From 08c920cd8f73a6f1180de27a03ae7e78cfaad8a1 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 5 Oct 2024 01:40:40 +0000 Subject: [PATCH] Bump helmet from 7.1.0 to 8.0.0 Bumps [helmet](https://github.com/helmetjs/helmet) from 7.1.0 to 8.0.0. - [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md) - [Commits](https://github.com/helmetjs/helmet/compare/v7.1.0...v8.0.0) --- updated-dependencies: - dependency-name: helmet dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index 555b0244..63ef0c83 100644 --- a/package.json +++ b/package.json @@ -52,7 +52,7 @@ "feathers-hooks-common": "^6.1.5", "feathers-permissions": "^2.1.4", "feathers-sequelize": "^6.4.0", - "helmet": "^7.1.0", + "helmet": "^8.0.0", "pg": "^8.13.0", "sequelize": "^6.37.3", "serve-favicon": "^2.5.0", diff --git a/yarn.lock b/yarn.lock index 40d908d2..43ffdbc1 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3042,10 +3042,10 @@ hasown@^2.0.0: dependencies: function-bind "^1.1.2" -helmet@^7.1.0: - version "7.1.0" - resolved "https://registry.yarnpkg.com/helmet/-/helmet-7.1.0.tgz#287279e00f8a3763d5dccbaf1e5ee39b8c3784ca" - integrity sha512-g+HZqgfbpXdCkme/Cd/mZkV0aV3BZZZSugecH03kl38m/Kmdx8jKjBikpDj2cr+Iynv4KpYEviojNdTJActJAg== +helmet@^8.0.0: + version "8.0.0" + resolved "https://registry.yarnpkg.com/helmet/-/helmet-8.0.0.tgz#05370fb1953aa7b81bd0ddfa459221247be6ea5c" + integrity sha512-VyusHLEIIO5mjQPUI1wpOAEu+wl6Q0998jzTxqUYGE45xCIcAxy3MsbEK/yyJUJ3ADeMoB6MornPH6GMWAf+Pw== html-escaper@^2.0.0: version "2.0.2"