Bump the npm-security-updates group across 5 directories with 7 updates#3129
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
Conversation
Bumps the npm-security-updates group with 1 update in the /tests/integration directory: [@babel/helpers](https://github.com/babel/babel/tree/HEAD/packages/babel-helpers). Bumps the npm-security-updates group with 5 updates in the /parser-sdk/nodejs directory: | Package | From | To | | --- | --- | --- | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.0.1` | `2.0.2` | | [jsonpath-plus](https://github.com/s3u/JSONPath) | `10.2.0` | `10.3.0` | | [tough-cookie](https://github.com/salesforce/tough-cookie) | `2.5.0` | `removed` | | [@kubernetes/client-node](https://github.com/kubernetes-client/javascript) | `0.22.3` | `1.3.0` | | [axios](https://github.com/axios/axios) | `1.7.9` | `1.8.2` | Bumps the npm-security-updates group with 4 updates in the /hook-sdk/nodejs directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [jsonpath-plus](https://github.com/s3u/JSONPath), [tough-cookie](https://github.com/salesforce/tough-cookie) and [@kubernetes/client-node](https://github.com/kubernetes-client/javascript). Bumps the npm-security-updates group with 4 updates in the /auto-discovery/kubernetes/pull-secret-extractor/integration-test directory: [@babel/helpers](https://github.com/babel/babel/tree/HEAD/packages/babel-helpers), [jsonpath-plus](https://github.com/s3u/JSONPath), [tough-cookie](https://github.com/salesforce/tough-cookie) and [@kubernetes/client-node](https://github.com/kubernetes-client/javascript). Bumps the npm-security-updates group with 4 updates in the / directory: [@babel/helpers](https://github.com/babel/babel/tree/HEAD/packages/babel-helpers), [jsonpath-plus](https://github.com/s3u/JSONPath), [tough-cookie](https://github.com/salesforce/tough-cookie) and [@kubernetes/client-node](https://github.com/kubernetes-client/javascript). Updates `@babel/helpers` from 7.26.0 to 7.27.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.27.6/packages/babel-helpers) Updates `brace-expansion` from 2.0.1 to 2.0.2 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.0.2) Updates `jsonpath-plus` from 10.2.0 to 10.3.0 - [Release notes](https://github.com/s3u/JSONPath/releases) - [Changelog](https://github.com/JSONPath-Plus/JSONPath/blob/main/CHANGES.md) - [Commits](JSONPath-Plus/JSONPath@v10.2.0...v10.3.0) Removes `tough-cookie` Updates `@kubernetes/client-node` from 0.22.3 to 1.3.0 - [Release notes](https://github.com/kubernetes-client/javascript/releases) - [Commits](kubernetes-client/javascript@0.22.3...1.3.0) Updates `axios` from 1.7.9 to 1.8.2 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.7.9...v1.8.2) Updates `ws` from 8.18.0 to 8.18.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.18.0...8.18.3) Updates `brace-expansion` from 2.0.1 to 2.0.2 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.0.2) Updates `jsonpath-plus` from 10.2.0 to 10.3.0 - [Release notes](https://github.com/s3u/JSONPath/releases) - [Changelog](https://github.com/JSONPath-Plus/JSONPath/blob/main/CHANGES.md) - [Commits](JSONPath-Plus/JSONPath@v10.2.0...v10.3.0) Removes `tough-cookie` Updates `@kubernetes/client-node` from 0.22.3 to 1.3.0 - [Release notes](https://github.com/kubernetes-client/javascript/releases) - [Commits](kubernetes-client/javascript@0.22.3...1.3.0) Updates `ws` from 8.18.0 to 8.18.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.18.0...8.18.3) Updates `@babel/helpers` from 7.26.0 to 7.27.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.27.6/packages/babel-helpers) Updates `jsonpath-plus` from 10.2.0 to 10.3.0 - [Release notes](https://github.com/s3u/JSONPath/releases) - [Changelog](https://github.com/JSONPath-Plus/JSONPath/blob/main/CHANGES.md) - [Commits](JSONPath-Plus/JSONPath@v10.2.0...v10.3.0) Removes `tough-cookie` Updates `@kubernetes/client-node` from 0.22.3 to 1.3.0 - [Release notes](https://github.com/kubernetes-client/javascript/releases) - [Commits](kubernetes-client/javascript@0.22.3...1.3.0) Updates `ws` from 8.18.0 to 8.18.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.18.0...8.18.3) Updates `@babel/helpers` from 7.24.4 to 7.27.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.27.6/packages/babel-helpers) Updates `jsonpath-plus` from 10.2.0 to 10.3.0 - [Release notes](https://github.com/s3u/JSONPath/releases) - [Changelog](https://github.com/JSONPath-Plus/JSONPath/blob/main/CHANGES.md) - [Commits](JSONPath-Plus/JSONPath@v10.2.0...v10.3.0) Removes `tough-cookie` Updates `@kubernetes/client-node` from 0.22.3 to 1.3.0 - [Release notes](https://github.com/kubernetes-client/javascript/releases) - [Commits](kubernetes-client/javascript@0.22.3...1.3.0) Updates `ws` from 8.18.0 to 8.18.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.18.0...8.18.3) --- updated-dependencies: - dependency-name: "@babel/helpers" dependency-version: 7.27.6 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: brace-expansion dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: jsonpath-plus dependency-version: 10.3.0 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: tough-cookie dependency-version: dependency-type: indirect dependency-group: npm-security-updates - dependency-name: "@kubernetes/client-node" dependency-version: 1.3.0 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: axios dependency-version: 1.8.2 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: ws dependency-version: 8.18.3 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: brace-expansion dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: jsonpath-plus dependency-version: 10.3.0 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: tough-cookie dependency-version: dependency-type: indirect dependency-group: npm-security-updates - dependency-name: "@kubernetes/client-node" dependency-version: 1.3.0 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: ws dependency-version: 8.18.3 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: "@babel/helpers" dependency-version: 7.27.6 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: jsonpath-plus dependency-version: 10.3.0 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: tough-cookie dependency-version: dependency-type: indirect dependency-group: npm-security-updates - dependency-name: "@kubernetes/client-node" dependency-version: 1.3.0 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: ws dependency-version: 8.18.3 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: "@babel/helpers" dependency-version: 7.27.6 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: jsonpath-plus dependency-version: 10.3.0 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: tough-cookie dependency-version: dependency-type: indirect dependency-group: npm-security-updates - dependency-name: "@kubernetes/client-node" dependency-version: 1.3.0 dependency-type: direct:production dependency-group: npm-security-updates - dependency-name: ws dependency-version: 8.18.3 dependency-type: indirect dependency-group: npm-security-updates ... Signed-off-by: dependabot[bot] <support@github.com>
✅ Deploy Preview for docs-securecodebox ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Member
|
fixed by #3088 |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the npm-security-updates group with 1 update in the /tests/integration directory: @babel/helpers.
Bumps the npm-security-updates group with 5 updates in the /parser-sdk/nodejs directory:
2.0.12.0.210.2.010.3.02.5.0removed0.22.31.3.01.7.91.8.2Bumps the npm-security-updates group with 4 updates in the /hook-sdk/nodejs directory: brace-expansion, jsonpath-plus, tough-cookie and @kubernetes/client-node.
Bumps the npm-security-updates group with 4 updates in the /auto-discovery/kubernetes/pull-secret-extractor/integration-test directory: @babel/helpers, jsonpath-plus, tough-cookie and @kubernetes/client-node.
Bumps the npm-security-updates group with 4 updates in the / directory: @babel/helpers, jsonpath-plus, tough-cookie and @kubernetes/client-node.
Updates
@babel/helpersfrom 7.26.0 to 7.27.6Release notes
Sourced from
@babel/helpers's releases.... (truncated)
Changelog
Sourced from
@babel/helpers's changelog.... (truncated)
Commits
baa4cb8v7.27.6fdbf1b3fix:finallycauses unexpected return value (#17366)7d06930v7.27.45b9468dReduceregeneratorsize more (#17287)cb78b5b[babel 8] Do not replace globalregeneratorRuntimereferences in regenerato...49c0dbbFix iterator compatibility ofregeneratorValues(#17335)d23a1bdUse shorter method names for regenerator context (#17334)9dcd115Restore behavior ofregeneratorRuntimehelper (#17329)fe32019Reduceregeneratorhelper size (#17268)a0690e3SplitregeneratorRuntimeinto multiple helpers (#17238)Updates
brace-expansionfrom 2.0.1 to 2.0.2Release notes
Sourced from brace-expansion's releases.
Commits
a3efcee2.0.214f1d91pkg: publish on tag 2.xed7780afmt36603d5Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
jsonpath-plusfrom 10.2.0 to 10.3.0Release notes
Sourced from jsonpath-plus's releases.
Changelog
Sourced from jsonpath-plus's changelog.
Commits
9754e4bchore: bump versionf690da1chore: update deps and devDeps313a9b4Merge pull request #238 from 80avin/shareable-demo39a0d03Merge pull request #237 from 80avin/fix-10.2.0-rce1c532fcfeat(demo): make demo link shareable3094289fix(eval): rce using non-string prop namesMaintainer changes
This version was pushed to npm by 80avin, a new releaser for jsonpath-plus since your current version.
Removes
tough-cookieUpdates
@kubernetes/client-nodefrom 0.22.3 to 1.3.0Release notes
Sourced from
@kubernetes/client-node's releases.... (truncated)
Commits
940af26Merge pull request #2457 from kubernetes-client/dependabot/npm_and_yarn/main/...5dad6d3Merge pull request #2456 from kubernetes-client/dependabot/npm_and_yarn/main/...55e1a8abuild(deps-dev): bump typescript-eslint from 8.32.1 to 8.33.0adf25e2build(deps): bump@types/nodefrom 22.15.21 to 22.15.232ed3379Merge pull request #2454 from cjihrig/bump4846defupdate package versions in preparation for releasef809c36Merge pull request #2452 from kubernetes-client/dependabot/npm_and_yarn/main/...52c1acfbuild(deps-dev): bump typedoc from 0.28.4 to 0.28.51fcb3a6Merge pull request #2447 from kubernetes-client/dependabot/npm_and_yarn/main/...affa86abuild(deps): bump tar-fs from 3.0.8 to 3.0.9Updates
axiosfrom 1.7.9 to 1.8.2Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
a9f7689chore(release): v1.8.2 (#6812)fb8eec2fix(http-adapter): add allowAbsoluteUrls to path building (#6810)9812045chore(sponsor): update sponsor block (#6804)72acf75chore(sponsor): update sponsor block (#6794)2e64afdchore(release): v1.8.1 (#6800)36a5a62fix(utils): movegenerateStringto platform utils to avoid importing crypto...cceb7b1chore(release): v1.8.0 (#6795)23a25affix(utils): replace getRandomValues with crypto module (#6788)32c7bccfeat: Add config for ignoring absolute URLs (#5902) (#6192)4a3e26cchore(config): adjust rollup config to preserve license header to minified Ja...Updates
wsfrom 8.18.0 to 8.18.3Release notes
Sourced from ws's releases.
Commits
dabbdec[dist] 8.18.333f5dba[fix] Respond with the supported protocol versions (#2291)22a5a17[ci] Test on node 24e67eb7a[ci] Do not test on node 23fa670f2[ci] Run the lint step on node 220eb8535[dist] 8.18.24f20aed[fix] Handle oversized messages with designated error (#2285)aa998e3[pkg] Update globals to version 16.0.0cf25954[minor] Fix nit in error messageb92745a[dist] 8.18.1Updates
brace-expansionfrom 2.0.1 to 2.0.2Release notes
Sourced from brace-expansion's releases.
Commits
a3efcee2.0.214f1d91pkg: publish on tag 2.xed7780afmt36603d5Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
jsonpath-plusfrom 10.2.0 to 10.3.0Release notes
Sourced from jsonpath-plus's releases.
Changelog
Sourced from jsonpath-plus's changelog.
Commits
9754e4bchore: bump versionf690da1chore: update deps and devDeps313a9b4Merge pull request #238 from 80avin/shareable-demo39a0d03Merge pull request #237 from 80avin/fix-10.2.0-rce1c532fcfeat(demo): make demo link shareable3094289fix(eval): rce using non-string prop namesMaintainer changes
This version was pushed to npm by 80avin, a new releaser for jsonpath-plus since your current version.
Removes
tough-cookieUpdates
@kubernetes/client-nodefrom 0.22.3 to 1.3.0Release notes
Sourced from
@kubernetes/client-node's releases.... (truncated)
Commits
940af26Merge pull request #2457 from kubernetes-client/dependabot/npm_and_yarn/main/...5dad6d3Merge pull request #2456 from kubernetes-client/dependabot/npm_and_yarn/main/...55e1a8abuild(deps-dev): bump typescript-eslint from 8.32.1 to 8.33.0adf25e2build(deps): bump@types/nodefrom 22.15.21 to 22.15.232ed3379Merge pull request #2454 from cjihrig/bump4846defupdate package versions in preparation for releasef809c36Merge pull request #2452 from kubernetes-client/dependabot/npm_and_yarn/main/...52c1acfbuild(deps-dev): bump typedoc from 0.28.4 to 0.28.51fcb3a6Merge pull request #2447 from kubernetes-client/dependabot/npm_and_yarn/main/...affa86abuild(deps): bump tar-fs from 3.0.8 to 3.0.9Updates
wsfrom 8.18.0 to 8.18.3Release notes
Sourced from ws's releases.
Commits
dabbdec[dist] 8.18.333f5dba[fix] Respond with the supported protocol versions (#2291)22a5a17[ci] Test on node 24