chore(deps): bump the npm_and_yarn group across 6 directories with 18 updates#3
chore(deps): bump the npm_and_yarn group across 6 directories with 18 updates#3dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
… updates Bumps the npm_and_yarn group with 4 updates in the / directory: [lodash](https://github.com/lodash/lodash), [send](https://github.com/pillarjs/send), [pug](https://github.com/pugjs/pug) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the npm_and_yarn group with 1 update in the /dev/coverage-action directory: [lodash](https://github.com/lodash/lodash). Bumps the npm_and_yarn group with 1 update in the /dev/del-old-packages directory: [@octokit/request](https://github.com/octokit/request.js). Bumps the npm_and_yarn group with 5 updates in the /dev/deploy-to-container directory: | Package | From | To | | --- | --- | --- | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.0.1` | `2.0.2` | | [cross-spawn](https://github.com/moxystudio/node-cross-spawn) | `7.0.3` | `7.0.6` | | [glob](https://github.com/isaacs/node-glob) | `10.3.12` | `10.5.0` | | [tar](https://github.com/isaacs/node-tar) | `7.4.3` | `7.5.8` | | [tar-fs](https://github.com/mafintosh/tar-fs) | `2.1.2` | `2.1.4` | Bumps the npm_and_yarn group with 5 updates in the /dev/diff directory: | Package | From | To | | --- | --- | --- | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.0.1` | `2.0.2` | | [cross-spawn](https://github.com/moxystudio/node-cross-spawn) | `7.0.3` | `7.0.6` | | [glob](https://github.com/isaacs/node-glob) | `10.3.12` | `10.5.0` | | [tar](https://github.com/isaacs/node-tar) | `7.4.3` | `7.5.8` | | [tar-fs](https://github.com/mafintosh/tar-fs) | `2.1.2` | `2.1.4` | Bumps the npm_and_yarn group with 9 updates in the /playwright directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.17.23` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.12` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.0.1` | `2.0.2` | | [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` | | [cross-spawn](https://github.com/moxystudio/node-cross-spawn) | `7.0.3` | `7.0.6` | | [ip](https://github.com/indutny/node-ip) | `2.0.0` | `removed` | | [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.0` | `4.1.1` | | [semver](https://github.com/npm/node-semver) | `6.3.0` | `6.3.1` | | [tar](https://github.com/isaacs/node-tar) | `6.1.15` | `removed` | | [playwright](https://github.com/microsoft/playwright) | `1.42.1` | `1.58.2` | Updates `lodash` from 4.17.21 to 4.17.23 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.17.23) Updates `send` from 0.18.0 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.18.0...0.19.0) Updates `pug` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug@3.0.2...pug@3.0.3) Updates `vite` from 4.5.3 to 5.4.21 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v5.4.21/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v5.4.21/packages/vite) Updates `esbuild` from 0.18.20 to 0.21.5 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2023.md) - [Commits](evanw/esbuild@v0.18.20...v0.21.5) Updates `rollup` from 3.29.4 to 4.57.1 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG-3.md) - [Commits](rollup/rollup@v3.29.4...v4.57.1) Updates `lodash` from 4.17.21 to 4.17.23 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.17.23) Updates `@octokit/request` from 6.2.2 to 10.0.7 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v6.2.2...v10.0.7) Updates `@octokit/request-error` from 3.0.2 to 7.1.0 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v3.0.2...v7.1.0) Updates `brace-expansion` from 2.0.1 to 2.0.2 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.0.2) Updates `cross-spawn` from 7.0.3 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6) Updates `glob` from 10.3.12 to 10.5.0 - [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md) - [Commits](isaacs/node-glob@v10.3.12...v10.5.0) Updates `tar` from 7.4.3 to 7.5.8 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v7.4.3...v7.5.8) Updates `tar-fs` from 2.1.2 to 2.1.4 - [Commits](mafintosh/tar-fs@v2.1.2...v2.1.4) Updates `brace-expansion` from 2.0.1 to 2.0.2 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.0.2) Updates `cross-spawn` from 7.0.3 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6) Updates `glob` from 10.3.12 to 10.5.0 - [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md) - [Commits](isaacs/node-glob@v10.3.12...v10.5.0) Updates `tar` from 7.4.3 to 7.5.8 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v7.4.3...v7.5.8) Updates `tar-fs` from 2.1.2 to 2.1.4 - [Commits](mafintosh/tar-fs@v2.1.2...v2.1.4) Updates `lodash` from 4.17.21 to 4.17.23 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.17.23) Updates `brace-expansion` from 1.1.11 to 1.1.12 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.0.2) Updates `brace-expansion` from 2.0.1 to 2.0.2 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.0.2) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `cross-spawn` from 7.0.3 to 7.0.6 - [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md) - [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6) Removes `ip` Updates `js-yaml` from 4.1.0 to 4.1.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@4.1.0...4.1.1) Updates `semver` from 6.3.0 to 6.3.1 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v6.3.1/CHANGELOG.md) - [Commits](npm/node-semver@v6.3.0...v6.3.1) Removes `tar` Updates `playwright` from 1.42.1 to 1.58.2 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.42.1...v1.58.2) --- updated-dependencies: - dependency-name: lodash dependency-version: 4.17.23 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: send dependency-version: 0.19.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: pug dependency-version: 3.0.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 5.4.21 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: esbuild dependency-version: 0.21.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.57.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.23 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 10.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request-error" dependency-version: 7.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: glob dependency-version: 10.5.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 7.5.8 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tar-fs dependency-version: 2.1.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: glob dependency-version: 10.5.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 7.5.8 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tar-fs dependency-version: 2.1.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.23 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: braces dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-spawn dependency-version: 7.0.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ip dependency-version: dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-version: 4.1.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-version: 6.3.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: playwright dependency-version: 1.58.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
3 issues found across 54 files
Prompt for AI agents (all issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="dev/deploy-to-container/package.json">
<violation number="1" location="dev/deploy-to-container/package.json:10">
P2: The new tar 7.5.8 dependency requires Node >=18, but this package still advertises support for Node >=16. That mismatch will break installs or runtime on Node 16. Align the engines requirement or pin tar to a Node 16-compatible version.</violation>
</file>
<file name="dev/del-old-packages/package.json">
<violation number="1" location="dev/del-old-packages/package.json:13">
P2: @octokit/core v7 drops Node 18 support (requires Node 20+), but this tool’s README still targets Node 18.x. Updating to ^7.0.6 will break installs/runs on Node 18. Either keep @octokit/core on the latest 6.x release or update the tool’s Node requirement/runtime to 20+.</violation>
</file>
<file name="package.json">
<violation number="1" location="package.json:76">
P2: Vite 5 requires Node.js 18+ while the project documents Node 16.x as the supported baseline. Upgrading to Vite 5 will break local installs and CI running on Node 16 unless the Node requirement is bumped or Vite stays on 4.x.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
| "nanoid-dictionary": "5.0.0", | ||
| "slugify": "1.6.6", | ||
| "tar": "^7.4.3", | ||
| "tar": "^7.5.8", |
There was a problem hiding this comment.
P2: The new tar 7.5.8 dependency requires Node >=18, but this package still advertises support for Node >=16. That mismatch will break installs or runtime on Node 16. Align the engines requirement or pin tar to a Node 16-compatible version.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At dev/deploy-to-container/package.json, line 10:
<comment>The new tar 7.5.8 dependency requires Node >=18, but this package still advertises support for Node >=16. That mismatch will break installs or runtime on Node 16. Align the engines requirement or pin tar to a Node 16-compatible version.</comment>
<file context>
@@ -4,10 +4,10 @@
"nanoid-dictionary": "5.0.0",
"slugify": "1.6.6",
- "tar": "^7.4.3",
+ "tar": "^7.5.8",
"yargs": "^17.7.2"
},
</file context>
| "license": "ISC", | ||
| "dependencies": { | ||
| "@octokit/core": "^4.2.4", | ||
| "@octokit/core": "^7.0.6", |
There was a problem hiding this comment.
P2: @octokit/core v7 drops Node 18 support (requires Node 20+), but this tool’s README still targets Node 18.x. Updating to ^7.0.6 will break installs/runs on Node 18. Either keep @octokit/core on the latest 6.x release or update the tool’s Node requirement/runtime to 20+.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At dev/del-old-packages/package.json, line 13:
<comment>@octokit/core v7 drops Node 18 support (requires Node 20+), but this tool’s README still targets Node 18.x. Updating to ^7.0.6 will break installs/runs on Node 18. Either keep @octokit/core on the latest 6.x release or update the tool’s Node requirement/runtime to 20+.</comment>
<file context>
@@ -10,7 +10,7 @@
"license": "ISC",
"dependencies": {
- "@octokit/core": "^4.2.4",
+ "@octokit/core": "^7.0.6",
"luxon": "^3.4.4"
}
</file context>
| "@octokit/core": "^7.0.6", | |
| "@octokit/core": "^6.1.6", |
| "sass": "1.72.0", | ||
| "seedrandom": "3.0.5", | ||
| "vite": "4.5.3" | ||
| "vite": "5.4.21" |
There was a problem hiding this comment.
P2: Vite 5 requires Node.js 18+ while the project documents Node 16.x as the supported baseline. Upgrading to Vite 5 will break local installs and CI running on Node 16 unless the Node requirement is bumped or Vite stays on 4.x.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At package.json, line 76:
<comment>Vite 5 requires Node.js 18+ while the project documents Node 16.x as the supported baseline. Upgrading to Vite 5 will break local installs and CI running on Node 16 unless the Node requirement is bumped or Vite stays on 4.x.</comment>
<file context>
@@ -70,10 +70,10 @@
"sass": "1.72.0",
"seedrandom": "3.0.5",
- "vite": "4.5.3"
+ "vite": "5.4.21"
},
"targets": {
</file context>
| "vite": "5.4.21" | |
| "vite": "4.5.3" |
Bumps the npm_and_yarn group with 4 updates in the / directory: lodash, send, pug and vite.
Bumps the npm_and_yarn group with 1 update in the /dev/coverage-action directory: lodash.
Bumps the npm_and_yarn group with 1 update in the /dev/del-old-packages directory: @octokit/request.
Bumps the npm_and_yarn group with 5 updates in the /dev/deploy-to-container directory:
2.0.12.0.27.0.37.0.610.3.1210.5.07.4.37.5.82.1.22.1.4Bumps the npm_and_yarn group with 5 updates in the /dev/diff directory:
2.0.12.0.27.0.37.0.610.3.1210.5.07.4.37.5.82.1.22.1.4Bumps the npm_and_yarn group with 9 updates in the /playwright directory:
4.17.214.17.231.1.111.1.122.0.12.0.23.0.23.0.37.0.37.0.62.0.0removed4.1.04.1.16.3.06.3.16.1.15removed1.42.11.58.2Updates
lodashfrom 4.17.21 to 4.17.23Commits
dec55b7Bump main to v4.17.23 (#6088)19c9251fix: setCacheHas JSDoc return type should be boolean (#6071)b5e6729jsdoc: Add -0 and BigInt zeros to _.compact falsey values list (#6062)edadd45Prevent prototype pollution on baseUnset function4879a7adoc: fix autoLink function, conversion of source links (#6056)9648f69chore: removeyarn.lockfile (#6053)dfa407dci: remove legacy configuration files (#6052)156e196feat: add renovate setup (#6039)933e106ci: add pipeline for Bun (#6023)072a807docs: update links related to Open JS Foundation (#5968)Updates
sendfrom 0.18.0 to 0.19.0Release notes
Sourced from send's releases.
Changelog
Sourced from send's changelog.
Commits
9d2db990.19.0ae4f298Merge commit from forkMaintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for send since your current version.
Updates
pugfrom 3.0.2 to 3.0.3Release notes
Sourced from pug's releases.
Commits
32acfe8fix: ensure template names are valid identifiers (#3438)4767cafrefactor: convert pug-error to TypeScript (#3355)a724446chore: update character-parser (#3354)6cca8f7docs: fix GitHub format in README (#3335)Updates
vitefrom 4.5.3 to 5.4.21Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
adce3c2release: v5.4.21cad1d31fix(dev): trim trailing slash beforeserver.fs.denycheck (#20968) (#20970)ca88ed7chore: update CHANGELOG997700frelease: v5.4.20482000ffix: applyfs.strictcheck to HTML files (#20736)80a333arelease: v5.4.19766947efix: backport #19965, check static serve file inside sirv (#19966)731b77drelease: v5.4.18823675bfix: backport #19830, reject requests with#in request-target (#19831)0a2518arelease: v5.4.17Updates
esbuildfrom 0.18.20 to 0.21.5Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
fc37c2fpublish 0.21.5 to npmcb11924fixSymbol.metadataerrors in decorator testsb93a2a9fix #3781: add metadata to all decorated classes953dae9fix #3797: import attributes and glob-style import98cb2edfix #3782: support${configDir}in tsconfig.json8e6603brunmake update-compat-tabledb1b8cafix #3792: import attributes and thecopyloaderde572d0fix non-deterministic import attribute plugin testae8d1b4fix #3794:--supported:object-accessors=false67cbf87publish 0.21.4 to npmUpdates
rollupfrom 3.29.4 to 4.57.1Release notes
Sourced from rollup's releases.
... (truncated)
Changelog
Sourced from rollup's changelog.
Commits
d37675f4.57.1eafac0bchore(deps): lock file maintenance (#6255)47fa568chore(deps): update dependency lru-cache to v11 (#6252)416f476Fully include dynamic imports in a try-catch (#6254)5e393e3fix: Isolate and cacheprocess.report.getReport()calls in a child process ...c931d23chore(deps): lock file maintenance minor/patch updates (#6253)c79e6c2Mitigate vulnerability that would allow to steal credentials743d0544.57.074121c7extend more hooks to include import attributes and add warnings (#5700)c519d82Refactor to reduce Rollup 5 upgrade diff (#6246)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for rollup since your current version.
Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
lodashfrom 4.17.21 to 4.17.23Commits
dec55b7Bump main to v4.17.23 (#6088)19c9251fix: setCacheHas JSDoc return type should be boolean (#6071)b5e6729jsdoc: Add -0 and BigInt zeros to _.compact falsey values list (#6062)edadd45Prevent prototype pollution on baseUnset function4879a7adoc: fix autoLink function, conversion of source links (#6056)9648f69chore: removeyarn.lockfile (#6053)dfa407dci: remove legacy configuration files (#6052)156e196feat: add renovate setup (#6039)933e106ci: add pipeline for Bun (#6023)072a807docs: update links related to Open JS Foundation (#5968)Updates
@octokit/requestfrom 6.2.2 to 10.0.7Release notes
Sourced from
@octokit/request's releases.... (truncated)
Commits
f17c1c1fix(readme): properly structure the options for custom agent (#786)ea46fa9ci(action): update github/codeql-action action to v4 (#778)8166d28chore(deps): update vitest monorepo to v4 (major) (#781)1aeac56fix(deps): update dependency@octokit/typesto v16 (#783)b5b08a2ci(action): update actions/setup-node action to v6 (#779)9a78123chore(deps): update dependency@types/nodeto v24 (#782)30f83b6fix(deps): update octokit deps (#772)b07d593ci(action): update actions/checkout action to v5 (#770)928c3d7chore(deps): update dependency prettier to v3.6.2 (#766)a84613eci(action): update actions/setup-node action to v5 (#771)Updates
@octokit/request-errorfrom 3.0.2 to 7.1.0Release notes
Sourced from
@octokit/request-error's releases.... (truncated)
Commits
2ea2780feat: inherit options from baseErrorclass to add support for thecause...ac7b309chore(deps): update vitest monorepo to v4 (major) (#531)dadc76dci(action): update peter-evans/create-or-update-comment action to v5 (#525)f57f2e6build(deps): lock file maintenance (#534)e5a75effix(deps): update dependency@octokit/typesto v16 (#533)e5d5de2chore(deps): update dependency@types/nodeto v24 (#532)8cc127bci(action): update actions/setup-node action to v6 (#529)b3a876bbuild(deps): lock file maintenance (#527)cf1817bci(action): update github/codeql-action action to v4 (#528)61f1e87chore(deps): update dependency tinybench to v5 (#519)Updates
brace-expansionfrom 2.0.1 to 2.0.2Release notes
Sourced from brace-expansion's releases.
Commits
a3efcee2.0.214f1d91pkg: publish on tag 2.xed7780afmt36603d5Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
cross-spawnfrom 7.0.3 to 7.0.6Changelog
Sourced from cross-spawn's changelog.
Commits
77cd97fchore(release): 7.0.66717de4chore: upgrade standard-versionf700743fix: update cross-spawn version to 7.0.5 in package-lock.json9a7e3b2chore: fix build status badge0852683chore(release): 7.0.5640d391fix: fix escaping bug introduced by backtrackingbff0c87chore: remove codecova7c6abcchore: replace travis with github workflows9b9246echore(release): 7.0.45ff3a07fix: disable regexp backtracking (#160)Updates
globfrom 10.3.12 to 10.5.0Changelog
Sourced from glob's changelog.
... (truncated)
Commits
56774ef10.5.01e4e297bin: Do not expose filenames to shell expansion1f0c1ca10.4.5eaf31dcwhatever, just allow any engines782751610.4.4d06c8f8restore support for node 14.latest and 16.latestc14b78710.4.38a69defnode 14 no longer supportedeef7ea310.4.2c76a7d2use package-json-from-dist to look up package.jsonUpdates
tarfrom 7.4.3 to 7.5.8Changelog
Sourced from tar's changelog.
... (truncated)
Commits
6b8eba07.5.82cb1120fix(unpack): improve UnpackSync symlink error "into" path accuracyd18e4e1fix: do not write linkpaths through symlinks4a37eb97.5.7f4a7aa9fix: properly sanitize hard links containing ..394ece67.5.67d4cc17fix race puting a Link ahead of its target File26ab9047.5.5e9a1ddbfix: do not prevent valid linkpaths within archive911c8867.5.4Maintainer changes
This version was pushed to npm by isaacs, a new releaser for tar since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
tar-fsfrom 2.1.2 to 2.1.4Commits
f421a232.1.4c412fa1refactor to same pattern as v34b7e8682.1.3266194bhardlink tweak from mainUpdates
brace-expansionfrom 2.0.1 to 2.0.2Release notes
Sourced from brace-expansion's releases.
Commits
a3efcee2.0.214f1d91pkg: publish on tag 2.xed7780afmt36603d5Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
cross-spawnfrom 7.0.3 to 7.0.6Changelog
Sourced from cross-spawn's changelog.
Commits
77cd97fchore(release): 7.0.66717de4chore: upgrade standard-versionf700743fix: update cross-spawn version to 7.0.5 in package-lock.json