chore(deps): bump the patch-and-minor group with 11 updates#15
chore(deps): bump the patch-and-minor group with 11 updates#15dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the patch-and-minor group with 11 updates: | Package | From | To | | --- | --- | --- | | [@stripe/stripe-js](https://github.com/stripe/stripe-js) | `9.0.0` | `9.6.0` | | [dompurify](https://github.com/cure53/DOMPurify) | `3.3.3` | `3.4.5` | | [dotenv](https://github.com/motdotla/dotenv) | `17.3.1` | `17.4.2` | | [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.3.1` | `8.5.2` | | [express-validator](https://github.com/express-validator/express-validator) | `7.3.1` | `7.3.2` | | [helmet](https://github.com/helmetjs/helmet) | `8.1.0` | `8.2.0` | | [joi](https://github.com/hapijs/joi) | `18.1.1` | `18.2.1` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `8.0.5` | `8.0.8` | | [validator](https://github.com/validatorjs/validator.js) | `13.15.26` | `13.15.35` | | [ws](https://github.com/websockets/ws) | `8.20.0` | `8.21.0` | | [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.4.9` | `2.4.15` | Updates `@stripe/stripe-js` from 9.0.0 to 9.6.0 - [Release notes](https://github.com/stripe/stripe-js/releases) - [Commits](stripe/stripe-js@v9.0.0...v9.6.0) Updates `dompurify` from 3.3.3 to 3.4.5 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.3.3...3.4.5) Updates `dotenv` from 17.3.1 to 17.4.2 - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v17.3.1...v17.4.2) Updates `express-rate-limit` from 8.3.1 to 8.5.2 - [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases) - [Commits](express-rate-limit/express-rate-limit@v8.3.1...v8.5.2) Updates `express-validator` from 7.3.1 to 7.3.2 - [Release notes](https://github.com/express-validator/express-validator/releases) - [Commits](express-validator/express-validator@v7.3.1...v7.3.2) Updates `helmet` from 8.1.0 to 8.2.0 - [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md) - [Commits](helmetjs/helmet@v8.1.0...v8.2.0) Updates `joi` from 18.1.1 to 18.2.1 - [Commits](hapijs/joi@v18.1.1...v18.2.1) Updates `nodemailer` from 8.0.5 to 8.0.8 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v8.0.5...v8.0.8) Updates `validator` from 13.15.26 to 13.15.35 - [Release notes](https://github.com/validatorjs/validator.js/releases) - [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md) - [Commits](validatorjs/validator.js@13.15.26...13.15.35) Updates `ws` from 8.20.0 to 8.21.0 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.20.0...8.21.0) Updates `@biomejs/biome` from 2.4.9 to 2.4.15 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.4.15/packages/@biomejs/biome) --- updated-dependencies: - dependency-name: "@stripe/stripe-js" dependency-version: 9.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: dompurify dependency-version: 3.4.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: dotenv dependency-version: 17.4.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: express-rate-limit dependency-version: 8.5.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: express-validator dependency-version: 7.3.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch-and-minor - dependency-name: helmet dependency-version: 8.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: joi dependency-version: 18.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: nodemailer dependency-version: 8.0.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch-and-minor - dependency-name: validator dependency-version: 13.15.35 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch-and-minor - dependency-name: ws dependency-version: 8.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: patch-and-minor - dependency-name: "@biomejs/biome" dependency-version: 2.4.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch-and-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Warning Review limit reached
More reviews will be available in 2 minutes and 45 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the patch-and-minor group with 11 updates:
9.0.09.6.03.3.33.4.517.3.117.4.28.3.18.5.27.3.17.3.28.1.08.2.018.1.118.2.18.0.58.0.813.15.2613.15.358.20.08.21.02.4.92.4.15Updates
@stripe/stripe-jsfrom 9.0.0 to 9.6.0Release notes
Sourced from @stripe/stripe-js's releases.
... (truncated)
Commits
c427b26v9.6.00c9277fAdd types for automatic_surcharge (#918)cbe49b0v9.5.06a321bfAdd types for new PE and ECEavailablepaymentmethodschangeevent (#924)1d3ca28v9.4.0446d324Add release train type (#923)bce84a5AddhashedValueoverload tohandleNextAction(#889)657af7fv9.3.14ece63fRemove client-only actions from form SDK (#922)77e472ev9.3.0Updates
dompurifyfrom 3.3.3 to 3.4.5Release notes
Sourced from dompurify's releases.
... (truncated)
Commits
011b0c7release: 3.4.5 (#1382)5817ad9release: 3.4.4 (#1374)520edb0release: 3.4.3 (#1352)6f67fd3Sync/3.4.2 (#1322)5b0cdbbchore: merge main into 3.x for 3.4.1 release (#1301)09f5911test: added three more browsers to test setup (OSX, mobile)5b16e0bGetting 3.x branch ready for 3.4.0 release (#1250)Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
dotenvfrom 17.3.1 to 17.4.2Changelog
Sourced from dotenv's changelog.
Commits
f116f7017.4.23a81612fix visual order of faq13f55a8Merge branch 'skill'4bbbf73reorganize faqc3da64bMerge pull request #1009 from motdotla/skill6f743b1update sourcefc2c624update skill972315bTighten up skill2795fcereorganize faqd5495d4adjust skillUpdates
express-rate-limitfrom 8.3.1 to 8.5.2Release notes
Sourced from express-rate-limit's releases.
Commits
97746938.5.20e94cc0v8.5.2 changelog9a583c5feat: simplify IPv6 key generation (#633)4f4b3fbchore(deps-dev): bump lint-staged from 16.4.0 to 17.0.4 (#632)3c1d6c5chore(deps-dev): bump the development-dependencies group with 7 updates (#631)18884b6chore(deps): bump basic-ftp from 5.2.0 to 5.3.1 (#630)dacc980chore(deps): bump handlebars from 4.7.8 to 4.7.9 (#629)486d0c6chore(deps): bump follow-redirects from 1.15.11 to 1.16.0 (#627)50cc3f68.5.192c8e3echore: bump ip-address library to latest (#626)Updates
express-validatorfrom 7.3.1 to 7.3.2Release notes
Sourced from express-validator's releases.
Commits
7d06bc37.3.273fb78bci: bump node version used across several action jobs8a6c2d6deps: upgrade docusaurus and friends2db1d81deps: further bump lodash to v4.18.10b1dbe3docs: fix incorrect type references in oneOf and validation-result docs (#1358)0386b00docs: fix duplicate variable declaration in matchedData example (#1359)97fde88fix(deps): bump lodash to 4.17.23 to fix CVE-2025-13465 (#1355)6c2df4ddocs: fix incorrect checkSchema().run() example (#1357)Updates
helmetfrom 8.1.0 to 8.2.0Changelog
Sourced from helmet's changelog.
Commits
638e43b8.2.0fdf25a8Update changelog for 8.2.0 releasebd293b7Update devDependencies to latest versions81ce5ccTest supported Node versions on CI807a888Update to new URLd4e0128Add direct link to FAQ437d2ebBump actions/setup-node from 6.3.0 to 6.4.0 (#537)a6bd779Upgrade actions/setup-node to 6.3.01e09f5fFix changelog typod526f5cBump Picomatch dev sub-dependencyUpdates
joifrom 18.1.1 to 18.2.1Commits
048fe0518.2.12392713Merge pull request #3113 from hapijs/fix/link-max-call-stackfc146a6fix: protect link recursion from max call stackf4e97e018.2.0626893dMerge pull request #3111 from hapijs/feat/link-maxRecursion9c7a443feat: add maxRecursion limit to links7d43b1218.1.2d98c802Merge pull request #3107 from mahmoodhamdi/fix/json-schema-number-rules7edc591fix: improve JSON Schema conversion for number.port() and number.sign()Updates
nodemailerfrom 8.0.5 to 8.0.8Release notes
Sourced from nodemailer's releases.
Changelog
Sourced from nodemailer's changelog.
Commits
15138a8chore(master): release 8.0.8 (#1819)850bb91fix: four listener/stream leaks in SMTP transport, connection, pool (#1817)833d6e5fix: enforce strict TLS for OAuth2 and Ethereal credential requests (#1818)1997040chore(master): release 8.0.7 (#1815)9b9c545chore: drop nodemailer-ntlm-auth devDependency (#1816)22bf90cBumped dev deps66d4ecbfix: keep domain as UTF-8 when local part is non-ASCII (#1814)6a4a01eFix/base64 wrap trailing crlf (#1813)a22efbcchore(master): release 8.0.6 (#1812)b1ae6c1fix: restore base64 wrap() trim behavior to prevent trailing CRLF (#1810) (#1...Updates
validatorfrom 13.15.26 to 13.15.35Release notes
Sourced from validator's releases.
Changelog
Sourced from validator's changelog.
Commits
7a80797maintenance: 2604 release (#2695)941db7ffix(isSlug): restrict allowed characters to valid slug charset (#2693)2758f70chore: fix typo in comment (#2591)fcfbff5feat(isJson): allow any valid JSON value to pass (#2690)f06caeerefactor: replace if-then-else flow by a single return statement (#2592)9fa1e3afeat(isPostalCode): Add postal code for Monaco (#2682)b1aea75feat(isMobilePhone): add Djibouti (fr-DJ) mobile phone validation (#2676)f715cddfix(isPassportNumber): improveMXlocale (#2643)e8c6914fix(isTaxID): add formatted CPF support and additional test cases for pt-BR l...90b0a9afix(isTaxID): improvept-BRlocale by adding support for alphanumeric CNPJ ...Updates
wsfrom 8.20.0 to 8.21.0Release notes
Sourced from ws's releases.
... (truncated)
Commits
bca91ad[dist] 8.21.02b2abd4[security] Limit retained message parts78eabe2[security] Add latest vulnerability to SECURITY.md5d9b316[dist] 8.20.1c0327ec[security] Fix uninitialized memory disclosure inwebsocket.close()ce2a3d6[ci] Test on node 2658e45b8[ci] Do not test on node 255f26c24[ci] Run the lint step on node 24Updates
@biomejs/biomefrom 2.4.9 to 2.4.15Release notes
Sourced from @biomejs/biome's releases.
... (truncated)
Changelog
Sourced from @biomejs/biome's changelog.
... (truncated)
Commits
9dd3271ci: release (#10210)7b8d4e1feat(lint/html/vue): adduseVueValidVFor(#10195)ba3480efeat(lint/js): adduseTestHooksInOrder(#9394)e0a54ccfeat(lint/js/vue): adduseVueNextTickPromise(#10254)1110256feat(lint/vue): addnoVueImportCompilerMacros(#10238)7f7419cfix: grammar in extends docstring (#10263)0ae5840feat(lint/js): adduseThisForClassMethods(#9807)83f7385feat(lint/js): addnoBaseToString(#9838)64aee45feat(lint/html/vue): addnoVueVOnNumberValues(#10219)46393e0ci: release (#10100)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions