salesforcedx-vscode
salesforcedx-vscode copied to clipboard
chore(deps): bump tough-cookie and npm
Bumps tough-cookie to 4.1.3 and updates ancestor dependency npm. These dependencies need to be updated together.
Updates tough-cookie
from 4.1.2 to 4.1.3
Release notes
Sourced from tough-cookie's releases.
4.1.3
Security fix for Prototype Pollution discovery in #282. This is a minor release, although output from the
inspect
utility is affected by this change, we felt this change was important enough to be pushed into the next patch.
Commits
Updates npm
from 6.14.18 to 9.8.0
Release notes
Sourced from npm's releases.
libnpmhook: v9.0.3
9.0.3 (2023-02-07)
Bug Fixes
12ec7ee
remove unused package.json scripts (@lukekarrys
)libnpmhook: v9.0.2
9.0.2 (2023-02-01)
Dependencies
libnpmpublish: v7.5.0
7.5.0 (2023-07-05)
Features
5baf6a2
#6613 SLSA 1.0 provenance statement (#6613) (@bdehamer
)libnpmpublish: v7.4.0
7.4.0 (2023-06-21)
Features
Bug Fixes
29622c1
#6530 public package check in libnpmpublish (#6530) (@bdehamer
)libnpmpublish: v7.3.0
7.3.0 (2023-05-31)
Features
a63a6d8
#6490 add provenanceFile option for libnpmpublish (@bdehamer
)libnpmpublish: v7.2.0
7.2.0 (2023-05-17)
Features
bdab631
#6428 expose provenance transparency url (#6428) (@JamesHenry
,@wraithgar
)Bug Fixes
f064696
#6437 Update publish /w provenance to ignore pkg vis 404 (#6437) (@feelepxyz
)
... (truncated)
Changelog
Sourced from npm's changelog.
9.8.0 (2023-07-05)
Features
67459e7
#6626 addpkg fix
subcommand (@wraithgar
)89b2741
#6548 add ps1 scripts (#6548) (@mribbons
,@lukekarrys
)Dependencies
b252164
#6626@npmcli/[email protected]
9238682
#6623[email protected]
(#6623)- Workspace:
@npmcli/[email protected]
- Workspace:
[email protected]
- Workspace:
[email protected]
- Workspace:
[email protected]
- Workspace:
[email protected]
- Workspace:
[email protected]
9.7.2 (2023-06-21)
Bug Fixes
939a188
#6574 ignore node prereleases in npm engines check (#6574) (@wraithgar
)d980405
#6556 better color support detection (#6556) (@lukekarrys
)40d7e09
#6555 remove unnecessary package.json values (#6555) (@lukekarrys
)3a7378d
#6554 cleanup bin contents (@lukekarrys
)e722439
#6497 move all definitions to@npmcli/config
package (@lukekarrys
)Documentation
405ffbf
#6557 remove redundant statement about files attribute (#6557) (@DaviDevMod
)cd1e6aa
#6551 add flagpackage-lock-only
fornpm install
(#6551) (@m4rch3n1ng
)Dependencies
aebc523
#6585[email protected]
[email protected]
(#6585)bb6054b
#6573[email protected]
aee4a30
#6573[email protected]
6105dbc
#6573[email protected]
22d44e8
#6573[email protected]
fdd02fd
#6573[email protected]
7797075
#6573[email protected]
f9780cc
#6573[email protected]
72d6a79
#6573[email protected]
98f1f5f
#6573[email protected]
8710ff8
#6573[email protected]
0cb539d
#6573[email protected]
39ad586
#6573[email protected]
5e0070c
#6573[email protected]
[email protected]
26cf235
#6573[email protected]
... (truncated)
Commits
b1c3256
chore: release 9.8.067459e7
feat: addpkg fix
subcommandc61e037
fix: use new load/create syntax for package-jsonb252164
deps:@npmcli/package-json
@4
.0.0690c9fc
chore: fix publish test in a git worktree (#6627)9238682
deps: [email protected] (#6623)5baf6a2
feat: SLSA 1.0 provenance statement (#6613)89b2741
feat: add ps1 scripts (#6548)332dec3
chore: run all windows shims testsa2fa41e
chore: normalize line endings and symlinks- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.