build(deps): [security] bump node-fetch from 2.3.0 to 2.6.1#374
Open
dependabot-preview[bot] wants to merge 1 commit into
Open
build(deps): [security] bump node-fetch from 2.3.0 to 2.6.1#374dependabot-preview[bot] wants to merge 1 commit into
dependabot-preview[bot] wants to merge 1 commit into
Conversation
70d7f04 to
e103857
Compare
3679d99 to
35acd37
Compare
18fae57 to
0b73a74
Compare
82f3b2b to
50c2784
Compare
586f4e3 to
efbdffb
Compare
ddeeb1e to
ebd10bd
Compare
a0cd880 to
7198ccd
Compare
7198ccd to
c3f5cb4
Compare
a518dfb to
729f121
Compare
2e46ca8 to
bad79e2
Compare
bad79e2 to
cdcb952
Compare
24e24ee to
d7be876
Compare
8dfce18 to
024a277
Compare
68d55e0 to
7a9db80
Compare
29d59e8 to
1f084e6
Compare
a8fe08f to
c0ba5cf
Compare
9c1307c to
3359959
Compare
3359959 to
e51c5b6
Compare
10e78a4 to
05d74d9
Compare
fad629e to
6e8f98b
Compare
6e8f98b to
458ae06
Compare
458ae06 to
4805bd7
Compare
Bumps [node-fetch](https://github.com/bitinn/node-fetch) from 2.3.0 to 2.6.1. **This update includes a security fix.** - [Release notes](https://github.com/bitinn/node-fetch/releases) - [Changelog](https://github.com/node-fetch/node-fetch/blob/master/docs/CHANGELOG.md) - [Commits](node-fetch/node-fetch@v2.3.0...v2.6.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
4805bd7 to
83b1f61
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps node-fetch from 2.3.0 to 2.6.1. This update includes a security fix.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Release notes
Sourced from node-fetch's releases.
Changelog
Sourced from node-fetch's changelog.
Commits
b5e2e41update version number2358a6cHonor thesizeoption after following a redirect and revert data uri support8c197f8docs: Fix typos and grammatical errors in README.md (#686)1e99050fix: Change error message thrown with redirect mode set to error (#653)244e6f6docs: Show backers in README6a5d192fix: Properly parse meta tag when parameters are reversed (#682)47a24a0chore: Add opencollective badge7b13662chore: Add funding link5535c2efix: Check for global.fetch before binding it (#674)1d5778adocs: Add Discord badgeMaintainer changes
This version was pushed to npm by akepinski, a new releaser for node-fetch since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard: