build(deps): bump the npm_and_yarn group across 2 directories with 15 updates#2
Open
dependabot[bot] wants to merge 1 commit intom133from
Conversation
… updates Bumps the npm_and_yarn group with 4 updates in the /infra/perfetto.dev directory: [mermaid](https://github.com/mermaid-js/mermaid), [ejs](https://github.com/mde/ejs), [highlight.js](https://github.com/highlightjs/highlight.js) and [braces](https://github.com/micromatch/braces). Bumps the npm_and_yarn group with 9 updates in the /ui directory: | Package | From | To | | --- | --- | --- | | [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` | | [esbuild](https://github.com/evanw/esbuild) | `0.21.5` | `0.25.0` | | [vega](https://github.com/vega/vega) | `5.30.0` | `5.32.0` | | [rollup](https://github.com/rollup/rollup) | `2.79.1` | `2.79.2` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.22.5` | `7.28.5` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.12` | | [form-data](https://github.com/form-data/form-data) | `4.0.0` | `4.0.5` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.1` | `3.14.2` | | [tmp](https://github.com/raszi/node-tmp) | `0.2.1` | `0.2.5` | Updates `mermaid` from 9.1.1 to 10.9.4 - [Release notes](https://github.com/mermaid-js/mermaid/releases) - [Commits](mermaid-js/mermaid@9.1.1...v10.9.4) Updates `ejs` from 3.0.1 to 3.1.10 - [Release notes](https://github.com/mde/ejs/releases) - [Commits](mde/ejs@v3.0.1...v3.1.10) Updates `highlight.js` from 10.1.2 to 10.4.1 - [Release notes](https://github.com/highlightjs/highlight.js/releases) - [Changelog](https://github.com/highlightjs/highlight.js/blob/main/CHANGES.md) - [Commits](highlightjs/highlight.js@10.1.2...10.4.1) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `d3-color` from 1.4.1 to 3.1.0 - [Release notes](https://github.com/d3/d3-color/releases) - [Commits](d3/d3-color@v1.4.1...v3.1.0) Updates `dompurify` from 2.3.6 to 3.1.6 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@2.3.6...3.1.6) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `esbuild` from 0.21.5 to 0.25.0 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md) - [Commits](evanw/esbuild@v0.21.5...v0.25.0) Updates `vega` from 5.30.0 to 5.32.0 - [Release notes](https://github.com/vega/vega/releases) - [Commits](vega/vega@v5.30.0...v5.32.0) Updates `rollup` from 2.79.1 to 2.79.2 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG-2.md) - [Commits](rollup/rollup@v2.79.1...v2.79.2) Updates `@babel/traverse` from 7.22.5 to 7.28.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.28.5/packages/babel-traverse) Updates `brace-expansion` from 1.1.11 to 1.1.12 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.12) Updates `form-data` from 4.0.0 to 4.0.5 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v4.0.0...v4.0.5) Updates `js-yaml` from 3.14.1 to 3.14.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.14.1...3.14.2) Updates `tmp` from 0.2.1 to 0.2.5 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](raszi/node-tmp@v0.2.1...v0.2.5) Updates `vega-functions` from 5.15.0 to 5.17.0 - [Release notes](https://github.com/vega/vega/releases) - [Commits](vega/vega@v5.15.0...v5.17.0) --- updated-dependencies: - dependency-name: mermaid dependency-version: 10.9.4 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ejs dependency-version: 3.1.10 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: highlight.js dependency-version: 10.4.1 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: braces dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: d3-color dependency-version: 3.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.1.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: braces dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: esbuild dependency-version: 0.25.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vega dependency-version: 5.32.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.79.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-version: 7.28.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: form-data dependency-version: 4.0.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-version: 3.14.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmp dependency-version: 0.2.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: vega-functions dependency-version: 5.17.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 4 updates in the /infra/perfetto.dev directory: mermaid, ejs, highlight.js and braces.
Bumps the npm_and_yarn group with 9 updates in the /ui directory:
3.0.23.0.30.21.50.25.05.30.05.32.02.79.12.79.27.22.57.28.51.1.111.1.124.0.04.0.53.14.13.14.20.2.10.2.5Updates
mermaidfrom 9.1.1 to 10.9.4Commits
80dcf2echore: fixed formattingcdff69fchore: updated upload artifact version2ce5801chore: bump mermaid version to 10.9.42efe338fix: sanitize addHtmlLabel in createLabel7509b06fix: Sanitize Katex85ec96achore: bump mermaid version to v10.9.39301a57style: prettify src/diagrams/block/blockDB.ts2bedd0echore(deps): update katex to 0.16.1192a07ffchore(deps): update bundled DOMPurify to 3.1.64dd4997chore: Bump versionMaintainer changes
This version was pushed to npm by sidv, a new releaser for mermaid since your current version.
Updates
ejsfrom 3.0.1 to 3.1.10Release notes
Sourced from ejs's releases.
Commits
d3f807dVersion 3.1.109ee26ddMocha TDDe469741Basic pollution protection715e950Merge pull request #756 from Jeffrey-mu/maincabe314Include advanced usage examples29b076cAdded header11503c7Merge branch 'main' of github.com:mde/ejs into main7690404Added security banner to READMEf47d7aeUpdate SECURITY.md828cea1Update SECURITY.mdUpdates
highlight.jsfrom 10.1.2 to 10.4.1Release notes
Sourced from highlight.js's releases.
... (truncated)
Changelog
Sourced from highlight.js's changelog.
... (truncated)
Commits
e96b915bump 10.4.1065f65fchore(release) allow release script to handle production releases68509fcchore(docs) bump SECURITY mention to 9.18.5aa0fb85chore(docs) Version 9 has reached EOL.fb0a626enh(ci): Add tests for polynomial regex issuesfa46dd1fix(reasonml) fix poly backtracking issued496052fix(latex) fix poly backtracking issued9f1cdbfix(javascript/typescript) fix poly backtracking issuefdec037fix(asciidoc) fix poly backtracking issue02ca487fix(kotlin) fix poly backtracking issueMaintainer changes
This version was pushed to npm by joshgoebel, a new releaser for highlight.js since your current version.
Updates
bracesfrom 3.0.2 to 3.0.3Commits
74b2db23.0.388f1429update eslint. lint, fix unit tests.415d660Snyk js braces 6838727 (#40)190510ffix tests, skip 1 test in test/braces.expand716eb9freadme bumpa5851e5Merge pull request #37 from coderaiser/fix/vulnerability2092bd1feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cffix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9remove funding file665ab5dupdate keepEscaping doc (#27)Updates
d3-colorfrom 1.4.1 to 3.1.0Release notes
Sourced from d3-color's releases.
Commits
7a1573e3.1.075c19c4update LICENSEef94e01update dependencies5e9f757method shorthande4bc34eformatHex8 (#103)ac660c6{rgb,hsl}.clamp() (#102)70e3a04clamp HSL format (#101)994d8fdavoid backtracking (#100)7d61bbe3.0.193bc4ffrelated d3/d33; extract copyrights from LICENSEUpdates
dompurifyfrom 2.3.6 to 3.1.6Release notes
Sourced from dompurify's releases.
... (truncated)
Commits
4083a90Merge pull request #978 from cure53/main90a10a1fix: Fixed a typo on the README65df042chore: Preparing 3.1.6 release6e03334fix: Made sure that remove() is not called directly from node00fc06cfix: Fixed a DOM clobbering issue leading to an error being thrownf8c2ef5Merge pull request #977 from cure53/dependabot/npm_and_yarn/multi-99ca4f73d8e5112ecbuild(deps): bump ws and socket.io-adapter9978cecdocs: Added better security warning about SAFE_FOR_XML to READMEfa542dffix: Changed the order for attribute checks slightly for safer hooksb8b552cMerge pull request #975 from cure53/dependabot/npm_and_yarn/multi-2d3aef8690Updates
bracesfrom 3.0.2 to 3.0.3Commits
74b2db23.0.388f1429update eslint. lint, fix unit tests.415d660Snyk js braces 6838727 (#40)190510ffix tests, skip 1 test in test/braces.expand716eb9freadme bumpa5851e5Merge pull request #37 from coderaiser/fix/vulnerability2092bd1feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cffix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9remove funding file665ab5dupdate keepEscaping doc (#27)Updates
esbuildfrom 0.21.5 to 0.25.0Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
e9174d6publish 0.25.0 to npmc27dbebfixhostsinplugin-tests.js6794f60fixhostsinnode-unref-tests.jsde85afdMerge commit from forkda1de1bfix #4065: bitwise operators can return bigintsf4e9d19switch case liveness:defaultis always last7aa47c3fix #4028: minify live/deadswitchcases better22ecd30minify: more constant folding for strict equality4cdf03cfix #4053: reordering of.tsxinnode_modulesdc71977fix #3692:0now picks a random ephemeral portUpdates
vegafrom 5.30.0 to 5.32.0Release notes
Sourced from vega's releases.
Commits
c46889dchore: update vega-cli to v5.32.0 (#4015)2fe2e63chore: v5.32.0 (#4014)81ed011chore: remove extra space in test name6026887fix: correct data year citation in dorling-cartogram example (#4006)a3af49efeat: Add base64 string encoder/decoder tovega-expressionand `vega-interp...cd88cc8fix(docs): Update typo in vega.timeFloor description (#4010)694560cMerge commit from fork560aeecdocs: Add Security Advisory Policy forvega(#4008)0b6a114feat(vega-typings): add Typescript Types forvega-loader(#4000)b83b8e5docs: Replace redirect url inexpressions.md(#3996)Updates
rollupfrom 2.79.1 to 2.79.2Release notes
Sourced from rollup's releases.
Changelog
Sourced from rollup's changelog.
Commits
c9bd03d2.79.248aef33fix: resolve DOM Clobbering CVE-2024-43788 (backport to v2) (#5677)Updates
@babel/traversefrom 7.22.5 to 7.28.5Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Changelog
Sourced from
@babel/traverse's changelog.... (truncated)
Commits
61647aev7.28.5e579cb0EnablestrictNullChecksfortraverse(#17499)7385eae[Babel 8] Improve scope information collection performance (#17043)26bc651[Babel 8] Better node type definitions forcomputed(#17500)e626523FixJSXIdentifierhandling inisReferencedIdentifier(#17503)19c9126fix: ensure scope.push register in anonymous fn (#17504)35055e3v7.28.4b41f8cdUpdate Jest to v30.1.1 (#17493)22493b6Improve@babel/traversetypings (#17485)18d88b8Improve@babel/coretypings (#17471)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for
@babel/traversesince your current version.Updates
brace-expansionfrom 1.1.11 to 1.1.12Release notes
Sourced from brace-expansion's releases.
Commits
44f33b41.1.12c460dbdpkg: publish on tag 1.xccb8ac6fmtc3c73c8Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
form-datafrom 4.0.0 to 4.0.5Release notes
Sourced from form-data's releases.
... (truncated)
Changelog
Sourced from form-data's changelog.