Chronos
Chronos copied to clipboard
Bump tough-cookie and less
Bumps tough-cookie and less. These dependencies needed to be updated together.
Updates tough-cookie from 2.3.4 to 4.1.3
Release notes
Sourced from tough-cookie's releases.
4.1.3
Security fix for Prototype Pollution discovery in #282. This is a minor release, although output from the
inspectutility is affected by this change, we felt this change was important enough to be pushed into the next patch.4.1.2 -- Patch and Bugfix Release
What's Changed
- fix: allow set cookies with localhost by
@​colincaseyin salesforce/tough-cookie#253Full Changelog: https://github.com/salesforce/tough-cookie/compare/v4.1.1...v4.1.2
4.1.1
Patch Release
What's Changed
- fix: allow special use domains by default by
@​colincaseyin salesforce/tough-cookie#249- 4.1.1 Patch -- allow special use domains by default by
@​awatermain salesforce/tough-cookie#250Full Changelog: https://github.com/salesforce/tough-cookie/compare/v4.1.0...v4.1.1
4.1.0
v4.1.0
Minor release, focused mainly on resolving reported issues and some minor feature work.
What's Changed
- Create CHANGELOG.md by
@​ShivanKaulin salesforce/tough-cookie#189- Missing param validation issue145 by
@​medelibero-sfdcin salesforce/tough-cookie#193- Create SECURITY.md by
@​ShivanKaulin salesforce/tough-cookie#201- Create CODE_OF_CONDUCT.md by
@​ShivanKaulin salesforce/tough-cookie#200- Fix for issue #195 by
@​medelibero-sfdcin salesforce/tough-cookie#202- Add explanation and more special-use domains by
@​ShivanKaulin salesforce/tough-cookie#203- Sync of constructor options for serialization by
@​medelibero-sfdcin salesforce/tough-cookie#204- Returned null in case of empty cookie value by
@​vsin12in salesforce/tough-cookie#196- 132 str trim not a function by
@​awatermain salesforce/tough-cookie#209- Fix for issue #153 by
@​medelibero-sfdcin salesforce/tough-cookie#210- Fix permuteDomain with trailing dot by
@​ruoho-sfdcin salesforce/tough-cookie#216- Issue #213 -- added gh-actions flow for building and testing tough-co… by
@​awatermain salesforce/tough-cookie#218- Issue #210 -- Updated workflow to use npm install. by
@​awatermain salesforce/tough-cookie#220- @GH-215 -- Tests that document localhost behavior when set as domain. by
@​awatermain salesforce/tough-cookie#221- fix: MemoryCookieStore methods should exist on the prototype, not on the class. by
@​wjhsfin salesforce/tough-cookie#226- Unit test cases for
allowSpecialUseDomainoption by@​colincaseyin salesforce/tough-cookie#225- [Snyk] Upgrade universalify from 0.1.2 to 0.2.0 by
@​snyk-botin salesforce/tough-cookie#228- React Native Support by
@​colincaseyin salesforce/tough-cookie#227- Adding Updating CODEOWNERS with ECCN as per Export Control Compliance by
@​svc-scmin salesforce/tough-cookie#223- fix: domain match routine by
@​colincaseyin salesforce/tough-cookie#236- Stop using the internal NodeJS punycode module by
@​gboerin salesforce/tough-cookie#238- Initial documentation review by
@​mcarey86in salesforce/tough-cookie#234- fix: distinguish between no samesite and samesite=none by
@​colincaseyin salesforce/tough-cookie#240- Prepare tough-cookie 4.1 for publishing (updated GitHub actions, move… by
@​awatermain salesforce/tough-cookie#242- 4.1.0 release to NPM by
@​awatermain salesforce/tough-cookie#245
... (truncated)
Commits
4ff4d294.1.3 release preparation, update the package and lib/version to 4.1.3. (#284)12d4747Prevent prototype pollution in cookie memstore (#283)f06b72dFix documentation for store.findCookies, missing allowSpecialUseDomain proper...b1a8898fix: allow set cookies with localhost (#253)ec707964.1.1 Patch -- allow special use domains by default (#250)d4ac580fix: allow special use domains by default (#249)79c2f7d4.1.0 release to NPM (#245)4fafc17Prepare tough-cookie 4.1 for publishing (updated GitHub actions, move Dockerf...aa4396dfix: distinguish between no samesite and samesite=none (#240)b8d7511Modernize README (#234)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by awaterma, a new releaser for tough-cookie since your current version.
Updates less from 2.7.3 to 4.1.3
Release notes
Sourced from less's releases.
v4.1.3
- #3673 Feat: add support for case-insensitive attribute selectors (#3673) (
@​iChenLei)- #3710 Feat: add
disablePluginRuleflag for render() options (#3710) (@​broofa@​edhgoose)- #3656 Fix #3655 for param tag is null (#3658) (
@​langren1353)- #3658 Fix #3646 forcefully change unsupported input to strings (#3658) (
@​gzb1128)- #3668 Fix change keyword plugin and import regexp (#3668) (
@​iChenLei)- #3613 Fix #3591: refactor debugInfo from class to function (#3613) (
@​drdevlin)- #3716 Fix https failures on macOS (#3716) (
@​joeyparrish)v4.1.2
- #3602 Fix currentFileInfo and index properties on nodes (#3602) (
@​bjpbakker)- #3626 Fix #3616 IfStatement requires double parentheses when dividing (#3626) (
@​iChenLei)- #3630 Fix needle dependency warning typo. (#3630) (
@​cjwilsontech)v4.1.1
- #3597 Fix expected response when there's a socket error (#3597) (
@​zxfrank)- #3589 Fixes #3586 (#3589) (
@​matthew-dean)v4.1.0
Mixin parentheses requirement removed
This was maybe too big a change without some kind of deprecation or conversion. So for this version, this works again:
.mixin;
- #3582 Fix #3576 import redirects. Replace native-request with needle. (#3582) (
@​zaquest)- #3583 Update rollup and other build dependencies (#3583) (
@​pravi)- #3588 Roll back paren requirement on mixin calls (#3588) (
@​matthew-dean)v4.0.0
This release has 2 breaking changes:
Parentheses required for mixin calls
This aligns it with syntax for calling detached rulesets.
Example
.mixin() {} .mixin; // error in 4.0Parens-division now the default math setting
Parentheses are required (by default) around division-like expressions, to force math evaluation.
Example:
</tr></table>
... (truncated)
Changelog
Sourced from less's changelog.
v4.1.3 (2022-06-09)
- #3673 Feat: add support for case-insensitive attribute selectors (#3673) (
@​iChenLei)- #3710 Feat: add
disablePluginRuleflag for render() options (#3710) (@​broofa@​edhgoose)- #3656 Fix #3655 for param tag is null (#3658) (
@​langren1353)- #3658 Fix #3646 forcefully change unsupported input to strings (#3658) (
@​gzb1128)- #3668 Fix change keyword plugin and import regexp (#3668) (
@​iChenLei)- #3613 Fix #3591: refactor debugInfo from class to function (#3613) (
@​drdevlin)- #3716 Fix https failures on macOS (#3716) (
@​joeyparrish)v4.1.2 (2021-10-04)
- #3602 Fix currentFileInfo and index properties on nodes (#3602) (
@​bjpbakker)- #3626 Fix #3616 IfStatement requires double parentheses when dividing (#3626) (
@​iChenLei)- #3630 Fix needle dependency warning typo. (#3630) (
@​cjwilsontech)v4.1.1 (2021-01-31)
- #3597 Fix expected response when there's a socket error (#3597) (
@​zxfrank)- #3589 Fixes #3586 (#3589) (
@​matthew-dean)v4.1.0 (2021-01-10)
- #3582 Fix #3576 import redirects. Replace native-request with needle. (#3582) (
@​zaquest)- #3583 Update rollup and other build dependencies (#3583) (
@​pravi)- #3588 Roll back paren requirement on mixin calls (#3588) (
@​matthew-dean)v4.0.0 (2020-12-18)
- #3573 v4.0.0 (#3573) (
@​matthew-dean)v3.13.1 (2020-12-18)
- #3575 Fixes #3574 (#3575) (
@​matthew-dean)v3.13.0 (2020-12-12)
- #3572 Fixes #3434 - memory / runtime improvements (#3572) (
@​matthew-dean)- #3550 Examples contain more valid CSS, to test with a new parser (#3550) (
@​matthew-dean)- #3546 Bug fixes - fixes #3446 #3368 (#3546) (
@​matthew-dean)v3.12.2 (2020-07-16)
- #3545 Release 3.12.2 (#3545) (
@​matthew-dean)v3.12.1 (2020-07-16)
- #3544 Fixes #3533 (#3544) (
@​matthew-dean)- #3543 Fixes #3541 (#3543) (
@​matthew-dean)v3.12.0 (2020-07-13)
- #3540 v3.12.0-RC.2 (#3540) (
@​matthew-dean)- #3532 Fixes #3371 Allow conditional evaluation of function args (#3532) (
@​matthew-dean)- #3531 Remove lib folder from git (#3531) (
@​matthew-dean)- #3530 Move changelog to root (#3530) (
@​matthew-dean)- #3529 Duplicate dist files in root for older links (#3529) (
@​matthew-dean)- #3525 Test-data module (#3525) (
@​matthew-dean)- #3523 Fixes #3504 / organizes tests (#3523) (
@​matthew-dean)- #3501 Restore nuked scripts (?), replace dependencies (#3501) (#3522) (
@​matthew-dean)
... (truncated)
Commits
6986f3eRelease v4.1.3 (#3722)c24f52cci: add node18 support and drop node17 ci (#3718)7491578feat: adddisablePluginRuleflag for render() options (#3701)1eafc06fix: Fix https failures on macOS (#3716)3f05b5cchore: remove unused vars and imports (#3682)ce973cdFix #3591: refactor debugInfo from class to function (#3613)7fc6a1d[skip ci] move issue tpl from workflows to issue_template (#3671)cb89770ci: reduce ci times and add node17 test (#3672)2431015feat: add support for case-insensitive attribute selectors (#3673)ee9e13bfix: change keyword plugin and import regexp (#3668)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.