Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump react-editable-json-tree from 2.2.1 to 2.2.2 #535

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 18, 2022

Bumps react-editable-json-tree from 2.2.1 to 2.2.2.

Release notes

Sourced from react-editable-json-tree's releases.

2.2.2

Fix

  • Add allowFunctionEvaluation prop to mitigate a security vulnerability
  • Use Function instead of eval for function evaluation

Thanks

Special thanks to @​Phanabani for this release

Changelog

Sourced from react-editable-json-tree's changelog.

2.2.2

Fix

  • Add allowFunctionEvaluation prop to mitigate a security vulnerability
  • Use Function instead of eval for function evaluation

2.2.0

Feature

  • Issue #7 (Thanks to Hawkpath for the idea) : inputElement and textareaElement can be a function that return dynamically element.
  • Raw value from input and textarea element can be now parsed by an external function

2.1.0

Fix

  • Issue #6 : Forgot to change code in "update array" when switch to promise

Feature

  • Add a way to give logger to component to log "catch" promise error

2.0.0

Code

  • Various change to support React V16

1.7.0

Code

  • Add data in isCollapsed function

1.6.0

Code

  • Read only with function now

1.5.0

Fix

  • Fix ESLint errors and warning
  • Demo works with IE

Code

  • Update webpack configurations
  • Update Travis CI and Circle CI configuration

Feature

  • Add "before action" on Remove, Update and Add action

1.4.0

Fix

  • Fix variable name in add part
  • Ignore circle.yml in npmignore

Code

  • Update scripts for npm
  • Downgrade eslint plugin version (not working)

... (truncated)

Commits
  • a84cb91 Release 2.2.2
  • c50bfff Merge pull request from GHSA-j3rv-w43q-f9x2
  • 9ace906 Move allowFunctionEvaluation's description into the Fix section.
  • 69226bb Add Phanabani as a contributor.
  • 2532f6e Bump patch version to 2.2.2.
  • 4027075 Add changelog entry for 2.2.2.
  • 0aa3bdf Add warning emoji to security advisory.
  • 828b6c2 Add security advisory details at the top of the readme.
  • 52ff87e Add allowFunctionEvaluation prop description.
  • 961ab09 Add allowFunctionEvaluation prop.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [react-editable-json-tree](https://github.com/oxyno-zeta/react-editable-json-tree) from 2.2.1 to 2.2.2.
- [Release notes](https://github.com/oxyno-zeta/react-editable-json-tree/releases)
- [Changelog](https://github.com/oxyno-zeta/react-editable-json-tree/blob/master/CHANGELOG.md)
- [Commits](oxyno-zeta/react-editable-json-tree@2.2.1...2.2.2)

---
updated-dependencies:
- dependency-name: react-editable-json-tree
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Aug 18, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants