chore(deps): bump the npm_and_yarn group across 1 directory with 32 updates
Type: Pull Request
State: Open
![dependabot[bot]](https://github.com/dependabot.png)
Association: None
Comments: 0
(about 22 hours ago)
(about 22 hours ago)
dependencies javascript
Bumps the npm_and_yarn group with 27 updates in the / directory:
Package | From | To |
---|---|---|
aws-sdk | 2.266.1 |
2.814.0 |
web3 | 1.0.0-beta.34 |
4.16.0 |
base-x | 3.0.5 |
3.0.11 |
bl | 1.2.2 |
1.2.3 |
brace-expansion | 1.1.11 |
1.1.12 |
browserify-sign | 4.0.4 |
4.2.3 |
cipher-base | 1.0.4 |
1.0.6 |
cookiejar | 2.1.2 |
2.1.4 |
decode-uri-component | 0.2.0 |
0.2.2 |
decompress | 4.2.0 |
4.2.1 |
express | 4.16.3 |
4.21.2 |
follow-redirects | 1.5.10 |
1.15.11 |
fstream | 1.0.11 |
1.0.12 |
get-func-name | 2.0.0 |
2.0.2 |
hosted-git-info | 2.6.1 |
2.8.9 |
https-proxy-agent | 2.2.1 |
2.2.4 |
ini | 1.3.5 |
1.3.8 |
js-yaml | 3.12.0 |
3.14.1 |
lodash.template | 4.4.0 |
4.5.0 |
mixin-deep | 1.3.1 |
1.3.2 |
moment | 2.22.2 |
2.30.1 |
pathval | 1.1.0 |
1.1.1 |
pbkdf2 | 3.0.16 |
3.1.3 |
sha.js | 2.4.11 |
2.4.12 |
simple-get | 2.8.1 |
2.8.2 |
thenify | 3.3.0 |
3.3.1 |
y18n | 3.2.1 |
3.2.2 |
Updates aws-sdk
from 2.266.1 to 2.814.0
Changelog
Sourced from aws-sdk's changelog.
2.814.0
- bugfix: Credentials: SDK will throw if shared ini file's profile name can be resolved to proto
- feature: EC2: EBS io2 volumes now supports Multi-Attach
- feature: PersonalizeRuntime: Updated FilterValues regex pattern to align with Filter Expression.
- feature: RDS: Adds IAM DB authentication information to the PendingModifiedValues output of the DescribeDBInstances API. Adds ClusterPendingModifiedValues information to the output of the DescribeDBClusters API.
2.813.0
- feature: ConfigService: Adding PutExternalEvaluation API which grants permission to deliver evaluation result to AWS Config
- feature: DLM: Provide Cross-account copy event based policy support in DataLifecycleManager (DLM)
- feature: EC2: C6gn instances are powered by AWS Graviton2 processors and offer 100 Gbps networking bandwidth. These instances deliver up to 40% better price-performance benefit versus comparable x86-based instances
- feature: Imagebuilder: This release adds support for building and distributing container images within EC2 Image Builder.
- feature: KMS: Added CreationDate and LastUpdatedDate timestamps to ListAliases API response
- feature: Route53: This release adds support for DNSSEC signing in Amazon Route 53.
- feature: Route53Resolver: Route 53 Resolver adds support for enabling resolver DNSSEC validation in virtual private cloud (VPC).
- feature: SQS: Amazon SQS adds queue attributes to enable high throughput FIFO.
- feature: ServiceCatalog: Support TagOptions sharing with Service Catalog portfolio sharing.
2.812.0
- feature: CostExplorer: This release updates the "MonitorArnList" from a list of String to be a list of Arn for both CreateAnomalySubscription and UpdateAnomalySubscription APIs
- feature: Location: Initial release of Amazon Location Service. A new geospatial service providing capabilities to render maps, geocode/reverse geocode, track device locations, and detect geofence entry/exit events.
- feature: QuickSight: QuickSight now supports connecting to federated data sources of Athena
- feature: WellArchitected: This is the first release of AWS Well-Architected Tool API support, use to review your workload and compare against the latest AWS architectural best practices.
2.811.0
- feature: Amp: (New Service) Amazon Managed Service for Prometheus is a fully managed Prometheus-compatible monitoring service that makes it easy to monitor containerized applications securely and at scale.
- feature: GreengrassV2: AWS IoT Greengrass V2 is a new major version of AWS IoT Greengrass. This release adds several updates such as modular components, continuous deployments, and improved ease of use.
- feature: IoTAnalytics: FileFormatConfiguration enables data store to save data in JSON or Parquet format. S3Paths enables you to specify the S3 objects that save your channel messages when you reprocess the pipeline.
- feature: IoTFleetHub: AWS IoT Fleet Hub, a new feature of AWS IoT Device Management that provides a web application for monitoring and managing device fleets connected to AWS IoT at scale.
- feature: IoTWireless: AWS IoT for LoRaWAN enables customers to setup a private LoRaWAN network by connecting their LoRaWAN devices and gateways to the AWS cloud without managing a LoRaWAN Network Server.
- feature: Iot: AWS IoT Rules Engine adds Kafka Action that allows sending data to Apache Kafka clusters inside a VPC. AWS IoT Device Defender adds custom metrics and machine-learning based anomaly detection.
- feature: IotDeviceAdvisor: AWS IoT Core Device Advisor is fully managed test capability for IoT devices. Device manufacturers can use Device Advisor to test their IoT devices for reliable and secure connectivity with AWS IoT.
- feature: Lambda: Added support for Apache Kafka as a event source. Added support for TumblingWindowInSeconds for streams event source mappings. Added support for FunctionResponseTypes for streams event source mappings
- feature: SSM: Adding support for Change Manager API content
2.810.0
- feature: DevOpsGuru: Documentation updates for DevOps Guru.
- feature: EC2: Add c5n.metal to ec2 instance types list
- feature: GlobalAccelerator: This release adds support for custom routing accelerators
2.809.0
- feature: AutoScaling: Documentation updates and corrections for Amazon EC2 Auto Scaling API Reference and SDKs.
- feature: CloudTrail: CloudTrailInvalidClientTokenIdException is now thrown when a call results in the InvalidClientTokenId error code. The Name parameter of the AdvancedEventSelector data type is now optional.
- feature: IoTSiteWise: Added the ListAssetRelationships operation and support for composite asset models, which represent structured sets of properties within asset models.
2.808.0
- feature: EC2: TGW connect simplifies connectivity of SD-WAN appliances; IGMP support for TGW multicast; VPC Reachability Analyzer for VPC resources connectivity analysis.
- feature: Kendra: Amazon Kendra now supports adding synonyms to an index through the new Thesaurus resource.
- feature: NetworkManager: This release adds API support for Transit Gateway Connect integration into AWS Network Manager.
2.807.0
... (truncated)
Commits
8875a35
Updates SDK to v2.814.0dd83d67
throw at invalid profile name in shared ini file (#3585)ee0c5a3
Updates SDK to v2.813.0468d15b
Updates SDK to v2.812.0c50132f
Update README.md with references to JS SDK V3 (#3582)3e19b08
Updates SDK to v2.811.0f26c00d
Updates SDK to v2.810.0b393a6e
Adds automatic PreSignedUrl generation to RDS.StartDBInstanceAutomatedBackups...fa57967
Updates SDK to v2.809.09a52018
Updates SDK to v2.808.0- Additional commits viewable in compare view
Updates web3
from 1.0.0-beta.34 to 4.16.0
Release notes
Sourced from web3's releases.
web3-eth@4.0.0-alpha.0
Initial alpha release
Install with
yarn add web3-eth@4.0.0-alpha.0
web3-core-requestmanager@4.0.0-alpha.0
Initial alpha release
Install with
yarn add web3-core-requestmanager@4.0.0-alpha.0
web3-providers-http@4.0.0-alpha.0
Initial alpha release
Install with
yarn add web3-providers-http@4.0.0-alpha.0
web3-providers-base@1.0.0-alpha.1
Changed
- Update version to
1.0.0-alpha.1
forweb3-providers-base
- Update version to
4.0.0-alpha.0
forweb3-utils
inweb3-providers-base
web3-utils@4.0.0-alpha.0
Initial alpha release
Install with
yarn add web3-utils@4.0.0-alpha.0
web3-packagetemplate@1.0.0-alpha.0
Initial alpha release
Install with
yarn add web3-packagetemplate@1.0.0-alpha.0
Changelog
Sourced from web3's changelog.
[4.16.0]
Fixed
web3
- Export Web3Account, Wallet and signature related types. (#7374)
web3-utils
- Make
fromWei
return "0" when input is0
(#7387)Removed
web3-eth-accounts
- Move signature related types to web3-types. Re-export them for backwards compatibility. (#7374)
Added
web3-types
web3-eth-accounts
- Updated Typescript version 4 -> 5 (#7272)
web3
- Updated Typescript version 4 -> 5 (#7272)
web3-core
- Updated Typescript version 4 -> 5 (#7272)
web3-account-abstraction
- RC release
web3-errors
- Updated Typescript version 4 -> 5 (#7272)
web3-eth
- Updated Typescript version 4 -> 5 (#7272)
web3-eth-contract
... (truncated)
Commits
aa197b8
add typescript and version bump to changelogs82ceab7
update web3-types2b7cf1c
v4.16.0 release926044b
chore(deps-dev): bump http-proxy-middleware from 2.0.6 to 2.0.7 (#7407)7a8df69
update typescript version to 5 (#7272)984cb7c
chore(deps): bump cross-spawn from 7.0.3 to 7.0.6 (#7404)3b122a2
fix: upgrade@cookbookdev/docsbot
from 4.24.0 to 4.24.4 (#7403)56d4aec
Replaces #7390, #7391, & #7400 (#7401)6379aa8
fix: remove force exit from blackbox tests (#7397)5437fbc
fix: upgrade@mdx-js/react
from 3.0.1 to 3.1.0 (#7395)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by luu-alex, a new releaser for web3 since your current version.
Updates base-x
from 3.0.5 to 3.0.11
Commits
043a888
3.0.112705ddd
[backport 3.x] Prohibit char codes that would overflow theBASE_MAP
3d43c0e
3.0.100a35446
Improve decoding performance4c10d33
3.0.9c9dcddd
Merge pull request #78 from cryptocoinjs/fix/space-alphabets6c54632
Fix alphabets with space in them69c09ed
Merge pull request #73 from terrierscript/patch-11dd3795
Update README.md806ef3f
3.0.8- Additional commits viewable in compare view
Updates bl
from 1.2.2 to 1.2.3
Commits
d69edfd
1.2.3847473a
test all branches0bd87ec
Fix unintialized memory accessdc097f3
test newer versions of Node- See full diff in compare view
Updates brace-expansion
from 1.1.11 to 1.1.12
Release notes
Sourced from brace-expansion's releases.
v1.1.12
- pkg: publish on tag 1.x c460dbd
- fmt ccb8ac6
- Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8
https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12
Commits
Updates browserify-sign
from 4.0.4 to 4.2.3
Changelog
Sourced from browserify-sign's changelog.
v4.2.3 - 2024-03-05
Commits
- [patch] widen support to 0.12
9247adf
- [patch] drop minimum node support to v1
4d0ee49
- [Dev Deps] update
aud
,npmignore
,tape
87f3a35
- [actions] remove redundant finisher
37a4758
- [Deps] pin
hash-base
to ~3.0, due to a breaking change9e2bf12
- [Deps] update
parse-asn1 [
f427270`](https://github.com/browserify/browserify-sign/commit/f427270ac11dc6be29f87d7afb046c16376a5a9c)- [Deps] update
elliptic
fb261ce
- [Deps] pin
elliptic
due to a breaking change168e16f
v4.2.2 - 2023-10-25
Fixed
- [Tests] log when openssl doesn't support cipher
[#37](https://github.com/crypto-browserify/browserify-sign/issues/37)
Commits
- Only apps should have lockfiles
09a8995
- [eslint] switch to eslint
83fe463
- [meta] add
npmignore
andauto-changelog
4418183
- [meta] fix package.json indentation
9ac5a5e
- [Tests] migrate from travis to github actions
d845d85
- [Fix]
sign
: throw on unsupported padding scheme8767739
- [Fix] properly check the upper bound for DSA signatures
85994cd
- [Tests] handle openSSL not supporting a scheme
f5f17c2
- [Deps] update
bn.js
,browserify-rsa
,elliptic
,parse-asn1
,readable-stream
,safe-buffer
a67d0eb
- [Dev Deps] update
nyc
,standard
,tape
cc5350b
- [Tests] always run coverage; downgrade
nyc
75ce1d5
- [meta] add
safe-publish-latest
dcf49ce
- [Tests] add
npm run posttest
75dd8fd
- [Dev Deps] update
tape
3aec038
- [Tests] skip unsupported schemes
703c83e
- [Tests] node < 6 lacks array
includes
3aa43cf
- [Dev Deps] fix eslint range
98d4e0d
v4.2.1 - 2020-08-04
Merged
v4.2.0 - 2020-05-18
Merged
- switch to safe buffer
[#53](https://github.com/crypto-browserify/browserify-sign/issues/53)
... (truncated)
Commits
bf2c3ec
v4.2.39247adf
[patch] widen support to 0.12f427270
[Deps] update `parse-asn187f3a35
[Dev Deps] updateaud
,npmignore
,tape
fb261ce
[Deps] updateelliptic
4d0ee49
[patch] drop minimum node support to v19e2bf12
[Deps] pinhash-base
to ~3.0, due to a breaking change168e16f
[Deps] pinelliptic
due to a breaking change37a4758
[actions] remove redundant finisher4af5a90
v4.2.2- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates cipher-base
from 1.0.4 to 1.0.6
Changelog
Sourced from cipher-base's changelog.
v1.0.6 - 2024-11-26
Commits
- [Fix] io.js 3.0 - Node.js 5.3 typed array support
b7ddd2a
v1.0.5 - 2024-11-17
Commits
- [Tests] standard -> eslint, make test dir, etc
ae02fd6
- [Tests] migrate from travis to GHA
66387d7
- [meta] fix package.json indentation
5c02918
- [Fix] return valid values on multi-byte-wide TypedArray input
8fd1364
- [meta] add
auto-changelog
88dc806
- [meta] add
npmignore
andsafe-publish-latest
7a137d7
- Only apps should have lockfiles
42528f2
- [Deps] update
inherits
,safe-buffer
0e7a2d9
- [meta] add missing
engines.node
f2dc13e
Commits
f5249f9
v1.0.6b7ddd2a
[Fix] io.js 3.0 - Node.js 5.3 typed array supportf03cebf
v1.0.588dc806
[meta] addauto-changelog
7a137d7
[meta] addnpmignore
andsafe-publish-latest
5c02918
[meta] fix package.json indentation8fd1364
[Fix] return valid values on multi-byte-wide TypedArray input66387d7
[Tests] migrate from travis to GHAf2dc13e
[meta] add missingengines.node
0e7a2d9
[Deps] updateinherits
,safe-buffer
- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for cipher-base since your current version.
Updates cookiejar
from 2.1.2 to 2.1.4
Commits
- See full diff in compare view
Updates decode-uri-component
from 0.2.0 to 0.2.2
Release notes
Sourced from decode-uri-component's releases.
v0.2.2
- Prevent overwriting previously decoded tokens 980e0bf
https://github.com/SamVerschueren/decode-uri-component/compare/v0.2.1...v0.2.2
v0.2.1
- Switch to GitHub workflows 76abc93
- Fix issue where decode throws - fixes #6 746ca5d
- Update license (#1) 486d7e2
- Tidelift tasks a650457
- Meta tweaks 66e1c28
https://github.com/SamVerschueren/decode-uri-component/compare/v0.2.0...v0.2.1
Commits
Updates decompress
from 4.2.0 to 4.2.1
Commits
Updates express
from 4.16.3 to 4.21.2
Release notes
Sourced from express's releases.
4.21.2
What's Changed
- Add funding field (v4) by
@bjohansebas
in expressjs/express#6065- deps: path-to-regexp@0.1.11 by
@blakeembrey
in expressjs/express#5956- deps: bump path-to-regexp@0.1.12 by
@jonchurch
in expressjs/express#6209- Release: 4.21.2 by
@UlisesGascon
in expressjs/express#6094Full Changelog: https://github.com/expressjs/express/compare/4.21.1...4.21.2
4.21.1
What's Changed
- Backport a fix for CVE-2024-47764 to the 4.x branch by
@joshbuker
in expressjs/express#6029- Release: 4.21.1 by
@UlisesGascon
in expressjs/express#6031Full Changelog: https://github.com/expressjs/express/compare/4.21.0...4.21.1
4.21.0
What's Changed
- Deprecate
"back"
magic string in redirects by@blakeembrey
in expressjs/express#5935- finalhandler@1.3.1 by
@wesleytodd
in expressjs/express#5954- fix(deps): serve-static@1.16.2 by
@wesleytodd
in expressjs/express#5951- Upgraded dependency qs to 6.13.0 to match qs in body-parser by
@agadzinski93
in expressjs/express#5946New Contributors
@agadzinski93
made their first contribution in expressjs/express#5946Full Changelog: https://github.com/expressjs/express/compare/4.20.0...4.21.0
4.20.0
What's Changed
Important
- IMPORTANT: The default
depth
level for parsing URL-encoded data is now32
(previously wasInfinity
)- Remove link renderization in html while using
res.redirect
Other Changes
- 4.19.2 Staging by
@wesleytodd
in expressjs/express#5561- remove duplicate location test for data uri by
@wesleytodd
in expressjs/express#5562- feat: document beta releases expectations by
@marco-ippolito
in expressjs/express#5565- Cut down on duplicated CI runs by
@jonchurch
in expressjs/express#5564- Add a Threat Model by
@UlisesGascon
in expressjs/express#5526- Assign captain of encodeurl by
@blakeembrey
in expressjs/express#5579- Nominate jonchurch as repo captain for
http-errors
,expressjs.com
,morgan
,cors
,body-parser
by@jonchurch
in expressjs/express#5587- docs: update Security.md by
@inigomarquinez
in expressjs/express#5590- docs: update triage nomination policy by
@UlisesGascon
in expressjs/express#5600- Add CodeQL (SAST) by
@UlisesGascon
in expressjs/express#5433- docs: add UlisesGascon as triage initiative captain by
@UlisesGascon
in expressjs/express#5605
... (truncated)
Changelog
Sourced from express's changelog.
4.21.2 / 2024-11-06
- deps: path-to-regexp@0.1.12
- Fix backtracking protection
- deps: path-to-regexp@0.1.11
- Throws an error on invalid path values
4.21.1 / 2024-10-08
- Backported a fix for CVE-2024-47764
4.21.0 / 2024-09-11
- Deprecate
res.location("back")
andres.redirect("back")
magic string- deps: serve-static@1.16.2
- includes send@0.19.0
- deps: finalhandler@1.3.1
- deps: qs@6.13.0
4.20.0 / 2024-09-10
- deps: serve-static@0.16.0
- Remove link renderization in html while redirecting
- deps: send@0.19.0
- Remove link renderization in html while redirecting
- deps: body-parser@0.6.0
- add
depth
option to customize the depth level in the parser- IMPORTANT: The default
depth
level for parsing URL-encoded data is now32
(previously wasInfinity
)- Remove link renderization in html while using
res.redirect
- deps: path-to-regexp@0.1.10
- Adds support for named matching groups in the routes using a regex
- Adds backtracking protection to parameters without regexes defined
- deps: encodeurl@~2.0.0
- Removes encoding of
\
,|
, and^
to align better with URL spec- Deprecate passing
options.maxAge
andoptions.expires
tores.clearCookie
- Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie
4.19.2 / 2024-03-25
- Improved fix for open redirect allow list bypass
4.19.1 / 2024-03-20
- Allow passing non-strings to res.location with new encoding handling checks
... (truncated)
Commits
1faf228
4.21.22e0fb64
deps: bump path-to-regexp@0.1.12 (#6209)59fc270
deps: path-to-regexp@0.1.11 (#5956)51fc39c
docs: add funding (#6065)8e229f9
4.21.1a024c8a
fix(deps): cookie@0.7.17e562c6
4.21.01bcde96
fix(deps): qs@6.13.0 (#5946)7d36477
fix(deps): serve-static@1.16.2 (#5951)40d2d8f
fix(deps): finalhandler@1.3.1- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by jonchurch, a new releaser for express since your current version.
Updates follow-redirects
from 1.5.10 to 1.15.11
Commits
21ef28a
Release version 1.15.11 of the npm package.7c88135
Roll back tree shaking.6e389ba
Release version 1.15.10 of the npm package.5bc496e
Shake me up before you go-go.694d6b4
Bump minimist from 1.2.5 to 1.2.8e4e55c7
Release version 1.15.9 of the npm package.31a1abf
Attempt much more gentle detection.d2aaa97
Fix url field.62558f0
Release version 1.15.8 of the npm package.a8d1cee
Return subtlety.- Additional commits viewable in compare view
Updates fstream
from 1.0.11 to 1.0.12
Commits
4235459
1.0.126a77d2f
Clobber a Link if it's in the way of a File- See full diff in compare view
Updates get-func-name
from 2.0.0 to 2.0.2
Release notes
Sourced from get-func-name's releases.
v2.0.2
What's Changed
Revert previous changes that shipped this as an ES module.
Full Changelog: https://github.com/chaijs/get-func-name/commits/v2.0.2
v2.0.1
What's Changed
Fix https://github.com/chaijs/get-func-name/security/advisories/GHSA-4q6p-r6v2-jvc5
Full Changelog: https://github.com/chaijs/get-func-name/commits/v2.0.1
Commits
- See full diff in compare view
Maintainer changes
This version was pushed to npm by keithamus, a new releaser for get-func-name since your current version.
Updates hosted-git-info
from 2.6.1 to 2.8.9
Changelog
Sourced from hosted-git-info's changelog.
2.8.9 (2021-04-07)
Bug Fixes
2.8.8 (2020-02-29)
Bug Fixes
- #61 & #65 addressing issues w/ url.URL implmentation which regressed node 6 support (5038b18), closes #66
2.8.7 (2020-02-26)
Bug Fixes
- Do not attempt to use url.URL when unavailable (2d0bb66), closes #61 #62
- Do not pass scp-style URLs to the WhatWG url.URL (f2cdfcf), closes #60
2.8.6 (2020-02-25)
2.8.5 (2019-10-07)
Bug Fixes
2.8.4 (2019-08-12)
... (truncated)
Commits
8d4b369
chore(release): 2.8.929adfe5
fix: backport regex fix from #76afeaefd
chore(release): 2.8.85038b18
fix: #61 & #65 addressing issues w/ url.URL implmentation which regressed nod...7440afa
chore(release): 2.8.72d0bb66
fix: Do not attempt to use url.URL when unavailablef2cdfcf
fix: Do not pass scp-style URLs to the WhatWG url.URLe1b83df
chore(release): 2.8.6ff259a6
Ensure passwords in hosted Git URLs are correctly escaped624fd6f
chore(release): 2.8.5- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates https-proxy-agent
from 2.2.1 to 2.2.4
Commits
- See full diff in compare view
Updates ini
from 1.3.5 to 1.3.8
Commits
a2c5da8
1.3.8af5c6bb
Do not use Object.create(null)8b648a1
don't test where our devdeps don't even workc74c8af
1.3.7024b8b5
update deps, add linting032fbaf
Use Object.create(null) to avoid default object property hazards2da9039
1.3.6cfea636
better git push script, before publish instead of after56d2805
do not allow invalid hazardous string as section name- See full diff in compare view
Maintainer changes
This version was pushed to npm by isaacs, a new releaser for ini since your current version.
Updates js-yaml
from 3.12.0 to 3.14.1
Changelog
Sourced from js-yaml's changelog.
[3.14.1] - 2020-12-07
Security
- Fix possible code execution in (already unsafe)
.load()
(in &anchor).[3.14.0] - 2020-05-22
Changed
- Support
safe/loadAll(input, options)
variant of call.- CI: drop outdated nodejs versions.
- Dev deps bump.
Fixed
- Quote
=
in plain scalars #519.- Check the node type for
!<?>
tag in case user manually specifies it.- Verify that there are no null-bytes in input.
- Fix wrong quote position when writing condensed flow, #526.
[3.13.1] - 2019-04-05
Security
- Fix possible code execution in (already unsafe)
.load()
, #480.[3.13.0] - 2019-03-20
Security
- Security fix:
safeLoad()
can hang when arrays with nested refs used as key. Now throws exception for nested arrays. #475.[3.12.2] - 2019-02-26
Fixed
- Fix
noArrayIndent
option for root level, #468.[3.12.1] - 2019-01-05
Added
- Added
noArrayIndent
option, #432.
Commits
37caaad
3.14.1 released094c0f7
dist rebuild9586ebe
Avoid calling hasOwnProperty of user-controlled objects34e5072
3.14.0 released7b25c83
Browser files rebuild6f73473
Dev deps bump0c29349
Travis-CI: drop old nodejs versions10be97e
fix(loader): Add support forsafe/loadAll(input, options)
d6983dd
Fix issue #526: wrong quote position writing condensed flow (#527)93fbf7d
fix issue 526 (wrong quote position writing condensed flow)- Additional commits viewable in compare view
Updates lodash.template
from 4.4.0 to 4.5.0
Commits
ab73503
Bump to v4.5.0.a4f7d4c
Rebuild lodash and docs.cca5ac6
Fix npm-test by removing the call to test-docs.9f7f9fc
Adjust heading order. [ci skip]6e2fb92
Remove unusedbaseArity
.4f702e2
Specify utf8 encoding.b188f90
Add fp tests for iteratee shorthands.7b93dc9
Ensure clone methods clone expando properties of boolean, number, & string ob...664d66a
Make string tests more consistent.-
Pull Request Statistics
Commits:
1Files Changed:
2Additions:
+1104Deletions:
-534
Package Dependencies
Security Advisories
Chaijs/get-func-name vulnerable to ReDoS
cookie accepts cookie name, path, and domain with out of bounds characters
Technical Details
ID: | 7615070 |
UUID: | 2823958446 |
Node ID: | PR_kwDOCbC5Vs6oUi-u |
Host: | GitHub |
Repository: | 0xferit/kleros-microservices |
Merge State: | Unknown |