Fix: Properties with the name __proto__ are added to objects and arrays.
(#199) This also fixes a prototype pollution vulnerability reported by
Jonathan Gregson! (#295).
v2.2.1
Fix: Removed dependence on minimist to patch CVE-2021-44906. (#266)
Fix: Properties with the name __proto__ are added to objects and arrays.
(#199) This also fixes a prototype pollution vulnerability reported by
Jonathan Gregson! (#295).
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/keep-network/website/network/alerts).
Bumps json5 to 2.2.2 and updates ancestor dependencies json5, gatsby, gatsby-plugin-netlify-cms, gatsby-plugin-purgecss, gatsby-plugin-sass and react-hot-loader. These dependencies need to be updated together.
Updates
json5
from 2.2.0 to 2.2.2Release notes
Sourced from json5's releases.
Changelog
Sourced from json5's changelog.
Commits
14f8cb1
2.2.210cc7ca
docs: update CHANGELOG for v2.2.27774c10
fix: add proto to objects and arraysedde30a
Readme: slight tweak to intro97286f8
Improve example in readmed720b4f
Improve readme (e.g. explain JSON5 better!) (#291)910ce25
docs: fix spelling of Aseem2aab4dd
test: require tap as t in cli tests6d42686
test: remove mocha syntax from tests4798b9d
docs: update installation and usage for modulesUpdates
gatsby
from 2.20.14 to 5.3.3Release notes
Sourced from gatsby's releases.
... (truncated)
Commits
da692c7
chore(release): Publishe333019
fix(gatsby-transformer-remark): Disallow JS frontmatter by default (#37244) (...3e7e996
fix(gatsby): [rendering engines] use results of exports removal if sourceMap ...f448e12
fix(gatsby): don't output file-loader assets to .cache (#37284) (#37295)8fc123c
chore(release): Publishb7477f4
fix(gatsby-plugin-image): Normalize filename for correct hashing (#37262) (#3...98cbee1
chore(release): Publisha283319
fix(gatsby): use file:// protocol when importing gatsby-config/node (#37257) ...287cabd
chore(release): Publishe9aafe4
Revert "fix(deps): update dependency lmdb to v2.7.1 (#37160)" (#37255) (#37258)Updates
gatsby-plugin-netlify-cms
from 4.2.2 to 7.3.0Release notes
Sourced from gatsby-plugin-netlify-cms's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-netlify-cms's changelog.
... (truncated)
Commits
b995fc2
chore(release): Publish30c8c61
chore(changelogs): update changelogs (#37106)7c27b0d
chore(release): Publish next pre-minor0befc25
chore(changelogs): update changelogs (#37078)f459f92
chore(release): Publish next pre-minorc6fc609
chore(changelogs): update changelogs (#36989)b556db3
chore(release): Publish next pre-minor964265c
chore(release): Publish nextb624442
chore: Update peerDeps (#36965)f4959a4
chore(release): Publish nextMaintainer changes
This version was pushed to npm by marvinjudehk, a new releaser for gatsby-plugin-netlify-cms since your current version.
Updates
gatsby-plugin-purgecss
from 4.0.1 to 6.1.2Release notes
Sourced from gatsby-plugin-purgecss's releases.
... (truncated)
Commits
37d940a
Release 6.1.2fed322c
build: update packages50b9e98
build: fix node version5e1246b
docs: update funding fieldsd6c8c9d
chore(deps): update dependency eslint-plugin-unicorn to v42d462cb7
chore(deps): update dependency eslint-plugin-sonarjs to ^0.13.0992eae0
chore(deps): update dependency eslint-plugin-unicorn to v41025eb90
chore(deps): update dependency dotenv-cli to v51808d6e
build: add funding field8f94a72
Create FUNDING.ymlUpdates
gatsby-plugin-sass
from 2.2.1 to 6.3.1Release notes
Sourced from gatsby-plugin-sass's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-sass's changelog.
... (truncated)
Commits
287cabd
chore(release): Publishb995fc2
chore(release): Publish03d6c59
chore(release): Publish next1dc347c
chore(release): Publish next11efd36
chore(release): Publish next30c8c61
chore(changelogs): update changelogs (#37106)7c27b0d
chore(release): Publish next pre-minor2d967cb
tests: Update pluginOptionsSchema tests (#27904)0befc25
chore(changelogs): update changelogs (#37078)f459f92
chore(release): Publish next pre-minorMaintainer changes
This version was pushed to npm by marvinjudehk, a new releaser for gatsby-plugin-sass since your current version.
Updates
react-hot-loader
from 4.12.20 to 4.13.1Release notes
Sourced from react-hot-loader's releases.
Changelog
Sourced from react-hot-loader's changelog.
Commits
07d1f4e
4.13.1bddd179
update loader-utils version (#1849)f58a931
Remove space after peerDependency version definition (#1843)642b705
README.md
fix typo (#1811)ed8b310
Note create-react-app support for fast refresh in readme (#1708)6032f42
chore(release): 4.13.0c05396b
feat: support React 17 (#1557)e44103a
fix: tailUpdate might be blocked by a PureComponent (#1448)74d3d9b
Merge pull request #1513 from gaearon/gaearon-patch-1d73d505
README: Link to Fast Refresh Webpack pluginDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/keep-network/website/network/alerts).