-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group across 1 directory with 18 updates #96
Closed
dependabot
wants to merge
1
commit into
main
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-78db6dfa3b
Closed
Bump the npm_and_yarn group across 1 directory with 18 updates #96
dependabot
wants to merge
1
commit into
main
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-78db6dfa3b
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [gatsby](https://github.com/gatsbyjs/gatsby) | `2.29.1` | `4.25.7` | | [gatsby-plugin-sharp](https://github.com/gatsbyjs/gatsby/tree/HEAD/packages/gatsby-plugin-sharp) | `2.11.1` | `4.25.1` | | [node-fetch](https://github.com/node-fetch/node-fetch) | `3.1.1` | `3.2.10` | | [semver](https://github.com/npm/node-semver) | `5.7.2` | `7.5.4` | | [gatsby](https://github.com/gatsbyjs/gatsby) | `4.25.7` | `5.13.3` | | [jpeg-js](https://github.com/eugeneware/jpeg-js) | `0.4.2` | `0.4.4` | | [sharp](https://github.com/lovell/sharp) | `0.26.3` | `0.32.6` | | [gatsby-plugin-sharp](https://github.com/gatsbyjs/gatsby/tree/HEAD/packages/gatsby-plugin-sharp) | `4.25.1` | `5.13.1` | | [gatsby-transformer-sharp](https://github.com/gatsbyjs/gatsby/tree/HEAD/packages/gatsby-transformer-sharp) | `2.9.0` | `5.13.1` | Updates `gatsby` from 2.29.1 to 4.25.7 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/compare/[email protected]@4.25.7) Updates `gatsby-plugin-sharp` from 2.11.1 to 4.25.1 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/packages/gatsby-plugin-sharp/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/commits/[email protected]/packages/gatsby-plugin-sharp) Updates `node-fetch` from 3.1.1 to 3.2.10 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v3.1.1...v3.2.10) Updates `semver` from 5.7.2 to 7.5.4 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v5.7.2...v7.5.4) Updates `gatsby` from 4.25.7 to 5.13.3 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/compare/[email protected]@4.25.7) Updates `file-type` from 3.9.0 to 9.0.0 - [Release notes](https://github.com/sindresorhus/file-type/releases) - [Commits](sindresorhus/file-type@v3.9.0...v9.0.0) Updates `axios` from 0.19.2 to 0.21.4 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v0.21.4/CHANGELOG.md) - [Commits](axios/axios@v0.19.2...v0.21.4) Updates `follow-redirects` from 1.5.10 to 1.15.5 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.5.10...v1.15.5) Updates `postcss` from 6.0.23 to 7.0.35 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@6.0.23...7.0.35) Updates `devcert` from 1.1.3 to 1.2.2 - [Release notes](https://github.com/davewasmer/devcert/releases) - [Changelog](https://github.com/davewasmer/devcert/blob/master/CHANGELOG.md) - [Commits](davewasmer/devcert@v1.1.3...v1.2.2) Updates `got` from 7.1.0 to 9.6.0 - [Release notes](https://github.com/sindresorhus/got/releases) - [Commits](sindresorhus/got@v7.1.0...v9.6.0) Updates `http-cache-semantics` from 3.8.1 to 4.1.0 - [Commits](kornelski/http-cache-semantics@v3.8.1...v4.1.0) Updates `jpeg-js` from 0.4.2 to 0.4.4 - [Release notes](https://github.com/eugeneware/jpeg-js/releases) - [Commits](jpeg-js/jpeg-js@v0.4.2...v0.4.4) Updates `minimatch` from 3.0.3 to 3.0.4 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.3...v3.0.4) Updates `parse-path` from 4.0.2 to 7.0.0 - [Release notes](https://github.com/IonicaBizau/parse-path/releases) - [Commits](IonicaBizau/parse-path@4.0.2...7.0.0) Updates `parse-url` from 5.0.2 to 8.1.0 - [Release notes](https://github.com/IonicaBizau/parse-url/releases) - [Commits](IonicaBizau/parse-url@5.0.2...8.1.0) Updates `sharp` from 0.26.3 to 0.32.6 - [Release notes](https://github.com/lovell/sharp/releases) - [Changelog](https://github.com/lovell/sharp/blob/main/docs/changelog.md) - [Commits](lovell/sharp@v0.26.3...v0.32.6) Updates `gatsby-plugin-sharp` from 4.25.1 to 5.13.1 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/packages/gatsby-plugin-sharp/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/commits/[email protected]/packages/gatsby-plugin-sharp) Updates `gatsby-transformer-sharp` from 2.9.0 to 5.13.1 - [Release notes](https://github.com/gatsbyjs/gatsby/releases) - [Changelog](https://github.com/gatsbyjs/gatsby/blob/master/packages/gatsby-transformer-sharp/CHANGELOG.md) - [Commits](https://github.com/gatsbyjs/gatsby/commits/[email protected]/packages/gatsby-transformer-sharp) Updates `shell-quote` from 1.6.1 to 1.8.1 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.6.1...v1.8.1) --- updated-dependencies: - dependency-name: gatsby dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: gatsby-plugin-sharp dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: node-fetch dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: gatsby dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: file-type dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: axios dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: postcss dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: devcert dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: got dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: http-cache-semantics dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jpeg-js dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: minimatch dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: parse-path dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: parse-url dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: sharp dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: gatsby-plugin-sharp dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: gatsby-transformer-sharp dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: shell-quote dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
the
dependencies
Pull requests that update a dependency file
label
Mar 12, 2024
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
bot
deleted the
dependabot/npm_and_yarn/npm_and_yarn-security-group-78db6dfa3b
branch
March 13, 2024 00:17
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 7 updates in the / directory:
2.29.1
4.25.7
2.11.1
4.25.1
3.1.1
3.2.10
5.7.2
7.5.4
4.25.7
5.13.3
0.4.2
0.4.4
0.26.3
0.32.6
4.25.1
5.13.1
2.9.0
5.13.1
Updates
gatsby
from 2.29.1 to 4.25.7Release notes
Sourced from gatsby's releases.
... (truncated)
Commits
db5eb18
chore(release): Publishfc22f4b
fix(gatsby): don't serve codeframes for files outside of compilation (#38059)...8889bfe
chore(release): Publishd3d5fd0
fix(gatsby-source-wordpress): prevent inconsistent schema customization (#377...5bdef4a
fix(gatsby): don't block event loop during inference (#37780) (#37801)50e3f94
chore(release): Publish3f8477d
chore: Update get-unowned-packages script to use npm 9 syntaxdcf88ed
fix(gatsby-plugin-sharp): don't serve static assets that are not result of cu...3be4a80
chore(release): Publish98c4d27
feat(gatsby): add initial webhook body env var to bootstrap context (#37478) ...Updates
gatsby-plugin-sharp
from 2.11.1 to 4.25.1Release notes
Sourced from gatsby-plugin-sharp's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-sharp's changelog.
... (truncated)
Commits
50e3f94
chore(release): Publishdcf88ed
fix(gatsby-plugin-sharp): don't serve static assets that are not result of cu...5e72a5d
chore(release): Publish2dc715d
chore: remove tracedSVG (#37093) (#37127)9f4c0b9
chore(release): Publish87f280a
chore(release): Publish nextea00e12
chore(release): Publish next6815536
chore(release): Publish next53a4e5a
chore(changelogs): update changelogs (#36605)ba43263
chore(release): Publish next pre-minorUpdates
node-fetch
from 3.1.1 to 3.2.10Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
2880238
fix: ReDoS referrer (#1611)e87b093
fix(Headers): don't forward secure headers on protocol change (#1599)bcfb71c
chore: remove triple-slash directives from typings (#1285) (#1287)95165d5
fix spelling (#1602)11b7033
fix: possibly flaky test (#1523)4f43c9e
fix: always warn Request.data (#1550)1c5ed6b
fix: undefined reference to response.body when aborted (#1578)a92b5d5
fix: use space in accept-encoding values (#1572)0f122b8
docs: fix formdata code example (#1562)6ae9c76
docs(readme): response.clone() is not async (#1560)Maintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
semver
from 5.7.2 to 7.5.4Release notes
Sourced from semver's releases.
... (truncated)
Changelog
Sourced from semver's changelog.
... (truncated)
Commits
36cd334
chore: release 7.5.48456d87
chore: postinstall for dependabot template-oss PRdde1f00
chore: postinstall for dependabot template-oss PRdffcd1b
chore: bump@npmcli/template-oss
from 4.16.0 to 4.17.0d619f66
chore: postinstall for dependabot template-oss PR3bc4247
chore: bump@npmcli/template-oss
from 4.15.1 to 4.16.0cc6fde2
fix: trim each range set before parsing99d8287
fix: correctly parse long build ids as valid (#583)4f0f6b1
chore: fix arguments in whitespace test (#574)6bd1a37
chore: remove duplicate test in semver class (#575)Updates
gatsby
from 4.25.7 to 5.13.3Release notes
Sourced from gatsby's releases.
... (truncated)
Commits
db5eb18
chore(release): Publishfc22f4b
fix(gatsby): don't serve codeframes for files outside of compilation (#38059)...8889bfe
chore(release): Publishd3d5fd0
fix(gatsby-source-wordpress): prevent inconsistent schema customization (#377...5bdef4a
fix(gatsby): don't block event loop during inference (#37780) (#37801)50e3f94
chore(release): Publish3f8477d
chore: Update get-unowned-packages script to use npm 9 syntaxdcf88ed
fix(gatsby-plugin-sharp): don't serve static assets that are not result of cu...3be4a80
chore(release): Publish98c4d27
feat(gatsby): add initial webhook body env var to bootstrap context (#37478) ...Updates
file-type
from 3.9.0 to 9.0.0Commits
4dea313
9.0.0eed45ff
Meta tweaks3a72728
Fix type detection fordocx
,xlsx
andpptx
(#159)4b0eb37
Add support for WavPack (#158)0b174f3
Fix eot mime type (#160)bb6ee19
Activate Monkey's Audio unit test (#154)38de6d7
Map MPEG-4 audio to MIME: audio/mp4 (#148)bad006f
Fix MIME type for.wav
and.avi
(#150)0333b2a
8.1.06a865a1
Add support for Monkey's Audio (ape) (#152)Updates
axios
from 0.19.2 to 0.21.4Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
66c4602
Merge branch 'master' into release/0.21.4fc15665
[Releasing] v0.21.4c2714f0
[Updating] incorrect JSON syntax in README.md0fc7248
fix json transform when data is pre-stringified (#4020)90205f8
Change headers type to string record (#3021)92b29d2
Make the default type of response data never (#3002)4eeb3b1
Improved type-safety for AxiosRequestConfig (#2995)cd7ff04
Adding HTTP status code to error.toJSON (#2956)b5a1a67
Adding nodejs http.request option: insecureHTTPParser (#2930)4f25380
Exposing the Axios constructor in index.d.ts (#2872)Maintainer changes
This version was pushed to npm by jasonsaayman, a new releaser for axios since your current version.
Updates
follow-redirects
from 1.5.10 to 1.15.5Commits
b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.6585820
Release version 1.15.4 of the npm package.7a6567e
Disallow bracketed hostnames.05629af
Prefer native URL instead of deprecated url.parse.1cba8e8
Prefer native URL instead of legacy url.resolve.72bc2a4
Simplify _processResponse error handling.3d42aec
Add bracket tests.bcbb096
Do not directly set Error properties.192dbe7
Release version 1.15.3 of the npm package.Updates
postcss
from 6.0.23 to 7.0.35Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
12832f3
Release 7.0.35 version4455ef6
Use OpenCollective in fundinge867c79
Add migration guide to PostCSS 8 error32a22a9
Release 7.0.34 version2293982
Lock build targets2c3a111
Release 7.0.33 version4105f21
Use yaspeller instead of yaspeller-cic8d02a0
Revert yaspeller-ci removalce95376
Add PostCSS 8 plugin error message69869c6
Update dependenciesUpdates
devcert
from 1.1.3 to 1.2.2Commits
2f42b5a
1.2.283dd841
Allow subdomains and localhost in new domain validator (#84)1ed164f
1.2.1b076321
switch from vulnerable VALID_DOMAIN regex to is-valid-domain lib (#79)fecd645
1.2.092a14f8
chore: bring lockfiles currentbe273aa
Feature: Allow multiple Subject Alternative Name (SAN) extensions (#52)Maintainer changes
This version was pushed to npm by jzetlen, a new releaser for devcert since your current version.
Updates
got
from 7.1.0 to 9.6.0Release notes
Sourced from got's releases.