-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group with 10 updates #4
base: master
Are you sure you want to change the base?
Conversation
Bumps the npm_and_yarn group with 10 updates: | Package | From | To | | --- | --- | --- | | [braces](https://github.com/micromatch/braces) | `2.3.2` | `3.0.3` | | [@docusaurus/theme-search-algolia](https://github.com/facebook/docusaurus/tree/HEAD/packages/docusaurus-theme-search-algolia) | `2.0.0-beta.9` | `2.4.3` | | [docusaurus-theme-search-typesense](https://github.com/typesense/docusaurus-theme-search-typesense) | `0.1.0` | `0.22.0` | | [loader-utils](https://github.com/webpack/loader-utils) | `1.4.0` | `2.0.4` | | [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `0.1.7` | `0.1.10` | | [postcss](https://github.com/postcss/postcss) | `8.3.9` | `8.4.49` | | [qs](https://github.com/ljharb/qs) | `6.7.0` | `6.11.0` | | [send](https://github.com/pillarjs/send) | `0.17.1` | `0.19.0` | | [serve-static](https://github.com/expressjs/serve-static) | `1.14.1` | `1.16.2` | | [webpack](https://github.com/webpack/webpack) | `5.58.2` | `5.96.1` | Updates `braces` from 2.3.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](https://github.com/micromatch/braces/commits/3.0.3) Updates `@docusaurus/theme-search-algolia` from 2.0.0-beta.9 to 2.4.3 - [Release notes](https://github.com/facebook/docusaurus/releases) - [Changelog](https://github.com/facebook/docusaurus/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/docusaurus/commits/v2.4.3/packages/docusaurus-theme-search-algolia) Updates `docusaurus-theme-search-typesense` from 0.1.0 to 0.22.0 - [Release notes](https://github.com/typesense/docusaurus-theme-search-typesense/releases) - [Commits](typesense/docusaurus-theme-search-typesense@v0.1.0...v0.22.0) Updates `loader-utils` from 1.4.0 to 2.0.4 - [Release notes](https://github.com/webpack/loader-utils/releases) - [Changelog](https://github.com/webpack/loader-utils/blob/v2.0.4/CHANGELOG.md) - [Commits](webpack/loader-utils@v1.4.0...v2.0.4) Updates `path-to-regexp` from 0.1.7 to 0.1.10 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v0.1.7...v0.1.10) Updates `postcss` from 8.3.9 to 8.4.49 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.3.9...8.4.49) Updates `qs` from 6.7.0 to 6.11.0 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.7.0...v6.11.0) Updates `send` from 0.17.1 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.17.1...0.19.0) Updates `serve-static` from 1.14.1 to 1.16.2 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/v1.16.2/HISTORY.md) - [Commits](expressjs/serve-static@v1.14.1...v1.16.2) Updates `webpack` from 5.58.2 to 5.96.1 - [Release notes](https://github.com/webpack/webpack/releases) - [Commits](webpack/webpack@v5.58.2...v5.96.1) --- updated-dependencies: - dependency-name: braces dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@docusaurus/theme-search-algolia" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: docusaurus-theme-search-typesense dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: loader-utils dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-to-regexp dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: postcss dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: webpack dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
Report too large to display inline |
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is a license policy violation?This package is not allowed per your license policy. Review the package's license to ensure compliance. Find a package that does not violate your license policy or adjust your policy to allow this package's license. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
Bumps the npm_and_yarn group with 10 updates:
2.3.2
3.0.3
2.0.0-beta.9
2.4.3
0.1.0
0.22.0
1.4.0
2.0.4
0.1.7
0.1.10
8.3.9
8.4.49
6.7.0
6.11.0
0.17.1
0.19.0
1.14.1
1.16.2
5.58.2
5.96.1
Updates
braces
from 2.3.2 to 3.0.3Changelog
Sourced from braces's changelog.
Commits
Updates
@docusaurus/theme-search-algolia
from 2.0.0-beta.9 to 2.4.3Release notes
Sourced from
@docusaurus/theme-search-algolia
's releases.... (truncated)
Changelog
Sourced from
@docusaurus/theme-search-algolia
's changelog.... (truncated)
Commits
56410aa
v2.4.34a2200a
chore: backport retro compatible commits for the Docusaurus v2.4.1 release (#...4fb67ef
chore: backport retro compatible commits for the Docusaurus v2.4 release (#8809)c60387d
chore: backport retro compatible commits for the Docusaurus v2.3.1 release (#...c84d779
chore: backport retro compatible commits for the Docusaurus v2.3 release (#8585)de97214
chore: backport retro compatible commits for the Docusaurus v2.2 release (#8264)7743aa6
chore: release Docusaurus v2.1.0 (#8040)bb65b5c
chore: release v2.0.1 (#7919)d255389
chore: prepare v2.0.0-rc.1 release (#7778)1ad9784
fix(algolia-search): test for canUseIntersectionObserver (#7761)Updates
docusaurus-theme-search-typesense
from 0.1.0 to 0.22.0Release notes
Sourced from docusaurus-theme-search-typesense's releases.
... (truncated)
Commits
19dfd33
v0.22.0e02e66d
v0.22.0-1838a170
Merge pull request #50 from lpillonel/master5c66543
Merge branch 'master' into lpillonel/master3c7bfea
Merge pull request #52 from fharper/fharper/3.5.289f1e5f
v0.22.0-0ed1855c
add missing peerDependencies upgrade for 3.5.2a1a73ac
Merge branch 'master' into lpillonel/master33d1d30
v0.21.0-08994425
Update additional packages to support Docusaurus 3.5.2Updates
loader-utils
from 1.4.0 to 2.0.4Release notes
Sourced from loader-utils's releases.
... (truncated)
Changelog
Sourced from loader-utils's changelog.
Commits
6688b50
chore(release): 2.0.4ac09944
fix: ReDoS problem (#225)7162619
chore(release): 2.0.3a93cf6f
fix(security): prototype polution exploit (#217)90c7c4b
chore(release): 2.0.28c2d24e
fix: base64 generation and unicode characters (#197)5fb5562
chore(release): 2.0.11069f61
fix: md4 support on Node.js v17 (#193)d9f4e23
chore(release): 2.0.0865dc03
refactor: switch tomd4
by default (#168)Updates
path-to-regexp
from 0.1.7 to 0.1.10Release notes
Sourced from path-to-regexp's releases.
Commits
c827fce
0.1.1029b96b4
Add backtrack protection to parametersac4c234
Update repo url (#314)bdb6635
0.1.9c4272e4
Allow a non-lookahead regex (#312)51a1955
0.1.8114f62d
Add support for named matching groups (#301)Updates
postcss
from 8.3.9 to 8.4.49Release notes
Sourced from postcss's releases.
... (truncated)
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
aed8b89
Release 8.4.49 version3450630
Fix position calculations when offset is missing (#1983)77420d6
Release 8.4.48 version341529f
Update dependencies66fa667
Add Node.js 23 to CI1a8b261
fix inconsistent position calculations (#1980)1cc6ac3
Clarify usage in docs5e6fd13
Release 8.4.47 version714bc10
Typo439d20e
Release 8.4.46 versionUpdates
qs
from 6.7.0 to 6.11.0Changelog
Sourced from qs's changelog.
... (truncated)
Commits
56763c1
v6.11.0ddd3e29
[readme] fix version badgec313472
[New] [Fix]stringify
: revert 0e903c0; addcommaRoundTrip
option95bc018
v6.10.50e903c0
[Fix]stringify
: witharrayFormat: comma
, properly include an explicit `[...ba9703c
v6.10.44e44019
[Fix]stringify
: witharrayFormat: comma
, include an explicit[]
on a s...113b990
[Dev Deps] updateobject-inspect
c77f38f
[Dev Deps] updateeslint
,@ljharb/eslint-config
,aud
,has-symbol
,tape
2cf45b2
[meta] usenpmignore
to autogenerate an npmignore fileUpdates
send
from 0.17.1 to 0.19.0Release notes
Sourced from send's releases.
Changelog
Sourced from send's changelog.
Commits
9d2db99
0.19.0ae4f298
Merge commit from forkb69cbb3
0.18.0f53edbb
Limit the headers removed for 304 response706d6dd
docs: add security policyb690ba4
docs: fix linux build badge linkfed09ff
docs: update copyrightaee1a65
deps: [email protected]6060bda
deps: [email protected]8055f78
build: [email protected]Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for send since your current version.
Updates
serve-static
from 1.14.1 to 1.16.2Release notes
Sourced from serve-static's releases.
Changelog
Sourced from serve-static's changelog.
Commits
ec9c5ec
1.16.2f454d37
fix(deps): encodeurl@~2.0.077a8255
1.16.14263f49
fix(deps): [email protected]48c7397
1.16.00c11fad
Merge commit from fork9b5a12a
1.15.0a39a0df
docs: update CI linkd702ea2
build: [email protected]ff1510a
deps: [email protected]Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for serve-static since your current version.
Updates
webpack
from 5.58.2 to 5.96.1Release notes
Sourced from webpack's releases.
... (truncated)
Commits
d4ced73
chore(release): 5.96.17d6dbea
fix: types regression in validate5c556e3
fix: types regression in validate2420eae
fix: add@types/eslint-scope
to dependencies due types regressionec45d2d
fix: add@types/eslint-scope
to dependenciesaff0c3e
chore(release): 5.96.06f11ec1
refactor: module source types codeb07142f
refactor: module source types code7d98b3c
fix: Module Federation should track all referenced chunks6d09769
chore: lintingMaintainer changes
This version was pushed to npm by evilebottnawi, a new releaser for webpack since your current version.
You can trigger a rebase of this PR by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.