Update helmet 8.1.0 → 8.2.0 (minor)#78
Open
depfu[bot] wants to merge 1 commit into
Open
Conversation
Not up to standards ⛔🔴 Issues
|
| Category | Results |
|---|---|
| Security | 2 medium 1 high |
🟢 Metrics 0 complexity · 0 duplication
Metric Results Complexity 0 Duplication 0
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ helmet (8.1.0 → 8.2.0) · Repo · Changelog
Release Notes
8.2.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 57 commits:
8.2.0Update changelog for 8.2.0 releaseUpdate devDependencies to latest versionsTest supported Node versions on CIUpdate to new URLAdd direct link to FAQBump actions/setup-node from 6.3.0 to 6.4.0 (#537)Upgrade actions/setup-node to 6.3.0Fix changelog typoBump Picomatch dev sub-dependencyUpdate another X-Frame-Options ALLOW-FROM linkUpdate X-Frame-Options ALLOW-FROM linkUpdate Origin-Agent-Cluster spec linkUpdate MSDN linkFix bad links in changelogUpdate changelog with Cross-Origin-Opener-Policy changeCross-Origin-Opener-Policy: support noopener-allow-popupsUpdate devDependencies to latest versionsFix MDN link for Cross-Origin-Embedder-PolicyUpdate devDependencies to latest versionsUpdate ESLint dependencies to latest versionsUpdate devDependencies to latest versionsBump actions/setup-node from 6.1.0 to 6.2.0Bump actions/checkout from 6.0.1 to 6.0.2Update devDependencies to latest versionsUpdate license year for 2026Update GitHub Actions versionsUpdate devDependencies to latest versionsTweak readmeUpdate checkout GH Action to latest versionUpdate devDependencies to latest versionsUpdate devDependencies to latest versionsUpdate ESLint to fix bugUpdate devDependencies to latest versionsBump actions/setup-node from 5.0.0 to 6.0.0Bump actions/setup-node from 4.4.0 to 5.0.0Update devDependencies to latest versionsDiscourage AI in contribution guidelinesAdd "funding" key to package.jsonUpdate devDependencies to latest versionsTweaks to SECURITY.md: just me, contact info, IRPUpdate checkout GH Action to latest versionUpdate devDependencies to latest versionsDocument `upgrade-insecure-requests` strategy in developmentUpdate devDependencies to latest versions, install tslibMinor tweaks to readme introductionUpdate devDependencies to latest versionsFix test for all middlewares disabledImprove error message when passing duplicate optionsUpdate devDependencies to latest versionsUpdate devDependencies to latest versionsCI: test with Node 24Bump setup-node CI action to latest versionSimplify source file testUpdate devDependencies to latest versionsUpdate devDependencies to latest versionsReference GitHub Actions by commit hashRelease Notes
17.2.3 (from changelog)
17.2.2 (from changelog)
17.2.1 (from changelog)
17.2.0 (from changelog)
17.1.0 (from changelog)
17.0.1 (from changelog)
17.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
2.0.4 (from changelog)
2.0.3 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 10 commits:
v2.0.4[types] drop the dead key-narrowing overload[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `eslint`v2.0.3[actions] update workflows[types] add overload that narrows the key[Dev Deps] update `@arethetypeswrong/cli`, `@ljharb/eslint-config`, `@ljharb/tsconfig`, `@types/tape`, `auto-changelog`, `eslint`, `mock-property`, `npmignore`, `tape`[Dev Deps] update `eslint`[Dev Deps] update `eslint`, `@ljharb/eslint-config`; migrate to flat config[meta] use `npm audit` instead of `aud`🆕 @types/graceful-fs (added, 4.1.9)
🆕 create-jest (added, 29.7.0)
🆕 diff-sequences (added, 29.6.3)
🆕 exit (added, 0.1.2)
🆕 is-core-module (added, 2.16.2)
🆕 jest-get-type (added, 29.6.3)
🆕 kleur (added, 3.0.3)
🆕 path-parse (added, 1.0.7)
🆕 prompts (added, 2.4.2)
🆕 resolve (added, 1.22.12)
🆕 resolve.exports (added, 2.0.3)
🆕 sisteransi (added, 1.0.5)
🆕 supports-preserve-symlinks-flag (added, 1.0.0)
🆕 @jest/console (added, 29.7.0)
🆕 @jest/core (added, 29.7.0)
🆕 @jest/environment (added, 29.7.0)
🆕 @jest/expect (added, 29.7.0)
🆕 @jest/expect-utils (added, 29.7.0)
🆕 @jest/fake-timers (added, 29.7.0)
🆕 @jest/globals (added, 29.7.0)
🆕 @jest/reporters (added, 29.7.0)
🆕 @jest/schemas (added, 29.6.3)
🆕 @jest/source-map (added, 29.6.3)
🆕 @jest/test-result (added, 29.7.0)
🆕 @jest/test-sequencer (added, 29.7.0)
🆕 @jest/transform (added, 29.7.0)
🆕 @jest/types (added, 29.6.3)
🆕 @sinclair/typebox (added, 0.27.10)
🆕 @sinonjs/fake-timers (added, 10.3.0)
🆕 babel-jest (added, 29.7.0)
🆕 babel-plugin-istanbul (added, 6.1.1)
🆕 babel-plugin-jest-hoist (added, 29.6.3)
🆕 babel-preset-jest (added, 29.6.3)
🆕 ci-info (added, 3.9.0)
🆕 cjs-module-lexer (added, 1.4.3)
🆕 wrap-ansi (added, 8.1.0)
🆕 expect (added, 29.7.0)
🆕 istanbul-lib-instrument (added, 5.2.1)
🆕 semver (added, 7.8.3)
🆕 istanbul-lib-source-maps (added, 4.0.1)
🆕 jest-changed-files (added, 29.7.0)
🆕 jest-circus (added, 29.7.0)
🆕 jest-config (added, 29.7.0)
🆕 jest-diff (added, 29.7.0)
🆕 jest-docblock (added, 29.7.0)
🆕 jest-each (added, 29.7.0)
🆕 jest-environment-node (added, 29.7.0)
🆕 jest-haste-map (added, 29.7.0)
🆕 jest-leak-detector (added, 29.7.0)
🆕 jest-matcher-utils (added, 29.7.0)
🆕 jest-message-util (added, 29.7.0)
🆕 jest-mock (added, 29.7.0)
🆕 jest-regex-util (added, 29.6.3)
🆕 jest-resolve (added, 29.7.0)
🆕 jest-resolve-dependencies (added, 29.7.0)
🆕 jest-runner (added, 29.7.0)
🆕 jest-runtime (added, 29.7.0)
🆕 jest-snapshot (added, 29.7.0)
🆕 jest-util (added, 29.7.0)
🆕 jest-validate (added, 29.7.0)
🆕 jest-watcher (added, 29.7.0)
🆕 jest-worker (added, 29.7.0)
🆕 pretty-format (added, 29.7.0)
🆕 pure-rand (added, 6.1.0)
🆕 write-file-atomic (added, 5.0.1)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands