stophecom / sharrr-svelte

End-to-end encrypted file transfer.
https://www.sharrr.com
MIT License
117 stars 4 forks source link

Bump @sveltejs/kit from 1.15.0 to 1.19.0 #89

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps @sveltejs/kit from 1.15.0 to 1.19.0.

Release notes

Sourced from @​sveltejs/kit's releases.

@​sveltejs/kit@​1.19.0

Minor Changes

  • feat: allow link options to be set to "true" and "false" (#10039)

  • feat: add resolvePath export for building relative paths from route IDs and parameters (#9949)

Patch Changes

  • fix: prevent history change when clicking same hash link (#10032)

  • fix: gracefully handle server endpoints that return Responses with immutable Headers when prerendering (#10030)

  • fix: do not add content-security-policy meta element if content is empty (#10026)

  • docs: correct ResolveOptions['preload'] inline documentation (#10037)

  • fix: avoid creating update check timer on the server (#10015)

@​sveltejs/kit@​1.18.0

Minor Changes

  • security: Stop implicitly tracking URLs as dependencies in server-side loads (#9945)

@​sveltejs/kit@​1.17.1

Patch Changes

  • fix: ensure styles are loaded in dev mode for routes containing special characters (#9894)

  • feat: warn users when enhancing forms with files but no enctype="multipart/form-data" (#9888)

@​sveltejs/kit@​1.17.0

Minor Changes

  • feat: unshadow data and form in enhance and warn about future deprecation when used in dev mode (#9902)

  • feat: crawl URLs in <meta> tags (#9900)

Patch Changes

  • fix: avoid trying to inline raw or url css imports (#9925)

  • feat: prerender in worker rather than subprocess to support Deno (#9919)

  • perf: add <script> to prerendered redirects for faster redirects (#9911)

  • fix: add typing for vitePlugin to Config (#9946)

  • fix: stop setting Kit cookie defaults on cookies parsed from headers (#9908)

... (truncated)

Changelog

Sourced from @​sveltejs/kit's changelog.

1.19.0

Minor Changes

  • feat: allow link options to be set to "true" and "false" (#10039)

  • feat: add resolvePath export for building relative paths from route IDs and parameters (#9949)

Patch Changes

  • fix: prevent history change when clicking same hash link (#10032)

  • fix: gracefully handle server endpoints that return Responses with immutable Headers when prerendering (#10030)

  • fix: do not add content-security-policy meta element if content is empty (#10026)

  • docs: correct ResolveOptions['preload'] inline documentation (#10037)

  • fix: avoid creating update check timer on the server (#10015)

1.18.0

Minor Changes

  • security: Stop implicitly tracking URLs as dependencies in server-side loads (#9945)

1.17.1

Patch Changes

  • fix: ensure styles are loaded in dev mode for routes containing special characters (#9894)

  • feat: warn users when enhancing forms with files but no enctype="multipart/form-data" (#9888)

1.17.0

Minor Changes

  • feat: unshadow data and form in enhance and warn about future deprecation when used in dev mode (#9902)

  • feat: crawl URLs in <meta> tags (#9900)

Patch Changes

  • fix: avoid trying to inline raw or url css imports (#9925)

  • feat: prerender in worker rather than subprocess to support Deno (#9919)

  • perf: add <script> to prerendered redirects for faster redirects (#9911)

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
vercel[bot] commented 1 year ago

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
sharrr-svelte ✅ Ready (Inspect) Visit Preview 💬 Add feedback May 26, 2023 10:07am
socket-security[bot] commented 1 year ago

New dependency changes detected. Learn more about Socket for GitHub ↗︎


🚨 Potential security issues found in this pull request. To accept the risk, merge this PR and you will not be notified again.

Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore @sveltejs/kit@1.19.0
📜 Install scripts

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Package Script field Source
@sveltejs/kit@1.19.0 (added) postinstall package-lock.json, package.json via @sveltejs/adapter-auto@2.0.1
Pull request alert summary
Issue Status
Install scripts ⚠️ 1 issue
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues

📊 Modified Dependency Overview:

➕ Added Package Capability Access +/- Transitive Count Publisher
@sveltejs/kit@1.19.0 eval, network, environment +21 svelte-admin
dependabot[bot] commented 1 year ago

Superseded by #90.