Bump the npm_and_yarn group across 2 directories with 12 updates #25
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 3 updates in the /ui directory: codemirror, dompurify and swagger-ui-dist.
Bumps the npm_and_yarn group with 8 updates in the /website directory:
7.20.77.27.61.1.111.1.127.5.57.5.1014.0.414.2.303.1.43.2.00.2.00.2.23.1.53.1.102.6.02.8.0Updates
codemirrorfrom 5.65.19 to 6.0.1Changelog
Sourced from codemirror's changelog.
... (truncated)
Commits
Updates
dompurifyfrom 3.2.5 to 3.2.6Release notes
Sourced from dompurify's releases.
Commits
32f765eMerge pull request #1105 from cure53/main6158ecbMerge pull request #1103 from cure53/main0f7ce14chore: Preparing 3.2.6 release848463bchore: removed unused test server scriptb0e0ebbUpdate README.mdf094f76Update README.md6bc6d60Merge pull request #1101 from odaysec/patch-1e9afd60Update server.js166151csee #1095ac7c594Merge pull request #1096 from Rotzbua/fix_missingUpdates
swagger-ui-distfrom 5.21.0 to 5.24.1Release notes
Sourced from swagger-ui-dist's releases.
... (truncated)
Commits
f2c454achore(release): cut the v5.24.1 releaseac106cdft(oas3): show the schema tab in the Try it Out mode (#10488)4680916chore(release): cut the v5.24.0 releaseeee5a98chore(release): bump the failed version releasecbd4b30fix(packagist): exclude large obsolete directories from publishing to Packagi...8045f06fix(release): fix failed v5.23.0 release2bf81f9chore(deps-dev): bump webpack-dev-server from 5.2.0 to 5.2.2 (#10484)9c2cd24chore(deps-dev): bump eslint-plugin-jest from 28.11.0 to 28.12.0 (#10475)a3607fbchore(deps): update swagger-client to v3.35.5 (#10483)2768dc9docs(README): add link to npm downloads badge (#10467)Updates
@babel/runtimefrom 7.20.7 to 7.27.6Release notes
Sourced from
@babel/runtime's releases.... (truncated)
Changelog
Sourced from
@babel/runtime's changelog.... (truncated)
Commits
baa4cb8v7.27.67d06930v7.27.45b9468dReduceregeneratorsize more (#17287)cb78b5b[babel 8] Do not replace globalregeneratorRuntimereferences in regenerato...a0690e3SplitregeneratorRuntimeinto multiple helpers (#17238)da5e371v7.27.3eebd3a0v7.27.1296cdc5Remove unusedregenerator-runtimedep in@babel/runtime(#17263)fdc0fb5[Babel 8] Bump nodejs requirements to^20.19.0 || >= 22.12.0(#17204)5c350eav7.27.0Updates
brace-expansionfrom 1.1.11 to 1.1.12Release notes
Sourced from brace-expansion's releases.
Commits
44f33b41.1.12c460dbdpkg: publish on tag 1.xccb8ac6fmtc3c73c8Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
wsfrom 7.5.5 to 7.5.10Release notes
Sourced from ws's releases.
Commits
d962d70[dist] 7.5.1022c2876[security] Fix crash when the Upgrade header cannot be read (#2231)8a78f87[dist] 7.5.90435e6e[security] Fix same host check for ws+unix: redirects4271f07[dist] 7.5.8dc1781b[security] Drop sensitive headers when following insecure redirects2758ed3[fix] Abort the handshake if the Upgrade header is invalida370613[dist] 7.5.71f72e2e[security] Drop sensitive headers when following redirects (#2013)8ecd890[dist] 7.5.6Updates
nextfrom 14.0.4 to 14.2.30Release notes
Sourced from next's releases.
Commits
243072bv14.2.30f523d4a[backport]: config.allowedDevOrigins (#80410)ca92115v14.2.29ec9ee87Only share incremental cache for edge in next start (#79389)e65628av14.2.283f5d774fix: node.js module import error when using middleware (#77945)43f10b8v14.2.27649ba86backport: fix dynamic route interception not working when deployed with middl...10a042cv14.2.268a511d6Match subrequest handling for edge and node (#77476)Updates
cross-fetchfrom 3.1.4 to 3.2.0Release notes
Sourced from cross-fetch's releases.
Changelog
Sourced from cross-fetch's changelog.
Commits
c6f6f83chore(release): 3.2.0d704d0achore: fixed prepublishOnly script312d047refactor: improved Makefiled1f85aarefactor: improved Makefile (#199)1555ceerefactor: improved make command reliabilityfbbecc8fix: updated whatwg-fetch to 3.6.20 (#198)ebf44c3feat: updated node-fetch to 2.7.0 (#191)c8736f5chore: changed default node version to 16f34b605chore: updated action/setup-node to v4 and hmarr/debug-action to v3f991e47chore: updated action/checkout and action/cache to v4Updates
node-fetchfrom 2.6.1 to 2.7.0Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
9b9d458feat:AbortError(#1744)65ae25afix: Remove the default connection close header (#1765)8bc3a7cfix: socket variable testing for undefined (#1726)afb36f6Revert "fix: handle bom in text and json (#1739)" (#1741)29909d7fix: handle bom in text and json (#1739)70f592dfix: "global is not defined" (#1704)0f1ebb0Prevent error when response is null (#1699)6e9464dci(release): install dependenciesdd2a0baci(release): install dependencies49bef02ci(release): use latest Node LTSMaintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
decode-uri-componentfrom 0.2.0 to 0.2.2Release notes
Sourced from decode-uri-component's releases.
Commits
a0eea460.2.2980e0bfPrevent overwriting previously decoded tokens3c8a3730.2.176abc93Switch to GitHub workflows746ca5dFix issue where decode throws - fixes #6486d7e2Update license (#1)a650457Tidelift tasks66e1c28Meta tweaksUpdates
ejsfrom 3.1.5 to 3.1.10Release notes
Sourced from ejs's releases.
Commits
d3f807dVersion 3.1.109ee26ddMocha TDDe469741Basic pollution protection715e950Merge pull request #756 from Jeffrey-mu/maincabe314Include advanced usage examples29b076cAdded header11503c7Merge branch 'main' of github.com:mde/ejs into main7690404Added security banner to READMEf47d7aeUpdate SECURITY.md828cea1Update SECURITY.mdUpdates
@hashicorp/platform-clifrom 2.6.0 to 2.8.0Release notes
Sourced from
@hashicorp/platform-cli's releases.... (truncated)
Changelog
Sourced from
@hashicorp/platform-cli's changelog.Commits
a0c7c8dVersion Packagesf50b853Extend jsx-a11y to also look for Next.js Imagesb312c73Version Packages5a8b65efix: update web presence github team name033e568chore(deps): update ejs dependencybd07218ADds themed image docsf1f4832Version Packages (#210)5baa5d2Version Packages (#207)72497fechore: update casing for some words (#204)a14714cVersion PackagesYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.