Skip to content

fix(deps): update minor and patch dependencies for gatsby-source-drupal - #481

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/gatsby-source-drupal-prod-minor
Open

fix(deps): update minor and patch dependencies for gatsby-source-drupal#481
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/gatsby-source-drupal-prod-minor

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2023

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
agentkeepalive ^4.2.1^4.6.0 age adoption passing confidence
body-parser ^1.20.0^1.20.6 age adoption passing confidence
fastq ^1.13.0^1.20.1 age adoption passing confidence
got ^11.8.5^11.8.6 age adoption passing confidence
http2-wrapper ^2.1.11^2.2.1 age adoption passing confidence
lodash (source) ^4.17.21^4.18.1 age adoption passing confidence
probe-image-size ^7.2.3^7.3.0 age adoption passing confidence

Release Notes

node-modules/agentkeepalive (agentkeepalive)

v4.6.0

Compare Source

==================

features

v4.5.0

Compare Source

==================

others

  • [1e5e312] - deps: remove debug and depd (#​114) (fengmk2 <<fengmk2@​gmail.com>>)

v4.4.0

Compare Source

==================

features

v4.3.0

Compare Source

==================

others

expressjs/body-parser (body-parser)

v1.20.6

Compare Source

What's Changed

Full Changelog: expressjs/body-parser@1.20.5...1.20.6

v1.20.5

Compare Source

What's Changed

The reason for this release is a fix to the extended urlencoded parser returning objects instead of arrays for large array inputs (> 100) on qs@​6.14.2+. (#​716)

New Contributors

Special thanks to triager @​krzysdz for keeping this on our radar and effectively triaging the specific issue!

Full Changelog: expressjs/body-parser@1.20.4...1.20.5

v1.20.4

Compare Source

===================

  • deps: qs@~6.14.0
  • deps: use tilde notation for dependencies
  • deps: http-errors@~2.0.1
  • deps: raw-body@~2.5.3

v1.20.3

Compare Source

===================

  • deps: qs@​6.13.0
  • add depth option to customize the depth level in the parser
  • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)

v1.20.2

Compare Source

===================

  • Fix strict json error message on Node.js 19+
  • deps: content-type@~1.0.5
    • perf: skip value escaping when unnecessary
  • deps: raw-body@​2.5.2

v1.20.1

Compare Source

===================

  • deps: qs@​6.11.0
  • perf: remove unnecessary object clone
mcollina/fastq (fastq)

v1.20.1

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.19.1...v1.20.1

v1.20.0

Compare Source

v1.19.1

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.19.0...v1.19.1

v1.19.0

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.18.0...v1.19.0

v1.18.0

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.17.1...v1.18.0

v1.17.1

Compare Source

What's Changed

Full Changelog: mcollina/fastq@v1.17.0...v1.17.1

v1.17.0

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.15.0...v1.17.0

v1.16.0

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.15.0...v1.16.0

v1.15.0

Compare Source

What's Changed

  • fix: queueAsPromised.drained() resolves while queue is idle by @​0xOlias in #​64

New Contributors

Full Changelog: mcollina/fastq@v1.14.0...v1.15.0

v1.14.0

Compare Source

What's Changed

New Contributors

Full Changelog: mcollina/fastq@v1.13.0...v1.14.0

sindresorhus/got (got)

v11.8.6

Compare Source

  • Destroy request object after successful response
szmarczak/http2-wrapper (http2-wrapper)

v2.2.1

Compare Source

v2.2.0

Compare Source

  • Fix buffer queue memory leak 51eeaf5
  • Print status message when proxy server rejects 7a9a46a
lodash/lodash (lodash)

v4.18.1

Compare Source

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See #​6167 (comment)

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

v4.18.0

Compare Source

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs
  • Add security notice for _.template in threat model and API docs (#​6099)
  • Document lower > upper behavior in _.random (#​6115)
  • Fix quotes in _.compact jsdoc (#​6090)
lodash.* modular packages

Diff

We have also regenerated and published a select number of the lodash.* modular packages.

These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:

v4.17.23

Compare Source

nodeca/probe-image-size (probe-image-size)

v7.3.0

Compare Source

Fixed
  • Fixed .readXXX() helpers in sync parsers.
  • Improved BMP format handling, #​77.
  • Ensure width/height are positive.
  • Fixed max redirects handling, #​81.
  • Fixed webp sync parser (adjust to streamed version).
  • Add bounds check to sync ICO parser.

Configuration

📅 Schedule: (in timezone GMT)

  • Branch creation
    • "before 7am on the first day of the month"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from aea3387 to 8c4c3fc Compare December 1, 2023 00:26
@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from 8c4c3fc to beebae7 Compare January 1, 2024 02:28
@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from beebae7 to 62dc48f Compare February 1, 2024 01:11
@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from 62dc48f to 4bc7fd5 Compare March 1, 2024 00:45
@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from 4bc7fd5 to ba302bf Compare October 1, 2024 00:42
@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from ba302bf to 92c11da Compare June 1, 2026 01:19
@renovate
renovate Bot force-pushed the renovate/gatsby-source-drupal-prod-minor branch from 92c11da to b06e4cf Compare August 1, 2026 01:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants