Skip to content

fix(deps): update dependency js-cookie to v3#2100

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/js-cookie-3.x
Open

fix(deps): update dependency js-cookie to v3#2100
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/js-cookie-3.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Sep 1, 2021

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
js-cookie ^2.2.1 -> ^3.0.0 age adoption passing confidence
@types/js-cookie (source) ^2.2.6 -> ^3.0.0 age adoption passing confidence

Release Notes

js-cookie/js-cookie

v3.0.1

Compare Source

  • Make package.json accessible in export - #​727

v3.0.0

Compare Source

  • Removed defaults in favor of a builder: now to supply an api instance with particular predefined (cookie) attributes there's Cookies.withAttributes(), e.g.:
const api = Cookies.withAttributes({
  path: '/',
  secure: true
})
api.set('key', 'value') // writes cookie with path: '/' and secure: true...
  • The attributes that an api instance is configured with are exposed as attributes property; it's an immutable object and unlike defaults cannot be changed to configure the api.
  • The mechanism to fall back to the standard, internal converter by returning a falsy value in a custom read converter has been removed. Instead the default converters are now exposed as Cookies.converter, which allows for implementing self-contained custom converters providing the same behavior:
const customReadConverter = (value, name) => {
  if (name === 'special') {
    return unescape(value)
  }
  return Cookies.converter.read(value)
}
  • withConverter() no longer accepts a function as argument to be turned into a read converter. It is now required to always pass an object with the explicit type(s) of converter(s):
const api = Cookies.withConverter({
  read: (value, name) => unescape(value)
})
  • The converter(s) that an api instance is configured with are exposed as converter property; it's an immutable object and cannot be changed to configure the api.
  • Started providing library as ES module, in addition to UMD module. The module field in package.json points to an ES module variant of the library.
  • Started using browser field instead of main in package.json (for the UMD variant of the library).
  • Dropped support for IE < 10.
  • Removed built-in JSON support, i.e. getJSON() and automatic stringifying in set(): use Cookies.set('foo', JSON.stringify({ ... })) and JSON.parse(Cookies.get('foo')) instead.
  • Removed support for Bower.
  • Added minified versions to package - #​501
  • Improved support for url encoded cookie values (support case insensitive encoding) - #​466, #​530
  • Expose default path via API - #​541
  • Handle falsy arguments passed to getters - #​399
  • No longer support Node < 12 when building (LTS versions only)

Configuration

πŸ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate Bot force-pushed the renovate/js-cookie-3.x branch from fcfe2dc to c0349d9 Compare October 1, 2021 22:58
@renovate renovate Bot changed the title fix(deps): update dependency js-cookie to v3 Update dependency js-cookie to v3 Dec 17, 2022
@renovate renovate Bot changed the title Update dependency js-cookie to v3 fix(deps): update dependency js-cookie to v3 Dec 17, 2022
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Mar 25, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@rashedmyt
Copy link
Copy Markdown

A new security vulnerability was reported in older versions of js-cookie package.

Is it possible to create a new release of this package with this PR updated and merged?

@uladzimirdev
Copy link
Copy Markdown

@streamich could you please take a look?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants