build(deps): bump the production-patch group across 1 directory with 9 updates#1556
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump the production-patch group across 1 directory with 9 updates#1556dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…9 updates Bumps the production-patch group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@bufbuild/protobuf](https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf) | `2.12.0` | `2.12.1` | | [fs-extra](https://github.com/jprichardson/node-fs-extra) | `11.3.5` | `11.3.6` | | [winston-loki](https://github.com/JaniAnttonen/winston-loki) | `6.1.4` | `6.1.5` | | [@scalar/express-api-reference](https://github.com/scalar/scalar/tree/HEAD/integrations/express) | `0.10.4` | `0.10.11` | | [graphql-tools](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/graphql-tools) | `9.0.28` | `9.0.33` | | [axios](https://github.com/axios/axios) | `1.18.0` | `1.18.1` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `9.0.1` | `9.0.3` | | [bson](https://github.com/mongodb/js-bson) | `7.3.0` | `7.3.1` | | [mongoose](https://github.com/Automattic/mongoose) | `9.7.1` | `9.7.4` | Updates `@bufbuild/protobuf` from 2.12.0 to 2.12.1 - [Release notes](https://github.com/bufbuild/protobuf-es/releases) - [Commits](https://github.com/bufbuild/protobuf-es/commits/v2.12.1/packages/protobuf) Updates `fs-extra` from 11.3.5 to 11.3.6 - [Changelog](https://github.com/jprichardson/node-fs-extra/blob/master/CHANGELOG.md) - [Commits](jprichardson/node-fs-extra@11.3.5...11.3.6) Updates `winston-loki` from 6.1.4 to 6.1.5 - [Release notes](https://github.com/JaniAnttonen/winston-loki/releases) - [Commits](JaniAnttonen/winston-loki@v6.1.4...v6.1.5) Updates `@scalar/express-api-reference` from 0.10.4 to 0.10.11 - [Release notes](https://github.com/scalar/scalar/releases) - [Changelog](https://github.com/scalar/scalar/blob/main/integrations/express/CHANGELOG.md) - [Commits](https://github.com/scalar/scalar/commits/HEAD/integrations/express) Updates `graphql-tools` from 9.0.28 to 9.0.33 - [Release notes](https://github.com/ardatan/graphql-tools/releases) - [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/graphql-tools/CHANGELOG.md) - [Commits](https://github.com/ardatan/graphql-tools/commits/[email protected]/packages/graphql-tools) Updates `axios` from 1.18.0 to 1.18.1 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.18.0...v1.18.1) Updates `nodemailer` from 9.0.1 to 9.0.3 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v9.0.1...v9.0.3) Updates `bson` from 7.3.0 to 7.3.1 - [Release notes](https://github.com/mongodb/js-bson/releases) - [Changelog](https://github.com/mongodb/js-bson/blob/main/HISTORY.md) - [Commits](mongodb/js-bson@v7.3.0...v7.3.1) Updates `mongoose` from 9.7.1 to 9.7.4 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@9.7.1...9.7.4) --- updated-dependencies: - dependency-name: "@bufbuild/protobuf" dependency-version: 2.12.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: fs-extra dependency-version: 11.3.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: winston-loki dependency-version: 6.1.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: "@scalar/express-api-reference" dependency-version: 0.10.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: graphql-tools dependency-version: 9.0.33 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: axios dependency-version: 1.18.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: nodemailer dependency-version: 9.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: bson dependency-version: 7.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch - dependency-name: mongoose dependency-version: 9.7.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-patch ... Signed-off-by: dependabot[bot] <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production-patch group with 9 updates in the / directory:
2.12.02.12.111.3.511.3.66.1.46.1.50.10.40.10.119.0.289.0.331.18.01.18.19.0.19.0.37.3.07.3.19.7.19.7.4Updates
@bufbuild/protobuffrom 2.12.0 to 2.12.1Release notes
Sourced from @bufbuild/protobuf's releases.
Commits
5dc9c95Release 2.12.1 (#1448)054cec8Bump protoc from 34.0.0 to 34.1.0 (#1431)150eeafReject duplicate keys when parsing JSON (#1446)9bc5438Fix open enum range checks (#1442)579f79bFix -0.0 serialization for implicit-presence float and double fields (#1443)00abde8Propagate BUF_BIGINT_DISABLE to Turborepo test tasks (#1444)da672c8Apply recursion limit to BinaryReader.skip (#1441)33932adRemove redundant npmignore (#1438)564d6c0Migrateprotobufbuild totshy(#1435)55278eeAdd recursion limit to fromBinary and fromJson (#1436)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@bufbuild/protobufsince your current version.Updates
fs-extrafrom 11.3.5 to 11.3.6Changelog
Sourced from fs-extra's changelog.
Commits
62a4e7211.3.601c0ca6Fix copy/move recursing into source through a symlinked dest ancestor (#1073)7268250docs: fix typo in README.md (seperate → separately) (#1074)2fd7b6cchore: Add Node 26 to the test matrix (#1072)Updates
winston-lokifrom 6.1.4 to 6.1.5Release notes
Sourced from winston-loki's releases.
Commits
81283baUse Node 24 in publish workflow for npm trusted publishing05ba93bMerge pull request #191 from JaniAnttonen/developmentabd8afaMerge pull request #190 from JaniAnttonen/fix/reject-non-2xx-responsesc899621Revert lazy btoa require, keep it hoisted in the constructorbb9d409Reject non-2xx responses from Loki push endpointMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for winston-loki since your current version.
Updates
@scalar/express-api-referencefrom 0.10.4 to 0.10.11Changelog
Sourced from @scalar/express-api-reference's changelog.
Commits
Updates
graphql-toolsfrom 9.0.28 to 9.0.33Changelog
Sourced from graphql-tools's changelog.
Commits
11f0a21chore(release): update monorepo packages versions (#8303)3c27f9achore(release): update monorepo packages versions (#8284)d246275build(deps): bump the actions-deps group with 4 updates (#8293)16096f7build(deps): bump the actions-deps group across 1 directory with 23 updates (...76b54dachore(release): update monorepo packages versions (#8264)062d229chore(release): update monorepo packages versions (#8261)c7f20acchore(release): update monorepo packages versions (#8157)1fb1076build(deps): bump the actions-deps group across 1 directory with 15 updates (...f0caccfbuild(deps): bump the actions-deps group across 1 directory with 9 updates (#...Updates
axiosfrom 1.18.0 to 1.18.1Release notes
Sourced from axios's releases.
Changelog
Sourced from axios's changelog.
Commits
a209bfbchore(release): prepare release 1.18.1 (#11027)fa6a55echore(deps-dev): bump multer from 2.1.1 to 2.2.0 (#11026)40e7be8docs: clarifies that request data is request-specific in axios (#11025)a446b39fix(AxiosURLSearchParams): use arrow function so encoder.call(this) receives ...cf1306adocs: add Deno to install instructions (#11023)b32880afix: incorrect use of error (#11021)1792edafix: ensure maxBodyLength is explicitly passed to follow-redirects (#10993)30499d6fix: various runtime crashes and type definition mismatches (#10959)20ce9c4fix(http): defer env proxy handling to Node (#10942)e64bcf9chore(deps): merge branch 'v1.x' into tests/module/cjs (#11014)Updates
nodemailerfrom 9.0.1 to 9.0.3Release notes
Sourced from nodemailer's releases.
Changelog
Sourced from nodemailer's changelog.
Commits
1f61eb4chore(master): release 9.0.3 (#1836)07d8253fix(smtp-connection): harden STARTTLS upgrade and secure socket handling (#1835)4801f3achore(master): release 9.0.2 (#1832)9ba1064fix(addressparser): keep operator chars inside an address-literal as text (#1...22ddceafix: harden smtp-connection low-severity issuesaf002ebchore: add Node.js 26 to the CI test matrix6347b47fix: reject CRLF in HTTP proxy CONNECT destination to prevent request injection68860b9fix: harden smtp-connection response parsing and socket lifecycle9517bc5fix: prevent SES transport callback double-invocation and hang on sync errors...Updates
bsonfrom 7.3.0 to 7.3.1Release notes
Sourced from bson's releases.
Changelog
Sourced from bson's changelog.
Commits
31bed5dchore(main): release 7.3.1 (#900)99433cdfix(NODE-7630): make startup snapshot calls more defensive (#899)ef8995bchore(NODE-7522): update dependencies (#889)Updates
mongoosefrom 9.7.1 to 9.7.4Release notes
Sourced from mongoose's releases.
Changelog
Sourced from mongoose's changelog.
Commits
62192d1chore: release 9.7.44d2b1c5Merge pull request #16363 from Automattic/vkarpov15/gh-1636206ca603Potential fix for pull request finding19ee447types(create): fix handling of nested objects typed as interfacese653b37Merge pull request #16353 from Automattic/dependabot/github_actions/master/ac...8f0e582Merge pull request #16354 from Automattic/dependabot/github_actions/master/ac...78d19edMerge pull request #16355 from Automattic/dependabot/npm_and_yarn/master/ark/...c4296bbMerge pull request #16358 from Automattic/dependabot/npm_and_yarn/master/mark...56f1202Merge pull request #16360 from Automattic/dependabot/npm_and_yarn/master/uuid...707ba75Merge pull request #16361 from Automattic/dependabot/npm_and_yarn/master/esli...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions