chore(deps): bump the npm_and_yarn group across 1 directory with 26 updates#1
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
chore(deps): bump the npm_and_yarn group across 1 directory with 26 updates#1dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
…pdates Bumps the npm_and_yarn group with 26 updates in the / directory: | Package | From | To | | --- | --- | --- | | [codecov](https://github.com/codecov/codecov-node) | `3.7.0` | `3.7.1` | | [rollup](https://github.com/rollup/rollup) | `2.18.0` | `2.79.2` | | [csvtojson](https://github.com/Keyang/node-csvtojson) | `2.0.10` | `2.0.11` | | [node-fetch](https://github.com/node-fetch/node-fetch) | `2.6.0` | `2.6.7` | | [tmp](https://github.com/raszi/node-tmp) | `0.2.1` | `0.2.4` | | [flat](https://github.com/hughsk/flat) | `5.0.0` | `5.0.1` | | [lodash](https://github.com/lodash/lodash) | `4.17.15` | `4.17.21` | | [object-path](https://github.com/mariocasciaro/object-path) | `0.11.4` | `0.11.8` | | [fast-csv](https://github.com/C2FO/fast-csv/tree/HEAD/packages/fast-csv) | `4.3.0` | `4.3.6` | | [jsondiffpatch](https://github.com/benjamine/jsondiffpatch) | `0.4.1` | `0.7.2` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.10.3` | `7.28.5` | | [@npmcli/git](https://github.com/npm/git) | `2.0.2` | `2.1.0` | | [ajv](https://github.com/ajv-validator/ajv) | `6.12.2` | `6.12.6` | | [bl](https://github.com/rvagg/bl) | `4.0.2` | `4.1.0` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.7.6` | `4.7.8` | | [ini](https://github.com/npm/ini) | `1.3.5` | `1.3.8` | | [jszip](https://github.com/Stuk/jszip) | `3.5.0` | `3.10.1` | | [node-notifier](https://github.com/mikaelbr/node-notifier) | `7.0.1` | `7.0.2` | | [npm-user-validate](https://github.com/npm/npm-user-validate) | `1.0.0` | `1.0.1` | | [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `1.8.0` | `1.9.0` | | [prismjs](https://github.com/PrismJS/prism) | `1.20.0` | `1.30.0` | | [qs](https://github.com/ljharb/qs) | `6.5.2` | `6.5.3` | | [set-getter](https://github.com/doowb/set-getter) | `0.1.0` | `0.1.1` | | [tmpl](https://github.com/daaku/nodejs-tmpl) | `1.0.4` | `1.0.5` | | [ws](https://github.com/websockets/ws) | `7.3.0` | `7.5.10` | Updates `codecov` from 3.7.0 to 3.7.1 - [Release notes](https://github.com/codecov/codecov-node/releases) - [Changelog](https://github.com/codecov/codecov-node/blob/master/CHANGELOG.md) - [Commits](codecov/codecov-node@v3.7.0...v3.7.1) Updates `rollup` from 2.18.0 to 2.79.2 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG-2.md) - [Commits](rollup/rollup@v2.18.0...v2.79.2) Updates `csvtojson` from 2.0.10 to 2.0.11 - [Release notes](https://github.com/Keyang/node-csvtojson/releases) - [Commits](Keyang/node-csvtojson@v2.0.10...v2.0.11) Updates `node-fetch` from 2.6.0 to 2.6.7 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v2.6.0...v2.6.7) Updates `tmp` from 0.2.1 to 0.2.4 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](raszi/node-tmp@v0.2.1...v0.2.4) Updates `flat` from 5.0.0 to 5.0.1 - [Release notes](https://github.com/hughsk/flat/releases) - [Commits](hughsk/flat@5.0.0...5.0.1) Updates `lodash` from 4.17.15 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.15...4.17.21) Updates `object-path` from 0.11.4 to 0.11.8 - [Commits](https://github.com/mariocasciaro/object-path/commits/v0.11.8) Updates `fast-csv` from 4.3.0 to 4.3.6 - [Release notes](https://github.com/C2FO/fast-csv/releases) - [Changelog](https://github.com/C2FO/fast-csv/blob/main/packages/fast-csv/CHANGELOG.md) - [Commits](https://github.com/C2FO/fast-csv/commits/v4.3.6/packages/fast-csv) Updates `jsondiffpatch` from 0.4.1 to 0.7.2 - [Release notes](https://github.com/benjamine/jsondiffpatch/releases) - [Commits](https://github.com/benjamine/jsondiffpatch/commits) Updates `@babel/traverse` from 7.10.3 to 7.28.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.28.5/packages/babel-traverse) Updates `@npmcli/git` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/npm/git/releases) - [Changelog](https://github.com/npm/git/blob/main/CHANGELOG.md) - [Commits](npm/git@v2.0.2...v2.1.0) Updates `ajv` from 6.12.2 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.12.2...v6.12.6) Updates `bl` from 4.0.2 to 4.1.0 - [Release notes](https://github.com/rvagg/bl/releases) - [Changelog](https://github.com/rvagg/bl/blob/master/CHANGELOG.md) - [Commits](rvagg/bl@v4.0.2...v4.1.0) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `handlebars` from 4.7.6 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.7.6...v4.7.8) Updates `ini` from 1.3.5 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.5...v1.3.8) Updates `jszip` from 3.5.0 to 3.10.1 - [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md) - [Commits](Stuk/jszip@v3.5.0...v3.10.1) Updates `node-notifier` from 7.0.1 to 7.0.2 - [Changelog](https://github.com/mikaelbr/node-notifier/blob/master/CHANGELOG.md) - [Commits](mikaelbr/node-notifier@v7.0.1...v7.0.2) Updates `npm-user-validate` from 1.0.0 to 1.0.1 - [Release notes](https://github.com/npm/npm-user-validate/releases) - [Changelog](https://github.com/npm/npm-user-validate/blob/main/CHANGELOG.md) - [Commits](npm/npm-user-validate@v1.0.0...v1.0.1) Updates `path-to-regexp` from 1.8.0 to 1.9.0 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v1.8.0...v1.9.0) Updates `prismjs` from 1.20.0 to 1.30.0 - [Release notes](https://github.com/PrismJS/prism/releases) - [Changelog](https://github.com/PrismJS/prism/blob/v2/CHANGELOG.md) - [Commits](PrismJS/prism@v1.20.0...v1.30.0) Updates `qs` from 6.5.2 to 6.5.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.2...v6.5.3) Updates `set-getter` from 0.1.0 to 0.1.1 - [Commits](https://github.com/doowb/set-getter/commits/0.1.1) Updates `tmpl` from 1.0.4 to 1.0.5 - [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5) Updates `ws` from 7.3.0 to 7.5.10 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@7.3.0...7.5.10) --- updated-dependencies: - dependency-name: codecov dependency-version: 3.7.1 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.79.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: csvtojson dependency-version: 2.0.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-version: 2.6.7 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tmp dependency-version: 0.2.4 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: flat dependency-version: 5.0.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.21 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: object-path dependency-version: 0.11.8 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: fast-csv dependency-version: 4.3.6 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: jsondiffpatch dependency-version: 0.7.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-version: 7.28.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@npmcli/git" dependency-version: 2.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ajv dependency-version: 6.12.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: bl dependency-version: 4.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-version: 0.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-version: 4.7.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-version: 1.3.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jszip dependency-version: 3.10.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: node-notifier dependency-version: 7.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: npm-user-validate dependency-version: 1.0.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-to-regexp dependency-version: 1.9.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: prismjs dependency-version: 1.30.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-version: 6.5.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: set-getter dependency-version: 0.1.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmpl dependency-version: 1.0.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 7.5.10 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 26 updates in the / directory:
3.7.03.7.12.18.02.79.22.0.102.0.112.6.02.6.70.2.10.2.45.0.05.0.14.17.154.17.210.11.40.11.84.3.04.3.60.4.10.7.27.10.37.28.52.0.22.1.06.12.26.12.64.0.24.1.00.2.00.2.24.7.64.7.81.3.51.3.83.5.03.10.17.0.17.0.21.0.01.0.11.8.01.9.01.20.01.30.06.5.26.5.30.1.00.1.11.0.41.0.57.3.07.5.10Updates
codecovfrom 3.7.0 to 3.7.1Changelog
Sourced from codecov's changelog.
Commits
29dd5b63.7.1c0711c6Switch from execSync to execFileSync (#180)5f6cc62Bump lodash from 4.17.15 to 4.17.19 (#183)0c4d7f3Merge pull request #182 from codecov/update-readme-badgescc5e121Update depstat image and urlsb44b44eUpdate readme with 400 error info (#181)bb79335V3.7.0 (#179)Updates
rollupfrom 2.18.0 to 2.79.2Release notes
Sourced from rollup's releases.
Changelog
Sourced from rollup's changelog.
... (truncated)
Commits
c9bd03d2.79.248aef33fix: resolve DOM Clobbering CVE-2024-43788 (backport to v2) (#5677)69ff4182.79.104dce1bUpdate changelog159137efix: typo docs and contributors link in CONTRIBUTING.md (#4639)e1392b3Update type definition of resolveId (#4641)7836357Improve performance of chunk naming collision check (#4643)71d20c9Reduce permissions for repl-artefacts.yml workflow (#4630)8193ea5Adapt workflow to use Node 14 sub-version to work with branch protection8477f8f2.79.0Updates
csvtojsonfrom 2.0.10 to 2.0.11Release notes
Sourced from csvtojson's releases.
Commits
89a9a36Updated package to 2.0.113e7999dMerge pull request #469 from Keyang/update-librarye5b60c8fix: removed unnessesary lines7264211feat: updated .gitignore99616e4feat: updated deprecated code3fb3a71feat: updated deprecated code1535bcfMerge pull request #406 from abramsimon/abramsimon/add-test-coverage-fromfile...1aee76fMerge pull request #457 from Keyang/dependabot/npm_and_yarn/loader-utils-1.4.23f0c24aBump loader-utils from 1.1.0 to 1.4.26720684Merge pull request #411 from kriscarle/patch-1Updates
node-fetchfrom 2.6.0 to 2.6.7Release notes
Sourced from node-fetch's releases.
Commits
1ef4b56backport of #1449 (#1453)8fe5c4e2.x: Specify encoding as an optional peer dependency in package.json (#1310)f56b0c6fix(URL): prefer built in URL version when available and fallback to whatwg (...b5417aefix: import whatwg-url in a way compatible with ESM Node (#1303)18193c5fix v2.6.3 that did not sending query params (#1301)ace7536fix: properly encode url with unicode characters (#1291)152214cFix(package.json): Corrected main file path in package.json (#1274)b5e2e41update version number2358a6cHonor thesizeoption after following a redirect and revert data uri support8c197f8docs: Fix typos and grammatical errors in README.md (#686)Maintainer changes
This version was pushed to npm by endless, a new releaser for node-fetch since your current version.
Updates
tmpfrom 0.2.1 to 0.2.4Changelog
Sourced from tmp's changelog.
Commits
08fa3abUpdate version1cf4ec5Merge commit from fork188b25eFix GHSA-52f5-9888-hmc673b9fe4Add test case for GHSA-52f5-9888-hmc6b8e2f29Remove broken tests2892a02Remove outdated URLf592318Reformat package.json995ac8cMerge pull request #301 from raszi/dependabot/npm_and_yarn/braces-3.0.3caa758dBump braces from 3.0.2 to 3.0.35f0b252Merge pull request #297 from raszi/feat/release-v0.2.3Updates
flatfrom 5.0.0 to 5.0.1Commits
f25d3a1Release 5.0.154cc7aduse standard formatting779816edrop dependencies2eea6d3Bump lodash from 4.17.15 to 4.17.19a61a554Bump acorn from 7.1.0 to 7.4.020ef0efFix prototype pollution on unflattene8fb281Test prototype pollution on unflatten6e95c43Add node 10 & 12 to travis config.Maintainer changes
This version was pushed to npm by timoxley, a new releaser for flat since your current version.
Updates
lodashfrom 4.17.15 to 4.17.21Commits
f299b52Bump to v4.17.21c4847ebImprove performance oftoNumber,trimandtrimEndon large input strings3469357Prevent command injection through_.template'svariableoptionded9bc6Bump to v4.17.20.63150efDocumentation fixes.00f0f62test.js: Remove trailing comma.846e434Temporarily use a custom fork oflodash-cli.5d046f3Re-enable Travis tests on4.17branch.aa816b3Remove/npm-package.d7fbc52Bump to v4.17.19Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash since your current version.
Updates
object-pathfrom 0.11.4 to 0.11.8Commits
Updates
fast-csvfrom 4.3.0 to 4.3.6Release notes
Sourced from fast-csv's releases.
... (truncated)
Changelog
Sourced from fast-csv's changelog.
Commits
3dc859echore(release): publish v4.3.6b908170chore(release): publish v4.3.56969d3echore(release): publish v4.3.4096bb87chore(release): publish v4.3.3fa749f4chore(): move@types/nodeto the parse and format package4769d9echore(): Update eslint librariesbbb783bchore(release): publish v4.3.223bf809chore(release): publish v4.3.10de3d0achore(): Fix renovatebotUpdates
jsondiffpatchfrom 0.4.1 to 0.7.2Release notes
Sourced from jsondiffpatch's releases.
... (truncated)
Commits
Updates
@babel/traversefrom 7.10.3 to 7.28.5Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Changelog
Sourced from
@babel/traverse's changelog.... (truncated)
Commits
61647aev7.28.5e579cb0EnablestrictNullChecksfortraverse(#17499)7385eae[Babel 8] Improve scope information collection performance (#17043)26bc651[Babel 8] Better node type definitions forcomputed(#17500)e626523FixJSXIdentifierhandling inisReferencedIdentifier(#17503)19c9126fix: ensure scope.push register in anonymous fn (#17504)35055e3v7.28.4b41f8cdUpdate Jest to v30.1.1 (#17493)22493b6Improve@babel/traversetypings (#17485)18d88b8Improve@babel/coretypings (#17471)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for
@babel/traversesince your current version.Updates
@npmcli/gitfrom 2.0.2 to 2.1.0Changelog
Sourced from
@npmcli/git's changelog.... (truncated)
Commits
101abac2.1.0766de2fThrow custom errors from spawn (#32)ef5cfcc2.0.9ab646cfDo not allow git replacement objects by default (#30)94e2543update tap, test on node 161ce7b972.0.89fab115Merge pull request #29 from npm/nlf/no-shellf48dc34chore: run lint as postteste69549ffix: remove path escaping since we do not need it when not using a shell766bfbefix: do not use a shell for git commandsMaintainer changes
This version was pushed to npm by lukekarrys, a new releaser for
@npmcli/gitsince your current version.Updates
ajvfrom 6.12.2 to 6.12.6Release notes
Sourced from ajv's releases.
Commits
fe591436.12.6d580d3eMerge pull request #1298 from ajv-validator/fix-urlfd36389fix: regular expression for "url" format490e34cdocs: link to v7-beta branch9cd93a1docs: note about v7 in readme877d286Merge pull request #1262 from b4h0-c4t/refactor-opt-object-typef1c8e456.12.5764035eMerge branch 'ChALkeR-chalker/fix-comma'3798160Merge branch 'chalker/fix-comma' of git://github.com/ChALkeR/ajv into ChALkeR...a3c7ebaMerge branch 'refactor-opt-object-type' of github.com:b4h0-c4t/ajv into refac...Updates
blfrom 4.0.2 to 4.1.0Release notes
Sourced from bl's releases.
Changelog
Sourced from bl's changelog.