Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Mar 9, 2025

Bumps pdfjs-dist to 4.8.69 and updates ancestor dependency react-pdf. These dependencies need to be updated together.

Updates pdfjs-dist from 3.11.174 to 4.8.69

Release notes

Sourced from pdfjs-dist's releases.

v4.8.69

This release contains improvements for the annotation editor, font conversion, form rendering, image conversion and the viewer.

Changes since v4.7.76

... (truncated)

Commits
  • 3634dab Merge pull request #18988 from Snuffleupagus/split-dom-factory
  • e930f30 Merge pull request #18992 from Snuffleupagus/getPdfManager-inline-flushChunks
  • e548510 Merge pull request #18990 from Snuffleupagus/ensure-structTree-serializable
  • aa4839e Merge pull request #18993 from Snuffleupagus/stringToUTF16HexString-hexNumbers
  • 2145a7b Use the hexNumbers structure in the stringToUTF16HexString helper
  • 196f7d7 Inline the flushChunks helper function, used in getPdfManager on the work...
  • b26dc19 Ensure that serializing of StructTree-data cannot fail during loading
  • 4e12906 Move the various DOM-factories into their own files
  • 06f3b2d Merge pull request #18983 from Snuffleupagus/api-FetchBuiltInCMap-FetchStanda...
  • 3ed438a Merge pull request #18979 from Snuffleupagus/L10n-#elements-lazy-init
  • Additional commits viewable in compare view

Updates react-pdf from 7.7.1 to 9.2.1

Release notes

Sourced from react-pdf's releases.

v9.2.1

Bug fixes

  • Fixed gray background appearing on selection (#1925).

v9.2.0

What's new?

  • Updated PDF.js to 4.8.69. Thanks, @​MGPOCKY!
  • Improved compatibility with Node.js 22.

v9.1.1

Bug fixes

  • Fixed "Worker was terminated" error on unmount (#1062, #1877). Thanks, @​CyberAndrii!
  • Fixed package.json exports not allowing to import package.json (#1876).

v9.1.0

What's new?

  • Updated PDF.js to 4.4.168.
    • Annotation improvements
    • Font conversion improvements
    • Image decoding improvements
    • Performance improvements
    • Text selection improvements
  • Added support for isolatedDeclarations in TypeScript.

What's changed?

  • Updated documentation.
  • Updated Next.js, Parcel and Webpack examples.

Bug fixes

  • Fixed missing hiddenCanvasElement styles (#1815).
  • Fixed overly large structTreeUtils.d.ts file, saving you 45 KB of disk space.

v9.0.0

See Upgrade guide from version 8.x to 9.x.

This version updates PDF.js to 4.3.136, fixing GHSA-wgrm-67xf-hhpq for good. React-PDF v8.0.2 and v7.7.3 have already included a mitigation of the issue and thus were not affected by this vulnerability, but caused automatic security alerts due to the outdated PDF.js version.

❗️ = breaking change

What's new?

  • Updated PDF.js to 4.3.136.
    • Optimizations for CPU and memory usage
    • Performance improvements

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [pdfjs-dist](https://github.com/mozilla/pdf.js) to 4.8.69 and updates ancestor dependency [react-pdf](https://github.com/wojtekmaj/react-pdf/tree/HEAD/packages/react-pdf). These dependencies need to be updated together.


Updates `pdfjs-dist` from 3.11.174 to 4.8.69
- [Release notes](https://github.com/mozilla/pdf.js/releases)
- [Commits](mozilla/pdf.js@v3.11.174...v4.8.69)

Updates `react-pdf` from 7.7.1 to 9.2.1
- [Release notes](https://github.com/wojtekmaj/react-pdf/releases)
- [Commits](https://github.com/wojtekmaj/react-pdf/commits/v9.2.1/packages/react-pdf)

---
updated-dependencies:
- dependency-name: pdfjs-dist
  dependency-type: indirect
- dependency-name: react-pdf
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Mar 9, 2025

Deploying finansu with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0d50d4a
Status: ✅  Deploy successful!
Preview URL: https://860838e5.finansu.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-view-nzhn.finansu.pages.dev

View logs

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 9, 2025
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 11, 2025

Superseded by #951.

@dependabot dependabot bot closed this Mar 11, 2025
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/view/next-project/multi-440ea45cb2 branch March 11, 2025 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant