Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Bump json5 and babelify in /test/dummy#227

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
dependabot wants to merge1 commit intomaster
base:master
Choose a base branch
Loading
fromdependabot/npm_and_yarn/test/dummy/json5-and-babelify-2.2.3

Conversation

dependabot[bot]
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubJan 6, 2023

Bumpsjson5 to 2.2.3 and updates ancestor dependencybabelify. These dependencies need to be updated together.

Updatesjson5 from 0.5.1 to 2.2.3

Release notes

Sourced fromjson5's releases.

v2.2.3

  • Fix: json5@2.2.3 is now the 'latest' release according to npm instead of v1.0.2. (#299)

v2.2.2

  • Fix: Properties with the name__proto__ are added to objects and arrays.(#199) This also fixes a prototype pollution vulnerability reported byJonathan Gregson! (#295).

v2.2.1

v2.2.0

  • New: Accurate and documented TypeScript declarations are now included. There is no need to install@types/json5. (#236,#244)

v2.1.3 [code,diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228,#229)

v2.1.2

  • Fix: Bumpminimist tov1.2.5. (#222)

v2.1.1

  • New:package.json andpackage.json5 include amodule property sobundlers like webpack, rollup and parcel can take advantage of the ES Modulebuild. (#208)
  • Fix:stringify outputs\0 as\\x00 when followed by a digit. (#210)
  • Fix: Spelling mistakes have been fixed. (#196)

v2.1.0

  • New: Theindex.mjs andindex.min.mjs browser builds in thedist directory support ES6 modules. (#187)

v2.0.1

  • Fix: The browser builds in thedist directory support ES5. (#182)

v2.0.0

  • Major: JSON5 officially supports Node.js v6 and later. Support for Node.jsv4 has been dropped. Since Node.js v6 supports ES5 features, the code has beenrewritten in native ES5, and the dependence on Babel has been eliminated.

  • New: Support for Unicode 10 has been added.

  • New: The test framework has been migrated from Mocha to Tap.

  • New: The browser build atdist/index.js is no longer minified by default. Aminified version is available atdist/index.min.js. (#181)

  • Fix: The warning has been made clearer when line and paragraph separators are

... (truncated)

Changelog

Sourced fromjson5's changelog.

v2.2.3 [code,diff]

  • Fix: json5@2.2.3 is now the 'latest' release according to npm instead ofv1.0.2. (#299)

v2.2.2 [code,diff]

  • Fix: Properties with the name__proto__ are added to objects and arrays.(#199) This also fixes a prototype pollution vulnerability reported byJonathan Gregson! (#295).

v2.2.1 [code,diff]

v2.2.0 [code,diff]

  • New: Accurate and documented TypeScript declarations are now included. Thereis no need to install@types/json5. (#236,#244)

v2.1.3 [code,diff]

  • Fix: An out of memory bug when parsing numbers has been fixed. (#228,#229)

v2.1.2 [code,diff]

  • Fix: Bumpminimist tov1.2.5. (#222)

v2.1.1 [code, [diff][d2.1.1]]

... (truncated)

Commits

Updatesbabelify from 7.2.0 to 10.0.0

Release notes

Sourced frombabelify's releases.

v10.0.0

No changes fromv10.0.0-beta.1, just re-releasing as stable.

v10.0.0-beta.1

  • Revert one change tosources in generated sourcemaps that landed between9.0.0 and10.0.0-beta.0 since it was not needed.

v10.0.0-beta.0

  • #267 - Fix handling forignoreed files from Babel
  • #262 - Fix README examples that were wrong
  • #273 - More updates for Babel 7.x
  • A bunch more fixes to make things work well

v9.0.0

  • #255 - Initial upgrade to Babel 7.x
  • #264 - Use Browserify'sbasedir as the working directory Babel's config.

This is marked as a prerelease because it was never published aslatest onnpm.

v8.0.0

  • Drop Node 0.10/0.12/5 (similar to everything else in Babel 7)
  • Add a peerDep onbabel-core (similar to how babel-loader works), this is because people end up using incompatible versions of plugins/presets/tools (especially as we make a new major)

https://github.com/babel/grunt-babel/releases/tag/v7.0.0https://github.com/babel/gulp-babel/releases/tag/v7.0.0

babel/babelify@02f97ec

Commits
  • 14e6295 10.0.0
  • 93d205d 10.0.0-beta.1
  • 53707d2 Browserify handles file-relative maps fine, so using Babel's default is fine.
  • 947752b 10.0.0-beta.0
  • 201652e Fix copy-paste fail
  • 31ecb43 Run babelify in strict mode.
  • 748faa1 Consider the stream class an implementation detail, but allow instanceof checks.
  • 9b2cbd0 Respect sourceMaps:false set in config files too.
  • 588bde8 Standardize sourcemap basedir processing to get relative paths.
  • 9c2f6bb Pass correct data property through.
  • Additional commits viewable incompare view
Maintainer changes

This version was pushed to npm byloganfsmyth, a new releaser for babelify since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from theSecurity Alerts page.

Bumps [json5](https://github.com/json5/json5) to 2.2.3 and updates ancestor dependency [babelify](https://github.com/babel/babelify). These dependencies need to be updated together.Updates `json5` from 0.5.1 to 2.2.3- [Release notes](https://github.com/json5/json5/releases)- [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md)- [Commits](json5/json5@v0.5.1...v2.2.3)Updates `babelify` from 7.2.0 to 10.0.0- [Release notes](https://github.com/babel/babelify/releases)- [Commits](babel/babelify@v7.2.0...v10.0.0)---updated-dependencies:- dependency-name: json5  dependency-type: indirect- dependency-name: babelify  dependency-type: direct:development...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot added the dependenciesPull requests that update a dependency file labelJan 6, 2023
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers
No reviews
Assignees
No one assigned
Labels
dependenciesPull requests that update a dependency file
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

0 participants

[8]ページ先頭

©2009-2025 Movatter.jp