Skip to content

chore(deps): Bump jspdf from 3.0.3 to 4.2.1#106

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jspdf-4.2.1
Open

chore(deps): Bump jspdf from 3.0.3 to 4.2.1#106
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jspdf-4.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 17, 2026

Bumps jspdf from 3.0.3 to 4.2.1.

Release notes

Sourced from jspdf's releases.

v4.2.1

This release fixes two security issues.

What's Changed

Full Changelog: parallax/jsPDF@v4.2.0...v4.2.1

v4.2.0

This release fixes three security issues.

What's Changed

New Contributors

Full Changelog: parallax/jsPDF@v4.1.0...v4.2.0

v4.1.0

This release fixes several security issues.

What's Changed

Full Changelog: parallax/jsPDF@v4.0.0...v4.1.0

v4.0.0

This release fixes a critical path traversal/local file inclusion security vulnerability in the jsPDF Node.js build. File system access is now restricted by default and can be enabled by either using node's --permission flag or the new jsPDF.allowFsRead property.

There are no other breaking changes.

v3.0.4

This release includes a bunch of bugfixes. Thanks to all contributors!

What's Changed

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added automated Automated PR dependencies Dependency updates labels Mar 17, 2026
@dependabot dependabot Bot requested a review from abdout as a code owner March 17, 2026 18:41
@dependabot dependabot Bot added dependencies Dependency updates automated Automated PR labels Mar 17, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented Mar 17, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
hogwarts Ignored Ignored Preview Apr 4, 2026 11:50pm

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/jspdf-4.2.1 branch from f60ca60 to e37aa2c Compare March 21, 2026 23:42
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/jspdf-4.2.1 branch from e37aa2c to 0577ef2 Compare April 3, 2026 16:03
Bumps [jspdf](https://github.com/parallax/jsPDF) from 3.0.3 to 4.2.1.
- [Release notes](https://github.com/parallax/jsPDF/releases)
- [Changelog](https://github.com/parallax/jsPDF/blob/master/RELEASE.md)
- [Commits](parallax/jsPDF@v3.0.3...v4.2.1)

---
updated-dependencies:
- dependency-name: jspdf
  dependency-version: 4.2.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/jspdf-4.2.1 branch from 0577ef2 to d0008bb Compare April 4, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated PR dependencies Dependency updates type: config

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants