Closed dependabot[bot] closed 1 week ago
The following labels could not be found: dependencies
, live
, nodejs
.
[!IMPORTANT]
Review skipped
Bot user detected.
To trigger a single review, invoke the
@coderabbitai review
command.You can disable this status message by setting the
reviews.review_status
tofalse
in the CodeRabbit configuration file.
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version
or @dependabot ignore this minor version
. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore
condition with the desired update_types
to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
Bumps helmet from 7.2.0 to 8.0.0.
Changelog
Sourced from helmet's changelog.
Commits
9a8e6d5
8.0.06562cd7
CSP: speed upgetDefaultDirectives
a8befb3
getDefaultDirectives
should do a deep copy558ef2c
HSTS: throw when misspelling "includeSubDomains" option73e7595
Content-Security-Policy: throw if directive value lacks necessary quotes76410e1
Content-Security-Policy can now use Object.hasOwn293bd18
Strict-Transport-Security: increase max-age to 1 year898cdc4
Require Node 18+Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show