Bump the npm_and_yarn group across 1 directory with 25 updates#2
Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
Closed
Bump the npm_and_yarn group across 1 directory with 25 updates#2dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 25 updates in the / directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.5` | `4.17.21` | | [acorn](https://github.com/acornjs/acorn) | `5.5.3` | `5.7.4` | | [bl](https://github.com/rvagg/bl) | `1.2.2` | `1.2.3` | | [color-string](https://github.com/Qix-/color-string) | `1.5.2` | `1.9.1` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [decompress](https://github.com/kevva/decompress) | `4.2.0` | `4.2.1` | | [extend](https://github.com/justmoon/node-extend) | `3.0.1` | `3.0.2` | | [fsevents](https://github.com/fsevents/fsevents) | `1.1.3` | `1.2.13` | | [fstream](https://github.com/npm/fstream) | `1.0.11` | `1.0.12` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.0.11` | `4.7.8` | | [hosted-git-info](https://github.com/npm/hosted-git-info) | `2.6.0` | `2.8.9` | | [ini](https://github.com/npm/ini) | `1.3.5` | `1.3.8` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.11.0` | `3.14.1` | | [lodash-es](https://github.com/lodash/lodash) | `4.17.8` | `4.17.21` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.4` | `3.1.2` | | [mixin-deep](https://github.com/jonschlinkert/mixin-deep) | `1.3.1` | `1.3.2` | | [morgan](https://github.com/expressjs/morgan) | `1.9.0` | `1.10.0` | | [path-parse](https://github.com/jbgutierrez/path-parse) | `1.0.5` | `1.0.7` | | [qs](https://github.com/ljharb/qs) | `6.4.0` | `6.4.1` | | [semver](https://github.com/npm/node-semver) | `5.5.0` | `5.7.2` | | [stringstream](https://github.com/mhart/StringStream) | `0.0.5` | `0.0.6` | | [tmpl](https://github.com/daaku/nodejs-tmpl) | `1.0.4` | `1.0.5` | | [ua-parser-js](https://github.com/faisalman/ua-parser-js) | `0.7.17` | `0.7.37` | | [url-parse](https://github.com/unshiftio/url-parse) | `1.3.0` | `1.5.10` | | [y18n](https://github.com/yargs/y18n) | `3.2.1` | `3.2.2` | Updates `lodash` from 4.17.5 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.5...4.17.21) Updates `acorn` from 5.5.3 to 5.7.4 - [Commits](acornjs/acorn@5.5.3...5.7.4) Updates `bl` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/rvagg/bl/releases) - [Changelog](https://github.com/rvagg/bl/blob/master/CHANGELOG.md) - [Commits](rvagg/bl@v1.2.2...v1.2.3) Updates `color-string` from 1.5.2 to 1.9.1 - [Release notes](https://github.com/Qix-/color-string/releases) - [Changelog](https://github.com/Qix-/color-string/blob/master/CHANGELOG.md) - [Commits](Qix-/color-string@1.5.2...1.9.1) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `decompress` from 4.2.0 to 4.2.1 - [Release notes](https://github.com/kevva/decompress/releases) - [Commits](kevva/decompress@v4.2.0...v4.2.1) Updates `extend` from 3.0.1 to 3.0.2 - [Changelog](https://github.com/justmoon/node-extend/blob/main/CHANGELOG.md) - [Commits](justmoon/node-extend@v3.0.1...v3.0.2) Updates `fsevents` from 1.1.3 to 1.2.13 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.1.3...v1.2.13) Updates `fstream` from 1.0.11 to 1.0.12 - [Commits](npm/fstream@v1.0.11...v1.0.12) Updates `handlebars` from 4.0.11 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.11...v4.7.8) Updates `hosted-git-info` from 2.6.0 to 2.8.9 - [Release notes](https://github.com/npm/hosted-git-info/releases) - [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md) - [Commits](npm/hosted-git-info@v2.6.0...v2.8.9) Updates `ini` from 1.3.5 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.5...v1.3.8) Updates `js-yaml` from 3.11.0 to 3.14.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.11.0...3.14.1) Updates `lodash-es` from 4.17.8 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](https://github.com/lodash/lodash/commits/4.17.21) Updates `minimatch` from 3.0.4 to 3.1.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.4...v3.1.2) Updates `mixin-deep` from 1.3.1 to 1.3.2 - [Commits](jonschlinkert/mixin-deep@1.3.1...1.3.2) Updates `morgan` from 1.9.0 to 1.10.0 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.9.0...1.10.0) Updates `path-parse` from 1.0.5 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `qs` from 6.4.0 to 6.4.1 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.4.0...v6.4.1) Updates `semver` from 5.5.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.5.0...v5.7.2) Updates `stringstream` from 0.0.5 to 0.0.6 - [Commits](mhart/StringStream@v0.0.5...v0.0.6) Updates `tmpl` from 1.0.4 to 1.0.5 - [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5) Updates `ua-parser-js` from 0.7.17 to 0.7.37 - [Release notes](https://github.com/faisalman/ua-parser-js/releases) - [Changelog](https://github.com/faisalman/ua-parser-js/blob/master/CHANGELOG.md) - [Commits](faisalman/ua-parser-js@0.7.17...0.7.37) Updates `url-parse` from 1.3.0 to 1.5.10 - [Commits](unshiftio/url-parse@1.3.0...1.5.10) Updates `y18n` from 3.2.1 to 3.2.2 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](https://github.com/yargs/y18n/commits) --- updated-dependencies: - dependency-name: lodash dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: acorn dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: bl dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: color-string dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decompress dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: extend dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fstream dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hosted-git-info dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash-es dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: mixin-deep dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: morgan dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: stringstream dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmpl dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ua-parser-js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: url-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
Author
|
Superseded by #3. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 25 updates in the / directory:
4.17.54.17.215.5.35.7.41.2.21.2.31.5.21.9.10.2.00.2.24.2.04.2.13.0.13.0.21.1.31.2.131.0.111.0.124.0.114.7.82.6.02.8.91.3.51.3.83.11.03.14.14.17.84.17.213.0.43.1.21.3.11.3.21.9.01.10.01.0.51.0.76.4.06.4.15.5.05.7.20.0.50.0.61.0.41.0.50.7.170.7.371.3.01.5.103.2.13.2.2Updates
lodashfrom 4.17.5 to 4.17.21Commits
f299b52Bump to v4.17.21c4847ebImprove performance oftoNumber,trimandtrimEndon large input strings3469357Prevent command injection through_.template'svariableoptionded9bc6Bump to v4.17.20.63150efDocumentation fixes.00f0f62test.js: Remove trailing comma.846e434Temporarily use a custom fork oflodash-cli.5d046f3Re-enable Travis tests on4.17branch.aa816b3Remove/npm-package.d7fbc52Bump to v4.17.19Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash since your current version.
Updates
acornfrom 5.5.3 to 5.7.4Commits
6370e90Mark version 5.7.4fbc15b1More rigorously check surrogate pairs in regexp validator910e62bMark version 5.7.33442a80Make generate-identifier-regex capable of rewriting src/identifier.js22b22f3Raise specific errors for unterminated template literals1461c7cFix a lint error0c12f63Fix tokenizing of regexps after .of832c308Fix 404 url95ca55cMark version 5.7.2bba80abRemove another fixed test from the 262 whitelistUpdates
blfrom 1.2.2 to 1.2.3Commits
d69edfd1.2.3847473atest all branches0bd87ecFix unintialized memory accessdc097f3test newer versions of NodeUpdates
color-stringfrom 1.5.2 to 1.9.1Release notes
Sourced from color-string's releases.
... (truncated)
Commits
d9b04bb1.9.1937b690fix to.keyword returning Object.prototype values (#67)4daceef1.9.094a429eadd parsing of exponential alpha values for HWB and HSLfc2f8801.8.232f3e00fix incorrect handling of optional comma in rgb() regex (fixes #65)0766ca71.8.10710543Fix rgb alpha percentage parsing from int to floatab299a71.8.0bea8702add anchors to keyword regexUpdates
decode-uri-componentfrom 0.2.0 to 0.2.2Release notes
Sourced from decode-uri-component's releases.
Commits
a0eea460.2.2980e0bfPrevent overwriting previously decoded tokens3c8a3730.2.176abc93Switch to GitHub workflows746ca5dFix issue where decode throws - fixes #6486d7e2Update license (#1)a650457Tidelift tasks66e1c28Meta tweaksUpdates
decompressfrom 4.2.0 to 4.2.1Release notes
Sourced from decompress's releases.
Commits
84a8c104.2.1fafff47Meta tweaks967146ePrevent directory traversal (#73)74a462aMeta tweaks7ddadd9Add note aboutfilteroptionUpdates
extendfrom 3.0.1 to 3.0.2Changelog
Sourced from extend's changelog.
Commits
8d106d2v3.0.2e97091f[Dev Deps] updatetapee841aac[Tests] up tonodev10.70e68e71[Fix] Prevent merging proto propertya689700Only apps should have lockfilesf13c1c4[Dev Deps] updateeslint,@ljharb/eslint-config,tapef3570fe[Tests] up tonodev10.0,v9.11,v8.11,v7.10,v6.14,v4.9; use...Updates
fseventsfrom 1.1.3 to 1.2.13Release notes
Sourced from fsevents's releases.
Commits
844a05dVersion Bumpf393f2aOnly build fsevents on macOS (#322)6a281a7[publish binary]acc2bce[publish binary]f532b6e[publish binary]4c6a1c0Add node 13 to travis matrix.92e40aaRelease 1.2.12.909af26Release v1.2.117074adbRelease v1.2.100a052f6Node.js v12 support for v1.x (#274)Updates
fstreamfrom 1.0.11 to 1.0.12Commits
42354591.0.126a77d2fClobber a Link if it's in the way of a FileUpdates
handlebarsfrom 4.0.11 to 4.7.8Release notes
Sourced from handlebars's releases.
Changelog
Sourced from handlebars's changelog.
... (truncated)
Commits
8dc3d25v4.7.8668c4fbFix browser tests in CI pipelinec65c6ccTest on Node 183d3796cMake library compatible with workers075b354Fix sync issue with npm lock-file30dbf04Fix compiling of each block params in strict modee3a5448Fix bundler issue with webpack 58e23642Fix integration-tests issue with npm >= 788ac068use https instead of git for mustache submodulec68bc08Fix typoMaintainer changes
This version was pushed to npm by jaylinski, a new releaser for handlebars since your current version.
Updates
hosted-git-infofrom 2.6.0 to 2.8.9Changelog
Sourced from hosted-git-info's changelog.
... (truncated)
Commits
8d4b369chore(release): 2.8.929adfe5fix: backport regex fix from #76afeaefdchore(release): 2.8.85038b18fix: #61 & #65 addressing issues w/ url.URL implmentation which regressed nod...7440afachore(release): 2.8.72d0bb66fix: Do not attempt to use url.URL when unavailablef2cdfcffix: Do not pass scp-style URLs to the WhatWG url.URLe1b83dfchore(release): 2.8.6ff259a6Ensure passwords in hosted Git URLs are correctly escaped624fd6fchore(release): 2.8.5Maintainer changes
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates
inifrom 1.3.5 to 1.3.8Commits
a2c5da81.3.8af5c6bbDo not use Object.create(null)8b648a1don't test where our devdeps don't even workc74c8af1.3.7024b8b5update deps, add linting032fbafUse Object.create(null) to avoid default object property hazards2da90391.3.6cfea636better git push script, before publish instead of after56d2805do not allow invalid hazardous string as section nameMaintainer changes
This version was pushed to npm by isaacs, a new releaser for ini since your current version.
Updates
js-yamlfrom 3.11.0 to 3.14.1Changelog
Sourced from js-yaml's changelog.
Commits
37caaad3.14.1 released094c0f7dist rebuild9586ebeAvoid calling hasOwnProperty of user-controlled objects34e50723.14.0 released7b25c83Browser files rebuild6f73473Dev deps bump0c29349Travis-CI: drop old nodejs versions10be97efix(loader): Add support forsafe/loadAll(input, options)d6983ddFix issue #526: wrong quote position writing condensed flow (#527)93fbf7dfix issue 526 (wrong quote position writing condensed flow)Updates
lodash-esfrom 4.17.8 to 4.17.21Commits
Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash-es since your current version.
Updates
minimatchfrom 3.0.4 to 3.1.2Commits
699c4593.1.22f2b5fffix: trim pattern25d7c0d3.1.155dda29fix: treat nocase:true as always having magic5e1fb8d3.1.0f8145c5Add 'allowWindowsEscape' option570e8b1add publishConfig for v3 publishes5b7cd333.0.620b4b56[fix] revert all breaking syntax changes2ff0388document, expose, and test 'partial:true' optionUpdates
mixin-deepfrom 1.3.1 to 1.3.2Commits
754f0c21.3.290ee1faensure keys are valid when mixing in valuesMaintainer changes
This version was pushed to npm by doowb, a new releaser for mixin-deep since your current version.
Updates
morganfrom 1.9.0 to 1.10.0Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
c68d2ea1.10.0aa718d7Add :total-time tokence15462build: remove deprecated Travis CI directivee13e0d3build: [email protected]f023828build: use nyc for test coverage30c0871build: [email protected]8114639docs: document success color in dev format5d8176fdocs: update rotating-file-stream usage for 2.xc54194ctests: ignore branch coverage that varies5659d2fbuild: [email protected]Updates
path-parsefrom 1.0.5 to 1.0.7Commits
Updates
qsfrom 6.4.0 to 6.4.1Changelog
Sourced from qs's changelog.
Commits
486aa46v6.4.1727ef5d[Fix]parse: ignore__proto__keys (#428)cd1874e[Robustness]stringify: avoid relying on a globalundefined(#427)45e987c[readme] remove travis badge; add github actions/codecov badges; update URLs90a3bce[meta] fix README.md (#399)9566d25[Fix] fix for an impossible situation: when the formatter is called with a no...74227efClean up license text so it’s properly detected as BSD-3-Clause35dfb22[actions] backport actions from main7d4670f[Dev Deps] backport from main0485440[Fix] usesafer-bufferinstead ofBufferconstructorUpdates
semverfrom 5.5.0 to 5.7.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
f8cc313chore: release 5.7.22f8fd41fix: better handling of whitespace (#585)deb5ad5chore:@npmcli/template-oss@4.16.0c83c18c5.7.1956e228Correct typo in README8055dda5.7.0604e73dauto-publishing scriptsbed01e2remove the nomin comments, since we don't minify any more anyway9cb68f1document parse method38d42ca5.7 changelogMaintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
stringstreamfrom 0.0.5 to 0.0.6Commits
fee31c50.0.62f4a9d4Merge pull request #9 from mhart/fix-buffer-constructor-vulnafbc744Ensure data is not a number in Buffer constructorUpdates
tmplfrom 1.0.4 to 1.0.5Commits
Updates
ua-parser-jsfrom 0.7.17 to 0.7.37Release notes
Sourced from ua-parser-js's releases.
Changelog
Sourced from ua-parser-js's changelog.
... (truncated)
Commits
d30ad46Bump version 0.7.375302e2dUpdate changelogf3de7b7Backport - Improve browser detection: WeChat (cherry picked from commit 17f0c...c41100eBackport - Improve browser detection: unified name for Baidu (cherry picked f...23c5d77Backport - Improve browser detection: remove unnecessary extra space in "Avan...e3d5f76Backport - Improve browser detection: rename "Samsung Browser" to "Samsung In...02af42fBackport - Fix #682 - Add new browser: Smart Lenovo Browser (cherry picked fr...57d1ac0Backport - Fix #683 - change MetaSr into Sogou Explorer (+add Sogou Mobile) (...ea2c829Backport - Fix misidentified WebView token as device model - found in #681 (c...3b896d5Backport - Fix #681 - Add new browser: Vivo Browser (cherry picked from commi...Updates
url-parsefrom 1.3.0 to 1.5.10Commits
8cd4c6c1.5.10ce7a01f[fix] Improve handling of empty port0071490[doc] Update JSDoc commenta7044e3[minor] Use more descriptive variable named547792[security] Add credits for CVE-2022-0691ad233571.5.90e3fb54[fix] Strip all control characters from the beginning of the URL61864a8[security] Add credits for CVE-2022-0686bb0104d1.5.8d5c6479[fix] Handle the case where the port is specified but emptyUpdates
y18nfrom 3.2.1 to 3.2.2Release notes
Sourced from y18n's releases.
Commits
Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for y18n since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it...Description has been truncated