chore(deps): bump cookie, cookie-parser and express in /api
Created by: dependabot[bot]
Bumps cookie to 0.7.2 and updates ancestor dependencies cookie, cookie-parser and express. These dependencies need to be updated together.
Updates cookie
from 0.4.1 to 0.7.2
Release notes
Sourced from cookie's releases.
v0.7.2
Fixed
- Fix object assignment of
hasOwnProperty
(#177) bc38ffdhttps://github.com/jshttp/cookie/compare/v0.7.1...v0.7.2
0.7.1
Fixed
- Allow leading dot for domain (#174)
- Although not permitted in the spec, some users expect this to work and user agents ignore the leading dot according to spec
- Add fast path for
serialize
without options, useobj.hasOwnProperty
when parsing (#172)https://github.com/jshttp/cookie/compare/v0.7.0...v0.7.1
0.7.0
- perf: parse cookies ~10% faster (#144 by
@kurtextrem
and #170)- fix: narrow the validation of cookies to match RFC6265 (#167 by
@bewinsnw
)- fix: add
main
topackage.json
for rspack (#166 by@proudparrot2
)https://github.com/jshttp/cookie/compare/v0.6.0...v0.7.0
0.6.0
- Add
partitioned
option0.5.0
- Add
priority
option- Fix
expires
option to reject invalid dates- pref: improve default decode speed
- pref: remove slow string split in parse
0.4.2
- pref: read value only when assigning in parse
- pref: remove unnecessary regexp in parse
Commits
-
d19eaa1
0.7.2 -
bc38ffd
Fix object assignment ofhasOwnProperty
(#177) -
cf4658f
0.7.1 -
6a8b8f5
Allow leading dot for domain (#174) -
58015c0
Remove more code and perf wins (#172) -
ab057d6
0.7.0 -
5f02ca8
Migrate history to GitHub releases -
a5d591c
Migrate history to GitHub releases -
51968f9
Skip isNaN -
9e7ca51
perf(parse): cache length, return early (#144) - Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by blakeembrey, a new releaser for cookie since your current version.
Updates cookie-parser
from 1.4.6 to 1.4.7
Release notes
Sourced from cookie-parser's releases.
1.4.7
What's Changed
- chore: add support for OSSF scorecard reporting by
@inigomarquinez
in expressjs/cookie-parser#103- ci: fix errors in ci github action for node 8 and 9 by
@inigomarquinez
in expressjs/cookie-parser#104- ci: Use GITHUB_OUTPUT envvar instead of set-output command by
@arunsathiya
in expressjs/cookie-parser#100- deps: cookie@0.7.2 by
@SamChatfield
in expressjs/cookie-parser#116- Release: 1.4.7 by
@UlisesGascon
in expressjs/cookie-parser#117New Contributors
@inigomarquinez
made their first contribution in expressjs/cookie-parser#103@arunsathiya
made their first contribution in expressjs/cookie-parser#100@SamChatfield
made their first contribution in expressjs/cookie-parser#116@UlisesGascon
made their first contribution in expressjs/cookie-parser#117Full Changelog: https://github.com/expressjs/cookie-parser/compare/1.4.6...1.4.7
Changelog
Sourced from cookie-parser's changelog.
1.4.7 / 2024-10-08
- deps: cookie@0.7.2
- Fix object assignment of
hasOwnProperty
- deps: cookie@0.7.1
- Allow leading dot for domain
- Although not permitted in the spec, some users expect this to work and user agents ignore the leading dot according to spec
- Add fast path for
serialize
without options, useobj.hasOwnProperty
when parsing- deps: cookie@0.7.0
- perf: parse cookies ~10% faster
- fix: narrow the validation of cookies to match RFC6265
- fix: add
main
topackage.json
for rspack- deps: cookie@0.6.0
- Add
partitioned
option- deps: cookie@0.5.0
- Add
priority
option- Fix
expires
option to reject invalid dates- pref: improve default decode speed
- pref: remove slow string split in parse
- deps: cookie@0.4.2
- pref: read value only when assigning in parse
- pref: remove unnecessary regexp in parse
Commits
-
5d61e1e
1.4.7 -
ccf1f54
deps: cookie@0.7.2 (#116) -
429cfd4
ci: Use GITHUB_OUTPUT envvar instead of set-output command (#100) -
ca4c97e
ci: fix errors in ci pipeline for node 8 and 9 (#104) -
97bdf39
ci: add support for OSSF scorecard reporting (#103) -
e5862bd
build: Node.js@17.6 -
f0688d2
build: Node.js@14.19 -
44ec541
build: Node.js@16.14 -
695435a
deps: cookie@0.4.2 -
f66e7e1
build: mocha@9.2.1 - Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for cookie-parser since your current version.
Updates express
from 4.21.0 to 4.21.1
Release notes
Sourced from express's releases.
4.21.1
What's Changed
- Backport a fix for CVE-2024-47764 to the 4.x branch by
@joshbuker
in expressjs/express#6029- Release: 4.21.1 by
@UlisesGascon
in expressjs/express#6031Full Changelog: https://github.com/expressjs/express/compare/4.21.0...4.21.1
Commits
-
8e229f9
4.21.1 -
a024c8a
fix(deps): cookie@0.7.1 - See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.