01f2752fcb
Finish version bump
2026-01-22 13:25:04 +01:00
Janis Hutz
89d7ca4379
Merge pull request #55 from janishutz/dependabot/npm_and_yarn/src/webapp/main/multi-a3036e3255
...
Bump tar and pdfjs-dist in /src/webapp/main
2026-01-22 12:23:11 +00:00
dependabot[bot]
aad3f47e41
Bump tar and pdfjs-dist in /src/webapp/main
...
Removes [tar](https://github.com/isaacs/node-tar ). It's no longer used after updating ancestor dependency [pdfjs-dist](https://github.com/mozilla/pdf.js ). These dependencies need to be updated together.
Removes `tar`
Updates `pdfjs-dist` from 4.2.67 to 4.10.38
- [Release notes](https://github.com/mozilla/pdf.js/releases )
- [Commits](https://github.com/mozilla/pdf.js/compare/v4.2.67...v4.10.38 )
---
updated-dependencies:
- dependency-name: tar
dependency-version:
dependency-type: indirect
- dependency-name: pdfjs-dist
dependency-version: 4.10.38
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-22 12:23:05 +00:00
Janis Hutz
ad2a86c3ab
Merge pull request #54 from janishutz/dependabot/npm_and_yarn/src/webapp/setup/lodash-4.17.23
...
Bump lodash from 4.17.21 to 4.17.23 in /src/webapp/setup
2026-01-22 12:22:55 +00:00
Janis Hutz
fa104cc100
Merge pull request #53 from janishutz/dependabot/npm_and_yarn/src/server/lodash-es-4.17.23
...
Bump lodash-es from 4.17.21 to 4.17.23 in /src/server
2026-01-22 12:22:43 +00:00
dependabot[bot]
04db517ff1
Bump lodash from 4.17.21 to 4.17.23 in /src/webapp/setup
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-22 12:22:14 +00:00
dependabot[bot]
20f841367b
Bump lodash-es from 4.17.21 to 4.17.23 in /src/server
...
Bumps [lodash-es](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash-es
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-22 12:22:11 +00:00
Janis Hutz
707091be2b
Merge pull request #52 from janishutz/dependabot/npm_and_yarn/src/webapp/main/lodash-es-4.17.23
...
Bump lodash-es from 4.17.21 to 4.17.23 in /src/webapp/main
2026-01-22 12:20:57 +00:00
Janis Hutz
e15ed09735
Merge pull request #51 from janishutz/dependabot/npm_and_yarn/src/server/multi-516376c24b
...
Bump tar and bcrypt in /src/server
2026-01-22 12:20:40 +00:00
Janis Hutz
e67fac0436
Merge pull request #50 from janishutz/dependabot/npm_and_yarn/src/server/multi-6d05d0e569
...
Bump qs, body-parser and express in /src/server
2026-01-22 12:20:28 +00:00
Janis Hutz
28ebd7da97
Merge pull request #49 from janishutz/dependabot/npm_and_yarn/src/server/nodemailer-7.0.11
...
Bump nodemailer from 7.0.10 to 7.0.11 in /src/server
2026-01-22 12:20:11 +00:00
f7ea972264
Prepare version bump
2026-01-22 13:19:31 +01:00
28acb2070c
[Android] Update app
2026-01-22 13:08:38 +01:00
dependabot[bot]
000339add6
Bump lodash-es from 4.17.21 to 4.17.23 in /src/webapp/main
...
Bumps [lodash-es](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash-es
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-21 23:39:30 +00:00
dependabot[bot]
2895709c73
Bump tar and bcrypt in /src/server
...
Removes [tar](https://github.com/isaacs/node-tar ). It's no longer used after updating ancestor dependency [bcrypt](https://github.com/kelektiv/node.bcrypt.js ). These dependencies need to be updated together.
Removes `tar`
Updates `bcrypt` from 5.1.1 to 6.0.0
- [Release notes](https://github.com/kelektiv/node.bcrypt.js/releases )
- [Changelog](https://github.com/kelektiv/node.bcrypt.js/blob/master/CHANGELOG.md )
- [Commits](https://github.com/kelektiv/node.bcrypt.js/compare/v5.1.1...v6.0.0 )
---
updated-dependencies:
- dependency-name: tar
dependency-version:
dependency-type: indirect
- dependency-name: bcrypt
dependency-version: 6.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-16 21:36:26 +00:00
dependabot[bot]
cda7769398
Bump qs, body-parser and express in /src/server
...
Bumps [qs](https://github.com/ljharb/qs ), [body-parser](https://github.com/expressjs/body-parser ) and [express](https://github.com/expressjs/express ). These dependencies needed to be updated together.
Updates `qs` from 6.14.0 to 6.14.1
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md )
- [Commits](https://github.com/ljharb/qs/compare/v6.14.0...v6.14.1 )
Updates `body-parser` from 1.20.3 to 1.20.4
- [Release notes](https://github.com/expressjs/body-parser/releases )
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md )
- [Commits](https://github.com/expressjs/body-parser/compare/1.20.3...1.20.4 )
Updates `express` from 4.21.2 to 4.22.1
- [Release notes](https://github.com/expressjs/express/releases )
- [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md )
- [Commits](https://github.com/expressjs/express/compare/4.21.2...v4.22.1 )
---
updated-dependencies:
- dependency-name: qs
dependency-version: 6.14.1
dependency-type: direct:production
- dependency-name: body-parser
dependency-version: 1.20.4
dependency-type: direct:production
- dependency-name: express
dependency-version: 4.22.1
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-01 13:53:43 +00:00
dependabot[bot]
19ecd7b1db
Bump nodemailer from 7.0.10 to 7.0.11 in /src/server
...
Bumps [nodemailer](https://github.com/nodemailer/nodemailer ) from 7.0.10 to 7.0.11.
- [Release notes](https://github.com/nodemailer/nodemailer/releases )
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodemailer/nodemailer/compare/v7.0.10...v7.0.11 )
---
updated-dependencies:
- dependency-name: nodemailer
dependency-version: 7.0.11
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-02 03:47:08 +00:00
0219e718dc
Finish version bump & security fixes
2025-11-19 15:25:18 +01:00
02a8325117
Finish version bump & security fixes
2025-09-28 09:06:51 +02:00
19782f0bc3
Finish version bump
2025-07-22 10:22:42 +02:00
0460c25e75
Version bump
2025-07-22 10:21:48 +02:00
b04bb8cd98
Update deps
2025-07-22 10:20:24 +02:00
Janis Hutz
503b376e1c
Merge pull request #41 from janishutz/dependabot/npm_and_yarn/src/server/form-data-4.0.4
...
Bump form-data from 4.0.2 to 4.0.4 in /src/server
2025-07-22 08:17:29 +00:00
Janis Hutz
1d1b6376de
Merge pull request #40 from janishutz/dependabot/npm_and_yarn/src/server/multi-0acb442647
...
Bump on-headers and express-session in /src/server
2025-07-22 08:17:20 +00:00
Janis Hutz
7a9ee5f34d
Merge pull request #39 from janishutz/dependabot/npm_and_yarn/src/server/multer-2.0.2
...
Bump multer from 2.0.1 to 2.0.2 in /src/server
2025-07-22 08:17:09 +00:00
dependabot[bot]
c86fd9283f
Bump form-data from 4.0.2 to 4.0.4 in /src/server
...
---
updated-dependencies:
- dependency-name: form-data
dependency-version: 4.0.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-22 05:08:45 +00:00
dependabot[bot]
be89d84dfd
Bump on-headers and express-session in /src/server
...
---
updated-dependencies:
- dependency-name: on-headers
dependency-version: 1.1.0
dependency-type: indirect
- dependency-name: express-session
dependency-version: 1.18.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-18 05:32:23 +00:00
dependabot[bot]
80b2210b57
Bump multer from 2.0.1 to 2.0.2 in /src/server
...
Bumps [multer](https://github.com/expressjs/multer ) from 2.0.1 to 2.0.2.
- [Release notes](https://github.com/expressjs/multer/releases )
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/expressjs/multer/compare/v2.0.1...v2.0.2 )
---
updated-dependencies:
- dependency-name: multer
dependency-version: 2.0.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-18 01:21:08 +00:00
208c657bf4
V1.1.12 Version Bump (high severity security fix for express)
2025-06-05 10:16:03 +02:00
Janis Hutz
4bac130bb4
Merge pull request #38 from janishutz/dependabot/npm_and_yarn/src/server/multer-2.0.1
2025-06-05 05:51:26 +00:00
dependabot[bot]
218fa641b5
Bump multer from 2.0.0 to 2.0.1 in /src/server
...
Bumps [multer](https://github.com/expressjs/multer ) from 2.0.0 to 2.0.1.
- [Release notes](https://github.com/expressjs/multer/releases )
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/expressjs/multer/compare/v2.0.0...v2.0.1 )
---
updated-dependencies:
- dependency-name: multer
dependency-version: 2.0.1
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-05 05:09:29 +00:00
Janis Hutz
7426d6ac31
Merge pull request #37 from janishutz/dependabot/npm_and_yarn/src/server/multer-2.0.0
...
Bump multer from 1.4.5-lts.2 to 2.0.0 in /src/server
2025-06-04 07:02:00 +00:00
dependabot[bot]
706b3b7cc4
Bump multer from 1.4.5-lts.2 to 2.0.0 in /src/server
...
Bumps [multer](https://github.com/expressjs/multer ) from 1.4.5-lts.2 to 2.0.0.
- [Release notes](https://github.com/expressjs/multer/releases )
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/expressjs/multer/compare/v1.4.5-lts.2...v2.0.0 )
---
updated-dependencies:
- dependency-name: multer
dependency-version: 2.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-04 06:58:37 +00:00