NaturalIntelligence / fast-xml-parser

Validate XML, Parse XML and Build XML rapidly without C/C++ based libraries and no callback.
https://naturalintelligence.github.io/fast-xml-parser/
MIT License
2.49k stars 302 forks source link

Bump https-proxy-agent and publish-please #504

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Removes https-proxy-agent. It's no longer used after updating ancestor dependency publish-please. These dependencies need to be updated together.

Removes https-proxy-agent

Updates publish-please from 2.4.1 to 5.5.2

Release notes

Sourced from publish-please's releases.

v5.5.1

[5.5.1] - 2019-07-28

Fixed

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#551---2019-07-28

v5.5.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#550---2019-07-01

v5.4.3

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#543---2018-12-02

v5.4.2

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#542---2018-11-29

v5.4.1

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#541---2018-11-26

v5.4.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#540---2018-11-26

v5.3.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#530---2018-11-21

v5.2.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#520---2018-11-04

v5.1.1

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#511---2018-10-30

v5.1.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#510---2018-10-29

v5.0.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#5000---2018-10-27

v4.1.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#410---2018-10-13

v4.0.1

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#401---2018-10-11

v4.0.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#400---2018-10-01

v3.2.0

Changelog: https://github.com/inikulin/publish-please/blob/master/CHANGELOG.md#320---2018-07-15

... (truncated)

Changelog

Sourced from publish-please's changelog.

[5.5.2] - 2020-10-08

Fixed

[5.5.1] - 2019-07-28

Fixed

[5.5.0] - 2019-07-01

Added

[5.4.3] - 2018-12-02

Changed

  • align the README with all previous changes

[5.4.2] - 2018-11-29

Fixed

  • fix CI reporter on TeamCity

[5.4.1] - 2018-11-26

Fixed

  • package 5.4.0 was published too early. Do not use it.

[5.4.0] - 2018-11-26

Changed

  • dry-run workflow should not prompt for user input

Fixed

  • tgz file is left in project directory after successfull dry-run

Fixed

  • last message showned in publishing workflow is not correct

[5.3.0] - 2018-11-21

Added

  • add a CI reporter and be able to automatically switch from elegant status reporter to CI reporter when running on CI

[5.2.0] - 2018-11-04

Added

  • be able to override .sensitivedata on per project basis

[5.1.1] - 2018-10-30

Fixed

  • fix: tgz file is left in project directory after publishing

[5.1.0] - 2018-10-29

Changed

  • update/remove dependencies

[5.0.0] - 2018-10-27

Fixed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by rb3as, a new releaser for publish-please since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/NaturalIntelligence/fast-xml-parser/network/alerts).
coveralls commented 1 year ago

Coverage Status

Coverage: 98.261%. Remained the same when pulling 2a2dff70d8a0904ad2d80513a20c2f8238485737 on dependabot/npm_and_yarn/https-proxy-agent-and-publish-please--removed into 7a7dbac2d0ccf3b7176f38b2ae91600e3c5db0bd on master.

guardrails[bot] commented 1 year ago

:warning: We detected 32 security issues in this pull request:

Vulnerable Libraries (32)
Severity | Details ----- | -------- High | [pkg:npm/decode-uri-component@0.2.2@0.2.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json) (t) - **no patch available** High | [pkg:npm/decode-uri-component@0.2.2@0.2.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) - **no patch available** High | [pkg:npm/json5@1.0.2@1.0.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) upgrade to: *2.2.2* Critical | [pkg:npm/set-value@2.0.1@2.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) - **no patch available** Critical | [pkg:npm/set-value@2.0.1@2.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json) (t) - **no patch available** Critical | [pkg:npm/set-value@2.0.1@2.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L8097) (t) - **no patch available** Critical | [pkg:npm/loader-utils@1.4.2@1.4.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) - **no patch available** High | [pkg:npm/json-stable-stringify@0.0.1@0.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json) (t) - **no patch available** High | [pkg:npm/json-stable-stringify@0.0.1@0.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) - **no patch available** Critical | [pkg:npm/unset-value@1.0.0@1.0.0](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L9216) (t) - **no patch available** Critical | [pkg:npm/unset-value@1.0.0@1.0.0](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) - **no patch available** Critical | [pkg:npm/lodash@4.17.20@4.17.20](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) - **no patch available** N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L13449) (t) upgrade to: *3.1.0* N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock) (t) upgrade to: *3.1.0* High | [pkg:npm/decode-uri-component@0.2.2@0.2.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L3802) (t) - **no patch available** High | [pkg:npm/decode-uri-component@0.2.2@0.2.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L12845) (t) - **no patch available** High | [pkg:npm/decode-uri-component@0.2.2@0.2.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L2015) (t) - **no patch available** High | [pkg:npm/json5@1.0.2@1.0.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L3174) (t) upgrade to: *2.2.2* Critical | [pkg:npm/set-value@2.0.1@2.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L4126) (t) - **no patch available** Critical | [pkg:npm/set-value@2.0.1@2.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L8082) (t) - **no patch available** Critical | [pkg:npm/set-value@2.0.1@2.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L16136) (t) - **no patch available** Critical | [pkg:npm/loader-utils@1.4.2@1.4.2](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L3238) (t) - **no patch available** High | [pkg:npm/json-stable-stringify@0.0.1@0.0.1](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L3168) (t) - **no patch available** Critical | [pkg:npm/unset-value@1.0.0@1.0.0](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L17024) (t) - **no patch available** Critical | [pkg:npm/unset-value@1.0.0@1.0.0](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L4608) (t) - **no patch available** Medium | [pkg:npm/lodash@4.17.20@4.17.20](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json) (t) upgrade to: *4.17.21,4.17.21* Critical | [pkg:npm/lodash@4.17.20@4.17.20](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L3283) (t) - **no patch available** N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json) (t) upgrade to: *3.1.0* N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L4594) (t) upgrade to: *3.1.0* N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L8298) (t) upgrade to: *3.1.0* N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/package-lock.json#L16263) (t) upgrade to: *3.1.0* N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/NaturalIntelligence/fast-xml-parser/blob/2a2dff70d8a0904ad2d80513a20c2f8238485737/yarn.lock#L1999) (t) upgrade to: *3.1.0* More info on how to fix Vulnerable Libraries in [JavaScript](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/using_vulnerable_libraries.html?utm_source=ghpr#).

👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

dependabot[bot] commented 1 year ago

Looks like these dependencies are no longer a dependency, so this is no longer needed.