forked from microsoft/pxt
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group across 1 directory with 24 updates #2
Open
dependabot
wants to merge
1
commit into
master
Choose a base branch
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-166b92a9aa
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Bump the npm_and_yarn group across 1 directory with 24 updates #2
dependabot
wants to merge
1
commit into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-166b92a9aa
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 19 updates in the / directory: | Package | From | To | | --- | --- | --- | | [marked](https://github.com/markedjs/marked) | `0.3.19` | `4.0.10` | | [request](https://github.com/request/request) | `2.85.0` | `2.88.2` | | [@types/request](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/request) | `2.0.8` | `2.48.12` | | [postcss](https://github.com/postcss/postcss) | `6.0.21` | `8.4.31` | | [jquery](https://github.com/jquery/jquery) | `3.3.1` | `3.5.0` | | [axios](https://github.com/axios/axios) | `0.15.3` | `` | | [karma](https://github.com/karma-runner/karma) | `2.0.0` | `6.4.3` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.3` | | [utilities](https://github.com/mde/utilities) | `0.0.37` | `` | | [jake](https://github.com/jakejs/jake) | `8.0.16` | `10.8.7` | | [hoek](https://github.com/hapijs/hoek) | `2.16.3` | `` | | [pouchdb](https://github.com/pouchdb/pouchdb) | `5.4.5` | `8.0.1` | | [less](https://github.com/less/less.js) | `2.7.3` | `4.2.0` | | [request](https://github.com/request/request) | `2.85.0` | `2.88.2` | | [minimist](https://github.com/minimistjs/minimist) | `1.2.0` | `1.2.8` | | [mkdirp](https://github.com/isaacs/node-mkdirp) | `0.5.1` | `0.5.6` | | [karma-mocha](https://github.com/karma-runner/karma-mocha) | `1.3.0` | `2.0.1` | | [mocha](https://github.com/mochajs/mocha) | `5.1.0` | `10.3.0` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.0.11` | `4.7.8` | | [shell-quote](https://github.com/ljharb/shell-quote) | `1.6.1` | `1.8.1` | Updates `marked` from 0.3.19 to 4.0.10 - [Release notes](https://github.com/markedjs/marked/releases) - [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json) - [Commits](markedjs/marked@v0.3.19...v4.0.10) Updates `request` from 2.85.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `@types/request` from 2.0.8 to 2.48.12 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/request) Updates `postcss` from 6.0.21 to 8.4.31 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@6.0.21...8.4.31) Updates `jquery` from 3.3.1 to 3.5.0 - [Release notes](https://github.com/jquery/jquery/releases) - [Commits](jquery/jquery@3.3.1...3.5.0) Removes `axios` Updates `karma` from 2.0.0 to 6.4.3 - [Release notes](https://github.com/karma-runner/karma/releases) - [Changelog](https://github.com/karma-runner/karma/blob/master/CHANGELOG.md) - [Commits](karma-runner/karma@v2.0.0...v6.4.3) Updates `browserify-sign` from 4.0.4 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.3) Removes `utilities` Updates `jake` from 8.0.16 to 10.8.7 - [Changelog](https://github.com/jakejs/jake/blob/main/changelog.md) - [Commits](jakejs/jake@v8.0.16...v10.8.7) Updates `follow-redirects` from 1.0.0 to 1.15.6 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.0.0...v1.15.6) Updates `fsevents` from 1.1.3 to 2.3.3 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.1.3...v2.3.3) Removes `hoek` Updates `pouchdb` from 5.4.5 to 8.0.1 - [Release notes](https://github.com/pouchdb/pouchdb/releases) - [Commits](pouchdb/pouchdb@5.4.5...8.0.1) Updates `less` from 2.7.3 to 4.2.0 - [Release notes](https://github.com/less/less.js/releases) - [Changelog](https://github.com/less/less.js/blob/master/CHANGELOG.md) - [Commits](less/less.js@v2.7.3...v4.2.0) Updates `request` from 2.85.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `minimist` from 1.2.0 to 1.2.8 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.0...v1.2.8) Updates `mkdirp` from 0.5.1 to 0.5.6 - [Changelog](https://github.com/isaacs/node-mkdirp/blob/main/CHANGELOG.md) - [Commits](isaacs/node-mkdirp@0.5.1...v0.5.6) Updates `karma-mocha` from 1.3.0 to 2.0.1 - [Release notes](https://github.com/karma-runner/karma-mocha/releases) - [Changelog](https://github.com/karma-runner/karma-mocha/blob/master/CHANGELOG.md) - [Commits](karma-runner/karma-mocha@v1.3.0...v2.0.1) Updates `mocha` from 5.1.0 to 10.3.0 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/master/CHANGELOG.md) - [Commits](mochajs/mocha@v5.1.0...v10.3.0) Updates `handlebars` from 4.0.11 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.11...v4.7.8) Updates `qs` from 6.1.2 to 6.5.1 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.1.2...v6.5.1) Updates `tough-cookie` from 2.2.2 to 2.3.4 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.2.2...v2.3.4) Updates `shell-quote` from 1.6.1 to 1.8.1 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.6.1...v1.8.1) Updates `socket.io-parser` from 3.1.3 to 4.2.4 - [Release notes](https://github.com/socketio/socket.io-parser/releases) - [Changelog](https://github.com/socketio/socket.io-parser/blob/main/CHANGELOG.md) - [Commits](socketio/socket.io-parser@3.1.3...4.2.4) --- updated-dependencies: - dependency-name: marked dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: "@types/request" dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: postcss dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: jquery dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: axios dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: karma dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: utilities dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jake dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: hoek dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: pouchdb dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: less dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: mkdirp dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: karma-mocha dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: mocha dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: shell-quote dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: socket.io-parser dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
the
dependencies
Pull requests that update a dependency file
label
Mar 14, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 19 updates in the / directory:
0.3.19
4.0.10
2.85.0
2.88.2
2.0.8
2.48.12
6.0.21
8.4.31
3.3.1
3.5.0
0.15.3
2.0.0
6.4.3
4.0.4
4.2.3
0.0.37
8.0.16
10.8.7
2.16.3
5.4.5
8.0.1
2.7.3
4.2.0
2.85.0
2.88.2
1.2.0
1.2.8
0.5.1
0.5.6
1.3.0
2.0.1
5.1.0
10.3.0
4.0.11
4.7.8
1.6.1
1.8.1
Updates
marked
from 0.3.19 to 4.0.10Release notes
Sourced from marked's releases.
... (truncated)
Commits
ae01170
chore(release): 4.0.10 [skip ci]fceda57
🗜️ build [skip ci]8f80657
fix(security): fix redos vulnerabilitiesc4a3ccd
Merge pull request from GHSA-rrrm-qjm4-v8hfd7212a6
chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (#2352)5a84db5
chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (#2350)2bc67a5
chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (#2351)98996b8
chore(deps-dev): Bump@babel/preset-env
from 7.16.5 to 7.16.7 (#2353)ebc2c95
chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (#2354)e5171a9
chore(release): 4.0.9 [skip ci]Maintainer changes
This version was pushed to npm by tonybrix, a new releaser for marked since your current version.
Updates
request
from 2.85.0 to 2.88.2Changelog
Sourced from request's changelog.
Commits
Updates
@types/request
from 2.0.8 to 2.48.12Commits
Updates
postcss
from 6.0.21 to 8.4.31Release notes
Sourced from postcss's releases.
... (truncated)
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
90208de
Release 8.4.31 version58cc860
Fix carrier return parsing4fff8e4
Improve pnpm test outputcd43ed1
Update dependenciescaa916b
Update dependencies8972f76
Typo11a5286
Typo45c5501
Release 8.4.30 versionbc3c341
Update linterb2be58a
Merge pull request #1881 from romainmenke/improve-sourcemap-performance--phil...Updates
jquery
from 3.3.1 to 3.5.0Release notes
Sourced from jquery's releases.
Commits
7a0a850
3.5.08570a08
Release: Update AUTHORS.txtda3dd85
Ajax: Do not execute scripts for unsuccessful HTTP responses065143c
Ajax: Overwrite s.contentType with content-type header value, if any1a4f10d
Tests: Blacklist one focusin test in IE9e15d6b
Event: Use only one focusin/out handler per matching window & document966a709
Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9
Manipulation: Make jQuery.htmlPrefilter an identity function04bf577
Selector: Update Sizzle from 2.3.4 to 2.3.57506c9c
Build: Resolve Travis config warningsMaintainer changes
This version was pushed to npm by mgol, a new releaser for jquery since your current version.
Removes
axios
Updates
karma
from 2.0.0 to 6.4.3Release notes
Sourced from karma's releases.
... (truncated)
Changelog
Sourced from karma's changelog.
... (truncated)
Commits
d8cf806
chore(release): 6.4.3 [skip ci]d7f2d69
fix: add build commits for patch release85a2eeb
build(deps-dev): bump decode-uri-component from 0.2.0 to 0.2.20bffce2
build(deps): updated socket.io version to fix security issues with socket.io-...86667ab
build(deps): bump follow-redirects from 1.11.0 to 1.15.4450fdfd
docs: Add deprecation notice to Karma README9de3c00
chore(release): 6.4.2 [skip ci]c6a4271
fix: few typos50f9635
docs: update codeclimate badge in readme.md0013121
chore(release): 6.4.1 [skip ci]Updates
browserify-sign
from 4.0.4 to 4.2.3Changelog
Sourced from browserify-sign's changelog.
... (truncated)
Commits
bf2c3ec
v4.2.39247adf
[patch] widen support to 0.12f427270
[Deps] update `parse-asn187f3a35
[Dev Deps] updateaud
,npmignore
,tape
fb261ce
[Deps] updateelliptic
4d0ee49
[patch] drop minimum node support to v19e2bf12
[Deps] pinhash-base
to ~3.0, due to a breaking change168e16f
[Deps] pinelliptic
due to a breaking change37a4758
[actions] remove redundant finisher4af5a90
v4.2.2Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Removes
utilities
Updates
jake
from 8.0.16 to 10.8.7Changelog
Sourced from jake's changelog.
... (truncated)
Commits
33492f7
Version 10.8.7a7d3515
Removed stray logging statements414bcac
Version 10.8.66fc1d17
Merge pull request #424 from martinholters/mh/fix_file_task62e5aa6
Added lint task8992031
Restore lint defaulta0378d1
Add test for file task with multiple prereqsf8e8533
Update file_task.js1c481a0
Merge pull request #421 from falsefalse/patch-1ffe8655
Bring back -q descriptionUpdates
follow-redirects
from 1.0.0 to 1.15.6Release notes
Sourced from follow-redirects's releases.
... (truncated)
Commits
35a517c
Release version 1.15.6 of the npm package.c4f847f
Drop Proxy-Authorization across hosts.8526b4a
Use GitHub for disclosure.b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.6585820
Release version 1.15.4 of the npm package.7a6567e
Disallow bracketed hostnames.05629af
Prefer native URL instead of deprecated url.parse.1cba8e8
Prefer native URL instead of legacy url.resolve.72bc2a4
Simplify _processResponse error handling.Updates
fsevents
from 1.1.3 to 2.3.3Release notes
Sourced from fsevents's releases.
... (truncated)
Commits
2db891e
Release v2.3.38ec87bf
Update nodejs.yml (#392)c20c3af
readme63709df
Merge pull request #384 from aleksanb/subdirsa77340f
Handle MustScanSubDirs for large projects66be519
Update README.md (#371)2f2a858
Update README.md (#364)a7f5d00
Release v2.3.2fab136a
fix: issue #355 (#356)328ae39
Release v2.3.1Maintainer changes
This version was pushed to npm by pipobscure, a new releaser for fsevents since your current version.
Removes
hoek
Updates
pouchdb
from 5.4.5 to 8.0.1Release notes
Sourced from pouchdb's releases.
... (truncated)
Commits
fde45b9
build 8.0.13c6e9ef
docs: add release post for 8.0.17484e24
docs: update 2022-12-14-pouchdb-8.0.0.mdff81fa3
ci: use node 1406bfe89
(pouchdb#8581) - Fix test2c81da4
(pouchdb#8581) - Fix test3d36d2d
(pouchdb#8581) - Fix test6a7fd46
(pouchdb#8581) - Fix test.da5069d
(pouchdb#8581) - Fix this of changesHandler0bdb342
feat: add mastodon verification linkMaintainer changes
This version was pushed to npm by albaherreriasdev, a new releaser for pouchdb since your current version.
Updates
less
from 2.7.3 to 4.2.0Release notes
Sourced from less's releases.
... (truncated)
Changelog
Sourced from less's changelog.