Kenneth Kehl
ecbceb3b63
upgrade chokidar and mkdirp
2024-06-19 08:32:17 -07:00
Kenneth Kehl
aa02e65c1f
revert upgrade of gulp
2024-06-18 11:25:05 -07:00
Kenneth Kehl
8f985f2429
update gulp to 5.0.0
2024-06-18 11:17:01 -07:00
Kenneth Kehl
b1624c25dc
more updated
2024-06-18 07:49:20 -07:00
Kenneth Kehl
3674dd4e4d
edit package lock
2024-06-17 15:08:31 -07:00
Kenneth Kehl
9817f9e434
revert gulp
2024-06-17 14:41:31 -07:00
Kenneth Kehl
00ab6f5122
hmm
2024-06-17 14:36:06 -07:00
Kenneth Kehl
5544400212
fix vulnerability
2024-06-17 14:27:59 -07:00
Kenneth Kehl
c491b4152c
initial
2024-06-17 13:55:25 -07:00
Beverly Nguyen
e5a9eed626
installing socketio
2024-06-05 14:56:22 -07:00
Beverly Nguyen
6855a6ebe4
installing chart.js via npm
2024-05-15 15:35:39 -07:00
dependabot[bot]
353383d323
Bump postcss and @uswds/compile
...
Bumps [postcss](https://github.com/postcss/postcss ) to 8.4.31 and updates ancestor dependency [@uswds/compile](https://github.com/uswds/uswds-compile ). These dependencies need to be updated together.
Updates `postcss` from 7.0.39 to 8.4.31
- [Release notes](https://github.com/postcss/postcss/releases )
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/postcss/compare/7.0.39...8.4.31 )
Updates `@uswds/compile` from 1.0.0 to 1.1.0
- [Release notes](https://github.com/uswds/uswds-compile/releases )
- [Commits](https://github.com/uswds/uswds-compile/compare/v1.0.0...v1.1.0 )
---
updated-dependencies:
- dependency-name: postcss
dependency-type: indirect
- dependency-name: "@uswds/compile"
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-12-13 17:11:55 +00:00
Jonathan Bobel
7ba937b14a
Updated sass-embedded to see if this fixes the dependency error
2023-11-01 11:14:02 -04:00
Jonathan Bobel
0cc91b43a9
800 - combining and updating the wording around messages remaining
2023-10-31 12:03:21 -04:00
Jonathan Bobel
54eb8df9f7
- Added new flag imagery for favicon and related images
...
- Removed preloaded fonts - legacy UK site stuff
- Added the ability to run pa11y scan with npm run pa11y-ci
2023-09-20 13:52:54 -04:00
Jonathan Bobel
84d436baf2
Adding back in sass-embedded
2023-08-28 16:36:35 -04:00
Jonathan Bobel
42c4670c89
Removing more sass includes to see if this addresses my issue
2023-08-28 16:33:25 -04:00
Jonathan Bobel
8ab550a22f
Radio buttons and list edits
2023-08-25 15:31:44 -04:00
dependabot[bot]
7f522b918c
Bump word-wrap from 1.2.3 to 1.2.4
...
Bumps [word-wrap](https://github.com/jonschlinkert/word-wrap ) from 1.2.3 to 1.2.4.
- [Release notes](https://github.com/jonschlinkert/word-wrap/releases )
- [Commits](https://github.com/jonschlinkert/word-wrap/compare/1.2.3...1.2.4 )
---
updated-dependencies:
- dependency-name: word-wrap
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-07-19 17:06:22 +00:00
dependabot[bot]
b8cc2baddf
Bump tough-cookie from 4.1.2 to 4.1.3 ( #608 )
...
Bumps [tough-cookie](https://github.com/salesforce/tough-cookie ) from 4.1.2 to 4.1.3.
- [Release notes](https://github.com/salesforce/tough-cookie/releases )
- [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md )
- [Commits](https://github.com/salesforce/tough-cookie/compare/v4.1.2...v4.1.3 )
---
updated-dependencies:
- dependency-name: tough-cookie
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-10 13:52:12 -04:00
Jonathan Bobel
eaf3681ae1
Initial USWDS install
2023-04-24 14:57:35 -04:00
dependabot[bot]
4aeb42ceac
Bump json5 from 2.2.1 to 2.2.3
...
Bumps [json5](https://github.com/json5/json5 ) from 2.2.1 to 2.2.3.
- [Release notes](https://github.com/json5/json5/releases )
- [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md )
- [Commits](https://github.com/json5/json5/compare/v2.2.1...v2.2.3 )
---
updated-dependencies:
- dependency-name: json5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-01-06 20:49:11 +00:00
stvnrlly
8a415bc31b
remove leaflet - it was for broadcasts
2022-12-14 13:30:27 -05:00
dependabot[bot]
5787fc1bf5
Bump decode-uri-component from 0.2.0 to 0.2.2
...
Bumps [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component ) from 0.2.0 to 0.2.2.
- [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases )
- [Commits](https://github.com/SamVerschueren/decode-uri-component/compare/v0.2.0...v0.2.2 )
---
updated-dependencies:
- dependency-name: decode-uri-component
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2022-12-08 19:07:22 +00:00
Ryan Ahearn
bb2d57b27b
Update tests to use most recent jest and supporting libraries
2022-10-27 11:12:39 -04:00
Ryan Ahearn
f9cacac204
Update js dependencies
2022-10-26 14:15:49 +00:00
Ben Thorner
b348e8ed03
Add better-npm-audit to check production packages
...
This is the same as [^1].
[^1]: https://github.com/alphagov/document-download-frontend/pull/120
2022-05-09 12:05:42 +01:00
Ben Thorner
da7dd3a852
Fix incorrect group for NPM dependencies
...
This means we can use tools like "npm audit" to look for security
vulnerabilities we definitely need to fix as they could pose a
direct risk to users. I've checked each of them with @tombye and
also against an external set of principles [^1].
Note: I've skimmed through the package-lock.json to check the only
changes are to add "dev: true", as well as a few integrity hashes.
[^1]: https://betterprogramming.pub/is-this-a-dependency-or-a-devdependency-678e04a55a5c
2022-05-06 12:31:10 +01:00
Ben Thorner
b6321ef4ae
Remove unused "del" package
...
This was added in [^1] and later removed in [^2].
[^1]: e1dc6ddaef
[^2]: https://github.com/alphagov/notifications-admin/pull/3198
2022-05-05 14:51:19 +01:00
Richard Baker
5fa324a680
Add package-lock.json file using Node 16 LTS & NPM 8
...
Creates a "v2" package-lock.json file for consistent dependency
installation.
Lock file created using `npm i --package-lock-only`
Signed-off-by: Richard Baker <richard.baker@digital.cabinet-office.gov.uk >
2022-04-05 11:36:33 +01:00
Chris Hill-Scott
c11a15338c
Remove package-lock.json
...
I don’t think we’re getting any benefit from it. Especially since we’re
not running any Node code in production, but just using it to build the
frontend.
The downside is we keep getting these massive diffs which means we don’t
get an accurate line count on pull requests.
Followed instructions here:
https://codeburst.io/disabling-package-lock-json-6be662f5b97d
2017-09-27 12:15:33 +01:00
chrisw
f012ec57c0
Allow user to add multiple reply-to addresses
2017-09-25 17:05:41 +01:00
venusbb
3a1e76ba92
Progress: passed trial_mode to /service end point
2017-09-22 15:46:52 +01:00
Chris Hill Scott
8e19dc194a
Add package-lock.json to version control
...
`package-lock.json` is a file that newer versions of NPM generated
when installing dependencies.
> It describes the exact tree that was generated, such that
> subsequent installs are able to generate identical trees,
> regardless of intermediate dependency updates.
> This file is intended to be committed into source repositories.
– https://docs.npmjs.com/files/package-lock.json
2017-07-03 12:11:24 +01:00