Bump node-fetch and bigchaindb-driver
Bumps node-fetch to 2.6.9 and updates ancestor dependency bigchaindb-driver. These dependencies need to be updated together.
Updates node-fetch from 1.5.1 to 2.6.9
Release notes
Sourced from node-fetch's releases.
v2.6.9
2.6.9 (2023-01-30)
Bug Fixes
v2.6.8
2.6.8 (2023-01-13)
Bug Fixes
- headers: don't forward secure headers on protocol change (#1605) (fddad0e), closes #1599
- premature close with chunked transfer encoding and for async iterators in Node 12 (#1172) (50536d1), closes #1064 node-fetch/node-fetch#1064
- prevent hoisting of the undefined
globalvariable inbrowser.js(#1534) (8bb6e31)v2.6.7
Security patch release
Recommended to upgrade, to not leak sensitive cookie and authentication header information to 3th party host while a redirect occurred
What's Changed
- fix: don't forward secure headers to 3th party by
@jimmywartingin node-fetch/node-fetch#1453Full Changelog: https://github.com/node-fetch/node-fetch/compare/v2.6.6...v2.6.7
v2.6.6
What's Changed
- fix(URL): prefer built in URL version when available and fallback to whatwg by
@jimmywartingin node-fetch/node-fetch#1352Full Changelog: https://github.com/node-fetch/node-fetch/compare/v2.6.5...v2.6.6
v2.6.2
fixed main path in package.json
v2.6.1
This is an important security release. It is strongly recommended to update as soon as possible.
See CHANGELOG for details.
v2.6.0
See CHANGELOG.
v2.5.0
See CHANGELOG.
v2.4.1
... (truncated)
Commits
70f592dfix: "global is not defined" (#1704)0f1ebb0Prevent error when response is null (#1699)6e9464dci(release): install dependenciesdd2a0baci(release): install dependencies49bef02ci(release): use latest Node LTSce37bcdci(semantic-release): config1768eaaci(release): initial version8bb6e31fix: prevent hoisting of the undefinedglobalvariable inbrowser.js(#1534)e218f8dAdd missing changelog entries. (#1613)fddad0efix(headers): don't forward secure headers on protocol change (#1605)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by node-fetch-bot, a new releaser for node-fetch since your current version.
Updates bigchaindb-driver from 4.0.0 to 4.3.0
Release notes
Sourced from bigchaindb-driver's releases.
Release 4.3.0
- Merge pull request #312 from bigchaindb/fet-improve-requests (f9a4675)
- ci: extends wait delay (7a12ee7)
- fix: use abort-controller pkg for node <15 (eee8da4)
- ci: run BCDB node in background (2f3b2db)
- Merge branch 'master' into fet-improve-requests (334a3f4)
- ci: update watched branch (1864f6f)
- ci: create GH workflow (2ffbe99)
- ci: create GH action workflow (ae13da5)
- feat: export extra types (30c15b9)
- fix: improve transaction typedefs (1ba488b)
- feat: update connection typedefs (fbc3d79)
- feat: add
limitquery for transaction search requests (46599f5)- feat: ensure timeout and request are properly cleared (8c0c726)
- chore: update dependencies (c5fe134)
- chore: update lint rules (dc353ee)
- fix: improve promises handling (38819a5)
- chore: update wepback config (34289b0)
- chore: update dev dependencies (1f95bec)
Release 4.2.2
- fix: improve typedefs (6aeece4)
- fix: add delegateSignatureAsync method (71a231a)
Release 4.2.1
- fix: improve imports (f020a35)
- fix: add missing types in package (9b395c1)
Release 4.2.0
- Merge pull request #308 from bigchaindb/add-type-defs (6aa5f01)
- fix: add type for TransactionOutput.condition (1779f6e)
- Merge branch 'add-type-defs' of github.com:bigchaindb/js-bigchaindb-driver into add-type-defs (44dfc8f)
- fix: makeoutput input type (d5fd300)
- fix: Crypto conditions parsers (71fe66c)
- fix: refine Crypoconditions parsers types (af90b97)
- fix: refine types definitions (b177ca0)
- fix: add type definitions (858acf2)
- fix: module exports (d26f667)
- fix: makeoutput input type (c98cc8e)
- fix: Crypto conditions parsers (2a104eb)
- fix: refine Crypoconditions parsers types (90a2cb2)
- fix: refine types definitions (84bd4ef)
- fix: add type definitions (5f6bef6)
- fix: module exports (cd5c529)
- Merge pull request #307 from bigchaindb/update-dependencies (7fe9040)
- Merge branches 'update-dependencies' and 'update-dependencies' of github.com:bigchaindb/js-bigchaindb-driver into update-dependencies (902885f)
- fix: run lint (abaa40b)
- fix: lint config (611624f)
- fix: update example (3d49a67)
- fix: update test constants (978585d)
... (truncated)
Commits
17d3a02Release 4.3.0f9a4675Merge pull request #312 from bigchaindb/fet-improve-requests7a12ee7ci: extends wait delayeee8da4fix: use abort-controller pkg for node <152f3b2dbci: run BCDB node in background334a3f4Merge branch 'master' into fet-improve-requests1864f6fci: update watched branch2ffbe99ci: create GH workflowae13da5ci: create GH action workflow30c15b9feat: export extra types- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by getlarge, a new releaser for bigchaindb-driver since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.