-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): bump the npm_and_yarn group across 1 directory with 36 updates #409
base: master
Are you sure you want to change the base?
Conversation
…pdates Bumps the npm_and_yarn group with 26 updates in the / directory: | Package | From | To | | --- | --- | --- | | [aws-sdk](https://github.com/aws/aws-sdk-js) | `2.368.0` | `2.814.0` | | [axios](https://github.com/axios/axios) | `0.16.0` | `0.28.0` | | [express](https://github.com/expressjs/express) | `4.16.2` | `4.19.2` | | [log4js](https://github.com/log4js-node/log4js-node) | `3.0.6` | `6.4.0` | | [moment-timezone](https://github.com/moment/moment-timezone) | `0.5.26` | `0.5.35` | | [sequelize](https://github.com/sequelize/sequelize) | `4.41.2` | `6.29.0` | | [sequelize-cli](https://github.com/sequelize/cli) | `4.0.0` | `5.5.0` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.1.6` | `7.24.7` | | [semver](https://github.com/npm/node-semver) | `5.3.0` | `5.7.2` | | [semver](https://github.com/npm/node-semver) | `5.6.0` | `5.7.2` | | [semver](https://github.com/npm/node-semver) | `5.7.1` | `5.7.2` | | [semver](https://github.com/npm/node-semver) | `5.5.0` | `5.7.2` | | [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `7.7.1` | `8.12.0` | | [async](https://github.com/caolan/async) | `2.6.1` | `2.6.4` | | [braces](https://github.com/micromatch/braces) | `1.8.5` | `3.0.3` | | [ava](https://github.com/avajs/ava) | `0.25.0` | `6.1.3` | | [ajv](https://github.com/ajv-validator/ajv) | `5.5.2` | `6.12.6` | | [eslint](https://github.com/eslint/eslint) | `4.14.0` | `9.4.0` | | [ini](https://github.com/npm/ini) | `1.3.4` | `1.3.8` | | [hoek](https://github.com/hapijs/hoek) | `6.1.2` | `removed` | | [joi](https://github.com/hapijs/joi) | `14.3.0` | `17.13.1` | | [https-proxy-agent](https://github.com/TooTallNate/proxy-agents/tree/HEAD/packages/https-proxy-agent) | `2.2.1` | `2.2.4` | | [lodash](https://github.com/lodash/lodash) | `4.17.11` | `4.17.21` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.0.11` | `4.7.8` | | [y18n](https://github.com/yargs/y18n) | `3.2.1` | `3.2.2` | | [path-parse](https://github.com/jbgutierrez/path-parse) | `1.0.5` | `1.0.7` | | [qs](https://github.com/ljharb/qs) | `6.5.1` | `6.11.0` | | [body-parser](https://github.com/expressjs/body-parser) | `1.18.2` | `1.20.2` | | [xml2js](https://github.com/Leonidas-from-XIV/node-xml2js) | `0.4.19` | `0.6.2` | | [aws-sdk](https://github.com/aws/aws-sdk-js) | `2.814.0` | `2.1638.0` | Updates `aws-sdk` from 2.368.0 to 2.814.0 - [Release notes](https://github.com/aws/aws-sdk-js/releases) - [Changelog](https://github.com/aws/aws-sdk-js/blob/v2.814.0/CHANGELOG.md) - [Commits](aws/aws-sdk-js@v2.368.0...v2.814.0) Updates `axios` from 0.16.0 to 0.28.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v0.28.0/CHANGELOG.md) - [Commits](axios/axios@v0.16.0...v0.28.0) Updates `express` from 4.16.2 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.16.2...4.19.2) Updates `log4js` from 3.0.6 to 6.4.0 - [Changelog](https://github.com/log4js-node/log4js-node/blob/master/CHANGELOG.md) - [Commits](log4js-node/log4js-node@v3.0.6...v6.4.0) Updates `moment-timezone` from 0.5.26 to 0.5.35 - [Release notes](https://github.com/moment/moment-timezone/releases) - [Changelog](https://github.com/moment/moment-timezone/blob/develop/changelog.md) - [Commits](moment/moment-timezone@0.5.26...0.5.35) Updates `sequelize` from 4.41.2 to 6.29.0 - [Release notes](https://github.com/sequelize/sequelize/releases) - [Changelog](https://github.com/sequelize/sequelize/blob/main/CHANGELOG.md) - [Commits](sequelize/sequelize@v4.41.2...v6.29.0) Updates `sequelize-cli` from 4.0.0 to 5.5.0 - [Release notes](https://github.com/sequelize/cli/releases) - [Changelog](https://github.com/sequelize/cli/blob/main/CHANGELOG.md) - [Commits](sequelize/cli@v4.0.0...v5.5.0) Updates `@babel/traverse` from 7.1.6 to 7.24.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.7/packages/babel-traverse) Updates `semver` from 5.3.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.3.0...v5.7.2) Updates `semver` from 5.6.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.3.0...v5.7.2) Updates `semver` from 5.7.1 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.3.0...v5.7.2) Updates `semver` from 5.5.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.3.0...v5.7.2) Updates `pg` from 7.7.1 to 8.12.0 - [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md) - [Commits](https://github.com/brianc/node-postgres/commits/[email protected]/packages/pg) Updates `async` from 2.6.1 to 2.6.4 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md) - [Commits](caolan/async@v2.6.1...v2.6.4) Updates `braces` from 1.8.5 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@1.8.5...3.0.3) Updates `ava` from 0.25.0 to 6.1.3 - [Release notes](https://github.com/avajs/ava/releases) - [Commits](avajs/ava@v0.25.0...v6.1.3) Updates `chownr` from 1.0.1 to 1.1.4 - [Commits](isaacs/chownr@v1.0.1...v1.1.4) Updates `dottie` from 2.0.1 to 2.0.6 - [Release notes](https://github.com/mickhansen/dottie.js/releases) - [Commits](mickhansen/dottie.js@v2.0.1...v2.0.6) Updates `es5-ext` from 0.10.46 to 0.10.64 - [Release notes](https://github.com/medikoo/es5-ext/releases) - [Changelog](https://github.com/medikoo/es5-ext/blob/main/CHANGELOG.md) - [Commits](medikoo/es5-ext@v0.10.46...v0.10.64) Updates `ajv` from 5.5.2 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v5.5.2...v6.12.6) Updates `eslint` from 4.14.0 to 9.4.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md) - [Commits](eslint/eslint@v4.14.0...v9.4.0) Updates `js-yaml` from 3.10.0 to 3.12.0 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.10.0...3.12.0) Updates `follow-redirects` from 1.0.0 to 1.15.6 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.0.0...v1.15.6) Updates `ini` from 1.3.4 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.4...v1.3.8) Updates `tar` from 4.4.1 to 4.4.19 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v4.4.1...v4.4.19) Removes `hoek` Updates `joi` from 14.3.0 to 17.13.1 - [Commits](hapijs/joi@v14.3.0...v17.13.1) Updates `https-proxy-agent` from 2.2.1 to 2.2.4 - [Release notes](https://github.com/TooTallNate/proxy-agents/releases) - [Changelog](https://github.com/TooTallNate/proxy-agents/blob/main/packages/https-proxy-agent/CHANGELOG.md) - [Commits](https://github.com/TooTallNate/proxy-agents/commits/2.2.4/packages/https-proxy-agent) Updates `lodash` from 4.17.11 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.11...4.17.21) Updates `lodash.merge` from 4.6.1 to 4.6.2 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](https://github.com/lodash/lodash/commits) Updates `moment` from 2.22.2 to 2.30.1 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.22.2...2.30.1) Updates `handlebars` from 4.0.11 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.11...v4.7.8) Updates `y18n` from 3.2.1 to 3.2.2 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](https://github.com/yargs/y18n/commits) Updates `yargs-parser` from 7.0.0 to 9.0.2 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md) - [Commits](yargs/yargs-parser@v7.0.0...v9.0.2) Updates `path-parse` from 1.0.5 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `qs` from 6.5.1 to 6.11.0 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.1...v6.11.0) Updates `body-parser` from 1.18.2 to 1.20.2 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.18.2...1.20.2) Updates `validator` from 10.9.0 to 13.12.0 - [Release notes](https://github.com/validatorjs/validator.js/releases) - [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md) - [Commits](validatorjs/validator.js@10.9.0...13.12.0) Updates `xml2js` from 0.4.19 to 0.6.2 - [Commits](Leonidas-from-XIV/node-xml2js@0.4.19...0.6.2) Updates `aws-sdk` from 2.814.0 to 2.1638.0 - [Release notes](https://github.com/aws/aws-sdk-js/releases) - [Changelog](https://github.com/aws/aws-sdk-js/blob/v2.814.0/CHANGELOG.md) - [Commits](aws/aws-sdk-js@v2.368.0...v2.814.0) --- updated-dependencies: - dependency-name: aws-sdk dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: axios dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: log4js dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: moment-timezone dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: sequelize dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: sequelize-cli dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: pg dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: async dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: braces dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ava dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: chownr dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: dottie dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: es5-ext dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ajv dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: eslint dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hoek dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: joi dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: https-proxy-agent dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash.merge dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: moment dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: body-parser dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: validator dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: xml2js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: aws-sdk dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
Por favor, catalogue-o seguindo as instruções nesta documentação. [Via VPN]. 💁 Qualquer problema ou dúvida, estamos no Slack, basta abrir um ticket no canal #help-foundation-platform. |
Gandalf - Continuous AppSec📌 LembreteEste repositório está sendo monitorando de forma automática e contínua em busca de achados que possam comprometer a segurança da aplicação. 📋 Resumo de achados no repositório superbowleto
|
Bumps the npm_and_yarn group with 26 updates in the / directory:
2.368.0
2.814.0
0.16.0
0.28.0
4.16.2
4.19.2
3.0.6
6.4.0
0.5.26
0.5.35
4.41.2
6.29.0
4.0.0
5.5.0
7.1.6
7.24.7
5.3.0
5.7.2
5.6.0
5.7.2
5.7.1
5.7.2
5.5.0
5.7.2
7.7.1
8.12.0
2.6.1
2.6.4
1.8.5
3.0.3
0.25.0
6.1.3
5.5.2
6.12.6
4.14.0
9.4.0
1.3.4
1.3.8
6.1.2
removed
14.3.0
17.13.1
2.2.1
2.2.4
4.17.11
4.17.21
4.0.11
4.7.8
3.2.1
3.2.2
1.0.5
1.0.7
6.5.1
6.11.0
1.18.2
1.20.2
0.4.19
0.6.2
2.814.0
2.1638.0
Updates
aws-sdk
from 2.368.0 to 2.814.0Changelog
Sourced from aws-sdk's changelog.
... (truncated)
Commits
8875a35
Updates SDK to v2.814.0dd83d67
throw at invalid profile name in shared ini file (#3585)ee0c5a3
Updates SDK to v2.813.0468d15b
Updates SDK to v2.812.0c50132f
Update README.md with references to JS SDK V3 (#3582)3e19b08
Updates SDK to v2.811.0f26c00d
Updates SDK to v2.810.0b393a6e
Adds automatic PreSignedUrl generation to RDS.StartDBInstanceAutomatedBackups...fa57967
Updates SDK to v2.809.09a52018
Updates SDK to v2.808.0Updates
axios
from 0.16.0 to 0.28.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
3b7635a
[Release] v0.28.0 (#6211)27c0076
feat(backport): added ability for paramsSerializer to handle function; (#6227)80c3d74
chore(ci): backported publish action; (#6224)2755df5
fix(security): fixed CVE-2023-45857 by backportingwithXSRFToken
option to ...880b42e
docs: Fix a typo in READMEc4bf0a4
Allow null indexes on formSerializer and paramsSerializer v0.x (#4961)1e2679f
fix: [Types] Type of header in AxiosRequestConfig / for Axios.create is incor...80b546c
fix: loosing request header (#4858) (#4871)6acb5ef
feat: brower platform add data protocol. (#4814)bbb2264
fix(typing): axios response headers can be undefined (#4813)Maintainer changes
This version was pushed to npm by jasonsaayman, a new releaser for axios since your current version.
Updates
express
from 4.16.2 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
04bc627
4.19.2da4d763
Improved fix for open redirect allow list bypass4f0f6cc
4.19.1a003cfa
Allow passing non-strings to res.location with new encoding handling checks f...a1fa90f
fixed un-edited version in history.md for 4.19.011f2b1d
build: fix build due to inconsistent supertest behavior in older versions084e365
4.19.00867302
Prevent open redirect allow list bypass due to encodeurl567c9c6
Add note on how to update docs for new release (#5541)69a4cf2
deps: [email protected]Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates
log4js
from 3.0.6 to 6.4.0Changelog
Sourced from log4js's changelog.
... (truncated)
Commits
9fdbed5
6.4.0788c7a8
Merge pull request #1150 from log4js-node/update-changelog7fdb141
chore: updated changelog for 6.4.0e6bd888
Merge pull request #1151 from log4js-node/feat-zero-backupac599e4
allow for zero backup - in sync with https://github.com/log4js-node/streamrol...53248cd
Merge pull request #1149 from log4js-node/migrate-daysToKeep-to-numBackups436d9b4
Merge pull request #1148 from log4js-node/update-docsd6b017e
chore(docs): updated fileSync.md and misc commentsd4617a7
chore(deps): migrated from daysToKeep to numBackups due to streamroller@^3.0.00ad0133
Merge pull request #1147 from log4js-node/update-depsMaintainer changes
This version was pushed to npm by csausdev, a new releaser for log4js since your current version.
Updates
moment-timezone
from 0.5.26 to 0.5.35Release notes
Sourced from moment-timezone's releases.
Changelog
Sourced from moment-timezone's changelog.
Commits
b8fb1ba
Build moment-timezone 0.5.35f1b5e5a
Add changelog for 0.5.358b0eb0c
Bump version to 0.5.357915ac5
Bugfix: Prevent cleartext transmission of tz data during buildce955a3
Bugfix: Fix command injection vulnerability in grunt tzdata pipeline9430b4c
Merge remote-tracking branch 'origin/master' into developfeaf900
Updated contributing.md + added 2021e files704cfac
updated contributing.md877c863
Updated contributing.md + added 2021e files5a3015c
updated contributing.mdUpdates
sequelize
from 4.41.2 to 6.29.0Release notes
Sourced from sequelize's releases.
... (truncated)
Commits
d3f5b5a
feat: throw an error if attribute includes parentheses (fixes CVE-2023-22578)...53bd9b7
meta: fix null test getWhereConditions (#15705)13f2e89
fix: accept undefined in where (#15703)d9e0728
fix: throw if where receives an invalid value (#15699)48d6193
fix: update moment-timezone version (#15685)fd4afa6
feat(types): use retry-as-promised types for retry options to match documenta...1247c01
feat: add support for bigints (backport of #14485) (#15413)94beace
feat(postgres): add support for lock_timeout #15345 (#15355)7885000
fix(oracle): remove hardcoded maxRows value (#15323)bc39fd6
fix: fix parameters not being replaced when after $$ strings (#15307)Maintainer changes
This version was pushed to npm by sdepold, a new releaser for sequelize since your current version.
Updates
sequelize-cli
from 4.0.0 to 5.5.0Changelog
Sourced from sequelize-cli's changelog.
... (truncated)
Commits
c46f744
5.5.03d1c41e
docs: changelog for next releasea04ff93
chores: remove extra build from cicd57b40
fix: special characters in password are not escaped (#722)0828c1f
chore(package): update mocha to version 6.0.0 (#745)c15c81f
change: default config for operator aliases (#743)8dc5a20
fix(package): update yargs to version 13.1.0 (#744)77a9a76
chore(package): update gulp to version 4.0.0 (#726)c19149f
docs: enum type (#728)139f854
5.4.0Updates
@babel/traverse
from 7.1.6 to 7.24.7Release notes
Sourced from
@babel/traverse
's releases.