Bump the npm_and_yarn group across 2 directories with 22 updates
Type: Pull Request
State: Open
Association: None
Comments: 0
(10 months ago)
(10 months ago)
dependencies javascript
Bumps the npm_and_yarn group with 10 updates in the / directory:
| Package | From | To |
|---|---|---|
| gatsby | 4.22.0 |
4.25.7 |
| @babel/helpers | 7.25.7 |
7.27.1 |
| @babel/runtime | 7.25.7 |
7.27.1 |
| base-x | 3.0.10 |
3.0.11 |
| cross-spawn | 6.0.5 |
6.0.6 |
| dompurify | 2.5.7 |
2.5.8 |
| express | 4.21.0 |
4.21.2 |
| nanoid | 3.3.7 |
3.3.11 |
| prismjs | 1.29.0 |
1.30.0 |
| undici | 6.19.8 |
6.21.3 |
Bumps the npm_and_yarn group with 6 updates in the /samples/adobe-auth-node directory:
| Package | From | To |
|---|---|---|
| body-parser | 1.18.2 |
1.20.3 |
| express | 4.16.3 |
4.21.2 |
| cookie | 0.3.1 |
0.7.2 |
| express-session | 1.15.6 |
1.18.1 |
| minimist | 0.0.8 |
1.2.8 |
| mkdirp | 0.5.1 |
0.5.6 |
Updates gatsby from 4.22.0 to 4.25.7
Release notes
Sourced from gatsby's releases.
v4.24
Welcome to
gatsby@4.24.0release (September 2022 #2)Key highlights of this release:
Bleeding Edge: Want to try new features as soon as possible? Install
gatsby@nextand let us know if you have any issues.v4.23
Welcome to
gatsby@4.23.0release (September 2022 #1)Key highlights of this release:
Bleeding Edge: Want to try new features as soon as possible? Install
gatsby@nextand let us know if you have any issues.
Commits
db5eb18chore(release): Publishfc22f4bfix(gatsby): don't serve codeframes for files outside of compilation (#38059)...8889bfechore(release): Publishd3d5fd0fix(gatsby-source-wordpress): prevent inconsistent schema customization (#377...5bdef4afix(gatsby): don't block event loop during inference (#37780) (#37801)50e3f94chore(release): Publish3f8477dchore: Update get-unowned-packages script to use npm 9 syntaxdcf88edfix(gatsby-plugin-sharp): don't serve static assets that are not result of cu...3be4a80chore(release): Publish98c4d27feat(gatsby): add initial webhook body env var to bootstrap context (#37478) ...- Additional commits viewable in compare view
Updates @babel/helpers from 7.25.7 to 7.27.1
Release notes
Sourced from @babel/helpers's releases.
v7.27.1 (2025-04-30)
Thanks
@kermanxand@woaitsAryanfor your first PRs!:eyeglasses: Spec Compliance
babel-parserbabel-parser,babel-types:bug: Bug Fix
babel-plugin-proposal-destructuring-private,babel-plugin-proposal-do-expressions,babel-traversebabel-helper-wrap-function,babel-plugin-transform-async-to-generator
- #17251 Fix: propagate argument evaluation errors through async promise chain (
@magic-akari)babel-helper-remap-async-to-generator,babel-plugin-transform-async-to-generatorbabel-helper-fixtures,babel-parserbabel-generator,babel-parserbabel-parserbabel-compat-data,babel-preset-envbabel-traverse
- #17156 fix: Objects and arrays with multiple references should not be evaluated (
@liuxingbaoyu)babel-generator:nail_care: Polish
babel-plugin-bugfix-v8-spread-parameters-in-optional-chaining,babel-plugin-proposal-decorators,babel-plugin-transform-arrow-functions,babel-plugin-transform-class-properties,babel-plugin-transform-destructuring,babel-plugin-transform-object-rest-spread,babel-plugin-transform-optional-chaining,babel-plugin-transform-parameters,babel-traverse
- #17221 Reduce generated names size for the 10th-11th (
@nicolo-ribaudo):house: Internal
babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime
- #17263 Remove unused
regenerator-runtimedep in@babel/runtime(@nicolo-ribaudo)babel-compat-data,babel-preset-envbabel-compat-data,babel-standalonebabel-register
- #16844 Migrate
@babel/registerto cts (@liuxingbaoyu)babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-regenerator,babel-preset-env,babel-runtime-corejs3
- #17205 Inline regenerator in the relevant packages (
@nicolo-ribaudo)- All packages
... (truncated)
Changelog
Sourced from @babel/helpers's changelog.
v7.27.1 (2025-04-30)
:eyeglasses: Spec Compliance
babel-parserbabel-parser,babel-types:bug: Bug Fix
babel-plugin-proposal-destructuring-private,babel-plugin-proposal-do-expressions,babel-traversebabel-helper-wrap-function,babel-plugin-transform-async-to-generator
- #17251 Fix: propagate argument evaluation errors through async promise chain (
@magic-akari)babel-helper-remap-async-to-generator,babel-plugin-transform-async-to-generatorbabel-helper-fixtures,babel-parserbabel-generator,babel-parserbabel-parserbabel-compat-data,babel-preset-envbabel-traverse
- #17156 fix: Objects and arrays with multiple references should not be evaluated (
@liuxingbaoyu)babel-generator:nail_care: Polish
babel-plugin-bugfix-v8-spread-parameters-in-optional-chaining,babel-plugin-proposal-decorators,babel-plugin-transform-arrow-functions,babel-plugin-transform-class-properties,babel-plugin-transform-destructuring,babel-plugin-transform-object-rest-spread,babel-plugin-transform-optional-chaining,babel-plugin-transform-parameters,babel-traverse
- #17221 Reduce generated names size for the 10th-11th (
@nicolo-ribaudo):house: Internal
babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime
- #17263 Remove unused
regenerator-runtimedep in@babel/runtime(@nicolo-ribaudo)babel-compat-data,babel-preset-envbabel-compat-data,babel-standalone- Other
babel-register
- #16844 Migrate
@babel/registerto cts (@liuxingbaoyu)babel-cli,babel-compat-data,babel-core,babel-generator,babel-helper-compilation-targets,babel-helper-fixtures,babel-helper-module-imports,babel-helper-module-transforms,babel-helper-plugin-test-runner,babel-helper-transform-fixture-test-runner,babel-helpers,babel-node,babel-parser,babel-plugin-transform-modules-amd,babel-plugin-transform-modules-commonjs,babel-plugin-transform-modules-systemjs,babel-plugin-transform-modules-umd,babel-plugin-transform-react-display-name,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-plugin-transform-typeof-symbol,babel-plugin-transform-typescript,babel-preset-env,babel-register,babel-standalone,babel-typesbabel-plugin-transform-regenerator
... (truncated)
Commits
eebd3a0v7.27.1b1f9184ReduceinteropRequireWildcardsize (#16538)9c351e5Useclassand add type definitions forregenerator(#17220)0f95b74ReduceregeneratorRuntimesize (#17213)317e332Enforce node protocol import (#17207)14ef1e9Babel 8 cleanup (#17211)97105cbRe-convert regeneratorRuntime to helper format (#17205)1b93b0cMove regenerator files to the relevant packages (#17205)b953a8fRemove bundled regeneratorRuntime helper (#17205)6874c25Prepare LICENSE files for incorporating regenerator (#17205)- Additional commits viewable in compare view
Updates @babel/runtime from 7.25.7 to 7.27.1
Release notes
Sourced from @babel/runtime's releases.
v7.27.1 (2025-04-30)
Thanks
@kermanxand@woaitsAryanfor your first PRs!:eyeglasses: Spec Compliance
babel-parserbabel-parser,babel-types:bug: Bug Fix
babel-plugin-proposal-destructuring-private,babel-plugin-proposal-do-expressions,babel-traversebabel-helper-wrap-function,babel-plugin-transform-async-to-generator
- #17251 Fix: propagate argument evaluation errors through async promise chain (
@magic-akari)babel-helper-remap-async-to-generator,babel-plugin-transform-async-to-generatorbabel-helper-fixtures,babel-parserbabel-generator,babel-parserbabel-parserbabel-compat-data,babel-preset-envbabel-traverse
- #17156 fix: Objects and arrays with multiple references should not be evaluated (
@liuxingbaoyu)babel-generator:nail_care: Polish
babel-plugin-bugfix-v8-spread-parameters-in-optional-chaining,babel-plugin-proposal-decorators,babel-plugin-transform-arrow-functions,babel-plugin-transform-class-properties,babel-plugin-transform-destructuring,babel-plugin-transform-object-rest-spread,babel-plugin-transform-optional-chaining,babel-plugin-transform-parameters,babel-traverse
- #17221 Reduce generated names size for the 10th-11th (
@nicolo-ribaudo):house: Internal
babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime
- #17263 Remove unused
regenerator-runtimedep in@babel/runtime(@nicolo-ribaudo)babel-compat-data,babel-preset-envbabel-compat-data,babel-standalonebabel-register
- #16844 Migrate
@babel/registerto cts (@liuxingbaoyu)babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-regenerator,babel-preset-env,babel-runtime-corejs3
- #17205 Inline regenerator in the relevant packages (
@nicolo-ribaudo)- All packages
... (truncated)
Changelog
Sourced from @babel/runtime's changelog.
v7.27.1 (2025-04-30)
:eyeglasses: Spec Compliance
babel-parserbabel-parser,babel-types:bug: Bug Fix
babel-plugin-proposal-destructuring-private,babel-plugin-proposal-do-expressions,babel-traversebabel-helper-wrap-function,babel-plugin-transform-async-to-generator
- #17251 Fix: propagate argument evaluation errors through async promise chain (
@magic-akari)babel-helper-remap-async-to-generator,babel-plugin-transform-async-to-generatorbabel-helper-fixtures,babel-parserbabel-generator,babel-parserbabel-parserbabel-compat-data,babel-preset-envbabel-traverse
- #17156 fix: Objects and arrays with multiple references should not be evaluated (
@liuxingbaoyu)babel-generator:nail_care: Polish
babel-plugin-bugfix-v8-spread-parameters-in-optional-chaining,babel-plugin-proposal-decorators,babel-plugin-transform-arrow-functions,babel-plugin-transform-class-properties,babel-plugin-transform-destructuring,babel-plugin-transform-object-rest-spread,babel-plugin-transform-optional-chaining,babel-plugin-transform-parameters,babel-traverse
- #17221 Reduce generated names size for the 10th-11th (
@nicolo-ribaudo):house: Internal
babel-runtime-corejs2,babel-runtime-corejs3,babel-runtime
- #17263 Remove unused
regenerator-runtimedep in@babel/runtime(@nicolo-ribaudo)babel-compat-data,babel-preset-envbabel-compat-data,babel-standalone- Other
babel-register
- #16844 Migrate
@babel/registerto cts (@liuxingbaoyu)babel-cli,babel-compat-data,babel-core,babel-generator,babel-helper-compilation-targets,babel-helper-fixtures,babel-helper-module-imports,babel-helper-module-transforms,babel-helper-plugin-test-runner,babel-helper-transform-fixture-test-runner,babel-helpers,babel-node,babel-parser,babel-plugin-transform-modules-amd,babel-plugin-transform-modules-commonjs,babel-plugin-transform-modules-systemjs,babel-plugin-transform-modules-umd,babel-plugin-transform-react-display-name,babel-plugin-transform-regenerator,babel-plugin-transform-runtime,babel-plugin-transform-typeof-symbol,babel-plugin-transform-typescript,babel-preset-env,babel-register,babel-standalone,babel-typesbabel-plugin-transform-regenerator
... (truncated)
Commits
eebd3a0v7.27.1296cdc5Remove unusedregenerator-runtimedep in@babel/runtime(#17263)fdc0fb5[Babel 8] Bump nodejs requirements to^20.19.0 || >= 22.12.0(#17204)5c350eav7.27.0ca4865aFix: align behaviour to tscrewriteRelativeImportExtensions(#17118)e1ce99dv7.26.10d5952e8Fix processing of replacement pattern with named capture groups (#17173)64bca7bv7.26.92d95140v7.26.763d3038v7.26.0- Additional commits viewable in compare view
Updates base-x from 3.0.10 to 3.0.11
Commits
043a8883.0.112705ddd[backport 3.x] Prohibit char codes that would overflow theBASE_MAP- See full diff in compare view
Updates cross-spawn from 6.0.5 to 6.0.6
Commits
Updates dompurify from 2.5.7 to 2.5.8
Release notes
Sourced from dompurify's releases.
DOMPurify 2.5.8
- Fixed two conditional sanitizer bypasses discovered by
@parrot409and@Slonser- Updated the attribute clobbering checks to prevent future bypasses, thanks
@parrot409
Commits
ee992fctest: Updated a custom element test for IE11 on Windows 108b68e9etest: Trying to work around a false alert in IE11 Win 8.10d770cdchore: Preparing 2.5.8 release9cd4f11fix: Added same attribute clobbering check for 2.x branchf7120a3fix: Fixed two conditional bypasses discovered by@parrot409and@Slonser193eef2Update README.mdf7712e4Update README.md1bb377bUpdate README.md- See full diff in compare view
Updates engine.io from 4.1.2 to 6.2.1
Release notes
Sourced from engine.io's releases.
engine.io-parser@5.2.3
Bug Fixes
- do not expose the TransformStream type (f9cb983)
Commits
- See full diff in compare view
Updates express from 4.21.0 to 4.21.2
Release notes
Sourced from express's releases.
4.21.2
What's Changed
- Add funding field (v4) by
@bjohansebasin expressjs/express#6065- deps: path-to-regexp@0.1.11 by
@blakeembreyin expressjs/express#5956- deps: bump path-to-regexp@0.1.12 by
@jonchurchin expressjs/express#6209- Release: 4.21.2 by
@UlisesGasconin expressjs/express#6094Full Changelog: https://github.com/expressjs/express/compare/4.21.1...4.21.2
4.21.1
What's Changed
- Backport a fix for CVE-2024-47764 to the 4.x branch by
@joshbukerin expressjs/express#6029- Release: 4.21.1 by
@UlisesGasconin expressjs/express#6031Full Changelog: https://github.com/expressjs/express/compare/4.21.0...4.21.1
Changelog
Sourced from express's changelog.
4.21.2 / 2024-11-06
- deps: path-to-regexp@0.1.12
- Fix backtracking protection
- deps: path-to-regexp@0.1.11
- Throws an error on invalid path values
4.21.1 / 2024-10-08
- Backported a fix for CVE-2024-47764
Commits
Maintainer changes
This version was pushed to npm by jonchurch, a new releaser for express since your current version.
Updates nanoid from 3.3.7 to 3.3.11
Release notes
Sourced from nanoid's releases.
3.3.11
- Fixed React Native support.
3.3.10
- Fixed React Native support (by
@steida).3.3.9
- Reduced npm package size.
Changelog
Sourced from nanoid's changelog.
3.3.11
- Fixed React Native support.
3.3.10
- Fixed React Native support (by
@steida).3.3.9
- Reduced npm package size.
3.3.8
- Fixed a way to break Nano ID by passing non-integer size (by
@myndzi).
Commits
37289ceRelease 3.3.11 version23690b7Fix CIc147962Fix RN supporta83734eMove to manually ESM/CJS dual packagebb12e8aRelease 3.3.10 version8f44264Fix Expo supportadf9b0cRelease 3.3.9 version1c6f088Remove dev file from npm package3044cd5Release 3.3.8 version4fe3495Update size limit- Additional commits viewable in compare view
Updates path-to-regexp from 0.1.10 to 0.1.12
Release notes
Sourced from path-to-regexp's releases.
Fix backtracking (again)
Fixed
- Improved backtracking protection for 0.1.x, will break some previously valid paths (see previous advisory: https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-9wv6-86v2-598j)
https://github.com/pillarjs/path-to-regexp/compare/v0.1.11...v0.1.12
Error on bad input
Changed
- Add error on bad input values 8f09549
https://github.com/pillarjs/path-to-regexp/compare/v0.1.10...v0.1.11
Commits
640e6940.1.12f01c26aMerge commit from fork0c711920.1.118f09549Add error on bad input values- See full diff in compare view
Updates prismjs from 1.29.0 to 1.30.0
Release notes
Sourced from prismjs's releases.
v1.30.0
What's Changed
- check that
currentScriptis set by a script tag by@lkuechlerin PrismJS/prism#3863New Contributors
@lkuechlermade their first contribution in PrismJS/prism#3863Full Changelog: https://github.com/PrismJS/prism/compare/v1.29.0...v1.30.0
Commits
Maintainer changes
This version was pushed to npm by dmitrysharabin, a new releaser for prismjs since your current version.
Updates socket.io-parser from 4.0.5 to 4.2.4
Release notes
Sourced from socket.io-parser's releases.
4.2.4
Bug Fixes
- ensure reserved events cannot be used as event names (d9db473)
- properly detect plain objects (b0e6400)
Links
4.2.3
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot convert object to primitive value at Socket.emit (node:events:507:25) at .../node_modules/socket.io/lib/socket.js:531:14Please upgrade as soon as possible.
Bug Fixes
- check the format of the event name (3b78117)
Links
4.2.2
Bug Fixes
- calling destroy() should clear all internal state (22c42e3)
- do not modify the input packet upon encoding (ae8dd88)
Links
4.2.1
Bug Fixes
- check the format of the index of each attachment (b5d0cb7)
Links
... (truncated)
Changelog
Sourced from socket.io-parser's changelog.
4.2.4 (2023-05-31)
Bug Fixes
- ensure reserved events cannot be used as event names (d9db473)
- properly detect plain objects (b0e6400)
3.4.3 (2023-05-22)
Bug Fixes
- check the format of the event name (2dc3c92)
4.2.3 (2023-05-22)
Bug Fixes
- check the format of the event name (3b78117)
4.2.2 (2023-01-19)
Bug Fixes
- calling destroy() should clear all internal state (22c42e3)
- do not modify the input packet upon encoding (ae8dd88)
3.3.3 (2022-11-09)
Bug Fixes
- check the format of the index of each attachment (fb21e42)
3.4.2 (2022-11-09)
... (truncated)
Commits
164ba2achore(release): 4.2.4b0e6400fix: properly detect plain objectsd9db473fix: ensure reserved events cannot be used as event names6a5a004docs(changelog): include changelog for release 3.4.3b6c824fchore(release): 4.2.3dcc70d9refactor: export typescript declarations for the commonjs build3b78117fix: check the format of the event name0841bd5chore: bump ua-parser-js from 1.0.32 to 1.0.33 (#121)28dd668chore(release): 4.2.222c42e3fix: calling destroy() should clear all internal state- Additional commits viewable in compare view
Updates socket.io from 3.1.2 to 4.5.4
Changelog
Sourced from socket.io's changelog.
4.5.4 (2022-11-22)
This release contains a bump of:
engine.ioin order to fix CVE-2022-41940socket.io-parserin order to fix CVE-2022-2421.Dependencies
4.5.3 (2022-10-15)
Bug Fixes
- typings: accept an HTTP2 server in the constructor (d3d0a2d)
- typings: apply types to "io.timeout(...).emit()" calls (e357daf)
4.5.2 (2022-09-02)
Bug Fixes
- prevent the socket from joining a room after disconnection (18f3fda)
- uws: prevent the server from crashing after upgrade (ba497ee)
2.5.0 (2022-06-26)
Bug Fixes
- fix race condition in dynamic namespaces (
Pull Request Statistics
Commits:
1Files Changed:
4Additions:
+862Deletions:
-548
Package Dependencies
Security Advisories
path-to-regexp outputs backtracking regular expressions
cookie accepts cookie name, path, and domain with out of bounds characters
Uncaught exception in engine.io
Insufficient validation when decoding a Socket.IO packet
Technical Details
| ID: | 278431 |
| UUID: | 2520335378 |
| Node ID: | PR_kwDONuu-_M6WOUQS |
| Host: | GitHub |
| Repository: | https-gitcom/adobe-dev-console |
| Merge State: | Unknown |