Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/exa-analytics/exatomic/network/alerts).
Bumps url-parse, @jupyter-widgets/base and @jupyter-widgets/controls. These dependencies needed to be updated together. Updates
url-parse
from 1.4.7 to 1.5.10Commits
8cd4c6c
1.5.10ce7a01f
[fix] Improve handling of empty port0071490
[doc] Update JSDoc commenta7044e3
[minor] Use more descriptive variable named547792
[security] Add credits for CVE-2022-0691ad23357
1.5.90e3fb54
[fix] Strip all control characters from the beginning of the URL61864a8
[security] Add credits for CVE-2022-0686bb0104d
1.5.8d5c6479
[fix] Handle the case where the port is specified but emptyUpdates
@jupyter-widgets/base
from 3.0.0 to 6.0.1Release notes
Sourced from
@jupyter-widgets/base
's releases.Commits
0688d8c
Bump versione5d8713
Merge pull request #3583 from jasongrout/migrationitems3aaa094
Change typescript migration example to js9120bf9
Remove migration note about selection widgets and dictionaries, now that we r...1609e12
Merge pull request #3582 from jasongrout/migratedefaults4c1fbb4
Add a note about defining widget model defaults with es6 inheritance.6ddc642
Merge pull request #3571 from vidartf/narrow-deserialize3a60698
Merge pull request #3581 from vidartf/datetime-fix04ecd58
Fix docs typo9618f39
Fix porting errorUpdates
@jupyter-widgets/controls
from 2.0.0 to 5.0.1Commits
0688d8c
Bump versione5d8713
Merge pull request #3583 from jasongrout/migrationitems3aaa094
Change typescript migration example to js9120bf9
Remove migration note about selection widgets and dictionaries, now that we r...1609e12
Merge pull request #3582 from jasongrout/migratedefaults4c1fbb4
Add a note about defining widget model defaults with es6 inheritance.6ddc642
Merge pull request #3571 from vidartf/narrow-deserialize3a60698
Merge pull request #3581 from vidartf/datetime-fix04ecd58
Fix docs typo9618f39
Fix porting errorDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/exa-analytics/exatomic/network/alerts).