forked from framasoft/ep_mypads
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group across 1 directory with 37 updates #1
Open
dependabot
wants to merge
1
commit into
master
Choose a base branch
from
dependabot/npm_and_yarn/npm_and_yarn-c627c4597f
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 28 updates in the / directory: | Package | From | To | | --- | --- | --- | | [async](https://github.com/caolan/async) | `2.6.3` | `2.6.4` | | [body-parser](https://github.com/expressjs/body-parser) | `1.12.4` | `1.20.3` | | [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) | `5.0.5` | `9.0.2` | | [passport-jwt](https://github.com/mikenicholson/passport-jwt) | `3.0.1` | `4.0.1` | | [passport](https://github.com/jaredhanson/passport) | `0.2.2` | `0.6.0` | | [express](https://github.com/expressjs/express) | `4.12.3` | `4.20.0` | | [mithril](https://github.com/MithrilJS/mithril.js) | `0.1.34` | `1.1.7` | | [ajv](https://github.com/ajv-validator/ajv) | `6.12.0` | `6.12.6` | | [ansi-regex](https://github.com/chalk/ansi-regex) | `3.0.0` | `3.0.1` | | [base64-url](https://github.com/joaquimserafim/base64-url) | `1.2.1` | `removed` | | [express-session](https://github.com/expressjs/session) | `1.11.1` | `1.18.1` | | [bl](https://github.com/rvagg/bl) | `0.4.2` | `removed` | | [docker](https://github.com/jbt/docker) | `0.2.14` | `1.0.0` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.3` | | [moment](https://github.com/moment/moment) | `2.24.0` | `2.30.1` | | [emailjs](https://github.com/eleith/emailjs) | `0.3.16` | `4.0.3` | | [cookie](https://github.com/jshttp/cookie) | `0.1.2` | `0.7.2` | | [cookie-parser](https://github.com/expressjs/cookie-parser) | `1.3.4` | `1.4.7` | | [express](https://github.com/expressjs/express) | `4.20.0` | `4.21.2` | | [fsevents](https://github.com/fsevents/fsevents) | `0.3.8` | `2.3.3` | | [watchify](https://github.com/browserify/watchify) | `2.6.2` | `4.0.0` | | [json-schema](https://github.com/kriszyp/json-schema) | `0.2.3` | `0.4.0` | | [jsprim](https://github.com/joyent/node-jsprim) | `1.4.1` | `1.4.2` | | [mysql](https://github.com/mysqljs/mysql) | `2.6.1` | `removed` | | [ueberdb2](https://github.com/ether/ueberDB) | `0.3.8` | `5.0.6` | | [shell-quote](https://github.com/ljharb/shell-quote) | `0.0.1` | `1.8.2` | | [browserify](https://github.com/browserify/browserify) | `9.0.8` | `17.0.1` | | [shelljs](https://github.com/shelljs/shelljs) | `0.3.0` | `removed` | | [jshint](https://github.com/jshint/jshint) | `2.11.0` | `2.13.6` | Updates `async` from 2.6.3 to 2.6.4 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md) - [Commits](caolan/async@v2.6.3...v2.6.4) Updates `body-parser` from 1.12.4 to 1.20.3 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.12.4...1.20.3) Updates `jsonwebtoken` from 5.0.5 to 9.0.2 - [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md) - [Commits](auth0/node-jsonwebtoken@v5.0.5...v9.0.2) Updates `passport-jwt` from 3.0.1 to 4.0.1 - [Commits](mikenicholson/passport-jwt@v3.0.1...v4.0.1) Updates `lodash` from 4.17.15 to 3.10.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.15...3.10.1) Updates `passport` from 0.2.2 to 0.6.0 - [Changelog](https://github.com/jaredhanson/passport/blob/master/CHANGELOG.md) - [Commits](jaredhanson/passport@v0.2.2...v0.6.0) Updates `express` from 4.12.3 to 4.20.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.12.3...4.20.0) Updates `mithril` from 0.1.34 to 1.1.7 - [Release notes](https://github.com/MithrilJS/mithril.js/releases) - [Changelog](https://github.com/MithrilJS/mithril.js/blob/main/docs/recent-changes.md) - [Commits](MithrilJS/mithril.js@v0.1.34...v1.1.7) Updates `tough-cookie` from 2.5.0 to 0.12.1 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.5.0...v0.12.1) Updates `ajv` from 6.12.0 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.12.0...v6.12.6) Updates `ansi-regex` from 3.0.0 to 3.0.1 - [Release notes](https://github.com/chalk/ansi-regex/releases) - [Commits](chalk/ansi-regex@v3.0.0...v3.0.1) Removes `base64-url` Updates `express-session` from 1.11.1 to 1.18.1 - [Release notes](https://github.com/expressjs/session/releases) - [Changelog](https://github.com/expressjs/session/blob/master/HISTORY.md) - [Commits](expressjs/session@v1.11.1...v1.18.1) Removes `bl` Updates `docker` from 0.2.14 to 1.0.0 - [Changelog](https://github.com/jbt/docker/blob/master/History.md) - [Commits](jbt/docker@v0.2.14...v1.0.0) Updates `browserify-sign` from 4.0.4 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.3) Updates `moment` from 2.24.0 to 2.30.1 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.24.0...2.30.1) Updates `emailjs` from 0.3.16 to 4.0.3 - [Changelog](https://github.com/eleith/emailjs/blob/main/CHANGELOG.md) - [Commits](https://github.com/eleith/emailjs/commits) Updates `debug` from 2.1.3 to 2.6.9 - [Release notes](https://github.com/debug-js/debug/releases) - [Changelog](https://github.com/debug-js/debug/blob/2.6.9/CHANGELOG.md) - [Commits](debug-js/debug@2.1.3...2.6.9) Updates `cookie` from 0.1.2 to 0.7.2 - [Release notes](https://github.com/jshttp/cookie/releases) - [Commits](jshttp/cookie@v0.1.2...v0.7.2) Updates `cookie-parser` from 1.3.4 to 1.4.7 - [Release notes](https://github.com/expressjs/cookie-parser/releases) - [Changelog](https://github.com/expressjs/cookie-parser/blob/master/HISTORY.md) - [Commits](expressjs/cookie-parser@1.3.4...1.4.7) Updates `express` from 4.20.0 to 4.21.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.12.3...4.20.0) Updates `elliptic` from 6.5.2 to 6.6.1 - [Commits](indutny/elliptic@v6.5.2...v6.6.1) Updates `qs` from 2.4.1 to 6.4.1 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v2.4.1...v6.4.1) Updates `fsevents` from 0.3.8 to 2.3.3 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v0.3.8...v2.3.3) Updates `watchify` from 2.6.2 to 4.0.0 - [Release notes](https://github.com/browserify/watchify/releases) - [Changelog](https://github.com/browserify/watchify/blob/master/CHANGELOG.md) - [Commits](browserify/watchify@v2.6.2...v4.0.0) Updates `json-schema` from 0.2.3 to 0.4.0 - [Commits](kriszyp/json-schema@v0.2.3...v0.4.0) Updates `jsprim` from 1.4.1 to 1.4.2 - [Changelog](https://github.com/TritonDataCenter/node-jsprim/blob/v1.4.2/CHANGES.md) - [Commits](TritonDataCenter/node-jsprim@v1.4.1...v1.4.2) Updates `minimist` from 1.2.5 to 1.2.8 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.5...v1.2.8) Removes `mysql` Updates `ueberdb2` from 0.3.8 to 5.0.6 - [Changelog](https://github.com/ether/ueberDB/blob/main/CHANGELOG.md) - [Commits](https://github.com/ether/ueberDB/commits/v5.0.6) Updates `semver` from 4.3.2 to 6.3.1 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v6.3.1/CHANGELOG.md) - [Commits](npm/node-semver@v4.3.2...v6.3.1) Updates `send` from 0.12.2 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.12.2...0.19.0) Updates `serve-static` from 1.9.3 to 1.16.2 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/v1.16.2/HISTORY.md) - [Commits](expressjs/serve-static@v1.9.3...v1.16.2) Updates `shell-quote` from 0.0.1 to 1.8.2 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v0.0.1...v1.8.2) Updates `browserify` from 9.0.8 to 17.0.1 - [Release notes](https://github.com/browserify/browserify/releases) - [Changelog](https://github.com/browserify/browserify/blob/master/changelog.markdown) - [Commits](browserify/browserify@9.0.8...v17.0.1) Removes `shelljs` Updates `jshint` from 2.11.0 to 2.13.6 - [Release notes](https://github.com/jshint/jshint/releases) - [Changelog](https://github.com/jshint/jshint/blob/main/CHANGELOG.md) - [Commits](jshint/jshint@2.11.0...2.13.6) --- updated-dependencies: - dependency-name: async dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: body-parser dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: jsonwebtoken dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: passport-jwt dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: passport dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: mithril dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: tough-cookie dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: ajv dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ansi-regex dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: base64-url dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express-session dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: bl dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: docker dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: moment dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: emailjs dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: debug dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie-parser dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: elliptic dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: watchify dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: json-schema dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jsprim dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: mysql dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ueberdb2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: shell-quote dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: shelljs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jshint dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 28 updates in the / directory:
2.6.3
2.6.4
1.12.4
1.20.3
5.0.5
9.0.2
3.0.1
4.0.1
0.2.2
0.6.0
4.12.3
4.20.0
0.1.34
1.1.7
6.12.0
6.12.6
3.0.0
3.0.1
1.2.1
removed
1.11.1
1.18.1
0.4.2
removed
0.2.14
1.0.0
4.0.4
4.2.3
2.24.0
2.30.1
0.3.16
4.0.3
0.1.2
0.7.2
1.3.4
1.4.7
4.20.0
4.21.2
0.3.8
2.3.3
2.6.2
4.0.0
0.2.3
0.4.0
1.4.1
1.4.2
2.6.1
removed
0.3.8
5.0.6
0.0.1
1.8.2
9.0.8
17.0.1
0.3.0
removed
2.11.0
2.13.6
Updates
async
from 2.6.3 to 2.6.4Changelog
Sourced from async's changelog.
Commits
c6bdaca
Version 2.6.48870da9
Update built files4df6754
update changelog8f7f903
Fix prototype pollution vulnerability (#1828)Maintainer changes
This version was pushed to npm by hargasinski, a new releaser for async since your current version.
Updates
body-parser
from 1.12.4 to 1.20.3Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
1752951
1.20.339744cf
chore: linter (#534)b2695c4
Merge commit from forkade0f3f
add scorecard to readme (#531)99a1bd6
deps: [email protected] (#521)9478591
fix: pin to [email protected]83db46a
ci: fix errors in ci github action for node 8 and 9 (#523)9d4e212
chore: add support for OSSF scorecard reporting (#522)ee91374
1.20.2368a93a
Fix strict json error message on Node.js 19+Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
jsonwebtoken
from 5.0.5 to 9.0.2Changelog
Sourced from jsonwebtoken's changelog.
... (truncated)
Commits
bc28861
Release 9.0.2 (#935)96b8906
refactor: use specific lodash packages (#933)ed35062
security: Updating semver to 7.5.4 to resolve CVE-2022-25883 (#932)84539b2
Updating package version to 9.0.1 (#920)a99fd4b
fix(stubs): allow decode method to be stubbed (#876)e1fa9dc
Merge pull request from GHSA-8cf7-32gw-wr335eaedbf
chore(ci): remove github test actions job (#861)cd4163e
chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)ecdf6cc
fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...8345030
fix(sign&verify)!: Remove defaultnone
support fromsign
andverify
met...Maintainer changes
This version was pushed to npm by charlesrea, a new releaser for jsonwebtoken since your current version.
Updates
passport-jwt
from 3.0.1 to 4.0.1Commits
fed94fa
4.0.1 releasecfb5566
Merge pull request #248 from mikenicholson/update-minmatch8e4ad5b
Address minmatch vulnerabilitye9cf2ce
Merge pull request #247 from mikenicholson/jsonwebtoken-9bfbc6cc
Update jsonwebtoken to 9.0.0a49b43e
Update minimist due to prototype pollution vulnerability in previous versiona5137c6
Merge pull request #192 from markhoney/patch-1ea824cd
Update jsonwebtoken and run npm audit fix8e57eec
Remove older node versions shiping npm without support for "ci"3ab9305
Add CI workflow in GitHub ActionsUpdates
lodash
from 4.17.15 to 3.10.1Commits
dfbd78f
Bump to v3.10.1.e132e87
Rebuild lodash and docs.bb78c0e
Provide correctargsCount
hint tocustomizer
functions of clone methods.1a77202
Documentation (includes
):value
->target
. [ci skip]230f901
Use strict equality checks forbaseIndexOf
comparisons.fbc7c28
Cleanup Safari 8 bug note inisFunction
. [ci skip]5d88cb7
Code formatting nit for coercing to strings.caae7a5
EnsuregetFuncName
returns a string.816f37b
MovegetData
function guard to `isLaziable.a2dd717
Let mozilla manage their i18n. [ci skip]Updates
passport
from 0.2.2 to 0.6.0Changelog
Sourced from passport's changelog.
... (truncated)
Commits
c33067b
0.6.03052bb4
Update changelog.42630cb
Merge pull request #900 from jaredhanson/fix-fixation8dd79fe
Use utils-merge rather than Object.assign for compatibility.4f6bd5b
Change keepSessionData to keepSessionData.46756e5
Silence verbose logging.987b191
Add tests.f8a175f
Add tests.29a90d6
No need to guard callback existence.bfba8a1
Add tests.Updates
express
from 4.12.3 to 4.20.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
21df421
4.20.04c9ddc1
feat: upgrade to [email protected]9ebe5d5
feat: upgrade to [email protected] (#5928)ec4a01b
feat: upgrade to [email protected] (#5926)54271f6
fix: don't render redirect values in anchor href125bb74
[email protected] (#5902)2a980ad
[email protected] (#5781)a3e7e05
docs: specify new instructions forquestion
anddiscuss
c5addb9
deps: [email protected] (#5603)e35380a
docs: add@IamLizu
to the triage team (#5836)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express since your current version.
Updates
mithril
from 0.1.34 to 1.1.7Release notes
Sourced from mithril's releases.
... (truncated)
Changelog
Sourced from mithril's changelog.
... (truncated)
Commits
35ab329
v1.1.78d7ff39
Add a package fix already included in v256ad8d6
Merge v1_1_x into master-v1_1_x4f3ddc1
Preparing for releaseb2b4800
Prevent prototype pollution while parsing query strings on V1 (#2523)93c84a5
[docs] typod13a61a
[docs] clarify the component/RouteResolver distinctionc335aa7
docs: latest site updates (#2126)6fb77b7
docs: update with latest fixes (#2116)8d30578
test: inline iframe.js so ospec doesn't try to run itMaintainer changes
This version was pushed to npm by isiahmeadows, a new releaser for mithril since your current version.
Updates
tough-cookie
from 2.5.0 to 0.12.1Commits
03a1bad
0.12.1d321a2d
Rename repository to tough-cookie37ecb0f
0.12.063d1d5e
Merge pull request #15 from goinstant/stash/sync-apid2a30fb
Docs for Sync APIe9c37a3
Cannot use Sync API on Async store1735855
Sync APIc13b08a
Update .jshintrc1975977
0.11.04810bbb
Merge pull request #14 from lalitkapoor/GH-5Updates
ajv
from 6.12.0 to 6.12.6Release notes
Sourced from ajv's releases.
Commits
fe59143
6.12.6d580d3e
Merge pull request #1298 from ajv-validator/fix-urlfd36389
fix: regular expression for "url" format490e34c
docs: link to v7-beta branch9cd93a1
docs: note about v7 in readme877d286
Merge pull request #1262 from b4h0-c4t/refactor-opt-object-typef1c8e45
6.12.5764035e
Merge branch 'ChALkeR-chalker/fix-comma'3798160
Merge branch 'chalker/fix-comma' of git://github.com/ChALkeR/ajv into ChALkeR...a3c7eba
Merge branch 'refactor-opt-object-type' of github.com:b4h0-c4t/ajv into refac...Updates
ansi-regex
from 3.0.0 to 3.0.1Commits
f545bdb
3.0.1c57d4c2
fix a few old XO issues for backport419250f
Fix potential ReDoS (#37)Removes
base64-url
Updates
express-session
from 1.11.1 to 1.18.1Release notes
Sourced from express-session's releases.
... (truncated)
Description has been truncated