build(deps): bump the npm_and_yarn group across 3 directories with 10 updates#51
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
build(deps): bump the npm_and_yarn group across 3 directories with 10 updates#51dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
… updates Bumps the npm_and_yarn group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [webpack](https://github.com/webpack/webpack) | `5.94.0` | `5.104.1` | | [electron](https://github.com/electron/electron) | `40.0.0` | `40.8.3` | | [body-parser](https://github.com/expressjs/body-parser) | `1.18.3` | `1.20.3` | | [express](https://github.com/expressjs/express) | `4.16.4` | `4.22.0` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.8` | `3.1.4` | | [serve-static](https://github.com/expressjs/serve-static) | `1.13.2` | `1.16.0` | | [socket.io](https://github.com/socketio/socket.io) | `2.2.0` | `2.5.0` | Bumps the npm_and_yarn group with 1 update in the /apps/desktop directory: [electron](https://github.com/electron/electron). Bumps the npm_and_yarn group with 5 updates in the /apps/server directory: | Package | From | To | | --- | --- | --- | | [body-parser](https://github.com/expressjs/body-parser) | `1.18.3` | `1.20.3` | | [express](https://github.com/expressjs/express) | `4.16.4` | `4.22.0` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.8` | `3.1.4` | | [serve-static](https://github.com/expressjs/serve-static) | `1.13.2` | `1.16.0` | | [socket.io](https://github.com/socketio/socket.io) | `2.2.0` | `2.5.0` | Updates `webpack` from 5.94.0 to 5.104.1 - [Release notes](https://github.com/webpack/webpack/releases) - [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md) - [Commits](webpack/webpack@v5.94.0...v5.104.1) Updates `electron` from 40.0.0 to 40.8.3 - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v40.0.0...v40.8.3) Updates `body-parser` from 1.18.3 to 1.20.3 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.18.3...1.20.3) Updates `express` from 4.16.4 to 4.22.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md) - [Commits](expressjs/express@4.16.4...4.22.0) Updates `minimatch` from 3.0.8 to 3.1.4 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.8...v3.1.4) Updates `serve-static` from 1.13.2 to 1.16.0 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md) - [Commits](expressjs/serve-static@v1.13.2...1.16.0) Updates `socket.io` from 2.2.0 to 2.5.0 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/2.5.0/CHANGELOG.md) - [Commits](socketio/socket.io@2.2.0...2.5.0) Updates `brace-expansion` from 1.1.12 to 1.1.13 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.13) Updates `parseuri` from 0.0.5 to 0.0.6 - [Release notes](https://github.com/slevithan/parseuri/releases) - [Commits](https://github.com/slevithan/parseuri/commits) Updates `ws` from 6.1.4 to 7.5.10 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@6.1.4...7.5.10) Updates `electron` from 40.0.0 to 40.8.3 - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v40.0.0...v40.8.3) Updates `body-parser` from 1.18.3 to 1.20.3 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.18.3...1.20.3) Updates `express` from 4.16.4 to 4.22.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md) - [Commits](expressjs/express@4.16.4...4.22.0) Updates `minimatch` from 3.0.8 to 3.1.4 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.8...v3.1.4) Updates `serve-static` from 1.13.2 to 1.16.0 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md) - [Commits](expressjs/serve-static@v1.13.2...1.16.0) Updates `socket.io` from 2.2.0 to 2.5.0 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/2.5.0/CHANGELOG.md) - [Commits](socketio/socket.io@2.2.0...2.5.0) --- updated-dependencies: - dependency-name: webpack dependency-version: 5.104.1 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: electron dependency-version: 40.8.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: body-parser dependency-version: 1.20.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-version: 4.22.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 3.1.4 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: serve-static dependency-version: 1.16.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: socket.io dependency-version: 2.5.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.13 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: parseuri dependency-version: 0.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 7.5.10 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: electron dependency-version: 40.8.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: body-parser dependency-version: 1.20.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-version: 4.22.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 3.1.4 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: serve-static dependency-version: 1.16.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: socket.io dependency-version: 2.5.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
Superseded by #52. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 7 updates in the / directory:
5.94.05.104.140.0.040.8.31.18.31.20.34.16.44.22.03.0.83.1.41.13.21.16.02.2.02.5.0Bumps the npm_and_yarn group with 1 update in the /apps/desktop directory: electron.
Bumps the npm_and_yarn group with 5 updates in the /apps/server directory:
1.18.31.20.34.16.44.22.03.0.83.1.41.13.21.16.02.2.02.5.0Updates
webpackfrom 5.94.0 to 5.104.1Release notes
Sourced from webpack's releases.
... (truncated)
Changelog
Sourced from webpack's changelog.
Commits
24e3c2dchore(release): new release (#20253)2efd21bfix(re-exports): reexports runtime calculation should not accessing `__WEBPAC...c510070fix(security): userinfo bypass vulnerability in HttpUriPlugin allowedUris4b0501cci: fix release (#20252)0c213ceci: use\<@&1450591255485743204>over@herefor discord notificationw5bf8bc5refactor: types for benchmarks and tests505a5e7chore(release): new release (#20188)0c06680refactor: update eslint configuration2eb0d6aci: release announcement (#20238)b2b2459ci: cancel in progress (#20239)Updates
electronfrom 40.0.0 to 40.8.3Release notes
Sourced from electron's releases.
... (truncated)
Commits
e094b39fix: user resizable transparent windows on win32 (#50301)339d44cfix: add ASAR support to additional copy methods (#50287)ee2d3dbtest: fix esm issue in node-spec-runner (#50294)139e238build: remove redundant bits of ncrypto node patch (#50280)a1550f5fix: prefer browser runtime over node in DevTools HostRuntime detection (#50275)3dd04c2ci: update actions/cache to 5.0.3 (#50236)d32b8a6chore: cherry-pick 7911bee5d90e from skia (#50229)425fe98chore: cherry-pick d5b0cb2acffe from v8 (#50231)6b4b7dfchore: backport running mac app icons from chromium (crrev.com/c/7239386) (#5...cc81658ci: add timeout to test step (#50211)Updates
body-parserfrom 1.18.3 to 1.20.3Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
17529511.20.339744cfchore: linter (#534)b2695c4Merge commit from forkade0f3fadd scorecard to readme (#531)99a1bd6deps: qs@6.12.3 (#521)9478591fix: pin to node@22.4.183db46aci: fix errors in ci github action for node 8 and 9 (#523)9d4e212chore: add support for OSSF scorecard reporting (#522)ee913741.20.2368a93aFix strict json error message on Node.js 19+Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
expressfrom 4.16.4 to 4.22.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)3a5edfafix(ci): updated github actions ci workflow (#6323)52d9781fix(test): add test for method routes without paths #5955Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express since your current version.
Updates
minimatchfrom 3.0.8 to 3.1.4Commits
1a2e0843.1.4ae24656update lockfileb100374limit recursion for **, improve perf considerably26ffeaalockfile update9eca892lock node version to 1400c323b3.1.330486b2update CI matrix and actions9c31b2dupdate test expectations for coalesced consecutive stars46fe687coalesce consecutive non-globstar * characters5a9ccbd[meta] update publishConfig.tag to legacy-v3Updates
serve-staticfrom 1.13.2 to 1.16.0Release notes
Sourced from serve-static's releases.
Changelog
Sourced from serve-static's changelog.
Commits
48c73971.16.00c11fadMerge commit from fork9b5a12a1.15.0a39a0dfdocs: update CI linkd702ea2build: Node.js@17.8ff1510adeps: send@0.18.0813c7e4build: mocha@9.2.22e029f9build: Node.js@17.73269f31build: supertest@6.2.271cd4f8build: mocha@9.2.1Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for serve-static since your current version.
Updates
socket.iofrom 2.2.0 to 2.5.0Changelog
Sourced from socket.io's changelog.
Commits
baa6804chore(release): 2.5.0f223178fix: prevent the socket from joining a room after disconnection226cc16fix: only set 'connected' to true after middleware execution05e1278fix: fix race condition in dynamic namespaces22d4bdffix: ignore packet received after disconnectiondfded53chore: update engine.io version to 3.6.0e6b8697chore(release): 2.4.1a169050revert: fix(security): do not allow all origins by default873fdc5chore(release): 2.4.0f78a575fix(security): do not allow all origins by defaultUpdates
brace-expansionfrom 1.1.12 to 1.1.13Commits
6c353ca1.1.137fd684fBackport fix for GHSA-f886-m6hf-6m8v (#95)Updates
parseurifrom 0.0.5 to 0.0.6Commits
Updates
wsfrom 6.1.4 to 7.5.10Release notes
Sourced from ws's releases.
... (truncated)
Commits
d962d70[dist] 7.5.1022c2876[security] Fix crash when the Upgrade header cannot be read (#2231)8a78f87[dist] 7.5.90435e6e[security] Fix same host check for ws+unix: redirects4271f07[dist] 7.5.8dc1781b[security] Drop sensitive headers when following insecure redirects2758ed3[fix] Abort the handshake if the Upgrade header is invalida370613[dist] 7.5.71f72e2e[security] Drop sensitive headers when following redirects (#2013)8ecd890[dist] 7.5.6Updates
electronfrom 40.0.0 to 40.8.3Release notes
Sourced from electron's releases.
... (truncated)
Commits
e094b39fix: user resizable transparent windows on win32 (#50301)