build(deps): bump the npm_and_yarn group with 19 updates#19
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
build(deps): bump the npm_and_yarn group with 19 updates#19dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the npm_and_yarn group with 19 updates: | Package | From | To | | --- | --- | --- | | [gatsby](https://github.com/gatsbyjs/gatsby) | `2.32.11` | `4.25.7` | | [gatsby-plugin-mdx](https://github.com/gatsbyjs/gatsby/tree/HEAD/packages/gatsby-plugin-mdx) | `1.10.1` | `2.14.1` | | [loader-utils](https://github.com/webpack/loader-utils) | `2.0.0` | `2.0.4` | | [node-fetch](https://github.com/node-fetch/node-fetch) | `2.6.7` | `2.7.0` | | [@sideway/formula](https://github.com/sideway/formula) | `3.0.0` | `3.0.1` | | [body-parser](https://github.com/expressjs/body-parser) | `1.19.0` | `1.20.2` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.2.1` | `4.2.3` | | [cookie](https://github.com/jshttp/cookie) | `0.4.1` | `0.4.2` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [devcert](https://github.com/davewasmer/devcert) | `1.1.3` | `1.2.2` | | [elliptic](https://github.com/indutny/elliptic) | `6.5.4` | `6.6.0` | | [express](https://github.com/expressjs/express) | `4.19.2` | `4.21.1` | | [jpeg-js](https://github.com/eugeneware/jpeg-js) | `0.4.3` | `0.4.4` | | [moment](https://github.com/moment/moment) | `2.29.1` | `2.30.1` | | [send](https://github.com/pillarjs/send) | `0.18.0` | `0.19.0` | | [serve-static](https://github.com/expressjs/serve-static) | `1.15.0` | `1.16.2` | | [ua-parser-js](https://github.com/faisalman/ua-parser-js) | `0.7.27` | `0.7.39` | | [url-parse](https://github.com/unshiftio/url-parse) | `1.5.7` | `1.5.10` | | [word-wrap](https://github.com/jonschlinkert/word-wrap) | `1.2.3` | `1.2.5` | Updates `gatsby` from 2.32.11 to 4.25.7 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/compare/gatsby@2.32.11...gatsby@4.25.7) Updates `gatsby-plugin-mdx` from 1.10.1 to 2.14.1 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/gatsby-plugin-mdx@2.14.1/packages/gatsby-plugin-mdx/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/commits/gatsby-plugin-mdx@2.14.1/packages/gatsby-plugin-mdx) Updates `loader-utils` from 2.0.0 to 2.0.4 - [Release notes](https://github.com/webpack/loader-utils/releases) - [Changelog](https://github.com/webpack/loader-utils/blob/v2.0.4/CHANGELOG.md) - [Commits](webpack/loader-utils@v2.0.0...v2.0.4) Updates `node-fetch` from 2.6.7 to 2.7.0 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v2.6.7...v2.7.0) Updates `@sideway/formula` from 3.0.0 to 3.0.1 - [Commits](hapijs/formula@v3.0.0...v3.0.1) Updates `body-parser` from 1.19.0 to 1.20.2 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.19.0...1.20.2) Updates `browserify-sign` from 4.2.1 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.2.1...v4.2.3) Updates `cookie` from 0.4.1 to 0.4.2 - [Release notes](https://github.com/jshttp/cookie/releases) - [Changelog](https://github.com/jshttp/cookie/blob/v0.4.2/HISTORY.md) - [Commits](jshttp/cookie@v0.4.1...v0.4.2) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `devcert` from 1.1.3 to 1.2.2 - [Release notes](https://github.com/davewasmer/devcert/releases) - [Changelog](https://github.com/davewasmer/devcert/blob/master/CHANGELOG.md) - [Commits](davewasmer/devcert@v1.1.3...v1.2.2) Updates `elliptic` from 6.5.4 to 6.6.0 - [Commits](indutny/elliptic@v6.5.4...v6.6.0) Updates `express` from 4.19.2 to 4.21.1 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.21.1/History.md) - [Commits](expressjs/express@4.19.2...4.21.1) Updates `jpeg-js` from 0.4.3 to 0.4.4 - [Release notes](https://github.com/eugeneware/jpeg-js/releases) - [Commits](jpeg-js/jpeg-js@v0.4.3...v0.4.4) Updates `moment` from 2.29.1 to 2.30.1 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.29.1...2.30.1) Updates `send` from 0.18.0 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.18.0...0.19.0) Updates `serve-static` from 1.15.0 to 1.16.2 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/v1.16.2/HISTORY.md) - [Commits](expressjs/serve-static@v1.15.0...v1.16.2) Updates `ua-parser-js` from 0.7.27 to 0.7.39 - [Release notes](https://github.com/faisalman/ua-parser-js/releases) - [Changelog](https://github.com/faisalman/ua-parser-js/blob/0.7.39/changelog.md) - [Commits](faisalman/ua-parser-js@0.7.27...0.7.39) Updates `url-parse` from 1.5.7 to 1.5.10 - [Commits](unshiftio/url-parse@1.5.7...1.5.10) Updates `word-wrap` from 1.2.3 to 1.2.5 - [Release notes](https://github.com/jonschlinkert/word-wrap/releases) - [Commits](jonschlinkert/word-wrap@1.2.3...1.2.5) --- updated-dependencies: - dependency-name: gatsby dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: gatsby-plugin-mdx dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: loader-utils dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@sideway/formula" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: body-parser dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: devcert dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: elliptic dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jpeg-js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: moment dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ua-parser-js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: url-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: word-wrap dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Nov 7, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 19 updates:
2.32.114.25.71.10.12.14.12.0.02.0.42.6.72.7.03.0.03.0.11.19.01.20.24.2.14.2.30.4.10.4.20.2.00.2.21.1.31.2.26.5.46.6.04.19.24.21.10.4.30.4.42.29.12.30.10.18.00.19.01.15.01.16.20.7.270.7.391.5.71.5.101.2.31.2.5Updates
gatsbyfrom 2.32.11 to 4.25.7Release notes
Sourced from gatsby's releases.
... (truncated)
Commits
db5eb18chore(release): Publishfc22f4bfix(gatsby): don't serve codeframes for files outside of compilation (#38059)...8889bfechore(release): Publishd3d5fd0fix(gatsby-source-wordpress): prevent inconsistent schema customization (#377...5bdef4afix(gatsby): don't block event loop during inference (#37780) (#37801)50e3f94chore(release): Publish3f8477dchore: Update get-unowned-packages script to use npm 9 syntaxdcf88edfix(gatsby-plugin-sharp): don't serve static assets that are not result of cu...3be4a80chore(release): Publish98c4d27feat(gatsby): add initial webhook body env var to bootstrap context (#37478) ...Updates
gatsby-plugin-mdxfrom 1.10.1 to 2.14.1Release notes
Sourced from gatsby-plugin-mdx's releases.
Changelog
Sourced from gatsby-plugin-mdx's changelog.
... (truncated)
Commits
4997d63chore(release): Publishff94ed5fix(gatsby-plugin-mdx): don't allow JS frontmatter by default (#35830) (#35834)f3f1bbcchore(release): Publish9e09fb3chore(release): Publish next048c7a7chore(deps): update babel monorepo (#32996)efdf037fix(deps): update dependency core-js to ^3.17.2 (#32980)f8f1666chore(release): Publish next3294536chore(changelogs): update changelogs for 3.13 release (#32970)eea2687chore(deps): update fs-extra (major) (#32654)401b358chore: add missing@babel/runtimedependencies (#32954)Updates
loader-utilsfrom 2.0.0 to 2.0.4Release notes
Sourced from loader-utils's releases.
Changelog
Sourced from loader-utils's changelog.
Commits
6688b50chore(release): 2.0.4ac09944fix: ReDoS problem (#225)7162619chore(release): 2.0.3a93cf6ffix(security): prototype polution exploit (#217)90c7c4bchore(release): 2.0.28c2d24efix: base64 generation and unicode characters (#197)5fb5562chore(release): 2.0.11069f61fix: md4 support on Node.js v17 (#193)Updates
node-fetchfrom 2.6.7 to 2.7.0Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
9b9d458feat:AbortError(#1744)65ae25afix: Remove the default connection close header (#1765)8bc3a7cfix: socket variable testing for undefined (#1726)afb36f6Revert "fix: handle bom in text and json (#1739)" (#1741)29909d7fix: handle bom in text and json (#1739)70f592dfix: "global is not defined" (#1704)0f1ebb0Prevent error when response is null (#1699)6e9464dci(release): install dependenciesdd2a0baci(release): install dependencies49bef02ci(release): use latest Node LTSMaintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
@sideway/formulafrom 3.0.0 to 3.0.1Commits
5b44c1b3.0.19fbc20achore: better number regex41ae98eCleanupc59f35eMove to SidewayMaintainer changes
This version was pushed to npm by marsup, a new releaser for
@sideway/formulasince your current version.Updates
body-parserfrom 1.19.0 to 1.20.2Release notes
Sourced from body-parser's releases.
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
ee913741.20.2368a93aFix strict json error message on Node.js 19+0385872deps: raw-body@2.5.22c35b41build: eslint@8.34.0f0646c2build: Node.js@18.14f345fb1build: Node.js@14.216842efcdeps: content-type@~1.0.55af7315build: eslint-plugin-promise@6.1.18e605b3build: supertest@6.3.3cba6e77build: mocha@10.2.0Updates
browserify-signfrom 4.2.1 to 4.2.3Changelog
Sourced from browserify-sign's changelog.
Commits
bf2c3ecv4.2.39247adf[patch] widen support to 0.12f427270[Deps] update `parse-asn187f3a35[Dev Deps] updateaud,npmignore,tapefb261ce[Deps] updateelliptic4d0ee49[patch] drop minimum node support to v19e2bf12[Deps] pinhash-baseto ~3.0, due to a breaking change168e16f[Deps] pinellipticdue to a breaking change37a4758[actions] remove redundant finisher4af5a90v4.2.2Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates
cookiefrom 0.4.1 to 0.4.2Release notes
Sourced from cookie's releases.
Changelog
Sourced from cookie's changelog.
Commits
55bac400.4.2519feb5build: mocha@9.2.0fadc4bcbuild: Node.js@14.19009b3cbpref: read value only when assigning in parse04be428lint: remove deprecated String.prototype.substr2dc6662bench: preserve decode behavior for top cookiesaa1a335pref: remove unnecessary regexp in parse2bcee5abench: add cookies from top 20 sites4f08c95docs: update benchmarkf056356build: mocha@9.1.4Updates
decode-uri-componentfrom 0.2.0 to 0.2.2Release notes
Sourced from decode-uri-component's releases.
Commits
a0eea460.2.2980e0bfPrevent overwriting previously decoded tokens3c8a3730.2.176abc93Switch to GitHub workflows746ca5dFix issue where decode throws - fixes #6486d7e2Update license (#1)a650457Tidelift tasks66e1c28Meta tweaksUpdates
devcertfrom 1.1.3 to 1.2.2Commits
2f42b5a1.2.283dd841Allow subdomains and localhost in new domain validator (#84)1ed164f1.2.1b076321switch from vulnerable VALID_DOMAIN regex to is-valid-domain lib (#79)fecd6451.2.092a14f8chore: bring lockfiles currentbe273aaFeature: Allow multiple Subject Alternative Name (SAN) extensions (#52)Maintainer changes
This version was pushed to npm by jzetlen, a new releaser for devcert since your current version.
Updates
ellipticfrom 6.5.4 to 6.6.0Commits
b8a7edd6.6.034c8534fix: signature verification due to leading zeros3e46a486.5.7accb61elib: DER signature decoding correction03e06e16.5.67ac5360Merge commit from fork75700786.5.5206da2elib: lint0a78e03[Fix] restore node < 4 compatUpdates
expressfrom 4.19.2 to 4.21.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
8e229f94.21.1a024c8afix(deps): cookie@0.7.17e562c64.21.01bcde96fix(deps): qs@6.13.0 (#5946)7d36477fix(deps): serve-static@1.16.2 (#5951)40d2d8ffix(deps): finalhandler@1.3.177ada90Deprecate"back"magic string in redirects (#5935)21df4214.20.04c9ddc1feat: upgrade to serve-static@0.16.09ebe5d5feat: upgrade to send@0.19.0 (#5928)Updates
jpeg-jsfrom 0.4.3 to 0.4.4Release notes
Sourced from jpeg-js's releases.
Commits
9ccd35ffix: validate sampling factors (#106)b58cc11fix(decoder): rethrow a more helpful error if Buffer is undefined (#93)2c90858chore(deps): bump y18n from 4.0.0 to 4.0.3 (#98)fd73289chore(deps): bump ws from 7.2.3 to 7.4.6 (#91)9449a8bchore(deps): bump hosted-git-info from 2.8.8 to 2.8.9 (#90)ffdc4a4chore(deps): bump lodash from 4.17.15 to 4.17.21 (#89)13e1ffafeat: add comment tag encoding (#87)417e8e2chore(ci): migrate to github actions (#86)Updates
momentfrom 2.29.1 to 2.30.1Changelog
Sourced from moment's changelog.