🚨 [security] Update cookie 0.6.0 → 0.7.1 (major) #1565
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ cookie (0.6.0 → 0.7.2) · Repo · Changelog
Security Advisories 🚨
🚨 cookie accepts cookie name, path, and domain with out of bounds characters
Release Notes
0.7.2
0.7.1
0.7.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 19 commits:
0.7.2
Fix object assignment of `hasOwnProperty` (#177)
0.7.1
Allow leading dot for domain (#174)
Remove more code and perf wins (#172)
0.7.0
Migrate history to GitHub releases
Migrate history to GitHub releases
Skip isNaN
perf(parse): cache length, return early (#144)
Fix tests for old node
Remove failing scorecard
test(serialize): additional tests for name, domain and path RFC validations (#171)
Iterate whitespace for perf (#170)
Add `main` to `package.json` (#166)
Fix CI
fix: narrow the validation of cookies to match RFC6265 (#167)
docs: fix typo in function description (#161)
ci: add scorecard pipeline (#158)
✳️ @babel/plugin-transform-modules-commonjs (7.18.6 → 7.25.9) · Repo · Changelog
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 14 commits:
v7.25.9
remove test options flaky (#16914)
fix: Accidentally publishing useless files (#16917)
chore: Improve logic regarding fast objects (#16919)
test(numeric-separator): fix invalid test layout (#16920)
perf: Make `VISITOR_KEYS` etc. faster to access (#16918)
fix: Keep type annotations in `syntacticPlaceholders` mode (#16905)
Update test262 (#16910)
Update compat data (#16909)
ci: pin latest node to 22 (#16913)
fix: support BROWSERSLIST{,_CONFIG} env (#16907)
Analyze `ClassAccessorProperty` to prevent the `no-undef` rule (#16884)
Update test262 (#16900)
Add v7.25.8 to CHANGELOG.md [skip ci]
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands