chore(deps): bump the npm_and_yarn group across 1 directory with 7 updates #6
No reviewers
Labels
No labels
bug
dependencies
documentation
duplicate
enhancement
good first issue
help wanted
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Cete/sipher#6
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "dependabot/npm_and_yarn/npm_and_yarn-af2bfed2c7"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Bumps the npm_and_yarn group with 5 updates in the / directory:
6.1.46.1.65.5.65.5.104.17.214.18.14.0.34.0.42.3.12.3.24.2.54.2.6Updates
nodemailerfrom 8.0.2 to 8.0.4Release notes
Sourced from nodemailer's releases.
Changelog
Sourced from nodemailer's changelog.
Commits
2d31975chore(master): release 8.0.4 (#1806)2d7b971fix: sanitize envelope size to prevent SMTP command injection4e702e9chore(master): release 8.0.3 (#1804)c803d90fix: remove familySupportCache that broke DNS resolution testse8c8b92fix: fix cookie bugs, remove dead code, and improve hot-path efficiency0e78ee1chore: update dependenciesaf73b4cchore: upgrade GitHub Actions to latest versions604b570chore: simplify remaining lib modules for clarity and consistency4ced83dchore: simplify shared, errors, mailer, mime-node, and mime-funcs modules0cba16echore: simplify smtp-pool with const, Object.assign, and cleaner control flowUpdates
defufrom 6.1.4 to 6.1.6Release notes
Sourced from defu's releases.
Changelog
Sourced from defu's changelog.
Commits
001c290chore(release): v6.1.6407b516build: fix mixed types23e59e6chore(release): v6.1.511ba022fix: ignore inherited enumerable properties3942bfbfix: prevent prototype pollution via__proto__in defaults (#156)d3ef16dchore(deps): update actions/checkout action to v6 (#151)869a053chore(deps): update actions/setup-node action to v6 (#149)a97310cchore(deps): update codecov/codecov-action action to v6 (#154)89df6bbchore: fix typecheck9237d9cci: bump nodeUpdates
fast-xml-parserfrom 5.5.6 to 5.5.10Release notes
Sourced from fast-xml-parser's releases.
Changelog
Sourced from fast-xml-parser's changelog.
... (truncated)
Commits
6473af0update release info537ea09increase default entity explansion limit71dc2d3update path-expression-matcher for performancee868ac5update discord link0400f86performance improvementea42a6aadd discord detaile7e02b4add discord seerver detaila8934f9upgrade strnum23d13e4combine typing files0c0a7dcupdate maintenance docsUpdates
kyselyfrom 0.28.11 to 0.28.15Release notes
Sourced from kysely's releases.
... (truncated)
Commits
87fe2390.28.15cb94018chore: bump dependencies. (#1775)5a5b6c0feat: addNonDehydrateable\<T>to opt-out from dehydration. (#1697)5049924fix: PostgreSQL introspector unnecessarily slow in result processing. (#1774)acb4162Add complex function helpers section to documentation (#1758)43c03edchore: bump TypeScript to 6. (#1769)91cf3730.28.149e02f3bbump deno kysely dependency.6ef6f63docs: document immediate value behavior in case() then/else (#1753)2fb071bRemove unnecessary ")" in Node SQLite link (#1755)Updates
lodashfrom 4.17.21 to 4.18.1Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)Updates
picomatchfrom 4.0.3 to 4.0.4Release notes
Sourced from picomatch's releases.
Commits
e5474fcPublish 4.0.44516eb5Merge commit from fork5eceecdMerge commit from fork0db7dd7Run benchmark again against latest minimatch version (#161)9500377docs: clarify what brace expansion syntax is and isn't supported (#134)2661f23fix typo in globstars.js test name (#138)1798b07docs: fixmakeReexample (#143)9d76bc5chore: undocument removed options (#146)e4d718bRemove unused time-require (#160)38dffebchore(deps): pin dependencies (#158)Updates
picomatchfrom 2.3.1 to 2.3.2Release notes
Sourced from picomatch's releases.
Commits
e5474fcPublish 4.0.44516eb5Merge commit from fork5eceecdMerge commit from fork0db7dd7Run benchmark again against latest minimatch version (#161)9500377docs: clarify what brace expansion syntax is and isn't supported (#134)2661f23fix typo in globstars.js test name (#138)1798b07docs: fixmakeReexample (#143)9d76bc5chore: undocument removed options (#146)e4d718bRemove unused time-require (#160)38dffebchore(deps): pin dependencies (#158)Updates
socket.io-parserfrom 4.2.5 to 4.2.6Release notes
Sourced from socket.io-parser's releases.
Commits
522edcdchore(release): socket.io-parser@4.2.63fff7cafix(parser): add a limit to the number of binary attachments37aad11fix: cleanup pending acks on timeout to prevent memory leakba9cd69revert: fix: cleanup pending acks on timeout to prevent memory leak84c2fb7chore(release): engine.io@6.6.607cbe15fix(eio): add@types/wsas dependency (#5458)44ed73ffix(eio): emit initial_headers and headers events in uServer (#5460)da04267fix: cleanup pending acks on timeout to prevent memory leak (#5442)74599a6fix(types): properly import http moduled48718cci: use actions/checkout@v6 and actions/setup-node@v6 (#5449)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.
Looks like these dependencies are updatable in another way, so this is no longer needed.
Pull request closed