Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump js-yaml from 3.14.1 to 4.1.0 #917

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 14, 2021

Bumps js-yaml from 3.14.1 to 4.1.0.

Changelog

Sourced from js-yaml's changelog.

[4.1.0] - 2021-04-15

Added

  • Types are now exported as yaml.types.XXX.
  • Every type now has options property with original arguments kept as they were (see yaml.types.int.options as an example).

Changed

  • Schema.extend() now keeps old type order in case of conflicts (e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as abcd instead of cbad).

[4.0.0] - 2021-01-03

Changed

  • Check migration guide to see details for all breaking changes.
  • Breaking: "unsafe" tags !!js/function, !!js/regexp, !!js/undefined are moved to js-yaml-js-types package.
  • Breaking: removed safe* functions. Use load, loadAll, dump instead which are all now safe by default.
  • yaml.DEFAULT_SAFE_SCHEMA and yaml.DEFAULT_FULL_SCHEMA are removed, use yaml.DEFAULT_SCHEMA instead.
  • yaml.Schema.create(schema, tags) is removed, use schema.extend(tags) instead.
  • !!binary now always mapped to Uint8Array on load.
  • Reduced nesting of /lib folder.
  • Parse numbers according to YAML 1.2 instead of YAML 1.1 (01234 is now decimal, 0o1234 is octal, 1:23 is parsed as string instead of base60).
  • dump() no longer quotes :, [, ], (, ) except when necessary, #470, #557.
  • Line and column in exceptions are now formatted as (X:Y) instead of at line X, column Y (also present in compact format), #332.
  • Code snippet created in exceptions now contains multiple lines with line numbers.
  • dump() now serializes undefined as null in collections and removes keys with undefined in mappings, #571.
  • dump() with skipInvalid=true now serializes invalid items in collections as null.
  • Custom tags starting with ! are now dumped as !tag instead of !<!tag>, #576.
  • Custom tags starting with tag:yaml.org,2002: are now shorthanded using !!, #258.

Added

  • Added .mjs (es modules) support.
  • Added quotingType and forceQuotes options for dumper to configure string literal style, #290, #529.
  • Added styles: { '!!null': 'empty' } option for dumper (serializes { foo: null } as "foo: "), #570.
  • Added replacer option (similar to option in JSON.stringify), #339.
  • Custom Tag can now handle all tags or multiple tags with the same prefix, #385.

Fixed

  • Astral characters are no longer encoded by dump(), #587.
  • "duplicate mapping key" exception now points at the correct column, #452.
  • Extra commas in flow collections (e.g. [foo,,bar]) now throw an exception instead of producing null, #321.
  • __proto__ key no longer overrides object prototype, #164.

... (truncated)

Commits
  • 2cef47b 4.1.0 released
  • 810b149 dist rebuild
  • 2b5620e Export built-in types, type override now preserves order
  • ab31bba doc: clarify lineWidth dump options (#612)
  • ee74ce4 4.0.0 released
  • a44bb7c dist rebuild
  • aee620a Throw an error if block sequence/mapping indent contains a tab
  • f0f205b Fix parsing of invalid block mappings
  • e8cf6f6 Fix error with anchor not being assigned to an empty node
  • a583097 Shorthand tags with !! whenever possible
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jun 14, 2021
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch 2 times, most recently from 50bd064 to ca13fcc Compare June 23, 2021 01:30
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from ca13fcc to e97de57 Compare July 6, 2021 15:34
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from e97de57 to 1e4d9f8 Compare August 5, 2021 18:36
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 1e4d9f8 to 324d521 Compare September 1, 2021 17:23
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 324d521 to 4ec4571 Compare September 21, 2021 16:33
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 4ec4571 to 7ba24c6 Compare October 8, 2021 21:35
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 7ba24c6 to 818cc62 Compare October 28, 2021 16:22
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 818cc62 to e6c9c67 Compare November 11, 2021 13:20
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from e6c9c67 to 56da22a Compare December 2, 2021 16:13
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 56da22a to 1ce1e65 Compare December 10, 2021 16:46
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 1ce1e65 to 6812520 Compare January 15, 2022 00:06
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 6812520 to c51c420 Compare January 27, 2022 15:22
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch 2 times, most recently from 5d85cb8 to 1072512 Compare March 3, 2022 22:49
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 1072512 to 3c1c44a Compare March 16, 2022 13:55
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 3c1c44a to 45d8ca8 Compare March 29, 2022 14:05
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 45d8ca8 to 4154f53 Compare April 15, 2022 16:27
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch 2 times, most recently from f5d21e0 to 717c0dc Compare June 9, 2022 19:44
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 717c0dc to 4e7bc98 Compare July 6, 2022 22:29
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch 3 times, most recently from 0a3328d to b2d3f57 Compare August 12, 2022 19:12
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from b2d3f57 to ce49c2c Compare August 30, 2022 19:02
@stale
Copy link

stale bot commented Nov 2, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix This will not be worked on label Nov 2, 2022
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from ce49c2c to 611c2d4 Compare November 9, 2022 19:44
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 611c2d4 to 1e71129 Compare January 3, 2023 21:44
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 1e71129 to 4869e96 Compare January 11, 2023 19:54
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from 4869e96 to e94b78f Compare January 31, 2023 20:19
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.1 to 4.1.0.
- [Release notes](https://github.com/nodeca/js-yaml/releases)
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.1...4.1.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.0 branch from e94b78f to 4766445 Compare March 7, 2023 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file wontfix This will not be worked on
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants