extension
extension copied to clipboard
Bump tough-cookie and node-sass in /services/web-app
Bumps tough-cookie to 4.1.3 and updates ancestor dependency node-sass. These dependencies need to be updated together.
Updates tough-cookie
from 4.1.2 to 4.1.3
Release notes
Sourced from tough-cookie's releases.
4.1.3
Security fix for Prototype Pollution discovery in #282. This is a minor release, although output from the
inspect
utility is affected by this change, we felt this change was important enough to be pushed into the next patch.
Commits
Updates node-sass
from 7.0.3 to 8.0.0
Release notes
Sourced from node-sass's releases.
v8.0.0
What's Changed
- Fix binaries being partially downloaded by
@xzyfer
in sass/node-sass#3313- Bump node-gyp and nan for node 19 support by
@xzyfer
in sass/node-sass#3314- feat: Node 18 and 19 support and drop Node 17 by
@nschonni
in sass/node-sass#3257Breaking changes
- Drop support for Node 12 (
@nschonni
)- Drop support for Node 17 (
@nschonni
)- Set
rejectUnauthorized
totrue
by default (@scott-ut
, #3149)Features
- Add support for Node 18 (
@nschonni
)- Add support for Node 19 (
@nschonni
)- Replace
request
withmake-fetch-happen
(@CamilleDrapier
@xzyfer
, #3193, #3313)Dependencies
- Bump [email protected]
- Bump node-gyp
@9
.0.0- Bump nan@^2.17.0
- Bump sass-graph@^4.0.1
Misc
- Bump various GitHub Actions dependencies (
@nschonni
)Supported Environments
OS Architecture Node Windows x86 & x64 14, 16, 18, 19 OSX x64 14, 16, 18, 19 Linux* x64 14, 16, 18, 19 Alpine Linux x64 14, 16, 18, 19 FreeBSD i386 amd64 12, 14 *Linux support refers to major distributions like Ubuntu, and Debian
Commits
ee13eb9
8.0.098e75b3
feat: Node 18 and 19 support and drop Node 17 (#3257)e9bb866
Bump node-gyp and nan for node 19 support (#3314)ab7840b
Fix binaries being partially downloaded (#3313)d595abf
7.0.33b556c1
7.0.2c716359
Bump sass-graph@^4.0.1 (#3292)24741b3
docs(readme): fix docpad plugin link1523330
feat: Drop Node 12365d357
update https://registry.npm.taobao.org to https://registry.npmmirror.com- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.