🚨 [security] Update @restorecommerce/gql-bot 1.0.8 → 1.0.9 (patch) #100
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ @restorecommerce/gql-bot (1.0.8 → 1.0.9) · Repo · Changelog
Release Notes
1.0.9 (from changelog)
Does any of this look wrong? Please let us know.
Security Advisories 🚨
🚨 graphql Uncontrolled Resource Consumption vulnerability
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Sorry, we couldn't find anything useful about this release.
Release Notes
4.0.2
4.0.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 29 commits:
Release 4.0.2.
Switch back to async stat / lstat
tsc: disable source maps
Merge pull request #199 from yuheiy/fix-promise-typing
improve typing for readdirpPromise
Merge pull request #198 from karlhorky/patch-1
Remove fileFilter "array of strings" from readme
Remove nodejs v14 from ci, macos-arm does not have it
Fix ci
readme
Remove dependabot
README
Release 4.0.1.
Fix esm import
Release 4.0.0.
readme
Upgrade devdeps
Lint
readme
Rewrite in typescript. Use hybrid ESM/commonjs
Enable GitHub Sponsors
Funding
Change version
Remove glob support
Update dependabot.yml
Merge pull request #177 from paulmillr/dependabot/add-v2-config-file
Upgrade to GitHub-native Dependabot
Merge pull request #174 from BlackYuzia/master
typo fix in readme
Commits
See the full diff on Github. The new version differs by 28 commits:
chore(publish): 4.0.0
Merge pull request #55 from benlesh/various-fixes
chore: remove Node 0.10. Unfortunately, we can't build with tsc in this environment, because of a TS incompatibility
refactor: Revert to `symbol` from `unique symbol`.
docs: Be more specific about the nature of this pony/polyfill
chore: update copyright year
fix: If Symbol.for doesn't exist, just use Symbol
chore(deps): bump lodash from 4.17.4 to 4.17.20 (#52)
chore: update TypeScript
chore(publish): 3.0.0
fix(TypeScript): `Symbol.observable` is now `unique symbol`.
fix(TypeScript): `Symbol[Symbol.observable]` is no longer incorrectly defined
chore(publish): 2.0.3
Add ponyfill.d.ts to release file allow-list (#51)
chore(publish): 2.0.2
Add ponyfill TypeScript type definitions (#50)
chore(publish): 2.0.1
fix(package.json): es/ponyfill.js no longer typoed
Add note for possible breaking change.
chore(publish): 2.0.0
fix: Resolve issues in environments with frozen Symbol
Update package.json (#46)
Merge pull request #45 from MichaelDeBoey/patch-1
Update .travis.yml
Typo fix (#39)
cleanup readme example observable (#36)
docs(README): add more information about usage.
Rename readme.md to README.md
Sorry, we couldn't find anything useful about this release.
Release Notes
2.8.1
2.8.0
2.7.0
2.6.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 38 commits:
2.8.1
Merge pull request #275 from microsoft/bug/es5-compat
Remove use of ES2015 syntax
Include non-enumerable keys in __importStar helper (#272)
Add missing registry-url parameter
Merge pull request #271 from microsoft/fix-publish
Fix publish workflow
2.8.0
Merge pull request #270 from microsoft/rewriteRelativeImportExtension
Missed update
Little optimizations
Add URL-ish test
Combine tsx case into regex
Test and fix invalid declaration-looking extensions
Do more with a regex
Shorten by one line
Case insensitivity, remove lookbehind
Add rewriteRelativeImportExtension helper
Merge pull request #269 from microsoft/test-infrastructure
Test export structure
Bump version to 2.7.0.
Use global 'Iterator.prototype' for downlevel generators (#267)
Implement deterministic collapse of 'await' in 'await using' (#262)
2.6.3
'await using' normative changes (#258)
Bump the github-actions group with 3 updates (#253)
Bump the github-actions group with 1 update (#242)
Bump the github-actions group with 1 update (#241)
Bump the github-actions group with 2 updates (#240)
JSDoc typo on `__exportStar`. (#221)
Bump the github-actions group with 1 update (#233)
Bump the github-actions group with 1 update (#230)
Bump the github-actions group with 2 updates (#228)
Pin CI actions missed in previous PR
CI: Hashpin sensitive actions and install dependabot (#226)
Fix __asyncGenerator to properly handle AsyncGeneratorUnwrapYieldResumption (#222)
Update codeql workflow using GUI (#223)
CI: set minimal permissions for GitHub Workflows (#218)
🆕 @apollo/client (added, 3.11.8)
🆕 @graphql-typed-document-node/core (added, 3.2.0)
🆕 @wry/caches (added, 1.0.1)
🆕 @wry/trie (added, 0.5.0)
🆕 @wry/trie (added, 0.4.3)
🆕 data-uri-to-buffer (added, 4.0.1)
🆕 fetch-blob (added, 3.2.0)
🆕 formdata-polyfill (added, 4.0.10)
🆕 hoist-non-react-statics (added, 3.3.2)
🆕 loose-envify (added, 1.4.0)
🆕 node-domexception (added, 1.0.0)
🆕 object-assign (added, 4.1.1)
🆕 prop-types (added, 15.8.1)
🆕 rehackt (added, 0.1.0)
🆕 response-iterator (added, 0.2.6)
🆕 web-streams-polyfill (added, 3.3.3)
🆕 chalk (added, 5.3.0)
🆕 node-fetch (added, 3.3.2)
🆕 react-is (added, 16.13.1)
🗑️ @restorecommerce/dataset-demoshop-catalog-transformer (removed)
🗑️ @restorecommerce/dataset-system-units-transformer (removed)
🗑️ @types/node (removed)
🗑️ @types/zen-observable (removed)
🗑️ apollo-cache (removed)
🗑️ apollo-cache-inmemory (removed)
🗑️ apollo-client (removed)
🗑️ apollo-link (removed)
🗑️ apollo-link-http (removed)
🗑️ apollo-link-http-common (removed)
🗑️ apollo-utilities (removed)
🗑️ csv-parser (removed)
🗑️ node-xlsx (removed)
🗑️ object-hash (removed)
🗑️ undici-types (removed)
🗑️ xlsx (removed)
🗑️ uuid (removed)
🗑️ through2 (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands