738b17812f57c7b6b5de4ea4c0298|`ce7a01f`> [fix] Improve handling of empty port • <https://github.com/unshiftio/url-parse/commit/00714900ea1e8ba0a1f87b9f8399001e47f060ec|`0071490`> [doc] Update JSDoc comment • <https://github.com/unshiftio/url-parse/commit/a7044e3e8bb2308ac0f74264d01951aeaca0d66f|`a7044e3`> [minor] Use more descriptive variable name • <https://github.com/unshiftio/url-parse/commit/d547792414a414b2f341a805141beafee728addf|`d547792`> [security] Add credits for <https://github.com/advisories/GHSA-jf5r-8hm2-f872|CVE-2022-0691> • <https://github.com/unshiftio/url-parse/commit/ad23357ad5fd9a6b011d049466e9ecff723e52b8|`ad23357`> 1.5.9 • <https://github.com/unshiftio/url-parse/commit/0e3fb542d60ddbf6933f22eb9b1e06e25eaa5b63|`0e3fb54`> [fix] Strip all control characters from the beginning of the URL • <https://github.com/unshiftio/url-parse/commit/61864a8eccff714a45d23db85a814e3c6ee0baba|`61864a8`> [security] Add credits for <https://github.com/advisories/GHSA-hgjh-723h-mx2j|CVE-2022-0686> • <https://github.com/unshiftio/url-parse/commit/bb0104d6439cf7c2662afbd9411e0772a9639664|`bb0104d`> 1.5.8 • <https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5|`d5c6479`> [fix] Handle the case where the port is specified but empty • Additional commits viewable in <https://github.com/unshiftio/url-parse/compare/1.4.7...1.5.10|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

:white_check_mark: All checks have passed

github2 06:56:28

<https://github.com/cofacts/rumors-site/pull/478|#478 Bump url-parse from 1.4.7 to 1.5.10>

Bumps <https://github.com/unshiftio/url-parse|url-parse> from 1.4.7 to 1.5.10. Commits • <https://github.com/unshiftio/url-parse/commit/8cd4c6c6435c1ea32243ec20c9cfe535251ec524|`8cd4c6c`> 1.5.10 • <https://github.com/unshiftio/url-parse/commit/ce7a01f2e10738b17812f57c7b6b5de4ea4c0298|`ce7a01f`> [fix] Improve handling of empty port • <https://github.com/unshiftio/url-parse/commit/00714900ea1e8ba0a1f87b9f8399001e47f060ec|`0071490`> [doc] Update JSDoc comment • <https://github.com/unshiftio/url-parse/commit/a7044e3e8bb2308ac0f74264d01951aeaca0d66f|`a7044e3`> [minor] Use more descriptive variable name • <https://github.com/unshiftio/url-parse/commit/d547792414a414b2f341a805141beafee728addf|`d547792`> [security] Add credits for <https://github.com/advisories/GHSA-jf5r-8hm2-f872|CVE-2022-0691> • <https://github.com/unshiftio/url-parse/commit/ad23357ad5fd9a6b011d049466e9ecff723e52b8|`ad23357`> 1.5.9 • <https://github.com/unshiftio/url-parse/commit/0e3fb542d60ddbf6933f22eb9b1e06e25eaa5b63|`0e3fb54`> [fix] Strip all control characters from the beginning of the URL • <https://github.com/unshiftio/url-parse/commit/61864a8eccff714a45d23db85a814e3c6ee0baba|`61864a8`> [security] Add credits for <https://github.com/advisories/GHSA-hgjh-723h-mx2j|CVE-2022-0686> • <https://github.com/unshiftio/url-parse/commit/bb0104d6439cf7c2662afbd9411e0772a9639664|`bb0104d`> 1.5.8 • <https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5|`d5c6479`> [fix] Handle the case where the port is specified but empty • Additional commits viewable in <https://github.com/unshiftio/url-parse/compare/1.4.7...1.5.10|compare view> <https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores|Dependabot compatibility score> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. * * * Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: • `@dependabot rebase` will rebase this PR • `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it • `@dependabot merge` will merge this PR after your CI passes on it • `@dependabot squash and merge` will squash and merge this PR after your CI passes on it • `@dependabot cancel merge` will cancel a previously requested merge and block automerging • `@dependabot reopen` will reopen this PR if it is closed • `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually • `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) • `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) • `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language • `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language • `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language • `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the <https://github.com/cofacts/rumors-site/network/alerts|Security Alerts page>.

github2 06:58:40

<https://github.com/cofacts/rumors-site/pull/478#issuecomment-1053711411|Comment on #478 Bump url-parse from 1.4.7 to 1.5.10>

<https://coveralls.io/builds/46914742|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/baf202989e42f1ede4325c0bac35db78606c634b|baf2029> on dependabot/npm_and_yarn/url-parse-1.5.10* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

github2 06:58:40

<https://github.com/cofacts/rumors-site/pull/478#issuecomment-1053711411|Comment on #478 Bump url-parse from 1.4.7 to 1.5.10>

<https://coveralls.io/builds/46914742|Coverage Status> Coverage remained the same at 73.942% when pulling *<https://github.com/cofacts/rumors-site/commit/baf202989e42f1ede4325c0bac35db78606c634b|baf2029> on dependabot/npm_and_yarn/url-parse-1.5.10* into *<https://github.com/cofacts/rumors-site/commit/61c7e77da047d69bc2173c456ca0ca4a69be5d78|61c7e77> on master*.

mrorz 16:58:26
感謝回報 m(_ _)m
Takedown announcement 已經發出,請大家審閱
mrorz 17:03:19
清潔溜溜囉 🧼
cai 17:53:40
https://fb.watch/bslfaLu8vP/

Facebook Watch

新竹市 新鮮事 - 媒體素養力UP-第三招 | Facebook

#查證小工具 #別讓關心變傷害 平常看到好康或妙招,是不是想趕快分享給家人好友呢?不過你可有想過,這些隨手轉傳的資訊真的正確嗎?其實只要在收到訊息時,先查證,小小一步就能減少錯誤訊息的擴散。 一起透過小華一家的故事,認識這些查證小工具吧!

1
cai 23:37:49
https://tfc-taiwan.org.tw/articles/6988
https://twitter.com/hashtag/UkraineFacts
烏俄相關的查核文章 hashtag

台灣事實查核中心

【查證最新動態】烏俄戰爭的查證訊息

twitter.com

#UkraineFacts hashtag on Twitter

On Feb 24 @ctardaguila tweeted: "140 falsehoods about the #RussiaUkraineC.." - read what others are saying and join the conversation.

1 🙌 1