Bump the npm_and_yarn group across 3 directories with 4 updates - #57
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the npm_and_yarn group with 2 updates in the / directory: [adm-zip](https://github.com/cthackers/adm-zip) and [morgan](https://github.com/expressjs/morgan). Bumps the npm_and_yarn group with 2 updates in the /extensions/copilot directory: [morgan](https://github.com/expressjs/morgan) and [csv-parse](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-parse). Bumps the npm_and_yarn group with 1 update in the /extensions/emmet directory: [image-size](https://github.com/image-size/image-size). Updates `adm-zip` from 0.5.18 to 0.6.1 - [Release notes](https://github.com/cthackers/adm-zip/releases) - [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md) - [Commits](cthackers/adm-zip@v0.5.18...v0.6.1) Updates `morgan` from 1.12.0 to 1.12.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.12.0...1.12.1) Updates `morgan` from 1.12.0 to 1.12.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.12.0...1.12.1) Updates `morgan` from 1.12.0 to 1.12.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.12.0...1.12.1) Updates `csv-parse` from 6.2.1 to 7.0.2 - [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-parse/CHANGELOG.md) - [Commits](https://github.com/adaltas/node-csv/commits/csv-parse@7.0.2/packages/csv-parse) Updates `morgan` from 1.12.0 to 1.12.1 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.12.0...1.12.1) Updates `image-size` from 1.0.2 to 2.0.3 - [Release notes](https://github.com/image-size/image-size/releases) - [Commits](https://github.com/image-size/image-size/commits) --- updated-dependencies: - dependency-name: adm-zip dependency-version: 0.6.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: morgan dependency-version: 1.12.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: morgan dependency-version: 1.12.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: morgan dependency-version: 1.12.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: csv-parse dependency-version: 7.0.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: morgan dependency-version: 1.12.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: image-size dependency-version: 2.0.3 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
Superseded by #59. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/npm_and_yarn-a39f51ff00
branch
September 28, 2026 22:00
Owner
|
@dependabot rebase |
Contributor
Author
|
Looks like this PR is closed. If the branch still exists, you can re-open the PR and then use |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 2 updates in the / directory: adm-zip and morgan.
Bumps the npm_and_yarn group with 2 updates in the /extensions/copilot directory: morgan and csv-parse.
Bumps the npm_and_yarn group with 1 update in the /extensions/emmet directory: image-size.
Updates
adm-zipfrom 0.5.18 to 0.6.1Release notes
Sourced from adm-zip's releases.
Changelog
Sourced from adm-zip's changelog.
... (truncated)
Commits
cb2cf9bFixed addLocalFolderAsync2 mangling local paths on Windows54902b6Fixed addLocalFolderPromise hanging on empty folders and swallowing errors73131bdFixed CI758898dRejected zip entries whose declared data extent runs past the buffer74b6e9fRouted malformed-header parse errors through the async callbackeaa35faBlocked extraction from writing through symlinks inside the target1e015e3Increment version05101d4Rejected archives with duplicate entry names4916006Enforced the decompression size cap on the async path and for size 06a63c33Stripped setuid/setgid/sticky bits from extracted file permissionsUpdates
morganfrom 1.12.0 to 1.12.1Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
b1272e71.12.1 (#386)4b695edfix: escape double quotes in log fields0f74ecabuild(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)e399e3cbuild(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)1e86b34build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)87c0afdbuild(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)286b000test: run CI on Windows and macOS (#379)5a5902adocs: fix typos across documentation (#378)Updates
morganfrom 1.12.0 to 1.12.1Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
b1272e71.12.1 (#386)4b695edfix: escape double quotes in log fields0f74ecabuild(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)e399e3cbuild(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)1e86b34build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)87c0afdbuild(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)286b000test: run CI on Windows and macOS (#379)5a5902adocs: fix typos across documentation (#378)Updates
morganfrom 1.12.0 to 1.12.1Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
b1272e71.12.1 (#386)4b695edfix: escape double quotes in log fields0f74ecabuild(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)e399e3cbuild(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)1e86b34build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)87c0afdbuild(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)286b000test: run CI on Windows and macOS (#379)5a5902adocs: fix typos across documentation (#378)Updates
csv-parsefrom 6.2.1 to 7.0.2Changelog
Sourced from csv-parse's changelog.
Commits
288c9c6chore(release): publish2ad6c07refactor(csv-parse): rename group_columns_by_name testseb4d148fix(csv-parse): prototype replacement reachable via columns (#497)1d4ed3bperf(csv-parse): avoid unnecessary allocation in ResizeableBuffer.toString (#...6e0d5a3chore(release): publishabfe4debuild: latest dependenciesa5ef896docs(csv-parse): fix changelog message from previous version230af8efix(csv-parse): ship stream cjs export (#490)3d71f0bchore(release): publish2ba4897build: use ts nodenextUpdates
morganfrom 1.12.0 to 1.12.1Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
b1272e71.12.1 (#386)4b695edfix: escape double quotes in log fields0f74ecabuild(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)e399e3cbuild(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)1e86b34build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)87c0afdbuild(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)286b000test: run CI on Windows and macOS (#379)5a5902adocs: fix typos across documentation (#378)Updates
image-sizefrom 1.0.2 to 2.0.3Release notes
Sourced from image-size's releases.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.