online-reader
online-reader copied to clipboard
Bump ms, body-parser, express, debug and webpack-dashboard
Bumps ms to 2.0.0 and updates ancestor dependencies ms, body-parser, express, debug and webpack-dashboard. These dependencies need to be updated together.
Updates ms
from 0.7.1 to 2.0.0
Release notes
Sourced from ms's releases.
2.0.0
Major Changes
- Limit str to 100 to avoid ReDoS of 0.3s: #89
Patches
- Ignored logs coming from npm: b1eaab752203e978492a4d540a7ae1d26e6306b1
- Bumped dependencies to the latest version: bcf57157678fd5afc691383145a35e116f9704d0
- Invalidated cache for slack badge: 94b995c1d6d5d13ec976a0c6849a3cca9b277e6b
Credits
Huge thanks to
@karenyavine
for their help!1.0.0
Major Changes
- Removed component specification: 1fbbe974cdcad96e592dcb65a7b2a8649f690420
Patches
- Test on LTS version of Node: c9b1fd319f0f9198d85ecf4ba83e46cc1216be04
- Removed XO: 94068ea6d518387670df277f740b1abada80ed48
- Use
prettier
andeslint
: 57b3ef8e3423cae6254f94c5564a11b4492cff43- Badge for XO removed: 389840b329436117741b2ef13a172725082695b9
- Removed browser testing: e818c3581aca3119c00d81901bfe8fe653bcfda4
- More suitable name for file containing tests: ee91f307a8dc3581ebdad614ec0533ddb3d8bf56
0.7.3
Patches
- Mark "options" param as optional in jsdoc: #77
- Lowercased text files: 5f0653ab192a30301aed8668b4588a87975b41ab
- Pinned dependencies: 126d7f094a1836b991c8d0abfeb4d0ce09ac280f
- Chore(package): update serve to version 5.0.1: #81
Credits
Huge thanks to
@Jokero
for their help!0.7.2
Patches 💅
- Added license field to package.json file: zeit/ms#42
- Renamed
long
andshort
(reserved keywords): zeit/ms#53- Capitalized important files: b2d9f9d
- Specified version numbers for
devDependencies
in package.json: abd3616- Updated license file to the latest version: 5d53ae8
- Only upload important files to npm, instead of excluding certain ones: 2b2f02a
- Adjusted name of repository in package.json: e84f95d
... (truncated)
Commits
9b88d15
2.0.094b995c
Invalidated cache for slack badgebcf5715
Bumped dependencies to the latest versionb1eaab7
Ignored logs coming from npmcaae298
Limit str to 100 to avoid ReDoS of 0.3s (#89)b83b36d
chore(package): update eslint to version 3.19.0 (#88)3f2a4d7
chore(package): update husky to version 0.13.3 (#86)7daf984
1.0.0ee91f30
More suitable name for file containing testse818c35
Removed browser testing- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by leo, a new releaser for ms since your current version.
Updates body-parser
from 1.15.2 to 1.20.1
Release notes
Sourced from body-parser's releases.
1.20.0
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
1.19.2
- deps: [email protected]
- deps: [email protected]
- Fix handling of
__proto__
keys- deps: [email protected]
- deps: [email protected]
1.19.1
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.18
1.19.0
- deps: [email protected]
- Add petabyte (
pb
) support- deps: [email protected]
- Set constructor name when possible
- deps: [email protected]
- deps: statuses@'>= 1.5.0 < 2'
- deps: [email protected]
- Added encoding MIK
- deps: [email protected]
- Fix parsing array brackets after index
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
... (truncated)
Changelog
Sourced from body-parser's changelog.
1.20.1 / 2022-10-06
- deps: [email protected]
- perf: remove unnecessary object clone
1.20.0 / 2022-04-02
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
1.19.2 / 2022-02-15
- deps: [email protected]
- deps: [email protected]
- Fix handling of
__proto__
keys- deps: [email protected]
- deps: [email protected]
1.19.1 / 2021-12-10
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.18
1.19.0 / 2019-04-25
... (truncated)
Commits
830bdfb
1.20.1ecad1cc
build: [email protected]03b93cf
build: [email protected]2c611fc
build: [email protected]f199e94
perf: remove unnecessary object clone0123e12
build: [email protected]de1e6c2
build: [email protected]477ff13
build: [email protected]40c3fff
deps: [email protected]4aa84b7
build: [email protected]- Additional commits viewable in compare view
Updates express
from 4.14.0 to 4.18.2
Release notes
Sourced from express's releases.
4.18.2
- Fix regression routing a large stack in a single route
- deps: [email protected]
- deps: [email protected]
- perf: remove unnecessary object clone
- deps: [email protected]
4.18.1
- Fix hanging on large stack of sync routes
4.18.0
- Add "root" option to
res.download
- Allow
options
withoutfilename
inres.download
- Deprecate string and non-integer arguments to
res.status
- Fix behavior of
null
/undefined
asmaxAge
inres.cookie
- Fix handling very large stacks of sync middleware
- Ignore
Object.prototype
values in settings throughapp.set
/app.get
- Invoke
default
with same arguments as types inres.format
- Support proper 205 responses using
res.send
- Use
http-errors
forres.format
error- deps: [email protected]
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Add
priority
option- Fix
expires
option to reject invalid dates- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- Remove set content headers that break response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Prevent loss of async hooks context
- deps: [email protected]
- deps: [email protected]
- Fix emitted 416 error missing headers property
- Limit the headers removed for 304 response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
... (truncated)
Changelog
Sourced from express's changelog.
4.18.2 / 2022-10-08
- Fix regression routing a large stack in a single route
- deps: [email protected]
- deps: [email protected]
- perf: remove unnecessary object clone
- deps: [email protected]
4.18.1 / 2022-04-29
- Fix hanging on large stack of sync routes
4.18.0 / 2022-04-25
- Add "root" option to
res.download
- Allow
options
withoutfilename
inres.download
- Deprecate string and non-integer arguments to
res.status
- Fix behavior of
null
/undefined
asmaxAge
inres.cookie
- Fix handling very large stacks of sync middleware
- Ignore
Object.prototype
values in settings throughapp.set
/app.get
- Invoke
default
with same arguments as types inres.format
- Support proper 205 responses using
res.send
- Use
http-errors
forres.format
error- deps: [email protected]
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Add
priority
option- Fix
expires
option to reject invalid dates- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- Remove set content headers that break response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Prevent loss of async hooks context
- deps: [email protected]
- deps: [email protected]
... (truncated)
Commits
8368dc1
4.18.261f4049
docs: replace Freenode with Libera Chatbb7907b
build: [email protected]f56ce73
build: [email protected]24b3dc5
deps: [email protected]689d175
deps: [email protected]340be0f
build: [email protected]33e8dc3
docs: use Node.js name style644f646
build: [email protected]ecd7572
build: [email protected]- Additional commits viewable in compare view
Updates debug
from 2.2.0 to 2.6.9
Release notes
Sourced from debug's releases.
2.6.9
Patches
- Remove ReDoS regexp in
%o
formatter: #504Credits
Huge thanks to
@zhuangya
for their help!release 2.6.7
No release notes provided.
release 2.6.6
No release notes provided.
release 2.6.5
No release notes provided.
release 2.6.4
No release notes provided.
release 2.6.3
No release notes provided.
release 2.6.2
No release notes provided.
release 2.6.1
No release notes provided.
release 2.6.0
No release notes provided.
release 2.5.2
No release notes provided.
release 2.5.1
No release notes provided.
release 2.4.5
No release notes provided.
release 2.4.4
No release notes provided.
release 2.4.3
No release notes provided.
release 2.4.2
No release notes provided.
... (truncated)
Changelog
Sourced from debug's changelog.
2.6.9 / 2017-09-22
- remove ReDoS regexp in %o formatter (#504)
2.6.8 / 2017-05-18
- Fix: Check for undefined on browser globals (#462,
@marbemac
)2.6.7 / 2017-05-16
- Fix: Update ms to 2.0.0 to fix regular expression denial of service vulnerability (#458,
@hubdotcom
)- Fix: Inline extend function in node implementation (#452,
@dougwilson
)- Docs: Fix typo (#455,
@msasad
)2.6.5 / 2017-04-27
- Fix: null reference check on window.documentElement.style.WebkitAppearance (#447,
@thebigredgeek
)- Misc: clean up browser reference checks (#447,
@thebigredgeek
)- Misc: add npm-debug.log to .gitignore (
@thebigredgeek
)2.6.4 / 2017-04-20
- Fix: bug that would occure if process.env.DEBUG is a non-string value. (#444,
@LucianBuzzo
)- Chore: ignore bower.json in npm installations. (#437,
@joaovieira
)- Misc: update "ms" to v0.7.3 (
@tootallnate
)2.6.3 / 2017-03-13
- Fix: Electron reference to
process.env.DEBUG
(#431,@paulcbetts
)- Docs: Changelog fix (
@thebigredgeek
)2.6.2 / 2017-03-10
- Fix: DEBUG_MAX_ARRAY_LENGTH (#420,
@slavaGanzin
)- Docs: Add backers and sponsors from Open Collective (#422,
@piamancini
)- Docs: Add Slackin invite badge (
@tootallnate
)2.6.1 / 2017-02-10
... (truncated)
Commits
13abeae
Release 2.6.9f53962e
remove ReDoS regexp in %o formatter (#504)52e1f21
Release 2.6.82482e08
Check for undefined on browser globals (#462)6bb07f7
release 2.6.715850cb
Fix Regular Expression Denial of Service (ReDoS)4a6c85c
update "debug" to v1.0.0 (#454)b68dbf8
Fix typo (#455)1351d2f
Inline extend function in node implementation (#452)c211947
update version for component- Additional commits viewable in compare view
Updates webpack-dashboard
from 0.2.1 to 3.3.7
Release notes
Sourced from webpack-dashboard's releases.
v3.0.7
Features
- Very minor path normalization for displaying modules paths on Windows and Prettier fixes for Windows. Included in: FormidableLabs/webpack-dashboard#284 by
@ryan-roemer
.- Add AppVeyor for Windows builds in CI. Included in: FormidableLabs/webpack-dashboard#284 by
@ryan-roemer
.Migration Instructions
No changes required to start using v3.0.7 🎉.
v3.0.6
Features
- Prevent dashboard from spawning its own console for the child process on Windows. Closes #212. Included in: FormidableLabs/webpack-dashboard#284 by
@snack-able
.Migration Instructions
No changes required to start using v3.0.6 🎉.
v3.0.5
Features
- Use
npm-run-all
as task runner forpackage.json
scripts. Included in: FormidableLabs/webpack-dashboard#283.- Use
test
in lieu oftest-summary
fornyc
coverage reporting on command line. Included in: FormidableLabs/webpack-dashboard#283.Security
- Address
handlebars
security vulnerability. Included in: FormidableLabs/webpack-dashboard#282 by@juliusl
.- Address additional security vulnerabilities in
js-yaml
. Included in: FormidableLabs/webpack-dashboard#283.v3.0.4
v3.0.4
was an erroneous publish.v3.0.3
Bugs
Socket.io disconnects / large stats object size: Dramatically reduce the size of the webpack stats object being sent from client (webpack plugin) to server (CLI). Add client error/disconnect information for better future debugging. Original issue: #279 and fix: #281.
Migration Instructions
No changes required to start using v3.0.3 🎉.
3.0.2
Features
- Upgrade
inspectpack
dependency to handlenull
chunks. Original issue: FormidableLabs/inspectpack#110 and upstream fix: FormidableLabs/inspectpack#111Migration Instructions
No changes required to start using v3.0.2 🎉.
3.0.1
... (truncated)
Changelog
Sourced from webpack-dashboard's changelog.
3.3.7
- Bug: Move plugin types and update to webpack v5. #324
3.3.6
[3.3.5] - 2021-07-12
- Chore: Update dependencies. #333
- Coverage: Add CodeCov stats. #206
- CI: Update Node matrix to 12/14/16.
[3.3.4] - 2021-07-12
- Chore: Refactor internal stats consumption to perform
inspectpack
analysis in the main thread, without usingmain
streams.- Chore: Refactor internal handler in plugin to always be a wrapped function so that we can't accidentally have asynchronous code call the handler function after it is removed / nulled.
- Bugfix: Add message counting delayed cleanup in plugin to allow messages to drain in Dashboard. Fixes #294.
[3.3.3] - 2021-05-05
- Security: Update
socket.io
version to get rid of vulnerablexmlhttprequest-ssl
package. Included in: FormidableLabs/webpack-dashboard#325 by@texpert
.[3.3.2] - 2021-05-05
- Empty publish.
[3.3.1] - 2021-01-29
- Bugfix: Ensure
Status
is properly updating and reaches completion. Fixes #321[3.3.0] - 2021-01-21
- Add
webpack@5
support. Closes #316- Bugfix:
webpack@5
warning message conflict. Fixes #314- Update various production dependencies.
[3.2.1] - 2020-08-24
- Add missing dependency on
chalk
. Included in: FormidableLabs/webpack-dashboard#309 by@am-a
.[3.2.0] - 2019-09-08
- Add left / right navigation keys to assets in Modules and Problems screens. Included in: FormidableLabs/webpack-dashboard#288 by
@wapgear
.[3.1.0] - 2019-08-27
- Add
DashboardPlugin({ includeAssets: [ "stringPrefix", /regexObj/ ] })
Webpack plugin filtering option.- Add
webpack-dashboard --include-assets stringPrefix1 -a stringPrefix2
CLI filtering option.
... (truncated)
Commits
cb31516
3.3.73370126
Changes for 3.3.74802585
Bug: TS fixes (#341)8a725a4
Merge pull request #340 from FormidableLabs/update-readme-imagesc80df63
update readme image urls530a59d
Cleaned up the issue template (#337)983a80c
3.3.6cb0aaa2
Changes for 3.3.6ee73086
Bug: (#338)1c958c4
3.3.5- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ryan.roemer, a new releaser for webpack-dashboard since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.