deps(nodegoat): bump the npm-minor-patch group in /NodeGoat with 18 updates#8
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps the npm-minor-patch group in /NodeGoat with 18 updates: | Package | From | To | | --- | --- | --- | | [body-parser](https://github.com/expressjs/body-parser) | `1.18.3` | `1.20.4` | | [csurf](https://github.com/expressjs/csurf) | `1.9.0` | `1.11.0` | | [dont-sniff-mimetype](https://github.com/helmetjs/dont-sniff-mimetype) | `1.0.0` | `1.1.0` | | [express](https://github.com/expressjs/express) | `4.16.4` | `4.22.1` | | [express-session](https://github.com/expressjs/session) | `1.15.6` | `1.18.2` | | [marked](https://github.com/markedjs/marked) | `0.3.5` | `0.8.2` | | [needle](https://github.com/tomas/needle) | `2.2.4` | `2.9.1` | | [serve-favicon](https://github.com/expressjs/serve-favicon) | `2.5.0` | `2.5.1` | | [underscore](https://github.com/jashkenas/underscore) | `1.9.1` | `1.13.7` | | [async](https://github.com/caolan/async) | `2.6.1` | `2.6.4` | | [cross-env](https://github.com/kentcdodds/cross-env) | `7.0.2` | `7.0.3` | | [cypress](https://github.com/cypress-io/cypress) | `3.3.1` | `3.8.3` | | [grunt](https://github.com/gruntjs/grunt) | `1.0.3` | `1.6.1` | | [grunt-cli](https://github.com/gruntjs/grunt-cli) | `1.3.2` | `1.4.3` | | [grunt-mocha-test](https://github.com/pghalliday/grunt-mocha-test) | `0.12.7` | `0.13.3` | | [jshint](https://github.com/jshint/jshint) | `2.12.0` | `2.13.6` | | [nodemon](https://github.com/remy/nodemon) | `1.19.1` | `1.19.4` | | [zaproxy](https://github.com/zaproxy/zap-api-nodejs) | `0.2.0` | `0.3.0` | Updates `body-parser` from 1.18.3 to 1.20.4 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.18.3...1.20.4) Updates `csurf` from 1.9.0 to 1.11.0 - [Release notes](https://github.com/expressjs/csurf/releases) - [Changelog](https://github.com/expressjs/csurf/blob/master/HISTORY.md) - [Commits](expressjs/csurf@1.9.0...1.11.0) Updates `dont-sniff-mimetype` from 1.0.0 to 1.1.0 - [Changelog](https://github.com/helmetjs/dont-sniff-mimetype/blob/v1.1.0/CHANGELOG.md) - [Commits](helmetjs/dont-sniff-mimetype@v1.0.0...v1.1.0) Updates `express` from 4.16.4 to 4.22.1 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md) - [Commits](expressjs/express@4.16.4...v4.22.1) Updates `express-session` from 1.15.6 to 1.18.2 - [Release notes](https://github.com/expressjs/session/releases) - [Changelog](https://github.com/expressjs/session/blob/master/HISTORY.md) - [Commits](expressjs/session@v1.15.6...v1.18.2) Updates `marked` from 0.3.5 to 0.8.2 - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@v0.3.5...v0.8.2) Updates `needle` from 2.2.4 to 2.9.1 - [Release notes](https://github.com/tomas/needle/releases) - [Commits](https://github.com/tomas/needle/commits) Updates `serve-favicon` from 2.5.0 to 2.5.1 - [Release notes](https://github.com/expressjs/serve-favicon/releases) - [Changelog](https://github.com/expressjs/serve-favicon/blob/master/HISTORY.md) - [Commits](expressjs/serve-favicon@2.5.0...2.5.1) Updates `underscore` from 1.9.1 to 1.13.7 - [Commits](jashkenas/underscore@1.9.1...1.13.7) Updates `async` from 2.6.1 to 2.6.4 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md) - [Commits](caolan/async@v2.6.1...v2.6.4) Updates `cross-env` from 7.0.2 to 7.0.3 - [Release notes](https://github.com/kentcdodds/cross-env/releases) - [Changelog](https://github.com/kentcdodds/cross-env/blob/main/CHANGELOG.md) - [Commits](kentcdodds/cross-env@v7.0.2...v7.0.3) Updates `cypress` from 3.3.1 to 3.8.3 - [Release notes](https://github.com/cypress-io/cypress/releases) - [Changelog](https://github.com/cypress-io/cypress/blob/develop/CHANGELOG.md) - [Commits](https://github.com/cypress-io/cypress/compare/@cypress/vite-dev-server-v3.3.1...v3.8.3) Updates `grunt` from 1.0.3 to 1.6.1 - [Release notes](https://github.com/gruntjs/grunt/releases) - [Changelog](https://github.com/gruntjs/grunt/blob/main/CHANGELOG) - [Commits](gruntjs/grunt@v1.0.3...v1.6.1) Updates `grunt-cli` from 1.3.2 to 1.4.3 - [Release notes](https://github.com/gruntjs/grunt-cli/releases) - [Changelog](https://github.com/gruntjs/grunt-cli/blob/main/CHANGELOG.md) - [Commits](gruntjs/grunt-cli@v1.3.2...v1.4.3) Updates `grunt-mocha-test` from 0.12.7 to 0.13.3 - [Commits](pghalliday/grunt-mocha-test@0.12.7...0.13.3) Updates `jshint` from 2.12.0 to 2.13.6 - [Release notes](https://github.com/jshint/jshint/releases) - [Changelog](https://github.com/jshint/jshint/blob/main/CHANGELOG.md) - [Commits](jshint/jshint@2.12.0...2.13.6) Updates `nodemon` from 1.19.1 to 1.19.4 - [Release notes](https://github.com/remy/nodemon/releases) - [Commits](remy/nodemon@v1.19.1...v1.19.4) Updates `zaproxy` from 0.2.0 to 0.3.0 - [Changelog](https://github.com/zaproxy/zap-api-nodejs/blob/main/CHANGELOG.md) - [Commits](https://github.com/zaproxy/zap-api-nodejs/commits) --- updated-dependencies: - dependency-name: body-parser dependency-version: 1.20.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: csurf dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: dont-sniff-mimetype dependency-version: 1.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: express dependency-version: 4.22.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: express-session dependency-version: 1.18.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: marked dependency-version: 0.8.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: needle dependency-version: 2.9.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: serve-favicon dependency-version: 2.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: underscore dependency-version: 1.13.7 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: async dependency-version: 2.6.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: cross-env dependency-version: 7.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: cypress dependency-version: 3.8.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: grunt dependency-version: 1.6.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: grunt-cli dependency-version: 1.4.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: grunt-mocha-test dependency-version: 0.13.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: jshint dependency-version: 2.13.6 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: nodemon dependency-version: 1.19.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: zaproxy dependency-version: 0.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Author
|
Looks like these dependencies are no longer a dependency, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-minor-patch group in /NodeGoat with 18 updates:
1.18.31.20.41.9.01.11.01.0.01.1.04.16.44.22.11.15.61.18.20.3.50.8.22.2.42.9.12.5.02.5.11.9.11.13.72.6.12.6.47.0.27.0.33.3.13.8.31.0.31.6.11.3.21.4.30.12.70.13.32.12.02.13.61.19.11.19.40.2.00.3.0Updates
body-parserfrom 1.18.3 to 1.20.4Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
7db202c1.20.4 (#672)d8f8adbci: add CodeQL (SAST) (#670)6d133c1chore: remove SECURITY.md (#669)fcd1535deps: use tilde notation and update certain dependencies (#668)ec5fa29deps: qs@~6.14.0 (#664)ffb95c1ci: restore CI for 1.x branch (#665)48a5f07ci: add support for Node.js v23 (#553)f20f6adRemove redundant depth check (#538)17529511.20.339744cfchore: linter (#534)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
csurffrom 1.9.0 to 1.11.0Release notes
Sourced from csurf's releases.
Changelog
Sourced from csurf's changelog.
Commits
daaeb5d1.11.062429d0build: mocha@7.0.0daab742build: eslint-plugin-import@2.20.09660c1ebuild: cookie-session@1.4.0a18eef0build: Node.js@13.62745086deps: cookie@0.4.0445eda6docs: add reference links in readme for patterns05307debuild: nyc@15.0.0f35b20ebuild: eslint-plugin-node@11.0.02601bf3build: Node.js@13.5Updates
dont-sniff-mimetypefrom 1.0.0 to 1.1.0Changelog
Sourced from dont-sniff-mimetype's changelog.
Commits
8f848461.1.0a85ea88Update changelog for 1.1.0 release8c98fb5Add a changelog1e0a2cbAdd /dist/ to gitignore045a827Convert module to TypeScript10a1198Travis should test on Node 1074d3598Update some package metadatadf8c47bUpdate license year for 20194163e0cAdd note about CORBd9d45f6Travis shouldn't test on EOL'd Node 4Updates
expressfrom 4.16.4 to 4.22.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
12fae144.22.15ddf311Revert "sec: security patch for CVE-2024-51999"49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)Maintainer changes
This version was pushed to npm by jonchurch, a new releaser for express since your current version.
Updates
express-sessionfrom 1.15.6 to 1.18.2Release notes
Sourced from express-session's releases.
... (truncated)
Changelog
Sourced from express-session's changelog.
... (truncated)
Commits
d10709f🔖 v1.18.2 (#1070)5808783deps: on-headers@1.1.0 (#1069)b9fcad8chore: fix typos (#1066)a698c81build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 (#1051)ec1957bbuild(deps): bump actions/upload-artifact from 4.5.0 to 4.6.2 (#1052)2caff6abuild(deps): bump actions/checkout from 4.1.1 to 4.2.2 (#1049)2633e88build(deps): bump github/codeql-action from 3.24.7 to 3.28.18 (#1050)7e2c696build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 (#1048)92dd300build(deps-dev): bump mocha from 10.2.0 to 10.8.2 (#1061)168271cfix(dependabot): do not update major versionsMaintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for express-session since your current version.
Updates
markedfrom 0.3.5 to 0.8.2Commits
4af69d3Merge pull request #1624 from UziTech/release-0.8.219f0d4f0.8.238403c0buildd7b05cbupdate devdeps17ee15fbuild [skip ci]58e9fedMerge pull request #1622 from UziTech/render-html193a41esimplify tag regex7330a9cadd html test to heading idsf01ba94add html to TextRenderercf3d0a0Merge pull request #1620 from julien-c/patch-1Maintainer changes
This version was pushed to npm by tonybrix, a new releaser for marked since your current version.
Updates
needlefrom 2.2.4 to 2.9.1Release notes
Sourced from needle's releases.
... (truncated)
Commits
Updates
serve-faviconfrom 2.5.0 to 2.5.1Release notes
Sourced from serve-favicon's releases.
Changelog
Sourced from serve-favicon's changelog.
Commits
83da8d52.5.1 (#68)c03a88bfeat: adopt flexible deps policy (#69)262b7bfdocs: include scorecard badge (#67)47663aefeat: remove appveyor (#66)d83f56cbuild(deps-dev): bump eslint-plugin-promise from 3.7.0 to 3.8.0 (#61)872a751build(deps-dev): bump eslint-plugin-import from 2.10.0 to 2.31.0 (#62)19e8af3build(deps-dev): bump mocha from 10.4.0 to 10.8.2 (#60)d976602ci: upgrade Node versions (#64)623e26ebuild(deps-dev): bump eslint-plugin-markdown from 1.0.0-beta.6 to 1.0.2 (#63)14fae4fbuild(deps-dev): bump eslint-plugin-standard from 3.0.1 to 3.1.0 (#59)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for serve-favicon since your current version.
Updates
underscorefrom 1.9.1 to 1.13.7Commits
d2e7e61Update autogenerated files for 1.13.7b1d4f23Add a change log entry for 1.13.7473970aBump the copyright yearsa1cbb48Bump the version to 1.13.71205eb5Merge pull request #2996 from elkcityhazard/feature/theme-togglebd3468beven more css formattingdd23fd0formatting, filter, darker darkmode184aae5unncessary prefers-color-scheme: light removal55720c0minimal dark mode implementationde20b6fincorporated stylesheet that was already availableMaintainer changes
This version was pushed to npm by jgonggrijp, a new releaser for underscore since your current version.
Updates
asyncfrom 2.6.1 to 2.6.4Changelog
Sourced from async's changelog.
Commits
c6bdacaVersion 2.6.48870da9Update built files4df6754update changelog8f7f903Fix prototype pollution vulnerability (#1828)f1d8383Version 2.6.32b674c1update changelogeab740ffix: udpate lodash. closes #1675eaf32beVersion 2.6.2684b42eUpdate built filese1bd3daupdate changelogMaintainer changesDescription has been truncated