{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":676456574,"defaultBranch":"master","name":"web3.js-plugin-template","ownerLogin":"web3","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2023-08-09T08:39:22.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/36739222?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1719837361.0","currentOid":""},"activityList":{"items":[{"before":null,"after":"fbcceec43a0620dfa233a9dfd5c20f06419be4a8","ref":"refs/heads/dependabot/npm_and_yarn/braces-3.0.3","pushedAt":"2024-07-01T12:36:01.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"chore(deps): Bump braces from 3.0.2 to 3.0.3\n\nBumps [braces](https://github.com/micromatch/braces) from 3.0.2 to 3.0.3.\n- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/braces/compare/3.0.2...3.0.3)\n\n---\nupdated-dependencies:\n- dependency-name: braces\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] Sourced from ws's\r\nreleases. A request with a number of headers exceeding\r\nthe[ const wss = new WebSocket.Server({ port: 0 }, function () {\r\nconst chars =\r\n"!#$%&'*+-.0123456789abcdefghijklmnopqrstuvwxyz^_`|~".split('');\r\nconst headers = {};\r\nlet count = 0; for (let i = 0; i < chars.length; i++) {\r\nif (count === 2000) break; } headers.Connection = 'Upgrade';\r\nheaders.Upgrade = 'websocket';\r\nheaders['Sec-WebSocket-Key'] = 'dGhlIHNhbXBsZSBub25jZQ==';\r\nheaders['Sec-WebSocket-Version'] = '13'; const request = http.request({\r\nheaders: headers,\r\nhost: '127.0.0.1',\r\nport: wss.address().port\r\n}); request.end();\r\n});\r\nRelease notes
\r\n\r\n
8.17.1
\r\nBug fixes
\r\n\r\n
\r\nserver.maxHeadersCount
][]\r\nthreshold could be used to crash a ws server.const http = require('http');\r\nconst WebSocket = require('ws');\r\n
\r\nfor (let j = 0; j < chars.length; j++) {\r\n const key = chars[i] + chars[j];\r\n headers[key] = 'x';\r\n\r\n if (++count === 2000) break;\r\n}\r\n
The vulnerability was reported by Ryan LaPointe in websockets/ws#2230.
\r\nIn vulnerable versions of ws, the issue can be mitigated in the\r\nfollowing ways:
\r\n--max-http-header-size=size
][] and/or the\r\n[maxHeaderSize
][] options so\r\nthat no more headers than the server.maxHeadersCount
limit\r\ncan be sent.... (truncated)
\r\n\r\n3c56601
\r\n[dist] 8.17.1e55e510
\r\n[security] Fix crash when the Upgrade header cannot be read (#2231)6a00029
\r\n[test] Increase code coverageddfe4a8
\r\n[perf] Reduce the amount of crypto.randomFillSync()
\r\ncallsb73b118
\r\n[dist] 8.17.029694a5
\r\n[test] Use the highWaterMark
variable934c9d6
\r\n[ci] Test on node 221817bac
\r\n[ci] Do not test on node 2196c9b3d
\r\n[major] Flip the default value of allowSynchronousEvents
\r\n(#2221)e5f32c7
\r\n[fix] Emit at most one event per event loop iteration (#2218)Sourced from @babel/traverse
's\r\nreleases.
\r\n\r\nv7.23.2 (2023-10-11)
\r\nNOTE: This release also re-publishes\r\n
\r\n@babel/core
, even if it does not appear in the linked\r\nrelease commit.Thanks
\r\n@jimmydief
for\r\nyour first PR!:bug: Bug Fix
\r\n\r\n
\r\n- \r\n
babel-traverse
\r\n\r\n
\r\n- #16033\r\nOnly evaluate own String/Number/Math methods (
\r\n@nicolo-ribaudo
)- \r\n
babel-preset-typescript
\r\n\r\n
\r\n- #16022\r\nRewrite
\r\n.tsx
extension when using\r\nrewriteImportExtensions
(@jimmydief
)- \r\n
babel-helpers
\r\n\r\n- \r\n
babel-helpers
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-runtime-corejs2
,babel-runtime-corejs3
,\r\nbabel-runtime
\r\n\r\n
\r\n- #16025\r\nAvoid override mistake in namespace imports (
\r\n@nicolo-ribaudo
)Committers: 5
\r\n\r\n
\r\n- Babel Bot (
\r\n@babel-bot
)- Huáng Jùnliàng (
\r\n@JLHwung
)- James Diefenderfer (
\r\n@jimmydief
)- Nicolò Ribaudo (
\r\n@nicolo-ribaudo
)- \r\n
@liuxingbaoyu
v7.23.1 (2023-09-25)
\r\nRe-publishing
\r\n@babel/helpers
due to a publishing error\r\nin 7.23.0.v7.23.0 (2023-09-25)
\r\nThanks
\r\n@lorenzoferre
\r\nand@RajShukla1
for\r\nyour first PRs!:rocket: New Feature
\r\n\r\n
\r\n\r\n- \r\n
babel-plugin-proposal-import-wasm-source
,\r\nbabel-plugin-syntax-import-source
,\r\nbabel-plugin-transform-dynamic-import
\r\n\r\n
\r\n- #15870\r\nSupport transforming
\r\nimport source
for wasm (@nicolo-ribaudo
)- \r\n
babel-helper-module-transforms
,\r\nbabel-helpers
,\r\nbabel-plugin-proposal-import-defer
,\r\nbabel-plugin-syntax-import-defer
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-runtime-corejs2
,babel-runtime-corejs3
,\r\nbabel-runtime
,babel-standalone
\r\n\r\n
\r\n- #15878\r\nImplement
\r\nimport defer
proposal transform support (@nicolo-ribaudo
)- \r\n
babel-generator
,babel-parser
,\r\nbabel-types
\r\n\r\n
\r\n- #15845\r\nImplement
\r\nimport defer
parsing support (@nicolo-ribaudo
)- #15829 Add\r\nparsing support for the "source phase imports" proposal (
\r\n@nicolo-ribaudo
)- \r\n
babel-generator
,\r\nbabel-helper-module-transforms
,babel-parser
,\r\nbabel-plugin-transform-dynamic-import
,\r\nbabel-plugin-transform-modules-amd
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-plugin-transform-modules-systemjs
,\r\nbabel-traverse
,babel-types
\r\n\r\n- \r\n
babel-standalone
\r\n\r\n- \r\n
babel-helper-function-name
,\r\nbabel-helper-member-expression-to-functions
,\r\nbabel-helpers
,babel-parser
,\r\nbabel-plugin-proposal-destructuring-private
,\r\nbabel-plugin-proposal-optional-chaining-assign
,\r\nbabel-plugin-syntax-optional-chaining-assign
,\r\nbabel-plugin-transform-destructuring
,\r\nbabel-plugin-transform-optional-chaining
,\r\nbabel-runtime-corejs2
,babel-runtime-corejs3
,\r\nbabel-runtime
,babel-standalone
,\r\nbabel-types
\r\n\r\n
\r\n- #15751 Add\r\nsupport for optional chain in assignments (
\r\n@nicolo-ribaudo
)- \r\n
babel-helpers
,\r\nbabel-plugin-proposal-decorators
\r\n\r\n
\r\n- #15895\r\nImplement the "decorator metadata" proposal (
\r\n@nicolo-ribaudo
)- \r\n
babel-traverse
,babel-types
\r\n\r\n
\r\n- #15893 Add\r\n
\r\nt.buildUndefinedNode
(@liuxingbaoyu
)- \r\n
babel-preset-typescript
... (truncated)
\r\nSourced from @babel/traverse
's\r\nchangelog.
\r\n\r\nv7.23.2 (2023-10-11)
\r\n:bug: Bug Fix
\r\n\r\n
\r\n- \r\n
babel-traverse
\r\n\r\n
\r\n- #16033\r\nOnly evaluate own String/Number/Math methods (
\r\n@nicolo-ribaudo
)- \r\n
babel-preset-typescript
\r\n\r\n
\r\n- #16022\r\nRewrite
\r\n.tsx
extension when using\r\nrewriteImportExtensions
(@jimmydief
)- \r\n
babel-helpers
\r\n\r\n- \r\n
babel-helpers
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-runtime-corejs2
,babel-runtime-corejs3
,\r\nbabel-runtime
\r\n\r\n
\r\n- #16025\r\nAvoid override mistake in namespace imports (
\r\n@nicolo-ribaudo
)v7.23.0 (2023-09-25)
\r\n:rocket: New Feature
\r\n\r\n
\r\n- \r\n
babel-plugin-proposal-import-wasm-source
,\r\nbabel-plugin-syntax-import-source
,\r\nbabel-plugin-transform-dynamic-import
\r\n\r\n
\r\n- #15870\r\nSupport transforming
\r\nimport source
for wasm (@nicolo-ribaudo
)- \r\n
babel-helper-module-transforms
,\r\nbabel-helpers
,\r\nbabel-plugin-proposal-import-defer
,\r\nbabel-plugin-syntax-import-defer
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-runtime-corejs2
,babel-runtime-corejs3
,\r\nbabel-runtime
,babel-standalone
\r\n\r\n
\r\n- #15878\r\nImplement
\r\nimport defer
proposal transform support (@nicolo-ribaudo
)- \r\n
babel-generator
,babel-parser
,\r\nbabel-types
\r\n\r\n
\r\n- #15845\r\nImplement
\r\nimport defer
parsing support (@nicolo-ribaudo
)- #15829 Add\r\nparsing support for the "source phase imports" proposal (
\r\n@nicolo-ribaudo
)- \r\n
babel-generator
,\r\nbabel-helper-module-transforms
,babel-parser
,\r\nbabel-plugin-transform-dynamic-import
,\r\nbabel-plugin-transform-modules-amd
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-plugin-transform-modules-systemjs
,\r\nbabel-traverse
,babel-types
\r\n\r\n- \r\n
babel-standalone
\r\n\r\n- \r\n
babel-helper-function-name
,\r\nbabel-helper-member-expression-to-functions
,\r\nbabel-helpers
,babel-parser
,\r\nbabel-plugin-proposal-destructuring-private
,\r\nbabel-plugin-proposal-optional-chaining-assign
,\r\nbabel-plugin-syntax-optional-chaining-assign
,\r\nbabel-plugin-transform-destructuring
,\r\nbabel-plugin-transform-optional-chaining
,\r\nbabel-runtime-corejs2
,babel-runtime-corejs3
,\r\nbabel-runtime
,babel-standalone
,\r\nbabel-types
\r\n\r\n
\r\n- #15751 Add\r\nsupport for optional chain in assignments (
\r\n@nicolo-ribaudo
)- \r\n
babel-helpers
,\r\nbabel-plugin-proposal-decorators
\r\n\r\n
\r\n- #15895\r\nImplement the "decorator metadata" proposal (
\r\n@nicolo-ribaudo
)- \r\n
babel-traverse
,babel-types
\r\n\r\n
\r\n- #15893 Add\r\n
\r\nt.buildUndefinedNode
(@liuxingbaoyu
)- \r\n
babel-preset-typescript
\r\n\r\n
\r\n- #15913 Add\r\n
\r\nrewriteImportExtensions
option to TS preset (@nicolo-ribaudo
)- \r\n
babel-parser
\r\n\r\n
\r\n- #15896\r\nAllow TS tuples to have both labeled and unlabeled elements (
\r\n@yukukotani
):bug: Bug Fix
\r\n\r\n
\r\n- \r\n
babel-plugin-transform-block-scoping
\r\n\r\n
\r\n- #15962\r\nfix:
\r\ntransform-block-scoping
captures the variables of the\r\nmethod in the loop (@liuxingbaoyu
):nail_care: Polish
\r\n\r\n
\r\n- \r\n
babel-traverse
\r\n\r\n
\r\n- #15797\r\nExpand evaluation of global built-ins in
\r\n@babel/traverse
\r\n(@lorenzoferre
)- \r\n
babel-plugin-proposal-explicit-resource-management
\r\n\r\n
\r\n- #15985\r\nImprove source maps for blocks with
\r\nusing
declarations (@nicolo-ribaudo
):microscope: Output optimization
\r\n\r\n
\r\n- \r\n
babel-core
,\r\nbabel-helper-module-transforms
,\r\nbabel-plugin-transform-async-to-generator
,\r\nbabel-plugin-transform-classes
,\r\nbabel-plugin-transform-dynamic-import
,\r\nbabel-plugin-transform-function-name
,\r\nbabel-plugin-transform-modules-amd
,\r\nbabel-plugin-transform-modules-commonjs
,\r\nbabel-plugin-transform-modules-umd
,\r\nbabel-plugin-transform-parameters
,\r\nbabel-plugin-transform-react-constant-elements
,\r\nbabel-plugin-transform-react-inline-elements
,\r\nbabel-plugin-transform-runtime
,\r\nbabel-plugin-transform-typescript
,\r\nbabel-preset-env
\r\n\r\n
\r\n- #15984\r\nInline
\r\nexports.XXX =
update in simple variable declarations\r\n(@nicolo-ribaudo
)v7.22.20 (2023-09-16)
\r\n\r\n
... (truncated)
\r\nb4b9942
\r\nv7.23.2b13376b
\r\nOnly evaluate own String/Number/Math methods (#16033)ca58ec1
\r\nv7.23.00f333da
\r\nAdd createImportExpressions
parser option (#15682)3744545
\r\nFix lintingc7e6806
\r\nAdd t.buildUndefinedNode
(#15893)38ee8b4
\r\nExpand evaluation of global built-ins in @babel/traverse
\r\n(#15797)9f3dfd9
\r\nv7.22.203ed28b2
\r\nFully support ||
and &&
in\r\npluginToggleBooleanFlag
(#15961)77b0d73
\r\nv7.22.19