auto-encrypt-localhost
auto-encrypt-localhost copied to clipboard
Bump json5 and dependency-cruiser
Bumps json5 to 2.2.2 and updates ancestor dependency dependency-cruiser. These dependencies need to be updated together.
Updates json5 from 1.0.1 to 2.2.2
Release notes
Sourced from json5's releases.
v2.2.2
- Fix: Properties with the name
__proto__are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).v2.2.1
- Fix: Removed dependence on minimist to patch CVE-2021-44906. (#266)
v2.2.0
- New: Accurate and documented TypeScript declarations are now included. There is no need to install
@types/json5. (#236, #244)v2.1.3 [code, diff]
v2.1.2
- Fix: Bump
minimisttov1.2.5. (#222)v2.1.1
- New:
package.jsonandpackage.json5include amoduleproperty so bundlers like webpack, rollup and parcel can take advantage of the ES Module build. (#208)- Fix:
stringifyoutputs\0as\\x00when followed by a digit. (#210)- Fix: Spelling mistakes have been fixed. (#196)
v2.1.0
- New: The
index.mjsandindex.min.mjsbrowser builds in thedistdirectory support ES6 modules. (#187)v2.0.1
- Fix: The browser builds in the
distdirectory support ES5. (#182)v2.0.0
Major: JSON5 officially supports Node.js v6 and later. Support for Node.js v4 has been dropped. Since Node.js v6 supports ES5 features, the code has been rewritten in native ES5, and the dependence on Babel has been eliminated.
New: Support for Unicode 10 has been added.
New: The test framework has been migrated from Mocha to Tap.
New: The browser build at
dist/index.jsis no longer minified by default. A minified version is available atdist/index.min.js. (#181)Fix: The warning has been made clearer when line and paragraph separators are used in strings.
Fix:
package.json5has been restored, and it is automatically generated and
... (truncated)
Changelog
Sourced from json5's changelog.
v2.2.2 [code, diff]
- Fix: Properties with the name
__proto__are added to objects and arrays. (#199) This also fixes a prototype pollution vulnerability reported by Jonathan Gregson! (#295).v2.2.1 [code, diff]
- Fix: Removed dependence on minimist to patch CVE-2021-44906. (#266)
v2.2.0 [code, diff]
- New: Accurate and documented TypeScript declarations are now included. There is no need to install
@types/json5. (#236, #244)v2.1.3 [code, diff]
v2.1.2 [code, diff]
- Fix: Bump
minimisttov1.2.5. (#222)v2.1.1 [code, diff]
... (truncated)
Commits
14f8cb12.2.210cc7cadocs: update CHANGELOG for v2.2.27774c10fix: add proto to objects and arraysedde30aReadme: slight tweak to intro97286f8Improve example in readmed720b4fImprove readme (e.g. explain JSON5 better!) (#291)910ce25docs: fix spelling of Aseem2aab4ddtest: require tap as t in cli tests6d42686test: remove mocha syntax from tests4798b9ddocs: update installation and usage for modules- Additional commits viewable in compare view
Updates dependency-cruiser from 9.23.3 to 12.3.0
Release notes
Sourced from dependency-cruiser's releases.
v12.3.0
β¨ features
- ff726419 feature(svelte): adds support for processing svelte templates with css pre-processors (#714)
Thanks to@βirvin93dfor finding the issue, providing the reproduction sample and testing the fix!- 76508e35 feature(init): adds extensions detection to one shot configs (#712)
π fixes
- 5b087435 bugfix(mermaid): circumvents mermaid edge naming ambiguities (#709)
π documentation
- 91c6dad2 doc(types): correct typos in cruise-result ts-doc
- 41461f45 doc(init-config): moves typings closer to source (#711)
π· maintenance
- cfb53ab9 build(npm): update external dependencies
- a7caf62d ci(deps): bump actions/stale from 6 to 7 (#710)
π sha-sum of the package as published on npmjs:
a75fc3a7344d95707952cc220b9770b7f01cda49v12.2.0
β¨ features
- 88051d6a feature(progress): re-vamps the performance log for ease of use (#698)
- f3af5df9 feature(progress): adds resident set size & v8 managed memory to the performance-log (#697)
- 854f6849 refactor(performance-log): improves readability of code (#708)
π fixes
- c482c0d4 bugfix(mermaid): makes nodes without a name render as well (#705)
- fc0404ce bugfix(report): improves instability alignment in metrics reporter (#707)
π documentation
- 78b0ecc6 doc: twitter -> mastodon
- 8af1605a doc(README): corrects flare badge link to GHA
- 3911345f chore: shortens parameter typings
π· maintenance
π code
- 8d34441e refactor(init-config): removes superfluous function; touches up the typing a bit (#706)
- a1cc3b6f refactor: reduces anonymous top level functions (#703)
- 656b17f8 refactor(report): replaces metrics formatting code with Intl API calls (#699)
- eae9d243 refactor: bans parameter re-assignments (#700)
... (truncated)
Commits
d2716c912.3.0cfb53abbuild(npm): update external dependencies91c6daddoc(types): correct typos in cruise-result ts-docff72641feature(svelte): adds support for processing svelte templates with css pre-pr...76508e3feature(init): adds extensions detection to one shot configs (#712)41461f4doc(init-config): moves typings closer to source (#711)a7caf62ci(deps): bump actions/stale from 6 to 7 (#710)5b08743bugfix(mermaid): circumvents mermaid edge naming ambiguities (#709)7789bbb12.2.0ad6b71dbuild(npm): update external dependencies- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.