Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump debug, express, compression, method-override, express-session and mongoose in /_learn-nodejs/passport #6

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Jan 11, 2023

Bumps debug to 2.6.9 and updates ancestor dependencies debug, express, compression, method-override, express-session and mongoose. These dependencies need to be updated together.

Updates debug from 1.0.4 to 2.6.9

Release notes

Sourced from debug's releases.

2.6.9

Patches

  • Remove ReDoS regexp in %o formatter: #504

Credits

Huge thanks to @​zhuangya for their help!

release 2.6.7

No release notes provided.

release 2.6.6

No release notes provided.

release 2.6.5

No release notes provided.

release 2.6.4

No release notes provided.

release 2.6.3

No release notes provided.

release 2.6.2

No release notes provided.

release 2.6.1

No release notes provided.

release 2.6.0

No release notes provided.

release 2.5.2

No release notes provided.

release 2.5.1

No release notes provided.

release 2.4.5

No release notes provided.

release 2.4.4

No release notes provided.

release 2.4.3

No release notes provided.

release 2.4.2

No release notes provided.

... (truncated)

Changelog

Sourced from debug's changelog.

2.6.9 / 2017-09-22

  • remove ReDoS regexp in %o formatter (#504)

2.6.8 / 2017-05-18

2.6.7 / 2017-05-16

2.6.5 / 2017-04-27

2.6.4 / 2017-04-20

2.6.3 / 2017-03-13

2.6.2 / 2017-03-10

2.6.1 / 2017-02-10

  • Fix: Module's export default syntax fix for IE8 Expected identifier error
  • Fix: Whitelist DEBUG_FD for values 1 and 2 only (#415, @​pi0)

... (truncated)

Commits

Updates express from 4.8.8 to 4.18.2

Release notes

Sourced from express's releases.

4.18.2

4.18.1

  • Fix hanging on large stack of sync routes

4.18.0

... (truncated)

Changelog

Sourced from express's changelog.

4.18.2 / 2022-10-08

4.18.1 / 2022-04-29

  • Fix hanging on large stack of sync routes

4.18.0 / 2022-04-25

... (truncated)

Commits

Updates compression from 1.0.11 to 1.7.4

Release notes

Sourced from compression's releases.

1.7.4

  • deps: compressible@~2.0.16
    • Mark text/less as compressible
    • deps: mime-db@'>= 1.38.0 < 2'
  • deps: on-headers@~1.0.2
    • Fix res.writeHead patch missing return value
  • perf: prevent unnecessary buffer copy

1.7.3

  • deps: accepts@~1.3.5
    • deps: mime-types@~2.1.18
  • deps: compressible@~2.0.14
    • Mark all XML-derived types as compressible
    • deps: mime-db@'>= 1.34.0 < 2'
  • deps: [email protected]

1.7.2

  • deps: compressible@~2.0.13
    • deps: mime-db@'>= 1.33.0 < 2'

1.7.1

  • deps: accepts@~1.3.4
    • deps: mime-types@~2.1.16
  • deps: [email protected]
  • deps: compressible@~2.0.11
    • deps: mime-db@'>= 1.29.0 < 2'
  • deps: [email protected]
  • deps: vary@~1.1.2
    • perf: improve header token parsing speed

1.7.0

  • Use safe-buffer for improved Buffer API
  • deps: [email protected]
  • deps: compressible@~2.0.10
    • Fix regex fallback to not override compressible: false in db
    • deps: mime-db@'>= 1.27.0 < 2'
  • deps: [email protected]
    • Allow colors in workers
    • Deprecated DEBUG_FD environment variable set to 3 or higher
    • Fix error when running under React Native
    • Fix DEBUG_MAX_ARRAY_LENGTH
    • Use same color for same namespace
    • deps: [email protected]
  • deps: vary@~1.1.1
    • perf: hoist regular expression

1.6.2

... (truncated)

Changelog

Sourced from compression's changelog.

1.7.4 / 2019-03-18

  • deps: compressible@~2.0.16
    • Mark text/less as compressible
    • deps: mime-db@'>= 1.38.0 < 2'
  • deps: on-headers@~1.0.2
    • Fix res.writeHead patch missing return value
  • perf: prevent unnecessary buffer copy

1.7.3 / 2018-07-15

  • deps: accepts@~1.3.5
    • deps: mime-types@~2.1.18
  • deps: compressible@~2.0.14
    • Mark all XML-derived types as compressible
    • deps: mime-db@'>= 1.34.0 < 2'
  • deps: [email protected]

1.7.2 / 2018-02-18

  • deps: compressible@~2.0.13
    • deps: mime-db@'>= 1.33.0 < 2'

1.7.1 / 2017-09-26

  • deps: accepts@~1.3.4
    • deps: mime-types@~2.1.16
  • deps: [email protected]
  • deps: compressible@~2.0.11
    • deps: mime-db@'>= 1.29.0 < 2'
  • deps: [email protected]
  • deps: vary@~1.1.2
    • perf: improve header token parsing speed

1.7.0 / 2017-07-10

  • Use safe-buffer for improved Buffer API
  • deps: [email protected]
  • deps: compressible@~2.0.10
    • Fix regex fallback to not override compressible: false in db
    • deps: mime-db@'>= 1.27.0 < 2'
  • deps: [email protected]
    • Allow colors in workers
    • Deprecated DEBUG_FD environment variable set to 3 or higher
    • Fix error when running under React Native

... (truncated)

Commits

Updates method-override from 2.2.0 to 2.3.10

Release notes

Sourced from method-override's releases.

2.3.10

  • deps: [email protected]
  • deps: parseurl@~1.3.2
    • perf: reduce overhead for full URLs
    • perf: unroll the "fast-path" RegExp
  • deps: vary@~1.1.2
    • perf: improve header token parsing speed
  • perf: skip unnecessary parsing of entire header

2.3.9

2.3.8

  • deps: [email protected]
    • Allow colors in workers
    • Deprecated DEBUG_FD environment variable
    • Fix: DEBUG_MAX_ARRAY_LENGTH
    • Use same color for same namespace

2.3.7

2.3.6

  • deps: methods@~1.1.2
    • perf: enable strict mode
  • deps: parseurl@~1.3.1
    • perf: enable strict mode
  • deps: vary@~1.1.0

2.3.5

  • perf: enable strict mode

2.3.4

  • deps: vary@~1.0.1

2.3.3

2.3.2

  • deps: debug@~2.1.3

... (truncated)

Changelog

Sourced from method-override's changelog.

2.3.10 / 2017-09-27

  • deps: [email protected]
  • deps: parseurl@~1.3.2
    • perf: reduce overhead for full URLs
    • perf: unroll the "fast-path" RegExp
  • deps: vary@~1.1.2
    • perf: improve header token parsing speed
  • perf: skip unnecessary parsing of entire header

2.3.9 / 2017-05-19

2.3.8 / 2017-03-24

  • deps: [email protected]
    • Allow colors in workers
    • Deprecated DEBUG_FD environment variable
    • Fix: DEBUG_MAX_ARRAY_LENGTH
    • Use same color for same namespace

2.3.7 / 2016-11-19

2.3.6 / 2016-05-20

  • deps: methods@~1.1.2
    • perf: enable strict mode
  • deps: parseurl@~1.3.1
    • perf: enable strict mode
  • deps: vary@~1.1.0

2.3.5 / 2015-07-31

  • perf: enable strict mode

... (truncated)

Commits

Updates express-session from 1.7.6 to 1.17.3

Release notes

Sourced from express-session's releases.

1.17.3

1.17.2

1.17.1

  • Fix internal method wrapping error on failed reloads

1.17.0

1.16.2

  • Fix restoring cookie.originalMaxAge when store returns Date
  • deps: parseurl@~1.3.3

1.16.1

  • Fix error passing data option to Cookie constructor
  • Fix uncaught error from bad session data

1.16.0

  • Catch invalid cookie.maxAge value earlier
  • Deprecate setting cookie.maxAge to a Date object
  • Fix issue where resave: false may not save altered sessions
  • Remove utils-merge dependency
  • Use safe-buffer for improved Buffer API
  • Use Set-Cookie as cookie header name for compatibility
  • deps: depd@~2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
    • perf: remove argument reassignment
  • deps: on-headers@~1.0.2
    • Fix res.writeHead patch missing return value

1.15.6

  • deps: [email protected]
  • deps: parseurl@~1.3.2
    • perf: reduce overhead for full URLs
    • perf: unroll the "fast-path" RegExp
  • deps: uid-safe@~2.1.5
    • perf: remove only trailing =
  • deps: [email protected]

1.15.5

  • Fix TypeError when req.url is an empty string

... (truncated)

Changelog

Sourced from express-session's changelog.

1.17.3 / 2022-05-11

1.17.2 / 2021-05-19

1.17.1 / 2020-04-16

  • Fix internal method wrapping error on failed reloads

1.17.0 / 2019-10-10

1.16.2 / 2019-06-12

  • Fix restoring cookie.originalMaxAge when store returns Date
  • deps: parseurl@~1.3.3

1.16.1 / 2019-04-11

  • Fix error passing data option to Cookie constructor
  • Fix uncaught error from bad session data

1.16.0 / 2019-04-10

  • Catch invalid cookie.maxAge value earlier
  • Deprecate setting cookie.maxAge to a Date object
  • Fix issue where resave: false may not save altered sessions
  • Remove utils-merge dependency
  • Use safe-buffer for improved Buffer API
  • Use Set-Cookie as cookie header name for compatibility
  • deps: depd@~2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
    • perf: remove argument reassignment

... (truncated)

Commits

Updates mongoose from 3.8.40 to 6.8.3

Release notes

Sourced from mongoose's releases.

6.8.3 / 2023-01-06

  • perf: improve performance of assignRawDocsToIdStructure for faster populate on large docs #12867 Uzlopak
  • fix(model): ensure consistent ordering of validation errors in insertMany() with ordered: false and rawResult: true #12866
  • fix: avoid passing final callback to pre hook, because calling the callback can mess up hook execution #12836
  • fix(types): avoid inferring timestamps if methods, virtuals, or statics set #12871
  • fix(types): correctly infer string enums on const arrays #12870 JavaScriptBach
  • fix(types): allow virtuals to be invoked in the definition of other virtuals #12874 sffc
  • fix(types): add type def for Aggregate#model without arguments #12864 hasezoey
  • docs(discriminators): add section about changing discriminator key #12861
  • docs(typescript): explain that virtuals inferred from schema only show up on Model, not raw document type #12860 #12684

6.8.2 / 2022-12-28

  • fix(schema): propagate strictQuery to implicitly created schemas for embedded discriminators #12827 #12796
  • fix(model): respect discriminators with Model.validate() #12824 #12621
  • fix(query): fix unexpected validation error when doing findOneAndReplace() with a nullish value #12826 #12821
  • fix(discriminator): apply built-in plugins to discriminator schema even if mergeHooks and mergePlugins are both false #12833 #12696
  • fix(types): add option "overwriteModels" as a schema option #12817 #12816 hasezoey
  • fix(types): add property "defaultOptions" #12818 hasezoey
  • docs: make search bar respect documentation version, so you can search 5.x docs #12548
  • docs(typescript): make note about recommending strict mode when using auto typed schemas #12825 #12420
  • docs: add section on sorting to query docs #12588 IslandRhythms
  • test(query.test): add write-concern option #12829 hasezoey

6.8.1 / 2022-12-19

  • fix(query): avoid throwing circular dependency error if same object is used in multiple properties #12774 orgads
  • fix(map): return value from super.delete() #12777 danbrud
  • fix(populate): handle virtual populate underneath document array with justOne=true and sort set where 1 element has only 1 result #12815 #12730
  • fix(update): handle embedded discriminators when casting array filters #12802 #12565
  • fix(populate): avoid calling transform if there's no populate results and using lean #12804 #12739
  • fix(model): prevent index creation on syncIndexes if not necessary #12785 #12250 lpizzinidev
  • fix(types): correctly infer this when using pre('updateOne') with { document: true, query: false } #12778
  • fix(types): make InferSchemaType: consider { required: boolean } required if it isn't explicitly false #12784 JavaScriptBach
  • docs: replace many occurrences of "localhost" with "127.0.0.1" #12811 #12741 hasezoey SadiqOnGithub
  • docs(mongoose): Added missing options to set #12810 lpizzinidev
  • docs: add info on $locals parameters to getters/setters tutorial #12814 #12550 IslandRhythms
  • docs: make Document.prototype.$clone() public #12803
  • docs(query): updated explanation for slice #12776 #12474 lpizzinidev
  • docs(middleware): fix broken links #12787 lpizzinidev
  • docs(queries): fixed broken links #12790 lpizzinidev

6.8.0 / 2022-12-05

... (truncated)

Changelog

Sourced from mongoose's changelog.

6.8.3 / 2023-01-06

  • perf: improve performance of assignRawDocsToIdStructure for faster populate on large docs #12867 Uzlopak
  • fix(model): ensure consistent ordering of validation errors in insertMany() with ordered: false and rawResult: true #12866
  • fix: avoid passing final callback to pre hook, because calling the callback can mess up hook execution #12836
  • fix(types): avoid inferring timestamps if methods, virtuals, or statics set #12871
  • fix(types): correctly infer string enums on const arrays #12870 JavaScriptBach
  • fix(types): allow virtuals to be invoked in the definition of other virtuals #12874 sffc
  • fix(types): add type def for Aggregate#model without arguments #12864 hasezoey
  • docs(discriminators): add section about changing discriminator key #12861
  • docs(typescript): explain that virtuals inferred from schema only show up on Model, not raw document type #12860 #12684

6.8.2 / 2022-12-28

  • fix(schema): propagate strictQuery to implicitly created schemas for embedded discriminators #12827 #12796
  • fix(model): respect discriminators with Model.validate() #12824 #12621
  • fix(query): fix unexpected validation error when doing findOneAndReplace() with a nullish value #12826 #12821
  • fix(discriminator): apply built-in plugins to discriminator schema even if mergeHooks and mergePlugins are both false #12833 #12696
  • fix(types): add option "overwriteModels" as a schema option #12817 #12816 hasezoey
  • fix(types): add property "defaultOptions" #12818 hasezoey
  • docs: make search bar respect documentation version, so you can search 5.x docs #12548
  • docs(typescript): make note about recommending strict mode when using auto typed schemas #12825 #12420
  • docs: add section on sorting to query docs #12588 IslandRhythms
  • test(query.test): add write-concern option #12829 hasezoey

6.8.1 / 2022-12-19

  • fix(query): avoid throwing circular dependency error if same object is used in multiple properties #12774 orgads
  • fix(map): return value from super.delete() #12777 danbrud
  • fix(populate): handle virtual populate underneath document array with justOne=true and sort set where 1 element has only 1 result #12815 #12730
  • fix(update): handle embedded discriminators when casting array filters #12802 #12565
  • fix(populate): avoid calling transform if there's no populate results and using lean #12804 #12739
  • fix(model): prevent index creation on syncIndexes if not necessary #12785 #12250 lpizzinidev
  • fix(types): correctly infer this when using pre('updateOne') with { document: true, query: false } #12778
  • fix(types): make InferSchemaType: consider { required: boolean } required if it isn't explicitly false #12784 JavaScriptBach
  • docs: replace many occurrences of "localhost" with "127.0.0.1" #12811 #12741 hasezoey SadiqOnGithub
  • docs(mongoose): Added missing options to set #12810 lpizzinidev
  • docs: add info on $locals parameters to getters/setters tutorial #12814 #12550 IslandRhythms
  • docs: make Document.prototype.$clone() public #12803
  • docs(query): updated explanation for slice #12776 #12474 lpizzinidev
  • docs(middleware): fix broken links #12787 lpizzinidev
  • docs(queries): fixed broken links #12790 lpizzinidev

6.8.0 / 2022-12-05

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

…d mongoose

Bumps [debug](https://github.com/debug-js/debug) to 2.6.9 and updates ancestor dependencies [debug](https://github.com/debug-js/debug), [express](https://github.com/expressjs/express), [compression](https://github.com/expressjs/compression), [method-override](https://github.com/expressjs/method-override), [express-session](https://github.com/expressjs/session) and [mongoose](https://github.com/Automattic/mongoose). These dependencies need to be updated together.


Updates `debug` from 1.0.4 to 2.6.9
- [Release notes](https://github.com/debug-js/debug/releases)
- [Changelog](https://github.com/debug-js/debug/blob/2.6.9/CHANGELOG.md)
- [Commits](debug-js/debug@1.0.4...2.6.9)

Updates `express` from 4.8.8 to 4.18.2
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/master/History.md)
- [Commits](expressjs/express@4.8.8...4.18.2)

Updates `compression` from 1.0.11 to 1.7.4
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](expressjs/compression@1.0.11...1.7.4)

Updates `method-override` from 2.2.0 to 2.3.10
- [Release notes](https://github.com/expressjs/method-override/releases)
- [Changelog](https://github.com/expressjs/method-override/blob/master/HISTORY.md)
- [Commits](expressjs/method-override@2.2.0...2.3.10)

Updates `express-session` from 1.7.6 to 1.17.3
- [Release notes](https://github.com/expressjs/session/releases)
- [Changelog](https://github.com/expressjs/session/blob/master/HISTORY.md)
- [Commits](expressjs/session@v1.7.6...v1.17.3)

Updates `mongoose` from 3.8.40 to 6.8.3
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@3.8.40...6.8.3)

---
updated-dependencies:
- dependency-name: debug
  dependency-type: indirect
- dependency-name: express
  dependency-type: direct:production
- dependency-name: compression
  dependency-type: direct:production
- dependency-name: method-override
  dependency-type: direct:production
- dependency-name: express-session
  dependency-type: direct:production
- dependency-name: mongoose
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants