Bump the npm_and_yarn group across 1 directory with 38 updates#8
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Bump the npm_and_yarn group across 1 directory with 38 updates#8dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 19 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@openzeppelin/contracts](https://github.com/OpenZeppelin/openzeppelin-contracts) | `3.2.0` | `4.9.6` | | [moment](https://github.com/moment/moment) | `2.22.2` | `2.29.4` | | [browserslist](https://github.com/browserslist/browserslist) | `4.16.3` | `4.23.2` | | [semver](https://github.com/npm/node-semver) | `5.6.0` | `5.7.2` | | [@truffle/contract](https://github.com/trufflesuite/truffle/tree/HEAD/packages/contract) | `4.2.23` | `4.6.31` | | [@truffle/hdwallet-provider](https://github.com/trufflesuite/truffle/tree/HEAD/packages/hdwallet-provider) | `1.1.0` | `2.1.15` | | [lodash](https://github.com/lodash/lodash) | `4.17.11` | `4.17.21` | | [web3](https://github.com/ChainSafe/web3.js) | `0.18.4` | `1.10.0` | | [eth-gas-reporter](https://github.com/cgewecke/eth-gas-reporter) | `0.1.12` | `0.2.27` | | [ajv](https://github.com/ajv-validator/ajv) | `6.6.1` | `6.12.6` | | [qs](https://github.com/ljharb/qs) | `6.5.2` | `6.5.3` | | [global-modules-path](https://github.com/rosen-vladimirov/global-modules-path) | `2.3.1` | `removed` | | [webpack-cli](https://github.com/webpack/webpack-cli) | `3.1.2` | `3.3.12` | | [json-schema](https://github.com/kriszyp/json-schema) | `0.2.3` | `0.4.0` | | [jsprim](https://github.com/joyent/node-jsprim) | `1.4.1` | `1.4.2` | | [minimist](https://github.com/minimistjs/minimist) | `0.0.8` | `removed` | | [mkdirp](https://github.com/isaacs/node-mkdirp) | `0.5.1` | `3.0.1` | | [pathval](https://github.com/chaijs/pathval) | `1.1.0` | `1.1.1` | | [y18n](https://github.com/yargs/y18n) | `3.2.1` | `3.2.2` | Updates `@openzeppelin/contracts` from 3.2.0 to 4.9.6 - [Release notes](https://github.com/OpenZeppelin/openzeppelin-contracts/releases) - [Changelog](https://github.com/OpenZeppelin/openzeppelin-contracts/blob/master/CHANGELOG.md) - [Commits](OpenZeppelin/openzeppelin-contracts@v3.2.0...v4.9.6) Updates `moment` from 2.22.2 to 2.29.4 - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.22.2...2.29.4) Updates `browserslist` from 4.16.3 to 4.23.2 - [Release notes](https://github.com/browserslist/browserslist/releases) - [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md) - [Commits](browserslist/browserslist@4.16.3...4.23.2) Updates `semver` from 5.6.0 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.6.0...v5.7.2) Updates `@truffle/contract` from 4.2.23 to 4.6.31 - [Release notes](https://github.com/trufflesuite/truffle/releases) - [Commits](https://github.com/trufflesuite/truffle/commits/@truffle/contract@4.6.31/packages/contract) Updates `@truffle/hdwallet-provider` from 1.1.0 to 2.1.15 - [Release notes](https://github.com/trufflesuite/truffle/releases) - [Commits](https://github.com/trufflesuite/truffle/commits/@truffle/hdwallet-provider@2.1.15/packages/hdwallet-provider) Updates `@babel/traverse` from 7.13.0 to 7.24.8 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.8/packages/babel-traverse) Updates `lodash` from 4.17.11 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.11...4.17.21) Updates `elliptic` from 6.3.3 to 6.4.1 - [Commits](indutny/elliptic@v6.3.3...v6.4.1) Updates `got` from 7.1.0 to 11.8.6 - [Release notes](https://github.com/sindresorhus/got/releases) - [Commits](sindresorhus/got@v7.1.0...v11.8.6) Updates `web3` from 0.18.4 to 1.10.0 - [Release notes](https://github.com/ChainSafe/web3.js/releases) - [Changelog](https://github.com/web3/web3.js/blob/v1.10.0/CHANGELOG.md) - [Commits](web3/web3.js@0.18.4...v1.10.0) Updates `eth-gas-reporter` from 0.1.12 to 0.2.27 - [Release notes](https://github.com/cgewecke/eth-gas-reporter/releases) - [Changelog](https://github.com/cgewecke/eth-gas-reporter/blob/master/CHANGELOG.md) - [Commits](https://github.com/cgewecke/eth-gas-reporter/commits/v0.2.27) Updates `ajv` from 6.6.1 to 6.12.6 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.6.1...v6.12.6) Updates `highlight.js` from 9.18.5 to 10.7.3 - [Release notes](https://github.com/highlightjs/highlight.js/releases) - [Changelog](https://github.com/highlightjs/highlight.js/blob/10.7.3/CHANGES.md) - [Commits](highlightjs/highlight.js@9.18.5...10.7.3) Updates `qs` from 6.5.2 to 6.5.3 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.5.2...v6.5.3) Updates `cross-fetch` from 2.2.3 to 2.2.6 - [Release notes](https://github.com/lquixada/cross-fetch/releases) - [Changelog](https://github.com/lquixada/cross-fetch/blob/v4.x/CHANGELOG.md) - [Commits](lquixada/cross-fetch@v2.2.3...v2.2.6) Updates `css-what` from 4.0.0 to 6.1.0 - [Release notes](https://github.com/fb55/css-what/releases) - [Commits](fb55/css-what@v4.0.0...v6.1.0) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `es5-ext` from 0.10.53 to 0.10.64 - [Release notes](https://github.com/medikoo/es5-ext/releases) - [Changelog](https://github.com/medikoo/es5-ext/blob/main/CHANGELOG.md) - [Commits](medikoo/es5-ext@v0.10.53...v0.10.64) Updates `express` from 4.17.1 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.17.1...4.19.2) Updates `node-fetch` from 1.7.3 to 2.7.0 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@1.7.3...v2.7.0) Removes `global-modules-path` Updates `webpack-cli` from 3.1.2 to 3.3.12 - [Release notes](https://github.com/webpack/webpack-cli/releases) - [Changelog](https://github.com/webpack/webpack-cli/blob/master/CHANGELOG.md) - [Commits](webpack/webpack-cli@v3.1.2...v3.3.12) Updates `http-cache-semantics` from 4.1.0 to 4.1.1 - [Commits](kornelski/http-cache-semantics@v4.1.0...v4.1.1) Updates `json-schema` from 0.2.3 to 0.4.0 - [Commits](kriszyp/json-schema@v0.2.3...v0.4.0) Updates `jsprim` from 1.4.1 to 1.4.2 - [Changelog](https://github.com/TritonDataCenter/node-jsprim/blob/v1.4.2/CHANGES.md) - [Commits](TritonDataCenter/node-jsprim@v1.4.1...v1.4.2) Updates `json5` from 0.5.1 to 1.0.2 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v0.5.1...v1.0.2) Updates `loader-utils` from 1.1.0 to 1.4.2 - [Release notes](https://github.com/webpack/loader-utils/releases) - [Changelog](https://github.com/webpack/loader-utils/blob/v1.4.2/CHANGELOG.md) - [Commits](webpack/loader-utils@v1.1.0...v1.4.2) Removes `minimist` Updates `mkdirp` from 0.5.1 to 3.0.1 - [Changelog](https://github.com/isaacs/node-mkdirp/blob/main/CHANGELOG.md) - [Commits](isaacs/node-mkdirp@0.5.1...v3.0.1) Updates `normalize-url` from 4.5.0 to 6.1.0 - [Release notes](https://github.com/sindresorhus/normalize-url/releases) - [Commits](sindresorhus/normalize-url@v4.5.0...v6.1.0) Updates `nth-check` from 2.0.0 to 2.1.1 - [Release notes](https://github.com/fb55/nth-check/releases) - [Commits](fb55/nth-check@v2.0.0...v2.1.1) Updates `path-parse` from 1.0.6 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `pathval` from 1.1.0 to 1.1.1 - [Release notes](https://github.com/chaijs/pathval/releases) - [Changelog](https://github.com/chaijs/pathval/blob/master/CHANGELOG.md) - [Commits](chaijs/pathval@v1.1.0...v1.1.1) Updates `simple-get` from 2.8.1 to 2.8.2 - [Commits](feross/simple-get@v2.8.1...v2.8.2) Updates `tar` from 4.4.13 to 4.4.19 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v4.4.13...v4.4.19) Updates `yargs-parser` from 11.1.1 to 2.4.1 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/docs/CHANGELOG-full.md) - [Commits](yargs/yargs-parser@v11.1.1...v2.4.1) Updates `y18n` from 3.2.1 to 3.2.2 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](https://github.com/yargs/y18n/commits) --- updated-dependencies: - dependency-name: "@openzeppelin/contracts" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: moment dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: browserslist dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@truffle/contract" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@truffle/hdwallet-provider" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: elliptic dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: got dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: web3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: eth-gas-reporter dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: ajv dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: highlight.js dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cross-fetch dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: css-what dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: es5-ext dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: express dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: global-modules-path dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: webpack-cli dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: http-cache-semantics dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json-schema dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: jsprim dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: loader-utils dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: mkdirp dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: normalize-url dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nth-check dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: pathval dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: simple-get dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Vulnerable Libraries (2)
More info on how to fix Vulnerable Libraries in JavaScript. 👉 Go to the dashboard for detailed results. 📥 Happy? Share your feedback with us. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 19 updates in the / directory:
3.2.04.9.62.22.22.29.44.16.34.23.25.6.05.7.24.2.234.6.311.1.02.1.154.17.114.17.210.18.41.10.00.1.120.2.276.6.16.12.66.5.26.5.32.3.1removed3.1.23.3.120.2.30.4.01.4.11.4.20.0.8removed0.5.13.0.11.1.01.1.13.2.13.2.2Updates
@openzeppelin/contractsfrom 3.2.0 to 4.9.6Release notes
Sourced from
@openzeppelin/contracts's releases.... (truncated)
Changelog
Sourced from
@openzeppelin/contracts's changelog.... (truncated)
Commits
dc44c9fRelease v4.9.6 (#4931)a6286d0Port Base64 tests to truffle (#4926) (#4929)bd325d5Release v4.9.5 (#4790)ad6a5b6Add changeset88ac712Replace doublefunctionDelegateCalla83918dBump node CI version to 16.x0d5f54eRelease v4.9.4 (#4784)ccfffe1Make Multicall context-aware9329cfaRemove Wizard page from 4.xe1b3d8cRemove Wizard from 4.x navigationUpdates
momentfrom 2.22.2 to 2.29.4Changelog
Sourced from moment's changelog.
... (truncated)
Commits
000ac18Build 2.24.4f2006b6Bump version to 2.24.4536ad0cUpdate changelog for 2.29.49a3b589[bugfix] Fix redos in preprocessRFC2822 regex (#6015)6374fd8Merge branch 'master' into developb4e6153Revert "[bugfix] Fix redos in preprocessRFC2822 regex (#6015)"7aebb16[bugfix] Fix redos in preprocessRFC2822 regex (#6015)57c9062Build 2.29.3aaf50b6Fixup release complaints26f4aefBump version to 2.29.3Updates
browserslistfrom 4.16.3 to 4.23.2Release notes
Sourced from browserslist's releases.
Changelog
Sourced from browserslist's changelog.
... (truncated)
Commits
cdcfbc0Release 4.23.2 version9e8188bUpdate dependencies543fc48Update Firefox ESRedd5309Release 4.23.1 version9e8ca3dSimplify codebbe6821Update locka36e1adUpdate ESLint and dependencies4424c96Use pnpm 9 for Node.js 20 and 182185077Add Node.js 22 to CIf78f90cMove to pnpm 9Updates
semverfrom 5.6.0 to 5.7.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
f8cc313chore: release 5.7.22f8fd41fix: better handling of whitespace (#585)deb5ad5chore:@npmcli/template-oss@4.16.0c83c18c5.7.1956e228Correct typo in README8055dda5.7.0604e73dauto-publishing scriptsbed01e2remove the nomin comments, since we don't minify any more anyway9cb68f1document parse method38d42ca5.7 changelogMaintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
@truffle/contractfrom 4.2.23 to 4.6.31Commits
a26df1fPublish9b23a59devDeps: webpack@^5.73.0->^5.88.2033fc64Publish56cab73chore: set engines.node in package manifests3fa384fPublisha9ca7eaPublish2748ccbPublisha6fb238Publish854a564Publishcb01f46PublishUpdates
@truffle/hdwallet-providerfrom 1.1.0 to 2.1.15Commits
033fc64Publish56cab73chore: set engines.node in package manifests3fa384fPublishc519492Update Ganache to 7.9.12748ccbPublish86330f3Update Ganache to 7.9.07983a54Publish5ff4b8eUpdate typescript to ^4.9.5ccf4ebcRevert "Update typescript to ^4.9.5"05606aaUpdate typescript to ^4.9.5Updates
@babel/traversefrom 7.13.0 to 7.24.8Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Changelog
Sourced from
@babel/traverse's changelog.... (truncated)
Commits
1f5af44v7.24.8c90bb0c[babel 8] Remove methods starting with_in@babel/traverse(#16504)e0368a8Avoid checkingScope.globalsmultiple times (#16619)683c654Enable some lint rules (#16605)cfe13c2[babel 8] Updateglobalsdependency (#16600)c36fa6aUpdate typescript-eslint v8 (#16557)12619ffimprove getBindingIdentifiers.keys typing (#16570)424fc90Update to TypeScript 5.5 (#16536)bf1e9a3v7.24.74463aa5fix: incorrectconstantViolationswith destructuring (#16522)Updates
lodashfrom 4.17.11 to 4.17.21Commits
f299b52Bump to v4.17.21c4847ebImprove performance oftoNumber,trimandtrimEndon large input strings3469357Prevent command injection through_.template'svariableoptionded9bc6Bump to v4.17.20.63150efDocumentation fixes.00f0f62test.js: Remove trailing comma.846e434Temporarily use a custom fork oflodash-cli.5d046f3Re-enable Travis tests on4.17branch.aa816b3Remove/npm-package.d7fbc52Bump to v4.17.19Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash since your current version.
Updates
ellipticfrom 6.3.3 to 6.4.1Commits
523da1c6.4.1776c9b0edwards: fixes for other values ofc1149e65edwards: fix doubling/isInfinityfc8f0eelib: remove unreachable code8628295readme: update example6b0d2b76.4.0efd560flib: split in modulesUpdates
gotfrom 7.1.0 to 11.8.6Release notes
Sourced from got's releases.
... (truncated)
Commits
2b1482c11.8.62d1497eDestroy request object after successful response (#2187)5e17bb711.8.5bce8ce7Backport 861ccd9ac2237df762a9e2beed7edd88c60782dc8ced192Fix build670eb0411.8.420f29feBackport #1543: Initialize globalResponse in case of ignored HTTPError (#2017)0da732f11.8.39463bb6Bump cacheable-request dependency (#1921)0e167b8HTTPError code set to 'HTTPError' #1711 (#1739)Updates
web3from 0.18.4 to 1.10.0Release notes
Sourced from web3's releases.
Changelog
Sourced from web3's changelog.
Commits
f3846d1Build commit for 1.10.02c74586v1.10.03ed053fbuild output and changelog update for v1.10.0-rc.0c7bdd99v1.10.0-rc.013a2edcRemove the unnecessary chainId parameter (#5888) (#6057)7b3ce911x update (#6044)195cd3cFilter option doesn't work in getPastEvents (#6015)48958eeNicos99/revert call (#6009)6ce085bFix error: "n.data.substring is not a function" (#6000)4e5afa1Formattransaction.typeto hex. Add emptyaccessListis `tx.type === '0x1...Maintainer changes
This version was pushed to npm by jdevcs, a new releaser for web3 since your current version.
Updates
eth-gas-reporterfrom 0.1.12 to 0.2.27Release notes
Sourced from eth-gas-reporter's relea...
Description has been truncated