asyncapi / generator

Use your AsyncAPI definition to generate literally anything. Markdown documentation, Node.js code, HTML documentation, anything!
https://asyncapi.com/docs/tools/generator
Apache License 2.0
767 stars 232 forks source link

chore(deps): bump jsonpath-plus and @asyncapi/parser in /apps/generator/test/test-templates/nunjucks-template #1317

Closed dependabot[bot] closed 4 days ago

dependabot[bot] commented 4 days ago

Bumps jsonpath-plus and @asyncapi/parser. These dependencies needed to be updated together. Updates jsonpath-plus from 7.1.0 to 10.1.0

Release notes

Sourced from jsonpath-plus's releases.

v7.2.0

7.2.0 (2022-09-02)

Changelog

Sourced from jsonpath-plus's changelog.

10.1.0

  • feat: add typeof operator to safe script

10.0.7

  • fix(security): prevent constructor access
  • docs: add security policy file

10.0.6

  • fix(security): prevent call/apply invocation of Function

10.0.5

  • fix: remove overly aggressive disabling of native functions but disallow __proto__

10.0.4

  • fix(security): further prevent binding of Function calls which may evade detection

10.0.3

  • fix(security): prevent binding of Function calls which may evade detection

10.0.2

  • fix(security): prevent Function calls outside of member expressions

10.0.1

  • fix(security): prohibit Function in "safe" vm

10.0.0

BREAKING CHANGES:

  • Require Node 18+

  • fix(security): use safe vm by default in Node

  • chore: bump jsep, devDeps. and lint

9.0.0

BREAKING CHANGES:

  • Removes preventEval property. Prefer eval: false instead.

  • Changed behavior of eval property. In the browser, eval/Function won't be used by default to evaluate expressions. Instead, we'll safely evaluate using a subset of JavaScript. To resume using unsafe eval in the browser, pass in the option eval: "native"

  • feat: add safe eval for browser and eval option (#185) (@​80avin)

  • feat: add ignoreEvalErrors property (@​80avin)

... (truncated)

Commits
  • 93612a3 chore: bump version
  • 4a16cbd feat: add undefined, null literals to safe script
  • f119fe3 feat: add typeof operator to safe script
  • b70aa71 fix(security): prevent constructor access in safe vm
  • 763ada0 fix(security): prevent call/apply invocation of Function
  • 98a6b22 fix: remove overly aggressive disabling of native functions but disallow `__p...
  • 30194c7 fix(security): further prevent binding of Function calls which may evade dete...
  • eac48fe fix(security): prevent binding of Function calls which may evade detection
  • 34a836b chore: bump version
  • 5a22e3f fix(security): prevent Function calls outside of member expressions
  • Additional commits viewable in compare view


Updates @asyncapi/parser from 3.2.2 to 3.4.0

Release notes

Sourced from @​asyncapi/parser's releases.

@​asyncapi/parser@​3.4.0

Minor Changes

  • e18f865: Updating jsonpath-plus dependency to mitigate CVE-2024-21534

@​asyncapi/parser@​3.3.0

Minor Changes

  • bebbd39: feat: create rule asyncapi3-channel-no-query-nor-fragment for v3 core ruleset
Commits
  • 7c7c556 chore(release): version packages (#1059)
  • e18f865 chore(deps): bump jsonpath-plus to ^10.0.0 to mitigate CVE-2024-21534 (#1058)
  • dd8c9e8 docs: fix stringify example broken link in README (#1055)
  • 1560df3 chore(release): version packages (#1054)
  • bebbd39 feat: create rule asyncapi3-channel-no-query-nor-fragment for v3 core rules...
  • 0d33904 chore(deps-dev): bump webpack from 5.93.0 to 5.94.0 (#1053)
  • efc05af fix: update @​asyncapi/specs to 6.8.0 version and others (#1052)
  • See full diff in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/asyncapi/generator/network/alerts).
changeset-bot[bot] commented 4 days ago

⚠️ No Changeset found

Latest commit: 10946c204481426b518f1e63660c02954089b374

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

sonarcloud[bot] commented 4 days ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud