build(deps): bump the npm_and_yarn group across 4 directories with 8 updates#1
Conversation
…updates Bumps the npm_and_yarn group with 1 update in the /pkgs/applications/editors/vim/plugins/patches/markdown-preview-nvim directory: [next](https://github.com/vercel/next.js). Bumps the npm_and_yarn group with 4 updates in the /pkgs/by-name/re/react-static directory: [axios](https://github.com/axios/axios), [tar-fs](https://github.com/mafintosh/tar-fs), [webpack-dev-server](https://github.com/webpack/webpack-dev-server) and [react-dev-utils](https://github.com/facebook/create-react-app/tree/HEAD/packages/react-dev-utils). Bumps the npm_and_yarn group with 1 update in the /pkgs/servers/home-assistant/custom-lovelace-modules/button-card directory: [semantic-release](https://github.com/semantic-release/semantic-release). Bumps the npm_and_yarn group with 2 updates in the /pkgs/tools/admin/meshcentral directory: [ws](https://github.com/websockets/ws) and [aedes](https://github.com/moscajs/aedes). Updates `next` from 7.0.3 to 15.5.2 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@7.0.3...v15.5.2) Updates `axios` from 0.21.4 to 1.11.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.21.4...v1.11.0) Updates `tar-fs` from 2.1.3 to 3.1.0 - [Commits](mafintosh/tar-fs@v2.1.3...v3.1.0) Updates `webpack-dev-server` from 3.11.3 to 5.2.2 - [Release notes](https://github.com/webpack/webpack-dev-server/releases) - [Changelog](https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md) - [Commits](webpack/webpack-dev-server@v3.11.3...v5.2.2) Updates `react-dev-utils` from 9.1.0 to 12.0.1 - [Release notes](https://github.com/facebook/create-react-app/releases) - [Changelog](https://github.com/facebook/create-react-app/blob/main/CHANGELOG-1.x.md) - [Commits](https://github.com/facebook/create-react-app/commits/react-dev-utils@12.0.1/packages/react-dev-utils) Updates `semantic-release` from 17.4.7 to 24.2.7 - [Release notes](https://github.com/semantic-release/semantic-release/releases) - [Commits](semantic-release/semantic-release@v17.4.7...v24.2.7) Updates `ws` from 8.18.0 to 8.18.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.18.0...8.18.3) Updates `aedes` from 0.39.0 to 0.42.1 - [Release notes](https://github.com/moscajs/aedes/releases) - [Commits](moscajs/aedes@v0.39.0...v0.42.1) --- updated-dependencies: - dependency-name: next dependency-version: 15.5.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 1.11.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tar-fs dependency-version: 3.1.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: webpack-dev-server dependency-version: 5.2.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: react-dev-utils dependency-version: 12.0.1 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: semantic-release dependency-version: 24.2.7 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 8.18.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: aedes dependency-version: 0.42.1 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the npm_and_yarn group with 1 update in the /pkgs/applications/editors/vim/plugins/patches/markdown-preview-nvim directory: next.
Bumps the npm_and_yarn group with 4 updates in the /pkgs/by-name/re/react-static directory: axios, tar-fs, webpack-dev-server and react-dev-utils.
Bumps the npm_and_yarn group with 1 update in the /pkgs/servers/home-assistant/custom-lovelace-modules/button-card directory: semantic-release.
Bumps the npm_and_yarn group with 2 updates in the /pkgs/tools/admin/meshcentral directory: ws and aedes.
Updates
nextfrom 7.0.3 to 15.5.2Release notes
Sourced from next's releases.
... (truncated)
Commits
497ec6av15.5.2bc72f41[backport] revert: add ?dpl to fonts in/_next/static/media(#83062) (#83066)c8faf68[backport] fix: disable unknownatrules lint rule entirely (#83059) (#83060)cc68cedv15.5.11ce9857[backport] fix: update validation return types (#82854) (#83027)b93c894[backport] fix: update the config.api.responseLimit type (#82852) (#83028)8a92f28[backport] fix: avoid importing types that will be unused (#82856) (#83026)19617ab[backport] feat: add typesafety with config.typedRoutes to redirect() and per...822e4c0[backport] fix: add path normalization to getRelativePath for Windows (#82918...bb67ca9[backport] fix: change "noUnknownAtRules" to "warn" for Biome (#82974) (#83022)Maintainer changes
This version was pushed to npm by vercel-release-bot, a new releaser for next since your current version.
Updates
axiosfrom 0.21.4 to 1.11.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
b76c4acchore(release): v1.11.0 (#6974)e72c193fix: form-data npm pakcage (#6970)8517aa1fix(types): resolve type discrepancies between ESM and CJS TypeScript declara...a2214cafix: prevent RangeError when using large Buffers (#6961)6161947refactor: use spread operator instead of '.apply()' (#6938)a1d16ddrefactor: use an object spread instead of Object.assign (#6939)07183cdchore(sponsor): update sponsor block (#6952)ef36347docs(CONTRIBUTING): update docs link for accuracy (#6894)b29bd6achore(sponsor): update sponsor block (#6948)a406a93chore(sponsor): update sponsor block (#6937)Updates
tar-fsfrom 2.1.3 to 3.1.0Commits
cb1c5713.1.0374460eadd optional disablement of symlink validation (#119)5bfe6df3.0.1063e12f9bare support2ceedf43.0.9647447bcheck windows tweak (#115)e4a7a403.0.8504ca0fupgrade bare packages1e4cc043.0.7a1dd7e7refactor and throw on bad symlinkUpdates
webpack-dev-serverfrom 3.11.3 to 5.2.2Release notes
Sourced from webpack-dev-server's releases.
... (truncated)
Changelog
Sourced from webpack-dev-server's changelog.
... (truncated)
Commits
195a7e6chore(release): 5.2.2620bef1chore(deps): update (#5511)03d1214fix: respect theallowedHostsoption for cross-origin header check (#5510)5ba862echore(deps-dev): bump the dependencies group across 1 directory with 7 update...f7fec94chore: fix typo (#5508)6ee8cd0ci: add Node.js v24 (#5492)d30f963chore: update http-proxy-middleware to ^2.0.9 (#5503)66cf033chore(deps-dev): bump the dependencies group with 2 updates (#5504)4367a5crefactor: use 'String#startsWith' & replace if-then-else (#5501)8e6604fchore(deps): bump the dependencies group across 1 directory with 4 updates (#...Updates
react-dev-utilsfrom 9.1.0 to 12.0.1Changelog
Sourced from react-dev-utils's changelog.
... (truncated)
Commits
19fa58dPublisha422bf2Ensure posix compliant joins for urls in middleware (#11640)221e511Publish3afbbc0Update all dependencies (#11624)3880ba6Remove dependency pinning (#11474)5cedfe4Bump browserslist from 4.14.2 to 4.16.5 (#11476)63bba07Upgrade jest and related packages from 26.6.0 to 27.1.0 (#11338)960b21eBump immer from 8.0.4 to 9.0.6 (#11364)f0a837cWebpack 5 (#11201)369fccffix: fast refresh stops on needed bail outs (#11105)Updates
semantic-releasefrom 17.4.7 to 24.2.7Release notes
Sourced from semantic-release's releases.
... (truncated)
Commits
85187e2perf(get-tags.js): bulk get for tags notes (#3732)672f951chore(deps): update dependency@types/nodeto v22.16.3 (#3801)de54db9chore(deps): update dependency@types/nodeto v22.16.2 (#3799)c6da348chore(deps): update dependency@types/nodeto v22.16.1 (#3798)fae2a78chore(deps): lock file maintenance (#3797)fb26b13docs(plugins): addsemantic-release-openapicommunity plugin (#3787)985f165chore(deps): update dependency@types/nodeto v22.16.0 (#3794)c8fea35ci(action): update github/codeql-action action to v3.29.2 (#3793)fab4d88chore(deps): lock file maintenance (#3792)93177d0fix(deps): update@semantic-release/npmto ^12.0.2 (#3791)Updates
wsfrom 8.18.0 to 8.18.3Release notes
Sourced from ws's releases.
Commits
dabbdec[dist] 8.18.333f5dba[fix] Respond with the supported protocol versions (#2291)22a5a17[ci] Test on node 24e67eb7a[ci] Do not test on node 23fa670f2[ci] Run the lint step on node 220eb8535[dist] 8.18.24f20aed[fix] Handle oversized messages with designated error (#2285)aa998e3[pkg] Update globals to version 16.0.0cf25954[minor] Fix nit in error messageb92745a[dist] 8.18.1Updates
aedesfrom 0.39.0 to 0.42.1Release notes
Sourced from aedes's releases.
... (truncated)
Commits
0a0e26cRelease 0.42.1e11148dfix: clean up the write callbacks in case of error (#492)379182fdocs: sdd Kuzzle to made with aedes section (#500)e60f85dfix: remove useless empty buff (#497)86b6815docs: authorizePublish clarification (#496)8d34ee5fix: catch writeToStream errors (#493)28c6cbbBump markdownlint-cli from 0.22.0 to 0.23.1 (#490)6586768Release 0.42.0684aa51fix: remove subs only when clean flag is false (#488)8494fe7Bump@types/nodefrom 13.13.6 to 14.0.1 (#485)Maintainer changes
This version was pushed to npm by roberts_lando, a new releaser for aedes since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.