Tim Donohue
|
e7ff564608
|
Remove unused postcss-responsive-type
|
2024-10-23 13:56:46 -05:00 |
|
Tim Donohue
|
04410485a5
|
Remove unused/unmaintained postcss-apply
|
2024-10-23 13:55:36 -05:00 |
|
Tim Donohue
|
39c5c755d7
|
Remove unused postcss-responsive-type
|
2024-10-23 13:39:01 -05:00 |
|
Tim Donohue
|
c93ed03004
|
Remove unused/unmaintained postcss-apply dep
|
2024-10-23 13:26:55 -05:00 |
|
Tim Donohue
|
bd43d959ab
|
Merge pull request #3544 from tdonohue/remove_types_sanitize_html
Remove unused `@types/sanitize-html` dependency
|
2024-10-23 13:16:13 -05:00 |
|
Tim Donohue
|
930d8ef8e0
|
Merge pull request #3546 from DSpace/backport-3481-to-dspace-8_x
[Port dspace-8_x] Fix code scanning alert no. 6: Incomplete string escaping or encoding
|
2024-10-23 13:15:39 -05:00 |
|
Tim Donohue
|
bb84d86cf5
|
Fix code scanning alert no. 6: Incomplete string escaping or encoding
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
(cherry picked from commit 372444c50a )
|
2024-10-23 17:25:18 +00:00 |
|
Tim Donohue
|
9486ab5fa1
|
Fix code scanning alert no. 6: Incomplete string escaping or encoding
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
(cherry picked from commit 372444c50a )
|
2024-10-23 17:25:14 +00:00 |
|
Tim Donohue
|
abd0d696dc
|
Merge pull request #3481 from DSpace/alert-autofix-6
Fix code scanning alert no. 6: Incomplete string escaping or encoding
|
2024-10-23 12:24:57 -05:00 |
|
Tim Donohue
|
74e85c79e7
|
Remove unused @types/sanitize-html
|
2024-10-23 11:42:09 -05:00 |
|
Tim Donohue
|
7c6ecf8e9e
|
Merge pull request #3530 from DSpace/dependabot/npm_and_yarn/dspace-7_x/reflect-metadata-0.2.2
Bump reflect-metadata from 0.1.13 to 0.2.2
|
2024-10-23 11:37:24 -05:00 |
|
Tim Donohue
|
ea8f24d410
|
Fix bug where all security-updates need unique IDs
|
2024-10-23 11:33:28 -05:00 |
|
Tim Donohue
|
92ee89e8e5
|
Fix bug in dependabot.yml "security-updates" settings
"security-updates" configs can only be in sections where there is no "target-branch". This is because they only apply to the primary branch.
|
2024-10-23 11:31:16 -05:00 |
|
Tim Donohue
|
c7497cdf4e
|
Merge pull request #3539 from DSpace/dependabot/npm_and_yarn/main/webpack-5.95.0
Bump webpack from 5.94.0 to 5.95.0
|
2024-10-23 11:01:18 -05:00 |
|
Tim Donohue
|
6198314a37
|
Merge pull request #3535 from DSpace/dependabot/npm_and_yarn/dspace-8_x/babel/runtime-7.25.9
Bump @babel/runtime from 7.25.7 to 7.25.9
|
2024-10-23 10:59:19 -05:00 |
|
Tim Donohue
|
81fb382b9a
|
Merge pull request #3536 from DSpace/dependabot/npm_and_yarn/main/babel/runtime-7.25.9
Bump @babel/runtime from 7.25.7 to 7.25.9
|
2024-10-23 10:58:40 -05:00 |
|
Tim Donohue
|
ae816815fc
|
Merge pull request #3538 from DSpace/dependabot/npm_and_yarn/main/postcss-8.4.47
Bump postcss from 8.4.39 to 8.4.47
|
2024-10-23 10:43:08 -05:00 |
|
Tim Donohue
|
87dc6be213
|
Remove unnecessary @ts-expect-error, as the bug they are expecting is fixed in webpack 5.95.0.
|
2024-10-23 10:25:49 -05:00 |
|
Tim Donohue
|
ee36bab60b
|
Merge pull request #3531 from DSpace/dependabot/npm_and_yarn/dspace-7_x/babel/runtime-7.25.9
Bump @babel/runtime from 7.21.0 to 7.25.9
|
2024-10-23 10:12:06 -05:00 |
|
Tim Donohue
|
89569d7989
|
Merge pull request #3533 from DSpace/dependabot/npm_and_yarn/dspace-8_x/typescript-5.4.5
Bump typescript from 5.3.3 to 5.4.5
|
2024-10-23 09:59:08 -05:00 |
|
dependabot[bot]
|
207e2ac9ae
|
Bump typescript from 5.3.3 to 5.4.5
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.3.3 to 5.4.5.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release.yml)
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.3.3...v5.4.5)
---
updated-dependencies:
- dependency-name: typescript
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-23 14:08:36 +00:00 |
|
Tim Donohue
|
09201b0d51
|
Merge pull request #3537 from DSpace/dependabot/npm_and_yarn/dspace-8_x/types/lodash-4.17.12
Bump @types/lodash from 4.17.10 to 4.17.12
|
2024-10-23 09:06:44 -05:00 |
|
Andreas Awouters
|
1a816228e8
|
118223: Add 'loading' overlay while bitstream is moving
|
2024-10-23 13:59:23 +02:00 |
|
Alan Orth
|
ccf6f36ade
|
Merge pull request #3526 from DSpace/dependabot/npm_and_yarn/dspace-7_x/angulartics2-12.2.1
|
2024-10-23 09:39:21 +03:00 |
|
dependabot[bot]
|
5cb22bb1d0
|
Bump reflect-metadata from 0.1.13 to 0.2.2
Bumps [reflect-metadata](https://github.com/rbuckton/reflect-metadata) from 0.1.13 to 0.2.2.
- [Release notes](https://github.com/rbuckton/reflect-metadata/releases)
- [Changelog](https://github.com/rbuckton/reflect-metadata/blob/main/tsconfig-release.json)
- [Commits](https://github.com/rbuckton/reflect-metadata/commits)
---
updated-dependencies:
- dependency-name: reflect-metadata
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 21:58:01 +00:00 |
|
Tim Donohue
|
b237c7f5cb
|
Merge pull request #3525 from DSpace/dependabot/npm_and_yarn/dspace-7_x/multi-c55d84953a
Bump sanitize-html and @types/sanitize-html
|
2024-10-22 16:56:11 -05:00 |
|
Tim Donohue
|
30c3e3db0c
|
Merge pull request #3532 from DSpace/dependabot/npm_and_yarn/dspace-7_x/zone.js-0.13.3
Bump zone.js from 0.11.8 to 0.13.3
|
2024-10-22 16:55:24 -05:00 |
|
Tim Donohue
|
39cdd1692a
|
Merge pull request #3528 from DSpace/dependabot/npm_and_yarn/dspace-7_x/webpack-dev-server-4.15.2
Bump webpack-dev-server from 4.13.3 to 4.15.2
|
2024-10-22 16:51:38 -05:00 |
|
dependabot[bot]
|
93c6ab2684
|
Bump webpack from 5.94.0 to 5.95.0
Bumps [webpack](https://github.com/webpack/webpack) from 5.94.0 to 5.95.0.
- [Release notes](https://github.com/webpack/webpack/releases)
- [Commits](https://github.com/webpack/webpack/compare/v5.94.0...v5.95.0)
---
updated-dependencies:
- dependency-name: webpack
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 21:34:52 +00:00 |
|
dependabot[bot]
|
2ab1472f22
|
Bump postcss from 8.4.39 to 8.4.47
Bumps [postcss](https://github.com/postcss/postcss) from 8.4.39 to 8.4.47.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.4.39...8.4.47)
---
updated-dependencies:
- dependency-name: postcss
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 21:34:01 +00:00 |
|
dependabot[bot]
|
a9febec691
|
Bump @types/lodash from 4.17.10 to 4.17.12
Bumps [@types/lodash](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/lodash) from 4.17.10 to 4.17.12.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/lodash)
---
updated-dependencies:
- dependency-name: "@types/lodash"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 21:33:31 +00:00 |
|
dependabot[bot]
|
280d6d92ad
|
Bump @babel/runtime from 7.25.7 to 7.25.9
Bumps [@babel/runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-runtime) from 7.25.7 to 7.25.9.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.25.9/packages/babel-runtime)
---
updated-dependencies:
- dependency-name: "@babel/runtime"
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 21:33:30 +00:00 |
|
dependabot[bot]
|
cddee3e1db
|
Bump @babel/runtime from 7.25.7 to 7.25.9
Bumps [@babel/runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-runtime) from 7.25.7 to 7.25.9.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.25.9/packages/babel-runtime)
---
updated-dependencies:
- dependency-name: "@babel/runtime"
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 21:33:14 +00:00 |
|
Tim Donohue
|
b7c4c737c1
|
Update dependabot.yml
|
2024-10-22 16:29:48 -05:00 |
|
dependabot[bot]
|
603e46283f
|
Bump angulartics2 from 12.2.0 to 12.2.1
Bumps [angulartics2](https://github.com/angulartics/angulartics2) from 12.2.0 to 12.2.1.
- [Release notes](https://github.com/angulartics/angulartics2/releases)
- [Commits](https://github.com/angulartics/angulartics2/compare/v12.2.0...v12.2.1)
---
updated-dependencies:
- dependency-name: angulartics2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 19:31:16 +00:00 |
|
Tim Donohue
|
c17adef242
|
Merge pull request #3523 from DSpace/dependabot/npm_and_yarn/dspace-7_x/axios-1.7.7
Bump axios from 1.7.5 to 1.7.7
|
2024-10-22 14:29:41 -05:00 |
|
Tim Donohue
|
bacd484832
|
Merge pull request #3515 from DSpace/dependabot/npm_and_yarn/dspace-7_x/ng-mocks-14.13.1
Bump ng-mocks from 14.10.0 to 14.13.1
|
2024-10-22 14:21:04 -05:00 |
|
dependabot[bot]
|
7eb0a47fca
|
Bump zone.js from 0.11.8 to 0.13.3
Bumps [zone.js](https://github.com/angular/angular/tree/HEAD/packages/zone.js) from 0.11.8 to 0.13.3.
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/packages/zone.js/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/zone.js-0.13.3/packages/zone.js)
---
updated-dependencies:
- dependency-name: zone.js
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 19:20:58 +00:00 |
|
dependabot[bot]
|
cfa6d50583
|
Bump @babel/runtime from 7.21.0 to 7.25.9
Bumps [@babel/runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-runtime) from 7.21.0 to 7.25.9.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.25.9/packages/babel-runtime)
---
updated-dependencies:
- dependency-name: "@babel/runtime"
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 19:20:30 +00:00 |
|
dependabot[bot]
|
47db669191
|
Bump webpack-dev-server from 4.13.3 to 4.15.2
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) from 4.13.3 to 4.15.2.
- [Release notes](https://github.com/webpack/webpack-dev-server/releases)
- [Changelog](https://github.com/webpack/webpack-dev-server/blob/v4.15.2/CHANGELOG.md)
- [Commits](https://github.com/webpack/webpack-dev-server/compare/v4.13.3...v4.15.2)
---
updated-dependencies:
- dependency-name: webpack-dev-server
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 19:19:40 +00:00 |
|
dependabot[bot]
|
ab60ad2072
|
Bump sanitize-html and @types/sanitize-html
Bumps [sanitize-html](https://github.com/apostrophecms/sanitize-html) and [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html). These dependencies needed to be updated together.
Updates `sanitize-html` from 2.12.1 to 2.13.1
- [Changelog](https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/sanitize-html/compare/2.12.1...2.13.1)
Updates `@types/sanitize-html` from 2.9.0 to 2.13.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)
---
updated-dependencies:
- dependency-name: sanitize-html
dependency-type: direct:production
update-type: version-update:semver-minor
- dependency-name: "@types/sanitize-html"
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 19:18:46 +00:00 |
|
Tim Donohue
|
f3eb5b8a86
|
Merge pull request #3480 from DSpace/dependabot/npm_and_yarn/main/typescript-5.4.5
Bump typescript from 5.3.3 to 5.4.5
|
2024-10-22 13:52:32 -05:00 |
|
Tim Donohue
|
081c573653
|
Merge pull request #3521 from DSpace/dependabot/npm_and_yarn/dspace-7_x/date-fns-2.30.0
Bump date-fns from 2.29.3 to 2.30.0
|
2024-10-22 13:48:32 -05:00 |
|
Tim Donohue
|
e22ed77527
|
Merge pull request #3520 from DSpace/dependabot/npm_and_yarn/dspace-7_x/webpack-bundle-analyzer-4.10.2
Bump webpack-bundle-analyzer from 4.8.0 to 4.10.2
|
2024-10-22 13:31:32 -05:00 |
|
Tim Donohue
|
4eca7c062c
|
Merge pull request #3514 from DSpace/dependabot/npm_and_yarn/dspace-7_x/sortablejs-1.15.3
Bump sortablejs from 1.15.0 to 1.15.3
|
2024-10-22 13:30:29 -05:00 |
|
Tim Donohue
|
bef3d37802
|
Merge pull request #3517 from DSpace/dependabot/npm_and_yarn/dspace-7_x/types/express-4.17.21
Bump @types/express from 4.17.17 to 4.17.21
|
2024-10-22 13:18:47 -05:00 |
|
Tim Donohue
|
2ab52dad8e
|
Merge pull request #3522 from DSpace/dependabot/npm_and_yarn/dspace-7_x/types/deep-freeze-0.1.5
Bump @types/deep-freeze from 0.1.2 to 0.1.5
|
2024-10-22 13:17:41 -05:00 |
|
Tim Donohue
|
6bd66910a9
|
Merge pull request #3518 from DSpace/dependabot/npm_and_yarn/dspace-7_x/fortawesome/fontawesome-free-6.6.0
Bump @fortawesome/fontawesome-free from 6.4.0 to 6.6.0
|
2024-10-22 13:16:03 -05:00 |
|
Tim Donohue
|
51e9acf9ff
|
Merge pull request #3430 from DSpace/dependabot/npm_and_yarn/dspace-8_x/webpack-5.95.0
Bump webpack from 5.94.0 to 5.95.0
|
2024-10-22 13:13:58 -05:00 |
|
dependabot[bot]
|
cfecf0ff62
|
Bump ng-mocks from 14.10.0 to 14.13.1
Bumps [ng-mocks](https://github.com/help-me-mom/ng-mocks) from 14.10.0 to 14.13.1.
- [Release notes](https://github.com/help-me-mom/ng-mocks/releases)
- [Changelog](https://github.com/help-me-mom/ng-mocks/blob/master/CHANGELOG.md)
- [Commits](https://github.com/help-me-mom/ng-mocks/compare/v14.10.0...v14.13.1)
---
updated-dependencies:
- dependency-name: ng-mocks
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2024-10-22 17:16:48 +00:00 |
|