build: bump the security-updates group across 1 directory with 8 updates #1654
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the security-updates group with 8 updates in the / directory:
1.7.4
1.8.2
8.18.0
8.18.1
5.76.1
5.94.0
7.25.0
7.28.4
1.0.4
1.0.6
6.5.7
6.6.1
2.4.11
2.4.12
1.1075.0
1.1299.0
Updates
axios
from 1.7.4 to 1.8.2Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
a9f7689
chore(release): v1.8.2 (#6812)fb8eec2
fix(http-adapter): add allowAbsoluteUrls to path building (#6810)9812045
chore(sponsor): update sponsor block (#6804)72acf75
chore(sponsor): update sponsor block (#6794)2e64afd
chore(release): v1.8.1 (#6800)36a5a62
fix(utils): movegenerateString
to platform utils to avoid importing crypto...cceb7b1
chore(release): v1.8.0 (#6795)23a25af
fix(utils): replace getRandomValues with crypto module (#6788)32c7bcc
feat: Add config for ignoring absolute URLs (#5902) (#6192)4a3e26c
chore(config): adjust rollup config to preserve license header to minified Ja...Updates
ws
from 8.18.0 to 8.18.1Release notes
Sourced from ws's releases.
Commits
b92745a
[dist] 8.18.1b3d9747
[doc] Fix nit021f7b8
[test] Shorten the path lengthsb9ca55b
[pkg] Update eslint-config-prettier to version 10.0.1c798dd4
[doc] Fix typo (#2271)6861472
[ci] Test on node 23019f28f
[minor] Improve JSDoc-inferred types (#2242)bfe1b2a
[doc] Remove unnecessary period (#2240)f7dc469
[doc] Fix the type of thedata
argumentUpdates
webpack
from 5.76.1 to 5.94.0Release notes
Sourced from webpack's releases.
... (truncated)
Commits
eabf85d
chore(release): 5.94.0955e057
security: fix DOM clobbering in auto public path9822387
test: fixcbb86ed
test: fix5ac3d7f
fix: unexpected asi generation with sequence expression2411661
security: fix DOM clobbering in auto public pathb8c03d4
fix: unexpected asi generation with sequence expressionf46a03c
revert: do not use heuristic fallback for "module-import"60f1898
fix: do not use heuristic fallback for "module-import"66306aa
Revert "fix: module-import get fallback from externalsPresets"Updates
@babel/runtime
from 7.25.0 to 7.28.4Release notes
Sourced from
@babel/runtime
's releases.... (truncated)
Changelog
Sourced from
@babel/runtime
's changelog.... (truncated)
Commits
35055e3
v7.28.4ef155f5
v7.28.3cac0ff4
v7.28.2f68ac51
chore: Avoid CITGM errors (#17382)baa4cb8
v7.27.67d06930
v7.27.45b9468d
Reduceregenerator
size more (#17287)cb78b5b
[babel 8] Do not replace globalregeneratorRuntime
references in regenerato...a0690e3
SplitregeneratorRuntime
into multiple helpers (#17238)da5e371
v7.27.3Updates
cipher-base
from 1.0.4 to 1.0.6Changelog
Sourced from cipher-base's changelog.
Commits
f5249f9
v1.0.6b7ddd2a
[Fix] io.js 3.0 - Node.js 5.3 typed array supportf03cebf
v1.0.588dc806
[meta] addauto-changelog
7a137d7
[meta] addnpmignore
andsafe-publish-latest
5c02918
[meta] fix package.json indentation8fd1364
[Fix] return valid values on multi-byte-wide TypedArray input66387d7
[Tests] migrate from travis to GHAf2dc13e
[meta] add missingengines.node
0e7a2d9
[Deps] updateinherits
,safe-buffer
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for cipher-base since your current version.
Updates
elliptic
from 6.5.7 to 6.6.1Commits
9b77436
6.6.104cb6f5
Merge commit from forkb8a7edd
6.6.034c8534
fix: signature verification due to leading zerosUpdates
sha.js
from 2.4.11 to 2.4.12Changelog
Sourced from sha.js's changelog.
Commits
eb4ea2f
v2.4.12d8d77c0
[meta] reorder package.jsondf9d521
[eslint] fix package.json indentation35aec35
[meta] addnpmignore
d528896
[Dev Deps] add missing peer depb46e711
[meta] addauto-changelog
94ca724
[Dev Deps] remove unusedbuffer
dep2dbe0aa
[Dev Deps] update@ljharb/eslint-config
73e33ae
[Tests] avoid console logsf2a258e
[Fix] support multi-byte wide typed arraysMaintainer changes
This version was pushed to npm by ljharb, a new releaser for sha.js since your current version.
Updates
snyk
from 1.1075.0 to 1.1299.0Release notes
Sourced from snyk's releases.
... (truncated)
Commits
2c059ca
Merge pull request #6148 from snyk/dotkas/final-cherry-picks0046eaa
chore: skip sbom reachability user journey testce9a5fe
fix: Fix reduced configuration cache usage48a8b5c
chore(ci): update CICD experimental_cli_download_base_url parameter07f63bb
fix: upgrade to go 1.24.631a00fb
Merge pull request #6140 from snyk/dotkas/more-cherrypicksdecf770
fix: conforming the way we take precedence of auth config valuesacf2d67
Merge pull request #6129 from snyk/dotkas/cherry-picks-for-release-candidate24fee58
fix: fixing host auto-detection bug in snyk auth6a782d1
feat: add linux static experimental binaryDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.