-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group across 1 directory with 10 updates #62
Merged
fufeck
merged 3 commits into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-8ee2bc10dc
Mar 12, 2024
Merged
Bump the npm_and_yarn group across 1 directory with 10 updates #62
fufeck
merged 3 commits into
master
from
dependabot/npm_and_yarn/npm_and_yarn-security-group-8ee2bc10dc
Mar 12, 2024
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [mongodb](https://github.com/mongodb/node-mongodb-native) | `5.6.0` | `5.8.0` | | [next](https://github.com/vercel/next.js) | `12.2.5` | `13.5.0` | | [next-auth](https://github.com/nextauthjs/next-auth) | `4.23.1` | `4.24.5` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `6.9.4` | `6.9.9` | | [sanitize-html](https://github.com/apostrophecms/sanitize-html) | `2.11.0` | `2.12.1` | | [sharp](https://github.com/lovell/sharp) | `0.31.2` | `0.32.6` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.21.3` | `7.24.0` | | [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.1.0` | `4.1.1` | | [ip](https://github.com/indutny/node-ip) | `2.0.0` | `2.0.1` | | [jose](https://github.com/panva/jose) | `4.14.4` | `4.15.5` | Updates `mongodb` from 5.6.0 to 5.8.0 - [Release notes](https://github.com/mongodb/node-mongodb-native/releases) - [Changelog](https://github.com/mongodb/node-mongodb-native/blob/v5.8.0/HISTORY.md) - [Commits](mongodb/node-mongodb-native@v5.6.0...v5.8.0) Updates `next` from 12.2.5 to 13.5.0 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v12.2.5...v13.5.0) Updates `next-auth` from 4.23.1 to 4.24.5 - [Release notes](https://github.com/nextauthjs/next-auth/releases) - [Commits](https://github.com/nextauthjs/next-auth/compare/[email protected]@4.24.5) Updates `nodemailer` from 6.9.4 to 6.9.9 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v6.9.4...v6.9.9) Updates `sanitize-html` from 2.11.0 to 2.12.1 - [Changelog](https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md) - [Commits](apostrophecms/sanitize-html@2.11.0...2.12.1) Updates `sharp` from 0.31.2 to 0.32.6 - [Release notes](https://github.com/lovell/sharp/releases) - [Changelog](https://github.com/lovell/sharp/blob/main/docs/changelog.md) - [Commits](lovell/sharp@v0.31.2...v0.32.6) Updates `@babel/traverse` from 7.21.3 to 7.24.0 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.0/packages/babel-traverse) Updates `http-cache-semantics` from 4.1.0 to 4.1.1 - [Commits](kornelski/http-cache-semantics@v4.1.0...v4.1.1) Updates `ip` from 2.0.0 to 2.0.1 - [Commits](indutny/node-ip@v2.0.0...v2.0.1) Updates `jose` from 4.14.4 to 4.15.5 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/v4.15.5/CHANGELOG.md) - [Commits](panva/jose@v4.14.4...v4.15.5) --- updated-dependencies: - dependency-name: mongodb dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: next dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: next-auth dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: nodemailer dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: sanitize-html dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: sharp dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: http-cache-semantics dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: ip dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: jose dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
force-pushed
the
dependabot/npm_and_yarn/npm_and_yarn-security-group-8ee2bc10dc
branch
from
March 12, 2024 13:26
dca2cc6
to
d35f0a9
Compare
dependabot
bot
added
the
dependencies
Pull requests that update a dependency file
label
Mar 12, 2024
fufeck
requested review from
MaGOs92 and
fufeck
and removed request for
MaGOs92
March 12, 2024 13:42
fufeck
force-pushed
the
dependabot/npm_and_yarn/npm_and_yarn-security-group-8ee2bc10dc
branch
from
March 12, 2024 13:46
96f1304
to
bd9cbf0
Compare
fufeck
approved these changes
Mar 12, 2024
MaGOs92
approved these changes
Mar 12, 2024
MaGOs92
approved these changes
Mar 12, 2024
dependabot
bot
deleted the
dependabot/npm_and_yarn/npm_and_yarn-security-group-8ee2bc10dc
branch
March 12, 2024 15:55
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 10 updates in the / directory:
5.6.0
5.8.0
12.2.5
13.5.0
4.23.1
4.24.5
6.9.4
6.9.9
2.11.0
2.12.1
0.31.2
0.32.6
7.21.3
7.24.0
4.1.0
4.1.1
2.0.0
2.0.1
4.14.4
4.15.5
Updates
mongodb
from 5.6.0 to 5.8.0Release notes
Sourced from mongodb's releases.
... (truncated)
Changelog
Sourced from mongodb's changelog.
Commits
43673fa
chore(5.x): release 5.8.0 [skip-ci] (#3825)4b2fc79
docs: fix cutoff sentence on CommandStartedEvent (#3828)39ff81d
feat(NODE-5465,NODE-5538): lower@aws-sdk/credential-providers
version to 3...e1af343
chore: update release automation scripts 5.x (#3823)c0d3927
feat(NODE-5399): use mongodb-js/saslprep instead of saslprep (#3818)4cf1e96
fix(NODE-5537): remove credentials from ConnectionPoolCreatedEvent options (#...e81d4a2
fix(NODE-5495): do not emit deprecation warning when tlsCertificateKeyFile is...c3b35b3
fix(NODE-5489): set kerberos compatibility to ^1.0.0 || ^2.0.0 (#3803)cc3069d
Revert "feat(NODE-5489): update kerberos dependency"8c25d6d
feat(NODE-5489): update kerberos dependencyMaintainer changes
This version was pushed to npm by dbx-node, a new releaser for mongodb since your current version.
Updates
next
from 12.2.5 to 13.5.0Commits
ffafad2
v13.5.04a589ed
v13.4.20-canary.41deb81cf
fix styled-jsx alias (#55581)1a9b0f6
improve internal error logging (#55582)0631549
Fix react packages are not bundled for metadata routes (#55579)bad5365
Update supported config options for Turbopack (#55556)8881c41
Fix useState function initialiser case foroptimize_server_react
transform ...1025011
Add react-icons to optimizePackageImports (#55572)d5c35a1
chore: replace issue triaing actions withnissuer
(#55525)33c561b
Consolidate experimental React opt-in & addppr
flag (#55560)Updates
next-auth
from 4.23.1 to 4.24.5Commits
5b647e1
chore(release): bump version [skip ci]d237059
fix: differentiate between issued JWTs0f0c444
chore: update cookie options snippet (#9095)fbd68a1
docs: Fix Adapters Link (#9009)18e8b92
fix(dev): fix import links forauthOptions
(#8938)09f5aab
docs: fix source links9dd2bce
docs: Update discord.md (#8958)f4ee563
docs: remove capitalization on osu! (#8975)4318a4c
docs: Fixes broken link on v4 auth0 provider page (#8998)62ec78c
docs: Fix link to database adapters doc (#8986)Updates
nodemailer
from 6.9.4 to 6.9.9Release notes
Sourced from nodemailer's releases.
Changelog
Sourced from nodemailer's changelog.
Commits
5a2e10f
chore(master): release 6.9.9 [skip-ci] (#1606)dd8f5e8
fix(security): Fix issues described in GHSA-9h6g-pr28-7cqp. Do not use eterna...2c2b46a
chore: do not use caret in version specifierbe45c1b
fix(tests): Use native node test runner, added code coverage support, removed...4233f6f
chore(master): release 6.9.8 [skip-ci] (#1605)09d502f
chore: removed double fileb4d0e0c
fix(punycode): do not use native punycode module8376c02
Test new github notice syntax for READMEbc46a3b
Updated stale github action78bdaf8
chore: remove redundant AWS SDK for JavaScript v2 (#1593)Updates
sanitize-html
from 2.11.0 to 2.12.1Changelog
Sourced from sanitize-html's changelog.
Commits
4a7d7dd
Merge pull request #654 from apostrophecms/release-2.12.1f8e02be
release 2.12.1c5dbdf7
Merge pull request #650 from dylanarmstrong/fix/ignore-source-maps5a5a74e
Merge pull request #652 from apostrophecms/add-thanks-to-changelogee71ff0
Add community contribution thanks youa226fe7
Merge pull request #651 from apostrophecms/release-2.12.0ff18600
release 2.12.01e2294c
test: added test for postcss mapc376501
doc: update changelog075499d
fix: ignore source maps when processing with postcssUpdates
sharp
from 0.31.2 to 0.32.6Changelog
Sourced from sharp's changelog.
... (truncated)
Commits
eefaa99
Release v0.32.6dbce6fa
Upgrade to libvips v8.14.5af0fcb3
Docs: changelog for #3799c6f54e5
Bump devDeps846563e
TypeScript: add definitions for block and unblock (#3799)9c217ab
Ensure withMetadata can add RGB16 profiles #3773e7381e5
Alternative fix for 4340d60, uses existing StaySequential4340d60
Ensure composite tile images fully decoded #37677f64d46
Docs: add missing returns property to raw67e927b
Docs: ensure all functions include method signature #3777Updates
@babel/traverse
from 7.21.3 to 7.24.0Release notes
Sourced from
@babel/traverse
's releases.... (truncated)
Changelog
Sourced from
@babel/traverse
's changelog.... (truncated)
Commits
ce59160
v7.24.0bd5abd5
fix: avoidpopContext
on unvisited node paths (#16305)08a057c
UseObject.hasOwn
when available (#16248)a0dd614
v7.23.91200542
fix: Don't throw ingetTypeAnnotation
when using TS+inference (#15383)e428a6d
v7.23.7d292822
fix: Crash when removing withoutProgram
(#16191)d02c1f7
v7.23.6cce807f
Bump debug to ^4.3.1 (#16164)8479012
v7.23.5Updates
http-cache-semantics
from 4.1.0 to 4.1.1Commits
2449650
Update mocha560b2d8
Don't use regex to trim whitespaceb1bdb92
Remove linting package zooc20dc7e
Cache 308Updates
ip
from 2.0.0 to 2.0.1Commits
3b0994a
2.0.132f468f
lib: fixed CVE-2023-42282 and added unit testUpdates
jose
from 4.14.4 to 4.15.5Release notes
Sourced from jose's releases.
Changelog
Sourced from jose's changelog.
... (truncated)
Commits
765aafd
chore(release): 4.15.5b36e45e
test: add export check to x509 pem import testse839ecb
test: stop testing JWE RSA1_5 Algorithm1b91d88
fix: add a maxOutputLength option to zlib inflate9ca2b24
build: remove release actionf3035d8
chore: cleanup after releasef0bb220
chore(release): 4.15.46f38554
chore: bump dev deps936c9df
fix(types): export GetKeyFunction (#592)5ac6619
chore: bump dev depsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.