Bump the npm_and_yarn group with 7 updates
Type: Pull Request
State: Open
![dependabot[bot]](https://github.com/dependabot.png)
Association: Contributor
Comments: 4
(21 days ago)
(6 days ago)
Bumps the npm_and_yarn group with 8 updates:
Package | From | To |
---|---|---|
brace-expansion | 1.1.11 |
1.1.12 |
form-data | 4.0.0 |
4.0.4 |
mermaid | 11.6.0 |
11.10.0 |
on-headers | 1.0.2 |
1.1.0 |
compression | 1.7.4 |
1.8.1 |
pbkdf2 | 3.1.2 |
3.1.3 |
tar-fs | 2.1.2 |
2.1.3 |
tar-fs | 3.0.8 |
3.1.0 |
Updates brace-expansion
from 1.1.11 to 1.1.12
Release notes
Sourced from brace-expansion's releases.
v1.1.12
- pkg: publish on tag 1.x c460dbd
- fmt ccb8ac6
- Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8
https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12
Commits
Updates form-data
from 4.0.0 to 4.0.4
Release notes
Sourced from form-data's releases.
v4.0.4
v4.0.4 - 2025-07-16
Commits
- [meta] add
auto-changelog
811f682
- [Tests] handle predict-v8-randomness failures in node < 17 and node > 23
1d11a76
- [Fix] Switch to using
crypto
random for boundary values3d17230
- [Tests] fix linting errors
5e34080
- [meta] actually ensure the readme backup isn’t published
316c82b
- [Dev Deps] update
@ljharb/eslint-config
58c25d7
- [meta] fix readme capitalization
2300ca1
v4.0.3
v4.0.3 - 2025-06-05
Fixed
- [Fix]
append
: avoid a crash on nullish values[#577](https://github.com/form-data/form-data/issues/577)
Commits
- [eslint] use a shared config
426ba9a
- [eslint] fix some spacing issues
2094191
- [Refactor] use
hasown
81ab41b
- [Fix] validate boundary type in
setBoundary()
method8d8e469
- [Tests] add tests to check the behavior of
getBoundary
with non-strings837b8a1
- [Dev Deps] remove unused deps
870e4e6
- [meta] remove local commit hooks
e6e83cc
- [Dev Deps] update
eslint
4066fd6
- [meta] fix scripts to use prepublishOnly
c4bbb13
v4.0.2
v4.0.2 - 2025-02-14
Merged
- [Fix] set
Symbol.toStringTag
when available[#573](https://github.com/form-data/form-data/issues/573)
- [Fix] set
Symbol.toStringTag
when available[#573](https://github.com/form-data/form-data/issues/573)
- fix (npmignore): ignore temporary build files
[#532](https://github.com/form-data/form-data/issues/532)
- fix (npmignore): ignore temporary build files
[#532](https://github.com/form-data/form-data/issues/532)
Fixed
- [Fix] set
Symbol.toStringTag
when available (#573)[#396](https://github.com/form-data/form-data/issues/396)
- [Fix] set
Symbol.toStringTag
when available (#573)[#396](https://github.com/form-data/form-data/issues/396)
- [Fix] set
Symbol.toStringTag
when available[#396](https://github.com/form-data/form-data/issues/396)
Commits
... (truncated)
Changelog
Sourced from form-data's changelog.
v4.0.4 - 2025-07-16
Commits
- [meta] add
auto-changelog
811f682
- [Tests] handle predict-v8-randomness failures in node < 17 and node > 23
1d11a76
- [Fix] Switch to using
crypto
random for boundary values3d17230
- [Tests] fix linting errors
5e34080
- [meta] actually ensure the readme backup isn’t published
316c82b
- [Dev Deps] update
@ljharb/eslint-config
58c25d7
- [meta] fix readme capitalization
2300ca1
v4.0.3 - 2025-06-05
Fixed
- [Fix]
append
: avoid a crash on nullish values[#577](https://github.com/form-data/form-data/issues/577)
Commits
- [eslint] use a shared config
426ba9a
- [eslint] fix some spacing issues
2094191
- [Refactor] use
hasown
81ab41b
- [Fix] validate boundary type in
setBoundary()
method8d8e469
- [Tests] add tests to check the behavior of
getBoundary
with non-strings837b8a1
- [Dev Deps] remove unused deps
870e4e6
- [meta] remove local commit hooks
e6e83cc
- [Dev Deps] update
eslint
4066fd6
- [meta] fix scripts to use prepublishOnly
c4bbb13
v4.0.2 - 2025-02-14
Merged
- [Fix] set
Symbol.toStringTag
when available[#573](https://github.com/form-data/form-data/issues/573)
- [Fix] set
Symbol.toStringTag
when available[#573](https://github.com/form-data/form-data/issues/573)
- fix (npmignore): ignore temporary build files
[#532](https://github.com/form-data/form-data/issues/532)
- fix (npmignore): ignore temporary build files
[#532](https://github.com/form-data/form-data/issues/532)
Fixed
- [Fix] set
Symbol.toStringTag
when available (#573)[#396](https://github.com/form-data/form-data/issues/396)
- [Fix] set
Symbol.toStringTag
when available (#573)[#396](https://github.com/form-data/form-data/issues/396)
- [Fix] set
Symbol.toStringTag
when available[#396](https://github.com/form-data/form-data/issues/396)
Commits
... (truncated)
Commits
41996f5
v4.0.4316c82b
[meta] actually ensure the readme backup isn’t published2300ca1
[meta] fix readme capitalization811f682
[meta] addauto-changelog
5e34080
[Tests] fix linting errors1d11a76
[Tests] handle predict-v8-randomness failures in node < 17 and node > 2358c25d7
[Dev Deps] update@ljharb/eslint-config
3d17230
[Fix] Switch to usingcrypto
random for boundary valuesd8d67dc
v4.0.3e6e83cc
[meta] remove local commit hooks- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for form-data since your current version.
Updates mermaid
from 11.6.0 to 11.10.0
Release notes
Sourced from mermaid's releases.
mermaid@11.10.0
Minor Changes
- #6744
daf8d8d
Thanks@SpecularAura
! - feat: Added support for per link curve styling in flowchart diagram using edge idsPatch Changes
#6857
b9ef683
Thanks@knsv
! - feat: Exposing elk configuration forceNodeModelOrder and considerModelOrder to the mermaid configuration#6653
2c0931d
Thanks@darshanr0107
! - chore: Remove the "-beta" suffix from the XYChart, Block, Sankey diagrams to reflect their stable status#6683
33e08da
Thanks@darshanr0107
! - fix: Position the edge label in state diagram correctly relative to the edge#6693
814b68b
Thanks@darshanr0107
! - fix: Apply correct dateFormat in Gantt chart to show only day when specified#6734
fce7cab
Thanks@darshanr0107
! - fix: handle exclude dates properly in Gantt charts when using dateFormat: 'YYYY-MM-DD HH:mm:ss'#6733
fc07f0d
Thanks@omkarht
! - fix: fixed connection gaps in flowchart for roundedRect, stadium and diamond shape#6876
12e01bd
Thanks@sidharthv96
! - fix: sanitize icon labels and icon SVGsResolves CVE-2025-54880 reported by
@fourcube
#6801
01aaef3
Thanks@sidharthv96
! - fix: Update casing of ID in requirement diagram#6796
c36cd05
Thanks@HashanCP
! - fix: Make flowchart elk detector regex match less greedy#6702
8bb29fc
Thanks@qraqras
! - fix(block): overflowing blocks no longer affect later linesThis may change the layout of block diagrams that have overflowing lines (i.e. block diagrams that use up more columns that the
columns
specifier).#6717
71b04f9
Thanks@darshanr0107
! - fix: log warning for blocks exceeding column widthThis update adds a validation check that logs a warning message when a block's width exceeds the defined column layout.
#6820
c99bce6
Thanks@kriss-u
! - fix: Add escaped class literal name on namespace#6332
6cc1926
Thanks@ajuckel
! - fix: Allow equals sign in sequenceDiagram labels#6651
9da6fb3
Thanks@darshanr0107
! - Add validation for negative values in pie charts:Prevents crashes during parsing by validating values post-parsing.
Provides clearer, user-friendly error messages for invalid negative inputs.
#6803
e48b0ba
Thanks@omkarht
! - chore: migrate to class-based ArchitectureDB implementation#6838
4d62d59
Thanks@saurabhg772244
! - fix: node border style for handdrawn shapes
... (truncated)
Commits
96778f7
Merge pull request #6880 from mermaid-js/changeset-release/masterd4c058b
Version Packagesb638a0a
temp: Remove peerDeps from examplesfd9aa36
chore: Update peerDependencies for examples46a9f1b
temp: Disable cspell check as it's blocking release83c6224
Merge pull request #6878 from mermaid-js/developd8161b1
fix: move fourcube to contributor8223141
chore: add fourcube to cspell99f98a6
Merge pull request #6877 from mermaid-js/update-timingsef28f54
chore: update E2E timings- Additional commits viewable in compare view
Updates on-headers
from 1.0.2 to 1.1.0
Release notes
Sourced from on-headers's releases.
1.1.0
Important
What's Changed
- Migrate CI pipeline to GitHub actions by
@carpasse
in jshttp/on-headers#12- fix README.md badges by
@carpasse
in jshttp/on-headers#13- add OSSF scorecard action by
@carpasse
in jshttp/on-headers#14- fix: use
ubuntu-latest
as ci runner by@UlisesGascon
in jshttp/on-headers#19- ci: apply OSSF Scorecard security best practices by
@UlisesGascon
in jshttp/on-headers#20- 👷 add upstream change detection by
@ctcpip
in jshttp/on-headers#31- ✨ add script to update known hashes by
@ctcpip
in jshttp/on-headers#32- 💚 update CI - add newer node versions by
@ctcpip
in jshttp/on-headers#33New Contributors
@carpasse
made their first contribution in jshttp/on-headers#12@UlisesGascon
made their first contribution in jshttp/on-headers#19@ctcpip
made their first contribution in jshttp/on-headers#31Full Changelog: https://github.com/jshttp/on-headers/compare/v1.0.2...v1.1.0
Commits
4b017af
1.1.0b636f2d
♻️ refactor header array code3e2c2d4
✨ ignore falsy header keys, matching node behavior172eb41
✨ support duplicate headersc6e3849
🔒️ fix array handling6893518
💚 update CI - add newer node versions56a345d
✨ add script to update known hashes175ab21
👷 add upstream change detection (#31)ce0b2c8
ci: apply OSSF Scorecard security best practices (#20)1a38c54
fix: useubuntu-latest
as ci runner (#19)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for on-headers since your current version.
Updates compression
from 1.7.4 to 1.8.1
Release notes
Sourced from compression's releases.
v1.8.1
What's Changed
- fix(docs): update multiple links from http to https by
@Phillip9587
in expressjs/compression#222- ci: add dependabot for github actions by
@bjohansebas
in expressjs/compression#207- build(deps): bump github/codeql-action from 2.23.2 to 3.28.15 by
@dependabot
[bot] in expressjs/compression#228- build(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.1 by
@dependabot
[bot] in expressjs/compression#229- build(deps-dev): bump eslint-plugin-import from 2.26.0 to 2.31.0 by
@dependabot
[bot] in expressjs/compression#230- build(deps-dev): bump supertest from 6.2.3 to 6.3.4 by
@dependabot
[bot] in expressjs/compression#231- [StepSecurity] ci: Harden GitHub Actions by
@step-security-bot
in expressjs/compression#235- build(deps): bump github/codeql-action from 3.28.15 to 3.29.2 by
@dependabot
[bot] in expressjs/compression#243- build(deps): bump actions/upload-artifact from 4.3.1 to 4.6.2 by
@dependabot
[bot] in expressjs/compression#239- build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 by
@dependabot
[bot] in expressjs/compression#240- build(deps): bump actions/checkout from 4.1.1 to 4.2.2 by
@dependabot
[bot] in expressjs/compression#241- build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 by
@dependabot
[bot] in expressjs/compression#244- deps: on-headers@1.1.0 by
@UlisesGascon
in expressjs/compression#246- Release: 1.8.1 by
@UlisesGascon
in expressjs/compression#247New Contributors
@dependabot
[bot] made their first contribution in expressjs/compression#228@step-security-bot
made their first contribution in expressjs/compression#235Full Changelog: https://github.com/expressjs/compression/compare/1.8.0...v1.8.1
v1.8.0
What's Changed
- Refactor chunkLength function for improved readability and consistency by
@Ayoub-Mabrouk
in expressjs/compression#203- Refactor toBuffer function to simplify buffer check logic by
@Ayoub-Mabrouk
in expressjs/compression#201- ci: add CodeQL (SAST) by
@bjohansebas
in expressjs/compression#204- Use headersSent instead of _header by
@maritz
in expressjs/compression#129- Bugfix/use write head instead of implicit header by
@Icehunter
in expressjs/compression#170- feat: add default option by
@bjohansebas
in expressjs/compression#191- ci: update ci workflow by
@bjohansebas
in expressjs/compression#206- feat: support for brotli by
@bjohansebas
in expressjs/compression#194- docs: improve readme by
@bjohansebas
in expressjs/compression#209- docs: keywords field by
@bjohansebas
in expressjs/compression#210- refactor: simplify encoding negotiation logic by
@bjohansebas
in expressjs/compression#213New Contributors
@Ayoub-Mabrouk
made their first contribution in expressjs/compression#203@maritz
made their first contribution in expressjs/compression#129@Icehunter
made their first contribution in expressjs/compression#170Full Changelog: https://github.com/expressjs/compression/compare/1.7.5...v1.8.0
1.7.5
What's Changed
- chore: add support for OSSF scorecard reporting by
@inigomarquinez
in expressjs/compression#186- ci: fix errors in ci github action for node 8 and 9 by
@inigomarquinez
in expressjs/compression#187- docs: fix spelling by
@dijonkitchen
in expressjs/compression#174- deps: bytes@3.1.2 by
@bjohansebas
in expressjs/compression#192
... (truncated)
Changelog
Sourced from compression's changelog.
1.8.1 / 2025-07-17
- deps: on-headers@~1.1.0
1.8.0 / 2025-02-10
- Use
res.headersSent
when available- Replace
_implicitHeader
withwriteHead
property- add brotli support for versions of node that support it
- Add the enforceEncoding option for requests without
Accept-Encoding
header1.7.5 / 2024-10-31
- deps: Replace accepts with negotiator@~0.6.4
- Add preference option
- deps: bytes@3.1.2
- Add petabyte (
pb
) support- Fix "thousandsSeparator" incorrecting formatting fractional part
- Fix return value for un-parsable strings
- deps: compressible@~2.0.18
- Mark
font/ttf
as compressible- Remove compressible from
multipart/mixed
- deps: mime-db@'>= 1.43.0 < 2'
- deps: safe-buffer@5.2.1
Commits
83a0c45
1.8.1ce62713
deps: on-headers@1.1.0 (#246)f4acb23
build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#244)6eaebe6
build(deps): bump actions/checkout from 4.1.1 to 4.2.2 (#241)37e0623
build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#240)bc436b2
build(deps): bump actions/upload-artifact from 4.3.1 to 4.6.2 (#239)2f9f572
build(deps): bump github/codeql-action from 3.28.15 to 3.29.2 (#243)5f13b14
[StepSecurity] ci: Harden GitHub Actions (#235)76e0945
build(deps-dev): bump supertest from 6.2.3 to 6.3.4 (#231)ae6ee80
build(deps-dev): bump eslint-plugin-import from 2.26.0 to 2.31.0 (#230)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for compression since your current version.
Updates pbkdf2
from 3.1.2 to 3.1.3
Changelog
Sourced from pbkdf2's changelog.
v3.1.3 - 2025-06-20
Commits
- Only apps should have lockfiles
8b06730
- [lint] fix whitespace
9a76e2f
- [lint] fix parens/curlies/semis/etc
6fd84bf
- [meta] add
auto-changelog
796c38d
- [Tests] fix tests in node 17
3661fb0
- Revert "[Tests] fix tests in node < 3"
7431b57
- [Tests] fix tests in node < 3
eb9f97a
- [Fix] ensure unknown algorithms throw + known ones match node
26d4fd3
- [Tests] add GHA, always run nyc
513906a
- [lint] fix a few more rules
ab04da8
- [lint] switch to eslint
89694cf
- [Tests] add coverage
d0d534b
- [Refactor] use
to-buffer
e3102a8
- [readme] improve badges
fca0c9d
- [Tests] remove unused travis file
a2c7d93
- [meta] switch from
files
tonpmignore
7f31fbc
- [Tests] use .nycrc
8d628e8
- [Refactor] minor tweaks
fc61005
- [Deps] update
create-hmac
,safe-buffer
,sha.js
ae2a7d0
- [Fix] pin
create-hash
,ripemd160
due to breaking changese079968
- [Tests] fix tests in node 3
45fbcf3
- [meta] skip publishing benchmarks
19ea57b
- [Dev Deps] add missing peer dep
645e252
Commits
3e40827
v3.1.3e3102a8
[Refactor] useto-buffer
7431b57
Revert "[Tests] fix tests in node < 3"19ea57b
[meta] skip publishing benchmarksa2c7d93
[Tests] remove unused travis file645e252
[Dev Deps] add missing peer dep796c38d
[meta] addauto-changelog
d0d534b
[Tests] add coverage7f31fbc
[meta] switch fromfiles
tonpmignore
fca0c9d
[readme] improve badges- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for pbkdf2 since your current version.
Updates tar-fs
from 2.1.2 to 2.1.3
Commits
4b7e868
2.1.3266194b
hardlink tweak from main- See full diff in compare view
Updates tar-fs
from 3.0.8 to 3.1.0
Commits
4b7e868
2.1.3266194b
hardlink tweak from main- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
0
0
+0
-0
Package Dependencies
Technical Details
ID: | 5418602 |
UUID: | 3338512392 |
Node ID: | PR_kwDOLiT3086khID0 |
Host: | GitHub |
Repository: | codeharborhub/codeharborhub.github.io |