Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update all non-major dependencies #24

Merged
merged 1 commit into from
Feb 19, 2024
Merged

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 8, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update
@nimiq/core-web (source) 2.0.0-alpha.19 -> 2.0.0-alpha.20 age adoption passing confidence dependencies patch
@nuxtjs/tailwindcss 6.11.3 -> 6.11.4 age adoption passing confidence dependencies patch
@types/node (source) 20.11.16 -> 20.11.19 age adoption passing confidence devDependencies patch
node 20.11.0-alpine3.19 -> 20.11.1-alpine3.19 age adoption passing confidence final patch
node 20.11.0-alpine3.19 -> 20.11.1-alpine3.19 age adoption passing confidence stage patch
nuxt (source) 3.10.1 -> 3.10.2 age adoption passing confidence dependencies patch
vite-node (source) 1.2.2 -> 1.3.0 age adoption passing confidence devDependencies minor

Release Notes

nimiq/core-js (@​nimiq/core-web)

v2.0.0-alpha.20

Compare Source

nuxt-modules/tailwindcss (@​nuxtjs/tailwindcss)

v6.11.4

Compare Source

compare changes

🩹 Fixes
💅 Refactors
  • Move colorette to consola/utils (#​805)
🏡 Chore
  • Assign postcss plugins in order (46c2025)
❤️ Contributors
nodejs/node (node)

v20.11.1: 2024-02-14, Version 20.11.1 'Iron' (LTS), @​RafaelGSS prepared by @​marco-ippolito

Compare Source

Notable changes

This is a security release.

Notable changes
  • CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  • CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  • CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
  • CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
  • CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  • CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
  • CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
  • CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
  • undici version 5.28.3
  • libuv version 1.48.0
  • OpenSSL version 3.0.13+quic1
Commits
nuxt/nuxt (nuxt)

v3.10.2

Compare Source

3.10.2 is a regularly-scheduled patch release.

✅ Upgrading

As usual, our recommendation for upgrading is to run:

nuxi upgrade --force

This will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the vue and unjs ecosystems.

👉 Changelog

compare changes

🩹 Fixes
  • nuxt: Export refreshCookie (#​25635)
  • nuxt: Allow prefetching urls with query string (#​25658)
  • nuxt: Remove undefined keys in route object (#​25667)
  • vite: Treat .pcss extension as a CSS extension (#​25673)
  • nuxt: Don't check for layout/page with <ClientOnly> (#​25714)
  • vite: Strip query strings for style chunk filenames (#​25764)
  • nuxt: Inline entry styles before component styles (#​25749)
  • vite: Optimise layer dependencies with vite (#​25752)
  • nuxt: Don't add extra baseURL on server useRequestURL (#​25765)
  • schema: Use rootDir, not process.cwd, for modulesDir (#​25766)
  • nuxt: Only warn for useId if attrs were not rendered (#​25770)
  • kit: Don't mutate existing component entry when overriding (#​25786)
📖 Documentation
🏡 Chore
  • schema: Add missing closing code block (#​25641)
❤️ Contributors
vitest-dev/vitest (vite-node)

v1.3.0

Compare Source

🚀 Features
🐞 Bug Fixes
View changes on GitHub

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title Update dependency @types/node to v20.11.17 Update all non-major dependencies Feb 10, 2024
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from 701ef31 to 8d67ac9 Compare February 16, 2024 18:54
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 8d67ac9 to a3d7bb2 Compare February 16, 2024 21:18
@faberto faberto merged commit de82145 into main Feb 19, 2024
5 checks passed
@renovate renovate bot deleted the renovate/all-minor-patch branch February 19, 2024 08:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant