npm-plugin: upgraded to the beta, which upgrades npm to v8 (f634b8c)
upgrade marked to resolve ReDos vulnerability (#2330) (d9e5bc0)
BREAKING CHANGES
npm-plugin:@semantic-release/npm has also dropped support for node v15
node v15 has been removed from our defined supported versions of node. this was done to upgrade to compatible versions of marked and marked-terminal that resolved the ReDoS vulnerability. removal of support of this node version should be low since it was not an LTS version and has been EOL for several months already.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/jo/couchdb-push/network/alerts).
Bumps marked and semantic-release. These dependencies needed to be updated together. Updates
marked
from 2.1.3 to 4.0.18Release notes
Sourced from marked's releases.
... (truncated)
Commits
459085b
chore(release): 4.0.18 [skip ci]9fb5721
🗜️ build [skip ci]01c98d1
fix: fix heading in list item (#2520)c906a1f
chore(deps): Bump moment from 2.29.3 to 2.29.4 (#2530)7b39f94
chore(deps-dev): Bump rollup from 2.75.7 to 2.76.0 (#2528)9633c19
chore(deps-dev): Bump@​semantic-release/github
from 8.0.4 to 8.0.5 (#2529)2e7c61d
chore(deps-dev): Bump eslint from 8.18.0 to 8.19.0 (#2522)3302455
chore(deps-dev): Bump@​babel/core
from 7.18.5 to 7.18.6 (#2523)e5b9e1d
chore(deps-dev): Bump eslint-plugin-n from 15.2.3 to 15.2.4 (#2524)32fa61a
chore(deps-dev): Bump@​babel/preset-env
from 7.18.2 to 7.18.6 (#2525)Updates
semantic-release
from 18.0.0 to 19.0.3Release notes
Sourced from semantic-release's releases.
... (truncated)
Commits
58a226f
fix(log-repo): use the original form of the repo url to remove the need to ma...17d60d3
build(deps): bump npm from 8.3.1 to 8.12.0 (#2447)ab45ab1
chore(lint): disabled rules that dont apply to this project (#2408)ea389c3
chore(deps): update dependency yargs-parser to 13.1.2 [security] (#2402)fa994db
build(deps): bump node-fetch from 2.6.1 to 2.6.7 (#2399)b79116b
build(deps): bump trim-off-newlines from 1.0.1 to 1.0.36fd7e56
build(deps): bump minimist from 1.2.5 to 1.2.62b94bb4
docs: update broken link to CI config recipes (#2378)b4bc191
docs: Correct circleci workflow (#2365)2c30e26
Merge pull request #2333 from semantic-release/nextDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/jo/couchdb-push/network/alerts).