Closed dependabot[bot] closed 7 months ago
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/@openzeppelin/contracts@5.0.2 | None | 0 |
1.7 MB | frangio |
npm/@zetachain/networks@6.0.0 | environment Transitive: filesystem | +1 |
108 kB | lucasjanon |
npm/@zetachain/protocol-contracts@7.0.0-rc1 | None | 0 |
3.06 MB | lucasjanon |
npm/axios@1.6.0 | network | +1 |
1.82 MB | jasonsaayman |
🚮 Removed packages: npm/@openzeppelin/contracts@4.9.6, npm/@zetachain/networks@4.0.0-rc1, npm/@zetachain/protocol-contracts@5.0.0-rc7, npm/axios@1.5.0
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.
To ignore these dependencies, configure ignore rules in dependabot.yml
Bumps the npm_and_yarn group with 5 updates in the / directory:
4.9.6
5.0.2
1.5.0
1.6.0
1.15.4
1.15.6
2.0.0
2.0.2
5.23.0
5.28.4
Updates
@openzeppelin/contracts
from 4.9.6 to 5.0.2Release notes
Sourced from
@openzeppelin/contracts
's releases.... (truncated)
Changelog
Sourced from
@openzeppelin/contracts
's changelog.... (truncated)
Commits
dbb6104
Release v5.0.2 (#4928)26b4b60
Port Base64 tests to truffle (#4926)d4ec278
List every contract in each API doc section (#4848)f7bb988
Replace Defender Admin with Transaction Proposals (#4804)e53f81b
Remove Governor's guide ERC6372 disclaimer for Tally (#4801)01ef448
Release v5.0.1 (#4785)9ce0340
Make Multicall context-aware4eb67a4
Closeaccess-control.adoc
code block (#4726) (#4727)83330a6
AddAccessManager
guide (#4691) (#4724)ab967b8
Update the "utilities" documentation page (#4678)Updates
axios
from 1.5.0 to 1.6.0Release notes
Sourced from axios's releases.
Changelog
Sourced from axios's changelog.
Commits
f7adacd
chore(release): v1.6.0 (#6031)9917e67
chore(ci): fix release-it arg; (#6032)96ee232
fix(CSRF): fixed CSRF vulnerability CVE-2023-45857 (#6028)7d45ab2
chore(tests): fixed tests to pass in node v19 and v20 withkeep-alive
enabl...5aaff53
fix(dns): fixed lookup function decorator to work properly in node v20; (#6011)a48a63a
chore(docs): added AxiosHeaders docs; (#5932)a1c8ad0
fix(types): fix AxiosHeaders types; (#5931)2ac731d
chore(docs): update readme.md (#5889)88fb52b
chore(release): v1.5.1 (#5920)e410779
fix(adapters): improved adapters loading logic to have clear error messages; ...Updates
follow-redirects
from 1.15.4 to 1.15.6Commits
35a517c
Release version 1.15.6 of the npm package.c4f847f
Drop Proxy-Authorization across hosts.8526b4a
Use GitHub for disclosure.b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.Updates
get-func-name
from 2.0.0 to 2.0.2Release notes
Sourced from get-func-name's releases.
Commits
Maintainer changes
This version was pushed to npm by keithamus, a new releaser for get-func-name since your current version.
Updates
undici
from 5.23.0 to 5.28.4Release notes
Sourced from undici's releases.
... (truncated)
Commits
fb98306
Bumped v5.28.42b39440
Merge pull request from GHSA-9qxr-qj54-h67264e3402
Merge pull request from GHSA-m4v8-wqvr-p9f7723c4e7
Revert "build(deps-dev): bump formdata-node from 4.4.1 to 6.0.3 (#2389)"0e9d54b
skip failing test due to Node.js changese71cb4c
Bumped v5.28.320c65b8
Fix tests for Node.js v20.11.0 (#2618)8ec52cd
Fix tests for Node.js v21 (#2609)d3aa574
Merge pull request from GHSA-3787-6prv-h9w39a14e5f
Bumped v5.28.2Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show