strudel
strudel copied to clipboard
build(deps): bump ecstatic from 2.2.1 to 2.2.2
Bumps ecstatic from 2.2.1 to 2.2.2.
Changelog
Sourced from ecstatic's changelog.
2019/05/03 Version 2.2.2
- Backport redirects bugfix
2017/06/06 Version 2.2.1
- Fix version number in CHANGELOG.md
2017/06/06 Version 2.2.0
- Will now properly serve gzip files when defaulting the extension
- Will fall back to serving non-gzip files if file with .gz extension is missing the magic bytes
- Updated he, url-join
- Updated devDependencies
- Added .npmrc
- Added package-lock.json
- Much improved documentation for the cli component
2016/08/10 Version 2.1.0
- New, prettier showDir pages with icons!
2016/08/09 Version 2.0.0
- No longer strip null bytes from uris before parsing. This avoids a regexp dos attack. The stripping was to avoid a bug regarding c++ null terminated strings shenanigans in some versions of node, but it appears fixed in LTS versions of node.
- When both showDir and autoIndex are turned off, do not redirect from /foo to /foo/.
- Add code coverage reports and codecov.io
2015/05/10 Version 1.4.1
- Compare if-modified-since header against server-generated last-modified header rather than raw mtime
2015/12/22 Version 1.4.0
- Add ability to specify custom mimetypes via a JSON blob (on the CLI)
- Started test suite around CLI options parsing
- Workaround for egregious v8 bug around date parsing throwing during modified-since checks
2015/11/15 Version 1.3.1
- Add recent contributors to CONTRIBUTORS.md
- Document showDotFiles in main options example
2015/11/14 Version 1.3.0
- opts.showDotFiles allows hiding dot files
2015/11/03 Version 1.2.0
- opts.cache supports function argument
2015/10/03 Version 1.1.3
... (truncated)
- Add CORS=false to defaults
Commits
-
709c0f0
Release 2.2.2 -
4e2a944
Backport redirect vuln fix - See full diff in compare view
Maintainer changes
This version was pushed to npm by jfhbrook, a new releaser for ecstatic since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot ignore this [patch|minor|major] version
will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.