react-storefront-boilerplate
react-storefront-boilerplate copied to clipboard
Bump ua-parser-js and browser-sync
Bumps ua-parser-js and browser-sync. These dependencies needed to be updated together.
Updates ua-parser-js
from 0.7.20 to 0.7.33
Changelog
Sourced from ua-parser-js's changelog.
Version 0.7.33 / 1.0.33
- Add new browser : Cobalt
- Identify Macintosh as an Apple device
- Fix ReDoS vulnerability
Version 0.8
Version 0.8 was created by accident. This version is now deprecated and no longer maintained, please update to version 0.7 / 1.0.
Commits
f2d0db0
Bump version 0.7.33a6140a1
Remove unsafe regex in trim() functiona886604
Fix #605 - Identify Macintosh as Apple deviceb814bcd
Merge pull request #606 from rileyjshaw/patch-17f71024
Fix documentationc239ac5
Merge pull request #604 from obecerra3/master8d3c2d3
Add new browser: Cobaltd11fc47
Bump version 0.7.32b490110
Merge branch 'develop' of github.com:faisalman/ua-parser-jscb5da5e
Merge pull request #600 from moekm/develop- Additional commits viewable in compare view
Updates browser-sync
from 2.26.7 to 2.27.11
Release notes
Sourced from browser-sync's releases.
2.27.9
What's Changed
- fix(cli): Where's the command help? fixes #1929 by
@shakyShane
in BrowserSync/browser-sync#1945A bug prevented the help output from displaying - it was introduced when the CLI parser
yargs
was updated, and is now fixed :)Full Changelog: https://github.com/BrowserSync/browser-sync/compare/v2.27.8...v2.27.9
2.27.8
This release upgrades Socket.io (client+server) to the latest versions - solving the following issues, and silencing security warning :)
PR:
Resolved Issues:
- BrowserSync/browser-sync#1850
- BrowserSync/browser-sync#1892
- BrowserSync/browser-sync#1925
- BrowserSync/browser-sync#1926
- BrowserSync/browser-sync#1933
Thanks to
@lachieh
for the original PR, which helped me land this fixadded
snippet: boolean
optionThis release adds a feature to address BrowserSync/browser-sync#1882
Sometimes you don't want Browsersync to auto-inject it's connection snippet into your HTML - now you can disable it globally via either a CLI param or the new
snippet
option :)browser-sync . --no-snippet
or in any Browsersync configuration
const config = { snippet: false, };
the original request was related to Eleventy usage, so here's how that would look
eleventyConfig.setBrowserSyncConfig({ snippet: false, });
... (truncated)
Commits
01caeb3
v2.27.1174873cc
updated deps (#1995)88527a8
Add CodeSee architecture diagram workflow to repository (#1972)f6965a6
v2.27.10e6c7bed
Updated portscanner to 2.2.0 (#1960)6a587ec
fix readme's91258ae
Merge branch 'browser-sync-1946-esbuild'f48d6b4
👋 app veyor30c24dc
Merge pull request #19479d24de5
drop webpack from UI- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
Dependabot tried to add @dijs
and @markbrocato
as reviewers to this PR, but received the following error from GitHub:
POST https://api.github.com/repos/moovweb/react-storefront-boilerplate/pulls/110/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the moovweb/react-storefront-boilerplate repository. // See: https://docs.github.com/rest/reference/pulls#request-reviewers-for-a-pull-request
I was researching ua-parser-js changelog. I recommend jumping to version [1.0.33](https://github.com/faisalman/ua-parser-js/releases/tag/1.0.33)
it's the same as 0.7.33.
UA parser is releasing same updates on multiple version due to incorrect NPM releases in the past. (the npm was hijacked), I don't think it make sense to be on lower version when 1.x is out.