Ultimate release that fixes both CVE-2024-4067 and CVE-2024-4068. We consider the issues low-priority, so even if you see automated scanners saying otherwise, don't be scared.
This version was pushed to npm by evilebottnawi, a new releaser for webpack since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/northumbrian-data/style/network/alerts).
Bumps micromatch to 4.0.8 and updates ancestor dependencies micromatch, @storybook/addon-essentials, @storybook/addon-interactions, @storybook/core-common, @storybook/react and webpack. These dependencies need to be updated together.
Updates
micromatch
from 4.0.5 to 4.0.8Release notes
Sourced from micromatch's releases.
Changelog
Sourced from micromatch's changelog.
Commits
8bd704e
4.0.8a0e6841
run verb to generate README documentation4ec2884
Merge branch 'v4' into hauserkristof-feature/v4.0.803aa805
Merge pull request #266 from hauserkristof/feature/v4.0.8814f5f7
lint67fcce6
fix: CHANGELOG about braces & CVE-2024-4068, v4.0.5113f2e3
fix: CVE numbers in CHANGELOGd9dbd9a
feat: updated CHANGELOG2ab1315
fix: use actions/setup-node@v41406ea3
feat: rework test to work on macos with node 10,12 and 14Updates
@storybook/addon-essentials
from 6.5.9 to 8.2.9Release notes
Sourced from
@storybook/addon-essentials
's releases.... (truncated)
Changelog
Sourced from
@storybook/addon-essentials
's changelog.... (truncated)
Commits
95d8beb
Bump version from "8.2.8" to "8.2.9" [skip ci]2faeae2
Bump version from "8.2.7" to "8.2.8" [skip ci]97d8476
Bump version from "8.2.6" to "8.2.7" [skip ci]ea266a0
Bump version from "8.2.5" to "8.2.6" [skip ci]e3c5995
Bump version from "8.2.4" to "8.2.5" [skip ci]7b84561
Bump version from "8.2.3" to "8.2.4" [skip ci]7067b33
Bump version from "8.2.2" to "8.2.3" [skip ci]480359d
Bump version from "8.2.1" to "8.2.2" [skip ci]9c3d891
Bump version from "8.2.0" to "8.2.1" [skip ci]8b2f2db
Bump version from "8.2.0-beta.3" to "8.2.0" [skip ci]Updates
@storybook/addon-interactions
from 6.5.9 to 8.2.9Release notes
Sourced from
@storybook/addon-interactions
's releases.... (truncated)
Changelog
Sourced from
@storybook/addon-interactions
's changelog.... (truncated)
Commits
95d8beb
Bump version from "8.2.8" to "8.2.9" [skip ci]2faeae2
Bump version from "8.2.7" to "8.2.8" [skip ci]97d8476
Bump version from "8.2.6" to "8.2.7" [skip ci]ea266a0
Bump version from "8.2.5" to "8.2.6" [skip ci]e3c5995
Bump version from "8.2.4" to "8.2.5" [skip ci]7b84561
Bump version from "8.2.3" to "8.2.4" [skip ci]7067b33
Bump version from "8.2.2" to "8.2.3" [skip ci]480359d
Bump version from "8.2.1" to "8.2.2" [skip ci]b33493e
Merge pull request #28518 from storybookjs/norrbert/cpc-bring-back-test-dep-t...9c3d891
Bump version from "8.2.0" to "8.2.1" [skip ci]Updates
@storybook/core-common
from 6.5.9 to 8.2.9Release notes
Sourced from
@storybook/core-common
's releases.... (truncated)
Commits
f2218fa
wip5aa7cfc
Merge branch 'next' into save-from-controls5b24137
Merge branch 'save-from-controls' of https://github.com/storybookjs/storybook...aee76c7
fix layout of error screen in previewdf9f64f
Merge remote-tracking branch 'refs/remotes/origin/next' into kasper/module-mo...9b836fe
Fix paths util5e63c2f
Fix issue with getProjectRoot function in paths.ts when user does not use rev...15901b9
thrown when missingeeabdb6
redesign error screencfb552c
Merge pull request #26809 from storybookjs/valentin/formatterUpdates
@storybook/react
from 6.5.9 to 8.2.9Release notes
Sourced from
@storybook/react
's releases.... (truncated)
Changelog
Sourced from
@storybook/react
's changelog.... (truncated)
Commits
95d8beb
Bump version from "8.2.8" to "8.2.9" [skip ci]2faeae2
Bump version from "8.2.7" to "8.2.8" [skip ci]97d8476
Bump version from "8.2.6" to "8.2.7" [skip ci]9a36be4
Merge pull request #28764 from storybookjs/kasper/introduce-run3333ee1
Merge pull request #28745 from storybookjs/norbert/cpc-fix-types-usageea266a0
Bump version from "8.2.5" to "8.2.6" [skip ci]e3c5995
Bump version from "8.2.4" to "8.2.5" [skip ci]beb96d5
git cherry-pick -m1 -x 4db60d6d8cefabb235c9245375c1699c5b0fcd5e7b84561
Bump version from "8.2.3" to "8.2.4" [skip ci]de22531
Merge pull request #28599 from storybookjs/norbert/cpc-add-shim-dependencies-...Updates
webpack
from 4.46.0 to 5.94.0Release notes
Sourced from webpack's releases.
... (truncated)
Commits
eabf85d
chore(release): 5.94.0955e057
security: fix DOM clobbering in auto public path9822387
test: fixcbb86ed
test: fix5ac3d7f
fix: unexpected asi generation with sequence expression2411661
security: fix DOM clobbering in auto public pathb8c03d4
fix: unexpected asi generation with sequence expressionf46a03c
revert: do not use heuristic fallback for "module-import"60f1898
fix: do not use heuristic fallback for "module-import"66306aa
Revert "fix: module-import get fallback from externalsPresets"Maintainer changes
This version was pushed to npm by evilebottnawi, a new releaser for webpack since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show