Bump the npm_and_yarn group across 1 directory with 15 updates#1
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the npm_and_yarn group across 1 directory with 15 updates#1dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the npm_and_yarn group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js) | `6.0.0` | `9.2.2` | | [axios](https://github.com/axios/axios) | `0.25.0` | `0.31.1` | | [csvtojson](https://github.com/Keyang/node-csvtojson) | `2.0.10` | `2.0.13` | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` | | [sharp](https://github.com/lovell/sharp) | `0.31.1` | `0.32.6` | | [@babel/runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-runtime) | `7.20.7` | `7.29.2` | | [@octokit/request-error](https://github.com/octokit/request-error.js) | `3.0.3` | `7.1.0` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.14` | | [cross-spawn](https://github.com/moxystudio/node-cross-spawn) | `5.1.0` | `7.0.6` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.5` | `3.1.5` | | [tar-fs](https://github.com/mafintosh/tar-fs) | `2.1.1` | `2.1.4` | Updates `@octokit/plugin-paginate-rest` from 6.0.0 to 9.2.2 - [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases) - [Commits](octokit/plugin-paginate-rest.js@v6.0.0...v9.2.2) Updates `axios` from 0.25.0 to 0.31.1 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.25.0...v0.31.1) Updates `csvtojson` from 2.0.10 to 2.0.13 - [Release notes](https://github.com/Keyang/node-csvtojson/releases) - [Commits](Keyang/node-csvtojson@v2.0.10...v2.0.13) Updates `form-data` from 4.0.0 to 4.0.5 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v4.0.0...v4.0.5) Updates `lodash` from 4.17.21 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.18.1) Updates `sharp` from 0.31.1 to 0.32.6 - [Release notes](https://github.com/lovell/sharp/releases) - [Changelog](https://github.com/lovell/sharp/blob/v0.32.6/docs/changelog.md) - [Commits](lovell/sharp@v0.31.1...v0.32.6) Updates `@babel/runtime` from 7.20.7 to 7.29.2 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.2/packages/babel-runtime) Updates `@octokit/request-error` from 3.0.3 to 7.1.0 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v3.0.3...v7.1.0) Updates `@octokit/request` from 6.2.3 to 10.0.9 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v6.2.3...v10.0.9) Updates `brace-expansion` from 1.1.11 to 1.1.14 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.14) Updates `cross-spawn` from 5.1.0 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@5.1.0...v7.0.6) Updates `follow-redirects` from 1.14.8 to 1.16.0 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.14.8...v1.16.0) Updates `minimatch` from 3.0.5 to 3.1.5 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.5...v3.1.5) Updates `semver` from 7.3.8 to 7.8.0 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.8...v7.8.0) Updates `tar-fs` from 2.1.1 to 2.1.4 - [Commits](mafintosh/tar-fs@v2.1.1...v2.1.4) --- updated-dependencies: - dependency-name: "@octokit/plugin-paginate-rest" dependency-version: 9.2.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 0.31.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: csvtojson dependency-version: 2.0.13 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: form-data dependency-version: 4.0.5 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.18.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: sharp dependency-version: 0.32.6 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@babel/runtime" dependency-version: 7.29.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request-error" dependency-version: 7.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 10.0.9 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.14 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-version: 1.16.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 3.1.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-version: 7.8.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar-fs dependency-version: 2.1.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 11 updates in the / directory:
6.0.09.2.20.25.00.31.12.0.102.0.134.17.214.18.10.31.10.32.67.20.77.29.23.0.37.1.01.1.111.1.145.1.07.0.63.0.53.1.52.1.12.1.4Updates
@octokit/plugin-paginate-restfrom 6.0.0 to 9.2.2Release notes
Sourced from @octokit/plugin-paginate-rest's releases.
... (truncated)
Commits
e1e4489fix: ReDos regex vulnerability, reported by@DayShift(#660)5b84386fix(pkg): pin@octokit/corepeerDependency to v5 (#599)fa01f94ci(action): update actions/add-to-project action to v0.6.0 (#598)75aeaaffeat: new/orgs/{org}/organization-roles/{role_id}/teamsand `/orgs/{org}/o...54d6bcfchore(deps): update dependency prettier to v3.2.51bfa2f8chore(deps): update dependency npm-run-all2 to v6eb4a8fechore(deps): replace dependency npm-run-all with npm-run-all2 ^5.0.011ef779chore(deps): update dependency esbuild to ^0.20.02b6cc98ci(action): update peter-evans/create-or-update-comment action to v4d7c9de5chore(deps): update dependency prettier to v3.2.4 (#588)Updates
axiosfrom 0.25.0 to 0.31.1Release notes
Sourced from axios's releases.
... (truncated)
Commits
a589dc5chore: bump version to v0.31.1 (#10766)b0c632ffix: backport security issues (#10764)b52187ffix: harden config merging (#10752)e3ddeb4fix: header security issues (#10750)f4f2d76chore: stop committing dist/ and remove bower (#10747)1f2f644chore: add CODEOWNERS (#10740)44bca90fix: improve regex in AxiosURLSearchParams (#10737)4c4f07ffix: form data recursion (#10728)5073ecachore: release v0.31.0 (#10697)b57eb1aci: update branch name (#10692)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for axios since your current version.
Updates
csvtojsonfrom 2.0.10 to 2.0.13Release notes
Sourced from csvtojson's releases.
Commits
141402crun build script8e430a2Fix issue #500 and #5014caeebdfix #498: prototype pollutionf303866update package-lock.json75a154dMerge pull request #437 from mothershipper/master89a9a36Updated package to 2.0.113e7999dMerge pull request #469 from Keyang/update-librarye5b60c8fix: removed unnessesary lines7264211feat: updated .gitignore99616e4feat: updated deprecated codeUpdates
form-datafrom 4.0.0 to 4.0.5Release notes
Sourced from form-data's releases.
... (truncated)
Changelog
Sourced from form-data's changelog.
... (truncated)
Commits
68ff7ddv4.0.55822467[Dev Deps] update@ljharb/eslint-config,eslint76d0dee[Fix] set Symbol.toStringTag in the proper place16e0076[Tests] Switch to newer v8 prediction library; enable node 24 testing41996f5v4.0.4316c82b[meta] actually ensure the readme backup isn’t published2300ca1[meta] fix readme capitalization811f682[meta] addauto-changelog5e34080[Tests] fix linting errors1d11a76[Tests] handle predict-v8-randomness failures in node < 17 and node > 23Maintainer changes
This version was pushed to npm by ljharb, a new releaser for form-data since your current version.
Install script changes
This version modifies
prepublishscript that runs during installation. Review the package contents before updating.Updates
lodashfrom 4.17.21 to 4.18.1Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)Updates
sharpfrom 0.31.1 to 0.32.6Changelog
Sourced from sharp's changelog.
... (truncated)
Commits
eefaa99Release v0.32.6dbce6faUpgrade to libvips v8.14.5af0fcb3Docs: changelog for #3799c6f54e5Bump devDeps846563eTypeScript: add definitions for block and unblock (#3799)9c217abEnsure withMetadata can add RGB16 profiles #3773e7381e5Alternative fix for 4340d60, uses existing StaySequential4340d60Ensure composite tile images fully decoded #37677f64d46Docs: add missing returns property to raw67e927bDocs: ensure all functions include method signature #3777Updates
@babel/runtimefrom 7.20.7 to 7.29.2Release notes
Sourced from @babel/runtime's releases.
... (truncated)
Commits
37d5595v7.29.2d7f4008v7.28.635055e3v7.28.4ef155f5v7.28.3cac0ff4v7.28.2f68ac51chore: Avoid CITGM errors (#17382)baa4cb8v7.27.67d06930v7.27.45b9468dReduceregeneratorsize more (#17287)cb78b5b[babel 8] Do not replace globalregeneratorRuntimereferences in regenerato...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@babel/runtimesince your current version.Updates
@octokit/request-errorfrom 3.0.3 to 7.1.0Release notes
Sourced from @octokit/request-error's releases.
... (truncated)
Commits
2ea2780feat: inherit options from baseErrorclass to add support for thecause...ac7b309chore(deps): update vitest monorepo to v4 (major) (#531)dadc76dci(action): update peter-evans/create-or-update-comment action to v5 (#525)f57f2e6build(deps): lock file maintenance (#534)e5a75effix(deps): update dependency@octokit/typesto v16 (#533)e5d5de2chore(deps): update dependency@types/nodeto v24 (#532)8cc127bci(action): update actions/setup-node action to v6 (#529)b3a876bbuild(deps): lock file maintenance (#527)cf1817bci(action): update github/codeql-action action to v4 (#528)61f1e87chore(deps): update dependency tinybench to v5 (#519)Updates
@octokit/requestfrom 6.2.3 to 10.0.9Release notes
Sourced from @octokit/request's releases.
... (truncated)
Commits
a9f64a0fix(deps): switch to using the "content-type" package for content type parsin...4abc280chore(deps): update dependency undici to v7.24.0 [security] (#800)f13f5d9fix: usejson-with-bigintinstead of built-in JSON methods in order to prop...9ba6ae0Document that unsuccessful HTTP status code result in an exception (#795)7160b82chore(deps): replace glob with tinyglobby (#791)ab8018bci(action): update peter-evans/create-or-update-comment action to v5 (#776)fb916e4build(deps): bump vite from 6.3.4 to 6.4.1 (#780)e1eb769chore(deps): update dependency esbuild to ^0.27.0 (#784)f17c1c1fix(readme): properly structure the options for custom agent (#786)ea46fa9ci(action): update github/codeql-action action to v4 (#778)