rez0n / docker-nodebb

NodeBB forum software Docker image with persistent storage support. k8s tested.
https://hub.docker.com/r/nibrev/nodebb
31 stars 13 forks source link

Bump NodeBB from `9500871` to `586eed1` #554

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps NodeBB from 9500871 to 586eed1.

Commits
  • 586eed1 fix: vulnerability in socket.io nested namespaces (#11117)
  • 1ea9481 fix: lock post/reply similar to user.create
  • bbaf26c chore: remove extraneous lines from changelog
  • a5c2edb chore: update changelog for v2.8.0
  • 7ce758d chore: incrementing version number - v2.8.0
  • ef500af fix(deps): update dependency sharp to v0.31.3 (#11110)
  • 7ab46b7 fix(deps): update dependency sanitize-html to v2.8.1 (#11109)
  • 13a3faa chore(deps): update dependency jquery to v3.6.3 (#11107)
  • eb6a9c4 fix(deps): update dependency esbuild to v0.16.10 (#11104)
  • 05443db fix(deps): update dependency mongodb to v4.13.0 (#11105)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 1 year ago

Superseded by #555.