[Snyk] Upgrade npm from 6.4.1 to 6.13.0 #7
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade npm from 6.4.1 to 6.13.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.The recommended version fixes:
Release notes
6.13.0 (2019-11-05)
NEW FEATURES
4414b06d9#273 add fund command (@ruyadorno)DOCUMENTATION
ae4c74d04#274 migrate existing docs to gatsby (@claudiahdz)4ff1bb180#277 updated documentation copy (@oletizi)BUG FIXES
e4455409f#281 delete ps1 files on package removal (@NoDocCat)cd14d4701#279 update supported node list to remove v6.0, v6.1, v9.0 - v9.2 (@ljharb)DEPENDENCIES
a37296b20pacote@9.5.9d3cb3abe8read-cmd-shim@1.0.5TESTING
688cd97be#272 use github actions for CI (@JasonEtco)9a2d8af84#240 Clean up some flakiness and inconsistency (@isaacs)6.12.1 (2019-10-29)
BUG FIXES
6508e833d#269 add node v13 as a supported version (@ljharb)b6588a8f7#265 Fix regression in lockfile repair for sub-deps (@feelepxyz)d5dfe57a1#266 resolve circular dependency in pack.js (@addaleax)DEPENDENCIES
73678bb59chownr@1.1.34b76926e2graceful-fs@4.2.3c691f36a9libcipm@4.0.75e1a14975npm-packlist@1.4.6c194482d6npm-registry-fetch@4.0.2bc6a8e0ectar@4.4.14dcca3cbbuuid@3.3.36.12.0 (2019-10-08):
Now
npm ciruns prepare scripts for git dependencies, and respects the--no-optionalargument. Warnings forenginemismatches are printed again. Various other fixes and cleanups.BUG FIXES
890b245dc#252 ci: add dirPacker to options (@claudiahdz)f3299acd0#257 npm.community#4792 warn message on engine mismatch (@ruyadorno)bbc92fb8f#259 npm.community#10288 Fix figgyPudding error innpm token(@benblank)70f54dcb5#241 doctor: Make OK more consistent (@gemal)FEATURES
ed993a29c#249 Add CI environment variables to user-agent (@isaacs)f6b0459a4#248 Add option to save package-lock without formatting Adds a new config--format-package-lock, which defaults to true. (@bl00mber)DEPENDENCIES
0ca063c5dnpm-lifecycle@3.1.4:5df6b0ea2libcipm@4.0.4:7e04f728ctar@4.4.125c380e5a3stringify-package@1.0.1(@isaacs)62f2ca692node-gyp@5.0.5(@isaacs)0ff0ea47anpm-install-checks@3.0.2(@isaacs)f46edae94hosted-git-info@2.8.5(@isaacs)TESTING
44a2b036b#262 fix root-ownership race conditions in meta-test (@isaacs)Now
npm ciruns prepare scripts for git dependencies, and respects the--no-optionalargument.BUG FIXES
890b245dc#252 chore(ci): add dirPacker to options (@claudiahdz)DEPENDENCIES
0ca063c5dnpm-lifecycle@3.1.4:5df6b0ea2libcipm@4.0.4:7e04f728ctar@4.4.126.11.3 (2019-09-03):
Fix npm ci regressions and npm outdated depth.
BUG FIXES
235ed1d28#239 Don't override user specified depth in outdated. Restores ability to update packages using--depthas suggested bynpm audit. (@G-Rath)1fafb5151#242 npm.community#9586 Revert "install: do not descend into directory deps' child modules" (@isaacs)cebf542e6#243 npm.community#9720 ci: pass appropriate configs for file/dir modes (@isaacs)DEPENDENCIES
e5fbb7ed1read-cmd-shim@1.0.4(@claudiahdz)23ce65616npm-pick-manifest@3.0.2(@claudiahdz)6.11.2 (2019-08-22):
Fix a recent Windows regression, and two long-standing Windows bugs. Also, get CI running on Windows, so these things are less likely in the future.
DEPENDENCIES
9778a1b87cmd-shim@3.0.3: Fix regression where shims fail to preserve exit code (@isaacs)bf93e91d8npm-package-arg@6.1.1: Properly handle git+file: urls on Windows when a drive letter is included. (@isaacs)BUGFIXES
6cc4cc66fescape args properly on Windows Bash Despite being bash, Node.js running on windows git mingw bash still executes child processes using cmd.exe. As a result, arguments in this environment need to be escaped in the style of cmd.exe, not bash. (@isaacs)TESTS
291aba7b8make tests pass on Windows (@isaacs)fea3a023atravis: run tests on Windows as well (@isaacs)6.11.1 (2019-08-20):
Fix a regression for windows command shim syntax.
37db29647cmd-shim@3.0.2(@isaacs)v6.11.0 (2019-08-20):
A few meaty bugfixes, and introducing
peerDependenciesMeta.FEATURES
a12341088#224 Implements peerDependenciesMeta (@arcanis)2f3b79bba#234 add new forbidden 403 error code (@claudiahdz)BUGFIXES
24acc9fc8and45772af0d#217 npm.community#8863 npm.community#9327 do not descend into directory deps' child modules, fix shrinkwrap files that inappropriately list child nodes of symlink packages (@isaacs and @salomvary)50cfe113d#229 fixed typo in semver doc (@gall0ws)e8fb2a1bd#231 Fix spelling mistakes in CHANGELOG-3.md (@XhmikosR)769d2e057npm/uid-number#7 Better error on invalid--user/--groupconfigs. This addresses the issue when people fail to install binary packages on Docker and other environments where there is no 'nobody' user. (@isaacs)8b43c9624nodejs/node#28987 npm.community#6032 npm.community#6658 npm.community#6069 npm.community#9323 Fix the regression where random config values in a .npmrc file are not passed to lifecycle scripts, breaking build processes which rely on them. (@isaacs)8b85eaa47save files with inferred ownership rather than relying onSUDO_UIDandSUDO_GID. (@isaacs)b7f6e5f02Infer ownership of shrinkwrap files (@isaacs)54b095d77#235 Add spec to dist-tag remove function (@theberbie)DEPENDENCIES
dc8f9e52fpacote@9.5.7: Infer the ownership of all unpacked files innode_modules, so that we never have user-owned files in root-owned folders, or root-owned files in user-owned folders. (@isaacs)bb33940c3cmd-shim@3.0.0:9c93ac3#2 npm#3380 Handle environment variables properly (@basbossink)2d277f8#25 #36 #35 Fix 'no shebang' case by always providing$basedirin shell script (@igorklopov)adaf20b#26 Fix$*causing an error when arguments contain parentheses (@satazor)49f0c13#30 Fix paths for MSYS/MINGW bash (@dscho)51a8af3#34 Add proper support for PowerShell (@ExE-Boss)4c37e04#10 Work around quoted batch file names (@isaacs)a4e279544npm-lifecycle@3.1.3(@isaacs):uid-numberraises an error7086a1809libcipm@4.0.3(@isaacs)8845141f9read-package-json@2.1.0(@isaacs)51c028215bin-links@1.1.3(@isaacs)534a5548cread-cmd-shim@1.0.3(@isaacs)3038f2fd5gentle-fs@2.2.1(@isaacs)a609a1648graceful-fs@4.2.2(@isaacs)f0346f754cacache@12.0.3(@isaacs)ca9c615c8npm-pick-manifest@3.0.0(@isaacs)b417affbfpacote@9.5.8(@isaacs)TESTS
b6df0913c#228 Proper handing of /usr/bin/node lifecycle-path test (@olivr70)aaf98e88cnpm-registry-mock@1.3.0(@isaacs)v6.10.3 (2019-08-06):
BUGFIXES
27cccfbda#223 vulns → vulnerabilities in npm audit output (@sapegin)d5e865eb7#222 #226 install, doctor: don't crash if registry unset (@dmitrydvorkin, @isaacs)5b3890226#227 npm.community#9167 Handle unhandledRejections, tell user what to do when encountering anEACCESerror in the cache. (@isaacs)DEPENDENCIES
77516df6elicensee@7.0.3(@isaacs)ceb993590query-string@6.8.2(@isaacs)4050b9189hosted-git-info@2.8.23b1d629#48 fix http protocol using sshurl by default (@fengmk2)5d4a8d7ignore noCommittish on tarball url generation (@isaacs)1692435use gist tarball url that works for anonymous gists (@isaacs)d5cf830Do not allow invalid gist urls (@isaacs)e518222Use LRU cache to prevent unbounded memory consumption (@iarna)v6.10.2 (2019-07-23):
tl;dr - Fixes several issues with the cache when npm is run as
sudoon Unix systems.TESTING
2a78b96f8check test cache for root-owned files (@isaacs)108646ebcrun sudo tests on Travis-CI (@isaacs)cf984e946set --no-esm tap flag (@isaacs)8e0a3100dadd script to run tests and leave fixtures for inspection and debugging (@isaacs)BUGFIXES
25f4f73f6add a util for writing arbitrary files to cache This prevents metrics timing and debug logs from becoming root-owned. (@isaacs)2c61ce65dinfer cache owner from parent dir incorrect-mkdirutil (@isaacs)235e5d6dfensure correct owner on cached all-packages metadata (@isaacs)e2d377bb6npm.community#8540 audit: report server error on failure (@isaacs)52576a39e#216 npm.community#5385 npm.community#6076 Fixnpm ciwithfile:dependencies. Partially reverts #40/#86, recording dependencies of linked deps in order fornpm cito work. (@jfirebaugh)DEPENDENCIES
0fefdee13cacache@12.0.2(@isaacs)e1d87a392pacote@9.5.4(@isaacs)3f035bf09infer-owner@1.0.4(@isaacs)ba3283112npm-registry-fetch@4.0.0(@isaacs)ee90c334dlibnpm@3.0.1(@isaacs)1e480c384libnpmaccess@3.0.2(@isaacs)7662ee850libnpmhook@5.0.3(@isaacs)1357fadc6libnpmorg@1.0.1(@isaacs)a621b5cb6libnpmsearch@2.0.2(@isaacs)560cd31ddlibnpmteam@1.0.2(@isaacs)de7ae0867npm-profile@4.0.2(@isaacs)e95da463clibnpm@3.0.1(@isaacs)554b641d4npm-registry-fetch@4.0.0(@isaacs)06772f34anode-gyp@5.0.3(@isaacs)85358db80npm-lifecycle@3.1.2(@isaacs)051cf20#26 fix switches for alternative shells on Windows (@gucong3000)3aaf954#25 set only one PATH env variable for child process on Windows (@zkochan)ea18ed2#36 #11 #18 remove procInterrupt listener on SIGINT in procError (@mattshin)5523951#29 #30 Use platform specific path casing if present (@mattezell)Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs