Commit 66ca51d
authored
Bump the npm_and_yarn group across 3 directories with 27 updates
Bumps the npm_and_yarn group with 1 update in the /lesson-03/demo-01-oauth-tests directory: [minimatch](https://github.com/isaacs/minimatch).
Bumps the npm_and_yarn group with 16 updates in the /vulnerable_repos/NodeGoat directory:
| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.12` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `3.5.5` | `3.14.2` |
| [grunt](https://github.com/gruntjs/grunt) | `1.0.3` | `1.6.1` |
| [body-parser](https://github.com/expressjs/body-parser) | `1.18.3` | `1.20.4` |
| [express](https://github.com/expressjs/express) | `4.16.4` | `4.22.1` |
| [marked](https://github.com/markedjs/marked) | `0.3.5` | `4.0.10` |
| [async](https://github.com/caolan/async) | `2.6.1` | `2.6.4` |
| [bson](https://github.com/mongodb/js-bson) | `1.0.9` | `7.2.0` |
| [tmp](https://github.com/raszi/node-tmp) | `0.0.24` | `0.2.5` |
| [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` |
| [got](https://github.com/sindresorhus/got) | `6.7.1` | `removed` |
| [i](https://github.com/pksunkara/inflect) | `0.3.6` | `0.3.7` |
| [json-schema](https://github.com/kriszyp/json-schema) | `0.2.3` | `0.4.0` |
| [jsonpointer](https://github.com/janl/node-jsonpointer) | `4.0.0` | `5.0.1` |
| [on-headers](https://github.com/jshttp/on-headers) | `1.0.1` | `1.1.0` |
| [set-value](https://github.com/jonschlinkert/set-value) | `2.0.0` | `2.0.1` |
Bumps the npm_and_yarn group with 4 updates in the /vulnerable_repos/juice-shop directory: [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken), [multer](https://github.com/expressjs/multer), [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) and [socket.io](https://github.com/socketio/socket.io).
Updates `minimatch` from 3.1.2 to 3.1.5
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.1.2...v3.1.5)
Updates `minimatch` from 9.0.5 to 9.0.9
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.1.2...v3.1.5)
Updates `brace-expansion` from 1.1.11 to 1.1.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.12)
Updates `js-yaml` from 3.5.5 to 3.14.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.5.5...3.14.2)
Updates `grunt` from 1.0.3 to 1.6.1
- [Release notes](https://github.com/gruntjs/grunt/releases)
- [Changelog](https://github.com/gruntjs/grunt/blob/main/CHANGELOG)
- [Commits](gruntjs/grunt@v1.0.3...v1.6.1)
Updates `minimatch` from 0.3.0 to 3.0.2
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.1.2...v3.1.5)
Updates `body-parser` from 1.18.3 to 1.20.4
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.18.3...1.20.4)
Updates `express` from 4.16.4 to 4.22.1
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md)
- [Commits](expressjs/express@4.16.4...v4.22.1)
Updates `express` from 4.16.4 to 4.22.1
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md)
- [Commits](expressjs/express@4.16.4...v4.22.1)
Updates `lodash` from 4.17.11 to 4.17.23
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.11...4.17.23)
Updates `marked` from 0.3.5 to 4.0.10
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v0.3.5...v4.0.10)
Updates `async` from 2.6.1 to 2.6.4
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.1...v2.6.4)
Updates `grunt` from 1.0.3 to 1.6.1
- [Release notes](https://github.com/gruntjs/grunt/releases)
- [Changelog](https://github.com/gruntjs/grunt/blob/main/CHANGELOG)
- [Commits](gruntjs/grunt@v1.0.3...v1.6.1)
Updates `bson` from 1.0.9 to 7.2.0
- [Release notes](https://github.com/mongodb/js-bson/releases)
- [Changelog](https://github.com/mongodb/js-bson/blob/main/HISTORY.md)
- [Commits](mongodb/js-bson@v1.0.9...v7.2.0)
Updates `tmp` from 0.0.24 to 0.2.5
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](raszi/node-tmp@v0.0.24...v0.2.5)
Updates `decode-uri-component` from 0.2.0 to 0.2.2
- [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases)
- [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2)
Updates `getobject` from 0.1.0 to 1.0.2
- [Release notes](https://github.com/cowboy/node-getobject/releases)
- [Commits](cowboy/node-getobject@v0.1.0...v1.0.2)
Removes `got`
Updates `i` from 0.3.6 to 0.3.7
- [Commits](pksunkara/inflect@v0.3.6...v0.3.7)
Updates `json-schema` from 0.2.3 to 0.4.0
- [Commits](kriszyp/json-schema@v0.2.3...v0.4.0)
Updates `jsonpointer` from 4.0.0 to 5.0.1
- [Release notes](https://github.com/janl/node-jsonpointer/releases)
- [Commits](janl/node-jsonpointer@4.0.0...v5.0.1)
Updates `on-headers` from 1.0.1 to 1.1.0
- [Release notes](https://github.com/jshttp/on-headers/releases)
- [Changelog](https://github.com/jshttp/on-headers/blob/master/HISTORY.md)
- [Commits](jshttp/on-headers@v1.0.1...v1.1.0)
Updates `path-to-regexp` from 0.1.7 to 0.1.12
- [Release notes](https://github.com/pillarjs/path-to-regexp/releases)
- [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md)
- [Commits](pillarjs/path-to-regexp@v0.1.7...v0.1.12)
Updates `send` from 0.16.2 to 0.19.2
- [Release notes](https://github.com/pillarjs/send/releases)
- [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md)
- [Commits](pillarjs/send@0.16.2...0.19.2)
Updates `serve-static` from 1.13.2 to 1.16.3
- [Release notes](https://github.com/expressjs/serve-static/releases)
- [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md)
- [Commits](expressjs/serve-static@v1.13.2...v1.16.3)
Updates `set-value` from 2.0.0 to 2.0.1
- [Commits](jonschlinkert/set-value@2.0.0...2.0.1)
Updates `undefsafe` from 2.0.2 to 2.0.5
- [Release notes](https://github.com/remy/undefsafe/releases)
- [Commits](remy/undefsafe@v2.0.2...v2.0.5)
Updates `jsonwebtoken` from 0.4.0 to 9.0.0
- [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](https://github.com/auth0/node-jsonwebtoken/commits/v9.0.0)
Updates `multer` from 1.4.5-lts.2 to 2.1.0
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v1.4.5-lts.2...v2.1.0)
Updates `sanitize-html` from 1.4.2 to 2.12.1
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/HEAD/packages/sanitize-html)
Updates `socket.io` from 3.1.2 to 4.8.3
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/3.1.2...socket.io@4.8.3)
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 3.1.5
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: brace-expansion
dependency-version: 1.1.12
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: js-yaml
dependency-version: 3.14.2
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: grunt
dependency-version: 1.6.1
dependency-type: direct:development
dependency-group: npm_and_yarn
- dependency-name: minimatch
dependency-version: 3.0.2
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: body-parser
dependency-version: 1.20.4
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: express
dependency-version: 4.22.1
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: express
dependency-version: 4.22.1
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: lodash
dependency-version: 4.17.23
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: marked
dependency-version: 4.0.10
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: async
dependency-version: 2.6.4
dependency-type: direct:development
dependency-group: npm_and_yarn
- dependency-name: grunt
dependency-version: 1.6.1
dependency-type: direct:development
dependency-group: npm_and_yarn
- dependency-name: bson
dependency-version: 7.2.0
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: tmp
dependency-version: 0.2.5
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: decode-uri-component
dependency-version: 0.2.2
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: getobject
dependency-version: 1.0.2
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: got
dependency-version:
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: i
dependency-version: 0.3.7
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: json-schema
dependency-version: 0.4.0
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: jsonpointer
dependency-version: 5.0.1
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: on-headers
dependency-version: 1.1.0
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: path-to-regexp
dependency-version: 0.1.12
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: send
dependency-version: 0.19.2
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: serve-static
dependency-version: 1.16.3
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: set-value
dependency-version: 2.0.1
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: undefsafe
dependency-version: 2.0.5
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: jsonwebtoken
dependency-version: 9.0.0
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: multer
dependency-version: 2.1.0
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: sanitize-html
dependency-version: 2.12.1
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: socket.io
dependency-version: 4.8.3
dependency-type: direct:production
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>1 parent ee3fe08 commit 66ca51d
4 files changed
Lines changed: 6495 additions & 5336 deletions
File tree
- lesson-03/demo-01-oauth-tests
- vulnerable_repos
- NodeGoat
- juice-shop
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments