Bump the npm_and_yarn group across 1 directory with 32 updates#4
Bump the npm_and_yarn group across 1 directory with 32 updates#4dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 19 updates in the / directory: | Package | From | To | | --- | --- | --- | | [hoek](https://github.com/hapijs/hoek) | `5.0.3` | `6.1.3` | | [npm](https://github.com/npm/cli) | `4.6.1` | `11.9.0` | | [angular](https://github.com/angular/angular.js) | `1.6.8` | `1.8.3` | | [angular-sanitize](https://github.com/angular/angular.js) | `1.6.8` | `1.8.3` | | [kind-of](https://github.com/jonschlinkert/kind-of) | `6.0.2` | `6.0.3` | | [async](https://github.com/caolan/async) | `2.6.0` | `2.6.4` | | [bl](https://github.com/rvagg/bl) | `1.2.1` | `1.2.3` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.5` | | [cached-path-relative](https://github.com/ashaffer/cached-path-relative) | `1.0.1` | `1.1.0` | | [cipher-base](https://github.com/crypto-browserify/cipher-base) | `1.0.4` | `1.0.7` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [flatnest](https://github.com/brycebaril/node-flatnest) | `1.0.0` | `1.0.1` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.4` | `3.1.2` | | [json-schema](https://github.com/kriszyp/json-schema) | `0.2.3` | `0.4.0` | | [json5](https://github.com/json5/json5) | `0.5.1` | `2.2.3` | | [lodash.merge](https://github.com/lodash/lodash) | `4.6.0` | `4.6.2` | | [node-notifier](https://github.com/mikaelbr/node-notifier) | `5.2.1` | `10.0.1` | | [stringstream](https://github.com/mhart/StringStream) | `0.0.5` | `0.0.6` | | [secp256k1](https://github.com/cryptocoinjs/secp256k1-node) | `3.5.0` | `3.8.1` | Updates `hoek` from 5.0.3 to 6.1.3 - [Release notes](https://github.com/hapijs/hoek/releases) - [Commits](hapijs/hoek@v5.0.3...v6.1.3) Updates `npm` from 4.6.1 to 11.9.0 - [Release notes](https://github.com/npm/cli/releases) - [Changelog](https://github.com/npm/cli/blob/latest/CHANGELOG.md) - [Commits](npm/cli@v4.6.1...v11.9.0) Updates `angular` from 1.6.8 to 1.8.3 - [Changelog](https://github.com/angular/angular.js/blob/master/CHANGELOG.md) - [Commits](angular/angular.js@v1.6.8...v1.8.3) Updates `angular-sanitize` from 1.6.8 to 1.8.3 - [Changelog](https://github.com/angular/angular.js/blob/master/CHANGELOG.md) - [Commits](angular/angular.js@v1.6.8...v1.8.3) Updates `ajv` from 4.11.4 to 4.11.8 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](https://github.com/ajv-validator/ajv/commits/4.11.8) Updates `kind-of` from 6.0.2 to 6.0.3 - [Changelog](https://github.com/jonschlinkert/kind-of/blob/master/CHANGELOG.md) - [Commits](jonschlinkert/kind-of@6.0.2...6.0.3) Updates `async` from 2.6.0 to 2.6.4 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md) - [Commits](caolan/async@v2.6.0...v2.6.4) Updates `bl` from 1.2.1 to 1.2.3 - [Release notes](https://github.com/rvagg/bl/releases) - [Changelog](https://github.com/rvagg/bl/blob/master/CHANGELOG.md) - [Commits](rvagg/bl@v1.2.1...v1.2.3) Updates `brace-expansion` from 1.1.6 to 1.1.8 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.6...v1.1.8) Updates `browserify-sign` from 4.0.4 to 4.2.5 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.5) Updates `cached-path-relative` from 1.0.1 to 1.1.0 - [Commits](https://github.com/ashaffer/cached-path-relative/commits) Updates `cipher-base` from 1.0.4 to 1.0.7 - [Changelog](https://github.com/browserify/cipher-base/blob/master/CHANGELOG.md) - [Commits](browserify/cipher-base@v1.0.4...v1.0.7) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `flatnest` from 1.0.0 to 1.0.1 - [Commits](https://github.com/brycebaril/node-flatnest/commits) Updates `form-data` from 2.1.2 to 2.1.4 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v2.1.2...v2.1.4) Updates `minimatch` from 3.0.4 to 3.1.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.4...v3.1.2) Updates `hosted-git-info` from 2.4.2 to 2.5.0 - [Release notes](https://github.com/npm/hosted-git-info/releases) - [Changelog](https://github.com/npm/hosted-git-info/blob/main/CHANGELOG.md) - [Commits](npm/hosted-git-info@v2.4.2...v2.5.0) Updates `ini` from 1.3.4 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.4...v1.3.8) Updates `json-schema` from 0.2.3 to 0.4.0 - [Commits](kriszyp/json-schema@v0.2.3...v0.4.0) Updates `json5` from 0.5.1 to 2.2.3 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v0.5.1...v2.2.3) Updates `lodash.merge` from 4.6.0 to 4.6.2 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](https://github.com/lodash/lodash/commits) Updates `micromatch` from 3.1.5 to 4.0.8 - [Release notes](https://github.com/micromatch/micromatch/releases) - [Changelog](https://github.com/micromatch/micromatch/blob/master/CHANGELOG.md) - [Commits](micromatch/micromatch@3.1.5...4.0.8) Updates `node-notifier` from 5.2.1 to 10.0.1 - [Changelog](https://github.com/mikaelbr/node-notifier/blob/master/CHANGELOG.md) - [Commits](mikaelbr/node-notifier@v5.2.1...v10.0.1) Updates `chownr` from 1.0.1 to 3.0.0 - [Commits](isaacs/chownr@v1.0.1...v3.0.0) Updates `npm-user-validate` from 0.1.5 to 4.0.0 - [Release notes](https://github.com/npm/npm-user-validate/releases) - [Changelog](https://github.com/npm/npm-user-validate/blob/main/CHANGELOG.md) - [Commits](npm/npm-user-validate@v0.1.5...v4.0.0) Updates `stringstream` from 0.0.5 to 0.0.6 - [Commits](mhart/StringStream@v0.0.5...v0.0.6) Updates `tough-cookie` from 2.3.2 to 2.3.3 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v2.3.2...v2.3.3) Updates `tar` from 2.2.1 to 7.5.7 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v2.2.1...v7.5.7) Updates `path-parse` from 1.0.5 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `pbkdf2` from 3.0.14 to 3.1.5 - [Changelog](https://github.com/browserify/pbkdf2/blob/master/CHANGELOG.md) - [Commits](browserify/pbkdf2@v3.0.14...v3.1.5) Updates `secp256k1` from 3.5.0 to 3.8.1 - [Release notes](https://github.com/cryptocoinjs/secp256k1-node/releases) - [Commits](cryptocoinjs/secp256k1-node@v3.5.0...v3.8.1) Updates `sha.js` from 2.4.10 to 2.4.12 - [Changelog](https://github.com/browserify/sha.js/blob/master/CHANGELOG.md) - [Commits](browserify/sha.js@v2.4.10...v2.4.12) --- updated-dependencies: - dependency-name: hoek dependency-version: 6.1.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: npm dependency-version: 11.9.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: angular dependency-version: 1.8.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: angular-sanitize dependency-version: 1.8.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: ajv dependency-version: 4.11.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: kind-of dependency-version: 6.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: async dependency-version: 2.6.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: bl dependency-version: 1.2.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-version: 4.2.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cached-path-relative dependency-version: 1.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cipher-base dependency-version: 1.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-version: 0.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: flatnest dependency-version: 1.0.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: form-data dependency-version: 2.1.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-version: 3.1.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hosted-git-info dependency-version: 2.5.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-version: 1.3.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json-schema dependency-version: 0.4.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json5 dependency-version: 2.2.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash.merge dependency-version: 4.6.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: micromatch dependency-version: 4.0.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: node-notifier dependency-version: 10.0.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: chownr dependency-version: 3.0.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: npm-user-validate dependency-version: 4.0.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: stringstream dependency-version: 0.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tough-cookie dependency-version: 2.3.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 7.5.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-version: 1.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: pbkdf2 dependency-version: 3.1.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: secp256k1 dependency-version: 3.8.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: sha.js dependency-version: 2.4.12 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the npm_and_yarn group with 19 updates in the / directory:
5.0.36.1.34.6.111.9.01.6.81.8.31.6.81.8.36.0.26.0.32.6.02.6.41.2.11.2.34.0.44.2.51.0.11.1.01.0.41.0.70.2.00.2.21.0.01.0.13.0.43.1.20.2.30.4.00.5.12.2.34.6.04.6.25.2.110.0.10.0.50.0.63.5.03.8.1Updates
hoekfrom 5.0.3 to 6.1.3Commits
47d63066.1.3eef9740cleanupfc934afCleanupf2eb7fdClone without prototype. Closes #2905bfe5b66.1.217fe9a1Revert all symbol handlings to false by default. Closes #283542939b6.1.1947a326Ignore symbols in deepEqual() by default. Closes #28127ac6306.1.0b3b5134Merge pull request #281 from kanongil/symbol-supportUpdates
npmfrom 4.6.1 to 11.9.0Release notes
Sourced from npm's releases.
... (truncated)
Changelog
Sourced from npm's changelog.
... (truncated)
Commits
417daa7chore: release 11.9.0332c9f3deps: glob@13.0.1eca02c7deps: minimatch@10.1.2@isaacs/brace-expansion@5.0.12242f25fix(webauth): improve error messages around webauth in non-TTY (#8952)b3f8475deps: minipass-fetch@5.0.14a82a8fchore: dev dependency updates924171bdeps: is-cidr@6.0.24404002deps: ci-info@4.4.0b65af73deps: lru-cache@11.2.5164c355deps: tar@7.5.7Maintainer changes
This version was pushed to npm by gar, a new releaser for npm since your current version.
Updates
angularfrom 1.6.8 to 1.8.3Changelog
Sourced from angular's changelog.
... (truncated)
Commits
cf16b24docs(changelog): add release notes for 1.8.3757d56edocs(*): update end-of-life messages (#17177)f362437docs(eol): add EOL options text and link to template header used in every pagefb04e42test(Angular): fixangularInit()tests on Safari v15+6a52c4ftest(input): fix tests on Firefox v93+ed30c4ddocs(README.md): add wiki link to MVC4032655chore(deps): bump js-yaml from 3.5.5 to 3.14.147f8c65chore(deps): bump normalize-url from 4.5.0 to 4.5.156b0ee3chore(e2e): run tests against Chrome 91 on macOS Catalina58cd897chore(e2e): run tests against Firefox 85 on macOS CatalinaUpdates
angular-sanitizefrom 1.6.8 to 1.8.3Changelog
Sourced from angular-sanitize's changelog.
... (truncated)
Commits
cf16b24docs(changelog): add release notes for 1.8.3757d56edocs(*): update end-of-life messages (#17177)f362437docs(eol): add EOL options text and link to template header used in every pagefb04e42test(Angular): fixangularInit()tests on Safari v15+6a52c4ftest(input): fix tests on Firefox v93+ed30c4ddocs(README.md): add wiki link to MVC4032655chore(deps): bump js-yaml from 3.5.5 to 3.14.147f8c65chore(deps): bump normalize-url from 4.5.0 to 4.5.156b0ee3chore(e2e): run tests against Chrome 91 on macOS Catalina58cd897chore(e2e): run tests against Firefox 85 on macOS CatalinaUpdates
ajvfrom 4.11.4 to 4.11.8Release notes
Sourced from ajv's releases.
Commits
Updates
kind-offrom 6.0.2 to 6.0.3Changelog
Sourced from kind-of's changelog.
... (truncated)
Commits
abab0856.0.3a18459crun verb to generate README documentationdc6bea5only need to checktypeof val.constructor1df992cMerge pull request #31 from xiaofen9/master975c13afix type checking vul in ctorName4da96c0Delete FUNDING.yml28266f2Create FUNDING.ymlMaintainer changes
This version was pushed to npm by doowb, a new releaser for kind-of since your current version.
Updates
asyncfrom 2.6.0 to 2.6.4Changelog
Sourced from async's changelog.
Commits
c6bdacaVersion 2.6.48870da9Update built files4df6754update changelog8f7f903Fix prototype pollution vulnerability (#1828)f1d8383Version 2.6.32b674c1update changelogeab740ffix: udpate lodash. closes #1675eaf32beVersion 2.6.2684b42eUpdate built filese1bd3daupdate changelogMaintainer changes
This version was pushed to npm by hargasinski, a new releaser for async since your current version.
Updates
blfrom 1.2.1 to 1.2.3Release notes
Sourced from bl's releases.
Commits
d69edfd1.2.3847473atest all branches0bd87ecFix unintialized memory accessdc097f3test newer versions of Nodefeaaa4cBumped v1.2.2.307da45Merge pull request #51 from rvagg/safe-buffeercf6b00eRemoved node 7 from .travis.yml4b8f524Added safe-buffer and updated dependencies4acbe24Merge pull request #45 from EdwardBetts/spelling52ed96ccorrect spelling mistakeUpdates
brace-expansionfrom 1.1.6 to 1.1.8Commits
8f59e681.1.86049719bump balanced-match (1.0.0 for semver updates)89251201.1.7ed46e5bMerge pull request #35 from kamael/masterb133812fix bug in juliangruber/brace-expansion#33265f6cdMerge pull request #34 from juliangruber/greenkeeper/initial9c5d643Update README.mdd6f2867Update README.mdc91e261docs(readme): add Greenkeeper badge499e205update travisUpdates
browserify-signfrom 4.0.4 to 4.2.5Changelog
Sourced from browserify-sign's changelog.
... (truncated)
Commits
d3a7458v4.2.537b083c[Tests] clean up tests and convert console info skips to tape skipsfaade86[Fix] restore node 0.10 support5a0f159[Deps] updateparse-asn1106be97[actions] drop unsupported nodes from CI9c37172v4.2.46d5b280[meta] removefilesfield17920d9[actions] split out node 10-20, and 20+31be0c2[Deps] updatebn.js,browserify-rsa,ellipticab975f4[Dev Deps] add missing peer depMaintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates
cached-path-relativefrom 1.0.1 to 1.1.0Commits
Updates
cipher-basefrom 1.0.4 to 1.0.7Changelog
Sourced from cipher-base's changelog.
Commits
0056718v1.0.7fd1e5ee[Refactor] useto-buffer08ba803[Dev Deps] update@ljharb/eslint-configf5249f9v1.0.6b7ddd2a[Fix] io.js 3.0 - Node.js 5.3 typed array supportf03cebfv1.0.588dc806[meta] addauto-changelog7a137d7[meta] addnpmignoreandsafe-publish-latest5c02918[meta] fix package.json indentation8fd1364[Fix] return valid values on multi-byte-wide TypedArray inputMaintainer changes
This version was pushed to npm by ljharb, a new releaser for cipher-base since your current version.
Updates
decode-uri-componentfrom 0.2.0 to 0.2.2Release notes
Sourced from decode-uri-component's releases.
Commits
a0eea460.2.2980e0bfPrevent overwriting previously decoded tokens3c8a3730.2.176abc93Switch to GitHub workflows746ca5dFix issue where decode throws - fixes #6486d7e2Update license (#1)a650457Tidelift tasks66e1c28Meta tweaksUpdates
flatnestfrom 1.0.0 to 1.0.1Commits
Updates
form-datafrom 2.1.2 to 2.1.4Release notes
Sourced from form-data's releases.
Changelog
Sourced from form-data's changelog.