This repository was archived by the owner on Feb 3, 2023. It is now read-only.
Update dependency helmet to v3.21.0#54
Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.1.0->3.21.0By merging this PR, the issue #64 will be automatically resolved and closed:
Release Notes
helmetjs/helmet
v3.21.0Compare Source
Added
x-xss-protectionto v1.3.0mode: nullto disablemode=blockChanged
helmet-cspto v2.9.1bowsersubdependency from 2.5.3 to 2.5.4. See helmet-csp#88v3.20.1Compare Source
Changed
helmet-cspto v2.9.0v3.20.0Compare Source
Changed
helmet-cspto v2.8.0v3.19.0Compare Source
Changed
dns-prefetch-controlto v0.2.0dont-sniff-mimetypeto v1.1.0helmet-crossdomainto v0.4.0hide-powered-byto v1.1.0x-xss-protectionto v1.2.0v3.18.0Compare Source
Added
featurePolicyhas 19 new features:ambientLightSensor,documentDomain,documentWrite,encryptedMedia,fontDisplayLateSwap,layoutAnimations,legacyImageFormats,loadingFrameDefaultEager,oversizedImages,pictureInPicture,serial,syncScript,unoptimizedImages,unoptimizedLosslessImages,unoptimizedLossyImages,unsizedMedia,verticalScroll,wakeLock, andxrChanged
expect-ctto v0.2.0feature-policyto v0.3.0frameguardto v3.1.0nocacheto v2.1.0v3.17.0Compare Source
Added
referrerPolicynow supports multiple valuesChanged
referrerPolicyto v1.2.0v3.16.0Compare Source
Added
bugsfield inpackage.jsonChanged
hststo v2.2.0ienoopento v1.1.0Deprecated
helmet.hsts'ssetIfoption has been deprecated and will be removed inhsts@3. See helmetjs/hsts#22 for moreincludeSubdomainsoption (with a lowercased) has been deprecated and will be removed inhsts@3. Use the uppercase-DincludeSubDomainsoption instead. See helmetjs/hsts#21 for morev3.15.1Compare Source
Deprecated
hpkpmiddleware has been deprecated. If you still need to use this module, install the standalonehpkpmodule from npm. See #180 for more.v3.15.0Compare Source
Added
helmet.featurePolicynow supports four new featuresv3.14.0Compare Source
Added
helmet.featurePolicymiddlewarev3.13.0Compare Source
Added
helmet.permittedCrossDomainPoliciesmiddlewarev3.12.2Compare Source
Fixed
lodash.reducedependency fromcspv3.12.1Compare Source
Fixed
expectCtshould use comma instead of semicolon as delimiterv3.12.0Compare Source
Added
xssFilternow supportsreportUrioptionv3.11.0Compare Source
Added
v3.10.0Compare Source
Added
cspnow supportsprefix-srcdirectiveFixed
cspno longer loads JSON files internally, helping some module bundlersfalseshould be able to disable a CSP directivev3.9.0Compare Source
Added
cspnow supportsstrict-dynamicvaluecspnow supportsrequire-sri-fordirectiveChanged
connectdependencyv3.8.2Compare Source
Changed
connectdependency to latestv3.8.1Compare Source
Fixed
cspdoes not automatically setreport-towhen settingreport-uriv3.8.0Compare Source
Changed
hstsno longer cares whether it's HTTPS and always sets the headerv3.7.0Compare Source
Added
cspnow supportsreport-todirectiveChanged
npmignorev3.6.1Compare Source
Changed
connectversionv3.6.0Compare Source
Added
expectCtmiddleware for setting theExpect-CTheaderv3.5.0Compare Source
Added
cspnow supports theworker-srcdirectivev3.4.1Compare Source
Changed
connectversionv3.4.0Compare Source
Added
cspnow supports moresandboxdirectivesv3.3.0Compare Source
Added
referrerPolicyallowsstrict-originandstrict-origin-when-cross-origindirectivesChanged
connectversionv3.2.0Compare Source
Added
cspnow allowsmanifest-srcdirective