This repository was archived by the owner on Nov 1, 2024. It is now read-only.
Bump the npm_and_yarn group across 1 directory with 15 updates#2
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Bump the npm_and_yarn group across 1 directory with 15 updates#2dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 3 updates in the /ring_hassio directory: [hosted-git-info](https://github.com/npm/hosted-git-info), [trim-newlines](https://github.com/sindresorhus/trim-newlines) and [ring-client-api](https://github.com/dgreif/ring). Updates `hosted-git-info` from 2.8.8 to 2.8.9 - [Release notes](https://github.com/npm/hosted-git-info/releases) - [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md) - [Commits](npm/hosted-git-info@v2.8.8...v2.8.9) Updates `http-cache-semantics` from 4.1.0 to 4.1.1 - [Commits](kornelski/http-cache-semantics@v4.1.0...v4.1.1) Updates `ip` from 1.1.5 to 1.1.9 - [Commits](indutny/node-ip@v1.1.5...v1.1.9) Updates `normalize-url` from 3.3.0 to 6.1.0 - [Release notes](https://github.com/sindresorhus/normalize-url/releases) - [Commits](sindresorhus/normalize-url@v3.3.0...v6.1.0) Updates `parse-path` from 4.0.1 to 4.0.4 - [Release notes](https://github.com/IonicaBizau/parse-path/releases) - [Commits](IonicaBizau/parse-path@4.0.1...4.0.4) Updates `parse-url` from 5.0.1 to 5.0.8 - [Release notes](https://github.com/IonicaBizau/parse-url/releases) - [Commits](IonicaBizau/parse-url@5.0.1...5.0.8) Updates `path-parse` from 1.0.6 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `semver` from 5.7.1 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.7.1...v5.7.2) Updates `simple-get` from 3.1.0 to 3.1.1 - [Commits](feross/simple-get@v3.1.0...v3.1.1) Updates `socket.io-parser` from 3.3.0 to 3.3.3 - [Release notes](https://github.com/socketio/socket.io-parser/releases) - [Changelog](https://github.com/socketio/socket.io-parser/blob/main/CHANGELOG.md) - [Commits](socketio/socket.io-parser@3.3.0...3.3.3) Updates `tar` from 6.0.2 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.0.2...v6.2.1) Removes `trim-newlines` Updates `ring-client-api` from 9.12.4 to 12.1.0 - [Release notes](https://github.com/dgreif/ring/releases) - [Commits](https://github.com/dgreif/ring/compare/v9.12.4...ring-client-api@12.1.0) Updates `xmlhttprequest-ssl` from 1.5.5 to 1.6.3 - [Commits](mjwwit/node-XMLHttpRequest@1.5.5...1.6.3) Updates `yargs-parser` from 10.1.0 to 21.1.1 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md) - [Commits](yargs/yargs-parser@v10.1.0...yargs-parser-v21.1.1) --- updated-dependencies: - dependency-name: hosted-git-info dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: http-cache-semantics dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ip dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: normalize-url dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: parse-path dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: parse-url dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: simple-get dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: socket.io-parser dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: trim-newlines dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ring-client-api dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: xmlhttprequest-ssl dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 3 updates in the /ring_hassio directory: hosted-git-info, trim-newlines and ring-client-api.
Updates
hosted-git-infofrom 2.8.8 to 2.8.9Changelog
Sourced from hosted-git-info's changelog.
Commits
8d4b369chore(release): 2.8.929adfe5fix: backport regex fix from #76Maintainer changes
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates
http-cache-semanticsfrom 4.1.0 to 4.1.1Commits
2449650Update mocha560b2d8Don't use regex to trim whitespaceb1bdb92Remove linting package zooc20dc7eCache 308Updates
ipfrom 1.1.5 to 1.1.9Commits
1ecbf2f1.1.96a3ada9lib: fixed CVE-2023-42282 and added unit test5dc3b2f1.1.88e6f28blib: even better node 6 support088c9e51.1.71a4ca35lib: add back support for Node.js 6af82ef41.1.6dba19f6package: exclude test folder from publishing7cd7f30ci: use github workflows4de50aelib: node 18 supportUpdates
normalize-urlfrom 3.3.0 to 6.1.0Release notes
Sourced from normalize-url's releases.
... (truncated)
Commits
437bf176.1.06216336Accept a boolean for theremoveQueryParametersoption (#136)305e3f26.0.1b1fdb51Fix ReDoS for data URLsb98fe7e6.0.001a4a91AddstripTextFragmentoption (#130)ba37969Renamemasterbranch tomain4dbc81bMove to GitHub Actionsededdbe5.3.0ddf2584Throw a friendly error onview-source:input (#124)Updates
parse-pathfrom 4.0.1 to 4.0.4Release notes
Sourced from parse-path's releases.
Commits
3795a3cUpdated docs16b37d8⬆️ 4.0.4 🎉6ff8639Replace new lines in the input url.5cef694Merge pull request #32 from ronyeh/master95fd0c5Use regex to check that the port is a series of digits 0-9.6098fcbUpdated docs19a36a2Use query-string -- fixes #286bb78e1⬆️ 4.0.3 🎉8acac4dUpdated docs1add785⬆️ 4.0.2 🎉Updates
parse-urlfrom 5.0.1 to 5.0.8Release notes
Sourced from parse-url's releases.
Commits
fa488b2Updated docs91051cf⬆️ 5.0.8 🎉e8dbac1Updated docsbe77c32Merge branch 'new-version' of github.com:IonicaBizau/parse-url into new-version2e37af3⬆️ 6.0.0 🎉802e19a⬆️ 6.0.0 🎉b99cf52Updated docs74520ffMerge branch 'feature/typescript' of https://github.com/Strandor/parse-url in...76c974b⬆️ 5.0.6 🎉b035d22Add unit test for normalize:true caseUpdates
path-parsefrom 1.0.6 to 1.0.7Commits
Updates
semverfrom 5.7.1 to 5.7.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
f8cc313chore: release 5.7.22f8fd41fix: better handling of whitespace (#585)deb5ad5chore:@npmcli/template-oss@4.16.0Maintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
simple-getfrom 3.1.0 to 3.1.1Commits
496166d3.1.16eb82c0Bug fix: Thirdparty cookie leakMaintainer changes
This version was pushed to npm by linusu, a new releaser for simple-get since your current version.
Updates
socket.io-parserfrom 3.3.0 to 3.3.3Release notes
Sourced from socket.io-parser's releases.
Changelog
Sourced from socket.io-parser's changelog.
... (truncated)
Commits
cd11e38chore(release): 3.3.3fb21e42fix: check the format of the index of each attachment3b0a392chore(release): 3.3.289197a0fix: prevent DoS (OOM) via massive packets (#95)25ca624chore(release): 3.3.1b51b39btest: use Node.js 10 for the browser tests4184e46chore: bump component-emitter dependencyUpdates
tarfrom 6.0.2 to 6.2.1Release notes
Sourced from tar's releases.
Changelog
Sourced from tar's changelog.
... (truncated)
Commits
bef7b1e6.2.1fe8cd57prevent extraction in excessively deep subfoldersfe7ebfdremove security.md5bc9d406.2.0fe1ef5echangelog 6.2e483220get rid of npm lint stuff689928aci that works outside of npm orgdb6f539file inference improvements for .tbr and .tgz336fa8frefactor: dry and other pr commentseeba222chore: lint fixesRemoves
trim-newlinesUpdates
ring-client-apifrom 9.12.4 to 12.1.0Release notes
Sourced from ring-client-api's releases.
... (truncated)
Commits
4b4e561Version Packages (#1377)7354a21Update dependencies088acfeBump axios from 1.5.0 to 1.6.1 (#1357)7be94d3Update camera utils package and homebridge ui info (#1352)ea472ddBump@babel/traversefrom 7.20.1 to 7.23.2 (#1336)dae7970Update ring-types.ts (#1334)26eebc8Bump systeminformation from 5.21.5 to 5.21.7 (#1314)1a22a8cBump graphql from 16.6.0 to 16.8.1 (#1315)0584b7dVersion Packages (#1310)3604f30Update dependenciesUpdates
xmlhttprequest-sslfrom 1.5.5 to 1.6.3Commits
711bd4aPrepare release 1.6.34e8322fMerge pull request #8 from mrcarlberg/mjwwit_unescape_url_pathname_when_loadi...ee1e81fFix CVE-2020-285026a0a91dUnescape pathname from url when loading from local filesystembf53329Fix issue where rejectUnauthorized would default to false instead of trueae388321.6.0534b586Remove superfluous + operatora9d93fbReplace deprecated sys.puts calls with console.log in testsefc39e9Merge pull request #6 from wesgarland/masterb9fedb0pushed version to 1.5.6Updates
yargs-parserfrom 10.1.0 to 21.1.1Release notes
Sourced from yargs-parser's releases.
... (truncated)
Changelog
Sourced from yargs-parser's changelog.
... (truncated)
Commits
3aba24cchore(main): release yargs-parser 21.1.1 (#455)d69f9c3fix(typescript): ignore .cts files during publish (#454)90067a0chore(main): release yargs-parser 21.1.0 (#446)d07bcdbfix: node version check now uses process.versions.node (#450)c0c6079chore(deps): update dependency puppeteer to v16 (#451)a89259ffeat: allow the browser build to be imported (#443)c474bc1fix(halt-at-non-option): prevent known args from being parsed when "unknown-o...fd30238chore(deps): update dependency serve to v14 (#449)a072f9achore(deps): update dependency puppeteer to v15 (#444)4f1060bfix: parse options ending with 3+ hyphens (#434)Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for yargs-parser since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.