Bumps the major group with 3 updates in the /@shared/api directory: prettier, typescript and @lavamoat/allow-scripts.
Bumps the major group with 1 update in the /@shared/helpers directory: typescript.
Bumps the major group with 1 update in the /@stellar/freighter-api directory: @lavamoat/allow-scripts.
Bumps the major group with 23 updates in the /extension directory:
Added: [unicorn/template-indent], (as a [special rule][unicorn/template-indent-special]). Thanks to Gürgün Dayıoğlu (@gurgunday)!
Changed: All the [formatting rules that were deprecated in ESLint 8.53.0][deprecated-8.53.0] are now excluded if you set the ESLINT_CONFIG_PRETTIER_NO_DEPRECATED environment variable.
Version 9.0.0 (2023-08-05)
Added: The CLI helper tool now works with eslint.config.js (flat config). Just like ESLint itself, the CLI tool automatically first tries eslint.config.js and then eslintrc, and you can force which one to use by setting the [ESLINT_USE_FLAT_CONFIG] environment variable. Note that the config of eslint-config-prettier has always been compatible with eslint.config.js (flat config) – it was just the CLI tool that needed updating. On top of that, the docs have been updated to mention how to use both eslint.config.js (flat config) and eslintrc, and the tests now test both config systems.
Changed: [unicode-bom] is no longer turned off. Prettier preserves the BOM if you have one, and does not add one if missing. It was wrong of eslint-config-prettier to disable that rule. If you get ESLint errors after upgrading, either add "unicode-bom": "off" to your config to disable it again, or run ESLint with --fix to fix all files according to the rule (add or remove BOM). Thanks to Nicolas Stepien (@nstepien)!
Version 8.10.0 (2023-08-03)
Added: [max-statements-per-line]. Thanks to @Zamiell!
Version 8.9.0 (2023-07-27)
Added: [vue/array-element-newline]. Thanks to @xcatliu!
Version 8.8.0 (2023-03-20)
Added: [@typescript-eslint/lines-around-comment]. Thanks to @ttionya!
Version 8.7.0 (2023-03-06)
Added: [@typescript-eslint/block-spacing]. Thanks to @ttionya!
Added: [@typescript-eslint/key-spacing]. Thanks to @ttionya!
Version 8.6.0 (2023-01-02)
Added: [vue/multiline-ternary]. Thanks to @xcatliu!
Version 8.5.0 (2022-03-02)
Added: [@typescript-eslint/space-before-blocks]. Thanks to Masafumi Koba (@ybiquitous)!
The maintainer of the package marked it as deprecated. This could indicate that a single version should not be used, or that the package is no longer maintained and any new vulnerabilities will not be fixed.
Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.
Take a deeper look at the dependency
Take a moment to review the security alert above. Review the linked
package source code to understand the potential risk. Ensure the package
is not malicious before proceeding. If you're unsure how to proceed, reach
out to your security team or ask the Socket team for help at support [AT]
socket [DOT] dev.
Remove the package
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
Mark a package as acceptable risk
To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all
Bumps the major group with 47 updates in the / directory:
7.31.2
10.4.0
4.2.4
6.6.3
5.14.9
6.0.0
5.62.0
8.12.2
5.62.0
8.12.2
8.57.0
9.14.0
6.15.0
9.1.0
2.7.1
3.6.3
4.7.0
8.0.3
4.6.2
5.0.0
9.3.5
11.0.0
11.8.5
14.4.3
8.0.3
9.1.6
3.1.0
4.0.2
28.1.3
29.7.0
24.9.1
29.5.14
16.7.0
25.0.1
10.5.4
15.2.10
2.8.8
3.3.3
2.0.2
4.0.0
3.7.7
5.6.3
5.10.0
6.0.1
2.5.1
3.3.0
1.0.3
2.1.0
48.11.0
50.4.3
1.2.1
2.1.1
16.13.1
18.3.1
5.3.11
6.1.13
1.6.0
2.3.0
14.3.1
16.0.1
7.2.1
14.5.2
16.2.15
21.1.7
12.20.55
22.8.6
4.3.0
5.0.7
5.3.0
9.0.1
4.10.1
5.3.0
4.7.11
5.0.0
21.10.0
23.16.4
6.1.8
8.0.0
28.1.3
29.7.0
1.0.1
4.1.0
11.18.6
15.1.0
7.2.9
9.1.2
5.3.4
6.27.0
4.2.1
5.0.1
14.2.1
16.0.3
0.18.8
1.9.1
Bumps the major group with 3 updates in the /@shared/api directory: prettier, typescript and @lavamoat/allow-scripts. Bumps the major group with 1 update in the /@shared/helpers directory: typescript. Bumps the major group with 1 update in the /@stellar/freighter-api directory: @lavamoat/allow-scripts. Bumps the major group with 23 updates in the /extension directory:
2.8.8
3.3.3
2.0.2
4.0.0
2.5.1
3.3.0
1.6.0
2.3.0
14.3.1
16.0.1
7.2.1
14.5.2
4.7.11
5.0.0
16.2.15
21.1.7
12.20.55
22.8.6
4.3.0
5.0.7
5.14.9
6.0.0
5.3.0
9.0.1
4.10.1
5.3.0
21.10.0
23.16.4
6.1.8
8.0.0
28.1.3
29.7.0
1.0.1
4.1.0
11.18.6
15.1.0
7.2.9
9.1.2
5.3.4
6.27.0
4.2.1
5.0.1
14.2.1
16.0.3
0.18.8
1.9.1
Updates
@testing-library/dom
from 7.31.2 to 10.4.0Release notes
Sourced from
@testing-library/dom
's releases.... (truncated)
Commits
a86c54c
feat: Reduce caught exceptions in prettyDom (reland) (#1323)33555a3
Test highlighting ofprettyDOM
explicitly (#1324)20d9894
docs: add sieem as a contributor for code (#1330)306526b
fix: safer read of DEBUG_PRINT_LIMIT (#1329)fdc12ec
fix: Revert "feat: Reduce caught exceptions inprettyDom
(#1321)" (#1325)76cb73d
feat: Reduce caught exceptions inprettyDom
(#1321)0a8ad65
feat: Support anonymous custom elements when pretty printing DOM (#1319)77448ba
docs: update Greg Bergé's bio link (#1318)56543d5
feat: Add window events "pagehide" / "pageshow" (#1308)47fe879
chore: correct some typos and spelling errors (#1309)Updates
@testing-library/jest-dom
from 4.2.4 to 6.6.3Release notes
Sourced from
@testing-library/jest-dom
's releases.... (truncated)
Commits
5ba0156
fix: add vitest import when extending vitest matchers (#646)4468378
fix: remove recursive type reference in vitest types (#636)abba961
docs: add billyjanitsch as a contributor for bug (#644)9490615
docs: add G-Rath as a contributor for code (#643)ced792e
fix: fix lodash import in to-have-selection.js (#642)9b14804
feat: implement toHaveSelection (#637)f5b0e94
docs: add diegohaz as a contributor for ideas (#640)68e927e
docs: add pwolaq as a contributor for code, and test (#639)04005db
docs: add silviuaavram as a contributor for code, and test (#638)4723de3
docs: add mibcadet as a contributor for doc (#628)Updates
@types/testing-library__jest-dom
from 5.14.9 to 6.0.0Commits
Updates
@typescript-eslint/eslint-plugin
from 5.62.0 to 8.12.2Release notes
Sourced from
@typescript-eslint/eslint-plugin
's releases.... (truncated)
Changelog
Sourced from
@typescript-eslint/eslint-plugin
's changelog.... (truncated)
Commits
4af866a
chore(release): publish 8.12.2cc7177c
fix(eslint-plugin): [switch-exhaustiveness-check] invert `considerDefaultExha...1edec1d
chore(release): publish 8.12.13413a2d
chore(release): publish 8.12.0ac18749
feat(eslint-plugin): [no-base-to-string] handle String() (#10005)3c8978d
feat(eslint-plugin): [switch-exhaustiveness-check] add allowDefaultCaseMatchU...af4743f
test(eslint-plugin): fix a typo in a test, causing it to test theerror
typ...9c956ee
feat(eslint-plugin): [consistent-indexed-object-style] report mapped types (#...e765033
feat(eslint-plugin): [prefer-nullish-coalescing] add support for assignment e...79c27a8
chore(release): publish 8.11.0Updates
@typescript-eslint/parser
from 5.62.0 to 8.12.2Release notes
Sourced from
@typescript-eslint/parser
's releases.... (truncated)
Changelog
Sourced from
@typescript-eslint/parser
's changelog.... (truncated)
Commits
4af866a
chore(release): publish 8.12.21edec1d
chore(release): publish 8.12.13413a2d
chore(release): publish 8.12.079c27a8
chore(release): publish 8.11.08d35958
chore: enable eslint-plugin-perfectionist on typescript-estree package (#9852)7effdea
chore(release): publish 8.10.0f9c49e3
feat: support TypeScript 5.6 (#9972)4666ed4
chore(release): publish 8.9.0f898248
chore(release): publish 8.8.12055cfb
chore(release): publish 8.8.0Updates
eslint
from 8.57.0 to 9.14.0Release notes
Sourced from eslint's releases.
... (truncated)
Changelog
Sourced from eslint's changelog.
... (truncated)
Commits
db0b844
9.14.020b0da1
Build: changelog update for 9.14.0f36cb16
chore: upgrade@eslint/js
@9
.14.0 (#19086)28be447
chore: package.json update for@eslint/js
release24d0172
fix: enable retry concurrency limit for readFile() (#19077)3fa009f
feat: add support for Import Attributes and RegExp Modifiers (#19076)b0faee3
feat: add types for the@eslint/js
package (#19010)151c965
docs: updatecontext.languageOptions.parser
description (#19084)dc34f94
docs: Update READMEf48a2a0
test: addno-invalid-regexp
tests with RegExp Modifiers (#19075)Updates
eslint-config-prettier
from 6.15.0 to 9.1.0Changelog
Sourced from eslint-config-prettier's changelog.
... (truncated)
Commits
Report too large to display inline
View full report↗︎
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎
To accept the risk, merge this PR and you will not be notified again.
extension/package.json
extension/package.json
View full report↗︎
Next steps
What is a deprecated package?
The maintainer of the package marked it as deprecated. This could indicate that a single version should not be used, or that the package is no longer maintained and any new vulnerabilities will not be fixed.
Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.
Take a deeper look at the dependency
Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.
Remove the package
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
Mark a package as acceptable risk
To ignore an alert, reply with a comment starting with
@SocketSecurity ignore
followed by a space separated list ofecosystem/package-name@version
specifiers. e.g.@SocketSecurity ignore npm/foo@1.0.0
or ignore all packages with@SocketSecurity ignore-all
@SocketSecurity ignore npm/@types/history@5.0.0
@SocketSecurity ignore npm/@types/testing-library__jest-dom@6.0.0
Looks like these dependencies are no longer updatable, so this is no longer needed.