From 729bc5f3ca3604e8ba1322753b17b2e52d4642cd Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 21 Mar 2024 14:14:57 -0700
Subject: [PATCH] Bump the npm_and_yarn group across 2 directories with 2
updates (#883)
Bumps the npm_and_yarn group with 2 updates in the
/src/Spd.Presentation.Licensing/ClientApp directory:
[axios](https://github.com/axios/axios) and
[webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware).
Bumps the npm_and_yarn group with 1 update in the
/src/Spd.Presentation.Screening/ClientApp directory:
[webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware).
Updates `axios` from 1.6.7 to 1.6.8
Release notes
Sourced from axios's
releases.
Release v1.6.8
Release notes:
Bug Fixes
- AxiosHeaders: fix AxiosHeaders conversion to an
object during config merging (#6243)
(2656612)
- import: use named export for EventEmitter; (7320430)
- vulnerability: update follow-redirects to 1.15.6
(#6300)
(8786e0f)
Contributors to this release
Changelog
Sourced from axios's
changelog.
1.6.8
(2024-03-15)
Bug Fixes
- AxiosHeaders: fix AxiosHeaders conversion to an
object during config merging (#6243)
(2656612)
- import: use named export for EventEmitter; (7320430)
- vulnerability: update follow-redirects to 1.15.6
(#6300)
(8786e0f)
Contributors to this release
Commits
ab3f0f9
chore(release): v1.6.8 (#6303)
2656612
fix(AxiosHeaders): fix AxiosHeaders conversion to an object during
config mer...
7320430
fix(import): use named export for EventEmitter;
8786e0f
fix(vulnerability): update follow-redirects to 1.15.6 (#6300)
d844227
chore: update and bump deps (#6238)
caa0625
docs: update README responseEncoding types (#6194)
41c4584
docs: Update README.md to point to current axios version in CDN links
(#6196)
bf6974f
chore(ci): add npm tag action; (#6231)
- See full diff in compare
view
Updates `webpack-dev-middleware` from 5.3.3 to 5.3.4
Release notes
Sourced from webpack-dev-middleware's
releases.
v5.3.4
5.3.4
(2024-03-20)
Bug Fixes
- security: do not allow to read files above (#1779)
(189c4ac)
Changelog
Sourced from webpack-dev-middleware's
changelog.
5.3.4
(2024-03-20)
Bug Fixes
- security: do not allow to read files above (#1779)
(189c4ac)
Commits
Updates `webpack-dev-middleware` from 5.3.3 to 5.3.4
Release notes
Sourced from webpack-dev-middleware's
releases.
v5.3.4
5.3.4
(2024-03-20)
Bug Fixes
- security: do not allow to read files above (#1779)
(189c4ac)
Changelog
Sourced from webpack-dev-middleware's
changelog.
5.3.4
(2024-03-20)
Bug Fixes
- security: do not allow to read files above (#1779)
(189c4ac)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore ` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/bcgov-c/PSSG-SPDBT/network/alerts).
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
.../ClientApp/package-lock.json | 14 +++++++-------
.../ClientApp/package-lock.json | 6 +++---
2 files changed, 10 insertions(+), 10 deletions(-)
diff --git a/src/Spd.Presentation.Licensing/ClientApp/package-lock.json b/src/Spd.Presentation.Licensing/ClientApp/package-lock.json
index c08b01147..79318f1d8 100644
--- a/src/Spd.Presentation.Licensing/ClientApp/package-lock.json
+++ b/src/Spd.Presentation.Licensing/ClientApp/package-lock.json
@@ -6473,12 +6473,12 @@
}
},
"node_modules/axios": {
- "version": "1.6.7",
- "resolved": "https://registry.npmjs.org/axios/-/axios-1.6.7.tgz",
- "integrity": "sha512-/hDJGff6/c7u0hDkvkGxR/oy6CbCs8ziCsC7SqmhjfozqiJGc8Z11wrv9z9lYfY4K8l+H9TpjcMDX0xOZmx+RA==",
+ "version": "1.6.8",
+ "resolved": "https://registry.npmjs.org/axios/-/axios-1.6.8.tgz",
+ "integrity": "sha512-v/ZHtJDU39mDpyBoFVkETcd/uNdxrWRrg3bKpOKzXFA6Bvqopts6ALSMU3y6ijYxbw2B+wPrIv46egTzJXCLGQ==",
"dev": true,
"dependencies": {
- "follow-redirects": "^1.15.4",
+ "follow-redirects": "^1.15.6",
"form-data": "^4.0.0",
"proxy-from-env": "^1.1.0"
}
@@ -15643,9 +15643,9 @@
}
},
"node_modules/webpack-dev-server/node_modules/webpack-dev-middleware": {
- "version": "5.3.3",
- "resolved": "https://registry.npmjs.org/webpack-dev-middleware/-/webpack-dev-middleware-5.3.3.tgz",
- "integrity": "sha512-hj5CYrY0bZLB+eTO+x/j67Pkrquiy7kWepMHmUMoPsmcUaeEnQJqFzHJOyxgWlq746/wUuA64p9ta34Kyb01pA==",
+ "version": "5.3.4",
+ "resolved": "https://registry.npmjs.org/webpack-dev-middleware/-/webpack-dev-middleware-5.3.4.tgz",
+ "integrity": "sha512-BVdTqhhs+0IfoeAf7EoH5WE+exCmqGerHfDM0IL096Px60Tq2Mn9MAbnaGUe6HiMa41KMCYF19gyzZmBcq/o4Q==",
"dev": true,
"dependencies": {
"colorette": "^2.0.10",
diff --git a/src/Spd.Presentation.Screening/ClientApp/package-lock.json b/src/Spd.Presentation.Screening/ClientApp/package-lock.json
index 33fffbd27..aa0b38c45 100644
--- a/src/Spd.Presentation.Screening/ClientApp/package-lock.json
+++ b/src/Spd.Presentation.Screening/ClientApp/package-lock.json
@@ -17281,9 +17281,9 @@
}
},
"node_modules/webpack-dev-server/node_modules/webpack-dev-middleware": {
- "version": "5.3.3",
- "resolved": "https://registry.npmjs.org/webpack-dev-middleware/-/webpack-dev-middleware-5.3.3.tgz",
- "integrity": "sha512-hj5CYrY0bZLB+eTO+x/j67Pkrquiy7kWepMHmUMoPsmcUaeEnQJqFzHJOyxgWlq746/wUuA64p9ta34Kyb01pA==",
+ "version": "5.3.4",
+ "resolved": "https://registry.npmjs.org/webpack-dev-middleware/-/webpack-dev-middleware-5.3.4.tgz",
+ "integrity": "sha512-BVdTqhhs+0IfoeAf7EoH5WE+exCmqGerHfDM0IL096Px60Tq2Mn9MAbnaGUe6HiMa41KMCYF19gyzZmBcq/o4Q==",
"dev": true,
"dependencies": {
"colorette": "^2.0.10",