14.json (5284B)
1 { 2 "number": 14, 3 "title": "Bump websocket-extensions from 0.1.3 to 0.1.4", 4 "state": "merged", 5 "diff_file": "14.diff", 6 "author": "dependabot[bot]", 7 "created_at": "2020-06-08T08:29:16Z", 8 "closed_at": "2020-06-08T15:10:44Z", 9 "merged_at": "2020-06-08T15:10:44Z", 10 "base_ref": "master", 11 "head_ref": "dependabot/npm_and_yarn/websocket-extensions-0.1.4", 12 "labels": [ 13 "dependencies" 14 ], 15 "assignees": [], 16 "requested_reviewers": [], 17 "body": "Bumps [websocket-extensions](https://github.com/faye/websocket-extensions-node) from 0.1.3 to 0.1.4.\n<details>\n<summary>Changelog</summary>\n<p><em>Sourced from <a href=\"https://github.com/faye/websocket-extensions-node/blob/master/CHANGELOG.md\">websocket-extensions's changelog</a>.</em></p>\n<blockquote>\n<h3>0.1.4 / 2020-06-02</h3>\n<ul>\n<li>Remove a ReDoS vulnerability in the header parser (CVE-2020-7662, reported by\nRobert McLaughlin)</li>\n<li>Change license from MIT to Apache 2.0</li>\n</ul>\n</blockquote>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/8efd0cd6e35faf9bb9cb08759be1e27082177d43\"><code>8efd0cd</code></a> Bump version to 0.1.4</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/3dad4ad44a8c5f74d4f8f4efd3f9d6e0b5df3051\"><code>3dad4ad</code></a> Remove ReDoS vulnerability in the Sec-WebSocket-Extensions header parser</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/4a76c75efb1c5d6a2f60550e9501757458d19533\"><code>4a76c75</code></a> Add Node versions 13 and 14 on Travis</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/44a677a9c0631daed0b0f4a4b68c095b624183b8\"><code>44a677a</code></a> Formatting change: {...} should have spaces inside the braces</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/f6c50aba0c20ff45b0f87cea33babec1217ec3f5\"><code>f6c50ab</code></a> Let npm reformat package.json</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/2d211f3705d52d9efb4f01daf5a253adf828592e\"><code>2d211f3</code></a> Change markdown formatting of docs.</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/0b620834cc1e1f2eace1d55ab17f71d90d88271d\"><code>0b62083</code></a> Update Travis target versions.</li>\n<li><a href=\"https://github.com/faye/websocket-extensions-node/commit/729a4653073fa8dd020561113513bfa2e2119415\"><code>729a465</code></a> Switch license to Apache 2.0.</li>\n<li>See full diff in <a href=\"https://github.com/faye/websocket-extensions-node/compare/0.1.3...0.1.4\">compare view</a></li>\n</ul>\n</details>\n<br />\n\n\n[](https://help.github.com/articles/configuring-automated-security-fixes)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n<details>\n<summary>Dependabot commands and options</summary>\n<br />\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language\n- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language\n- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language\n- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language\n\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/MTRNord/Daydream/network/alerts).\n\n</details>", 18 "comments": [ 19 { 20 "author": "MTRNord", 21 "created_at": "2020-06-08T15:03:13Z", 22 "body": "@dependabot rebase" 23 } 24 ], 25 "review_comments": [] 26 }