Bump the npm_and_yarn group across 1 directory with 22 updates#20
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Bump the npm_and_yarn group across 1 directory with 22 updates#20dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 11 updates in the /backend/functions directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.13` | `4.17.21` | | [request](https://github.com/request/request) | `2.88.0` | `2.88.2` | | [@firebase/util](https://github.com/firebase/firebase-js-sdk/tree/HEAD/packages/util) | `0.2.14` | `1.9.6` | | [firebase-admin](https://github.com/firebase/firebase-admin-node) | `7.0.0` | `12.1.1` | | [semver](https://github.com/npm/node-semver) | `5.7.0` | `5.7.2` | | [ajv](https://github.com/ajv-validator/ajv) | `6.10.0` | `6.12.6` | | [debug](https://github.com/debug-js/debug) | `4.1.1` | `4.3.5` | | [express](https://github.com/expressjs/express) | `4.17.1` | `4.19.2` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.4` | `3.1.2` | | [minimist](https://github.com/minimistjs/minimist) | `0.0.8` | `1.2.8` | | [mkdirp](https://github.com/isaacs/node-mkdirp) | `0.5.1` | `0.5.6` | Updates `lodash` from 4.17.13 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.13...4.17.21) Updates `request` from 2.88.0 to 2.88.2 - [Changelog](https://github.com/request/request/blob/master/CHANGELOG.md) - [Commits](https://github.com/request/request/commits) Updates `@firebase/util` from 0.2.14 to 1.9.6 - [Release notes](https://github.com/firebase/firebase-js-sdk/releases) - [Changelog](https://github.com/firebase/firebase-js-sdk/blob/master/packages/util/CHANGELOG.md) - [Commits](https://github.com/firebase/firebase-js-sdk/commits/@firebase/util@1.9.6/packages/util) Updates `firebase-admin` from 7.0.0 to 12.1.1 - [Release notes](https://github.com/firebase/firebase-admin-node/releases) - [Commits](firebase/firebase-admin-node@v7.0.0...v12.1.1) Updates `@google-cloud/firestore` from 1.3.0 to 7.8.0 - [Release notes](https://github.com/googleapis/nodejs-firestore/releases) - [Changelog](https://github.com/googleapis/nodejs-firestore/blob/main/CHANGELOG.md) - [Commits](googleapis/nodejs-firestore@v1.3.0...v7.8.0) Updates `@grpc/grpc-js` from 0.3.6 to 1.10.9 - [Release notes](https://github.com/grpc/grpc-node/releases) - [Commits](https://github.com/grpc/grpc-node/compare/@grpc/grpc-js@0.3.6...@grpc/grpc-js@1.10.9) Updates `semver` from 5.7.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.7.0...v5.7.2) Updates `ajv` from 6.10.0 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.10.0...v6.12.6) Updates `ansi-regex` from 2.1.1 to 3.0.0 - [Release notes](https://github.com/chalk/ansi-regex/releases) - [Commits](chalk/ansi-regex@2.1.1...v3.0.0) Updates `debug` from 4.1.1 to 4.3.5 - [Release notes](https://github.com/debug-js/debug/releases) - [Commits](debug-js/debug@4.1.1...4.3.5) Updates `express` from 4.17.1 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.17.1...4.19.2) Updates `jsonwebtoken` from 8.1.0 to 8.5.1 - [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md) - [Commits](auth0/node-jsonwebtoken@v8.1.0...v8.5.1) Updates `node-forge` from 0.7.4 to 1.3.1 - [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md) - [Commits](digitalbazaar/forge@0.7.4...v1.3.1) Updates `ini` from 1.3.5 to 1.3.8 - [Release notes](https://github.com/npm/ini/releases) - [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md) - [Commits](npm/ini@v1.3.5...v1.3.8) Updates `minimatch` from 3.0.4 to 3.1.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.4...v3.1.2) Updates `minimist` from 0.0.8 to 1.2.8 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v0.0.8...v1.2.8) Updates `mkdirp` from 0.5.1 to 0.5.6 - [Changelog](https://github.com/isaacs/node-mkdirp/blob/main/CHANGELOG.md) - [Commits](isaacs/node-mkdirp@0.5.1...v0.5.6) Updates `json-bigint` from 0.3.0 to 1.0.0 - [Commits](sidorares/json-bigint@v0.3.0...v1.0.0) Updates `json-schema` from 0.2.3 to 0.4.0 - [Commits](kriszyp/json-schema@v0.2.3...v0.4.0) Updates `node-fetch` from 2.6.0 to 2.7.0 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v2.6.0...v2.7.0) Updates `qs` from 6.5.2 to 6.5.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.2...v6.5.3) Updates `y18n` from 3.2.1 to 5.0.8 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](yargs/y18n@v3.2.1...v5.0.8) --- updated-dependencies: - dependency-name: lodash dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: request dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@firebase/util" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: firebase-admin dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@google-cloud/firestore" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@grpc/grpc-js" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ajv dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ansi-regex dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: debug dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jsonwebtoken dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: node-forge dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ini dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimatch dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: mkdirp dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json-bigint dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json-schema dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Jun 10, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 11 updates in the /backend/functions directory:
4.17.134.17.212.88.02.88.20.2.141.9.67.0.012.1.15.7.05.7.26.10.06.12.64.1.14.3.54.17.14.19.23.0.43.1.20.0.81.2.80.5.10.5.6Updates
lodashfrom 4.17.13 to 4.17.21Commits
f299b52Bump to v4.17.21c4847ebImprove performance oftoNumber,trimandtrimEndon large input strings3469357Prevent command injection through_.template'svariableoptionded9bc6Bump to v4.17.20.63150efDocumentation fixes.00f0f62test.js: Remove trailing comma.846e434Temporarily use a custom fork oflodash-cli.5d046f3Re-enable Travis tests on4.17branch.aa816b3Remove/npm-package.d7fbc52Bump to v4.17.19Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash since your current version.
Updates
requestfrom 2.88.0 to 2.88.2Changelog
Sourced from request's changelog.
Commits
Updates
@firebase/utilfrom 0.2.14 to 1.9.6Changelog
Sourced from
@firebase/util's changelog.... (truncated)
Commits
8fb372aVersion Packages (#8236)13762a4Version Packages (#8101)0c51501Run npm pkg fix on all packages (#8079)9fa0e9fVersion Packages (#7995)434f841Fix isSafari() throwing on React Native (fixes #7962) (#7963)ebc694aComment changes for OSS (#7778)2be12d7[CI] update chrome install steps for Auth builds. (#7602)2e7e548Version Packages (#7069)c59f537Improve decodeBase64() to throw on invalid input rather than silently accept ...3d605f8Version Packages (#7008)Maintainer changes
This version was pushed to npm by google-wombot, a new releaser for
@firebase/utilsince your current version.Updates
firebase-adminfrom 7.0.0 to 12.1.1Release notes
Sourced from firebase-admin's releases.
... (truncated)
Commits
e2515f2[chore] Release 12.1.1 (#2561)4d4fd39build(deps): updgrade jwks-rsa (#2570)1754b7e--- (#2568)72f0169--- (#2566)8f622cf--- (#2567)f8f8eb9--- (#2569)ee78c87build(deps-dev): bump@firebase/auth-typesfrom 0.12.1 to 0.12.2 (#2556)f837c23build(deps-dev): bump@microsoft/api-extractorfrom 7.43.2 to 7.43.7 (#2559)41aea3achore: upgrade firestore to 7.7.0 (#2560)26cd8b0build(deps-dev): bump@firebase/app-compatfrom 0.2.32 to 0.2.33 (#2555)Maintainer changes
This version was pushed to npm by google-wombot, a new releaser for firebase-admin since your current version.
Updates
@google-cloud/firestorefrom 1.3.0 to 7.8.0Release notes
Sourced from
@google-cloud/firestore's releases.... (truncated)
Changelog
Sourced from
@google-cloud/firestore's changelog.... (truncated)
Commits
df748acchore(main): release 7.8.0 (#2048)6dbe4b0feat: update Nodejs generator to send API versions in headers for GAPICs (#2041)d406f14feat: Query profiling for VectorQuery (#2045)1e949b8chore: refactor reference.ts to one class per file (#2037)591fff1chore(deps): update dependency sinon to v18 (#2044)392ecf3chore(main): release 7.7.0 (#2038)0b9efa6fix: Upgrade thegoogle-gaxdependency version. (#2040)52099c8fix: Nonblocking rollback (#2039)2c726a1feat: Lazy-started transactions (#2017)5811492docs: Allow 14 week backup retention for Firestore daily backups (#2031)Updates
@grpc/grpc-jsfrom 0.3.6 to 1.10.9Release notes
Sourced from
@grpc/grpc-js's releases.... (truncated)
Commits
674f4e3Merge pull request from GHSA-7v5v-9h63-cj867ecaa2dgrpc-js: Bump to 1.10.9e64d816grpc-js: Avoid buffering significantly more than max_receive_message_size per...45e5fe5Merge pull request #2750 from murgatroid99/grpc-js_idle_uds_fix87a3541grpc-js: Fix UDS channels not reconnecting after going idle3105791Merge pull request #2740 from sergiitk/backport-1.10-psm-interop-common-prod-...fec135aMerge pull request #2729 from sergiitk/psm-interop-common-prod-tests76fe802Merge pull request #2739 from murgatroid99/backport-1.10-grpc-js_linkify-it_fixd5edf49Merge pull request #2735 from murgatroid99/grpc-js_linkify-it_fix23c05fcMerge pull request #2732 from murgatroid99/grpc-js_proto-loader_updateUpdates
semverfrom 5.7.0 to 5.7.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
f8cc313chore: release 5.7.22f8fd41fix: better handling of whitespace (#585)deb5ad5chore:@npmcli/template-oss@4.16.0c83c18c5.7.1956e228Correct typo in READMEMaintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
ajvfrom 6.10.0 to 6.12.6Release notes
Sourced from ajv's releases.
Commits
fe591436.12.6d580d3eMerge pull request #1298 from ajv-validator/fix-urlfd36389fix: regular expression for "url" format490e34cdocs: link to v7-beta branch9cd93a1docs: note about v7 in readme877d286Merge pull request #1262 from b4h0-c4t/refactor-opt-object-typef1c8e456.12.5764035eMerge branch 'ChALkeR-chalker/fix-comma'3798160Merge branch 'chalker/fix-comma' of git://github.com/ChALkeR/ajv into ChALkeR...a3c7ebaMerge branch 'refactor-opt-object-type' of github.com:b4h0-c4t/ajv into refac...Updates
ansi-regexfrom 2.1.1 to 3.0.0Commits
0a8cc193.0.0d9d806eMinor tweaks69bebf6Support urxvt escapes (#13)3dff5e7Use Map instead of Object for the fixturesbaacbabRequire Node.js 4 and meta tweaksUpdates
debugfrom 4.1.1 to 4.3.5Release notes
Sourced from debug's releases.
... (truncated)
Commits
5464bdd4.3.5f244adaupdate authorship contact infocac39b1Fix/debug depth (#926)f66cb2dremove .github folder (and the outdated issue templates)d161662Update ISSUE_TEMPLATE.md12c1ad0Update ISSUE_TEMPLATE.mdda66c864.3.49b33412replace deprecated String.prototype.substr() (#876)c0805ccadd section about configuring JS console to show debug messages (#866)043d3cd4.3.3Maintainer changes
This version was pushed to npm by qix, a new releaser for debug since your current version.
Updates
expressfrom 4.17.1 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
04bc6274.19.2da4d763Improved fix for open redirect allow list bypass4f0f6cc4.19.1a003cfaAllow passing non-strings to res.location with new encoding handling checks f...a1fa90ffixed un-edited version in history.md for 4.19.011f2b1dbuild: fix build due to inconsistent supertest behavior in older versions084e3654.19.00867302Prevent open redirect allow list bypass due to encodeurl567c9c6Add note on how to update docs for new release (#5541)69a4cf2deps: cookie@0.6.0Maintainer changes
This version was p...
Description has been truncated