Bump the npm_and_yarn group across 1 directory with 27 updates#9
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
Bump the npm_and_yarn group across 1 directory with 27 updates#9dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the npm_and_yarn group with 24 updates in the / directory: | Package | From | To | | --- | --- | --- | | [express](https://github.com/expressjs/express) | `4.17.2` | `4.19.2` | | [got](https://github.com/sindresorhus/got) | `11.8.2` | `11.8.5` | | [liquidjs](https://github.com/harttle/liquidjs) | `9.22.1` | `10.0.0` | | [next](https://github.com/vercel/next.js) | `11.1.4` | `13.5.1` | | [semver](https://github.com/npm/node-semver) | `7.3.5` | `7.5.2` | | [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core) | `1.6.0` | `1.9.1` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.16.10` | `7.24.1` | | [@sideway/formula](https://github.com/sideway/formula) | `3.0.0` | `3.0.1` | | [axios](https://github.com/axios/axios) | `0.21.4` | `1.6.8` | | [jest-puppeteer](https://github.com/argos-ci/jest-puppeteer/tree/HEAD/packages/jest-puppeteer) | `5.0.4` | `10.0.1` | | [jest-environment-puppeteer](https://github.com/argos-ci/jest-puppeteer/tree/HEAD/packages/jest-environment-puppeteer) | `5.0.4` | `10.0.1` | | [start-server-and-test](https://github.com/bahmutov/start-server-and-test) | `1.14.0` | `2.0.3` | | [qs](https://github.com/ljharb/qs) | `6.9.3` | `6.11.0` | | [formidable](https://github.com/node-formidable/formidable) | `2.0.1` | `2.1.2` | | [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.1.0` | `4.1.1` | | [jpeg-js](https://github.com/eugeneware/jpeg-js) | `0.4.2` | `0.4.4` | | [@jimp/jpeg](https://github.com/jimp-dev/jimp) | `0.16.1` | `0.16.13` | | [json5](https://github.com/json5/json5) | `1.0.1` | `1.0.2` | | [jszip](https://github.com/Stuk/jszip) | `3.7.1` | `3.10.1` | | [async](https://github.com/caolan/async) | `2.6.3` | `2.6.4` | | [tough-cookie](https://github.com/salesforce/tough-cookie) | `4.0.0` | `4.1.3` | | [xml2js](https://github.com/Leonidas-from-XIV/node-xml2js) | `0.4.23` | `0.5.0` | | [rss-parser](https://github.com/bobby-brennan/rss-parser) | `3.12.0` | `3.13.0` | | [parse-bmfont-xml](https://github.com/mattdesl/parse-bmfont-xml) | `1.1.4` | `1.1.6` | Updates `express` from 4.17.2 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.17.2...4.19.2) Updates `got` from 11.8.2 to 11.8.5 - [Release notes](https://github.com/sindresorhus/got/releases) - [Commits](sindresorhus/got@v11.8.2...v11.8.5) Updates `liquidjs` from 9.22.1 to 10.0.0 - [Release notes](https://github.com/harttle/liquidjs/releases) - [Changelog](https://github.com/harttle/liquidjs/blob/master/CHANGELOG.md) - [Commits](harttle/liquidjs@v9.22.1...v10.0.0) Updates `next` from 11.1.4 to 13.5.1 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v11.1.4...v13.5.1) Updates `semver` from 7.3.5 to 7.5.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.5...v7.5.2) Updates `@actions/core` from 1.6.0 to 1.9.1 - [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md) - [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core) Updates `postcss` from 8.4.6 to 8.4.14 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.6...8.4.14) Updates `@babel/traverse` from 7.16.10 to 7.24.1 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.1/packages/babel-traverse) Updates `@sideway/formula` from 3.0.0 to 3.0.1 - [Commits](hapijs/formula@v3.0.0...v3.0.1) Updates `axios` from 0.21.4 to 1.6.8 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.21.4...v1.6.8) Updates `jest-puppeteer` from 5.0.4 to 10.0.1 - [Release notes](https://github.com/argos-ci/jest-puppeteer/releases) - [Changelog](https://github.com/argos-ci/jest-puppeteer/blob/main/packages/jest-puppeteer/CHANGELOG.md) - [Commits](https://github.com/argos-ci/jest-puppeteer/commits/v10.0.1/packages/jest-puppeteer) Updates `jest-environment-puppeteer` from 5.0.4 to 10.0.1 - [Release notes](https://github.com/argos-ci/jest-puppeteer/releases) - [Changelog](https://github.com/argos-ci/jest-puppeteer/blob/main/packages/jest-environment-puppeteer/CHANGELOG.md) - [Commits](https://github.com/argos-ci/jest-puppeteer/commits/v10.0.1/packages/jest-environment-puppeteer) Updates `start-server-and-test` from 1.14.0 to 2.0.3 - [Release notes](https://github.com/bahmutov/start-server-and-test/releases) - [Commits](bahmutov/start-server-and-test@v1.14.0...v2.0.3) Updates `follow-redirects` from 1.14.8 to 1.15.6 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.14.8...v1.15.6) Updates `qs` from 6.9.3 to 6.11.0 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.9.3...v6.11.0) Updates `formidable` from 2.0.1 to 2.1.2 - [Release notes](https://github.com/node-formidable/formidable/releases) - [Changelog](https://github.com/node-formidable/formidable/blob/master/CHANGELOG.md) - [Commits](https://github.com/node-formidable/formidable/commits) Updates `http-cache-semantics` from 4.1.0 to 4.1.1 - [Commits](kornelski/http-cache-semantics@v4.1.0...v4.1.1) Updates `jpeg-js` from 0.4.2 to 0.4.4 - [Release notes](https://github.com/eugeneware/jpeg-js/releases) - [Commits](jpeg-js/jpeg-js@v0.4.2...v0.4.4) Updates `@jimp/jpeg` from 0.16.1 to 0.16.13 - [Release notes](https://github.com/jimp-dev/jimp/releases) - [Changelog](https://github.com/jimp-dev/jimp/blob/main/CHANGELOG.md) - [Commits](jimp-dev/jimp@v0.16.1...v0.16.13) Updates `json5` from 1.0.1 to 1.0.2 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v1.0.1...v1.0.2) Updates `jszip` from 3.7.1 to 3.10.1 - [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md) - [Commits](Stuk/jszip@v3.7.1...v3.10.1) Updates `loader-utils` from 1.2.3 to 1.4.0 - [Release notes](https://github.com/webpack/loader-utils/releases) - [Changelog](https://github.com/webpack/loader-utils/blob/master/CHANGELOG.md) - [Commits](webpack/loader-utils@v1.2.3...v1.4.0) Updates `async` from 2.6.3 to 2.6.4 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md) - [Commits](caolan/async@v2.6.3...v2.6.4) Updates `tough-cookie` from 4.0.0 to 4.1.3 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v4.0.0...v4.1.3) Updates `xml2js` from 0.4.23 to 0.5.0 - [Commits](https://github.com/Leonidas-from-XIV/node-xml2js/commits/0.5.0) Updates `rss-parser` from 3.12.0 to 3.13.0 - [Commits](rbren/rss-parser@v3.12.0...v3.13.0) Updates `parse-bmfont-xml` from 1.1.4 to 1.1.6 - [Commits](mattdesl/parse-bmfont-xml@v1.1.4...v1.1.6) --- updated-dependencies: - dependency-name: express dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: got dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: liquidjs dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: next dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: semver dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: "@actions/core" dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: postcss dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: "@sideway/formula" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: axios dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jest-puppeteer dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: jest-environment-puppeteer dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: start-server-and-test dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: formidable dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: http-cache-semantics dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jpeg-js dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: "@jimp/jpeg" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: json5 dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jszip dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: loader-utils dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: async dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: xml2js dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: rss-parser dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: parse-bmfont-xml dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Apr 11, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 24 updates in the / directory:
4.17.24.19.211.8.211.8.59.22.110.0.011.1.413.5.17.3.57.5.21.6.01.9.17.16.107.24.13.0.03.0.10.21.41.6.85.0.410.0.15.0.410.0.11.14.02.0.36.9.36.11.02.0.12.1.24.1.04.1.10.4.20.4.40.16.10.16.131.0.11.0.23.7.13.10.12.6.32.6.44.0.04.1.30.4.230.5.03.12.03.13.01.1.41.1.6Updates
expressfrom 4.17.2 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
04bc6274.19.2da4d763Improved fix for open redirect allow list bypass4f0f6cc4.19.1a003cfaAllow passing non-strings to res.location with new encoding handling checks f...a1fa90ffixed un-edited version in history.md for 4.19.011f2b1dbuild: fix build due to inconsistent supertest behavior in older versions084e3654.19.00867302Prevent open redirect allow list bypass due to encodeurl567c9c6Add note on how to update docs for new release (#5541)69a4cf2deps: cookie@0.6.0Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates
gotfrom 11.8.2 to 11.8.5Release notes
Sourced from got's releases.
Commits
5e17bb711.8.5bce8ce7Backport 861ccd9ac2237df762a9e2beed7edd88c60782dc8ced192Fix build670eb0411.8.420f29feBackport #1543: Initialize globalResponse in case of ignored HTTPError (#2017)0da732f11.8.39463bb6Bump cacheable-request dependency (#1921)0e167b8HTTPError code set to 'HTTPError' #1711 (#1739)Updates
liquidjsfrom 9.22.1 to 10.0.0Release notes
Sourced from liquidjs's releases.
... (truncated)
Changelog
Sourced from liquidjs's changelog.
... (truncated)
Commits
9b9ef37chore(release): 10.0.0 [skip ci]5bbdc08chore(deps): bump minimatch from 3.0.4 to 3.1.21380ac9refactor: more consistent tags to make it easier to iterate over, #5244e1a30arefactor:_evalTokenrenamed toevalToken9299268refactor: Tag class support in registerTag()1f6ce7cperf: target Node.js 14 for cjs bundle (main entry)7eb6216refactor: changeownPropertyOnlydefault value totrueffefd91refactor: removetoThenableexportb115077refactor: remove use of internalContextclass inevalValueargumentbb58d3erefactor: delay creation ofoperatorsTrieand hide this implementationUpdates
nextfrom 11.1.4 to 13.5.1Commits
0c1c7f8v13.5.19744285v13.5.1-canary.144eba02improve publish-release (#55597)c652dc8v13.5.1-canary.0ffafad2v13.5.04a589edv13.4.20-canary.41deb81cffix styled-jsx alias (#55581)1a9b0f6improve internal error logging (#55582)0631549Fix react packages are not bundled for metadata routes (#55579)bad5365Update supported config options for Turbopack (#55556)Updates
semverfrom 7.3.5 to 7.5.2Release notes
Sourced from semver's releases.
... (truncated)
Changelog
Sourced from semver's changelog.
... (truncated)
Commits
e7b78dechore: release 7.5.258c791ffix: diff when detecting major change from prerelease (#566)5c8efbcfix: preserve build in raw after inc (#565)717534efix: better handling of whitespace (#564)2f738e9chore: bump@npmcli/template-ossfrom 4.14.1 to 4.15.1 (#558)aa016a6chore: release 7.5.1d30d25afix: show type on invalid semver error (#559)09c69e2chore: bump@npmcli/template-ossfrom 4.13.0 to 4.14.1 (#555)5b02ad7chore: release 7.5.0e219bb4fix: throw on bad version with correct error message (#552)Maintainer changes
This version was pushed to npm by npm-cli-ops, a new releaser for semver since your current version.
Updates
@actions/corefrom 1.6.0 to 1.9.1Changelog
Sourced from
@actions/core's changelog.Commits
Updates
postcssfrom 8.4.6 to 8.4.14Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
b7d1836Release 8.4.14 version57006b4Update dependencies2a97ab8Merge pull request #1744 from zardoy/patch-16447b55Merge pull request #1747 from ben-lau/maine36ed17Update plugins.md24f2efcUpdate depedencies9bda624Try to fix CI7cd8e27improve warnings count testing2295e28fix testsfc19f1bfix: print deprecation warning only when plugin is usedUpdates
@babel/traversefrom 7.16.10 to 7.24.1Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Changelog
Sourced from
@babel/traverse's changelog.