Bump the minor-and-patch group with 16 updates - #112
Conversation
Bumps the minor-and-patch group with 16 updates: | Package | From | To | | --- | --- | --- | | [@sentry/node](https://github.com/getsentry/sentry-javascript) | `8.13.0` | `8.18.0` | | [ajv](https://github.com/ajv-validator/ajv) | `8.12.0` | `8.17.1` | | [axios](https://github.com/axios/axios) | `1.5.1` | `1.7.2` | | [fastify](https://github.com/fastify/fastify) | `4.24.3` | `4.28.1` | | [ioredis](https://github.com/luin/ioredis) | `5.3.2` | `5.4.1` | | [prom-client](https://github.com/siimon/prom-client) | `15.1.0` | `15.1.3` | | [@babel/preset-typescript](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-typescript) | `7.23.2` | `7.24.7` | | [@types/jest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/jest) | `29.5.6` | `29.5.12` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `20.8.7` | `20.14.11` | | [@types/yargs](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/yargs) | `17.0.29` | `17.0.32` | | [dotenv](https://github.com/motdotla/dotenv) | `16.3.1` | `16.4.5` | | [lint-staged](https://github.com/okonet/lint-staged) | `15.0.2` | `15.2.7` | | [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.1.1` | `29.2.2` | | [ts-loader](https://github.com/TypeStrong/ts-loader) | `9.5.0` | `9.5.1` | | [typescript](https://github.com/Microsoft/TypeScript) | `5.2.2` | `5.5.3` | | [webpack](https://github.com/webpack/webpack) | `5.89.0` | `5.93.0` | Updates `@sentry/node` from 8.13.0 to 8.18.0 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@8.13.0...8.18.0) Updates `ajv` from 8.12.0 to 8.17.1 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v8.12.0...v8.17.1) Updates `axios` from 1.5.1 to 1.7.2 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.5.1...v1.7.2) Updates `fastify` from 4.24.3 to 4.28.1 - [Release notes](https://github.com/fastify/fastify/releases) - [Commits](fastify/fastify@v4.24.3...v4.28.1) Updates `ioredis` from 5.3.2 to 5.4.1 - [Release notes](https://github.com/luin/ioredis/releases) - [Changelog](https://github.com/redis/ioredis/blob/main/CHANGELOG.md) - [Commits](redis/ioredis@v5.3.2...v5.4.1) Updates `prom-client` from 15.1.0 to 15.1.3 - [Release notes](https://github.com/siimon/prom-client/releases) - [Changelog](https://github.com/siimon/prom-client/blob/master/CHANGELOG.md) - [Commits](prometheus/client_js@v15.1.0...v15.1.3) Updates `@babel/preset-typescript` from 7.23.2 to 7.24.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.7/packages/babel-preset-typescript) Updates `@types/jest` from 29.5.6 to 29.5.12 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/jest) Updates `@types/node` from 20.8.7 to 20.14.11 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@types/yargs` from 17.0.29 to 17.0.32 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/yargs) Updates `dotenv` from 16.3.1 to 16.4.5 - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v16.3.1...v16.4.5) Updates `lint-staged` from 15.0.2 to 15.2.7 - [Release notes](https://github.com/okonet/lint-staged/releases) - [Changelog](https://github.com/lint-staged/lint-staged/blob/master/CHANGELOG.md) - [Commits](lint-staged/lint-staged@v15.0.2...v15.2.7) Updates `ts-jest` from 29.1.1 to 29.2.2 - [Release notes](https://github.com/kulshekhar/ts-jest/releases) - [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md) - [Commits](kulshekhar/ts-jest@v29.1.1...v29.2.2) Updates `ts-loader` from 9.5.0 to 9.5.1 - [Release notes](https://github.com/TypeStrong/ts-loader/releases) - [Changelog](https://github.com/TypeStrong/ts-loader/blob/main/CHANGELOG.md) - [Commits](TypeStrong/ts-loader@v9.5.0...v9.5.1) Updates `typescript` from 5.2.2 to 5.5.3 - [Release notes](https://github.com/Microsoft/TypeScript/releases) - [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release.yml) - [Commits](microsoft/TypeScript@v5.2.2...v5.5.3) Updates `webpack` from 5.89.0 to 5.93.0 - [Release notes](https://github.com/webpack/webpack/releases) - [Commits](webpack/webpack@v5.89.0...v5.93.0) --- updated-dependencies: - dependency-name: "@sentry/node" dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ajv dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: axios dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: fastify dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ioredis dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: prom-client dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@babel/preset-typescript" dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@types/jest" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/node" dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@types/yargs" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: dotenv dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: lint-staged dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ts-jest dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ts-loader dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: typescript dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: webpack dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is filesystem access?Accesses the file system, and could potentially read sensitive data. If a package must read the file system, clarify what it will read and ensure it reads only what it claims to. If appropriate, packages can leave file system access to consumers and operate on data passed to it instead. What is debug access?Uses debug, reflection and dynamic code execution features. Removing the use of debug will reduce the risk of any reflection and dynamic code execution. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
…oof in body; 5s skew Addresses Jake's design-doc review on #316: - Generalize the src/auth primitive from onramp-specific to a reusable "address proof": verifyAddressProof, ADDRESS_PROOF_DOMAIN ("freighter:address-proof:v1"), reasons, and result type. The domain tag is named generically on purpose — it lives in the signed bytes, so a later rename would be a wire-breaking v2. Onramp is now the first consumer; the rollout policy (onrampAuthPreHandler, ONRAMP_AUTH_MODE, the onramp metric) stays onramp-scoped. - Move the proof out of the Authorization header into the `address_proof` POST-body field, so it composes with v2's JWT (which occupies Authorization) and v2 needs no second auth scheme. body_hash now covers the business body with the proof field removed (sign-everything-but-the-signature). - Bump clock skew 2s -> 5s to match freighter-backend-v2 #112 (ClockSkewLeeway). tsc clean; jest green (auth + route + config suites). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bumps the minor-and-patch group with 16 updates:
8.13.08.18.08.12.08.17.11.5.11.7.24.24.34.28.15.3.25.4.115.1.015.1.37.23.27.24.729.5.629.5.1220.8.720.14.1117.0.2917.0.3216.3.116.4.515.0.215.2.729.1.129.2.29.5.09.5.15.2.25.5.35.89.05.93.0Updates
@sentry/nodefrom 8.13.0 to 8.18.0Release notes
Sourced from
@sentry/node's releases.... (truncated)
Changelog
Sourced from
@sentry/node's changelog.... (truncated)
Commits
c9ea6b8release: 8.18.09a25dadMerge pull request #12932 from getsentry/prepare-release/8.18.0c57e363meta: Update CHANGELOG for 8.18.06f4c045fix(node): Ensure correct URL is passed toignoreIncomingRequestscallback ...707afd6fix(tracing): Ensure you can passnullasparentSpaninstartSpan*(#12...475d66ffix(sveltekit): Add Vite peer dep for proper type resolution (#12926)9d1b35dfeat(browser): Add user agent to INP standalone span attributes (#12896)f9ab138ci: Do not run external contributor job for bots (#12886)383743afix(solidstart): Set proper sentry origin for solid router integration when u...1d3e208feat: Exposeexcludeandincludeoptions for ESM loader (#12910)Updates
ajvfrom 8.12.0 to 8.17.1Release notes
Sourced from ajv's releases.
... (truncated)
Commits
9050ba1bump version to 8.17.1 (#2472)f7831b4fixes #2217 - clarify custom keyword naming (#2457)a523784fix: changes for@typescript-eslint/array-typerule (#2467)595fe58feat: add test for encoded refs and bump fast-uri (#2449)a18641eUpdate modifying-data.md - fix broken strict-mode link (#2459)650c7f6Fix grammatical typo in managing-schemas.md (#2305)603f63bdocs: refactor to improve legibility (#2432)8bccdc4docs: clarify behaviour of addVocabulary (#2454)85dafb0fix: ignore new eslint error (#2455)80c014fRevert "Revert fast-uri change (#2444)" (#2448)Updates
axiosfrom 1.5.1 to 1.7.2Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
0e4f9fachore(release): v1.7.2 (#6414)4f79aeffix(fetch): enhance fetch API detection; (#6413)67d1373chore(release): v1.7.1 (#6411)733f15ffix(fetch): fixed ReferenceError issue when TextEncoder is not available in t...3041c61[Release] v1.7.0 (#6408)18b13cbchore(docs): add fetch adapter docs; (#6407)e62099bfix(fetch): fixed a possible memory leak in the AbortController for the strea...b49aa8echore(release): v1.7.0-beta.2 (#6403)d57f03achore(ci): bump create-pull-request version to fix a bug; (#6405)097b0d1chore(ci): add tag resolution for npm releases based on package version; (#6404)Updates
fastifyfrom 4.24.3 to 4.28.1Release notes
Sourced from fastify's releases.
... (truncated)
Commits
94068edBumped v4.28.1ee0ae68fix: update .npmignore (#5538)ca1987ctest: fix test finished earlier than expected (#5540) (#5541)ff88853fix: server.listen listener is not cleanup properly (#5522) (#5523)4212551Bumped v4.28.0db01168auxilliary hook handler type fix + test fix (#5518)1d7b955refactor(backport v4.x): hasRoute method comparison with case insensitive (#5...369858d[Backport 4.x] refactor: changereply.redirect()signature (#5483) (#5484)d2d6d9atest: fix closing - pipelining (#5486)fe25981Bumped v4.27.0Maintainer changes
This version was pushed to npm by eomm, a new releaser for fastify since your current version.
Updates
ioredisfrom 5.3.2 to 5.4.1Release notes
Sourced from ioredis's releases.
Changelog
Sourced from ioredis's changelog.
Commits
af83275chore(release): 5.4.1 [skip ci]558497cfix: remove console.log4f2ab44chore(release): 5.4.0 [skip ci]804ee07fix: whenrefreshSlotsCacheis callback concurrently, call the callback onl...673ac77feat: add support forsocketTimeoutinRedis(#1882)ec42c82Update README.md (#1818)9c17550docs(README): migrate repo links (#1770)ea8a006docs(README): Avoid ambiguity in the unit of EX flags7096a10docs: Update README.md (#1752)5812275docs(example): Advocate HSET (#1755)Updates
prom-clientfrom 15.1.0 to 15.1.3Release notes
Sourced from prom-client's releases.
Changelog
Sourced from prom-client's changelog.
Commits
c1d76c515.1.359dee8cchore: update changelog for releasecba73a0Update README.md - fix wrong variable name (#636)9dec7bbchore: update prettier and husky (#635)5a0c6d3chore(ci): run lint checks separately from tests (#634)bd45211Improve error message on labels (#633)564e467chore: fix lint errors in TS file (#630)1c7a4c0chore: add ts-eslint (#627)cdae42f15.1.2f05678bchore: update changelog for releaseUpdates
@babel/preset-typescriptfrom 7.23.2 to 7.24.7Release notes
Sourced from
@babel/preset-typescript's releases.... (truncated)
Changelog
Sourced from
@babel/preset-typescript's changelog.