shekohex / dead-simple-feedback-app

just a dead simple feedback application
https://dead-simple-feedback.herokuapp.com/
MIT License
8 stars 4 forks source link

Bump mquery from 2.3.2 to 3.2.5 #20

Open dependabot[bot] opened 3 years ago

dependabot[bot] commented 3 years ago

Bumps mquery from 2.3.2 to 3.2.5.

Changelog

Sourced from mquery's changelog.

3.2.5 / 2021-03-29

  • fix(utils): make mergeClone() skip special properties like __proto__ #121 zpbrent

3.2.4 / 2021-02-12

3.2.3 / 2020-12-10

  • fix(utils): avoid copying special properties like __proto__ when merging and cloning. Fix CVE-2020-35149

3.2.2 / 2019-09-22

3.2.1 / 2018-08-24

  • chore: upgrade deps

3.2.0 / 2018-08-24

  • feat: add $useProjection to opt in to using projection instead of fields re: MongoDB deprecation warnings Automattic/mongoose#6880

3.1.2 / 2018-08-01

3.1.1 / 2018-07-30

3.1.0 / 2018-07-29

3.0.1 / 2018-07-02

3.0.0 / 2018-01-20

  • chore: upgrade deps and add nsp

3.0.0-rc0 / 2017-12-06

  • BREAKING CHANGE: remove support for node < 4

... (truncated)

Commits
  • 6646bd9 chore: release 3.2.5
  • 158f059 Merge pull request #121 from 418sec/1-npm-mquery
  • d3b230b Merge pull request #1 from zpbrent/patch-1
  • a7b6d7c Update utils.js
  • 34344fa chore: release 3.2.4
  • 2dd768d fix(utils): make clone() only copy own properties
  • bb185d9 chore: update changelog with CVE
  • eeaa57c chore: release 3.2.3
  • 792e69f fix(utils): avoid copying special properties like __proto__ when merging an...
  • 2268a48 Merge pull request #118 from aheckmann/dependabot/npm_and_yarn/mongodb-3.6.1
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/shekohex/dead-simple-feedback-app/network/alerts).