π¨ [security] Update nodemon 2.0.5 β 3.1.9 (major) #150
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ nodemon (2.0.5 β 3.1.9) Β· Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
3.1.3
3.1.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 10 commits:
3.1.3
Merge pull request #50 from micromatch/phated/keep-trailing-sep
fix: Keep trailing slash on paths
Merge pull request #42 from Alucelx/master
add a override of teststring is null
Release 3.1.2.
Merge pull request #37 from mihkeleidast/issue/36
Merge pull request #39 from genisysram/master
Update .travis.yml
do not create pattern from negative matchers
Release Notes
2.3.0
2.2.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 6 commits:
2.3.0
Meta tweaks
Add `afdesign`, `afphoto`, and `afpub` (#30)
2.2.0
Add OpenDocument file extensions (#27)
Move to GitHub Actions (#26)
Security Advisories π¨
π¨ Uncontrolled resource consumption in braces
Commits
See the full diff on Github. The new version differs by 12 commits:
3.0.3
update eslint. lint, fix unit tests.
Snyk js braces 6838727 (#40)
fix tests, skip 1 test in test/braces.expand
readme bump
Merge pull request #37 from coderaiser/fix/vulnerability
feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/36#issuecomment-2110820796)
fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)
remove funding file
update keepEscaping doc (#27)
Failing test cases for issue \#29 (#30)
Create FUNDING.yml
Release Notes
3.6.0
3.5.2
3.5.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 71 commits:
Release 3.6.0.
Add github ci autopublish
Merge pull request #1300 from ben-polinsky/fix-fswatcher-types-1299
fix formatting
update fs.FSWatcher types to satisfy node versions >= 16; fixes #1299
Merge pull request #1197 from MarcCelani-at/handleMustScanSubDirs
Merge pull request #1288 from JLHwung/fix-ready-count
ready call # is unfortunately platform specific
fix readyCount logic
Adjust funding field in pkg
Enable GitHub Sponsors
Merge pull request #1242 from zqianem/fix/tests
Fix test case using unsupported option for Node 8
Fix `close` tests
Merge pull request #1226 from Mutahhar/patch-1
Update README.md
Merge pull request #1198 from XhmikosR/rm-unused-deps
Merge pull request #1199 from XhmikosR/patch-1
Update CI config
Remove unused devDependencies
move to constants
handle MustScanSubDirs
Release 3.5.3.
Funding.
Merge pull request #1159 from alan-agius4/patch-1
style: delete yarn.lock
Merge pull request #1158 from alan-agius4/test-async
Merge pull request #1157 from alan-agius4/fix-chain-return
ci: add `dtslint` in the lint workflow
style: fix dts lint issue
build: add missing `typescript`
test: update `close` method test
fix: improve `add` and `unwatch` TypeScript definitions
Merge pull request #1010 from nicks/nicks/symlink
Merge pull request #1142 from mcecode/update-chokidar-cli-link
Update chokidar-cli link in README.md
Merge pull request #1140 from iheyunfei/types/0816
types: use correct type def for ignored option
Release 3.5.2.
Update some deps
Update package.json
Merge pull request #1108 from tamuratak/fix_doc
Fix doc for unwatch() and close().
Update dependabot.yml
Merge pull request #1093 from paulmillr/dependabot/add-v2-config-file
Upgrade to GitHub-native Dependabot
Merge pull request #1091 from bartenra/patch-1
Add another downside to fs.watch
Merge pull request #1083 from RoXuS/symlinkDepthBug
fix some tests by adding delay and moving some tests
Merge pull request #1041 from RoXuS/symlinkDepthBug
Use realPath instead of path on watchers
Merge pull request #1082 from paulmillr/dependabot/npm_and_yarn/readdirp-3.6.0
Bump readdirp from 3.5.0 to 3.6.0
Update full_changelog.md
Add IBM i 400 support (#1070)
Release 3.5.1.
Merge pull request #1063 from CuddlySheep/bugfix/#1061
fix: Fixed unprecised symlink recognision for folders (closes #1061)
test: Added unit test to reproduce bug #1061
Merge pull request #1062 from CuddlySheep/bugfix/#1058
fix: Fixed bug in unit test which always fails (closes #1058)
Release 3.5.0.
Merge pull request #1055 from CuddlySheep/bugfix/#1042
fix: Made unit tests platform-independent
fix: Fixed missing removal of symlinks when the target path was deleted (closes #1042)
test: Added unit test to reproduce bug #1024
Merge pull request #1046 from valera-rozuvan/patch-1
Simplify conditional check
Merge pull request #1045 from pipobscure/fseventsupdate
Update fsevents to ~2.2.0
Commits
See the full diff on Github. The new version differs by 7 commits:
7.1.1
ensure that maxLen is passed down, to handle zero-padding
update eslint. lint.
Delete FUNDING.yml
Create FUNDING.yml
7.0.1
fix regressions
Release Notes
2.3.3
2.3.2
2.3.1
2.2.2
2.2.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 36 commits:
Release v2.3.3
Update nodejs.yml (#392)
readme
Merge pull request #384 from aleksanb/subdirs
Handle MustScanSubDirs for large projects
Update README.md (#371)
Update README.md (#364)
Release v2.3.2
fix: issue #355 (#356)
Release v2.3.1
Release 2.3.0.
Release 2.3.0
Try first actual action release
Fix GH Release Step
Testing Release Action (dyr-run)
Again fixing actions
Try fixing action
Try fixing action
Add automated npm pblishing when merging to master (#352)
Merge pull request #351 from cclauss/patch-1
GitHub Actions: Upgrade checkout to v2
Update README.md
Merge pull request #350 from andreialecu/fix-arm64
skip build on macos10
fix exit code
fix syntax
run tests on macos 10.15
fix: build universal binary (arm64/apple silicon)
Merge pull request #348 from SimenB/patch-1
fix(typings): add return type to `watch` overload
Merge pull request #347 from valera-rozuvan/patch-1
Update URLs pointing to constants in Apple docs
Fix Exiting Beahviour (#346)
remove static things from c-code (#342)
Update tests to include LTS & current (#344)
Closes #336.
Security Advisories π¨
π¨ glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex
Release Notes
5.1.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 5 commits:
chore: update changelog
chore: release 5.1.2
fix: eliminate ReDoS (#36)
chore: add JSDoc returns information (#33)
chore: generate initial changelog
Commits
See the full diff on Github. The new version differs by 8 commits:
4.0.3
fix: Improve performance (#15)
chore(ci): Switch to GitHub Actions for CI (#16)
4.0.2
4.1.1
Merge pull request #14 from Trott/perf
fix: improve performance
Create FUNDING.yml
Release Notes
2.3.1
2.3.0 (from changelog)
2.2.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 32 commits:
2.3.1
Merge pull request #102 from micromatch/ISSUE-93_incorrect_extglob_expanding
fix: support stars in negation extglobs with expression after closing parenthesis
Merge pull request #85 from XhmikosR/codeql
Merge pull request #91 from XhmikosR/patch-1
Merge pull request #94 from peterblazejewicz/patch-1
Merge pull request #98 from mojavelinux/document-automatic-lookbehind-detection
document that lookbehind detection is automatic
delete funding.yml
Update README.md
Create FUNDING.yml
Fix .eslintrc.json
Add CodeQL Action
2.3.0
Merge pull request #84 from micromatch/fix-83
fixes https://github.com/micromatch/picomatch/issues/83
update .eslintrc.json
add code comments, minor edits and linting
add example for https://github.com/gulpjs/glob-parent/issues/39#issuecomment-794075641
Merge pull request #81 from XhmikosR/patch-2
Merge pull request #80 from XhmikosR/patch-1
chore: CI: add Node.js 16
chore: CI: Add `FORCE_COLOR: 2 for colored output
feat: Add new `negatedExtglob` state to result of scan
2.2.3
chore: Update CI config (#75)
fix: do not skip pattern seperator for square brackets
fix: set negatedExtGlob also if it does not span the whole pattern
Merge pull request #70 from Krinkle/patch-1
test: fix typo in test name
Merge pull request #67 from GilgameshxZero/bugfix-readme-typo
fix typo in readme
Commits
See the full diff on Github. The new version differs by 5 commits:
Release 3.6.0.
Prettier
Update check for fs.stat/fs.lstat bigint support. (#171)
Merge pull request #169 from ath0mas/fix/168-recusive-warn
Skip with warn for circular symlinks, instead of exit with error (#168)
Commits
See the full diff on Github. The new version differs by 3 commits:
3.1.1
properly support sub-second stat times
remove nopt dep
Commits
See the full diff on Github. The new version differs by 2 commits:
chore: adding semver release
fix: remove debug and add tests
π simple-update-notifier (added, 2.0.0)
ποΈ @βsindresorhus/is (removed)
ποΈ @βszmarczak/http-timer (removed)
ποΈ abbrev (removed)
ποΈ ansi-align (removed)
ποΈ ansi-regex (removed)
ποΈ ansi-styles (removed)
ποΈ boxen (removed)
ποΈ cacheable-request (removed)
ποΈ camelcase (removed)
ποΈ chalk (removed)
ποΈ ci-info (removed)
ποΈ cli-boxes (removed)
ποΈ clone-response (removed)
ποΈ configstore (removed)
ποΈ crypto-random-string (removed)
ποΈ decompress-response (removed)
ποΈ deep-extend (removed)
ποΈ defer-to-connect (removed)
ποΈ dot-prop (removed)
ποΈ duplexer3 (removed)
ποΈ emoji-regex (removed)
ποΈ end-of-stream (removed)
ποΈ escape-goat (removed)
ποΈ get-stream (removed)
ποΈ global-dirs (removed)
ποΈ got (removed)
ποΈ graceful-fs (removed)
ποΈ has-yarn (removed)
ποΈ http-cache-semantics (removed)
ποΈ import-lazy (removed)
ποΈ imurmurhash (removed)
ποΈ ini (removed)
ποΈ is-ci (removed)
ποΈ is-fullwidth-code-point (removed)
ποΈ is-installed-globally (removed)
ποΈ is-npm (removed)
ποΈ is-obj (removed)
ποΈ is-path-inside (removed)
ποΈ is-typedarray (removed)
ποΈ is-yarn-global (removed)
ποΈ json-buffer (removed)
ποΈ keyv (removed)
ποΈ latest-version (removed)
ποΈ lowercase-keys (removed)
ποΈ make-dir (removed)
ποΈ mimic-response (removed)
ποΈ nopt (removed)
ποΈ normalize-url (removed)
ποΈ p-cancelable (removed)
ποΈ package-json (removed)
ποΈ prepend-http (removed)
ποΈ pump (removed)
ποΈ pupa (removed)
ποΈ rc (removed)
ποΈ registry-auth-token (removed)
ποΈ registry-url (removed)
ποΈ responselike (removed)
ποΈ semver-diff (removed)
ποΈ signal-exit (removed)
ποΈ string-width (removed)
ποΈ strip-ansi (removed)
ποΈ strip-json-comments (removed)
ποΈ term-size (removed)
ποΈ to-readable-stream (removed)
ποΈ type-fest (removed)
ποΈ typedarray-to-buffer (removed)
ποΈ unique-string (removed)
ποΈ update-notifier (removed)
ποΈ url-parse-lax (removed)
ποΈ widest-line (removed)
ποΈ write-file-atomic (removed)
ποΈ xdg-basedir (removed)
π No CI detected
You don't seem to have any Continuous Integration service set up!
Without a service that will test the Depfu branches and pull requests, we can't inform you if incoming updates actually work with your app. We think that this degrades the service we're trying to provide down to a point where it is more or less meaningless.
This is fine if you just want to give Depfu a quick try. If you want to really let Depfu help you keep your app up-to-date, we recommend setting up a CI system:
* [Circle CI](https://circleci.com), [Semaphore ](https://semaphoreci.com) and [Github Actions](https://docs.github.com/actions) are all excellent options. * If you use something like Jenkins, make sure that you're using the Github integration correctly so that it reports status data back to Github. * If you have already set up a CI for this repository, you might need to check your configuration. Make sure it will run on all new branches. If you donβt want it to run on every branch, you can whitelist branches starting with `depfu/`.Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands