Bump the security group across 1 directory with 7 updates#199
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
Bump the security group across 1 directory with 7 updates#199dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the security group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [devalue](https://github.com/sveltejs/devalue) | `4.3.3` | `5.3.2` | | [@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers) | `0.7.4` | `0.8.70` | | [esbuild](https://github.com/evanw/esbuild) | `0.17.19` | `0.25.4` | | [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `3.111.0` | `4.34.0` | | [form-data](https://github.com/form-data/form-data) | `4.0.2` | `4.0.4` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.2.4` | `6.3.5` | Updates `devalue` from 4.3.3 to 5.3.2 - [Release notes](https://github.com/sveltejs/devalue/releases) - [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md) - [Commits](sveltejs/devalue@v4.3.3...v5.3.2) Updates `@cloudflare/vitest-pool-workers` from 0.7.4 to 0.8.70 - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/vitest-pool-workers/CHANGELOG.md) - [Commits](https://github.com/cloudflare/workers-sdk/commits/@cloudflare/vitest-pool-workers@0.8.70/packages/vitest-pool-workers) Updates `esbuild` from 0.17.19 to 0.25.4 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2023.md) - [Commits](evanw/esbuild@v0.17.19...v0.25.4) Updates `wrangler` from 3.111.0 to 4.34.0 - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/wrangler/CHANGELOG.md) - [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.34.0/packages/wrangler) Updates `form-data` from 4.0.2 to 4.0.4 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v4.0.2...v4.0.4) Updates `undici` from 5.28.5 to 7.15.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v5.28.5...v7.15.0) Updates `vite` from 6.2.4 to 6.3.5 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.3.5/packages/vite) --- updated-dependencies: - dependency-name: devalue dependency-version: 5.3.2 dependency-type: indirect dependency-group: security - dependency-name: "@cloudflare/vitest-pool-workers" dependency-version: 0.8.70 dependency-type: direct:development dependency-group: security - dependency-name: esbuild dependency-version: 0.25.4 dependency-type: indirect dependency-group: security - dependency-name: wrangler dependency-version: 4.34.0 dependency-type: direct:development dependency-group: security - dependency-name: form-data dependency-version: 4.0.4 dependency-type: indirect dependency-group: security - dependency-name: undici dependency-version: 7.15.0 dependency-type: indirect dependency-group: security - dependency-name: vite dependency-version: 6.3.5 dependency-type: indirect dependency-group: security ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the security group with 6 updates in the / directory:
4.3.35.3.20.7.40.8.700.17.190.25.43.111.04.34.04.0.24.0.46.2.46.3.5Updates
devaluefrom 4.3.3 to 5.3.2Release notes
Sourced from devalue's releases.
Changelog
Sourced from devalue's changelog.
Commits
86a6a66Version Packages (#109)0623a47Merge commit from fork02d20e8Version Packages (#108)ae904c5fix stringify not picking up negative zero if a normal zero has appeared befo...e95b87afix pkg.repository8300172fix changeset config434d8aeVersion Packages (#106)67c8334mention support for URL/URLSearchParams/Temporal in READMEfec694dfeat: support URL and URLSearchParams (#92)2896e7bAdd support for Temporal objects (#98)Maintainer changes
This version was pushed to npm by svelte-admin, a new releaser for devalue since your current version.
Updates
@cloudflare/vitest-pool-workersfrom 0.7.4 to 0.8.70Release notes
Sourced from
@cloudflare/vitest-pool-workers's releases.... (truncated)
Changelog
Sourced from
@cloudflare/vitest-pool-workers's changelog.... (truncated)
Commits
dfce01fVersion Packages (#10532)2e2b788Version Packages (#10486)38bdb78chore: bump devalue to 5.3.2 (#10471)25ef29dVersion Packages (#10467)c4fde06Version Packages (#10428)e329195Version Packages (#10406)18701d1Version Packages (#10372)8287f46Version Packages (#10352)53cabb4Use pnpm catalog for workerd & workers-types (#10359)20da05eVersion Packages (#10351)Updates
esbuildfrom 0.17.19 to 0.25.4Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
218d29epublish 0.25.4 to npme66cd0bdev server: simple support for CORS requests (#4171)8bf3368js api: validate some options as arrays of strings1e7375ajs api: simplify comma-separated array validation5f5964drelease notes for #4163adb5284fix: handle__proto__as a computed property in exports and add tests for s...0aa9f7bfix #4169: keep invalid source map URLs unmodified5959289add additional guards for #4114 when using:is()677910bpublish 0.25.3 to npma41040efix #4110: support custom non-IPhostvaluesUpdates
wranglerfrom 3.111.0 to 4.34.0Release notes
Sourced from wrangler's releases.
... (truncated)
Changelog
Sourced from wrangler's changelog.
... (truncated)
Commits
dfce01fVersion Packages (#10532)653f796chore: fix version upload e2e test (#10547)cc47b51Wrangler preview urls default to disabled (#10478)6e8dd80Up max asset count to 100k (#10489)7cb05f5fix: update start script to use build instead of bundle (#10526)c6a39f5fix versions upload positional arg (#10515)c22acc6default max_instances to 1 (#10533)a565291use the nativenode:http2when available (#10536)c71d59erefactor unenv e2e tests now that workerd >= 20250901 (#10537)7211609fix(wrangler): vectorize list-vectors should output valid json (#10517)Updates
form-datafrom 4.0.2 to 4.0.4Release notes
Sourced from form-data's releases.
Changelog
Sourced from form-data's changelog.
Commits
41996f5v4.0.4316c82b[meta] actually ensure the readme backup isn’t published2300ca1[meta] fix readme capitalization811f682[meta] addauto-changelog5e34080[Tests] fix linting errors1d11a76[Tests] handle predict-v8-randomness failures in node < 17 and node > 2358c25d7[Dev Deps] update@ljharb/eslint-config3d17230[Fix] Switch to usingcryptorandom for boundary valuesd8d67dcv4.0.3e6e83cc[meta] remove local commit hooksUpdates
undicifrom 5.28.5 to 7.15.0Release notes
Sourced from undici's releases.