Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jan 11, 2023

Bumps debug to 2.6.9 and updates ancestor dependencies debug, mongoose, socket.io and fsevents. These dependencies need to be updated together.

Updates debug from 2.2.0 to 2.6.9

Release notes

Sourced from debug's releases.

2.6.9

Patches

  • Remove ReDoS regexp in %o formatter: #504

Credits

Huge thanks to @​zhuangya for their help!

release 2.6.7

No release notes provided.

release 2.6.6

No release notes provided.

release 2.6.5

No release notes provided.

release 2.6.4

No release notes provided.

release 2.6.3

No release notes provided.

release 2.6.2

No release notes provided.

release 2.6.1

No release notes provided.

release 2.6.0

No release notes provided.

release 2.5.2

No release notes provided.

release 2.5.1

No release notes provided.

release 2.4.5

No release notes provided.

release 2.4.4

No release notes provided.

release 2.4.3

No release notes provided.

release 2.4.2

No release notes provided.

... (truncated)

Changelog

Sourced from debug's changelog.

2.6.9 / 2017-09-22

  • remove ReDoS regexp in %o formatter (#504)

2.6.8 / 2017-05-18

2.6.7 / 2017-05-16

2.6.5 / 2017-04-27

2.6.4 / 2017-04-20

2.6.3 / 2017-03-13

2.6.2 / 2017-03-10

2.6.1 / 2017-02-10

  • Fix: Module's export default syntax fix for IE8 Expected identifier error
  • Fix: Whitelist DEBUG_FD for values 1 and 2 only (#415, @​pi0)

... (truncated)

Commits

Updates mongoose from 4.5.8 to 4.13.21

Changelog

Sourced from mongoose's changelog.

4.13.21 / 2020-07-12

  • fix(query): delete top-level _bsontype property in queries to prevent silent empty queries #8222

5.9.23 / 2020-07-10

  • fix(model): fix syncIndexes() error when db index has a collation but Mongoose index does not #9224 clhuang
  • fix(array): only cast array to proper depth if it contains an non-array value #9217 #9215 cyrilgandon
  • docs(schematype): document the transform option #9211
  • docs(mongoose): fix typo #9212 JNa0

5.9.22 / 2020-07-06

  • fix(schema): treat { type: mongoose.Schema.Types.Array } as equivalent to { type: Array } #9194
  • fix: revert fix for #9107 to avoid issues when calling connect() multiple times #9167
  • fix(update): respect storeSubdocValidationError option with update validators #9172
  • fix: upgrade to safe-buffer 5.2 #9198
  • docs: add a note about SSL validation to migration guide #9147
  • docs(schemas): fix inconsistent header #9196 samtsai15

5.9.21 / 2020-07-01

  • fix: propagate typeKey option to implicitly created schemas from typePojoToMixed #9185 joaoritter
  • fix(populate): handle embedded discriminator refPath with multiple documents #9153
  • fix(populate): handle deselected foreign field with perDocumentLimit and multiple documents #9175
  • fix(document): disallow transform functions that return promises #9176 #9163 AbdelrahmanHafez
  • fix(document): use strict equality when checking mixed paths for modifications #9165
  • docs: add target="_blank" to all edit links #9058

5.9.20 / 2020-06-22

  • fix(populate): handle populating primitive array under document array discriminator #9148
  • fix(connection): make sure to close previous connection when calling openUri() on an already open connection #9107
  • fix(model): fix conflicting $setOnInsert default values with update values in bulkWrite #9160 #9157 AbdelrahmanHafez
  • docs(validation): add note about validateBeforeSave and invalidate #9144 dandv
  • docs: specify the array field syntax for invalidate #9137 dandv
  • docs: fix several typos and broken references #9024 AbdelrahmanHafez
  • docs: fix minor typo #9143 dandv

5.9.19 / 2020-06-15

  • fix: upgrade mongodb driver -> 3.5.9 #9124 AbdelrahmanHafez
  • fix: copy required validator on single nested subdoc correctly when calling Schema#clone() #8819
  • fix(discriminator): handle tiedValue when casting update on nested paths #9108
  • fix(model): allow empty arrays for bulkWrite #9132 #9131 AbdelrahmanHafez
  • fix(schema): correctly set partialFilterExpression for nested schema indexes #9091
  • fix(castArrayFilters): handle casting on all fields of array filter #9122 lafeuil
  • fix(update): handle nested path createdAt when overwriting parent path #9105
  • docs(subdocs): add some notes on the difference between single nested subdocs and nested paths #9085
  • docs(subdocs): improve docs on typePojoToMixed #9085

... (truncated)

Commits
  • f88eb25 fix(query): delete top-level _bsontype property in queries to prevent silen...
  • 1db031c test(schema): clean up messy tests re: #8459
  • 8fa8012 test: test cleanup re: #8459
  • 4a55040 chore: remove problematic mongoose-long dep and use mongodb 3.4 in tests
  • 91f95da chore: run consistent mongod version in tests
  • 0e65e6e chore: release 4.13.20
  • 803090d fix(schema): make aliases handle mongoose-lean-virtuals
  • 6a8b381 chore: add .config.js to gitignore and npmignore
  • f51c4aa chore: release 4.13.19
  • 2aeeaa8 Merge pull request #7950 from cdimitroulas/backport-aggregate-options-bugfix
  • Additional commits viewable in compare view

Updates socket.io from 1.4.8 to 4.5.4

Release notes

Sourced from socket.io's releases.

4.5.4

This release contains a bump of:

Links:

4.5.3

Bug Fixes

  • typings: accept an HTTP2 server in the constructor (d3d0a2d)
  • typings: apply types to "io.timeout(...).emit()" calls (e357daf)

Links:

4.5.2

Bug Fixes

  • prevent the socket from joining a room after disconnection (18f3fda)
  • uws: prevent the server from crashing after upgrade (ba497ee)

Links:

4.5.1

Bug Fixes

  • forward the local flag to the adapter when using fetchSockets() (30430f0)
  • typings: add HTTPS server to accepted types (#4351) (9b43c91)

Links:

... (truncated)

Changelog

Sourced from socket.io's changelog.

4.5.4 (2022-11-22)

This release contains a bump of:

Dependencies

4.5.3 (2022-10-15)

Bug Fixes

  • typings: accept an HTTP2 server in the constructor (d3d0a2d)
  • typings: apply types to "io.timeout(...).emit()" calls (e357daf)

4.5.2 (2022-09-02)

Bug Fixes

  • prevent the socket from joining a room after disconnection (18f3fda)
  • uws: prevent the server from crashing after upgrade (ba497ee)

2.5.0 (2022-06-26)

Bug Fixes

  • fix race condition in dynamic namespaces (05e1278)
  • ignore packet received after disconnection (22d4bdf)
  • only set 'connected' to true after middleware execution (226cc16)
  • prevent the socket from joining a room after disconnection (f223178)

4.5.1 (2022-05-17)

Bug Fixes

... (truncated)

Commits
  • 3b7ced7 chore(release): 4.5.4
  • c00bb95 chore: bump engine.io to version 6.2.1
  • 57e5f25 chore: bump socket.io-parser to version 4.2.1
  • f4b6984 docs: add missing versions in the changelog
  • 945c84b chore(release): 4.5.3
  • d3d0a2d fix(typings): accept an HTTP2 server in the constructor
  • 19b225b docs(examples): update dependencies of the basic CRUD example
  • 8fae95d docs: add jsdoc for each public method
  • e6f6b90 docs: add deprecation notice for the allSockets() method
  • 596eb88 ci: upgrade to actions/checkout@3 and actions/setup-node@3
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by darrachequesne, a new releaser for socket.io since your current version.


Updates fsevents from 1.0.14 to 1.2.13

Release notes

Sourced from fsevents's releases.

Release v1.2.13

Only build on Mac-OSX

Release v1.2.11

Removing node-pre-gyp so that building fsevents becomes easier and enabled without the download of binaries.

The credentials to the AWS store have been lost. Releasing to AWS is both insecure and no longer possible due to the lost credentials.

Intermediate Release

No release notes provided.

Release v1.2.9 - Node v12 compatibility

No release notes provided.

Release Pre-NAPI v1.2.8

No release notes provided.

Version Bump (bundle node-pre-gyp)

No release notes provided.

Prebuilt v11.x

No release notes provided.

v1.2.3

  • Added node v10 for pre-built binaries
  • C++ tuning to fix potential SIGILL and cyclic dependency (#204)

v1.2.2

Fixed node-pre-gyp bundling issue

v1.2.1

[unpublished because of errors during publish process]

v1.2.0

  • BREAKING: End support for Node v0.12. If you are using Node v0.12 please pin your fsevents dependencies to v1.1.3. Not bumping semver major for this release was a compromise solution discussed in #199 and #201.
    • Node v0.10 should continue to work with local compilation for now, but hosted pre-built binaries will no longer be provided. If this is a constraint for you, please pin to an earlier version.
  • Fixed security vulnerability warnings by updating node-pre-gyp to ^0.9.0
  • Compatibility updates for nan v2.9.0

v1.1.3

  • Added node v9 for pre-built binaries
  • Fixed bug related to using --no-bin-links option on install
  • Updated node-pre-gyp to latest version (0.6.39)

v1.1.2

  • Added Node.js v8 to the prebuild binary assets.
  • Stopped prebuilding for io.js (can still be built locally)
  • Updated node-pre-gyp to latest version (0.6.36)

v1.1.1

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [debug](https://github.com/debug-js/debug) to 2.6.9 and updates ancestor dependencies [debug](https://github.com/debug-js/debug), [mongoose](https://github.com/Automattic/mongoose), [socket.io](https://github.com/socketio/socket.io) and [fsevents](https://github.com/fsevents/fsevents). These dependencies need to be updated together.


Updates `debug` from 2.2.0 to 2.6.9
- [Release notes](https://github.com/debug-js/debug/releases)
- [Changelog](https://github.com/debug-js/debug/blob/2.6.9/CHANGELOG.md)
- [Commits](debug-js/debug@2.2.0...2.6.9)

Updates `mongoose` from 4.5.8 to 4.13.21
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@4.5.8...4.13.21)

Updates `socket.io` from 1.4.8 to 4.5.4
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](socketio/socket.io@1.4.8...4.5.4)

Updates `fsevents` from 1.0.14 to 1.2.13
- [Release notes](https://github.com/fsevents/fsevents/releases)
- [Commits](fsevents/fsevents@v1.0.14...v1.2.13)

---
updated-dependencies:
- dependency-name: debug
  dependency-type: indirect
- dependency-name: mongoose
  dependency-type: direct:production
- dependency-name: socket.io
  dependency-type: direct:production
- dependency-name: fsevents
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant