Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: bump the production-dependencies group with 6 updates #80

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 10, 2023

Bumps the production-dependencies group with 6 updates:

Package From To
axios 1.5.1 1.6.1
typeorm-extension 3.0.2 3.1.1
@vue/compat 3.3.4 3.3.8
swagger-ui 5.9.0 5.9.3
vue 3.3.4 3.3.8
vue-i18n 9.5.0 9.6.5

Updates axios from 1.5.1 to 1.6.1

Release notes

Sourced from axios's releases.

Release v1.6.1

Release notes:

Bug Fixes

  • formdata: fixed content-type header normalization for non-standard browser environments; (#6056) (dd465ab)
  • platform: fixed emulated browser detection in node.js environment; (#6055) (3dc8369)

Contributors to this release

Release v1.6.0

Release notes:

Bug Fixes

PRs

  • CVE 2023 45857 ( #6028 )

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

Contributors to this release

Changelog

Sourced from axios's changelog.

1.6.1 (2023-11-08)

Bug Fixes

  • formdata: fixed content-type header normalization for non-standard browser environments; (#6056) (dd465ab)
  • platform: fixed emulated browser detection in node.js environment; (#6055) (3dc8369)

Contributors to this release

1.6.0 (2023-10-26)

Bug Fixes

PRs

  • CVE 2023 45857 ( #6028 )

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

Contributors to this release

Commits
  • f6d2cf9 chore(ci): fix publish action content permission; (#6061)
  • a22f4b9 chore(release): v1.6.1 (#6060)
  • cb8bb2b chore(ci): Publish to NPM with provenance (#5835)
  • 37cbf92 chore(ci): added labeling and notification for published PRs; (#6059)
  • dd465ab fix(formdata): fixed content-type header normalization for non-standard brows...
  • 3dc8369 fix(platform): fixed emulated browser detection in node.js environment; (#6055)
  • f7adacd chore(release): v1.6.0 (#6031)
  • 9917e67 chore(ci): fix release-it arg; (#6032)
  • 96ee232 fix(CSRF): fixed CSRF vulnerability CVE-2023-45857 (#6028)
  • 7d45ab2 chore(tests): fixed tests to pass in node v19 and v20 with keep-alive enabl...
  • Additional commits viewable in compare view

Updates typeorm-extension from 3.0.2 to 3.1.1

Release notes

Sourced from typeorm-extension's releases.

v3.1.1

3.1.1 (2023-10-24)

Bug Fixes

  • multiple shebangs in cli entrypoint (c227c66)

v3.1.0

3.1.0 (2023-10-21)

Bug Fixes

  • deps: bump @​faker-js/faker from 8.0.2 to 8.2.0 (#734) (f3e5054)
  • deps: bump smob from 1.4.0 to 1.4.1 (#732) (fb71fae)

Features

  • async data-source exports (a2cdb9d)
Changelog

Sourced from typeorm-extension's changelog.

3.1.1 (2023-10-24)

Bug Fixes

  • multiple shebangs in cli entrypoint (c227c66)

3.1.0 (2023-10-21)

Bug Fixes

  • deps: bump @​faker-js/faker from 8.0.2 to 8.2.0 (#734) (f3e5054)
  • deps: bump smob from 1.4.0 to 1.4.1 (#732) (fb71fae)

Features

  • async data-source exports (a2cdb9d)
Commits

Updates @vue/compat from 3.3.4 to 3.3.8

Release notes

Sourced from @​vue/compat's releases.

v3.3.8

Please refer to CHANGELOG.md for details.

v3.3.7

Please refer to CHANGELOG.md for details.

v3.3.6

Please refer to CHANGELOG.md for details.

v3.3.5

Please refer to CHANGELOG.md for details.

Changelog

Sourced from @​vue/compat's changelog.

3.3.8 (2023-11-06)

Bug Fixes

  • compile-sfc: support Error type in defineProps (#5955) (a989345)
  • compiler-core: known global should be shadowed by local variables in expression rewrite (#9492) (a75d1c5), closes #9482
  • compiler-sfc: fix dynamic directive arguments usage check for slots (#9495) (b39fa1f), closes #9493
  • deps: update dependency @​vue/repl to ^2.6.2 (#9536) (5cef325)
  • deps: update dependency @​vue/repl to ^2.6.3 (#9540) (176d590)
  • hydration: fix tagName access eeror on comment/text node hydration mismatch (dd8a0cf), closes #9531
  • types: avoid exposing lru-cache types in generated dts (462aeb3), closes #9521
  • warn: avoid warning on empty children with Suspense (#3962) (405f345)

3.3.7 (2023-10-24)

Bug Fixes

  • compiler-sfc: avoid gen useCssVars when targeting SSR (#6979) (c568778), closes #6926
  • compiler-ssr: proper scope analysis for ssr vnode slot fallback (#7184) (e09c26b), closes #7095
  • correctly resolve types from relative paths on Windows (#9446) (089d36d), closes #8671
  • hmr: fix hmr error for hoisted children array in v-for (7334376), closes #6978 #7114
  • reactivity: assigning array.length while observing a symbol property (#7568) (e9e2778)
  • scheduler: ensure jobs are in the correct order (#7748) (a8f6638), closes #7576
  • ssr: fix hydration mismatch for disabled teleport at component root (#9399) (d8990fc), closes #6152
  • Suspense: calling hooks before the transition finishes (#9388) (00de3e6), closes #5844 #5952
  • transition/ssr: make transition appear work with SSR (#8859) (5ea8a8a), closes #6951
  • types: fix ComponentCustomProps augmentation (#9468) (7374e93), closes #8376
  • types: improve h overload to support union of string and component (#5432) (16ecb44), closes #5431

3.3.6 (2023-10-20)

Bug Fixes

  • compiler-sfc: model name conflict (#8798) (df81da8)
  • compiler-sfc: support asset paths containing spaces (#8752) (36c99a9)
  • compiler-ssr: fix missing scopeId on server-rendered TransitionGroup (#7557) (61c1357), closes #7554
  • compiler-ssr: fix ssr compile error for select with non-option children (#9442) (cdb2e72), closes #9440
  • runtime-core: delete stale slots which are present but undefined (#6484) (75b8722), closes #9109
  • runtime-core: fix error when using cssvars with disabled teleport (#7341) (8f0472c), closes #7342
  • teleport: ensure descendent component would be unmounted correctly (#6529) (4162311), closes #6347
  • types: support contenteditable="plaintext-only" (#8796) (26ca89e)

... (truncated)

Commits
  • bc58469 release: v3.3.8
  • 2f8c769 chore: delete unrelated test case
  • dd8a0cf fix(hydration): fix tagName access eeror on comment/text node hydration mismatch
  • 405f345 fix(warn): avoid warning on empty children with Suspense (#3962)
  • b39fa1f fix(compiler-sfc): fix dynamic directive arguments usage check for slots (#9495)
  • 462aeb3 fix(types): avoid exposing lru-cache types in generated dts
  • 32bdc5d chore: typo [skip ci]
  • 176d590 fix(deps): update dependency @​vue/repl to ^2.6.3 (#9540)
  • 4a88b71 chore: add maintenance handbook
  • 5cef325 fix(deps): update dependency @​vue/repl to ^2.6.2 (#9536)
  • Additional commits viewable in compare view

Updates swagger-ui from 5.9.0 to 5.9.3

Release notes

Sourced from swagger-ui's releases.

Swagger UI v5.9.3 Released!

5.9.3 (2023-11-09)

Bug Fixes

  • a11y: remove redundant aria-label from accordion button (#9361) (2a4afd9), closes #9353
  • response-body: show download button both for non-empty Blob and string responses (#9343) (f803fa3), closes #9298

Swagger UI v5.9.2 Released!

5.9.2 (2023-11-08)

Bug Fixes

  • swagger-client: fix handling cycles in OpenAPI 3.1.0 definitions (#9364) (a187bfb), closes #9337

Swagger UI v5.9.1 Released!

5.9.1 (2023-10-25)

Bug Fixes

  • build: add support for remix.run bundler (#9327) (c7d6214)
Commits
  • 343b0ab chore(release): cut the v5.9.3 release
  • f803fa3 fix(response-body): show download button both for non-empty Blob and string r...
  • 2a4afd9 fix(a11y): remove redundant aria-label from accordion button (#9361)
  • 987702d chore(deps-dev): bump @​babel/plugin-transform-runtime (#9367)
  • d463a79 chore(deps-dev): bump cypress from 13.4.0 to 13.5.0 (#9369)
  • 73187d9 chore(deps-dev): bump @​babel/preset-react from 7.22.15 to 7.23.3 (#9368)
  • 84de63c chore(release): cut the v5.9.2 release
  • a187bfb fix(swagger-client): fix handling cycles in OpenAPI 3.1.0 definitions (#9364)
  • b9120fb chore(deps-dev): bump @​commitlint/config-conventional (#9339)
  • 979c52e chore(deps-dev): bump start-server-and-test from 2.0.1 to 2.0.2 (#9360)
  • Additional commits viewable in compare view

Updates vue from 3.3.4 to 3.3.8

Release notes

Sourced from vue's releases.

v3.3.8

Please refer to CHANGELOG.md for details.

v3.3.7

Please refer to CHANGELOG.md for details.

v3.3.6

Please refer to CHANGELOG.md for details.

v3.3.5

Please refer to CHANGELOG.md for details.

Changelog

Sourced from vue's changelog.

3.3.8 (2023-11-06)

Bug Fixes

  • compile-sfc: support Error type in defineProps (#5955) (a989345)
  • compiler-core: known global should be shadowed by local variables in expression rewrite (#9492) (a75d1c5), closes #9482
  • compiler-sfc: fix dynamic directive arguments usage check for slots (#9495) (b39fa1f), closes #9493
  • deps: update dependency @​vue/repl to ^2.6.2 (#9536) (5cef325)
  • deps: update dependency @​vue/repl to ^2.6.3 (#9540) (176d590)
  • hydration: fix tagName access eeror on comment/text node hydration mismatch (dd8a0cf), closes #9531
  • types: avoid exposing lru-cache types in generated dts (462aeb3), closes #9521
  • warn: avoid warning on empty children with Suspense (#3962) (405f345)

3.3.7 (2023-10-24)

Bug Fixes

  • compiler-sfc: avoid gen useCssVars when targeting SSR (#6979) (c568778), closes #6926
  • compiler-ssr: proper scope analysis for ssr vnode slot fallback (#7184) (e09c26b), closes #7095
  • correctly resolve types from relative paths on Windows (#9446) (089d36d), closes #8671
  • hmr: fix hmr error for hoisted children array in v-for (7334376), closes #6978 #7114
  • reactivity: assigning array.length while observing a symbol property (#7568) (e9e2778)
  • scheduler: ensure jobs are in the correct order (#7748) (a8f6638), closes #7576
  • ssr: fix hydration mismatch for disabled teleport at component root (#9399) (d8990fc), closes #6152
  • Suspense: calling hooks before the transition finishes (#9388) (00de3e6), closes #5844 #5952
  • transition/ssr: make transition appear work with SSR (#8859) (5ea8a8a), closes #6951
  • types: fix ComponentCustomProps augmentation (#9468) (7374e93), closes #8376
  • types: improve h overload to support union of string and component (#5432) (16ecb44), closes #5431

3.3.6 (2023-10-20)

Bug Fixes

  • compiler-sfc: model name conflict (#8798) (df81da8)
  • compiler-sfc: support asset paths containing spaces (#8752) (36c99a9)
  • compiler-ssr: fix missing scopeId on server-rendered TransitionGroup (#7557) (61c1357), closes #7554
  • compiler-ssr: fix ssr compile error for select with non-option children (#9442) (cdb2e72), closes #9440
  • runtime-core: delete stale slots which are present but undefined (#6484) (75b8722), closes #9109
  • runtime-core: fix error when using cssvars with disabled teleport (#7341) (8f0472c), closes #7342
  • teleport: ensure descendent component would be unmounted correctly (#6529) (4162311), closes #6347
  • types: support contenteditable="plaintext-only" (#8796) (26ca89e)

... (truncated)

Commits
  • bc58469 release: v3.3.8
  • 2f8c769 chore: delete unrelated test case
  • dd8a0cf fix(hydration): fix tagName access eeror on comment/text node hydration mismatch
  • 405f345 fix(warn): avoid warning on empty children with Suspense (#3962)
  • b39fa1f fix(compiler-sfc): fix dynamic directive arguments usage check for slots (#9495)
  • 462aeb3 fix(types): avoid exposing lru-cache types in generated dts
  • 32bdc5d chore: typo [skip ci]
  • 176d590 fix(deps): update dependency @​vue/repl to ^2.6.3 (#9540)
  • 4a88b71 chore: add maintenance handbook
  • 5cef325 fix(deps): update dependency @​vue/repl to ^2.6.2 (#9536)
  • Additional commits viewable in compare view

Updates vue-i18n from 9.5.0 to 9.6.5

Release notes

Sourced from vue-i18n's releases.

v9.6.5

What's Changed

🐛 Bug Fixes

New Contributors

Full Changelog: intlify/vue-i18n@v9.6.4...v9.6.5

v9.6.4

What's Changed

🐛 Bug Fixes

Full Changelog: intlify/vue-i18n@v9.6.3...v9.6.4

v9.6.3

What's Changed

🐛 Bug Fixes

New Contributors

Full Changelog: intlify/vue-i18n@v9.6.2...v9.6.3

v9.6.2

What's Changed

🐛 Bug Fixes

Full Changelog: intlify/vue-i18n@v9.6.1...v9.6.2

v9.6.1

What's Changed

🐛 Bug Fixes

... (truncated)

Changelog

Sourced from vue-i18n's changelog.

v9.6.5 (2023-11-04T01:42:38Z)

This changelog is generated by GitHub Releases

What's Changed

🐛 Bug Fixes

New Contributors

Full Changelog: intlify/vue-i18n@v9.6.4...v9.6.5

v9.6.4 (2023-11-02T04:44:53Z)

This changelog is generated by GitHub Releases

What's Changed

🐛 Bug Fixes

Full Changelog: intlify/vue-i18n@v9.6.3...v9.6.4

v9.6.3 (2023-11-02T04:05:31Z)

This changelog is generated by GitHub Releases

What's Changed

🐛 Bug Fixes

New Contributors

Full Changelog: intlify/vue-i18n@v9.6.2...v9.6.3

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will merge this PR once CI passes on it, as requested by @neferin12.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [axios](https://github.com/axios/axios) | `1.5.1` | `1.6.1` |
| [typeorm-extension](https://github.com/tada5hi/typeorm-extension) | `3.0.2` | `3.1.1` |
| [@vue/compat](https://github.com/vuejs/core) | `3.3.4` | `3.3.8` |
| [swagger-ui](https://github.com/swagger-api/swagger-ui) | `5.9.0` | `5.9.3` |
| [vue](https://github.com/vuejs/core) | `3.3.4` | `3.3.8` |
| [vue-i18n](https://github.com/intlify/vue-i18n-next/tree/HEAD/packages/vue-i18n) | `9.5.0` | `9.6.5` |


Updates `axios` from 1.5.1 to 1.6.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.5.1...v1.6.1)

Updates `typeorm-extension` from 3.0.2 to 3.1.1
- [Release notes](https://github.com/tada5hi/typeorm-extension/releases)
- [Changelog](https://github.com/tada5hi/typeorm-extension/blob/develop/CHANGELOG.md)
- [Commits](tada5hi/typeorm-extension@v3.0.2...v3.1.1)

Updates `@vue/compat` from 3.3.4 to 3.3.8
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.3.4...v3.3.8)

Updates `swagger-ui` from 5.9.0 to 5.9.3
- [Release notes](https://github.com/swagger-api/swagger-ui/releases)
- [Changelog](https://github.com/swagger-api/swagger-ui/blob/master/.releaserc)
- [Commits](swagger-api/swagger-ui@v5.9.0...v5.9.3)

Updates `vue` from 3.3.4 to 3.3.8
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.3.4...v3.3.8)

Updates `vue-i18n` from 9.5.0 to 9.6.5
- [Release notes](https://github.com/intlify/vue-i18n-next/releases)
- [Changelog](https://github.com/intlify/vue-i18n-next/blob/master/CHANGELOG.md)
- [Commits](https://github.com/intlify/vue-i18n-next/commits/v9.6.5/packages/vue-i18n)

---
updated-dependencies:
- dependency-name: axios
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: typeorm-extension
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@vue/compat"
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: swagger-ui
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: vue
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: vue-i18n
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Nov 10, 2023
@neferin12
Copy link
Member

@dependabot merge

@dependabot dependabot bot merged commit be94d20 into develop Nov 10, 2023
8 checks passed
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/production-dependencies-19cf85013c branch November 10, 2023 13:12
@neferin12
Copy link
Member

🎉 This PR is included in version timeclicker_client-v1.12.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

@neferin12
Copy link
Member

🎉 This issue has been resolved in version timeclicker_server-v1.8.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file released
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant