chore(deps): bump the npm_and_yarn group across 1 directory with 13 updates #1019
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 12 updates in the / directory:
4.3.14.3.24.16.44.19.21.48.32.25.20.10.500.10.641.1.51.1.92.26.02.30.12.6.02.7.06.5.26.5.31.9.11.13.66.1.16.1.21.2.31.2.54.0.04.0.3Updates
debugfrom 4.3.1 to 4.3.2Release notes
Sourced from debug's releases.
Commits
e47f96d4.3.21e9d38ccache enabled status per-logger (#799)Updates
expressfrom 4.16.4 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
04bc6274.19.2da4d763Improved fix for open redirect allow list bypass4f0f6cc4.19.1a003cfaAllow passing non-strings to res.location with new encoding handling checks f...a1fa90ffixed un-edited version in history.md for 4.19.011f2b1dbuild: fix build due to inconsistent supertest behavior in older versions084e3654.19.00867302Prevent open redirect allow list bypass due to encodeurl567c9c6Add note on how to update docs for new release (#5541)69a4cf2deps: [email protected]Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates
plotly.jsfrom 1.48.3 to 2.25.2Release notes
Sourced from plotly.js's releases.
... (truncated)
Changelog
Sourced from plotly.js's changelog.
... (truncated)
Commits
e8241992.25.2920a50eupdate readme and changelog for v2.25.227932d6Merge pull request #6705 from plotly/reduce-flakiness0249840Merge pull request #6704 from plotly/nestedProperty-protoa4a69d5reduce flakiness on CIa860a32Merge pull request #6690 from Mkranj/croatian_translation5cfbd6eadd test2bec998guard against polluting proto in nestedProperty5efd2a1Merge pull request #6703 from plotly/expandObjectPaths-protoe1e3175fix delay in testMaintainer changes
This version was pushed to npm by archmoj, a new releaser for plotly.js since your current version.
Updates
es5-extfrom 0.10.50 to 0.10.64Release notes
Sourced from es5-ext's releases.
... (truncated)
Changelog
Sourced from es5-ext's changelog.
... (truncated)
Commits
f76b03dchore: Release v0.10.642881acdchore: Bump dependenciesc2e2bb9fix: Revert update meant to fix Powershell issue, as it's a regression16f2b72docs: Fix date in the changelogde4e03cchore: Release v0.10.633fd53b7chore: Upgradelint-stagedto v13bf8ed79chore: Ensure postinstall script does not crash on Windows2cbbb07chore: Bump dependencies22d0416chore: Bump LICENSE yeara52e957fix: Support ES2015+ function definitions infunction#toStringTokens()Updates
ipfrom 1.1.5 to 1.1.9Commits
1ecbf2f1.1.96a3ada9lib: fixed CVE-2023-42282 and added unit test5dc3b2f1.1.88e6f28blib: even better node 6 support088c9e51.1.71a4ca35lib: add back support for Node.js 6af82ef41.1.6dba19f6package: exclude test folder from publishing7cd7f30ci: use github workflows4de50aelib: node 18 supportUpdates
momentfrom 2.26.0 to 2.30.1Changelog
Sourced from moment's changelog.
... (truncated)
Commits
485d9a7Build 2.30.1e048b09Bump version to 2.30.1f9f2d58Update changelog for 2.30.1a52ffb2Revert "Merge pull request #5827 from BobZombie:feature/fix_d.ts"ddd6809Build 2.30.0be64d00Bump version to 2.30.0ad41179Update changelog for 2.30.063fe479[misc] Make code ES6 compatible0f0195fRevert "Merge pull request #5599 from Alanscut:issue_4985"15b82f5Revert "Merge pull request #5597 from Alanscut:issue-5596"Updates
node-fetchfrom 2.6.0 to 2.7.0Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
9b9d458feat:AbortError(#1744)65ae25afix: Remove the default connection close header (#1765)8bc3a7cfix: socket variable testing for undefined (#1726)afb36f6Revert "fix: handle bom in text and json (#1739)" (#1741)29909d7fix: handle bom in text and json (#1739)70f592dfix: "global is not defined" (#1704)0f1ebb0Prevent error when response is null (#1699)6e9464dci(release): install dependenciesdd2a0baci(release): install dependencies49bef02ci(release): use latest Node LTSMaintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
qsfrom 6.5.2 to 6.5.3Changelog
Sourced from qs's changelog.
Commits
298bfa5v6.5.3ed0f5dc[Fix]parse: ignore__proto__keys (#428)691e739[Robustness]stringify: avoid relying on a globalundefined(#427)1072d57[readme] remove travis badge; add github actions/codecov badges; update URLs12ac1c4[meta] fix README.md (#399)0338716[actions] backport actions from main5639c20Clean up license text so it’s properly detected as BSD-3-Clause51b8a0badd FUNDING.yml45f6759[Fix] fix for an impossible situation: when the formatter is called with a no...f814a7f[Dev Deps] backport from mainUpdates
static-evalfrom 0.2.4 to 2.1.1Release notes
Sourced from static-eval's releases.
Changelog
Sourced from static-eval's changelog.
Commits
c6821472.1.122fc478Merge pull request #43 from FabianWarnecke/patch-1cdf877dUpdate dependency "escodegen".aff732bmaybe they will email me about "security" issues if i put this in there1a4d7342.1.0054adacci: add node 1409c4b83Merge pull request #31 from archmoj/allow-cwise-transforme619afcmake option to enable allowAccessToMethodsOnFunctions namely to be used by cw...36587c2remove trailing spaces798b0d5ci: add node 12 and 13Maintainer changes
This version was pushed to npm by goto-bus-stop, a new releaser for static-eval since your current version.
Updates
underscorefrom 1.9.1 to 1.13.6Commits
bd2d35cMerge remote-tracking branch 'upstream/master'2e7c0f2Update generated files, tag 1.13.6 release732cafeUnderscore 1.13.6e8f86fbAdd changelog entry for versioin 1.13.643e827aBump the version to 1.13.6 (hotfix)1c1d1a2Remove patch-package postinstall script4eb6894Merge pull request #2974 from paulsmithkc/patch-12edcdc1Hostfix for broken builds66ee70dVerify that production and doc builds still work in CI68e5eb6Update generated sources, tag 1.13.5 releaseMaintainer changes
This version was pushed to npm by jgonggrijp, a new releaser for underscore since your current version.
Updates
webpack-dev-middlewarefrom 6.1.1 to 6.1.2Release notes
Sourced from webpack-dev-middleware's releases.
Changelog
Sourced from webpack-dev-middleware's changelog.
Commits
54e4a96chore(release): 6.1.29670b34fix(security): do not allow to read files above (#1778)Updates
word-wrapfrom 1.2.3 to 1.2.5Release notes
Sourced from word-wrap's releases.
Commits
207044e1.2.59894315revert default indentf64b188run verb to generate README03ea082Merge pull request #42 from jonschlinkert/chore/publish-workflow420dce9Merge pull request #41 from jonschlinkert/fix/CVE-2023-26115-2bfa694eUpdate .github/workflows/publish.ymlace0b3cchore: bump version to 1.2.46fd7275chore: add publish workflow30d6dafchore: fix test655929cchore: remove package-lockUpdates
y18nfrom 4.0.0 to 4.0.3Changelog
Sourced from y18n's changelog.
Commits
0aa97c5chore: release 4.x.x (#128)a8e7f04build(release-please): configure branch properly (#127)1e21a53fix(release): 4.x.x should not enforce Node 10 (#126)8dc7580docs: update CHANGELOG7de58cafix: address prototype pollution issueMaintainer changes
This version was pushed to npm by oss-bot, a new releaser for y18n since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manuallyDescription has been truncated