Bump the npm_and_yarn group across 1 directory with 8 updates #5
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 6 updates in the / directory:
1.1.1
1.9.1
7.3.2
7.5.2
3.0.0
3.0.1
4.1.0
5.0.2
8.0.1
8.4.0
2.6.0
2.7.0
Updates
@actions/core
from 1.1.1 to 1.9.1Changelog
Sourced from
@actions/core
's changelog.... (truncated)
Commits
Maintainer changes
This version was pushed to npm by thboop, a new releaser for
@actions/core
since your current version.Updates
semver
from 7.3.2 to 7.5.2Release notes
Sourced from semver's releases.
... (truncated)
Changelog
Sourced from semver's changelog.
... (truncated)
Commits
e7b78de
chore: release 7.5.258c791f
fix: diff when detecting major change from prerelease (#566)5c8efbc
fix: preserve build in raw after inc (#565)717534e
fix: better handling of whitespace (#564)2f738e9
chore: bump@npmcli/template-oss
from 4.14.1 to 4.15.1 (#558)aa016a6
chore: release 7.5.1d30d25a
fix: show type on invalid semver error (#559)09c69e2
chore: bump@npmcli/template-oss
from 4.13.0 to 4.14.1 (#555)5b02ad7
chore: release 7.5.0e219bb4
fix: throw on bad version with correct error message (#552)Maintainer changes
This version was pushed to npm by npm-cli-ops, a new releaser for semver since your current version.
Updates
ansi-regex
from 3.0.0 to 3.0.1Commits
f545bdb
3.0.1c57d4c2
fix a few old XO issues for backport419250f
Fix potential ReDoS (#37)Updates
flat
from 4.1.0 to 5.0.2Commits
e5ffd66
Release 5.0.2fdb79d5
Update dependencies, refresh lockfile, format with standard.e52185d
Test against node 14 in CI.0189cb1
Avoid arrow function syntax.f25d3a1
Release 5.0.154cc7ad
use standard formatting779816e
drop dependencies2eea6d3
Bump lodash from 4.17.15 to 4.17.19a61a554
Bump acorn from 7.1.0 to 7.4.020ef0ef
Fix prototype pollution on unflattenMaintainer changes
This version was pushed to npm by timoxley, a new releaser for flat since your current version.
Updates
mocha
from 8.0.1 to 8.4.0Release notes
Sourced from mocha's releases.
... (truncated)
Changelog
Sourced from mocha's changelog.
... (truncated)
Commits
5064c28
Release v8.4.09cbcc8b
update CHANGELOG for v8.4.0 [ci skip]0079ae7
Change CLI file parsing errors to use an error code (#4502)d35eb9d
docs: add "options.require" to Mocha constructor (#4630) [ci skip]908aa05
GH actions: add Node v16 (#4629)8285910
Watch for test files are crashed (#4614)34643e4
Run browser tests on forked PRs by a dedicated label (#4616)8a2da76
docs: dynamic tests with top-level await (#4617) [ci skip]d7ed5c2
Remove unused test.retries(n) (#4611)a41f18a
GH actions: stale workflow (#4613) [ci skip]Updates
node-fetch
from 2.6.0 to 2.7.0Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
9b9d458
feat:AbortError
(#1744)65ae25a
fix: Remove the default connection close header (#1765)8bc3a7c
fix: socket variable testing for undefined (#1726)afb36f6
Revert "fix: handle bom in text and json (#1739)" (#1741)29909d7
fix: handle bom in text and json (#1739)70f592d
fix: "global is not defined" (#1704)0f1ebb0
Prevent error when response is null (#1699)6e9464d
ci(release): install dependenciesdd2a0ba
ci(release): install dependencies49bef02
ci(release): use latest Node LTSMaintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
serialize-javascript
from 3.0.0 to 5.0.1Release notes
Sourced from serialize-javascript's releases.
... (truncated)
Commits
8eb19aa
v5.0.1d17bcb2
Exclude .vscode and .github directories from package (#97)282a3b8
v5.0.013feb10
Bump mocha from 8.1.2 to 8.1.3 (#96)96431aa
Support sparse arrays (#95)d4bed9c
Bump mocha from 8.1.1 to 8.1.2 (#94)704a483
Bump mocha from 8.1.0 to 8.1.1 (#92)776a081
Create Dependabot config file (#91)ccff78b
Bump mocha from 8.0.1 to 8.1.0 (#90)89eded4
Bump lodash from 4.17.15 to 4.17.19 (#89)Updates
y18n
from 4.0.0 to 5.0.8Release notes
Sourced from y18n's releases.
Changelog
Sourced from y18n's changelog.
... (truncated)
Commits
58a9a3c
chore: release 5.0.8 (#129)b1c215a
fix(deno): force modern release for Denoe73fb19
chore: release 5.0.7 (#123)d3f2560
fix(deno): force release for deno (#121)e9fda61
chore: release 5.0.6 (#118)6966fa9
fix(webpack): skip readFileSync if not defined (#117)c755582
docs: add entry for v4.0.1 (#114)2d4c56c
chore(deps): update dependency standardx to v6 (#110)b64ae70
chore: release 5.0.5 (#109)a9ac604
fix: address prototype pollution issue (#108)Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for y18n since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.