Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump socket.io-parser, karma and webpack-dashboard #262

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 28, 2022

Bumps socket.io-parser to 4.2.1 and updates ancestor dependencies socket.io-parser, karma and webpack-dashboard. These dependencies need to be updated together.

Updates socket.io-parser from 2.3.1 to 4.2.1

Release notes

Sourced from socket.io-parser's releases.

4.2.1

Bug Fixes

  • check the format of the index of each attachment (b5d0cb7)

Links

4.2.0

Features

  • allow the usage of custom replacer and reviver (#112) (b08bc1a)

Links

4.1.2

Bug Fixes

  • allow objects with a null prototype in binary packets (#114) (7f6b262)

Links

4.1.1

Links

4.1.0

Features

  • provide an ESM build with and without debug (388c616)

Links

4.0.5

Bug Fixes

  • check the format of the index of each attachment (b559f05)

Links

... (truncated)

Changelog

Sourced from socket.io-parser's changelog.

4.2.1 (2022-06-27)

Bug Fixes

  • check the format of the index of each attachment (b5d0cb7)

4.2.0 (2022-04-17)

Features

  • allow the usage of custom replacer and reviver (#112) (b08bc1a)

4.1.2 (2022-02-17)

Bug Fixes

  • allow objects with a null prototype in binary packets (#114) (7f6b262)

4.1.1 (2021-10-14)

4.1.0 (2021-10-11)

Features

  • provide an ESM build with and without debug (388c616)

4.0.4 (2021-01-15)

Bug Fixes

  • allow integers as event names (1c220dd)

4.0.3 (2021-01-05)

4.0.2 (2020-11-25)

... (truncated)

Commits
  • 5a2ccff chore(release): 4.2.1
  • b5d0cb7 fix: check the format of the index of each attachment
  • c7514b5 chore(release): 4.2.0
  • 931f152 chore: add Node.js 16 in the test matrix
  • 6c9cb27 chore: bump @​socket.io/component-emitter to version 3.1.0
  • b08bc1a feat: allow the usage of custom replacer and reviver (#112)
  • aed252c chore(release): 4.1.2
  • 89209fa chore: bump cached-path-relative from 1.0.2 to 1.1.0 (#113)
  • 0a3b556 chore: bump path-parse from 1.0.6 to 1.0.7 (#108)
  • 7f6b262 fix: allow objects with a null prototype in binary packets (#114)
  • Additional commits viewable in compare view

Updates karma from 1.5.0 to 6.4.1

Release notes

Sourced from karma's releases.

v6.4.1

6.4.1 (2022-09-19)

Bug Fixes

v6.4.0

6.4.0 (2022-06-14)

Features

  • support SRI verification of link tags (dc51a2e)
  • support SRI verification of script tags (6a54b1c)

v6.3.20

6.3.20 (2022-05-13)

Bug Fixes

  • prefer IPv4 addresses when resolving domains (e17698f), closes #3730

v6.3.19

6.3.19 (2022-04-19)

Bug Fixes

  • client: error out when opening a new tab fails (099b85e)

v6.3.18

6.3.18 (2022-04-13)

Bug Fixes

  • deps: upgrade socket.io to v4.4.1 (52a30bb)

v6.3.17

6.3.17 (2022-02-28)

Bug Fixes

  • deps: update colors to maintained version (#3763) (fca1884)

v6.3.16

... (truncated)

Changelog

Sourced from karma's changelog.

6.4.1 (2022-09-19)

Bug Fixes

6.4.0 (2022-06-14)

Features

  • support SRI verification of link tags (dc51a2e)
  • support SRI verification of script tags (6a54b1c)

6.3.20 (2022-05-13)

Bug Fixes

  • prefer IPv4 addresses when resolving domains (e17698f), closes #3730

6.3.19 (2022-04-19)

Bug Fixes

  • client: error out when opening a new tab fails (099b85e)

6.3.18 (2022-04-13)

Bug Fixes

  • deps: upgrade socket.io to v4.4.1 (52a30bb)

6.3.17 (2022-02-28)

Bug Fixes

  • deps: update colors to maintained version (#3763) (fca1884)

6.3.16 (2022-02-10)

Bug Fixes

  • security: mitigate the "Open Redirect Vulnerability" (ff7edbb)

... (truncated)

Commits
  • 0013121 chore(release): 6.4.1 [skip ci]
  • 63d86be fix: pass integrity value
  • 84f7cc3 chore(release): 6.4.0 [skip ci]
  • f2d0663 docs: add integrity parameter
  • dc51a2e feat: support SRI verification of link tags
  • 6a54b1c feat: support SRI verification of script tags
  • 5e71cf5 chore(release): 6.3.20 [skip ci]
  • e17698f fix: prefer IPv4 addresses when resolving domains
  • 60f4f79 build: add Node 16 and 18 to the CI matrix
  • 6ff5aaf chore(release): 6.3.19 [skip ci]
  • Additional commits viewable in compare view

Updates webpack-dashboard from 0.3.0 to 3.3.7

Release notes

Sourced from webpack-dashboard's releases.

v3.0.7

Features

Migration Instructions

No changes required to start using v3.0.7 🎉.

v3.0.6

Features

Migration Instructions

No changes required to start using v3.0.6 🎉.

v3.0.5

Features

Security

v3.0.4

v3.0.4 was an erroneous publish.

v3.0.3

Bugs

Socket.io disconnects / large stats object size: Dramatically reduce the size of the webpack stats object being sent from client (webpack plugin) to server (CLI). Add client error/disconnect information for better future debugging. Original issue: #279 and fix: #281.

Migration Instructions

No changes required to start using v3.0.3 🎉.

3.0.2

Features

Migration Instructions

No changes required to start using v3.0.2 🎉.

3.0.1

... (truncated)

Changelog

Sourced from webpack-dashboard's changelog.

3.3.7

  • Bug: Move plugin types and update to webpack v5. #324

3.3.6

  • Bug: Allow socket messages to be null. #335, #336

[3.3.5] - 2021-07-12

  • Chore: Update dependencies. #333
  • Coverage: Add CodeCov stats. #206
  • CI: Update Node matrix to 12/14/16.

[3.3.4] - 2021-07-12

  • Chore: Refactor internal stats consumption to perform inspectpack analysis in the main thread, without using main streams.
  • Chore: Refactor internal handler in plugin to always be a wrapped function so that we can't accidentally have asynchronous code call the handler function after it is removed / nulled.
  • Bugfix: Add message counting delayed cleanup in plugin to allow messages to drain in Dashboard. Fixes #294.

[3.3.3] - 2021-05-05

[3.3.2] - 2021-05-05

  • Empty publish.

[3.3.1] - 2021-01-29

  • Bugfix: Ensure Status is properly updating and reaches completion. Fixes #321

[3.3.0] - 2021-01-21

  • Add webpack@5 support. Closes #316
  • Bugfix: webpack@5 warning message conflict. Fixes #314
  • Update various production dependencies.

[3.2.1] - 2020-08-24

[3.2.0] - 2019-09-08

[3.1.0] - 2019-08-27

  • Add DashboardPlugin({ includeAssets: [ "stringPrefix", /regexObj/ ] }) Webpack plugin filtering option.
  • Add webpack-dashboard --include-assets stringPrefix1 -a stringPrefix2 CLI filtering option.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by ryan.roemer, a new releaser for webpack-dashboard since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [socket.io-parser](https://github.com/socketio/socket.io-parser) to 4.2.1 and updates ancestor dependencies [socket.io-parser](https://github.com/socketio/socket.io-parser), [karma](https://github.com/karma-runner/karma) and [webpack-dashboard](https://github.com/FormidableLabs/webpack-dashboard). These dependencies need to be updated together.


Updates `socket.io-parser` from 2.3.1 to 4.2.1
- [Release notes](https://github.com/socketio/socket.io-parser/releases)
- [Changelog](https://github.com/socketio/socket.io-parser/blob/main/CHANGELOG.md)
- [Commits](socketio/socket.io-parser@2.3.1...4.2.1)

Updates `karma` from 1.5.0 to 6.4.1
- [Release notes](https://github.com/karma-runner/karma/releases)
- [Changelog](https://github.com/karma-runner/karma/blob/master/CHANGELOG.md)
- [Commits](karma-runner/karma@v1.5.0...v6.4.1)

Updates `webpack-dashboard` from 0.3.0 to 3.3.7
- [Release notes](https://github.com/FormidableLabs/webpack-dashboard/releases)
- [Changelog](https://github.com/FormidableLabs/webpack-dashboard/blob/master/CHANGELOG.md)
- [Commits](FormidableLabs/webpack-dashboard@v0.3.0...v3.3.7)

---
updated-dependencies:
- dependency-name: socket.io-parser
  dependency-type: indirect
- dependency-name: karma
  dependency-type: direct:development
- dependency-name: webpack-dashboard
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Oct 28, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants