-
Notifications
You must be signed in to change notification settings - Fork 38
Bump the npm_and_yarn group across 1 directory with 26 updates #183
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
master
Choose a base branch
from
dependabot/npm_and_yarn/npm_and_yarn-424669fe6d
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 25 updates in the / directory: | Package | From | To | | --- | --- | --- | | [jquery](https://github.com/jquery/jquery) | `3.1.1` | `3.5.0` | | [minimist](https://github.com/minimistjs/minimist) | `1.2.0` | `1.2.6` | | [node-fetch](https://github.com/node-fetch/node-fetch) | `1.6.3` | `2.6.7` | | [bl](https://github.com/rvagg/bl) | `1.2.0` | `1.2.3` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.6` | `1.1.11` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.0` | `4.2.3` | | [elliptic](https://github.com/indutny/elliptic) | `6.3.2` | `6.5.5` | | [es5-ext](https://github.com/medikoo/es5-ext) | `0.10.12` | `0.10.64` | | [extend](https://github.com/justmoon/node-extend) | `3.0.0` | `3.0.2` | | [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.13.0` | `1.15.6` | | [fsevents](https://github.com/fsevents/fsevents) | `1.0.17` | `1.2.13` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.0.6` | `4.7.8` | | [ini](https://github.com/npm/ini) | `1.3.4` | `1.3.8` | | [is-my-json-valid](https://github.com/mafintosh/is-my-json-valid) | `2.15.0` | `2.20.6` | | [is-url](https://github.com/segmentio/is-url) | `1.2.2` | `1.2.4` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.7.0` | `3.14.1` | | [lodash](https://github.com/lodash/lodash) | `4.17.4` | `4.17.21` | | [mime](https://github.com/broofa/mime) | `1.3.4` | `1.6.0` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.3` | `3.1.2` | | [moment](https://github.com/moment/moment) | `2.17.1` | `2.30.1` | | [set-getter](https://github.com/doowb/set-getter) | `0.1.0` | `0.1.1` | | [sshpk](https://github.com/joyent/node-sshpk) | `1.10.2` | `1.18.0` | | [stringstream](https://github.com/mhart/StringStream) | `0.0.5` | `0.0.6` | | [tree-kill](https://github.com/pkrumins/node-tree-kill) | `1.1.0` | `1.2.2` | | [websocket-extensions](https://github.com/faye/websocket-extensions-node) | `0.1.1` | `0.1.4` | Updates `jquery` from 3.1.1 to 3.5.0 - [Release notes](https://github.com/jquery/jquery/releases) - [Commits](jquery/jquery@3.1.1...3.5.0) Updates `minimist` from 1.2.0 to 1.2.6 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.0...v1.2.6) Updates `node-fetch` from 1.6.3 to 2.6.7 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v1.6.3...v2.6.7) Updates `bl` from 1.2.0 to 1.2.3 - [Release notes](https://github.com/rvagg/bl/releases) - [Changelog](https://github.com/rvagg/bl/blob/master/CHANGELOG.md) - [Commits](rvagg/bl@v1.2.0...v1.2.3) Updates `brace-expansion` from 1.1.6 to 1.1.11 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.6...1.1.11) Updates `browserify-sign` from 4.0.0 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.0...v4.2.3) Updates `elliptic` from 6.3.2 to 6.5.5 - [Commits](indutny/elliptic@v6.3.2...v6.5.5) Updates `es5-ext` from 0.10.12 to 0.10.64 - [Release notes](https://github.com/medikoo/es5-ext/releases) - [Changelog](https://github.com/medikoo/es5-ext/blob/main/CHANGELOG.md) - [Commits](medikoo/es5-ext@v0.10.12...v0.10.64) Updates `extend` from 3.0.0 to 3.0.2 - [Changelog](https://github.com/justmoon/node-extend/blob/main/CHANGELOG.md) - [Commits](justmoon/node-extend@v3.0.0...v3.0.2) Updates `follow-redirects` from 1.13.0 to 1.15.6 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.13.0...v1.15.6) Updates `fsevents` from 1.0.17 to 1.2.13 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.0.17...v1.2.13) Updates `handlebars` from 4.0.6 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.6...v4.7.8) Updates `ini` from 1.3.4 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.4...v1.3.8) Updates `is-my-json-valid` from 2.15.0 to 2.20.6 - [Commits](mafintosh/is-my-json-valid@v2.15.0...v2.20.6) Updates `is-url` from 1.2.2 to 1.2.4 - [Changelog](https://github.com/segmentio/is-url/blob/master/History.md) - [Commits](segmentio/is-url@v1.2.2...v1.2.4) Updates `js-yaml` from 3.7.0 to 3.14.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.7.0...3.14.1) Updates `jsonpointer` from 4.0.1 to 5.0.1 - [Release notes](https://github.com/janl/node-jsonpointer/releases) - [Commits](janl/node-jsonpointer@4.0.1...v5.0.1) Updates `lodash` from 4.17.4 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.4...4.17.21) Updates `mime` from 1.3.4 to 1.6.0 - [Changelog](https://github.com/broofa/mime/blob/v1.6.0/CHANGELOG.md) - [Commits](broofa/mime@v1.3.4...v1.6.0) Updates `minimatch` from 3.0.3 to 3.1.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.3...v3.1.2) Updates `moment` from 2.17.1 to 2.30.1 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.17.1...2.30.1) Updates `set-getter` from 0.1.0 to 0.1.1 - [Commits](https://github.com/doowb/set-getter/commits/0.1.1) Updates `sshpk` from 1.10.2 to 1.18.0 - [Release notes](https://github.com/joyent/node-sshpk/releases) - [Commits](https://github.com/joyent/node-sshpk/commits) Updates `stringstream` from 0.0.5 to 0.0.6 - [Commits](mhart/StringStream@v0.0.5...v0.0.6) Updates `tree-kill` from 1.1.0 to 1.2.2 - [Release notes](https://github.com/pkrumins/node-tree-kill/releases) - [Commits](pkrumins/node-tree-kill@v1.1.0...v1.2.2) Updates `websocket-extensions` from 0.1.1 to 0.1.4 - [Changelog](https://github.com/faye/websocket-extensions-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-extensions-node@0.1.1...0.1.4) --- updated-dependencies: - dependency-name: jquery dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: minimist dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: bl dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: elliptic dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: es5-ext dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: extend dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: is-my-json-valid dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: is-url dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jsonpointer dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: mime dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: moment dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: set-getter dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: sshpk dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: stringstream dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tree-kill dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: websocket-extensions dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
This was referenced Jun 10, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 25 updates in the / directory:
3.1.13.5.01.2.01.2.61.6.32.6.71.2.01.2.31.1.61.1.114.0.04.2.36.3.26.5.50.10.120.10.643.0.03.0.21.13.01.15.61.0.171.2.134.0.64.7.81.3.41.3.82.15.02.20.61.2.21.2.43.7.03.14.14.17.44.17.211.3.41.6.03.0.33.1.22.17.12.30.10.1.00.1.11.10.21.18.00.0.50.0.61.1.01.2.20.1.10.1.4Updates
jqueryfrom 3.1.1 to 3.5.0Release notes
Sourced from jquery's releases.
Commits
7a0a8503.5.08570a08Release: Update AUTHORS.txtda3dd85Ajax: Do not execute scripts for unsuccessful HTTP responses065143cAjax: Overwrite s.contentType with content-type header value, if any1a4f10dTests: Blacklist one focusin test in IE9e15d6bEvent: Use only one focusin/out handler per matching window & document966a709Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9Manipulation: Make jQuery.htmlPrefilter an identity function04bf577Selector: Update Sizzle from 2.3.4 to 2.3.57506c9cBuild: Resolve Travis config warningsMaintainer changes
This version was pushed to npm by mgol, a new releaser for jquery since your current version.
Updates
minimistfrom 1.2.0 to 1.2.6Changelog
Sourced from minimist's changelog.
Commits
7efb22a1.2.6ef88b93security notice for additional prototype pollution issuec2b9819isConstructorOrProto adapted from PRbc8eceetest from prototype pollution PRaeb3e271.2.5278677b1.2.44cf1354security notice1043d21additional test for constructor prototype pollution6457d741.2.338a4d1ceven more aggressive checks for protocol pollutionUpdates
node-fetchfrom 1.6.3 to 2.6.7Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
1ef4b56backport of #1449 (#1453)8fe5c4e2.x: Specify encoding as an optional peer dependency in package.json (#1310)f56b0c6fix(URL): prefer built in URL version when available and fallback to whatwg (...b5417aefix: import whatwg-url in a way compatible with ESM Node (#1303)18193c5fix v2.6.3 that did not sending query params (#1301)ace7536fix: properly encode url with unicode characters (#1291)152214cFix(package.json): Corrected main file path in package.json (#1274)b5e2e41update version number2358a6cHonor thesizeoption after following a redirect and revert data uri support8c197f8docs: Fix typos and grammatical errors in README.md (#686)Maintainer changes
This version was pushed to npm by endless, a new releaser for node-fetch since your current version.
Updates
blfrom 1.2.0 to 1.2.3Release notes
Sourced from bl's releases.
Commits
d69edfd1.2.3847473atest all branches0bd87ecFix unintialized memory accessdc097f3test newer versions of Nodefeaaa4cBumped v1.2.2.307da45Merge pull request #51 from rvagg/safe-buffeercf6b00eRemoved node 7 from .travis.yml4b8f524Added safe-buffer and updated dependencies4acbe24Merge pull request #45 from EdwardBetts/spelling52ed96ccorrect spelling mistakeUpdates
brace-expansionfrom 1.1.6 to 1.1.11Release notes
Sourced from brace-expansion's releases.
... (truncated)
Commits
e52ad1cMerge pull request #42 from juliangruber/greenkeeper/update-to-node-10fb4c692Update to node 10 in .travis.yml01a21de1.1.11d7c93eesponsors54a61761.1.10327c729Merge pull request #40 from Parcley/add-license-1b6ba2e0create LICENSE file0f82dab1.1.9acd1754support40ff02dMerge pull request #39 from EdwardBetts/spellingUpdates
browserify-signfrom 4.0.0 to 4.2.3Changelog
Sourced from browserify-sign's changelog.
... (truncated)
Commits
bf2c3ecv4.2.39247adf[patch] widen support to 0.12f427270[Deps] update `parse-asn187f3a35[Dev Deps] updateaud,npmignore,tapefb261ce[Deps] updateelliptic4d0ee49[patch] drop minimum node support to v19e2bf12[Deps] pinhash-baseto ~3.0, due to a breaking change168e16f[Deps] pinellipticdue to a breaking change37a4758[actions] remove redundant finisher4af5a90v4.2.2Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates
ellipticfrom 6.3.2 to 6.5.5Commits
75700786.5.5206da2elib: lint0a78e03[Fix] restore node < 4 compat43ac7f26.5.4f4bc72bpackage: bump deps441b742ec: validate that a point before deriving keyse71b2d9lib: relint using eslint8421a01build(deps): bump elliptic from 6.4.1 to 6.5.3 (#231)86478036.5.3856fe4dsignature: prevent malleability and overflowsUpdates
es5-extfrom 0.10.12 to 0.10.64Release notes
Sourced from es5-ext's releases.
... (truncated)
Changelog
Sourced from es5-ext's changelog.
... (truncated)
Commits
f76b03dchore: Release v0.10.642881acdchore: Bump dependenciesc2e2bb9fix: Revert update meant to fix Powershell issue, as it's a regression16f2b72docs: Fix date in the changelogde4e03cchore: Release v0.10.633fd53b7chore: Upgradelint-stagedto v13bf8ed79chore: Ensure postinstall script does not crash on Windows2cbbb07chore: Bump dependencies22d0416chore: Bump LICENSE yeara52e957fix: Support ES2015+ function definitions infunction#toStringTokens()Updates
extendfrom 3.0.0 to 3.0.2Changelog
Sourced from extend's changelog.
Commits
8d106d2v3.0.2e97091f[Dev Deps] updatetapee841aac[Tests] up tonodev10.70e68e71[Fix] Prevent merging proto propertya689700Only apps should have lockfilesf13c1c4[Dev Deps] updateeslint,@ljharb/eslint-config,tapef3570fe[Tests] up tonodev10.0,v9.11,v8.11,v7.10,v6.14,v4.9; use...138b515v3.0.17e19a6f[Tests] up tonodev7.9,v6.10,v4.8; improve matrix0191e27[Dev Deps] updatetape,eslint,@ljharb/eslint-configUpdates
follow-redirectsfrom 1.13.0 to 1.15.6Commits
35a517cRelease version 1.15.6 of the npm package.c4f847fDrop Proxy-Authorization across hosts.8526b4aUse GitHub for disclosure.b1677ceRelease version 1.15.5 of the npm package.d8914f7Preserve fragment in responseUrl.6585820Release version 1.15.4 of the npm package.7a6567eDisallow bracketed hostnames.05629afPrefer native URL instead of deprecated url.parse.1cba8e8Prefer native URL instead of legacy url.resolve.72bc2a4Simplify _processResponse error handling.Updates
fseventsfrom 1.0.17 to 1.2.13Release notes
Sourced from fsevents's releases.
... (truncated)
Commits
844a05dVersion Bumpf393f2aOnly build fsevents on macOS (#322)6a281a7[publish binary]acc2bce[publish binary]f532b6e[publish binary]4c6a1c0Add node 13 to travis matrix.92e40aaRelease 1.2.12.909af26Release v1.2.117074adbRelease v1.2.100a052f6Node.js v12 support for v1.x (#274)Updates
handlebarsfrom 4.0.6 to 4.7.8Release notes
Sourced from handlebars's releases.
Changelog
Sourced from handlebars's changelog.
... (truncated)
Commits
8dc3d25v4.7.8668c4fbFix browser tests in CI pipelinec65c6ccTest on Node 183d3796cMake library compatible with workers075b354Fix sync issue with npm lock-file30dbf04Fix compiling of each block params in strict modee3a5448Fix bundler issue with webpack 58e23642Fix integration-tests issue with npm >= 788ac068use https instead of git for mustache submodulec68bc08Fix typoMaintainer changes
This version was pushed to npm by jaylinski, a new releaser for handlebars since your current version.
Updates
inifrom 1.3.4 to 1.3.8Commits
a2c5da81.3.8af5c6bbDo not use Object.create(null)8b648a1don't test where our devdeps don't even workc74c8af1.3.7024b8b5update deps, add linting032fbafUse Object.create(null) to avoid default object property hazards2da90391.3.6cfea636better git push script, before publish instead of after56d2805do not allow invalid hazardous string as section name738eca5v1.3.5Maintainer changes
This version was pushed to npm by isaacs, a new releaser for ini since your current version.
Updates
is-my-json-validfrom 2.15.0 to 2.20.6Commits
58d30cb2.20.6f76edf0Merge pull request #188 from axelniklasson/master4eef089Upgrade jsonpointer to address security vulnerability441f8122.20.5d36a1b1Merge pull request #182 from ChALkeR/chalker/fix-commab6ea484Fix uri prefix detection5389c5bMerge pull request #181 from ChALkeR/chalker/fix-undefdf5b313add funding filec224619Fix 'required' implementation2534af42.20.4Maintainer changes
This version was pushed to npm by linusu, a new releaser for is-my-json-valid since your current version.
Updates
is-urlfrom 1.2.2 to 1.2.4Commits
d2048281.2.4a524d7fMerge pull request #20 from davisjam/FixUndefb33cac4handle undefined string8585facMerge pull request #23 from segmentio/fix-testse572e5dadd travis confige1c30e1remove cruft and fix the test scriptf1c83cf1.2.355ee8eeMerge pull request #18 from davisjam/FixREDOS1495509security: Fix REDOS vulnerabilityUpdates
js-yamlfrom 3.7.0 to 3.14.1Changelog
Sourced from js-yaml's changelog.