build(deps): bump the npm_and_yarn group across 2 directories with 9 updates#20
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump the npm_and_yarn group across 2 directories with 9 updates#20dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
8218019 to
4e61070
Compare
…updates Dependabot couldn't find the original pull request head commit, 73a2185.
4e61070 to
fcf7721
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 6 updates in the / directory:
4.1.14.3.11.18.31.20.34.16.44.22.05.3.36.0.01.13.21.16.02.2.02.5.0Bumps the npm_and_yarn group with 6 updates in the /apps/server directory:
4.1.14.3.11.18.31.20.34.16.44.22.05.3.36.0.01.13.21.16.02.2.02.5.0Updates
debugfrom 4.1.1 to 4.3.1Release notes
Sourced from debug's releases.
Commits
0d3d66b4.3.1b6d12fdfix regression3f563134.3.0e2d3bc9add deprecation notice for debug.destroy()72e7f86fix memory leak within debug instance27152caadd test for enable/disable of existing instances22e13fefix quoted percent sign80ef62a4.2.009914afMarks supports-color as an optional peer dependencydb306dbUpdate and pin ms to 2.1.2Maintainer changes
This version was pushed to npm by qix, a new releaser for debug since your current version.
Updates
body-parserfrom 1.18.3 to 1.20.3Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
17529511.20.339744cfchore: linter (#534)b2695c4Merge commit from forkade0f3fadd scorecard to readme (#531)99a1bd6deps: qs@6.12.3 (#521)9478591fix: pin to node@22.4.183db46aci: fix errors in ci github action for node 8 and 9 (#523)9d4e212chore: add support for OSSF scorecard reporting (#522)ee913741.20.2368a93aFix strict json error message on Node.js 19+Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
expressfrom 4.16.4 to 4.22.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)3a5edfafix(ci): updated github actions ci workflow (#6323)52d9781fix(test): add test for method routes without paths #5955Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express since your current version.
Updates
express-jwtfrom 5.3.3 to 6.0.0Commits
678f3b06.0.07ecab5fMerge pull request from GHSA-6g6m-m6h5-w9gf304a1c5Made algorithms mandatoryMaintainer changes
This version was pushed to npm by yacine-b, a new releaser for express-jwt since your current version.
Updates
serve-staticfrom 1.13.2 to 1.16.0Release notes
Sourced from serve-static's releases.
Changelog
Sourced from serve-static's changelog.
Commits
48c73971.16.00c11fadMerge commit from fork9b5a12a1.15.0a39a0dfdocs: update CI linkd702ea2build: Node.js@17.8ff1510adeps: send@0.18.0813c7e4build: mocha@9.2.22e029f9build: Node.js@17.73269f31build: supertest@6.2.271cd4f8build: mocha@9.2.1Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for serve-static since your current version.
Updates
socket.iofrom 2.2.0 to 2.5.0Changelog
Sourced from socket.io's changelog.
Commits
baa6804chore(release): 2.5.0f223178fix: prevent the socket from joining a room after disconnection226cc16fix: only set 'connected' to true after middleware execution05e1278fix: fix race condition in dynamic namespaces22d4bdffix: ignore packet received after disconnectiondfded53chore: update engine.io version to 3.6.0e6b8697chore(release): 2.4.1a169050revert: fix(security): do not allow all origins by default873fdc5chore(release): 2.4.0f78a575fix(security): do not allow all origins by defaultUpdates
engine.iofrom 3.3.2 to 3.6.2Commits
Updates
parseurifrom 0.0.5 to 0.0.6Commits
Updates
wsfrom 6.1.4 to 7.5.10Release notes
Sourced from ws's releases.
... (truncated)
Commits
d962d70[dist] 7.5.1022c2876[security] Fix crash when the Upgrade header cannot be read (#2231)8a78f87[dist] 7.5.90435e6e[security] Fix same host check for ws+unix: redirects4271f07[dist] 7.5.8dc1781b[security] Drop sensitive headers when following insecure redirects2758ed3[fix] Abort the handshake if the Upgrade header is invalida370613[dist] 7.5.71f72e2e[security] Drop sensitive headers when following redirects (#2013)8ecd890[dist] 7.5.6Updates
body-parserfrom 1.18.3 to 1.20.4Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
17529511.20.339744cfchore: linter (#534)b2695c4Merge commit from forkade0f3fadd scorecard to readme (#531)99a1bd6deps: qs@6.12.3 (#521)9478591fix: pin to node@22.4.183db46aci: fix errors in ci github action for node 8 and 9 (#523)9d4e212chore: add support for OSSF scorecard reporting (#522)ee913741.20.2368a93aFix strict json error message on Node.js 19+Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
debugfrom 4.1.1 to 4.3.1Release notes
Sourced from debug's releases.
Commits
0d3d66b4.3.1b6d12fdfix regression3f563134.3.0e2d3bc9add deprecation notice for debug.destroy()72e7f86fix memory leak within debug instance27152caadd test for enable/disable of existing instances22e13fefix quoted percent sign80ef62a4.2.009914afMarks supports-color as an optional peer dependencydb306dbUpdate and pin ms to 2.1.2Maintainer changes
This version was pushed to npm by qix, a new releaser for debug since your current version.
Updates
expressfrom 4.16.4 to 4.22.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)3a5edfafix(ci): updated github actions ci workflow (#6323)52d9781fix(test): add test for method routes without paths #5955Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express since your current version.
Updates
express-jwtfrom 5.3.3 to 6.0.0Commits
678f3b06.0.07ecab5fMerge pull request from GHSA-6g6m-m6h5-w9gf304a1c5Made algorithms mandatoryMaintainer changes
This version was pushed to npm by yacine-b, a new releaser for express-jwt since your current version.
Updates
serve-staticfrom 1.13.2 to 1.16.3Release notes
Sourced from serve-static's releases.