usabilityhub / rails-erb-loader

Embedded Ruby (.erb) webpack loader for Ruby projects.
MIT License
103 stars 28 forks source link

Bump terser and terser-webpack-plugin #121

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps terser and terser-webpack-plugin. These dependencies needed to be updated together. Updates terser from 3.17.0 to 4.8.1

Changelog

Sourced from terser's changelog.

v4.8.1 (backport)

  • Security fix for RegExps that should not be evaluated (regexp DDOS)

v4.8.0

  • Support for numeric separators (million = 1_000_000) was added.
  • Assigning properties to a class is now assumed to be pure.
  • Fixed bug where yield wasn't considered a valid property key in generators.

v4.7.0

  • A bug was fixed where an arrow function would have the wrong size
  • arguments object is now considered safe to retrieve properties from (useful for length, or 0) even when pure_getters is not set.
  • Fixed erroneous const declarations without value (which is invalid) in some corner cases when using collapse_vars.

v4.6.13

  • Fixed issue where ES5 object properties were being turned into ES6 object properties due to more lax unicode rules.
  • Fixed parsing of BigInt with lowercase e in them.

v4.6.12

  • Fixed subtree comparison code, making it see that [1,[2, 3]] is different from [1, 2, [3]]
  • Printing of unicode identifiers has been improved

v4.6.11

  • Read unused classes' properties and method keys, to figure out if they use other variables.
  • Prevent inlining into block scopes when there are name collisions
  • Functions are no longer inlined into parameter defaults, because they live in their own special scope.
  • When inlining identity functions, take into account the fact they may be used to drop this in function calls.
  • Nullish coalescing operator (x ?? y), plus basic optimization for it.
  • Template literals in binary expressions such as + have been further optimized

v4.6.10

  • Do not use reduce_vars when classes are present

v4.6.9

  • Check if block scopes actually exist in blocks

v4.6.8

  • Take into account "executed bits" of classes like static properties or computed keys, when checking if a class evaluation might throw or have side effects.

v4.6.7

  • Some new performance gains through a AST_Node.size() method which measures a node's source code length without printing it to a string first.

... (truncated)

Commits


Updates terser-webpack-plugin from 1.2.3 to 1.4.5

Release notes

Sourced from terser-webpack-plugin's releases.

v1.4.5

1.4.5 (2020-08-12)

  • update serialize-javascript

v1.4.4

1.4.4 (2020-06-03)

Bug Fixes

v1.4.3

1.4.3 (2019-12-11)

SECURITY

  • update serialize-javascript to 2.1.2 version.

v1.4.2

1.4.2 (2019-12-06)

SECURITY

  • update serialize-javascript to 2.1.1 version.

v1.4.1

1.4.1 (2019-07-31)

Bug Fixes

v1.4.0

1.4.0 (2019-07-31)

Features

v1.3.0

1.3.0 (2019-05-24)

Features

... (truncated)

Changelog

Sourced from terser-webpack-plugin's changelog.

1.4.5 (2020-08-12)

  • update serialize-javascript

1.4.4 (2020-06-03)

Bug Fixes

1.4.3 (2019-12-11)

SECURITY

  • update serialize-javascript to 2.1.2 version.

1.4.2 (2019-12-06)

SECURITY

  • update serialize-javascript to 2.1.1 version.

1.4.1 (2019-07-31)

Bug Fixes

1.4.0 (2019-07-31)

Features

1.3.0 (2019-05-24)

Features

1.2.4 (2019-05-15)

... (truncated)

Commits


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/usabilityhub/rails-erb-loader/network/alerts).