Bumps json5 to 2.2.3 and updates ancestor dependencies json5, json5, @vue/babel-preset-app and @vue/cli-service. These dependencies need to be updated together.
Updates json5 from 2.1.1 to 2.2.3
Release notes
Sourced from json5's releases.
v2.2.3
- Fix: json5@2.2.3 is now the 'latest' release according to npm instead of v1.0.2. (#299)
v2.2.2
- Fix: Properties with the name __proto__are added to objects and arrays.
(#199) This also fixes a prototype pollution vulnerability reported by
Jonathan Gregson! (#295).
v2.2.1
v2.2.0
- New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)
- Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)
v2.1.2
- Fix: Bump minimisttov1.2.5. (#222)
 
Changelog
Sourced from json5's changelog.
- Fix: json5@2.2.3 is now the 'latest' release according to npm instead of
v1.0.2. (#299)
- Fix: Properties with the name __proto__are added to objects and arrays.
(#199) This also fixes a prototype pollution vulnerability reported by
Jonathan Gregson! (#295).
- New: Accurate and documented TypeScript declarations are now included. There
is no need to install @types/json5. (#236, #244)
- Fix: An out of memory bug when parsing numbers has been fixed. (#228,
#229)
- Fix: Bump minimisttov1.2.5. (#222)
 
Commits
 
Updates json5 from 1.0.1 to 2.2.3
Release notes
Sourced from json5's releases.
v2.2.3
- Fix: json5@2.2.3 is now the 'latest' release according to npm instead of v1.0.2. (#299)
v2.2.2
- Fix: Properties with the name __proto__are added to objects and arrays.
(#199) This also fixes a prototype pollution vulnerability reported by
Jonathan Gregson! (#295).
v2.2.1
v2.2.0
- New: Accurate and documented TypeScript declarations are now included. There is no need to install @types/json5. (#236, #244)
- Fix: An out of memory bug when parsing numbers has been fixed. (#228, #229)
v2.1.2
- Fix: Bump minimisttov1.2.5. (#222)
 
Changelog
Sourced from json5's changelog.
- Fix: json5@2.2.3 is now the 'latest' release according to npm instead of
v1.0.2. (#299)
- Fix: Properties with the name __proto__are added to objects and arrays.
(#199) This also fixes a prototype pollution vulnerability reported by
Jonathan Gregson! (#295).
- New: Accurate and documented TypeScript declarations are now included. There
is no need to install @types/json5. (#236, #244)
- Fix: An out of memory bug when parsing numbers has been fixed. (#228,
#229)
- Fix: Bump minimisttov1.2.5. (#222)
 
Commits
 
Updates @vue/babel-preset-app from 4.0.5 to 4.5.19
Release notes
Sourced from @vue/babel-preset-app's releases.
v4.5.19
IMPORTANT NOTE: IE 11 has reached End-of-Life. The default browserslist query no longer includes IE 11 as a target.
If your project still has to support IE 11, you MUST manually add IE 11 to the last line of the .browserslistrc file in the project (or browserslist field in package.json)
🐛 Bug Fix
- @vue/babel-preset-app- 
- [c7fa1cf] fix: always transpile syntaxes introduced in ES2020 or later, so that optional chaining and nullish coalescing syntaxes won't cause errors in webpack 4 and ESLint 6.
 
- @vue/cli-plugin-typescript
v4.5.18
Fix compatibility with the upcoming Vue 2.7 (currently in alpha) and Vue Loader 15.10 (currently in beta).
In Vue 2.7, vue-template-compiler is no longer a required peer dependency. Rather, there's a new export under the main package as vue/compiler-sfc.
v4.5.17
🐛 Bug Fix
- @vue/cli-shared-utils,- @vue/cli-ui- 
- d7a9881 fix: replace node-ipcwith@achrinza/node-ipcto further secure the dependency chain
 
Committers: 1
v4.5.16
4.5.16 (2022年03月15日)
🐛 Bug Fix
- @vue/cli-service- 
- Fix demo-lib.html and demo-wc.html for Vue 2
 
- @vue/cli-shared-utils,- @vue/cli-ui
v4.5.15
Bug Fixes
- fix: set .mjsfile type tojavascript/auto[15b1e1b]
This change allows an .mjs file to import named exports from .cjs and plain .js files.
Fixes compatibility with pinia.
v4.5.14
Security Fixes
This version fixed a CORS vulnerability and an XSS vulnerability in Vue CLI UI.
We recommend all users of vue ui to upgrade to this version as soon as possible.
Credits:
Ngo Wei Lin (@Creastery) of STAR Labs (@starlabs_sg)
... (truncated)
 
Changelog
Sourced from @vue/babel-preset-app's changelog.
4.5.19 (2022年06月28日)
IMPORTANT NOTE: IE 11 has reached End-of-Life. The default browserslist query no longer includes IE 11 as a target.
If your project still has to support IE 11, you MUST manually add IE 11 to the last line of the .browserslistrc file in the project (or browserslist field in package.json)
🐛 Bug Fix
- @vue/babel-preset-app- 
- [c7fa1cf] fix: always transpile syntaxes introduced in ES2020 or later, so that optional chaining and nullish coalescing syntaxes won't cause errors in webpack 4 and ESLint 6.
 
- @vue/cli-plugin-typescript
4.5.18 (2022年06月16日)
Fix compatibility with the upcoming Vue 2.7 (currently in alpha) and Vue Loader 15.10 (currently in beta).
In Vue 2.7, vue-template-compiler is no longer a required peer dependency. Rather, there's a new export under the main package as vue/compiler-sfc.
4.5.17 (2022年03月23日)
🐛 Bug Fix
- @vue/cli-shared-utils,- @vue/cli-ui- 
- d7a9881 fix: replace node-ipcwith@achrinza/node-ipcto further secure the dependency chain
 
Committers: 1
4.5.16 (2022年03月15日)
🐛 Bug Fix
- @vue/cli-service- 
- Fix demo-lib.html and demo-wc.html for Vue 2
 
- @vue/cli-shared-utils,- @vue/cli-ui
4.5.15 (2021年10月28日)
Bug Fixes
- fix: set .mjsfile type tojavascript/auto[15b1e1b]
This change allows an .mjs file to import named exports from .cjs and plain .js files.
Fixes compatibility with pinia.
4.5.14 (2021年10月14日)
... (truncated)
 
Commits
 
Updates @vue/cli-service from 4.0.5 to 5.0.8
Release notes
Sourced from @vue/cli-service's releases.
v5.0.8
🐛 Bug Fix
- @vue/cli-service
- @vue/cli-ui
v5.0.7
- @vue/cli-service
- @vue/cli-ui- 
- #7210 chore: upgrade to apollo-server-express 3.x
 
Committers: 2
v5.0.6
Fix compatibility with the upcoming Vue 2.7 (currently in alpha) and Vue Loader 15.10 (currently in beta).
In Vue 2.7, vue-template-compiler is no longer a required peer dependency. Rather, there's a new export under the main package as vue/compiler-sfc.
v5.0.5
🐛 Bug Fix
- @vue/cli- 
- #7167 fix(upgrade): prevent changing the structure of package.json file during upgrade (@blzsaa)
 
- @vue/cli-service
- @vue/cli-plugin-e2e-cypress- 
- [697bb44] fix: should correctly resolve cypress bin path for Cypress 10 (Note that the project is still created with Cypress 9 by default, but you can upgrade to Cypress 10 on your own now)
 
Committers: 3
v5.0.4
🐛 Bug Fix
- @vue/cli-service
- @vue/cli-shared-utils,- @vue/cli-ui- 
- 75826d6 fix: replace node-ipcwith@achrinza/node-ipcto further secure the dependency chain
 
Committers: 1
v5.0.3
... (truncated)
 
Changelog
Sourced from @vue/cli-service's changelog.
5.0.7 (2022年07月05日)
- @vue/cli-service
- @vue/cli-ui- 
- #7210 chore: upgrade to apollo-server-express 3.x
 
Committers: 2
5.0.6 (2022年06月16日)
Fix compatibility with the upcoming Vue 2.7 (currently in alpha) and Vue Loader 15.10 (currently in beta).
In Vue 2.7, vue-template-compiler is no longer a required peer dependency. Rather, there's a new export under the main package as vue/compiler-sfc.
5.0.5 (2022年06月16日)
🐛 Bug Fix
- @vue/cli- 
- #7167 feat(upgrade): prevent changing the structure of package.json file during upgrade (@blzsaa)
 
- @vue/cli-service
Committers: 3
5.0.4 (2022年03月22日)
🐛 Bug Fix
- @vue/cli-service
- @vue/cli-shared-utils,- @vue/cli-ui- 
- 75826d6 fix: replace node-ipcwith@achrinza/node-ipcto further secure the dependency chain
 
Committers: 1
... (truncated)
 
Commits
- b154dbdv5.0.8
- 0260e4dfix: add devServer.server.type to useHttps judgement (#7222)
- 4a0655fv5.0.7
- beffe8afix: allow disabling progress plugin via- devServer.client.progress
- 558dea2fix: support- devServer.serveroption, avoid deprecation warning
- bddd64dfix: optimize the judgment on whether HTTPS has been set in options (#7202)
- ef08a08v5.0.6
- fcf27e3fixup! fix: compatibility with Vue 2.7
- a648958fix: compatibility with Vue 2.7
- 98c66c9v5.0.5
- Additional commits viewable in compare view 
 
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebasewill rebase this PR
- @dependabot recreatewill recreate this PR, overwriting any edits that have been made to it
- @dependabot mergewill merge this PR after your CI passes on it
- @dependabot squash and mergewill squash and merge this PR after your CI passes on it
- @dependabot cancel mergewill cancel a previously requested merge and block automerging
- @dependabot reopenwill reopen this PR if it is closed
- @dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labelswill set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
 
  
 
Bumps json5 to 2.2.3 and updates ancestor dependencies json5, json5, @vue/babel-preset-app and @vue/cli-service. These dependencies need to be updated together.
Updates
json5from 2.1.1 to 2.2.3Release notes
Sourced from json5's releases.
Changelog
Sourced from json5's changelog.
Commits
c3a75242.2.394fd06ddocs: update CHANGELOG for v2.2.33b8cebfdocs(security): use GitHub security advisoriesf0fd9e1docs: publish a security policy6a91a05docs(template): bug -> bug report14f8cb12.2.210cc7cadocs: update CHANGELOG for v2.2.27774c10fix: add proto to objects and arraysedde30aReadme: slight tweak to intro97286f8Improve example in readmeUpdates
json5from 1.0.1 to 2.2.3Release notes
Sourced from json5's releases.
Changelog
Sourced from json5's changelog.
Commits
c3a75242.2.394fd06ddocs: update CHANGELOG for v2.2.33b8cebfdocs(security): use GitHub security advisoriesf0fd9e1docs: publish a security policy6a91a05docs(template): bug -> bug report14f8cb12.2.210cc7cadocs: update CHANGELOG for v2.2.27774c10fix: add proto to objects and arraysedde30aReadme: slight tweak to intro97286f8Improve example in readmeUpdates
@vue/babel-preset-appfrom 4.0.5 to 4.5.19Release notes
Sourced from
@vue/babel-preset-app's releases.... (truncated)
Changelog
Sourced from
@vue/babel-preset-app's changelog.... (truncated)
Commits
bef7a67v4.5.19434c72ctest: explicitly add ie 11 to targets in testsc7fa1cffix: always transpile syntaxes introduced in ES2020 or later9245eb2v4.5.1858ff39cv4.5.17c38e755v4.5.1622a8a78v4.5.15f128c0cv4.5.146e0d846v4.5.139a125a2fix(v4): fix modern mode optional chaining syntax tranpilation (#6459)Updates
@vue/cli-servicefrom 4.0.5 to 5.0.8Release notes
Sourced from
@vue/cli-service's releases.... (truncated)
Changelog
Sourced from
@vue/cli-service's changelog.... (truncated)
Commits
b154dbdv5.0.80260e4dfix: add devServer.server.type to useHttps judgement (#7222)4a0655fv5.0.7beffe8afix: allow disabling progress plugin viadevServer.client.progress558dea2fix: supportdevServer.serveroption, avoid deprecation warningbddd64dfix: optimize the judgment on whether HTTPS has been set in options (#7202)ef08a08v5.0.6fcf27e3fixup! fix: compatibility with Vue 2.7a648958fix: compatibility with Vue 2.798c66c9v5.0.5Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and languageYou can disable automated security fix PRs for this repo from the Security Alerts page.