-
-
Notifications
You must be signed in to change notification settings - Fork 2
Bump the npm_and_yarn group across 1 directory with 14 updates #21
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
9trocode
merged 2 commits into
master
from
dependabot/npm_and_yarn/npm_and_yarn-0dbb24436e
Nov 14, 2025
Merged
Bump the npm_and_yarn group across 1 directory with 14 updates #21
9trocode
merged 2 commits into
master
from
dependabot/npm_and_yarn/npm_and_yarn-0dbb24436e
Nov 14, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the npm_and_yarn group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [cloudinary](https://github.com/cloudinary/cloudinary_npm) | `1.19.0` | `2.7.0` | | [ansi-regex](https://github.com/chalk/ansi-regex) | `3.0.0` | `3.0.1` | | [ansi-regex](https://github.com/chalk/ansi-regex) | `4.1.0` | `4.1.1` | | [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` | | [date-and-time](https://github.com/knowledgecode/date-and-time) | `0.12.0` | `0.14.2` | | [debug](https://github.com/debug-js/debug) | `4.1.1` | `4.4.3` | | [get-func-name](https://github.com/chaijs/get-func-name) | `2.0.0` | `2.0.2` | | [json-bigint](https://github.com/sidorares/json-bigint) | `0.3.0` | `1.0.0` | | [pathval](https://github.com/chaijs/pathval) | `1.1.0` | `1.1.1` | | [xml2js](https://github.com/Leonidas-from-XIV/node-xml2js) | `0.4.19` | `0.6.2` | Updates `cloudinary` from 1.19.0 to 2.7.0 - [Release notes](https://github.com/cloudinary/cloudinary_npm/releases) - [Changelog](https://github.com/cloudinary/cloudinary_npm/blob/master/CHANGELOG.md) - [Commits](cloudinary/cloudinary_npm@1.19.0...2.7.0) Updates `ansi-regex` from 3.0.0 to 3.0.1 - [Release notes](https://github.com/chalk/ansi-regex/releases) - [Commits](chalk/ansi-regex@v3.0.0...v3.0.1) Updates `ansi-regex` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/chalk/ansi-regex/releases) - [Commits](chalk/ansi-regex@v3.0.0...v3.0.1) Updates `braces` from 3.0.2 to 3.0.3 - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) Updates `date-and-time` from 0.12.0 to 0.14.2 - [Release notes](https://github.com/knowledgecode/date-and-time/releases) - [Commits](knowledgecode/date-and-time@v0.12.0...v0.14.2) Updates `debug` from 4.1.1 to 4.4.3 - [Release notes](https://github.com/debug-js/debug/releases) - [Commits](debug-js/debug@4.1.1...4.4.3) Updates `flat` from 4.1.0 to 5.0.2 - [Release notes](https://github.com/hughsk/flat/releases) - [Commits](hughsk/flat@4.1.0...5.0.2) Updates `get-func-name` from 2.0.0 to 2.0.2 - [Release notes](https://github.com/chaijs/get-func-name/releases) - [Commits](https://github.com/chaijs/get-func-name/commits/v2.0.2) Updates `json-bigint` from 0.3.0 to 1.0.0 - [Commits](sidorares/json-bigint@v0.3.0...v1.0.0) Updates `lodash` from 4.17.15 to 4.17.21 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.15...4.17.21) Updates `node-fetch` from 2.6.0 to 2.7.0 - [Release notes](https://github.com/node-fetch/node-fetch/releases) - [Commits](node-fetch/node-fetch@v2.6.0...v2.7.0) Updates `pathval` from 1.1.0 to 1.1.1 - [Release notes](https://github.com/chaijs/pathval/releases) - [Changelog](https://github.com/chaijs/pathval/blob/master/CHANGELOG.md) - [Commits](chaijs/pathval@v1.1.0...v1.1.1) Updates `xml2js` from 0.4.19 to 0.6.2 - [Commits](Leonidas-from-XIV/node-xml2js@0.4.19...0.6.2) Updates `y18n` from 4.0.0 to 5.0.8 - [Release notes](https://github.com/yargs/y18n/releases) - [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md) - [Commits](yargs/y18n@v4.0.0...v5.0.8) Updates `yargs-parser` from 13.1.1 to 21.1.1 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md) - [Commits](yargs/yargs-parser@v13.1.1...yargs-parser-v21.1.1) --- updated-dependencies: - dependency-name: cloudinary dependency-version: 2.7.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ansi-regex dependency-version: 3.0.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ansi-regex dependency-version: 4.1.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: braces dependency-version: 3.0.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: date-and-time dependency-version: 0.14.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: debug dependency-version: 4.4.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: flat dependency-version: 5.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: get-func-name dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json-bigint dependency-version: 1.0.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.17.21 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: node-fetch dependency-version: 2.7.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: pathval dependency-version: 1.1.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: xml2js dependency-version: 0.6.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: y18n dependency-version: 5.0.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yargs-parser dependency-version: 21.1.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Nov 13, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update javascript code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the npm_and_yarn group with 9 updates in the / directory:
1.19.02.7.03.0.03.0.14.1.04.1.13.0.23.0.30.12.00.14.24.1.14.4.32.0.02.0.20.3.01.0.01.1.01.1.10.4.190.6.2Updates
cloudinaryfrom 1.19.0 to 2.7.0Release notes
Sourced from cloudinary's releases.
... (truncated)
Changelog
Sourced from cloudinary's changelog.
... (truncated)
Commits
923a66eVersion 2.7.0ec4b65ffix: prevent parameter injection via ampersand in parameter values (#709)c7f784dVersion 2.6.14afcd36fix: uploader methods return correct type (#706)ad90190Version 2.6.064bdc9dfix: defaults for related asset methods and proper content_type (#705)25e04e6Updated Sample Projects (#698)265ccb8fix: metadata field datasource type (#693)d6c51e2feat: Add support for DELETE /resources/backup/:asset_id (#700)c072e37Minor typo fix (#703)Updates
ansi-regexfrom 3.0.0 to 3.0.1Commits
f545bdb3.0.1c57d4c2fix a few old XO issues for backport419250fFix potential ReDoS (#37)Updates
ansi-regexfrom 4.1.0 to 4.1.1Commits
f545bdb3.0.1c57d4c2fix a few old XO issues for backport419250fFix potential ReDoS (#37)Updates
bracesfrom 3.0.2 to 3.0.3Commits
74b2db23.0.388f1429update eslint. lint, fix unit tests.415d660Snyk js braces 6838727 (#40)190510ffix tests, skip 1 test in test/braces.expand716eb9freadme bumpa5851e5Merge pull request #37 from coderaiser/fix/vulnerability2092bd1feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cffix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9remove funding file665ab5dupdate keepEscaping doc (#27)Updates
date-and-timefrom 0.12.0 to 0.14.2Commits
6dab608Updated README.md0bda3b4Bump version9e4b501Fixed regular expression denial of service (ReDoS) vulnerability73103a3Merge branch 'dependabot/npm_and_yarn/bl-4.0.3' into master93bf9daBump bl from 4.0.2 to 4.0.35597efaMerge branch 'develop' into masterc158464Updated README.md1748bc2Bump version9f7941c#41 Fixed a bug characters inside square brackets are not validated6f726d9Merge branch 'develop'Updates
debugfrom 4.1.1 to 4.4.3Release notes
Sourced from debug's releases.
... (truncated)
Commits
6b2c5fb4.4.333330fa4.4.198df33eremove istanbulbf2f574fixes #987 fallback to localStorage.DEBUG if debug is not defined (#988)a0497bdReplace whitespaces in namespaces string with commas globally instead of just...7e3814c4.4.0d2d6bf0fix inefficient .enable() regex and .enabled() testbc609144.3.7c63e96eUpgrade ms to version 2.1.3 (#819)382864aremove archaic badges from readmeMaintainer changes
This version was pushed to npm by qix, a new releaser for debug since your current version.
Updates
flatfrom 4.1.0 to 5.0.2Commits
e5ffd66Release 5.0.2fdb79d5Update dependencies, refresh lockfile, format with standard.e52185dTest against node 14 in CI.0189cb1Avoid arrow function syntax.f25d3a1Release 5.0.154cc7aduse standard formatting779816edrop dependencies2eea6d3Bump lodash from 4.17.15 to 4.17.19a61a554Bump acorn from 7.1.0 to 7.4.020ef0efFix prototype pollution on unflattenMaintainer changes
This version was pushed to npm by timoxley, a new releaser for flat since your current version.
Updates
get-func-namefrom 2.0.0 to 2.0.2Release notes
Sourced from get-func-name's releases.
Commits
Maintainer changes
This version was pushed to npm by keithamus, a new releaser for get-func-name since your current version.
Updates
json-bigintfrom 0.3.0 to 1.0.0Commits
390482a1.0.0f2d8f83typo6ee392eMerge pull request #37 from sidorares/fix/prototypec85a430MAJOR: Add protoAction and constructorAction options4c2dbf4build: add node 14b348ea3fix assertion after chai upgrade725777cadd files section and bump depsebd1d91add prettier config6c659f5Merge pull request #36 from babyadoresorange/master1556563update READMEUpdates
lodashfrom 4.17.15 to 4.17.21Commits
f299b52Bump to v4.17.21c4847ebImprove performance oftoNumber,trimandtrimEndon large input strings3469357Prevent command injection through_.template'svariableoptionded9bc6Bump to v4.17.20.63150efDocumentation fixes.00f0f62test.js: Remove trailing comma.846e434Temporarily use a custom fork oflodash-cli.5d046f3Re-enable Travis tests on4.17branch.aa816b3Remove/npm-package.d7fbc52Bump to v4.17.19Maintainer changes
This version was pushed to npm by bnjmnt4n, a new releaser for lodash since your current version.
Updates
node-fetchfrom 2.6.0 to 2.7.0Release notes
Sourced from node-fetch's releases.
... (truncated)
Commits
9b9d458feat:AbortError(#1744)65ae25afix: Remove the default connection close header (#1765)8bc3a7cfix: socket variable testing for undefined (#1726)afb36f6Revert "fix: handle bom in text and json (#1739)" (#1741)29909d7fix: handle bom in text and json (#1739)70f592dfix: "global is not defined" (#1704)0f1ebb0Prevent error when response is null (#1699)6e9464dci(release): install dependenciesdd2a0baci(release): install dependencies49bef02ci(release): use latest Node LTSMaintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates
pathvalfrom 1.1.0 to 1.1.1Release notes
Sourced from pathval's releases.
Commits
db6c3e3chore: v1.1.17859e0eMerge pull request #60 from deleonio/fix/vulnerability-prototype-pollution49ce1f4style: correct rule in package.jsonc77b9d2fix: prototype pollution vulnerability + working tests49031e4chore: remove very old nodejs57730a9chore: update deps and tool configurationa123018Merge pull request #55 from chaijs/remove-lgtm07eb4a8Delete MAINTAINERSa0147cdMerge pull request #54 from astorije/patch-1aebb278Center repo name on READMEMaintainer changes
This version was pushed to npm by chai, a new releaser for pathval since your current version.
Updates
xml2jsfrom 0.4.19 to 0.6.2Commits
cf3e061New release, 0.6.2cb2f77eFix read-only constraint via mistyped key name8e9a120Update version number for release 0.6.130f9d61Replace filtering of names withdefinePropertyba46e54Update package lock0e29f0eRelease new versiona25035cRemove old unused files1de4688Merge pull request #680 from Leonidas-from-XIV/zap-dependency-fix3b97ae5Merge pull request #681 from Leonidas-from-XIV/cve-compat-fix167a385Fix zap to be the original dependencyUpdates
y18nfrom 4.0.0 to 5.0.8Release notes
Sourced from y18n's releases.
Changelog
Sourced from y18n's changelog.
... (truncated)
Commits
58a9a3cchore: release 5.0.8 (#129)b1c215afix(deno): force modern release for Denoe73fb19chore: release 5.0.7 (#123)d3f2560fix(deno): force release for deno (#121)e9fda61chore: release 5.0.6 (#118)6966fa9fix(webpack): skip readFileSync if not defined (#117)c755582docs: add entry for v4.0.1 (#114)2d4c56cchore(deps): update dependency standardx to v6 (#110)b64ae70chore: release 5.0.5 (#109)a9ac604fix: address prototype pollution issue (#108)Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for y18n since your current version.
Updates
yargs-parserfrom 13.1.1 to 21.1.1Release notes
Sourced from yargs-parser's releases.
... (truncated)
Changelog
Sourced from yargs-parser's changelog.
... (truncated)
Commits
3aba24cchore(main): release yargs-parser 21.1.1 (#455)d69f9c3fix(typescript): ignore .cts files during publish (#454)90067a0chore(main): release yargs-parser 21.1.0 (#446)d07bcdbfix: node version check now uses process.versions.node (#450)c0c6079chore(deps): update dependency puppeteer to v16 (#451)a89259ffeat: allow the browser build to be imported (#443)c474bc1fix(halt-at-non-option): prevent known args from being parsed when "unknown-o...fd30238chore(deps): update dependency serve to v14 (#449)a072f9achore(deps): update dependency puppeteer to v15 (#444)4f1060bfix: parse options ending with 3+ hyphens (#434)Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for yargs-parser since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.