Bump undici from 5.28.4 to 6.11.1 in the npm_and_yarn group
Bumps the npm_and_yarn group with 1 update: undici.
Updates undici from 5.28.4 to 6.11.1
Release notes
Sourced from undici's releases.
v6.11.1
:warning: Security Release ⚠️
What's Changed
- Fixes https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7 CVE-2024-30260
- Fixes https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672 CVE-2024-30261
- Revert "fix: don't leak internal class (#3024)" by
@mcollinain nodejs/undici#3044Full Changelog: https://github.com/nodejs/undici/compare/v6.11.0...v6.11.1
v6.11.0
What's Changed
- refactor(#3023): Pass headers as array instead by
@metcoder95in nodejs/undici#3025- fix: don't leak internal class by
@ronagin nodejs/undici#3024- build(deps): bump codecov/codecov-action from 4.1.0 to 4.1.1 by
@dependabotin nodejs/undici#3034- build(deps-dev): bump tsd from 0.30.7 to 0.31.0 by
@dependabotin nodejs/undici#3038- build(deps-dev): bump borp from 0.9.1 to 0.10.0 by
@dependabotin nodejs/undici#2947- missing commits by
@ronagin nodejs/undici#3040- build(deps): bump actions/checkout from 4.1.1 to 4.1.2 by
@dependabotin nodejs/undici#3036- fix: regexp pattern by
@tsctxin nodejs/undici#3041Full Changelog: https://github.com/nodejs/undici/compare/v6.10.2...v6.11.0
v6.10.2
What's Changed
- Do not fail test if streams support typed arrays by
@mcollinain nodejs/undici#2978- fix(fetch): properly redirect non-ascii location header url by
@Xvezdain nodejs/undici#2971- perf: Remove double-stringify in setCookie by
@peterverin nodejs/undici#2980- [fix #2982] use DispatcherInterceptor type for Dispatcher#Compose by
@clovis-guillemotin nodejs/undici#2983- fix: make EventSource properties enumerable by
@MattBidewellin nodejs/undici#2987- docs: ✏️ fixed benchmark links by
@benhalversonin nodejs/undici#2991- fix(#2986): bad start check by
@metcoder95in nodejs/undici#2992- fix(H2 Client): bind stream 'data' listener only after received 'response' event by
@St3ffGv4in nodejs/undici#2985- feat: added search input by
@benhalversonin nodejs/undici#2993- chore: validate responses can be consumed without a Content-Length or… by
@jacob-ebeyin nodejs/undici#2995- fix error message by
@KhafraDevin nodejs/undici#2998- Revert "perf: reuse TextDecoder instance (#2863)" by
@panvain nodejs/undici#2999- test: remove only by
@metcoder95in nodejs/undici#3001New Contributors
@Xvezdamade their first contribution in nodejs/undici#2971@petervermade their first contribution in nodejs/undici#2980@clovis-guillemotmade their first contribution in nodejs/undici#2983@MattBidewellmade their first contribution in nodejs/undici#2987@benhalversonmade their first contribution in nodejs/undici#2991@St3ffGv4made their first contribution in nodejs/undici#2985@jacob-ebeymade their first contribution in nodejs/undici#2995
... (truncated)
Commits
6df3c73Bumped v6.11.1c346b66Revert "fix: don't leak internal class (#3024)"d542b8cMerge pull request from GHSA-9qxr-qj54-h6726805746Merge pull request from GHSA-m4v8-wqvr-p9f7ee5f892Bumped v6.11.071a6d74Merge branch 'main' of github.com:nodejs/undici0f0f239fix: regexp pattern (#3041)31f9e67build(deps): bump actions/checkout from 4.1.1 to 4.1.2 (#3036)c8a43aefixup8b5e2c8fixup- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page.
Oxygen deployed a preview of your dependabot/npm_and_yarn/npm_and_yarn-cb5f744117 branch. Details:
| Storefront | Status | Preview link | Deployment details | Last update (UTC) |
|---|---|---|---|---|
| Skeleton (skeleton.hydrogen.shop) | ✅ Successful (Logs) | Preview deployment | Inspect deployment | September 27, 2024 3:25 AM |
| metaobjects | ✅ Successful (Logs) | Preview deployment | Inspect deployment | September 27, 2024 3:25 AM |
| custom-cart-method | ✅ Successful (Logs) | Preview deployment | Inspect deployment | September 27, 2024 3:25 AM |
| sitemap | ✅ Successful (Logs) | Preview deployment | Inspect deployment | September 27, 2024 3:25 AM |
| third-party-queries-caching | ✅ Successful (Logs) | Preview deployment | Inspect deployment | September 27, 2024 3:25 AM |
| classic-remix | ✅ Successful (Logs) | Preview deployment | Inspect deployment | September 27, 2024 3:25 AM |
Learn more about Hydrogen's GitHub integration.
Outdated.
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.
To ignore these dependencies, configure ignore rules in dependabot.yml