Bump qs, express and body-parser #150
Closed
dependabot[bot] wants to merge 1 commits from
dependabot/npm_and_yarn/multi-7fc46f649c into main
pull from: dependabot/npm_and_yarn/multi-7fc46f649c
merge into: frishi:main
frishi:main
frishi:dep-hell
frishi:dependabot/npm_and_yarn/picomatch-2.3.2
frishi:dependabot/npm_and_yarn/multi-c136cad177
frishi:dependabot/npm_and_yarn/flatted-3.4.2
frishi:dependabot/npm_and_yarn/socket.io-parser-4.2.6
frishi:dependabot/npm_and_yarn/underscore-1.13.8
frishi:dependabot/npm_and_yarn/svgo-4.0.1
frishi:graphql-refactor
frishi:react-19-upgrade
frishi:airdcpp-regression
frishi:comicvine-integration-improvements
frishi:qbittorrent-integration
frishi:dark-mode-3
frishi:dark-mode-2
frishi:dark-mode-refactor
frishi:dark-mode-refactor-2
frishi:comic-detail-react-query
frishi:zustand-react-query-navbar
frishi:qbittorrent-settings-form
frishi:move-to-zustand-react-query
frishi:import-queue-progress
frishi:service-statuses-settings
frishi:80-vite-env-var-hostname-fix
frishi:76-hostname-docker-context-fix
frishi:71-dockerfile-update
frishi:comicvine-import-improvements
frishi:bugfix-#59
frishi:relocating-screenshots
frishi:storybook-7-upgrade
frishi:elasticsearch-upgrade-fix
frishi:vite-build-system
frishi:funding-fix
frishi:funding
frishi:service-statuses
frishi:dcpp-socket-status
frishi:dev
frishi:rishighan-screenshots-dec-2022
No Reviewers
Labels
Clear labels
P0
bug
catch-all
dependencies
documentation
duplicate
enhancement
fix
good first issue
help wanted
invalid
javascript
major
question
refactor
tech debt
testing-required
wontfix
Game-stopping bug
Something isn't working
Holding place for similar issues
Pull requests that update a dependency file
Improvements or additions to documentation
This issue or pull request already exists
New feature or request
Good for newcomers
Extra attention is needed
This doesn't seem right
Pull requests that update javascript code
Further information is requested
Fix issued, but tests are pending
This will not be worked on
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: frishi/threetwo#150
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "dependabot/npm_and_yarn/multi-7fc46f649c"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Bumps qs to 6.15.0 and updates ancestor dependencies qs, express and body-parser. These dependencies need to be updated together.
Updates
qsfrom 6.11.0 to 6.15.0Changelog
Sourced from qs's changelog.
... (truncated)
Commits
d9b4c66v6.15.0cb41a54[New]parse: addstrictMergeoption to wrap object/primitive conflicts in...88e1563[Fix]duplicatesoption should not apply to bracket notation keys9d441d2Merge backport release tags v6.0.6–v6.13.3 into main85cc8cav6.12.5ffc12aav6.11.40506b11[actions] update reusable workflows6a37faf[actions] update reusable workflows8e8df5a[Fix] fix regressions from robustness refactord60bab3v6.10.7Updates
expressfrom 4.20.0 to 4.22.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
12fae144.22.15ddf311Revert "sec: security patch for CVE-2024-51999"49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)Maintainer changes
This version was pushed to npm by jonchurch, a new releaser for express since your current version.
Updates
body-parserfrom 1.20.3 to 1.20.4Release notes
Sourced from body-parser's releases.
Changelog
Sourced from body-parser's changelog.
Commits
7db202c1.20.4 (#672)d8f8adbci: add CodeQL (SAST) (#670)6d133c1chore: remove SECURITY.md (#669)fcd1535deps: use tilde notation and update certain dependencies (#668)ec5fa29deps: qs@~6.14.0 (#664)ffb95c1ci: restore CI for 1.x branch (#665)48a5f07ci: add support for Node.js v23 (#553)f20f6adRemove redundant depth check (#538)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Looks like these dependencies are up-to-date now, so this is no longer needed.
Pull request closed