Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump jszip from 3.2.2 to 3.10.1 in /client #136

Open
wants to merge 35 commits into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Sep 8, 2022

Bumps jszip from 3.2.2 to 3.10.1.

Changelog

Sourced from jszip's changelog.

v3.10.1 2022-08-02

  • Add sponsorship files.
    • If you appreciate the time spent maintaining JSZip then I would really appreciate your sponsorship.
  • Consolidate metadata types and expose OnUpdateCallback #851 and #852
  • use const instead var in example from README.markdown #828
  • Switch manual download link to HTTPS #839

Internals:

  • Replace jshint with eslint #842
  • Add performance tests #834

v3.10.0 2022-05-20

  • Change setimmediate dependency to more efficient one. Fixes Stuk/jszip#617 (see #829)
  • Update types of currentFile metadata to include null (see #826)

v3.9.1 2022-04-06

  • Fix recursive definition of InputFileFormat introduced in 3.9.0.

v3.9.0 2022-04-04

  • Update types JSZip#loadAsync to accept a promise for data, and remove arguments from new JSZip() (see #752)
  • Update types for compressionOptions to JSZipFileOptions and JSZipGeneratorOptions (see #722)
  • Add types for generateInternalStream (see #774)

v3.8.0 2022-03-30

  • Santize filenames when files are loaded with loadAsync, to avoid "zip slip" attacks. The original filename is available on each zip entry as unsafeOriginalName. See the documentation. Many thanks to McCaulay Hudson for reporting.

v3.7.1 2021-08-05

  • Fix build of dist files.
    • Note: this version ensures the changes from 3.7.0 are actually included in the dist files. Thanks to Evan W for reporting.

v3.7.0 2021-07-23

  • Fix: Use a null prototype object for this.files (see #766)
    • This change might break existing code if it uses prototype methods on the .files property of a zip object, for example zip.files.toString(). This approach is taken to prevent files in the zip overriding object methods that would exist on a normal object.

v3.6.0 2021-02-09

  • Fix: redirect main to dist on browsers (see #742)
  • Fix duplicate require DataLengthProbe, utils (see #734)
  • Fix small error in read_zip.md (see #703)

v3.5.0 2020-05-31

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Nir Galon and others added 30 commits February 2, 2017 20:55
* Cleanup and add new client

* Add travis-ci, and cleanup server

* Update README file

* Add server side

* Add codecov to python in travis-ci

* Try add python coverage

* Fix coverage command on travis-ci

* Try fix path in travis-ci

* Install requirements in travis-ci

* Create postgres database in travis-ci

* Try coverage in xml

* Try coverage in html

* Create the coverage xml file after the report

* Add codecov config file

* Change pach to codecov config file

* Add test for users api

* Add pycodestyle to travis-ci

* Execute python unit tests in travis-ci

* Fix python coverage report

* Ignore apps.py files in coverage
* Add macos to gitignore file

* Get the user data with ngrx, and show it

* Add util file to codecov ignore list
* Add Dockerfile to client side

* Cleanup

* Docker for django app (server) works
* Upgrade ng-cli version

* Fix tests

* Fix npm test command
* Update angular version

* Fix lint errors

* Test users component

* Test user effects
* Add files

* Change nginx to haproxy

* Update dependencies

* Update README file

* Server is working

* Fix test errors

* Show data from server

* Serve static files for server

* Cleanup
* Add ELK stack

* Cleanup

* Fix tests

* Add logstash settings

* Fix logging settings

* Save logs in ELK
* Update node.js version on travis-ci

* Update client

* Fix lint warnings

* Update server
* Add load tests

* Fix lint errors

* Add load tests file to codecov ignore
* Add auth to server and fix user.service to accommodate it

* Fix tests

* Fix test
* Lower postgres restart policy

* Add a backup script to postgres db to run in cron.daily

* Add an option to login to api view

* Fix server test

* Add Database Backups section to README

* Edit README file

* Edit README file take 2

* Try different indentation

* Fix tests take 1

* Fix tests teke 2
* Add angular2-logger package

* Fix codacy errors

* Add codacy badge

* Add maintenance badge

* Fix github releases badge

* Remove angular2-logger package

* Update links
* Upgrade angular-cli and ngrx versions

* Fix new ngrx/store and ngrx/effects

* Fix tests
* Create new client project

* Basic users module is done
Nir Galon and others added 5 commits June 13, 2018 11:27
* Get users from backend and store them in the store.

* Show data on screen

* Cleanup
* Update client to angular v8

* Fix server database connection

* Fix client errors

* Add requirements file from pipfile

* Fix travis file

* Fix travis

* Fix server errors

* Fix travis errors

* Fix travis

* Fix travis

* Fix travis

* Fix travis

* Fix angular lint errors

* Fix travis

* Add chrome to travis

* Fix travis

* Fix travis

* Fix travis

* Fix travis last take?

* Fix travis

* Fix server errors

* Add pwa

* Cleanup
* Cleanup

* Add cloudbuild.yaml file for angular client app

* Add server Dockerfile and kubernetes files

* Change readme
Bumps [jszip](https://github.com/Stuk/jszip) from 3.2.2 to 3.10.1.
- [Release notes](https://github.com/Stuk/jszip/releases)
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](Stuk/jszip@v3.2.2...v3.10.1)

---
updated-dependencies:
- dependency-name: jszip
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 8, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant