Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

12 patch security update #19

Open
wants to merge 30 commits into
base: master
Choose a base branch
from
Open

Commits on Oct 25, 2022

  1. Bump copy-props from 2.0.4 to 2.0.5

    Bumps [copy-props](https://github.com/gulpjs/copy-prop) from 2.0.4 to 2.0.5.
    - [Release notes](https://github.com/gulpjs/copy-prop/releases)
    - [Commits](https://github.com/gulpjs/copy-prop/commits)
    
    ---
    updated-dependencies:
    - dependency-name: copy-props
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    b78fe40 View commit details
    Browse the repository at this point in the history
  2. Bump path-parse from 1.0.6 to 1.0.7

    Bumps [path-parse](https://github.com/jbgutierrez/path-parse) from 1.0.6 to 1.0.7.
    - [Release notes](https://github.com/jbgutierrez/path-parse/releases)
    - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7)
    
    ---
    updated-dependencies:
    - dependency-name: path-parse
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    fce538f View commit details
    Browse the repository at this point in the history
  3. Bump y18n from 3.2.1 to 3.2.2

    Bumps [y18n](https://github.com/yargs/y18n) from 3.2.1 to 3.2.2.
    - [Release notes](https://github.com/yargs/y18n/releases)
    - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md)
    - [Commits](https://github.com/yargs/y18n/commits)
    
    ---
    updated-dependencies:
    - dependency-name: y18n
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    6905c48 View commit details
    Browse the repository at this point in the history
  4. Bump hosted-git-info from 2.7.1 to 2.8.9

    Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.7.1 to 2.8.9.
    - [Release notes](https://github.com/npm/hosted-git-info/releases)
    - [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md)
    - [Commits](npm/hosted-git-info@v2.7.1...v2.8.9)
    
    ---
    updated-dependencies:
    - dependency-name: hosted-git-info
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    ceddb6c View commit details
    Browse the repository at this point in the history
  5. Bump yargs-parser from 5.0.0 to 5.0.1

    Bumps [yargs-parser](https://github.com/yargs/yargs-parser) from 5.0.0 to 5.0.1.
    - [Release notes](https://github.com/yargs/yargs-parser/releases)
    - [Changelog](https://github.com/yargs/yargs-parser/blob/v5.0.1/CHANGELOG.md)
    - [Commits](yargs/yargs-parser@v5.0.0...v5.0.1)
    
    ---
    updated-dependencies:
    - dependency-name: yargs-parser
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    979cea5 View commit details
    Browse the repository at this point in the history
  6. Bump ini from 1.3.5 to 1.3.8

    Bumps [ini](https://github.com/npm/ini) from 1.3.5 to 1.3.8.
    - [Release notes](https://github.com/npm/ini/releases)
    - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md)
    - [Commits](npm/ini@v1.3.5...v1.3.8)
    
    ---
    updated-dependencies:
    - dependency-name: ini
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    a07540e View commit details
    Browse the repository at this point in the history
  7. Merge pull request #6 from ValentinGratz/dependabot/npm_and_yarn/ini-…

    …1.3.8
    
    Bump ini from 1.3.5 to 1.3.8
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    4bfe22d View commit details
    Browse the repository at this point in the history
  8. Merge pull request #5 from ValentinGratz/dependabot/npm_and_yarn/yarg…

    …s-parser-5.0.1
    
    Bump yargs-parser from 5.0.0 to 5.0.1
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    fa2f11b View commit details
    Browse the repository at this point in the history
  9. Merge pull request #4 from ValentinGratz/dependabot/npm_and_yarn/host…

    …ed-git-info-2.8.9
    
    Bump hosted-git-info from 2.7.1 to 2.8.9
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    df8c1b6 View commit details
    Browse the repository at this point in the history
  10. Merge pull request #3 from ValentinGratz/dependabot/npm_and_yarn/y18n…

    …-3.2.2
    
    Bump y18n from 3.2.1 to 3.2.2
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    03f489e View commit details
    Browse the repository at this point in the history
  11. Merge pull request #2 from ValentinGratz/dependabot/npm_and_yarn/path…

    …-parse-1.0.7
    
    Bump path-parse from 1.0.6 to 1.0.7
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    0181f7a View commit details
    Browse the repository at this point in the history
  12. Merge pull request #1 from ValentinGratz/dependabot/npm_and_yarn/copy…

    …-props-2.0.5
    
    Bump copy-props from 2.0.4 to 2.0.5
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    eb173b3 View commit details
    Browse the repository at this point in the history
  13. Configuration menu
    Copy the full SHA
    72067d8 View commit details
    Browse the repository at this point in the history
  14. Configuration menu
    Copy the full SHA
    37e8a16 View commit details
    Browse the repository at this point in the history
  15. Bump ini from 1.3.5 to 1.3.8

    Bumps [ini](https://github.com/npm/ini) from 1.3.5 to 1.3.8.
    - [Release notes](https://github.com/npm/ini/releases)
    - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md)
    - [Commits](npm/ini@v1.3.5...v1.3.8)
    
    ---
    updated-dependencies:
    - dependency-name: ini
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    1e17154 View commit details
    Browse the repository at this point in the history
  16. Merge pull request #7 from ValentinGratz/dependabot/npm_and_yarn/ini-…

    …1.3.8
    
    Bump ini from 1.3.5 to 1.3.8
    ValentinGratz authored Oct 25, 2022
    Configuration menu
    Copy the full SHA
    91a03cc View commit details
    Browse the repository at this point in the history

Commits on Nov 13, 2022

  1. Bump minimatch from 3.0.4 to 3.1.2

    Bumps [minimatch](https://github.com/isaacs/minimatch) from 3.0.4 to 3.1.2.
    - [Release notes](https://github.com/isaacs/minimatch/releases)
    - [Commits](isaacs/minimatch@v3.0.4...v3.1.2)
    
    ---
    updated-dependencies:
    - dependency-name: minimatch
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Nov 13, 2022
    Configuration menu
    Copy the full SHA
    501b048 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #8 from ValentinGratz/dependabot/npm_and_yarn/mini…

    …match-3.1.2
    
    Bump minimatch from 3.0.4 to 3.1.2
    ValentinGratz authored Nov 13, 2022
    Configuration menu
    Copy the full SHA
    5e6a984 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    b9fec31 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    e96f116 View commit details
    Browse the repository at this point in the history
  5. tar

    ValentinGratz authored Nov 13, 2022
    Configuration menu
    Copy the full SHA
    e18983d View commit details
    Browse the repository at this point in the history

Commits on Nov 25, 2022

  1. update

    ValentinGratz authored Nov 25, 2022
    Configuration menu
    Copy the full SHA
    31feb2d View commit details
    Browse the repository at this point in the history

Commits on Dec 9, 2022

  1. Bump decode-uri-component from 0.2.0 to 0.2.2

    Bumps [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) from 0.2.0 to 0.2.2.
    - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases)
    - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2)
    
    ---
    updated-dependencies:
    - dependency-name: decode-uri-component
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Dec 9, 2022
    Configuration menu
    Copy the full SHA
    69c211a View commit details
    Browse the repository at this point in the history

Commits on Dec 11, 2022

  1. Merge pull request #9 from ValentinGratz/dependabot/npm_and_yarn/deco…

    …de-uri-component-0.2.2
    
    Bump decode-uri-component from 0.2.0 to 0.2.2
    ValentinGratz authored Dec 11, 2022
    Configuration menu
    Copy the full SHA
    e681b28 View commit details
    Browse the repository at this point in the history
  2. Bump qs from 6.5.2 to 6.11.0

    Bumps [qs](https://github.com/ljharb/qs) from 6.5.2 to 6.11.0.
    - [Release notes](https://github.com/ljharb/qs/releases)
    - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
    - [Commits](ljharb/qs@v6.5.2...v6.11.0)
    
    ---
    updated-dependencies:
    - dependency-name: qs
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Dec 11, 2022
    Configuration menu
    Copy the full SHA
    cfc32c4 View commit details
    Browse the repository at this point in the history
  3. Merge pull request #10 from ValentinGratz/dependabot/npm_and_yarn/qs-…

    …6.11.0
    
    Bump qs from 6.5.2 to 6.11.0
    ValentinGratz authored Dec 11, 2022
    Configuration menu
    Copy the full SHA
    d6a6c52 View commit details
    Browse the repository at this point in the history

Commits on Apr 8, 2023

  1. Configuration menu
    Copy the full SHA
    cfcdb0a View commit details
    Browse the repository at this point in the history
  2. Add files via upload

    ValentinGratz authored Apr 8, 2023
    Configuration menu
    Copy the full SHA
    ea5bb60 View commit details
    Browse the repository at this point in the history

Commits on Jun 14, 2024

  1. Bump braces and gulp

    Bumps [braces](https://github.com/micromatch/braces) to 3.0.3 and updates ancestor dependency [gulp](https://github.com/gulpjs/gulp). These dependencies need to be updated together.
    
    
    Updates `braces` from 3.0.2 to 3.0.3
    - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
    - [Commits](micromatch/braces@3.0.2...3.0.3)
    
    Updates `gulp` from 4.0.2 to 5.0.0
    - [Release notes](https://github.com/gulpjs/gulp/releases)
    - [Changelog](https://github.com/gulpjs/gulp/blob/master/CHANGELOG.md)
    - [Commits](gulpjs/gulp@v4.0.2...v5.0.0)
    
    ---
    updated-dependencies:
    - dependency-name: braces
      dependency-type: indirect
    - dependency-name: gulp
      dependency-type: direct:development
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Jun 14, 2024
    Configuration menu
    Copy the full SHA
    cea0799 View commit details
    Browse the repository at this point in the history

Commits on Jul 6, 2024

  1. Merge pull request #11 from ValentinGratz/dependabot/npm_and_yarn/mul…

    …ti-a9f852c250
    
    Bump braces and gulp
    ValentinGratz authored Jul 6, 2024
    Configuration menu
    Copy the full SHA
    7756917 View commit details
    Browse the repository at this point in the history