dependabot[bot]
9912c37272
Bump css-loader from 6.7.2 to 6.7.3 ( #2484 )
...
Bumps [css-loader](https://github.com/webpack-contrib/css-loader ) from 6.7.2 to 6.7.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/css-loader/releases ">css-loader's releases</a>.</em></p>
<blockquote>
<h2>v6.7.3</h2>
<h3><a href="https://github.com/webpack-contrib/css-loader/compare/v6.7.2...v6.7.3 ">6.7.3</a> (2022-12-14)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>remove <code>sourceURL</code> from emitted CSS (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1487 ">#1487</a>) (<a href="962924c79e
">962924c</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/css-loader/blob/master/CHANGELOG.md ">css-loader's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack-contrib/css-loader/compare/v6.7.2...v6.7.3 ">6.7.3</a> (2022-12-14)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>remove <code>sourceURL</code> from emitted CSS (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1487 ">#1487</a>) (<a href="962924c79e
">962924c</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="ef749f29f8
"><code>ef749f2</code></a> chore(release): 6.7.3</li>
<li><a href="36fb945ac9
"><code>36fb945</code></a> chore: fix cspell</li>
<li><a href="962924c79e
"><code>962924c</code></a> fix: remove <code>sourceURL</code> from emitted CSS (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1487 ">#1487</a>)</li>
<li><a href="3f3f302808
"><code>3f3f302</code></a> chore(deps): bump decode-uri-component from 0.2.0 to 0.2.2 (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1486 ">#1486</a>)</li>
<li><a href="04ca71342b
"><code>04ca713</code></a> chore: update dependencies to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1485 ">#1485</a>)</li>
<li><a href="9449827b3f
"><code>9449827</code></a> chore: update styfle/cancel-workflow-action (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1484 ">#1484</a>)</li>
<li><a href="6c67af8c06
"><code>6c67af8</code></a> chore: add cSpell to check spelling issues (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1482 ">#1482</a>)</li>
<li><a href="239b9ac450
"><code>239b9ac</code></a> chore(deps): bump loader-utils from 2.0.3 to 2.0.4 (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1481 ">#1481</a>)</li>
<li>See full diff in <a href="https://github.com/webpack-contrib/css-loader/compare/v6.7.2...v6.7.3 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=css-loader&package-manager=npm_and_yarn&previous-version=6.7.2&new-version=6.7.3 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
07f2d0dc2e
Bump prettier from 2.8.0 to 2.8.1 ( #2476 )
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.8.0 to 2.8.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/releases ">prettier's releases</a>.</em></p>
<blockquote>
<h2>2.8.1</h2>
<p>🔗 <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md#281 ">Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md ">prettier's changelog</a>.</em></p>
<blockquote>
<h1>2.8.1</h1>
<p><a href="https://github.com/prettier/prettier/compare/2.8.0...2.8.1 ">diff</a></p>
<h4>Fix SCSS map in arguments (<a href="https://github-redirect.dependabot.com/prettier/prettier/pull/9184 ">#9184</a> by <a href="https://github.com/agamkrbit "><code>@agamkrbit</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="scss"><code>// Input
$display-breakpoints: map-deep-merge(
(
"print-only": "only print",
"screen-only": "only screen",
"xs-only": "only screen and (max-width: #{map-get($grid-breakpoints, "sm")-1})",
),
$display-breakpoints
);
<p>// Prettier 2.8.0
$display-breakpoints: map-deep-merge(
(
"print-only": "only print",
"screen-only": "only screen",
"xs-only": "only screen and (max-width: #{map-get($grid-breakpoints, " sm
")-1})",
),
$display-breakpoints
);</p>
<p>// Prettier 2.8.1
$display-breakpoints: map-deep-merge(
(
"print-only": "only print",
"screen-only": "only screen",
"xs-only": "only screen and (max-width: #{map-get($grid-breakpoints, "sm")-1})",
),
$display-breakpoints
);
</code></pre></p>
<h4>Support auto accessors syntax (<a href="https://github-redirect.dependabot.com/prettier/prettier/pull/13919 ">#13919</a> by <a href="https://github.com/sosukesuzuki "><code>@sosukesuzuki</code></a>)</h4>
<p>Support for <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-4-9/#auto-accessors-in-classes ">Auto Accessors Syntax</a> landed in TypeScript 4.9.</p>
<p>(Doesn't work well with <code>babel-ts</code> parser)</p>
<!-- raw HTML omitted -->
<pre lang="tsx"><code>class Foo {
accessor foo: number = 3;
</tr></table>
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="cd1df1a184
"><code>cd1df1a</code></a> Release 2.8.1</li>
<li><a href="5541a63d76
"><code>5541a63</code></a> Remove version validation</li>
<li><a href="1cf760a184
"><code>1cf760a</code></a> Support decorator auto accessors syntax (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13919 ">#13919</a>)</li>
<li><a href="aa34209820
"><code>aa34209</code></a> test: format instantiation expr in logical expr (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13897 ">#13897</a>)</li>
<li><a href="957b4f20e8
"><code>957b4f2</code></a> Build(deps): Bump decode-uri-component from 0.2.0 to 0.2.2 in /website (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13933 ">#13933</a>)</li>
<li><a href="e4240aeaf0
"><code>e4240ae</code></a> Add tests for keyword class property (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13927 ">#13927</a>)</li>
<li><a href="655a161d0f
"><code>655a161</code></a> Add tests for multiple comments (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13890 ">#13890</a>)</li>
<li><a href="4a1e32a9de
"><code>4a1e32a</code></a> Fixed scss function arguments on different lines in maps <a href="https://github-redirect.dependabot.com/prettier/prettier/issues/9128 ">#9128</a> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/9184 ">#9184</a>)</li>
<li><a href="38806fe666
"><code>38806fe</code></a> Migrate from probot/no-response to lee-dohm/no-response (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13891 ">#13891</a>)</li>
<li><a href="a60bee2e2d
"><code>a60bee2</code></a> Add '--single-attribute-per-line' option to Playground (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13587 ">#13587</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/2.8.0...2.8.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=2.8.0&new-version=2.8.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
9dc150b6ab
Bump webpack-cli from 5.0.0 to 5.0.1 ( #2474 )
...
Bumps [webpack-cli](https://github.com/webpack/webpack-cli ) from 5.0.0 to 5.0.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-cli/releases ">webpack-cli's releases</a>.</em></p>
<blockquote>
<h2>v5.0.1</h2>
<h2><a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@5.0.0...webpack-cli@5.0.1 ">5.0.1</a> (2022-12-05)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>make <code>define-process-env-node-env</code> alias <code>node-env</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3514 ">#3514</a>) (<a href="346a518dd7
">346a518</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-cli/blob/master/CHANGELOG.md ">webpack-cli's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@5.0.0...webpack-cli@5.0.1 ">5.0.1</a> (2022-12-05)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>make <code>define-process-env-node-env</code> alias <code>node-env</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3514 ">#3514</a>) (<a href="346a518dd7
">346a518</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="4a0f89380b
"><code>4a0f893</code></a> chore(release): publish new version</li>
<li><a href="9de982c0ed
"><code>9de982c</code></a> chore: fix cspell</li>
<li><a href="32d26c87b7
"><code>32d26c8</code></a> chore(deps-dev): bump cspell from 6.15.1 to 6.16.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3517 ">#3517</a>)</li>
<li><a href="2788bf9445
"><code>2788bf9</code></a> chore(deps-dev): bump eslint from 8.28.0 to 8.29.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3516 ">#3516</a>)</li>
<li><a href="ac88ee4ab9
"><code>ac88ee4</code></a> chore(deps-dev): bump lint-staged from 13.0.4 to 13.1.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3515 ">#3515</a>)</li>
<li><a href="346a518dd7
"><code>346a518</code></a> fix: make define-process-env-node-env alias node-env (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3514 ">#3514</a>)</li>
<li><a href="3ec7b169e1
"><code>3ec7b16</code></a> chore(deps): bump yeoman-environment from 3.12.1 to 3.13.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3508 ">#3508</a>)</li>
<li><a href="c8adfa6f47
"><code>c8adfa6</code></a> chore(deps-dev): bump <code>@types/node</code> from 18.11.9 to 18.11.10 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3513 ">#3513</a>)</li>
<li><a href="0ad8cc299d
"><code>0ad8cc2</code></a> chore(deps-dev): bump cspell from 6.15.0 to 6.15.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3512 ">#3512</a>)</li>
<li><a href="d30f261716
"><code>d30f261</code></a> chore(deps-dev): bump ts-loader from 9.4.1 to 9.4.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3511 ">#3511</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@5.0.0...webpack-cli@5.0.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-cli&package-manager=npm_and_yarn&previous-version=5.0.0&new-version=5.0.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
de737dc44e
Bump prettier from 2.7.1 to 2.8.0 ( #2459 )
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.7.1 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/releases ">prettier's releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<p><a href="https://github.com/prettier/prettier/compare/2.7.1...2.8.0 ">diff</a></p>
<p>🔗 <a href="https://prettier.io/blog/2022/11/23/2.8.0.html ">Release note</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md ">prettier's changelog</a>.</em></p>
<blockquote>
<h1>2.8.0</h1>
<p><a href="https://github.com/prettier/prettier/compare/2.7.1...2.8.0 ">diff</a></p>
<p>🔗 <a href="https://prettier.io/blog/2022/11/23/2.8.0.html ">Release Notes</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="dcc0623911
"><code>dcc0623</code></a> Release 2.8.0</li>
<li><a href="7f7498109b
"><code>7f74981</code></a> Remove version validattion temp</li>
<li><a href="876c297589
"><code>876c297</code></a> Update changelog for <code>satisfies</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13879 ">#13879</a>)</li>
<li><a href="fd376000e9
"><code>fd37600</code></a> Update <code>@typescript-eslint/typescript-estree</code> to support <code>satisfies</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13872 ">#13872</a>)</li>
<li><a href="fac87619a4
"><code>fac8761</code></a> Build(deps): Bump minimatch from 3.0.4 to 3.1.2 in /scripts/release (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13854 ">#13854</a>)</li>
<li><a href="68ea881498
"><code>68ea881</code></a> Update typescript to v4.9 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13852 ">#13852</a>)</li>
<li><a href="5e0b88329e
"><code>5e0b883</code></a> Fix generate truncate comment (backport <a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13437 ">#13437</a>) (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13814 ">#13814</a>)</li>
<li><a href="a980caa7db
"><code>a980caa</code></a> Add missing changelog for <a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13016 ">#13016</a> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13812 ">#13812</a>)</li>
<li><a href="520dbcd36e
"><code>520dbcd</code></a> Add changelog for <a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13783 ">#13783</a> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13811 ">#13811</a>)</li>
<li><a href="ae4d85ab3c
"><code>ae4d85a</code></a> Update description of <code>vueIndentScriptAndStyle</code> option (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13781 ">#13781</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/2.7.1...2.8.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=2.7.1&new-version=2.8.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
a5bf5a2212
Bump bootstrap from 5.2.2 to 5.2.3 ( #2456 )
...
Bumps [bootstrap](https://github.com/twbs/bootstrap ) from 5.2.2 to 5.2.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/twbs/bootstrap/releases ">bootstrap's releases</a>.</em></p>
<blockquote>
<h2>v5.2.3</h2>
<h2>Fixes</h2>
<h3>🎨 CSS</h3>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37377 ">#37377</a>: Import root in bootstrap-utilities</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37425 ">#37425</a>: Fix deprecation warning with sass 1.56.0</li>
<li>Carousel: Fix RTL <code>translate()</code> direction</li>
</ul>
<h3>☕ ️ JavaScript</h3>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37235 ">#37235</a>: fix tooltip/popper disposal inconsistencies</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="cb021439c6
"><code>cb02143</code></a> Dist</li>
<li><a href="39589472f7
"><code>3958947</code></a> Bump version to 5.2.3</li>
<li><a href="7e3074c165
"><code>7e3074c</code></a> fix tooltip/popper disposal inconsistencies (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37235 ">#37235</a>)</li>
<li><a href="127a816f77
"><code>127a816</code></a> fix(carousel): RTL <code>translate()</code> direction</li>
<li><a href="77c456d8c4
"><code>77c456d</code></a> Import root in <code>bootstrap-utilities</code> (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37377 ">#37377</a>)</li>
<li><a href="b72236981f
"><code>b722369</code></a> Fix deprecation warning with sass 1.56.0 (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37425 ">#37425</a>)</li>
<li>See full diff in <a href="https://github.com/twbs/bootstrap/compare/v5.2.2...v5.2.3 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=bootstrap&package-manager=npm_and_yarn&previous-version=5.2.2&new-version=5.2.3 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
6c3a9a5948
Bump webpack-cli from 4.10.0 to 5.0.0 ( #2443 )
...
Bumps [webpack-cli](https://github.com/webpack/webpack-cli ) from 4.10.0 to 5.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-cli/releases ">webpack-cli's releases</a>.</em></p>
<blockquote>
<h2>v5.0.0</h2>
<h1><a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@4.10.0...webpack-cli@5.0.0 ">5.0.0</a> (2022-11-17)</h1>
<h3>Bug Fixes</h3>
<ul>
<li>improve description of the <code>--disable-interpret</code> option (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3364 ">#3364</a>) (<a href="bdb7e20a3f
">bdb7e20</a>)</li>
<li>remove the redundant <code>utils</code> export (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3343 ">#3343</a>) (<a href="a9ce5d077f
">a9ce5d0</a>)</li>
<li>respect <code>NODE_PATH</code> env variable (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3411 ">#3411</a>) (<a href="83d1f58fb5
">83d1f58</a>)</li>
<li>show all CLI specific flags in the minimum help output (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3354 ">#3354</a>) (<a href="35843e87c6
">35843e8</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>failOnWarnings option (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3317 ">#3317</a>) (<a href="c48c848c6c
">c48c848</a>)</li>
<li>update commander to v9 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3460 ">#3460</a>) (<a href="6621c023ab
">6621c02</a>)</li>
<li>added the <code>--define-process-env-node-env</code> option</li>
<li>update <code>interpret</code> to v3 and <code>rechoir</code> to v0.8</li>
<li>add an option for preventing interpret (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3329 ">#3329</a>) (<a href="c7373832b9
">c737383</a>)</li>
</ul>
<h3>BREAKING CHANGES</h3>
<ul>
<li>the minimum supported webpack version is v5.0.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3342 ">#3342</a>) (<a href="b1af0dc7eb
">b1af0dc</a>), closes <a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3342 ">#3342</a></li>
<li>webpack-cli no longer supports webpack v4, the minimum supported version is webpack v5.0.0</li>
<li>webpack-cli no longer supports webpack-dev-server v3, the minimum supported version is webpack-dev-server v4.0.0</li>
<li>remove the <code>migrate</code> command (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3291 ">#3291</a>) (<a href="56b43e4baf
">56b43e4</a>), closes <a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3291 ">#3291</a></li>
<li>remove the <code>--prefetch</code> option in favor the <code>PrefetchPlugin</code> plugin</li>
<li>remove the <code>--node-env</code> option in favor <code>--define-process-env-node-env</code></li>
<li>remove the <code>--hot</code> option in favor of directly using the <code>HotModuleReplacement</code> plugin (only for <code>build</code> command, for <code>serve</code> it will work)</li>
<li>the behavior logic of the <code>--entry</code> option has been changed - previously it replaced your entries, now the option adds a specified entry, if you want to return the previous behavior please use <code> webpack --entry-reset --entry './src/my-entry.js'</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-cli/blob/master/CHANGELOG.md ">webpack-cli's changelog</a>.</em></p>
<blockquote>
<h1><a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@4.10.0...webpack-cli@5.0.0 ">5.0.0</a> (2022-11-17)</h1>
<h3>Bug Fixes</h3>
<ul>
<li>improve description of the <code>--disable-interpret</code> option (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3364 ">#3364</a>) (<a href="bdb7e20a3f
">bdb7e20</a>)</li>
<li>remove the redundant <code>utils</code> export (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3343 ">#3343</a>) (<a href="a9ce5d077f
">a9ce5d0</a>)</li>
<li>respect <code>NODE_PATH</code> env variable (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3411 ">#3411</a>) (<a href="83d1f58fb5
">83d1f58</a>)</li>
<li>show all CLI specific flags in the minimum help output (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3354 ">#3354</a>) (<a href="35843e87c6
">35843e8</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>failOnWarnings option (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3317 ">#3317</a>) (<a href="c48c848c6c
">c48c848</a>)</li>
<li>update commander to v9 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3460 ">#3460</a>) (<a href="6621c023ab
">6621c02</a>)</li>
<li>added the <code>--define-process-env-node-env</code> option</li>
<li>update <code>interpret</code> to v3 and <code>rechoir</code> to v0.8</li>
<li>add an option for preventing interpret (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3329 ">#3329</a>) (<a href="c7373832b9
">c737383</a>)</li>
</ul>
<h3>BREAKING CHANGES</h3>
<ul>
<li>the minimum supported webpack version is v5.0.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3342 ">#3342</a>) (<a href="b1af0dc7eb
">b1af0dc</a>), closes <a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3342 ">#3342</a></li>
<li>webpack-cli no longer supports webpack v4, the minimum supported version is webpack v5.0.0</li>
<li>webpack-cli no longer supports webpack-dev-server v3, the minimum supported version is webpack-dev-server v4.0.0</li>
<li>remove the <code>migrate</code> command (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3291 ">#3291</a>) (<a href="56b43e4baf
">56b43e4</a>), closes <a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3291 ">#3291</a></li>
<li>remove the <code>--prefetch</code> option in favor the <code>PrefetchPlugin</code> plugin</li>
<li>remove the <code>--node-env</code> option in favor <code>--define-process-env-node-env</code></li>
<li>remove the <code>--hot</code> option in favor of directly using the <code>HotModuleReplacement</code> plugin (only for <code>build</code> command, for <code>serve</code> it will work)</li>
<li>the behavior logic of the <code>--entry</code> option has been changed - previously it replaced your entries, now the option adds a specified entry, if you want to return the previous behavior please use <code> webpack --entry-reset --entry './src/my-entry.js'</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="1d6ada1a84
"><code>1d6ada1</code></a> chore(release): 5.0.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3492 ">#3492</a>)</li>
<li><a href="24334d944d
"><code>24334d9</code></a> refactor: resolve TODO for devServer.stdin</li>
<li><a href="49b6aeae08
"><code>49b6aea</code></a> chore: peer deps in root package</li>
<li><a href="636ba3efff
"><code>636ba3e</code></a> chore(deps-dev): bump cspell from 6.12.0 to 6.14.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3488 ">#3488</a>)</li>
<li><a href="f3016a5eb5
"><code>f3016a5</code></a> chore(deps-dev): bump eslint from 8.24.0 to 8.27.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3487 ">#3487</a>)</li>
<li><a href="5782242d67
"><code>5782242</code></a> chore(deps-dev): bump lerna from 6.0.1 to 6.0.3 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3486 ">#3486</a>)</li>
<li><a href="80eb8c828b
"><code>80eb8c8</code></a> chore(deps-dev): bump <code>@commitlint/config-conventional</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3485 ">#3485</a>)</li>
<li><a href="8ea9020153
"><code>8ea9020</code></a> chore(deps-dev): bump ts-jest from 29.0.1 to 29.0.3 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3484 ">#3484</a>)</li>
<li><a href="515971abd9
"><code>515971a</code></a> chore(deps-dev): bump css-loader from 6.7.1 to 6.7.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3481 ">#3481</a>)</li>
<li><a href="f106109f18
"><code>f106109</code></a> chore(deps-dev): bump <code>@typescript-eslint/eslint-plugin</code></li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@4.10.0...webpack-cli@5.0.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-cli&package-manager=npm_and_yarn&previous-version=4.10.0&new-version=5.0.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
2165451537
Bump loader-utils from 2.0.3 to 2.0.4 ( #2442 )
...
Bumps [loader-utils](https://github.com/webpack/loader-utils ) from 2.0.3 to 2.0.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/loader-utils/releases ">loader-utils's releases</a>.</em></p>
<blockquote>
<h2>v2.0.4</h2>
<h3><a href="https://github.com/webpack/loader-utils/compare/v2.0.3...v2.0.4 ">2.0.4</a> (2022-11-11)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>ReDoS problem (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/225 ">#225</a>) (<a href="ac09944dfa
">ac09944</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/loader-utils/blob/v2.0.4/CHANGELOG.md ">loader-utils's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/loader-utils/compare/v2.0.3...v2.0.4 ">2.0.4</a> (2022-11-11)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>ReDoS problem (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/225 ">#225</a>) (<a href="ac09944dfa
">ac09944</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="6688b50281
"><code>6688b50</code></a> chore(release): 2.0.4</li>
<li><a href="ac09944dfa
"><code>ac09944</code></a> fix: ReDoS problem (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/225 ">#225</a>)</li>
<li>See full diff in <a href="https://github.com/webpack/loader-utils/compare/v2.0.3...v2.0.4 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=loader-utils&package-manager=npm_and_yarn&previous-version=2.0.3&new-version=2.0.4 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/boa-dev/boa/network/alerts ).
</details>
2 years ago
dependabot[bot]
fcab8051d4
Bump css-loader from 6.7.1 to 6.7.2 ( #2434 )
...
Bumps [css-loader](https://github.com/webpack-contrib/css-loader ) from 6.7.1 to 6.7.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/css-loader/releases ">css-loader's releases</a>.</em></p>
<blockquote>
<h2>v6.7.2</h2>
<h3><a href="https://github.com/webpack-contrib/css-loader/compare/v6.7.1...v6.7.2 ">6.7.2</a> (2022-11-13)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>css modules generation with inline syntax (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1480 ">#1480</a>) (<a href="2f4c27399f
">2f4c273</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/css-loader/blob/master/CHANGELOG.md ">css-loader's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack-contrib/css-loader/compare/v6.7.1...v6.7.2 ">6.7.2</a> (2022-11-13)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>css modules generation with inline syntax (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1480 ">#1480</a>) (<a href="2f4c27399f
">2f4c273</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="394d200cf9
"><code>394d200</code></a> chore(release): 6.7.2</li>
<li><a href="2f4c27399f
"><code>2f4c273</code></a> fix: css modules generation with inline syntax (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1480 ">#1480</a>)</li>
<li><a href="7c5cdcca16
"><code>7c5cdcc</code></a> chore(deps): bump loader-utils from 2.0.2 to 2.0.3 (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1479 ">#1479</a>)</li>
<li><a href="d5bc6eac3c
"><code>d5bc6ea</code></a> chore: update dependencies to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1478 ">#1478</a>)</li>
<li><a href="85b6bf705f
"><code>85b6bf7</code></a> ci: add node v19 (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1477 ">#1477</a>)</li>
<li><a href="0f85c5b94c
"><code>0f85c5b</code></a> chore: update dependencies to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1474 ">#1474</a>)</li>
<li><a href="560c05f2bb
"><code>560c05f</code></a> ci: add dependency review action (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1476 ">#1476</a>)</li>
<li><a href="cc4e08f996
"><code>cc4e08f</code></a> chore: update commitlint action (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1473 ">#1473</a>)</li>
<li><a href="9846913b94
"><code>9846913</code></a> chore: run cancel workflow on pull request (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1472 ">#1472</a>)</li>
<li><a href="845718cdcf
"><code>845718c</code></a> chore: update jest to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/css-loader/issues/1471 ">#1471</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack-contrib/css-loader/compare/v6.7.1...v6.7.2 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=css-loader&package-manager=npm_and_yarn&previous-version=6.7.1&new-version=6.7.2 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
2362f7353c
Bump webpack from 5.74.0 to 5.75.0 ( #2427 )
...
Bumps [webpack](https://github.com/webpack/webpack ) from 5.74.0 to 5.75.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack/releases ">webpack's releases</a>.</em></p>
<blockquote>
<h2>v5.75.0</h2>
<h1>Bugfixes</h1>
<ul>
<li><code>experiments.*</code> normalize to <code>false</code> when opt-out</li>
<li>avoid <code>NaN%</code></li>
<li>show the correct error when using a conflicting chunk name in code</li>
<li>HMR code tests existance of <code>window</code> before trying to access it</li>
<li>fix <code>eval-nosources-*</code> actually exclude sources</li>
<li>fix race condition where no module is returned from processing module</li>
<li>fix position of standalong semicolon in runtime code</li>
</ul>
<h1>Features</h1>
<ul>
<li>add support for <code>@import</code> to extenal CSS when using experimental CSS in node</li>
<li>add <code>i64</code> support to the deprecated WASM implementation</li>
</ul>
<h1>Developer Experience</h1>
<ul>
<li>expose <code>EnableWasmLoadingPlugin</code></li>
<li>add more typings</li>
<li>generate getters instead of readonly properties in typings to allow overriding them</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="8241da7f1e
"><code>8241da7</code></a> 5.75.0</li>
<li><a href="a91d9232ea
"><code>a91d923</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16458 ">#16458</a> from webpack/bugfix/semi</li>
<li><a href="4608b11416
"><code>4608b11</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16457 ">#16457</a> from webpack/tooling/update</li>
<li><a href="dfdd0b0e42
"><code>dfdd0b0</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16122 ">#16122</a> from AnmolBansalDEV/bug/compilationCallback</li>
<li><a href="23b9a1c01f
"><code>23b9a1c</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16167 ">#16167</a> from exposir/fixts</li>
<li><a href="6f2c5e852a
"><code>6f2c5e8</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16257 ">#16257</a> from alexzhang1030/calc_deterministic_verbose</li>
<li><a href="f7f36ad412
"><code>f7f36ad</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16339 ">#16339</a> from Liamolucko/wasm-i64</li>
<li><a href="761a54285e
"><code>761a542</code></a> fix semicolon position</li>
<li><a href="2403a36326
"><code>2403a36</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16345 ">#16345</a> from ahabhgk/fix-eval-nosources</li>
<li><a href="c18203c894
"><code>c18203c</code></a> update tooling</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack/compare/v5.74.0...v5.75.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack&package-manager=npm_and_yarn&previous-version=5.74.0&new-version=5.75.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
2ffae5b6f3
Bump loader-utils from 2.0.2 to 2.0.3 ( #2421 )
...
Bumps [loader-utils](https://github.com/webpack/loader-utils ) from 2.0.2 to 2.0.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/loader-utils/releases ">loader-utils's releases</a>.</em></p>
<blockquote>
<h2>v2.0.3</h2>
<h3><a href="https://github.com/webpack/loader-utils/compare/v2.0.1...v2.0.3 ">2.0.3</a> (2022-10-20)</h3>
<h3>Bug Fixes</h3>
<ul>
<li><strong>security:</strong> prototype pollution exploit (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/217 ">#217</a>) (<a href="a93cf6f470
">a93cf6f</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/loader-utils/blob/v2.0.3/CHANGELOG.md ">loader-utils's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/loader-utils/compare/v2.0.1...v2.0.3 ">2.0.3</a> (2022-10-20)</h3>
<h3>Bug Fixes</h3>
<ul>
<li><strong>security:</strong> prototype pollution exploit (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/217 ">#217</a>) (<a href="a93cf6f470
">a93cf6f</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="7162619fb9
"><code>7162619</code></a> chore(release): 2.0.3</li>
<li><a href="a93cf6f470
"><code>a93cf6f</code></a> fix(security): prototype polution exploit (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/217 ">#217</a>)</li>
<li><a href="90c7c4be17
"><code>90c7c4b</code></a> chore(release): 2.0.2</li>
<li><a href="8c2d24ee40
"><code>8c2d24e</code></a> fix: base64 generation and unicode characters (<a href="https://github-redirect.dependabot.com/webpack/loader-utils/issues/197 ">#197</a>)</li>
<li>See full diff in <a href="https://github.com/webpack/loader-utils/compare/v2.0.2...v2.0.3 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=loader-utils&package-manager=npm_and_yarn&previous-version=2.0.2&new-version=2.0.3 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/boa-dev/boa/network/alerts ).
</details>
2 years ago
dependabot[bot]
b0cf873a46
Bump monaco-editor from 0.34.0 to 0.34.1 ( #2351 )
...
Bumps [monaco-editor](https://github.com/microsoft/monaco-editor ) from 0.34.0 to 0.34.1.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md ">monaco-editor's changelog</a>.</em></p>
<blockquote>
<h2>[0.34.1]</h2>
<ul>
<li>Adds API to register global actions, commands, or keybinding rules</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a href="https://github.com/microsoft/monaco-editor/commits ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=monaco-editor&package-manager=npm_and_yarn&previous-version=0.34.0&new-version=0.34.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
b44f6f0ad2
Bump bootstrap from 5.2.1 to 5.2.2 ( #2322 )
...
Bumps [bootstrap](https://github.com/twbs/bootstrap ) from 5.2.1 to 5.2.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/twbs/bootstrap/releases ">bootstrap's releases</a>.</em></p>
<blockquote>
<h2>v5.2.2</h2>
<h2>Highlights</h2>
<ul>
<li><strong>Accordion</strong>
<ul>
<li>Use Sass variable for the accordion color instead of an invalid CSS variable</li>
</ul>
</li>
<li><strong>Buttons</strong>
<ul>
<li>Undo changes to <code>.btn:hover</code> from v5.2.1. We now explicitly target <code>.btn-check</code> styles instead.</li>
</ul>
</li>
<li><strong>Dropdowns</strong>
<ul>
<li>Temporarily restore ability for dropdowns to work without an explicit <code>data</code> attribute (will be removed again in v6)</li>
</ul>
</li>
<li><strong>Modals</strong>
<ul>
<li>Improve modal event listeners</li>
<li>Use <code><h1></code> for all <code>.modal-title</code> instances in our docs</li>
</ul>
</li>
<li><strong>Tables</strong>
<ul>
<li>Don't redefine <code>$border-color</code> in <code>table-variant()</code> mixin</li>
</ul>
</li>
<li><strong>Tabs</strong>
<ul>
<li>Tabs no longer autofocus and cause pages to jump on <code>tab.show()</code></li>
<li>Fix <code>.active</code> class toggling of tabs within dropdowns</li>
</ul>
</li>
<li><strong>Toasts</strong>
<ul>
<li>Properly set toast <code>z-index</code> on <code>.toast-container</code> as opposed to individual <code>.toast</code>s that don't receive any other positioning</li>
</ul>
</li>
<li><strong>Tooltips</strong>
<ul>
<li>Fix tooltip selectors with <code>title</code> attribute on dynamically created elements</li>
</ul>
</li>
</ul>
<h2>🎨 CSS</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37118 ">#37118</a>: Set toast z-index variable in the correct spot</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37165 ">#37165</a>: Explicitly target <code>.btn-check</code> and undo <code>:hover</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37182 ">#37182</a>: Use Sass variable for accordion color</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37239 ">#37239</a>: Don't redefine <code>$border-color</code> in <code>table-variant</code> mixin</li>
</ul>
<h2>☕ ️ JavaScript</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36914 ">#36914</a>: Fix tooltip selector usage</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37128 ">#37128</a>: Fix modal event listeners</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37146 ">#37146</a>: Drop tabs auto-focus</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37151 ">#37151</a>: Fix active class toggling of tabs within dropdown</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37189 ">#37189</a>: Enrich Tab Test for keyboard handler</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37190 ">#37190</a>: Dropdown: fix case with invalid markup</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37200 ">#37200</a>: Ensure Tab keyboard functionality after <a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37146 ">#37146</a></li>
</ul>
<h2>📖 Docs</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36899 ">#36899</a>: Slightly improve image compression</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37142 ">#37142</a>: Add informative note for Tooltip/Popover selector option</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37145 ">#37145</a>: Docs: minor fix for Navbar > Offcanvas examples</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37153 ">#37153</a>: Fix typo in docs - Configure Vite section</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37199 ">#37199</a>: Replace Webpack and Vite PNGs by SVGs</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37210 ">#37210</a>: Use <code><h1></code> for all <code>modal-title</code> examples/uses</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37214 ">#37214</a>: Docs: Change <code>view in GitHub</code> links inside <code>main</code></li>
</ul>
<h2>🌎 Accessibility</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="961d5ff984
"><code>961d5ff</code></a> Release v5.2.2 (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37236 ">#37236</a>)</li>
<li><a href="9edfed8a5e
"><code>9edfed8</code></a> Don't redefine <code>$border-color</code> in <code>table-variant</code> mixin (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37239 ">#37239</a>)</li>
<li><a href="d49d8ce583
"><code>d49d8ce</code></a> Ensure Tab keyboard functionality after <a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37146 ">#37146</a> (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37200 ">#37200</a>)</li>
<li><a href="0a5f6e078c
"><code>0a5f6e0</code></a> Use <code>\<h1></code> for all <code>modal-title</code> examples/uses (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37210 ">#37210</a>)</li>
<li><a href="812f891bfc
"><code>812f891</code></a> Update devDependencies (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37238 ">#37238</a>)</li>
<li><a href="da0fe8c8b2
"><code>da0fe8c</code></a> Minor docs changes (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37215 ">#37215</a>)</li>
<li><a href="abb1cf529f
"><code>abb1cf5</code></a> Add eslint-plugin-html to lint JS in HTML files (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37186 ">#37186</a>)</li>
<li><a href="f84d82ada0
"><code>f84d82a</code></a> NuGet: Use license expression (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36421 ">#36421</a>)</li>
<li><a href="80482af57b
"><code>80482af</code></a> Changing the way <code>View on GitHub</code> links are handled (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37214 ">#37214</a>)</li>
<li><a href="597c402314
"><code>597c402</code></a> Dropdown: fix case with invalid markup (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37190 ">#37190</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/twbs/bootstrap/compare/v5.2.1...v5.2.2 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=bootstrap&package-manager=npm_and_yarn&previous-version=5.2.1&new-version=5.2.2 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
Iban Eguia
a3062d1f45
Fixing CI ( #2302 )
...
This PR fixes the CI after the version bump.
2 years ago
Iban Eguia
f5be60975b
Updated dependencies for 0.16 release ( #2300 )
...
This Pull Request updates the dependencies for the 0.16 release.
Co-authored-by: José Julián Espina <jedel0124@gmail.com>
2 years ago
dependabot[bot]
558477f97a
Bump webpack-dev-server from 4.11.0 to 4.11.1 ( #2292 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.11.0 to 4.11.1.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.11.0...v4.11.1 ">4.11.1</a> (2022-09-19)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>respect <code>client.logging</code> option for all logs (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4572 ">#4572</a>) (<a href="375835c926
">375835c</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="418e932004
"><code>418e932</code></a> chore(release): 4.11.1</li>
<li><a href="375835c926
"><code>375835c</code></a> fix: respect <code>client.logging</code> option for all logs (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4572 ">#4572</a>)</li>
<li><a href="ef2f9e934b
"><code>ef2f9e9</code></a> chore: fix examples for open target not working (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4575 ">#4575</a>)</li>
<li><a href="7da7336561
"><code>7da7336</code></a> ci: workflow security</li>
<li><a href="5d4b3479c9
"><code>5d4b347</code></a> chore(deps-dev): bump core-js from 3.25.1 to 3.25.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4574 ">#4574</a>)</li>
<li><a href="87072c7a70
"><code>87072c7</code></a> chore(deps-dev): bump <code>@types/node-forge</code> from 1.0.4 to 1.0.5 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4571 ">#4571</a>)</li>
<li><a href="28f6381e1b
"><code>28f6381</code></a> chore(deps-dev): bump <code>@babel/plugin-transform-runtime</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4567 ">#4567</a>)</li>
<li><a href="595003b286
"><code>595003b</code></a> chore(deps-dev): bump <code>@babel/core</code> from 7.19.0 to 7.19.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4568 ">#4568</a>)</li>
<li><a href="67acc2e786
"><code>67acc2e</code></a> chore(deps-dev): bump <code>@babel/eslint-parser</code> from 7.18.9 to 7.19.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4569 ">#4569</a>)</li>
<li><a href="ad2dcc5081
"><code>ad2dcc5</code></a> chore(deps-dev): bump <code>@babel/preset-env</code> from 7.19.0 to 7.19.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4570 ">#4570</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.11.0...v4.11.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.11.0&new-version=4.11.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
ba91449e00
Bump webpack-dev-server from 4.10.1 to 4.11.0 ( #2270 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.10.1 to 4.11.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.11.0</h2>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.10.1...v4.11.0 ">4.11.0</a> (2022-09-07)</h2>
<h3>Features</h3>
<ul>
<li>make allowedHosts accept localhost subdomains by default (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4357 ">#4357</a>) (<a href="0a33e6a752
">0a33e6a</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>auto reply to OPTIONS requests only when unhandled (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4559 ">#4559</a>) (<a href="984af026a5
">984af02</a>), closes <a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4551 ">#4551</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.10.1...v4.11.0 ">4.11.0</a> (2022-09-07)</h2>
<h3>Features</h3>
<ul>
<li>make allowedHosts accept localhost subdomains by default (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4357 ">#4357</a>) (<a href="0a33e6a752
">0a33e6a</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>auto reply to OPTIONS requests only when unhandled (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4559 ">#4559</a>) (<a href="984af026a5
">984af02</a>), closes <a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4551 ">#4551</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="8abb295bf7
"><code>8abb295</code></a> chore(release): 4.11.0</li>
<li><a href="984af026a5
"><code>984af02</code></a> fix: auto reply to OPTIONS requests only when unhandled (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4559 ">#4559</a>)</li>
<li><a href="85dcb31d76
"><code>85dcb31</code></a> chore(deps-dev): bump <code>@babel/core</code> from 7.18.13 to 7.19.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4557 ">#4557</a>)</li>
<li><a href="fe058dc586
"><code>fe058dc</code></a> chore(deps-dev): bump <code>@babel/preset-env</code> from 7.18.10 to 7.19.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4558 ">#4558</a>)</li>
<li><a href="1368d1db05
"><code>1368d1d</code></a> chore(deps-dev): bump <code>@babel/runtime</code> from 7.18.9 to 7.19.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4556 ">#4556</a>)</li>
<li><a href="0a33e6a752
"><code>0a33e6a</code></a> feat: make allowedHosts accept localhost subdomains by default (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4357 ">#4357</a>)</li>
<li><a href="088a318d72
"><code>088a318</code></a> chore(deps-dev): bump marked from 4.0.19 to 4.1.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4553 ">#4553</a>)</li>
<li><a href="45ed9bdb5a
"><code>45ed9bd</code></a> chore(deps): bump bonjour-service from 1.0.13 to 1.0.14 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4554 ">#4554</a>)</li>
<li>See full diff in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.10.1...v4.11.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.10.1&new-version=4.11.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
92ecbda7b2
Bump bootstrap from 5.2.0 to 5.2.1 ( #2271 )
...
Bumps [bootstrap](https://github.com/twbs/bootstrap ) from 5.2.0 to 5.2.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/twbs/bootstrap/releases ">bootstrap's releases</a>.</em></p>
<blockquote>
<h2>v5.2.1</h2>
<h2>🚀 Highlights</h2>
<ul>
<li><strong>Accordion</strong>
<ul>
<li>Update <code>color</code> value to use the <code>$accordion-button-color</code> Sass variable instead of our color contrast function</li>
</ul>
</li>
<li><strong>Buttons</strong>
<ul>
<li>Added a <code>transparent</code> default hover border color CSS variable for buttons to fix a visual regression</li>
<li><code>.btn-link</code> no longer has a gradient when <code>$enable-gradients</code> is set to <code>true</code></li>
</ul>
</li>
<li><strong>Forms</strong>
<ul>
<li>Input groups have updated <code>z-index</code> values to ensure proper rendering of validated form fields</li>
<li>Floating labels now reset their <code>text-align</code> to ensure consistent styling</li>
</ul>
</li>
<li><strong>List Groups</strong>
<ul>
<li>Horizontal list groups with only one child now render the correct <code>border-radius</code></li>
<li>Modified the <code>list-group-item</code> selectors to better support nested imports of Bootstrap's CSS</li>
</ul>
</li>
<li><strong>Modals</strong>
<ul>
<li>Fixed modal event listeners during dismiss click, allowing you to once again click scrollbars without dismissing the modal</li>
</ul>
</li>
<li><strong>Pagination</strong>
<ul>
<li>Fixed incorrect <code>border-radius</code> values inside pagination components</li>
</ul>
</li>
<li><strong>Scrollspy</strong>
<ul>
<li>Scrollspy threshold option is now configurable</li>
</ul>
</li>
<li><strong>Tooltips</strong>
<ul>
<li>Reverted some tooltip plugin updates to prevent issues with <code>selector</code>, dynamic content, and disposed tooltips using <code>title</code></li>
</ul>
</li>
</ul>
<h2>🚀 Features</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36750 ">#36750</a>: ScrollSpy: make the threshold option configurable</li>
</ul>
<h2>🎨 CSS</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36507 ">#36507</a>: v5/docs: reintroduce <code>outline</code> for docs code samples, buttons when <code>:not(:focus-visible)</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36593 ">#36593</a>: flush variant of accordion border radius</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36663 ">#36663</a>: fix <a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36662 ">#36662</a> List-group-item margin-top is offset when importing sass in a nested class</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36694 ">#36694</a>: Docs: add grid-row-columns variable</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36791 ">#36791</a>: Remove a unused sass parameter from banner mixin</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36828 ">#36828</a>: Fix pagination page items border radius</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36849 ">#36849</a>: Define correctly <code>$popover-header-color</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36873 ">#36873</a>: Fix floating labels under <code>.text-center</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36874 ">#36874</a>: Floating labels in input group: Border fix</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36921 ">#36921</a>: Accordion color should use $accordion-color</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36986 ">#36986</a>: bugfix undefined border color variable for btn <a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36938 ">#36938</a></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37017 ">#37017</a>: List group: Fix horizontal when only one child</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37021 ">#37021</a>: Scss: Adding missing <code>z-index</code> CSS variables.</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37026 ">#37026</a>: Rework button focus/active styling, with extra changes for checks/radios</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37027 ">#37027</a>: Search modal: Set cursor on auto</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37034 ">#37034</a>: More consistency for CSS/Sass vars doc for components with dark variants</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37059 ">#37059</a>: Fix input group z-index focus + validation</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37078 ">#37078</a>: Remove gradient from <code>.btn-link</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37079 ">#37079</a>: Add workarounds for postcss values parser error</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37080 ">#37080</a>: btn-group draws first input margin <a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36794 ">#36794</a></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37093 ">#37093</a>: Fix accordion button color</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="23e50829f9
"><code>23e5082</code></a> Release v5.2.1 (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37098 ">#37098</a>)</li>
<li><a href="23fb7a7915
"><code>23fb7a7</code></a> Fix modal event-listeners during dismiss click (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36863 ">#36863</a>)</li>
<li><a href="949456984a
"><code>9494569</code></a> Fix tooltip manual toggling (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37086 ">#37086</a>)</li>
<li><a href="7a7469b8ab
"><code>7a7469b</code></a> Fix accordion button color</li>
<li><a href="9b943880fc
"><code>9b94388</code></a> Update _button-group.scss</li>
<li><a href="97a9060a8f
"><code>97a9060</code></a> Update _button-group.scss</li>
<li><a href="2504b89950
"><code>2504b89</code></a> Remove gradient from .btn-link</li>
<li><a href="32c457db4b
"><code>32c457d</code></a> Rework button focus/active styling, with extra changes for checks/radios (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/37 ">#37</a>...</li>
<li><a href="b8880e5eec
"><code>b8880e5</code></a> Add workarounds for postcss values parser error</li>
<li><a href="75e09b1c0f
"><code>75e09b1</code></a> Bump rtlcss from 3.5.0 to 4.0.0 (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36968 ">#36968</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/twbs/bootstrap/compare/v5.2.0...v5.2.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=bootstrap&package-manager=npm_and_yarn&previous-version=5.2.0&new-version=5.2.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
cb610d8073
Bump webpack-dev-server from 4.10.0 to 4.10.1 ( #2253 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.10.0 to 4.10.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.10.1</h2>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.10.0...v4.10.1 ">4.10.1</a> (2022-08-29)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>compatibility with old browsers (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4544 ">#4544</a>) (<a href="6a430d495e
">6a430d4</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.10.0...v4.10.1 ">4.10.1</a> (2022-08-29)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>compatibility with old browsers (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4544 ">#4544</a>) (<a href="6a430d495e
">6a430d4</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="eb997bba98
"><code>eb997bb</code></a> chore(release): 4.10.1</li>
<li><a href="4eed30e606
"><code>4eed30e</code></a> ci: enable jest <code>--shard</code> option in github-actions (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4545 ">#4545</a>)</li>
<li><a href="97dba79fec
"><code>97dba79</code></a> chore(deps-dev): bump eslint from 8.22.0 to 8.23.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4550 ">#4550</a>)</li>
<li><a href="a2eb40cfd0
"><code>a2eb40c</code></a> chore(deps-dev): bump core-js from 3.24.1 to 3.25.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4548 ">#4548</a>)</li>
<li><a href="6a430d495e
"><code>6a430d4</code></a> fix: compatibility with old browsers (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4544 ">#4544</a>)</li>
<li><a href="735864c305
"><code>735864c</code></a> chore(deps-dev): bump marked from 4.0.18 to 4.0.19 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4546 ">#4546</a>)</li>
<li><a href="22443c2a42
"><code>22443c2</code></a> chore(deps-dev): bump typescript from 4.7.4 to 4.8.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4549 ">#4549</a>)</li>
<li><a href="02e11e133d
"><code>02e11e1</code></a> chore(deps-dev): bump <code>@babel/core</code> from 7.18.10 to 7.18.13 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4547 ">#4547</a>)</li>
<li><a href="751214a294
"><code>751214a</code></a> chore(deps-dev): bump eslint from 8.21.0 to 8.22.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4541 ">#4541</a>)</li>
<li><a href="544543a0b3
"><code>544543a</code></a> ci: add workflow to cancel previous runs (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4542 ">#4542</a>)</li>
<li>See full diff in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.10.0...v4.10.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.10.0&new-version=4.10.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
d9720f71ab
Bump terser-webpack-plugin from 5.3.5 to 5.3.6 ( #2254 )
...
Bumps [terser-webpack-plugin](https://github.com/webpack-contrib/terser-webpack-plugin ) from 5.3.5 to 5.3.6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/releases ">terser-webpack-plugin's releases</a>.</em></p>
<blockquote>
<h2>v5.3.6</h2>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.5...v5.3.6 ">5.3.6</a> (2022-08-29)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>allow disable compress options for <code>terser</code> and <code>swc</code> (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/514 ">#514</a>) (<a href="52c1aef218
">52c1aef</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/blob/master/CHANGELOG.md ">terser-webpack-plugin's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.5...v5.3.6 ">5.3.6</a> (2022-08-29)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>allow disable compress options for <code>terser</code> and <code>swc</code> (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/514 ">#514</a>) (<a href="52c1aef218
">52c1aef</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="9718859ada
"><code>9718859</code></a> chore(release): 5.3.6</li>
<li><a href="52c1aef218
"><code>52c1aef</code></a> fix: allow disable compress options for <code>terser</code> and <code>swc</code> (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/514 ">#514</a>)</li>
<li>See full diff in <a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.5...v5.3.6 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=terser-webpack-plugin&package-manager=npm_and_yarn&previous-version=5.3.5&new-version=5.3.6 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
28c13a420c
Bump terser-webpack-plugin from 5.3.4 to 5.3.5 ( #2240 )
...
Bumps [terser-webpack-plugin](https://github.com/webpack-contrib/terser-webpack-plugin ) from 5.3.4 to 5.3.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/releases ">terser-webpack-plugin's releases</a>.</em></p>
<blockquote>
<h2>v5.3.5</h2>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.4...v5.3.5 ">5.3.5</a> (2022-08-16)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>types (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/512 ">#512</a>) (<a href="5c13ba748f
">5c13ba7</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/blob/master/CHANGELOG.md ">terser-webpack-plugin's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.4...v5.3.5 ">5.3.5</a> (2022-08-16)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>types (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/512 ">#512</a>) (<a href="5c13ba748f
">5c13ba7</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="c5a9d4146c
"><code>c5a9d41</code></a> chore(release): 5.3.5</li>
<li><a href="5c13ba748f
"><code>5c13ba7</code></a> fix: types (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/512 ">#512</a>)</li>
<li><a href="9ebedf27a1
"><code>9ebedf2</code></a> ci: add job to cancel previous runs (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/510 ">#510</a>)</li>
<li>See full diff in <a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.4...v5.3.5 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=terser-webpack-plugin&package-manager=npm_and_yarn&previous-version=5.3.4&new-version=5.3.5 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
dab00f03e0
Bump terser-webpack-plugin from 5.3.3 to 5.3.4 ( #2235 )
...
Bumps [terser-webpack-plugin](https://github.com/webpack-contrib/terser-webpack-plugin ) from 5.3.3 to 5.3.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/releases ">terser-webpack-plugin's releases</a>.</em></p>
<blockquote>
<h2>v5.3.4</h2>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.3...v5.3.4 ">5.3.4</a> (2022-08-12)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>respect environment options for terser and swc compress options (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/509 ">#509</a>) (<a href="29bbc3ae1c
">29bbc3a</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/blob/master/CHANGELOG.md ">terser-webpack-plugin's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.3...v5.3.4 ">5.3.4</a> (2022-08-12)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>respect environment options for terser and swc compress options (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/509 ">#509</a>) (<a href="29bbc3ae1c
">29bbc3a</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="9a6e47c10b
"><code>9a6e47c</code></a> chore(release): 5.3.4</li>
<li><a href="29bbc3ae1c
"><code>29bbc3a</code></a> fix: respect environment options for terser and swc compress options (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/509 ">#509</a>)</li>
<li><a href="64f2ff5ac9
"><code>64f2ff5</code></a> chore: update dependencies to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/508 ">#508</a>)</li>
<li><a href="d17562a1d5
"><code>d17562a</code></a> ci: add GitHub token permissions for workflow (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/505 ">#505</a>)</li>
<li><a href="7515a5a85b
"><code>7515a5a</code></a> chore(deps): update (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/504 ">#504</a>)</li>
<li><a href="bc1ddccd07
"><code>bc1ddcc</code></a> docs: update note in README.md (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/497 ">#497</a>)</li>
<li><a href="01e4b9d3e2
"><code>01e4b9d</code></a> chore: update dependencies to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/499 ">#499</a>)</li>
<li><a href="e7d39aefbd
"><code>e7d39ae</code></a> chore: ignore types for eslint (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/496 ">#496</a>)</li>
<li><a href="ccf48f1340
"><code>ccf48f1</code></a> chore: disable commit message length check (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/494 ">#494</a>)</li>
<li>See full diff in <a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.3...v5.3.4 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=terser-webpack-plugin&package-manager=npm_and_yarn&previous-version=5.3.3&new-version=5.3.4 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
af72e6178d
Bump webpack-dev-server from 4.9.3 to 4.10.0 ( #2228 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.9.3 to 4.10.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.10.0</h2>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.3...v4.10.0 ">4.10.0</a> (2022-08-10)</h2>
<h3>Features</h3>
<ul>
<li>allow to configure more <code>client</code> options via resource URL (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4274 ">#4274</a>) (<a href="216e3cbe62
">216e3cb</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>response correctly when receive an OPTIONS request (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4185 ">#4185</a>) (<a href="2b3b7e000f
">2b3b7e0</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.3...v4.10.0 ">4.10.0</a> (2022-08-10)</h2>
<h3>Features</h3>
<ul>
<li>allow to configure more <code>client</code> options via resource URL (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4274 ">#4274</a>) (<a href="216e3cbe62
">216e3cb</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>response correctly when receive an OPTIONS request (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4185 ">#4185</a>) (<a href="2b3b7e000f
">2b3b7e0</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="49efdf8734
"><code>49efdf8</code></a> chore(release): 4.10.0</li>
<li><a href="2b3b7e000f
"><code>2b3b7e0</code></a> fix: response correctly when receive an OPTIONS request (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4185 ">#4185</a>)</li>
<li><a href="480f1e1312
"><code>480f1e1</code></a> chore(deps-dev): bump core-js from 3.24.0 to 3.24.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4533 ">#4533</a>)</li>
<li><a href="890f27254a
"><code>890f272</code></a> chore(deps-dev): bump <code>@babel/plugin-transform-runtime</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4535 ">#4535</a>)</li>
<li><a href="75ff939c41
"><code>75ff939</code></a> chore(deps-dev): bump <code>@babel/cli</code> from 7.18.9 to 7.18.10 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4537 ">#4537</a>)</li>
<li><a href="56ac714705
"><code>56ac714</code></a> chore(deps-dev): bump eslint from 8.20.0 to 8.21.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4538 ">#4538</a>)</li>
<li><a href="7a92f8af55
"><code>7a92f8a</code></a> chore(deps-dev): bump <code>@babel/preset-env</code> from 7.18.9 to 7.18.10 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4539 ">#4539</a>)</li>
<li><a href="7b2fc6a22a
"><code>7b2fc6a</code></a> chore(deps-dev): bump <code>@babel/core</code> from 7.18.9 to 7.18.10 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4536 ">#4536</a>)</li>
<li><a href="695b43ab2c
"><code>695b43a</code></a> chore(deps): bump <code>@types/serve-static</code> from 1.13.10 to 1.15.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4534 ">#4534</a>)</li>
<li><a href="83951c8762
"><code>83951c8</code></a> chore(deps-dev): bump core-js from 3.23.5 to 3.24.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4530 ">#4530</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.3...v4.10.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.9.3&new-version=4.10.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
a42716b7e5
Bump monaco-editor from 0.33.0 to 0.34.0 ( #2221 )
...
Bumps [monaco-editor](https://github.com/microsoft/monaco-editor ) from 0.33.0 to 0.34.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md ">monaco-editor's changelog</a>.</em></p>
<blockquote>
<h2>[0.34.0]</h2>
<ul>
<li>Introduction of <code>IEditor.createDecorationsCollection</code> API</li>
<li>New function <code>removeAllMarkers</code> to remove all markers</li>
<li>Support for light high contrast theme</li>
<li>Introduction of <code>BracketPairColorizationOptions.independentColorPoolPerBracketType</code></li>
<li>Introduction of <code>PositionAffinity.LeftOfInjectedText</code> and <code>PositionAffinity.RightOfInjectedText</code></li>
<li>Introduction of <code>IEditorOptions.showFoldingControls: 'never'</code></li>
<li>Introduction of <code>IDiffEditorBaseOptions.renderMarginRevertIcon: boolean</code></li>
<li>Inline Quick Suggestions</li>
<li>Introduction of <code>IContentWidgetPosition.positionAffinity</code></li>
<li>Provider can now be registered for a <code>LanguageSelector</code></li>
</ul>
<h3>Breaking Changes</h3>
<ul>
<li><code>IEditorInlayHintsOptions</code> tweaks</li>
<li>Iteration on <code>InlineCompletion</code> API</li>
<li><code>WorkspaceFileEdit</code> -> <code>IWorkspaceFileEdit</code>
<ul>
<li><code>oldUri</code> -> <code>oldResource</code></li>
<li><code>newUri</code> -> <code>newResource</code></li>
</ul>
</li>
<li><code>WorkspaceTextEdit</code> -> <code>IWorkspaceTextEdit</code>
<ul>
<li><code>edit</code> -> <code>textEdit</code> (now supports <code>insertAsSnippet</code>)</li>
<li><code>modelVersionId?: number</code> -> <code>versionId: number | undefined</code></li>
</ul>
</li>
<li><code>InlayHint</code> API tweaks</li>
<li>Soft deprecation of <code>ICodeEditor.deltaDecorations</code>, no adoption required. <code>IEditor.createDecorationsCollection</code> API should be used instead.</li>
</ul>
<p>Contributions to <code>monaco-editor</code>:</p>
<ul>
<li><a href="https://github.com/alexander-zw "><code>@alexander-zw (Alexander Wu)</code></a>: [webpack readme] Add how to get languages/features [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3171 ">#3171</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3171 ">microsoft/monaco-editor#3171</a>)</li>
<li><a href="https://github.com/anjbur "><code>@anjbur (Angela Burton)</code></a>: Update Q# keywords [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3222 ">#3222</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3222 ">microsoft/monaco-editor#3222</a>)</li>
<li><a href="https://github.com/bsorrentino "><code>@bsorrentino (bsorrentino)</code></a>: Fix issue <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/2295 ">#2295</a> - Models with "@" in their name do not resolve as dependencies [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3057 ">#3057</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3057 ">microsoft/monaco-editor#3057</a>)</li>
<li><a href="https://github.com/MasterOdin "><code>@MasterOdin (Matthew Peveler)</code></a>: Remove duplicate testcases for mysql [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3138 ">#3138</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3138 ">microsoft/monaco-editor#3138</a>)</li>
<li><a href="https://github.com/mhsdesign "><code>@mhsdesign (Marc Henry Schultz)</code></a>: [DOCS] IEditorOptions.automaticLayout uses ResizeObserver 3051 [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3052 ">#3052</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3052 ">microsoft/monaco-editor#3052</a>)</li>
<li><a href="https://github.com/supersonictw "><code>@supersonictw (SuperSonic)</code></a>: Fix menu link in integrate-esm.md [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3214 ">#3214</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3214 ">microsoft/monaco-editor#3214</a>)</li>
<li><a href="https://github.com/tonilastre "><code>@tonilastre (Toni)</code></a>: Add config and tokenizer for query language Cypher [PR <a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/issues/3102 ">#3102</a>](<a href="https://github-redirect.dependabot.com/microsoft/monaco-editor/pull/3102 ">microsoft/monaco-editor#3102</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a href="https://github.com/microsoft/monaco-editor/commits ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=monaco-editor&package-manager=npm_and_yarn&previous-version=0.33.0&new-version=0.34.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
fafa006c9a
Bump webpack from 5.73.0 to 5.74.0 ( #2201 )
...
Bumps [webpack](https://github.com/webpack/webpack ) from 5.73.0 to 5.74.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack/releases ">webpack's releases</a>.</em></p>
<blockquote>
<h2>v5.74.0</h2>
<h1>Features</h1>
<ul>
<li>add <code>resolve.extensionAlias</code> option which allows to alias extensions
<ul>
<li>This is useful when you are forced to add the <code>.js</code> extension to imports when the file really has a <code>.ts</code> extension (typescript + <code>"type": "module"</code>)</li>
</ul>
</li>
<li>add support for ES2022 features like static blocks</li>
<li>add Tree Shaking support for <code>ProvidePlugin</code></li>
</ul>
<h1>Bugfixes</h1>
<ul>
<li>fix persistent cache when some build dependencies are on a different windows drive</li>
<li>make order of evaluation of side-effect-free modules deterministic between concatenated and non-concatenated modules</li>
<li>remove left-over from debugging in TLA/async modules runtime code</li>
<li>remove unneeded extra 1s timestamp offset during watching when files are actually untouched
<ul>
<li>This sometimes caused an additional second build which are not really needed</li>
</ul>
</li>
<li>fix <code>shareScope</code> option for <code>ModuleFederationPlugin</code></li>
<li>set `"use-credentials"`` also for same origin scripts</li>
</ul>
<h1>Performance</h1>
<ul>
<li>Improve memory usage and performance of aggregating needed files/directories for watching
<ul>
<li>This affects rebuild performance</li>
</ul>
</li>
</ul>
<h1>Extensibility</h1>
<ul>
<li>export <code>HarmonyImportDependency</code> for plugins</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="8f87b50dc7
"><code>8f87b50</code></a> 5.74.0</li>
<li><a href="3e1f24498d
"><code>3e1f244</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16071 ">#16071</a> from devinan/patch-1</li>
<li><a href="c7e14e2e8e
"><code>c7e14e2</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15910 ">#15910</a> from ludofischer/fix-message</li>
<li><a href="7b63346518
"><code>7b63346</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15627 ">#15627</a> from webpack/feat/issue-12441</li>
<li><a href="402d152ccf
"><code>402d152</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15642 ">#15642</a> from webpack/set-use-credentials-without-origin-check</li>
<li><a href="fcb0e35f82
"><code>fcb0e35</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15996 ">#15996</a> from webdiscus/main</li>
<li><a href="6dc6a19ae1
"><code>6dc6a19</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16031 ">#16031</a> from evantd/main</li>
<li><a href="52351a654a
"><code>52351a6</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16033 ">#16033</a> from varunsh-coder/token-perms</li>
<li><a href="555915b412
"><code>555915b</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16065 ">#16065</a> from webpack/fix/issue-16054</li>
<li><a href="d4cab5b6f7
"><code>d4cab5b</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/16077 ">#16077</a> from webpack/fix-scheme</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack/compare/v5.73.0...v5.74.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack&package-manager=npm_and_yarn&previous-version=5.73.0&new-version=5.74.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
deb0d90dc4
Bump terser from 5.14.0 to 5.14.2 ( #2197 )
...
Bumps [terser](https://github.com/terser/terser ) from 5.14.0 to 5.14.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/terser/terser/blob/master/CHANGELOG.md ">terser's changelog</a>.</em></p>
<blockquote>
<h2>v5.14.2</h2>
<ul>
<li>Security fix for RegExps that should not be evaluated (regexp DDOS)</li>
<li>Source maps improvements (<a href="https://github-redirect.dependabot.com/terser/terser/issues/1211 ">#1211</a>)</li>
<li>Performance improvements in long property access evaluation (<a href="https://github-redirect.dependabot.com/terser/terser/issues/1213 ">#1213</a>)</li>
</ul>
<h2>v5.14.1</h2>
<ul>
<li>keep_numbers option added to TypeScript defs (<a href="https://github-redirect.dependabot.com/terser/terser/issues/1208 ">#1208</a>)</li>
<li>Fixed parsing of nested template strings (<a href="https://github-redirect.dependabot.com/terser/terser/issues/1204 ">#1204</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a href="https://github.com/terser/terser/commits ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=terser&package-manager=npm_and_yarn&previous-version=5.14.0&new-version=5.14.2 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/boa-dev/boa/network/alerts ).
</details>
2 years ago
dependabot[bot]
fc30061453
Bump bootstrap from 5.1.3 to 5.2.0 ( #2194 )
...
Bumps [bootstrap](https://github.com/twbs/bootstrap ) from 5.1.3 to 5.2.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/twbs/bootstrap/releases ">bootstrap's releases</a>.</em></p>
<blockquote>
<h2>v5.2.0</h2>
<h2>🚀 Highlights</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36168 ">#36168</a>: Manually set hover and active backgrounds and borders for dark and light buttons</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36327 ">#36327</a>: Truncate text to prevent multiline floating label</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36382 ">#36382</a>: Rewrite Webpack guide</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36411 ">#36411</a>: Rewrite Parcel guide</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36412 ">#36412</a>: Docs: Add a Vite Getting Started guide</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36500 ">#36500</a>: Generate local CSS variables on utilities when using state option</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36528 ">#36528</a>: Scrollspy: enable <code>smooth-scroll</code> behavior</li>
</ul>
<h2>🚀 Features</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36352 ">#36352</a>: Fix StackBlitz examples by embedding snippets.js when needed</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36528 ">#36528</a>: Scrollspy: enable <code>smooth-scroll</code> behavior</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36759 ">#36759</a>: Support input groups in floating forms</li>
</ul>
<h2>🎨 CSS</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36156 ">#36156</a>: Update <code>.form-control-color</code> sizing and styles</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36168 ">#36168</a>: Manually set hover and active backgrounds and borders for dark and light buttons</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36178 ">#36178</a>: Add a banner mixin, helping future releases and maintenance</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36327 ">#36327</a>: Truncate text to prevent multiline floating label</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36353 ">#36353</a>: Fix offcanvas not showing with <code>.showing</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36366 ">#36366</a>: add back focus box shadow to <code>btn-link</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36406 ">#36406</a>: CSS: few proposals</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36423 ">#36423</a>: Stylelint: Disable <code>custom-property-empty-line-before</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36446 ">#36446</a>: Update Sass for computing <code>.table-group-divider</code> border</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36447 ">#36447</a>: Fix <code>.dropdown-item</code> <code>border-radius</code> when <code>$dropdown-padding-y</code> is <code>0</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36461 ">#36461</a>: Fix alert border radius</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36476 ">#36476</a>: Docs: fix Reboot Horizontal rules using border utilities</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36477 ">#36477</a>: Docs: remove unused _algolia.scss</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36499 ">#36499</a>: Don't style <code>readonly</code> inputs as <code>disabled</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36500 ">#36500</a>: Generate local CSS variables on utilities when using state option</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36509 ">#36509</a>: Remove <code>--bs-headings-color</code> CSS variable due to backward compatibility issues</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36535 ">#36535</a>: Fix 'Remove from map' Sass description</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36608 ">#36608</a>: dashboard example: minor fix</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36627 ">#36627</a>: Fix search modal z-index to be on top of all docs showcased components</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36646 ">#36646</a>: Fix tooltip/badge border radius when rounded disabled</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36680 ">#36680</a>: Revert db61cf3 for <code>$text-muted</code> default value</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36689 ">#36689</a>: Add missing CSS vars for <code>.navbar-nav</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36704 ">#36704</a>: Fix missing <code>--bs-btn-disabled-border-color</code> in <code>button-outline-variant</code> mixin</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36711 ">#36711</a>: Add <code>$display-font-family</code> and <code>$display-font-style</code></li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36740 ">#36740</a>: Fixing pagination compile issue</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36747 ">#36747</a>: Fix active/focused button link text color</li>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36759 ">#36759</a>: Support input groups in floating forms</li>
</ul>
<h2>☕ ️ JavaScript</h2>
<ul>
<li><a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/35679 ">#35679</a>: Force tooltip and popover to recreate content every time it opens</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="edf9c40956
"><code>edf9c40</code></a> Release v5.2.0 (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36768 ">#36768</a>)</li>
<li><a href="f451b4161e
"><code>f451b41</code></a> Fix failing test on EventHandler (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36772 ">#36772</a>)</li>
<li><a href="4035ad1a0e
"><code>4035ad1</code></a> Update devDependencies (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36767 ">#36767</a>)</li>
<li><a href="eae51cdf32
"><code>eae51cd</code></a> Fix various small typos in documentation (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36762 ">#36762</a>)</li>
<li><a href="705d6857ad
"><code>705d685</code></a> Fix typos in code (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36763 ">#36763</a>)</li>
<li><a href="154916ca2e
"><code>154916c</code></a> Fixing pagination compile issue</li>
<li><a href="9d5c834f94
"><code>9d5c834</code></a> Fix indentation in code sample</li>
<li><a href="150b374933
"><code>150b374</code></a> Fix active/focused button link text color</li>
<li><a href="d262a50c1f
"><code>d262a50</code></a> Add links to Webpack, Parcel, and Vite guides on homepage (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36760 ">#36760</a>)</li>
<li><a href="71cbb88f09
"><code>71cbb88</code></a> Support input groups in floating forms (<a href="https://github-redirect.dependabot.com/twbs/bootstrap/issues/36759 ">#36759</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/twbs/bootstrap/compare/v5.1.3...v5.2.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=bootstrap&package-manager=npm_and_yarn&previous-version=5.1.3&new-version=5.2.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
2 years ago
dependabot[bot]
a2a33e749f
Bump webpack-dev-server from 4.9.2 to 4.9.3 ( #2151 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.9.2 to 4.9.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.9.3</h2>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.2...v4.9.3 ">4.9.3</a> (2022-06-29)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>avoid creation unnecessary stream for static sockjs file (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4482 ">#4482</a>) (<a href="049b153b87
">049b153</a>)</li>
<li>history-api-fallback now supports HEAD requests and handles them the same as GET (<a href="8936082809
">8936082</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.2...v4.9.3 ">4.9.3</a> (2022-06-29)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>avoid creation unnecessary stream for static sockjs file (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4482 ">#4482</a>) (<a href="049b153b87
">049b153</a>)</li>
<li>history-api-fallback now supports HEAD requests and handles them the same as GET (<a href="8936082809
">8936082</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="fa5e454d19
"><code>fa5e454</code></a> chore(release): 4.9.3</li>
<li><a href="42facd28eb
"><code>42facd2</code></a> chore(deps-dev): bump <code>@babel/plugin-transform-object-assign</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4506 ">#4506</a>)</li>
<li><a href="257549bd8a
"><code>257549b</code></a> chore(deps-dev): bump <code>@babel/cli</code> from 7.17.10 to 7.18.6 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4507 ">#4507</a>)</li>
<li><a href="8936082809
"><code>8936082</code></a> fix: history-api-fallback now supports HEAD requests and handles them the sam...</li>
<li><a href="e0c4e7edf3
"><code>e0c4e7e</code></a> chore(deps-dev): bump <code>@babel/core</code> from 7.18.5 to 7.18.6 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4504 ">#4504</a>)</li>
<li><a href="0370b5a527
"><code>0370b5a</code></a> chore(deps-dev): bump <code>@babel/runtime</code> from 7.18.3 to 7.18.6 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4503 ">#4503</a>)</li>
<li><a href="73129c7f9d
"><code>73129c7</code></a> chore(deps-dev): bump <code>@babel/plugin-transform-runtime</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4505 ">#4505</a>)</li>
<li><a href="0e0100201c
"><code>0e01002</code></a> chore(deps-dev): bump <code>@babel/preset-env</code> from 7.18.2 to 7.18.6 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4502 ">#4502</a>)</li>
<li><a href="8866300f05
"><code>8866300</code></a> refactor: move scripts to same folder (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4500 ">#4500</a>)</li>
<li><a href="7f1f2027dc
"><code>7f1f202</code></a> chore(deps-dev): bump core-js from 3.23.2 to 3.23.3 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4499 ">#4499</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.2...v4.9.3 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.9.2&new-version=4.9.3 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
80e804c8fd
Bump prettier from 2.7.0 to 2.7.1 ( #2126 )
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.7.0 to 2.7.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/releases ">prettier's releases</a>.</em></p>
<blockquote>
<h2>2.7.1</h2>
<p>🔗 <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md#271 ">Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md ">prettier's changelog</a>.</em></p>
<blockquote>
<h1>2.7.1</h1>
<p><a href="https://github.com/prettier/prettier/compare/2.7.0...2.7.1 ">diff</a></p>
<h4>Keep useful empty lines in description (<a href="https://github-redirect.dependabot.com/prettier/prettier/pull/13013 ">#13013</a> by <a href="https://github.com/chimurai "><code>@chimurai</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="graphql"><code># Input
"""
First line
<p>Second Line
"""
type Person {
name: String
}
</code></pre></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="eeed611c72
"><code>eeed611</code></a> Release 2.7.1</li>
<li><a href="794d9d1558
"><code>794d9d1</code></a> bugfix(graphql): Keep useful empty lines in description (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/13013 ">#13013</a>)</li>
<li><a href="dd2af6f053
"><code>dd2af6f</code></a> Fix <code>--skip-dependencies-install</code></li>
<li><a href="b21772baaa
"><code>b21772b</code></a> Allow skip depencies install & set repo</li>
<li><a href="5530ad24b9
"><code>5530ad2</code></a> Merge branch 'main' of github.com:prettier/prettier</li>
<li><a href="c7c99305e9
"><code>c7c9930</code></a> Clean changelog</li>
<li><a href="448786fe35
"><code>448786f</code></a> Revert changes in release script</li>
<li><a href="6b388faa50
"><code>6b388fa</code></a> Add truncate</li>
<li><a href="109333ad99
"><code>109333a</code></a> Git blame ignore 2.7.0</li>
<li><a href="59ec4f2ef4
"><code>59ec4f2</code></a> Bump Prettier dependency to 2.7.0</li>
<li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/2.7.0...2.7.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=2.7.0&new-version=2.7.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
69f806d99d
Bump prettier from 2.6.2 to 2.7.0 ( #2120 )
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.6.2 to 2.7.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/releases ">prettier's releases</a>.</em></p>
<blockquote>
<h2>2.7.0</h2>
<p><a href="https://github.com/prettier/prettier/compare/2.7.0...2.7.0 ">diff</a></p>
<p>🔗 <a href="https://prettier.io/blog/2022/06/14/2.7.0.html ">Release note</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md ">prettier's changelog</a>.</em></p>
<blockquote>
<h1>2.7.0</h1>
<p><a href="https://github.com/prettier/prettier/compare/2.6.2...2.7.0 ">diff</a></p>
<p>🔗 <a href="https://prettier.io/blog/2022/06/14/2.7.0.html ">Release Notes</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="13dcc16330
"><code>13dcc16</code></a> Release 2.7.0</li>
<li><a href="00ee6fb6f8
"><code>00ee6fb</code></a> Skip depenedencies install</li>
<li><a href="d2bcaea121
"><code>d2bcaea</code></a> Throw errors for invalid <code>TSEmptyBodyFunctionExpression</code> node (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12982 ">#12982</a>)</li>
<li><a href="1bec824556
"><code>1bec824</code></a> Revert "print as instead of colon for babel-ts parser" (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12995 ">#12995</a>)</li>
<li><a href="2316e2fecd
"><code>2316e2f</code></a> Update <code>linguist-language</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12994 ">#12994</a>)</li>
<li><a href="e5868ad368
"><code>e5868ad</code></a> Update changelog</li>
<li><a href="fdccc0f48e
"><code>fdccc0f</code></a> Add <code>--cache</code> CLI option (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12800 ">#12800</a>)</li>
<li><a href="97bab8f984
"><code>97bab8f</code></a> Update <code>angular-estree-parser</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12993 ">#12993</a>)</li>
<li><a href="7f9a08762d
"><code>7f9a087</code></a> Update dependency flow-parser to v0.180.0 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12990 ">#12990</a>)</li>
<li><a href="aa1d536e29
"><code>aa1d536</code></a> Build(deps): Bump tmpl from 1.0.4 to 1.0.5 in /scripts/release (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12984 ">#12984</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/2.6.2...2.7.0 ">compare view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a href="https://www.npmjs.com/~prettier-bot ">prettier-bot</a>, a new releaser for prettier since your current version.</p>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=2.6.2&new-version=2.7.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
0e0ee49f95
Bump webpack-cli from 4.9.2 to 4.10.0 ( #2118 )
...
Bumps [webpack-cli](https://github.com/webpack/webpack-cli ) from 4.9.2 to 4.10.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-cli/releases ">webpack-cli's releases</a>.</em></p>
<blockquote>
<h2>v4.10.0</h2>
<h1><a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@4.9.2...webpack-cli@4.10.0 ">4.10.0</a> (2022-06-13)</h1>
<h3>Bug Fixes</h3>
<ul>
<li>changeTime is already in milliseconds (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3198 ">#3198</a>) (<a href="d390d32fe0
">d390d32</a>)</li>
<li>improve parsing of <code>--env</code> flag (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3286 ">#3286</a>) (<a href="402c0fe9d4
">402c0fe</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>added types (<a href="8ec1375092
">8ec1375</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-cli/blob/master/CHANGELOG.md ">webpack-cli's changelog</a>.</em></p>
<blockquote>
<h1><a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@4.9.2...webpack-cli@4.10.0 ">4.10.0</a> (2022-06-13)</h1>
<h3>Bug Fixes</h3>
<ul>
<li>changeTime is already in milliseconds (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3198 ">#3198</a>) (<a href="d390d32fe0
">d390d32</a>)</li>
<li>improve parsing of <code>--env</code> flag (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3286 ">#3286</a>) (<a href="402c0fe9d4
">402c0fe</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>added types (<a href="8ec1375092
">8ec1375</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="20882d4634
"><code>20882d4</code></a> chore(release): publish new version</li>
<li><a href="22f013b0f1
"><code>22f013b</code></a> docs: remove redundant link (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3292 ">#3292</a>)</li>
<li><a href="3e1df05713
"><code>3e1df05</code></a> chore: update package.json (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3289 ">#3289</a>)</li>
<li><a href="402c0fe9d4
"><code>402c0fe</code></a> fix: improve parsing of <code>--env</code> flag (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3286 ">#3286</a>)</li>
<li><a href="ce7352d840
"><code>ce7352d</code></a> chore: disable length related <code>commitlint</code> rules (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3287 ">#3287</a>)</li>
<li><a href="652cc70216
"><code>652cc70</code></a> feat: add summary to smoketests (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3288 ">#3288</a>)</li>
<li><a href="1072e3880e
"><code>1072e38</code></a> docs: update options (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3285 ">#3285</a>)</li>
<li><a href="6075c636ce
"><code>6075c63</code></a> chore(deps-dev): bump <code>@types/node</code></li>
<li><a href="979dbade27
"><code>979dbad</code></a> chore(deps-dev): bump typescript-eslint</li>
<li><a href="9941274f22
"><code>9941274</code></a> chore(deps-dev): bump webpack-dev-server from 4.9.1 to 4.9.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-cli/issues/3282 ">#3282</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-cli/compare/webpack-cli@4.9.2...webpack-cli@4.10.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-cli&package-manager=npm_and_yarn&previous-version=4.9.2&new-version=4.10.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
Iban Eguia
1dbd31e2b7
Added changelog, updated dependencies, bumped version number for 0.15 ( #2102 )
...
This Pull Request bumps the version number to 0.15, adds the changelog for this new versions and updates all dependencies to the latest versions.
3 years ago
dependabot[bot]
5002b9b8e4
Bump webpack-dev-server from 4.9.1 to 4.9.2 ( #2105 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.9.1 to 4.9.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.9.2</h2>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.1...v4.9.2 ">4.9.2</a> (2022-06-06)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>add <code>@types/serve-static</code> to dependencies (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4468 ">#4468</a>) (<a href="af83deb199
">af83deb</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.1...v4.9.2 ">4.9.2</a> (2022-06-06)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>add <code>@types/serve-static</code> to dependencies (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4468 ">#4468</a>) (<a href="af83deb199
">af83deb</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="297f8f0417
"><code>297f8f0</code></a> chore(release): 4.9.2</li>
<li><a href="af83deb199
"><code>af83deb</code></a> fix: add <code>@types/serve-static</code> to dependencies (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4468 ">#4468</a>)</li>
<li><a href="07aaa4533b
"><code>07aaa45</code></a> chore(deps-dev): bump typescript from 4.7.2 to 4.7.3 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4474 ">#4474</a>)</li>
<li><a href="8b18bd1146
"><code>8b18bd1</code></a> chore(deps): bump colorette from 2.0.16 to 2.0.17 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4473 ">#4473</a>)</li>
<li><a href="4ee117c421
"><code>4ee117c</code></a> chore(deps-dev): bump webpack from 5.72.1 to 5.73.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4472 ">#4472</a>)</li>
<li><a href="cb1393643e
"><code>cb13936</code></a> chore(deps-dev): bump core-js from 3.22.7 to 3.22.8 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4471 ">#4471</a>)</li>
<li><a href="341dc60551
"><code>341dc60</code></a> chore(deps-dev): bump lint-staged from 12.4.3 to 12.5.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4470 ">#4470</a>)</li>
<li>See full diff in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.1...v4.9.2 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.9.1&new-version=4.9.2 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
6fdac9e632
Bump webpack from 5.72.1 to 5.73.0 ( #2101 )
...
Bumps [webpack](https://github.com/webpack/webpack ) from 5.72.1 to 5.73.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack/releases ">webpack's releases</a>.</em></p>
<blockquote>
<h2>v5.73.0</h2>
<h1>Features</h1>
<ul>
<li>add options for default <code>dynamicImportMode</code> and prefetch and preload</li>
<li>add support for <code>import { createRequire } from "module"</code> in source code</li>
</ul>
<h1>Bugfixes</h1>
<ul>
<li>fix code generation of e. g. <code>return"field"in Module</code></li>
<li>fix performance of large JSON modules</li>
<li>fix performance of async modules evaluation</li>
</ul>
<h1>Developer Experience</h1>
<ul>
<li>export <code>PathData</code> in typings</li>
<li>improve error messages with more details</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="36051a5ca7
"><code>36051a5</code></a> 5.73.0</li>
<li><a href="520d31473c
"><code>520d314</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15899 ">#15899</a> from webpack/bugfix/async-modules-performance</li>
<li><a href="096efc3821
"><code>096efc3</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15801 ">#15801</a> from webpack/refactor-json-modules</li>
<li><a href="b8748cfe14
"><code>b8748cf</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15873 ">#15873</a> from webpack/more-informative-error</li>
<li><a href="b1cc471f86
"><code>b1cc471</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15888 ">#15888</a> from webpack/feature/issue-13695</li>
<li><a href="509a060025
"><code>509a060</code></a> fix quadratic evaluation performance of async modules</li>
<li><a href="cc0cd60909
"><code>cc0cd60</code></a> more informative error when emitting multiple assets</li>
<li><a href="e71d3b49fe
"><code>e71d3b4</code></a> more informative error in ProvideSharedPlugin</li>
<li><a href="aa76e823b0
"><code>aa76e82</code></a> fix discussions</li>
<li><a href="2738eebc78
"><code>2738eeb</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15579 ">#15579</a> from webpack/support-create-require</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack/compare/v5.72.1...v5.73.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack&package-manager=npm_and_yarn&previous-version=5.72.1&new-version=5.73.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
758a1ed4a9
Bump terser-webpack-plugin from 5.3.1 to 5.3.3 ( #2099 )
...
Bumps [terser-webpack-plugin](https://github.com/webpack-contrib/terser-webpack-plugin ) from 5.3.1 to 5.3.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/releases ">terser-webpack-plugin's releases</a>.</em></p>
<blockquote>
<h2>v5.3.3</h2>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.2...v5.3.3 ">5.3.3</a> (2022-06-02)</h3>
<h3>Fixes</h3>
<ul>
<li>fix broken release</li>
</ul>
<h2>v5.3.2</h2>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.1...v5.3.2 ">5.3.2</a> (2022-06-02)</h3>
<h3>Chore</h3>
<ul>
<li>switched to <code>@jridgewell/source-map</code> for error generation</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/terser-webpack-plugin/blob/master/CHANGELOG.md ">terser-webpack-plugin's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.2...v5.3.3 ">5.3.3</a> (2022-06-02)</h3>
<h3>Fixes</h3>
<ul>
<li>fix broken release</li>
</ul>
<h3><a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.1...v5.3.2 ">5.3.2</a> (2022-06-02)</h3>
<h3>Chore</h3>
<ul>
<li>switched to <code>@jridgewell/source-map</code> for error generation</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="2b2111faa5
"><code>2b2111f</code></a> chore(release): 5.3.3</li>
<li><a href="e2b9a45782
"><code>e2b9a45</code></a> chore(release): 5.3.2</li>
<li><a href="f61bc5da07
"><code>f61bc5d</code></a> refactor: replace deprecated String.prototype.substr() (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/479 ">#479</a>)</li>
<li><a href="bd10e13418
"><code>bd10e13</code></a> ci: node.js v18 (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/490 ">#490</a>)</li>
<li><a href="6020a94544
"><code>6020a94</code></a> perf: replace <code>source-map</code> package with <code>@jridgewell/trace-mapping</code> (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/489 ">#489</a>)</li>
<li><a href="66fdec85d7
"><code>66fdec8</code></a> docs: remove old badge (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/488 ">#488</a>)</li>
<li><a href="11712b940c
"><code>11712b9</code></a> chore: update github actions (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/487 ">#487</a>)</li>
<li><a href="463ed9e3ec
"><code>463ed9e</code></a> ci: don't install webpack again (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/483 ">#483</a>)</li>
<li><a href="f259590b49
"><code>f259590</code></a> chore(deps): bump minimist from 1.2.5 to 1.2.6 (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/480 ">#480</a>)</li>
<li><a href="3d6539f632
"><code>3d6539f</code></a> docs(readme): add types (<a href="https://github-redirect.dependabot.com/webpack-contrib/terser-webpack-plugin/issues/477 ">#477</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack-contrib/terser-webpack-plugin/compare/v5.3.1...v5.3.3 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=terser-webpack-plugin&package-manager=npm_and_yarn&previous-version=5.3.1&new-version=5.3.3 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
86aae26236
Bump webpack-dev-server from 4.9.0 to 4.9.1 ( #2096 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.9.0 to 4.9.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.9.1</h2>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.0...v4.9.1 ">4.9.1</a> (2022-05-31)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>security problem with sockjs (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4465 ">#4465</a>) (<a href="e765182e42
">e765182</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.0...v4.9.1 ">4.9.1</a> (2022-05-31)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>security problem with sockjs (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4465 ">#4465</a>) (<a href="e765182e42
">e765182</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="511f51a872
"><code>511f51a</code></a> chore(release): 4.9.1</li>
<li><a href="e765182e42
"><code>e765182</code></a> fix: security problem with sockjs (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4465 ">#4465</a>)</li>
<li><a href="e2113ed329
"><code>e2113ed</code></a> chore(deps-dev): bump sockjs-client from 1.6.0 to 1.6.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4464 ">#4464</a>)</li>
<li><a href="3166fcdaf0
"><code>3166fcd</code></a> chore(deps-dev): bump memfs from 3.4.3 to 3.4.4 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4463 ">#4463</a>)</li>
<li><a href="df7ce6e8f6
"><code>df7ce6e</code></a> chore: update deps and types (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4461 ">#4461</a>)</li>
<li><a href="b3511e0139
"><code>b3511e0</code></a> chore(deps-dev): bump core-js from 3.22.6 to 3.22.7 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4452 ">#4452</a>)</li>
<li><a href="c90438da91
"><code>c90438d</code></a> chore(deps-dev): bump lint-staged from 12.4.1 to 12.4.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4451 ">#4451</a>)</li>
<li><a href="a414b263ec
"><code>a414b26</code></a> chore(deps-dev): bump <code>@babel/eslint-parser</code> from 7.17.0 to 7.18.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4459 ">#4459</a>)</li>
<li><a href="c562d31676
"><code>c562d31</code></a> chore(deps-dev): bump <code>@babel/preset-env</code></li>
<li><a href="e8f8008995
"><code>e8f8008</code></a> chore(deps-dev): bump <code>@babel/core</code></li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.9.0...v4.9.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.9.0&new-version=4.9.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
f3db18fc54
Bump copy-webpack-plugin from 10.2.4 to 11.0.0 ( #2077 )
...
Bumps [copy-webpack-plugin](https://github.com/webpack-contrib/copy-webpack-plugin ) from 10.2.4 to 11.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/copy-webpack-plugin/releases ">copy-webpack-plugin's releases</a>.</em></p>
<blockquote>
<h2>v11.0.0</h2>
<h2><a href="https://github.com/webpack-contrib/copy-webpack-plugin/compare/v10.2.4...v11.0.0 ">11.0.0</a> (2022-05-17)</h2>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li>minimum supported <code>Node.js</code> version is <code>14.15.0</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack-contrib/copy-webpack-plugin/blob/master/CHANGELOG.md ">copy-webpack-plugin's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/webpack-contrib/copy-webpack-plugin/compare/v10.2.4...v11.0.0 ">11.0.0</a> (2022-05-17)</h2>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li>minimum supported <code>Node.js</code> version is <code>14.15.0</code></li>
</ul>
<h3>build</h3>
<ul>
<li>drop node v12 (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/691 ">#691</a>) (<a href="675c676d96
">675c676</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="f3b2c2419c
"><code>f3b2c24</code></a> chore(release): 11.0.0</li>
<li><a href="8424ca82c1
"><code>8424ca8</code></a> chore(deps): regenerate lock file (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/693 ">#693</a>)</li>
<li><a href="675c676d96
"><code>675c676</code></a> build: drop node v12 (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/691 ">#691</a>)</li>
<li><a href="a2b1f199e8
"><code>a2b1f19</code></a> chore: update gitub actions (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/692 ">#692</a>)</li>
<li><a href="238c062ffe
"><code>238c062</code></a> chore: upgrade dependencies to the latest version (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/688 ">#688</a>)</li>
<li><a href="e27006edc3
"><code>e27006e</code></a> ci: remove node v17 (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/687 ">#687</a>)</li>
<li><a href="e50d708535
"><code>e50d708</code></a> chore: add node 18 to workflow (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/686 ">#686</a>)</li>
<li><a href="f1a91e6c1a
"><code>f1a91e6</code></a> ci: don't install webpack again (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/680 ">#680</a>)</li>
<li><a href="64cf06f139
"><code>64cf06f</code></a> docs: add path string to options signature (<a href="https://github-redirect.dependabot.com/webpack-contrib/copy-webpack-plugin/issues/683 ">#683</a>)</li>
<li><a href="4b18a6be39
"><code>4b18a6b</code></a> docs: improve readme</li>
<li>Additional commits viewable in <a href="https://github.com/webpack-contrib/copy-webpack-plugin/compare/v10.2.4...v11.0.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=copy-webpack-plugin&package-manager=npm_and_yarn&previous-version=10.2.4&new-version=11.0.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
27db657983
Bump webpack from 5.72.0 to 5.72.1 ( #2070 )
...
Bumps [webpack](https://github.com/webpack/webpack ) from 5.72.0 to 5.72.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack/releases ">webpack's releases</a>.</em></p>
<blockquote>
<h2>v5.72.1</h2>
<h1>Bugfixes</h1>
<ul>
<li>fix <code>__webpack_nonce__</code> with HMR</li>
<li>fix <code>in</code> operator in some cases</li>
<li>fix json parsing error messages</li>
<li>fix module concatenation with using <code>this.importModule</code></li>
<li>upgrade enhanced-resolve</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="08ecfbbc03
"><code>08ecfbb</code></a> 5.72.1</li>
<li><a href="ada9c0b3a1
"><code>ada9c0b</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15802 ">#15802</a> from webpack/fix-nonce</li>
<li><a href="ce56e3b61c
"><code>ce56e3b</code></a> add NonceRuntimeModule</li>
<li><a href="3ad4fcac25
"><code>3ad4fca</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15689 ">#15689</a> from webpack/fix-inmemory-cache</li>
<li><a href="ccf8bf53e2
"><code>ccf8bf5</code></a> add comments to infrastructure-log</li>
<li><a href="293e677b35
"><code>293e677</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15660 ">#15660</a> from webpack/add-provided-info-tests</li>
<li><a href="0456807b72
"><code>0456807</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15673 ">#15673</a> from Semigradsky/replace-dependency</li>
<li><a href="0791f77b04
"><code>0791f77</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15678 ">#15678</a> from webpack/remove-infrastructure-log</li>
<li><a href="390dd06209
"><code>390dd06</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15681 ">#15681</a> from webpack/fix-concatenation-with-import-module</li>
<li><a href="0d408d1c7f
"><code>0d408d1</code></a> fix modules concatenation with importModule usage</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack/compare/v5.72.0...v5.72.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack&package-manager=npm_and_yarn&previous-version=5.72.0&new-version=5.72.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
0e49ce863b
Bump webpack-dev-server from 4.8.1 to 4.9.0 ( #2061 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.8.1 to 4.9.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.9.0</h2>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.8.1...v4.9.0 ">4.9.0</a> (2022-05-04)</h2>
<h3>Features</h3>
<ul>
<li>support Trusted Types for client overlay (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4404 ">#4404</a>) (<a href="8132e1d029
">8132e1d</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>ie11 runtime (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4403 ">#4403</a>) (<a href="256d5fb5fe
">256d5fb</a>)</li>
<li>replace portfinder with custom implementation and fix security problem (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4384 ">#4384</a>) (<a href="eea50f342e
">eea50f3</a>)</li>
<li>use the host in options to check if port is available (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4385 ">#4385</a>) (<a href="a10c7cfd29
">a10c7cf</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.8.1...v4.9.0 ">4.9.0</a> (2022-05-04)</h2>
<h3>Features</h3>
<ul>
<li>support Trusted Types for client overlay (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4404 ">#4404</a>) (<a href="8132e1d029
">8132e1d</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>ie11 runtime (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4403 ">#4403</a>) (<a href="256d5fb5fe
">256d5fb</a>)</li>
<li>replace portfinder with custom implementation and fix security problem (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4384 ">#4384</a>) (<a href="eea50f342e
">eea50f3</a>)</li>
<li>use the host in options to check if port is available (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4385 ">#4385</a>) (<a href="a10c7cfd29
">a10c7cf</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="4340c73fbc
"><code>4340c73</code></a> chore(release): 4.9.0</li>
<li><a href="2b386fb671
"><code>2b386fb</code></a> test: update (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4427 ">#4427</a>)</li>
<li><a href="925370ec6c
"><code>925370e</code></a> chore(deps-dev): bump marked from 4.0.14 to 4.0.15 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4426 ">#4426</a>)</li>
<li><a href="8132e1d029
"><code>8132e1d</code></a> feat: support Trusted Types for client overlay (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4404 ">#4404</a>)</li>
<li><a href="79536ab657
"><code>79536ab</code></a> chore(deps-dev): bump core-js from 3.22.3 to 3.22.4 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4425 ">#4425</a>)</li>
<li><a href="c2fee3b585
"><code>c2fee3b</code></a> chore(deps-dev): bump <code>@babel/preset-env</code> from 7.16.11 to 7.17.10 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4422 ">#4422</a>)</li>
<li><a href="a6a367a4ce
"><code>a6a367a</code></a> chore(deps-dev): bump <code>@babel/plugin-transform-runtime</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4423 ">#4423</a>)</li>
<li><a href="710f2e2652
"><code>710f2e2</code></a> chore: bump <code>@commitlint/config-conventional</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4411 ">#4411</a>)</li>
<li><a href="e42d691de9
"><code>e42d691</code></a> chore(deps): bump ws from 8.5.0 to 8.6.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4418 ">#4418</a>)</li>
<li><a href="401493d9b0
"><code>401493d</code></a> chore(deps): bump express from 4.18.0 to 4.18.1 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4419 ">#4419</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.8.1...v4.9.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.8.1&new-version=4.9.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
67a2dd84ca
Bump async from 2.6.3 to 2.6.4 ( #2047 )
...
Bumps [async](https://github.com/caolan/async ) from 2.6.3 to 2.6.4.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md ">async's changelog</a>.</em></p>
<blockquote>
<h1>v2.6.4</h1>
<ul>
<li>Fix potential prototype pollution exploit (<a href="https://github-redirect.dependabot.com/caolan/async/issues/1828 ">#1828</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="c6bdaca4f9
"><code>c6bdaca</code></a> Version 2.6.4</li>
<li><a href="8870da9d50
"><code>8870da9</code></a> Update built files</li>
<li><a href="4df6754ef4
"><code>4df6754</code></a> update changelog</li>
<li><a href="8f7f90342a
"><code>8f7f903</code></a> Fix prototype pollution vulnerability (<a href="https://github-redirect.dependabot.com/caolan/async/issues/1828 ">#1828</a>)</li>
<li>See full diff in <a href="https://github.com/caolan/async/compare/v2.6.3...v2.6.4 ">compare view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a href="https://www.npmjs.com/~hargasinski ">hargasinski</a>, a new releaser for async since your current version.</p>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=async&package-manager=npm_and_yarn&previous-version=2.6.3&new-version=2.6.4 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/boa-dev/boa/network/alerts ).
</details>
3 years ago
Iban Eguia
8d746ecc0b
Upgraded wasm-bindgen ( #2020 )
...
This Pull Request supersedes #2018 and #2017 .
It changes the following:
- Updates the wasm-bindgen dependency now that a new version without the clippy bug has been released
- Updates all dependencies to their latest versions
3 years ago
dependabot[bot]
a1b5191ec6
Bump webpack-dev-server from 4.8.0 to 4.8.1 ( #2013 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.8.0 to 4.8.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.8.1</h2>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.8.0...v4.8.1 ">4.8.1</a> (2022-04-06)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>types (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4373 ">#4373</a>) (<a href="f6fe6be276
">f6fe6be</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h3><a href="https://github.com/webpack/webpack-dev-server/compare/v4.8.0...v4.8.1 ">4.8.1</a> (2022-04-06)</h3>
<h3>Bug Fixes</h3>
<ul>
<li>types (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4373 ">#4373</a>) (<a href="f6fe6be276
">f6fe6be</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="cfbba4a7e3
"><code>cfbba4a</code></a> chore(release): 4.8.1</li>
<li><a href="f6fe6be276
"><code>f6fe6be</code></a> fix: types (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4373 ">#4373</a>)</li>
<li><a href="56410ba7f9
"><code>56410ba</code></a> chore(deps-dev): bump eslint-plugin-import</li>
<li><a href="58bdd5155d
"><code>58bdd51</code></a> chore(deps-dev): bump prettier from 2.6.1 to 2.6.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4364 ">#4364</a>)</li>
<li>See full diff in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.8.0...v4.8.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.8.0&new-version=4.8.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
aeb5460bd6
Bump webpack from 5.71.0 to 5.72.0 ( #2016 )
...
Bumps [webpack](https://github.com/webpack/webpack ) from 5.71.0 to 5.72.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack/releases ">webpack's releases</a>.</em></p>
<blockquote>
<h2>v5.72.0</h2>
<h1>Features</h1>
<ul>
<li>make cache warnings caused by build errors less verbose</li>
<li>Allow banner to be placed as a footer with the BannerPlugin</li>
<li>allow to concatenate asset modules</li>
</ul>
<h1>Bugfixes</h1>
<ul>
<li>fix RemoteModules when using HMR (Module Federation + HMR)</li>
<li>throw error when using module concatenation and cacheUnaffected</li>
<li>fix <code>in</code> operator with nested exports</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="d3a0f8de03
"><code>d3a0f8d</code></a> 5.72.0</li>
<li><a href="360373d76e
"><code>360373d</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15563 ">#15563</a> from cool-little-fish/fix-12408</li>
<li><a href="b9b73c5418
"><code>b9b73c5</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15634 ">#15634</a> from webpack/fix/issue-15633</li>
<li><a href="216c3daa4e
"><code>216c3da</code></a> fix ExportsInfo</li>
<li><a href="cb639b3efc
"><code>cb639b3</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15624 ">#15624</a> from webpack/add-warning-when-cache-unaffected-and-...</li>
<li><a href="c38caa2d82
"><code>c38caa2</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15515 ">#15515</a> from webpack/feat/concatenate-assets</li>
<li><a href="99a5793ca8
"><code>99a5793</code></a> throw error when using module concatenation and cacheUnaffected</li>
<li><a href="19d1a9384e
"><code>19d1a93</code></a> fix lint and tests</li>
<li><a href="05ebf5bba6
"><code>05ebf5b</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15617 ">#15617</a> from DavidTanner/bannerAsFooter</li>
<li><a href="2a58ce7883
"><code>2a58ce7</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15542 ">#15542</a> from wangjinyang/bugfix/mf-hmr-error</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack/compare/v5.71.0...v5.72.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack&package-manager=npm_and_yarn&previous-version=5.71.0&new-version=5.72.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
b0490d421e
Bump webpack-dev-server from 4.7.4 to 4.8.0 ( #2011 )
...
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server ) from 4.7.4 to 4.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/releases ">webpack-dev-server's releases</a>.</em></p>
<blockquote>
<h2>v4.8.0</h2>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.7.4...v4.8.0 ">4.8.0</a> (2022-04-05)</h2>
<h3>Features</h3>
<ul>
<li>export initialized socket client (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4304 ">#4304</a>) (<a href="7920364d6b
">7920364</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>update description for <code>--no-client-reconnect</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4248 ">#4248</a>) (<a href="317648df21
">317648d</a>)</li>
<li>update description for <code>--no-client</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4250 ">#4250</a>) (<a href="c3b6690770
">c3b6690</a>)</li>
<li>update description for <code>--no-history-api-fallback</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4277 ">#4277</a>) (<a href="d63a0a2987
">d63a0a2</a>)</li>
<li>update negated descriptions for more options (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4287 ">#4287</a>) (<a href="c64bd94fb7
">c64bd94</a>)</li>
<li>update schema to have <code>negatedDescription</code> only for type <code>boolean</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4280 ">#4280</a>) (<a href="fcf8e8e6a9
">fcf8e8e</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md ">webpack-dev-server's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/webpack/webpack-dev-server/compare/v4.7.4...v4.8.0 ">4.8.0</a> (2022-04-05)</h2>
<h3>Features</h3>
<ul>
<li>export initialized socket client (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4304 ">#4304</a>) (<a href="7920364d6b
">7920364</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>update description for <code>--no-client-reconnect</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4248 ">#4248</a>) (<a href="317648df21
">317648d</a>)</li>
<li>update description for <code>--no-client</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4250 ">#4250</a>) (<a href="c3b6690770
">c3b6690</a>)</li>
<li>update description for <code>--no-history-api-fallback</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4277 ">#4277</a>) (<a href="d63a0a2987
">d63a0a2</a>)</li>
<li>update negated descriptions for more options (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4287 ">#4287</a>) (<a href="c64bd94fb7
">c64bd94</a>)</li>
<li>update schema to have <code>negatedDescription</code> only for type <code>boolean</code> (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4280 ">#4280</a>) (<a href="fcf8e8e6a9
">fcf8e8e</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="5aad1e72ee
"><code>5aad1e7</code></a> chore(release): 4.8.0</li>
<li><a href="28ad7edf37
"><code>28ad7ed</code></a> chore(deps): bump graceful-fs from 4.2.9 to 4.2.10 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4368 ">#4368</a>)</li>
<li><a href="7920364d6b
"><code>7920364</code></a> feat: export initialized socket client (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4304 ">#4304</a>)</li>
<li><a href="4e7800ea17
"><code>4e7800e</code></a> chore: update webpack (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4367 ">#4367</a>)</li>
<li><a href="fbda2a805b
"><code>fbda2a8</code></a> chore(deps-dev): bump body-parser from 1.19.2 to 1.20.0 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4366 ">#4366</a>)</li>
<li><a href="67c080b069
"><code>67c080b</code></a> chore(deps-dev): bump puppeteer from 13.5.1 to 13.5.2 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4361 ">#4361</a>)</li>
<li><a href="56ec41132b
"><code>56ec411</code></a> chore(deps): bump html-entities from 2.3.2 to 2.3.3 (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4358 ">#4358</a>)</li>
<li><a href="ca8a53af6a
"><code>ca8a53a</code></a> chore: update deps and fix audit (<a href="https://github-redirect.dependabot.com/webpack/webpack-dev-server/issues/4356 ">#4356</a>)</li>
<li><a href="501f6aa441
"><code>501f6aa</code></a> chore(deps-dev): bump <code>@babel/runtime</code></li>
<li><a href="7d2b4f0082
"><code>7d2b4f0</code></a> chore(deps-dev): bump <code>@babel/core</code></li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-server/compare/v4.7.4...v4.8.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack-dev-server&package-manager=npm_and_yarn&previous-version=4.7.4&new-version=4.8.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
e72c7c1bf9
Bump prettier from 2.6.1 to 2.6.2 ( #2005 )
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.6.1 to 2.6.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/releases ">prettier's releases</a>.</em></p>
<blockquote>
<h2>2.6.2</h2>
<p>🔗 <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md#262 ">Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md ">prettier's changelog</a>.</em></p>
<blockquote>
<h1>2.6.2</h1>
<p><a href="https://github.com/prettier/prettier/compare/2.6.1...2.6.2 ">diff</a></p>
<h4>Fix LESS/SCSS format error (<a href="https://github-redirect.dependabot.com/prettier/prettier/pull/12536 ">#12536</a> by <a href="https://github.com/fisker "><code>@fisker</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="less"><code>// Input
.background-gradient(@cut ) {
background: linear-gradient(
to right,
@white 0%,
@white (@cut - 0.01%),
@portal-background @cut ,
@portal-background 100%
);
}
<p>// Prettier 2.6.1
TypeError: Cannot read properties of undefined (reading 'endOffset')</p>
<p>// Prettier 2.6.2
.background-gradient(<a href="https://github.com/cut "><code>@cut</code></a>) {
background: linear-gradient(
to right,
<a href="https://github.com/white "><code>@white</code></a> 0%,
<a href="https://github.com/white "><code>@white</code></a> (<a href="https://github.com/cut "><code>@cut</code></a> - 0.01%),
<a href="https://github.com/portal-background "><code>@portal-background</code></a> <a href="https://github.com/cut "><code>@cut</code></a>,
<a href="https://github.com/portal-background "><code>@portal-background</code></a> 100%
);
}
</code></pre></p>
<h4>Update <code>meriyah</code> to fix several bugs (<a href="https://github-redirect.dependabot.com/prettier/prettier/pull/12567 ">#12567</a> by <a href="https://github.com/fisker "><code>@fisker</code></a>, fixes in <a href="https://github.com/meriyah/meriyah/ "><code>meriyah</code></a> by <a href="https://github.com/3cp "><code>@3cp</code></a>)</h4>
<p>Fixes bugs when parsing following valid code:</p>
<pre lang="js"><code>foo(await bar());
</code></pre>
<pre lang="js"><code>const regex = /.*/ms;
</code></pre>
<pre lang="js"><code>const element = <p>{/w/.test(s)}</p>;
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="d6f82a024a
"><code>d6f82a0</code></a> Release 2.6.2</li>
<li><a href="2bca9d65f4
"><code>2bca9d6</code></a> Add new workflow to prevent updating <code>users.yml</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/11784 ">#11784</a>)</li>
<li><a href="378370a01e
"><code>378370a</code></a> Build(deps): Bump leven from 3.1.0 to 4.0.0 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/11349 ">#11349</a>)</li>
<li><a href="3c96a08176
"><code>3c96a08</code></a> Build(deps): Bump strip-ansi from 6.0.0 to 7.0.0 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/10731 ">#10731</a>)</li>
<li><a href="1bfb08f289
"><code>1bfb08f</code></a> Build(deps): Bump meriyah from 4.2.0 to 4.2.1 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12567 ">#12567</a>)</li>
<li><a href="9400c893a3
"><code>9400c89</code></a> Refactor: Add a wrapped <code>normalizeCliOptions</code> version for CLI usage (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12573 ">#12573</a>)</li>
<li><a href="5e3de4828d
"><code>5e3de48</code></a> Build(deps): Bump escape-string-regexp from 4.0.0 to 5.0.0 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/10725 ">#10725</a>)</li>
<li><a href="5d73acc42d
"><code>5d73acc</code></a> Build(deps-dev): Bump esbuild from 0.14.29 to 0.14.30 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12581 ">#12581</a>)</li>
<li><a href="e2eac0cb8a
"><code>e2eac0c</code></a> Move some bundle test code into <code>tests/</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12577 ">#12577</a>)</li>
<li><a href="7d33ed5452
"><code>7d33ed5</code></a> Build(deps-dev): Bump eslint-plugin-unicorn from 41.0.1 to 42.0.0 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12580 ">#12580</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/2.6.1...2.6.2 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=2.6.1&new-version=2.6.2 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
d1972a9160
Bump webpack from 5.70.0 to 5.71.0 ( #2004 )
...
Bumps [webpack](https://github.com/webpack/webpack ) from 5.70.0 to 5.71.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/webpack/webpack/releases ">webpack's releases</a>.</em></p>
<blockquote>
<h2>v5.71.0</h2>
<h1>Features</h1>
<ul>
<li>choose smarter default for <code>uniqueName</code> when using a <code>output.library</code> which includes placeholders</li>
<li>add support for expressions with <code>in</code> of a imported binding</li>
<li>generate UMD code with arrow functions when possible</li>
</ul>
<h1>Bugfixes</h1>
<ul>
<li>fix source map source names for ContextModule to be relative</li>
<li>fix <code>chunkLoading</code> option in module module</li>
<li>fix edge case where <code>evaluateExpression</code> returns <code>null</code></li>
<li>retain optional chaining in imported bindings</li>
<li>include runtime code for the base URI even if not using chunk loading</li>
<li>don't throw errors in persistent caching when importing node.js builtin modules via ESM</li>
<li>fix crash when using <code>lazy-once</code> Context modules</li>
<li>improve handling of context modules with multiple contexts</li>
<li>fix race condition HMR chunk loading when importing chunks during HMR updating</li>
<li>handle errors in <code>runAsChild</code> callback</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="c2079f7e76
"><code>c2079f7</code></a> 5.71.0</li>
<li><a href="4a0937fdd0
"><code>4a0937f</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15578 ">#15578</a> from webpack/feat/catch-error-in-run-as-child</li>
<li><a href="c3f5897df9
"><code>c3f5897</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15586 ">#15586</a> from webpack/bugfix/chunk-load-during-hmr</li>
<li><a href="c4f1e4e9f0
"><code>c4f1e4e</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15611 ">#15611</a> from webpack/bugfix/esm-build-deps</li>
<li><a href="ab40959467
"><code>ab40959</code></a> support node.js builtin modules in esm build dependencies</li>
<li><a href="e1179bf9bb
"><code>e1179bf</code></a> fix egde case where a HMR chunk is incorrectly downloaded when loading a unch...</li>
<li><a href="2c200d1656
"><code>2c200d1</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15585 ">#15585</a> from webpack/refactor/support-context-in-dependency</li>
<li><a href="3929e688a4
"><code>3929e68</code></a> fix discussions</li>
<li><a href="129477d11d
"><code>129477d</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15536 ">#15536</a> from webpack/fix/issue-15518</li>
<li><a href="5d8a9719ca
"><code>5d8a971</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/webpack/webpack/issues/15551 ">#15551</a> from webpack/fix/issue-15545</li>
<li>Additional commits viewable in <a href="https://github.com/webpack/webpack/compare/v5.70.0...v5.71.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=webpack&package-manager=npm_and_yarn&previous-version=5.70.0&new-version=5.71.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
3f3f0aae6e
Bump prettier from 2.6.0 to 2.6.1 ( #1977 )
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.6.0 to 2.6.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/releases ">prettier's releases</a>.</em></p>
<blockquote>
<h2>2.6.1</h2>
<p>🔗 <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md#261 ">Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md ">prettier's changelog</a>.</em></p>
<blockquote>
<h1>2.6.1</h1>
<p><a href="https://github.com/prettier/prettier/compare/2.6.0...2.6.1 ">diff</a></p>
<h4>Ignore <code>loglevel</code> when printing information (<a href="https://github-redirect.dependabot.com/prettier/prettier/pull/12477 ">#12477</a> by <a href="https://github.com/fisker "><code>@fisker</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="bash"><code></code></pre>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="ad505bf771
"><code>ad505bf</code></a> Release 2.6.1</li>
<li><a href="6128c5c4e4
"><code>6128c5c</code></a> Build: Fix <code>esbuildPluginReplaceModule</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12530 ">#12530</a>)</li>
<li><a href="11649270f6
"><code>1164927</code></a> Enable <code>unicorn/text-encoding-identifier-case</code> rule (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12526 ">#12526</a>)</li>
<li><a href="0e6c1d58d8
"><code>0e6c1d5</code></a> Enter OTP via <code>enquirer</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12528 ">#12528</a>)</li>
<li><a href="67edeeaf72
"><code>67edeea</code></a> Build(deps): Bump minimist from 1.2.5 to 1.2.6 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12513 ">#12513</a>)</li>
<li><a href="6664253b9e
"><code>6664253</code></a> Fix error when bundle prettier with webpack (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12511 ">#12511</a>)</li>
<li><a href="9e7f7b9295
"><code>9e7f7b9</code></a> Updated the State of JS Survey Results (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12350 ">#12350</a>)</li>
<li><a href="becb6c9b74
"><code>becb6c9</code></a> Fix non-idempotent formatting of function calls with complex type arguments (...</li>
<li><a href="1939f92be5
"><code>1939f92</code></a> Build(deps): Bump <code>@typescript-eslint/typescript-estree</code> (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12514 ">#12514</a>)</li>
<li><a href="6fece964c8
"><code>6fece96</code></a> Build(deps): Bump json5 from 2.2.0 to 2.2.1 (<a href="https://github-redirect.dependabot.com/prettier/prettier/issues/12515 ">#12515</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/2.6.0...2.6.1 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=2.6.0&new-version=2.6.1 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
3 years ago
dependabot[bot]
3549ea5046
Bump minimist from 1.2.5 to 1.2.6 ( #1978 )
...
Bumps [minimist](https://github.com/substack/minimist ) from 1.2.5 to 1.2.6.
<details>
<summary>Commits</summary>
<ul>
<li><a href="7efb22a518
"><code>7efb22a</code></a> 1.2.6</li>
<li><a href="ef88b9325f
"><code>ef88b93</code></a> security notice for additional prototype pollution issue</li>
<li><a href="c2b981977f
"><code>c2b9819</code></a> isConstructorOrProto adapted from PR</li>
<li><a href="bc8ecee438
"><code>bc8ecee</code></a> test from prototype pollution PR</li>
<li>See full diff in <a href="https://github.com/substack/minimist/compare/1.2.5...1.2.6 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=minimist&package-manager=npm_and_yarn&previous-version=1.2.5&new-version=1.2.6 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/boa-dev/boa/network/alerts ).
</details>
3 years ago
dependabot[bot]
3ad9d18d74
Bump node-forge from 1.2.1 to 1.3.0 ( #1969 )
...
Bumps [node-forge](https://github.com/digitalbazaar/forge ) from 1.2.1 to 1.3.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md ">node-forge's changelog</a>.</em></p>
<blockquote>
<h2>1.3.0 - 2022-03-17</h2>
<h3>Security</h3>
<ul>
<li>Three RSA PKCS#1 v1.5 signature verification issues were reported by Moosa
Yahyazadeh (<a href="mailto:moosa-yahyazadeh@uiowa.edu">moosa-yahyazadeh@uiowa.edu</a>).</li>
<li><strong>HIGH</strong>: Leniency in checking <code>digestAlgorithm</code> structure can lead to
signature forgery.
<ul>
<li>The code is lenient in checking the digest algorithm structure. This can
allow a crafted structure that steals padding bytes and uses unchecked
portion of the PKCS#1 encoded message to forge a signature when a low
public exponent is being used. For more information, please see
<a href="https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QE/ ">"Bleichenbacher's RSA signature forgery based on implementation
error"</a>
by Hal Finney.</li>
<li>CVE ID: <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24771 ">CVE-2022-24771</a></li>
<li>GHSA ID: <a href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-cfm4-qjh2-4765 ">GHSA-cfm4-qjh2-4765</a></li>
</ul>
</li>
<li><strong>HIGH</strong>: Failing to check tailing garbage bytes can lead to signature
forgery.
<ul>
<li>The code does not check for tailing garbage bytes after decoding a
<code>DigestInfo</code> ASN.1 structure. This can allow padding bytes to be removed
and garbage data added to forge a signature when a low public exponent is
being used. For more information, please see <a href="https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QE/ ">"Bleichenbacher's RSA
signature forgery based on implementation
error"</a>
by Hal Finney.</li>
<li>CVE ID: <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24772 ">CVE-2022-24772</a></li>
<li>GHSA ID: <a href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-x4jg-mjrx-434g ">GHSA-x4jg-mjrx-434g</a></li>
</ul>
</li>
<li><strong>MEDIUM</strong>: Leniency in checking type octet.
<ul>
<li><code>DigestInfo</code> is not properly checked for proper ASN.1 structure. This can
lead to successful verification with signatures that contain invalid
structures but a valid digest.</li>
<li>CVE ID: <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24773 ">CVE-2022-24773</a></li>
<li>GHSA ID: <a href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-2r2c-g63r-vccr ">GHSA-2r2c-g63r-vccr</a></li>
</ul>
</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>[asn1] Add fallback to pretty print invalid UTF8 data.</li>
<li>[asn1] <code>fromDer</code> is now more strict and will default to ensuring all input
bytes are parsed or throw an error. A new option <code>parseAllBytes</code> can disable
this behavior.
<ul>
<li><strong>NOTE</strong>: The previous behavior is being changed since it can lead to
security issues with crafted inputs. It is possible that code doing custom
DER parsing may need to adapt to this new behavior and optional flag.</li>
</ul>
</li>
<li>[rsa] Add and use a validator to check for proper structure of parsed ASN.1
<code>RSASSA-PKCS-v1_5</code> <code>DigestInfo</code> data. Additionally check that the hash
algorithm identifier is a known value from RFC 8017
<code>PKCS1-v1-5DigestAlgorithms</code>. An invalid <code>DigestInfo</code> or algorithm identifier
will now throw an error.
<ul>
<li><strong>NOTE</strong>: The previous lenient behavior is being changed to be more strict
since it could lead to security issues with crafted inputs. It is possible
that code may have to handle the errors from these stricter checks.</li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="6c5b90133d
"><code>6c5b901</code></a> Release 1.3.0.</li>
<li><a href="0f3972ad58
"><code>0f3972a</code></a> Update changelog.</li>
<li><a href="dc77b39dd3
"><code>dc77b39</code></a> Fix error checking.</li>
<li><a href="bb822c02df
"><code>bb822c0</code></a> Add advisory links.</li>
<li><a href="d4395fec83
"><code>d4395fe</code></a> Update changelog.</li>
<li><a href="a4405bb9d6
"><code>a4405bb</code></a> Improve signature verification tests.</li>
<li><a href="aa9372d6dd
"><code>aa9372d</code></a> Add missing RFC 8017 algorithm identifiers.</li>
<li><a href="3f0b49a057
"><code>3f0b49a</code></a> Fix signature verification issues.</li>
<li><a href="c20f309311
"><code>c20f309</code></a> Adjust remaining length.</li>
<li><a href="e27f61230f
"><code>e27f612</code></a> Remove unused option.</li>
<li>Additional commits viewable in <a href="https://github.com/digitalbazaar/forge/compare/v1.2.1...v1.3.0 ">compare view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=node-forge&package-manager=npm_and_yarn&previous-version=1.2.1&new-version=1.3.0 )](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/boa-dev/boa/network/alerts ).
</details>
3 years ago
jedel1043
f25ce46a1e
Migrate to NPM and cleanup Playground ( #1951 )
...
This Pull Request closes #1912 by migrating to a NPM based build, hopefully making it easier to contribute to the Playground.
Also, reduces the number of features of the editor, since most of them were support for other languages or features that don't make sense in a playground environment. This considerably reduces the number of fetched files per page load and the total size of the playground.
3 years ago