π¨ [security] Update @restorecommerce/gql-bot 1.0.8 β 1.0.9 (patch) #100
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ @βrestorecommerce/gql-bot (1.0.8 β 1.0.9) Β· Repo Β· Changelog
Release Notes
1.0.9 (from changelog)
Does any of this look wrong? Please let us know.
Security Advisories π¨
π¨ graphql Uncontrolled Resource Consumption vulnerability
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Security Advisories π¨
π¨ node-fetch Inefficient Regular Expression Complexity
π¨ node-fetch forwards secure headers to untrusted sites
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
4.1.2
4.1.1
4.1.0
4.0.2
4.0.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 56 commits:
Release 4.1.2.Update ci release and build scriptsUpdate jsbtMerge pull request #205 from Chocobozzz/patch-1Fix broken stream on normal flow errorBump micro-should devdepRelease 4.1.1.Fix esm testsFix type module. Closes gh-203Release 4.1.0.READMERemove garbage from jsrConsolidate ci workflows, add jsr.jsonMore comments.ci: add lintRename ciMerge workflowsFix lintFix deno and bunTest in bun and denoSwitch tests from mocha to micro-shouldMove tests to ESM. Switch from nyc to c8. Pass in deno, bunBump min nodejs from 14.16 to 14.18 for node prefixUse node: imports. Use ts isolatedDeclarations.Fix types of readdirpPromiseDitch enumsfix(#201): typings (#202)Release 4.0.2.Switch back to async stat / lstattsc: disable source mapsMerge pull request #199 from yuheiy/fix-promise-typingimprove typing for readdirpPromiseMerge pull request #198 from karlhorky/patch-1Remove fileFilter "array of strings" from readmeRemove nodejs v14 from ci, macos-arm does not have itFix cireadmeRemove dependabotREADMERelease 4.0.1.Fix esm importRelease 4.0.0.readmeUpgrade devdepsLintreadmeRewrite in typescript. Use hybrid ESM/commonjsEnable GitHub SponsorsFundingChange versionRemove glob supportUpdate dependabot.ymlMerge pull request #177 from paulmillr/dependabot/add-v2-config-fileUpgrade to GitHub-native DependabotMerge pull request #174 from BlackYuzia/mastertypo fix in readmeCommits
See the full diff on Github. The new version differs by 28 commits:
chore(publish): 4.0.0Merge pull request #55 from benlesh/various-fixeschore: remove Node 0.10. Unfortunately, we can't build with tsc in this environment, because of a TS incompatibilityrefactor: Revert to `symbol` from `unique symbol`.docs: Be more specific about the nature of this pony/polyfillchore: update copyright yearfix: If Symbol.for doesn't exist, just use Symbolchore(deps): bump lodash from 4.17.4 to 4.17.20 (#52)chore: update TypeScriptchore(publish): 3.0.0fix(TypeScript): `Symbol.observable` is now `unique symbol`.fix(TypeScript): `Symbol[Symbol.observable]` is no longer incorrectly definedchore(publish): 2.0.3Add ponyfill.d.ts to release file allow-list (#51)chore(publish): 2.0.2Add ponyfill TypeScript type definitions (#50)chore(publish): 2.0.1fix(package.json): es/ponyfill.js no longer typoedAdd note for possible breaking change.chore(publish): 2.0.0fix: Resolve issues in environments with frozen SymbolUpdate package.json (#46)Merge pull request #45 from MichaelDeBoey/patch-1Update .travis.ymlTypo fix (#39)cleanup readme example observable (#36)docs(README): add more information about usage.Rename readme.md to README.mdSorry, we couldn't find anything useful about this release.
π @βapollo/client (added, 3.14.0)
π @βgraphql-typed-document-node/core (added, 3.2.0)
π @βwry/caches (added, 1.0.1)
π @βwry/trie (added, 0.5.0)
π data-uri-to-buffer (added, 4.0.1)
π fetch-blob (added, 3.2.0)
π formdata-polyfill (added, 4.0.10)
π hoist-non-react-statics (added, 3.3.2)
π loose-envify (added, 1.4.0)
π node-domexception (added, 1.0.0)
π object-assign (added, 4.1.1)
π prop-types (added, 15.8.1)
π rehackt (added, 0.1.0)
π web-streams-polyfill (added, 3.3.3)
π chalk (added, 5.6.2)
π react-is (added, 16.13.1)
ποΈ @βesbuild/aix-ppc64 (removed)
ποΈ @βesbuild/aix-ppc64 (removed)
ποΈ @βesbuild/android-arm (removed)
ποΈ @βesbuild/android-arm (removed)
ποΈ @βesbuild/android-arm64 (removed)
ποΈ @βesbuild/android-arm64 (removed)
ποΈ @βesbuild/android-x64 (removed)
ποΈ @βesbuild/android-x64 (removed)
ποΈ @βesbuild/darwin-arm64 (removed)
ποΈ @βesbuild/darwin-arm64 (removed)
ποΈ @βesbuild/darwin-x64 (removed)
ποΈ @βesbuild/darwin-x64 (removed)
ποΈ @βesbuild/freebsd-arm64 (removed)
ποΈ @βesbuild/freebsd-arm64 (removed)
ποΈ @βesbuild/freebsd-x64 (removed)
ποΈ @βesbuild/freebsd-x64 (removed)
ποΈ @βesbuild/linux-arm (removed)
ποΈ @βesbuild/linux-arm (removed)
ποΈ @βesbuild/linux-arm64 (removed)
ποΈ @βesbuild/linux-arm64 (removed)
ποΈ @βesbuild/linux-ia32 (removed)
ποΈ @βesbuild/linux-ia32 (removed)
ποΈ @βesbuild/linux-loong64 (removed)
ποΈ @βesbuild/linux-loong64 (removed)
ποΈ @βesbuild/linux-mips64el (removed)
ποΈ @βesbuild/linux-mips64el (removed)
ποΈ @βesbuild/linux-ppc64 (removed)
ποΈ @βesbuild/linux-ppc64 (removed)
ποΈ @βesbuild/linux-riscv64 (removed)
ποΈ @βesbuild/linux-riscv64 (removed)
ποΈ @βesbuild/linux-s390x (removed)
ποΈ @βesbuild/linux-s390x (removed)
ποΈ @βesbuild/linux-x64 (removed)
ποΈ @βesbuild/linux-x64 (removed)
ποΈ @βesbuild/netbsd-x64 (removed)
ποΈ @βesbuild/netbsd-x64 (removed)
ποΈ @βesbuild/openbsd-x64 (removed)
ποΈ @βesbuild/openbsd-x64 (removed)
ποΈ @βesbuild/sunos-x64 (removed)
ποΈ @βesbuild/sunos-x64 (removed)
ποΈ @βesbuild/win32-arm64 (removed)
ποΈ @βesbuild/win32-arm64 (removed)
ποΈ @βesbuild/win32-ia32 (removed)
ποΈ @βesbuild/win32-ia32 (removed)
ποΈ @βesbuild/win32-x64 (removed)
ποΈ @βesbuild/win32-x64 (removed)
ποΈ esbuild (removed)
ποΈ esbuild (removed)
ποΈ @βbcoe/v8-coverage (removed)
ποΈ @βbufbuild/protobuf (removed)
ποΈ @βcolors/colors (removed)
ποΈ @βdabh/diagnostics (removed)
ποΈ @βelastic/ecs-helpers (removed)
ποΈ @βelastic/ecs-pino-format (removed)
ποΈ @βelastic/elasticsearch (removed)
ποΈ @βelastic/transport (removed)
ποΈ @βesbuild/netbsd-arm64 (removed)
ποΈ @βesbuild/openbsd-arm64 (removed)
ποΈ @βesbuild/openharmony-arm64 (removed)
ποΈ @βeslint/config-array (removed)
ποΈ @βeslint/config-helpers (removed)
ποΈ @βeslint/core (removed)
ποΈ @βeslint/object-schema (removed)
ποΈ @βeslint/plugin-kit (removed)
ποΈ @βgrpc/grpc-js (removed)
ποΈ @βgrpc/proto-loader (removed)
ποΈ @βhumanfs/core (removed)
ποΈ @βhumanfs/node (removed)
ποΈ @βhumanwhocodes/retry (removed)
ποΈ @βhumanwhocodes/retry (removed)
ποΈ @βistanbuljs/schema (removed)
ποΈ @βjs-sdsl/ordered-map (removed)
ποΈ @βlocalazy/languages (removed)
ποΈ @βopentelemetry/api (removed)
ποΈ @βopentelemetry/core (removed)
ποΈ @βopentelemetry/resources (removed)
ποΈ @βopentelemetry/sdk-metrics (removed)
ποΈ @βopentelemetry/semantic-conventions (removed)
ποΈ @βprotobufjs/aspromise (removed)
ποΈ @βprotobufjs/base64 (removed)
ποΈ @βprotobufjs/codegen (removed)
ποΈ @βprotobufjs/eventemitter (removed)
ποΈ @βprotobufjs/fetch (removed)
ποΈ @βprotobufjs/float (removed)
ποΈ @βprotobufjs/inquire (removed)
ποΈ @βprotobufjs/path (removed)
ποΈ @βprotobufjs/pool (removed)
ποΈ @βprotobufjs/utf8 (removed)
ποΈ @βrestorecommerce/dataset-demoshop-catalog-transformer (removed)
ποΈ @βrestorecommerce/dataset-system-units-transformer (removed)
ποΈ @βrestorecommerce/dataset-system-world-transformer (removed)
ποΈ @βrestorecommerce/dev (removed)
ποΈ @βeslint/compat (removed)
ποΈ @βtypescript-eslint/scope-manager (removed)
ποΈ @βtypescript-eslint/scope-manager (removed)
ποΈ @βtypescript-eslint/scope-manager (removed)
ποΈ @βtypescript-eslint/scope-manager (removed)
ποΈ @βtypescript-eslint/types (removed)
ποΈ @βtypescript-eslint/types (removed)
ποΈ @βtypescript-eslint/types (removed)
ποΈ @βtypescript-eslint/types (removed)
ποΈ @βtypescript-eslint/typescript-estree (removed)
ποΈ @βtypescript-eslint/typescript-estree (removed)
ποΈ @βtypescript-eslint/typescript-estree (removed)
ποΈ @βtypescript-eslint/typescript-estree (removed)
ποΈ @βtypescript-eslint/utils (removed)
ποΈ @βtypescript-eslint/utils (removed)
ποΈ @βtypescript-eslint/utils (removed)
ποΈ @βtypescript-eslint/utils (removed)
ποΈ @βtypescript-eslint/visitor-keys (removed)
ποΈ @βtypescript-eslint/visitor-keys (removed)
ποΈ @βtypescript-eslint/visitor-keys (removed)
ποΈ @βtypescript-eslint/visitor-keys (removed)
ποΈ eslint-plugin-prefer-arrow-functions (removed)
ποΈ ts-api-utils (removed)
ποΈ ts-api-utils (removed)
ποΈ @βrestorecommerce/grpc-client (removed)
ποΈ @βrestorecommerce/logger (removed)
ποΈ @βrestorecommerce/rc-grpc-clients (removed)
ποΈ @βrollup/rollup-android-arm-eabi (removed)
ποΈ @βrollup/rollup-android-arm64 (removed)
ποΈ @βrollup/rollup-darwin-arm64 (removed)
ποΈ @βrollup/rollup-darwin-x64 (removed)
ποΈ @βrollup/rollup-freebsd-arm64 (removed)
ποΈ @βrollup/rollup-freebsd-x64 (removed)
ποΈ @βrollup/rollup-linux-arm-gnueabihf (removed)
ποΈ @βrollup/rollup-linux-arm-musleabihf (removed)
ποΈ @βrollup/rollup-linux-arm64-gnu (removed)
ποΈ @βrollup/rollup-linux-arm64-musl (removed)
ποΈ @βrollup/rollup-linux-loongarch64-gnu (removed)
ποΈ @βrollup/rollup-linux-powerpc64le-gnu (removed)
ποΈ @βrollup/rollup-linux-riscv64-gnu (removed)
ποΈ @βrollup/rollup-linux-riscv64-musl (removed)
ποΈ @βrollup/rollup-linux-s390x-gnu (removed)
ποΈ @βrollup/rollup-linux-x64-gnu (removed)
ποΈ @βrollup/rollup-linux-x64-musl (removed)
ποΈ @βrollup/rollup-win32-arm64-msvc (removed)
ποΈ @βrollup/rollup-win32-ia32-msvc (removed)
ποΈ @βrollup/rollup-win32-x64-msvc (removed)
ποΈ @βstylistic/eslint-plugin (removed)
ποΈ @βswc/helpers (removed)
ποΈ @βtypes/argparse (removed)
ποΈ @βtypes/command-line-args (removed)
ποΈ @βtypes/command-line-usage (removed)
ποΈ @βtypes/estree (removed)
ποΈ @βtypes/google-protobuf (removed)
ποΈ @βtypes/js-yaml (removed)
ποΈ @βtypes/json-schema (removed)
ποΈ @βtypes/node (removed)
ποΈ @βtypes/node (removed)
ποΈ @βtypes/triple-beam (removed)
ποΈ @βtypes/zen-observable (removed)
ποΈ @βtypescript-eslint/eslint-plugin (removed)
ποΈ @βtypescript-eslint/eslint-plugin (removed)
ποΈ @βtypescript-eslint/parser (removed)
ποΈ @βtypescript-eslint/parser (removed)
ποΈ @βtypescript-eslint/type-utils (removed)
ποΈ @βtypescript-eslint/type-utils (removed)
ποΈ @βvitest/coverage-v8 (removed)
ποΈ @βvitest/expect (removed)
ποΈ @βvitest/mocker (removed)
ποΈ @βvitest/pretty-format (removed)
ποΈ @βvitest/runner (removed)
ποΈ @βvitest/snapshot (removed)
ποΈ @βvitest/spy (removed)
ποΈ @βvitest/utils (removed)
ποΈ @βvvo/tzdb (removed)
ποΈ abort-controller-x (removed)
ποΈ acorn-import-assertions (removed)
ποΈ after-all-results (removed)
ποΈ agentkeepalive (removed)
ποΈ apache-arrow (removed)
ποΈ undici-types (removed)
ποΈ undici-types (removed)
ποΈ apollo-cache (removed)
ποΈ apollo-cache-inmemory (removed)
ποΈ apollo-client (removed)
ποΈ apollo-link (removed)
ποΈ apollo-link-http (removed)
ποΈ apollo-link-http-common (removed)
ποΈ apollo-utilities (removed)
ποΈ array-back (removed)
ποΈ asap (removed)
ποΈ assertion-error (removed)
ποΈ async-cache (removed)
ποΈ async-hook-jl (removed)
ποΈ async-value (removed)
ποΈ async-value-promise (removed)
ποΈ atomic-sleep (removed)
ποΈ basic-auth (removed)
ποΈ binary-search (removed)
ποΈ breadth-filter (removed)
ποΈ builtin-modules (removed)
ποΈ cac (removed)
ποΈ chai (removed)
ποΈ chalk-template (removed)
ποΈ check-error (removed)
ποΈ cjs-module-lexer (removed)
ποΈ clean-regexp (removed)
ποΈ cls-hooked (removed)
ποΈ cls-rtracer (removed)
ποΈ color (removed)
ποΈ color-string (removed)
ποΈ colorspace (removed)
ποΈ command-line-args (removed)
ποΈ command-line-usage (removed)
ποΈ console-log-level (removed)
ποΈ cookie (removed)
ποΈ core-js-compat (removed)
ποΈ csv-parser (removed)
ποΈ currency-list (removed)
ποΈ dayjs (removed)
ποΈ deep-eql (removed)
ποΈ elastic-apm-node (removed)
ποΈ emitter-listener (removed)
ποΈ enabled (removed)
ποΈ error-callsites (removed)
ποΈ error-stack-parser (removed)
ποΈ es-module-lexer (removed)
ποΈ eslint-plugin-file-extension-in-import-ts (removed)
ποΈ eslint-plugin-unicorn (removed)
ποΈ estree-walker (removed)
ποΈ expect-type (removed)
ποΈ fast-redact (removed)
ποΈ fast-safe-stringify (removed)
ποΈ fast-stream-to-buffer (removed)
ποΈ fecha (removed)
ποΈ find-replace (removed)
ποΈ flatbuffers (removed)
ποΈ flatstr (removed)
ποΈ fn.name (removed)
ποΈ forwarded-parse (removed)
ποΈ fsevents (removed)
ποΈ google-protobuf (removed)
ποΈ hpagent (removed)
ποΈ html-escaper (removed)
ποΈ http-headers (removed)
ποΈ humanize-ms (removed)
ποΈ import-in-the-middle (removed)
ποΈ is-builtin-module (removed)
ποΈ is-finite (removed)
ποΈ is-integer (removed)
ποΈ is-native (removed)
ποΈ is-nil (removed)
ποΈ istanbul-lib-coverage (removed)
ποΈ istanbul-lib-report (removed)
ποΈ istanbul-lib-source-maps (removed)
ποΈ istanbul-reports (removed)
ποΈ json-bignum (removed)
ποΈ kuler (removed)
ποΈ lodash.camelcase (removed)
ποΈ lodash.defaults (removed)
ποΈ lodash.omit (removed)
ποΈ lodash.sortby (removed)
ποΈ logform (removed)
ποΈ long (removed)
ποΈ loupe (removed)
ποΈ magic-string (removed)
ποΈ magicast (removed)
ποΈ mapcap (removed)
ποΈ measured-core (removed)
ποΈ measured-reporting (removed)
ποΈ module-details-from-path (removed)
ποΈ monitor-event-loop-delay (removed)
ποΈ nanoid (removed)
ποΈ next-line (removed)
ποΈ nice-grpc (removed)
ποΈ nice-grpc-client-middleware-deadline (removed)
ποΈ nice-grpc-client-middleware-retry (removed)
ποΈ nice-grpc-common (removed)
ποΈ node-xlsx (removed)
ποΈ object-filter-sequence (removed)
ποΈ object-hash (removed)
ποΈ object-identity-map (removed)
ποΈ one-time (removed)
ποΈ optional-js (removed)
ποΈ original-url (removed)
ποΈ pathe (removed)
ποΈ pathval (removed)
ποΈ pino (removed)
ποΈ pino-std-serializers (removed)
ποΈ pluralize (removed)
ποΈ postcss (removed)
ποΈ process-warning (removed)
ποΈ promise (removed)
ποΈ protobufjs (removed)
ποΈ pseudomap (removed)
ποΈ quick-format-unescaped (removed)
ποΈ regexp-tree (removed)
ποΈ regjsparser (removed)
ποΈ relative-microtime (removed)
ποΈ require-in-the-middle (removed)
ποΈ rollup (removed)
ποΈ safe-stable-stringify (removed)
ποΈ secure-json-parse (removed)
ποΈ shallow-clone-shim (removed)
ποΈ shimmer (removed)
ποΈ siginfo (removed)
ποΈ simple-swizzle (removed)
ποΈ sonic-boom (removed)
ποΈ source-map-js (removed)
ποΈ source-map-support (removed)
ποΈ sql-summary (removed)
ποΈ stack-chain (removed)
ποΈ stack-trace (removed)
ποΈ stackback (removed)
ποΈ stackframe (removed)
ποΈ std-env (removed)
ποΈ stream-chopper (removed)
ποΈ table-layout (removed)
ποΈ test-exclude (removed)
ποΈ text-hex (removed)
ποΈ tinybench (removed)
ποΈ tinyexec (removed)
ποΈ tinypool (removed)
ποΈ tinyrainbow (removed)
ποΈ tinyspy (removed)
ποΈ to-source-code (removed)
ποΈ triple-beam (removed)
ποΈ ts-error (removed)
ποΈ ts-proto-descriptors (removed)
ποΈ typescript-eslint (removed)
ποΈ typical (removed)
ποΈ undici (removed)
ποΈ unicode-byte-truncate (removed)
ποΈ unicode-substring (removed)
ποΈ vite (removed)
ποΈ vite-node (removed)
ποΈ vitest (removed)
ποΈ why-is-node-running (removed)
ποΈ winston (removed)
ποΈ winston-elasticsearch (removed)
ποΈ winston-transport (removed)
ποΈ wordwrapjs (removed)
ποΈ world-countries (removed)
ποΈ xlsx (removed)
ποΈ eslint-visitor-keys (removed)
ποΈ @βeslint/eslintrc (removed)
ποΈ espree (removed)
ποΈ globals (removed)
ποΈ globals (removed)
ποΈ @βeslint/js (removed)
ποΈ uuid (removed)
ποΈ uuid (removed)
ποΈ lru-cache (removed)
ποΈ eslint (removed)
ποΈ eslint-scope (removed)
ποΈ file-entry-cache (removed)
ποΈ flat-cache (removed)
ποΈ yallist (removed)
ποΈ through2 (removed)
ποΈ source-map (removed)
ποΈ tr46 (removed)
ποΈ webidl-conversions (removed)
ποΈ whatwg-url (removed)
ποΈ is-arrayish (removed)
ποΈ jsesc (removed)
ποΈ picomatch (removed)
ποΈ retry (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands