Bump fast-json-patch and web-ext
Bumps fast-json-patch to 3.1.1 and updates ancestor dependency web-ext. These dependencies need to be updated together.
Updates fast-json-patch from 2.2.1 to 3.1.1
Release notes
Sourced from fast-json-patch's releases.
3.1.1
Security Fix for Prototype Pollution - huntr.dev #262
Bug fixes and ES6 modules
Use ES6 Modules
- package now exports non-bundled ES module Starcounter-Jack/JSON-Patch#232
mainstill points to CommonJS module for backward compatibility- README recommends use of named ES imports
List of changes https://github.com/Starcounter-Jack/JSON-Patch/compare/v2.2.1...3.0.0-0
Use ES6 Modules
- package now exports non-bundled ES module Starcounter-Jack/JSON-Patch#232
mainstill points to CommonJS module for backward compatibility- README recommends use of named ES imports
Full list of changes https://github.com/Starcounter-Jack/JSON-Patch/compare/v2.2.1...3.0.0-0
Commits
9d313acfix(tests): Updated tests to reflect new error messagee4f4eb33.1.1d7903fbfix: typescript codegen changes5f04488Bumping version number7e9fe13Typescript provided097864aDocumentation updated51964edfeat: Cleaned up vars vs consts8a6a360New buildadeb422Update .gitignore59336feMerge pull request #292 from Starcounter-Jack/dependabot/npm_and_yarn/ajv-6.12.6- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by mountain-jack, a new releaser for fast-json-patch since your current version.
Updates web-ext from 6.2.0 to 7.5.0
Release notes
Sourced from web-ext's releases.
7.5.0
Features
- web-ext lint: updated to use addons-linter v5.27.0 (#2573, #2583, #2602, #2619)
- import Firefox
109.0b9API schema- ensure empty ZIP files will output results when auto-close feature is disabled
- switch to vendored
ajv-merge-patchlibrary to fix a potential security issue- prevent errors when
permissionsin manifest.json isn't an array- web-ext sign: send user agent header with signing requests (#2540)
Bug Fixes
- web-ext sign: added missing type for
channelparameter (#2546)- web-ext sign: fixed the default AMO API base URL used by the experimental
--use-submission-apiCLI flag (#2621)- Other dependencies updated:
See all changes: https://github.com/mozilla/web-ext/compare/7.4.0...7.5.0
7.4.0
Features
web-ext lint: enabled MV3 by default (#2557)web-ext lint: updated to use addons-linter v5.23.0 (#2537) (#2561)
- Firefox 108.0b5 schema has been imported
- MV3 event pages are now fully supported by the linter
- Various fixes related to CSP have been made in the linter
Bug Fixes
- Other dependencies updated:
See all changes https://github.com/mozilla/web-ext/compare/7.3.1...7.4.0
7.3.1
Bug Fixes
web-ext sign: fixed a bug that caused the experimental CLI flag--use-submission-apito use an invalid URL (#2531)See all changes https://github.com/mozilla/web-ext/compare/7.3.0...7.3.1
... (truncated)
Commits
fa989f77.5.071e19d2add trailing slash to amo-base-url & enforce within submit-addon Client (#2621)00250d0chore(deps): bump@babel/runtimefrom 7.20.7 to 7.20.13 (#2622)0bf4881ci: use Node 18 in Circle CI (#2618)ca817f3chore: remove 'fast-json-patch' from the exclusion list in .nsprc (#2620)6659079chore(deps): bump addons-linter from 5.26.0 to 5.27.0 (#2619)6356fa9fix: Add missing type for channel parameter (#2546) (#2570)870b1d1chore(deps-dev): bump eslint-plugin-import from 2.27.4 to 2.27.5 (#2613)9369afbchore(deps-dev): bump prettier from 2.8.2 to 2.8.3 (#2610)829884dchore(deps-dev): bump eslint from 8.31.0 to 8.32.0 (#2612)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.