deps(deps): bump the production-dependencies group with 6 updates #11
+428
−270
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the production-dependencies group with 6 updates:
2.4.3
3.0.2
4.21.2
5.1.0
7.5.1
8.1.0
7.2.0
8.1.0
17.13.3
18.0.1
10.1.4
11.0.2
Updates
bcryptjs
from 2.4.3 to 3.0.2Release notes
Sourced from bcryptjs's releases.
Commits
28e5103
fix: Use upstream fix to emit interop helperse7055ca
fix: Separate ESM and UMD type definitions2a9bea9
Update publish workflowd5656b3
Add helper to check for password input lengthe09eb9a
Add note on using the ESM variant in the browser58333a1
Update types2e3b176
Merge lint and test workflowsec02e8a
Fix tests9db275f
Update legacy fallback to handle crypto dependencyac70ac5
Update lint workflow titleUpdates
express
from 4.21.2 to 5.1.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
cd7d439
5.1.04c4f3ea
fix(deps): serve-static@^2.2.0 (#6418)cb4c56e
fix(docs): remove@mertcanaltin
from Triagers (#6408)7b44e1d
ci: use full SHAs for github action versionseb6d125
deps: router@^2.2.0 (#6417)f1a2dc8
deps: type-is@^2.0.1 (#6420)6b51e8e
deps: body-parser@^2.2.0 (#6419)1f311c5
build(deps-dev): bump cookie-session from 2.0.0 to 2.1.0 (#6399)9e97144
feat(deps): finalhandler@2.1.0 (#6373)29d0980
build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 (#6397)Updates
express-rate-limit
from 7.5.1 to 8.1.0Release notes
Sourced from express-rate-limit's releases.
Commits
6061935
8.1.02f2ed4d
Add validation check for Forwarded header (#549)d0e7c85
chore(deps-dev): bump the all group across 1 directory with 5 updates (#554)66aa1b0
test: check for renamed Request in types (#543)658c201
Document windowMs limit for MemoryStore and warn on invalid values (#550)aa3b291
fix: include RateLimit-Reset header when resetSeconds is 0 (#553)1eca1a4
Update CI workflow to include pull_request triggerec8a6f9
chore: migrate biome config for current version207100e
chore(deps-dev): bump the all group with 4 updates (#548)471076d
chore(deps-dev): bump the all group with 4 updates (#547)Updates
helmet
from 7.2.0 to 8.1.0Changelog
Sourced from helmet's changelog.
Commits
57e1b39
8.1.0c8efbe3
Update changelog for 8.1.0 release3396804
Add 8.0.0 release date to changelog52dd8eb
Content-Security-Policy: better error when value should be quoted4af4777
Use built-in test runner (instead of Jest)ba10272
Organize importse0f1387
Update devDependencies to latest versions842393c
Check types duringnpm test
, run in parallel77fbe3a
Strict-Transport-Security: fix documentation for default max-age632e629
Update license year for 2025Updates
joi
from 17.13.3 to 18.0.1Commits
1b923c1
18.0.11ceea4e
Merge pull request #3087 from hapijs/fix/array-typesc8bee29
fix: proper types for more complex cases of array0ffadef
chore: run prettier on types55b0096
18.0.08ccad73
chore: add guid wrapper types6c9dead
Merge pull request #3082 from ben-walters/feature/fail-bracketed-uuidd8d8434
Applied suggestionsdec12ec
Added wrapper option to uuid function703c12c
chore: fix timeout warningUpdates
nano
from 10.1.4 to 11.0.2Release notes
Sourced from nano's releases.
Commits
3d754f8
11.0.2066fdb0
add customer headers to typescript definition8dcfdd7
11.0.1e20ffea
Capture error message, otherwise capture cause of HTTP failure (#358)26fb0e1
Use fetch instead of axios (#314)ac8f4d0
Bump axios from 1.10.0 to 1.11.0 (#354)2f648c8
asf.yaml format update as syntax was out-of-date (#353)255872f
update axios to v1.10.0 + audit fix (#351)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions