forked from OWASP/NodeGoat
-
Notifications
You must be signed in to change notification settings - Fork 1
Bump the npm_and_yarn group across 1 directory with 17 updates #60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
master
Choose a base branch
from
dependabot/npm_and_yarn/npm_and_yarn-736f231d91
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [marked](https://github.com/markedjs/marked) | `0.3.5` | `4.0.10` | | [mongodb](https://github.com/mongodb/node-mongodb-native) | `2.2.36` | `3.1.13` | | [underscore](https://github.com/jashkenas/underscore) | `1.9.1` | `1.13.7` | | [debug](https://github.com/debug-js/debug) | `3.2.6` | `3.2.7` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.12` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.5.5` | `3.14.1` | | [dot-prop](https://github.com/sindresorhus/dot-prop) | `4.2.0` | `4.2.1` | | [qs](https://github.com/ljharb/qs) | `6.5.2` | `6.5.3` | | [qs](https://github.com/ljharb/qs) | `6.3.2` | `6.3.3` | | [mixin-deep](https://github.com/jonschlinkert/mixin-deep) | `1.3.1` | `1.3.2` | | [y18n](https://github.com/yargs/y18n) | `3.2.1` | `3.2.2` | | [set-value](https://github.com/jonschlinkert/set-value) | `2.0.0` | `2.0.1` | | [websocket-extensions](https://github.com/faye/websocket-extensions-node) | `0.1.3` | `0.1.4` | Updates `marked` from 0.3.5 to 4.0.10 - [Release notes](https://github.com/markedjs/marked/releases) - [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json) - [Commits](markedjs/marked@v0.3.5...v4.0.10) Updates `mongodb` from 2.2.36 to 3.1.13 - [Release notes](https://github.com/mongodb/node-mongodb-native/releases) - [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md) - [Commits](mongodb/node-mongodb-native@v2.2.36...v3.1.13) Updates `underscore` from 1.9.1 to 1.13.7 - [Commits](jashkenas/underscore@1.9.1...1.13.7) Updates `debug` from 3.2.6 to 3.2.7 - [Release notes](https://github.com/debug-js/debug/releases) - [Commits](debug-js/debug@3.2.6...3.2.7) Updates `bl` from 1.0.3 to 1.1.2 - [Release notes](https://github.com/rvagg/bl/releases) - [Changelog](https://github.com/rvagg/bl/blob/master/CHANGELOG.md) - [Commits](rvagg/bl@v1.0.3...v1.1.2) Updates `brace-expansion` from 1.1.11 to 1.1.12 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.12) Updates `js-yaml` from 3.5.5 to 3.14.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.5.5...3.14.1) Updates `tough-cookie` from 2.2.2 to 2.3.1 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.2.2...v2.3.1) Updates `dot-prop` from 4.2.0 to 4.2.1 - [Release notes](https://github.com/sindresorhus/dot-prop/releases) - [Commits](sindresorhus/dot-prop@v4.2.0...v4.2.1) Updates `minimatch` from 0.3.0 to 3.0.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v0.3.0...v3.0.2) Updates `qs` from 6.5.2 to 6.5.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.2...v6.5.3) Updates `qs` from 6.3.2 to 6.3.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.2...v6.5.3) Updates `hawk` from 1.0.0 to 3.1.3 - [Release notes](https://github.com/mozilla/hawk/releases) - [Commits](mozilla/hawk@v1.0.0...v3.1.3) Updates `hoek` from 0.9.1 to 2.16.3 - [Release notes](https://github.com/hapijs/hoek/releases) - [Commits](hapijs/hoek@v0.9.1...v2.16.3) Updates `mixin-deep` from 1.3.1 to 1.3.2 - [Commits](jonschlinkert/mixin-deep@1.3.1...1.3.2) Updates `y18n` from 3.2.1 to 3.2.2 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](https://github.com/yargs/y18n/commits) Updates `set-value` from 2.0.0 to 2.0.1 - [Commits](jonschlinkert/set-value@2.0.0...2.0.1) Updates `websocket-extensions` from 0.1.3 to 0.1.4 - [Changelog](https://github.com/faye/websocket-extensions-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-extensions-node@0.1.3...0.1.4) --- updated-dependencies: - dependency-name: marked dependency-version: 4.0.10 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: mongodb dependency-version: 3.1.13 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: underscore dependency-version: 1.13.7 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: debug dependency-version: 3.2.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: bl dependency-version: 1.1.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-version: 3.14.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tough-cookie dependency-version: 2.3.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: dot-prop dependency-version: 4.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 3.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-version: 6.5.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-version: 6.3.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hawk dependency-version: 3.1.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hoek dependency-version: 2.16.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: mixin-deep dependency-version: 1.3.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-version: 3.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: set-value dependency-version: 2.0.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: websocket-extensions dependency-version: 0.1.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update javascript code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.



Bumps the npm_and_yarn group with 12 updates in the / directory:
0.3.54.0.102.2.363.1.131.9.11.13.73.2.63.2.71.1.111.1.123.5.53.14.14.2.04.2.16.5.26.5.36.3.26.3.31.3.11.3.23.2.13.2.22.0.02.0.10.1.30.1.4Updates
markedfrom 0.3.5 to 4.0.10Release notes
Sourced from marked's releases.
... (truncated)
Commits
ae01170chore(release): 4.0.10 [skip ci]fceda57🗜️ build [skip ci]8f80657fix(security): fix redos vulnerabilitiesc4a3ccdMerge pull request from GHSA-rrrm-qjm4-v8hfd7212a6chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (#2352)5a84db5chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (#2350)2bc67a5chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (#2351)98996b8chore(deps-dev): Bump@babel/preset-envfrom 7.16.5 to 7.16.7 (#2353)ebc2c95chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (#2354)e5171a9chore(release): 4.0.9 [skip ci]Maintainer changes
This version was pushed to npm by tonybrix, a new releaser for marked since your current version.
Updates
mongodbfrom 2.2.36 to 3.1.13Changelog
Sourced from mongodb's changelog.
... (truncated)
Commits
c6f417echore(release): 3.1.13210c71dfix(db_ops): ensure we async resolve errors in createCollection5ad9fa9fix(changeStream): properly handle changeStream event mid-close (#1902)e806be4fix(bulk): honor ignoreUndefined in initializeUnorderedBulkOp050267dfix(*): restore ability to webpack by removingmakeLazyLoader6e896f4docs: adding aggregation, createIndex, and runCommand examplescb3cd12chore(release): 3.1.12508d685Revert "chore(release): 3.2.0"e7619aachore(release): 3.2.0d0dc228chore(travis): include forgotten stage info for sharded buildsUpdates
underscorefrom 1.9.1 to 1.13.7Commits
d2e7e61Update autogenerated files for 1.13.7b1d4f23Add a change log entry for 1.13.7473970aBump the copyright yearsa1cbb48Bump the version to 1.13.71205eb5Merge pull request #2996 from elkcityhazard/feature/theme-togglebd3468beven more css formattingdd23fd0formatting, filter, darker darkmode184aae5unncessary prefers-color-scheme: light removal55720c0minimal dark mode implementationde20b6fincorporated stylesheet that was already availableMaintainer changes
This version was pushed to npm by jgonggrijp, a new releaser for underscore since your current version.
Updates
debugfrom 3.2.6 to 3.2.7Commits
33832603.2.74e21502fix regressionMaintainer changes
This version was pushed to npm by qix, a new releaser for debug since your current version.
Updates
blfrom 1.0.3 to 1.1.2Commits
ea420211.1.2950e9dbminor formatting tweaks, name functions62a04991.1.1cbb1429unwrap bl children when passed to append() & support bl in constructorc72ba4e1.1.0Updates
brace-expansionfrom 1.1.11 to 1.1.12Release notes
Sourced from brace-expansion's releases.
Commits
44f33b41.1.12c460dbdpkg: publish on tag 1.xccb8ac6fmtc3c73c8Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
js-yamlfrom 3.5.5 to 3.14.1Changelog
Sourced from js-yaml's changelog.
... (truncated)
Commits
37caaad3.14.1 released094c0f7dist rebuild9586ebeAvoid calling hasOwnProperty of user-controlled objects34e50723.14.0 released7b25c83Browser files rebuild6f73473Dev deps bump0c29349Travis-CI: drop old nodejs versions10be97efix(loader): Add support forsafe/loadAll(input, options)d6983ddFix issue #526: wrong quote position writing condensed flow (#527)93fbf7dfix issue 526 (wrong quote position writing condensed flow)Updates
tough-cookiefrom 2.2.2 to 2.3.1Commits
c11a2d12.3.14c0a3adMerge pull request #69 from SalesforceEng/restore-back-compatb24c17fRestore backwards compatibility to node 0.85d155792.3.06156272Merge pull request #68 from SalesforceEng/fix-too-many-semicolonse4fc2e0Reduce parse time for many semicolons.ce76918Test on 4.4 until Travis supports --lts72820beSupport 4.0 (minimum), lts, and stable43dc0d6Merge pull request #65 from ide/patch-11fbeb07Add links to 3rd party stores to the READMEMaintainer changes
This version was pushed to npm by jstash, a new releaser for tough-cookie since your current version.
Updates
dot-propfrom 4.2.0 to 4.2.1Release notes
Sourced from dot-prop's releases.
Commits
c914124feat: patch 4.2.0 with fixes for CVE-2020-8116Updates
minimatchfrom 0.3.0 to 3.0.2Changelog
Sourced from minimatch's changelog.
... (truncated)
Commits
81edb7cv3.0.26944abfHandle extremely long and terrible patterns more gracefully8ac560ev3.0.14f3a8bcupdate tap9cf2d88Remove mentions of cache from readme7df236fUse svg instead of png to get better image quality361f803Fixes spelling mistake from "instanting" to "instantiating"ea0c690update travis270dbeav3.0.0668a1f4Don't package browser versionMaintainer changes
This version was pushed to npm by isaacs, a new releaser for minimatch since your current version.
Updates
qsfrom 6.5.2 to 6.5.3Changelog
Sourced from qs's changelog.
Commits
298bfa5v6.5.3ed0f5dc[Fix]parse: ignore__proto__keys (#428)691e739[Robustness]stringify: avoid relying on a globalundefined(#427)1072d57[readme] remove travis badge; add github actions/codecov badges; update URLs12ac1c4[meta] fix README.md (#399)0338716[actions] backport actions from main5639c20Clean up license text so it’s properly detected as BSD-3-Clause51b8a0badd FUNDING.yml45f6759[Fix] fix for an impossible situation: when the formatter is called with a no...f814a7f[Dev Deps] backport from mainUpdates
qsfrom 6.3.2 to 6.3.3Changelog
Sourced from qs's changelog.
Commits
298bfa5v6.5.3ed0f5dc[Fix]parse: ignore__proto__keys (#428)691e739[Robustness]stringify: avoid relying on a globalundefined(#427)1072d57[readme] remove travis badge; add github actions/codecov badges; update URLs12ac1c4[meta] fix README.md (#399)0338716[actions] backport actions from main5639c20Clean up license text so it’s properly detected as BSD-3-Clause51b8a0badd FUNDING.yml45f6759[Fix] fix for an impossible situation: when the formatter is called with a no...f814a7f[Dev Deps] backport from mainUpdates
hawkfrom 1.0.0 to 3.1.3Commits
2f0b93bcleanup8a955a33.1.3bef99aeMerge pull request #171 from remy/fix/ddos-on-3dotxbb5cf9cClean linting on client.js3fd1e20Add tests for DoS via headerccebde4Fix minor DoS attack on long headers or uris.66dd8f93.1.210daa13Cleanup for #1485e72fa2Merge pull request #148 from LeviticusMB/parseUri-fix9feb3f4Rewrite parseUri to handle unusual but valid URI characters.Updates
hoekfrom 0.9.1 to 2.16.3Commits
20f36e82.16.314113f7dont fail when getOwnPropertyDescriptor returns undefined, closes #16259e62cf2.16.2a09325dallow empty keys, closes #161b5a57552.16.1e40c16acleanup for #148008ac4e2.16.04db71b6Merge pull request #159 from Marsup/empty-reach17456e3Allow reach to work with falsy values (empty str)131fce02.15.0Updates
mixin-deepfrom 1.3.1 to 1.3.2Commits
754f0c21.3.290ee1faensure keys are valid when mixing in valuesMaintainer changes
This version was pushed to npm by doowb, a new releaser for mixin-deep since your current version.
Updates
y18nfrom 3.2.1 to 3.2.2Release notes
Sourced from y18n's releases.
Commits
Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for y18n since your current version.
Updates
set-valuefrom 2.0.0 to 2.0.1Commits
bb0f0382.0.1cb12f14ensure only valid keys are usedMaintainer changes
This version was pushed to npm by doowb, a new releaser for set-value since your current version.
Updates
websocket-extensionsfrom 0.1.3 to 0.1.4Changelog
Sourced from websocket-extensions's changelog.
Commits
5ea0b42Bump version to 0.1.429496f6Remove ReDoS vulnerability in the Sec-WebSocket-Extensions header parser4a76c75Add Node versions 13 and 14 on Travis44a677aFormatting change: {...} should have spaces inside the bracesf6c50abLet npm reformat package.json2d211f3Change markdown formatting of docs.0b62083Update Travis target versions.729a465Switch license to Apache 2.0.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.