Commit 4824da6
authored
upgrade: Bump lodash, @release-it/conventional-changelog and release-it (#661)
Bumps [lodash](https://github.com/lodash/lodash) to 4.17.23 and updates
ancestor dependencies [lodash](https://github.com/lodash/lodash),
[@release-it/conventional-changelog](https://github.com/release-it/conventional-changelog)
and [release-it](https://github.com/release-it/release-it). These
dependencies need to be updated together.
Updates `lodash` from 4.17.21 to 4.17.23
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lodash/lodash/commit/dec55b7a3b382da075e2eac90089b4cd00a26cbb"><code>dec55b7</code></a>
Bump main to v4.17.23 (<a
href="https://redirect.github.com/lodash/lodash/issues/6088">#6088</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/19c9251b3631d7cf220b43bc757eb33f1084f117"><code>19c9251</code></a>
fix: setCacheHas JSDoc return type should be boolean (<a
href="https://redirect.github.com/lodash/lodash/issues/6071">#6071</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/b5e672995ae26929d111a6e94589f8d03fb8e578"><code>b5e6729</code></a>
jsdoc: Add -0 and BigInt zeros to _.compact falsey values list (<a
href="https://redirect.github.com/lodash/lodash/issues/6062">#6062</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/edadd452146f7e4bad4ea684e955708931d84d81"><code>edadd45</code></a>
Prevent prototype pollution on baseUnset function</li>
<li><a
href="https://github.com/lodash/lodash/commit/4879a7a7d0a4494b0e83c7fa21bcc9fc6e7f1a6d"><code>4879a7a</code></a>
doc: fix autoLink function, conversion of source links (<a
href="https://redirect.github.com/lodash/lodash/issues/6056">#6056</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/9648f692b0fc7c2f6a7a763d754377200126c2e8"><code>9648f69</code></a>
chore: remove <code>yarn.lock</code> file (<a
href="https://redirect.github.com/lodash/lodash/issues/6053">#6053</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/dfa407db0bf5b200f2c7a9e4f06830ceaf074be9"><code>dfa407d</code></a>
ci: remove legacy configuration files (<a
href="https://redirect.github.com/lodash/lodash/issues/6052">#6052</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/156e1965ae78b121a88f81178ab81632304e8d64"><code>156e196</code></a>
feat: add renovate setup (<a
href="https://redirect.github.com/lodash/lodash/issues/6039">#6039</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/933e1061b8c344d3fc742cdc400175d5ffc99bce"><code>933e106</code></a>
ci: add pipeline for Bun (<a
href="https://redirect.github.com/lodash/lodash/issues/6023">#6023</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/072a807ff7ad8ffc7c1d2c3097266e815d138e20"><code>072a807</code></a>
docs: update links related to Open JS Foundation (<a
href="https://redirect.github.com/lodash/lodash/issues/5968">#5968</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/lodash/lodash/compare/4.17.21...4.17.23">compare
view</a></li>
</ul>
</details>
<br />
Updates `@release-it/conventional-changelog` from 8.0.1 to 10.0.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/release-it/conventional-changelog/releases"><code>@release-it/conventional-changelog</code>'s
releases</a>.</em></p>
<blockquote>
<h2>Release 10.0.5</h2>
<ul>
<li>test: add should generate changelog with remote origin urls (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/132">#132</a>)
(7e53f8ce957b1e2469acfff6bb2d1f9a46654b6f) - thanks <a
href="https://github.com/Maxel01"><code>@Maxel01</code></a>!</li>
<li>fix: pass parserOpts to both Bumper and ConventionalChangelog (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/135">#135</a>)
(4dce48ad332aeba00ae49c2f9df229961ab902eb) - thanks <a
href="https://github.com/aarond-sp"><code>@aarond-sp</code></a>!</li>
</ul>
<h2>Release 10.0.4</h2>
<ul>
<li>fix: add readRepository to resolve correct urls (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/131">#131</a>)
(933bcc6aa5d854158dc3702f004b5cbd4caf4cad) - thanks <a
href="https://github.com/Maxel01"><code>@Maxel01</code></a>!</li>
<li>Update release-it (ac4426a38d5d2c948884901acf8adec065d54c4f)</li>
</ul>
<h2>Release 10.0.3</h2>
<ul>
<li>Remove verbose comments
(eb178bd556e5939b93a374adc418d6be5cc85323)</li>
<li>fix: remove preset options filtering (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/129">#129</a>)
(1b9fb95608117bc3f0f3379188f5c82f3231a792) - thanks <a
href="https://github.com/NateSmyth"><code>@NateSmyth</code></a>!</li>
</ul>
<h2>Release 10.0.2</h2>
<ul>
<li>Remove node 18 from test matrix
(e00dabf5cdd374a33361aeda9aa9eaf8cb4be485)</li>
<li>feat: Preserve <code>preReleaseBase</code> config option (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/111">#111</a>)
(678faefe7049e30499d19d002c5ef6234a8a77b6) - thanks <a
href="https://github.com/ChAyLom"><code>@ChAyLom</code></a>!</li>
<li>Bump tmp from 0.2.3 to 0.2.4 (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/120">#120</a>)
(5ccbc29ba2e54308b5ad6fbf5209d50f4268916c) - thanks <a
href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]!</li>
<li>Fix CVE-2025-59433: Update dependencies and enable all tests (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/124">#124</a>)
(c838c6789872c12916ccc63ea93813ade66040cf) - thanks <a
href="https://github.com/nbouvrette"><code>@nbouvrette</code></a>!</li>
<li>Add Node 24 to CI workflow
(8f5ac43899d8e43f0eb9e4cc57aa8f07483fb921)</li>
<li>Add github release notes + comments
(2d0a4b396cfadb3f7a2807fdde6b763c773e668a)</li>
<li>Bump engines.node (not breaking as release-it has this too)
(5fa0ce80e0604296128d95748b345c9ee5a3f5df)</li>
</ul>
<h2>Release 10.0.1</h2>
<ul>
<li>Add dummy config file in test (3e9f528)</li>
<li>Support release-it v19 (a2f5059)</li>
<li>Add note about
<code>conventional-changelog-conventionalcommits</code> override (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/110">#110</a>)
(587be05)</li>
<li>docs: Show that whatBump accepts a function for recommending the new
version (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/109">#109</a>)
(bf27526)</li>
</ul>
<h2>Release 10.0.0</h2>
<ul>
<li>Update dependencies + bump engines.node (273c84f)</li>
</ul>
<h2>Release 9.0.4</h2>
<ul>
<li>Add default header (resolves <a
href="https://redirect.github.com/release-it/conventional-changelog/issues/108">#108</a>)
(6197330)</li>
</ul>
<h2>Release 9.0.3</h2>
<ul>
<li>Format (09fdb3e)</li>
<li>fix: use whatBump option (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/106">#106</a>)
(09aac9e)</li>
</ul>
<h2>Release 9.0.2</h2>
<ul>
<li>Minor refactor for readability (ccdd687)</li>
<li>Format docs (73e212c)</li>
<li>fix: Resolve whatBump is not a function error (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/105">#105</a>)
(5e0af0c)</li>
</ul>
<h2>Release 9.0.1</h2>
<ul>
<li>Update dependencies (6059558)</li>
<li>fix: Allow whatBump to return undefined to skip versioning (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/102">#102</a>)
(3301fbe)</li>
</ul>
<h2>Release 9.0.0</h2>
<ul>
<li>Update dependencies (1db67c1)</li>
<li>Add .gitignore file (d9416d7)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/066a90d3ef5bc1d931d4ea1e3563d7071be427b9"><code>066a90d</code></a>
Release 10.0.5</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/4dce48ad332aeba00ae49c2f9df229961ab902eb"><code>4dce48a</code></a>
fix: pass parserOpts to both Bumper and ConventionalChangelog (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/135">#135</a>)</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/7e53f8ce957b1e2469acfff6bb2d1f9a46654b6f"><code>7e53f8c</code></a>
test: add should generate changelog with remote origin urls (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/132">#132</a>)</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/a8b9b8a9db2d0e7d899a48b76d6f4359f9a253bb"><code>a8b9b8a</code></a>
Release 10.0.4</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/ac4426a38d5d2c948884901acf8adec065d54c4f"><code>ac4426a</code></a>
Update release-it</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/933bcc6aa5d854158dc3702f004b5cbd4caf4cad"><code>933bcc6</code></a>
fix: add readRepository to resolve correct urls (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/131">#131</a>)</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/5dcc152c3873565295dd8f971e930a751edb3072"><code>5dcc152</code></a>
Release 10.0.3</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/1b9fb95608117bc3f0f3379188f5c82f3231a792"><code>1b9fb95</code></a>
fix: remove preset options filtering (<a
href="https://redirect.github.com/release-it/conventional-changelog/issues/129">#129</a>)</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/eb178bd556e5939b93a374adc418d6be5cc85323"><code>eb178bd</code></a>
Remove verbose comments</li>
<li><a
href="https://github.com/release-it/conventional-changelog/commit/f81bb521b8048cbc9758822a94fa5ebb0a2aff4b"><code>f81bb52</code></a>
Release 10.0.2</li>
<li>Additional commits viewable in <a
href="https://github.com/release-it/conventional-changelog/compare/8.0.1...10.0.5">compare
view</a></li>
</ul>
</details>
<br />
Updates `release-it` from 17.1.1 to 19.2.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/release-it/release-it/releases">release-it's
releases</a>.</em></p>
<blockquote>
<h2>Release 19.2.4</h2>
<ul>
<li>chore: update dependencies to resolve security vulnerabilities (<a
href="https://redirect.github.com/release-it/release-it/issues/1273">#1273</a>)
(b45dd1aa3749d74ce279600dea242cb3c9dd5e8d) - thanks <a
href="https://github.com/Yeom-JinHo"><code>@Yeom-JinHo</code></a>!</li>
<li>Update a few dev deps
(cd8acdc8fdb50cf60ba45e8bd5128c4669a04f00)</li>
</ul>
<h2>Release 19.2.3</h2>
<ul>
<li>Reuse generated changelog
(316dbfa458d670fc92d2da7fe7298ad90f44dc68)</li>
<li>Remove obsolete eslint compat packages/config
(f6cc8f3622995ebe98c43a8a5adb8d62b2de70b8)</li>
<li>Update remark-preset-webpro and fix broken links
(6e6dd4b893bd53a621ea2bee9ad48d5fa42f6279)</li>
</ul>
<h2>Release 19.2.2</h2>
<ul>
<li>Improve <code>getChangelog</code> method
(7a56364997d8ca4a640251bc9be37ed7cbf8568c)</li>
</ul>
<h2>Release 19.2.1</h2>
<ul>
<li>Improve commit prompt
(b7aca7c159b3d34fe45f6fb722bb5f664c4bae9a)</li>
<li>Remedy potential edge case in template helper
(5c0a6eeeddf7ed1ce0e4cfcffc1c2c72ab63a01b)</li>
</ul>
<h2>Release 19.2.0</h2>
<ul>
<li>Add option to exit gracefully
(e1f825dce259118401f17c1d9de0002233e21e67)</li>
<li>Update dependencies (424c9f6c1d9681f4e4a3a37552dd2a99a750a3d2)</li>
<li>Auto-format docs (06f41bbb4b0cbb59ef39a6bd426ee9034b6f396e)</li>
<li>fix: add shell mode for npm commands on windows (<a
href="https://redirect.github.com/release-it/release-it/issues/1266">#1266</a>)
(382e3464095628c23ef9c85c363933f3bf1db09e) - thanks <a
href="https://github.com/julienbenac"><code>@julienbenac</code></a>!</li>
<li>Feat: Add <code>publishPackageManager</code> config option in NPM
plugin to allow using different package manager for publishing (e.g.
Bun) (<a
href="https://redirect.github.com/release-it/release-it/issues/1169">#1169</a>)
(0dafc0b72159931f088e7232da6c34f0f1e8b06f) - thanks <a
href="https://github.com/chrispader"><code>@chrispader</code></a>!</li>
<li>Only use <code>--workspaces=false</code> with npm
(12bb89ccaacdc2cbc0ba231f93d7bd389241d6a4)</li>
<li>Fix up docs/types a bit
(05a59863648a0b4ce9186b65cd21225a8421e181)</li>
<li>Format (c9d6ebf0415d264e42945f967baae845401d016b)</li>
</ul>
<h2>Release 19.1.0</h2>
<ul>
<li>Ignore .npmrc (8ccd060)</li>
<li>Update lockfile (c4cd2ba)</li>
<li>Support interactive shell in non-CI mode for 2FA flow (resolve <a
href="https://redirect.github.com/release-it/release-it/issues/1263">#1263</a>)
(a10b20d)</li>
<li>Add <code>--workspaces=false</code> to get rid of the
<code>null</code>/<code>matches</code> error (14a4907)</li>
<li>Remove npm config env var warnings (b8c1247)</li>
<li>doc(readme): add <code>release-it-beautiful-changelog</code> plugin
to list of plugins (<a
href="https://redirect.github.com/release-it/release-it/issues/1261">#1261</a>)
(1b68c21)</li>
<li>Add 403 to consider resource alive (7969849)</li>
</ul>
<h2>Release 19.0.6</h2>
<ul>
<li>Update list of projects using release-it
(92b49d367d28f0eef8cebb7d29059ab54259edff)</li>
<li>Bump github/codeql-action from 2 to 4 (<a
href="https://redirect.github.com/release-it/release-it/issues/1253">#1253</a>)
(21309d3dfcc29d6f87061f345610566070e092a8) - thanks <a
href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]!</li>
<li>Bump actions/setup-node from 5 to 6 (<a
href="https://redirect.github.com/release-it/release-it/issues/1255">#1255</a>)
(3fbaab14e2e3240a6b442b84be6019c57685c30e) - thanks <a
href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]!</li>
<li>Test in node 24 (7a12b12a8f75006c72854b0a0934faf5a320067f)</li>
<li>Upgrade c12 (resolve <a
href="https://redirect.github.com/release-it/release-it/issues/1254">#1254</a>)
(1f48d03ddfe5d0dff66e2b2211db688c01e5fff4)</li>
</ul>
<h2>Release 19.0.5</h2>
<ul>
<li>Add link to release-it-gitea plugin
(bf6f1fbb77797ece76c24b47bb1bcd89a9dbd18b)</li>
<li>Bump actions/checkout from 4 to 5 (<a
href="https://redirect.github.com/release-it/release-it/issues/1243">#1243</a>)
(e42e7dce72b1469ac1944a6d9eb6b6a8d987a919) - thanks <a
href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]!</li>
<li>Add OIDC publishing docs (<a
href="https://redirect.github.com/release-it/release-it/issues/1245">#1245</a>)
(9933c0d3a3ea7a06513b01863098445552942fce) - thanks <a
href="https://github.com/mceachen"><code>@mceachen</code></a>!</li>
<li>Bump actions/setup-node from 4 to 5 (<a
href="https://redirect.github.com/release-it/release-it/issues/1247">#1247</a>)
(7d9b77fa7ea8f4772257d675036f691982317c08) - thanks <a
href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]!</li>
<li>Auto-format (96181f33ec493a239b32667bfc30f4c8841488f9)</li>
<li>Update dependencies (0b907d1cf621572b06663c5acfe989c422d0bf09)</li>
<li>Remove redundant knip entry
(ca2f7b516585e115e0fbce7c96d0dbc219d2e665)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/release-it/release-it/blob/main/CHANGELOG.md">release-it's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<p>This document lists breaking changes for each major release.</p>
<p>See the GitHub Releases page for detailed changelogs:
<a
href="https://github.com/release-it/release-it/releases">https://github.com/release-it/release-it/releases</a></p>
<h2>v19 (2025-04-18)</h2>
<ul>
<li>No breaking changes (dependency party)</li>
</ul>
<h2>v18 (2025-01-06)</h2>
<ul>
<li>Removed support for Node.js v18.</li>
</ul>
<h2>v17 (2023-11-11)</h2>
<ul>
<li>Removed support for Node.js v16.</li>
</ul>
<h2>v16 (2023-07-05)</h2>
<ul>
<li>Removed support for Node.js v14.</li>
</ul>
<h2>v15 (2022-04-30)</h2>
<ul>
<li>Removed support for Node.js v10 and v12.</li>
<li>Removed support for GitLab v12.4 and lower.</li>
<li>Removed anonymous metrics (and the option to disable it).</li>
<li>Programmatic usage and plugins only through ES Module syntax
(<code>import</code>)</li>
</ul>
<p>Use release-it v14 in legacy environments.</p>
<h2>v14 (2020-09-03)</h2>
<ul>
<li>Removed <code>global</code> property from plugins. Use
<code>this.config[key]</code> instead.</li>
<li>Removed deprecated <code>npm.access</code> option. Set this in
<code>package.json</code> instead.</li>
</ul>
<h2>v13 (2020-03-07)</h2>
<ul>
<li>Dropped support for Node v8</li>
<li>Dropped support for GitLab v11.6 and lower.</li>
<li>Deprecated <code>scripts</code> are removed (in favor of <a
href="https://github.com/release-it/release-it#hooks">hooks</a>).</li>
<li>Removed deprecated <code>--non-interactive</code> (<code>-n</code>)
argument. Use <code>--ci</code> instead.</li>
<li>Removed old <code>%s</code> and <code>[REV_RANGE]</code> syntax in
command substitutions. Use <code>${version}</code> and
<code>${latestTag}</code> instead.</li>
</ul>
<h2>v12 (2019-05-03)</h2>
<ul>
<li>The <code>--follow-tags</code> argument for <code>git push</code>
has been moved to the default configuration. This is only a breaking
change if <code>git.pushArgs</code> was not empty (it was empty by
default).</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/release-it/release-it/commit/aa30853747fc926495525bf3216688071827f38e"><code>aa30853</code></a>
Release 19.2.4</li>
<li><a
href="https://github.com/release-it/release-it/commit/cd8acdc8fdb50cf60ba45e8bd5128c4669a04f00"><code>cd8acdc</code></a>
Update a few dev deps</li>
<li><a
href="https://github.com/release-it/release-it/commit/b45dd1aa3749d74ce279600dea242cb3c9dd5e8d"><code>b45dd1a</code></a>
chore: update dependencies to resolve security vulnerabilities (<a
href="https://redirect.github.com/release-it/release-it/issues/1273">#1273</a>)</li>
<li><a
href="https://github.com/release-it/release-it/commit/e52cea04e5f858c0676be81c9d28435044de8177"><code>e52cea0</code></a>
Release 19.2.3</li>
<li><a
href="https://github.com/release-it/release-it/commit/6e6dd4b893bd53a621ea2bee9ad48d5fa42f6279"><code>6e6dd4b</code></a>
Update remark-preset-webpro and fix broken links</li>
<li><a
href="https://github.com/release-it/release-it/commit/f6cc8f3622995ebe98c43a8a5adb8d62b2de70b8"><code>f6cc8f3</code></a>
Remove obsolete eslint compat packages/config</li>
<li><a
href="https://github.com/release-it/release-it/commit/316dbfa458d670fc92d2da7fe7298ad90f44dc68"><code>316dbfa</code></a>
Reuse generated changelog</li>
<li><a
href="https://github.com/release-it/release-it/commit/3378faf75f1a8e2e87f63a4914f8df68223b3a5b"><code>3378faf</code></a>
Release 19.2.2</li>
<li><a
href="https://github.com/release-it/release-it/commit/7a56364997d8ca4a640251bc9be37ed7cbf8568c"><code>7a56364</code></a>
Improve <code>getChangelog</code> method</li>
<li><a
href="https://github.com/release-it/release-it/commit/6c58c96457849d646e8b8570f6d1d965149af983"><code>6c58c96</code></a>
Release 19.2.1</li>
<li>Additional commits viewable in <a
href="https://github.com/release-it/release-it/compare/17.1.1...19.2.4">compare
view</a></li>
</ul>
</details>
<br />
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/qunitjs/eslint-plugin-qunit/network/alerts).
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent 466a58f commit 4824da6
2 files changed
+1902
-3003
lines changed
0 commit comments