-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump the npm_and_yarn group with 19 updates #19
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/npm_and_yarn/npm_and_yarn-83e498163d
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 19 updates: | Package | From | To | | --- | --- | --- | | [gatsby](https://github.com/gatsbyjs/gatsby) | `2.32.11` | `4.25.7` | | [gatsby-plugin-mdx](https://github.com/gatsbyjs/gatsby/tree/HEAD/packages/gatsby-plugin-mdx) | `1.10.1` | `2.14.1` | | [loader-utils](https://github.com/webpack/loader-utils) | `2.0.0` | `2.0.4` | | [node-fetch](https://github.com/node-fetch/node-fetch) | `2.6.7` | `2.7.0` | | [@sideway/formula](https://github.com/sideway/formula) | `3.0.0` | `3.0.1` | | [body-parser](https://github.com/expressjs/body-parser) | `1.19.0` | `1.20.2` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.2.1` | `4.2.3` | | [cookie](https://github.com/jshttp/cookie) | `0.4.1` | `0.4.2` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [devcert](https://github.com/davewasmer/devcert) | `1.1.3` | `1.2.2` | | [elliptic](https://github.com/indutny/elliptic) | `6.5.4` | `6.6.0` | | [express](https://github.com/expressjs/express) | `4.19.2` | `4.21.1` | | [jpeg-js](https://github.com/eugeneware/jpeg-js) | `0.4.3` | `0.4.4` | | [moment](https://github.com/moment/moment) | `2.29.1` | `2.30.1` | | [send](https://github.com/pillarjs/send) | `0.18.0` | `0.19.0` | | [serve-static](https://github.com/expressjs/serve-static) | `1.15.0` | `1.16.2` | | [ua-parser-js](https://github.com/faisalman/ua-parser-js) | `0.7.27` | `0.7.39` | | [url-parse](https://github.com/unshiftio/url-parse) | `1.5.7` | `1.5.10` | | [word-wrap](https://github.com/jonschlinkert/word-wrap) | `1.2.3` | `1.2.5` | Updates `gatsby` from 2.32.11 to 4.25.7 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/compare/[email protected]@4.25.7) Updates `gatsby-plugin-mdx` from 1.10.1 to 2.14.1 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/[email protected]/packages/gatsby-plugin-mdx/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/commits/[email protected]/packages/gatsby-plugin-mdx) Updates `loader-utils` from 2.0.0 to 2.0.4 - [Release notes](https://github.com/webpack/loader-utils/releases) - [Changelog](https://github.com/webpack/loader-utils/blob/v2.0.4/CHANGELOG.md) - [Commits](webpack/loader-utils@v2.0.0...v2.0.4) Updates `node-fetch` from 2.6.7 to 2.7.0 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v2.6.7...v2.7.0) Updates `@sideway/formula` from 3.0.0 to 3.0.1 - [Commits](hapijs/formula@v3.0.0...v3.0.1) Updates `body-parser` from 1.19.0 to 1.20.2 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.19.0...1.20.2) Updates `browserify-sign` from 4.2.1 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.2.1...v4.2.3) Updates `cookie` from 0.4.1 to 0.4.2 - [Release notes](https://github.com/jshttp/cookie/releases) - [Changelog](https://github.com/jshttp/cookie/blob/v0.4.2/HISTORY.md) - [Commits](jshttp/cookie@v0.4.1...v0.4.2) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `devcert` from 1.1.3 to 1.2.2 - [Release notes](https://github.com/davewasmer/devcert/releases) - [Changelog](https://github.com/davewasmer/devcert/blob/master/CHANGELOG.md) - [Commits](davewasmer/devcert@v1.1.3...v1.2.2) Updates `elliptic` from 6.5.4 to 6.6.0 - [Commits](indutny/elliptic@v6.5.4...v6.6.0) Updates `express` from 4.19.2 to 4.21.1 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.21.1/History.md) - [Commits](expressjs/express@4.19.2...4.21.1) Updates `jpeg-js` from 0.4.3 to 0.4.4 - [Release notes](https://github.com/eugeneware/jpeg-js/releases) - [Commits](jpeg-js/jpeg-js@v0.4.3...v0.4.4) Updates `moment` from 2.29.1 to 2.30.1 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.29.1...2.30.1) Updates `send` from 0.18.0 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.18.0...0.19.0) Updates `serve-static` from 1.15.0 to 1.16.2 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/v1.16.2/HISTORY.md) - [Commits](expressjs/serve-static@v1.15.0...v1.16.2) Updates `ua-parser-js` from 0.7.27 to 0.7.39 - [Release notes](https://github.com/faisalman/ua-parser-js/releases) - [Changelog](https://github.com/faisalman/ua-parser-js/blob/0.7.39/changelog.md) - [Commits](faisalman/ua-parser-js@0.7.27...0.7.39) Updates `url-parse` from 1.5.7 to 1.5.10 - [Commits](unshiftio/url-parse@1.5.7...1.5.10) Updates `word-wrap` from 1.2.3 to 1.2.5 - [Release notes](https://github.com/jonschlinkert/word-wrap/releases) - [Commits](jonschlinkert/word-wrap@1.2.3...1.2.5) --- updated-dependencies: - dependency-name: gatsby dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: gatsby-plugin-mdx dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: loader-utils dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@sideway/formula" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: body-parser dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: devcert dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: elliptic dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jpeg-js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: moment dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ua-parser-js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: url-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: word-wrap dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
This was referenced Nov 7, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 19 updates:
2.32.11
4.25.7
1.10.1
2.14.1
2.0.0
2.0.4
2.6.7
2.7.0
3.0.0
3.0.1
1.19.0
1.20.2
4.2.1
4.2.3
0.4.1
0.4.2
0.2.0
0.2.2
1.1.3
1.2.2
6.5.4
6.6.0
4.19.2
4.21.1
0.4.3
0.4.4
2.29.1
2.30.1
0.18.0
0.19.0
1.15.0
1.16.2
0.7.27
0.7.39
1.5.7
1.5.10
1.2.3
1.2.5
Updates
gatsby
from 2.32.11 to 4.25.7Release notes
Sourced from gatsby's releases.
... (truncated)
Commits
db5eb18
chore(release): Publishfc22f4b
fix(gatsby): don't serve codeframes for files outside of compilation (#38059)...8889bfe
chore(release): Publishd3d5fd0
fix(gatsby-source-wordpress): prevent inconsistent schema customization (#377...5bdef4a
fix(gatsby): don't block event loop during inference (#37780) (#37801)50e3f94
chore(release): Publish3f8477d
chore: Update get-unowned-packages script to use npm 9 syntaxdcf88ed
fix(gatsby-plugin-sharp): don't serve static assets that are not result of cu...3be4a80
chore(release): Publish98c4d27
feat(gatsby): add initial webhook body env var to bootstrap context (#37478) ...Updates
gatsby-plugin-mdx
from 1.10.1 to 2.14.1Release notes
Sourced from gatsby-plugin-mdx's releases.
Changelog
Sourced from gatsby-plugin-mdx's changelog.
... (truncated)
Commits
4997d63
chore(release): Publishff94ed5
fix(gatsby-plugin-mdx): don't allow JS frontmatter by default (#35830) (#35834)f3f1bbc
chore(release): Publish9e09fb3
chore(release): Publish next048c7a7
chore(deps): update babel monorepo (#32996)efdf037
fix(deps): update dependency core-js to ^3.17.2 (#32980)f8f1666
chore(release): Publish next3294536
chore(changelogs): update changelogs for 3.13 release (#32970)eea2687
chore(deps): update fs-extra (major) (#32654)401b358
chore: add missing@babel/runtime
dependencies (#32954)Updates
loader-utils
from 2.0.0 to 2.0.4Release notes
Sourced from loader-utils's releases.
Changelog
Sourced from loader-utils's changelog.
Commits
6688b50
chore(release): 2.0.4ac09944
fix: ReDoS problem (#225)7162619
chore(release): 2.0.3a93cf6f
fix(security): prototype polution exploit (#217)90c7c4b
chore(release): 2.0.28c2d24e
fix: base64 generation and unicode characters (#197)5fb5562
chore(release): 2.0.11069f61
fix: md4 support on Node.js v17 (#193)Updates
node-fetch
from 2.6.7 to 2.7.0Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
9b9d458
feat:AbortError
(#1744)65ae25a
fix: Remove the default connection close header (#1765)8bc3a7c
fix: socket variable testing for undefined (#1726)afb36f6
Revert "fix: handle bom in text and json (#1739)" (#1741)29909d7
fix: handle bom in text and json (#1739)70f592d
fix: "global is not defined" (#1704)0f1ebb0
Prevent error when response is null (#1699)6e9464d
ci(release): install dependenciesdd2a0ba
ci(release): install dependencies49bef02
ci(release): use latest Node LTSMaintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
@sideway/formula
from 3.0.0 to 3.0.1Commits
5b44c1b
3.0.19fbc20a
chore: better number regex41ae98e
Cleanupc59f35e
Move to SidewayMaintainer changes
This version was pushed to npm by marsup, a new releaser for
@sideway/formula
since your current version.Updates
body-parser
from 1.19.0 to 1.20.2Release notes
Sourced from body-parser's releases.
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
ee91374
1.20.2368a93a
Fix strict json error message on Node.js 19+0385872
deps: [email protected]2c35b41
build: [email protected]f0646c2
build: [email protected]f345fb1
build: [email protected]6842efc
deps: content-type@~1.0.55af7315
build: [email protected]8e605b3
build: [email protected]cba6e77
build: [email protected]Updates
browserify-sign
from 4.2.1 to 4.2.3Changelog
Sourced from browserify-sign's changelog.
Commits
bf2c3ec
v4.2.39247adf
[patch] widen support to 0.12f427270
[Deps] update `parse-asn187f3a35
[Dev Deps] updateaud
,npmignore
,tape
fb261ce
[Deps] updateelliptic
4d0ee49
[patch] drop minimum node support to v19e2bf12
[Deps] pinhash-base
to ~3.0, due to a breaking change168e16f
[Deps] pinelliptic
due to a breaking change37a4758
[actions] remove redundant finisher4af5a90
v4.2.2Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates
cookie
from 0.4.1 to 0.4.2Release notes
Sourced from cookie's releases.
Changelog
Sourced from cookie's changelog.
Commits
55bac40
0.4.2519feb5
build: [email protected]fadc4bc
build: [email protected]009b3cb
pref: read value only when assigning in parse04be428
lint: remove deprecated String.prototype.substr2dc6662
bench: preserve decode behavior for top cookiesaa1a335
pref: remove unnecessary regexp in parse2bcee5a
bench: add cookies from top 20 sites4f08c95
docs: update benchmarkf056356
build: [email protected]Updates
decode-uri-component
from 0.2.0 to 0.2.2Release notes
Sourced from decode-uri-component's releases.
Commits
a0eea46
0.2.2980e0bf
Prevent overwriting previously decoded tokens3c8a373
0.2.176abc93
Switch to GitHub workflows746ca5d
Fix issue where decode throws - fixes #6486d7e2
Update license (#1)a650457
Tidelift tasks66e1c28
Meta tweaksUpdates
devcert
from 1.1.3 to 1.2.2Commits
2f42b5a
1.2.283dd841
Allow subdomains and localhost in new domain validator (#84)1ed164f
1.2.1b076321
switch from vulnerable VALID_DOMAIN regex to is-valid-domain lib (#79)fecd645
1.2.092a14f8
chore: bring lockfiles currentbe273aa
Feature: Allow multiple Subject Alternative Name (SAN) extensions (#52)Maintainer changes
This version was pushed to npm by jzetlen, a new releaser for devcert since your current version.
Updates
elliptic
from 6.5.4 to 6.6.0Commits
b8a7edd
6.6.034c8534
fix: signature verification due to leading zeros3e46a48
6.5.7accb61e
lib: DER signature decoding correction03e06e1
6.5.67ac5360
Merge commit from fork7570078
6.5.5206da2e
lib: lint0a78e03
[Fix] restore node < 4 compatUpdates
express
from 4.19.2 to 4.21.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
8e229f9
4.21.1a024c8a
fix(deps): [email protected]7e562c6
4.21.01bcde96
fix(deps): [email protected] (#5946)7d36477
fix(deps): [email protected] (#5951)40d2d8f
fix(deps): [email protected]77ada90
Deprecate"back"
magic string in redirects (#5935)21df421
4.20.04c9ddc1
feat: upgrade to [email protected]9ebe5d5
feat: upgrade to [email protected] (#5928)Updates
jpeg-js
from 0.4.3 to 0.4.4Release notes
Sourced from jpeg-js's releases.
Commits
9ccd35f
fix: validate sampling factors (#106)b58cc11
fix(decoder): rethrow a more helpful error if Buffer is undefined (#93)2c90858
chore(deps): bump y18n from 4.0.0 to 4.0.3 (#98)fd73289
chore(deps): bump ws from 7.2.3 to 7.4.6 (#91)9449a8b
chore(deps): bump hosted-git-info from 2.8.8 to 2.8.9 (#90)ffdc4a4
chore(deps): bump lodash from 4.17.15 to 4.17.21 (#89)13e1ffa
feat: add comment tag encoding (#87)417e8e2
chore(ci): migrate to github actions (#86)Updates
moment
from 2.29.1 to 2.30.1Changelog
Sourced from moment's changelog.