Bump the npm_and_yarn group across 1 directory with 13 updates
Type: Pull Request
State: Open
Association: None
Comments: 0
(about 1 year ago)
(about 1 year ago)
dependencies javascript
Bumps the npm_and_yarn group with 11 updates in the / directory:
| Package | From | To |
|---|---|---|
| webpack | 5.76.0 |
5.99.9 |
| axios | 0.26.1 |
removed |
| vscode-tas-client | 0.1.63 |
0.1.84 |
| braces | 3.0.2 |
3.0.3 |
| gulp | 4.0.2 |
5.0.1 |
| browserify-sign | 4.0.4 |
4.2.3 |
| @babel/traverse | 7.7.4 |
7.27.4 |
| serialize-javascript | 6.0.0 |
6.0.2 |
| mocha | 9.2.2 |
11.5.0 |
| tar-fs | 2.1.1 |
2.1.3 |
| ws | 7.5.7 |
7.5.10 |
Updates webpack from 5.76.0 to 5.99.9
Release notes
Sourced from webpack's releases.
v5.99.9
Fixes
- HMR might fail if there are new initial chunks
- Destructuring namespace import with default
- Destructuring namespace import with computed-property
- Generate valid code for es export generation for multiple module entries
- Fixed public path issue for ES modules
- Asset modules work when lazy compilation used
- Eliminate unused statements in certain scenarios
- Fixed regression with location and order of dependencies
- Fixed typescript types
v5.99.8
Fixes
- Fixed type error with latest
@types/node- Fixed typescript types
v5.99.7
Fixes
- Don't skip export generation for
defaultreexport (#19463)- Fixed module library export generation for reexport (#19459)
- Avoid module concatenation in child compilation for module library (#19457)
- Ensure HMR recover gracefully when CSS module with error
- Respect
causeof any errors anderrorsof AggregateError in stats output- Added missing
@types/json-schemain typesv5.99.6
Fixes
- Respect public path for ES modules
- Fixed generation of module for
modulelibrary when mixing commonjs and esm modules- Always apply
FlagDependencyExportsPluginfor libraries where it required- Faster logic for dead control flow
- Typescript types
v5.99.5
Fixes
- Control dead flow for labeled and blockless statements
v5.99.4
Fixes
- Fixed terminated state for
if/elsev5.99.3
Fixes
... (truncated)
Commits
6c9f912chore(release): 5.99.9bca3d40fix: eliminate unused statements in certain scenarios (#19536)356c5d1ci: benchmarks stability (#19552)2c4f967fix: sourceTypes of asset module when lazy compilation (#19539)6b3e1c5chore(deps): bump the dependencies group with 2 updates (#19551)dc19f82chore: fix todo types (#19550)598767echore: fix typo in comment34ec1d8chore: refactor tests scripts (#19549)12b8458fix: publicPath issue for ES modules (#19546)c1e7ba2docs: update examples (#19545)- Additional commits viewable in compare view
Removes axios
Updates vscode-tas-client from 0.1.63 to 0.1.84
Updates braces from 3.0.2 to 3.0.3
Commits
74b2db23.0.388f1429update eslint. lint, fix unit tests.415d660Snyk js braces 6838727 (#40)190510ffix tests, skip 1 test in test/braces.expand716eb9freadme bumpa5851e5Merge pull request #37 from coderaiser/fix/vulnerability2092bd1feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cffix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9remove funding file665ab5dupdate keepEscaping doc (#27)- Additional commits viewable in compare view
Updates gulp from 4.0.2 to 5.0.1
Release notes
Sourced from gulp's releases.
gulp v5.0.1
Bug Fixes
- Avoid globbing before read stream is opened (#2839) (19122f3)
- Avoid Node.js deprecation warning for
fs.Stats(#2838) (69a5d0e)- Support top-level await on Node 22.12+ (#2836) (04b4a74)
gulp v5.0.0
We've tried to provide a high-level changelog for gulp v5 below, but it doesn't contain all changes from the 60+ dependencies that we maintain.
Please see individual changelogs to drill down into all changes that were made.
⚠ BREAKING CHANGES
- Drop support for Node.js <10.13
- Default stream encoding to UTF-8
- Standardized on
anymatchlibrary for globbing paths. All globs should work the same betweensrcandwatchnow!- Removed support for ordered globs. This aligns with the chokidar globbing implementation. If you need your globs to be ordered, you can use
ordered-read-stream- All globs and paths are normalized to unix-like filepaths
- Only allow JS variants for
.gulp.*config files- Removed support for alpha releases of v4 from
gulp-cli- Removed the
--verifyflag- Renamed the
--requireflag to--preloadto avoid conflicting with Node.js flags- Removed many legacy and deprecated loaders
- Upgrade to chokidar v3
- Clone
Vinylobjects with stream contents usingteex, but no longer wait for all streams to flow before cloned streams will receive data- Stop using
process.umask()to make directories, instead falling back to Node's default mode- Throw on non-function, non-string option coercers
- Drop support of Node.js snake_case flags
- Use a Symbol for attaching the
gulplognamespace to the store- Use a Symbol for attaching the
gulplogstore to the global- Use sha256 to hash the
v8flagscache into a filenameFeatures
- Streamlined the dependency tree
- Switch all streams implementation to Streamx
- Rewrote
glob-streamto use a custom directory walk that relies on newer Node.js features and is more performant than old implementation- Implement translation support for all CLI messages and all messages passing through gulplog
- Allow users to customize or remove the timestamp from their logs
- Upgraded gulplog to v2. Messages logged via v1 will also display a deprecated warning. Plugins should update to v2 as the community upgrades to gulp 5
- Added support for
gulpile.cjsandgulpfile.mjs- Add support for
swc,esbuild,sucrase, andmdxloaders- Provide an ESM export (#2760) (b00de68)
- Support sourcemap handling on streaming
Vinylcontents
... (truncated)
Changelog
Sourced from gulp's changelog.
5.0.1 (2025-06-01)
Bug Fixes
- Avoid globbing before read stream is opened (#2839) (19122f3)
- Avoid Node.js deprecation warning for
fs.Stats(#2838) (69a5d0e)- Support top-level await on Node 22.12+ (#2836) (04b4a74)
5.0.0 (2024-03-29)
We've tried to provide a high-level changelog for gulp v5 below, but it doesn't contain all changes from the 60+ dependencies that we maintain.
Please see individual changelogs to drill down into all changes that were made.
⚠ BREAKING CHANGES
- Drop support for Node.js <10.13
- Default stream encoding to UTF-8
- Standardized on
anymatchlibrary for globbing paths. All globs should work the same betweensrcandwatchnow!- Removed support for ordered globs. This aligns with the chokidar globbing implementation. If you need your globs to be ordered, you can use
ordered-read-stream- All globs and paths are normalized to unix-like filepaths
- Only allow JS variants for
.gulp.*config files- Removed support for alpha releases of v4 from
gulp-cli- Removed the
--verifyflag- Renamed the
--requireflag to--preloadto avoid conflicting with Node.js flags- Removed many legacy and deprecated loaders
- Upgrade to chokidar v3
- Clone
Vinylobjects with stream contents usingteex, but no longer wait for all streams to flow before cloned streams will receive data- Stop using
process.umask()to make directories, instead falling back to Node's default mode- Throw on non-function, non-string option coercers
- Drop support of Node.js snake_case flags
- Use a Symbol for attaching the
gulplognamespace to the store- Use a Symbol for attaching the
gulplogstore to the global- Use sha256 to hash the
v8flagscache into a filenameFeatures
- Streamlined the dependency tree
- Switch all streams implementation to Streamx
- Rewrote
glob-streamto use a custom directory walk that relies on newer Node.js features and is more performant than old implementation- Implement translation support for all CLI messages and all messages passing through gulplog
- Allow users to customize or remove the timestamp from their logs
- Upgraded gulplog to v2. Messages logged via v1 will also display a deprecated warning. Plugins should update to v2 as the community upgrades to gulp 5
- Added support for
gulpile.cjsandgulpfile.mjs- Add support for
swc,esbuild,sucrase, andmdxloaders- Provide an ESM export (#2760) (b00de68)
- Support sourcemap handling on streaming
Vinylcontents
... (truncated)
Commits
0003e9fchore: release 5.0.1 (#2837)19122f3fix: Avoid globbing before read stream is opened (#2839)69a5d0efix: Avoid Node.js deprecation warning forfs.Stats(#2838)04b4a74fix: Support top-level await on Node 22.12+ (#2836)c90e79echore: Fix CI (#2835)5412605chore(docs): Update async completion document for newer RxJS (#2831)2fa4981chore: Update glob docs with replacement to ordered globs (#2788)fe9dee6chore: Remove locale docs (#2787)a85eddbchore: Remove node-glob options from docs (#2786)9c818e6chore: update src.md docs to add encoding parameter- Additional commits viewable in compare view
Updates browserify-sign from 4.0.4 to 4.2.3
Changelog
Sourced from browserify-sign's changelog.
v4.2.3 - 2024-03-05
Commits
- [patch] widen support to 0.12
9247adf- [patch] drop minimum node support to v1
4d0ee49- [Dev Deps] update
aud,npmignore,tape87f3a35- [actions] remove redundant finisher
37a4758- [Deps] pin
hash-baseto ~3.0, due to a breaking change9e2bf12- [Deps] update
parse-asn1 [f427270`](https://github.com/browserify/browserify-sign/commit/f427270ac11dc6be29f87d7afb046c16376a5a9c)- [Deps] update
ellipticfb261ce- [Deps] pin
ellipticdue to a breaking change168e16fv4.2.2 - 2023-10-25
Fixed
- [Tests] log when openssl doesn't support cipher
[#37](https://github.com/crypto-browserify/browserify-sign/issues/37)Commits
- Only apps should have lockfiles
09a8995- [eslint] switch to eslint
83fe463- [meta] add
npmignoreandauto-changelog4418183- [meta] fix package.json indentation
9ac5a5e- [Tests] migrate from travis to github actions
d845d85- [Fix]
sign: throw on unsupported padding scheme8767739- [Fix] properly check the upper bound for DSA signatures
85994cd- [Tests] handle openSSL not supporting a scheme
f5f17c2- [Deps] update
bn.js,browserify-rsa,elliptic,parse-asn1,readable-stream,safe-buffera67d0eb- [Dev Deps] update
nyc,standard,tapecc5350b- [Tests] always run coverage; downgrade
nyc75ce1d5- [meta] add
safe-publish-latestdcf49ce- [Tests] add
npm run posttest75dd8fd- [Dev Deps] update
tape3aec038- [Tests] skip unsupported schemes
703c83e- [Tests] node < 6 lacks array
includes3aa43cf- [Dev Deps] fix eslint range
98d4e0dv4.2.1 - 2020-08-04
Merged
v4.2.0 - 2020-05-18
Merged
- switch to safe buffer
[#53](https://github.com/crypto-browserify/browserify-sign/issues/53)
... (truncated)
Commits
bf2c3ecv4.2.39247adf[patch] widen support to 0.12f427270[Deps] update `parse-asn187f3a35[Dev Deps] updateaud,npmignore,tapefb261ce[Deps] updateelliptic4d0ee49[patch] drop minimum node support to v19e2bf12[Deps] pinhash-baseto ~3.0, due to a breaking change168e16f[Deps] pinellipticdue to a breaking change37a4758[actions] remove redundant finisher4af5a90v4.2.2- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates elliptic from 6.5.4 to 6.6.1
Commits
Updates yargs-parser from 5.0.0-security.0 to 18.1.3
Release notes
Sourced from yargs-parser's releases.
yargs-parser yargs-parser-v15.0.3
Bug Fixes
- build: should use releases_created when using manifest (49ea4ef)
yargs-parser yargs-parser-v15.0.2
Bug Fixes
Changelog
Sourced from yargs-parser's changelog.
18.1.3 (2020-04-16)
Bug Fixes
18.1.2 (2020-03-26)
Bug Fixes
18.1.1 (2020-03-16)
Bug Fixes
- __proto__ will now be replaced with ___proto___ in parse (#258), patching a potential prototype pollution vulnerability. This was reported by the Snyk Security Research Team.(63810ca)
18.1.0 (2020-03-07)
Features
18.0.0 (2020-03-02)
⚠ BREAKING CHANGES
- the narg count is now enforced when parsing arrays.
Features
- NaN can now be provided as a value for nargs, indicating "at least" one value is expected for array (#251) (9db4be8)
17.1.0 (2020-03-01)
Features
- introduce greedy-arrays config, for specifying whether arrays consume multiple positionals (#249) (60e880a)
17.0.1 (2020-02-29)
... (truncated)
Commits
- See full diff in compare view
Updates @babel/traverse from 7.7.4 to 7.27.4
Release notes
Sourced from @babel/traverse's releases.
v7.27.4 (2025-05-30)
:eyeglasses: Spec Compliance
babel-parser,babel-plugin-proposal-explicit-resource-management:nail_care: Polish
:microscope: Output optimization
babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-async-to-generator,babel-plugin-transform-block-scoping,babel-plugin-transform-classes,babel-plugin-transform-destructuring,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-preset-env,babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime
- #17287 Reduce
regeneratorsize more (@liuxingbaoyu)babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-async-to-generator,babel-plugin-transform-block-scoping,babel-plugin-transform-classes,babel-plugin-transform-destructuring,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-preset-env,babel-runtime-corejs3
- #17334 Use shorter method names for regenerator context (
@nicolo-ribaudo)- #17268 Reduce
regeneratorhelper size (@liuxingbaoyu)babel-core,babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-async-to-generator,babel-plugin-transform-block-scoping,babel-plugin-transform-classes,babel-plugin-transform-destructuring,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-preset-env,babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime,babel-standalone
- #17238 Split
regeneratorRuntimeinto multiple helpers (@nicolo-ribaudo)Committers: 4
- Babel Bot (
@babel-bot)- Huáng Jùnliàng (
@JLHwung)- Nicolò Ribaudo (
@nicolo-ribaudo)@liuxingbaoyuv7.27.3 (2025-05-27)
:bug: Bug Fix
babel-generatorbabel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-regenerator,babel-preset-env,babel-runtime-corejs3
- #17328 Correctly set
.displayNameonGeneratorFunction(@nicolo-ribaudo)babel-plugin-proposal-explicit-resource-managementbabel-plugin-proposal-decorators,babel-types
- #17321 fix(converter): Remove
abstractmodifiers in class declaration to expression conversion (@magic-akari)babel-helper-module-transforms,babel-plugin-proposal-explicit-resource-management,babel-plugin-transform-modules-amd,babel-plugin-transform-modules-commonjs,babel-plugin-transform-modules-umdbabel-parser
- #17312 fix(parser): properly handle optional markers in generator class methods (
@magic-akari)- #17307 fix(parser): Terminate modifier parsing at newline (
@magic-akari)babel-generator,babel-parserCommitters: 7
- Babel Bot (
@babel-bot)- Huáng Jùnliàng (
@JLHwung)- Nicolò Ribaudo (
@nicolo-ribaudo)- Vik R (
@vikr01)
... (truncated)
Changelog
Sourced from @babel/traverse's changelog.
v7.27.4 (2025-05-30)
:eyeglasses: Spec Compliance
babel-parser,babel-plugin-proposal-explicit-resource-management:nail_care: Polish
:microscope: Output optimization
babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-async-to-generator,babel-plugin-transform-block-scoping,babel-plugin-transform-classes,babel-plugin-transform-destructuring,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-preset-env,babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime
- #17287 Reduce
regeneratorsize more (@liuxingbaoyu)babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-async-to-generator,babel-plugin-transform-block-scoping,babel-plugin-transform-classes,babel-plugin-transform-destructuring,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-preset-env,babel-runtime-corejs3
- #17334 Use shorter method names for regenerator context (
@nicolo-ribaudo)- #17268 Reduce
regeneratorhelper size (@liuxingbaoyu)babel-core,babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-async-to-generator,babel-plugin-transform-block-scoping,babel-plugin-transform-classes,babel-plugin-transform-destructuring,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-preset-env,babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime,babel-standalone
- #17238 Split
regeneratorRuntimeinto multiple helpers (@nicolo-ribaudo)v7.27.3 (2025-05-27)
:bug: Bug Fix
babel-generatorbabel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-regenerator,babel-preset-env,babel-runtime-corejs3
- #17328 Correctly set
.displayNameonGeneratorFunction(@nicolo-ribaudo)babel-plugin-proposal-explicit-resource-managementbabel-plugin-proposal-decorators,babel-types
- #17321 fix(converter): Remove
abstractmodifiers in class declaration to expression conversion (@magic-akari)babel-helper-module-transforms,babel-plugin-proposal-explicit-resource-management,babel-plugin-transform-modules-amd,babel-plugin-transform-modules-commonjs,babel-plugin-transform-modules-umdbabel-parser
- #17312 fix(parser): properly handle optional markers in generator class methods (
@magic-akari)- #17307 fix(parser): Terminate modifier parsing at newline (
@magic-akari)babel-generator,babel-parserv7.27.2 (2025-05-06)
:bug: Bug Fix
babel-parser
- #17289 fix:
@babel/parser/bin/index.jscontainsnode:protocol require (@liuxingbaoyu)- #17291 fix: Private class method not found when TS and estree (
@liuxingbaoyu)babel-plugin-transform-object-rest-spreadbabel-plugin-transform-modules-commonjs,babel-template
- #17284 fix(babel-template): Properly handle empty string replacements (
@magic-akari):running_woman: Performance
babel-cli
... (truncated)
Commits
7d06930v7.27.405f28c8[Babel 8] Changescope.{references,uids}toSet(#16624)da5e371v7.27.32d0c76eImprove integrations of using declaration with other transforms (#17330)eebd3a0v7.27.162af1a6fix: do expressions should allow early exit (#17137)8e23272[Babel 8] perf: Improve traverse performance (#16965)9a40d85[Babel 8]: Remove record and tuple syntax support (#17242)4d39e9dHarden variable declarator validations (#17217)6cd1c60Reduce generated names size for the 10th-11th (#17221)- Additional commits viewable in compare view
Updates serialize-javascript from 6.0.0 to 6.0.2
Release notes
Sourced from serialize-javascript's releases.
v6.0.2
- fix: serialize URL string contents to prevent XSS (#173) f27d65d
- Bump
@babel/traversefrom 7.10.1 to 7.23.7 (#171) 02499c0- docs: update readme with URL support (#146) 0d88527
- chore: update node version and lock file e2a3a91
- fix typo (#164) 5a1fa64
https://github.com/yahoo/serialize-javascript/compare/v6.0.1...v6.0.2
v6.0.1
What's Changed
- Bump mocha from 9.0.1 to 9.0.2 by
@dependabotin yahoo/serialize-javascript#126- Bump mocha from 9.0.2 to 9.0.3 by
@dependabotin yahoo/serialize-javascript#127- Bump path-parse from 1.0.6 to 1.0.7 by
@dependabotin yahoo/serialize-javascript#129- Bump mocha from 9.0.3 to 9.1.0 by
@dependabotin yahoo/serialize-javascript#130- Bump mocha from 9.1.0 to 9.1.1 by
@dependabotin yahoo/serialize-javascript#131- Bump mocha from 9.1.1 to 9.1.2 by
@dependabotin yahoo/serialize-javascript#132- Bump mocha from 9.1.2 to 9.1.3 by
@dependabotin yahoo/serialize-javascript#133- Bump mocha from 9.1.3 to 9.1.4 by
@dependabotin yahoo/serialize-javascript#137- Bump mocha from 9.1.4 to 9.2.0 by
@dependabotin yahoo/serialize-javascript#138- Bump chai from 4.3.4 to 4.3.6 by
@dependabotin yahoo/serialize-javascript#140- Bump ansi-regex from 5.0.0 to 5.0.1 by
@dependabotin yahoo/serialize-javascript#141- Bump mocha from 9.2.0 to 9.2.2 by
@dependabotin yahoo/serialize-javascript#143- Bump minimist from 1.2.5 to 1.2.6 by
@dependabotin yahoo/serialize-javascript#144- Bump mocha from 9.2.2 to 10.0.0 by
@dependabotin yahoo/serialize-javascript#145- Bump mocha from 10.0.0 to 10.1.0 by
@dependabotin yahoo/serialize-javascript#149- Bump chai from 4.3.6 to 4.3.7 by
@dependabotin yahoo/serialize-javascript#150- ci: test.yml - actions bump by
@piwysockiin yahoo/serialize-javascript#151- Bump minimatch from 3.0.4 to 3.1.2 by
@dependabotin yahoo/serialize-javascript#152- Bump mocha from 10.1.0 to 10.2.0 by
@dependabotin yahoo/serialize-javascript#153- Bump json5 from 2.1.3 to 2.2.3 by
@dependabotin yahoo/serialize-javascript#155- Fix serialization issue for 0n. by
@momocowin yahoo/serialize-javascript#156- Release v6.0.1 by
@okuryuin yahoo/serialize-javascript#157New Contributors
@piwysockimade their first contribution in yahoo/serialize-javascript#151@momocowmade their first contribution in yahoo/serialize-javascript#156Full Changelog: https://github.com/yahoo/serialize-javascript/compare/v6.0.0...v6.0.1
Commits
b71ec236.0.2f27d65dfix: serialize URL string contents to prevent XSS (#173)02499c0Bump@babel/traversefrom 7.10.1 to 7.23.7 (#171)0d88527docs: update readme with URL support (#146)e2a3a91chore: update node version and lock file5a1fa64fix typo (#164)7139f92Release v6.0.1 (#157)7e23ae8Fix serialization issue for 0n. (#156)343abd9Bump json5 from 2.1.3 to 2.2.3 (#155)38d0e70Bump mocha from 10.1.0 to 10.2.0 (#153)- Additional commits viewable in compare view
Updates mocha from 9.2.2 to 11.5.0
Release notes
Sourced from mocha's releases.
v11.5.0
11.5.0 (2025-05-22)
🌟 Features
v11.4.0
11.4.0 (2025-05-19)
🌟 Features
📚 Documentation
v11.3.0
11.3.0 (2025-05-16)
🌟 Features
📚 Documentation
- Deploy new site alongside old one (#5360) (6c96545)
- mention explicit browser support range (#5354) (c514c0b)
- update Node.js version requirements for 11.x (#5329) (abf3dd9)
🧹 Chores
v11.2.2
11.2.2 (2025-04-10)
🩹 Fixes
... (truncated)
Changelog
Sourced from mocha's changelog.
11.5.0 (2025-05-22)
🌟 Features
11.4.0 (2025-05-19)
🌟 Features
📚 Documentation
11.3.0 (2025-05-16)
🌟 Features
📚 Documentation
- Deploy new site alongside old one (#5360) (6c96545)
- mention explicit browser support range (#5354) (c514c0b)
- update Node.js version requirements for 11.x (#5329) (abf3dd9)
🧹 Chores
11.2.2 (2025-04-10)
🩹 Fixes
Pull Request Statistics
1
2
+3697
-5240
Package Dependencies
Technical Details
| ID: | 1272039 |
| UUID: | 2562916746 |
| Node ID: | PR_kwDOJ07ubM6YwwGK |
| Host: | GitHub |
| Repository: | Al8a/vscode-python |
| Merge State: | Unknown |