-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): bump the npm_and_yarn group across 6 directories with 18 updates #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
… updates Bumps the npm_and_yarn group with 3 updates in the / directory: [send](https://github.com/pillarjs/send), [pug](https://github.com/pugjs/pug) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the npm_and_yarn group with 3 updates in the /dev/coverage-action directory: [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js), [@octokit/request](https://github.com/octokit/request.js) and [undici](https://github.com/nodejs/undici). Bumps the npm_and_yarn group with 2 updates in the /dev/del-old-packages directory: [@octokit/request](https://github.com/octokit/request.js) and [@octokit/core](https://github.com/octokit/core.js). Bumps the npm_and_yarn group with 4 updates in the /dev/deploy-to-container directory: [cross-spawn](https://github.com/moxystudio/node-cross-spawn), [nanoid](https://github.com/ai/nanoid), [tar-fs](https://github.com/mafintosh/tar-fs) and [dockerode](https://github.com/apocas/dockerode). Bumps the npm_and_yarn group with 3 updates in the /dev/diff directory: [cross-spawn](https://github.com/moxystudio/node-cross-spawn), [tar-fs](https://github.com/mafintosh/tar-fs) and [dockerode](https://github.com/apocas/dockerode). Bumps the npm_and_yarn group with 6 updates in the /playwright directory: | Package | From | To | | --- | --- | --- | | [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` | | [cross-spawn](https://github.com/moxystudio/node-cross-spawn) | `7.0.3` | `7.0.6` | | [ip](https://github.com/indutny/node-ip) | `2.0.0` | `removed` | | [socks](https://github.com/JoshGlazebrook/socks) | `2.7.1` | `2.8.4` | | [semver](https://github.com/npm/node-semver) | `6.3.0` | `7.5.4` | | [tar](https://github.com/isaacs/node-tar) | `6.1.15` | `6.2.1` | Updates `send` from 0.18.0 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.18.0...0.19.0) Updates `pug` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug@3.0.2...pug@3.0.3) Updates `vite` from 4.5.3 to 4.5.14 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v4.5.14/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v4.5.14/packages/vite) Updates `pug-code-gen` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug-code-gen@3.0.2...pug-code-gen@3.0.3) Updates `@octokit/plugin-paginate-rest` from 9.0.0 to 9.2.2 - [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases) - [Commits](octokit/plugin-paginate-rest.js@v9.0.0...v9.2.2) Updates `@octokit/request` from 8.1.4 to 8.4.1 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v8.1.4...v8.4.1) Updates `@octokit/request-error` from 5.0.1 to 5.1.1 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v5.0.1...v5.1.1) Updates `undici` from 5.26.4 to 5.29.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v5.26.4...v5.29.0) Updates `@octokit/request` from 6.2.2 to 10.0.2 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v8.1.4...v8.4.1) Updates `@octokit/core` from 4.2.4 to 7.0.2 - [Release notes](https://github.com/octokit/core.js/releases) - [Commits](octokit/core.js@v4.2.4...v7.0.2) Updates `@octokit/request-error` from 3.0.2 to 7.0.0 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v5.0.1...v5.1.1) Updates `cross-spawn` from 7.0.3 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6) Updates `nanoid` from 5.0.9 to 5.1.5 - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@5.0.9...5.1.5) Updates `tar-fs` from 2.0.1 to 2.1.3 - [Commits](https://github.com/mafintosh/tar-fs/commits) Updates `dockerode` from 4.0.4 to 4.0.6 - [Release notes](https://github.com/apocas/dockerode/releases) - [Commits](apocas/dockerode@v4.0.4...v4.0.6) Updates `cross-spawn` from 7.0.3 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6) Updates `tar-fs` from 2.0.1 to 2.1.3 - [Commits](https://github.com/mafintosh/tar-fs/commits) Updates `dockerode` from 4.0.4 to 4.0.6 - [Release notes](https://github.com/apocas/dockerode/releases) - [Commits](apocas/dockerode@v4.0.4...v4.0.6) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `cross-spawn` from 7.0.3 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6) Removes `ip` Updates `socks` from 2.7.1 to 2.8.4 - [Release notes](https://github.com/JoshGlazebrook/socks/releases) - [Commits](JoshGlazebrook/socks@2.7.1...2.8.4) Updates `semver` from 6.3.0 to 7.5.4 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v6.3.0...v7.5.4) Updates `tar` from 6.1.15 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.15...v6.2.1) --- updated-dependencies: - dependency-name: send dependency-version: 0.19.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: pug dependency-version: 3.0.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 4.5.14 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: pug-code-gen dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/plugin-paginate-rest" dependency-version: 9.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 8.4.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request-error" dependency-version: 5.1.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 5.29.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 10.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/core" dependency-version: 7.0.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@octokit/request-error" dependency-version: 7.0.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nanoid dependency-version: 5.1.5 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tar-fs dependency-version: 2.1.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: dockerode dependency-version: 4.0.6 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar-fs dependency-version: 2.1.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: dockerode dependency-version: 4.0.6 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: braces dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ip dependency-version: dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: socks dependency-version: 2.8.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-version: 7.5.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 6.2.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the npm_and_yarn group with 3 updates in the / directory: send, pug and vite.
Bumps the npm_and_yarn group with 3 updates in the /dev/coverage-action directory: @octokit/plugin-paginate-rest, @octokit/request and undici.
Bumps the npm_and_yarn group with 2 updates in the /dev/del-old-packages directory: @octokit/request and @octokit/core.
Bumps the npm_and_yarn group with 4 updates in the /dev/deploy-to-container directory: cross-spawn, nanoid, tar-fs and dockerode.
Bumps the npm_and_yarn group with 3 updates in the /dev/diff directory: cross-spawn, tar-fs and dockerode.
Bumps the npm_and_yarn group with 6 updates in the /playwright directory:
3.0.23.0.37.0.37.0.62.0.0removed2.7.12.8.46.3.07.5.46.1.156.2.1Updates
sendfrom 0.18.0 to 0.19.0Release notes
Sourced from send's releases.
Changelog
Sourced from send's changelog.
Commits
9d2db990.19.0ae4f298Merge commit from forkMaintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for send since your current version.
Updates
pugfrom 3.0.2 to 3.0.3Release notes
Sourced from pug's releases.
Commits
32acfe8fix: ensure template names are valid identifiers (#3438)4767cafrefactor: convert pug-error to TypeScript (#3355)a724446chore: update character-parser (#3354)6cca8f7docs: fix GitHub format in README (#3335)Updates
vitefrom 4.5.3 to 4.5.14Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
9bfe2b1release: v4.5.147739479fix: backport #19965, check static serve file inside sirv (#19967)99afb60chore: run formatcd60e8brelease: v4.5.1341f3819fix: backport #19830, reject requests with#in request-target (#19832)6104addrelease: v4.5.120a3dcf5fix: backport #19782, fs check with svg and relative paths (#19785)07ddc3erelease: v4.5.1126e1764fix: backport #19761, fs check in transform middleware (#19763)86e7a6brelease: v4.5.10Updates
pug-code-genfrom 3.0.2 to 3.0.3Release notes
Sourced from pug-code-gen's releases.
Commits
32acfe8fix: ensure template names are valid identifiers (#3438)4767cafrefactor: convert pug-error to TypeScript (#3355)a724446chore: update character-parser (#3354)6cca8f7docs: fix GitHub format in README (#3335)d4b7f60Properly handle errors originating from included files when compileDebug is e...d6f0615fix capture groups for "each" statements (#3274)73ea7cffix: keep lexer plugins inside tag interpolation (#3296)29a53c5fix: Fix pug-lexer parsed escaped interpolations incorrectly (#3299)60b1b15chore: update supported versions (#3315)Updates
@octokit/plugin-paginate-restfrom 9.0.0 to 9.2.2Release notes
Sourced from
@octokit/plugin-paginate-rest's releases.... (truncated)
Commits
e1e4489fix: ReDos regex vulnerability, reported by@DayShift(#660)5b84386fix(pkg): pin@octokit/corepeerDependency to v5 (#599)fa01f94ci(action): update actions/add-to-project action to v0.6.0 (#598)75aeaaffeat: new/orgs/{org}/organization-roles/{role_id}/teamsand `/orgs/{org}/o...54d6bcfchore(deps): update dependency prettier to v3.2.51bfa2f8chore(deps): update dependency npm-run-all2 to v6eb4a8fechore(deps): replace dependency npm-run-all with npm-run-all2 ^5.0.011ef779chore(deps): update dependency esbuild to ^0.20.02b6cc98ci(action): update peter-evans/create-or-update-comment action to v4d7c9de5chore(deps): update dependency prettier to v3.2.4 (#588)Updates
@octokit/requestfrom 8.1.4 to 8.4.1Release notes
Sourced from
@octokit/request's releases.... (truncated)
Commits
356411efix: ReDos regex vulnerability, reported by@DayShift(#741)abc4955feat: re-addredirectrequest option (#636)4e7127cfix: upgrade@octokit/endpoint2e67925feat(security): Add provenance (#685)6822e8bfix: upgrade@octokit/typesdbfeab2feat: add documentation link in error message (#667)c013de4docs: fix spelling errors (#671)3d22c38chore(deps): update dependency prettier to v3.2.5984ec17chore(deps): update dependency esbuild to ^0.20.02a9cf78ci(action): update peter-evans/create-or-update-comment action to v4Updates
@octokit/request-errorfrom 5.0.1 to 5.1.1Release notes
Sourced from
@octokit/request-error's releases.Commits
b51ed27test: ReDos regex vulnerability, reported by@dayshift12a14f0fix: ReDos regex vulnerability, reported by@dayshift3af20bdfix: upgrade@octokit/typesto v1394147e8feat(security): Add provenance (#416)Updates
undicifrom 5.26.4 to 5.29.0Release notes
Sourced from undici's releases.
... (truncated)
Commits
9528f68Bumped v5.29.0f1d75a4increase timeout for redirect test2d31ed6remove fuzzing tests6b36d49fix redirect test in Node v16648dd8fmore fix for the wpt runner on Windowsa0516badon't use internal header state for cookies (#3295)87ce4affix test/client for node 20c2c8fd5fix: accept v20 SSL specific error for alpn selection in http/282200bd[v6.x] fix wpts on windows (#4093)47546fatest: fix windows wpt (#4050)Updates
@octokit/requestfrom 6.2.2 to 10.0.2Release notes
Sourced from
@octokit/request's releases.... (truncated)
Commits
356411efix: ReDos regex vulnerability, reported by@DayShift(#741)abc4955feat: re-addredirectrequest option (#636)4e7127cfix: upgrade@octokit/endpoint2e67925feat(security): Add provenance (#685)6822e8bfix: upgrade@octokit/typesdbfeab2feat: add documentation link in error message (#667)c013de4docs: fix spelling errors (#671)3d22c38chore(deps): update dependency prettier to v3.2.5984ec17chore(deps): update dependency esbuild to ^0.20.02a9cf78ci(action): update peter-evans/create-or-update-comment action to v4Updates
@octokit/corefrom 4.2.4 to 7.0.2Release notes
Sourced from
@octokit/core's releases.... (truncated)
Commits
629fa4efix(deps): update octokit monorepo (major) (#742)1aba598chore(deps): update dependency undici to v7 (#711)2abf89efix(deps): update dependency before-after-hook to v4 (#739)78747bfci: stop testing against NodeJS v18 (#738)38dd554chore(deps): update dependency undici to v6.21.2 [security] (#741)f7cb18fbuild: remove glob (#737)22243bdchore(deps): bump vite from 6.2.6 to 6.3.4 (#735)e0d36c5ci: replaceOCTOKITBOT_PROJECT_ACTION_TOKENandOCTOKITBOT_PATwith a tok...e72adddchore(deps): bump vite from 6.2.5 to 6.2.6 (#733)3700c41fix(deps): update dependency@octokit/typesto v14 (#731)Updates
@octokit/request-errorfrom 3.0.2 to 7.0.0Release notes
Sourced from
@octokit/request-error's releases.Commits
b51ed27test: ReDos regex vulnerability, reported by@dayshift12a14f0fix: ReDos regex vulnerability, reported by@dayshift3af20bdfix: upgrade@octokit/typesto v1394147e8feat(security): Add provenance (#416)Updates
cross-spawnfrom 7.0.3 to 7.0.6Changelog
Sourced from cross-spawn's changelog.
Commits
77cd97fchore(release): 7.0.66717de4chore: upgrade standard-versionf700743fix: update cross-spawn version to 7.0.5 in package-lock.json9a7e3b2chore: fix build status badge0852683chore(release): 7.0.5640d391fix: fix escaping bug introduced by backtrackingbff0c87chore: remove codecova7c6abcchore: replace travis with github workflows9b9246echore(release): 7.0.45ff3a07fix: disable regexp backtracking (#160)Updates
nanoidfrom 5.0.9 to 5.1.5Release notes
Sourced from nanoid's releases.
Changelog
Sourced from nanoid's changelog.
Commits
5b1220dRelease 5.1.5 versione62fd22Backport changes from 3.x991dc53Update benchmark523a74eRelease 5.1.4 version7772155Backport Changelog changes from v38e456c2Update dependencies29025b2Add the first PR author2839aacFix merge conflict50b6d96Fix Expo, #468 (#515)32bc9bfRelease 5.1.3 versionUpdates
tar-fsfrom 2.0.1 to 2.1.3Commits
Updates
dockerodefrom 4.0.4 to 4.0.6Release notes
Sourced from dockerode's releases.
Commits
3f68f9bimage.inspect otpsb15fc4bMerge pull request #800 from jpinz/inspect-manifest-param23a36b0Update image.inspect calls to accept undefined as the first argument for the ...4078c78Merge branch 'apocas:master' into inspect-manifest-param0f2ce8bversion bump02d4bdaMerge pull request #801 from apocas/dependabot/npm_and_yarn/tar-fs-2.1.2d225327Bump tar-fs from 2.0.1 to 2.1.29d35666Update image.inspect method to accept options7d73e87Merge pull request #793 from pipex/build-image-from-cache88597ccUse JSON serialization for cachefrom optionUpdates
cross-spawnfrom 7.0.3 to 7.0.6Changelog
Sourced from cross-spawn's changelog.
Commits
77cd97fchore(release): 7.0.66717de4chore: upgrade standard-versionf700743fix: update cross-spawn version to 7.0.5 in package-lock.json9a7e3b2chore: fix build status badge0852683chore(release): 7.0.5640d391fix: fix escaping bug introduced by backtrackingbff0c87chore: remove codecov