🚨 [security] Update all of commitlint 12.1.1 → 12.1.4 (patch)
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳ ️ @commitlint/cli (12.1.1 → 12.1.4) · Repo · Changelog
✳ ️ @commitlint/config-conventional (12.1.1 → 12.1.4) · Repo · Changelog
↗ ️ @commitlint/lint (indirect, 12.1.1 → 12.1.4) · Repo · Changelog
Release Notes
12.1.4
fix node v10 support
12.1.3
12.1.3 (2021-05-12)
Bug Fixes
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 54 commits:
v12.1.4
Fix/node10 support (#2595)
chore: update babel monorepo to v7.14.2 (#2592)
chore: update dependency @types/node to v12.20.13 (#2594)
chore: update node.js to v12.22.1 (#2590)
chore: update node.js to v16 (#2582)
v12.1.3
chore: update dependency @types/lodash to v4.14.169 (#2589)
chore: update typescript-eslint monorepo to v4.23.0 (#2588)
chore(deps): bump hosted-git-info from 2.8.8 to 2.8.9 (#2587)
chore: update dependency prettier to v2.3.0 (#2586)
chore: update dependency eslint to v7.26.0 (#2585)
chore: update dependency lint-staged to v11 (#2584)
chore: update dependency commitizen to v4.2.4 (#2583)
chore: update typescript-eslint monorepo to v4.22.1 (#2577)
chore: update dependency ts-jest to v26.5.6 (#2581)
chore: update dependency @types/node to v12.20.12 (#2579)
chore: update dependency @babel/preset-env to v7.14.1 (#2576)
fix: update dependency fs-extra to v10 (#2575)
Make cz-commitlint searchable and easy to get start (#2572)
fix: update dependency yargs to v17 (#2574)
docs(local-setup): fix npx command (#2573)
chore: update babel monorepo to v7.14.0 (#2569)
v12.1.2
chore(cz-commitlint): update package name #2547
Feature/cz commitlint (#2547)
chore: update dependency @types/node to v12.20.11 (#2566)
chore: update dependency @types/semver to v7.3.5 (#2563)
chore: update dependency @types/jest to v26.0.23 (#2562)
docs: correct way to get the default module in examples (#2425)
chore: update dependency eslint-plugin-jest to v24.3.6 (#2561)
chore: update dependency eslint-config-prettier to v8.3.0 (#2559)
Remove get-sdtin dependency (#2557)
chore: update dependency eslint to v7.25.0 (#2558)
Update package.json (#2556)
chore: update dependency @babel/core to v7.13.16 (#2555)
docs: update text to husky v6 (#2554)
chore: update dependency @types/node to v12.20.10 (#2551)
chore: update dependency ts-jest to v26.5.5 (#2550)
chore: update dependency @types/node to v12.20.8 (#2549)
chore: update dependency eslint-config-prettier to v8.2.0 (#2548)
Update README.md (#2542)
chore: update typescript-eslint monorepo to v4.22.0 (#2546)
docs: fix husky add hook in 'Getting started' (#2544)
chore: update dependency eslint-plugin-jest to v24.3.5 (#2545)
Fix rules configuration key types (#2541)
chore: update dependency eslint to v7.24.0 (#2543)
fix(types): update chalk import (#2535)
fix(rules): fix subject-full-stop rule config value type (#2534)
chore: update babel monorepo to v7.13.15 (#2540)
chore: update dependency typescript to v4.2.4 (#2539)
chore: update typescript-eslint monorepo to v4.21.0 (#2538)
chore: update dependency eslint-plugin-jest to v24.3.4 (#2537)
chore: update dependency eslint-plugin-jest to v24.3.3 (#2536)
↗ ️ @commitlint/load (indirect, 12.1.1 → 12.1.4) · Repo · Changelog
Release Notes
12.1.4
fix node v10 support
12.1.3
12.1.3 (2021-05-12)
Bug Fixes
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 54 commits:
v12.1.4
Fix/node10 support (#2595)
chore: update babel monorepo to v7.14.2 (#2592)
chore: update dependency @types/node to v12.20.13 (#2594)
chore: update node.js to v12.22.1 (#2590)
chore: update node.js to v16 (#2582)
v12.1.3
chore: update dependency @types/lodash to v4.14.169 (#2589)
chore: update typescript-eslint monorepo to v4.23.0 (#2588)
chore(deps): bump hosted-git-info from 2.8.8 to 2.8.9 (#2587)
chore: update dependency prettier to v2.3.0 (#2586)
chore: update dependency eslint to v7.26.0 (#2585)
chore: update dependency lint-staged to v11 (#2584)
chore: update dependency commitizen to v4.2.4 (#2583)
chore: update typescript-eslint monorepo to v4.22.1 (#2577)
chore: update dependency ts-jest to v26.5.6 (#2581)
chore: update dependency @types/node to v12.20.12 (#2579)
chore: update dependency @babel/preset-env to v7.14.1 (#2576)
fix: update dependency fs-extra to v10 (#2575)
Make cz-commitlint searchable and easy to get start (#2572)
fix: update dependency yargs to v17 (#2574)
docs(local-setup): fix npx command (#2573)
chore: update babel monorepo to v7.14.0 (#2569)
v12.1.2
chore(cz-commitlint): update package name #2547
Feature/cz commitlint (#2547)
chore: update dependency @types/node to v12.20.11 (#2566)
chore: update dependency @types/semver to v7.3.5 (#2563)
chore: update dependency @types/jest to v26.0.23 (#2562)
docs: correct way to get the default module in examples (#2425)
chore: update dependency eslint-plugin-jest to v24.3.6 (#2561)
chore: update dependency eslint-config-prettier to v8.3.0 (#2559)
Remove get-sdtin dependency (#2557)
chore: update dependency eslint to v7.25.0 (#2558)
Update package.json (#2556)
chore: update dependency @babel/core to v7.13.16 (#2555)
docs: update text to husky v6 (#2554)
chore: update dependency @types/node to v12.20.10 (#2551)
chore: update dependency ts-jest to v26.5.5 (#2550)
chore: update dependency @types/node to v12.20.8 (#2549)
chore: update dependency eslint-config-prettier to v8.2.0 (#2548)
Update README.md (#2542)
chore: update typescript-eslint monorepo to v4.22.0 (#2546)
docs: fix husky add hook in 'Getting started' (#2544)
chore: update dependency eslint-plugin-jest to v24.3.5 (#2545)
Fix rules configuration key types (#2541)
chore: update dependency eslint to v7.24.0 (#2543)
fix(types): update chalk import (#2535)
fix(rules): fix subject-full-stop rule config value type (#2534)
chore: update babel monorepo to v7.13.15 (#2540)
chore: update dependency typescript to v4.2.4 (#2539)
chore: update typescript-eslint monorepo to v4.21.0 (#2538)
chore: update dependency eslint-plugin-jest to v24.3.4 (#2537)
chore: update dependency eslint-plugin-jest to v24.3.3 (#2536)
↗ ️ @commitlint/types (indirect, 12.1.1 → 12.1.4) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 54 commits:
v12.1.4
Fix/node10 support (#2595)
chore: update babel monorepo to v7.14.2 (#2592)
chore: update dependency @types/node to v12.20.13 (#2594)
chore: update node.js to v12.22.1 (#2590)
chore: update node.js to v16 (#2582)
v12.1.3
chore: update dependency @types/lodash to v4.14.169 (#2589)
chore: update typescript-eslint monorepo to v4.23.0 (#2588)
chore(deps): bump hosted-git-info from 2.8.8 to 2.8.9 (#2587)
chore: update dependency prettier to v2.3.0 (#2586)
chore: update dependency eslint to v7.26.0 (#2585)
chore: update dependency lint-staged to v11 (#2584)
chore: update dependency commitizen to v4.2.4 (#2583)
chore: update typescript-eslint monorepo to v4.22.1 (#2577)
chore: update dependency ts-jest to v26.5.6 (#2581)
chore: update dependency @types/node to v12.20.12 (#2579)
chore: update dependency @babel/preset-env to v7.14.1 (#2576)
fix: update dependency fs-extra to v10 (#2575)
Make cz-commitlint searchable and easy to get start (#2572)
fix: update dependency yargs to v17 (#2574)
docs(local-setup): fix npx command (#2573)
chore: update babel monorepo to v7.14.0 (#2569)
v12.1.2
chore(cz-commitlint): update package name #2547
Feature/cz commitlint (#2547)
chore: update dependency @types/node to v12.20.11 (#2566)
chore: update dependency @types/semver to v7.3.5 (#2563)
chore: update dependency @types/jest to v26.0.23 (#2562)
docs: correct way to get the default module in examples (#2425)
chore: update dependency eslint-plugin-jest to v24.3.6 (#2561)
chore: update dependency eslint-config-prettier to v8.3.0 (#2559)
Remove get-sdtin dependency (#2557)
chore: update dependency eslint to v7.25.0 (#2558)
Update package.json (#2556)
chore: update dependency @babel/core to v7.13.16 (#2555)
docs: update text to husky v6 (#2554)
chore: update dependency @types/node to v12.20.10 (#2551)
chore: update dependency ts-jest to v26.5.5 (#2550)
chore: update dependency @types/node to v12.20.8 (#2549)
chore: update dependency eslint-config-prettier to v8.2.0 (#2548)
Update README.md (#2542)
chore: update typescript-eslint monorepo to v4.22.0 (#2546)
docs: fix husky add hook in 'Getting started' (#2544)
chore: update dependency eslint-plugin-jest to v24.3.5 (#2545)
Fix rules configuration key types (#2541)
chore: update dependency eslint to v7.24.0 (#2543)
fix(types): update chalk import (#2535)
fix(rules): fix subject-full-stop rule config value type (#2534)
chore: update babel monorepo to v7.13.15 (#2540)
chore: update dependency typescript to v4.2.4 (#2539)
chore: update typescript-eslint monorepo to v4.21.0 (#2538)
chore: update dependency eslint-plugin-jest to v24.3.4 (#2537)
chore: update dependency eslint-plugin-jest to v24.3.3 (#2536)
↗ ️ @types/minimist (indirect, 1.2.1 → 1.2.5) · Repo
Sorry, we couldn't find anything useful about this release.
↗ ️ @types/normalize-package-data (indirect, 2.4.0 → 2.4.4) · Repo
Sorry, we couldn't find anything useful about this release.
↗ ️ @types/parse-json (indirect, 4.0.0 → 4.0.2) · Repo
Sorry, we couldn't find anything useful about this release.
↗ ️ conventional-changelog-angular (indirect, 5.0.12 → 5.0.13) · Repo · Changelog
Release Notes
5.0.13 (from changelog)
Bug Fixes
- conventional-commits-parser: address CVE-2021-23425 (#841) (02b3d53)
Does any of this look wrong? Please let us know.
↗ ️ conventional-changelog-conventionalcommits (indirect, 4.5.0 → 4.6.3) · Repo · Changelog
Release Notes
4.6.3 (from changelog)
Bug Fixes
4.6.2 (from changelog)
Bug Fixes
4.6.1 (from changelog)
Bug Fixes
- conventional-commits-parser: address CVE-2021-23425 (#841) (02b3d53)
4.6.0 (from changelog)
Features
Does any of this look wrong? Please let us know.
↗ ️ conventional-commits-parser (indirect, 3.2.1 → 3.2.4) · Repo · Changelog
Release Notes
3.2.4 (from changelog)
Bug Fixes
3.2.3 (from changelog)
Bug Fixes
3.2.2 (from changelog)
Bug Fixes
- conventional-commits-parser: address CVE-2021-23425 (#841) (02b3d53)
Does any of this look wrong? Please let us know.
↗ ️ decamelize-keys (indirect, 1.1.0 → 1.1.1) · Repo
Sorry, we couldn't find anything useful about this release.
↗ ️ git-raw-commits (indirect, 2.0.10 → 2.0.11) · Repo · Changelog
↗ ️ hosted-git-info (indirect, 2.8.5 → 4.1.0) · Repo · Changelog
Security Advisories 🚨
🚨 Regular Expression Denial of Service in hosted-git-info
The npm package
hosted-git-info
before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
🚨 Regular Expression Denial of Service in hosted-git-info
The npm package
hosted-git-info
before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
↗ ️ lines-and-columns (indirect, 1.1.6 → 1.2.4) · Repo
Sorry, we couldn't find anything useful about this release.
↗ ️ map-obj (indirect, 4.2.1 → 4.3.0) · Repo
Release Notes
4.3.0
- Add
mapObject.mapObjectSkip
for removing object keys (#38) 9ee1876
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
↗ ️ normalize-package-data (indirect, 2.5.0 → 3.0.3) · Repo · Changelog
Commits
See the full diff on Github. The new version differs by 28 commits:
3.0.3
fix(deps) replace resolve with is-core-module (#125)
fix: account for "licence" as spelling variant (#124)
chore(ci): update ci (#123)
Update LICENSE (#109)
docs(README): fix license link to BDS-2-Clause (#119)
fix: Treeshake `semver` dependendency (#113)
3.0.2
hosted-git-info@4.0.1
semver@7.3.4
resolve@1.20.0
tap@14.11.0
3.0.1
chore(publish): there is no linting here yet
hosted-git-info@4.0.0
chore(publish): update publish lifcycle
chore: update badge look
chore: updated .travis.yml ci test environments
3.0.0
fix: broken tests w/ latest hosted-git-info
hosted-git-info@3.0.6
chore: update engines
resolve@1.17.0
semver@7.3.2
chore: remove async dev dep
tap@14.10.8
chore: remove underscore dev dep
chore: update to package-lock v2
↗ ️ spdx-correct (indirect, 3.1.0 → 3.2.0) · Repo
Commits
See the full diff on Github. The new version differs by 21 commits:
3.2.0
Merge pull request #40 from jslicense/contributors
Add GitHub contributors link to README
Remove contributors list from package.json
Remove author from package.json
Merge pull request #39 from lkoskela/fix-transposition-for-lgpl
actions/setup-node@v3
actions/checkout@v3
Run CI GitHub Action for pull requests
Fix transposition of LGPL patterns into a correct LGPL SDPX identifier
Replace Travis CI with GitHub Action
standard-markdown@6.0.0
standard@14.3.4
tape@5.0.1
defence-cli@3.0.1
3.1.1
Merge pull request #29 from jslicense/more-bsd-spellings
Merge pull request #31 from mvandervliet/fix/UPL
Added fix for UPL
support for even more common spellings of BSD license variants
Add support for more common spellings of BSD license variants
↗ ️ spdx-exceptions (indirect, 2.2.0 → 2.5.0) · Repo
Commits
See the full diff on Github. The new version differs by 12 commits:
2.5.0
npm run build
2.4.0
Go back to case-insensitive sort order to avoid a SemVer change
Use `const` in build script
Add GitHub Action to check against latest list
Build separate list of deprecated exception IDs
Add new exceptions (Close #11, Close #34)
2.3.0
Add newline at end of file
Sort ignoring case
Add build script to generate from spdx.org data
↗ ️ spdx-expression-parse (indirect, 3.0.0 → 3.0.1) · Repo
Commits
See the full diff on Github. The new version differs by 18 commits:
3.0.1
Fix #28 incorrect links in README
standard@14.1.0
standard@13.0.2
Use deepStrictEqual instead of deepEqual
Rename test/index.js to test.js
Drop mocha
Configure npm to skip lockfile
Configure Travis CI to test on more Node versions
Configure Travis CI to lint only on latest Node
npx standard --fix
standard@12.0.1
git rm package-lock.json
defence-cli@3.0.1
Use https:// in author URL
Configure Travis CI to test on Node.js 4 and later
standard@11.0.1
mocha@5.2.0
↗ ️ spdx-license-ids (indirect, 3.0.5 → 3.0.18) · Repo
Commits
See the full diff on Github. The new version differs by 52 commits:
3.0.18
update license list to v3.24.0 (2024-05-22)
Fix lint error
Remove ranges from deprecated IDs list
3.0.17
update license list to v3.23 (2024-02-08)
3.0.16
update license list to v3.22 (2023-10-05)
3.0.15
remove checking for ids endsWith +
eslint@8.49.0
tape@5.6.6
3.0.14
update license list to v3.21 (2023-06-18)
bump tape and eslint (#32)
Configure GitHub Actions to run CI for PRs
3.0.13
update license list to v3.20 (2023-02-17) (#31)
3.0.12
update license list to v3.18 (2022-08-11)
Update URLs in README
npm audit fix
Update setup-node GitHub action
3.0.11
update license list to v3.15 (2021-11-14)
Reimplement build.js without get-spdx-license-ids
Fix ESlint configuration
@shinnn/eslint-config@7.0.0
chalk@4.1.2
eslint@8.2.0
tape@5.3.1
3.0.10
update license list to v3.14 (2021-08-08)
3.0.9
update license list to v3.13 (2021-05-20)
3.0.8
update license list to v3.12 (2021-03-07)
Sort results from get-spdx-license-ids
Rename master branch to main
3.0.7
update license list to v3.11 (2020-11-28)
Add semicolons to latest script
Modernize GitHub CI workflow
Move GitHub workflow files to subdirectory
Add GitHub Workflow to check against spdx.org (#22)
Bump kind-of from 6.0.2 to 6.0.3 (#27)
Bump acorn from 6.0.4 to 6.4.1 (#26)
Bump lodash from 4.17.11 to 4.17.20 (#25)
Bump eslint-utils from 1.3.1 to 1.4.3 (#24)
3.0.6
Update repository in package.json (#21)
update license list to v3.10 (2020-08-03) (#19)
↗ ️ string-width (indirect, 4.2.2 → 4.2.3) · Repo
Commits
See the full diff on Github. The new version differs by 1 commit:
↗ ️ trim-newlines (indirect, 3.0.0 → 3.0.1) · Repo
Security Advisories 🚨
🚨 Uncontrolled Resource Consumption in trim-newlines
@rkesters/gnuplot is an easy to use node module to draw charts using gnuplot and ps2pdf. The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the
.end()
method.
Sorry, we couldn't find anything useful about this release.
↗ ️ type-fest (indirect, 0.6.0 → 0.18.1) · Repo
Release Notes
Too many releases to show here. View the full release notes.
Sorry, we couldn't find anything useful about this release.
↗ ️ universalify (indirect, 2.0.0 → 2.0.1) · Repo
Release Notes
2.0.1
- Performance improvements (thanks @H4ad!)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 5 commits:
↗ ️ yargs-parser (indirect, 20.2.7 → 20.2.9)
Sorry, we couldn't find anything useful about this release.
🆕 hasown (added, 2.0.2)
🗑 ️ trim-off-newlines (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase
.
All Depfu comment commands
- @depfu rebase
- Rebases against your default branch and redoes this update
- @depfu recreate
- Recreates this PR, overwriting any edits that you've made to it
- @depfu merge
- Merges this PR once your tests are passing and conflicts are resolved
- @depfu cancel merge
- Cancels automatic merging of this PR
- @depfu close
- Closes this PR and deletes the branch
- @depfu reopen
- Restores the branch and reopens this PR (if it's closed)
- @depfu pause
- Ignores all future updates for this dependency and closes this PR
- @depfu pause [minor|major]
- Ignores all future minor/major updates for this dependency and closes this PR
- @depfu resume
- Future versions of this dependency will create PRs again (leaves this PR as is)