niccarp / vulnerable-web-app

0 stars 0 forks source link

Bump minimist and express-handlebars #3

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps minimist to 1.2.7 and updates ancestor dependency express-handlebars. These dependencies need to be updated together.

Updates minimist from 0.0.10 to 1.2.7

Changelog

Sourced from minimist's changelog.

v1.2.7 - 2022-10-10

Commits

  • [meta] add auto-changelog 0ebf4eb
  • [actions] add reusable workflows e115b63
  • [eslint] add eslint; rules to enable later are warnings f58745b
  • [Dev Deps] switch from covert to nyc ab03356
  • [readme] rename and add badges 236f4a0
  • [meta] create FUNDING.yml; add funding in package.json 783a49b
  • [meta] use npmignore to autogenerate an npmignore file f81ece6
  • Only apps should have lockfiles 56cad44
  • [Dev Deps] update covert, tape; remove unnecessary tap 49c5f9f
  • [Tests] add aud in posttest 228ae93
  • [meta] add safe-publish-latest 01fc23f
  • [meta] update repo URLs 6b164c7

v1.2.6 - 2022-03-21

Commits

  • test from prototype pollution PR bc8ecee
  • isConstructorOrProto adapted from PR c2b9819
  • security notice for additional prototype pollution issue ef88b93

v1.2.5 - 2020-03-12

v1.2.4 - 2020-03-11

Commits

  • security notice 4cf1354
  • additional test for constructor prototype pollution 1043d21

v1.2.3 - 2020-03-10

Commits

  • more failing proto pollution tests 13c01a5
  • even more aggressive checks for protocol pollution 38a4d1c

v1.2.2 - 2020-03-10

Commits

... (truncated)

Commits
  • c590d75 v1.2.7
  • 0ebf4eb [meta] add auto-changelog
  • e115b63 [actions] add reusable workflows
  • 01fc23f [meta] add safe-publish-latest
  • f58745b [eslint] add eslint; rules to enable later are warnings
  • 228ae93 [Tests] add aud in posttest
  • 236f4a0 [readme] rename and add badges
  • ab03356 [Dev Deps] switch from covert to nyc
  • 49c5f9f [Dev Deps] update covert, tape; remove unnecessary tap
  • 783a49b [meta] create FUNDING.yml; add funding in package.json
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by ljharb, a new releaser for minimist since your current version.


Updates express-handlebars from 2.0.1 to 6.0.6

Release notes

Sourced from express-handlebars's releases.

v6.0.6

6.0.6 (2022-05-13)

Bug Fixes

  • deps: update dependency glob to ^8.0.2 (8202ea1)

v6.0.5

6.0.5 (2022-04-11)

Bug Fixes

  • deps: update dependency glob to v8 (4025b58)

v6.0.4

6.0.4 (2022-04-06)

Bug Fixes

  • deps: update dependency graceful-fs to ^4.2.10 (2d6e89c)

v6.0.3

6.0.3 (2022-03-03)

Bug Fixes

  • allow false for defaultLayout (#303) (d6180fe)
  • deps: update dependency graceful-fs to ^4.2.9 (#271) (ea0f1f5)

v6.0.2

6.0.2 (2021-11-25)

Bug Fixes

  • fix typescript in strict mode (6833d8d)

v6.0.1

6.0.1 (2021-11-13)

Bug Fixes

... (truncated)

Changelog

Sourced from express-handlebars's changelog.

6.0.6 (2022-05-13)

Bug Fixes

  • deps: update dependency glob to ^8.0.2 (8202ea1)

6.0.5 (2022-04-11)

Bug Fixes

  • deps: update dependency glob to v8 (4025b58)

6.0.4 (2022-04-06)

Bug Fixes

  • deps: update dependency graceful-fs to ^4.2.10 (2d6e89c)

6.0.3 (2022-03-03)

Bug Fixes

  • allow false for defaultLayout (#303) (d6180fe)
  • deps: update dependency graceful-fs to ^4.2.9 (#271) (ea0f1f5)

6.0.2 (2021-11-25)

Bug Fixes

  • fix typescript in strict mode (6833d8d)

6.0.1 (2021-11-13)

Bug Fixes

6.0.0 (2021-11-13)

Features

... (truncated)

Commits
  • c8bac06 chore(release): 6.0.6 [skip ci]
  • f748b0f Merge pull request #339 from express-handlebars/renovate/glob-8.x
  • 8202ea1 fix(deps): update dependency glob to ^8.0.2
  • 0e3a34e chore(deps): update devdependency @​types/jest to ^27.5.1
  • 35a1c04 chore(deps): update typescript-eslint monorepo to ^5.23.0
  • 074201b chore(deps): update devdependency ts-jest to ^28.0.2
  • ba3e38c chore(deps): update devdependency eslint to ^8.15.0
  • 8d1fedb chore(deps): update devdependency jest-cli to ^28.1.0
  • 93c55b4 chore(deps): update devdependency ts-jest to ^28.0.1
  • 7c1cd06 Merge pull request #327 from express-handlebars/renovate/major-jest-monorepo
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by tonybrix, a new releaser for express-handlebars since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/niccarp/vulnerable-web-app/network/alerts).