754f0c2
1.3.290ee1fa
ensure keys are valid when mixing in valuesThis version was pushed to npm by doowb, a new releaser for mixin-deep since your current version.
Sourced from node-sass's releases.
v4.14.1
Community
Fixes
Supported Environments
OS Architecture Node Windows x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 OSX x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 Linux* x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8**, 9**, 10**^, 11**^, 12**^, 13**^, 14**^ Alpine Linux x64 6, 8, 10, 11, 12, 13, 14 FreeBSD i386 amd64 10, 12, 13 *Linux support refers to Ubuntu, Debian, and CentOS 5+ ** Not available on CentOS 5 ^ Only available on x64
v4.14.0
Features
Fixes
Supported Environments
OS Architecture Node Windows x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 OSX x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 Linux* x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8**, 9**, 10**^, 11**^, 12**^, 13**^, 14**^ Alpine Linux x64 6, 8, 10, 11, 12, 13, 14 FreeBSD i386 amd64 10, 12, 13 *Linux support refers to Ubuntu, Debian, and CentOS 5+ ** Not available on CentOS 5 ^ Only available on x64
v4.13.1
Community
- Fix render example syntax (@ZoranPandovski , #2787)
Sourced from node-sass's changelog.
v4.14.0
https://github.com/sass/node-sass/releases/tag/v4.14.0
v4.13.1
0d6c3cc
4.14.11cc6263
Bump sass-graph@2.2.5 (#2915)aa193f6
chore: Add GitHub Actions for Alpine CIeac343c
4.14.0bbeb78c
Update changelog1210aab
Fix #2621: Report libsass version 3.5.5 (#2769)5a4a48a
feat: Add Node 14 supportb54053a
Update changelog01db051
4.13.1338fd7a
Merge pull request from GHSA-f6rp-gv58-9cw3d7fbc52
Bump to v4.17.192e1c0f2
Add npm-package1b6c282
Bump to v4.17.18a370ac8
Bump to v4.17.171144918
Rebuild lodash and docs3a3b0fd
Bump to v4.17.16c84fe82
fix(zipObjectDeep): prototype pollution (#4759)e7b28ea
Sanitize sourceURL so it cannot affect evaled code (#4518)0cec225
Fix lodash.isEqual for circular references (#4320) (#4515)94c3a81
Document matches* shorthands for over* methods (#4510) (#4514)This version was pushed to npm by mathias, a new releaser for lodash since your current version.
Sourced from angular's changelog.
1.8.0 nested-vaccination (2020-06-01)
This release contains a breaking change to resolve a security issue which was discovered by Krzysztof Kotowicz(@koto); and independently by Esben Sparre Andreasen (@esbena) while performing a Variant Analysis of CVE-2020-11022 which itself was found and reported by Masato Kinugawa (@masatokinugawa).
Bug Fixes
- jqLite:
- prevent possible XSS due to regex-based HTML replacement (2df43c)
Breaking Changes
jqLite due to:
- 2df43c: prevent possible XSS due to regex-based HTML replacement
JqLite no longer turns XHTML-like strings like
<div /><span />
to sibling elements<div></div><span></span>
when not in XHTML mode. Instead it will leave them as-is. The browser, in non-XHTML mode, will convert these to:<div><span></span></div>
.This is a security fix to avoid an XSS vulnerability if a new jqLite element is created from a user-controlled HTML string. If you must have this functionality and understand the risk involved then it is posible to restore the original behavior by calling
angular.UNSAFE_restoreLegacyJqLiteXHTMLReplacement();
But you should adjust your code for this change and remove your use of this function as soon as possible.
Note that this only patches jqLite. If you use jQuery 3.5.0 or newer, please read the jQuery 3.5 upgrade guide for more details about the workarounds.
1.7.9 pollution-eradication (2019-11-19)
Bug Fixes
- angular.merge: do not merge proto property (726f49)
(Thanks to the Snyk Security Research Team for identifyng this issue.)- ngStyle: correctly remove old style when new style value is invalid (5edd25, #16860, #16868)
1.7.8 enthusiastic-oblation (2019-03-11)
... (truncated)
e55d352
docs(*): update changelog for 1.8.078ab691
chore(*): prep for 1.8.059b5651
docs(ngRepeat): missing closing backtickc8b7c16
fix(jqLite): improve documentation05cf606
fix(jqLite): apply suggestions from code review2df43c0
fix(jqLite): prevent possible XSS due to regex-based HTML replacement295213d
chore(*): clean up package.json
and CircleCI configa31c207
chore(docs-app): remove document.write()
from docs index.html
2518966
fix(grunt-utils): insert the core CSS styles without using innerHTML7de25c8
chore(ci): ensure that deployment files are ready for deploymentThis version was pushed to npm by petebacondarwin, a new releaser for angular since your current version.
7a0a850
3.5.08570a08
Release: Update AUTHORS.txtda3dd85
Ajax: Do not execute scripts for unsuccessful HTTP responses065143c
Ajax: Overwrite s.contentType with content-type header value, if any1a4f10d
Tests: Blacklist one focusin test in IE9e15d6b
Event: Use only one focusin/out handler per matching window & document966a709
Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9
Manipulation: Make jQuery.htmlPrefilter an identity function04bf577
Selector: Update Sizzle from 2.3.4 to 2.3.57506c9c
Build: Resolve Travis config warningsThis version was pushed to npm by mgol, a new releaser for jquery since your current version.
Sourced from https-proxy-agent's releases.
2.2.4
Patches
- Add
.editorconfig
file: a0d4a20458498fc31e5721471bd2b655e992d44b- Add
.eslintrc.js
file: eecea74a1db1c943eaa4f667a561fd47c33da897- Use a
net.Socket
instead of a plainEventEmitter
for replaying proxy errors: #83- Remove unused
stream
module: 9fdcd47bd813e9979ee57920c69e2ee2e0683cd4Credits
Huge thanks to @lpinca for helping!
2.2.3
Patches
- Update README with actual
secureProxy
behavior: #65- Update
proxy
to v1.0.0: d0e3c18079119057b05582cb72d4fda21dfc2546- Remove unreachable code: 46aad0988b471f042856436cf3192b0e09e36fe6
- Test on Node.js 10 and 12: 3535951e482ea52af4888938f59649ed92e81b2b
- Fix compatibility with Node.js >= 10.0.0: #73
- Use an
EventEmitter
to replay failed proxy connect HTTP requests: #77Credits
Huge thanks to @stoically, @lpinca, and @zkochan for helping!
2.2.2
Patches
- Remove
package-lock.json
: c881009b9873707f5c4a0e9c277dde588e1139c7- Ignore test directory, History.md and .travis.yml when creating npm package. Fixes #42: #45
- Update
agent-base
to v4.2: #50- Add TypeScript type definitions: #66
- Feat(typescript): Allow input to be options or string: #68
- Update
agent-base
to v4.3: #69Credits
Huge thanks to @marco-c, @tareqhs, @ianhowe76, and @BYK for helping!
4c4cce8
2.2.49fdcd47
Remove unused stream
module34ea884
Use a net.Socket
instead of a plain EventEmitter
for replaying proxy erro...4296770
Prettiereecea74
Add .eslintrc.js
filea0d4a20
Add .editorconfig
file0d8e8bf
2.2.3850b835
Revert "Use Mocha 5 for Node 4 support"f5f56fa
Remove Node 4 from Travisbb837b9
Revert "Remove Node 4 from Travis"Sourced from node-sass's releases.
v4.14.1
Community
Fixes
Supported Environments
OS Architecture Node Windows x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 OSX x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 Linux* x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8**, 9**, 10**^, 11**^, 12**^, 13**^, 14**^ Alpine Linux x64 6, 8, 10, 11, 12, 13, 14 FreeBSD i386 amd64 10, 12, 13 *Linux support refers to Ubuntu, Debian, and CentOS 5+ ** Not available on CentOS 5 ^ Only available on x64
v4.14.0
Features
Fixes
Supported Environments
OS Architecture Node Windows x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 OSX x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 Linux* x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8**, 9**, 10**^, 11**^, 12**^, 13**^, 14**^ Alpine Linux x64 6, 8, 10, 11, 12, 13, 14 FreeBSD i386 amd64 10, 12, 13 *Linux support refers to Ubuntu, Debian, and CentOS 5+ ** Not available on CentOS 5 ^ Only available on x64
v4.13.1
Community
- Fix render example syntax (@ZoranPandovski , #2787)
Sourced from node-sass's changelog.
v4.14.0
https://github.com/sass/node-sass/releases/tag/v4.14.0
v4.13.1
0d6c3cc
4.14.11cc6263
Bump sass-graph@2.2.5 (#2915)aa193f6
chore: Add GitHub Actions for Alpine CIeac343c
4.14.0bbeb78c
Update changelog1210aab
Fix #2621: Report libsass version 3.5.5 (#2769)5a4a48a
feat: Add Node 14 supportb54053a
Update changelog01db051
4.13.1338fd7a
Merge pull request from GHSA-f6rp-gv58-9cw3d7fbc52
Bump to v4.17.192e1c0f2
Add npm-package1b6c282
Bump to v4.17.18a370ac8
Bump to v4.17.171144918
Rebuild lodash and docs3a3b0fd
Bump to v4.17.16c84fe82
fix(zipObjectDeep): prototype pollution (#4759)e7b28ea
Sanitize sourceURL so it cannot affect evaled code (#4518)0cec225
Fix lodash.isEqual for circular references (#4320) (#4515)94c3a81
Document matches* shorthands for over* methods (#4510) (#4514)This version was pushed to npm by mathias, a new releaser for lodash since your current version.
Sourced from angular's changelog.
1.8.0 nested-vaccination (2020-06-01)
This release contains a breaking change to resolve a security issue which was discovered by Krzysztof Kotowicz(@koto); and independently by Esben Sparre Andreasen (@esbena) while performing a Variant Analysis of CVE-2020-11022 which itself was found and reported by Masato Kinugawa (@masatokinugawa).
Bug Fixes
- jqLite:
- prevent possible XSS due to regex-based HTML replacement (2df43c)
Breaking Changes
jqLite due to:
- 2df43c: prevent possible XSS due to regex-based HTML replacement
JqLite no longer turns XHTML-like strings like
<div /><span />
to sibling elements<div></div><span></span>
when not in XHTML mode. Instead it will leave them as-is. The browser, in non-XHTML mode, will convert these to:<div><span></span></div>
.This is a security fix to avoid an XSS vulnerability if a new jqLite element is created from a user-controlled HTML string. If you must have this functionality and understand the risk involved then it is posible to restore the original behavior by calling
angular.UNSAFE_restoreLegacyJqLiteXHTMLReplacement();
But you should adjust your code for this change and remove your use of this function as soon as possible.
Note that this only patches jqLite. If you use jQuery 3.5.0 or newer, please read the jQuery 3.5 upgrade guide for more details about the workarounds.
1.7.9 pollution-eradication (2019-11-19)
Bug Fixes
- angular.merge: do not merge proto property (726f49)
(Thanks to the Snyk Security Research Team for identifyng this issue.)- ngStyle: correctly remove old style when new style value is invalid (5edd25, #16860, #16868)
1.7.8 enthusiastic-oblation (2019-03-11)
... (truncated)
e55d352
docs(*): update changelog for 1.8.078ab691
chore(*): prep for 1.8.059b5651
docs(ngRepeat): missing closing backtickc8b7c16
fix(jqLite): improve documentation05cf606
fix(jqLite): apply suggestions from code review2df43c0
fix(jqLite): prevent possible XSS due to regex-based HTML replacement295213d
chore(*): clean up package.json
and CircleCI configa31c207
chore(docs-app): remove document.write()
from docs index.html
2518966
fix(grunt-utils): insert the core CSS styles without using innerHTML7de25c8
chore(ci): ensure that deployment files are ready for deploymentThis version was pushed to npm by petebacondarwin, a new releaser for angular since your current version.
7a0a850
3.5.08570a08
Release: Update AUTHORS.txtda3dd85
Ajax: Do not execute scripts for unsuccessful HTTP responses065143c
Ajax: Overwrite s.contentType with content-type header value, if any1a4f10d
Tests: Blacklist one focusin test in IE9e15d6b
Event: Use only one focusin/out handler per matching window & document966a709
Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9
Manipulation: Make jQuery.htmlPrefilter an identity function04bf577
Selector: Update Sizzle from 2.3.4 to 2.3.57506c9c
Build: Resolve Travis config warningsThis version was pushed to npm by mgol, a new releaser for jquery since your current version.
Sourced from https-proxy-agent's releases.
2.2.4
Patches
- Add
.editorconfig
file: a0d4a20458498fc31e5721471bd2b655e992d44b- Add
.eslintrc.js
file: eecea74a1db1c943eaa4f667a561fd47c33da897- Use a
net.Socket
instead of a plainEventEmitter
for replaying proxy errors: #83- Remove unused
stream
module: 9fdcd47bd813e9979ee57920c69e2ee2e0683cd4Credits
Huge thanks to @lpinca for helping!
2.2.3
Patches
- Update README with actual
secureProxy
behavior: #65- Update
proxy
to v1.0.0: d0e3c18079119057b05582cb72d4fda21dfc2546- Remove unreachable code: 46aad0988b471f042856436cf3192b0e09e36fe6
- Test on Node.js 10 and 12: 3535951e482ea52af4888938f59649ed92e81b2b
- Fix compatibility with Node.js >= 10.0.0: #73
- Use an
EventEmitter
to replay failed proxy connect HTTP requests: #77Credits
Huge thanks to @stoically, @lpinca, and @zkochan for helping!
2.2.2
Patches
- Remove
package-lock.json
: c881009b9873707f5c4a0e9c277dde588e1139c7- Ignore test directory, History.md and .travis.yml when creating npm package. Fixes #42: #45
- Update
agent-base
to v4.2: #50- Add TypeScript type definitions: #66
- Feat(typescript): Allow input to be options or string: #68
- Update
agent-base
to v4.3: #69Credits
Huge thanks to @marco-c, @tareqhs, @ianhowe76, and @BYK for helping!
4c4cce8
2.2.49fdcd47
Remove unused stream
module34ea884
Use a net.Socket
instead of a plain EventEmitter
for replaying proxy erro...4296770
Prettiereecea74
Add .eslintrc.js
filea0d4a20
Add .editorconfig
file0d8e8bf
2.2.3850b835
Revert "Use Mocha 5 for Node 4 support"f5f56fa
Remove Node 4 from Travisbb837b9
Revert "Remove Node 4 from Travis"