Bump the npm_and_yarn group across 1 directories with 18 updates#5
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Conversation
Bumps the npm_and_yarn group with 17 updates in the /. directory: | Package | From | To | | --- | --- | --- | | [ip](https://github.com/indutny/node-ip) | `1.1.8` | `1.1.9` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `3.2.5` | `3.2.8` | | [axios](https://github.com/axios/axios) | `0.18.1` | `0.28.0` | | [webpack](https://github.com/webpack/webpack) | `5.75.0` | `5.76.0` | | [electron](https://github.com/electron/electron) | `21.3.5` | `22.3.25` | | [semver](https://github.com/npm/node-semver) | `7.3.8` | `7.6.0` | | [semver](https://github.com/npm/node-semver) | `6.3.0` | `7.6.0` | | [semver](https://github.com/npm/node-semver) | `5.7.1` | `7.6.0` | | @pm2/agent | `2.0.1` | `2.0.3` | | [@pm2/io](https://github.com/keymetrics/pm2-io-apm) | `5.0.0` | `5.0.2` | | [electron-builder](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-builder) | `23.6.0` | `24.12.0` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.20.5` | `7.23.9` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.2.1` | `4.2.2` | | [postcss](https://github.com/postcss/postcss) | `8.4.20` | `8.4.35` | | [tough-cookie](https://github.com/salesforce/tough-cookie) | `4.1.2` | `4.1.3` | | [web3](https://github.com/ChainSafe/web3.js) | `1.8.1` | `4.5.0` | | [systeminformation](https://github.com/sebhildebrandt/systeminformation) | `5.16.6` | `5.22.0` | | [undici](https://github.com/nodejs/undici) | `5.14.0` | `5.28.3` | | [word-wrap](https://github.com/jonschlinkert/word-wrap) | `1.2.3` | `1.2.5` | Updates `ip` from 1.1.8 to 1.1.9 - [Commits](indutny/node-ip@v1.1.8...v1.1.9) Updates `vite` from 3.2.5 to 3.2.8 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v3.2.8/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v3.2.8/packages/vite) Updates `axios` from 0.18.1 to 0.28.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v0.28.0/CHANGELOG.md) - [Commits](axios/axios@v0.18.1...v0.28.0) Updates `webpack` from 5.75.0 to 5.76.0 - [Release notes](https://github.com/webpack/webpack/releases) - [Commits](webpack/webpack@v5.75.0...v5.76.0) Updates `electron` from 21.3.5 to 22.3.25 - [Release notes](https://github.com/electron/electron/releases) - [Changelog](https://github.com/electron/electron/blob/main/docs/breaking-changes.md) - [Commits](electron/electron@v21.3.5...v22.3.25) Updates `semver` from 7.3.8 to 7.6.0 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.8...v7.6.0) Updates `semver` from 6.3.0 to 7.6.0 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.8...v7.6.0) Updates `semver` from 5.7.1 to 7.6.0 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.8...v7.6.0) Updates `@pm2/agent` from 2.0.1 to 2.0.3 Updates `@pm2/io` from 5.0.0 to 5.0.2 - [Release notes](https://github.com/keymetrics/pm2-io-apm/releases) - [Changelog](https://github.com/keymetrics/pm2-io-apm/blob/master/CHANGELOG.md) - [Commits](keymetrics/pm2-io-apm@5.0.0...v5.0.2) Updates `electron-builder` from 23.6.0 to 24.12.0 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-builder/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/v24.12.0/packages/electron-builder) Updates `@babel/traverse` from 7.20.5 to 7.23.9 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.23.9/packages/babel-traverse) Updates `follow-redirects` from 1.5.10 to 1.15.2 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.5.10...v1.15.2) Updates `browserify-sign` from 4.2.1 to 4.2.2 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.2.1...v4.2.2) Updates `postcss` from 8.4.20 to 8.4.35 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.20...8.4.35) Updates `tough-cookie` from 4.1.2 to 4.1.3 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v4.1.2...v4.1.3) Updates `web3` from 1.8.1 to 4.5.0 - [Release notes](https://github.com/ChainSafe/web3.js/releases) - [Changelog](https://github.com/web3/web3.js/blob/4.x/CHANGELOG.md) - [Commits](web3/web3.js@v1.8.1...v4.5.0) Updates `systeminformation` from 5.16.6 to 5.22.0 - [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md) - [Commits](sebhildebrandt/systeminformation@v5.16.6...v5.22.0) Updates `undici` from 5.14.0 to 5.28.3 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v5.14.0...v5.28.3) Updates `word-wrap` from 1.2.3 to 1.2.5 - [Release notes](https://github.com/jonschlinkert/word-wrap/releases) - [Commits](jonschlinkert/word-wrap@1.2.3...1.2.5) --- updated-dependencies: - dependency-name: ip dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: vite dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: axios dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: webpack dependency-type: direct:development dependency-group: npm_and_yarn-security-group - dependency-name: electron dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: "@pm2/agent" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: "@pm2/io" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: electron-builder dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: postcss dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: web3 dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: systeminformation dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: undici dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: word-wrap dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 17 updates in the /. directory:
1.1.81.1.93.2.53.2.80.18.10.28.05.75.05.76.021.3.522.3.257.3.87.6.06.3.07.6.05.7.17.6.02.0.12.0.35.0.05.0.223.6.024.12.07.20.57.23.94.2.14.2.28.4.208.4.354.1.24.1.31.8.14.5.05.16.65.22.05.14.05.28.31.2.31.2.5Updates
ipfrom 1.1.8 to 1.1.9Commits
1ecbf2f1.1.96a3ada9lib: fixed CVE-2023-42282 and added unit testUpdates
vitefrom 3.2.5 to 3.2.8Changelog
Sourced from vite's changelog.
Commits
7e3a866release: v3.2.8a26c87dfix: fs deny for case insensitive494f36brelease: v3.2.70574f80fix: port #13348 to v3, fs.deny with leading double slash (#13349)f494760release: v3.2.6b48ac2afix: escape msg in render restricted error html, backport (#12889) (#12892)Updates
axiosfrom 0.18.1 to 0.28.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
3b7635a[Release] v0.28.0 (#6211)27c0076feat(backport): added ability for paramsSerializer to handle function; (#6227)80c3d74chore(ci): backported publish action; (#6224)2755df5fix(security): fixed CVE-2023-45857 by backportingwithXSRFTokenoption to ...880b42edocs: Fix a typo in READMEc4bf0a4Allow null indexes on formSerializer and paramsSerializer v0.x (#4961)1e2679ffix: [Types] Type of header in AxiosRequestConfig / for Axios.create is incor...80b546cfix: loosing request header (#4858) (#4871)6acb5effeat: brower platform add data protocol. (#4814)bbb2264fix(typing): axios response headers can be undefined (#4813)Maintainer changes
This version was pushed to npm by jasonsaayman, a new releaser for axios since your current version.
Updates
webpackfrom 5.75.0 to 5.76.0Release notes
Sourced from webpack's releases.
Commits
97b1718Merge pull request #16781 from askoufis/loader-context-target-typeb84efe6Merge pull request #16759 from ryanwilsonperkin/real-content-hash-regex-perfc98e9e0Merge pull request #16493 from piwysocki/patch-15f34acffeat: AddtargettoLoaderContexttypeb7fc4d8Merge pull request #16703 from ryanwilsonperkin/ryanwilsonperkin/fix-1616063ea82dMerge branch 'webpack:main' into patch-14ba2252Merge pull request #16446 from akhilgkrishnan/patch-11acd635Merge pull request #16613 from jakebailey/ts-logo302eb37Merge pull request #16614 from jakebailey/html5-logocfdb1dfImprove performance of hashRegExp lookupMaintainer changes
This version was pushed to npm by evilebottnawi, a new releaser for webpack since your current version.
Updates
electronfrom 21.3.5 to 22.3.25Commits
1c1c132chore: cherry-pick 3fbd1dca6a4d from libvpx (#40026)d892c2bbuild: fixup autoninja (#39899)6132e80build: run on circle hosts for forks (#39865)a953199build: use aks backed runners for linux builds (#39838)056eacfchore: cherry-pick b2eab7500a18 from chromium (#39827)5f8ef81fix: ensure app load is limited to real asar files when appropriate (#39811)4995c9echore: cherry-pick 1 changes from Release-3-M116 (#39758)e29cdacbuild: fix depot_tools patch application (#39751)b58903dchore: cherry-pick 1 changes from Release-2-M116 (#39689)33f9dcechore: cherry-pick 2 changes from Release-1-M116 (#39648)Updates
semverfrom 7.3.8 to 7.6.0Release notes
Sourced from semver's releases.
... (truncated)
Changelog
Sourced from semver's changelog.
... (truncated)
Commits
377f709chore: release 7.6.0 (#661)a7ab13afeat: preserve pre-release and build parts of a version on coerce (#671)816c7b2chore: postinstall for dependabot template-oss PR0bd24d9chore: bump@npmcli/template-ossfrom 4.21.1 to 4.21.3e521932chore: postinstall for dependabot template-oss PR8873991chore: chore: chore: postinstall for dependabot template-oss PRf317dc8chore: bump@npmcli/template-ossfrom 4.19.0 to 4.21.07303db1chore: add clean() test for build metadata (#658)6240d75chore: add missing quotes in README.md (#656)14d263fchore: postinstall for dependabot template-oss PRMaintainer changes
This version was pushed to npm by npm-cli-ops, a new releaser for semver since your current version.
Updates
semverfrom 6.3.0 to 7.6.0Release notes
Sourced from semver's releases.
... (truncated)
Changelog
Sourced from semver's changelog.
... (truncated)
Commits
377f709chore: release 7.6.0 (#661)a7ab13afeat: preserve pre-release and build parts of a version on coerce (#671)816c7b2chore: postinstall for dependabot template-oss PR0bd24d9chore: bump@npmcli/template-ossfrom 4.21.1 to 4.21.3e521932chore: postinstall for depen...Description has been truncated