-
Notifications
You must be signed in to change notification settings - Fork 0
Bump the npm_and_yarn group across 1 directory with 58 updates #2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Bumps the npm_and_yarn group with 54 updates in the / directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.11` | `4.17.21` | | [request](https://github.com/request/request) | `2.87.0` | `2.88.2` | | [@types/request](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/request) | `2.47.0` | `2.48.12` | | [semver](https://github.com/npm/node-semver) | `5.5.0` | `5.7.2` | | [tree-kill](https://github.com/pkrumins/node-tree-kill) | `1.2.0` | `1.2.2` | | [ws](https://github.com/websockets/ws) | `3.3.3` | `4.0.0` | | [xml2js](https://github.com/Leonidas-from-XIV/node-xml2js) | `0.4.19` | `0.5.0` | | [codecov](https://github.com/codecov/codecov-node) | `3.0.2` | `3.7.1` | | [flat](https://github.com/hughsk/flat) | `4.0.0` | `5.0.1` | | [jsdom](https://github.com/jsdom/jsdom) | `12.2.0` | `16.5.0` | | [loader-utils](https://github.com/webpack/loader-utils) | `1.1.0` | `1.4.2` | | [react-dev-utils](https://github.com/facebook/create-react-app/tree/HEAD/packages/react-dev-utils) | `5.0.2` | `11.0.4` | | [webpack-bundle-analyzer](https://github.com/webpack-contrib/webpack-bundle-analyzer) | `3.0.3` | `3.3.2` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.1.0` | `7.24.7` | | [ajv](https://github.com/ajv-validator/ajv) | `6.5.4` | `6.12.6` | | [ajv](https://github.com/ajv-validator/ajv) | `6.9.1` | `6.12.6` | | [@jupyterlab/services](https://github.com/jupyterlab/jupyterlab) | `3.2.1` | `7.2.2` | | [har-validator](https://github.com/ahmadnassri/node-har-validator) | `5.1.0` | `5.1.5` | | [extend](https://github.com/justmoon/node-extend) | `3.0.1` | `3.0.2` | | [azure-storage](https://github.com/Azure/azure-storage-node) | `2.10.1` | `2.10.7` | | [bl](https://github.com/rvagg/bl) | `1.2.2` | `1.2.3` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.3` | | [chownr](https://github.com/isaacs/chownr) | `1.0.1` | `1.1.4` | | [copy-props](https://github.com/gulpjs/copy-prop) | `2.0.4` | `2.0.5` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [decompress](https://github.com/kevva/decompress) | `4.2.0` | `4.2.1` | | [elliptic](https://github.com/indutny/elliptic) | `6.4.1` | `6.5.5` | | [fsevents](https://github.com/fsevents/fsevents) | `1.2.4` | `1.2.13` | | [ini](https://github.com/npm/ini) | `1.3.5` | `1.3.8` | | [fstream](https://github.com/npm/fstream) | `1.0.11` | `1.0.12` | | [global-modules-path](https://github.com/rosen-vladimirov/global-modules-path) | `2.3.0` | `removed` | | [webpack-cli](https://github.com/webpack/webpack-cli) | `3.1.2` | `3.3.12` | | [y18n](https://github.com/yargs/y18n) | `3.2.1` | `3.2.2` | | [yargs-parser](https://github.com/yargs/yargs-parser) | `5.0.0` | `5.0.1` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.1.0` | `4.7.8` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.11.0` | `3.14.1` | | [gulp-inline-source](https://github.com/fmal/gulp-inline-source) | `3.2.0` | `4.0.0` | | [json-schema](https://github.com/kriszyp/json-schema) | `0.2.3` | `0.4.0` | | [jsprim](https://github.com/joyent/node-jsprim) | `1.4.1` | `1.4.2` | | [json5](https://github.com/json5/json5) | `1.0.1` | `2.2.3` | | [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.1.0` | `7.24.7` | | [html-webpack-plugin](https://github.com/jantimon/html-webpack-plugin) | `3.2.0` | `5.6.0` | | [styled-jsx](https://github.com/vercel/styled-jsx) | `3.1.0` | `3.4.7` | | [svg-inline-loader](https://github.com/sairion/svg-inline-loader) | `0.8.0` | `0.8.2` | | [mixin-deep](https://github.com/jonschlinkert/mixin-deep) | `1.3.1` | `1.3.2` | | [moment](https://github.com/moment/moment) | `2.21.0` | `2.30.1` | | [underscore](https://github.com/jashkenas/underscore) | `1.4.4` | `removed` | | [nearley](https://github.com/hardmath123/nearley) | `2.15.1` | `2.20.1` | | [azure-storage](https://github.com/Azure/azure-storage-node) | `2.10.2` | `2.10.7` | | [pathval](https://github.com/chaijs/pathval) | `1.1.0` | `1.1.1` | | [postcss](https://github.com/postcss/postcss) | `6.0.23` | `8.4.38` | | [css-loader](https://github.com/webpack-contrib/css-loader) | `1.0.1` | `7.1.2` | | [qs](https://github.com/ljharb/qs) | `6.5.2` | `6.5.3` | | [set-value](https://github.com/jonschlinkert/set-value) | `2.0.0` | `2.0.1` | | [union-value](https://github.com/jonschlinkert/union-value) | `1.0.0` | `1.0.1` | | [url-parse](https://github.com/unshiftio/url-parse) | `1.4.3` | `1.5.10` | Updates `lodash` from 4.17.11 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.11...4.17.21) Updates `request` from 2.87.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `@types/request` from 2.47.0 to 2.48.12 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/request) Updates `semver` from 5.5.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.5.0...v5.7.2) Updates `tree-kill` from 1.2.0 to 1.2.2 - [Release notes](https://github.com/pkrumins/node-tree-kill/releases) - [Commits](pkrumins/node-tree-kill@v1.2.0...v1.2.2) Updates `ws` from 3.3.3 to 4.0.0 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@3.3.3...4.0.0) Updates `xml2js` from 0.4.19 to 0.5.0 - [Commits](Leonidas-from-XIV/node-xml2js@0.4.19...0.5.0) Updates `codecov` from 3.0.2 to 3.7.1 - [Release notes](https://github.com/codecov/codecov-node/releases) - [Changelog](https://github.com/codecov/codecov-node/blob/master/CHANGELOG.md) - [Commits](codecov/codecov-node@v3.0.2...v3.7.1) Updates `flat` from 4.0.0 to 5.0.1 - [Release notes](https://github.com/hughsk/flat/releases) - [Commits](hughsk/flat@4.0.0...5.0.1) Updates `jsdom` from 12.2.0 to 16.5.0 - [Release notes](https://github.com/jsdom/jsdom/releases) - [Changelog](https://github.com/jsdom/jsdom/blob/main/Changelog.md) - [Commits](jsdom/jsdom@12.2.0...16.5.0) Updates `loader-utils` from 1.1.0 to 1.4.2 - [Release notes](https://github.com/webpack/loader-utils/releases) - [Changelog](https://github.com/webpack/loader-utils/blob/v1.4.2/CHANGELOG.md) - [Commits](webpack/loader-utils@v1.1.0...v1.4.2) Updates `react-dev-utils` from 5.0.2 to 11.0.4 - [Release notes](https://github.com/facebook/create-react-app/releases) - [Changelog](https://github.com/facebook/create-react-app/blob/main/CHANGELOG-1.x.md) - [Commits](https://github.com/facebook/create-react-app/commits/HEAD/packages/react-dev-utils) Updates `webpack-bundle-analyzer` from 3.0.3 to 3.3.2 - [Changelog](https://github.com/webpack-contrib/webpack-bundle-analyzer/blob/master/CHANGELOG.md) - [Commits](webpack/webpack-bundle-analyzer@v3.0.3...v3.3.2) Updates `@babel/traverse` from 7.1.0 to 7.24.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.7/packages/babel-traverse) Updates `ajv` from 6.5.4 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.5.4...v6.12.6) Updates `ajv` from 6.9.1 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.5.4...v6.12.6) Updates `@jupyterlab/services` from 3.2.1 to 7.2.2 - [Release notes](https://github.com/jupyterlab/jupyterlab/releases) - [Changelog](https://github.com/jupyterlab/jupyterlab/blob/main/CHANGELOG.md) - [Commits](https://github.com/jupyterlab/jupyterlab/compare/@jupyterlab/services@3.2.1...@jupyterlab/services@7.2.2) Updates `har-validator` from 5.1.0 to 5.1.5 - [Release notes](https://github.com/ahmadnassri/node-har-validator/releases) - [Changelog](https://github.com/ahmadnassri/node-har-validator/blob/master/.releaserc) - [Commits](ahmadnassri/node-har-validator@v5.1.0...v5.1.5) Updates `extend` from 3.0.1 to 3.0.2 - [Changelog](https://github.com/justmoon/node-extend/blob/main/CHANGELOG.md) - [Commits](justmoon/node-extend@v3.0.1...v3.0.2) Updates `azure-storage` from 2.10.1 to 2.10.7 - [Release notes](https://github.com/Azure/azure-storage-node/releases) - [Changelog](https://github.com/Azure/azure-storage-node/blob/master/ChangeLog.md) - [Commits](https://github.com/Azure/azure-storage-node/commits) Updates `tough-cookie` from 2.3.4 to 2.4.3 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.3.4...v2.4.3) Updates `bl` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/rvagg/bl/releases) - [Changelog](https://github.com/rvagg/bl/blob/master/CHANGELOG.md) - [Commits](rvagg/bl@v1.2.2...v1.2.3) Updates `browserify-sign` from 4.0.4 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.3) Updates `chownr` from 1.0.1 to 1.1.4 - [Commits](isaacs/chownr@v1.0.1...v1.1.4) Updates `copy-props` from 2.0.4 to 2.0.5 - [Commits](https://github.com/gulpjs/copy-prop/commits) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `decompress` from 4.2.0 to 4.2.1 - [Release notes](https://github.com/kevva/decompress/releases) - [Commits](kevva/decompress@v4.2.0...v4.2.1) Updates `ejs` from 2.6.1 to 2.7.4 - [Release notes](https://github.com/mde/ejs/releases) - [Commits](mde/ejs@v2.6.1...v2.7.4) Updates `elliptic` from 6.4.1 to 6.5.5 - [Commits](indutny/elliptic@v6.4.1...v6.5.5) Updates `express` from 4.16.4 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.16.4...4.19.2) Updates `fsevents` from 1.2.4 to 1.2.13 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.2.4...v1.2.13) Updates `ini` from 1.3.5 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.5...v1.3.8) Updates `fstream` from 1.0.11 to 1.0.12 - [Commits](npm/fstream@v1.0.11...v1.0.12) Removes `global-modules-path` Updates `webpack-cli` from 3.1.2 to 3.3.12 - [Release notes](https://github.com/webpack/webpack-cli/releases) - [Changelog](https://github.com/webpack/webpack-cli/blob/master/CHANGELOG.md) - [Commits](webpack/webpack-cli@v3.1.2...v3.3.12) Updates `y18n` from 3.2.1 to 3.2.2 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](https://github.com/yargs/y18n/commits) Updates `yargs-parser` from 5.0.0 to 5.0.1 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/v5.0.1/CHANGELOG.md) - [Commits](yargs/yargs-parser@v5.0.0...v5.0.1) Updates `handlebars` from 4.1.0 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.1.0...v4.7.8) Updates `js-yaml` from 3.11.0 to 3.14.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.11.0...3.14.1) Updates `gulp-inline-source` from 3.2.0 to 4.0.0 - [Release notes](https://github.com/fmal/gulp-inline-source/releases) - [Commits](fmal/gulp-inline-source@v3.2.0...v4.0.0) Updates `json-schema` from 0.2.3 to 0.4.0 - [Commits](kriszyp/json-schema@v0.2.3...v0.4.0) Updates `jsprim` from 1.4.1 to 1.4.2 - [Changelog](https://github.com/TritonDataCenter/node-jsprim/blob/v1.4.2/CHANGES.md) - [Commits](TritonDataCenter/node-jsprim@v1.4.1...v1.4.2) Updates `json5` from 1.0.1 to 2.2.3 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v1.0.1...v2.2.3) Updates `@babel/core` from 7.1.0 to 7.24.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.7/packages/babel-core) Updates `html-webpack-plugin` from 3.2.0 to 5.6.0 - [Release notes](https://github.com/jantimon/html-webpack-plugin/releases) - [Changelog](https://github.com/jantimon/html-webpack-plugin/blob/main/CHANGELOG.md) - [Commits](jantimon/html-webpack-plugin@v3.2.0...v5.6.0) Updates `styled-jsx` from 3.1.0 to 3.4.7 - [Release notes](https://github.com/vercel/styled-jsx/releases) - [Changelog](https://github.com/vercel/styled-jsx/blob/main/Changelog.md) - [Commits](vercel/styled-jsx@3.1.0...v3.4.7) Updates `svg-inline-loader` from 0.8.0 to 0.8.2 - [Release notes](https://github.com/sairion/svg-inline-loader/releases) - [Changelog](https://github.com/webpack-contrib/svg-inline-loader/blob/master/CHANGELOG.md) - [Commits](webpack-contrib/svg-inline-loader@v0.8.0...v0.8.2) Updates `mixin-deep` from 1.3.1 to 1.3.2 - [Commits](jonschlinkert/mixin-deep@1.3.1...1.3.2) Updates `moment` from 2.21.0 to 2.30.1 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.21.0...2.30.1) Removes `underscore` Updates `nearley` from 2.15.1 to 2.20.1 - [Release notes](https://github.com/hardmath123/nearley/releases) - [Commits](https://github.com/hardmath123/nearley/commits) Updates `azure-storage` from 2.10.2 to 2.10.7 - [Release notes](https://github.com/Azure/azure-storage-node/releases) - [Changelog](https://github.com/Azure/azure-storage-node/blob/master/ChangeLog.md) - [Commits](https://github.com/Azure/azure-storage-node/commits) Updates `pathval` from 1.1.0 to 1.1.1 - [Release notes](https://github.com/chaijs/pathval/releases) - [Changelog](https://github.com/chaijs/pathval/blob/master/CHANGELOG.md) - [Commits](chaijs/pathval@v1.1.0...v1.1.1) Updates `postcss` from 6.0.23 to 8.4.38 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@6.0.23...8.4.38) Updates `css-loader` from 1.0.1 to 7.1.2 - [Release notes](https://github.com/webpack-contrib/css-loader/releases) - [Changelog](https://github.com/webpack-contrib/css-loader/blob/master/CHANGELOG.md) - [Commits](webpack/css-loader@v1.0.1...v7.1.2) Updates `qs` from 6.5.2 to 6.5.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.2...v6.5.3) Updates `set-value` from 2.0.0 to 2.0.1 - [Commits](jonschlinkert/set-value@2.0.0...2.0.1) Updates `union-value` from 1.0.0 to 1.0.1 - [Release notes](https://github.com/jonschlinkert/union-value/releases) - [Commits](jonschlinkert/union-value@1.0.0...1.0.1) Updates `shell-quote` from 1.6.1 to 1.7.2 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.6.1...v1.7.2) Updates `url-parse` from 1.4.3 to 1.5.10 - [Commits](unshiftio/url-parse@1.4.3...1.5.10) --- updated-dependencies: - dependency-name: lodash dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@types/request" dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: semver dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tree-kill dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ws dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: xml2js dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: codecov dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: flat dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: jsdom dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: loader-utils dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: react-dev-utils dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: webpack-bundle-analyzer dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ajv dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ajv dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@jupyterlab/services" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: har-validator dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: extend dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: azure-storage dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: bl dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: chownr dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: copy-props dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decompress dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ejs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: elliptic dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fsevents dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fstream dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: global-modules-path dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: webpack-cli dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: y18n dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: gulp-inline-source dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: json-schema dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jsprim dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@babel/core" dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: html-webpack-plugin dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: styled-jsx dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: svg-inline-loader dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: mixin-deep dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: moment dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: underscore dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nearley dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: azure-storage dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: pathval dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: postcss dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: css-loader dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: set-value dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: union-value dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: shell-quote dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: url-parse dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is an install script?Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts. Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
|
Superseded by #3. |
Bumps the npm_and_yarn group with 54 updates in the / directory:
4.17.114.17.212.87.02.88.22.47.02.48.125.5.05.7.21.2.01.2.23.3.34.0.00.4.190.5.03.0.23.7.14.0.05.0.112.2.016.5.01.1.01.4.25.0.211.0.43.0.33.3.27.1.07.24.76.5.46.12.66.9.16.12.63.2.17.2.25.1.05.1.53.0.13.0.22.10.12.10.71.2.21.2.34.0.44.2.31.0.11.1.42.0.42.0.50.2.00.2.24.2.04.2.16.4.16.5.51.2.41.2.131.3.51.3.81.0.111.0.122.3.0removed3.1.23.3.123.2.13.2.25.0.05.0.14.1.04.7.83.11.03.14.13.2.04.0.00.2.30.4.01.4.11.4.21.0.12.2.37.1.07.24.73.2.05.6.03.1.03.4.70.8.00.8.21.3.11.3.22.21.02.30.11.4.4removed2.15.12.20.12.10.22.10.71.1.01.1.16.0.238.4.381.0.17.1.26.5.26.5.32.0.02.0.11.0.01.0.11.4.31.5.10Updates
lodashfrom 4.17.11 to 4.17.21Commits
f299b52Bump to v4.17.21c4847ebImprove performance oftoNumber,trimandtrimEndon large input strings3469357Prevent command injection through_.template'svariableoptionded9bc6Bump to v4.17.20.63150efDocumentation fixes.00f0f62test.js: Remove trailing comma.846e434Temporarily use a custom fork oflodash-cli.5d046f3Re-enable Travis tests on4.17branch.aa816b3Remove/npm-package.d7fbc52Bump to v4.17.19Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash since your current version.
Updates
requestfrom 2.87.0 to 2.88.2Changelog
Sourced from request's changelog.
Commits
Updates
@types/requestfrom 2.47.0 to 2.48.12Commits
Updates
semverfrom 5.5.0 to 5.7.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
f8cc313chore: release 5.7.22f8fd41fix: better handling of whitespace (#585)deb5ad5chore:@npmcli/template-oss@4.16.0c83c18c5.7.1956e228Correct typo in README8055dda5.7.0604e73dauto-publishing scriptsbed01e2remove the nomin comments, since we don't minify any more anyway9cb68f1document parse method38d42ca5.7 changelogMaintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
tree-killfrom 1.2.0 to 1.2.2Release notes
Sourced from tree-kill's releases.
Commits
cb478381.2.2deee138fix: handle sanitising better, add testsff73dbffix: sanitise pid parameter (#31)3b5b8feupdate Changelogd408f041.2.132624c1Merge pull request #24 from LinusU/patch-1c784c3dAdd callback-as-second-argument support to typings6d6843cMerge pull request #21 from orodley/patch-1d515c80Add LICENSE fileUpdates
wsfrom 3.3.3 to 4.0.0Release notes
Sourced from ws's releases.
Commits
a04d985[dist] 4.0.0d03ada2[minor] Rename some variables for claritya206e98[major] RemoveWebSocket#pause()andWebSocket#resume()1c783c2[major] Rename the 'headers' event to 'upgrade'9bbc978[test] Reorganize testsfdec524[fix] Fixextentionsproperty type46461a9[minor] Refactor server client initializationee9b5f3[major] Remove non-standardbytesReceivedattribute7f8ebc6[major] Remove non-standardprotocolVersionattribute30c9f71[major] MakeWebSocket#p{i,o}ng()accept an optional callbackUpdates
xml2jsfrom 0.4.19 to 0.5.0Commits
9f730bbUpdate package.json with latest PR50a492aMerge pull request #603 from autopulated/master7bc3c5dMerge pull request #598 from fnimick/masterf412a12Merge pull request #635 from wisesimpson/patch-1d318ce0Update README.md581b19ause Object.create(null) to create all parsed objects (prevent prototype repla...a212950Add documentation forexplicitCharkeyoption1832e0bMerge pull request #512 from economia/master198063cMerge pull request #556 from Omega-Ariston/fix-issue5440d71785Merge pull request #562 from Omega-Ariston/addDocExampleUpdates
codecovfrom 3.0.2 to 3.7.1Release notes
Sourced from codecov's releases.
Changelog
Sourced from codecov's changelog.
... (truncated)
Commits
29dd5b63.7.1c0711c6Switch from execSync to execFileSync (#180)5f6cc62Bump lodash from 4.17.15 to 4.17.19 (#183)0c4d7f3Merge pull request #182 from codecov/update-readme-badgescc5e121Update depstat image and urlsb44b44eUpdate readme with 400 error info (#181)bb79335V3.7.0 (#179)0d7b9b0Remove'x-amz-acl': 'public-read'header (#178)eeff4e1Bump acorn from 5.7.3 to 5.7.4 (#174)eb8a527Merge pull request #172 from RoboCafaz/bugfix/codebuild-pr-parserMaintainer changes
This version was pushed to npm by drazisil, a new releaser for codecov since your current version.
Updates
flatfrom 4.0.0 to 5.0.1Commits
f25d3a1Release 5.0.154cc7aduse standard formatting779816edrop dependencies2eea6d3Bump lodash from 4.17.15 to 4.17.19a61a554Bump acorn from 7.1.0 to 7.4.020ef0efFix prototype pollution on unflattene8fb281Test prototype pollution on unflatten6e95c43Add node 10 & 12 to travis config.38239ccRelease 5.0.0beaea9dAdd tests around cli. Only show usage if on TTY & no argument, allow eaccess ...Maintainer changes
This version was pushed to npm by timoxley, a new releaser for flat since your current version.
Updates
jsdomfrom 12.2.0 to 16.5.0Release notes
Sourced from jsdom's releases.
... (truncated)
Changelog
Sourced from jsdom's changelog.
... (truncated)
Commits
2d82763Version 16.5.09741311Fix loading of subresources with Unicode filenames5e46553Use domenic's ESLint config as the base19b35daFix the URL of about:blank iframes017568eSupport inputType on InputEvent29f4fdfUpgrade dependenciese2f7639Refactor create‑event‑accessor.js to remove code duplicationff69a75Convert JSDOM to use callback functions19df6bcUpdate links in contributing guidelines1e34ff5Test triageUpdates
loader-utilsfrom 1.1.0 to 1.4.2Release notes
Sourced from loader-utils's releases.
... (truncated)
Changelog
Sourced from loader-utils's changelog.
... (truncated)
Commits
331ad50chore(release): 1.4.217cbf8ffix: ReDoS problem (#226)8f082b3chore(release): 1.4.14504e34fix: security problem (#220)d95b8b5chore(release): 1.4.0cd0e428feat: theresourceQueryis passed to theinterpolateNamemethod (#163)06d36cfchore(release): 1.3.0469eebafeat: support the[query]template for theinterpolatedNamemethod (#162)909c99dchore: funding.yml config and CI fix (#159)b5b74f0Set up CI with Azure PipelinesMaintainer changes
This version was pushed to npm by evilebottnawi, a new releaser for loader-utils since your current version.
Updates
react-dev-utilsfrom 5.0.2 to 11.0.4Changelog
Sourced from react-dev-utils's changelog.
... (truncated)
Commits
Updates
webpack-bundle-analyzerfrom 3.0.3 to 3.3.2Changelog
Sourced from webpack-bundle-analyzer's changelog.
Commits
345c3f5v3.3.2a615815Merge pull request #264 from webpack-contrib/fix-escape-regression20f2b4cFix regression with escaping internal assets9836649v3.3.1d1db526Remove outdated item from troubleshooting sectionca34279Merge pull request #261 from webpack-contrib/relative-links-to-assets99818f9Fix changelog21722d2Add changelog entryed99c32Use relative links for serving internal assets3ce1b8cMerge pull request #262 from webpack-contrib/proper-js-escapeUpdates
@babel/traversefrom 7.1.0 to 7.24.7Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Changelog
Sourced from
@babel/traverse's changelog.