NOTE: This version fixes a security vulnerability allowing denial of service attacks with a specially crafted request payload.
Please update as soon as possible.
Fixed
switched to use Array.isArray in array checks from instanceof operator
Changed
libphonenumber-js package updated to 1.9.43 from 1.9.7
This version was pushed to npm by typestack-release-bot, a new releaser for class-validator since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/bangbang93/minecraft-proxy/network/alerts).
Bumps validator and class-validator. These dependencies needed to be updated together. Updates
validator
from 12.0.0 to 13.7.0Release notes
Sourced from validator's releases.
... (truncated)
Changelog
Sourced from validator's changelog.
... (truncated)
Commits
47ee5ad
13.7.0496fc8b
fix(rtrim): remove regex to prevent ReDOS attack (#1738)45901ec
Merge pull request #1851 from validatorjs/chore/fix-merge-conflicts83cb7f8
chore: merge conflict clean-upf17e220
feat(isMobilePhone): add El Salvador es-SV locale5b06703
feat(isMobilePhone): add Palestine ar-PS localea3faa83
feat(isMobilePhone): add Botswana en-BW locale26605f9
feat(isMobilePhone): add Turkmenistan tk-TM0e5d5d4
feat(isMobilePhone): add Guyana en-GY localef7ff349
feat(isMobilePhone): add Frech Polynesia fr-PF localeMaintainer changes
This version was pushed to npm by profnandaa, a new releaser for validator since your current version.
Updates
class-validator
from 0.11.0 to 0.13.2Changelog
Sourced from class-validator's changelog.
... (truncated)
Commits
5f91937
merge: release 0.13.2 (#1409)8e841ef
refactor: ignore linter error6a57621
refactor: format code with latest Prettier6c50113
build: bump version to 0.13.2495a275
docs: add changelog for 0.13.270278ab
build: move@types/validator
to dev dependenciesbdcf15c
fix: use Array.isArray instead of instanceof checksc6984bb
build: squash dependabot commits into one since last released0cb39f
build: update GH action for Dependabot auto-merge945f154
build(deps-dev): bump eslint-plugin-jest from 24.1.9 to 24.3.2 (#973)Maintainer changes
This version was pushed to npm by typestack-release-bot, a new releaser for class-validator since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/bangbang93/minecraft-proxy/network/alerts).