Closed
requested to merge dependabot/npm_and_yarn/samples/client/petstore/typescript-angular-v12-provided-in-root/terser-and-angular-devkit/build-angular-5.14.2 into master
Created by: dependabot[bot]
Bumps terser and @angular-devkit/build-angular. These dependencies needed to be updated together.
Updates terser from 5.7.1 to 5.14.2
Changelog
Sourced from terser's changelog.
v5.14.2
- Security fix for RegExps that should not be evaluated (regexp DDOS)
- Source maps improvements (#1211)
- Performance improvements in long property access evaluation (#1213)
v5.14.1
- keep_numbers option added to TypeScript defs (#1208)
- Fixed parsing of nested template strings (#1204)
v5.14.0
- Switched to
@jridgewell/source-mapfor sourcemap generation (#1190, #1181)- Fixed source maps with non-terminated segments (#1106)
- Enabled typescript types to be imported from the package (#1194)
- Extra DOM props have been added (#1191)
- Delete the AST while generating code, as a means to save RAM
v5.13.1
- Removed self-assignments (
varname=varname) (closes #1081)- Separated inlining code (for inlining things into references, or removing IIFEs)
- Allow multiple identifiers with the same name in
vardestructuring (egvar { a, a } = x) (#1176)v5.13.0
- All calls to eval() were removed (#1171, #1184)
source-mapwas updated to 0.8.0-beta.0 (#1164)- NavigatorUAData was added to domprops to avoid property mangling (#1166)
v5.12.1
- Fixed an issue with function definitions inside blocks (#1155)
- Fixed parens of
newin some situations (closes #1159)v5.12.0
TERSER_DEBUG_DIRenvironment variable@copyrightcomments are now preserved with the comments="some" option (#1153)v5.11.0
- Unicode code point escapes (
\u{abcde}) are not emitted inside RegExp literals anymore (#1147)- acorn is now a regular dependency
v5.10.0
... (truncated)
Commits
-
c5cb19d5.14.2 -
a4da734fix potential regexp DDOS -
839b81bAdd source mapping for closing}(#1211) -
645a092Optimize property access evaluation (#1213) -
6706fec5.14.1 -
4a56ef2update changelog -
c558e12Add keep_numbers option. Closes #1208 -
f745ac7fix parsing of nested template strings. Closes #1204 -
17077535.14.0 -
cb82833update changelog - Additional commits viewable in compare view
Updates @angular-devkit/build-angular from 12.2.17 to 12.2.18
Release notes
Sourced from @angular-devkit/build-angular's releases.
v12.2.18
12.2.18 (2022-07-21)
@angular-devkit/build-angular
Commit Description update terser to address CVE-2022-25858 Special Thanks
Alan Agius, Joey Perrott and Paul Gschwendtner
Changelog
Sourced from @angular-devkit/build-angular's changelog.
12.2.18 (2022-07-21)
@angular-devkit/build-angular
Commit Type Description 4d723ca95 fix update terser to address CVE-2022-25858 Special Thanks
Alan Agius, Joey Perrott and Paul Gschwendtner
Commits
-
455848frelease: cut the v12.2.18 release -
ed08d83test: use correct version of material -
4d723cafix(@angular-devkit/build-angular): update terser to address CVE-2022-25858 -
7e33d1etest: remove material-design-icons e2e test -
789c4e3ci: add nightly CI run for 12.2.x branch -
b61724ebuild: update saucelabs key -
6723a3cbuild: changes for primary branch rename tomain. -
60a756fbuild: preparation for primary branch rename in the Angular repos - See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.