forked from microsoft/pxt
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group across 1 directories with 23 updates #1
Closed
dependabot
wants to merge
1
commit into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-b83d974fcd
Closed
Bump the npm_and_yarn group across 1 directories with 23 updates #1
dependabot
wants to merge
1
commit into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-b83d974fcd
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 18 updates in the /. directory: | Package | From | To | | --- | --- | --- | | [marked](https://github.com/markedjs/marked) | `0.3.19` | `4.0.10` | | [request](https://github.com/request/request) | `2.85.0` | `2.88.2` | | [@types/request](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/request) | `2.0.8` | `2.48.12` | | [postcss](https://github.com/postcss/postcss) | `6.0.21` | `8.4.31` | | [jquery](https://github.com/jquery/jquery) | `3.3.1` | `3.5.0` | | [karma](https://github.com/karma-runner/karma) | `2.0.0` | `6.3.16` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.2` | | [utilities](https://github.com/mde/utilities) | `0.0.37` | `` | | [jake](https://github.com/jakejs/jake) | `8.0.16` | `10.8.7` | | [hoek](https://github.com/hapijs/hoek) | `2.16.3` | `` | | [pouchdb](https://github.com/pouchdb/pouchdb) | `5.4.5` | `8.0.1` | | [less](https://github.com/less/less.js) | `2.7.3` | `4.2.0` | | [request](https://github.com/request/request) | `2.85.0` | `2.88.2` | | [minimist](https://github.com/minimistjs/minimist) | `1.2.0` | `1.2.8` | | [mkdirp](https://github.com/isaacs/node-mkdirp) | `0.5.1` | `0.5.6` | | [karma-mocha](https://github.com/karma-runner/karma-mocha) | `1.3.0` | `2.0.1` | | [mocha](https://github.com/mochajs/mocha) | `5.1.0` | `10.3.0` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.0.11` | `4.7.8` | | [shell-quote](https://github.com/ljharb/shell-quote) | `1.6.1` | `1.8.1` | Updates `marked` from 0.3.19 to 4.0.10 - [Release notes](https://github.com/markedjs/marked/releases) - [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json) - [Commits](markedjs/marked@v0.3.19...v4.0.10) Updates `request` from 2.85.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `@types/request` from 2.0.8 to 2.48.12 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/request) Updates `postcss` from 6.0.21 to 8.4.31 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@6.0.21...8.4.31) Updates `jquery` from 3.3.1 to 3.5.0 - [Release notes](https://github.com/jquery/jquery/releases) - [Commits](jquery/jquery@3.3.1...3.5.0) Updates `karma` from 2.0.0 to 6.3.16 - [Release notes](https://github.com/karma-runner/karma/releases) - [Changelog](https://github.com/karma-runner/karma/blob/master/CHANGELOG.md) - [Commits](karma-runner/karma@v2.0.0...v6.3.16) Updates `browserify-sign` from 4.0.4 to 4.2.2 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.2) Removes `utilities` Updates `jake` from 8.0.16 to 10.8.7 - [Changelog](https://github.com/jakejs/jake/blob/main/changelog.md) - [Commits](jakejs/jake@v8.0.16...v10.8.7) Updates `follow-redirects` from 1.0.0 to 1.15.5 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.0.0...v1.15.5) Updates `fsevents` from 1.1.3 to 2.3.3 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.1.3...v2.3.3) Removes `hoek` Updates `pouchdb` from 5.4.5 to 8.0.1 - [Release notes](https://github.com/pouchdb/pouchdb/releases) - [Commits](pouchdb/pouchdb@5.4.5...8.0.1) Updates `less` from 2.7.3 to 4.2.0 - [Release notes](https://github.com/less/less.js/releases) - [Changelog](https://github.com/less/less.js/blob/master/CHANGELOG.md) - [Commits](less/less.js@v2.7.3...v4.2.0) Updates `request` from 2.85.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `minimist` from 1.2.0 to 1.2.8 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.0...v1.2.8) Updates `mkdirp` from 0.5.1 to 0.5.6 - [Changelog](https://github.com/isaacs/node-mkdirp/blob/main/CHANGELOG.md) - [Commits](isaacs/node-mkdirp@0.5.1...v0.5.6) Updates `karma-mocha` from 1.3.0 to 2.0.1 - [Release notes](https://github.com/karma-runner/karma-mocha/releases) - [Changelog](https://github.com/karma-runner/karma-mocha/blob/master/CHANGELOG.md) - [Commits](karma-runner/karma-mocha@v1.3.0...v2.0.1) Updates `mocha` from 5.1.0 to 10.3.0 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/master/CHANGELOG.md) - [Commits](mochajs/mocha@v5.1.0...v10.3.0) Updates `handlebars` from 4.0.11 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.11...v4.7.8) Updates `qs` from 6.1.2 to 6.5.1 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.1.2...v6.5.1) Updates `tough-cookie` from 2.2.2 to 2.3.4 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.2.2...v2.3.4) Updates `shell-quote` from 1.6.1 to 1.8.1 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.6.1...v1.8.1) Updates `socket.io-parser` from 3.1.3 to 4.2.4 - [Release notes](https://github.com/socketio/socket.io-parser/releases) - [Changelog](https://github.com/socketio/socket.io-parser/blob/main/CHANGELOG.md) - [Commits](socketio/socket.io-parser@3.1.3...4.2.4) --- updated-dependencies: - dependency-name: marked dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: "@types/request" dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: postcss dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: jquery dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: karma dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: utilities dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jake dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: hoek dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: pouchdb dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: less dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: mkdirp dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: karma-mocha dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: mocha dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: shell-quote dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: socket.io-parser dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
the
dependencies
Pull requests that update a dependency file
label
Feb 20, 2024
Superseded by #2. |
dependabot
bot
deleted the
dependabot/npm_and_yarn/npm_and_yarn-security-group-b83d974fcd
branch
March 14, 2024 17:58
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 18 updates in the /. directory:
0.3.19
4.0.10
2.85.0
2.88.2
2.0.8
2.48.12
6.0.21
8.4.31
3.3.1
3.5.0
2.0.0
6.3.16
4.0.4
4.2.2
0.0.37
8.0.16
10.8.7
2.16.3
5.4.5
8.0.1
2.7.3
4.2.0
2.85.0
2.88.2
1.2.0
1.2.8
0.5.1
0.5.6
1.3.0
2.0.1
5.1.0
10.3.0
4.0.11
4.7.8
1.6.1
1.8.1
Updates
marked
from 0.3.19 to 4.0.10Release notes
Sourced from marked's releases.
... (truncated)
Commits
ae01170
chore(release): 4.0.10 [skip ci]fceda57
🗜️ build [skip ci]8f80657
fix(security): fix redos vulnerabilitiesc4a3ccd
Merge pull request from GHSA-rrrm-qjm4-v8hfd7212a6
chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (#2352)5a84db5
chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (#2350)2bc67a5
chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (#2351)98996b8
chore(deps-dev): Bump@babel/preset-env
from 7.16.5 to 7.16.7 (#2353)ebc2c95
chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (#2354)e5171a9
chore(release): 4.0.9 [skip ci]Maintainer changes
This version was pushed to npm by tonybrix, a new releaser for marked since your current version.
Updates
request
from 2.85.0 to 2.88.2Changelog
Sourced from request's changelog.
Commits
Updates
@types/request
from 2.0.8 to 2.48.12Commits
Updates
postcss
from 6.0.21 to 8.4.31Release notes
Sourced from postcss's releases.
... (truncated)
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
90208de
Release 8.4.31 version58cc860
Fix carrier return parsing4fff8e4
Improve pnpm test outputcd43ed1
Update dependenciescaa916b
Update dependencies8972f76
Typo11a5286
Typo45c5501
Release 8.4.30 versionbc3c341
Update linterb2be58a
Merge pull request #1881 from romainmenke/improve-sourcemap-performance--phil...Updates
jquery
from 3.3.1 to 3.5.0Release notes
Sourced from jquery's releases.
Commits
7a0a850
3.5.08570a08
Release: Update AUTHORS.txtda3dd85
Ajax: Do not execute scripts for unsuccessful HTTP responses065143c
Ajax: Overwrite s.contentType with content-type header value, if any1a4f10d
Tests: Blacklist one focusin test in IE9e15d6b
Event: Use only one focusin/out handler per matching window & document966a709
Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9
Manipulation: Make jQuery.htmlPrefilter an identity function04bf577
Selector: Update Sizzle from 2.3.4 to 2.3.57506c9c
Build: Resolve Travis config warningsMaintainer changes
This version was pushed to npm by mgol, a new releaser for jquery since your current version.
Updates
karma
from 2.0.0 to 6.3.16Release notes
Sourced from karma's releases.
... (truncated)
Changelog
Sourced from karma's changelog.
... (truncated)
Commits
ab4b328
chore(release): 6.3.16 [skip ci]ff7edbb
fix(security): mitigate the "Open Redirect Vulnerability"c1befa0
chore(release): 6.3.15 [skip ci]d9dade2
fix(helper): make mkdirIfNotExists helper resilient to concurrent calls653c762
ci: prevent duplicate CI tasks on creating a PRc97e562
chore(release): 6.3.14 [skip ci]91d5acd
fix: remove string template from client code69cfc76
fix: warn whensingleRun
andautoWatch
arefalse
839578c
fix(security): remove XSS vulnerability inreturnUrl
query paramdb53785
chore(release): 6.3.13 [skip ci]Updates
browserify-sign
from 4.0.4 to 4.2.2Changelog
Sourced from browserify-sign's changelog.
Commits
4af5a90
v4.2.23aec038
[Dev Deps] updatetape
85994cd
[Fix] properly check the upper bound for DSA signatures9ac5a5e
[meta] fix package.json indentationdcf49ce
[meta] addsafe-publish-latest
4418183
[meta] addnpmignore
andauto-changelog
8767739
[Fix]sign
: throw on unsupported padding scheme5f6fb17
[Tests] log when openssl doesn't support cipherf5f17c2
[Tests] handle openSSL not supporting a schemed845d85
[Tests] migrate from travis to github actionsMaintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Removes
utilities
Updates
jake
from 8.0.16 to 10.8.7Changelog
Sourced from jake's changelog.
... (truncated)
Commits
33492f7
Version 10.8.7a7d3515
Removed stray logging statements414bcac
Version 10.8.66fc1d17
Merge pull request #424 from martinholters/mh/fix_file_task62e5aa6
Added lint task8992031
Restore lint defaulta0378d1
Add test for file task with multiple prereqsf8e8533
Update file_task.js1c481a0
Merge pull request #421 from falsefalse/patch-1ffe8655
Bring back -q descriptionUpdates
follow-redirects
from 1.0.0 to 1.15.5Release notes
Sourced from follow-redirects's releases.
... (truncated)
Commits
b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.6585820
Release version 1.15.4 of the npm package.7a6567e
Disallow bracketed hostnames.05629af
Prefer native URL instead of deprecated url.parse.1cba8e8
Prefer native URL instead of legacy url.resolve.72bc2a4
Simplify _processResponse error handling.3d42aec
Add bracket tests.bcbb096
Do not directly set Error properties.192dbe7
Release version 1.15.3 of the npm package.Updates
fsevents
from 1.1.3 to 2.3.3Release notes
Sourced from fsevents's releases.
... (truncated)
Commits
2db891e
Release v2.3.38ec87bf
Update nodejs.yml (#392)c20c3af
readme63709df
Merge pull request #384 from aleksanb/subdirsa77340f
Handle MustScanSubDirs for large projects66be519
Update README.md (#371)2f2a858
Update README.md (#364)a7f5d00
Release v2.3.2fab136a
fix: issue #355 (#356)328ae39
Release v2.3.1Maintainer changes
This version was pushed to npm by pipobscure, a new releaser for fsevents since your current version.
Removes
hoek
Updates
pouchdb
from 5.4.5 to 8.0.1Release notes
Sourced from pouchdb's releases.
... (truncated)
Commits
fde45b9
build 8.0.13c6e9ef
docs: add release post for 8.0.17484e24
docs: update 2022-12-14-pouchdb-8.0.0.mdff81fa3
ci: use node 1406bfe89
(pouchdb#8581) - Fix test2c81da4
(pouchdb#8581) - Fix test3d36d2d
(pouchdb#8581) - Fix test6a7fd46
(pouchdb#8581) - Fix test.da5069d
(pouchdb#8581) - Fix this of changesHandler0bdb342
feat: add mastodon verification linkMaintainer changes
This version was pushed to npm by albaherreriasdev, a new releaser for pouchdb since your current version.
Updates
less
from 2.7.3 to 4.2.0Release notes
Sourced from less's releases.
... (truncated)
Changelog
Sourced from less's changelog.