build(deps): bump the npm_and_yarn group across 1 directory with 15 updates#175
build(deps): bump the npm_and_yarn group across 1 directory with 15 updates#175dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
…pdates Bumps the npm_and_yarn group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` | | [rollup](https://github.com/rollup/rollup) | `2.79.2` | `2.80.0` | | [semantic-release](https://github.com/semantic-release/semantic-release) | `17.4.7` | `19.0.3` | | [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.15.6` | `1.16.0` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.1` | `3.14.2` | | [picomatch](https://github.com/micromatch/picomatch) | `2.2.2` | `2.3.2` | Updates `lodash` from 4.17.21 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.18.1) Updates `rollup` from 2.79.2 to 2.80.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v2.79.2...v2.80.0) Updates `semantic-release` from 17.4.7 to 19.0.3 - [Release notes](https://github.com/semantic-release/semantic-release/releases) - [Commits](semantic-release/semantic-release@v17.4.7...v19.0.3) Updates `@octokit/plugin-paginate-rest` from 2.11.0 to 6.1.2 - [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases) - [Commits](octokit/plugin-paginate-rest.js@v2.11.0...v6.1.2) Updates `@octokit/request-error` from 2.0.5 to 3.0.3 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v2.0.5...v3.0.3) Updates `@octokit/request` from 5.4.14 to 6.2.8 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v5.4.14...v6.2.8) Updates `@tootallnate/once` from 1.1.2 to 2.0.0 - [Release notes](https://github.com/TooTallNate/once/releases) - [Changelog](https://github.com/TooTallNate/once/blob/master/CHANGELOG.md) - [Commits](TooTallNate/once@1.1.2...2.0.0) Updates `follow-redirects` from 1.15.6 to 1.16.0 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.15.6...v1.16.0) Updates `handlebars` from 4.7.7 to 4.7.9 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.7.7...v4.7.9) Updates `http-cache-semantics` from 3.8.1 to 4.2.0 - [Commits](https://github.com/kornelski/http-cache-semantics/commits) Updates `js-yaml` from 3.14.1 to 3.14.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.14.1...3.14.2) Updates `marked` from 2.0.1 to 4.3.0 - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@v2.0.1...v4.3.0) Updates `picomatch` from 2.2.2 to 2.3.2 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.2.2...2.3.2) Updates `tar` from 4.4.19 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v4.4.19...v6.2.1) Updates `yargs-parser` from 7.0.0 to 18.1.3 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md) - [Commits](yargs/yargs-parser@v7.0.0...v18.1.3) --- updated-dependencies: - dependency-name: lodash dependency-version: 4.18.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.80.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: semantic-release dependency-version: 19.0.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@octokit/plugin-paginate-rest" dependency-version: 6.1.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request-error" dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 6.2.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@tootallnate/once" dependency-version: 2.0.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-version: 1.16.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-version: 4.7.9 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: http-cache-semantics dependency-version: 4.2.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-version: 3.14.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: marked dependency-version: 4.3.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 6.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-version: 18.1.3 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Resolves intercom/intercom#500235.
Bumps the npm_and_yarn group with 6 updates in the / directory:
4.17.214.18.12.79.22.80.017.4.719.0.31.15.61.16.03.14.13.14.22.2.22.3.2Updates
lodashfrom 4.17.21 to 4.18.1Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)Updates
rollupfrom 2.79.2 to 2.80.0Changelog
Sourced from rollup's changelog.
Commits
d17ae152.80.0d6dee5eValidate bundle stays within output dir (#6277)Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
semantic-releasefrom 17.4.7 to 19.0.3Commits
58a226ffix(log-repo): use the original form of the repo url to remove the need to ma...17d60d3build(deps): bump npm from 8.3.1 to 8.12.0 (#2447)ab45ab1chore(lint): disabled rules that dont apply to this project (#2408)ea389c3chore(deps): update dependency yargs-parser to 13.1.2 [security] (#2402)fa994dbbuild(deps): bump node-fetch from 2.6.1 to 2.6.7 (#2399)b79116bbuild(deps): bump trim-off-newlines from 1.0.1 to 1.0.36fd7e56build(deps): bump minimist from 1.2.5 to 1.2.62b94bb4docs: update broken link to CI config recipes (#2378)b4bc191docs: Correct circleci workflow (#2365)2c30e26Merge pull request #2333 from semantic-release/nextUpdates
@octokit/plugin-paginate-restfrom 2.11.0 to 6.1.2Release notes
Sourced from
@octokit/plugin-paginate-rest's releases.... (truncated)
Commits
3ba0db6fix(build): replace Pika with esbuild and tsc (#527)9240b2ffix: bump@octokit/types(#528)6c2eeadbuild: update cache (#526)7a92a4ebuild(deps): lock file maintenance20aa882build(deps): lock file maintenance (#522)06d6543feat: many new endpoints (#518)ce80cc3chore(deps): update dependency prettier to v2.8.8 (#520)ded0209build: add script to fixpackage.jsonbefore publishing (#519)abd9deebuild(deps): lock file maintenance6dca030build(deps): lock file maintenance (#516)Updates
@octokit/request-errorfrom 2.0.5 to 3.0.3Release notes
Sourced from
@octokit/request-error's releases.... (truncated)
Commits
82c78fcfix(deps): update dependency@octokit/typesto v9 (#307)77c025dbuild(deps): lock file maintenance (#306)ff02c35chore(deps): update dependency prettier to v2.8.3faa94a9Default branch rename (#304)ef89a55🚧 Workflows have changed (#303)cb67bdcbuild(deps): lock file maintenance (#302)c0dda2cbuild(release.yml): set node-version to lts/*11ec169chore(deps): update dependency prettier to v2.8.2 (#301)aa91a4bbuild(deps): lock file maintenance (#299)e5d6520🚧 Workflows have changed (#300)Updates
@octokit/requestfrom 5.4.14 to 6.2.8Release notes
Sourced from
@octokit/request's releases.... (truncated)
Commits
9c9c6d7Revert "fix(deps): update dependency@octokit/request-errorto v4 (#593)"62f51d6fix(deps): update dependency@octokit/request-errorto v4 (#593)cbd121fdocs: replace references to Skypack CDN with esm.sh (#595)71d7488fix(deps): update dependency@octokit/tsconfigto v2, explicitly mark type ...ab33ea2chore(deps): update dependency esbuild to ^0.18.0 (#590)947d7a5fix(build): replace pika with esbuild and tsc (#584)3df1556fix: addsduplexoption when sending a body792a68fchore(deps): update dependency prettier to v2.8.82970f68ci(action): update actions/add-to-project action to v0.5.0 (#578)cdf3701[fix] addsduplexoption when sending a bodyUpdates
@tootallnate/oncefrom 1.1.2 to 2.0.0Release notes
Sourced from
@tootallnate/once's releases.Commits
b71b6e82.0.04460bffBig refactor for v2 (#5)c4862ceRemove test script (#4)de4a704Create LICENSE (#2)f02eb4bREADME++c326013Fixd00821fAddREADME.mdUpdates
follow-redirectsfrom 1.15.6 to 1.16.0Commits
0c23a22Release version 1.16.0 of the npm package.844c4d3Add sensitiveHeaders option.5e8b8d0ci: add Node.js 24.x to the CI matrix7953e22ci: upgrade GitHub Actions to use setup-node@v6 and checkout@v686dc1f8Sanitizing input.21ef28aRelease version 1.15.11 of the npm package.7c88135Roll back tree shaking.6e389baRelease version 1.15.10 of the npm package.5bc496eShake me up before you go-go.694d6b4Bump minimist from 1.2.5 to 1.2.8Updates
handlebarsfrom 4.7.7 to 4.7.9Release notes
Sourced from handlebars's releases.
Changelog
Sourced from handlebars's changelog.
Commits
dce542cv4.7.98a41389Update release notes68d8df5Fix security issuesb2a0831Fix browser tests9f98c16Fix release script45443b4Revert "Improve partial indenting performance"8841a5fFix CI errors with lintinge0137c2fix: enable shell mode for spawn to resolve Windows EINVAL issuee914d60Improve rendering performance7de4b41Upgrade GitHub Actions checkout and setup-node on 4.x branchMaintainer changes
This version was pushed to npm by jaylinski, a new releaser for handlebars since your current version.
Updates
http-cache-semanticsfrom 3.8.1 to 4.2.0Commits
Updates
js-yamlfrom 3.14.1 to 3.14.2Changelog
Sourced from js-yaml's changelog.
... (truncated)
Commits
9963d363.14.2 released10d3c8edist rebuild5278870fix prototype pollution in merge (<<) (#731)Updates
markedfrom 2.0.1 to 4.3.0Release notes
Sourced from marked's releases.
... (truncated)
Commits
d65cf63chore(release): 4.3.0 [skip ci]28f4342🗜️ build v4.3.0 [skip ci]9b452bcfeat: add preprocess and postprocess hooks (#2730)042dcc5fix: always return promise if async (#2728)3acbb7ffix: fenced code doesn't need a trailing newline (#2756)d1f1319chore(deps-dev): Bump rollup from 3.19.1 to 3.20.0 (#2760)0ced8a5chore(deps-dev): Bump jasmine from 4.5.0 to 4.6.0 (#2758)a5bbe19chore(deps-dev): Bump@babel/corefrom 7.21.0 to 7.21.3 (#2761)00f6e2achore(deps-dev): Bump semantic-release from 20.1.1 to 20.1.3 (#2759)8c7bca8chore(deps-dev): Bump node-fetch from 3.3.0 to 3.3.1 (#2754)Updates
picomatchfrom 2.2.2 to 2.3.2Release notes
Sourced from picomatch's releases.
Changelog
Sourced from picomatch's changelog.
... (truncated)
Commits
81cba8dPublish 2.3.2fc1f6b6Merge commit from forkeec17aeMerge commit from fork78f8ca4Merge pull request #156 from micromatch/backport-1443f4f10eMerge pull request #144 from Jason3S/jdent-object-properties5467a5a2.3.19f241efMerge pull request #102 from micromatch/ISSUE-93_incorrect_extglob_expandingac3cb66fix: support stars in negation extglobs with expression after closing parenth...719d348Merge pull request #85 from XhmikosR/codeqlac74e57Merge pull request #91 from XhmikosR/patch-1Maintainer changes
This version was pushed to npm by danez, a new releaser for picomatch since your current version.
Updates
tarfrom 4.4.19 to 6.2.1Release notes
Sourced from tar's releases.
Changelog
Sourced from tar's changelog.
... (truncated)
Commits
bef7b1e6.2.1fe8cd57prevent extraction in excessively deep subfoldersfe7ebfdremove security.md5bc9d406.2.0fe1ef5echangelog 6.2e483220get rid of npm lint stuff689928aci that works outside of npm orgdb6f539file inference improvements for .tbr and .tgz336fa8frefactor: dry and other pr commentseeba222chore: lint fixesUpdates
yargs-parserfrom 7.0.0 to 18.1.3Release notes
Sourced from yargs-parser's releases.
Changelog
Sourced from yargs-parser's changelog.