Closed dependabot[bot] closed 3 months ago
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/braces@3.0.3 | None | 0 |
44.6 kB | jonschlinkert |
npm/fill-range@7.1.1 | None | 0 |
16.7 kB | jonschlinkert |
npm/undici@6.19.5 | None | 0 |
1.13 MB | ethan_arrowood, matteo.collina, ronag |
npm/ws@6.2.3 | network | 0 |
102 kB | lpinca |
🚮 Removed packages: npm/braces@3.0.2, npm/fill-range@7.0.1, npm/undici@6.17.0, npm/ws@6.2.2
Looks like these dependencies are updatable in another way, so this is no longer needed.
Bumps the npm_and_yarn group with 4 updates in the / directory: braces, fast-loops, undici and ws.
Updates
braces
from 3.0.2 to 3.0.3Commits
74b2db2
3.0.388f1429
update eslint. lint, fix unit tests.415d660
Snyk js braces 6838727 (#40)190510f
fix tests, skip 1 test in test/braces.expand716eb9f
readme bumpa5851e5
Merge pull request #37 from coderaiser/fix/vulnerability2092bd1
feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cf
fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9
remove funding file665ab5d
update keepEscaping doc (#27)Updates
fast-loops
from 1.1.3 to 1.1.4Commits
Updates
undici
from 6.17.0 to 6.19.5Release notes
Sourced from undici's releases.
... (truncated)
Commits
8499c4b
Bumped v6.19.593605ab
fix: restore externalized Node.js dep compatibility (#3421)62241c3
Bumped v6.19.4e51aa88
Update esbuild to 0.19.10 (#3415)99102cc
Bumped v6.19.3b696a78
In CITGM, skip tests that are flaky there (#3413)532b7b2
Bumped v6.19.2 (#3342)a7441d8
fix: interceptors.d.ts has no default export (#3332)5dadb95
build: usehusky
ashusky install
is deprecated (#3340)035524e
fix #3337 (#3338)Updates
ws
from 6.2.2 to 6.2.3Release notes
Sourced from ws's releases.
Commits
d87f3b6
[dist] 6.2.3eeb76d3
[security] Fix crash when the Upgrade header cannot be read (#2231)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show