chore: Bump the npm_and_yarn group across 15 directories with 29 updates#4
chore: Bump the npm_and_yarn group across 15 directories with 29 updates#4dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 22 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@babel/runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-runtime) | `7.16.3` | `7.26.10` | | [gh-pages](https://github.com/tschaub/gh-pages) | `3.2.3` | `5.0.0` | | [rollup](https://github.com/rollup/rollup) | `1.14.6` | `2.80.0` | | [form-data](https://github.com/form-data/form-data) | `4.0.0` | `4.0.4` | | [node-fetch](https://github.com/node-fetch/node-fetch) | `2.6.6` | `2.6.7` | | [minimist](https://github.com/minimistjs/minimist) | `1.2.5` | `1.2.6` | | [webpack](https://github.com/webpack/webpack) | `5.64.4` | `5.104.1` | | [body-parser](https://github.com/expressjs/body-parser) | `1.19.0` | `1.20.3` | | [express](https://github.com/expressjs/express) | `4.17.1` | `4.22.0` | | [url-parse](https://github.com/unshiftio/url-parse) | `1.5.3` | `1.5.9` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.4.5` | `7.29.0` | | [browserify-sign](https://github.com/crypto-browserify/browserify-sign) | `4.0.4` | `4.2.5` | | [cipher-base](https://github.com/crypto-browserify/cipher-base) | `1.0.4` | `1.0.7` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [docsify](https://github.com/docsifyjs/docsify) | `4.12.1` | `4.13.1` | | [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.5.5` | `1.15.11` | | [fsevents](https://github.com/fsevents/fsevents) | `1.2.9` | `1.2.13` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.1.2` | `4.7.8` | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.17.23` | | [postcss](https://github.com/postcss/postcss) | `8.4.3` | `8.5.6` | | [sha.js](https://github.com/crypto-browserify/sha.js) | `2.4.11` | `2.4.12` | | [socket.io](https://github.com/socketio/socket.io) | `4.4.0` | `4.8.3` | Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-fetch directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-node-http directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-puppeteer directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-xhr directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/cli directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/core directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/node-server directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-fs directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-in-memory directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-local-storage directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-rest directory: [rollup](https://github.com/rollup/rollup). Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/utils directory: [rollup](https://github.com/rollup/rollup). Updates `@babel/runtime` from 7.16.3 to 7.26.10 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.26.10/packages/babel-runtime) Updates `gh-pages` from 3.2.3 to 5.0.0 - [Release notes](https://github.com/tschaub/gh-pages/releases) - [Changelog](https://github.com/tschaub/gh-pages/blob/main/changelog.md) - [Commits](tschaub/gh-pages@v3.2.3...v5.0.0) Updates `rollup` from 1.14.6 to 2.80.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `form-data` from 4.0.0 to 4.0.4 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v4.0.0...v4.0.4) Updates `node-fetch` from 2.6.6 to 2.6.7 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v2.6.6...v2.6.7) Updates `minimist` from 1.2.5 to 1.2.6 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.5...v1.2.6) Updates `webpack` from 5.64.4 to 5.104.1 - [Release notes](https://github.com/webpack/webpack/releases) - [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md) - [Commits](webpack/webpack@v5.64.4...v5.104.1) Updates `body-parser` from 1.19.0 to 1.20.3 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.19.0...1.20.3) Updates `express` from 4.17.1 to 4.22.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md) - [Commits](expressjs/express@4.17.1...4.22.0) Updates `qs` from 6.10.1 to 6.14.2 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.10.1...v6.14.2) Updates `url-parse` from 1.5.3 to 1.5.9 - [Commits](unshiftio/url-parse@1.5.3...1.5.9) Updates `@babel/traverse` from 7.4.5 to 7.29.0 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.0/packages/babel-traverse) Updates `browserify-sign` from 4.0.4 to 4.2.5 - [Changelog](https://github.com/browserify/browserify-sign/blob/main/CHANGELOG.md) - [Commits](browserify/browserify-sign@v4.0.4...v4.2.5) Updates `cipher-base` from 1.0.4 to 1.0.7 - [Changelog](https://github.com/browserify/cipher-base/blob/master/CHANGELOG.md) - [Commits](browserify/cipher-base@v1.0.4...v1.0.7) Updates `cookie` from 0.4.0 to 0.4.1 - [Release notes](https://github.com/jshttp/cookie/releases) - [Changelog](https://github.com/jshttp/cookie/blob/v0.4.1/HISTORY.md) - [Commits](jshttp/cookie@v0.4.0...v0.4.1) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `docsify` from 4.12.1 to 4.13.1 - [Release notes](https://github.com/docsifyjs/docsify/releases) - [Changelog](https://github.com/docsifyjs/docsify/blob/develop/CHANGELOG.md) - [Commits](docsifyjs/docsify@v4.12.1...v4.13.1) Updates `follow-redirects` from 1.5.5 to 1.15.11 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.5.5...v1.15.11) Updates `fsevents` from 1.2.9 to 1.2.13 - [Release notes](https://github.com/fsevents/fsevents/releases) - [Commits](fsevents/fsevents@v1.2.9...v1.2.13) Updates `handlebars` from 4.1.2 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.1.2...v4.7.8) Updates `lodash` from 4.17.21 to 4.17.23 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.17.23) Updates `path-to-regexp` from 0.1.7 to 0.1.12 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v0.1.7...v0.1.12) Updates `postcss` from 8.4.3 to 8.5.6 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.3...8.5.6) Updates `prismjs` from 1.25.0 to 1.30.0 - [Release notes](https://github.com/PrismJS/prism/releases) - [Changelog](https://github.com/PrismJS/prism/blob/v2/CHANGELOG.md) - [Commits](PrismJS/prism@v1.25.0...v1.30.0) Updates `send` from 0.17.1 to 0.19.2 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.17.1...0.19.2) Updates `serve-static` from 1.14.1 to 1.16.3 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md) - [Commits](expressjs/serve-static@v1.14.1...v1.16.3) Updates `sha.js` from 2.4.11 to 2.4.12 - [Changelog](https://github.com/browserify/sha.js/blob/master/CHANGELOG.md) - [Commits](browserify/sha.js@v2.4.11...v2.4.12) Updates `socket.io` from 4.4.0 to 4.8.3 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/compare/4.4.0...socket.io@4.8.3) Updates `tar` from 4.4.10 to 4.4.19 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v4.4.10...v4.4.19) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) Updates `rollup` from 1.32.1 to 4.59.0 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/v2.80.0/CHANGELOG.md) - [Commits](rollup/rollup@v1.14.6...v2.80.0) --- updated-dependencies: - dependency-name: "@babel/runtime" dependency-version: 7.26.10 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: gh-pages dependency-version: 5.0.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 2.80.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: form-data dependency-version: 4.0.4 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-version: 2.6.7 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: minimist dependency-version: 1.2.6 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: webpack dependency-version: 5.104.1 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: body-parser dependency-version: 1.20.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-version: 4.22.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: qs dependency-version: 6.14.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: url-parse dependency-version: 1.5.9 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-version: 7.29.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: browserify-sign dependency-version: 4.2.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cipher-base dependency-version: 1.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-version: 0.4.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-version: 0.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: docsify dependency-version: 4.13.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-version: 1.15.11 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fsevents dependency-version: 1.2.13 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-version: 4.7.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.23 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-to-regexp dependency-version: 0.1.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: postcss dependency-version: 8.5.6 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: prismjs dependency-version: 1.30.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-version: 0.19.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-version: 1.16.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: sha.js dependency-version: 2.4.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: socket.io dependency-version: 4.8.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 4.4.19 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.59.0 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 3 potential issues.
Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
| "body-parser": "^2.2.2", | ||
| "cors": "^2.8.5", | ||
| "express": "^4.17.1", | ||
| "express": "^5.2.1", |
There was a problem hiding this comment.
Express bumped to v5 instead of v4.22
High Severity
The express production dependency is bumped to ^5.2.1 instead of ^4.22.0 as described in the PR. Express 5 is a major rewrite with breaking changes including path route matching syntax changes, removed methods like res.sendfile() and req.param(), and requiring Node.js 18+. Similarly, body-parser is bumped to ^2.2.2 instead of ^1.20.3, which drops bodyParser() combination middleware and changes req.body initialization behavior. These are production dependencies of @pollyjs/node-server and will affect all consumers.
Additional Locations (1)
| "get-stream": "^6.0.1", | ||
| "node-fetch": "^2.6.6", | ||
| "rollup": "^1.14.6" | ||
| "node-fetch": "^3.3.2", |
There was a problem hiding this comment.
node-fetch bumped to ESM-only v3 breaking tests
High Severity
node-fetch is bumped from ^2.6.6 to ^3.3.2 instead of the described ^2.6.7. node-fetch v3 is ESM-only and cannot be used with require(). Several files use require('node-fetch') (e.g., example files) and named imports like import { Response } from 'node-fetch' whose constructor behavior changed in v3. This will break the test suite in both adapter-node-http and adapter-puppeteer packages.
Additional Locations (1)
| }, | ||
| "devDependencies": { | ||
| "rollup": "^1.14.6" | ||
| "rollup": "^4.59.0" |
There was a problem hiding this comment.
Sub-package rollup v4 incompatible with v1 plugins
Medium Severity
All 14 sub-packages bump rollup to ^4.59.0 while the root bumps to ^2.80.0. The PR describes bumping rollup to 2.80.0, not 4.x. The shared rollup configs in scripts/rollup/ use legacy plugins (rollup-plugin-commonjs, rollup-plugin-node-resolve, rollup-plugin-babel) that are incompatible with rollup v4, which requires the renamed @rollup/plugin-* equivalents. This will break all package builds.


Bumps the npm_and_yarn group with 22 updates in the / directory:
7.16.37.26.103.2.35.0.01.14.62.80.04.0.04.0.42.6.62.6.71.2.51.2.65.64.45.104.11.19.01.20.34.17.14.22.01.5.31.5.97.4.57.29.04.0.44.2.51.0.41.0.70.2.00.2.24.12.14.13.11.5.51.15.111.2.91.2.134.1.24.7.84.17.214.17.238.4.38.5.62.4.112.4.124.4.04.8.3Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-fetch directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-node-http directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-puppeteer directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/adapter-xhr directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/cli directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/core directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/node-server directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-fs directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-in-memory directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-local-storage directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/persister-rest directory: rollup.
Bumps the npm_and_yarn group with 1 update in the /packages/@pollyjs/utils directory: rollup.
Updates
@babel/runtimefrom 7.16.3 to 7.26.10Release notes
Sourced from
@babel/runtime's releases.... (truncated)
Commits
e1ce99dv7.26.10d5952e8Fix processing of replacement pattern with named capture groups (#17173)64bca7bv7.26.92d95140v7.26.763d3038v7.26.0b07957ev7.25.9af91759fix: Accidentally publishing useless files (#16917)2533cfbv7.25.769d65f1[babel 8] Require Node.js^18.20.0 || ^20.17.0 || >=22.8.0(#16800)2f72b97v7.25.6Updates
gh-pagesfrom 3.2.3 to 5.0.0Release notes
Sourced from gh-pages's releases.
Changelog
Sourced from gh-pages's changelog.
Commits
f729b975.0.051534c7Log changesace063bMerge pull request #438 from Vicropht/patch-158e54beMerge pull request #459 from tschaub/dependabot/npm_and_yarn/async-3.2.42189df3Bump async from 2.6.4 to 3.2.4051846eMerge pull request #454 from tschaub/dependabot/npm_and_yarn/email-addresses-...5c91c67Merge pull request #455 from tschaub/dependabot/github_actions/actions/setup-...fe0ad83Merge pull request #453 from tschaub/dependabot/github_actions/actions/checko...b89287dMerge pull request #445 from Nezteb/patch-1e890bd1Bump email-addresses from 3.0.1 to 5.0.0Updates
rollupfrom 1.14.6 to 2.80.0Release notes
Sourced from rollup's releases.
Changelog
Sourced from rollup's changelog.
... (truncated)
Commits
d17ae152.80.0d6dee5eValidate bundle stays within output dir (#6277)c9bd03d2.79.248aef33fix: resolve DOM Clobbering CVE-2024-43788 (backport to v2) (#5677)69ff4182.79.104dce1bUpdate changelog159137efix: typo docs and contributors link in CONTRIBUTING.md (#4639)e1392b3Update type definition of resolveId (#4641)7836357Improve performance of chunk naming collision check (#4643)71d20c9Reduce permissions for repl-artefacts.yml workflow (#4630)Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
form-datafrom 4.0.0 to 4.0.4Release notes
Sourced from form-data's releases.
... (truncated)
Changelog
Sourced from form-data's changelog.
... (truncated)
Commits
41996f5v4.0.4316c82b[meta] actually ensure the readme backup isn’t published2300ca1[meta] fix readme capitalization811f682[meta] addauto-changelog5e34080[Tests] fix linting errors1d11a76[Tests] handle predict-v8-randomness failures in node < 17 and node > 2358c25d7[Dev Deps] update@ljharb/eslint-config3d17230[Fix] Switch to usingcryptorandom for boundary valuesd8d67dcv4.0.3e6e83cc[meta] remove local commit hooksMaintainer changes
This version was pushed to npm by ljharb, a new releaser for form-data since your current version.
Install script changes
This version modifies
prepublishscript that runs during installation. Review the package contents before updating.Updates
node-fetchfrom 2.6.6 to 2.6.7Release notes
Sourced from node-fetch's releases.
Commits
1ef4b56backport of #1449 (#1453)8fe5c4e2.x: Specify encoding as an optional peer dependency in package.json (#1310)Updates
minimistfrom 1.2.5 to 1.2.6Changelog
Sourced from minimist's changelog.
Commits
7efb22a1.2.6ef88b93security notice for additional prototype pollution issuec2b9819isConstructorOrProto adapted from PRbc8eceetest from prototype pollution PRUpdates
webpackfrom 5.64.4 to 5.104.1Release notes
Sourced from webpack's releases.
... (truncated)
Changelog
Sourced from webpack's changelog.
Commits
24e3c2dchore(release): new release (#20253)2efd21bfix(re-exports): reexports runtime calculation should not accessing `__WEBPAC...c510070fix(security): userinfo bypass vulnerability in HttpUriPlugin allowedUris4b0501cci: fix release (#20252)0c213ceci: use\<@&1450591255485743204>over@herefor discord notificationw5bf8bc5refactor: types for benchmarks and tests505a5e7chore(release): new release (#20188)0c06680refactor: update eslint configuration2eb0d6aci: release announcement (#20238)b2b2459ci: cancel in progress (#20239)Maintainer changes
This version was pushed to npm by evilebottnawi, a new releaser for webpack since your current version.
Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
body-parserfrom 1.19.0 to 1.20.3Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
17529511.20.339744cfchore: linter (#534)b2695c4Merge commit from forkade0f3fadd scorecard to readme (#531)99a1bd6deps: qs@6.12.3 (#521)9478591fix: pin to node@22.4.183db46aci: fix errors in ci github action for node 8 and 9 (#523)9d4e212chore: add support for OSSF scorecard reporting (#522)ee913741.20.2368a93aFix strict json error message on Node.js 19+Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
expressfrom 4.17.1 to 4.22.0Release notes
Sourced from express's releases.