mdn / express-locallibrary-tutorial

Local Library website written in NodeJS/Express; example for the MDN server-side development NodeJS module: https://developer.mozilla.org/en-US/docs/Learn/Server-side/Express_Nodejs.
Creative Commons Zero v1.0 Universal
1.23k stars 697 forks source link

Bump helmet from 7.0.0 to 7.1.0 #241

Closed dependabot[bot] closed 9 months ago

dependabot[bot] commented 10 months ago

Bumps helmet from 7.0.0 to 7.1.0.

Changelog

Sourced from helmet's changelog.

7.1.0 - 2023-11-07

Added

  • helmet.crossOriginEmbedderPolicy now supports the unsafe-none directive. See #477
Commits
  • 9d93280 7.1.0
  • b8eedf9 Update changelog for 7.1.0 release
  • 19d2295 Add additional package keywords
  • 977466f Update devDependencies to latest versions
  • 466ffad Update changelog for recent COEP change
  • e0baa58 Support unsafe-none in COEP
  • 3123831 CI: update setup-node action to version 4
  • ea8cfc9 Update devDependencies to latest versions
  • 69294ad CI should use the latest Node version
  • 14b8519 CI should test on Node 20
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)