Closed dependabot[bot] closed 5 months ago
Bumps the npm_and_yarn group with 10 updates in the / directory:
7.5.4
7.6.0
3.1.0
removed
4.47.0
5.91.0
6.2.4
8.5.1
3.1.6
4.18.2
4.19.2
1.15.4
1.15.6
2.7.1
2.8.9
1.3.5
1.3.8
8.4.31
8.4.38
Bumps the npm_and_yarn group with 5 updates in the /search-prototype directory:
6.3.0
6.3.1
4.18.1
3.1.8
3.1.10
1.2.3
1.2.5
Updates semver from 7.5.4 to 7.6.0
semver
Sourced from semver's releases.
v7.6.0 7.6.0 (2024-01-31) Features a7ab13a #671 preserve pre-release and build parts of a version on coerce (#671) (@madtisa, madtisa, @wraithgar) Chores 816c7b2 #667 postinstall for dependabot template-oss PR (@lukekarrys) 0bd24d9 #667 bump @npmcli/template-oss from 4.21.1 to 4.21.3 (@dependabot[bot]) e521932 #652 postinstall for dependabot template-oss PR (@lukekarrys) 8873991 #652 chore: chore: postinstall for dependabot template-oss PR (@lukekarrys) f317dc8 #652 bump @npmcli/template-oss from 4.19.0 to 4.21.0 (@dependabot[bot]) 7303db1 #658 add clean() test for build metadata (#658) (@jethrodaniel) 6240d75 #656 add missing quotes in README.md (#656) (@zyxkad) 14d263f #625 postinstall for dependabot template-oss PR (@lukekarrys) 7c34e1a #625 bump @npmcli/template-oss from 4.18.1 to 4.19.0 (@dependabot[bot]) 123e0b0 #622 postinstall for dependabot template-oss PR (@lukekarrys) 737d5e1 #622 bump @npmcli/template-oss from 4.18.0 to 4.18.1 (@dependabot[bot]) cce6180 #598 postinstall for dependabot template-oss PR (@lukekarrys) b914a3d #598 bump @npmcli/template-oss from 4.17.0 to 4.18.0 (@dependabot[bot])
a7ab13a
@madtisa
@wraithgar
816c7b2
@lukekarrys
0bd24d9
@npmcli/template-oss
@dependabot
e521932
8873991
f317dc8
7303db1
@jethrodaniel
6240d75
@zyxkad
14d263f
7c34e1a
123e0b0
737d5e1
cce6180
b914a3d
Sourced from semver's changelog.
7.6.0 (2024-01-31) Features a7ab13a #671 preserve pre-release and build parts of a version on coerce (#671) (@madtisa, madtisa, @wraithgar) Chores 816c7b2 #667 postinstall for dependabot template-oss PR (@lukekarrys) 0bd24d9 #667 bump @npmcli/template-oss from 4.21.1 to 4.21.3 (@dependabot[bot]) e521932 #652 postinstall for dependabot template-oss PR (@lukekarrys) 8873991 #652 chore: chore: postinstall for dependabot template-oss PR (@lukekarrys) f317dc8 #652 bump @npmcli/template-oss from 4.19.0 to 4.21.0 (@dependabot[bot]) 7303db1 #658 add clean() test for build metadata (#658) (@jethrodaniel) 6240d75 #656 add missing quotes in README.md (#656) (@zyxkad) 14d263f #625 postinstall for dependabot template-oss PR (@lukekarrys) 7c34e1a #625 bump @npmcli/template-oss from 4.18.1 to 4.19.0 (@dependabot[bot]) 123e0b0 #622 postinstall for dependabot template-oss PR (@lukekarrys) 737d5e1 #622 bump @npmcli/template-oss from 4.18.0 to 4.18.1 (@dependabot[bot]) cce6180 #598 postinstall for dependabot template-oss PR (@lukekarrys) b914a3d #598 bump @npmcli/template-oss from 4.17.0 to 4.18.0 (@dependabot[bot])
377f709
Removes glob-parent
glob-parent
Updates webpack from 4.47.0 to 5.91.0
webpack
Sourced from webpack's releases.
v5.91.0 Bug Fixes Deserializer for ignored modules doesn't crash Allow the unsafeCache option to be a proxy object Normalize the snapshot.unmanagedPaths option Fixed fs types Fixed resolve's plugins types Fixed wrongly calculate postOrderIndex Fixed watching types Output import attrbiutes/import assertions for external JS imports Throw an error when DllPlugin needs to generate multiple manifest files, but the path is the same [CSS] Output layer/supports/media for external CSS imports New Features Allow to customize the stage of BannerPlugin [CSS] Support CSS exports convention [CSS] support CSS local ident name [CSS] Support __webpack_nonce__ for CSS chunks [CSS] Support fetchPriority for CSS chunks [CSS] Allow to use LZW to compress css head meta (enabled in the production mode by default) [CSS] Support prefetch/preload for CSS chunks v5.90.3 Bug Fixes don't mangle when destructuring a reexport types for Stats.toJson() and Stats.toString() many internal types [CSS] clean up export css local vars Perf simplify and optimize chunk graph creation v5.90.2 Bug Fixes use Math.imul in fnv1a32 to avoid loss of precision, directly hash UTF16 values the setStatus() of the HMR module should not return an array, which may cause infinite recursion __webpack_exports_info__.xxx.canMangle shouldn't always same as default mangle export with destructuring use new runtime to reconsider skipped connections activeState make dynamic import optional in try/catch improve auto publicPath detection Dependencies & Maintenance improve CI setup and include Node.js@21
unsafeCache
snapshot.unmanagedPaths
fs
layer
supports
media
__webpack_nonce__
fetchPriority
production
Stats.toJson()
Stats.toString()
Math.imul
fnv1a32
setStatus()
__webpack_exports_info__.xxx.canMangle
activeState
try/catch
... (truncated)
60daca5
8dad9ce
@babel/preset-react
a3229f9
@babel/core
40c2e44
@types/node
a04faba
8f22221
8df6912
711c618
c462bb3
f0d3e3e
Updates @hapi/hoek from 6.2.4 to 8.5.1
@hapi/hoek
5bd73f6
4d0804b
4ae5f53
83019b8
b9aa286
5dcbb9c
d898b06
ea1741d
f6eb28d
8fa5664
Updates @hapi/topo from 3.1.0 to 3.1.6
@hapi/topo
745941e
e50af62
2a524b6
9e20087
80de44a
f793bd0
b79bfcf
87f9a7d
d5c2c62
acb364d
Updates express from 4.18.2 to 4.19.2
express
Sourced from express's releases.
4.19.2 What's Changed Improved fix for open redirect allow list bypass Full Changelog: https://github.com/expressjs/express/compare/4.19.1...4.19.2 4.19.1 What's Changed Fix ci after location patch by @wesleytodd in expressjs/express#5552 fixed un-edited version in history.md for 4.19.0 by @wesleytodd in expressjs/express#5556 Full Changelog: https://github.com/expressjs/express/compare/4.19.0...4.19.1 4.19.0 What's Changed fix typo in release date by @UlisesGascon in expressjs/express#5527 docs: nominating @wesleytodd to be project captian by @wesleytodd in expressjs/express#5511 docs: loosen TC activity rules by @wesleytodd in expressjs/express#5510 Add note on how to update docs for new release by @crandmck in expressjs/express#5541 Prevent open redirect allow list bypass due to encodeurl Release 4.19.0 by @wesleytodd in expressjs/express#5551 New Contributors @crandmck made their first contribution in expressjs/express#5541 Full Changelog: https://github.com/expressjs/express/compare/4.18.3...4.19.0 4.18.3 Main Changes Fix routing requests without method deps: body-parser@1.20.2 Fix strict json error message on Node.js 19+ deps: content-type@~1.0.5 deps: raw-body@2.5.2 Other Changes Use https: protocol instead of deprecated git: protocol by @vcsjones in expressjs/express#5032 build: Node.js@16.18 and Node.js@18.12 by @abenhamdine in expressjs/express#5034 ci: update actions/checkout to v3 by @armujahid in expressjs/express#5027 test: remove unused function arguments in params by @raksbisht in expressjs/express#5124 Remove unused originalIndex from acceptParams by @raksbisht in expressjs/express#5119 Fixed typos by @raksbisht in expressjs/express#5117 examples: remove unused params by @raksbisht in expressjs/express#5113 fix: parameter str is not described in JSDoc by @raksbisht in expressjs/express#5130 fix: typos in History.md by @raksbisht in expressjs/express#5131 build : add Node.js@19.7 by @abenhamdine in expressjs/express#5028 test: remove unused function arguments in params by @raksbisht in expressjs/express#5137
Full Changelog: https://github.com/expressjs/express/compare/4.19.1...4.19.2
@wesleytodd
Full Changelog: https://github.com/expressjs/express/compare/4.19.0...4.19.1
@UlisesGascon
@crandmck
Full Changelog: https://github.com/expressjs/express/compare/4.18.3...4.19.0
@vcsjones
@abenhamdine
@armujahid
@raksbisht
Sourced from express's changelog.
4.19.2 / 2024-03-25 Improved fix for open redirect allow list bypass 4.19.1 / 2024-03-20 Allow passing non-strings to res.location with new encoding handling checks 4.19.0 / 2024-03-20 Prevent open redirect allow list bypass due to encodeurl deps: cookie@0.6.0 4.18.3 / 2024-02-29 Fix routing requests without method deps: body-parser@1.20.2 Fix strict json error message on Node.js 19+ deps: content-type@~1.0.5 deps: raw-body@2.5.2 deps: cookie@0.6.0 Add partitioned option
partitioned
04bc627
da4d763
4f0f6cc
a003cfa
a1fa90f
11f2b1d
084e365
0867302
567c9c6
69a4cf2
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates follow-redirects from 1.15.4 to 1.15.6
follow-redirects
35a517c
c4f847f
8526b4a
b1677ce
d8914f7
Updates hosted-git-info from 2.7.1 to 2.8.9
hosted-git-info
Sourced from hosted-git-info's changelog.
2.8.9 (2021-04-07) Bug Fixes backport regex fix from #76 (29adfe5), closes #84 2.8.8 (2020-02-29) Bug Fixes #61 & #65 addressing issues w/ url.URL implmentation which regressed node 6 support (5038b18), closes #66 2.8.7 (2020-02-26) Bug Fixes Do not attempt to use url.URL when unavailable (2d0bb66), closes #61 #62 Do not pass scp-style URLs to the WhatWG url.URL (f2cdfcf), closes #60 2.8.6 (2020-02-25) 2.8.5 (2019-10-07) Bug Fixes updated pathmatch for gitlab (e8325b5), closes #51 updated pathmatch for gitlab (ffe056f) 2.8.4 (2019-08-12)
8d4b369
29adfe5
afeaefd
5038b18
7440afa
2d0bb66
f2cdfcf
e1b83df
ff259a6
624fd6f
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates ini from 1.3.5 to 1.3.8
ini
a2c5da8
af5c6bb
8b648a1
c74c8af
024b8b5
032fbaf
2da9039
cfea636
56d2805
This version was pushed to npm by isaacs, a new releaser for ini since your current version.
Updates postcss from 8.4.31 to 8.4.38
postcss
Sourced from postcss's releases.
8.4.38 Fixed endIndex: 0 in errors and warnings (by @romainmenke). 8.4.37 Fixed original.column are not numbers error in another case. 8.4.36 Fixed original.column are not numbers error on broken previous source map. 8.4.35 Avoid ! in node.parent.nodes type. Allow to pass undefined to node adding method to simplify types. 8.4.34 Fixed AtRule#nodes type (by @tim-we). Cleaned up code (by @DrKiraDmitry). 8.4.33 Fixed NoWorkResult behavior difference with normal mode (by @romainmenke). Fixed NoWorkResult usage conditions (by @ahmdammarr). 8.4.32 Fixed postcss().process() types (by @ferreira-tb).
endIndex: 0
@romainmenke
original.column are not numbers
!
node.parent.nodes
undefined
AtRule#nodes
@tim-we
@DrKiraDmitry
NoWorkResult
@ahmdammarr
postcss().process()
@ferreira-tb
Sourced from postcss's changelog.
8.4.38 Fixed endIndex: 0 in errors and warnings (by @romainmenke). 8.4.37 Fixed original.column are not numbers error in another case. 8.4.36 Fixed original.column are not numbers error on broken previous source map. 8.4.35 Avoid ! in node.parent.nodes type. Allow to pass undefined to node adding method to simplify types. 8.4.34 Fixed AtRule#nodes type (by Tim Weißenfels). Cleaned up code (by Dmitry Kirillov). 8.4.33 Fixed NoWorkResult behavior difference with normal mode (by Romain Menke). Fixed NoWorkResult usage conditions (by @ahmdammarr). 8.4.32 Fixed postcss().process() types (by Andrew Ferreira).
a69d45e
64e35d9
c1ad8fb
b45e7e9
1bea246
0fd1d86
49c906e
b5bd92c
2882039
e5ad939
Updates semver from 6.3.0 to 6.3.1
Updates express from 4.18.1 to 4.19.2
This version was pushed to npm by wesleytod... _Description has been truncated_
The major version update to webpack may cause breaking changes that need to be tested.
Superseded by #211.
Bumps the npm_and_yarn group with 10 updates in the / directory:
7.5.4
7.6.0
3.1.0
removed
4.47.0
5.91.0
6.2.4
8.5.1
3.1.0
3.1.6
4.18.2
4.19.2
1.15.4
1.15.6
2.7.1
2.8.9
1.3.5
1.3.8
8.4.31
8.4.38
Bumps the npm_and_yarn group with 5 updates in the /search-prototype directory:
6.3.0
6.3.1
4.18.1
4.19.2
1.15.4
1.15.6
3.1.8
3.1.10
1.2.3
1.2.5
Updates
semver
from 7.5.4 to 7.6.0Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
377f709
chore: release 7.6.0 (#661)a7ab13a
feat: preserve pre-release and build parts of a version on coerce (#671)816c7b2
chore: postinstall for dependabot template-oss PR0bd24d9
chore: bump@npmcli/template-oss
from 4.21.1 to 4.21.3e521932
chore: postinstall for dependabot template-oss PR8873991
chore: chore: chore: postinstall for dependabot template-oss PRf317dc8
chore: bump@npmcli/template-oss
from 4.19.0 to 4.21.07303db1
chore: add clean() test for build metadata (#658)6240d75
chore: add missing quotes in README.md (#656)14d263f
chore: postinstall for dependabot template-oss PRRemoves
glob-parent
Updates
webpack
from 4.47.0 to 5.91.0Release notes
Sourced from webpack's releases.
... (truncated)
Commits
60daca5
chore(release): 5.91.08dad9ce
chore(deps-dev): bump@babel/preset-react
from 7.23.3 to 7.24.1a3229f9
chore(deps-dev): bump@babel/core
from 7.24.0 to 7.24.140c2e44
chore(deps-dev): bump@types/node
from 20.11.29 to 20.11.30a04faba
chore(deps-dev): bump memfs from 4.7.7 to 4.8.08f22221
chore(deps): bump es-module-lexer from 1.4.1 to 1.4.28df6912
chore(deps): bump es-module-lexer from 1.4.1 to 1.4.2711c618
chore(deps-dev): bump memfs from 4.7.7 to 4.8.0c462bb3
chore(deps-dev): bump@types/node
from 20.11.29 to 20.11.30f0d3e3e
chore(deps-dev): bump@babel/preset-react
from 7.23.3 to 7.24.1Updates
@hapi/hoek
from 6.2.4 to 8.5.1Commits
5bd73f6
8.5.14d0804b
Backport #352. Closes #3534ae5f53
8.5.083019b8
Add isPromise(). Closes #346b9aa286
Add declaration5dcbb9c
8.4.0d898b06
Add TS utils. Closes #345ea1741d
8.3.2f6eb28d
Improve clone() performance. Closes #3448fa5664
8.3.1Updates
@hapi/topo
from 3.1.0 to 3.1.6Commits
745941e
3.1.6e50af62
Hoek dep. Closes #582a524b6
3.1.59e20087
Remove types. Closes #5680de44a
3.1.4f793bd0
Cleanupb79bfcf
Merge pull request #46 from jarrodyellets/master87f9a7d
Update README.mdd5c2c62
Merge pull request #47 from jarrodyellets/apiUpdateacb364d
update APIUpdates
express
from 4.18.2 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
04bc627
4.19.2da4d763
Improved fix for open redirect allow list bypass4f0f6cc
4.19.1a003cfa
Allow passing non-strings to res.location with new encoding handling checks f...a1fa90f
fixed un-edited version in history.md for 4.19.011f2b1d
build: fix build due to inconsistent supertest behavior in older versions084e365
4.19.00867302
Prevent open redirect allow list bypass due to encodeurl567c9c6
Add note on how to update docs for new release (#5541)69a4cf2
deps: cookie@0.6.0Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates
follow-redirects
from 1.15.4 to 1.15.6Commits
35a517c
Release version 1.15.6 of the npm package.c4f847f
Drop Proxy-Authorization across hosts.8526b4a
Use GitHub for disclosure.b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.Updates
hosted-git-info
from 2.7.1 to 2.8.9Changelog
Sourced from hosted-git-info's changelog.
... (truncated)
Commits
8d4b369
chore(release): 2.8.929adfe5
fix: backport regex fix from #76afeaefd
chore(release): 2.8.85038b18
fix: #61 & #65 addressing issues w/ url.URL implmentation which regressed nod...7440afa
chore(release): 2.8.72d0bb66
fix: Do not attempt to use url.URL when unavailablef2cdfcf
fix: Do not pass scp-style URLs to the WhatWG url.URLe1b83df
chore(release): 2.8.6ff259a6
Ensure passwords in hosted Git URLs are correctly escaped624fd6f
chore(release): 2.8.5Maintainer changes
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates
ini
from 1.3.5 to 1.3.8Commits
a2c5da8
1.3.8af5c6bb
Do not use Object.create(null)8b648a1
don't test where our devdeps don't even workc74c8af
1.3.7024b8b5
update deps, add linting032fbaf
Use Object.create(null) to avoid default object property hazards2da9039
1.3.6cfea636
better git push script, before publish instead of after56d2805
do not allow invalid hazardous string as section nameMaintainer changes
This version was pushed to npm by isaacs, a new releaser for ini since your current version.
Updates
postcss
from 8.4.31 to 8.4.38Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
a69d45e
Release 8.4.38 version64e35d9
Update dependenciesc1ad8fb
Merge pull request #1932 from romainmenke/fix-warning-end-index--inventive-nu...b45e7e9
fix endIndex1bea246
failing test: for endIndex 0 in rangeBy0fd1d86
Add changelog auto release on Github49c906e
Release 8.4.37 versionb5bd92c
Fix another broken prev source map issue2882039
Update dependenciese5ad939
Release 8.4.36 versionUpdates
semver
from 6.3.0 to 6.3.1Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
377f709
chore: release 7.6.0 (#661)a7ab13a
feat: preserve pre-release and build parts of a version on coerce (#671)816c7b2
chore: postinstall for dependabot template-oss PR0bd24d9
chore: bump@npmcli/template-oss
from 4.21.1 to 4.21.3e521932
chore: postinstall for dependabot template-oss PR8873991
chore: chore: chore: postinstall for dependabot template-oss PRf317dc8
chore: bump@npmcli/template-oss
from 4.19.0 to 4.21.07303db1
chore: add clean() test for build metadata (#658)6240d75
chore: add missing quotes in README.md (#656)14d263f
chore: postinstall for dependabot template-oss PRUpdates
express
from 4.18.1 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
04bc627
4.19.2da4d763
Improved fix for open redirect allow list bypass4f0f6cc
4.19.1a003cfa
Allow passing non-strings to res.location with new encoding handling checks f...a1fa90f
fixed un-edited version in history.md for 4.19.011f2b1d
build: fix build due to inconsistent supertest behavior in older versions084e365
4.19.00867302
Prevent open redirect allow list bypass due to encodeurl567c9c6
Add note on how to update docs for new release (#5541)69a4cf2
deps: cookie@0.6.0Maintainer changes
This version was pushed to npm by wesleytod... _Description has been truncated_