Bump shell-quote and react-scripts in /frontend
Bumps shell-quote to 1.8.0 and updates ancestor dependency react-scripts. These dependencies need to be updated together.
Updates shell-quote
from 1.7.2 to 1.8.0
Changelog
Sourced from shell-quote's changelog.
v1.8.0 - 2023-01-30
Commits
- [New] extract
parse
andquote
to their own deep imports553fdfc
- [Tests] add
nyc
coveragefd7ddcd
- [New] Add support for here strings (
<<<
)9802fb3
- [New]
parse
: Add syntax support for duplicating input file descriptors216b198
- [Dev Deps] update
@ljharb/eslint-config
,aud
,tape
85f8e31
- [Tests] add
evalmd
c5549fc
- [actions] update checkout action
62e9b49
v1.7.4 - 2022-10-12
Merged
- Add node_modules to .gitignore
[#48](https://github.com/ljharb/shell-quote/issues/48)
Commits
- [eslint] fix indentation and whitespace
aaa9d1f
- [eslint] additional cleanup
397cb62
- [meta] add
auto-changelog
497fca5
- [actions] add reusable workflows
4763c36
- [eslint] add eslint
6ee1437
- [readme] rename, add badges
7eb5134
- [meta] update URLs
67381b6
- [meta] create FUNDING.yml; add
funding
in package.json8641572
- [meta] use
npmignore
to autogenerate an npmignore file2e2007a
- Only apps should have lockfiles
f97411e
- [Dev Deps] update
tape
051f608
- [meta] add
safe-publish-latest
18cadf9
- [Tests] add
aud
inposttest
dc1cc12
1.7.3
- Fix a security issue where the regex for windows drive letters allowed some shell meta-characters to escape the quoting rules. (CVE-2021-42740)
Commits
-
508e2f9
v1.8.0 -
fd7ddcd
[Tests] addnyc
coverage -
9802fb3
[New] Add support for here strings (<<<
) -
216b198
[New]parse
: Add syntax support for duplicating input file descriptors -
c5549fc
[Tests] addevalmd
-
553fdfc
[New] extractparse
andquote
to their own deep imports -
85f8e31
[Dev Deps] update@ljharb/eslint-config
,aud
,tape
-
62e9b49
[actions] update checkout action -
5409e72
v1.7.4 -
4763c36
[actions] add reusable workflows - Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for shell-quote since your current version.
Updates react-scripts
from 3.4.3 to 5.0.1
Changelog
Sourced from react-scripts's changelog.
3.4.4 (2020-10-20)
v3.4.4 release bumps
resolve-url-loader
to a version for whichnpm audit
does not report a vulnerability. Note that this vulnerability did not affect Create React App projects, so this change is only necessary to satisfy auditing tools.
Commits
-
19fa58d
Publish -
9802941
fix: webpack noise printed only if error or warning (#12245) -
2eef1d0
Update templates to use React 18createRoot
(#12220) -
221e511
Publish -
5614c87
Add support for Tailwind (#11717) -
20edab4
fix(webpackDevServer): disable overlay for warnings (#11413) -
3afbbc0
Update all dependencies (#11624) -
f5467d5
feat(eslint-config-react-app): support ESLint 8.x (#11375) -
c7627ce
Update webpack and dev server (#11646) -
544befe
Update package.json (#11597) - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.