chore(deps): bump the npm-security group across 1 directory with 15 updates#106
chore(deps): bump the npm-security group across 1 directory with 15 updates#106dependabot[bot] wants to merge 1 commit into
Conversation
…pdates Bumps the npm-security group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [dompurify](https://github.com/cure53/DOMPurify) | `3.3.3` | `3.4.0` | | [postcss](https://github.com/postcss/postcss) | `8.5.3` | `8.5.10` | | [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.27.1` | `7.29.7` | | [@tootallnate/once](https://github.com/TooTallNate/once) | `2.0.0` | `2.0.1` | | [yaml](https://github.com/eemeli/yaml) | `2.7.1` | `2.9.0` | | [axios](https://github.com/axios/axios) | `0.26.1` | `1.18.0` | | [basic-ftp](https://github.com/patrickjuchli/basic-ftp) | `5.0.5` | `5.3.1` | | [qs](https://github.com/ljharb/qs) | `6.13.0` | `6.15.2` | | [fast-uri](https://github.com/fastify/fast-uri) | `3.0.6` | `3.1.2` | | [ip-address](https://github.com/beaugunderson/ip-address) | `9.0.5` | `10.2.0` | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` | | [node-forge](https://github.com/digitalbazaar/forge) | `1.3.1` | `1.4.0` | | [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git) | `3.27.0` | `3.36.0` | | [tmp](https://github.com/raszi/node-tmp) | `0.0.33` | `removed` | Updates `dompurify` from 3.3.3 to 3.4.0 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.3.3...3.4.0) Updates `postcss` from 8.5.3 to 8.5.10 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.3...8.5.10) Updates `@babel/plugin-transform-modules-systemjs` from 7.27.1 to 7.29.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.7/packages/babel-plugin-transform-modules-systemjs) Updates `@tootallnate/once` from 2.0.0 to 2.0.1 - [Release notes](https://github.com/TooTallNate/once/releases) - [Changelog](https://github.com/TooTallNate/once/blob/v2.0.1/CHANGELOG.md) - [Commits](TooTallNate/once@2.0.0...v2.0.1) Updates `yaml` from 2.7.1 to 2.9.0 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.7.1...v2.9.0) Updates `axios` from 0.26.1 to 1.18.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.26.1...v1.18.0) Updates `basic-ftp` from 5.0.5 to 5.3.1 - [Release notes](https://github.com/patrickjuchli/basic-ftp/releases) - [Changelog](https://github.com/patrickjuchli/basic-ftp/blob/master/CHANGELOG.md) - [Commits](patrickjuchli/basic-ftp@v5.0.5...v5.3.1) Updates `qs` from 6.13.0 to 6.15.2 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.13.0...v6.15.2) Updates `fast-uri` from 3.0.6 to 3.1.2 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.0.6...v3.1.2) Updates `follow-redirects` from 1.15.9 to 1.16.0 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.15.9...v1.16.0) Updates `ip-address` from 9.0.5 to 10.2.0 - [Commits](beaugunderson/ip-address@v9.0.5...v10.2.0) Updates `lodash` from 4.17.21 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.18.1) Updates `node-forge` from 1.3.1 to 1.4.0 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@v1.3.1...v1.4.0) Updates `simple-git` from 3.27.0 to 3.36.0 - [Release notes](https://github.com/steveukx/git-js/releases) - [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md) - [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.36.0/simple-git) Removes `tmp` --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.0 dependency-type: direct:production dependency-group: npm-security - dependency-name: postcss dependency-version: 8.5.10 dependency-type: direct:production dependency-group: npm-security - dependency-name: "@babel/plugin-transform-modules-systemjs" dependency-version: 7.29.7 dependency-type: indirect dependency-group: npm-security - dependency-name: "@tootallnate/once" dependency-version: 2.0.1 dependency-type: indirect dependency-group: npm-security - dependency-name: yaml dependency-version: 2.9.0 dependency-type: indirect dependency-group: npm-security - dependency-name: axios dependency-version: 1.18.0 dependency-type: indirect dependency-group: npm-security - dependency-name: basic-ftp dependency-version: 5.3.1 dependency-type: indirect dependency-group: npm-security - dependency-name: qs dependency-version: 6.15.2 dependency-type: indirect dependency-group: npm-security - dependency-name: fast-uri dependency-version: 3.1.2 dependency-type: indirect dependency-group: npm-security - dependency-name: follow-redirects dependency-version: 1.16.0 dependency-type: indirect dependency-group: npm-security - dependency-name: ip-address dependency-version: 10.2.0 dependency-type: indirect dependency-group: npm-security - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect dependency-group: npm-security - dependency-name: node-forge dependency-version: 1.4.0 dependency-type: indirect dependency-group: npm-security - dependency-name: simple-git dependency-version: 3.36.0 dependency-type: indirect dependency-group: npm-security - dependency-name: tmp dependency-version: dependency-type: indirect dependency-group: npm-security ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the npm-security group with 14 updates in the / directory:
3.3.33.4.08.5.38.5.107.27.17.29.72.0.02.0.12.7.12.9.00.26.11.18.05.0.55.3.16.13.06.15.23.0.63.1.29.0.510.2.04.17.214.18.11.3.11.4.03.27.03.36.00.0.33removedUpdates
dompurifyfrom 3.3.3 to 3.4.0Release notes
Sourced from dompurify's releases.
Commits
5b16e0bGetting 3.x branch ready for 3.4.0 release (#1250)Updates
postcssfrom 8.5.3 to 8.5.10Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
33b9790Release 8.5.10 version536c79eEscape </style> in CSS output (#2074)afa96b2Update dependencies (#2073)effe88bTypo (#2072)3ee79a2Thread model (#2071)2e0683dCreate incident response docs (#2070)fe88ac2Release 8.5.9 versionc551632Avoid RegExp when we can use simple JS89a6b74Move SECURITY.txt for docs folder to keep GitHub page cleaner6ceb8a4Create SECURITY.mdUpdates
@babel/plugin-transform-modules-systemjsfrom 7.27.1 to 7.29.7Release notes
Sourced from @babel/plugin-transform-modules-systemjs's releases.
... (truncated)
Commits
4fba754v7.29.7a458f66v7.29.432ebd5a[7.x backport]fix(systemjs): improve module string name support (#17974)aa8394ev7.29.00053db6Update polyfill packages (#17727)61647aev7.28.5a177d55[Babel 8] Uset.traverseFastto replace somepath.traverse(#17518)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@babel/plugin-transform-modules-systemjssince your current version.Updates
@tootallnate/oncefrom 2.0.0 to 2.0.1Release notes
Sourced from @tootallnate/once's releases.
Changelog
Sourced from @tootallnate/once's changelog.
Commits
bcbb21dci: fix OIDC publishing — Node 24, npm latest, provenancedc24387Version Packages (2.x) (#12)b8a6f80CI: test all Node versions on Linux onlydabcc0fci: drop EOL Node.js 14.x/16.x, add 22.xb464efcUpdate CI: modern Node versions, fix macOS ARM64 compata1e5e2dFix promise hang when AbortSignal is abortedMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@tootallnate/oncesince your current version.Updates
yamlfrom 2.7.1 to 2.9.0Release notes
Sourced from yaml's releases.
Commits
ddb21b02.9.0167365bdocs: Clarify that not all errors can be avoided6eca2a7fix: Avoid calling Array.prototype.push.apply() with large source array0543cd5fix(lexer): Avoid recursive calls that may exhaust the call stackccdf7432.8.4f625789fix: Disable alias resolution with maxAliasCount:0 (#677)e1a1a77fix: Handle invalid unicode escapesa163ea0style: Satify Prettierb2a5a6cfix: Apply minFractionDigits only to decimal strings (#676)93c951bchore: Bump JSR version to v2.8.3 (#673)Updates
axiosfrom 0.26.1 to 1.18.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
2d06f96chore(release): prepare release 1.18.0 (#11003)32fc489fix: malformed http urls (#11000)b40ce49chore(deps-dev): bump the development_dependencies group with 10 updates (#10...fe964f9docs: mark proxy config as Node.js only (#10995)5f229d2chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...fae9d4edocs: clarify package update PR policy (#10992)28ab2cechore(deps-dev): bump the development_dependencies group with 2 updates (#10989)a8e4f13fix(core): keep default validateStatus when request passes undefined (#10899)614f455docs: publish v1.17.0 release notes (#10988)6bb12c1fix: custom auth headers not stripped on cross-origin redirects (#10892)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for axios since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
basic-ftpfrom 5.0.5 to 5.3.1Release notes
Sourced from basic-ftp's releases.
Changelog
Sourced from basic-ftp's changelog.
Commits
980371bGuard against unbounded control response50827c7Adjust changelog to match release notesc9378a8Fix test22abe43Update Github Actions0feaaecFix test6629d7dImprove error message9c3bf4fSet higher default value for max size of directory listingacd3942Bump version1304429Offer maxListingBytes as an option5cb5367Add bounded StringWriterMaintainer changes
This version was pushed to npm by patrickjuchli, a new releaser for basic-ftp since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
qsfrom 6.13.0 to 6.15.2Changelog
Sourced from qs's changelog.
... (truncated)
Commits
9aca407v6.15.25e33d33[Dev Deps] update@ljharb/eslint-config21f80b3[Fix]stringify: skip null/undefined entries inarrayFormat: 'comma'+ `e...a0a81ea[Fix]stringify: use configureddelimiteraftercharsetSentinele3062f7[Fix]stringify: applyformatterto encoded key understrictNullHandling0c180a4[Fix]stringify: skip null/undefined filter-array entries instead of crashi...3a8b94a[Tests] add regression tests for keys containing percent-encoded bracket text96755ab[readme] fix grammara419ce5[Fix]parse: handle nested bracket groups and add regression tests3f5e1c5v6.15.1Updates
fast-urifrom 3.0.6 to 3.1.2Release notes
Sourced from fast-uri's releases.
... (truncated)
Commits
919dd8eBumped v3.1.2c65ba57fixup: linting6c86c17Merge commit from forka95158aHandle malformed fragment decoding without throwing (#171)cea547cBumped v3.1.1876ce79Merge commit from forkdcdf690ci: add lock-threads workflow (#169)c860e65build(deps-dev): bump neostandard from 0.12.2 to 0.13.0 (#167)9b4c6dcbuild(deps): bump fastify/workflows/.github/workflows/plugins-ci.yml (#166)85d09a9build(deps): bump fastify/workflows/.github/workflows/plugins-ci-package-mana...Updates
follow-redirectsfrom 1.15.9 to 1.16.0Commits
0c23a22Release version 1.16.0 of the npm package.844c4d3Add sensitiveHeaders option.5e8b8d0ci: add Node.js 24.x to the CI matrix7953e22ci: upgrade GitHub Actions to use setup-node@v6 and checkout@v686dc1f8Sanitizing input.21ef28aRelease version 1.15.11 of the npm package.7c88135Roll back tree shaking.6e389baRelease version 1.15.10 of the npm package.