Bump the npm_and_yarn group across 1 directory with 12 updates - #106
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the npm_and_yarn group with 12 updates in the /source directory: | Package | From | To | | --- | --- | --- | | [pdfjs-dist](https://github.com/mozilla/pdf.js) | `5.6.205` | `6.2.108` | | [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` | | [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.0` | `2.11.26` | | [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.29.1` | | [csv-parse](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-parse) | `5.6.0` | `7.0.2` | | [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` | | [re2](https://github.com/uhop/node-re2) | `1.23.3` | `1.26.1` | | [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.4` | `1.10.0` | | [stream-json](https://github.com/uhop/stream-json) | `1.9.1` | `3.7.0` | | [tar](https://github.com/isaacs/node-tar) | `7.5.19` | `7.5.22` | | [undici](https://github.com/nodejs/undici) | `6.27.0` | `6.28.1` | | [websocket-driver](https://github.com/faye/websocket-driver-node) | `0.7.4` | `0.7.5` | Updates `pdfjs-dist` from 5.6.205 to 6.2.108 - [Release notes](https://github.com/mozilla/pdf.js/releases) - [Commits](mozilla/pdf.js@v5.6.205...v6.2.108) Updates `@humanfs/node` from 0.16.7 to 0.16.8 - [Release notes](https://github.com/humanwhocodes/humanfs/releases) - [Changelog](https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md) - [Commits](https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node) Updates `baseline-browser-mapping` from 2.10.0 to 2.11.26 - [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases) - [Commits](web-platform-dx/baseline-browser-mapping@v2.10.0...v2.11.26) Updates `browserslist` from 4.28.1 to 4.29.1 - [Release notes](https://github.com/browserslist/browserslist/releases) - [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md) - [Commits](browserslist/browserslist@4.28.1...4.29.1) Updates `csv-parse` from 5.6.0 to 7.0.2 - [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-parse/CHANGELOG.md) - [Commits](https://github.com/adaltas/node-csv/commits/csv-parse@7.0.2/packages/csv-parse) Updates `nanoid` from 3.3.11 to 3.3.19 - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@3.3.11...3.3.19) Updates `re2` from 1.23.3 to 1.26.1 - [Release notes](https://github.com/uhop/node-re2/releases) - [Commits](uhop/node-re2@1.23.3...1.26.1) Updates `shell-quote` from 1.8.4 to 1.10.0 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.8.4...v1.10.0) Updates `stream-json` from 1.9.1 to 3.7.0 - [Commits](uhop/stream-json@1.9.1...3.7.0) Updates `tar` from 7.5.19 to 7.5.22 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v7.5.19...v7.5.22) Updates `undici` from 6.27.0 to 6.28.1 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v6.27.0...v6.28.1) Updates `websocket-driver` from 0.7.4 to 0.7.5 - [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-driver-node@0.7.4...0.7.5) --- updated-dependencies: - dependency-name: pdfjs-dist dependency-version: 6.2.108 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@humanfs/node" dependency-version: 0.16.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: baseline-browser-mapping dependency-version: 2.11.26 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserslist dependency-version: 4.29.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: csv-parse dependency-version: 7.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nanoid dependency-version: 3.3.19 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: re2 dependency-version: 1.26.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: shell-quote dependency-version: 1.10.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: stream-json dependency-version: 3.7.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 7.5.22 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 6.28.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: websocket-driver dependency-version: 0.7.5 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 12 updates in the /source directory:
5.6.2056.2.1080.16.70.16.82.10.02.11.264.28.14.29.15.6.07.0.23.3.113.3.191.23.31.26.11.8.41.10.01.9.13.7.07.5.197.5.226.27.06.28.10.7.40.7.5Updates
pdfjs-distfrom 5.6.205 to 6.2.108Release notes
Sourced from pdfjs-dist's releases.
... (truncated)
Commits
0365cbdMerge pull request #21654 from calixteman/fix/cyclesf704f2eMerge pull request #21652 from Snuffleupagus/signatures-async-helpers01ba4c4Merge pull request #21646 from calixteman/update/pdf.js.qcms0299cdcMerge pull request #21653 from Snuffleupagus/jsActions-_getElementsByName-sho...8c3e101Merge pull request #21650 from mozilla/dependabot/github_actions/github/codeq...14afb86Merge pull request #21649 from mozilla/dependabot/github_actions/github/codeq...14fc73bMerge pull request #21648 from mozilla/dependabot/github_actions/github/codeq...257f4c2Merge pull request #21647 from mozilla/dependabot/github_actions/actions/setu...93958e4Merge pull request #21640 from Snuffleupagus/defaultOptions-Mapbc6b5b0Merge pull request #21651 from mozilla/dependabot/github_actions/actions/chec...Updates
@humanfs/nodefrom 0.16.7 to 0.16.8Release notes
Sourced from @humanfs/node's releases.
Changelog
Sourced from @humanfs/node's changelog.
Commits
e96070echore: release main (#146)22bbaa4Merge commit from fork956ce7afix: Include type dependencies at runtimeUpdates
baseline-browser-mappingfrom 2.10.0 to 2.11.26Release notes
Sourced from baseline-browser-mapping's releases.
Commits
c1934c6Patch to 2.11.26 because browser or feature data changed4873684Browser or feature data changed9030798Updating static sitea5df351Updating static siteecc5b54Updating static site719bf7aPatch to 2.11.25 because browser or feature data changedc4f5b49Browser or feature data changedaa194afUpdating static site0d33c4aPatch to 2.11.24 because browser or feature data changed1dac891Browser or feature data changedUpdates
browserslistfrom 4.28.1 to 4.29.1Release notes
Sourced from browserslist's releases.
Changelog
Sourced from browserslist's changelog.
Commits
d539317Release 4.29.1 version5618b50Update dependencies1078f90Fix config loading protection for Windows7f0971cMerge pull request #951 from charmander/resolve-filter-cleanup5bd707aMerge pull request #950 from charmander/usage-filter-cleanupa42d9e3Merge pull request #949 from wahidrizka/fix-case-insensitive-stats-supports7cce1eccleanup: Combine equivalentnot/and notlogic; implementandas opposit...6a13e4bcleanup: Use common function to filter versions by usage predicatea3dd621Make percentage and supports queries case-insensitive6d6530bMerge pull request #948 from jakezwang/fix-case-insensitive-notMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for browserslist since your current version.
Updates
csv-parsefrom 5.6.0 to 7.0.2Changelog
Sourced from csv-parse's changelog.
... (truncated)
Commits
288c9c6chore(release): publish2ad6c07refactor(csv-parse): rename group_columns_by_name testseb4d148fix(csv-parse): prototype replacement reachable via columns (#497)1d4ed3bperf(csv-parse): avoid unnecessary allocation in ResizeableBuffer.toString (#...6e0d5a3chore(release): publishabfe4debuild: latest dependenciesa5ef896docs(csv-parse): fix changelog message from previous version230af8efix(csv-parse): ship stream cjs export (#490)3d71f0bchore(release): publish2ba4897build: use ts nodenextMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for csv-parse since your current version.
Updates
nanoidfrom 3.3.11 to 3.3.19Release notes
Sourced from nanoid's releases.
Changelog
Sourced from nanoid's changelog.
Commits
eb63bd6Release 3.3.19 version9067e03Sync CJS and ESM9ad9805Release 3.3.18 version55e50a0Update CI actione10f8d4Update index.native.js (#606)73d6716Release 3.3.17 versionf9d13f1Sync 0 size behaviour with PostCSS 59760e11Release 3.3.16 versione835c9bfix(non-secure): clamp negative size to prevent infinite loop (#601)96dd086Update CI actionMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for nanoid since your current version.
Updates
re2from 1.23.3 to 1.26.1Commits
411f6b4New version: 1.26.1.9d72042Bench + comment. Fixes #272.ee763b8Restrict size of malformed UTF-8 buffers.c594907Updated deps.448e682Bump tar from 7.5.16 to 7.5.20 (#273)922a0f8Bump actions/setup-node from 6 to 7 in the gh-actions group (#271)3168dfaBump tape-six from 1.14.0 to 1.15.0 in the npm-deps group (#270)2ac2f37Bump the npm-deps group with 4 updates (#269)65ae823New version: 1.26.0ef1ea18Prep for 1.26.0.Install script changes
This version modifies
installscript that runs during installation. Review the package contents before updating.Updates
shell-quotefrom 1.8.4 to 1.10.0Changelog
Sourced from shell-quote's changelog.
Commits
64988d9v1.10.0617d119[Tests]quote: the tilde test escapes every~, not just a leading one (#9)59bbf8b[types] fix an error TS v6 ignores but v7 fails on190e236[Tests]quote: pin that a backslash with whitespace is not doubled in singl...a04d475[Dev Deps] update@arethetypeswrong/cli,evalmdb9545b3[New]parse: add opt-insplitUnquotedoption for shell field-splitting of...1b36468[readme]quote: use output verbatim; do not re-quote it (#11)1c36f3f[Tests]quote: pin conservative escaping of=,@,^,,,:,!(#11)e1c75cd[readme] documentparse's supported parameter-expansion subsetc0842c8[Fix]parse: match nested${...}braces so nested parameter expansion is ...Updates
stream-jsonfrom 1.9.1 to 3.7.0Commits
ac4a46dNew version: 3.7.0.ca2bb67Removed dead code.c06c9a3Perf optimization.1929fd8Added depth capping for DoS hardening.9e35c67Bump the npm-deps group with 2 updates (#222)945c62fBump@types/nodefrom 26.4.0 to 26.5.0 in the npm-deps group (#221)77a4946New version: 3.6.0.0291333Added simplified replacement + fast check tests.0c816aeBump@types/nodefrom 26.2.0 to 26.3.0 in the npm-deps group (#219)c0299dcReworked how comments are handled in JSONC.Updates
tarfrom 7.5.19 to 7.5.22Commits
2a22bfc7.5.22df1cd8dAllow transform to be falsey0cd9cc37.5.21631ae59list: prevent unbounded recursionebbb7207.5.202f27196fix: fully disable and dispose of unzip when aborting parserUpdates
undicifrom 6.27.0 to 6.28.1Release notes
Sourced from undici's releases.
Commits
ffc8aa0Bumped v6.28.1 (#5773)3866a3bperf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5770)ce31bc8fix(retry): validate resumed response framing2af0faffix(websocket): reject unrequested subprotocols07c60d9fix(websocket): destroy inflater after decompression limitbd90fffperf: reduce EventSourceStream parser allocations (#5032) (#5647)01a912eBumped v6.28.0 (#5591)481ecfcUse Node 22 and npm 11 to release740a0b7fix: validate blob body content type2698e49fix: validate coerced header values for CRLF (#5579)Updates
websocket-driverfrom 0.7.4 to 0.7.5Changelog
Sourced from websocket-driver's changelog.
Commits
5d6a9aaBump version to 0.7.5c55679aFail the connection if a message is larger than the configured max length aft...5b197caClose a draft-75/76 connection if a length header grows to exceed the configu...fc93a48Test on Node v22, v24, and v262e82d34Test on recent versions of Nodee4962dbSwitch from Travis CI to GitHub Actions3f2f9b7Travis update: cache npm modules, remove sudo, run on Node 15Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.