Commit Graph

246 Commits

Author SHA1 Message Date
arkon
f1f3d36558 Bump dependencies 2022-11-20 11:33:16 -05:00
arkon
78e35fc060 Bump dependencies 2022-11-20 11:13:10 -05:00
dependabot[bot]
1bf58301d3
Bump minimatch from 3.0.4 to 3.0.8 (#968)
Bumps [minimatch](https://github.com/isaacs/minimatch) from 3.0.4 to 3.0.8.
- [Release notes](https://github.com/isaacs/minimatch/releases)
- [Commits](https://github.com/isaacs/minimatch/compare/v3.0.4...v3.0.8)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-11-12 16:53:49 -05:00
arkon
29a23cec48 chore: bump dependencies 2022-11-12 16:47:30 -05:00
renovate[bot]
ca9f4ed73d
Update dependency marked to v4.2.2 (#966)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-11-07 23:35:44 -05:00
renovate[bot]
d9000e65be
Update dependency eslint-plugin-promise to v6.1.1 (#958)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-10-22 21:27:43 -04:00
renovate[bot]
41e63903a4
Update dependency eslint-plugin-promise to v6.1.0 (#955)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-10-15 22:40:11 -04:00
renovate[bot]
4142b6ae6c
Update dependency eslint-plugin-vue to v9.6.0 (#947)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-10-04 21:48:09 -04:00
arkon
0f8c960b97 Bump dependencies 2022-10-01 23:16:21 -04:00
renovate[bot]
8db62cf9a7
Update dependency node-sass to v7.0.3 (#945)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-09-10 23:46:26 -04:00
renovate[bot]
aa99c01f85
Update dependency scss-tokenizer to 0.4.3 [SECURITY] (#944)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-09-08 08:05:49 -04:00
arkon
387a5c01a0 Bump dependencies 2022-08-30 12:42:52 -04:00
renovate[bot]
9bab231308
Update dependency eslint-plugin-vue to v9.3.0 (#938)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-07-31 18:00:45 -04:00
dependabot[bot]
2dddb1edb1
Bump terser from 4.8.0 to 4.8.1 (#936)
Bumps [terser](https://github.com/terser/terser) from 4.8.0 to 4.8.1.
- [Release notes](https://github.com/terser/terser/releases)
- [Changelog](https://github.com/terser/terser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/terser/terser/commits)

---
updated-dependencies:
- dependency-name: terser
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-20 11:25:53 -04:00
arkon
d51f77ac58 Bump dependencies 2022-07-16 19:02:17 -04:00
arkon
9e14021ded Bump dependencies 2022-07-16 18:51:50 -04:00
arkon
78e482d269 Bump dependencies 2022-06-28 09:19:19 -04:00
renovate[bot]
65f05f55ad
Update dependency eslint-config-vuepress to v3.9.0 (#915)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-06-02 08:07:20 -04:00
renovate[bot]
b0473d4b50
Update dependency eslint-plugin-vue to v9.1.0 (#914)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-06-01 10:13:40 -04:00
dependabot[bot]
5fee7d3625
Bump eventsource from 1.1.0 to 1.1.1 (#913)
Bumps [eventsource](https://github.com/EventSource/eventsource) from 1.1.0 to 1.1.1.
- [Release notes](https://github.com/EventSource/eventsource/releases)
- [Changelog](https://github.com/EventSource/eventsource/blob/master/HISTORY.md)
- [Commits](https://github.com/EventSource/eventsource/compare/v1.1.0...v1.1.1)

---
updated-dependencies:
- dependency-name: eventsource
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-06-01 07:50:35 -04:00
renovate[bot]
98427a01f6
Update dependency eslint-config-vuepress to v3.8.0 (#911)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-05-28 08:04:27 -04:00
renovate[bot]
8432226b28
Update dependency eslint-plugin-vue to v9.0.1 (#908)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-05-18 17:41:57 -04:00
renovate[bot]
0ff79b1389
Update dependency eslint-plugin-vue to v9 (#907)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-05-18 08:50:08 -04:00
renovate[bot]
fe4af86180
Update dependency marked to v4.0.16 (#906)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-05-17 12:22:34 -04:00
renovate[bot]
aab94dab98
Update dependency core-js to v2.6.12 (#892)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-05-15 23:42:11 -04:00
renovate[bot]
c1acb9a7b8
Pin dependencies (#889)
Co-authored-by: Renovate Bot <bot@renovateapp.com>
2022-05-15 12:33:25 -04:00
arkon
60760efb25 Bump dependencies 2022-05-15 12:21:58 -04:00
arkon
2b177afff6 Update dependencies 2022-04-27 22:32:57 -04:00
arkon
8341c4e835 Bump dependencies 2022-04-14 16:36:33 -04:00
arkon
c6ec6abd52 Update dependencies 2022-03-13 11:02:26 -04:00
arkon
91b2fc023d Update dependencies 2022-03-06 15:29:20 -05:00
dependabot[bot]
ac2e3efd81
Bump url-parse from 1.5.4 to 1.5.7 (#846)
Bumps [url-parse](https://github.com/unshiftio/url-parse) from 1.5.4 to 1.5.7.
- [Release notes](https://github.com/unshiftio/url-parse/releases)
- [Commits](https://github.com/unshiftio/url-parse/compare/1.5.4...1.5.7)

---
updated-dependencies:
- dependency-name: url-parse
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-02-18 07:59:25 -05:00
dependabot[bot]
123fd0f3f9
Bump axios from 0.25.0 to 0.26.0 (#845)
Bumps [axios](https://github.com/axios/axios) from 0.25.0 to 0.26.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/master/CHANGELOG.md)
- [Commits](https://github.com/axios/axios/compare/v0.25.0...v0.26.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-02-13 19:09:55 -05:00
dependabot[bot]
db2465617c
Bump eslint-plugin-vue from 8.4.0 to 8.4.1 (#844)
Bumps [eslint-plugin-vue](https://github.com/vuejs/eslint-plugin-vue) from 8.4.0 to 8.4.1.
- [Release notes](https://github.com/vuejs/eslint-plugin-vue/releases)
- [Commits](https://github.com/vuejs/eslint-plugin-vue/compare/v8.4.0...v8.4.1)

---
updated-dependencies:
- dependency-name: eslint-plugin-vue
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-02-06 20:10:52 -05:00
arkon
5dd34fd1ad Update dependencies 2022-01-31 15:56:24 -05:00
dependabot[bot]
d0882aa6da
Bump marked from 4.0.10 to 4.0.12 (#842)
Bumps [marked](https://github.com/markedjs/marked) from 4.0.10 to 4.0.12.
- [Release notes](https://github.com/markedjs/marked/releases)
- [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json)
- [Commits](https://github.com/markedjs/marked/compare/v4.0.10...v4.0.12)

---
updated-dependencies:
- dependency-name: marked
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-01-30 19:04:09 -05:00
dependabot[bot]
517fdb9d6e
Bump eslint-plugin-vue from 8.2.0 to 8.3.0 (#829)
Bumps [eslint-plugin-vue](https://github.com/vuejs/eslint-plugin-vue) from 8.2.0 to 8.3.0.
- [Release notes](https://github.com/vuejs/eslint-plugin-vue/releases)
- [Commits](https://github.com/vuejs/eslint-plugin-vue/compare/v8.2.0...v8.3.0)

---
updated-dependencies:
- dependency-name: eslint-plugin-vue
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-01-23 15:03:15 -05:00
dependabot[bot]
f0161b9511
Bump marked from 4.0.9 to 4.0.10 (#826)
Bumps [marked](https://github.com/markedjs/marked) from 4.0.9 to 4.0.10.
- [Release notes](https://github.com/markedjs/marked/releases)
- [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json)
- [Commits](https://github.com/markedjs/marked/compare/v4.0.9...v4.0.10)

---
updated-dependencies:
- dependency-name: marked
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-01-14 22:53:36 -05:00
arkon
0c07b64f16 Update dependabot config 2022-01-08 15:27:15 -05:00
arkon
7a1c73935b Update dependencies 2022-01-08 15:14:35 -05:00
arkon
3a024aceea Update dependencies 2021-12-22 19:19:24 -05:00
dependabot[bot]
1c0df762e8
Bump eslint-plugin-promise from 5.2.0 to 6.0.0 (#796)
Bumps [eslint-plugin-promise](https://github.com/xjamundx/eslint-plugin-promise) from 5.2.0 to 6.0.0.
- [Release notes](https://github.com/xjamundx/eslint-plugin-promise/releases)
- [Changelog](https://github.com/xjamundx/eslint-plugin-promise/blob/development/CHANGELOG.md)
- [Commits](https://github.com/xjamundx/eslint-plugin-promise/commits)

---
updated-dependencies:
- dependency-name: eslint-plugin-promise
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-19 19:24:16 -05:00
dependabot[bot]
2490ac3281
Bump marked from 4.0.7 to 4.0.8 (#795)
Bumps [marked](https://github.com/markedjs/marked) from 4.0.7 to 4.0.8.
- [Release notes](https://github.com/markedjs/marked/releases)
- [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json)
- [Commits](https://github.com/markedjs/marked/compare/v4.0.7...v4.0.8)

---
updated-dependencies:
- dependency-name: marked
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-19 19:23:49 -05:00
dependabot[bot]
e559bfdc86
Bump vue-agile from 1.1.3 to 2.0.0 (#790)
Bumps [vue-agile](https://github.com/lukaszflorczak/vue-agile) from 1.1.3 to 2.0.0.
- [Release notes](https://github.com/lukaszflorczak/vue-agile/releases)
- [Commits](https://github.com/lukaszflorczak/vue-agile/compare/v1.1.3...v2.0.0)

---
updated-dependencies:
- dependency-name: vue-agile
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-15 17:38:28 -05:00
dependabot[bot]
f7a2e7ac2b
Bump marked from 4.0.6 to 4.0.7 (#792)
Bumps [marked](https://github.com/markedjs/marked) from 4.0.6 to 4.0.7.
- [Release notes](https://github.com/markedjs/marked/releases)
- [Changelog](https://github.com/markedjs/marked/blob/master/.releaserc.json)
- [Commits](https://github.com/markedjs/marked/compare/v4.0.6...v4.0.7)

---
updated-dependencies:
- dependency-name: marked
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-09 19:11:49 -05:00
arkon
35bf3078d7 Fix lint errors 2021-12-07 21:26:19 -05:00
arkon
765538f2ea Update dependencies
via
up to date, audited 1702 packages in 3s

123 packages are looking for funding
  run `npm fund` for details

# npm audit report

ansi-regex  >2.1.1 <5.0.1
Severity: moderate
 Inefficient Regular Expression Complexity in chalk/ansi-regex - https://github.com/advisories/GHSA-93q8-gq69-wqmw
fix available via `npm audit fix --force`
Will install node-sass@4.14.0, which is a breaking change
node_modules/cliui/node_modules/ansi-regex
node_modules/wrap-ansi/node_modules/ansi-regex
node_modules/yargs/node_modules/ansi-regex
  strip-ansi  4.0.0 - 5.2.0
  Depends on vulnerable versions of ansi-regex
  node_modules/cliui/node_modules/strip-ansi
  node_modules/wrap-ansi/node_modules/strip-ansi
  node_modules/yargs/node_modules/strip-ansi
    cliui  4.0.0 - 5.0.0
    Depends on vulnerable versions of strip-ansi
    Depends on vulnerable versions of wrap-ansi
    node_modules/cliui
      yargs  10.1.0 - 15.0.0
      Depends on vulnerable versions of cliui
      Depends on vulnerable versions of string-width
      node_modules/yargs
        sass-graph  2.2.5 || >=3.0.5
        Depends on vulnerable versions of yargs
        node_modules/sass-graph
          node-sass  >=4.14.1
          Depends on vulnerable versions of sass-graph
          node_modules/node-sass
        webpack-dev-server  2.0.0-beta - 3.11.3
        Depends on vulnerable versions of chokidar
        Depends on vulnerable versions of yargs
        node_modules/webpack-dev-server
    string-width  2.1.0 - 4.1.0
    Depends on vulnerable versions of strip-ansi
    node_modules/cliui/node_modules/string-width
    node_modules/wrap-ansi/node_modules/string-width
    node_modules/yargs/node_modules/string-width
      wrap-ansi  3.0.0 - 6.1.0
      Depends on vulnerable versions of string-width
      Depends on vulnerable versions of strip-ansi
      node_modules/wrap-ansi
        webpackbar  3.0.0-0 - 3.2.0
        Depends on vulnerable versions of wrap-ansi
        node_modules/webpackbar

glob-parent  <5.1.2
Severity: high
Regular expression denial of service - https://github.com/advisories/GHSA-ww39-953v-wcq6
No fix available
node_modules/chokidar/node_modules/glob-parent
node_modules/copy-webpack-plugin/node_modules/glob-parent
node_modules/fast-glob/node_modules/glob-parent
  chokidar  1.0.0-rc1 - 2.1.8
  Depends on vulnerable versions of glob-parent
  node_modules/chokidar
    @vuepress/core  <=1.8.2
    Depends on vulnerable versions of chokidar
    node_modules/@vuepress/core
      vuepress  1.0.0-alpha.0 - 1.8.2
      Depends on vulnerable versions of @vuepress/core
      node_modules/vuepress
        @mr-hope/vuepress-types  *
        Depends on vulnerable versions of @types/markdown-it
        Depends on vulnerable versions of vuepress
        node_modules/@mr-hope/vuepress-types
          @mr-hope/vuepress-plugin-sitemap  >=1.20.3
          Depends on vulnerable versions of @mr-hope/vuepress-types
          node_modules/@mr-hope/vuepress-plugin-sitemap
    watchpack-chokidar2  *
    Depends on vulnerable versions of chokidar
    node_modules/watchpack-chokidar2
      watchpack  1.7.2 - 1.7.5
      Depends on vulnerable versions of watchpack-chokidar2
      node_modules/watchpack
        webpack  4.44.0 - 4.46.0
        Depends on vulnerable versions of watchpack
        node_modules/webpack
    webpack-dev-server  2.0.0-beta - 3.11.3
    Depends on vulnerable versions of chokidar
    Depends on vulnerable versions of yargs
    node_modules/webpack-dev-server
  copy-webpack-plugin  5.0.1 - 5.1.2
  Depends on vulnerable versions of glob-parent
  node_modules/copy-webpack-plugin
  fast-glob  <=2.2.7
  Depends on vulnerable versions of glob-parent
  node_modules/fast-glob
    globby  8.0.0 - 9.2.0
    Depends on vulnerable versions of fast-glob
    node_modules/globby
      @vuepress/shared-utils  *
      Depends on vulnerable versions of globby
      node_modules/@vuepress/shared-utils
        @vuepress/markdown  <=1.8.2
        Depends on vulnerable versions of @vuepress/shared-utils
        node_modules/@vuepress/markdown
          @vuepress/markdown-loader  *
          Depends on vulnerable versions of @vuepress/markdown
          node_modules/@vuepress/markdown-loader
        @vuepress/plugin-pwa  <=1.8.2
        Depends on vulnerable versions of @vuepress/shared-utils
        node_modules/@vuepress/plugin-pwa
        @vuepress/plugin-register-components  <=1.8.2
        Depends on vulnerable versions of @vuepress/shared-utils
        node_modules/@vuepress/plugin-register-components
        vuepress-plugin-container  >=2.1.5
        Depends on vulnerable versions of @vuepress/shared-utils
        node_modules/vuepress-plugin-container
        vuepress-plugin-dehydrate  *
        Depends on vulnerable versions of @vuepress/shared-utils
        node_modules/vuepress-plugin-dehydrate

highlight.js  9.0.0 - 10.4.0
Severity: moderate
ReDOS vulnerabities: multiple grammars - https://github.com/advisories/GHSA-7wwv-vh3v-89cq
fix available via `npm audit fix --force`
Will install @mr-hope/vuepress-plugin-sitemap@1.20.0, which is a breaking change
node_modules/highlight.js
  @types/markdown-it  10.0.3
  Depends on vulnerable versions of highlight.js
  node_modules/@types/markdown-it
    @mr-hope/vuepress-types  *
    Depends on vulnerable versions of @types/markdown-it
    Depends on vulnerable versions of vuepress
    node_modules/@mr-hope/vuepress-types
      @mr-hope/vuepress-plugin-sitemap  >=1.20.3
      Depends on vulnerable versions of @mr-hope/vuepress-types
      node_modules/@mr-hope/vuepress-plugin-sitemap

nth-check  <2.0.1
Severity: moderate
Inefficient Regular Expression Complexity in nth-check - https://github.com/advisories/GHSA-rp65-9cf3-cjxr
fix available via `npm audit fix`
node_modules/nth-check
  css-select  <=3.1.0
  Depends on vulnerable versions of nth-check
  node_modules/css-select
    svgo  1.0.0 - 1.3.2
    Depends on vulnerable versions of css-select
    node_modules/svgo
      postcss-svgo  4.0.0-nightly.2020.1.9 - 5.0.0-rc.2
      Depends on vulnerable versions of svgo
      node_modules/postcss-svgo
        cssnano-preset-default  <=4.0.8
        Depends on vulnerable versions of postcss-svgo
        node_modules/cssnano-preset-default
          cssnano  4.0.0-nightly.2020.1.9 - 4.1.11
          Depends on vulnerable versions of cssnano-preset-default
          node_modules/cssnano
            optimize-css-assets-webpack-plugin  3.2.1 || 5.0.0 - 5.0.8
            Depends on vulnerable versions of cssnano
            node_modules/optimize-css-assets-webpack-plugin

trim-newlines  <3.0.1
Severity: high
Regular Expression Denial of Service in trim-newlines - https://github.com/advisories/GHSA-7p7h-4mm5-852v
No fix available
node_modules/generate-robotstxt/node_modules/trim-newlines
  meow  3.4.0 - 5.0.0
  Depends on vulnerable versions of trim-newlines
  Depends on vulnerable versions of yargs-parser
  node_modules/generate-robotstxt/node_modules/meow
    generate-robotstxt  5.0.1 - 8.0.0
    Depends on vulnerable versions of meow
    node_modules/generate-robotstxt
      vuepress-plugin-robots  *
      Depends on vulnerable versions of generate-robotstxt
      node_modules/vuepress-plugin-robots

yargs-parser  6.0.0 - 13.1.1
Severity: moderate
Prototype Pollution in yargs-parser - https://github.com/advisories/GHSA-p9pc-299p-vxgp
No fix available
node_modules/generate-robotstxt/node_modules/yargs-parser
  meow  3.4.0 - 5.0.0
  Depends on vulnerable versions of trim-newlines
  Depends on vulnerable versions of yargs-parser
  node_modules/generate-robotstxt/node_modules/meow
    generate-robotstxt  5.0.1 - 8.0.0
    Depends on vulnerable versions of meow
    node_modules/generate-robotstxt
      vuepress-plugin-robots  *
      Depends on vulnerable versions of generate-robotstxt
      node_modules/vuepress-plugin-robots

43 vulnerabilities (20 moderate, 23 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues possible (including breaking changes), run:
  npm audit fix --force

Some issues need review, and may require choosing
a different dependency.
2021-12-07 21:05:43 -05:00
arkon
0668342bcc Update vue dependencies 2021-12-07 21:03:40 -05:00
arkon
ab0102972c Update eslint plugins 2021-12-07 21:03:27 -05:00
arkon
03e3267e80 Update marked 2021-12-07 20:35:13 -05:00