Open dependabot[bot] opened 3 months ago
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/braces@3.0.3 | None | 0 |
44.6 kB | jonschlinkert |
npm/fill-range@7.1.1 | None | 0 |
16.7 kB | jonschlinkert |
npm/undici@6.19.7 | environment, network | 0 |
1.13 MB | matteo.collina |
🚮 Removed packages: npm/braces@3.0.2, npm/fill-range@7.0.1, npm/undici@6.17.0
Bumps the npm_and_yarn group with 3 updates in the / directory: braces, fast-loops and undici.
Updates
braces
from 3.0.2 to 3.0.3Commits
74b2db2
3.0.388f1429
update eslint. lint, fix unit tests.415d660
Snyk js braces 6838727 (#40)190510f
fix tests, skip 1 test in test/braces.expand716eb9f
readme bumpa5851e5
Merge pull request #37 from coderaiser/fix/vulnerability2092bd1
feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cf
fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9
remove funding file665ab5d
update keepEscaping doc (#27)Updates
fast-loops
from 1.1.3 to 1.1.4Commits
Updates
undici
from 6.17.0 to 6.19.7Release notes
Sourced from undici's releases.
... (truncated)
Commits
c81f5a7
Bumped v6.19.709c5667
build: remove -i flag to docker run to allow command being run without a TTYb9bf7ad
Bumped v6.19.6638ee32
fix: memory leak in finalization first appearing in v6.16.0 (#3445)8499c4b
Bumped v6.19.593605ab
fix: restore externalized Node.js dep compatibility (#3421)62241c3
Bumped v6.19.4e51aa88
Update esbuild to 0.19.10 (#3415)99102cc
Bumped v6.19.3b696a78
In CITGM, skip tests that are flaky there (#3413)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show