Bump the npm-dependencies group across 1 directory with 32 updates#275
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the npm-dependencies group across 1 directory with 32 updates#275dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the npm-dependencies group with 30 updates in the / directory: | Package | From | To | | --- | --- | --- | | [body-parser](https://github.com/expressjs/body-parser) | `1.20.3` | `2.2.2` | | [ejs](https://github.com/mde/ejs) | `3.1.10` | `5.0.2` | | [express](https://github.com/expressjs/express) | `4.21.2` | `5.2.1` | | [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `7.5.0` | `8.5.2` | | [express-slow-down](https://github.com/express-rate-limit/express-slow-down) | `2.0.3` | `3.1.0` | | [helmet](https://github.com/helmetjs/helmet) | `8.0.0` | `8.2.0` | | [i18next-browser-languagedetector](https://github.com/i18next/i18next-browser-languageDetector) | `8.0.2` | `8.2.1` | | [i18next-http-backend](https://github.com/i18next/i18next-http-backend) | `3.0.1` | `4.0.0` | | [morgan](https://github.com/expressjs/morgan) | `1.10.0` | `1.10.1` | | [pug](https://github.com/pugjs/pug) | `3.0.3` | `3.0.4` | | [react-i18next](https://github.com/i18next/react-i18next) | `15.3.0` | `17.0.8` | | [system-sleep](https://github.com/jochemstoel/nodejs-system-sleep) | `1.3.7` | `1.3.8` | | [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.26.0` | `7.29.0` | | [@babel/preset-env](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-env) | `7.26.0` | `7.29.5` | | [@babel/preset-react](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-react) | `7.26.3` | `7.28.5` | | [babel-loader](https://github.com/babel/babel-loader) | `9.2.1` | `10.1.1` | | [bootstrap](https://github.com/twbs/bootstrap) | `5.3.3` | `5.3.8` | | [eslint](https://github.com/eslint/eslint) | `9.17.0` | `10.4.0` | | [i18next](https://github.com/i18next/i18next) | `24.2.0` | `26.2.0` | | [jquery](https://github.com/jquery/jquery) | `3.7.1` | `4.0.0` | | [mocha](https://github.com/mochajs/mocha) | `11.0.1` | `11.7.6` | | [nyc](https://github.com/istanbuljs/nyc) | `17.1.0` | `18.0.0` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.0.0` | `19.2.6` | | [react-bootstrap](https://github.com/react-bootstrap/react-bootstrap) | `2.10.7` | `2.10.10` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.0.0` | `19.2.6` | | [react-redux](https://github.com/reduxjs/react-redux) | `9.2.0` | `9.3.0` | | [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.1.1` | `7.15.1` | | [supertest](https://github.com/ladjs/supertest) | `7.0.0` | `7.2.2` | | [webpack](https://github.com/webpack/webpack) | `5.97.1` | `5.107.1` | | [webpack-cli](https://github.com/webpack/webpack-cli) | `6.0.1` | `7.0.2` | Updates `body-parser` from 1.20.3 to 2.2.2 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.20.3...v2.2.2) Updates `debug` from 4.4.0 to 4.4.3 - [Release notes](https://github.com/debug-js/debug/releases) - [Commits](debug-js/debug@4.4.0...4.4.3) Updates `ejs` from 3.1.10 to 5.0.2 - [Release notes](https://github.com/mde/ejs/releases) - [Changelog](https://github.com/mde/ejs/blob/main/RELEASE_NOTES_v5.md) - [Commits](mde/ejs@v3.1.10...v5.0.2) Updates `express` from 4.21.2 to 5.2.1 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.21.2...v5.2.1) Updates `express-rate-limit` from 7.5.0 to 8.5.2 - [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases) - [Commits](express-rate-limit/express-rate-limit@v7.5.0...v8.5.2) Updates `express-slow-down` from 2.0.3 to 3.1.0 - [Changelog](https://github.com/express-rate-limit/express-slow-down/blob/main/changelog.md) - [Commits](express-rate-limit/express-slow-down@v2.0.3...v3.1.0) Updates `helmet` from 8.0.0 to 8.2.0 - [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md) - [Commits](helmetjs/helmet@v8.0.0...v8.2.0) Updates `http-errors` from 2.0.0 to 2.0.1 - [Release notes](https://github.com/jshttp/http-errors/releases) - [Changelog](https://github.com/jshttp/http-errors/blob/master/HISTORY.md) - [Commits](jshttp/http-errors@v2.0.0...v2.0.1) Updates `i18next-browser-languagedetector` from 8.0.2 to 8.2.1 - [Changelog](https://github.com/i18next/i18next-browser-languageDetector/blob/master/CHANGELOG.md) - [Commits](i18next/i18next-browser-languageDetector@v8.0.2...v8.2.1) Updates `i18next-http-backend` from 3.0.1 to 4.0.0 - [Changelog](https://github.com/i18next/i18next-http-backend/blob/master/CHANGELOG.md) - [Commits](i18next/i18next-http-backend@v3.0.1...v4.0.0) Updates `morgan` from 1.10.0 to 1.10.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.10.0...1.10.1) Updates `pug` from 3.0.3 to 3.0.4 - [Release notes](https://github.com/pugjs/pug/releases) - [Commits](https://github.com/pugjs/pug/compare/pug@3.0.3...pug@3.0.4) Updates `react-i18next` from 15.3.0 to 17.0.8 - [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md) - [Commits](i18next/react-i18next@v15.3.0...v17.0.8) Updates `system-sleep` from 1.3.7 to 1.3.8 - [Commits](https://github.com/jochemstoel/nodejs-system-sleep/commits) Updates `@babel/core` from 7.26.0 to 7.29.0 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.0/packages/babel-core) Updates `@babel/preset-env` from 7.26.0 to 7.29.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.5/packages/babel-preset-env) Updates `@babel/preset-react` from 7.26.3 to 7.28.5 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.28.5/packages/babel-preset-react) Updates `babel-loader` from 9.2.1 to 10.1.1 - [Release notes](https://github.com/babel/babel-loader/releases) - [Changelog](https://github.com/babel/babel-loader/blob/main/CHANGELOG.md) - [Commits](babel/babel-loader@v9.2.1...v10.1.1) Updates `bootstrap` from 5.3.3 to 5.3.8 - [Release notes](https://github.com/twbs/bootstrap/releases) - [Commits](twbs/bootstrap@v5.3.3...v5.3.8) Updates `eslint` from 9.17.0 to 10.4.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v9.17.0...v10.4.0) Updates `i18next` from 24.2.0 to 26.2.0 - [Release notes](https://github.com/i18next/i18next/releases) - [Changelog](https://github.com/i18next/i18next/blob/master/CHANGELOG.md) - [Commits](i18next/i18next@v24.2.0...v26.2.0) Updates `jquery` from 3.7.1 to 4.0.0 - [Release notes](https://github.com/jquery/jquery/releases) - [Changelog](https://github.com/jquery/jquery/blob/main/changelog.md) - [Commits](jquery/jquery@3.7.1...4.0.0) Updates `mocha` from 11.0.1 to 11.7.6 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/v11.7.6/CHANGELOG.md) - [Commits](mochajs/mocha@v11.0.1...v11.7.6) Updates `nyc` from 17.1.0 to 18.0.0 - [Release notes](https://github.com/istanbuljs/nyc/releases) - [Changelog](https://github.com/istanbuljs/nyc/blob/main/CHANGELOG.md) - [Commits](istanbuljs/nyc@nyc-v17.1.0...nyc-v18.0.0) Updates `react` from 19.0.0 to 19.2.6 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react) Updates `react-bootstrap` from 2.10.7 to 2.10.10 - [Release notes](https://github.com/react-bootstrap/react-bootstrap/releases) - [Changelog](https://github.com/react-bootstrap/react-bootstrap/blob/v2.10.10/CHANGELOG.md) - [Commits](react-bootstrap/react-bootstrap@v2.10.7...v2.10.10) Updates `react-dom` from 19.0.0 to 19.2.6 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react-dom) Updates `react-redux` from 9.2.0 to 9.3.0 - [Release notes](https://github.com/reduxjs/react-redux/releases) - [Changelog](https://github.com/reduxjs/react-redux/blob/master/CHANGELOG.md) - [Commits](reduxjs/react-redux@v9.2.0...v9.3.0) Updates `react-router-dom` from 7.1.1 to 7.15.1 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.15.1/packages/react-router-dom) Updates `supertest` from 7.0.0 to 7.2.2 - [Release notes](https://github.com/ladjs/supertest/releases) - [Commits](forwardemail/supertest@v7.0.0...v7.2.2) Updates `webpack` from 5.97.1 to 5.107.1 - [Release notes](https://github.com/webpack/webpack/releases) - [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md) - [Commits](webpack/webpack@v5.97.1...v5.107.1) Updates `webpack-cli` from 6.0.1 to 7.0.2 - [Release notes](https://github.com/webpack/webpack-cli/releases) - [Changelog](https://github.com/webpack/webpack-cli/blob/main/CHANGELOG.md) - [Commits](https://github.com/webpack/webpack-cli/compare/webpack-cli@6.0.1...webpack-cli@7.0.2) --- updated-dependencies: - dependency-name: body-parser dependency-version: 2.2.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: debug dependency-version: 4.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: ejs dependency-version: 5.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: express dependency-version: 5.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: express-rate-limit dependency-version: 8.5.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: express-slow-down dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: helmet dependency-version: 8.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: http-errors dependency-version: 2.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: i18next-browser-languagedetector dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: i18next-http-backend dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: morgan dependency-version: 1.10.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: pug dependency-version: 3.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: react-i18next dependency-version: 17.0.8 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: system-sleep dependency-version: 1.3.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@babel/core" dependency-version: 7.29.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: "@babel/preset-env" dependency-version: 7.29.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: "@babel/preset-react" dependency-version: 7.28.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: babel-loader dependency-version: 10.1.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: bootstrap dependency-version: 5.3.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: eslint dependency-version: 10.4.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: i18next dependency-version: 26.2.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: jquery dependency-version: 4.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: mocha dependency-version: 11.7.6 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: nyc dependency-version: 18.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: react dependency-version: 19.2.6 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: react-bootstrap dependency-version: 2.10.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: react-dom dependency-version: 19.2.6 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: react-redux dependency-version: 9.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: react-router-dom dependency-version: 7.15.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: supertest dependency-version: 7.2.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: webpack dependency-version: 5.107.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: webpack-cli dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-dependencies group with 30 updates in the / directory:
1.20.32.2.23.1.105.0.24.21.25.2.17.5.08.5.22.0.33.1.08.0.08.2.08.0.28.2.13.0.14.0.01.10.01.10.13.0.33.0.415.3.017.0.81.3.71.3.87.26.07.29.07.26.07.29.57.26.37.28.59.2.110.1.15.3.35.3.89.17.010.4.024.2.026.2.03.7.14.0.011.0.111.7.617.1.018.0.019.0.019.2.62.10.72.10.1019.0.019.2.69.2.09.3.07.1.17.15.17.0.07.2.25.97.15.107.16.0.17.0.2Updates
body-parserfrom 1.20.3 to 2.2.2Release notes
Sourced from body-parser's releases.
... (truncated)
Changelog
Sourced from body-parser's changelog.
... (truncated)
Commits
3d248662.2.2 (#691)8474a98refactor(json): simplify strict mode error string construction (#693)03f17c2deps: qs@^6.14.1 (#689)ea1f25edocs: use standard jsdoc tags everywhere (#677)d7deef8docs: update URL-encoded parser description to include ISO-8859-1 encoding su...b6f52aadocs: release notes for the v1.20.4 release (#674)2965ca4docs: update links (#673)d96b63d2.2.1 (#659)b204886sec: security patch for CVE-2025-13466e20e351feat: removehistory.mdfrom being packaged on publish (#660)Updates
debugfrom 4.4.0 to 4.4.3Release notes
Sourced from debug's releases.
Commits
6b2c5fb4.4.333330fa4.4.198df33eremove istanbulbf2f574fixes #987 fallback to localStorage.DEBUG if debug is not defined (#988)a0497bdReplace whitespaces in namespaces string with commas globally instead of just...Updates
ejsfrom 3.1.10 to 5.0.2Release notes
Sourced from ejs's releases.
Changelog
Sourced from ejs's changelog.
... (truncated)
Commits
a464c96Version 5.0.2b4f7b49Hardening2b15562Added release notesf9ab0b7Version 5.0.1173c46fBump version for release35ad41bRemoved Jakebf142d1Updated version number3cd835cRemove broken playground link6e1289cFix minification5090873Fixes #746, removed old 'client' flagUpdates
expressfrom 4.21.2 to 5.2.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
dbac7415.2.1697547cRevert "sec: security patch for CVE-2024-51999"4007ad1Release: 5.2.0 (#6920)2f64f68sec: security patch for CVE-2024-51999ed0ba3fbuild(deps): bump actions/checkout from 5.0.0 to 6.0.0 (#6928)8eace46build(deps): bump github/codeql-action from 4.31.2 to 4.31.6 (#6929)30bae81build(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 (#6930)758d435deps: body-parser@^2.2.1 (#6922)77bcd52docs: update emeritus triagers (#6890)f33caf1Nominate to@efekrsklfor triage team (#6888)Updates
express-rate-limitfrom 7.5.0 to 8.5.2Release notes
Sourced from express-rate-limit's releases.
Commits
97746938.5.20e94cc0v8.5.2 changelog9a583c5feat: simplify IPv6 key generation (#633)4f4b3fbchore(deps-dev): bump lint-staged from 16.4.0 to 17.0.4 (#632)3c1d6c5chore(deps-dev): bump the development-dependencies group with 7 updates (#631)18884b6chore(deps): bump basic-ftp from 5.2.0 to 5.3.1 (#630)dacc980chore(deps): bump handlebars from 4.7.8 to 4.7.9 (#629)486d0c6chore(deps): bump follow-redirects from 1.15.11 to 1.16.0 (#627)50cc3f68.5.192c8e3echore: bump ip-address library to latest (#626)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for express-rate-limit since your current version.
Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
express-slow-downfrom 2.0.3 to 3.1.0Changelog
Sourced from express-slow-down's changelog.
Commits
796b4013.1.0116552cv3.1.0 changelog9483035Merge pull request #84 from Sigmabrogz/feat/support-headers5e82865lint05cfbddBe more explicit about standard headers draft versions in tests3388dd3feat: support headers options from express-rate-limit5d8851bMerge pull request #79 from express-rate-limit/dependabot/npm_and_yarn/webpac...4430dffbuild(deps-dev): bump webpack from 5.94.0 to 5.105.0e336ce5build(deps-dev): bump lodash-es from 4.17.21 to 4.17.23 (#75)883857fbuild(deps-dev): bump lodash from 4.17.21 to 4.17.23 (#76)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for express-slow-down since your current version.
Updates
helmetfrom 8.0.0 to 8.2.0Changelog
Sourced from helmet's changelog.
Commits
638e43b8.2.0fdf25a8Update changelog for 8.2.0 releasebd293b7Update devDependencies to latest versions81ce5ccTest supported Node versions on CI807a888Update to new URLd4e0128Add direct link to FAQ437d2ebBump actions/setup-node from 6.3.0 to 6.4.0 (#537)a6bd779Upgrade actions/setup-node to 6.3.01e09f5fFix changelog typod526f5cBump Picomatch dev sub-dependencyUpdates
http-errorsfrom 2.0.0 to 2.0.1Release notes
Sourced from http-errors's releases.
Changelog
Sourced from http-errors's changelog.
Commits
61aee572.0.1 (#140)6acba1fbuild(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#134)d2dcbbfbuild(deps): bump github/codeql-action from 3.29.11 to 4.31.2 (#137)fa47a60build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#138)09b3881build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#132)f1ad322build(deps): bump github/codeql-action from 3.29.7 to 3.29.11 (#133)109fe03build(deps-dev): bump eslint-plugin-import from 2.25.3 to 2.32.0 (#129)7a05446ci: add nodejs v18 - v24 to test matrix (#127)6dfaf49build(deps): bump github/codeql-action from 3.28.18 to 3.29.5 (#131)535aebfchore: add funding to package.json (#130)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for http-errors since your current version.
Updates
i18next-browser-languagedetectorfrom 8.0.2 to 8.2.1Changelog
Sourced from i18next-browser-languagedetector's changelog.
Commits
71641268.2.16df69c7release1ffa1cfAdd missing typescript definition for hash options (#315)697d89bBump js-yaml (#313)ce82da9Bump lodash from 4.17.21 to 4.17.23 (#312)d05fe5afix url in readme9d1d7d2Bump tmp from 0.2.1 to 0.2.5 (#309)32f0429Bump cipher-base from 1.0.4 to 1.0.6 (#307)9c0db8fBump sha.js from 2.4.11 to 2.4....Description has been truncated