[Snyk] Upgrade: node-fetch, , chai, cheerio, mime-types, get-image-colors, image-size, semver, inquirer, tinycolor2, jimp, json-stable-stringify, lint-staged, prettier, sharp, sinon #21
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
node-fetch
from 2.6.1 to 2.7.0 | 13 versions ahead of your current version | a year ago
on 2023-08-23
@octokit/rest
from 18.5.5 to 18.12.0 | 24 versions ahead of your current version | 3 years ago
on 2021-10-07
chai
from 4.3.4 to 4.5.0 | 9 versions ahead of your current version | 2 months ago
on 2024-07-25
cheerio
from 1.0.0-rc.9 to 1.0.0 | 4 versions ahead of your current version | a month ago
on 2024-08-09
mime-types
from 2.1.30 to 2.1.35 | 5 versions ahead of your current version | 2 years ago
on 2022-03-12
get-image-colors
from 4.0.0 to 4.0.1 | 1 version ahead of your current version | 3 years ago
on 2022-02-04
image-size
from 1.0.0 to 1.1.1 | 4 versions ahead of your current version | 8 months ago
on 2024-01-02
semver
from 5.7.1 to 5.7.2 | 1 version ahead of your current version | a year ago
on 2023-07-10
inquirer
from 8.1.0 to 8.2.6 | 12 versions ahead of your current version | a year ago
on 2023-08-02
tinycolor2
from 1.4.2 to 1.6.0 | 13 versions ahead of your current version | 2 years ago
on 2023-02-03
jimp
from 0.16.1 to 0.22.12 | 111 versions ahead of your current version | 7 months ago
on 2024-02-23
json-stable-stringify
from 1.0.1 to 1.1.1 | 3 versions ahead of your current version | 8 months ago
on 2024-01-16
lint-staged
from 11.0.0 to 11.2.6 | 14 versions ahead of your current version | 3 years ago
on 2021-10-26
prettier
from 2.3.0 to 2.8.8 | 20 versions ahead of your current version | a year ago
on 2023-04-23
sharp
from 0.28.3 to 0.33.5 | 47 versions ahead of your current version | a month ago
on 2024-08-16
sinon
from 11.1.1 to 11.1.2 | 1 version ahead of your current version | 3 years ago
on 2021-07-27
Issues fixed by the recommended upgrade:
SNYK-JS-NTHCHECK-1586032
SNYK-JS-NTHCHECK-1586032
SNYK-JS-SEMVER-3247795
SNYK-JS-SEMVER-3247795
SNYK-JS-SHELLQUOTE-1766506
SNYK-JS-SIMPLEGET-2361683
SNYK-JS-TRIMNEWLINES-1298042
SNYK-JS-JPEGJS-2859218
SNYK-JS-JPEGJS-2859218
SNYK-JS-JSONSCHEMA-1920922
SNYK-JS-MICROMATCH-6838728
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-DECODEURICOMPONENT-3149970
SNYK-JS-NODEFETCH-2342118
SNYK-JS-SHARP-2848109
SNYK-JS-SHARP-5922108
SNYK-JS-QS-3153490
SNYK-JS-SEMVER-3247795
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-BRACES-6838727
SNYK-JS-GETFUNCNAME-5923417
SNYK-JS-ISSVG-1085627
SNYK-JS-ISSVG-1243891
SNYK-JS-XML2JS-5414874
SNYK-JS-JPEGJS-570039
SNYK-JS-PHIN-6598077
SNYK-JS-MINIMIST-2429795
Release notes
Package name: node-fetch
-
2.7.0 - 2023-08-23
-
2.6.13 - 2023-08-18
- Remove the default connection close header (#1765) (65ae25a), closes #1735 #1473 #1736
-
2.6.12 - 2023-06-29
- socket variable testing for undefined (#1726) (8bc3a7c)
-
2.6.11 - 2023-05-09
- Revert "fix: handle bom in text and json (#1739)" (#1741) (afb36f6), closes #1739 #1741
-
2.6.10 - 2023-05-08
- handle bom in text and json (#1739) (29909d7)
-
2.6.9 - 2023-01-30
- "global is not defined" (#1704) (70f592d)
-
2.6.8 - 2023-01-13
- headers: don't forward secure headers on protocol change (#1605) (fddad0e), closes #1599
- premature close with chunked transfer encoding and for async iterators in Node 12 (#1172) (50536d1), closes #1064 /github.com/node-fetch/node-fetch/pull/1064#issuecomment-849167400
- prevent hoisting of the undefined
-
2.6.7 - 2022-01-16
-
2.6.6 - 2021-10-31
-
2.6.5 - 2021-09-22
-
2.6.4 - 2021-09-21
-
2.6.3 - 2021-09-20
-
2.6.2 - 2021-09-06
-
2.6.1 - 2020-09-05
from node-fetch GitHub release notes2.7.0 (2023-08-23)
Features
AbortError(#1744) (9b9d458)2.6.13 (2023-08-18)
Bug Fixes
2.6.12 (2023-06-29)
Bug Fixes
2.6.11 (2023-05-09)
Reverts
2.6.10 (2023-05-08)
Bug Fixes
2.6.9 (2023-01-30)
Bug Fixes
2.6.8 (2023-01-13)
Bug Fixes
globalvariable inbrowser.js(#1534) (8bb6e31)Package name: @octokit/rest
-
18.12.0 - 2021-10-07
-
18.11.4 - 2021-09-30
- removes defunkt endpoints:
-
18.11.3 - 2021-09-30
- deps: bump minimal version of
-
18.11.2 - 2021-09-27
-
18.11.1 - 2021-09-24
- typescript: graduate previews
-
18.11.0 - 2021-09-22
-
18.10.0 - 2021-08-31
- typescript:
- typescript: fix type for
-
18.9.1 - 2021-08-16
- deps: update dependency @ octokit/plugin-rest-endpoint-methods to v5.8.0 (1b9ca1e)
-
18.9.0 - 2021-08-03
- typescript:
-
18.8.0 - 2021-08-02
-
18.7.2 - 2021-07-30
-
18.7.1 - 2021-07-23
-
18.7.0 - 2021-07-21
-
18.6.8 - 2021-07-20
-
18.6.7 - 2021-07-04
-
18.6.6 - 2021-06-30
-
18.6.5 - 2021-06-30
-
18.6.4 - 2021-06-29
-
18.6.3 - 2021-06-26
-
18.6.2 - 2021-06-24
-
18.6.1 - 2021-06-23
-
18.6.0 - 2021-06-12
-
18.5.6 - 2021-06-01
-
18.5.6-beta.1 - 2021-06-01
-
18.5.5 - 2021-05-28
from @octokit/rest GitHub release notes18.12.0 (2021-10-07)
Features
.actions.downloadWorkflowRunAttemptLogs(),.actions.getWorkflowRunAttempt(),.repos.generateReleaseNotes(),.checks.rerequestRun(). Graduatenebula,zzzax,switcheroo,baptistepreviews. Removes defunkt/repos/{owner}/{repo}/actions/runs/{run_id}/retryendpoint. Renames methods to have consistentAuthenticatedUser()suffix, deprecates previous method names (#125) (4daa9f3)18.11.4 (2021-09-30)
Bug Fixes
GET /repos/{owner}/{repo}/community/code_of_conduct,DELETE /reactions/{reaction_id}.encrypted_valueandkey_idparameters are required for.rest.actions.{createOrUpdateEnvironmentSecret,setSelectedReposForOrgSecret}().access_tokenparameter is required for.rest.apps.deleteAuthorization(). Previews graduated:ant-man,flash,scarlet-witch,squirrel-girl(#122) (9c02e7d)18.11.3 (2021-09-30)
Bug Fixes
@ octokit/plugin-paginate-resttov2.16.4to prevent typescript compile errors (#120) (fca1907)18.11.2 (2021-09-27)
Bug Fixes
luke-cagepreview graduated (#119) (38a823f)18.11.1 (2021-09-24)
Bug Fixes
dorian,inertia,london,lydian,wyandotte(#116) (f1e2416)18.11.0 (2021-09-22)
Features
octokit.rest.repos.{enable,disable}LfsForRepo(),octokit.rest.repos.mergeUpstream({ owner, repo, branch })(916a8bb)18.10.0 (2021-08-31)
Features
.packages.deletePackageForUser(),.packages.deletePackageVersionForUser(),.packages.restorePackageForUser(),.packages.restorePackageVersionForUser(),.secretScanning.listAlertsForOrg()(#105) (40aeaff)Bug Fixes
labelsparameter in.issues.{add,set}Labels()(#105) (40aeaff)18.9.1 (2021-08-16)
Bug Fixes
18.9.0 (2021-08-03)
Features
allow_auto_mergeparameter when creating / updating a repository. Search:ownerin repository items may no longer benull(#95) (c26c4fe)18.8.0 (2021-08-02)
Features
.rest.repos.createAutolink(),.rest.repos.listAutolinks(),.rest.repos.getAutolink(),.rest.repos.deleteAutolink()(#94) (13df9e7)Package name: chai
-
4.5.0 - 2024-07-25
- Update type detect (#1631) 1a36d35
- Update type detect by @ koddsson in #1631
-
4.4.1 - 2024-01-12
- fix: removes
-
4.4.0 - 2024-01-05
- Allow deepEqual fonction to be configured globally (4.x.x branch) by @ forty in #1553
-
4.3.10 - 2023-09-28
-
4.3.9 - 2023-09-27
-
4.3.8 - 2023-08-24
-
4.3.7 - 2022-11-07
-
4.3.6 - 2022-01-26
-
4.3.5 - 2022-01-25
-
4.3.4 - 2021-03-12
from chai GitHub release notesv4.4.1...v4.5.0
What's Changed
Full Changelog: v4.4.1...v4.5.0
What's Changed
??for node compat by @ 43081j in #1574Full Changelog: v4.4.0...v4.4.1
What's Changed
Full Changelog: v4.3.10...v4.4.0
Package name: cheerio
Cheerio 1.0 is here! 🎉
Announcement Blog Post
Breaking Changes
The minimum NodeJS version is now 18.17 or higher #3959
Import paths were simplified. For example, use
cheerio/sliminstead ofcheerio/lib/slim. #3970The deprecated default Cheerio instance and static methods were removed. #3974
Before, it was possible to write code like this:
html(cheerio('<test></test>')); // ~ '<test></test>' -- NO LONGER WORKS
Make sure to always load documents first:
cheerio.load('<test></test>').html();
Node types previously re-exported by Cheerio must now be imported directly
from (
domhandler)(https://github.com/fb55/domhandler). #3969htmlparser2 options now reside exclusively under the
xmlkey (#2916):New Features
Fixes
cheerio/utilsby @ blixt in #2601data, and simplify by @ fb55 in #2818closestbe able to start from text nodes by @ Qualtagh in #2811Other
Full Changelog: v1.0.0-rc.12...v1.0.0
Bugfix release. Fixed issues:
propundefined handling with jQuery by @ fb55 in #2557cheerio/lib/utilsby @ blixt in #2601New Contributors
Full Changelog: v1.0.0-rc.11...v1.0.0-rc.12
[email protected]is hopefully the last RC before the 1.0.0 release of Cheerio. There are two APIs that will be added for the next major release: Anexractmethod (#2523) and NodeJS specific loader methods (#2051). These are still in flux and I'd appreciate feedback on the proposals.A big thank you to everyone that contributed to this release! This includes code contributors, as well as the amazing financial support on GitHub Sponsors!
Under the hood, a lot of work for this release went into updating parse5, cheerio's default HTML parser. Have a look at parse5's release notes to see what has changed there.
Breaking
scriptandstylecontents are added again in.text()#2509.text()to.prop('innerText')Features
cheerio-select#2511pseudosoption..prop()method:textContentandinnerTextprops #2214baseURIoption, which will lead tohrefandsrcprops to be resolved as URLs. #2510slimexport, which will always use htmlparser2 #1960Fixes
textturn passed values to strings #2047undefinedin the return type ofgetby @ glen-84 in #2392undefinedreturn value #2505Refactor
domutilsmodule directly #1928isHTML#1935load#1951closest#2057Development Experience
Docs
New Contributors
Full Changelog: v1.0.0-rc.10...v1.0.0-rc.11
Fixes:
.html(node)now moves passed nodes (#1923, fixes #940) 258b26bfilterwork on all collections (#1870, fixes #1867) fb8d31eDocumentation: