🚨 [security] Update chai 4.2.0 → 4.5.0 (minor) #140
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ chai (4.2.0 → 4.5.0) · Repo · Changelog
Release Notes
4.5.0
4.4.1
4.3.10
4.3.9
4.3.8
4.3.7
4.3.6
4.3.5
4.3.4
4.3.3
4.3.1
4.3.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Commits
See the full diff on Github. The new version differs by 8 commits:
1.0.3upgrade depsMerge pull request #12 from lucasfcosta/external-get-func-namechore: use external get-func-name modulefix: adapt getConstructorName to work with more robust version of getFunctionNameMerge pull request #10 from vieiralucas/patch-1Add @vieiralucas to MAINTAINERSfix: anonymous functions on node 6.5 and aboveCommits
See the full diff on Github. The new version differs by 36 commits:
fix: catch fake collections throwing (#100) (#101)feat: only compare enumerable symbols (#91)fix benchmarkssort package.jsonremove semantic-release, ghooks, validate-commit-msgchore: upgrade depsapply development version number to package.jsonCreate publish.ymlfix: multiple symbols and sort fails - Cannot convert a Symbol value to a string (#83)4.1.1fix: TypeError: Cannot convert a Symbol value to a string (#89)4.1.0feat: add support for Temporal objects (#88)4.0.1fixup package lockfix: deep symbol comparison (#81)Merge pull request #68 from koddsson/update-the-last-of-the-dependenciesClean up the README a bit (#71)chore: update `lcov-result-merger` to latest versionchore: run `npm audit fix --force`chore: remove componentchore: update various dependenciesfix branch name in GitHub CI action (#75)ci: replace phantomjs with chrome (#72)chore: remove watchify (#73)Update README.mddocs: add deep-eql-logo to README (#50)chore: eslint and friends (#67)chore: update some dev dependencies (#66)GitHub CI (#69)chore: roll npm tokenbuild: add npmrc before whoamibuild: output npm username during buildchore: roll travis secure keysfeat: change error comparison algorithm again (#59)feat: change error comparison algorithm (#57)Security Advisories 🚨
🚨 Chaijs/get-func-name vulnerable to ReDoS
Commits
See the full diff on Github. The new version differs by 29 commits:
2.0.2fix GHSA-4q6p-r6v2-jvc5Merge pull request #23 from lucasfcosta/release-return-null-for-non-functionchore: getFuncName returns null for non function.Merge pull request #22 from lucasfcosta/return-null-for-non-function-releasechore: BREAKING CHANGE getFuncName returning null for non-function argumentsMerge pull request #20 from lucasfcosta/return-null-for-non-functionchore: return null when passed a non-function argumentMerge pull request #21 from chaijs/remove-lgtmDelete MAINTAINERSMerge pull request #19 from chaijs/vieiralucas-patch-1Center repo name on READMEMerge pull request #14 from vieiralucas/refact-testschore(test): split single test into multiple testsMerge pull request #9 from chaijs/greenkeeper-mocha-3.1.2chore(package): update mocha to version 3.1.2Merge pull request #12 from lucasfcosta/fix-eslint-versionchore: fix eslint dependency versionMerge pull request #2 from chaijs/greenkeeper-update-allMerge pull request #7 from lucasfcosta/new-repo-namefix(repo-name): fix whole repo structure for releasing with the new nameMerge pull request #8 from chaijs/add-travis-keyschore(travis): configure secure varsMerge pull request #5 from lucasfcosta/new-repo-namefeat: get available name on NPMchore(package): update dependenciesMerge pull request #1 from lucasfcosta/full-repochore: initial implementationInitial CommitSecurity Advisories 🚨
🚨 Prototype pollution in pathval
Release Notes
1.1.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 12 commits:
chore: v1.1.1Merge pull request #60 from deleonio/fix/vulnerability-prototype-pollutionstyle: correct rule in package.jsonfix: prototype pollution vulnerability + working testschore: remove very old nodejschore: update deps and tool configurationMerge pull request #55 from chaijs/remove-lgtmDelete MAINTAINERSMerge pull request #54 from astorije/patch-1Center repo name on READMEMerge pull request #45 from lucasfcosta/update-docs-for-setdocs: explicitly mention that setPathValue returns the target objectRelease Notes
4.1.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 18 commits:
Add a GitHub action for CI (#147)Update dependencies (#148)Fix deno link (#149)Merge pull request #142 from chaijs/feat-add-support-for-denoMerge pull request #141 from chaijs/readme-tweaksdocs: pre-empt 4.1.0 release in deno import statementdocs: use deno.land/x/ proxy for importdocs: fix deno import statementchore: npm audit fixfeat: add support for Denofix: use globalThis polyfill to get globalObjectfeat: switch to typescriptUpdate README.mdMerge pull request #128 from chaijs/add-type-detect-logo-readmeMerge pull request #140 from bricksphd/bricksphd-patch-1Clarify browser usage. #139Merge pull request #136 from koddsson/patch-1chore: remove xvfb pre-test step in travis🆕 loupe (added, 2.3.7)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands