forked from microsoft/pxt
-
Notifications
You must be signed in to change notification settings - Fork 0
Bump the npm_and_yarn group across 1 directories with 23 updates #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
dependabot
wants to merge
1
commit into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-b83d974fcd
Closed
Bump the npm_and_yarn group across 1 directories with 23 updates #1
dependabot
wants to merge
1
commit into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-b83d974fcd
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 18 updates in the /. directory: | Package | From | To | | --- | --- | --- | | [marked](https://github.com/markedjs/marked) | `0.3.19` | `4.0.10` | | [request](https://github.com/request/request) | `2.85.0` | `2.88.2` | | [@types/request](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/request) | `2.0.8` | `2.48.12` | | [postcss](https://github.com/postcss/postcss) | `6.0.21` | `8.4.31` | | [jquery](https://github.com/jquery/jquery) | `3.3.1` | `3.5.0` | | [karma](https://github.com/karma-runner/karma) | `2.0.0` | `6.3.16` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.2` | | [utilities](https://github.com/mde/utilities) | `0.0.37` | `` | | [jake](https://github.com/jakejs/jake) | `8.0.16` | `10.8.7` | | [hoek](https://github.com/hapijs/hoek) | `2.16.3` | `` | | [pouchdb](https://github.com/pouchdb/pouchdb) | `5.4.5` | `8.0.1` | | [less](https://github.com/less/less.js) | `2.7.3` | `4.2.0` | | [request](https://github.com/request/request) | `2.85.0` | `2.88.2` | | [minimist](https://github.com/minimistjs/minimist) | `1.2.0` | `1.2.8` | | [mkdirp](https://github.com/isaacs/node-mkdirp) | `0.5.1` | `0.5.6` | | [karma-mocha](https://github.com/karma-runner/karma-mocha) | `1.3.0` | `2.0.1` | | [mocha](https://github.com/mochajs/mocha) | `5.1.0` | `10.3.0` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.0.11` | `4.7.8` | | [shell-quote](https://github.com/ljharb/shell-quote) | `1.6.1` | `1.8.1` | Updates `marked` from 0.3.19 to 4.0.10 - [Release notes](https://github.com/markedjs/marked/releases) - [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json) - [Commits](markedjs/marked@v0.3.19...v4.0.10) Updates `request` from 2.85.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `@types/request` from 2.0.8 to 2.48.12 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/request) Updates `postcss` from 6.0.21 to 8.4.31 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@6.0.21...8.4.31) Updates `jquery` from 3.3.1 to 3.5.0 - [Release notes](https://github.com/jquery/jquery/releases) - [Commits](jquery/jquery@3.3.1...3.5.0) Updates `karma` from 2.0.0 to 6.3.16 - [Release notes](https://github.com/karma-runner/karma/releases) - [Changelog](https://github.com/karma-runner/karma/blob/master/CHANGELOG.md) - [Commits](karma-runner/karma@v2.0.0...v6.3.16) Updates `browserify-sign` from 4.0.4 to 4.2.2 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.2) Removes `utilities` Updates `jake` from 8.0.16 to 10.8.7 - [Changelog](https://github.com/jakejs/jake/blob/main/changelog.md) - [Commits](jakejs/jake@v8.0.16...v10.8.7) Updates `follow-redirects` from 1.0.0 to 1.15.5 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.0.0...v1.15.5) Updates `fsevents` from 1.1.3 to 2.3.3 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.1.3...v2.3.3) Removes `hoek` Updates `pouchdb` from 5.4.5 to 8.0.1 - [Release notes](https://github.com/pouchdb/pouchdb/releases) - [Commits](apache/pouchdb@5.4.5...8.0.1) Updates `less` from 2.7.3 to 4.2.0 - [Release notes](https://github.com/less/less.js/releases) - [Changelog](https://github.com/less/less.js/blob/master/CHANGELOG.md) - [Commits](less/less.js@v2.7.3...v4.2.0) Updates `request` from 2.85.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `minimist` from 1.2.0 to 1.2.8 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.0...v1.2.8) Updates `mkdirp` from 0.5.1 to 0.5.6 - [Changelog](https://github.com/isaacs/node-mkdirp/blob/main/CHANGELOG.md) - [Commits](isaacs/node-mkdirp@0.5.1...v0.5.6) Updates `karma-mocha` from 1.3.0 to 2.0.1 - [Release notes](https://github.com/karma-runner/karma-mocha/releases) - [Changelog](https://github.com/karma-runner/karma-mocha/blob/master/CHANGELOG.md) - [Commits](karma-runner/karma-mocha@v1.3.0...v2.0.1) Updates `mocha` from 5.1.0 to 10.3.0 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/master/CHANGELOG.md) - [Commits](mochajs/mocha@v5.1.0...v10.3.0) Updates `handlebars` from 4.0.11 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.11...v4.7.8) Updates `qs` from 6.1.2 to 6.5.1 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.1.2...v6.5.1) Updates `tough-cookie` from 2.2.2 to 2.3.4 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.2.2...v2.3.4) Updates `shell-quote` from 1.6.1 to 1.8.1 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.6.1...v1.8.1) Updates `socket.io-parser` from 3.1.3 to 4.2.4 - [Release notes](https://github.com/socketio/socket.io-parser/releases) - [Changelog](https://github.com/socketio/socket.io-parser/blob/main/CHANGELOG.md) - [Commits](socketio/socket.io-parser@3.1.3...4.2.4) --- updated-dependencies: - dependency-name: marked dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: "@types/request" dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: postcss dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: jquery dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: karma dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: utilities dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jake dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: hoek dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: pouchdb dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: less dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: mkdirp dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: karma-mocha dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: mocha dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: shell-quote dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: socket.io-parser dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
Superseded by #2. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 18 updates in the /. directory:
0.3.194.0.102.85.02.88.22.0.82.48.126.0.218.4.313.3.13.5.02.0.06.3.164.0.44.2.20.0.378.0.1610.8.72.16.35.4.58.0.12.7.34.2.02.85.02.88.21.2.01.2.80.5.10.5.61.3.02.0.15.1.010.3.04.0.114.7.81.6.11.8.1Updates
markedfrom 0.3.19 to 4.0.10Release notes
Sourced from marked's releases.
... (truncated)
Commits
ae01170chore(release): 4.0.10 [skip ci]fceda57🗜️ build [skip ci]8f80657fix(security): fix redos vulnerabilitiesc4a3ccdMerge pull request from GHSA-rrrm-qjm4-v8hfd7212a6chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (#2352)5a84db5chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (#2350)2bc67a5chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (#2351)98996b8chore(deps-dev): Bump@babel/preset-envfrom 7.16.5 to 7.16.7 (#2353)ebc2c95chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (#2354)e5171a9chore(release): 4.0.9 [skip ci]Maintainer changes
This version was pushed to npm by tonybrix, a new releaser for marked since your current version.
Updates
requestfrom 2.85.0 to 2.88.2Changelog
Sourced from request's changelog.
Commits
Updates
@types/requestfrom 2.0.8 to 2.48.12Commits
Updates
postcssfrom 6.0.21 to 8.4.31Release notes
Sourced from postcss's releases.
... (truncated)
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
90208deRelease 8.4.31 version58cc860Fix carrier return parsing4fff8e4Improve pnpm test outputcd43ed1Update dependenciescaa916bUpdate dependencies8972f76Typo11a5286Typo45c5501Release 8.4.30 versionbc3c341Update linterb2be58aMerge pull request #1881 from romainmenke/improve-sourcemap-performance--phil...Updates
jqueryfrom 3.3.1 to 3.5.0Release notes
Sourced from jquery's releases.
Commits
7a0a8503.5.08570a08Release: Update AUTHORS.txtda3dd85Ajax: Do not execute scripts for unsuccessful HTTP responses065143cAjax: Overwrite s.contentType with content-type header value, if any1a4f10dTests: Blacklist one focusin test in IE9e15d6bEvent: Use only one focusin/out handler per matching window & document966a709Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9Manipulation: Make jQuery.htmlPrefilter an identity function04bf577Selector: Update Sizzle from 2.3.4 to 2.3.57506c9cBuild: Resolve Travis config warningsMaintainer changes
This version was pushed to npm by mgol, a new releaser for jquery since your current version.
Updates
karmafrom 2.0.0 to 6.3.16Release notes
Sourced from karma's releases.
... (truncated)
Changelog
Sourced from karma's changelog.
... (truncated)
Commits
ab4b328chore(release): 6.3.16 [skip ci]ff7edbbfix(security): mitigate the "Open Redirect Vulnerability"c1befa0chore(release): 6.3.15 [skip ci]d9dade2fix(helper): make mkdirIfNotExists helper resilient to concurrent calls653c762ci: prevent duplicate CI tasks on creating a PRc97e562chore(release): 6.3.14 [skip ci]91d5acdfix: remove string template from client code69cfc76fix: warn whensingleRunandautoWatcharefalse839578cfix(security): remove XSS vulnerability inreturnUrlquery paramdb53785chore(release): 6.3.13 [skip ci]Updates
browserify-signfrom 4.0.4 to 4.2.2Changelog
Sourced from browserify-sign's changelog.
Commits
4af5a90v4.2.23aec038[Dev Deps] updatetape85994cd[Fix] properly check the upper bound for DSA signatures9ac5a5e[meta] fix package.json indentationdcf49ce[meta] addsafe-publish-latest4418183[meta] addnpmignoreandauto-changelog8767739[Fix]sign: throw on unsupported padding scheme5f6fb17[Tests] log when openssl doesn't support cipherf5f17c2[Tests] handle openSSL not supporting a schemed845d85[Tests] migrate from travis to github actionsMaintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Removes
utilitiesUpdates
jakefrom 8.0.16 to 10.8.7Changelog
Sourced from jake's changelog.
... (truncated)
Commits
33492f7Version 10.8.7a7d3515Removed stray logging statements414bcacVersion 10.8.66fc1d17Merge pull request #424 from martinholters/mh/fix_file_task62e5aa6Added lint task8992031Restore lint defaulta0378d1Add test for file task with multiple prereqsf8e8533Update file_task.js1c481a0Merge pull request #421 from falsefalse/patch-1ffe8655Bring back -q descriptionUpdates
follow-redirectsfrom 1.0.0 to 1.15.5Release notes
Sourced from follow-redirects's releases.
... (truncated)
Commits
b1677ceRelease version 1.15.5 of the npm package.d8914f7Preserve fragment in responseUrl.6585820Release version 1.15.4 of the npm package.7a6567eDisallow bracketed hostnames.05629afPrefer native URL instead of deprecated url.parse.1cba8e8Prefer native URL instead of legacy url.resolve.72bc2a4Simplify _processResponse error handling.3d42aecAdd bracket tests.bcbb096Do not directly set Error properties.192dbe7Release version 1.15.3 of the npm package.Updates
fseventsfrom 1.1.3 to 2.3.3Release notes
Sourced from fsevents's releases.
... (truncated)
Commits
2db891eRelease v2.3.38ec87bfUpdate nodejs.yml (#392)c20c3afreadme63709dfMerge pull request #384 from aleksanb/subdirsa77340fHandle MustScanSubDirs for large projects66be519Update README.md (#371)2f2a858Update README.md (#364)a7f5d00Release v2.3.2fab136afix: issue #355 (#356)328ae39Release v2.3.1Maintainer changes
This version was pushed to npm by pipobscure, a new releaser for fsevents since your current version.
Removes
hoekUpdates
pouchdbfrom 5.4.5 to 8.0.1Release notes
Sourced from pouchdb's releases.
... (truncated)
Commits
fde45b9build 8.0.13c6e9efdocs: add release post for 8.0.17484e24docs: update 2022-12-14-pouchdb-8.0.0.mdff81fa3ci: use node 1406bfe89(pouchdb#8581) - Fix test2c81da4(pouchdb#8581) - Fix test3d36d2d(pouchdb#8581) - Fix test6a7fd46(pouchdb#8581) - Fix test.da5069d(pouchdb#8581) - Fix this of changesHandler0bdb342feat: add mastodon verification linkMaintainer changes
This version was pushed to npm by albaherreriasdev, a new releaser for pouchdb since your current version.
Updates
lessfrom 2.7.3 to 4.2.0Release notes
Sourced from less's releases.
... (truncated)
Changelog
Sourced from less's changelog.