Skip to content

Bump the npm_and_yarn group across 2 directories with 10 updates - #277

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/Src/PackageGuard.Specs/TestCases/YarnApp/npm_and_yarn-bd0a3e029e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/Src/PackageGuard.Specs/TestCases/YarnApp/npm_and_yarn-bd0a3e029e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /Src/PackageGuard.Specs/TestCases/YarnApp directory: proxy-addr.
Bumps the npm_and_yarn group with 10 updates in the /website directory:

Package From To
proxy-addr 2.0.7 2.0.8
qs 6.15.3 6.16.0
brace-expansion 1.1.18 1.1.21
compression 1.8.1 1.8.2
fast-uri 3.1.7 3.1.8
http-cache-semantics 4.2.0 4.3.0
joi 17.13.7 17.13.8
shell-quote 1.10.0 1.12.0
source-map-js 1.2.1 1.2.2
sprintf-js 1.0.3 removed

Updates proxy-addr from 2.0.7 to 2.0.8

Release notes

Sourced from proxy-addr's releases.

2.0.8

Important

What's Changed

New Contributors

Full Changelog: jshttp/proxy-addr@v2.0.7...v2.0.8

Changelog

Sourced from proxy-addr's changelog.

2.0.8

Commits
  • a11ad82 2.0.8 (#70)
  • 780911d fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix
  • 92e103e fix(ci): use publised as release trigger event (#71)
  • 3e5ac75 ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (#69)
  • 4b9db81 chore(ci): npm-publish via workflows (#54)
  • 655e895 build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#39)
  • 50ce4d0 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#45)
  • 0fd347f build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#63)
  • 6a517fa build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (#64)
  • 0d45e2a Fix "arugment" typo in README (#61)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for proxy-addr since your current version.


Updates proxy-addr from 2.0.7 to 2.0.8

Release notes

Sourced from proxy-addr's releases.

2.0.8

Important

What's Changed

New Contributors

Full Changelog: jshttp/proxy-addr@v2.0.7...v2.0.8

Changelog

Sourced from proxy-addr's changelog.

2.0.8

Commits
  • a11ad82 2.0.8 (#70)
  • 780911d fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix
  • 92e103e fix(ci): use publised as release trigger event (#71)
  • 3e5ac75 ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (#69)
  • 4b9db81 chore(ci): npm-publish via workflows (#54)
  • 655e895 build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#39)
  • 50ce4d0 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#45)
  • 0fd347f build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#63)
  • 6a517fa build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (#64)
  • 0d45e2a Fix "arugment" typo in README (#61)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for proxy-addr since your current version.


Updates qs from 6.15.3 to 6.16.0

Changelog

Sourced from qs's changelog.

6.16.0

  • [New] stringify: add a depth option to bound recursion depth (default Infinity)
  • [Fix] stringify: serialize Date values when a filter is provided
  • [Fix] parse: enforce arrayLimit on comma groups under []= when throwOnLimitExceeded is set
  • [Fix] parse: flatten a collection appended to an overflowed array (#571)
  • [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or drop own keys) on an empty array with own properties
  • [Fix] stringify: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (#562)
  • [Docs] threat model: clarify stringify deep-nesting DoS is caller-bounded
  • [Docs] clarify arrayLimit is a representation threshold, not an element-count cap
  • [Tests] parse: remove a test that pinned []= comma groups escaping arrayLimit
  • [Tests] stringify: pin current encodeDotInKeys separator-dot behavior
  • [Dev Deps] update @ljharb/eslint-config, eslint
  • [Dev Deps] update eslint, evalmd
Commits
  • bb9379e v6.16.0
  • 62fd254 [Fix] stringify: serialize Date values when a filter is provided
  • 8859c37 [Fix] parse: enforce arrayLimit on comma groups under []= when `throwOn...
  • 8079adc [Tests] parse: remove a test that pinned []= comma groups escaping `array...
  • d56f48c [Fix] parse: flatten a collection appended to an overflowed array
  • e83d321 [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • 7e87a07 [Dev Deps] update @ljharb/eslint-config, eslint
  • 9a76af2 [Dev Deps] update eslint, evalmd
  • 3a890d4 [Dev Deps] update eslint, evalmd
  • b433a9b [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or dro...
  • Additional commits viewable in compare view

Updates brace-expansion from 1.1.18 to 1.1.21

Commits

Updates compression from 1.8.1 to 1.8.2

Release notes

Sourced from compression's releases.

v1.8.2

Important

What's Changed

New Contributors

Full Changelog: expressjs/compression@v1.8.1...v1.8.2

Changelog

Sourced from compression's changelog.

1.8.2

Commits
  • 0f97074 1.8.2 (#287)
  • 151f63e fix: destroy compression stream on response close
  • 0a76495 fix: match Cache-Control no-transform directive case-insensitively (#286)
  • c17b6e5 docs: update outdated Brotli note and fix npm install docs URL (#276)
  • 112911a chore(ci): npm-publish via reusable workflows (#269)
  • 1bf5eb0 build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#267)
  • d8fe64d build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#266)
  • b218ff5 build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (#265)
  • 8a1cf8e build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#268)
  • 4a19855 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#257)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for compression since your current version.


Updates fast-uri from 3.1.7 to 3.1.8

Release notes

Sourced from fast-uri's releases.

v3.1.8

⚠️ Security Warning

This security release fixes the following medium-severity security advisory:

Users of the v3.x release line should upgrade to v3.1.8.

Full Changelog: fastify/fast-uri@v3.1.7...v3.1.8

Commits

Updates http-cache-semantics from 4.2.0 to 4.3.0

Commits

Updates joi from 17.13.7 to 17.13.8

Commits

Updates shell-quote from 1.10.0 to 1.12.0

Changelog

Sourced from shell-quote's changelog.

v1.12.0 - 2026-10-02

Fixed

Commits

  • [New] parse: support tab-stripping here-documents (<<-) dbfac37
  • [New] parse: support output process substitution (>() 2053315
  • [New] parse: support the case test-next terminator (;;&) 7d688b9
  • [New] parse: support the case fall-through terminator (;&) f27010e
  • [New] parse: support redirecting output despite noclobber (>|) b78d19c
  • [New] parse: support opening a file for reading and writing (<>) 21cc333
  • [New] parse: support redirecting stdout and stderr (&>) 6ad6cd2
  • [New] parse: support appending stdout and stderr (&>>) 90cde9c
  • [Dev Deps] update @ljharb/eslint-config 3a7b4ae

v1.11.0 - 2026-09-29

Fixed

Commits

  • [Fix] quote: reject line terminators in tokens after a comment 6002b2e
  • [Fix] parse: preserve text after special shell parameters 81b08a5
  • [Fix] parse: an escaped backslash does not escape the character after it d708019
  • [Fix] quote: preserve ! in arguments that also contain ' ad39927
  • [Fix] parse: treat $_name as a variable name, not $_ followed by text 28f88cd
  • [Fix] quote: preserve empty glob patterns 35c9b97
  • [Fix] quote: escape ~ in glob patterns to prevent shell tilde-expansion 239d49c
  • [Dev Deps] update @ljharb/eslint-config, auto-changelog, eslint, evalmd b1e406e
  • [meta] npmignore some files ebfc308
  • [actions] add permissions 3429b0d
  • [actions] set least-privilege cache-mode 36f2394
  • [Dev Deps] update eslint 6de9a41
Commits
  • 6ecb8aa v1.12.0
  • 3a7b4ae [Dev Deps] update @ljharb/eslint-config
  • 7d688b9 [New] parse: support the case test-next terminator (;;&)
  • f27010e [New] parse: support the case fall-through terminator (;&)
  • 90cde9c [New] parse: support appending stdout and stderr (&>>)
  • 6ad6cd2 [New] parse: support redirecting stdout and stderr (&>)
  • 2053315 [New] parse: support output process substitution (>()
  • b78d19c [New] parse: support redirecting output despite noclobber (>|)
  • 21cc333 [New] parse: support opening a file for reading and writing (\<>)
  • dbfac37 [New] parse: support tab-stripping here-documents (<<-)
  • Additional commits viewable in compare view

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Removes sprintf-js

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the /Src/PackageGuard.Specs/TestCases/YarnApp directory: [proxy-addr](https://github.com/jshttp/proxy-addr).
Bumps the npm_and_yarn group with 10 updates in the /website directory:

| Package | From | To |
| --- | --- | --- |
| [proxy-addr](https://github.com/jshttp/proxy-addr) | `2.0.7` | `2.0.8` |
| [qs](https://github.com/ljharb/qs) | `6.15.3` | `6.16.0` |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.18` | `1.1.21` |
| [compression](https://github.com/expressjs/compression) | `1.8.1` | `1.8.2` |
| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.7` | `3.1.8` |
| [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.2.0` | `4.3.0` |
| [joi](https://github.com/hapijs/joi) | `17.13.7` | `17.13.8` |
| [shell-quote](https://github.com/ljharb/shell-quote) | `1.10.0` | `1.12.0` |
| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |
| [sprintf-js](https://github.com/alexei/sprintf.js) | `1.0.3` | `removed` |



Updates `proxy-addr` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/jshttp/proxy-addr/releases)
- [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md)
- [Commits](jshttp/proxy-addr@v2.0.7...v2.0.8)

Updates `proxy-addr` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/jshttp/proxy-addr/releases)
- [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md)
- [Commits](jshttp/proxy-addr@v2.0.7...v2.0.8)

Updates `qs` from 6.15.3 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.3...v6.16.0)

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

Updates `compression` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](expressjs/compression@v1.8.1...v1.8.2)

Updates `fast-uri` from 3.1.7 to 3.1.8
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.7...v3.1.8)

Updates `http-cache-semantics` from 4.2.0 to 4.3.0
- [Commits](https://github.com/kornelski/http-cache-semantics/commits)

Updates `joi` from 17.13.7 to 17.13.8
- [Commits](hapijs/joi@v17.13.7...v17.13.8)

Updates `shell-quote` from 1.10.0 to 1.12.0
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.10.0...v1.12.0)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Removes `sprintf-js`

---
updated-dependencies:
- dependency-name: proxy-addr
  dependency-version: 2.0.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: proxy-addr
  dependency-version: 2.0.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: compression
  dependency-version: 1.8.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: http-cache-semantics
  dependency-version: 4.3.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: joi
  dependency-version: 17.13.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: shell-quote
  dependency-version: 1.12.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: sprintf-js
  dependency-version:
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Test Results

  2 files   - 1    2 suites   - 1   5m 13s ⏱️ +54s
437 tests  - 1  437 ✅  - 1  0 💤 ±0  0 ❌ ±0 
874 runs   - 1  874 ✅  - 1  0 💤 ±0  0 ❌ ±0 

Results for commit f96f8b2. ± Comparison against base commit 2f67b22.

This pull request removes 1 test.
PackageGuard.ApiVerificationTests.ApiApproval ‑ ApproveApi

♻️ This comment has been updated with latest results.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants