Update dependency helmet to v8#1296
Conversation
f65600c to
6952869
Compare
6952869 to
8c3f495
Compare
8c3f495 to
60aeb50
Compare
60aeb50 to
aa50796
Compare
aa50796 to
1c2edd3
Compare
1c2edd3 to
eb28dab
Compare
eb28dab to
dff2cc9
Compare
dff2cc9 to
6cc8e2e
Compare
6cc8e2e to
f45f0f0
Compare
f45f0f0 to
e9c4efe
Compare
e9c4efe to
f64fbf9
Compare
f64fbf9 to
4658cee
Compare
4658cee to
69cebed
Compare
69cebed to
a5c646c
Compare
3de15f1 to
9dba38e
Compare
9dba38e to
d230227
Compare
d230227 to
191c380
Compare
191c380 to
aa199d4
Compare
aa199d4 to
4ace8a3
Compare
4ace8a3 to
8a48a84
Compare
8a48a84 to
0093025
Compare
0093025 to
033d687
Compare
033d687 to
8288c24
Compare
8288c24 to
a5733b5
Compare
a5733b5 to
a39b60e
Compare
|
5 similar comments
|
|
|
|
|
|



This PR contains the following updates:
^7.0.0→^8.0.0Release Notes
helmetjs/helmet (helmet)
v8.1.0Compare Source
Changed
Content-Security-Policygives a better error when a directive value, likeself, should be quoted. See #482v8.0.0Compare Source
Changed
Strict-Transport-Securitynow has a max-age of 365 days, up from 180Content-Security-Policymiddleware now throws an error if a directive should have quotes but does not, such asselfinstead of'self'. See #454Content-Security-Policy'sgetDefaultDirectivesnow returns a deep copy. This only affects users who were mutating the resultStrict-Transport-Securitynow throws an error when "includeSubDomains" option is misspelled. This was previously a warningRemoved
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.