chore(deps): bump the gutenberg-security group across 1 directory with 12 updates#105
Conversation
…h 12 updates Bumps the gutenberg-security group with 8 updates in the /modules/gutenberg directory: | Package | From | To | | --- | --- | --- | | [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.28.5` | `7.29.7` | | [tar-fs](https://github.com/mafintosh/tar-fs) | `2.1.1` | `3.1.2` | | [qs](https://github.com/ljharb/qs) | `6.5.3` | `6.15.2` | | [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.2` | | [ip-address](https://github.com/beaugunderson/ip-address) | `10.1.0` | `10.2.0` | | [node-forge](https://github.com/digitalbazaar/forge) | `1.3.3` | `1.4.0` | | [svgo](https://github.com/svg/svgo) | `3.3.2` | `3.3.3` | | [tmp](https://github.com/raszi/node-tmp) | `0.2.5` | `0.2.7` | Updates `@babel/plugin-transform-modules-systemjs` from 7.28.5 to 7.29.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.7/packages/babel-plugin-transform-modules-systemjs) Updates `tar-fs` from 2.1.1 to 3.1.2 - [Commits](mafintosh/tar-fs@v2.1.1...v3.1.2) Updates `axios` from 1.13.2 to 1.18.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.13.2...v1.18.0) Updates `basic-ftp` from 5.1.0 to 5.3.1 - [Release notes](https://github.com/patrickjuchli/basic-ftp/releases) - [Changelog](https://github.com/patrickjuchli/basic-ftp/blob/master/CHANGELOG.md) - [Commits](patrickjuchli/basic-ftp@v5.1.0...v5.3.1) Updates `qs` from 6.5.3 to 6.15.2 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.3...v6.15.2) Updates `fast-uri` from 3.1.0 to 3.1.2 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.0...v3.1.2) Updates `follow-redirects` from 1.15.11 to 1.16.0 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.15.11...v1.16.0) Updates `ip-address` from 10.1.0 to 10.2.0 - [Commits](beaugunderson/ip-address@v10.1.0...v10.2.0) Updates `node-forge` from 1.3.3 to 1.4.0 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@v1.3.3...v1.4.0) Updates `uuid` from 3.4.0 to 8.3.2 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v3.4.0...v8.3.2) Updates `svgo` from 3.3.2 to 3.3.3 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v3.3.2...v3.3.3) Updates `tmp` from 0.2.5 to 0.2.7 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](raszi/node-tmp@v0.2.5...v0.2.7) --- updated-dependencies: - dependency-name: "@babel/plugin-transform-modules-systemjs" dependency-version: 7.29.7 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: tar-fs dependency-version: 3.1.2 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: axios dependency-version: 1.18.0 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: basic-ftp dependency-version: 5.3.1 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: qs dependency-version: 6.15.2 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: fast-uri dependency-version: 3.1.2 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: follow-redirects dependency-version: 1.16.0 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: ip-address dependency-version: 10.2.0 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: node-forge dependency-version: 1.4.0 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: uuid dependency-version: 8.3.2 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: svgo dependency-version: 3.3.3 dependency-type: indirect dependency-group: gutenberg-security - dependency-name: tmp dependency-version: 0.2.7 dependency-type: indirect dependency-group: gutenberg-security ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the gutenberg-security group with 8 updates in the /modules/gutenberg directory:
7.28.57.29.72.1.13.1.26.5.36.15.23.1.03.1.210.1.010.2.01.3.31.4.03.3.23.3.30.2.50.2.7Updates
@babel/plugin-transform-modules-systemjsfrom 7.28.5 to 7.29.7Release notes
Sourced from @babel/plugin-transform-modules-systemjs's releases.
... (truncated)
Commits
4fba754v7.29.7a458f66v7.29.432ebd5a[7.x backport]fix(systemjs): improve module string name support (#17974)aa8394ev7.29.00053db6Update polyfill packages (#17727)Updates
tar-fsfrom 2.1.1 to 3.1.2Commits
522415f3.1.2c6206bbfix missing xfs and tweaks0aa57de3.1.10bd54cdexpand checkcb1c5713.1.0374460eadd optional disablement of symlink validation (#119)5bfe6df3.0.1063e12f9bare support2ceedf43.0.9647447bcheck windows tweak (#115)Updates
axiosfrom 1.13.2 to 1.18.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
2d06f96chore(release): prepare release 1.18.0 (#11003)32fc489fix: malformed http urls (#11000)b40ce49chore(deps-dev): bump the development_dependencies group with 10 updates (#10...fe964f9docs: mark proxy config as Node.js only (#10995)5f229d2chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...fae9d4edocs: clarify package update PR policy (#10992)28ab2cechore(deps-dev): bump the development_dependencies group with 2 updates (#10989)a8e4f13fix(core): keep default validateStatus when request passes undefined (#10899)614f455docs: publish v1.17.0 release notes (#10988)6bb12c1fix: custom auth headers not stripped on cross-origin redirects (#10892)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for axios since your current version.
Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
basic-ftpfrom 5.1.0 to 5.3.1Release notes
Sourced from basic-ftp's releases.
Changelog
Sourced from basic-ftp's changelog.
Commits
980371bGuard against unbounded control response50827c7Adjust changelog to match release notesc9378a8Fix test22abe43Update Github Actions0feaaecFix test6629d7dImprove error message9c3bf4fSet higher default value for max size of directory listingacd3942Bump version1304429Offer maxListingBytes as an option5cb5367Add bounded StringWriterMaintainer changes
This version was pushed to npm by patrickjuchli, a new releaser for basic-ftp since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
qsfrom 6.5.3 to 6.15.2Changelog
Sourced from qs's changelog.
... (truncated)
Commits
9aca407v6.15.25e33d33[Dev Deps] update@ljharb/eslint-config21f80b3[Fix]stringify: skip null/undefined entries inarrayFormat: 'comma'+ `e...a0a81ea[Fix]stringify: use configureddelimiteraftercharsetSentinele3062f7[Fix]stringify: applyformatterto encoded key understrictNullHandling0c180a4[Fix]stringify: skip null/undefined filter-array entries instead of crashi...3a8b94a[Tests] add regression tests for keys containing percent-encoded bracket text96755ab[readme] fix grammara419ce5[Fix]parse: handle nested bracket groups and add regression tests3f5e1c5v6.15.1Updates
fast-urifrom 3.1.0 to 3.1.2Release notes
Sourced from fast-uri's releases.
Commits
919dd8eBumped v3.1.2c65ba57fixup: linting6c86c17Merge commit from forka95158aHandle malformed fragment decoding without throwing (#171)cea547cBumped v3.1.1876ce79Merge commit from forkdcdf690ci: add lock-threads workflow (#169)c860e65build(deps-dev): bump neostandard from 0.12.2 to 0.13.0 (#167)9b4c6dcbuild(deps): bump fastify/workflows/.github/workflows/plugins-ci.yml (#166)85d09a9build(deps): bump fastify/workflows/.github/workflows/plugins-ci-package-mana...Updates
follow-redirectsfrom 1.15.11 to 1.16.0Commits
0c23a22Release version 1.16.0 of the npm package.844c4d3Add sensitiveHeaders option.5e8b8d0ci: add Node.js 24.x to the CI matrix7953e22ci: upgrade GitHub Actions to use setup-node@v6 and checkout@v686dc1f8Sanitizing input.Updates
ip-addressfrom 10.1.0 to 10.2.0Commits
80fccaa10.2.0abaeb4dType Address4.addressMinusSuffix as non-nilable (closes #143)2878c29Preserve subnet prefix through Address6.to4() (closes #123) (#203)586666eReject trailing junk in Address6.fromURL (closes #158) (#202)80bc76eValidate static factories instead of silently overflowing (#201)98927beClarify isValid() accepts CIDRs with host bits set (#81)a0eb073Fix getScope() and broaden getType() classification (closes #122) (#200)ec52105Add networkForm() for CIDR network-address strings (#199)a9443a7Add isMapped4() predicate for IPv4-mapped IPv6 addresses (closes #62) (#198)f01d742Add address-property predicates (private, ULA, loopback, link-local, etc.) (#...Updates
node-forgefrom 1.3.3 to 1.4.0Changelog
Sourced from node-forge's changelog.
... (truncated)
Commits
fa385f9Release 1.4.0.07d4e16Update changelog.cb90fd9Update changelog.963e7c5Add unit test for "pseudonym"f0b6f5bAdd pseudonym OID3df48a3Fix missing CVE ID.2e49283Add x509basicConstraintscheck.bdecf11Add canonical signature scaler check for S < L.af094e6Add RSA padding and DigestInfo length checks.796eeb1Improve jsbn fix.Updates
uuidfrom 3.4.0 to 8.3.2Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
ed32401chore(release): 8.3.2df0f5d1docs: add examples of per-version validation (#543)334ef62chore(release): 8.3.2-beta.016c8f6dfix: lazy load getRandomValues (#537)f3bd455docs: fix react-native link from prefacef34e37bdocs: fix typo in readme (#530)252ebcfchore(release): 8.3.1e6d1603chore: upgrade all devDependencies (#524)c65a0f3fix: support expo>=39.0.0 (#515)ac1b3afdocs: be explicit about react native import order (#518)Updates
svgofrom 3.3.2 to 3.3.3Release notes
Sourced from svgo's releases.
Commits
...Description has been truncated