Bump the npm_and_yarn group across 3 directories with 28 updates#7
Open
dependabot[bot] wants to merge 1 commit intocanaryfrom
Conversation
Bumps the npm_and_yarn group with 1 update in the /test/integration/with-electron/app directory: [electron](https://github.com/electron/electron). Bumps the npm_and_yarn group with 1 update in the /turbopack/benchmark-apps directory: [mdast-util-to-hast](https://github.com/syntax-tree/mdast-util-to-hast). Bumps the npm_and_yarn group with 24 updates in the /turbopack/crates/turbopack-tracing/tests/node-file-trace directory: | Package | From | To | | --- | --- | --- | | [es5-ext](https://github.com/medikoo/es5-ext) | `0.10.62` | `0.10.64` | | [express](https://github.com/expressjs/express) | `4.18.2` | `4.22.0` | | [firebase](https://github.com/firebase/firebase-js-sdk) | `7.24.0` | `10.9.0` | | [json5](https://github.com/json5/json5) | `1.0.1` | `1.0.2` | | [semver](https://github.com/npm/node-semver) | `7.3.8` | `7.5.2` | | [tar](https://github.com/isaacs/node-tar) | `6.1.11` | `6.2.1` | | [axios](https://github.com/axios/axios) | `0.21.4` | `0.30.2` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.2.1` | `4.2.5` | | [cookiejar](https://github.com/bmeck/node-cookiejar) | `2.1.3` | `2.1.4` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [esbuild](https://github.com/evanw/esbuild) | `0.15.12` | `0.25.0` | | [word-wrap](https://github.com/jonschlinkert/word-wrap) | `1.2.3` | `1.2.5` | | [@google-cloud/firestore](https://github.com/googleapis/nodejs-firestore) | `4.15.1` | `6.2.0` | | [mongoose](https://github.com/Automattic/mongoose) | `5.13.15` | `6.13.6` | | [pug](https://github.com/pugjs/pug) | `3.0.2` | `3.0.3` | | [sequelize](https://github.com/sequelize/sequelize) | `5.22.5` | `6.29.0` | | [sqlite3](https://github.com/TryGhost/node-sqlite3) | `5.1.2` | `5.1.5` | | [vm2](https://github.com/patriksimek/vm2) | `3.9.11` | `3.10.0` | | [engine.io](https://github.com/socketio/socket.io) | `3.6.0` | `3.6.2` | | [jose](https://github.com/panva/jose) | `2.0.6` | `2.0.7` | | [luxon](https://github.com/moment/luxon) | `3.0.4` | `3.7.2` | | [msgpackr](https://github.com/kriszyp/msgpackr) | `1.7.2` | `1.11.8` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `6.8.0` | `6.10.1` | | [socket.io-parser](https://github.com/Automattic/socket.io-parser) | `3.3.2` | `3.3.4` | Updates `electron` from 5.0.0 to 35.7.5 - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v5.0.0...v35.7.5) Updates `mdast-util-to-hast` from 13.2.0 to 13.2.1 - [Release notes](https://github.com/syntax-tree/mdast-util-to-hast/releases) - [Commits](syntax-tree/mdast-util-to-hast@13.2.0...13.2.1) Updates `es5-ext` from 0.10.62 to 0.10.64 - [Release notes](https://github.com/medikoo/es5-ext/releases) - [Changelog](https://github.com/medikoo/es5-ext/blob/main/CHANGELOG.md) - [Commits](medikoo/es5-ext@v0.10.62...v0.10.64) Updates `express` from 4.18.2 to 4.22.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md) - [Commits](expressjs/express@4.18.2...4.22.0) Updates `firebase` from 7.24.0 to 10.9.0 - [Release notes](https://github.com/firebase/firebase-js-sdk/releases) - [Changelog](https://github.com/firebase/firebase-js-sdk/blob/main/CHANGELOG.md) - [Commits](https://github.com/firebase/firebase-js-sdk/compare/firebase@7.24.0...firebase@10.9.0) Updates `json5` from 1.0.1 to 1.0.2 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v1.0.1...v1.0.2) Updates `semver` from 7.3.8 to 7.5.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.8...v7.5.2) Updates `tar` from 6.1.11 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.11...v6.2.1) Updates `axios` from 0.21.4 to 0.30.2 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.21.4...v0.30.2) Updates `browserify-sign` from 4.2.1 to 4.2.5 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.2.1...v4.2.5) Updates `cookiejar` from 2.1.3 to 2.1.4 - [Commits](https://github.com/bmeck/node-cookiejar/commits) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `esbuild` from 0.15.12 to 0.25.0 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2022.md) - [Commits](evanw/esbuild@v0.15.12...v0.25.0) Updates `follow-redirects` from 1.15.2 to 1.15.11 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.15.2...v1.15.11) Updates `word-wrap` from 1.2.3 to 1.2.5 - [Release notes](https://github.com/jonschlinkert/word-wrap/releases) - [Commits](jonschlinkert/word-wrap@1.2.3...1.2.5) Updates `@google-cloud/firestore` from 4.15.1 to 6.2.0 - [Release notes](https://github.com/googleapis/nodejs-firestore/releases) - [Changelog](https://github.com/googleapis/nodejs-firestore/blob/main/CHANGELOG.md) - [Commits](googleapis/nodejs-firestore@v4.15.1...v6.2.0) Updates `mongoose` from 5.13.15 to 6.13.6 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@5.13.15...6.13.6) Updates `pug` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug@3.0.2...pug@3.0.3) Updates `sequelize` from 5.22.5 to 6.29.0 - [Release notes](https://github.com/sequelize/sequelize/releases) - [Commits](sequelize/sequelize@v5.22.5...v6.29.0) Updates `sqlite3` from 5.1.2 to 5.1.5 - [Release notes](https://github.com/TryGhost/node-sqlite3/releases) - [Commits](TryGhost/node-sqlite3@v5.1.2...v5.1.5) Updates `vm2` from 3.9.11 to 3.10.0 - [Release notes](https://github.com/patriksimek/vm2/releases) - [Commits](patriksimek/vm2@3.9.11...v3.10.0) Updates `dottie` from 2.0.2 to 2.0.6 - [Release notes](https://github.com/mickhansen/dottie.js/releases) - [Commits](mickhansen/dottie.js@v2.0.2...v2.0.6) Updates `engine.io` from 3.6.0 to 3.6.2 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/commits) Updates `jose` from 2.0.6 to 2.0.7 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/v2.0.7/CHANGELOG.md) - [Commits](panva/jose@v2.0.6...v2.0.7) Updates `luxon` from 3.0.4 to 3.7.2 - [Changelog](https://github.com/moment/luxon/blob/master/CHANGELOG.md) - [Commits](moment/luxon@3.0.4...3.7.2) Updates `msgpackr` from 1.7.2 to 1.11.8 - [Release notes](https://github.com/kriszyp/msgpackr/releases) - [Commits](https://github.com/kriszyp/msgpackr/commits/v1.11.8) Updates `nodemailer` from 6.8.0 to 6.10.1 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v6.8.0...v6.10.1) Updates `socket.io-parser` from 3.3.2 to 3.3.4 - [Release notes](https://github.com/Automattic/socket.io-parser/releases) - [Changelog](https://github.com/socketio/socket.io-parser/blob/3.3.4/CHANGELOG.md) - [Commits](socketio/socket.io-parser@3.3.2...3.3.4) --- updated-dependencies: - dependency-name: electron dependency-version: 35.7.5 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: mdast-util-to-hast dependency-version: 13.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: es5-ext dependency-version: 0.10.64 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express dependency-version: 4.22.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: firebase dependency-version: 10.9.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: json5 dependency-version: 1.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-version: 7.5.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 6.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 0.30.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-version: 4.2.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookiejar dependency-version: 2.1.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-version: 0.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: esbuild dependency-version: 0.25.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-version: 1.15.11 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: word-wrap dependency-version: 1.2.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@google-cloud/firestore" dependency-version: 6.2.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: mongoose dependency-version: 6.13.6 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: pug dependency-version: 3.0.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: sequelize dependency-version: 6.29.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: sqlite3 dependency-version: 5.1.5 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: vm2 dependency-version: 3.10.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: dottie dependency-version: 2.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: engine.io dependency-version: 3.6.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jose dependency-version: 2.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: luxon dependency-version: 3.7.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: msgpackr dependency-version: 1.11.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nodemailer dependency-version: 6.10.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: socket.io-parser dependency-version: 3.3.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 1 update in the /test/integration/with-electron/app directory: electron.
Bumps the npm_and_yarn group with 1 update in the /turbopack/benchmark-apps directory: mdast-util-to-hast.
Bumps the npm_and_yarn group with 24 updates in the /turbopack/crates/turbopack-tracing/tests/node-file-trace directory:
0.10.620.10.644.18.24.22.07.24.010.9.01.0.11.0.27.3.87.5.26.1.116.2.10.21.40.30.24.2.14.2.52.1.32.1.40.2.00.2.20.15.120.25.01.2.31.2.54.15.16.2.05.13.156.13.63.0.23.0.35.22.56.29.05.1.25.1.53.9.113.10.03.6.03.6.22.0.62.0.73.0.43.7.21.7.21.11.86.8.06.10.13.3.23.3.4Updates
electronfrom 5.0.0 to 35.7.5Release notes
Sourced from electron's releases.
Commits
86d839abuild: correct CHECK syntax (#48106)5be0be7fix: ensure snapshot is valid (#48105)df232d1ci: cleanup use new arc cluster (#48007)ab51554ci: fixup mac runner hang (#47992)203abddci: use new arc cluster (#47913)ea17e83build: fix ffmpeg generation on Windows non-x64 (#47845)7b5d411build(dev-deps): drop unused@types/webpackdep (#47806)def6203build: deep update brace-expansion to resolve an audit alert (#47719)28d8ed0test: cleanup RenderFrame lifespan tests (#47795)ee8942dbuild: drop eslint-plugin-unicorn (#47690)Updates
mdast-util-to-hastfrom 13.2.0 to 13.2.1Release notes
Sourced from mdast-util-to-hast's releases.
Commits
174795b13.2.13d05b3aUpdate Node in Actionsab3a795Fix support for spaces in class namesefb5312Refactor to use@importsa5bc210Add declaration mapsb54955dAdd.tsbuildinfoto.gitignoreUpdates
es5-extfrom 0.10.62 to 0.10.64Release notes
Sourced from es5-ext's releases.
Changelog
Sourced from es5-ext's changelog.
Commits
f76b03dchore: Release v0.10.642881acdchore: Bump dependenciesc2e2bb9fix: Revert update meant to fix Powershell issue, as it's a regression16f2b72docs: Fix date in the changelogde4e03cchore: Release v0.10.633fd53b7chore: Upgradelint-stagedto v13bf8ed79chore: Ensure postinstall script does not crash on Windows2cbbb07chore: Bump dependencies22d0416chore: Bump LICENSE yeara52e957fix: Support ES2015+ function definitions infunction#toStringTokens()Updates
expressfrom 4.18.2 to 4.22.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)3a5edfafix(ci): updated github actions ci workflow (#6323)52d9781fix(test): add test for method routes without paths #5955Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express since your current version.
Updates
firebasefrom 7.24.0 to 10.9.0Commits
1eb302fVersion Packages (#8063)b498867Merge master into releasece88e71snapshot listeners source from cache (#7982)6d487d7Prevent using authTokenSyncURL if the string begins with a double slash (#8060)b4d59d6Merge master into release2b22838Fix glob pattern to work with Node 20 and its NPM version (#8059)feb5038Update CI node.js versions to 20.x (#8055)245dd26Enforce authTokenSyncURL being a path and not a url. (#8056)e60188dVersion Packages (#8046)7e2efbfMerge master into releaseUpdates
json5from 1.0.1 to 1.0.2Release notes
Sourced from json5's releases.
Changelog
Sourced from json5's changelog.
... (truncated)
Commits
a62db1e1.0.2e0c23fedocs: update CHANGELOG for v1.0.262a6540fix: add proto to objects and arraysUpdates
semverfrom 7.3.8 to 7.5.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
e7b78dechore: release 7.5.258c791ffix: diff when detecting major change from prerelease (#566)5c8efbcfix: preserve build in raw after inc (#565)717534efix: better handling of whitespace (#564)2f738e9chore: bump@npmcli/template-ossfrom 4.14.1 to 4.15.1 (#558)aa016a6chore: release 7.5.1d30d25afix: show type on invalid semver error (#559)09c69e2chore: bump@npmcli/template-ossfrom 4.13.0 to 4.14.1 (#555)5b02ad7chore: release 7.5.0e219bb4fix: throw on bad version with correct error message (#552)Maintainer changes
This version was pushed to npm by npm-cli-ops, a new releaser for semver since your current version.
Updates
tarfrom 6.1.11 to 6.2.1Release notes
Sourced from tar's releases.
Changelog
Sourced from tar's changelog.
... (truncated)
Commits
bef7b1e6.2.1fe8cd57prevent extraction in excessively deep subfoldersfe7ebfdremove security.md5bc9d406.2.0fe1ef5echangelog 6.2e483220get rid of npm lint stuff689928aci that works outside of npm orgdb6f539file inference improvements for .tbr and .tgz336fa8frefactor: dry and other pr commentseeba222chore: lint fixesUpdates
axiosfrom 0.21.4 to 0.30.2Release notes
Sourced from axios's releases.
... (truncated)
Commits
2fcb4ecchore: v0.30.2153f483chore: preversionee548fffix: tests failinga1b1d3ffix: backportmaxContentLengthvulnerability fix to v0.x (#7034)b17c4dechore: build latest versionad6b82achore: build latest versionda447d5chore(deps): bump form-data from 4.0.0 to 4.0.4 (#6978)6e922e4chore: added build artifactsa06ed1echore: added pre-release artifactsc010622feat: add type for allowAbsoluteUrls (#6849)Updates
browserify-signfrom 4.2.1 to 4.2.5Changelog
Sourced from browserify-sign's changelog.