This repository was archived by the owner on May 6, 2025. It is now read-only.
Bump the npm_and_yarn group across 1 directory with 19 updates#1
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
Bump the npm_and_yarn group across 1 directory with 19 updates#1dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the npm_and_yarn group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [express](https://github.com/expressjs/express) | `4.17.3` | `4.20.0` | | [passport](https://github.com/jaredhanson/passport) | `0.4.1` | `0.6.0` | | [pug](https://github.com/pugjs/pug) | `3.0.2` | `3.0.3` | | [socket.io](https://github.com/socketio/socket.io) | `2.3.0` | `2.5.0` | | [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` | | [got](https://github.com/sindresorhus/got) | `9.6.0` | `removed` | | [nodemon](https://github.com/remy/nodemon) | `2.0.15` | `2.0.22` | | [tar](https://github.com/isaacs/node-tar) | `6.1.11` | `6.2.1` | Updates `express` from 4.17.3 to 4.20.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.17.3...4.20.0) Updates `passport` from 0.4.1 to 0.6.0 - [Changelog](https://github.com/jaredhanson/passport/blob/master/CHANGELOG.md) - [Commits](jaredhanson/passport@v0.4.1...v0.6.0) Updates `pug` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug@3.0.2...pug@3.0.3) Updates `socket.io` from 2.3.0 to 2.5.0 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/2.5.0/CHANGELOG.md) - [Commits](socketio/socket.io@2.3.0...2.5.0) Updates `body-parser` from 1.19.2 to 1.20.3 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.19.2...1.20.3) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `cookie` from 0.3.1 to 0.4.1 - [Release notes](https://github.com/jshttp/cookie/releases) - [Changelog](https://github.com/jshttp/cookie/blob/v0.4.1/HISTORY.md) - [Commits](jshttp/cookie@v0.3.1...v0.4.1) Updates `engine.io` from 3.4.2 to 3.6.2 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/commits) Updates `parseuri` from 0.0.5 to 0.0.6 - [Release notes](https://github.com/slevithan/parseuri/releases) - [Commits](https://github.com/slevithan/parseuri/commits) Updates `ws` from 6.1.4 to 7.5.10 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@6.1.4...7.5.10) Removes `got` Updates `nodemon` from 2.0.15 to 2.0.22 - [Release notes](https://github.com/remy/nodemon/releases) - [Commits](remy/nodemon@v2.0.15...v2.0.22) Updates `path-to-regexp` from 0.1.7 to 0.1.10 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v0.1.7...v0.1.10) Updates `pug-code-gen` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug-code-gen@3.0.2...pug-code-gen@3.0.3) Updates `send` from 0.17.2 to 0.18.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.17.2...0.18.0) Updates `serve-static` from 1.14.2 to 1.16.0 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md) - [Commits](expressjs/serve-static@v1.14.2...1.16.0) Updates `socket.io-parser` from 3.3.2 to 3.3.4 - [Release notes](https://github.com/Automattic/socket.io-parser/releases) - [Changelog](https://github.com/socketio/socket.io-parser/blob/3.3.4/CHANGELOG.md) - [Commits](socketio/socket.io-parser@3.3.2...3.3.4) Updates `tar` from 6.1.11 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.11...v6.2.1) Updates `xmlhttprequest-ssl` from 1.5.5 to 1.6.3 - [Commits](mjwwit/node-XMLHttpRequest@1.5.5...1.6.3) --- updated-dependencies: - dependency-name: express dependency-version: 4.20.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: passport dependency-version: 0.6.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: pug dependency-version: 3.0.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: socket.io dependency-version: 2.5.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: body-parser dependency-version: 1.20.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: braces dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-version: 0.4.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: engine.io dependency-version: 3.6.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: parseuri dependency-version: 0.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 7.5.10 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: got dependency-version: dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nodemon dependency-version: 2.0.22 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: path-to-regexp dependency-version: 0.1.10 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: pug-code-gen dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-version: 0.18.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-version: 1.16.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: socket.io-parser dependency-version: 3.3.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 6.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: xmlhttprequest-ssl dependency-version: 1.6.3 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 8 updates in the / directory:
4.17.34.20.00.4.10.6.03.0.23.0.32.3.02.5.03.0.23.0.39.6.0removed2.0.152.0.226.1.116.2.1Updates
expressfrom 4.17.3 to 4.20.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
21df4214.20.04c9ddc1feat: upgrade to serve-static@0.16.09ebe5d5feat: upgrade to send@0.19.0 (#5928)ec4a01bfeat: upgrade to body-parser@1.20.3 (#5926)54271f6fix: don't render redirect values in anchor href125bb74path-to-regexp@0.1.10 (#5902)2a980admerge-descriptors@1.0.3 (#5781)a3e7e05docs: specify new instructions forquestionanddiscussc5addb9deps: path-to-regexp@0.1.8 (#5603)e35380adocs: add@IamLizuto the triage team (#5836)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express since your current version.
Updates
passportfrom 0.4.1 to 0.6.0Changelog
Sourced from passport's changelog.
... (truncated)
Commits
c33067b0.6.03052bb4Update changelog.42630cbMerge pull request #900 from jaredhanson/fix-fixation8dd79feUse utils-merge rather than Object.assign for compatibility.4f6bd5bChange keepSessionData to keepSessionData.46756e5Silence verbose logging.987b191Add tests.f8a175fAdd tests.29a90d6No need to guard callback existence.bfba8a1Add tests.Updates
pugfrom 3.0.2 to 3.0.3Release notes
Sourced from pug's releases.
Commits
32acfe8fix: ensure template names are valid identifiers (#3438)4767cafrefactor: convert pug-error to TypeScript (#3355)a724446chore: update character-parser (#3354)6cca8f7docs: fix GitHub format in README (#3335)Updates
socket.iofrom 2.3.0 to 2.5.0Changelog
Sourced from socket.io's changelog.
Commits
baa6804chore(release): 2.5.0f223178fix: prevent the socket from joining a room after disconnection226cc16fix: only set 'connected' to true after middleware execution05e1278fix: fix race condition in dynamic namespaces22d4bdffix: ignore packet received after disconnectiondfded53chore: update engine.io version to 3.6.0e6b8697chore(release): 2.4.1a169050revert: fix(security): do not allow all origins by default873fdc5chore(release): 2.4.0f78a575fix(security): do not allow all origins by defaultUpdates
body-parserfrom 1.19.2 to 1.20.3Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
Commits
17529511.20.339744cfchore: linter (#534)b2695c4Merge commit from forkade0f3fadd scorecard to readme (#531)99a1bd6deps: qs@6.12.3 (#521)9478591fix: pin to node@22.4.183db46aci: fix errors in ci github action for node 8 and 9 (#523)9d4e212chore: add support for OSSF scorecard reporting (#522)ee913741.20.2368a93aFix strict json error message on Node.js 19+Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
bracesfrom 3.0.2 to 3.0.3Commits
74b2db23.0.388f1429update eslint. lint, fix unit tests.415d660Snyk js braces 6838727 (#40)190510ffix tests, skip 1 test in test/braces.expand716eb9freadme bumpa5851e5Merge pull request #37 from coderaiser/fix/vulnerability2092bd1feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cffix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9remove funding file665ab5dupdate keepEscaping doc (#27)Updates
cookiefrom 0.3.1 to 0.4.1Release notes
Sourced from cookie's releases.
Changelog
Sourced from cookie's changelog.
Commits
b22458d0.4.1fa5fe95build: fix typo in Travis CI directive2436f3fbuild: use nyc for code coverage08e98eebuild: Node.js@13.1380372a4build: remove deprecated Travis CI directivee248786Fix maxAge option to reject invalid values7e1398fbuild: Node.js@13.12cb5746dbuild: Node.js@10.209b4abbdbuild: mocha@7.1.1004b693build: Node.js@13.10Updates
engine.iofrom 3.4.2 to 3.6.2Commits
Updates
parseurifrom 0.0.5 to 0.0.6Commits
Updates
wsfrom 6.1.4 to 7.5.10Release notes
Sourced from ws's releases.
... (truncated)
Commits
d962d70[dist] 7.5.1022c2876[security] Fix crash when the Upgrade header cannot be read (#2231)8a78f87[dist] 7.5.90435e6e[security] Fix same host check for ws+unix: redirects4271f07[dist] 7.5.8dc1781b[security] Drop sensitive headers when following insecure redirects2758ed3[fix] Abort the handshake if the Upgrade header is invalida370613[dist] 7.5.71f72e2e[security] Drop sensitive headers when following redirects (#2013)8ecd890[dist] 7.5.6Removes
gotUpdates
nodemonfrom 2.0.15 to 2.0.22Release notes
Sourced from nodemon's releases.
... (truncated)
Commits
c971fdcMerge branch 'main' of github.com:remy/nodemonb9679a2chore: supportersf7816e4fix: remove ts mapping if loader present9f3ffdbOne more fixabc8522Get rid of spawning shell windows if nodemon is started without console.b11ddd1Merge branch 'main' of github.com:remy/nodemon204af11chore: missing supporters1468397fix: remove ts mapping if loader present26b1f0fchore: add conventional commit checkadaafa1One more fixUpdates
path-to-regexpfrom 0.1.7 to 0.1.10Release notes
Sourced from path-to-regexp's releases.
Commits
c827fce0.1.1029b96b4Add backtrack protection to parametersac4c234Update repo url (#314)bdb66350.1.9c4272e4Allow a non-lookahead regex (#312)51a19550.1.8114f62dAdd support for named matching groups (#301)Updates
pug-code-genfrom 3.0.2 to 3.0.3Release notes
Sourced from pug-code-gen's releases.
Commits
32acfe8fix: ensure template names are valid identifiers (#3438)4767cafrefactor: convert pug-error to TypeScript (#3355)a724446chore: update character-parser (#3354)6cca8f7docs: fix GitHub format in README (#3335)d4b7f60Properly handle errors originating from included files when compileDebug is e...d6f0615fix capture groups for "each" statements (#3274)73ea7cffix: keep lexer plugins inside tag interpolation (#3296)29a53c5fix: Fix pug-lexer parsed escaped interpolations incorrectly (#3299)60b1b15chore: update supported versions (#3315)Updates
sendfrom 0.17.2 to 0.18.0Changelog
Sourced from send's changelog.
Commits
b69cbb30.18.0f53edbbLimit the headers removed for 304 response706d6dddocs: add security policyb690ba4docs: fix linux build badge linkfed09ffdocs: update copyrightaee1a65deps: destroy@1.2.06060bdadeps: on-finished@2.4.18055f78build: Node.js@17.75364219build: mocha@9.2.2f3cf8a9deps: statuses@2.0.1Updates
serve-staticfrom 1.14.2 to 1.16.0Release notes
Sourced from serve-static's releases.
Changelog
Sourced from serve-static's changelog.
Commits
48c73971.16.00c11fadMerge commit from fork9b5a12a1.15.0a39a0dfdocs: update CI linkd702ea2build: Node.js@17.8ff1510adeps: send@0.18.0813c7e4build: mocha@9.2.22e029f9build: Node.js@17.73269f31build: supertest@6.2.271cd4f8build: mocha@9.2.1Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for serve-static since your current version.
Updates
socket.io-parserfrom 3.3.2 to 3.3.4Release notes
Sourced from socket.io-parser's releases.
Changelog
Sourced from socket.io-parser's changelog.
Commits
1e9ebc6chore(release): 3.3.4ee00660fix: check the format of the event name (#125)cd11e38chore(release): 3.3.3fb21e42fix: check the format of the index of each attachmentUpdates
tarfrom 6.1.11 to 6.2.1Release notes
Sourced from tar's releases.
Changelog
Sourced from tar's changelog.