-
Notifications
You must be signed in to change notification settings - Fork 128
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the npm_and_yarn group across 1 directory with 13 updates #136
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/npm_and_yarn/npm_and_yarn-b96e04ecd2
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [express](https://github.com/expressjs/express) | `4.18.2` | `4.19.2` | | [firebase-tools](https://github.com/firebase/firebase-tools) | `12.9.1` | `13.6.0` | | [@grpc/grpc-js](https://github.com/grpc/grpc-node) | `1.8.21` | `1.8.22` | | [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.2.1` | `4.2.3` | | [ws](https://github.com/websockets/ws) | `7.4.6` | `7.5.10` | | [protobufjs](https://github.com/protobufjs/protobuf.js) | `7.2.4` | `7.2.5` | | [firebase-admin](https://github.com/firebase/firebase-admin-node) | `11.11.1` | `12.1.1` | | [jose](https://github.com/panva/jose) | `4.15.3` | `4.15.7` | | [jsrsasign](https://github.com/kjur/jsrsasign) | `10.5.26` | `removed` | | [@simplewebauthn/server](https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server) | `6.3.0-alpha.1` | `10.0.0` | | [undici](https://github.com/nodejs/undici) | `5.26.5` | `5.28.4` | | [firebase](https://github.com/firebase/firebase-js-sdk) | `10.7.1` | `10.12.2` | Updates `express` from 4.18.2 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.18.2...4.19.2) Updates `firebase-tools` from 12.9.1 to 13.6.0 - [Release notes](https://github.com/firebase/firebase-tools/releases) - [Changelog](https://github.com/firebase/firebase-tools/blob/master/CHANGELOG.md) - [Commits](firebase/firebase-tools@v12.9.1...v13.6.0) Updates `@grpc/grpc-js` from 1.8.21 to 1.8.22 - [Release notes](https://github.com/grpc/grpc-node/releases) - [Commits](https://github.com/grpc/grpc-node/compare/@grpc/[email protected]...@grpc/[email protected]) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `browserify-sign` from 4.2.1 to 4.2.3 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.2.1...v4.2.3) Updates `ws` from 7.4.6 to 7.5.10 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@7.4.6...7.5.10) Updates `protobufjs` from 7.2.4 to 7.2.5 - [Release notes](https://github.com/protobufjs/protobuf.js/releases) - [Changelog](https://github.com/protobufjs/protobuf.js/blob/master/CHANGELOG.md) - [Commits](protobufjs/protobuf.js@protobufjs-v7.2.4...protobufjs-v7.2.5) Updates `firebase-admin` from 11.11.1 to 12.1.1 - [Release notes](https://github.com/firebase/firebase-admin-node/releases) - [Commits](firebase/firebase-admin-node@v11.11.1...v12.1.1) Updates `jose` from 4.15.3 to 4.15.7 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/v4.15.7/CHANGELOG.md) - [Commits](panva/jose@v4.15.3...v4.15.7) Removes `jsrsasign` Updates `@simplewebauthn/server` from 6.3.0-alpha.1 to 10.0.0 - [Release notes](https://github.com/MasterKale/SimpleWebAuthn/releases) - [Changelog](https://github.com/MasterKale/SimpleWebAuthn/blob/master/CHANGELOG.md) - [Commits](https://github.com/MasterKale/SimpleWebAuthn/commits/v10.0.0/packages/server) Updates `undici` from 5.26.5 to 5.28.4 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v5.26.5...v5.28.4) Updates `firebase` from 10.7.1 to 10.12.2 - [Release notes](https://github.com/firebase/firebase-js-sdk/releases) - [Changelog](https://github.com/firebase/firebase-js-sdk/blob/master/CHANGELOG.md) - [Commits](https://github.com/firebase/firebase-js-sdk/compare/[email protected]@10.12.2) --- updated-dependencies: - dependency-name: express dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: firebase-tools dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@grpc/grpc-js" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: braces dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ws dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: protobufjs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: firebase-admin dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: jose dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jsrsasign dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@simplewebauthn/server" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: undici dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: firebase dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update Javascript code
labels
Jun 18, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update Javascript code
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 13 updates in the / directory:
4.18.2
4.19.2
12.9.1
13.6.0
1.8.21
1.8.22
3.0.2
3.0.3
4.2.1
4.2.3
7.4.6
7.5.10
7.2.4
7.2.5
11.11.1
12.1.1
4.15.3
4.15.7
10.5.26
removed
6.3.0-alpha.1
10.0.0
5.26.5
5.28.4
10.7.1
10.12.2
Updates
express
from 4.18.2 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
04bc627
4.19.2da4d763
Improved fix for open redirect allow list bypass4f0f6cc
4.19.1a003cfa
Allow passing non-strings to res.location with new encoding handling checks f...a1fa90f
fixed un-edited version in history.md for 4.19.011f2b1d
build: fix build due to inconsistent supertest behavior in older versions084e365
4.19.00867302
Prevent open redirect allow list bypass due to encodeurl567c9c6
Add note on how to update docs for new release (#5541)69a4cf2
deps: [email protected]Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates
firebase-tools
from 12.9.1 to 13.6.0Release notes
Sourced from firebase-tools's releases.
... (truncated)
Commits
f6b7d05
13.6.0a26c3d0
Ignore quota project in GCF source uploads (#6917)476bd33
Update to PubSub emulator 0.8.2 (#6916)ccab9b7
Add Service Usage Consumer role to GitHub Actions service account (#6895)4c1bd42
Switching a few more places to getters (#6914)6950829
Fix "could not assert Secret Manager permissions" Cloud Build error (#6904)4a17ca7
Refactor api.ts file constants to getters (#6913)c6d1615
Update Firestore Emulator version (#6912)90b6506
Vector config support (#6900)dc13cb9
make fetchLinkableGitRepositories get all linkable git repositories (#6889)Updates
@grpc/grpc-js
from 1.8.21 to 1.8.22Release notes
Sourced from
@grpc/grpc-js
's releases.Commits
a8a0203
Merge pull request from GHSA-7v5v-9h63-cj863b110cd
grpc-js: Bump to 1.8.228e62222
grpc-js: Avoid buffering significantly more than max_receive_message_size per...9d83947
Merge pull request #2742 from sergiitk/backport-1.8-psm-interop-common-prod-t...00f348c
Merge pull request #2729 from sergiitk/psm-interop-common-prod-tests36d105b
Merge pull request #2737 from murgatroid99/backport-1.8-grpc-js_linkify-it_fix969e305
Merge pull request #2735 from murgatroid99/grpc-js_linkify-it_fixd78216f
Merge pull request #2715 from sergiitk/backport-1.8-psm-interop-pkg-devf38966a
Merge pull request #2712 from sergiitk/psm-interop-pkg-devffefff2
Merge pull request #2640 from XuanWang-Amos/backport-1.8-psm-interop-shared-b...Updates
braces
from 3.0.2 to 3.0.3Commits
74b2db2
3.0.388f1429
update eslint. lint, fix unit tests.415d660
Snyk js braces 6838727 (#40)190510f
fix tests, skip 1 test in test/braces.expand716eb9f
readme bumpa5851e5
Merge pull request #37 from coderaiser/fix/vulnerability2092bd1
feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cf
fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9
remove funding file665ab5d
update keepEscaping doc (#27)Updates
browserify-sign
from 4.2.1 to 4.2.3Changelog
Sourced from browserify-sign's changelog.
Commits
bf2c3ec
v4.2.39247adf
[patch] widen support to 0.12f427270
[Deps] update `parse-asn187f3a35
[Dev Deps] updateaud
,npmignore
,tape
fb261ce
[Deps] updateelliptic
4d0ee49
[patch] drop minimum node support to v19e2bf12
[Deps] pinhash-base
to ~3.0, due to a breaking change168e16f
[Deps] pinelliptic
due to a breaking change37a4758
[actions] remove redundant finisher4af5a90
v4.2.2Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates
ws
from 7.4.6 to 7.5.10Release notes
Sourced from ws's releases.
... (truncated)
Commits
d962d70
[dist] 7.5.1022c2876
[security] Fix crash when the Upgrade header cannot be read (#2231)8a78f87
[dist] 7.5.90435e6e
[security] Fix same host check for ws+unix: redirects4271f07
[dist] 7.5.8dc1781b
[security] Drop sensitive headers when following insecure redirects2758ed3
[fix] Abort the handshake if the Upgrade header is invalida370613
[dist] 7.5.71f72e2e
[security] Drop sensitive headers when following redirects (#2013)8ecd890
[dist] 7.5.6Updates
protobufjs
from 7.2.4 to 7.2.5Release notes
Sourced from protobufjs's releases.
Changelog
Sourced from protobufjs's changelog.
Commits
4436cc7
chore: release master (#1925)e93286e
fix: deprecation warning for new Buffer (#1905)eaf9f0a
fix: crash in comment parsing (#1890)f2a8620
fix: possible infinite loop when parsing option (#1923)Updates
firebase-admin
from 11.11.1 to 12.1.1Release notes
Sourced from firebase-admin's releases.
... (truncated)
Commits
e2515f2
[chore] Release 12.1.1 (#2561)4d4fd39
build(deps): updgrade jwks-rsa (#2570)1754b7e
--- (#2568)72f0169
--- (#2566)8f622cf
--- (#2567)f8f8eb9
--- (#2569)ee78c87
build(deps-dev): bump@firebase/auth-types
from 0.12.1 to 0.12.2 (#2556)f837c23
build(deps-dev): bump@microsoft/api-extractor
from 7.43.2 to 7.43.7 (#2559)41aea3a
chore: upgrade firestore to 7.7.0 (#2560)26cd8b0
build(deps-dev): bump@firebase/app-compat
from 0.2.32 to 0.2.33 (#2555)Updates
jose
from 4.15.3 to 4.15.7Release notes
Sourced from jose's releases.
Changelog
Sourced from jose's changelog.
Commits
5084808
chore(release): 4.15.7122c939
chore(release): 4.15.6e36d69e
fix: add a workerd package.json target765aafd
chore(release): 4.15.5b36e45e
test: add export check to x509 pem import testse839ecb
test: stop testing JWE RSA1_5 Algorithm1b91d88
fix: add a maxOutputLength option to zlib inflate9ca2b24
build: remove release actionf3035d8
chore: cleanup after releasef0bb220
chore(release): 4.15.4Removes
jsrsasign
Updates
@simplewebauthn/server
from 6.3.0-alpha.1 to 10.0.0Release notes
Sourced from
@simplewebauthn/server
's releases.... (truncated)
Changelog
Sourced from
@simplewebauthn/server
's changelog.... (truncated)
Commits
81d9e49
chore(release): publish v10.0.07a86e80
Modernize server method docstringseb1988a
Require rpID arg when generating auth optionsb316c3f
Update uses of base64url string methods84a2ea5
Clarify string encoding on isoBase64URL methodsa95489e
Remove trailing close parenthesisd470a1c
Explicitly disallow string userIDs9ebd9ec
Update generateRegistrationOptions tests4c3f693
Generate user IDs by defaultb1b6d33
Add method to generate user IDsUpdates
undici
from 5.26.5 to 5.28.4Release notes
Sourced from undici's releases.