🚨 [security] Update xo 0.44.0 → 0.60.0 (major)
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ xo (0.44.0 → 0.60.0) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ @babel/code-frame (indirect, 7.12.11 → 7.26.2) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 10 commits:
v7.26.2fix: Parse placeholder for TS namespace (#16903)Add test for current wrong behavior (#16948)fix: Account for offsets when creating new Position instances (#16937)Fix CI e2e-babel error (#16946)Update regjsparser (#16939)chore: fix typo in function name (#16938)Update compat data (#16930)Update test262 (#16931)Add v7.26.1 to CHANGELOG.md [skip ci]
↗️ @babel/helper-validator-identifier (indirect, 7.14.9 → 7.25.9) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 14 commits:
v7.25.9remove test options flaky (#16914)fix: Accidentally publishing useless files (#16917)chore: Improve logic regarding fast objects (#16919)test(numeric-separator): fix invalid test layout (#16920)perf: Make `VISITOR_KEYS` etc. faster to access (#16918)fix: Keep type annotations in `syntacticPlaceholders` mode (#16905)Update test262 (#16910)Update compat data (#16909)ci: pin latest node to 22 (#16913)fix: support BROWSERSLIST{,_CONFIG} env (#16907)Analyze `ClassAccessorProperty` to prevent the `no-undef` rule (#16884)Update test262 (#16900)Add v7.25.8 to CHANGELOG.md [skip ci]
↗️ @eslint/eslintrc (indirect, 0.4.3 → 2.1.4) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ @types/eslint (indirect, 7.28.0 → 8.56.12) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ @types/estree (indirect, 0.0.50 → 1.0.6) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ @types/json-schema (indirect, 7.0.9 → 7.0.15) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ @types/node (indirect, 16.4.13 → 22.10.1) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ @types/normalize-package-data (indirect, 2.4.1 → 2.4.4) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ @typescript-eslint/eslint-plugin (indirect, 4.29.1 → 7.18.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 21 commits:
chore(release): publish 7.18.0docs: link no-duplicate-type-constituents and no-redundant-type-constituents to each other (#9612)chore(deps): update dependency mocha to v10.7.0 (#9650)chore(deps): update dependency eslint-plugin-react to v7.35.0 (#9647)chore(deps): update dependency cspell to v8.11.0 (#9624)chore(deps): update dependency @swc/core to v1.7.0 (#9637)chore(deps): update dependency husky to v9.1.1 (#9635)fix(eslint-plugin): [strict-boolean-expressions] support branded booleans (#9297)docs: add ast-spec, type-utils docs with docusaurus-plugin-typedoc (#9293)docs: remove unnecessary v8 links (#9611)fix(eslint-plugin): [no-duplicate-type-constituents] shouldn't report on error types (#9600)fix(eslint-plugin): [unbound-method] report on destructuring in function parameters (#8952)fix(eslint-plugin): [no-unnecessary-type-assertion] prevent runtime error when asserting a variable declared in default TS lib (#9660)chore: reorg repo level utils, lint and typecheck repo files (#9618)docs: final updates to v8 beta post (#9627)chore(website): remove incorrect `twitterHandle` from type (#9651)feat(types): update ECMA versions (#9634)test: add integration test against @types/eslint v9 (#9622)chore: enable radix (#9563)docs: update perfectionist domain (#9619)chore: fix integration tests by pinning @types/eslint v8 (#9620)
↗️ @typescript-eslint/parser (indirect, 4.29.1 → 7.18.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 21 commits:
chore(release): publish 7.18.0docs: link no-duplicate-type-constituents and no-redundant-type-constituents to each other (#9612)chore(deps): update dependency mocha to v10.7.0 (#9650)chore(deps): update dependency eslint-plugin-react to v7.35.0 (#9647)chore(deps): update dependency cspell to v8.11.0 (#9624)chore(deps): update dependency @swc/core to v1.7.0 (#9637)chore(deps): update dependency husky to v9.1.1 (#9635)fix(eslint-plugin): [strict-boolean-expressions] support branded booleans (#9297)docs: add ast-spec, type-utils docs with docusaurus-plugin-typedoc (#9293)docs: remove unnecessary v8 links (#9611)fix(eslint-plugin): [no-duplicate-type-constituents] shouldn't report on error types (#9600)fix(eslint-plugin): [unbound-method] report on destructuring in function parameters (#8952)fix(eslint-plugin): [no-unnecessary-type-assertion] prevent runtime error when asserting a variable declared in default TS lib (#9660)chore: reorg repo level utils, lint and typecheck repo files (#9618)docs: final updates to v8 beta post (#9627)chore(website): remove incorrect `twitterHandle` from type (#9651)feat(types): update ECMA versions (#9634)test: add integration test against @types/eslint v9 (#9622)chore: enable radix (#9563)docs: update perfectionist domain (#9619)chore: fix integration tests by pinning @types/eslint v8 (#9620)
↗️ @typescript-eslint/scope-manager (indirect, 4.29.1 → 7.18.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 21 commits:
chore(release): publish 7.18.0docs: link no-duplicate-type-constituents and no-redundant-type-constituents to each other (#9612)chore(deps): update dependency mocha to v10.7.0 (#9650)chore(deps): update dependency eslint-plugin-react to v7.35.0 (#9647)chore(deps): update dependency cspell to v8.11.0 (#9624)chore(deps): update dependency @swc/core to v1.7.0 (#9637)chore(deps): update dependency husky to v9.1.1 (#9635)fix(eslint-plugin): [strict-boolean-expressions] support branded booleans (#9297)docs: add ast-spec, type-utils docs with docusaurus-plugin-typedoc (#9293)docs: remove unnecessary v8 links (#9611)fix(eslint-plugin): [no-duplicate-type-constituents] shouldn't report on error types (#9600)fix(eslint-plugin): [unbound-method] report on destructuring in function parameters (#8952)fix(eslint-plugin): [no-unnecessary-type-assertion] prevent runtime error when asserting a variable declared in default TS lib (#9660)chore: reorg repo level utils, lint and typecheck repo files (#9618)docs: final updates to v8 beta post (#9627)chore(website): remove incorrect `twitterHandle` from type (#9651)feat(types): update ECMA versions (#9634)test: add integration test against @types/eslint v9 (#9622)chore: enable radix (#9563)docs: update perfectionist domain (#9619)chore: fix integration tests by pinning @types/eslint v8 (#9620)
↗️ @typescript-eslint/types (indirect, 4.29.1 → 7.18.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 21 commits:
chore(release): publish 7.18.0docs: link no-duplicate-type-constituents and no-redundant-type-constituents to each other (#9612)chore(deps): update dependency mocha to v10.7.0 (#9650)chore(deps): update dependency eslint-plugin-react to v7.35.0 (#9647)chore(deps): update dependency cspell to v8.11.0 (#9624)chore(deps): update dependency @swc/core to v1.7.0 (#9637)chore(deps): update dependency husky to v9.1.1 (#9635)fix(eslint-plugin): [strict-boolean-expressions] support branded booleans (#9297)docs: add ast-spec, type-utils docs with docusaurus-plugin-typedoc (#9293)docs: remove unnecessary v8 links (#9611)fix(eslint-plugin): [no-duplicate-type-constituents] shouldn't report on error types (#9600)fix(eslint-plugin): [unbound-method] report on destructuring in function parameters (#8952)fix(eslint-plugin): [no-unnecessary-type-assertion] prevent runtime error when asserting a variable declared in default TS lib (#9660)chore: reorg repo level utils, lint and typecheck repo files (#9618)docs: final updates to v8 beta post (#9627)chore(website): remove incorrect `twitterHandle` from type (#9651)feat(types): update ECMA versions (#9634)test: add integration test against @types/eslint v9 (#9622)chore: enable radix (#9563)docs: update perfectionist domain (#9619)chore: fix integration tests by pinning @types/eslint v8 (#9620)
↗️ @typescript-eslint/typescript-estree (indirect, 4.29.1 → 7.18.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 21 commits:
chore(release): publish 7.18.0docs: link no-duplicate-type-constituents and no-redundant-type-constituents to each other (#9612)chore(deps): update dependency mocha to v10.7.0 (#9650)chore(deps): update dependency eslint-plugin-react to v7.35.0 (#9647)chore(deps): update dependency cspell to v8.11.0 (#9624)chore(deps): update dependency @swc/core to v1.7.0 (#9637)chore(deps): update dependency husky to v9.1.1 (#9635)fix(eslint-plugin): [strict-boolean-expressions] support branded booleans (#9297)docs: add ast-spec, type-utils docs with docusaurus-plugin-typedoc (#9293)docs: remove unnecessary v8 links (#9611)fix(eslint-plugin): [no-duplicate-type-constituents] shouldn't report on error types (#9600)fix(eslint-plugin): [unbound-method] report on destructuring in function parameters (#8952)fix(eslint-plugin): [no-unnecessary-type-assertion] prevent runtime error when asserting a variable declared in default TS lib (#9660)chore: reorg repo level utils, lint and typecheck repo files (#9618)docs: final updates to v8 beta post (#9627)chore(website): remove incorrect `twitterHandle` from type (#9651)feat(types): update ECMA versions (#9634)test: add integration test against @types/eslint v9 (#9622)chore: enable radix (#9563)docs: update perfectionist domain (#9619)chore: fix integration tests by pinning @types/eslint v8 (#9620)
↗️ @typescript-eslint/visitor-keys (indirect, 4.29.1 → 7.18.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 21 commits:
chore(release): publish 7.18.0docs: link no-duplicate-type-constituents and no-redundant-type-constituents to each other (#9612)chore(deps): update dependency mocha to v10.7.0 (#9650)chore(deps): update dependency eslint-plugin-react to v7.35.0 (#9647)chore(deps): update dependency cspell to v8.11.0 (#9624)chore(deps): update dependency @swc/core to v1.7.0 (#9637)chore(deps): update dependency husky to v9.1.1 (#9635)fix(eslint-plugin): [strict-boolean-expressions] support branded booleans (#9297)docs: add ast-spec, type-utils docs with docusaurus-plugin-typedoc (#9293)docs: remove unnecessary v8 links (#9611)fix(eslint-plugin): [no-duplicate-type-constituents] shouldn't report on error types (#9600)fix(eslint-plugin): [unbound-method] report on destructuring in function parameters (#8952)fix(eslint-plugin): [no-unnecessary-type-assertion] prevent runtime error when asserting a variable declared in default TS lib (#9660)chore: reorg repo level utils, lint and typecheck repo files (#9618)docs: final updates to v8 beta post (#9627)chore(website): remove incorrect `twitterHandle` from type (#9651)feat(types): update ECMA versions (#9634)test: add integration test against @types/eslint v9 (#9622)chore: enable radix (#9563)docs: update perfectionist domain (#9619)chore: fix integration tests by pinning @types/eslint v8 (#9620)
↗️ acorn (indirect, 7.4.1 → 8.14.0) · Repo
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ ansi-escapes (indirect, 4.3.2 → 6.2.1) · Repo
Release Notes
6.2.1
- Fix compatibility with TypeScript 5.4 3b1f99e
6.2.0
6.1.0
6.0.0
Breaking
- Require Node.js 14 96312e0
Improvements
- Update dependencies 96312e0
5.0.0
Breaking
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 13 commits:
6.2.1Fix compatibility with TypeScript 5.4Meta tweaksUpdate link to VT100 escape sequences site in the readme (#36)6.2.0Add escapes for entering/exiting the alternative screen (#33)6.1.0Support browser usage (#31)6.0.0Require Node.js 14 and update dependenciesUpdate `cursorTo` to use `SEP` constant (#28)5.0.0Require Node.js 12 and move to ESM
↗️ ansi-regex (indirect, 5.0.0 → 5.0.1) · Repo
Security Advisories 🚨
🚨 Inefficient Regular Expression Complexity in chalk/ansi-regex
ansi-regex is vulnerable to Inefficient Regular Expression Complexity which could lead to a denial of service when parsing invalid ANSI escape codes.
Proof of Concept
import ansiRegex from 'ansi-regex'; for(var i = 1; i <= 50000; i++) { var time = Date.now(); var attack_str = "\u001B["+";".repeat(i*10000); ansiRegex().test(attack_str) var time_cost = Date.now() - time; console.log("attack_str.length: " + attack_str.length + ": " + time_cost+" ms") }The ReDOS is mainly due to the sub-patterns
[[\\]()#;?]*and(?:;[-a-zA-Z\\d\\/#&.:=?%@~_]*)*
Release Notes
5.0.1
Fixes (backport of
6.0.1to v5)This is a backport of the minor ReDos vulnerability in
ansi-regex@<6.0.1, as requested in #38.
- Fix ReDoS in certain cases (#37)
You are only really affected if you run the regex on untrusted user input in a server context, which it's very unlikely anyone is doing, since this regex is mainly used in command-line tools.https://github.com/chalk/ansi-regex/compare/v5.0.0..v5.0.1
Thank you @yetingli for the patch and reproduction case!
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 5 commits:
↗️ argparse (indirect, 1.0.10 → 2.0.1) · Repo · Changelog
Release Notes
2.0.1 (from changelog)
Fixed
- Fix issue with
process.argvwhen used with interpreters (coffee,ts-node, etc.), #150.
2.0.0 (from changelog)
Changed
- Full rewrite. Now port from python 3.9.0 & more precise following. See doc for difference and migration info.
- node.js 10+ required
- Removed most of local docs in favour of original ones.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 15 commits:
2.0.1 releasedAlways assume process.argv[0] is interpreterAdd more migration docs2.0.0 releasedImplement argparse.js version 2.0Add 2.0 configs & docsDrop old sources (2.0 is full rewrite)Merge pull request #145 from lpinca/document/version-optionAdd documentation for the version optionreadme: update titelift infochangelog format updateAdd Tidelift link & fix headers formattingCreate FUNDING.ymlMerge pull request #129 from marcin-mazurek/patch-1Fix require statements in README examples
↗️ array-includes (indirect, 3.1.3 → 3.1.8) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 34 commits:
v3.1.8[Deps] update `call-bind`, `define-properties`, `es-abstract`, `get-intrinsic`[Refactor] use `es-object-atoms` where possible[Dev Deps] update `aud`, `npmignore`, `tape`[Tests] use `call-bind` instead of `function-bind`[actions] remove redundant finisherv3.1.7[Deps] update `define-properties`, `es-abstract`, `get-intrinsic`[Dev Deps] update `@es-shims/api`, `@ljharb/eslint-config`, `aud`, `tape`v3.1.6[meta] add `auto-changelog`[Deps] update `es-abstract`, `get-intrinsic`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `aud`, `tape`[actions] update rebase action to use reusable workflow[readme] note that FF 102+ no longer needs this packagev3.1.5[Fix] install polyfill on FF 99+[Deps] update `define-properties`, `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `functions-have-names`, `tape`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `safe-publish-latest`, `tape`[actions] update codecov uploaderv3.1.4[readme] add github actions/codecov badges[Robustness] avoid a runtime `Math.max` call[Deps] update `es-abstract`, `is-string`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `aud`, `tape`[actions] update workflows[readme] fix repo URLs; remove travis badge[Deps] update `es-abstract`[Dev Deps] update `eslint`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
⁉️ array-union (downgrade, 3.0.1 → 2.1.0) · Repo
Commits
See the full diff on Github. The new version differs by 18 commits:
2.1.0Add TypeScript definition (#6)2.0.0Require Node.js 8Require Node.js 6 and drop the dependency on array-uniq (#5)Add test to show two different homogeneous array are supported toobetter examples (#2)1.0.2meta tweaksUpdate .travis.yml1.0.1Merge pull request #1 from cthrax/masterUp version of array-uniq1.0.0tweaksminor tweak0.1.0init
↗️ array.prototype.flat (indirect, 1.2.4 → 1.3.2) · Repo · Changelog
Release Notes
1.3.2 (from changelog)
Commits
1.3.1 (from changelog)
Commits
1.3.0 (from changelog)
- [New]
shim/auto: addflattoSymbol.unscopables- [Deps] update
es-abstract- [actions] reuse common workflows
- [actions] update codecov uploader
- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,aud,auto-changelog,object-inspect,safe-publish-latest,tape
1.2.5 (from changelog)
- [readme] add github actions/codecov badges; remove travis badge
- [Deps] update
call-bind,es-abstract- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,aud,has-strict-mode,object-inspect,tape- [meta] use
prepublishOnly, for npm 7+- [actions] use
node/installinstead ofnode/run; usecodecovaction- [actions] update workflows
- [Tests] increase coverage
- [meta] fix changelog for v1.2.4
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 31 commits:
v1.3.2[Deps] update `define-properties`, `es-abstract`[Dev Deps] update `@es-shims/api`, `@ljharb/eslint-config`, `aud`, `object-inspect`, `tape`v1.3.1[meta] add `auto-changelog`[Deps] update `define-properties`, `es-abstract`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `aud`, `object-inspect`, `tape`[actions] update rebase action to use reusable workflowv1.3.0[New] `shim`/`auto`: add `flat` to `Symbol.unscopables`[Deps] update `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `object-inspect`, `tape`[actions] reuse common workflows[Deps] update `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploaderv1.2.5[readme] add github actions/codecov badges[Deps] update `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `aur`, `object-inspect`, `tape`[Tests] increase coverage[Deps] update `es-abstract`[Dev Deps] update `eslint`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly`, for npm 7+[readme] remove travis badge[Deps] update `call-bind`, `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `has-strict-mode`, `object-inspect`, `tape`[actions] update workflows[meta] fix changelog for v1.2.4
↗️ braces (indirect, 3.0.2 → 3.0.3) · Repo · Changelog
Security Advisories 🚨
🚨 Uncontrolled resource consumption in braces
The NPM package
bracesfails to limit the number of characters it can handle, which could lead to Memory Exhaustion. Inlib/parse.js,if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.
Commits
See the full diff on Github. The new version differs by 12 commits:
3.0.3update eslint. lint, fix unit tests.Snyk js braces 6838727 (#40)fix tests, skip 1 test in test/braces.expandreadme bumpMerge pull request #37 from coderaiser/fix/vulnerabilityfeature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/36#issuecomment-2110820796)fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)remove funding fileupdate keepEscaping doc (#27)Failing test cases for issue \#29 (#30)Create FUNDING.yml
↗️ browserslist (indirect, 4.16.7 → 4.24.2) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ builtin-modules (indirect, 3.2.0 → 3.3.0) · Repo
Commits
See the full diff on Github. The new version differs by 3 commits:
↗️ call-bind (indirect, 1.0.2 → 1.0.8) · Repo · Changelog
Release Notes
1.0.8 (from changelog)
Commits
- [Refactor] extract out some helpers and avoid get-intrinsic usage
407fd5e- [Refactor] replace code with extracted
call-bind-apply-helpers81018fb- [Tests] use
set-function-length/env0fc311d- [actions] split out node 10-20, and 20+
77a0cad- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,es-value-fixtures,gopd,object-inspect,tapea145d10- [Tests] replace
audwithnpm audit30ca3dd- [Deps] update
set-function-length57c79a3- [Dev Deps] add missing peer dep
601cfa5
1.0.7 (from changelog)
Commits
1.0.6 (from changelog)
Commits
1.0.5 (from changelog)
Commits
1.0.3 (from changelog)
Commits
- [actions] reuse common workflows
a994df6- [meta] use
npmignoreto autogenerate an npmignore fileeef3ef2- [readme] flesh out content
1845ccf- [actions] use
node/installinstead ofnode/run; usecodecovaction5b47d53- [Refactor] use
set-function-lengtha0e165c- [Dev Deps] update
@ljharb/eslint-config,aud,tape9c50103- [meta] simplify "exports"
019c6d0- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,safe-publish-latest,tape23bd718- [actions] update codecov uploader
62552d7- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,tapeec81665- [Dev Deps] update
eslint,@ljharb/eslint-config,safe-publish-latest,tape35d67fc- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,tape0266d8d- [Dev Deps] update
@ljharb/eslint-config,aud,tape43a5b28- [Deps] update
define-data-property,function-bind,get-intrinsic780eb36- [Dev Deps] update
aud,tape90d50ad- [meta] use
prepublishOnlyscript for npm 7+44c5433- [Deps] update
get-intrinsic86bfbfc- [Deps] update
get-intrinsic5c53354- [actions] update checkout action
4c393a8- [Deps] update
get-intrinsic4e70bde- [Deps] update
get-intrinsic55ae803
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 43 commits:
v1.0.8[Refactor] replace code with extracted `call-bind-apply-helpers`[Tests] use `set-function-length/env`[Refactor] extract out some helpers and avoid get-intrinsic usage[Deps] update `set-function-length`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `es-value-fixtures`, `gopd`, `object-inspect`, `tape`[Tests] replace `aud` with `npm audit`[actions] split out node 10-20, and 20+v1.0.7[Refactor] use `es-define-property`[Deps] update `get-intrinsic`, `set-function-length`v1.0.6[Refactor] use `es-errors`, so things that only need those do not need `get-intrinsic`[meta] add missing `engines.node`[Deps] update `get-intrinsic`, `set-function-length`[Dev Deps] update `aud`, `npmignore`, `tape`v1.0.5[Deps] update `set-function-length`[Fix] throw an error on non-functions as early as possiblev1.0.4v1.0.3[Refactor] use `set-function-length`[Deps] update `define-data-property`, `function-bind`, `get-intrinsic`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[Deps] update `get-intrinsic`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[Deps] update `get-intrinsic`[Dev Deps] update `aud`, `tape`[actions] update checkout action[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[Deps] update `get-intrinsic`[actions] reuse common workflows[meta] simplify "exports"[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[readme] flesh out content[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `safe-publish-latest`, `tape`[actions] update codecov uploader[Deps] update `get-intrinsic`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
↗️ caniuse-lite (indirect, 1.0.30001249 → 1.0.30001687) · Repo · Changelog
↗️ ci-info (indirect, 3.2.0 → 4.1.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ confusing-browser-globals (indirect, 1.0.10 → 1.0.11) · Repo · Changelog
Release Notes
1.0.11
1.0.11 (2017-08-09)
🐛 Bug Fix
create-react-app
#2884 Improve offline heuristic for proxied environments. (@bsyk)
When a Yarn proxy is set, we will check its connectivity if we cannot reach Yarn's registry. This is often the case when DNS lookups must be made through the proxy.
#2853 Allow use of scoped packages with a pinned version. (@wileybenet)
react-dev-utils
react-dev-utils,react-scripts
react-scripts
- #2806 Fix SockJS version compatibility. (@christianbundy)
- #2738 Fix Jest
nodefile resolution. (@mostafah)
💅 Enhancement
react-scripts
#2818 Allow sourcemaps to be disabled. (@viankakrisna)
As applications grow more complex, it is possible webpack may run out of memory while generating source maps. They may now be disabled by setting
GENERATE_SOURCEMAP=false.#2913 Allow flags to be passed to node when running
react-scripts. (@koistya)#2747 Simplify webpack configuration using
Rule.oneOf. (@Furizaa)react-dev-utils,react-scripts
- #2468 Allow importing
package.json. (@iamdoron)- #2650 Make UglifyJS error friendlier. (@viankakrisna)
create-react-app
- #2785 Change error wording and list conflicting files when initializing app. (@OwenFlood)
react-dev-utilseslint-config-react-app,react-scripts
- #2735 Upgrade to
eslint@4. (@trungdq88)eslint-config-react-app
- #2701 Set
allowTaggedTemplatesto true (eslint). (@denkristoffer)
📝 Documentation
- Other
- #2728 Add Electrode to alternatives. (@animesh10)
- #2788 Update link for motion. (@viankakrisna)
- #2697 Fix env list ordering. (@alexeyraspopov)
react-dev-utils
- #2798 Update note about
webpackHotDevClientsupport. (@ForbesLindesay)react-scriptsbabel-preset-react-app
- #2732 Update link to issue blocking JSX hoisting. (@ForbesLindesay)
🏠 Internal
create-react-app,eslint-config-react-app,react-dev-utils,react-error-overlay,react-scriptseslint-config-react-app
- #2718 Re-enable flowtype warning. (@oskarkook)
- Other
react-scripts
- #2873 Use template strings. (@monkindey)
Committers: 26
- 864907600cc (ccloli)
- Ade Viankakrisna Fadlil (viankakrisna)
- Alexey Raspopov (alexeyraspopov)
- Andreas Hoffmann (Furizaa)
- Animesh Dutta (animesh10)
- Ben Sykes (bsyk)
- Christian Bundy (christianbundy)
- Dan Abramov (gaearon)
- Dan Ristea (danrr)
- Danny Ho (hodanny)
- Forbes Lindesay (ForbesLindesay)
- Joe Haddad (Timer)
- Jon Crenshaw (jdcrensh)
- Kiho · Cham (monkindey)
- Konstantin Tarkus (koistya)
- Kristoffer (denkristoffer)
- Mostafa Hajizadeh (mostafah)
- Oskar Köök (oskarkook)
- Owen Flood (OwenFlood)
- Stéphane Goetz (onigoetz)
- Trygve Aaberge (trygveaa)
- Wiley Bennett (wileybenet)
- iamdoron
- themre
- zeel (zeel)
- Đinh Quang Trung (trungdq88)
Migrating from 1.0.10 to 1.0.11
Inside any created project that has not been ejected, run:
npm install --save --save-exact react-scripts@1.0.11or
yarn add --exact react-scripts@1.0.11
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 39 commits:
PublishPrepare for 1.0.11 release (#2924)Update dev deps (#2923)Update README.mdUse env variable to disable source maps (#2818)Make formatWebpackMessages return all messages (#2834)Adjust the `checkIfOnline` check if in a corporate proxy environment (#2884)Fix the order of arguments in spawned child proc (#2913)Feature/webpack 3 4 (#2875)Allow importing package.json (#2468)Re-enable flowtype warning (#2718)Format UglifyJs error (#2650)Unstage yarn.lock pre-commit (#2700)Update README.mdUpdate README.mdAdd Electrode to alternatives (#2728)Fix parsing HTML/JSX tags to real elements (#2796)Update webpack version note (#2798)Use modern syntax feature (#2873)Allow use of scoped packages with a pinned version (#2853)Bump Webpack 3.4 (#2850)Feature/webpack3 (#2574)Add explicit "Opting Out of Caching" header (#2822)Upgrade webpack-dev-server (#2806)Update link for motion (#2788)List conflicting files when initializing app (#2785)Moved npm run build before npm test (#2725)Docs for react-router v4 basename feature (#2668)Don't prompt to install serve if already installed (#2761)Autodetect JetBrains IDEs (#2754)Use Rule.oneOf to resolve correct loader (#2747)ESLint 4 (#2735)Add "node" to Jest's moduleFileExtensions (#2738)Support PyCharm in launchEditor (#2740)Update link to issue blocking JSX hoisting (#2732)Reorder vim arguments in launchEditor so --remote works (#2723)Remove Windows note for source-map-explorer (#2719)allowTaggedTemplates to avoid warnings from SC's (#2701)Issue template: fix env list ordering (#2697)
↗️ cosmiconfig (indirect, 7.0.0 → 9.0.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ deep-is (indirect, 0.1.3 → 0.1.4) · Repo
Commits
See the full diff on Github. The new version differs by 3 commits:
↗️ define-properties (indirect, 1.1.3 → 1.2.1) · Repo · Changelog
Release Notes
1.2.1 (from changelog)
Commits
1.2.0 (from changelog)
Commits
- [New] if the predicate is boolean
true, it compares the existing value with===as the predicated8dd6fc- [meta] add
auto-changelog7ebe2b0- [meta] use
npmignoreto autogenerate an npmignore file647478a- [Dev Deps] update
@ljharb/eslint-config,aud,tapee620d70- [Dev Deps] update
aud,tapef1e5072- [actions] update checkout action
628b3af
1.1.4 (from changelog)
- [Refactor] use
has-property-descriptors- [readme] add github actions/codecov badges
- [Docs] fix header parsing; remove testling
- [Deps] update
object-keys- [meta] use
prepublishOnlyscript for npm 7+- [meta] add
fundingfield; create FUNDING.yml- [actions] add "Allow Edits" workflow; automatic rebasing / merge commit blocking
- [actions] reuse common workflows
- [actions] update codecov uploader
- [actions] use
node/installinstead ofnode/run; usecodecovaction- [Tests] migrate tests to Github Actions
- [Tests] run
nycon all tests; usetaperunner- [Tests] use shared travis-ci config
- [Tests] use
npx audinstead ofnspornpm auditwith hoops- [Tests] remove
jscs- [Dev Deps] update
eslint,@ljharb/eslint-config,safe-publish-latest,tape; addaud,safe-publish-latest
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 43 commits:
v1.2.1[actions] use reusable rebase action[Refactor] use `define-data-property`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`v1.2.0[New] if the predicate is boolean `true`, it compares the existing value with `===` as the predicate[meta] add `auto-changelog`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[Dev Deps] update `aud`, `tape`[actions] update checkout actionv1.1.4[Refactor] use `has-property-descriptors`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[readme] add github actions/codecov badges[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `safe-publish-latest`, `tape`[actions] update codecov uploader[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[Tests] migrate tests to Github Actions[Tests] run `nyc` on all tests; use `tape` runner[meta] add "Allow Edits" workflow; update rebase workflow[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`; add `aud`[actions] switch Automatic Rebase workflow to `pull_request_target` event[actions] add automatic rebasing / merge commit blocking[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`, `safe-publish-latest`[Docs] fix header parsing; remove testling[Dev Deps] update `eslint`, `@ljharb/eslint-config`[Tests] use shared travis-ci config[meta] add `funding` field[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`; add `safe-publish-latest`[Deps] update `object-keys`[Tests] up to `node` `v12.10`, `v11.15`, `v10.16`, `v8.16`, `v6.17`[Tests] use `npx aud` instead of `nsp` or `npm audit` with hoops[meta] create FUNDING.yml[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `covert`, `tape`[Tests] up to `node` `v11.7`, `v10.15`, `v8.15`, `v6.16`[Tests] use `npm audit` instead of `nsp`[Tests] remove `jscs`
↗️ electron-to-chromium (indirect, 1.3.799 → 1.5.71) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 2 commits:
↗️ emoji-regex (indirect, 8.0.0 → 10.4.0) · Repo
Commits
See the full diff on Github. The new version differs by 46 commits:
Release v10.4.0Update to draft release of Unicode v16.0.0Cross-link emoji-regex-xs (#113)Release v10.3.0feat: update emoji-test-regex-pattern dependency to v2.1.0 (#109)Release v10.2.1Include index.mjs in package.json#files (#101)Align coding styleRelease v10.2.0Update dependenciesAdd JavaScript module support (#99)Release v10.1.0Update dependencies to reduce bundle sizeRelease v10.0.1Re-generate outputUpdate emoji-test-regex-pattern to v1.7.2 (#98)Fix typoRun checks against PRsAdd npm version badgeRelease v10.0.0Refactor using emoji-test-regex-patternRemove .npmrcRelease v9.2.2Add *.d.ts to .editorconfigFix type definitionsStop outputting the pattern as a text fileRemove redundant commandUpdate branch name in Travis CI badgeUpdate branch nameRelease v9.2.1Add support for Emoji 13.1 sequences (#84)Produce a text file containing only the generated pattern (#82)Release v9.2.0Add RGI_Emoji output (#75)Update maintainer instructionsRelease v9.1.1Limit NPM_TOKEN dependency to `publish` command (#74)Release v9.1.0Automate `npm publish` for new tags (#73)Document how to update emoji-regex after Unicode Standard releases (#72)Provide correct export types for CJS module (#63)Future-proof build script + tests (#71)Test on Node.js v12Release v9.0.0Update to Unicode v13.0.0Update dependencies
↗️ env-editor (indirect, 0.4.2 → 1.1.0) · Repo
Commits
See the full diff on Github. The new version differs by 6 commits:
↗️ es-abstract (indirect, 1.18.5 → 1.23.5) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ es-module-lexer (indirect, 0.7.1 → 1.5.4) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ es-to-primitive (indirect, 1.2.1 → 1.3.0) · Repo · Changelog
Release Notes
1.3.0 (from changelog)
Commits
- [actions] reuse common workflows
bb72efc- [Tests] use
es-value-fixturesa912f7b- [Tests] migrate tests to Github Actions
510baf0- [New] add types
69ba1fd- [meta] remove unused Makefile
4ea66e6- [actions] use
node/installinstead ofnode/run; usecodecovaction3c31937- [meta] do not publish github action workflow files
389567e- [meta] use
npmignoreto autogenerate an npmignore file9f3aa76- [actions] split out node 10-20, and 20+
c60d7d8- [Tests] run
nycon all tests; usetaperunner29cbb89- [meta] add
auto-changelogea744b2- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,function.prototype.name,has-symbols,object-inspect,object-is,tapee5c3c79- [actions] add automatic rebasing / merge commit blocking
a5a6f00- [Dev Deps] update
@ljharb/eslint-config,es-value-fixtures,function.prototype.name,npmignore,object-inspect,object-is,tape7941fd5- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,es-value-fixtures,foreach,object-inspect,tapeeb1c79c- [Dev Deps] update
eslint,@ljharb/eslint-config,function.prototype.name,object-inspect,safe-publish-latest,tape249b42f- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,function.prototype.name,object-inspect,object-is,taped57d5e9- [actions] update codecov uploader
003b62c- [actions] add "Allow Edits" workflow
75ee990- [Dev Deps] update
eslint,@ljharb/eslint-config,tape,object-is; addsafe-publish-latestba5da7b- [readme] remove travis badge
6f7aec7- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,object-inspect,tape3291fd5- [Dev Deps] update
eslint,@ljharb/eslint-config,function.prototype.name,has-symbols,object-inspect53007f2- [actions] update checkout action
69640db- [Dev Deps] update
eslint,@ljharb/eslint-config,object-is,tape; addaudc9d644e- [Tests] use
for-eachinstead offoreache9117bb- [readme] add github actions/codecov badges
53cd375- [Deps] update
is-callable,is-date-object,is-symbol8116c68- [Tests] fix test skipping for
Symbol.toPrimitivee6268ef- [actions] switch Automatic Rebase workflow to
pull_request_targeteventda41c40- [Deps] update
is-callable,is-date-object96fe13f- [Tests] replace
audwithnpm audit0b53154- [meta] use
prepublishOnlyscript for npm 7+9d7d485- [Deps] update
is-callable3c990b6- [Deps] update
is-callable9bcfff2- [Deps] update
is-callable1eb5478- [meta] only run
audon prod deps1fcd896- [Deps] update
is-symbol7174a47
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 39 commits:
v1.3.0[meta] add `auto-changelog`[New] add types[Tests] fix test skipping for `Symbol.toPrimitive`[actions] split out node 10-20, and 20+[Deps] update `is-callable`[Dev Deps] update `@ljharb/eslint-config`, `es-value-fixtures`, `function.prototype.name`, `npmignore`, `object-inspect`, `object-is`, `tape`[Tests] replace `aud` with `npm audit`[Tests] use `for-each` instead of `foreach`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `es-value-fixtures`, `foreach`, `object-inspect`, `tape`[actions] update checkout action[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `function.prototype.name`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploader[meta] do not publish github action workflow files[Tests] use `es-value-fixtures`[readme] add github actions/codecov badges[Deps] update `is-callable`, `is-date-object`, `is-symbol`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `object-inspect`, `tape`[Deps] update `is-callable`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `function.prototype.name`, `has-symbols`, `object-inspect`, `object-is`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+[Deps] update `is-callable`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `function.prototype.name`, `object-inspect`, `object-is`, `tape`[readme] remove travis badge[Tests] migrate tests to Github Actions[Tests] run `nyc` on all tests; use `tape` runner[actions] add "Allow Edits" workflow[actions] switch Automatic Rebase workflow to `pull_request_target` event[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `object-is`, `tape`; add `aud`[meta] only run `aud` on prod deps[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`, `object-is`; add `safe-publish-latest`[Deps] update `is-callable`, `is-date-object`[Deps] update `is-symbol`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `function.prototype.name`, `has-symbols`, `object-inspect`[meta] remove unused Makefile[actions] add automatic rebasing / merge commit blocking
↗️ escalade (indirect, 3.1.1 → 3.2.0) · Repo
Release Notes
3.2.0
Patches
- Declare separate ESM and CommonJS TypeScript definitions: a72e1c3
Previously, only ESM definitions were shipped but were exported in a way that could cause tool/resolution ambiguity.Chores
- Update Node.js version matrix in CI suite: a8c6820
Full Changelog: v3.1.2...v3.2.0
3.1.2
Patches
- Support TypeScript’s
nodenextmodule resolution mode (#10): d872fbdThank you @NMinhNguyen
Chores
- Add
licenses.devbadge to README: 02dcb8b- Update CI matrix versions: 3c916b2
Full Changelog: v3.1.1...v3.1.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ eslint (indirect, 7.32.0 → 8.57.1) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ eslint-config-xo (indirect, 0.38.0 → 0.45.0) · Repo
Release Notes
0.45.0
0.44.0
Breaking
- Require Node.js 18 f2060de
New rules
logical-assignment-operators27049c1prefer-object-has-own288a3caobject-curly-newline(#83) 3a5448bImprovements
0.43.1
- Disable
logical-assignment-operatorsrule until we target Node.js 16 ffb7d6e
0.42.0
0.41.0
- Add
no-constant-binary-expressionrule af63ee6- Enforce single-quotes for JSX (#78) 0a302bd
0.40.0
Breaking
- Require ESLint 8 and Node.js 12 da1fd09
Improvements
0.39.0
- Use
'latest'forecmaVersion66bc17e- Add
no-bitwiserule 9d9eae9
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 38 commits:
0.45.0Allow class fields with no blank lines between (#85)0.44.0Require Node.js 18Enable `logical-assignment-operators` ruleEnable `prefer-object-has-own` ruleBan `atob` and `btoa``no-unused-vars`: Allow ignoring variables by prefixing with underscoreMeta tweaksAdd `object-curly-newline` rule (#83)Ban `Buffer` in favor of `Uint8Array`Replace deprecated `no-new-object` rule0.43.1Disable `logical-assignment-operators` rule until we target Node.js 160.43.0Add `no-empty-static-block` ruleAdd `no-new-native-nonconstructor` rule`prefer-regex-literals`: Set `disallowRedundantWrapping` option (#80)Add `logical-assignment-operators` rule0.42.0Allow lower case type-coverage comments (#79)Meta tweaks0.41.0Add `no-constant-binary-expression` ruleEnforce single-quotes for JSX (#78)0.40.0Remove `default-param-last` ruleFix testsAvoid explicit return arrows in `object-shorthand` rule (#76)Add linting (#77)Require ESLint 8 and Node.js 12Add `prefer-object-has-own` ruleDrop outdated ES2015 mention from readme (#75)Add no-issue issue template (#74)0.39.0Use `'latest'` for `ecmaVersion`Add `no-bitwise` ruleRemove out-of-date note about config overrides (#71)
↗️ eslint-config-xo-typescript (indirect, 0.44.0 → 5.0.0) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ eslint-formatter-pretty (indirect, 4.1.0 → 6.0.1) · Repo
Release Notes
6.0.1
6.0.0
Breaking
- Require Node.js 18 13383af
5.0.0
Breaking
- Require Node.js 14 ee9a212
Improvements
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 11 commits:
↗️ eslint-import-resolver-node (indirect, 0.3.5 → 0.3.9) · Repo · Changelog
↗️ eslint-import-resolver-webpack (indirect, 0.13.1 → 0.13.9) · Repo · Changelog
↗️ eslint-module-utils (indirect, 2.6.2 → 2.12.0) · Repo · Changelog
Release Notes
2.12.0 (from changelog)
Added
- Ignore type imports for
namedrule (#931, thanks @mattijsbliek)- Add documentation for
no-useless-path-segmentsrule (#1068, thanks @manovotny)packageDiroption forno-extraneous-dependenciescan be array-valued (#1085, thanks @hulkish)
2.11.0 (from changelog)
Added
- Fixer for
first(#1046, thanks @fengkfengk)allow-requireoption forno-commonjsrule (#880, thanks @futpib)Fixed
- memory/CPU regression where ASTs were held in memory (#1058, thanks @klimashkin/@lukeapage)
2.10.0 (from changelog)
Added
2.9.0 (from changelog)
Added
- Add
group-exportsrule: style-guide rule to report use of multiple named exports (#721, thanks @robertrossmann)- Add
no-self-importrule: forbids a module from importing itself. (#727, #449, #447, thanks @giodamelio).- Add
no-default-exportrule (#889, thanks @isiahmeadows)- Add
no-useless-path-segmentsrule (#912, thanks @graingert and @danny-andrews)- ... and more! check the commits for v2.9.0
2.8.0 (from changelog)
Added
exports-lastrule (#620 + #632, thanks @k15a)Changed
Fixed
- support scoped modules containing hyphens (#744, thanks @rosswarren)
- core-modules now resolves files inside declared modules (#886 / #891, thanks @mplewis)
- TypeError for missing AST fields from TypeScript (#842 / #944, thanks @alexgorbatchev)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 15 commits:
changelog/package bumpsexclude tests from coverage + bump TS parser (#1095)webpack resolver: cache instance(s) of resolve function (#1091)Merge pull request #1085 from benmosher/packageDir-arrayrevert `has` removal per @ljharb's note[Refactor] use "has" instead of ".hasOwnProperty"Fix typo: 'runtime'fix typoMerge branch 'master' into packageDir-arraymerge import/paths setting into existing packageDir optionchangelog linksMerge pull request #1081 from benmosher/releaseMerge branch 'master' into releaseIgnore type imports for named rule. (#1057)memo-parser cautionary note
↗️ eslint-plugin-ava (indirect, 12.0.0 → 14.0.0) · Repo
Release Notes
14.0.0
Breaking
- Require Node.js 14 and ESLint 8 bd8c4c6
Fixes
13.2.0
What's Changed
Full Changelog: v13.1.0...v13.2.0
13.1.0
Full Changelog: v13.0.0...v13.1.0
13.0.0
This release contains changes for compatibility with AVA 4, but can still be used with AVA 3 projects. Note however that
test.cb()is being removed in AVA 4 and is no longer covered by this plugin.
- Support the
defaultmodifier in AVA 4 64cc8c6- Match AVA 4 supported Node.js versions (^12.22, ^14.17, ^16.4) 98f7613
- Remove callback-test related rules, this is being removed in AVA 4 2f8a226
- Support
test.macro(), new in AVA 4 abc162fOther changes:
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 29 commits:
14.0.0`prefer-t-regex`: Prevent some type errors (#350)Update to eslint-doc-generator v1 (#349)Automate docs with eslint-doc-generator (#348)Require Node.js 14 and ESLint 813.2.0`use-test`: Ignore type importEnforce strict mode (#341)Fix integration test (#340)Update XO (#339)13.1.0Support ESLint 8.xUse `latest` as `ecmaVersion`Add another test for `prefer-t-regex` (#334)Update actions (#337)13.0.0Try and fail to upgrade the integration testsUpgrade XOFix fixable flag of rules/no-incorrect-deep-equalSupport the default modifierMatch AVA 4 supported Node.js versionsUpdate (some) dev dependenciesUpdate dependenciesDisable import/extensionsRemove callback-test related rulesSupport test.macro()Fix no-identical-title when there is no titleSimplify use-t to only check the first parameterMinor docs tweaks
↗️ eslint-plugin-import (indirect, 2.24.0 → 2.31.0) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ eslint-plugin-promise (indirect, 5.1.0 → 6.6.0) · Repo · Changelog
Release Notes
6.6.0
6.6.0 (2024-07-21)
Bug Fixes
Features
6.5.1
6.5.1 (2024-07-20)
Bug Fixes
6.5.0
6.5.0 (2024-07-19)
Features
6.4.0
6.4.0 (2024-07-01)
Features
6.2.0
6.2.0 (2024-05-27)
Bug Fixes
Features
6.1.1
6.1.1 (2022-10-19)
Bug Fixes
6.1.0
6.1.0 (2022-10-13)
Bug Fixes
- always-return: false positives for logical expr (#363) (a60d1cb)
- CI: fix release script (#380) (71e53a0)
- minor typos (#359) (b431e46)
- no-nesting: nested references vars in closure (#361) (08052e8)
- update repo link (#349) (3906810)
Features
- add
no-multiple-resolvedrule (#369) (3a6fdbe)- always-return: add
ignoreLastCallbackoption (#365) (01def31)- catch-or-return,no-new-statics,no-promise-in-callback,valid-params: add support for
Promise.allSettled()&Promise.any()(#370) (e080f82)- param-names: add
resolvePattern&rejectPatternoption (#368) (df25e3c)
6.0.0 (from changelog)
5.2.0 (from changelog)
- Updated
param-namesrule to allow for unused params
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ eslint-plugin-unicorn (indirect, 35.0.0 → 56.0.1) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ eslint-rule-docs (indirect, 1.1.231 → 1.1.235) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ eslint-scope (indirect, 5.1.1 → 7.2.2) · Repo · Changelog
Release Notes
7.2.2
7.2.2 (2023-07-27)
Chores
7.2.1
7.2.1 (2023-05-31)
Chores
7.2.0
Features
Documentation
Build Related
Chores
7.1.1
Bug Fixes
Chores
7.1.0
Features
7.0.0
Breaking Changes
Build Related
6.0.0
4ee1d80Fix: Ensure correct version in package (#73) (Nicholas C. Zakas)82a7e6dBreaking: Switch to ESM (fixes #70) (#71) (Brett Zamir)0b4a5f1Update: support class fields (refs eslint/eslint#14343) (#69) (Toru Nagashima)39f8cfcChore: upgrade estraverse to version 5 (#68) (Rouven Weßling)ae27ff3Docs: Add range to espree options in README (fixes #66) (#67) (Alan Liang)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 36 commits:
chore: release 7.2.2 (#103)chore: Add PRs to triage (#104)ci: generate provenance statements when release (#102)chore: release 7.2.1 (#100)chore: set up release-please (#99)ci: run tests on Node.js v20 (#97)7.2.0Build: changelog update for 7.2.0feat: Add isGlobalReturn method on scopeManager. (#96)chore: add triage action (#95)ci: add Node v19 (#94)ci: update Github actions (#93)chore: add funding field (#92)build: add node v18 (#91)docs: add badges (#89)7.1.1Build: changelog update for 7.1.1chore: upgrade espree@9.3.1 eslint-visitor-keys@3.3.0 (#88)fix: ignore `"use strict"` directives in ES3 (#87)ci: use node v16 (#84)test: add tests with year-based `ecmaVersion` (#83)7.1.0Build: changelog update for 7.1.0feat: Add sourceType:commonjs support (#81)7.0.0Build: changelog update for 7.0.0feat!: support class static blocks (#80)build: upgrade eslint-release to v3.2.0 to support conventional commits (#79)Build: add node v17 (#76)6.0.0Build: changelog update for 6.0.0Fix: Ensure correct version in package (#73)Breaking: Switch to ESM (fixes #70) (#71)Update: support class fields (refs eslint/eslint#14343) (#69)Chore: upgrade estraverse to version 5 (#68)Docs: Add range to espree options in README (fixes #66) (#67)
↗️ eslint-utils (indirect, 2.1.0 → 3.0.0) · Repo
Release Notes
3.0.0
💥 Breaking Changes
- 9a5c4fb, 5361c33 dropped old Node.js support. The new range is
^10.0.0 || ^12.0.0 || >= 14.0.0.- 5361c33 added the
exportsfield topackage.json. Now direct accesses to internal files are disallowed.- c5574ce, 46771e1 changed the result of
getFunctionNameWithKind(node)function in some cases.
- Functions at method places prefer the method name than function's id. E.g.,
{ foo: function bar() {} }ismethod 'foo'.- Arrow functions at method places are now methods. E.g.,
{ foo: () => {} }ismethod 'foo'.- Function expressions at variable initializers or the RHS of assignments are named. E.g.
foo = function() {}isfunction 'foo'.
✨ Enhancements
- 05b8390 supports the new class features of ES2022: public class fields, private class members, and static of them.
- 46771e1 added the optional second parameter to
getFunctionNameWithKind(node). If you givecontext.getSourceCode()to that, thegetFunctionNameWithKind(node, sourceCode)function handles the name of computed properties. E.g.,{ [foo]() {} }ismethod [foo].
🐛 Bug fixes
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 15 commits:
🔖 3.0.0🎨 use prettier💥 add exports field to package.json✅ fix tests⚒ update espree of tests✅ add tests for reference tracker🐛 fix for literal property names⚒ remove CLIEngine from tests✨ improve 'getFunctionNameWithKind'✨ supports for ES2022 class features (#20)🎨 simplify token predicates (#19)🐛 fix `isParenthesized()` check on `CatchClause.param` (#16)✨ Give `FunctionExpression` names if possible (#14)🐛 #12 by not resolving static value of `Symbol()` (#13)💥 drop old Node.js versions (#7)
↗️ eslint-visitor-keys (indirect, 2.1.0 → 3.4.3) · Repo · Changelog
Release Notes
3.4.3
3.4.3 (2023-08-08)
Chores
3.4.2
3.4.2 (2023-07-27)
Documentation
Chores
3.4.1
3.4.1 (2023-05-05)
Bug Fixes
Chores
3.4.0
Features
Bug Fixes
Documentation
Build Related
Chores
3.3.0
Features
3.2.0
Features
Documentation
3.1.0
Enhancements
Documentation
Build Related
5e3e687build: upgrade eslint-release to v3.2.0 to support conventional commits (#31) (Milos Djermanovic)53d3939Build: add node v17 (#30) (唯然)Chores
e89bff9Chore: use actions/setup-node@v2 (薛定谔的猫)
3.0.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 42 commits:
chore: release 3.4.3 (#57)chore: Add back add-to-triage (#59)chore: standardize npm script names (#55)chore: update `typedef` in build keys template (#58)chore: Remove add-to-triage (#56)chore: release 3.4.2 (#51)chore: Add PRs to triage (#54)ci: generate provenance statements when release (#53)docs: remove `release` script reference from README (#52)docs: fix spelling mistakes (#50)chore: release 3.4.1 (#49)chore: set up release-please (#48)fix: correct types for node16 resolution (#47)ci: run tests on Node.js v20 (#45)3.4.0Build: changelog update for 3.4.0fix: remove useless sourcemap url (fixes #43) (#44)chore: add triage action (#42)ci: add Node v19 (#41)chore: update github actions and add funding field (#40)build: add node v18 (#39)feat: add `JSXSpreadChild` and tool to build keys out of AST definitions (#36)docs: update badges (#37)3.3.0Build: changelog update for 3.3.0feat: Bundle JSDoc-built TypeScript declaration file (#34)3.2.0Build: changelog update for 3.2.0feat: add missing JSXOpeningFragment and JSXClosingFragment (#33)docs: readme add syntax highlighting (#32)3.1.0Build: changelog update for 3.1.0build: upgrade eslint-release to v3.2.0 to support conventional commits (#31)Build: add node v17 (#30)Update: add StaticBlock (#29)Chore: use actions/setup-node@v2Docs: Update the minimum Node.js version requirement (#26)v3.0.0Breaking: drop node v10/v13/v15 (refs eslint/eslint#14023) (#23)Breaking: Switch to ESM (#24)Build: Update branch reference in CI (#25)Upgrade: eslint-release (#21)
↗️ espree (indirect, 7.3.1 → 9.6.1) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ esquery (indirect, 1.4.0 → 1.6.0) · Repo
Commits
See the full diff on Github. The new version differs by 26 commits:
Version 1.6.0allow naked binaryOp at the start of a selector within :has() (#145)pull lowercasing out of class matcher (#141)Version 1.5.0External class resolve (#140)Allow for custom node type keys (#139)Version 1.4.2Check that the node has a parent before matching a 'child' selector (#138)Version 1.4.1pin some dev dependencies that seem to have made breaking changesadd node 18 to the test matrixdrop node 6 from test matrixcombine the from-start and from-end paths in nthChildseparate the caching wrapper from the matcher generatorStyle fix: ++k instead of k++Cache selector matcher functions in a WeakMapAllow negative `nth` parameter in nthChildFix code style issuesCreate fewer intermediate objects in inPathTraverse only once & break early in "has" selectorReplace 'has' rule collector array with a boolean flagAvoid .indexOf in nthChildUse basic for loops instead of for-ofCreate even more specific attribute matchersHoist repeatedly recreated constantsCreate cached matcher functions for selectors
↗️ estraverse (indirect, 4.3.0 → 5.3.0) · Repo
Commits
See the full diff on Github. The new version differs by 9 commits:
↗️ execa (indirect, 5.1.1 → 9.5.1) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ fast-glob (indirect, 3.2.7 → 3.3.2) · Repo
Release Notes
3.3.2
Full Changelog: 3.3.1...3.3.2
🐛 Bug fixes
3.3.1
Full Changelog: 3.3.0...3.3.1
This release fixes a regression for cases where the
ignoreoption is used with a string (#403, #404).The public interface of this package does not support a string as the value for the
ignoreoption since 2018 year (release).So, in the next major release, we will reintroduce method implementations that do not involve strings in the
ignoreoption.
3.3.0
Full Changelog: 3.2.12...3.3.0
🚀 ImprovementsMethod aliases
New methods (
glob,globSync,globStream) have been added in addition to the current methods (default import,sync,stream), which eliminate the need to rename the method when importing. In addition, anasyncalias has been added for the default import, which makes it possible to use this packet with ESM.Method to convert paths to globs
A new method (
convertPathToPattern) has been added in this release to convert a path to a pattern. The primary goal is to enable users to avoid processing Windows paths in each location where this package is used by utilities from third-party packages.See more details in the pull request.
🐛 Bug fixes
- In the past, we mishandled patterns that contained slashes when the
baseNameMatchoption was enabled, which went against the documented behavior. (#312)- Several problems with matching patterns that contain brace expansion have been resolved. The primary issue solved is when the pattern has duplicate slashes after it is expanded (#394), or the
micromatchpackage does not correctly generate a regular expression (#365).- All negative patterns will now have the
dotoption enabled when matching paths. Previously, the!**/*patterns did not exclude hidden files (start with a dot). (#343)- The issue that led to duplicates in the results when overlapping or duplicate patterns were present among the patterns has been fixed. At the moment, we are only talking about leading dot. Other cases are not included. For example, running with the patterns
['./file.md', 'file.md', '*']will now only includefile.mdonce in the results. (#190)
📖 DocumentationA clarifying note has been added for the
concurrencyoption, which provides more detailed information about the Thread Pool utilization.
⚙️ Infrastructure
- The benchmark in CI is now running on Node.js 20.
- The benchmark now uses the public package bencho instead of an in-house implementation. You may want to try this solution for your packages and provide feedback.
🥇 New Contributors
- @josh-hemphill made their first contribution in #383
- @mairaw made their first contribution in #401
3.2.12
Full Changelog: 3.2.11...3.2.12
🐛 Bug fixesFixed an issue introduced in
3.2.7related to incorrect application of patterns to entries with a trailing slash when the entry is not a directory.Before changes:
fg.sync('**/!(*.md)') // ['file.md', 'a/file.md', 'a/file.txt']After fix:
fg.sync('**/!(*.md)') // ['a/file.txt']Thanks @AgentEnder for the issue (#357).
🚀 ImprovementsThis release includes performance improvements for the asynchronous method. For this method we now use an asynchronous directory traversal interface instead of using a streaming interface. This gives up to 15% acceleration for medium and large directories. The result depends a lot on hardware.
You can find the benchmark results for this release in CI here.
Here are a few of measurements on my laptop:
===> Benchmark pattern "*" with 100 launches (regression, async) ===> Max stdev: 7 | Retries: 3 | Options: {} Name Time, ms Time stdev, % Memory, MB Memory stdev, % Entries Errors Retries --------------------- -------- ------------- ---------- --------------- ------- ------ ------- fast-glob-current.js 4.390 0.252 6.253 0.015 4 0 1 fast-glob-previous.js 5.653 0.633 6.051 0.056 4 0 1 ===> Benchmark pattern "**" with 100 launches (regression, async) ===> Max stdev: 7 | Retries: 3 | Options: {} Name Time, ms Time stdev, % Memory, MB Memory stdev, % Entries Errors Retries --------------------- -------- ------------- ---------- --------------- ------- ------ ------- fast-glob-current.js 34.587 1.287 10.654 0.607 11835 0 1 fast-glob-previous.js 41.972 2.086 10.236 1.224 11835 0 1
3.2.11
Full Changelog: 3.2.10...3.2.11
🐛 Bug fixesYeap, this is another release aimed at fixing problems with detecting brace expansions in patterns. This time, patterns like
abc/{a.txt,b.js}was not marked as a dynamic pattern. So, now the regex has been rewritten to a generalized solution as a function to avoid future problems due to the complexity of the regular expression.
3.2.10
Full Changelog: 3.2.9...3.2.10
🐛 Bug fixes
- Fixed a regression in
3.2.8when the{a,b,c}pattern no longer considered a dynamic pattern (thanks @amitdahan, #347).
🥇 New Contributors
- @amitdahan made their first contribution in #348
3.2.9
Full Changelog: 3.2.8...3.2.9
🐛 Bug fixes
- Fixed a regression in
3.2.8with invalid regular expression on older node.js versions (#345).
3.2.8
Full Changelog: 3.2.7...3.2.8
🐛 Bug fixesFix directory matching with trailing slashes (#290)
Thanks @Trott for investigating the problem and the detailed description.
Previously the
src/*/pattern did not work as expected (likesrc/*).Double-slash in the middle of the pattern is not collapsed (#330)
Starting from this release, patterns like
src//*will work like similar patterns without duplicate slashes. This was done for continuity with other solutions (glob,ls src//*, python, golang, …).Adjust inefficient regular expressions (#336, #342, #344)
Thanks @Trott for fixing bugs and @XhmikosR for adding the CodeQL action to CI pipeline.
📖 Documentation
- Some documentation improvements (#327, thanks @MarcelloTheArcane).
⚙️ Infrastructure
- The CodeQL action has been added to CI pipeline (#338, thanks @XhmikosR).
🥇 New Contributors
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ fastq (indirect, 1.11.1 → 1.17.1) · Repo
Release Notes
1.17.1
What's Changed
Full Changelog: v1.17.0...v1.17.1
1.17.0
What's Changed
- Bump typescript from 4.9.5 to 5.0.4 by @dependabot in #68
- fix ci by @Uzlopak in #72
- add running to typescript definition by @Uzlopak in #71
- fix: unshift with worker throwing error (#77) by @aguegu in #78
- Consistently respect the configured concurrency by @mart-jansink in #81
New Contributors
- @dependabot made their first contribution in #68
- @Uzlopak made their first contribution in #72
- @aguegu made their first contribution in #78
- @mart-jansink made their first contribution in #81
Full Changelog: v1.15.0...v1.17.0
1.16.0
What's Changed
- Bump typescript from 4.9.5 to 5.0.4 by @dependabot in #68
- fix ci by @Uzlopak in #72
- add running to typescript definition by @Uzlopak in #71
- fix: unshift with worker throwing error (#77) by @aguegu in #78
New Contributors
- @dependabot made their first contribution in #68
- @Uzlopak made their first contribution in #72
- @aguegu made their first contribution in #78
Full Changelog: v1.15.0...v1.16.0
1.15.0
What's Changed
New Contributors
Full Changelog: v1.14.0...v1.15.0
1.14.0
What's Changed
- Update README on error callback expected behaviour by @giovanni-bertoncelli in #59
- fix(typings): pass generic type to error handler by @AVVS in #62
New Contributors
- @giovanni-bertoncelli made their first contribution in #59
- @AVVS made their first contribution in #62
Full Changelog: v1.13.0...v1.14.0
1.13.0
What's Changed
- feat: run to completion by @gillesdemey in #57
New Contributors
- @gillesdemey made their first contribution in #57
Full Changelog: v1.12.0...v1.13.0
1.12.0
What's Changed
Full Changelog: v1.11.1...v1.12.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 19 commits:
Bumped v1.17.1Emit drain event after pause/resume combo (#82)Bumped v1.17.0Consistently respect the configured concurrency (#81)Bumped v1.16.0fix: unshift with worker throwing error (#77) (#78)add running to typescript definition (#71)fix ci (#72)Bump typescript from 4.9.5 to 5.0.4 (#68)Bumped v1.15.0fix: queueAsPromised.drained() resolves while queue is idle (#64)Bumped v1.14.0fix(typings): pass generic type to error handler (#62)Update README.md (#59)Bumped v1.13.0feat: run to completion (#57)Bumped v1.12.0Fire and forget promises (#54)Added node v16 to CI (#55)
↗️ fill-range (indirect, 7.0.1 → 7.1.1) · Repo
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ find-cache-dir (indirect, 3.3.1 → 5.0.0) · Repo
Release Notes
5.0.0
Breaking
- Require Node.js 16 e14dff6
- Remove
thunkoption e14dff6
- Just use
path.join()on the result.- The
filesoption now only accepts an array of strings e14dff6
- Previously, it accepted both an array or a string.
Improvements
4.0.0
Breaking
- Require Node.js 14 c5e8e5c
- This package is now pure ESM. Please read this.
Improvements
- Upgrade dependencies
- Reduce amount of dependencies
3.3.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 9 commits:
↗️ function-bind (indirect, 1.1.1 → 1.1.2) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 26 commits:
v1.1.2[meta] add `auto-changelog`[Robustness] remove runtime dependency on all builtins except `.apply`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[meta] add `funding` field; create FUNDING.yml[Tests] use `aud` instead of `npm audit`[meta] update `.gitignore`[Tests] switch to nyc for coverage[meta] add `safe-publish-latest`[Dev Deps] update `@ljharb/eslint-config`, `tape`[actions] fix permissionsRevert "Point to the correct file"Merge pull request #16 from svedova/patch-1Point to the correct file[readme] update badges[meta] use `npmignore` to autogenerate an npmignore file[Tests] migrate tests to Github Actions[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`[meta] create SECURITY.md[Tests] fix eslint errors from #15[Dev Deps] update `@ljharb/eslint‑config`, `eslint`, `tape`[Tests] up to `node` `v11.10`, `v10.15`, `v9.11`, `v8.15`, `v6.16`, `v4.9`; use `nvm install-latest-npm`; run audit script in tests[Tests] add `npm run audit`[Tests] remove `jscs`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `covert`, `tape`Docs: enable badges; update wording
↗️ get-intrinsic (indirect, 1.1.1 → 1.2.5) · Repo · Changelog
Release Notes
1.2.4 (from changelog)
Commits
- [Refactor] use all 7 <+ ES6 Errors from
es-errorsbcac811
1.2.3 (from changelog)
Commits
- [Refactor] use
es-errors, so things that only need those do not needget-intrinsicf11db9c- [Dev Deps] update
aud,es-abstract,mock-property,npmignoreb7ac7d1- [meta] simplify
exportsfaa0cc6- [meta] add missing
engines.node774dd0b- [Dev Deps] update
tape5828e8e- [Robustness] use null objects for lookups
eb9a11f- [meta] add
sideEffectsflag89bcc7a
1.2.2 (from changelog)
Commits
1.2.1 (from changelog)
Commits
1.2.0 (from changelog)
Commits
- [actions] update checkout action
ca6b12f- [Dev Deps] update
@ljharb/eslint-config,es-abstract,object-inspect,tape41a3727- [Fix] ensure
Error.prototypeis undeniablec511e97- [Dev Deps] update
aud,es-abstract,tape1bef8a8- [Dev Deps] update
aud,es-abstract0d41f16- [New] add
BigInt64ArrayandBigUint64Arraya6cca25- [Tests] use
gopdecf7722
1.1.3 (from changelog)
Commits
1.1.2 (from changelog)
Fixed
- [Fix] properly validate against extra % signs
#16Commits
- [actions] reuse common workflows
0972547- [meta] use
npmignoreto autogenerate an npmignore file5ba0b51- [actions] use
node/installinstead ofnode/run; usecodecovactionc364492- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,es-abstract,object-inspect,tapedc04dad- [Dev Deps] update
eslint,@ljharb/eslint-config,es-abstract,object-inspect,safe-publish-latest,tape1c14059- [Tests] use
mock-propertyb396ef0- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,object-inspect,tapec2c758d- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,es-abstract,es-value-fixtures,object-inspect,tape29e3c09- [actions] update codecov uploader
8cbc141- [Dev Deps] update
@ljharb/eslint-config,es-abstract,es-value-fixtures,object-inspect,tape10b6f5c- [readme] add github actions/codecov badges
4e25400- [Tests] use
for-eachinstead offoreachc05b957- [Dev Deps] update
es-abstract29b05ae- [meta] use
prepublishOnlyscript for npm 7+95c285d- [Deps] update
has-symbols593cb4f- [readme] fix repo URLs
1c8305b- [Deps] update
has-symbolsc7138b6- [Dev Deps] remove unused
has-bigintsbd63aff
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 62 commits:
v1.2.5[Deps] update `es-define-property`[actions] split out node 10-20, and 20+[Refactor] use `dunder-proto` and `call-bind-apply-helpers` instead of `has-proto`[Refactor] cache `es-define-property` as well[Tests] use `call-bound` directly[Deps] update `gopd`, `has-proto`, `has-symbols`, `hasown`[Refactor] use `gopd`[Deps] update `has-proto`, `has-symbols`, `hasown`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `es-abstract`, `es-value-fixtures`, `gopd`, `mock-property`, `object-inspect`, `tape`[Tests] replace `aud` with `npm audit`[Deps] update `has-proto`, `hasown`[Dev Deps] update `call-bind`, `es-abstract`, `tape`v1.2.4[Refactor] use all 7 <+ ES6 Errors from `es-errors`v1.2.3[Refactor] use `es-errors`, so things that only need those do not need `get-intrinsic`[Dev Deps] update `tape`[meta] add missing `engines.node`[Robustness] use null objects for lookups[Dev Deps] update `aud`, `es-abstract`, `mock-property`, `npmignore`[meta] simplify `exports`[meta] add `sideEffects` flagv1.2.2[Refactor] use `hasown` instead of `has`[Deps] update `function-bind`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `call-bind`, `es-abstract`, `mock-property`, `object-inspect`, `tape`v1.2.1[Fix] avoid a crash in envs without `__proto__`[Dev Deps] update `es-abstract`v1.2.0[New] add `BigInt64Array` and `BigUint64Array`[Dev Deps] update `@ljharb/eslint-config`, `es-abstract`, `object-inspect`, `tape`[Fix] ensure `Error.prototype` is undeniable[Dev Deps] update `aud`, `es-abstract`[Tests] use `gopd`[Dev Deps] update `aud`, `es-abstract`, `tape`[actions] update checkout actionv1.1.3[Fix] properly check for % signs[Dev Deps] update `es-abstract`, `es-value-fixtures`, `tape`v1.1.2[Fix] properly validate against extra % signs[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `@ljharb/eslint-config`, `es-abstract`, `es-value-fixtures`, `object-inspect`, `tape`[Tests] use `for-each` instead of `foreach`[Tests] use `mock-property`[Dev Deps] remove unused `has-bigints`[Deps] update `has-symbols`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `object-inspect`, `tape`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `es-abstract`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploader[readme] add github actions/codecov badges[Dev Deps] update `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `es-abstract`, `object-inspect`, `tape`[readme] fix repo URLs[Deps] update `has-symbols`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `es-abstract`, `es-value-fixtures`, `object-inspect`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
↗️ get-stream (indirect, 6.0.1 → 9.0.1) · Repo
Release Notes
9.0.1
9.0.0
Breaking
Improvements
8.0.1
Fixes
- Ensure
error.bufferedDatais as full as possible. (#106)- Fix the
maxBufferoption being one byte off in some edge case. (#105)
8.0.0
Huge thanks to @ehmicky for doing all the work for this release 🙌
Breaking
- Remove the
encodingoption. (#69, #67)
- This package handles binary, UTF-8 and object streams.
- For other encodings like UTF-16, hexacimal and base64, please see the following tip. (#84)
- Methods like
buffer.toString('hex')orbuffer.toString('base64')can also be used.Improvements
- Support any JavaScript environment, including browsers. (#85)
- Support web streams (
ReadableStream). (#82, #78, #79, #80)- Support async iterables. (#69, #93)
- Add
getStreamAsArray()method to pass streams in object mode. (#86)- Add
getStreamAsArrayBuffer()method to return the stream as anArrayBuffer. (#81)- When the stream is larger than the maximum size for a string, buffer or
ArrayBuffer, seterror.bufferedDatawith the partially read data instead of leaving it empty. (#68, #48)Fixes
- Do not crash on big streams (with one/many GBs). (#66)
- Ensure
maxBufferstops infinite streams. (#62)- Stop consuming the streaming when hitting
maxBuffer. (#42, #69).- Set
error.bufferedDatawhen the stream errors for other reasons thanmaxBuffer. (#56, #63)- Ensure
error.bufferedDatais smaller thanmaxBuffer. (#89)TypeScript types
- The
streamargument must be aReadable,ReadableStreamorAsyncIterable. (#71)Documentation
- Add tips on alternatives,
Bloband JSON streaming. (#58, #95, #96, #97)Performance
- Do not block the event loop when the stream ends. (#92)
7.0.1
- Work around issue with handling large sizes e58d141
7.0.0
Breaking
- Require Node.js 16 70571f8
- This package is now pure ESM. Please read this.
- Removed
getStream.array()
- It complicated the codebase considerably and I personally never used it.
- You can use
readableStream.toArray()instead. Exampleconst getStream = require('get-stream'); getStream.buffer(…);→import {getStreamAsBuffer} from 'get-stream'; getStreamAsBuffer(…);const getStream = require('get-stream'); getStream.MaxBufferError;→import {MaxBufferError} from 'get-stream'; MaxBufferError;Tip
You may not need this package anymore.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 68 commits:
9.0.1Upgrade `ReadableStream[Symbol.asyncIterator]` ponyfill (#128)Upgrade ava (#127)Upgrade xo (#126)9.0.0Meta tweaksAdd browser entrypoint (#124)Remove use of `highWatermark` option (#125)Fix browser support (#122)Allow multiple readers at once (#121)Speed up test (#120)Add a test for async iterables (#118)Improve test utility (#117)Handle unusual error types (#115)Drop support for Node 16 (#111)8.0.1Ensure `error.bufferedData` is as full as possible (#106)Fix `maxBuffer` bug with `TextDecoder()` (#105)Refactor `getStreamAsArrayBuffer()` (#104)8.0.0Meta tweaksAdd test for `getStreamAsBuffer()` when `Buffer` is not available (#101)Fix `package.json` description (#99)Split into multiple files (#98)Document how to stream JSON arrays (#96)Add benchmarks (#94)Improve `Alternatives` documentation (#97)Document how to create `Blob`s (#95)Document support for async iterables (#93)Remove end-of-stream blocking (#92)Add more high-level tests (#91)Add tests for streams with several chunks (#90)Fix `bufferedData` being larger than `maxBuffer` (#89)Simplify `getStreamAsBuffer()` implementation (#88)Add support for streams in object mode (#86)Fix `error.bufferedData` with `getStreamAsArrayBuffer()` (#87)Support any JavaScript environment (#85)Document `TextDecoderStream` usage (#84)Small performance improvement (#83)Add support for `ReadableStream` (#82)Add `getStreamAsArrayBuffer()` method (#81)Add support for `ArrayBuffer` stream chunks (#80)Add support for `DataView` stream chunks (#79)Add support for `TypedArray` stream chunks (#78)Improve tests (#77)Add high-level tests (#76)Validate streams in object mode (#75)Fix UTF-8 sequences being split (#74)Improve first argument's validation (#73)Improve `readme.md` (#72)Improve TypeScript types (#71)Add a test for big chunks (#70)Truncate `error.bufferedData` if too large (#68)Remove `encoding` option (#69)Do not crash on big streams (#66)Add more tests related to the `encoding` option (#65)Remove `devDependency` (#64)Set `error.bufferedData` when stream errors (#63)Handle infinite streams (#62)Test `encoding` option (#59)Simplify `encoding` option (#60)Document `node:stream/consumers` (#58)Refactoring simplifying code (#57)7.0.1Work around issue with handling large sizes7.0.0Require Node.js 16 and move to ESMAdd reference to into-stream (#49)
↗️ glob-parent (indirect, 5.1.2 → 6.0.2) · Repo · Changelog
Security Advisories 🚨
🚨 glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service
glob-parent 6.0.0 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1.
This vulnerability is separate from GHSA-ww39-953v-wcq6.
Release Notes
6.0.2
Bug Fixes
6.0.1
Bug Fixes
6.0.0
⚠ BREAKING CHANGES
- Correct mishandled escaped path separators (#34)
- upgrade scaffold, dropping node <10 support
Bug Fixes
Miscellaneous Chores
- upgrade scaffold, dropping node <10 support (e83d0c5)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 16 commits:
chore: release 6.0.2 (#54)chore: Run prettierfix: Improve performance (#53)chore: Run prettierchore: release 6.0.1 (#52)chore: Run prettierfix: Resolve ReDoS vulnerability from CVE-2021-35065 (#49)chore: Run prettierchore: release 6.0.0 (#41)fix!: Correct mishandled escaped path separators (#34)chore(ci): Upgrade coveralls action to 1.1.2chore(ci): Update workflowchore: fix typo in badgesBuild: Run prettierci: add release-please & cleanup actionschore!: upgrade scaffold, dropping node <10 support
↗️ globals (indirect, 13.10.0 → 13.24.0) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 32 commits:
13.24.0Meta tweaksAdd WebXR classes to `browser` (#206)13.23.0Add `ToggleEvent` to `browser` (#203)13.22.0Add `MediaStreamConstraints` to `browser` (#202)13.21.0Add missing Node.js and browser globals (#200)13.20.0Add missing Fetch API globals for Node.js (#197)13.19.0Add `NavigatorUAData` to browser (#196)13.18.0Add `ClipboardItem` to browser (#194)13.17.0Add missing events to browser, worker, service worker environments (#192)Add `TransformStream` for browser (#193)13.16.0Add `reportError` (#191)13.15.0Add `structuredClone` for browser (#190)13.14.0Add `fetch` global for Node.js (#189)13.13.0Add `MediaMetadata` to `browser` environment (#186)13.12.1Remove trailing space from `AudioWorkletGlobalScope` (#184)13.12.0Update Node.js builtins (#182)13.11.0Add `GM_addElement` to `greasemonkey` (#180)
↗️ globby (indirect, 12.0.0 → 14.0.2) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 65 commits:
14.0.2Fix types14.0.1Meta tweaksFix `expandDirectories.extension` option (#263)Fix read permission error on ignore files search (#259)14.0.0Add `convertPathToPattern()` methodRequire Node.js 1813.2.2Update dependencies (#253)13.2.1Fix `ignore` and `expandDirectories` default handling (#252)13.2.0Meta tweaksPass deep option to ignore filter to avoid unnecessary recursion (#251)13.1.4Fix error when reading inaccessible directories with `gitignore: true` and `suppressErrors: true` (#246)Remove `URL` TypeScript type workaround (#230)13.1.3Fix an edge-case bug (#242)Update CI config (#243)13.1.2Ignore failing test for nowMake `ignoreFiles` option accept readonly arrays (#235)Fix CI13.1.1Fix duplicated result when using globstar (#231)Improve ignore test coverage (#229)13.1.0Add `ignoreFiles` option (#228)Minor tweak (#226)Style tweak (#227)13.0.0Meta tweaksRemove `ignore` option for `isGitIgnored` and `isGitIgnoredSync` (#225)Improve performance with mutiple patterns (#222)Don't pass `options.ignore` to `isGitIgnored` (#223)Expose new `generateGlobTasks` and `generateGlobTasksSync` (#221)Fix `bench` script (#220)Improve task expansion (#219)Simplify `expandDirectories` option handling (#218)Simplify task expansion (#215)Minor refactoring (#217)Improve test coverage (#216)Apply arguments check logic to `isDynamicPattern` (#214)Simplify result filter and unique (#213)Remove `array-union` (#211)Fix `generateGlobTasks` call without options (#212)Fix bug with `objectMode` option (#210)Fix typo (#209)Drop support for checking object with `path` property in function returns by `isGitIgnored` (#208)12.2.0Fix readmeWork around TypeScript type problem with `URL` global (#206)Accept `URL` in function returned by `isGitIgnored` (#207)12.1.0Support `URL` as `cwd` (#201)DRY a little bit (#203)Use `fs.promises.readFile` instead of `promisify(fs.readFile)` (#204)Upgrade dev dependencies12.0.2Ensure async method is completely async12.0.1Meta tweaks
↗️ graceful-fs (indirect, 4.2.8 → 4.2.11) · Repo
Commits
See the full diff on Github. The new version differs by 17 commits:
4.2.11Add EBUSY to handled error codes for windows directory renameupdate and improve tests somewhat4.2.10fix spurious ENOTEMPTY in test on windows ciavoid spurious EBUSY in windows CI testsci: output raw tap from testactually fix memory leak test failing spuriouslyfix memory leak test failing spuriouslydo not try to patch missing fs functionsAvoid setPrototypeOf if prototype is undefinedinstall with npm 8fix: fs.readdir() on ancient nodes that don't know about optionschore: add copyright year to licenseci: makework4.2.9fix(stat): support throwIfNoEntry for `statSync`
↗️ has-bigints (indirect, 1.0.1 → 1.0.2) · Repo · Changelog
Release Notes
1.0.2 (from changelog)
Commits
- [actions] reuse common workflows
a655b7f- [actions] use
node/installinstead ofnode/run; usecodecovaction730a2e5- [readme] add github actions/codecov badges; update URLs
9a83788- [Dev Deps] update
eslint,@ljharb/eslint-config,safe-publish-latest,tapeb1edc52- [actions] update codecov uploader
cbb1bd0- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,tape8717e6d- [Dev Deps] update
eslint,@ljharb/eslint-config,auto-changelog,safe-publish-latest,tape5f70eab- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,tapea1446bc- [meta] use
prepublishOnlyscript for npm 7+f2dd197- [actions] use checkout v3
1ba72f1- [Refactor] use a global variable to get the original BigInt instead of a global property
a7ccfac- [actions] skip
npm lson older nodes62d31e7
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 13 commits:
v1.0.2[actions] use checkout v3[Refactor] use a global variable to get the original BigInt instead of a global property[actions] skip `npm ls` on older nodes[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `auto-changelog`, `safe-publish-latest`, `tape`[readme] add github actions/codecov badges; update URLs[actions] update codecov uploader[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
↗️ has-symbols (indirect, 1.0.2 → 1.1.0) · Repo · Changelog
Release Notes
1.1.0 (from changelog)
Commits
- [actions] update workflows
548c0bf- [actions] further shard; update action deps
bec56bb- [meta] use
npmignoreto autogenerate an npmignore fileac81032- [New] add types
6469cbf- [actions] update rebase action to use reusable workflow
9c9d4d0- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,tapeadb5887- [Dev Deps] update
@ljharb/eslint-config,aud,tape13ec198- [Dev Deps] update
auto-changelog,core-js,tape941be52- [Tests] replace
audwithnpm audit74f49e9- [Dev Deps] update
npmignore9c0ac04- [Dev Deps] add missing peer dep
52337a5
1.0.3 (from changelog)
Commits
- [actions] use
node/installinstead ofnode/run; usecodecovaction518b28f- [meta] add
bugsandhomepagefields; reorder package.jsonc480b13- [actions] reuse common workflows
01d0ee0- [actions] update codecov uploader
6424ebe- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,tapedfa7e7f- [Dev Deps] update
eslint,@ljharb/eslint-config,safe-publish-latest,tape0c8d436- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,tape9026554- [readme] add actions and codecov badges
eaa9682- [Dev Deps] update
eslint,tapebc7a3ba- [Dev Deps] update
eslint,auto-changelog0ace00a- [meta] use
prepublishOnlyscript for npm 7+093f72b- [Tests] test on all 16 minors
9b80d3d
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 25 commits:
v1.1.0[New] add types[Dev Deps] add missing peer dep[Dev Deps] update `auto-changelog`, `core-js`, `tape`[actions] update workflows[Tests] replace `aud` with `npm audit`[actions] further shard; update action deps[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[Dev Deps] update `npmignore`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[actions] update rebase action to use reusable workflowv1.0.3[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[meta] add `bugs` and `homepage` fields; reorder package.json[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[actions] update codecov uploader[Dev Deps] update `eslint`, `tape`[Tests] test on all 16 minors[readme] add actions and codecov badges[Dev Deps] update `eslint`, `auto-changelog`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
⁉️ hosted-git-info (downgrade, 4.0.2 → 2.8.9) · Repo · Changelog
Security Advisories 🚨
🚨 Regular Expression Denial of Service in hosted-git-info
The npm package
hosted-git-infobefore 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ human-signals (indirect, 2.1.0 → 8.0.0) · Repo · Changelog
Release Notes
8.0.0
Breaking changes (types)
- The
SignalNumberandSignal['number']types in TypeScript are now stricter. They only allow valid signal numbers like 1 or 9. They do not allow invalid signal numbers like -1, 1.5 or 999. Please note that 0 is not considered a valid signal number, although it can be passed toprocess.kill().Types
- The
signalsByName[signalName]andsignalsByNumber[signalNumber]types in TypeScript are nowSignalinstead ofSignal | undefined. This means you can now dosignalsByName[signalName].descriptioninstead ofsignalsByName[signalName]!.description.
7.0.0
Breaking changes (types)
- The
SignalNameandSignal['name']types in TypeScript are now stricter. They only allow valid signal names like'SIGINT'. They do not allow lowercase signals like'sigint'nor unknown signals like'SIGOTHER'.
6.0.0
Breaking changes
- Minimal supported Node.js version is now
18.18.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ ignore (indirect, 4.0.6 → 5.3.2) · Repo · Changelog
Release Notes
5.3.0
5.3.0
- MINOR export
Optionsinterface (#105)An upgrade is safe for all dependents
It allows typing external methods which expect
Optionsas a param, by importing theOptionsinterface.import {Options} from 'ignore'
5.2.4
- PATCH fixes normal single asterisk and normal consecutive asterisks defined in gitignore spec (#57)
- PATCH invalid trailing backslash will not throw unexpectedly
An upgrade is recommended for all dependents
The following rules could be not properly parsed with previous
ignoreversions**foo *bar qu*ux abc\ # `ignore` would throw if no whitespace after `\`
5.2.0
- PATCH support readonly arrays of typescript. (#70)
- MINOR bring backward compatibility with relative paths. (#75)
An upgrade is recommended for all dependents.
ignore().ignores('../foo/bar.js') // will throwAnd the code below will not throw, however it is not recommended
ignore({ allowRelativePaths: true }).ignores('../foo/bar.js')Recommend:
ignore().ignores('foo/bar.js')
5.1.9
- PATCH fixes
ignorecasewhen internal cache is hit. (#74)An upgrade is recommended for all dependents.
5.1.5
- PATCH fixes escaping for square brackets (#59)
An upgrade is recommended for all dependents.
5.1.1
- PATCH fixes
isPathValidon Windows (#54)On Windows, if
pathis an absolute path,ig.ignores(path),ig.test(path)and related methods will now throw an error as expected.
5.1.0
- FEATURE: Typescript: export interface Ignore (#53)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
⁉️ indent-string (downgrade, 5.0.0 → 4.0.0) · Repo
Commits
See the full diff on Github. The new version differs by 41 commits:
4.0.0Meta tweaksRequire Node.js 8, add TypeScript definition (#16)3.2.0Rename the `blank` option to `includeEmptyLines`Add option to indent empty lines (#13)3.1.0Remove the `repeating` dependency3.0.0[BREAKING] switch the arguments order & es2015ify - fixes #7 (#9):lipstick: (#8)tweaks2.1.0bump deps2.0.0move CLI into a separate module1.2.2Merge pull request #6 from jbblanchet/masterDon't indent when count is explicitly 0minor package.json tweaks1.2.1bump depsUpdate .travis.yml1.2.0improve perf1.1.0Merge pull request #5 from blakeembrey/leading-whitespaceIndent all non-whitespace-only lines1.0.0tweaksUpdate readme.md0.1.3fix require0.1.2make sure `count` is a number if defined - closes #3simplify regex0.1.1Merge pull request #1 from bevacqua/patch-1Update index.js0.1.0init
↗️ irregular-plurals (indirect, 3.3.0 → 3.5.0) · Repo
Release Notes
3.5.0
3.4.1
- Fix compatibility with bundlers fe4ec96
3.4.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ is-bigint (indirect, 1.0.3 → 1.1.0) · Repo · Changelog
Release Notes
1.1.0 (from changelog)
Commits
- [actions] reuse common workflows
0e63a44- [meta] use
npmignoreto autogenerate an npmignore file47584ee- [Tests] use
for-eachandes-value-fixturesf226864- [New] add types
78e2c47- [actions] split out node 10-20, and 20+
4395a8d- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,has-symbols,object-inspect,tapec188501- [Dev Deps] update
eslint,@ljharb/eslint-config,object-inspect,safe-publish-latest,tape5360d32- [actions] update rebase action to use reusable workflow
d5c1775- [actions] update codecov uploader
c7478c7- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,npmignore,object-inspect,tape6fbce66- [meta] add missing
engines.node6f9ed42- [Tests] replace
audwithnpm audit21846c3- [Dev Deps] remove unused
has-symbols, add missinghas-tostringtagb378d94- [Deps] update
has-bigintsf46c35b- [Dev Deps] add missing peer dep
2b9be16
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 21 commits:
v1.1.0[Dev Deps] remove unused `has-symbols`, add missing `has-tostringtag`[meta] add missing `engines.node`[New] add types[Tests] use `for-each` and `es-value-fixtures`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `npmignore`, `object-inspect`, `tape`[actions] split out node 10-20, and 20+[Tests] replace `aud` with `npm audit`[Deps] update `has-bigints`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `has-symbols`, `object-inspect`, `tape`[actions] update rebase action to use reusable workflow[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploaderv1.0.4[readme] add github actions/codecov badges[Dev Deps] update `tape`[Deps] add `has-bigints` as a runtime dependency[eslint] remove unnecessary eslintrc file
↗️ is-boolean-object (indirect, 1.1.2 → 1.2.0) · Repo · Changelog
Release Notes
1.2.0 (from changelog)
Commits
- [actions] reuse common workflows
380fa25- [meta] use
npmignoreto autogenerate an npmignore filebefa203- [actions] split out node 10-20, and 20+
ca31663- [New] add types
6d58609- [Dev Deps] update
eslint,@ljharb/eslint-config,core-js,safe-publish-latest,tape06cc67e- [actions] update codecov uploader
0722346- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,tape100acdf- [actions] update rebase action to use reusable workflow
26333ff- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,core-js,tapefde97ee- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,core-js,npmignore,tapef5ed3c8- [Deps] update
call-bind,has-tostringtag61912e2- [Tests] replace
audwithnpm auditc6a0db5- [meta] better
eccheckcommand3a59ec6- [Dev Deps] add missing peer dep
c0e10db
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 15 commits:
v1.2.0[New] add types[Deps] update `call-bind`, `has-tostringtag`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `core-js`, `npmignore`, `tape`[actions] split out node 10-20, and 20+[Tests] replace `aud` with `npm audit`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[actions] update rebase action to use reusable workflow[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `core-js`, `tape`[meta] better `eccheck` command[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `core-js`, `safe-publish-latest`, `tape`[actions] update codecov uploader
↗️ is-builtin-module (indirect, 3.1.0 → 3.2.1) · Repo
Commits
See the full diff on Github. The new version differs by 5 commits:
↗️ is-callable (indirect, 1.2.4 → 1.2.7) · Repo · Changelog
Release Notes
1.2.7 (from changelog)
Commits
- [Fix] recognize
document.allin IE 6-1006c1db2- [Tests] improve logic for FF 20-35
0f7d9b9- [Fix] handle
document.allin FF 27 (and +, probably)696c661- [Tests] fix proxy tests in FF 42-63
985df0d- [readme] update tested browsers
389e919- [Fix] detect
document.allin Opera 12.16b9f1022- [Fix] HTML elements: properly report as callable in Opera 12.16
17391fe- [Tests] fix inverted logic in FF3 test
056ebd4
1.2.6 (from changelog)
Commits
- [Fix] work for
document.allin Firefox 3 and IE 6-8015132a- [Test] skip function toString check for nullish values
8698116- [readme] add "supported engines" section
0442207- [Tests] skip one of the fixture objects in FF 3.6
a501141- [Tests] allow
classconstructor tests to fail in FF v45 - v54, which has undetectable classesb12e4a4- [Fix] Safari 4: regexes should not be considered callable
4b732ff- [Fix] properly recognize
document.allin Safari 43193735
1.2.5 (from changelog)
Commits
- [actions] reuse common workflows
5bb4b32- [meta] better
eccheckcommandb9bd597- [meta] use
npmignoreto autogenerate an npmignore file3192d38- [Fix] for HTML constructors, always use
tryFunctionObjecteven in pre-toStringTag browsers3076ea2- [Dev Deps] update
eslint,@ljharb/eslint-config,available-typed-arrays,object-inspect,safe-publish-latest,tape8986746- [meta] add
auto-changelog7dda9d0- [Fix] properly report
document.allda90b2b- [actions] update codecov uploader
c8f847c- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,object-inspect,tape899ae00- [Dev Deps] update
eslint,@ljharb/eslint-config,es-value-fixtures,object-inspect,tape344e913- [meta] remove greenkeeper config
737dce5- [meta] npmignore coverage output
680a883
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 30 commits:
v1.2.7[readme] update tested browsers[Tests] fix proxy tests in FF 42-63[Fix] recognize `document.all` in IE 6-10[Fix] HTML elements: properly report as callable in Opera 12.16[Fix] detect `document.all` in Opera 12.16[Tests] improve logic for FF 20-35[Fix] handle `document.all` in FF 27 (and +, probably)[Tests] fix inverted logic in FF3 testv1.2.6[readme] add "supported engines" section[Test] skip function toString check for nullish values[Tests] skip one of the fixture objects in FF 3.6[Tests] allow `class` constructor tests to fail in FF v45 - v54, which has undetectable classes[Fix] work for `document.all` in Firefox 3 and IE 6-8[Fix] Safari 4: regexes should not be considered callable[Fix] properly recognize `document.all` in Safari 4v1.2.5[Fix] for HTML constructors, always use `tryFunctionObject` even in pre-toStringTag browsers[Fix] properly report `document.all`[meta] use `npmignore` to autogenerate an npmignore file[meta] add `auto-changelog`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `es-value-fixtures`, `object-inspect`, `tape`[meta] remove greenkeeper config[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `object-inspect`, `tape`[meta] better `eccheck` command[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `available-typed-arrays`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploader[meta] npmignore coverage output
↗️ is-core-module (indirect, 2.5.0 → 2.15.1) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 59 commits:
v2.15.1[Dev Deps] add missing peer dep[Fix] `test/mock_loader` is no longer exposed as of v22.7[Dev Deps] update `mock-property`[Tests] replace `aud` with `npm audit`[Tests] add `process.getBuiltinModule` testsv2.15.0[New] add `node:sea`v2.14.0[meta] add missing `engines.node`[New] add `test/mock_loader`[Deps] update `hasown`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `mock-property`, `npmignore`, `tape`v2.13.1[Refactor] use `hasown` instead of `has`[Dev Deps] update `mock-property`, `tape`v2.13.0[New] `node:test/reporters` and `wasi`/`node:wasi` are in v18.17[Dev Deps] update `@ljharb/eslint-config`, `aud`, `semver`, `tape`v2.12.1[Fix] `test/reporters` now requires the `node:` prefix as of v20.2v2.12.0[New] `test/reporters` added in v19.9, `wasi` added in v20[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[Dev Deps] add missing `in-publish` dep[actions] update rebase action to use reusable workflowv2.11.0[New] `inspector/promises` and `node:inspector/promises` is now available in node 19[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `aud`, `tape`v2.10.0[New] `node:test` is now available in node ^16.17[Tests] improve skip messagev2.9.0[New] add `node:test`, in node 18+[meta] simplify "exports"[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[Tests] use `mock-property`v2.8.1[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`[Fix] update node 0.4 results[Tests] run `nyc` in `tests-only`, not `test`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`v2.8.0[New] add `readline/promises` to node v17+[Tests] node ^14.18 supports `node:` prefixes for CJS[actions] update codecov uploaderv2.7.0[Dev Deps] update `@ljharb/eslint-config`[New] node `v14.18` added `node:`-prefixed core modules to `require`[eslint] fix linter warning[meta] add `sideEffects` flag[Tests] add coverage for Object.prototype pollutionv2.6.0[New] add `stream/consumers` to node `>= 16.7`[Dev Deps] update `eslint`, `tape`[Refactor] Remove duplicated `&&` operand[Tests] include prereleases
↗️ is-docker (indirect, 2.2.1 → 3.0.0) · Repo
Commits
See the full diff on Github. The new version differs by 4 commits:
↗️ is-glob (indirect, 4.0.1 → 4.0.3) · Repo
Commits
See the full diff on Github. The new version differs by 8 commits:
↗️ is-negative-zero (indirect, 2.0.1 → 2.0.3) · Repo · Changelog
Release Notes
2.0.3 (from changelog)
Commits
- add types
e28f0d5- [meta] use
npmignoreto autogenerate an npmignore filef68ec13- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,tape70abff7- [actions] update rebase action to use reusable workflow
6e1356e- [Dev Deps] update
@ljharb/eslint-config,aud,npmignore,tapec00d4ab- [meta] add
sideEffectsflag9c45539
2.0.2 (from changelog)
Commits
- [actions] reuse common workflows
ece923d- [actions] use
node/installinstead ofnode/run; usecodecovaction3a26f43- [meta] do not publish workflow files
2cea0c2- [readme] add github actions/codecov badges; update URLs
0c0be3e- [Dev Deps] update
eslint,@ljharb/eslint-config,safe-publish-latest,tapea93d16e- [meta] create FUNDING.yml
b4f425e- [actions] update codecov uploader
7999db3- [Dev Deps] update
eslint,@ljharb/eslint-config,auto-changelog,safe-publish-latest,tape140e4d9- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,tape23a8b6d- [readme] add actions and codecov badges
fe92126- [readme] fix repo URLs
50c428e- [Dev Deps] update
eslint,@ljharb/eslint-config,tape688155f- [meta] use
prepublishOnlyscript for npm 7+83171f9- [actions] update workflows
e9823db
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 22 commits:
v2.0.3[meta] add `sideEffects` flagadd types[Dev Deps] update `@ljharb/eslint-config`, `aud`, `npmignore`, `tape`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[actions] update rebase action to use reusable workflowv2.0.2[actions] reuse common workflows[meta] do not publish workflow files[meta] create FUNDING.yml[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[readme] add github actions/codecov badges; update URLs[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `auto-changelog`, `safe-publish-latest`, `tape`[actions] update codecov uploader[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[readme] add actions and codecov badges[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+[readme] fix repo URLs[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`[actions] update workflows
↗️ is-number-object (indirect, 1.0.6 → 1.1.0) · Repo · Changelog
Release Notes
1.1.0 (from changelog)
Commits
- [meta] use
npmignoreto autogenerate an npmignore filecb8423c- [New] add types
273e406- [actions] split out node 10-20, and 20+
3da6267- [Robustness] use
call-bind834c098- [actions] update rebase action to use reusable workflow
84a8a9f- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,core-js,npmignore,tape7275bca- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,core-js,tape49a83aa- [Tests] replace
audwithnpm audit061492b- [Refactor] avoid an expensive check, for null
08d29a8- [Deps] update
has-tostringtag4e2ad65- [Dev Deps] add missing peer dep
8228bfa
1.0.7 (from changelog)
Commits
- [actions] reuse common workflows
8f9a1b0- [meta] better
eccheckcommand9dc8dff- [Dev Deps] update
eslint,@ljharb/eslint-config,core-js,safe-publish-latest,tapec50ecbf- [actions] update codecov uploader
f1a2560- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,core-js,tape4b06ace- [Dev Deps] update
eslint,@ljharb/eslint-config,auto-changelog,core-js,tape3dc0e8b- [meta] add
bugs/homepagepackage.json fieldsd7e0bcf
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 20 commits:
v1.1.0[New] add types[Refactor] avoid an expensive check, for null[Robustness] use `call-bind`[Deps] update `has-tostringtag`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `core-js`, `npmignore`, `tape`[actions] split out node 10-20, and 20+[Tests] replace `aud` with `npm audit`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `core-js`, `tape`[actions] update rebase action to use reusable workflowv1.0.7[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `auto-changelog`, `core-js`, `tape`[meta] add `bugs`/`homepage` package.json fields[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `core-js`, `tape`[meta] better `eccheck` command[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `core-js`, `safe-publish-latest`, `tape`[actions] update codecov uploader
⁉️ is-path-inside (downgrade, 4.0.0 → 3.0.3) · Repo
Commits
See the full diff on Github. The new version differs by 29 commits:
3.0.3Fix handling of root directory as parent path (#15)Move to GitHub Actions (#16)3.0.2Clarify the use-case for this package3.0.1Fix nested paths with the same base but actually is a different directory (#12)3.0.0Require Node.js 8Make the check case-insensitive on Windows (#10)Tidelift tasksAdd Node.js 12 to testing (#9)2.1.0Add TypeScript definition (#8)2.0.0Require Node.js 6Require Node.js 4 and meta tweaks1.0.1update tests for latest AVA versionTest on `stable` instead of `iojs`Add XOES2015ify testsFix examples in documentationtweaksUpdate .travis.yml1.0.0tweaks0.1.0init
↗️ is-plain-obj (indirect, 1.1.0 → 4.1.0) · Repo
Release Notes
4.1.0
4.0.0
Breaking
3.0.0
Breaking
- Require Node.js 10 1e18041
Breaking for TypeScript users
2.1.0
2.0.0
Breaking:
- Require Node.js 8 9748067
Enhancements:
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 24 commits:
4.1.0Improve performance (#16)Use `node:vm` instead of `vm` (#18)Add one example (#17)Add tests for JSON and Atomics (#15)Make it work across realms (#14)Add a test for `Object.create({})` (#13)Minor tweak4.0.0Require Node.js 12 and move to ESMMove to GitHub Actions3.0.0Require Node.js 10Make the TypeScript types stricter (#10)2.1.0Refactor: Use `Object.prototype` directly (#8)Tidelift tasksCreate funding.ymlAdd Node.js 12 to testing (#5)2.0.0Require Node.js 8Add TypeScript definition (#4)Require Node.js 6update tests for latest AVA version
↗️ is-regex (indirect, 1.1.4 → 1.2.0) · Repo · Changelog
Release Notes
1.2.0 (from changelog)
Fixed
- [Tests] allow tests to pass if zero traps are triggered
#35Commits
- [actions] reuse common workflows
be7bf6a- [New] add types
39066a4- [meta] use
npmignoreto autogenerate an npmignore file8938588- [Refactor] reorganize code
2f76f26- [actions] split out node 10-20, and 20+
8c9aedf- [meta] better
eccheckcommand6b39408- [Dev Deps] update
eslint,@ljharb/eslint-config,safe-publish-latest,tapee38cf3c- [actions] update codecov uploader
487c75d- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,core-js,foreach,tape0d7da87- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,core-js,tapec1c1198- [actions] update rebase action to use reusable workflow
213646e- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,core-js,npmignore,tape0a44e77- [Refactor] use
hasownd939332- [Deps] update
call-bind,has-tostringtag46bfdc9- [Tests] use
for-eachinstead offoreach138b3f2- [Tests] replace
audwithnpm audit37ed80a- [Deps] update
gopd6fd4097- [Dev Deps] update
core-js97c1c60- [Dev Deps] add missing peer dep
7329b8e
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 21 commits:
v1.2.0[New] add types[Deps] update `gopd`[Dev Deps] update `core-js`[Refactor] reorganize code[Refactor] use `hasown`[actions] split out node 10-20, and 20+[Dev Deps] add missing peer dep[Tests] allow tests to pass if zero traps are triggered[Deps] update `call-bind`, `has-tostringtag`[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `core-js`, `npmignore`, `tape`[Tests] replace `aud` with `npm audit`[meta] use `npmignore` to autogenerate an npmignore file[Tests] use `for-each` instead of `foreach`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `core-js`, `foreach`, `tape`[actions] update rebase action to use reusable workflow[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `core-js`, `tape`[meta] better `eccheck` command[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[actions] update codecov uploader
↗️ is-stream (indirect, 2.0.1 → 4.0.1) · Repo
Release Notes
4.0.1
- Fix docs 022693d
3.0.0
Breaking
- Require Node.js 12.20 5831295
- This package is now pure ESM. Please read this.
- Changed from a default export to named exports.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 9 commits:
↗️ is-string (indirect, 1.0.7 → 1.1.0) · Repo · Changelog
Release Notes
1.1.0 (from changelog)
Commits
- [actions] reuse common workflows
12aa75b- [meta] use
npmignoreto autogenerate an npmignore file6401572- [actions] split out node 10-20, and 20+
223540c- [New] add types
7e83d67- [Dev Deps] update
eslint,@ljharb/eslint-config,core-js,safe-publish-latest,tapefebd26e- [readme] add github actions/codecov badges; update URLs
f6bf065- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,core-js,tape8afc37a- [Robustness] use
call-bindac86dd7- [actions] update rebase action to use reusable workflow
77058c8- [actions] update codecov uploader
4312be5- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,core-js,tape98c3779- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,core-js,npmignore,tape7d8e0e5- [Dev Deps] update
eslint,@ljharb/eslint-config,core-js,safe-publish-latest,tape3284ad1- [Tests] replace
audwithnpm audit8cb7ea7- [Refactor] skip expensive check, for null
20fde50- [Deps] update
has-tostringtagb67a78d- [meta] fix repo URL
1a2ee6b- [meta] better
eccheckcommand6913c75- [Dev Deps] add missing peer dep
8ac8551
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 20 commits:
v1.1.0[New] add types[Robustness] use `call-bind`[Refactor] skip expensive check, for null[Deps] update `has-tostringtag`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `core-js`, `npmignore`, `tape`[actions] split out node 10-20, and 20+[Tests] replace `aud` with `npm audit`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `core-js`, `tape`[actions] update rebase action to use reusable workflow[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `core-js`, `tape`[meta] fix repo URL[meta] better `eccheck` command[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `core-js`, `safe-publish-latest`, `tape`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `core-js`, `safe-publish-latest`, `tape`[readme] add github actions/codecov badges; update URLs[actions] update codecov uploader
↗️ is-symbol (indirect, 1.0.4 → 1.1.0) · Repo · Changelog
Release Notes
1.1.0 (from changelog)
Commits
- [actions] reuse common workflows
acf85f0- [meta] use
npmignoreto autogenerate an npmignore file77c818e- [Tests] use
for-eachandes-value-fixtures93dfed0- [New] add types
ed6a057- [actions] split out node 10-20, and 20+
7f81ccc- [Robustness] use
call-bindandsafe-regex-testdc7e142- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,object-inspect,tape70f87c2- [Dev Deps] update
eslint,@ljharb/eslint-config,object-inspect,safe-publish-latest,tape3f02ff4- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,has-tostringtag,npmignore,object-inspect,tape9588872- [actions] update rebase action to use reusable workflow
59e2f68- [actions] update codecov uploader
e4759f8- [Dev Deps] update
eslint,auto-changelog,object-inspect,tape33990c0- [Tests] use
has-tostringtagfor more robust Symbol.toStringTag detectiond6154e1- [Tests] replace
audwithnpm audit3215a60- [Refactor] avoid an expensive check, for primitives
59f1a42- [Deps] update
has-symbols06be1a9- [Dev Deps] add missing peer dep
799b0da
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 18 commits:
v1.1.0[New] add types[Tests] use `for-each` and `es-value-fixtures`[Refactor] avoid an expensive check, for primitives[Robustness] use `call-bind` and `safe-regex-test`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `has-tostringtag`, `npmignore`, `object-inspect`, `tape`[actions] split out node 10-20, and 20+[Tests] replace `aud` with `npm audit`[Deps] update `has-symbols`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `object-inspect`, `tape`[actions] update rebase action to use reusable workflow[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploader[Dev Deps] update `eslint`, `auto-changelog`, `object-inspect`, `tape`[Tests] use `has-tostringtag` for more robust Symbol.toStringTag detection
↗️ is-wsl (indirect, 2.2.0 → 3.1.0) · Repo
Commits
See the full diff on Github. The new version differs by 6 commits:
↗️ jest-worker (indirect, 27.0.6 → 27.5.1) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ js-yaml (indirect, 3.14.1 → 4.1.0) · Repo · Changelog
Release Notes
4.1.0 (from changelog)
Added
- Types are now exported as
yaml.types.XXX.- Every type now has
optionsproperty with original arguments kept as they were (seeyaml.types.int.optionsas an example).Changed
Schema.extend()now keeps old type order in case of conflicts (e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered asabcdinstead ofcbad).
4.0.0 (from changelog)
Changed
- Check migration guide to see details for all breaking changes.
- Breaking: "unsafe" tags
!!js/function,!!js/regexp,!!js/undefinedare moved to js-yaml-js-types package.- Breaking: removed
safe*functions. Useload,loadAll,dumpinstead which are all now safe by default.yaml.DEFAULT_SAFE_SCHEMAandyaml.DEFAULT_FULL_SCHEMAare removed, useyaml.DEFAULT_SCHEMAinstead.yaml.Schema.create(schema, tags)is removed, useschema.extend(tags)instead.!!binarynow always mapped toUint8Arrayon load.- Reduced nesting of
/libfolder.- Parse numbers according to YAML 1.2 instead of YAML 1.1 (
01234is now decimal,0o1234is octal,1:23is parsed as string instead of base60).dump()no longer quotes:,[,],(,)except when necessary, #470, #557.- Line and column in exceptions are now formatted as
(X:Y)instead ofat line X, column Y(also present in compact format), #332.- Code snippet created in exceptions now contains multiple lines with line numbers.
dump()now serializesundefinedasnullin collections and removes keys withundefinedin mappings, #571.dump()withskipInvalid=truenow serializes invalid items in collections as null.- Custom tags starting with
!are now dumped as!taginstead of!<!tag>, #576.- Custom tags starting with
tag:yaml.org,2002:are now shorthanded using!!, #258.Added
- Added
.mjs(es modules) support.- Added
quotingTypeandforceQuotesoptions for dumper to configure string literal style, #290, #529.- Added
styles: { '!!null': 'empty' }option for dumper (serializes{ foo: null }as "foo:"), #570.- Added
replaceroption (similar to option in JSON.stringify), #339.- Custom
Tagcan now handle all tags or multiple tags with the same prefix, #385.Fixed
- Astral characters are no longer encoded by
dump(), #587.- "duplicate mapping key" exception now points at the correct column, #452.
- Extra commas in flow collections (e.g.
[foo,,bar]) now throw an exception instead of producing null, #321.__proto__key no longer overrides object prototype, #164.- Removed
bower.json.- Tags are now url-decoded in
load()and url-encoded indump()(previously usage of custom non-ascii tags may have led to invalid YAML that can't be parsed).- Anchors now work correctly with empty nodes, #301.
- Fix incorrect parsing of invalid block mapping syntax, #418.
- Throw an error if block sequence/mapping indent contains a tab, #80.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ jsesc (indirect, 2.5.2 → 3.0.2) · Repo
Commits
See the full diff on Github. The new version differs by 15 commits:
Release v3.0.2feat: check for Buffer existence (#64)Release v3.0.1Tweak whitespace scriptEscape non-ASCII whitespace in minimal mode (#62)Release v3.0.0Remove problematic testAvoid old-school Buffer usage in testsRemove stray requireReplace string escaping with regex replace (#61)Test in modern versions of Node.jsUpdate test expectationRevert "Escape lone surrogates in minimal output (#59)"Escape lone surrogates in minimal output (#59)Fix typo
⁉️ json5 (downgrade, 2.2.0 → 1.0.2) · Repo · Changelog
Release Notes
2.2.0
2.1.3
v2.1.3 [code, diff]
2.1.2
- Fix: Bump
minimisttov1.2.5. ([#222])
2.1.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ line-column-path (indirect, 2.0.0 → 3.0.0) · Repo
Release Notes
3.0.0
Breaking
- Require Node.js 12.20 8c5d1f2
- This package is now pure ESM. Please read this.
- Changed from a default export to named exports.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 4 commits:
↗️ lines-and-columns (indirect, 1.1.6 → 1.2.4) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ loader-runner (indirect, 4.2.0 → 4.3.0) · Repo
Commits
See the full diff on Github. The new version differs by 4 commits:
↗️ log-symbols (indirect, 4.1.0 → 6.0.0) · Repo
Release Notes
6.0.0
Breaking
- Require Node.js 18 22e0d8c
Improvements
5.1.0
- Upgrade dependencies 2ee4f5d
5.0.0
Breaking
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ meow (indirect, 10.1.1 → 13.2.0) · Repo
Release Notes
13.2.0
- Add
helpIndentoption (#241) e9a55cd
13.1.0
- Remove
hardRejectionoption 99fe7a6
- It's the default behavior in Node.js since Node.js 16.
13.0.0
Breaking
- Require Node.js 18 2ecd29d
Improvements
- Update dependencies 2ecd29d
12.1.1
12.1.0
- Bundle dependencies (#242) 41e628c
meowis now dependency-less!
12.0.1
12.0.0
Breaking
- Require Node.js 16 (#235) 24d5e9c
- Rename
aliasflag option toshortFlag(#225) 14e870d
- Short flag is a more correct term for what
aliaswas previously used for. We now have a separatealiasesoption for actual aliases.Improvements
- Add
aliasesflag option (#226) 901b9fc- Add
choicesflag option (#228) 149d7af- Add error when
flag.defaultisn't a valid choice (#231) b2d7ce7- Don't indent single line
help/descriptiontext (#232) a5d15e8
Thanks to @tommy-mitchell for doing most of the work on this release
🙌
11.0.0
Breaking
- Require Node.js 14 01cf2a5
Improvements
10.1.5
10.1.4
10.1.3
10.1.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 39 commits:
13.2.0Add `helpIndent` option (#241)13.1.0Meta tweaksRemove `hardRejection` option13.0.0Require Node.js 1812.1.1Fix TypeScript types (#245)12.1.0Readme tweakBundle dependencies (#242)Add Node.js 20 to CI matrix, update dependencies (#243)12.0.1Fix flag `default` values validation (#238)12.0.0Meta tweaksTarget Node 16 (#235)Separate `index.js` and `test.js` into different files (#234)Don't indent single line `help` / `description` text (#232)Add error when `flag.default` isn't a valid choice (#231)Provide JSDoc comments for flag properties (#230)Add `choices` option (#228)Add test for `unnormalizedFlags` with `aliases` (#227)Add `aliases` option (#226)Rename `alias` to `shortFlag` (#225)11.0.0Require Node.js 14Improve TypeScript types (#218)10.1.5Fix for custom config for help (#217)10.1.4Fix `autoHelp` and `autoVersion` with `allowUnknownFlags` set to false (#215)10.1.3Fix return type for `.showHelp()` (#213)Bump dev dependencies (#207)Fix readme typo10.1.2Fix `engines` field (#203)
↗️ micromatch (indirect, 4.0.4 → 4.0.8) · Repo · Changelog
Security Advisories 🚨
🚨 Regular Expression Denial of Service (ReDoS) in micromatch
The NPM package
micromatchprior to version 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs inmicromatch.braces()inindex.jsbecause the pattern.*will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persisted prior to #266. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching.
Commits
See the full diff on Github. The new version differs by 26 commits:
4.0.8run verb to generate README documentationMerge branch 'v4' into hauserkristof-feature/v4.0.8Merge pull request #266 from hauserkristof/feature/v4.0.8lintfix: CHANGELOG about braces & CVE-2024-4068, v4.0.5fix: CVE numbers in CHANGELOGfeat: updated CHANGELOGfix: use actions/setup-node@v4feat: rework test to work on macos with node 10,12 and 14fix: removed unused isObject functionfeat: backported CVE fix from 4.0.6 over to 4.0.7Release 4.0.7.Prepare for 4.0.7 with picomatch v2Update README.mdAdd sponsor to readme4.0.5 - Massive (100x) performance improvement of `micromatch.not()`, thanks to @joyceerhl at Microsoft.fix windows testsadd github workflows, upgrade depsMerge pull request #228 from antonyk/patch-1Merge pull request #229 from antonyk/patch-2Merge pull request #233 from joyceerhl/patch-1Use `Set.prototype.has` over `Array.prototype.includes`fix parse method's jsdocfix typo in docsRemove tidelift
↗️ minimatch (indirect, 3.0.4 → 3.1.2) · Repo · Changelog
Security Advisories 🚨
🚨 minimatch ReDoS vulnerability
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Commits
See the full diff on Github. The new version differs by 17 commits:
3.1.2fix: trim pattern3.1.1fix: treat nocase:true as always having magic3.1.0Add 'allowWindowsEscape' optionadd publishConfig for v3 publishes3.0.6[fix] revert all breaking syntax changesdocument, expose, and test 'partial:true' optionci: tests and makeworkfull test coverage, adding tests, deleting dead codeCredit @yetingli for the regexp improvement3.0.5Improve redos protection, add many testsUse master branch for travis badgeupdate travis
↗️ minimist (indirect, 1.2.5 → 1.2.8) · Repo · Changelog
Security Advisories 🚨
🚨 Prototype Pollution in minimist
Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file
index.js, functionsetKey()(lines 69-95).
Release Notes
1.2.8 (from changelog)
Merged
- [Fix] Fix long option followed by single dash
#17- [Tests] Remove duplicate test
#12- [Fix] opt.string works with multiple aliases
#10Fixed
- [Fix] Fix long option followed by single dash (#17)
#15- [Tests] Remove duplicate test (#12)
#8- [Fix] Fix long option followed by single dash
#15- [Fix] opt.string works with multiple aliases (#10)
#9- [Fix] Fix handling of short option with non-trivial equals
#5- [Tests] Remove duplicate test
#8- [Fix] opt.string works with multiple aliases
#9Commits
- Merge tag 'v0.2.3'
a026794- [eslint] fix indentation and whitespace
5368ca4- [eslint] fix indentation and whitespace
e5f5067- [eslint] more cleanup
62fde7d- [eslint] more cleanup
36ac5d0- [meta] add
auto-changelog73923d2- [actions] add reusable workflows
d80727d- [eslint] add eslint; rules to enable later are warnings
48bc06a- [eslint] fix indentation
34b0f1c- [readme] rename and add badges
5df0fe4- [Dev Deps] switch from
coverttonyca48b128- [Dev Deps] update
covert,tape; remove unnecessarytapf0fb958- [meta] create FUNDING.yml; add
fundingin package.json3639e0c- [meta] use
npmignoreto autogenerate an npmignore filebe2e038- Only apps should have lockfiles
282b570- isConstructorOrProto adapted from PR
ef9153f- [Dev Deps] update
@ljharb/eslint-config,aud098873c- [Dev Deps] update
@ljharb/eslint-config,aud3124ed3- [meta] add
safe-publish-latest4b927de- [Tests] add
audinposttestb32d9bd- [meta] update repo URLs
f9fdfc0- [actions] Avoid 0.6 tests due to build failures
ba92fe6- [Dev Deps] update
tape950eaa7- [Dev Deps] add missing
npmignoredev dep3226afa- Merge tag 'v0.2.2'
980d7ac
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 52 commits:
v1.2.8Merge tag 'v0.2.3'v0.2.3[Fix] Fix long option followed by single dash (#17)[Tests] Remove duplicate test (#12)[eslint] fix indentation[Dev Deps] add missing `npmignore` dev dep[Dev Deps] update `@ljharb/eslint-config`, `aud`[Fix] Fix long option followed by single dash[actions] Avoid 0.6 tests due to build failures[Dev Deps] update `tape`[Fix] opt.string works with multiple aliases (#10)[Fix] Fix handling of short option with non-trivial equals[Dev Deps] update `@ljharb/eslint-config`, `aud`[Tests] Remove duplicate test[Fix] opt.string works with multiple aliases[eslint] more cleanup[eslint] fix indentation and whitespaceMerge tag 'v0.2.2'v0.2.2v1.2.7[meta] add `auto-changelog`[meta] add `auto-changelog`[actions] add reusable workflows[meta] add `safe-publish-latest`[eslint] add eslint; rules to enable later are warnings[Tests] add `aud` in `posttest`[readme] rename and add badges[actions] add reusable workflows[meta] add `safe-publish-latest`[eslint] add eslint; rules to enable later are warnings[Tests] add `aud` in `posttest`[readme] rename and add badges[Dev Deps] switch from `covert` to `nyc`[Dev Deps] switch from `covert` to `nyc`[Dev Deps] update `covert`, `tape`; remove unnecessary `tap`[Dev Deps] update `covert`, `tape`; remove unnecessary `tap`[meta] create FUNDING.yml; add `funding` in package.json[meta] use `npmignore` to autogenerate an npmignore file[meta] create FUNDING.yml; add `funding` in package.json[meta] use `npmignore` to autogenerate an npmignore file[meta] update repo URLs[meta] update repo URLsOnly apps should have lockfilesOnly apps should have lockfiles1.2.6security notice for additional prototype pollution issueisConstructorOrProto adapted from PR[eslint] more cleanup[eslint] fix indentation and whitespaceisConstructorOrProto adapted from PRtest from prototype pollution PR
↗️ node-releases (indirect, 1.1.73 → 2.0.18) · Repo
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
⁉️ normalize-package-data (downgrade, 3.0.2 → 2.5.0) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ npm-run-path (indirect, 4.0.1 → 6.0.0) · Repo
Release Notes
6.0.0
Breaking
Improvements
5.3.0
5.2.0
5.1.0
5.0.1
- Fix a typo 5ae23bc
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 19 commits:
6.0.0Meta tweaksHandle empty `PATH` better (#21)Make it idempotent (#20)Run tests on Windows (#22)TweaksUpgrade Node.js version and dependencies (#19)5.3.0Add `preferLocal` and `addExecaPath` options (#18)5.2.0Meta tweaksAllow `execPath` to be a file URL (#16)5.1.0Allow `cwd` option to be a `URL` (#15)5.0.1Fix a typo5.0.0Require Node.js 12.20 and move to ESMMove to GitHub Actions (#12)
↗️ object-inspect (indirect, 1.11.0 → 1.13.3) · Repo · Changelog
Release Notes
1.13.3 (from changelog)
Commits
- [actions] split out node 10-20, and 20+
44395a8- [Fix]
quoteStyle: properly escape only the containing quotes5137f8f- [Refactor] clean up
quoteStylecode450680c- [Tests] add
quoteStyleescaping testse997c59- [Dev Deps] update
auto-changelog,es-value-fixtures,taped5a469c- [Tests] replace
audwithnpm auditfb7815f- [Dev Deps] update
mock-property11c817b
1.13.2 (from changelog)
Commits
- [readme] update badges
8a51e6b- [Dev Deps] update
@ljharb/eslint-config,tapeef05f58- [Dev Deps] update
error-cause,has-tostringtag,tapec0c6c26- [Fix] Don't throw when
globalis not definedd4d0965- [meta] add missing
engines.node17a352a- [Dev Deps] update
globalthis9c08884- [Dev Deps] update
error-cause6af352d- [Dev Deps] update
npmignore94e617d- [Dev Deps] update
mock-property2ac24d7- [Dev Deps] update
tape46125e5
1.13.1 (from changelog)
Commits
- [Fix] in IE 8, global can !== window despite them being prototypes of each other
30d0859
1.13.0 (from changelog)
Commits
- [New] add special handling for the global object
431bab2- [Dev Deps] update
@ljharb/eslint-config,aud,tapefd4f619- [Dev Deps] update
mock-property,tapeb453f6c- [Dev Deps] update
error-causee8ffc57- [Dev Deps] update
tape054b8b9- [Dev Deps] temporarily remove
auddue to breaking change in transitive deps2476845- [Dev Deps] pin
glob, since v10.3.8+ requires a brokenjackspeak383fa5e- [Dev Deps] pin
jackspeaksince 2.1.2+ depends on npm aliases, which kill the install process in npm < 668c244c
1.12.3 (from changelog)
Commits
1.12.2 (from changelog)
Commits
1.12.1 (from changelog)
Commits
- [Tests] use
mock-property4ec8893- [meta] use
npmignoreto autogenerate an npmignore file07f868c- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,tapeb05244b- [Dev Deps] update
@ljharb/eslint-config,error-cause,es-value-fixtures,functions-have-names,taped037398- [Fix] properly handle callable regexes in older engines
848fe48
1.12.0 (from changelog)
Commits
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 61 commits:
v1.13.3[Fix] `quoteStyle`: properly escape only the containing quotes[Refactor] clean up `quoteStyle` code[actions] split out node 10-20, and 20+[Tests] add `quoteStyle` escaping tests[Tests] replace `aud` with `npm audit`[Dev Deps] update `auto-changelog`, `es-value-fixtures`, `tape`[Dev Deps] update `mock-property`v1.13.2[readme] update badges[Dev Deps] update `@ljharb/eslint-config`, `tape`[Fix] Don't throw when `global` is not defined[Dev Deps] update `globalthis`[Dev Deps] update `error-cause`[Dev Deps] update `error-cause`, `has-tostringtag`, `tape`[meta] add missing `engines.node`[Dev Deps] update `npmignore`[Dev Deps] update `mock-property`[Dev Deps] update `tape`v1.13.1[Fix] in IE 8, global can !== window despite them being prototypes of each otherv1.13.0[Dev Deps] update `error-cause`[Dev Deps] temporarily remove `aud` due to breaking change in transitive deps[New] add special handling for the global object[Dev Deps] pin `glob`, since v10.3.8+ requires a broken `jackspeak`[Dev Deps] update `mock-property`, `tape`[Dev Deps] update `tape`[Dev Deps] pin `jackspeak` since 2.1.2+ depends on npm aliases, which kill the install process in npm < 6[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`v1.12.3[Fix] in eg FF 24, collections lack forEach[Dev Deps] update `@ljharb/eslint-config`, `aud`, `error-cause`[Dev Deps] update `aud`, `es-value-fixtures`, `tape`[actions] update rebase action to use reusable workflow[Tests] add `@pkgjs/support` to `postlint`v1.12.2[meta] add support info[Fix] ignore `cause` in node v16.9 and v16.10 where it has a bug[Fix] use `util.inspect` for a custom inspection symbol methodv1.12.1[Fix] properly handle callable regexes in older engines[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `@ljharb/eslint-config`, `error-cause`, `es-value-fixtures`, `functions-have-names`, `tape`[Tests] use `mock-property`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`v1.12.0[meta] fix auto-changelog settings[New] ensure an Error’s `cause` is displayed[Dev Deps] update `eslint`, `@ljharb/eslint-config`[Robustness] cache more prototype methods[New] add `numericSeparator` boolean option[Robustness] cache `RegExp.prototype.test`1.11.1[meta] add `sideEffects` flag[meta] add `auto-changelog`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `safe-publish-latest`, `tape`[actions] update codecov uploader[Dev Deps] update `eslint`, `tape`[Refactor] use `has-tostringtag` to behave correctly in the presence of symbol shams
↗️ object.assign (indirect, 4.1.2 → 4.1.5) · Repo · Changelog
Release Notes
4.1.5 (from changelog)
- [meta] republish without testing HTML file (#85)
- [Deps] update
call-bind,define-properties- [Dev Deps] use
hasowninstead ofhas- [Dev Deps] update
@es-shims/api,@ljharb/eslint-config,aud,npmignore,mock-property,tape- [actions] update rebase action
4.1.4 (from changelog)
- [meta] fix
npmignoreintegration (#83)
4.1.3 (from changelog)
- [Refactor] make steps closer to actual spec
- [Refactor] simplify object coercible check
- [readme] remove defunct badges, add coverage and actions badges
- [eslint] ignore coverage output
- [meta] use
npmignoreto autogenerate an npmignore file- [meta] remove audit-level
- [Deps] update
call-bind,define-properties,has-symbols- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,aud,functions-have-names,safe-publish-latest,ses,tape- [actions] use
node/installinstead ofnode/run; usecodecovaction- [actions] reuse common workflows
- [actions] update codecov uploader
- [Tests] add implementation tests
- [Tests] use
mock-property- [Tests] disable posttest pending
audhandlingfile:deps- [Tests] migrate remaining tests to Github Actions (#81)
- [Tests] gitignore coverage output
- [Tests] test node v1-v9 on Github Actions instead of travis; resume testing all minors (#80)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 46 commits:
v4.1.5[Dev Deps] update `npmignore`[Deps] update `call-bind`, `define-properties`[Dev Deps] use `hasown` instead of `has`[Dev Deps] update `mock-property`, `tape`[Dev Deps] update `tape`[Dev Deps] update `tape`[Dev Deps] update `aud`[Dev Deps] update `@es-shims/api`, `@ljharb/eslint-config`[Deps] update `define-properties`[Dev Deps] update `@es-shims/api`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[actions] update rebase action[Dev Deps] update `aud`, `tape`[Dev Deps] update `tape`v4.1.4[meta] fix `npmignore` integrationv4.1.3[Refactor] make steps closer to actual spec[Tests] add implementation tests[meta] use `npmignore` to autogenerate an npmignore file[Tests] use `mock-property`[Deps] update `define-properties`[Dev Deps] update `@ljharb/eslint-config`, `functions-have-names`[Deps] update `has-symbols`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`[Refactor] simplify object coercible check[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[Dev Deps] update `eslint`, `tape`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `safe-publish-latest`, `tape`[Tests] disable posttest pending `aud` handling `file:` deps[actions] update workflows[actions] update codecov uploader[meta] remove audit-level[Deps] update `has-symbols`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `tape`[readme] remove defunct badges, add coverage and actions badges[actions] use `node/install` instead of `node/run`; use `codecov` action[eslint] ignore coverage output[Deps] update `call-bind`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `functions-have-names`, `ses`, `tape`[Dev Deps] update `ses`[Tests] migrate remaining tests to Github Actions[Tests] gitignore coverage output[Tests] test node v1-v9 on Github Actions instead of travis; resume testing all minors
↗️ object.values (indirect, 1.1.4 → 1.2.0) · Repo · Changelog
Release Notes
1.1.7 (from changelog)
Commits
1.1.6 (from changelog)
Commits
- [actions] reuse common workflows
4072b71- [meta] use
npmignoreto autogenerate an npmignore file6881278- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,array.prototype.map,safe-publish-latest,tape28c21e6- [Dev Deps] update
eslint,@ljharb/eslint-config,array.prototype.map,aud,auto-changelog,functions-have-names,tape0e78caa- [actions] update rebase action to use reusable workflow
6f37c60- [actions] update codecov uploader
d7c5f30- [Deps] update
define-properties,es-abstract911ca0e
1.1.5 (from changelog)
Commits
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 20 commits:
v1.2.0[New] add `auto` entrypoint[Refactor] use `es-object-atoms` instead of `es-abstract`; update `call-bind`, `define-properties`[Dev Deps] update `array.prototype.map`, `aud`, `npmignore`, `tape`v1.1.7[Deps] update `define-properties`, `es-abstract`[Dev Deps] update `@es-shims/api`, `@ljharb/eslint-config`, `aud`, `tape`v1.1.6[Deps] update `define-properties`, `es-abstract`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `array.prototype.map`, `aud`, `auto-changelog`, `functions-have-names`, `tape`[actions] update rebase action to use reusable workflow[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `array.prototype.map`, `safe-publish-latest`, `tape`[actions] update codecov uploaderv1.1.5[Robustness] use a call-bound `Array.prototype.push`[Deps] update `es-abstract`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `tape`[meta] npmignore coverage output
↗️ open (indirect, 7.4.2 → 10.1.0) · Repo
Release Notes
10.1.0
10.0.4
10.0.3
10.0.2
- Fix Linux compatibility 798cd93
10.0.1
10.0.0
Breaking
- Require Node.js 18 5628dc8
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 64 commits:
10.1.0Linux: Update `xdg-open` to 1.2.1 (#338)10.0.4Fix support for passing predefined app to `openApp()` (#335)10.0.3Fix `target` option on macOS (#332)10.0.2Fix Linux compatibility10.0.1Add Windows environment variable fallback for some broken systems (#328)10.0.0Require Node.js 18Test on Node.js 20 (#312)9.1.0Update dependencies9.0.0Require Node.js 14 and move to ESMAdd the ability to open default browser and default browser in private mode (#294)8.4.2Fix support for Podman8.4.1Meta tweaksFix `allowNonzeroExitCode` option (#296)Fix the `app` argument with WSL (#295)Meta tweaks8.4.0Improve ArchLinux support (#265)8.3.0Add `openApp` method (#263)Update readmeClarify docs about app arguments8.2.1Fix lintingGracefully handle reused array being passed in (#255)Remove outdate caveat in readme8.2.0Add `newInstance` option for macOS (#253)8.1.0Add `open.apps.edge` (#252)8.0.9Revert "Hide PowerShell window on Windows" (#250)8.0.8WSL: Ignore commented mount point lines in wsl.conf (#247)8.0.7Meta tweaksFix multiple apps support for `open.apps` (#245)8.0.6Fix getting WSL mount point on Windows (#243)8.0.5Fix `chrome` app on macOS (#240)8.0.4Fix the `app.argument` option (#237)8.0.3Hide PowerShell window on Windows (#235)8.0.2Memoize getting `mountPoint` (#232)Meta tweaks (#233)8.0.1Meta tweaksFix Node.js 12 compatibility (#229)8.0.0Require Node.js 12Detect architecture (#227)Require Node.js 10.17, add `.apps` and allow multiple apps to be tried (#222)
↗️ open-editor (indirect, 3.0.0 → 5.0.0) · Repo
Release Notes
5.0.0
Breaking
Improvements
4.1.1
4.1.0
4.0.0
Breaking
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 12 commits:
↗️ optionator (indirect, 0.9.1 → 0.9.4) · Repo · Changelog
↗️ p-try (indirect, 1.0.0 → 2.2.0) · Repo
Commits
See the full diff on Github. The new version differs by 9 commits:
↗️ path-type (indirect, 4.0.0 → 5.0.0) · Repo
Release Notes
5.0.0
Breaking
- Require Node.js 12 (#8) 24e52d3
- This package is now pure ESM
- This means you need to use
import {isFile} from 'path-type'instead ofconst {isFile} = require('path-type').- I would recommend moving to ESM. ESM can still import CommonJS packages, but CommonJS cannot import ESM packages synchronously.
- If you cannot move to ESM yet, don't upgrade to this version.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ picomatch (indirect, 2.3.0 → 2.3.1) · Repo · Changelog
Release Notes
2.3.1
Fixed
- Fixes bug when a pattern containing an expression after the closing parenthesis (
/!(*.d).{ts,tsx}) was incorrectly converted to regexp (9f241ef).Changed
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 13 commits:
2.3.1Merge pull request #102 from micromatch/ISSUE-93_incorrect_extglob_expandingfix: support stars in negation extglobs with expression after closing parenthesisMerge pull request #85 from XhmikosR/codeqlMerge pull request #91 from XhmikosR/patch-1Merge pull request #94 from peterblazejewicz/patch-1Merge pull request #98 from mojavelinux/document-automatic-lookbehind-detectiondocument that lookbehind detection is automaticdelete funding.ymlUpdate README.mdCreate FUNDING.ymlFix .eslintrc.jsonAdd CodeQL Action
↗️ pkg-dir (indirect, 4.2.0 → 5.0.0) · Repo
Commits
See the full diff on Github. The new version differs by 5 commits:
↗️ plur (indirect, 4.0.0 → 5.1.0) · Repo
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ prettier (indirect, 1.19.1 → 3.4.2) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ read-pkg (indirect, 3.0.0 → 5.2.0) · Repo
Release Notes
5.2.0
5.1.1
5.1.0
5.0.0
Breaking:
- Require Node.js 8 267b050
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 19 commits:
5.2.0Bump dependencies (#17)Fix readme example (#16)Tidelift tasksCreate funding.yml5.1.1Fix types for default value of `normalize` (#14)Add Node.js 12 to testing (#13)5.1.0Meta tweaksAdd TypeScript definition (#12)Fix Travis5.0.0Require Node.js 84.0.1Use `pify`4.0.0Remove the `path` arguments and drop BOM strippingRequire Node.js 6
↗️ read-pkg-up (indirect, 3.0.0 → 7.0.1) · Repo
Release Notes
7.0.1
- Documentation fix d96ce60
7.0.0
Breaking
- Rename
.packageto.packageJson8140c73
I'm really sorry about the churn. It was brought to my attention thatpackageis a reserved keyword, and it meant that the result could previously not be easily destructured.
6.0.0
Breaking:
- Rename
pkgproperty topackage(#10) 1c15896- Return
undefinedinstead of empty object when the package.json cannot be found (#10) 1c15896Enhancements:
5.0.0
Breaking:
- Require Node.js 8 4412fe2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 17 commits:
7.0.1Readme tweaksTidelift tasks7.0.0Update dependenciesRename `.package` to `.packageJson`Tidelift tasksCreate funding.yml6.0.0Rename `pkg` property to `package`, return `undefined` instead of empty object, add TypeScript definition (#10)Add Node.js 12 to testing (#9)5.0.0Require Node.js 8Upgrade `read-pkg` to v4 (#7)4.0.0Meta tweaksRequire Node.js 6 (#5)
↗️ regexp-tree (indirect, 0.1.23 → 0.1.27) · Repo
Sorry, we couldn’t find anything useful about this release.
↗️ resolve (indirect, 1.20.0 → 2.0.0-next.5) · Repo
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ schema-utils (indirect, 3.1.1 → 3.3.0) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 7 commits:
↗️ semver (indirect, 7.3.5 → 7.6.3) · Repo · Changelog
Security Advisories 🚨
🚨 semver vulnerable to Regular Expression Denial of Service
Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ serialize-javascript (indirect, 6.0.0 → 6.0.2) · Repo
Release Notes
6.0.2
6.0.1
What's Changed
- Bump mocha from 9.0.1 to 9.0.2 by @dependabot in #126
- Bump mocha from 9.0.2 to 9.0.3 by @dependabot in #127
- Bump path-parse from 1.0.6 to 1.0.7 by @dependabot in #129
- Bump mocha from 9.0.3 to 9.1.0 by @dependabot in #130
- Bump mocha from 9.1.0 to 9.1.1 by @dependabot in #131
- Bump mocha from 9.1.1 to 9.1.2 by @dependabot in #132
- Bump mocha from 9.1.2 to 9.1.3 by @dependabot in #133
- Bump mocha from 9.1.3 to 9.1.4 by @dependabot in #137
- Bump mocha from 9.1.4 to 9.2.0 by @dependabot in #138
- Bump chai from 4.3.4 to 4.3.6 by @dependabot in #140
- Bump ansi-regex from 5.0.0 to 5.0.1 by @dependabot in #141
- Bump mocha from 9.2.0 to 9.2.2 by @dependabot in #143
- Bump minimist from 1.2.5 to 1.2.6 by @dependabot in #144
- Bump mocha from 9.2.2 to 10.0.0 by @dependabot in #145
- Bump mocha from 10.0.0 to 10.1.0 by @dependabot in #149
- Bump chai from 4.3.6 to 4.3.7 by @dependabot in #150
- ci: test.yml - actions bump by @piwysocki in #151
- Bump minimatch from 3.0.4 to 3.1.2 by @dependabot in #152
- Bump mocha from 10.1.0 to 10.2.0 by @dependabot in #153
- Bump json5 from 2.1.3 to 2.2.3 by @dependabot in #155
- Fix serialization issue for 0n. by @momocow in #156
- Release v6.0.1 by @okuryu in #157
New Contributors
- @piwysocki made their first contribution in #151
- @momocow made their first contribution in #156
Full Changelog: v6.0.0...v6.0.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 28 commits:
6.0.2fix: serialize URL string contents to prevent XSS (#173)Bump @babel/traverse from 7.10.1 to 7.23.7 (#171)docs: update readme with URL support (#146)chore: update node version and lock filefix typo (#164)Release v6.0.1 (#157)Fix serialization issue for 0n. (#156)Bump json5 from 2.1.3 to 2.2.3 (#155)Bump mocha from 10.1.0 to 10.2.0 (#153)Bump minimatch from 3.0.4 to 3.1.2 (#152)ci: bump GitHub ActionsBump chai from 4.3.6 to 4.3.7 (#150)Bump mocha from 10.0.0 to 10.1.0 (#149)Bump mocha from 9.2.2 to 10.0.0 (#145)Bump minimist from 1.2.5 to 1.2.6 (#144)Bump mocha from 9.2.0 to 9.2.2 (#143)Bump ansi-regex from 5.0.0 to 5.0.1 (#141)Bump chai from 4.3.4 to 4.3.6 (#140)Bump mocha from 9.1.4 to 9.2.0 (#138)Bump mocha from 9.1.3 to 9.1.4 (#137)Bump mocha from 9.1.2 to 9.1.3 (#133)Bump mocha from 9.1.1 to 9.1.2 (#132)Bump mocha from 9.1.0 to 9.1.1 (#131)Bump mocha from 9.0.3 to 9.1.0 (#130)Bump path-parse from 1.0.6 to 1.0.7 (#129)Bump mocha from 9.0.2 to 9.0.3 (#127)Bump mocha from 9.0.1 to 9.0.2 (#126)
↗️ side-channel (indirect, 1.0.4 → 1.0.6) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 22 commits:
v1.0.6add types[meta] simplify `exports`[Deps] update `call-bind`[Dev Deps] update `tape`v1.0.5[Deps] update `get-intrinsic`[meta] add missing `engines.node`[Refactor] use `es-errors`, so things that only need those do not need `get-intrinsic`[Deps] update `call-bind`, `get-intrinsic`, `object-inspect`[Dev Deps] update `@ljharb/eslint-config`, `aud`, `npmignore`, `tape`[Deps] update `get-intrinsic`, `object-inspect`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `@ljharb/eslint-config`, `aud`, `tape`[actions] update rebase action[Tests] increase coverage[meta] add `.editorconfig`; add `eclint`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `tape`[Deps] update `object-inspect`[actions] reuse common workflows[Deps] update `call-bind`, `get-intrinsic`, `object-inspect`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `safe-publish-latest`, `tape`
↗️ signal-exit (indirect, 3.0.3 → 4.1.0) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 34 commits:
4.1.0add prettierignore fileremove incorrect line from changelogallow handler to capture signal exitsci: drop node 144.0.3increment by old signal-exit's count, not just 14.0.2chore: remove error logadd no longer setting process.exitCode to changelog4.0.1don't get confused by old versions of signal-exitupdate license yearc8 ignore a platform-specific line4.0.0v4 rewrite: hybrid module, TS, and named exportsci: tests and fundingchore: correct license copyright statementci: makework3.0.7dep updatesgracefully no-op unwrap function3.0.6More properly handle global.process mutatingupdate tap, use automated publish scripts3.0.5chore: update deps[Fix] unbreak v33.0.4gracefully no-op when process missing or invalidremove standardupdate depsdocs: correct spelling mistake (#48)fix: regenerate `pacakge-lock.json` file for npm ci
↗️ slash (indirect, 4.0.0 → 5.1.0) · Repo
Release Notes
5.1.0
5.0.1
5.0.0
Breaking
- Require Node.js 14 5c5d1d6
Improvements
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 8 commits:
↗️ source-map (indirect, 0.5.7 → 0.6.1) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 30 commits:
Merge pull request #290 from tromey/version-0.6.1Release version 0.6.1Merge pull request #289 from tromey/m-c-fixesHandle absolute source lookup in more methodsAdd aSourceMapURL parameter to SourceMapConsumer.fromSourceMapMerge pull request #287 from tromey/version-0.6.0Release version 0.6.0Merge pull request #288 from tromey/fix-issue-247Avoid undefined line in fromStringWithSourceMapMerge pull request #286 from tromey/fix-source-root-prependingChange sourceRoot resolution to match the specMerge pull request #279 from tromey/issue-258Handle null name in IndexedSourceMapConsumer._parseMappingsMerge pull request #283 from tromey/json-xssi-avoidanceRemove entire first line when JSON XSSI prevention seenMerge pull request #285 from tromey/url-parsing-fixSlightly loosen urlRegexpMerge pull request #280 from tromey/issue-227Normalize the sourceRoot in BasicSourceMapConsumerMerge pull request #281 from tromey/install-typings-fileAdd source-map.d.ts to files in package.jsonMerge pull request #277 from tromey/document-offsetsUpdate documentation to note basis of lines and columnsMerge pull request #276 from tromey/fix-hyphenMerge pull request #251 from dmurat/emptyMappingsFixMerge pull request #271 from mjesun/make-getters-overridablesMerge pull request #272 from iamstolis/patch-1Correctly parse URL where host includes "-"Fixing some comparatorsMake getters configurables/enumerables
↗️ source-map-support (indirect, 0.5.19 → 0.5.21) · Repo
Commits
See the full diff on Github. The new version differs by 11 commits:
0.5.21Merge pull request #257 from brettz9/register-hook-require0.5.20Update built filesAdd back missing unlink callMerge pull request #297 from tapjs/isaacs/do-not-break-on-missing-global-processfix: do not crash if process is not setfix(test): fix writeFileSync on newer node versionsfix: replace build.js curl call with node httpsMerge pull request #282 from evanw/dependabot/npm_and_yarn/http-proxy-1.18.1Bump http-proxy from 1.17.0 to 1.18.1
↗️ spdx-correct (indirect, 3.1.1 → 3.2.0) · Repo
Commits
See the full diff on Github. The new version differs by 15 commits:
3.2.0Merge pull request #40 from jslicense/contributorsAdd GitHub contributors link to READMERemove contributors list from package.jsonRemove author from package.jsonMerge pull request #39 from lkoskela/fix-transposition-for-lgplactions/setup-node@v3actions/checkout@v3Run CI GitHub Action for pull requestsFix transposition of LGPL patterns into a correct LGPL SDPX identifierReplace Travis CI with GitHub Actionstandard-markdown@6.0.0standard@14.3.4tape@5.0.1defence-cli@3.0.1
↗️ spdx-exceptions (indirect, 2.3.0 → 2.5.0) · Repo
Commits
See the full diff on Github. The new version differs by 8 commits:
↗️ spdx-license-ids (indirect, 3.0.10 → 3.0.20) · Repo
Commits
See the full diff on Github. The new version differs by 35 commits:
3.0.20update license list to v3.25.0 (2024-08-19)3.0.19npm audit fix3.0.18update license list to v3.24.0 (2024-05-22)Fix lint errorRemove ranges from deprecated IDs list3.0.17update license list to v3.23 (2024-02-08)3.0.16update license list to v3.22 (2023-10-05)3.0.15remove checking for ids endsWith +eslint@8.49.0tape@5.6.63.0.14update license list to v3.21 (2023-06-18)bump tape and eslint (#32)Configure GitHub Actions to run CI for PRs3.0.13update license list to v3.20 (2023-02-17) (#31)3.0.12update license list to v3.18 (2022-08-11)Update URLs in READMEnpm audit fixUpdate setup-node GitHub action3.0.11update license list to v3.15 (2021-11-14)Reimplement build.js without get-spdx-license-idsFix ESlint configuration@shinnn/eslint-config@7.0.0chalk@4.1.2eslint@8.2.0tape@5.3.1
↗️ string-width (indirect, 4.2.2 → 7.2.0) · Repo
Release Notes
7.2.0
- Handle more edge-cases be33439
7.1.0
7.0.0
Breaking
- Require Node.js 18 97b50e8
Improvements
- It now uses the most recent Unicode data, which fixes some false-positives 97b50e8
6.1.0
6.0.0
Breaking
Improvements
- Add
countAnsiEscapeCodesoption (#48) 6e6993b- Improve compatibility with some languages (#47) f85812f
5.1.2
5.1.1
- Fix incorrect default for
ambiguousIsNarrowoption 483baa1
5.1.0
5.0.1
5.0.0
Breaking
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 25 commits:
7.2.0Handle more edge-casesMeta tweaks7.1.0Meta tweaksImprove performance (#54)7.0.0Require Node.js 18 and use more recent Unicode data6.1.0Improve performance (#49)6.0.0Meta tweaksAdd `countAnsiEscapeCodes` option (#48)Use `Intl.Segmenter`, require Node.js v16 (#47)5.1.2Use `for..of` loop (#40)Add test for #2 (#39)5.1.1Fix incorrect default for `ambiguousIsNarrow` option5.1.0Add `ambiguousIsNarrow` option (#34)5.0.1Upgrade `strip-ansi` (#31)5.0.0Require Node.js 12 and move to ESM
↗️ string.prototype.trimend (indirect, 1.0.4 → 1.0.8) · Repo · Changelog
Release Notes
1.0.7 (from changelog)
Commits
1.0.6 (from changelog)
Commits
1.0.5 (from changelog)
Commits
- [actions] reuse common workflows
69a56ce- [actions] use
node/installinstead ofnode/run; usecodecovaction5d7db31- [Fix] ensure main entry point properly checks the receiver in ES3 engines
bb1983d- [Fix] as of unicode v6, the mongolian vowel separator is no longer whitespace
10a1091- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,safe-publish-latest,tapea08e14b- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,functions-have-names,tape1c4c8da- [actions] update codecov uploader
70c4a7c- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,aud,auto-changelog,tape4b08ed7- [readme] add github actions/codecov badges
9805501- [Dev Deps] update
eslint,tape50ec335- [actions] update workflows
bf9c32e- [meta] use
prepublishOnlyscript for npm 7+9d921bd- [Deps] update
define-properties15617ce
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 25 commits:
v1.0.8[Refactor] replace `es-abstract` with `es-object-atoms`[Dev Deps] update `aud`, `npmignore`, `tape`v1.0.7[Deps] update `define-properties`, `es-abstract`[Dev Deps] update `@es-shims/api`, `@ljharb/eslint-config`, `aud`, `tape`v1.0.6[Deps] update `es-abstract`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `aud`, `tape`[actions] update rebase action to use reusable workflowv1.0.5[Deps] update `define-properties`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `functions-have-names`, `tape`[Fix] as of unicode v6, the mongolian vowel separator is no longer whitespace[Fix] ensure main entry point properly checks the receiver in ES3 engines[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `safe-publish-latest`, `tape`[actions] update codecov uploader[readme] add github actions/codecov badges[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `aud`, `auto-changelog`, `tape`[actions] update workflows[Dev Deps] update `eslint`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
↗️ string.prototype.trimstart (indirect, 1.0.4 → 1.0.8) · Repo · Changelog
Release Notes
1.0.7 (from changelog)
Commits
1.0.6 (from changelog)
Commits
1.0.5 (from changelog)
Commits
- [actions] reuse common workflows
61d4009- [actions] use
node/installinstead ofnode/run; usecodecovactionbfe39c4- [Fix] ensure main entry point properly checks the receiver in ES3 engines
36e3730- [Fix] as of unicode v6, the mongolian vowel separator is no longer whitespace
4f77eed- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,safe-publish-latest,tape59fcb99- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,functions-have-names,tape486ffcf- [actions] update codecov uploader
b33ac48- [Dev Deps] update
eslint,@ljharb/eslint-config,@es-shims/api,aud,auto-changelog,tape3c89fa5- [readme] add github actions/codecov badges
00be6b3- [Dev Deps] update
eslint,tape13a08f5- [actions] update workflows
6ac576d- [meta] use
prepublishOnlyscript for npm 7+fa382ca- [Deps] update
define-propertiesd57bffe
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 28 commits:
v1.0.8[Deps] update `call-bind`, `define-properties`[Refactor] use `es-object-atoms` instead of `es-abstract`[Dev Deps] update `aud`, `npmignore`, `tape`[meta] add missing `engines.node`[actions] use reusable workflowsv1.0.7[Deps] update `define-properties`, `es-abstract`[Dev Deps] update `@es-shims/api`, `@ljharb/eslint-config`, `aud`, `tape`v1.0.6[Deps] update `es-abstract`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `aud`, `tape`[actions] update rebase action to use reusable workflowv1.0.5[Deps] update `define-properties`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `functions-have-names`, `tape`[Fix] ensure main entry point properly checks the receiver in ES3 engines[Fix] as of unicode v6, the mongolian vowel separator is no longer whitespace[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `safe-publish-latest`, `tape`[actions] update codecov uploader[readme] add github actions/codecov badges[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `@es-shims/api`, `aud`, `auto-changelog`, `tape`[actions] update workflows[Dev Deps] update `eslint`, `tape`[actions] use `node/install` instead of `node/run`; use `codecov` action[meta] use `prepublishOnly` script for npm 7+
↗️ strip-ansi (indirect, 6.0.0 → 6.0.1) · Repo
↗️ strip-final-newline (indirect, 2.0.0 → 4.0.0) · Repo
Release Notes
4.0.0
Breaking
- Require Node.js 18 (#7) 077250c
- When specifying a
Uint8Array, the returned value is no longer copied. Learn moreImprovements
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 13 commits:
⁉️ strip-indent (downgrade, 4.0.0 → 3.0.0) · Repo
Commits
See the full diff on Github. The new version differs by 27 commits:
3.0.0Meta tweaksRequire Node.js 8, add TypeScript definition (#6)Meta tweaksUse min-indent (#4)Meta tweaksUse variable `str` in readme example (#2)Update .travis.yml2.0.0[breaking] ES2015ify and extract CLIbump depsUse `meow` in CLIminor package.json tweaks1.0.1bump depsUpdate .travis.yml1.0.0tweaksUpdate readme.mdsimplify regex0.1.30.1.2simplify0.1.1ignore whitespace-only lines0.1.0init
↗️ supports-hyperlinks (indirect, 2.2.0 → 3.1.0) · Repo
Release Notes
3.1.0
3.0.0
Breaking
- Require Node.js 14
Improvements
2.3.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 11 commits:
↗️ terser (indirect, 5.7.1 → 5.37.0) · Repo · Changelog
Security Advisories 🚨
🚨 Terser insecure use of regular expressions leads to ReDoS
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ terser-webpack-plugin (indirect, 5.1.4 → 5.3.10) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ to-absolute-glob (indirect, 2.0.2 → 3.0.0) · Repo
Commits
See the full diff on Github. The new version differs by 6 commits:
↗️ tsconfig-paths (indirect, 3.10.1 → 3.15.0) · Repo · Changelog
Release Notes
3.14.2 (from changelog)
Fixed
- bump JSON5 from v1.0.1 to v1.0.2 in tsconfig-paths v3.14.1 to fix CVE-2022-46175 #234. See PR #234. Thanks to @mihaiplesa for this PR!
3.14.1 (from changelog)
Fixed
- Use minimist 1.2.6 for all depencencies becuase of pollution vulnerability. See PR #197. Thanks to @gopijaganthan for this fix!
3.14.0 (from changelog)
Added
- Support for path mapping starting with
/. See PR #180, issue #113, and issue #128. Thanks to @benevbright for this fix!
3.13.0 (from changelog)
Fixed
- Include file extension in paths resolved from package.json "main" field. See PR #135 and issue #133. Thanks to @katywings for this fix!
3.12.0 (from changelog)
- Add support for baseUrl override using TS_NODE_BASEURL env var #185 and #114. Thanks to @ejhayes and @information-security for these PRs!
3.11.0 (from changelog)
- Reverted upgrade of json5 due to being a breaking change. See PR #173.
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 31 commits:
v3.15.0Changelog for 3.15.0Add support for extends as array of strings to v3 (backport of #245) (#260)v3.14.2bump jsot5 to fix CVE-2022-46175 (#234)v3.14.1Update changelog for 3.14.1Use minimist 1.2.6 for all depsFixing pollution vulnerability in minimist (#197)v3.14.0Update changelog for 3.14Fix the root path (#180)v3.13.0Update changelog for 3.13.0Add missing extensionsfix: regard file extensions during path resolution (#133) (#193)Remove old publish scriptChange testing framework to Jest (#186)Codecov now uses github actionsFix coverage filenameRemove travisUpdate build badgeFix coverage filenameAdd github actionsv3.12.0Update changelog for 3.12.0Add support for baseUrl override using TS_NODE_BASEURL env var (#185)Clarify bootstrappingv3.11.0Update changelog for 3.11.0Revert "deps: bump json5 to use type definition provided officially (#158)" (#173)
↗️ tslib (indirect, 1.14.1 → 2.8.1) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ typescript (indirect, 4.3.5 → 5.7.2) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ unbox-primitive (indirect, 1.0.1 → 1.0.2) · Repo · Changelog
Release Notes
1.0.2 (from changelog)
Commits
- [actions] reuse common workflows
e6420b9- [actions] update codecov uploader
b90aff2- [readme] add github actions/codecov badges; update URLs
bcc39b9- [Dev Deps] update
eslint,@ljharb/eslint-config,object-inspect,safe-publish-latest,tapea704a32- [Refactor] use
call-bindinstead offunction-bind0a609f1- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,object-inspect,safe-publish-latest,tape6a45317- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,object-inspect,tape795c76f- [Deps] update
has-bigints,has-symbols257a065
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 9 commits:
v1.0.2[Deps] update `has-bigints`, `has-symbols`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `object-inspect`, `tape`[Refactor] use `call-bind` instead of `function-bind`[actions] reuse common workflows[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `object-inspect`, `safe-publish-latest`, `tape`[readme] add github actions/codecov badges; update URLs[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `object-inspect`, `safe-publish-latest`, `tape`[actions] update codecov uploader
↗️ watchpack (indirect, 2.2.0 → 2.4.2) · Repo
Release Notes
2.4.2
Bugfixes
- handle empty strings and arrays in ignored
2.4.1
Bugfixes
- do not report directory as initial missing on the second watch
2.4.0
Bugfixes
- respect filesystem accuracy more accurately
2.3.0
Features
- allow to grab separate file and directory time info objects
- allow functions passed to the
ignoredoptionBugfixes
- ignore EACCESS errors during initial scan
Performance
- improve performance of watcher update
Contributing
- CI tests node.js 17 too
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 57 commits:
chore(release): 2.4.2fix: ignore empty strings in an arrayfix: ignore empty strings in an arrayfix: handle an empty array for the `ignored` optionfix: ignore empty string tootest: fixfix: handle an empty array for the ignored optionci: fixci: fixchore(release): 2.4.1fix: do not report directory as initial missing on the second watchtest: morefix: logicrefactor: remove debug codefix: do not report directory as initial missing on the second watchchore(deps): regenerate lock filerefactor: update scriptsstyle: fixchore(deps): regenerate lock filedocs: fix badgedocs: fix badgeci: migrate on github actionsdocs: update readmeci: fix codecov tokenci: migrate on github actions2.4.0Merge pull request #215 from markjm/markjm/repsect-fs-accuracyrespect FS_ACCURACY2.3.1Merge pull request #212 from webpack/bugfix/context-time-infoadd test caseset file info for directories tooreport time info for directories correctly2.3.0Merge pull request #211 from webpack/bugfix/missing-infofix missing time info in filesMerge pull request #205 from markjm/markjm/splitMerge pull request #210 from webpack/ci/no-macos-pollingMerge branch 'main' into markjm/splitMerge pull request #197 from markjm/markjm/watch-changeprovide additional method instead of changing existing onedisable testing polling for macos ciMerge pull request #208 from webpack/perf/update-watchersrename branch to mainimprove watcher update performancefix typoavoid RegexpLike in favor of a functionMerge pull request #203 from rishabh3112/patch-1Merge pull request #207 from webpack/bugfix/ignore-permission-warningsMerge pull request #206 from markjm/markjm/stabilize-testsavoid EACCES permission errorstest: fix instability in polling testsSupport splitting of files and directories in getTimeInfoEntriesAllow function in watchOptions.ignoredchore: add node v17 in CIMerge pull request #191 from webpack/dependabot/npm_and_yarn/handlebars-4.7.7Merge pull request #192 from webpack/dependabot/npm_and_yarn/lodash-4.17.21
↗️ webpack (indirect, 5.49.0 → 5.97.1) · Repo
Security Advisories 🚨
🚨 Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
Summary
We discovered a DOM Clobbering vulnerability in Webpack’s
AutoPublicPathRuntimeModule. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., animgtag with an unsanitizednameattribute) are present.We found the real-world exploitation of this gadget in the Canvas LMS which allows XSS attack happens through an javascript code compiled by Webpack (the vulnerable part is from Webpack). We believe this is a severe issue. If Webpack’s code is not resilient to DOM Clobbering attacks, it could lead to significant security vulnerabilities in any web application using Webpack-compiled code.
Details
Backgrounds
DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. More for information about DOM Clobbering, here are some references:
[1] https://scnps.co/papers/sp23_domclob.pdf
[2] https://research.securitum.com/xss-in-amp4email-dom-clobbering/Gadgets found in Webpack
We identified a DOM Clobbering vulnerability in Webpack’s
AutoPublicPathRuntimeModule. When theoutput.publicPathfield in the configuration is not set or is set toauto, the following code is generated in the bundle to dynamically resolve and load additional JavaScript files:/******/ /* webpack/runtime/publicPath */ /******/ (() => { /******/ var scriptUrl; /******/ if (__webpack_require__.g.importScripts) scriptUrl = __webpack_require__.g.location + ""; /******/ var document = __webpack_require__.g.document; /******/ if (!scriptUrl && document) { /******/ if (document.currentScript) /******/ scriptUrl = document.currentScript.src; /******/ if (!scriptUrl) { /******/ var scripts = document.getElementsByTagName("script"); /******/ if(scripts.length) { /******/ var i = scripts.length - 1; /******/ while (i > -1 && (!scriptUrl || !/^http(s?):/.test(scriptUrl))) scriptUrl = scripts[i--].src; /******/ } /******/ } /******/ } /******/ // When supporting browsers where an automatic publicPath is not supported you must specify an output.publicPath manually via configuration /******/ // or pass an empty string ("") and set the __webpack_public_path__ variable from your code to use your own logic. /******/ if (!scriptUrl) throw new Error("Automatic publicPath is not supported in this browser"); /******/ scriptUrl = scriptUrl.replace(/#.*$/, "").replace(/\?.*$/, "").replace(/\/[^\/]+$/, "/"); /******/ __webpack_require__.p = scriptUrl; /******/ })();However, this code is vulnerable to a DOM Clobbering attack. The lookup on the line with
document.currentScriptcan be shadowed by an attacker, causing it to return an attacker-controlled HTML element instead of the current script element as intended. In such a scenario, thesrcattribute of the attacker-controlled element will be used as thescriptUrland assigned to__webpack_require__.p. If additional scripts are loaded from the server,__webpack_require__.pwill be used as the base URL, pointing to the attacker's domain. This could lead to arbitrary script loading from the attacker's server, resulting in severe security risks.PoC
Please note that we have identified a real-world exploitation of this vulnerability in the Canvas LMS. Once the issue has been patched, I am willing to share more details on the exploitation. For now, I’m providing a demo to illustrate the concept.
Consider a website developer with the following two scripts,
entry.jsandimport1.js, that are compiled using Webpack:// entry.js import('./import1.js') .then(module => { module.hello(); }) .catch(err => { console.error('Failed to load module', err); });// import1.js export function hello () { console.log('Hello'); }The webpack.config.js is set up as follows:
const path = require('path'); module.exports = { entry: './entry.js', // Ensure the correct path to your entry file output: { filename: 'webpack-gadgets.bundle.js', // Output bundle file path: path.resolve(__dirname, 'dist'), // Output directory publicPath: "auto", // Or leave this field not set }, target: 'web', mode: 'development', };When the developer builds these scripts into a bundle and adds it to a webpage, the page could load the
import1.jsfile from the attacker's domain,attacker.controlled.server. The attacker only needs to insert animgtag with thenameattribute set tocurrentScript. This can be done through a website's feature that allows users to embed certain script-less HTML (e.g., markdown renderers, web email clients, forums) or via an HTML injection vulnerability in third-party JavaScript loaded on the page.<!DOCTYPE html> <html> <head> <title>Webpack Example</title> <!-- Attacker-controlled Script-less HTML Element starts--!> <img name="currentScript" src="https://attacker.controlled.server/"></img> <!-- Attacker-controlled Script-less HTML Element ends--!> </head> <script src="./dist/webpack-gadgets.bundle.js"></script> <body> </body> </html>Impact
This vulnerability can lead to cross-site scripting (XSS) on websites that include Webpack-generated files and allow users to inject certain scriptless HTML tags with improperly sanitized name or id attributes.
Patch
A possible patch to this vulnerability could refer to the Google Closure project which makes itself resistant to DOM Clobbering attack: https://github.com/google/closure-library/blob/b312823ec5f84239ff1db7526f4a75cba0420a33/closure/goog/base.js#L174
/******/ /* webpack/runtime/publicPath */ /******/ (() => { /******/ var scriptUrl; /******/ if (__webpack_require__.g.importScripts) scriptUrl = __webpack_require__.g.location + ""; /******/ var document = __webpack_require__.g.document; /******/ if (!scriptUrl && document) { /******/ if (document.currentScript && document.currentScript.tagName.toUpperCase() === 'SCRIPT') // Assume attacker cannot control script tag, otherwise it is XSS already :> /******/ scriptUrl = document.currentScript.src; /******/ if (!scriptUrl) { /******/ var scripts = document.getElementsByTagName("script"); /******/ if(scripts.length) { /******/ var i = scripts.length - 1; /******/ while (i > -1 && (!scriptUrl || !/^http(s?):/.test(scriptUrl))) scriptUrl = scripts[i--].src; /******/ } /******/ } /******/ } /******/ // When supporting browsers where an automatic publicPath is not supported you must specify an output.publicPath manually via configuration /******/ // or pass an empty string ("") and set the __webpack_public_path__ variable from your code to use your own logic. /******/ if (!scriptUrl) throw new Error("Automatic publicPath is not supported in this browser"); /******/ scriptUrl = scriptUrl.replace(/#.*$/, "").replace(/\?.*$/, "").replace(/\/[^\/]+$/, "/"); /******/ __webpack_require__.p = scriptUrl; /******/ })();Please note that if we do not receive a response from the development team within three months, we will disclose this vulnerability to the CVE agent.
🚨 Cross-realm object access in Webpack 5
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗️ webpack-sources (indirect, 3.2.0 → 3.2.3) · Repo
Release Notes
3.2.2
Bugfixes
- Source Code is splitted into lines via custom code instead of using a RegExp
- In weird edge cases the RegExp caused a Stack Overflow
3.2.1
Bugfixes
RawSourceswith Buffers can now be concatenated withConcatSource- Source Code is splitted into lines via custom code instead of using a RegExp
- In weird edge cases the RegExp caused a Stack Overflow
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 25 commits:
3.2.3Merge pull request #143 from doniyor2109/avount_regexavoid regex3.2.2Merge pull request #142 from webpack/bugfix/no-regexrewrite regexp to split function3.2.1Merge pull request #137 from webpack/dependabot/npm_and_yarn/ws-7.5.5Merge pull request #107 from webpack/dependabot/npm_and_yarn/lodash-4.17.21Merge pull request #112 from webpack/dependabot/npm_and_yarn/glob-parent-5.1.2Merge pull request #108 from webpack/dependabot/npm_and_yarn/hosted-git-info-2.8.9Merge pull request #106 from webpack/dependabot/npm_and_yarn/handlebars-4.7.7Merge pull request #136 from webpack/dependabot/npm_and_yarn/y18n-4.0.3Bump ws from 7.3.1 to 7.5.5Bump glob-parent from 5.1.1 to 5.1.2Bump lodash from 4.17.20 to 4.17.21Merge pull request #135 from webpack/bugfix/string-match-overflowBump y18n from 4.0.0 to 4.0.3Bump handlebars from 4.7.6 to 4.7.7Bump hosted-git-info from 2.8.8 to 2.8.9Merge pull request #130 from webpack/dependabot/npm_and_yarn/path-parse-1.0.7avoid splitting into lines via regexpMerge pull request #134 from webpack/bugfix/concat-bufferadd support for concatenating Buffer RawSourcesBump path-parse from 1.0.6 to 1.0.7
↗️ which-boxed-primitive (indirect, 1.0.2 → 1.1.0) · Repo · Changelog
Release Notes
1.1.0 (from changelog)
Commits
- [actions] reuse common workflows
893df44- [meta] use
npmignoreto autogenerate an npmignore filebab1ff8- [Tests] use
es-value-fixturesandfor-eachecacfa0- [New] add types
ab38e78- [actions] split out node 10-20, and 20+
7ee9c3c- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,object-inspect,safe-publish-latest,tape142215a- [Dev Deps] update
eslint,@ljharb/eslint-config,aud,auto-changelog,has-symbols,object-inspect,tape3559371- [actions] update rebase action to use reusable workflow
928901a- [Deps] update
is-bigint,is-boolean-object,is-number-object,is-string,is-symbolf7b14be- [Dev Deps] update
@ljharb/eslint-config,auto-changelog,npmignore,object-inspect,tape5296738- [Deps] update
is-bigint,is-boolean-object,is-number-object,is-string,is-symbolcaa6d1c- [meta] add missing
engines.nodeca40880- [Tests] replace
audwithnpm auditb0f4069- [Dev Deps] update
aud8d0e336- [Deps] update
is-number-objecteafcabf- [Dev Deps] add missing peer dep
ec4dd52
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 17 commits:
v1.1.0[meta] add missing `engines.node`[New] add types[Deps] update `is-bigint`, `is-boolean-object`, `is-number-object`, `is-string`, `is-symbol`[Tests] use `es-value-fixtures` and `for-each`[Dev Deps] add missing peer dep[Dev Deps] update `@ljharb/eslint-config`, `auto-changelog`, `npmignore`, `object-inspect`, `tape`[actions] split out node 10-20, and 20+[Tests] replace `aud` with `npm audit`[Dev Deps] update `aud`[Deps] update `is-number-object`[meta] use `npmignore` to autogenerate an npmignore file[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `has-symbols`, `object-inspect`, `tape`[actions] update rebase action to use reusable workflow[actions] reuse common workflows[Deps] update `is-bigint`, `is-boolean-object`, `is-number-object`, `is-string`, `is-symbol`[Dev Deps] update `eslint`, `@ljharb/eslint-config`, `aud`, `auto-changelog`, `object-inspect`, `safe-publish-latest`, `tape`
↗️ word-wrap (indirect, 1.2.3 → 1.2.5) · Repo
Security Advisories 🚨
🚨 word-wrap vulnerable to Regular Expression Denial of Service
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Release Notes
1.2.5
Changes:
Reverts default value for
options.indentto two spaces' '.Full Changelog: 1.2.4...1.2.5
1.2.4
What's Changed
- Remove default indent by @mohd-akram in #24
🔒 fix: CVE 2023 26115 (2) by @OlafConijn in #41🔒 fix: CVE-2023-26115 by @aashutoshrathi in #33- chore: publish workflow by @OlafConijn in #42
New Contributors
- @mohd-akram made their first contribution in #24
- @OlafConijn made their first contribution in #41
- @aashutoshrathi made their first contribution in #33
Full Changelog: 1.2.3...1.2.4
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 16 commits:
1.2.5revert default indentrun verb to generate READMEMerge pull request #42 from jonschlinkert/chore/publish-workflowMerge pull request #41 from jonschlinkert/fix/CVE-2023-26115-2Update .github/workflows/publish.ymlchore: bump version to 1.2.4chore: add publish workflowchore: fix testchore: remove package-lockchore: added an additional testcasefix: cve 2023-26115fix: settle for new regex to support lower node versions:lock: fix: CVE-2023-26115Merge pull request #24 from mohd-akram/remove-default-indentRemove default indent