Bump the npm_and_yarn group across 1 directory with 30 updates#1
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
Bumps the npm_and_yarn group with 9 updates in the /examples/basic directory: | Package | From | To | | --- | --- | --- | | [ajv](https://github.com/ajv-validator/ajv) | `4.11.4` | `6.12.6` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.6` | `1.1.12` | | [hosted-git-info](https://github.com/npm/hosted-git-info) | `2.2.0` | `2.8.9` | | [min-document](https://github.com/Raynos/min-document) | `2.19.0` | `2.19.2` | | [path-parse](https://github.com/jbgutierrez/path-parse) | `1.0.5` | `1.0.7` | | [sshpk](https://github.com/joyent/node-sshpk) | `1.11.0` | `1.18.0` | | [tmpl](https://github.com/daaku/nodejs-tmpl) | `1.0.4` | `1.0.5` | | [ua-parser-js](https://github.com/faisalman/ua-parser-js) | `0.7.12` | `0.7.41` | | [y18n](https://github.com/yargs/y18n) | `3.2.1` | `3.2.2` | Updates `ajv` from 4.11.4 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](https://github.com/ajv-validator/ajv/commits/v6.12.6) Updates `body-parser` from 1.13.3 to 1.20.4 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.13.3...1.20.4) Updates `brace-expansion` from 1.1.6 to 1.1.12 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.6...v1.1.12) Updates `cookie` from 0.1.3 to 0.7.2 - [Release notes](https://github.com/jshttp/cookie/releases) - [Commits](jshttp/cookie@v0.1.3...v0.7.2) Updates `cross-spawn` from 2.2.3 to 5.1.0 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@2.2.3...5.1.0) Updates `debug` from 0.7.4 to 2.6.1 - [Release notes](https://github.com/debug-js/debug/releases) - [Changelog](https://github.com/debug-js/debug/blob/2.6.1/CHANGELOG.md) - [Commits](debug-js/debug@0.7.4...2.6.1) Updates `diff` from 2.2.3 to 3.5.1 - [Changelog](https://github.com/kpdecker/jsdiff/blob/master/release-notes.md) - [Commits](kpdecker/jsdiff@v2.2.3...v3.5.1) Updates `form-data` from 2.1.2 to 2.3.3 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](https://github.com/form-data/form-data/commits) Updates `hosted-git-info` from 2.2.0 to 2.8.9 - [Release notes](https://github.com/npm/hosted-git-info/releases) - [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md) - [Commits](npm/hosted-git-info@v2.2.0...v2.8.9) Updates `lodash` from 3.10.1 to 4.17.4 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@3.10.1...4.17.4) Updates `min-document` from 2.19.0 to 2.19.2 - [Commits](Raynos/min-document@v2.19.0...v2.19.2) Updates `morgan` from 1.6.1 to 1.10.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.6.1...1.10.1) Updates `ms` from 0.7.1 to 0.7.2 - [Release notes](https://github.com/vercel/ms/releases) - [Commits](vercel/ms@0.7.1...0.7.2) Updates `on-headers` from 1.0.1 to 1.1.0 - [Release notes](https://github.com/jshttp/on-headers/releases) - [Changelog](https://github.com/jshttp/on-headers/blob/master/HISTORY.md) - [Commits](jshttp/on-headers@v1.0.1...v1.1.0) Updates `path-parse` from 1.0.5 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `plist` from 1.2.0 to 2.0.1 - [Release notes](https://github.com/TooTallNate/node-plist/releases) - [Changelog](https://github.com/TooTallNate/plist.js/blob/master/History.md) - [Commits](TooTallNate/plist.js@1.2.0...2.0.1) Updates `qs` from 4.0.0 to 6.5.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v4.0.0...v6.5.3) Updates `request` from 2.81.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `semver` from 2.2.1 to 5.3.0 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v2.2.1...v5.3.0) Updates `send` from 0.13.2 to 0.19.2 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.13.2...0.19.2) Updates `serve-static` from 1.10.3 to 1.16.3 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md) - [Commits](expressjs/serve-static@v1.10.3...v1.16.3) Updates `simple-plist` from 0.1.4 to 0.2.1 - [Release notes](https://github.com/wollardj/simple-plist/releases) - [Commits](wollardj/simple-plist@v0.1.4...0.2.1) Updates `sshpk` from 1.11.0 to 1.18.0 - [Release notes](https://github.com/joyent/node-sshpk/releases) - [Commits](TritonDataCenter/node-sshpk@v1.11.0...v1.18.0) Updates `tmp` from 0.0.29 to 0.0.33 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](raszi/node-tmp@v0.0.29...v0.0.33) Updates `tmpl` from 1.0.4 to 1.0.5 - [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5) Updates `tough-cookie` from 2.3.2 to 2.5.0 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.3.2...v2.5.0) Updates `tunnel-agent` from 0.4.3 to 0.6.0 - [Commits](request/tunnel-agent@v0.4.3...v0.6.0) Updates `ua-parser-js` from 0.7.12 to 0.7.41 - [Release notes](https://github.com/faisalman/ua-parser-js/releases) - [Changelog](https://github.com/faisalman/ua-parser-js/blob/master/CHANGELOG.md) - [Commits](faisalman/ua-parser-js@0.7.12...0.7.41) Updates `y18n` from 3.2.1 to 3.2.2 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](https://github.com/yargs/y18n/commits) Updates `yargs-parser` from 4.2.1 to 7.0.0 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md) - [Commits](yargs/yargs-parser@v4.2.1...v7.0.0) --- updated-dependencies: - dependency-name: ajv dependency-version: 6.12.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: body-parser dependency-version: 1.20.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-version: 0.7.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 5.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: debug dependency-version: 2.6.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: diff dependency-version: 3.5.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: form-data dependency-version: 2.3.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hosted-git-info dependency-version: 2.8.9 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: min-document dependency-version: 2.19.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: morgan dependency-version: 1.10.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ms dependency-version: 0.7.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: on-headers dependency-version: 1.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-version: 1.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: plist dependency-version: 2.0.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-version: 6.5.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: request dependency-version: 2.88.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-version: 5.3.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-version: 0.19.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-version: 1.16.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: simple-plist dependency-version: 0.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: sshpk dependency-version: 1.18.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmp dependency-version: 0.0.33 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmpl dependency-version: 1.0.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tough-cookie dependency-version: 2.5.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tunnel-agent dependency-version: 0.6.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ua-parser-js dependency-version: 0.7.41 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-version: 3.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-version: 7.0.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 9 updates in the /examples/basic directory:
4.11.46.12.61.1.61.1.122.2.02.8.92.19.02.19.21.0.51.0.71.11.01.18.01.0.41.0.50.7.120.7.413.2.13.2.2Updates
ajvfrom 4.11.4 to 6.12.6Release notes
Sourced from ajv's releases.
... (truncated)
Commits
Updates
body-parserfrom 1.13.3 to 1.20.4Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
7db202c1.20.4 (#672)d8f8adbci: add CodeQL (SAST) (#670)6d133c1chore: remove SECURITY.md (#669)fcd1535deps: use tilde notation and update certain dependencies (#668)ec5fa29deps: qs@~6.14.0 (#664)ffb95c1ci: restore CI for 1.x branch (#665)48a5f07ci: add support for Node.js v23 (#553)f20f6adRemove redundant depth check (#538)17529511.20.339744cfchore: linter (#534)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
brace-expansionfrom 1.1.6 to 1.1.12Release notes
Sourced from brace-expansion's releases.
... (truncated)
Commits
44f33b41.1.12c460dbdpkg: publish on tag 1.xccb8ac6fmtc3c73c8Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)01a21de1.1.11d7c93eesponsors54a61761.1.10327c729Merge pull request #40 from Parcley/add-license-1b6ba2e0create LICENSE file0f82dab1.1.9Updates
cookiefrom 0.1.3 to 0.7.2Release notes
Sourced from cookie's releases.
... (truncated)
Commits
d19eaa10.7.2bc38ffdFix object assignment ofhasOwnProperty(#177)cf4658f0.7.16a8b8f5Allow leading dot for domain (#174)58015c0Remove more code and perf wins (#172)ab057d60.7.05f02ca8Migrate history to GitHub releasesa5d591cMigrate history to GitHub releases51968f9Skip isNaN9e7ca51perf(parse): cache length, return early (#144)Maintainer changes
This version was pushed to npm by blakeembrey, a new releaser for cookie since your current version.
Updates
cross-spawnfrom 2.2.3 to 5.1.0Changelog
Sourced from cross-spawn's changelog.
Commits
1da4c09Release 5.1.02eeda0eNode 4.8 supports the shell option for spawn (#67)d74d461Release 5.0.1444efdbFix shell option with Node 7 (#48)8deb123Update README.mdd424f89CS.4187519Typo in comment.2d22b33Release 5.0.09ba08ebUpdate README.md36ac0f5Add support for options.shell and other goodies (#46)Updates
debugfrom 0.7.4 to 2.6.1Changelog
Sourced from debug's changelog.
... (truncated)
Commits
37e14d6Whitelist DEBUG_FD for values 1 and 2 only Fixes #410 (#415)705a9feMerge pull request #414 from vgoma/export-default-fix78ae6c9Fixed IE8 "Expected identifier" error1c163a4added names and skips arrays erasing on enable call (#409)ac5ccaerelease 2.6.05895595better null pointer checks for browser useColors6646130remove explicitwindow.debugexport (#404)62df220Deprecate DEBUG_FD (#405)9a18d66release 2.5.2eba68cefix(browser): prevent ReferenceError in workers (#393)Maintainer changes
This version was pushed to npm by thebigredgeek, a new releaser for debug since your current version.
Updates
difffrom 2.2.3 to 3.5.1Changelog
Sourced from diff's changelog.
... (truncated)
Commits
e8bb422v3.5.12f5bf5eBackport kpdecker/jsdiff#649c9f00dbBackport kpdecker/jsdiff#647e9ab948v3.5.0b73884cUpdate release notes8953021Update release notes1023590Omit redundant slice in join method of diffArraysc72ef4aAdd missing test coverageb9ef24fSupport patches with empty lines10aaabbSupport patches with empty linesMaintainer changes
This version was pushed to npm by explodingcabbage, a new releaser for diff since your current version.
Updates
form-datafrom 2.1.2 to 2.3.3Release notes
Sourced from form-data's releases.
Changelog
Sourced from form-data's changelog.
... (truncated)
Commits
Updates
hosted-git-infofrom 2.2.0 to 2.8.9Changelog
Sourced from hosted-git-info's changelog.
... (truncated)
Commits
8d4b369chore(release): 2.8.929adfe5fix: backport regex fix from #76afeaefdchore(release): 2.8.85038b18fix: #61 & #65 addressing issues w/ url.URL implmentation which regressed nod...7440afachore(release): 2.8.72d0bb66fix: Do not attempt to use url.URL when unavailablef2cdfcffix: Do not pass scp-style URLs to the WhatWG url.URLe1b83dfchore(release): 2.8.6ff259a6Ensure passwords in hosted Git URLs are correctly escaped624fd6fchore(release): 2.8.5Maintainer changes
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates
lodashfrom 3.10.1 to 4.17.4Release notes
Sourced from lodash's releases.
... (truncated)
Commits
912d6b0Bump to v4.17.4.1655720Rebuild lodash and docs.ae467c7Update deps.1e80c19Remove dead “modern environments” link from readme. [ci skip]6eeafd3Update kitchen sink size. [ci skip]e33b156Ensure_.omitdoesn’t mutateobjectwith deep paths. [closes #2912]a23b918Increment package version to enable ci tests.ef61899Bump to v4.17.3.708b962Rebuild lodash and docs.da2d08dUpdate deps.Updates
min-documentfrom 2.19.0 to 2.19.2Commits
0d141502.19.249c2e06Merge pull request #56 from wasabina67/fix/prototype-pollution-removeAttribut...9666461Fix prototype pollution vulnerability in removeAttributeNS4490b402.19.12cd5871update ignorefe32e8dMerge pull request #55 from jameswassink/fix/prototype-pollution-removeAttrib...6c5f31aBetter prototype pollution fix0d4e819Fix prototype pollution in removeAttributeNSbf7b691Update package.json1b5402dMerge pull request #49 from PixnBits/patch-1Updates
morganfrom 1.6.1 to 1.10.1Release notes
Sourced from morgan's releases.
... (truncated)
Changelog
Sourced from morgan's changelog.
... (truncated)
Details
Description has been truncated