Bump the production-dependencies group across 1 directory with 12 updates
Type: Pull Request
State: Closed
Association: Contributor
Comments: 2
(5 months ago)
(4 months ago)
(4 months ago)
dependencies javascript
Bumps the production-dependencies group with 12 updates in the /backend directory:
| Package | From | To |
|---|---|---|
| @octokit/core | 6.1.4 |
7.0.2 |
| cron | 4.1.3 |
4.3.1 |
| dotenv | 16.4.7 |
16.5.0 |
| eventsource | 3.0.6 |
4.0.0 |
| express | 4.21.2 |
5.1.0 |
| @types/express | 4.17.21 |
5.0.2 |
| mongoose | 8.13.2 |
8.15.1 |
| mysql2 | 3.14.0 |
3.14.1 |
| octokit | 4.1.2 |
5.0.3 |
| smee-client | 3.1.1 |
4.2.0 |
| validator | 13.15.0 |
13.15.15 |
| @types/validator | 13.15.0 |
13.15.1 |
Updates @octokit/core from 6.1.4 to 7.0.2
Release notes
Sourced from @octokit/core's releases.
v7.0.2
7.0.2 (2025-05-20)
Bug Fixes
v7.0.1
7.0.1 (2025-05-20)
Bug Fixes
v7.0.0
7.0.0 (2025-05-20)
Continuous Integration
BREAKING CHANGES
Drop support for NodeJS v18
build: set minimal node version in build script to v20
ci: stop testing against NodeJS v18
v6.1.5
6.1.5 (2025-04-10)
Bug Fixes
Commits
629fa4efix(deps): update octokit monorepo (major) (#742)1aba598chore(deps): update dependency undici to v7 (#711)2abf89efix(deps): update dependency before-after-hook to v4 (#739)78747bfci: stop testing against NodeJS v18 (#738)38dd554chore(deps): update dependency undici to v6.21.2 [security] (#741)f7cb18fbuild: remove glob (#737)22243bdchore(deps): bump vite from 6.2.6 to 6.3.4 (#735)e0d36c5ci: replaceOCTOKITBOT_PROJECT_ACTION_TOKENandOCTOKITBOT_PATwith a tok...e72adddchore(deps): bump vite from 6.2.5 to 6.2.6 (#733)3700c41fix(deps): update dependency@octokit/typesto v14 (#731)- Additional commits viewable in compare view
Updates cron from 4.1.3 to 4.3.1
Release notes
Sourced from cron's releases.
v4.3.1
4.3.1 (2025-05-29)
🐛 Bug Fixes
♻️ Chores
- action: update actions/setup-node action to v4.4.0 (86f8cec)
- action: update github/codeql-action action to v3.28.16 (33d396f)
- action: update github/codeql-action action to v3.28.17 (97a9185)
- action: update github/codeql-action action to v3.28.18 (6a72709)
- action: update step-security/harden-runner action to v2.12.0 (c0ad19d)
- deps: lock file maintenance (784bc9c)
- deps: lock file maintenance (7a97350)
- deps: lock file maintenance (40163b4)
- deps: lock file maintenance (9bcb7e3)
- deps: lock file maintenance (#983) (3df1cf6)
- deps: update dependency
@eslint/js to v9.25.1 (162008f)- deps: update dependency
@eslint/js to v9.27.0 (5c1161c)- deps: update dependency
@semantic-release/github to v11.0.2 (d27afcd)- deps: update dependency
@swc/core to v1.11.21 (a195b0f)- deps: update dependency
@swc/core to v1.11.29 (edd52d4)- deps: update dependency
@types/node to v22.14.1 (f24a7cb)- deps: update dependency
@types/node to v22.15.15 (#984) (bfb12a7)- deps: update dependency
@types/node to v22.15.21 (86b539a)- deps: update dependency lint-staged to v15.5.1 (25a3659)
- deps: update dependency lint-staged to v15.5.2 (be017c5)
- deps: update linters (6ed6fdb)
- deps: update semantic-release related packages (555bba9)
- deps: update swc monorepo (edd3284)
v4.3.0
4.3.0 (2025-04-15)
✨ Features
- add options to handle cases where jobs could stop unexpectedly (#980) (994b93a), closes #963 #962 #962 #963
v4.2.1-beta.1
4.2.1-beta.1 (2025-04-15)
🐛 Bug Fixes
v4.2.0
4.2.0 (2025-04-14)
... (truncated)
Changelog
Sourced from cron's changelog.
4.3.1 (2025-05-29)
🐛 Bug Fixes
♻️ Chores
- action: update actions/setup-node action to v4.4.0 (86f8cec)
- action: update github/codeql-action action to v3.28.16 (33d396f)
- action: update github/codeql-action action to v3.28.17 (97a9185)
- action: update github/codeql-action action to v3.28.18 (6a72709)
- action: update step-security/harden-runner action to v2.12.0 (c0ad19d)
- deps: lock file maintenance (784bc9c)
- deps: lock file maintenance (7a97350)
- deps: lock file maintenance (40163b4)
- deps: lock file maintenance (9bcb7e3)
- deps: lock file maintenance (#983) (3df1cf6)
- deps: update dependency
@eslint/js to v9.25.1 (162008f)- deps: update dependency
@eslint/js to v9.27.0 (5c1161c)- deps: update dependency
@semantic-release/github to v11.0.2 (d27afcd)- deps: update dependency
@swc/core to v1.11.21 (a195b0f)- deps: update dependency
@swc/core to v1.11.29 (edd52d4)- deps: update dependency
@types/node to v22.14.1 (f24a7cb)- deps: update dependency
@types/node to v22.15.15 (#984) (bfb12a7)- deps: update dependency
@types/node to v22.15.21 (86b539a)- deps: update dependency lint-staged to v15.5.1 (25a3659)
- deps: update dependency lint-staged to v15.5.2 (be017c5)
- deps: update linters (6ed6fdb)
- deps: update semantic-release related packages (555bba9)
- deps: update swc monorepo (edd3284)
4.3.0 (2025-04-15)
✨ Features
- add options to handle cases where jobs could stop unexpectedly (#980) (994b93a), closes #963 #962 #962 #963
4.2.1-beta.1 (2025-04-15)
🐛 Bug Fixes
4.2.0 (2025-04-14)
✨ Features
... (truncated)
Commits
7b4cf13Release v4.3.1 [skip ci]0db2c2dfix: prevent sourcemap error in IDEs (#988)784bc9cchore(deps): lock file maintenance5c1161cchore(deps): update dependency@eslint/jsto v9.27.0555bba9chore(deps): update semantic-release related packages86b539achore(deps): update dependency@types/nodeto v22.15.21edd52d4chore(deps): update dependency@swc/coreto v1.11.296a72709chore(action): update github/codeql-action action to v3.28.187a97350chore(deps): lock file maintenance40163b4chore(deps): lock file maintenance- Additional commits viewable in compare view
Updates dotenv from 16.4.7 to 16.5.0
Changelog
Sourced from dotenv's changelog.
16.5.0 (2025-04-07)
Added
- 🎉 Added new sponsor Graphite - the AI developer productivity platform helping teams on GitHub ship higher quality software, faster.
[!TIP] Become a sponsor
The dotenvx README is viewed thousands of times DAILY on GitHub and NPM. Sponsoring dotenv is a great way to get in front of developers and give back to the developer community at the same time.
Changed
- Remove
_logmethod. Use_debug#862
Commits
Updates eventsource from 3.0.6 to 4.0.0
Release notes
Sourced from eventsource's releases.
v4.0.0
4.0.0 (2025-05-13)
⚠ BREAKING CHANGES
FetchLikeInitis now removed. UseEventSourceFetchInit.- Drop support for Node.js v18, as it is end-of-life.
Features
- require node.js v20 or higher (91a3a48)
Bug Fixes
- drop
FetchLikeInittype. UseEventSourceFetchInitinstead. (6786e46)
This release is also available on:
v3.0.7
3.0.7 (2025-05-09)
Bug Fixes
- mark fetch init properties required in typings (1282872)
This release is also available on:
Changelog
Sourced from eventsource's changelog.
4.0.0 (2025-05-13)
⚠ BREAKING CHANGES
FetchLikeInitis now removed. UseEventSourceFetchInit.- Drop support for Node.js v18, as it is end-of-life.
Features
- require node.js v20 or higher (91a3a48)
Bug Fixes
- drop
FetchLikeInittype. UseEventSourceFetchInitinstead. (6786e46)3.0.7 (2025-05-09)
Bug Fixes
- mark fetch init properties required in typings (1282872)
Commits
d4385cbchore(release): 4.0.0 [skip ci]3057f3adocs: update migration guide6786e46fix!: dropFetchLikeInittype. UseEventSourceFetchInitinstead.91a3a48feat!: require node.js v20 or higher54fbb3echore(deps): upgrade dev dependencies to latest versions270e7f2chore(release): 3.0.7 [skip ci]1282872fix: mark fetch init properties required in typings- See full diff in compare view
Updates express from 4.21.2 to 5.1.0
Release notes
Sourced from express's releases.
v5.1.0
What's Changed
- Update captains by
@UlisesGasconin expressjs/express#6027- build: Node.js 23.0 by
@bjohansebasin expressjs/express#6075- Add funding field (v5) by
@bjohansebasin expressjs/express#6064- ✅ add discarded middleware test by
@ctcpipin expressjs/express#5819- update homepage link http to https by
@bjohansebasin expressjs/express#5920- Improve readme by
@bjohansebasin expressjs/express#5994- Add bjohansebas as repo captain for expressjs.com by
@crandmckin expressjs/express#6058- Remove Object.setPrototypeOf polyfill by
@Phillip9587in expressjs/express#6081- fix(buffer): use node:buffer instead of safe-buffer by
@bhavya3024in expressjs/express#6071- docs: Add DCO by
@UlisesGasconin expressjs/express#6048- cleanup: remove promise support check from tests by
@Phillip9587in expressjs/express#6148- Use loop for acceptParams by
@blakeembreyin expressjs/express#6066- Improve documentation step in release process by
@bjohansebasin expressjs/express#6150- cleanup: remove unnecessary require for global Buffer by
@Phillip9587in expressjs/express#6146- cleanup: remove AsyncLocalStorage check by
@Phillip9587in expressjs/express#6147- update history.md for acceptParams change by
@jonchurchin expressjs/express#6177- docs: add
@rxmarblesto the triage team by@UlisesGasconin expressjs/express#6151- refactor: improve readability by
@sazk07in expressjs/express#6173- docs: clarify the security process in the triage role by
@bjohansebasin expressjs/express#6217- chore: replace
methodsdependency with standard library by@jonkoopsin expressjs/express#6196- Remove
utils-mergedependency - use spread syntax instead by@Phillip9587in expressjs/express#6091- fix(securite): fix vulnerabilities by
@Abdel-Monaam-Aouiniin expressjs/express#6211- refactor: prefix built-in node module imports by
@slagiewkain expressjs/express#6236- fix: remove download size badges by
@wesleytoddin expressjs/express#6266- Remove unused
depddependency by@jonkoopsin expressjs/express#6197- fix: usage of
Invalid action input 'persist-credentials'foractions/setup-node@v4inci.ymlby@hamirmahalin expressjs/express#6256- Add support for OSSF scorecard reporting by
@UlisesGasconin expressjs/express#5431- docs: add
@Phillip9587to the triage team by@bjohansebasin expressjs/express#6276- fix: added a missing semicolon in css styles in examples/auth by
@pr4j3shin expressjs/express#6297- docs: include team email in the security policy by
@UlisesGasconin expressjs/express#6278- refactor: simplify
normalizeTypesfunction by@Ayoub-Mabroukin expressjs/express#6097- ci: updated github actions ci workflow by
@Phillip9587in expressjs/express#6314- ci: fix npm install --include typo by
@Phillip9587in expressjs/express#6324- ci: updated scorecard actions by
@Phillip9587in expressjs/express#6322- build(deps): use carat notation for dependency versions by
@dpopp07in expressjs/express#6317- chore(deps): update
debugto ^4.4.0 by@Phillip9587in expressjs/express#6313- docs: retroactively note 5.0.0-beta.1 api change in history file by
@dpopp07in expressjs/express#6333- feat(deps): body-parser@^2.1.0 by
@wesleytoddin expressjs/express#6332- feat(deps): router@^2.1.0 by
@wesleytoddin expressjs/express#6331- Update repo captains by
@UlisesGasconin expressjs/express#6234- deps: upgrade nyc by
@agungjatiin expressjs/express#6122- fix (deps): update deps by
@wesleytoddin expressjs/express#6337- response: add support for ETag option in res.sendFile by
@juanarbolin expressjs/express#6073- Update multiple links to use
httpsinstead ofhttpby@Phillip9587in expressjs/express#6338- Extend res.links() to allow adding multiple links with the same rel #2729 by
@andveain expressjs/express#4885- docs: update emeritus triagers by
@UlisesGasconin expressjs/express#6345- docs: update guidance for triager nominations by
@bjohansebasin expressjs/express#6349- docs: clarify guidelines for becoming a committer by
@bjohansebasin expressjs/express#6364
... (truncated)
Changelog
Sourced from express's changelog.
5.1.0 / 2025-03-31
- Add support for
Uint8Arrayinres.send()- Add support for ETag option in
res.sendFile()- Add support for multiple links with the same rel in
res.links()- Add funding field to package.json
- perf: use loop for acceptParams
- refactor: prefix built-in node module imports
- deps: remove
setprototypeof- deps: remove
safe-buffer- deps: remove
utils-merge- deps: remove
methods- deps: remove
depd- deps:
debug@^4.4.0- deps:
body-parser@^2.2.0- deps:
router@^2.2.0- deps:
content-type@^1.0.5- deps:
finalhandler@^2.1.0- deps:
qs@^6.14.0- deps:
server-static@2.2.0- deps:
type-is@2.0.15.0.1 / 2024-10-08
- Update
cookiesemver lock to address CVE-2024-477645.0.0 / 2024-09-10
- remove:
path-is-absolutedependency - usepath.isAbsoluteinstead- breaking:
res.status()accepts only integers, and input must be greater than 99 and less than 1000
- will throw a
RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000.for inputs outside this range- will throw a
TypeError: Invalid status code: ${code}. Status code must be an integer.for non integer inputs- deps: send@1.0.0
res.redirect('back')andres.location('back')is no longer a supported magic string, explicitly usereq.get('Referrer') || '/'.- change:
res.clearCookiewill ignore user providedmaxAgeandexpiresoptions- deps: cookie-signature@^1.2.1
- deps: debug@4.3.6
- deps: merge-descriptors@^2.0.0
- deps: serve-static@^2.1.0
- deps: qs@6.13.0
- deps: accepts@^2.0.0
- deps: mime-types@^3.0.0
application/javascript=>text/javascript- deps: type-is@^2.0.0
- deps: content-disposition@^1.0.0
... (truncated)
Commits
cd7d4395.1.04c4f3eafix(deps): serve-static@^2.2.0 (#6418)cb4c56efix(docs): remove@mertcanaltinfrom Triagers (#6408)7b44e1dci: use full SHAs for github action versionseb6d125deps: router@^2.2.0 (#6417)f1a2dc8deps: type-is@^2.0.1 (#6420)6b51e8edeps: body-parser@^2.2.0 (#6419)1f311c5build(deps-dev): bump cookie-session from 2.0.0 to 2.1.0 (#6399)9e97144feat(deps): finalhandler@2.1.0 (#6373)29d0980build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 (#6397)- Additional commits viewable in compare view
Updates @types/express from 4.17.21 to 5.0.2
Commits
- See full diff in compare view
Updates mongoose from 8.13.2 to 8.15.1
Release notes
Sourced from mongoose's releases.
8.15.1 / 2025-05-26
- types: correct handling of _id in ProjectionType #15432 #15418
- types: fix definition of VectorSearch.$vectorSearch #15429 chriskrycho
- docs: add Document#save to list of function with callbacks removed #15433 SethFalco
8.15.0 / 2025-05-16
- feat: CSFLE support #15390 baileympearson
- feat: add strictFilter option to findOneAndUpdate (#14913) #15402 #14913 muazahmed-dev
- feat(error): set cause to MongoDB error reason on ServerSelection errors #15420 #15416
- fix(model): make bulkSave() rely on document.validateSync() to validate docs and skip bulkWrite casting #15415 #15410
- types: stricter projection typing with 1-level deep nesting #15418 #15327 #13840 pshaddel
- docs: emphasize automatic type inference in TypeScript intro and statics/methods, remove duplicated statics.md #15421
8.14.3 / 2025-05-13
- types(schema): allow post('init') #15413 #15412 #15333
- types: fix signature of DocumentArray.id #15414 Sainan
- docs: fix typo - change 'prodecure' to 'procedure' #15419 0xEbrahim
8.14.2 / 2025-05-08
- fix(query): handle casting array filter paths underneath array filter paths with embedded discriminators #15388 #15386
- docs(typescript): correct schema and model generic params in TS virtuals docs #15391
- docs+types(schema): add alternative optimisticConcurrency syntaxes to docs + types #15405 #10591
- chore: add Node 24 to CI matrix #15408 stscoundrel
8.14.1 / 2025-04-29
- fix: correct change tracking with maps of arrays of primitives and maps of maps #15374 #15350
- fix(populate): consistently convert Buffer representation of UUID to hex string to avoid confusing populate assignment #15383 #15382
- docs: add TypeScript Query guide with info on lean() + transform() #15377 #15311
8.14.0 / 2025-04-25
- feat: upgrade MongoDB driver -> 6.16 #15371
- feat: implement Query findById methods #15337 sderrow
- feat(subdocument): support schematype-level minimize option to disable minimizing empty subdocuments #15336 #15313
- feat: add skipOriginalStackTraces option to avoid stack trace performance overhead #15345 #15194
- fix(model): disallow Model.findOneAndUpdate(update) and fix TypeScript types re: findOneAndUpdate #15365 #15363
- types: correctly recurse in InferRawDocType #15357 #14954 JavaScriptBach
- types: include virtuals in toJSON and toObject output if virtuals: true set #15346 #15316
- types: make init hooks types accurately reflect runtime behavior #15331 #15301
8.13.3 / 2025-04-24
... (truncated)
Changelog
Sourced from mongoose's changelog.
8.15.1 / 2025-05-26
- types: correct handling of _id in ProjectionType #15432 #15418
- types: fix definition of VectorSearch.$vectorSearch #15429 chriskrycho
- docs: add Document#save to list of function with callbacks removed #15433 SethFalco
8.15.0 / 2025-05-16
- feat: CSFLE support #15390 baileympearson
- feat: add strictFilter option to findOneAndUpdate (#14913) #15402 #14913 muazahmed-dev
- feat(error): set cause to MongoDB error reason on ServerSelection errors #15420 #15416
- fix(model): make bulkSave() rely on document.validateSync() to validate docs and skip bulkWrite casting #15415 #15410
- types: stricter projection typing with 1-level deep nesting #15418 #15327 #13840 pshaddel
- docs: emphasize automatic type inference in TypeScript intro and statics/methods, remove duplicated statics.md #15421
8.14.3 / 2025-05-13
- types(schema): allow post('init') #15413 #15412 #15333
- types: fix signature of DocumentArray.id #15414 Sainan
- docs: fix typo - change 'prodecure' to 'procedure' #15419 0xEbrahim
8.14.2 / 2025-05-08
- fix(query): handle casting array filter paths underneath array filter paths with embedded discriminators #15388 #15386
- docs(typescript): correct schema and model generic params in TS virtuals docs #15391
- docs+types(schema): add alternative optimisticConcurrency syntaxes to docs + types #15405 #10591
- chore: add Node 24 to CI matrix #15408 stscoundrel
7.8.7 / 2025-04-30
- types(aggregate): allow calling project() with a string #15304 #15300
- docs: update deleteOne & deleteMany API def #15360 Elliot67 SethFalco
8.14.1 / 2025-04-29
- fix: correct change tracking with maps of arrays of primitives and maps of maps #15374 #15350
- fix(populate): consistently convert Buffer representation of UUID to hex string to avoid confusing populate assignment #15383 #15382
- docs: add TypeScript Query guide with info on lean() + transform() #15377 #15311
8.14.0 / 2025-04-25
- feat: upgrade MongoDB driver -> 6.16 #15371
- feat: implement Query findById methods #15337 sderrow
- feat(subdocument): support schematype-level minimize option to disable minimizing empty subdocuments #15336 #15313
- feat: add skipOriginalStackTraces option to avoid stack trace performance overhead #15345 #15194
- fix(model): disallow Model.findOneAndUpdate(update) and fix TypeScript types re: findOneAndUpdate #15365 #15363
- types: correctly recurse in InferRawDocType #15357 #14954 JavaScriptBach
- types: include virtuals in toJSON and toObject output if virtuals: true set #15346 #15316
- types: make init hooks types accurately reflect runtime behavior #15331 #15301
... (truncated)
Commits
0c5f56fchore: release 8.15.17f00685Merge branch '7.x'15e7743chore: bump tsda45ed3eMerge branch '6.x' into 7.xb331eacMerge pull request #15434 from Automattic/vkarpov15/gh-154272097837chore: remove upload-artifact8045783chore: bump ubuntu versions in GitHub actions5235028docs(compatibility): add note that Mongoose ^6.5 works with MongoDB server 7.x49bad32Merge pull request #15430 from Automattic/vkarpov15/mongoose-lean-getters-4437134b0Merge pull request #15433 from SethFalco/patch-1- Additional commits viewable in compare view
Updates mysql2 from 3.14.0 to 3.14.1
Release notes
Sourced from mysql2's releases.
v3.14.1
3.14.1 (2025-04-27)
Bug Fixes
- Fix for SET NAMES utf8 causing an unknown encoding error (#3551) 0617813d21cf9de5fcbd4dd283eafc6d090eeeaf
Changelog
Sourced from mysql2's changelog.
3.14.1 (2025-04-27)
Miscellaneous Chores
- release 3.14.1 (9d097f8)
Commits
202c9cachore(master): release 3.14.1 (#3552)9d097f8chore: release 3.14.149a6bdbbuild(deps-dev): bump@types/nodefrom 22.14.1 to 22.15.2 in /website (#3549)d5d6c77build(deps): bump sass from 1.86.3 to 1.87.0 in /website (#3548)5303541build(deps-dev): bump@types/nodefrom 22.14.1 to 22.15.2 (#3550)5cff0d3Description has been truncated
Pull Request Statistics
1
2
+400
-1079
Package Dependencies
Technical Details
| ID: | 1245385 |
| UUID: | 2561866862 |
| Node ID: | PR_kwDONBIPLs6Ysvxu |
| Host: | GitHub |
| Repository: | austenstone/github-value |
| Mergeable: | Yes |
| Merge State: | Unstable |