-
Notifications
You must be signed in to change notification settings - Fork 0
Bump the npm_and_yarn group across 2 directories with 12 updates #11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Bump the npm_and_yarn group across 2 directories with 12 updates #11
Conversation
Bumps the npm_and_yarn group with 1 update in the /backend directory: [multer](https://github.com/expressjs/multer). Bumps the npm_and_yarn group with 11 updates in the /frontend directory: | Package | From | To | | --- | --- | --- | | [esbuild](https://github.com/evanw/esbuild) | `0.18.20` | `0.25.9` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `5.4.19` | `7.1.3` | | [vite-plugin-pwa](https://github.com/vite-pwa/vite-plugin-pwa) | `0.17.5` | `1.0.3` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `0.34.6` | `3.2.4` | | [@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui) | `0.34.7` | `3.2.4` | | [@storybook/addon-essentials](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/essentials) | `7.6.20` | `8.6.14` | | [@storybook/addon-onboarding](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/onboarding) | `1.0.11` | `9.1.3` | | [@storybook/blocks](https://github.com/storybookjs/storybook/tree/HEAD/code/lib/blocks) | `7.6.20` | `8.6.14` | | [@storybook/react](https://github.com/storybookjs/storybook/tree/HEAD/code/renderers/react) | `7.6.20` | `9.1.3` | | [@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite) | `7.6.20` | `9.1.3` | | [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) | `7.6.20` | `9.1.3` | Updates `multer` from 1.4.5-lts.2 to 2.0.2 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v1.4.5-lts.2...v2.0.2) Updates `esbuild` from 0.18.20 to 0.25.9 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2023.md) - [Commits](evanw/esbuild@v0.18.20...v0.25.9) Updates `vite` from 5.4.19 to 7.1.3 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v7.1.3/packages/vite) Updates `vite-plugin-pwa` from 0.17.5 to 1.0.3 - [Release notes](https://github.com/vite-pwa/vite-plugin-pwa/releases) - [Commits](vite-pwa/vite-plugin-pwa@v0.17.5...v1.0.3) Updates `vitest` from 0.34.6 to 3.2.4 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v3.2.4/packages/vitest) Updates `@vitest/ui` from 0.34.7 to 3.2.4 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v3.2.4/packages/ui) Updates `@storybook/addon-essentials` from 7.6.20 to 8.6.14 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/v8.6.14/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v8.6.14/code/addons/essentials) Updates `@storybook/addon-onboarding` from 1.0.11 to 9.1.3 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/code/addons/onboarding/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v9.1.3/code/addons/onboarding) Updates `@storybook/blocks` from 7.6.20 to 8.6.14 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/v8.6.14/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v8.6.14/code/lib/blocks) Updates `@storybook/react` from 7.6.20 to 9.1.3 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v9.1.3/code/renderers/react) Updates `@storybook/react-vite` from 7.6.20 to 9.1.3 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v9.1.3/code/frameworks/react-vite) Updates `storybook` from 7.6.20 to 9.1.3 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v9.1.3/code/core) --- updated-dependencies: - dependency-name: multer dependency-version: 2.0.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: esbuild dependency-version: 0.25.9 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 7.1.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: vite-plugin-pwa dependency-version: 1.0.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: vitest dependency-version: 3.2.4 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@vitest/ui" dependency-version: 3.2.4 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@storybook/addon-essentials" dependency-version: 8.6.14 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@storybook/addon-onboarding" dependency-version: 9.1.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@storybook/blocks" dependency-version: 8.6.14 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@storybook/react" dependency-version: 9.1.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@storybook/react-vite" dependency-version: 9.1.3 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: storybook dependency-version: 9.1.3 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
|
The files' contents are under analysis for test generation. |
Changed Files
|
Micro-Learning Topic: Directory traversal (Detected by phrase)Matched on "directory traversal"Path traversal vulnerabilities occur when inputs that have not been sufficiently validated or sanitised are used to build directory or file paths. If an attacker can influence the path being accessed by the server, they may be able to gain unauthorised access to files or even execute arbitrary code on the server (when coupled with file upload functionality). Try a challenge in Secure Code WarriorHelpful references
|
|
Review these changes at https://app.gitnotebooks.com/OneFineStarstuff/OneFineStarstuff.github.io/pull/11 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could not review PR. Too many requests in the last 5 minutes.
Max 1 pr 5 minutes. Last review was in OneFineStarstuff/OneFineStarstuff.github.io at Thu, 28 Aug 2025 16:12:26 GMT.
Next review is available in approx 2 minutes.
Upgrade to a premium Reviewabot plan or contact us at [email protected] to request an exemption.
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Join our Discord community for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR/Issue comments)Type Other keywords and placeholders
CodeRabbit Configuration File (
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Micro-Learning Topic: Cross-site scripting (Detected by phrase)Matched on "xss"Cross-site scripting vulnerabilities occur when unescaped input is rendered into a page displayed to the user. When HTML or script is included in the input, it will be processed by a user's browser as HTML or script and can alter the appearance of the page or execute malicious scripts in their user context. Try a challenge in Secure Code WarriorHelpful references
|
|
View changes in DiffLens |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Message that will be displayed on users' first pull request
❌ Deploy Preview for onefinestarstuff failed.
|
Bumps the npm_and_yarn group with 1 update in the /backend directory: multer.
Bumps the npm_and_yarn group with 11 updates in the /frontend directory:
0.18.200.25.95.4.197.1.30.17.51.0.30.34.63.2.40.34.73.2.47.6.208.6.141.0.119.1.37.6.208.6.147.6.209.1.37.6.209.1.37.6.209.1.3Updates
multerfrom 1.4.5-lts.2 to 2.0.2Release notes
Sourced from multer's releases.
... (truncated)
Changelog
Sourced from multer's changelog.
Commits
e5db9ca🔖 2.0.2adfeaf6🥅 improve error handlinge259a7e🔖 2.0.135a3272Fixes expressjs/multer#1233. Makes multer handle mi...f897007ci: apply security best practices (#1311)061f4cb📝 list languages in table to prevent GH right-aligning list due to RTL language854d769deps: update dependencies to latest versions (#1328)256da2f♻️ use version tag for CI, fix CI badge, fix references to master/maindd9dde4📝 fix badges in translation files (#1321)dc2a880ci: change branch referenceMaintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for multer since your current version.
Updates
esbuildfrom 0.18.20 to 0.25.9Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
195e05cpublish 0.25.9 to npm3dac33ffix #3131, fix #3663: yarnpnp + windows + D drive0f2c5c8mock fs now supports multiple volumes on windows100a51esplit out yarnpnp snapshot tests13aace3removeC:assumption from windows snapshot testsf1f413ffix #4252: preserve parentheses around functions1bc8091fix #4257, close #4258: go 1.23.10 => 1.23.12bc52135move the go compiler version togo.versiona0af5d1makefile: useESBUILD_VERSIONconsistently8c71947publish 0.25.8 to npmUpdates
vitefrom 5.4.19 to 7.1.3Release notes
Sourced from vite's releases.
... (truncated)
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
e090b7drelease: v7.1.39ccf142fix: support multiline new URL(..., import.meta.url) expressions (#20644)731d3e6test: removecheckNodeVersiontest (#20647)a9ba017feat: generate code frame for parse errors thrown by terser (#20642)530687arefactor: useimportin worker threads (#20641)a1be1bffeat(cli): add Node.js version warning for unsupported versions (#20638)1559577feat: support long lines ingenerateCodeFrame(#20640)f691f57perf(cli): dynamically importresolveConfig(#20646)446fe83fix(optimizer): incorrect incompatible error (#20439)42816derefactor: replace startsWith with strict equality (#20603)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for vite since your current version.
Updates
vite-plugin-pwafrom 0.17.5 to 1.0.3Release notes
Sourced from vite-plugin-pwa's releases.
... (truncated)
Commits
84e66d7chore: release v1.0.3aa07862fix: add origin to scope_extensions to comply with the spec and get rid of wa...8247192docs: proper default (#848)db4ecdbperf: add hook filters (#877)4385f0achore: release v1.0.29b650a1chore: update pnpm tov10.13.10340498feat(pwa-assets): add additional checks to resolve images (#876)9fd1a03chore: release v1.0.11967829chore: updatepnpmtov10.12.4(#870)3422925fix: added vite 7.0.0 support (#868)Updates
vitestfrom 0.34.6 to 3.2.4Release notes
Sourced from vitest's releases.
... (truncated)
Commits
c666d14chore: release v3.2.48a18c8efix(cli): throw error when--shard x/\<count>exceeds count of test files (#...8abd7ccchore(deps): updatetinypool(#8174)93f3200fix(deps): update all non-major dependencies (#8123)0c3be6ffix(coverage): ignore SCSS in browser mode (#8161)790bc31chore: update deprecation notice for globs (#8148)c0eae7dchore: update deprecated workspace file log (#8118)14dc072fix(pool): auto-adjustminWorkerswhen onlymaxWorkersspecified (#8110)85dc019fix(cli): use absolute path environment on Windows (#8105)27df68afix(reporter):task.metashould be available in custom reporter's errors (#...Maintainer changes
This version was pushed to npm by vitestbot, a new releaser for vitest since your current version.
Updates
@vitest/uifrom 0.34.7 to 3.2.4Release notes
Sourced from
@vitest/ui's releases.... (truncated)
Commits
c666d14chore: release v3.2.493f3200fix(deps): update all non-major dependencies (#8123)b87ee3echore: release v3.2.3c69be1ffeat(ui): show test annotations and metadata in the test report tab (#8093)7ddcd33chore: release v3.2.2f858f3bchore: release v3.2.159200aechore: release v3.2.0cce98d3chore(deps): update all non-major dependencies (#8067)b03f209feat: annotation API (#7953)3bdf05dfix: ensure errors keep their message and stack aftertoJSONserialisation ...