Open dependabot[bot] opened 4 days ago
Add one of following labels
- kind/feature -> Use it when you want to submit a new feature
- kind/enhancement -> Use it when you modify or improve an existing feature
- kind/bug -> Use it when you fix a bug
Bumps jsonpath-plus to 10.1.0 and updates ancestor dependency @kubernetes/client-node. These dependencies need to be updated together.
Updates
jsonpath-plus
from 0.19.0 to 10.1.0Release notes
Sourced from jsonpath-plus's releases.
... (truncated)
Changelog
Sourced from jsonpath-plus's changelog.
... (truncated)
Commits
93612a3
chore: bump version4a16cbd
feat: add undefined, null literals to safe scriptf119fe3
feat: add typeof operator to safe scriptb70aa71
fix(security): preventconstructor
access in safe vm763ada0
fix(security): preventcall
/apply
invocation ofFunction
98a6b22
fix: remove overly aggressive disabling of native functions but disallow `__p...30194c7
fix(security): further prevent binding of Function calls which may evade dete...eac48fe
fix(security): prevent binding of Function calls which may evade detection34a836b
chore: bump version5a22e3f
fix(security): prevent Function calls outside of member expressionsUpdates
@kubernetes/client-node
from 0.15.1 to 0.22.2Release notes
Sourced from
@kubernetes/client-node
's releases.... (truncated)
Commits
88da3bd
Rev to new version.25c3b04
Merge pull request #1993 from kubernetes-client/dependabot/npm_and_yarn/mocha...c803b15
Merge pull request #1976 from ArpanSolanki29/masterffc04fd
Merge pull request #1992 from kubernetes-client/dependabot/npm_and_yarn/types...d1d7483
build(deps-dev): bump mocha from 10.7.3 to 10.8.13b4dc5c
build(deps-dev): bump@types/node
from 22.8.2 to 22.8.45131a49
Merge pull request #1988 from kubernetes-client/dependabot/npm_and_yarn/types...5ba5196
Merge pull request #1987 from kubernetes-client/dependabot/npm_and_yarn/types...21b88e9
build(deps-dev): bump@types/chai
from 5.0.0 to 5.0.1c5e1940
build(deps-dev): bump@types/node
from 22.8.1 to 22.8.2Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show