Bumps qs from 6.11.0 to 6.14.2.
Changelog
Sourced from qs's changelog.
6.14.2
- [Fix]
parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)
- [Fix]
arrayLimit means max count, not max index, in combine/merge/parseArrayValue
- [Fix]
parse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)
- [Fix]
parse: enforce arrayLimit on comma-parsed values
- [Fix]
parse: fix error message to reflect arrayLimit as max index; remove extraneous comments (#545)
- [Robustness] avoid
.push, use void
- [readme] document that
addQueryPrefix does not add ? to empty output (#418)
- [readme] clarify
parseArrays and arrayLimit documentation (#543)
- [readme] replace runkit CI badge with shields.io check-runs badge
- [meta] fix changelog typo (
arrayLength → arrayLimit)
- [actions] fix rebase workflow permissions
6.14.1
- [Fix] ensure
arrayLimit applies to [] notation as well
- [Fix]
parse: when a custom decoder returns null for a key, ignore that key
- [Refactor]
parse: extract key segment splitting helper
- [meta] add threat model
- [actions] add workflow permissions
- [Tests]
stringify: increase coverage
- [Dev Deps] update
eslint, @ljharb/eslint-config, npmignore, es-value-fixtures, for-each, object-inspect
6.14.0
- [New]
parse: add throwOnParameterLimitExceeded option (#517)
- [Refactor]
parse: use utils.combine more
- [patch]
parse: add explicit throwOnLimitExceeded default
- [actions] use shared action; re-add finishers
- [meta] Fix changelog formatting bug
- [Deps] update
side-channel
- [Dev Deps] update
es-value-fixtures, has-bigints, has-proto, has-symbols
- [Tests] increase coverage
6.13.1
- [Fix]
stringify: avoid a crash when a filter key is null
- [Fix]
utils.merge: functions should not be stringified into keys
- [Fix]
parse: avoid a crash with interpretNumericEntities: true, comma: true, and iso charset
- [Fix]
stringify: ensure a non-string filter does not crash
- [Refactor] use
__proto__ syntax instead of Object.create for null objects
- [Refactor] misc cleanup
- [Tests]
utils.merge: add some coverage
- [Tests] fix a test case
- [actions] split out node 10-20, and 20+
- [Dev Deps] update
es-value-fixtures, mock-property, object-inspect, tape
6.13.0
- [New]
parse: add strictDepth option (#511)
- [Tests] use
npm audit instead of aud
6.12.3
- [Fix]
parse: properly account for strictNullHandling when allowEmptyArrays
... (truncated)
Commits
bdcf0c7 v6.14.2
294db90 [readme] document that addQueryPrefix does not add ? to empty output
5c308e5 [readme] clarify parseArrays and arrayLimit documentation
6addf8c [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit
cfc108f [Fix] arrayLimit means max count, not max index, in combine/merge/`pars...
febb644 [Fix] parse: throw on arrayLimit exceeded with indexed notation when `thr...
f6a7abf [Fix] parse: enforce arrayLimit on comma-parsed values
fbc5206 [Fix] parse: fix error message to reflect arrayLimit as max index; remove e...
1b9a8b4 [actions] fix rebase workflow permissions
2a35775 [meta] fix changelog typo (arrayLength → arrayLimit)
- Additional commits viewable in compare view
Dependabot compatibility score
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Bumps qs from 6.11.0 to 6.14.2.
Changelog
Sourced from qs's changelog.
... (truncated)
Commits
bdcf0c7v6.14.2294db90[readme] document thataddQueryPrefixdoes not add?to empty output5c308e5[readme] clarifyparseArraysandarrayLimitdocumentation6addf8c[Fix]parse: mark overflow objects for indexed notation exceedingarrayLimitcfc108f[Fix]arrayLimitmeans max count, not max index, incombine/merge/`pars...febb644[Fix]parse: throw onarrayLimitexceeded with indexed notation when `thr...f6a7abf[Fix]parse: enforcearrayLimitoncomma-parsed valuesfbc5206[Fix]parse: fix error message to reflect arrayLimit as max index; remove e...1b9a8b4[actions] fix rebase workflow permissions2a35775[meta] fix changelog typo (arrayLength→arrayLimit)Dependabot compatibility score
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.