ronin-dpos-contracts
ronin-dpos-contracts copied to clipboard
chore(deps): bump undici from 5.27.0 to 5.28.4
Bumps undici from 5.27.0 to 5.28.4.
Release notes
Sourced from undici's releases.
v5.28.4
:warning: Security Release :warning:
- Fixes https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7 CVE-2024-30260
- Fixes https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672 CVE-2024-30261
Full Changelog: https://github.com/nodejs/undici/compare/v5.28.3...v5.28.4
v5.28.3
⚠️ Security Release ⚠️
Fixes:
Full Changelog: https://github.com/nodejs/undici/compare/v5.28.2...v5.28.3
v5.28.2
What's Changed
- fix: remove optional chainning for compatible with Nodejs12 and below by
@bugb
in nodejs/undici#2470- fix: remove
node:
prefix by@tsctx
in nodejs/undici#2471- perf: avoid Headers initialization by
@tsctx
in nodejs/undici#2468- fix: handle SharedArrayBuffer correctly by
@tsctx
in nodejs/undici#2466- fix: Add
null
type tosignal
inRequestInit
by@gebsh
in nodejs/undici#2455- fix: correctly handle data URL with hashes. by
@tsctx
in nodejs/undici#2475- fix: check response for timinginfo allow flag by
@ToshB
in nodejs/undici#2477- Make call to onBodySent conditional in RetryHandler by
@MzUgM
in nodejs/undici#2478- refactor: better integrity check by
@tsctx
in nodejs/undici#2462- fix: Added support for inline URL username:password proxy auth by
@matt-way
in nodejs/undici#2473- build(deps-dev): bump jsdom from 22.1.0 to 23.0.0 by
@dependabot
in nodejs/undici#2472- build(deps-dev): bump sinon from 16.1.3 to 17.0.1 by
@dependabot
in nodejs/undici#2405- build(deps): bump ossf/scorecard-action from 2.2.0 to 2.3.1 by
@dependabot
in nodejs/undici#2396- build(deps): bump actions/setup-node from 3.8.1 to 4.0.0 by
@dependabot
in nodejs/undici#2395- build(deps): bump step-security/harden-runner from 2.5.0 to 2.6.0 by
@dependabot
in nodejs/undici#2392- build(deps-dev): bump formdata-node from 4.4.1 to 6.0.3 by
@dependabot
in nodejs/undici#2389- build(deps): bump actions/upload-artifact from 3.1.2 to 3.1.3 by
@dependabot
in nodejs/undici#2302New Contributors
@bugb
made their first contribution in nodejs/undici#2470@gebsh
made their first contribution in nodejs/undici#2455@ToshB
made their first contribution in nodejs/undici#2477@MzUgM
made their first contribution in nodejs/undici#2478@matt-way
made their first contribution in nodejs/undici#2473Full Changelog: https://github.com/nodejs/undici/compare/v5.28.1...v5.28.2
v5.28.1
What's Changed
- perf: Improve
normalizeMethod
by@tsctx
in nodejs/undici#2456- fix: dispatch error handling by
@ronag
in nodejs/undici#2459
... (truncated)
Commits
fb98306
Bumped v5.28.42b39440
Merge pull request from GHSA-9qxr-qj54-h67264e3402
Merge pull request from GHSA-m4v8-wqvr-p9f7723c4e7
Revert "build(deps-dev): bump formdata-node from 4.4.1 to 6.0.3 (#2389)"0e9d54b
skip failing test due to Node.js changese71cb4c
Bumped v5.28.320c65b8
Fix tests for Node.js v20.11.0 (#2618)8ec52cd
Fix tests for Node.js v21 (#2609)d3aa574
Merge pull request from GHSA-3787-6prv-h9w39a14e5f
Bumped v5.28.2- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.