Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update node dependencies #1733

Merged
merged 1 commit into from
Apr 14, 2024
Merged

Conversation

ggrossetie
Copy link
Member

@ggrossetie ggrossetie commented Apr 2, 2024

This PR contains the following updates:

Package Type Update Change
@excalidraw/excalidraw dependencies patch 0.17.3 -> 0.17.5
@softwaretechnik/dbml-renderer dependencies patch 1.0.27 -> 1.0.30
node volta patch 18.20.0 -> 18.20.2
pino (source) dependencies minor 8.19.0 -> 8.20.0
vega-lite (source) dependencies minor 5.17.0 -> 5.18.0

Release Notes

excalidraw/excalidraw

v0.17.5

Compare Source

v0.17.4

Compare Source

softwaretechnik-berlin/dbml-renderer

v1.0.30

Compare Source

Updated dependencies.

No other changes.

v1.0.29

Compare Source

v1.0.28

Compare Source

This release brings more parsing resilience.

  • #​32 Support for qualified type names.
  • PR #​36 from @​pierresouchay addresses #​35, allowing SQL Functions used as indices for tables.
  • #​24 Handle spaces at the start of declarations, and comments in more places.
  • #​26 Handle enums qualified with a schema name.
  • #​28 Handle trailing spaces at the end of lines.
  • #​29 Handle types like decimal(1,2).
nodejs/node

v18.20.2

Compare Source

This is a security release.

Notable Changes
  • CVE-2024-27980 - Command injection via args parameter of child_process.spawn without shell option enabled on Windows
Commits

v18.20.1

Compare Source

This is a security release.

Notable Changes
  • CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High)
  • CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium)
  • llhttp version 9.2.1
  • undici version 5.28.4
Commits
pinojs/pino

v8.20.0

Compare Source

What's Changed
New Contributors

Full Changelog: pinojs/pino@v8.19.0...v8.20.0

vega/vega-lite

v5.18.0

Compare Source

Bug Fixes
Features
  • add explicit option to control how densities are resolved, change how densities are resolved by default (#​9172) (bf0b8d3)

Configuration

📅 Schedule: At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by Renovate Bot.

@ggrossetie ggrossetie added the 🔗 dependencies Pull requests that update a dependency file label Apr 2, 2024
@ggrossetie ggrossetie changed the title chore(deps): update dependency @softwaretechnik/dbml-renderer to v1.0.30 chore(deps): update node dependencies Apr 4, 2024
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch 3 times, most recently from a20c6b1 to c06a95a Compare April 10, 2024 02:12
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch from c06a95a to 9bd91cd Compare April 11, 2024 02:13
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch from 9bd91cd to 895e0bc Compare April 13, 2024 02:04
@ggrossetie ggrossetie merged commit 5bb986a into main Apr 14, 2024
2 checks passed
@ggrossetie ggrossetie deleted the renovate/node-dependencies branch April 14, 2024 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🔗 dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant