Bumps tough-cookie to 4.1.3 and updates ancestor dependencies tough-cookie, jsdom and lerna. These dependencies need to be updated together.
Updates tough-cookie from 2.5.0 to 4.1.3
Release notes
Sourced from tough-cookie's releases.
4.1.3
Security fix for Prototype Pollution discovery in #282. This is a minor release, although output from the inspect utility is affected by this change, we felt this change was important enough to be pushed into the next patch.
4.1.2 -- Patch and Bugfix Release
What's Changed
Full Changelog: salesforce/tough-cookie@v4.1.1...v4.1.2
4.1.1
Patch Release
What's Changed
Full Changelog: salesforce/tough-cookie@v4.1.0...v4.1.1
4.1.0
v4.1.0
Minor release, focused mainly on resolving reported issues and some minor feature work.
What's Changed
... (truncated)
Commits
4ff4d29 4.1.3 release preparation, update the package and lib/version to 4.1.3. (#284)
12d4747 Prevent prototype pollution in cookie memstore (#283)
f06b72d Fix documentation for store.findCookies, missing allowSpecialUseDomain proper...
b1a8898 fix: allow set cookies with localhost (#253)
ec70796 4.1.1 Patch -- allow special use domains by default (#250)
d4ac580 fix: allow special use domains by default (#249)
79c2f7d 4.1.0 release to NPM (#245)
4fafc17 Prepare tough-cookie 4.1 for publishing (updated GitHub actions, move Dockerf...
aa4396d fix: distinguish between no samesite and samesite=none (#240)
b8d7511 Modernize README (#234)
- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by awaterma, a new releaser for tough-cookie since your current version.
Updates jsdom from 16.5.3 to 16.7.0
Release notes
Sourced from jsdom's releases.
Version 16.7.0
- Added
AbortSignal.abort(). (ninevra)
- Added dummy
x and y properties to the return value of getBoundingClientRect(). (eiko)
- Implemented wrapping for
textareaEl.value if the wrap="" attribute is specified. (ninevra)
- Changed newline normalization in
<textarea>s according to recent HTML Standard updates. (ninevra)
- Fixed some bad cascade computation in
getComputedStyle(). (romain-trotard)
Version 16.6.0
- Added
parentNode.replaceChildren(). (@ninevra)
- Fixed jsdom's handling of when code running inside the jsdom throws
null or undefined as an exception. (@mbest)
- Removed the dependency on the deprecated
request package, in the process fixing several issues with the XMLHttpRequest implementation around header processing. Thanks go to @tobyhinloopen, @andrewaylett, and especially @vegardbb, for completing this months-long effort!
Changelog
Sourced from jsdom's changelog.
16.7.0
- Added
AbortSignal.abort(). (ninevra)
- Added dummy
x and y properties to the return value of getBoundingClientRect(). (eiko)
- Implemented wrapping for
textareaEl.value if the wrap="" attribute is specified. (ninevra)
- Changed newline normalization in
<textarea>s according to recent HTML Standard updates. (ninevra)
- Fixed some bad cascade computation in
getComputedStyle(). (romain-trotard)
16.6.0
- Added
parentNode.replaceChildren(). (ninevra)
- Fixed jsdom's handling of when code running inside the jsdom throws
null or undefined as an exception. (mbest)
- Removed the dependency on the deprecated
request package, in the process fixing several issues with the XMLHttpRequest implementation around header processing. Special thanks to vegardbb for completing this months-long effort!
Commits
Updates lerna from 4.0.0 to 7.1.1
Release notes
Sourced from lerna's releases.
7.1.1
7.1.1 (2023年06月28日)
Bug Fixes
- fix strict-ssl mapping for node-fetch-registry during unpublished projects lookup (#3747) (5fcf94e)
- publish: catch publish conflict 403 error from npm (#3753) (6123e86)
- publish: ensure that error code is valid (#3748) (c59b45b)
- schema: add missing ref to changelogEntryAdditionalMarkdown (b41afab)
7.1.0
7.1.0 (2023年06月25日)
Features
- core: export detectProjects utility function (#3740) (641fecb)
- repair: add migration to remove unused "lerna" field from lerna.json (#3734) (4fb0427)
- version: add --changelog-entry-additional-markdown option (#3751) (63671df)
7.0.2
7.0.2 (2023年06月15日)
Bug Fixes
- publish: revert auto-copying of assets to custom contents/directory (#3732) (70d4438)
7.0.1
7.0.1 (2023年06月13日)
Bug Fixes
- core: reset nx daemon after command finishes (#3726) (c0de66a)
7.0.0
7.0.0 (2023年06月08日)
BREAKING CHANGES
After updating we strongly recommend running lerna repair in your project. This will migrate your lerna.json to the latest and greatest and remove any outdated options.
As this is a major release there are a few breaking changes to be aware of, which may or may not affect your lerna repos, depending on how you are using the tool.
- legacy package management commands have been removed
We no longer include the bootstrap, add, and link commands by default. We strongly recommend using your package manager (npm, yarn, pnpm) for package management related concerns such as installing and linking dependencies.
... (truncated)
Changelog
Sourced from lerna's changelog.
7.1.1 (2023年06月28日)
Bug Fixes
- schema: add missing ref to changelogEntryAdditionalMarkdown (b41afab)
7.1.0 (2023年06月25日)
Features
- core: export detectProjects utility function (#3740) (641fecb)
- repair: add migration to remove unused "lerna" field from lerna.json (#3734) (4fb0427)
- version: add --changelog-entry-additional-markdown option (#3751) (63671df)
7.0.2 (2023年06月15日)
Note: Version bump only for package lerna
7.0.1 (2023年06月13日)
Note: Version bump only for package lerna
7.0.0 (2023年06月08日)
Bug Fixes
Features
- add migration for adding $schema, increase some strictness (73ceac3)
Bug Fixes
Features
- add migration for adding $schema, increase some strictness (73ceac3)
... (truncated)
Commits
04642ff chore(misc): publish 7.1.1
b41afab fix(schema): add missing ref to changelogEntryAdditionalMarkdown
2a6bb29 chore(misc): publish 7.1.0
63671df feat(version): add --changelog-entry-additional-markdown option (#3751)
641fecb feat(core): export detectProjects utility function (#3740)
4fb0427 feat(repair): add migration to remove unused "lerna" field from lerna.json (#...
e6c7427 chore(misc): publish 7.0.2
273ed54 chore(misc): publish 7.0.1
c81422d chore: add v7 release notes
3900fe9 chore(misc): publish 7.0.0
- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by jameshenry, a new releaser for lerna since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Bumps tough-cookie to 4.1.3 and updates ancestor dependencies tough-cookie, jsdom and lerna. These dependencies need to be updated together.
Updates
tough-cookiefrom 2.5.0 to 4.1.3Release notes
Sourced from tough-cookie's releases.
... (truncated)
Commits
4ff4d294.1.3 release preparation, update the package and lib/version to 4.1.3. (#284)12d4747Prevent prototype pollution in cookie memstore (#283)f06b72dFix documentation for store.findCookies, missing allowSpecialUseDomain proper...b1a8898fix: allow set cookies with localhost (#253)ec707964.1.1 Patch -- allow special use domains by default (#250)d4ac580fix: allow special use domains by default (#249)79c2f7d4.1.0 release to NPM (#245)4fafc17Prepare tough-cookie 4.1 for publishing (updated GitHub actions, move Dockerf...aa4396dfix: distinguish between no samesite and samesite=none (#240)b8d7511Modernize README (#234)Maintainer changes
This version was pushed to npm by awaterma, a new releaser for tough-cookie since your current version.
Updates
jsdomfrom 16.5.3 to 16.7.0Release notes
Sourced from jsdom's releases.
Changelog
Sourced from jsdom's changelog.
Commits
1aa3cbcVersion 16.7.0df1f551Don't run WebSocketStream testseb105b2Fix browser tests by enabling SharedArrayBuffer0dedfc0Fix some bad cascade computation in getComputedStyle()8021a56Fix "configuation" typo (#3213)a7febe3Fix typo in level2/html.js (#3222)c9896c0Return x, y properties from Element.getBoundingClientRect (#3187)346ea98Update web-platform tests (#3203)364c77dBump to ws 7.4.693ba6a0We are now on Matrix (#3207)Updates
lernafrom 4.0.0 to 7.1.1Release notes
Sourced from lerna's releases.
... (truncated)
Changelog
Sourced from lerna's changelog.
... (truncated)
Commits
04642ffchore(misc): publish 7.1.1b41afabfix(schema): add missing ref to changelogEntryAdditionalMarkdown2a6bb29chore(misc): publish 7.1.063671dffeat(version): add --changelog-entry-additional-markdown option (#3751)641fecbfeat(core): export detectProjects utility function (#3740)4fb0427feat(repair): add migration to remove unused "lerna" field from lerna.json (#...e6c7427chore(misc): publish 7.0.2273ed54chore(misc): publish 7.0.1c81422dchore: add v7 release notes3900fe9chore(misc): publish 7.0.0Maintainer changes
This version was pushed to npm by jameshenry, a new releaser for lerna since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.