guillotine-packer
guillotine-packer copied to clipboard
chore(deps): bump minimist, mkdirp, commitizen and handlebars
Bumps minimist to 1.2.7 and updates ancestor dependencies minimist, minimist, mkdirp, commitizen and handlebars. These dependencies need to be updated together.
Updates minimist
from 1.2.0 to 1.2.7
Changelog
Sourced from minimist's changelog.
v1.2.7 - 2022-10-10
Commits
- [meta] add
auto-changelog
0ebf4eb
- [actions] add reusable workflows
e115b63
- [eslint] add eslint; rules to enable later are warnings
f58745b
- [Dev Deps] switch from
covert
tonyc
ab03356
- [readme] rename and add badges
236f4a0
- [meta] create FUNDING.yml; add
funding
in package.json783a49b
- [meta] use
npmignore
to autogenerate an npmignore filef81ece6
- Only apps should have lockfiles
56cad44
- [Dev Deps] update
covert
,tape
; remove unnecessarytap
49c5f9f
- [Tests] add
aud
inposttest
228ae93
- [meta] add
safe-publish-latest
01fc23f
- [meta] update repo URLs
6b164c7
v1.2.6 - 2022-03-21
Commits
- test from prototype pollution PR
bc8ecee
- isConstructorOrProto adapted from PR
c2b9819
- security notice for additional prototype pollution issue
ef88b93
v1.2.5 - 2020-03-12
v1.2.4 - 2020-03-11
Commits
v1.2.3 - 2020-03-10
Commits
- more failing proto pollution tests
13c01a5
- even more aggressive checks for protocol pollution
38a4d1c
v1.2.2 - 2020-03-10
Commits
... (truncated)
Commits
c590d75
v1.2.70ebf4eb
[meta] addauto-changelog
e115b63
[actions] add reusable workflows01fc23f
[meta] addsafe-publish-latest
f58745b
[eslint] add eslint; rules to enable later are warnings228ae93
[Tests] addaud
inposttest
236f4a0
[readme] rename and add badgesab03356
[Dev Deps] switch fromcovert
tonyc
49c5f9f
[Dev Deps] updatecovert
,tape
; remove unnecessarytap
783a49b
[meta] create FUNDING.yml; addfunding
in package.json- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for minimist since your current version.
Updates minimist
from 1.2.5 to 1.2.7
Changelog
Sourced from minimist's changelog.
v1.2.7 - 2022-10-10
Commits
- [meta] add
auto-changelog
0ebf4eb
- [actions] add reusable workflows
e115b63
- [eslint] add eslint; rules to enable later are warnings
f58745b
- [Dev Deps] switch from
covert
tonyc
ab03356
- [readme] rename and add badges
236f4a0
- [meta] create FUNDING.yml; add
funding
in package.json783a49b
- [meta] use
npmignore
to autogenerate an npmignore filef81ece6
- Only apps should have lockfiles
56cad44
- [Dev Deps] update
covert
,tape
; remove unnecessarytap
49c5f9f
- [Tests] add
aud
inposttest
228ae93
- [meta] add
safe-publish-latest
01fc23f
- [meta] update repo URLs
6b164c7
v1.2.6 - 2022-03-21
Commits
- test from prototype pollution PR
bc8ecee
- isConstructorOrProto adapted from PR
c2b9819
- security notice for additional prototype pollution issue
ef88b93
v1.2.5 - 2020-03-12
v1.2.4 - 2020-03-11
Commits
v1.2.3 - 2020-03-10
Commits
- more failing proto pollution tests
13c01a5
- even more aggressive checks for protocol pollution
38a4d1c
v1.2.2 - 2020-03-10
Commits
... (truncated)
Commits
c590d75
v1.2.70ebf4eb
[meta] addauto-changelog
e115b63
[actions] add reusable workflows01fc23f
[meta] addsafe-publish-latest
f58745b
[eslint] add eslint; rules to enable later are warnings228ae93
[Tests] addaud
inposttest
236f4a0
[readme] rename and add badgesab03356
[Dev Deps] switch fromcovert
tonyc
49c5f9f
[Dev Deps] updatecovert
,tape
; remove unnecessarytap
783a49b
[meta] create FUNDING.yml; addfunding
in package.json- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for minimist since your current version.
Updates mkdirp
from 0.5.1 to 0.5.6
Commits
92f086d
0.5.62a28125
clean up testsc905d65
update minimist049cf18
0.5.5bea6382
Remove unnecessary umask calls42a012c
0.5.42867920
fix infinite loop on windows machinesd784e70
0.5.3d612c5d
add files list so this package isn't a monsterb2e7ba0
0.5.2- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by isaacs, a new releaser for mkdirp since your current version.
Updates commitizen
from 3.1.2 to 4.3.0
Release notes
Sourced from commitizen's releases.
v4.3.0
4.3.0 (2023-01-19)
Features
v4.2.6
4.2.6 (2022-12-06)
Bug Fixes
v4.2.5
4.2.5 (2022-07-17)
Bug Fixes
- deps: update all non-major dependencies (69de704)
- deps: update all non-major dependencies (3c2553f)
- deps: update dependencies from renovatebot PRs (#862) (64a8ed6)
- deps: update dependency glob to v7.1.6 (#861) (2505419)
- deps: update dependency inquirer to v8 (#874) (9c7e863)
- do not include .nyc_output in published files (#851) (68c377b), closes 4.2.4#d2h-425221 #730
- fix the "isFunction" utility to match both "asyncFunction"s and "Function"s (#927) (25dc80c), closes #926
- git-cz.js,staging.js: check for staged files before running prompt (#818) (fdb73cd), closes #785 #585 #785
v4.2.4
4.2.4 (2021-05-07)
Bug Fixes
v4.2.3
4.2.3 (2021-01-15)
Bug Fixes
v4.2.2
4.2.2 (2020-10-20)
... (truncated)
Commits
c1f4142
feat(init): add pnpm support (#915)87138d3
chore(deps) Update all non-major dependencies815c69d
fix(sec): upgrade semantic-release to 19.0.3 (#953)0939910
ci(release): defined a github workflow to release with semantic-release (#923)757a806
chore(deps): update all non-major dependencies25dc80c
fix: fix the "isFunction" utility to match both "asyncFunction"s and "Functio...fc283fb
chore(deps): update dependency semver to v7.3.7c35a3c7
chore(deps): update all non-major dependencies69de704
fix(deps): update all non-major dependenciese79f3ee
chore(deps): update dependency@babel/core
to v7.17.8- Additional commits viewable in compare view
Updates handlebars
from 4.7.2 to 4.7.7
Changelog
Sourced from handlebars's changelog.
v4.7.7 - February 15th, 2021
- fix weird error in integration tests - eb860c0
- fix: check prototype property access in strict-mode (#1736) - b6d3de7
- fix: escape property names in compat mode (#1736) - f058970
- refactor: In spec tests, use expectTemplate over equals and shouldThrow (#1683) - 77825f8
- chore: start testing on Node.js 12 and 13 - 3789a30
(POSSIBLY) BREAKING CHANGES:
- the changes from version 4.6.0 now also apply in when using the compile-option "strict: true". Access to prototype properties is forbidden completely by default, specific properties or methods can be allowed via runtime-options. See #1633 for details. If you are using Handlebars as documented, you should not be accessing prototype properties from your template anyway, so the changes should not be a problem for you. Only the use of undocumented features can break your build.
That is why we only bump the patch version despite mentioning breaking changes.
v4.7.6 - April 3rd, 2020
Chore/Housekeeping:
- #1672 - Switch cmd parser to latest minimist (
@dougwilson
Compatibility notes:
- Restored Node.js compatibility
v4.7.5 - April 2nd, 2020
Chore/Housekeeping:
Node.js version support has been changed to v6+Reverted in 4.7.6Compatibility notes:
Node.js < v6 is no longer supportedReverted in 4.7.6v4.7.4 - April 1st, 2020
Chore/Housekeeping:
- #1666 - Replaced minimist with yargs for handlebars CLI (
@aorinevo
,@AviVahl
&@fabb
)Compatibility notes:
... (truncated)
Commits
a9a8e40
v4.7.7e66aed5
Update release notes7d4d170
disable IE in Saucelabs testseb860c0
fix weird error in integration testsb6d3de7
fix: check prototype property access in strict-mode (#1736)f058970
fix: escape property names in compat mode (#1736)77825f8
refator: In spec tests, use expectTemplate over equals and shouldThrow (#1683)3789a30
chore: start testing on Node.js 12 and 13e6ad93e
v4.7.62bf4fc6
Update release notes- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.