worknenjoy / gitpay

Bounties for issues on demand. Be rewarded by learning, using Git workflow and continuous integration
http://gitpay.me
Other
180 stars 159 forks source link

Bump json5, babel-core, extract-react-intl and extract-react-intl-messages in /frontend #963

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps json5 to 1.0.2 and updates ancestor dependencies json5, babel-core, extract-react-intl and extract-react-intl-messages. These dependencies need to be updated together.

Updates json5 from 1.0.1 to 1.0.2

Release notes

Sourced from json5's releases.

v1.0.2

  • Fix: Properties with the name __proto__ are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295). This has been backported to v1. (#298)
Changelog

Sourced from json5's changelog.

Unreleased [code, diff]

v2.2.3 [code, diff]

  • Fix: json5@2.2.3 is now the 'latest' release according to npm instead of v1.0.2. (#299)

v2.2.2 [code, diff]

  • Fix: Properties with the name __proto__ are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).

v2.2.1 [code, diff]

  • Fix: Removed dependence on minimist to patch CVE-2021-44906. (#266)

v2.2.0 [code, diff]

  • New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)

v2.1.3 [code, diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)

v2.1.2 [code, diff]

... (truncated)

Commits


Updates babel-core from 6.26.3 to 7.0.0-bridge.0

Commits


Updates extract-react-intl from 0.6.0 to 0.9.0

Release notes

Sourced from extract-react-intl's releases.

Allow to specify custom module name passed to babel-plugin-react-intl

Feat

  • Allow to specify custom module name passed to babel-plugin-react-intl 449f6ae

https://github.com/akameco/extract-react-intl/compare/v0.8.1...v0.9.0

v0.8.1

  • chore(deps): udpate 5ce314a

https://github.com/akameco/extract-react-intl/compare/v0.8.0...v0.8.1

v0.8.0

  • refactor(deps): update babel7 b73b8a5
  • fix(lint): fix eslint error 13165ea
  • chore: update deps e79f8b7

https://github.com/akameco/extract-react-intl/compare/v0.7.0...v0.8.0

For Babel 6

  • Allow to specify custom module name passed to babel-plugin-react-intl 449f6ae
  • fix(lint): fix eslint error 13165ea
  • chore: update deps e79f8b7

https://github.com/akameco/extract-react-intl/compare/v0.7.0...v0.7.1

Commits


Updates extract-react-intl-messages from 0.10.0 to 4.1.1

Release notes

Sourced from extract-react-intl-messages's releases.

v4.1.1

  • fix: fix cli option message d5577da

https://github.com/akameco/extract-react-intl-messages/compare/v4.1.0...v4.1.1

v4.1.0

  • Feature: Add option overwrite-default, to be able to opt out of overwriting the default locale fd67919

https://github.com/akameco/extract-react-intl-messages/compare/v4.0.0...v4.1.0

v4.0.0

  • required Node v10 7d2df7b

https://github.com/akameco/extract-react-intl-messages/compare/v3.0.0...v4.0.0

v3.0.0

  • Merge pull request #66 from toshitanian/master a8aca40
  • Sort keys without flat option in default 8e0bda8
  • Merge pull request #64 from lensbart/patch-1 f17c6fc
  • build(deps): bump handlebars from 4.2.0 to 4.5.3 (#62) 36aef16
  • Add --sort-when-not-flat option as keys were not sorted in flat mode 7260b69
  • Added myself to contributors table 4b83d8c
  • docs: single-line comment explaining the change d9b2dad
  • Fixes #63 4c929bd
  • build(deps): bump handlebars from 4.2.0 to 4.5.3 c5db8cb

https://github.com/akameco/extract-react-intl-messages/compare/v2.3.5...v3.0.0

v2.3.5

  • fix: extractReactIntl named export is overwritten #58 8b53347

https://github.com/akameco/extract-react-intl-messages/compare/v2.3.4...v2.3.5

v2.3.4

  • fix: babel-plugin-react-intl error (#61) bbc890c

https://github.com/akameco/extract-react-intl-messages/compare/v2.3.3...v2.3.4

v2.3.3

  • fix: support common js exports 8e9da31
  • build(renovate): add renovate.json 8c85fe3
  • chore(deps): upgrade dependencies 92444c4

https://github.com/akameco/extract-react-intl-messages/compare/v2.3.2...v2.3.3

v2.3.2

  • removes extract-react-intl from deps (#51) 70947de
  • fixes babel-plugin-react-intl boolean options parsing of in cli (#49) (#50) 9486905

https://github.com/akameco/extract-react-intl-messages/compare/v2.3.1...v2.3.2

... (truncated)

Commits
  • 60be551 v4.1.1
  • d5577da fix: fix cli option message
  • 2037209 v4.1.0
  • c13df01 chore: update package.json
  • c8ea01c feat: enable extractFromFormatMessageCall by default
  • 63c0e11 Merge pull request #54 from testower/feature/opt-out-overwrite
  • 5c62d8f test: add overwriteDefault test
  • 4501919 Merge branch 'master' into feature/opt-out-overwrite
  • 41e2870 docs: update
  • f953e86 docs: add github actions's badge
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/worknenjoy/gitpay/network/alerts).
dependabot[bot] commented 1 year ago

Superseded by #964.