-
Notifications
You must be signed in to change notification settings - Fork 12
Bump the npm-dependencies group across 1 directory with 26 updates #269
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/npm_and_yarn/npm-dependencies-3a773e0e79
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Bump the npm-dependencies group across 1 directory with 26 updates #269
dependabot
wants to merge
1
commit into
main
from
dependabot/npm_and_yarn/npm-dependencies-3a773e0e79
+1,924
−1,776
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm-dependencies group with 24 updates in the / directory: | Package | From | To | | --- | --- | --- | | [body-parser](https://github.com/expressjs/body-parser) | `1.20.3` | `2.2.1` | | [express](https://github.com/expressjs/express) | `4.21.2` | `5.2.1` | | [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `7.5.0` | `8.2.1` | | [express-slow-down](https://github.com/express-rate-limit/express-slow-down) | `2.0.3` | `3.0.1` | | [helmet](https://github.com/helmetjs/helmet) | `8.0.0` | `8.1.0` | | [i18next-browser-languagedetector](https://github.com/i18next/i18next-browser-languageDetector) | `8.0.2` | `8.2.0` | | [i18next-http-backend](https://github.com/i18next/i18next-http-backend) | `3.0.1` | `3.0.2` | | [morgan](https://github.com/expressjs/morgan) | `1.10.0` | `1.10.1` | | [react-i18next](https://github.com/i18next/react-i18next) | `15.3.0` | `16.5.0` | | [system-sleep](https://github.com/jochemstoel/nodejs-system-sleep) | `1.3.7` | `1.3.8` | | [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.26.0` | `7.28.5` | | [@babel/preset-env](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-env) | `7.26.0` | `7.28.5` | | [@babel/preset-react](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-react) | `7.26.3` | `7.28.5` | | [babel-loader](https://github.com/babel/babel-loader) | `9.2.1` | `10.0.0` | | [bootstrap](https://github.com/twbs/bootstrap) | `5.3.3` | `5.3.8` | | [eslint](https://github.com/eslint/eslint) | `9.17.0` | `9.39.2` | | [i18next](https://github.com/i18next/i18next) | `24.2.0` | `25.7.3` | | [mocha](https://github.com/mochajs/mocha) | `11.0.1` | `11.7.5` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.0.0` | `19.2.3` | | [react-bootstrap](https://github.com/react-bootstrap/react-bootstrap) | `2.10.7` | `2.10.10` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.0.0` | `19.2.3` | | [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.1.1` | `7.10.1` | | [supertest](https://github.com/ladjs/supertest) | `7.0.0` | `7.1.4` | | [webpack](https://github.com/webpack/webpack) | `5.97.1` | `5.103.0` | Updates `body-parser` from 1.20.3 to 2.2.1 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.20.3...v2.2.1) Updates `debug` from 4.4.0 to 4.4.3 - [Release notes](https://github.com/debug-js/debug/releases) - [Commits](debug-js/debug@4.4.0...4.4.3) Updates `express` from 4.21.2 to 5.2.1 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.21.2...v5.2.1) Updates `express-rate-limit` from 7.5.0 to 8.2.1 - [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases) - [Commits](express-rate-limit/express-rate-limit@v7.5.0...v8.2.1) Updates `express-slow-down` from 2.0.3 to 3.0.1 - [Changelog](https://github.com/express-rate-limit/express-slow-down/blob/main/changelog.md) - [Commits](express-rate-limit/express-slow-down@v2.0.3...v3.0.1) Updates `helmet` from 8.0.0 to 8.1.0 - [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md) - [Commits](helmetjs/helmet@v8.0.0...v8.1.0) Updates `http-errors` from 2.0.0 to 2.0.1 - [Release notes](https://github.com/jshttp/http-errors/releases) - [Changelog](https://github.com/jshttp/http-errors/blob/master/HISTORY.md) - [Commits](jshttp/http-errors@v2.0.0...v2.0.1) Updates `i18next-browser-languagedetector` from 8.0.2 to 8.2.0 - [Changelog](https://github.com/i18next/i18next-browser-languageDetector/blob/master/CHANGELOG.md) - [Commits](i18next/i18next-browser-languageDetector@v8.0.2...v8.2.0) Updates `i18next-http-backend` from 3.0.1 to 3.0.2 - [Changelog](https://github.com/i18next/i18next-http-backend/blob/master/CHANGELOG.md) - [Commits](i18next/i18next-http-backend@v3.0.1...v3.0.2) Updates `morgan` from 1.10.0 to 1.10.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.10.0...1.10.1) Updates `react-i18next` from 15.3.0 to 16.5.0 - [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md) - [Commits](i18next/react-i18next@v15.3.0...v16.5.0) Updates `system-sleep` from 1.3.7 to 1.3.8 - [Commits](https://github.com/jochemstoel/nodejs-system-sleep/commits) Updates `@babel/core` from 7.26.0 to 7.28.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.28.5/packages/babel-core) Updates `@babel/preset-env` from 7.26.0 to 7.28.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.28.5/packages/babel-preset-env) Updates `@babel/preset-react` from 7.26.3 to 7.28.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.28.5/packages/babel-preset-react) Updates `babel-loader` from 9.2.1 to 10.0.0 - [Release notes](https://github.com/babel/babel-loader/releases) - [Changelog](https://github.com/babel/babel-loader/blob/main/CHANGELOG.md) - [Commits](babel/babel-loader@v9.2.1...v10.0.0) Updates `bootstrap` from 5.3.3 to 5.3.8 - [Release notes](https://github.com/twbs/bootstrap/releases) - [Commits](twbs/bootstrap@v5.3.3...v5.3.8) Updates `eslint` from 9.17.0 to 9.39.2 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v9.17.0...v9.39.2) Updates `i18next` from 24.2.0 to 25.7.3 - [Release notes](https://github.com/i18next/i18next/releases) - [Changelog](https://github.com/i18next/i18next/blob/master/CHANGELOG.md) - [Commits](i18next/i18next@v24.2.0...v25.7.3) Updates `mocha` from 11.0.1 to 11.7.5 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/v11.7.5/CHANGELOG.md) - [Commits](mochajs/mocha@v11.0.1...v11.7.5) Updates `react` from 19.0.0 to 19.2.3 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.3/packages/react) Updates `react-bootstrap` from 2.10.7 to 2.10.10 - [Release notes](https://github.com/react-bootstrap/react-bootstrap/releases) - [Changelog](https://github.com/react-bootstrap/react-bootstrap/blob/v2.10.10/CHANGELOG.md) - [Commits](react-bootstrap/react-bootstrap@v2.10.7...v2.10.10) Updates `react-dom` from 19.0.0 to 19.2.3 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.3/packages/react-dom) Updates `react-router-dom` from 7.1.1 to 7.10.1 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.10.1/packages/react-router-dom) Updates `supertest` from 7.0.0 to 7.1.4 - [Release notes](https://github.com/ladjs/supertest/releases) - [Commits](forwardemail/supertest@v7.0.0...v7.1.4) Updates `webpack` from 5.97.1 to 5.103.0 - [Release notes](https://github.com/webpack/webpack/releases) - [Commits](webpack/webpack@v5.97.1...v5.103.0) --- updated-dependencies: - dependency-name: body-parser dependency-version: 2.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: debug dependency-version: 4.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: express dependency-version: 5.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: express-rate-limit dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: express-slow-down dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: helmet dependency-version: 8.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: http-errors dependency-version: 2.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: i18next-browser-languagedetector dependency-version: 8.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: i18next-http-backend dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: morgan dependency-version: 1.10.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: react-i18next dependency-version: 16.5.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: system-sleep dependency-version: 1.3.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@babel/core" dependency-version: 7.28.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: "@babel/preset-env" dependency-version: 7.28.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: "@babel/preset-react" dependency-version: 7.28.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: babel-loader dependency-version: 10.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: bootstrap dependency-version: 5.3.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: eslint dependency-version: 9.39.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: i18next dependency-version: 25.7.3 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: mocha dependency-version: 11.7.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: react dependency-version: 19.2.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: react-bootstrap dependency-version: 2.10.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: react-dom dependency-version: 19.2.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: react-router-dom dependency-version: 7.10.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: supertest dependency-version: 7.1.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: webpack dependency-version: 5.103.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update javascript code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm-dependencies group with 24 updates in the / directory:
1.20.32.2.14.21.25.2.17.5.08.2.12.0.33.0.18.0.08.1.08.0.28.2.03.0.13.0.21.10.01.10.115.3.016.5.01.3.71.3.87.26.07.28.57.26.07.28.57.26.37.28.59.2.110.0.05.3.35.3.89.17.09.39.224.2.025.7.311.0.111.7.519.0.019.2.32.10.72.10.1019.0.019.2.37.1.17.10.17.0.07.1.45.97.15.103.0Updates
body-parserfrom 1.20.3 to 2.2.1Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
d96b63d2.2.1 (#659)b204886sec: security patch for CVE-2025-13466e20e351feat: removehistory.mdfrom being packaged on publish (#660)0d7ce71docs: switch badges from badgen.net to shields.io (#661)168afffci: also test on first supported node.js version (#646)e539a71build(deps): bump actions/setup-node from 5.0.0 to 6.0.0 (#654)9391612build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#655)57baafbbuild(deps): bump github/codeql-action from 3.30.5 to 4.31.2 (#656)a6a088ebuild(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 (#657)10a114dtest: add test for urlencoded invalid defaultCharset (#643)Updates
debugfrom 4.4.0 to 4.4.3Release notes
Sourced from debug's releases.
Commits
6b2c5fb4.4.333330fa4.4.198df33eremove istanbulbf2f574fixes #987 fallback to localStorage.DEBUG if debug is not defined (#988)a0497bdReplace whitespaces in namespaces string with commas globally instead of just...Updates
expressfrom 4.21.2 to 5.2.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
dbac7415.2.1697547cRevert "sec: security patch for CVE-2024-51999"4007ad1Release: 5.2.0 (#6920)2f64f68sec: security patch for CVE-2024-51999ed0ba3fbuild(deps): bump actions/checkout from 5.0.0 to 6.0.0 (#6928)8eace46build(deps): bump github/codeql-action from 4.31.2 to 4.31.6 (#6929)30bae81build(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 (#6930)758d435deps: body-parser@^2.2.1 (#6922)77bcd52docs: update emeritus triagers (#6890)f33caf1Nominate to@efekrsklfor triage team (#6888)Updates
express-rate-limitfrom 7.5.0 to 8.2.1Release notes
Sourced from express-rate-limit's releases.
Commits
fe1604d8.2.1b11c05bFix: don't warn for extra config from express-slow-down (#580)37347338.2.0962d737feat: Unknown Options validation check (#578)992c15cchore(deps-dev): bump the development-dependencies group with 3 updates (#579)449a28achore(deps-dev): bump the development-dependencies group across 1 directory w...ceaff6fchore(deps-dev): bump@biomejs/biomefrom 2.2.5 to 2.2.6 (#574)4fccb9echore(deps-dev): bump lint-staged from 16.2.4 to 16.2.5 (#573)b597770Rework dependabot grouping03e8336chore(deps-dev): bump mintlify from 4.2.114 to 4.2.175 (#572)Updates
express-slow-downfrom 2.0.3 to 3.0.1Changelog
Sourced from express-slow-down's changelog.
Commits
6f812163.0.17bb950ev3.0.1 changelog599ec11Merge pull request #67 from express-rate-limit/fix-erl-optionse3a6574add reminder to strip new options before passing to ERLc1156a7Merge pull request #68 from express-rate-limit/typo3ce5fdfFix typos471171dFix: don't pass extra options to express-rate-limit0b73eee3.0.03719920Merge pull request #65 from express-rate-limit/update-erl3b3dd64semver major in changelogUpdates
helmetfrom 8.0.0 to 8.1.0Changelog
Sourced from helmet's changelog.
Commits
57e1b398.1.0c8efbe3Update changelog for 8.1.0 release3396804Add 8.0.0 release date to changelog52dd8ebContent-Security-Policy: better error when value should be quoted4af4777Use built-in test runner (instead of Jest)ba10272Organize importse0f1387Update devDependencies to latest versions842393cCheck types duringnpm test, run in parallel77fbe3aStrict-Transport-Security: fix documentation for default max-age632e629Update license year for 2025Updates
http-errorsfrom 2.0.0 to 2.0.1Release notes
Sourced from http-errors's releases.
Changelog
Sourced from http-errors's changelog.
Commits
61aee572.0.1 (#140)6acba1fbuild(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#134)d2dcbbfbuild(deps): bump github/codeql-action from 3.29.11 to 4.31.2 (#137)fa47a60build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#138)09b3881build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#132)f1ad322build(deps): bump github/codeql-action from 3.29.7 to 3.29.11 (#133)109fe03build(deps-dev): bump eslint-plugin-import from 2.25.3 to 2.32.0 (#129)7a05446ci: add nodejs v18 - v24 to test matrix (#127)6dfaf49build(deps): bump github/codeql-action from 3.28.18 to 3.29.5 (#131)535aebfchore: add funding to package.json (#130)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for http-errors since your current version.
Updates
i18next-browser-languagedetectorfrom 8.0.2 to 8.2.0Changelog
Sourced from i18next-browser-languagedetector's changelog.
Commits
ae044f88.2.07feb356introduce hash detector #304e3d30a1not execute encodeURIComponent twice2a6913bfix cookie.remove73e5d138.1.000cd9fdreleasec7b00c9feat: add support for Partitioned cookies (#303)6b71927Bump@babel/runtimefrom 7.23.2 to 7.27.0 (#302)2d5939b8.0.59985ec7check for common xss attack patterns on detected languageUpdates
i18next-http-backendfrom 3.0.1 to 3.0.2Changelog
Sourced from i18next-http-backend's changelog.
Commits
a0c695a3.0.29c04ef0optimize fetchApi selectorcd1649dBump next from 14.2.15 to 14.2.21 in /example/next (#165)fd8e218Bump next from 14.2.10 to 14.2.15 in /example/next (#162)429e9d8update some deps in the examplesUpdates
morganfrom 1.10.0 to 1.10.1Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
c1c7f10🔖 1.10.1eb896c2⬆️ bump on-headers1c3eec6remove --bail (#314)b144728ci: apply OSSF Scorecard security best practices (#300)68c2d21ci: use ubuntu-latest (