media-element-syncer
media-element-syncer copied to clipboard
Bump tough-cookie and parcel
Removes tough-cookie. It's no longer used after updating ancestor dependency parcel. These dependencies need to be updated together.
Removes tough-cookie
Updates parcel from 1.12.4 to 2.9.3
Release notes
Sourced from parcel's releases.
v2.9.3
Fixed
Resolver
- Fix the development and production package conditions – Details
JavaScript
- Update SWC to fix generics in JSX elements – Details
v2.9.2
Fixed
- Core
- JavaScript
- Treat re-exports of
*from empty files withsideEffects: falseas ESM – Details- CSS
- Fix self references error in CSS module JS assets causing "Bundle group cannot have more than one entry bundle of the same type" – Details
- Dev server
- Serve folder's index when requesting folder without slash – Details
- Web extensions
- Allow source maps files in webextension – Details
- Image
- Add core as peerdep to image optimizer – Details
v2.9.1
Fixed
- Resolver
v2.9.0
Parcel v2.9.0 includes many long requested features, including a brand new resolver with support for package.json "exports" and tsconfig.json features, support for ESM plugins and configs, and local Parcel plugins. It also improves performance with a new default JS minifier powered by SWC, incremental symbol propagation, and improved bundler data structures.
Blog post: https://parceljs.org/blog/v2-9-0/
Added
Core
- Add support for ESM plugins and configs – Details
- Add support for local parcel plugins – Details
- Incremental Symbol Propagation for improved performance and improved export errors in development – Details
- Add support for plugin tracing, which shows where time is being spent during a Parcel build – Details
- Support
.proxyrc.cjsconfig files – Details- Add support for
loadConfigfunction to resolver plugins – DetailsResolver
- New resolver implementation in Rust supporting package.json "exports" and "imports", and tsconfig.json "baseUrl", "paths", and "moduleSuffixes" – Details
... (truncated)
Changelog
Sourced from parcel's changelog.
[2.9.3] – 2023-06-24
Fixed
Resolver
- Fix the development and production package conditions – Details
JavaScript
- Update SWC to fix generics in JSX elements – Details
[2.9.2] - 2023-06-08
Fixed
Core
JavaScript
- Treat re-exports of
*from empty files withsideEffects: falseas ESM – DetailsCSS
- Fix self references error in CSS module JS assets causing "Bundle group cannot have more than one entry bundle of the same type" – Details
Dev server
- Serve folder's index when requesting folder without slash – Details
Web extensions
- Allow source maps files in webextension – Details
Image
- Add core as peerdep to image optimizer – Details
[2.9.1] - 2023-06-07
Fixed
- Resolver
[2.9.0] - 2023-05-26
Added
- Core
- Add support for ESM plugins and configs – Details
- Add support for local parcel plugins – Details
- Incremental Symbol Propagation for improved performance and improved export errors in development – Details
- Add support for plugin tracing, which shows where time is being spent during a Parcel build – Details
... (truncated)
Commits
db3bcaev2.9.334103e2Updated SWC crate for JS Transformer (#9104)b79eab8Bump semver from 5.7.1 to 7.5.2 (#9107)76e7100Fix the development and production package conditions (#9108)76aa20fChangelog for v2.9.26e346c8v2.9.240bf1c2Fix self references in CSS module JS assets (#9080)f7fedafServe folder's index when requesting folder without slash (#9066)4db35cdTreat re-exports of '*' from empty files as ESM (#9079)44c5d73Add core as peerdep to image optimizer (#9070)- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Updated dependencies detected. Learn more about Socket for GitHub ↗︎
| Packages | Version | New capabilities | Transitives | Size | Publisher |
|---|---|---|---|---|---|
| parcel | 1.12.4...2.9.3 | None | +152/-536 |
295 MB | devongovett |
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎
To accept the risk, merge this PR and you will not be notified again.
| Issue | Package | Version | Note | Source |
|---|---|---|---|---|
| Native code | lmdb | 2.7.11 |
|
|
| Native code | msgpackr-extract | 3.0.2 |
|
Next steps
What's wrong with native code?
Contains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs.
Ensure that native code bindings are expected. Consumers may consider pure JS and functionally similar alternatives to avoid the challenges and risks associated with native code bindings.
Take a deeper look at the dependency
Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.
Remove the package
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
Mark a package as acceptable risk
To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore [email protected] bar@* or ignore all packages with @SocketSecurity ignore-all
@SocketSecurity ignore [email protected]@SocketSecurity ignore [email protected]