Files
khoa/package-lock.json
dependabot[bot] d2066cf2a5 build(deps): bump content-disposition from 0.5.4 to 1.0.1 (#1917)
Bumps
[content-disposition](https://github.com/jshttp/content-disposition)
from 0.5.4 to 1.0.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jshttp/content-disposition/releases">content-disposition's
releases</a>.</em></p>
<blockquote>
<h2>1.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Remove dependency <code>safe-buffer</code> by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/53">jshttp/content-disposition#53</a></li>
<li>fix: update package.json engines field to reflect minimum supported
node version by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/56">jshttp/content-disposition#56</a></li>
<li>tests: Spelling by <a
href="https://github.com/jsoref"><code>@​jsoref</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/59">jshttp/content-disposition#59</a></li>
<li>chore: upgrade scorecard workflow pinned action versions by <a
href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/65">jshttp/content-disposition#65</a></li>
<li>Fix badges by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/55">jshttp/content-disposition#55</a></li>
<li>ci: updated github actions ci workflow by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/69">jshttp/content-disposition#69</a></li>
<li>Replace var with const in example code by <a
href="https://github.com/Binilkks"><code>@​Binilkks</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/67">jshttp/content-disposition#67</a></li>
<li>replace <code>mocha</code> and <code>nyc</code> with native node
test runner and <code>c8</code> by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/54">jshttp/content-disposition#54</a></li>
<li>ci: add dependabot by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/73">jshttp/content-disposition#73</a></li>
<li>ci: add CodeQl (SAST) by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/71">jshttp/content-disposition#71</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/75">jshttp/content-disposition#75</a></li>
<li>build(deps): bump github/codeql-action from 3.27.9 to 3.28.18 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/80">jshttp/content-disposition#80</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/81">jshttp/content-disposition#81</a></li>
<li>chore: add funding to package.json by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/jshttp/content-disposition/pull/84">jshttp/content-disposition#84</a></li>
<li>build(deps): bump actions/upload-artifact from 4 to 5 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/94">jshttp/content-disposition#94</a></li>
<li>build(deps): bump actions/download-artifact from 4 to 6 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/93">jshttp/content-disposition#93</a></li>
<li>build(deps): bump github/codeql-action from 3.28.18 to 4.31.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/92">jshttp/content-disposition#92</a></li>
<li>Release: 1.0.1 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/58">jshttp/content-disposition#58</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a>
made their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/53">jshttp/content-disposition#53</a></li>
<li><a href="https://github.com/jsoref"><code>@​jsoref</code></a> made
their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/59">jshttp/content-disposition#59</a></li>
<li><a href="https://github.com/Binilkks"><code>@​Binilkks</code></a>
made their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/67">jshttp/content-disposition#67</a></li>
<li><a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
made their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/75">jshttp/content-disposition#75</a></li>
<li><a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
made their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/58">jshttp/content-disposition#58</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/jshttp/content-disposition/compare/v1.0.0...v1.0.1">https://github.com/jshttp/content-disposition/compare/v1.0.0...v1.0.1</a></p>
<h2>1.0.0</h2>
<h2>Breaking Changes</h2>
<ul>
<li>drop support to node &lt;18 versions <a
href="https://redirect.github.com/jshttp/content-disposition/pull/50">jshttp/content-disposition#50</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Fix CI GH action by <a
href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/48">jshttp/content-disposition#48</a></li>
<li>Add OSSF scorecard pipeline by <a
href="https://github.com/carpasse"><code>@​carpasse</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/49">jshttp/content-disposition#49</a></li>
<li>Replace deprecated String.prototype.substr() by <a
href="https://github.com/CommanderRoot"><code>@​CommanderRoot</code></a>
in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/42">jshttp/content-disposition#42</a></li>
<li>fix(ci)!:drop node &lt;18 and update ci by <a
href="https://github.com/wesleytodd"><code>@​wesleytodd</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/50">jshttp/content-disposition#50</a></li>
<li>Support decode 'utf8' (no dash) by <a
href="https://github.com/alexstrat"><code>@​alexstrat</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/13">jshttp/content-disposition#13</a></li>
<li>1.x Staging PR by <a
href="https://github.com/wesleytodd"><code>@​wesleytodd</code></a> in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/51">jshttp/content-disposition#51</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/CommanderRoot"><code>@​CommanderRoot</code></a>
made their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/42">jshttp/content-disposition#42</a></li>
<li><a
href="https://github.com/wesleytodd"><code>@​wesleytodd</code></a> made
their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/50">jshttp/content-disposition#50</a></li>
<li><a href="https://github.com/alexstrat"><code>@​alexstrat</code></a>
made their first contribution in <a
href="https://redirect.github.com/jshttp/content-disposition/pull/13">jshttp/content-disposition#13</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/jshttp/content-disposition/compare/v0.5.4...v1.0.0">https://github.com/jshttp/content-disposition/compare/v0.5.4...v1.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jshttp/content-disposition/blob/master/HISTORY.md">content-disposition's
changelog</a>.</em></p>
<blockquote>
<h1>1.0.1 / 2025-11-18</h1>
<ul>
<li>Updated <code>engines</code> field to Node@18 or higher (fixed
reference, see 1.0.0)</li>
<li>Remove dependency <code>safe-buffer</code></li>
</ul>
<h1>1.0.0 / 2024-08-31</h1>
<ul>
<li>drop node &lt;18</li>
<li>allow utf8 as alias for utf-8</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="b56faefa03"><code>b56faef</code></a>
1.0.1 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/58">#58</a>)</li>
<li><a
href="0839a62f09"><code>0839a62</code></a>
build(deps): bump github/codeql-action from 3.28.18 to 4.31.2 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/92">#92</a>)</li>
<li><a
href="5badd4b7da"><code>5badd4b</code></a>
build(deps): bump actions/download-artifact from 4 to 6 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/93">#93</a>)</li>
<li><a
href="4162dbd398"><code>4162dbd</code></a>
build(deps): bump actions/upload-artifact from 4 to 5 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/94">#94</a>)</li>
<li><a
href="b2ce0fbd8b"><code>b2ce0fb</code></a>
chore: add funding to package.json (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/84">#84</a>)</li>
<li><a
href="f0c058a81d"><code>f0c058a</code></a>
build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/81">#81</a>)</li>
<li><a
href="1f4451c299"><code>1f4451c</code></a>
build(deps): bump github/codeql-action from 3.27.9 to 3.28.18 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/80">#80</a>)</li>
<li><a
href="765ef23860"><code>765ef23</code></a>
build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.1 (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/75">#75</a>)</li>
<li><a
href="21c68cd454"><code>21c68cd</code></a>
ci: add CodeQl (SAST) (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/71">#71</a>)</li>
<li><a
href="8fec68dca4"><code>8fec68d</code></a>
ci: add dependabot (<a
href="https://redirect.github.com/jshttp/content-disposition/issues/73">#73</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/jshttp/content-disposition/compare/v0.5.4...v1.0.1">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~ulisesgascon">ulisesgascon</a>, a new
releaser for content-disposition since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=content-disposition&package-manager=npm_and_yarn&previous-version=0.5.4&new-version=1.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

You can trigger a rebase of this PR by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-04 00:10:11 +01:00

181 KiB