dependabot[bot] opened a new pull request, #1681:
URL: https://github.com/apache/airflow-site/pull/1681

   Bumps the npm-security group with 5 updates in the /landing-pages directory:
   
   | Package | From | To |
   | --- | --- | --- |
   | [brace-expansion](https://github.com/juliangruber/brace-expansion) | 
`1.1.18` | `1.1.21` |
   | [compression](https://github.com/expressjs/compression) | `1.8.1` | 
`1.8.2` |
   | [proxy-addr](https://github.com/jshttp/proxy-addr) | `2.0.7` | `2.0.8` |
   | [shell-quote](https://github.com/ljharb/shell-quote) | `1.10.0` | `1.12.0` 
|
   | [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | 
`1.2.2` |
   
   
   Updates `brace-expansion` from 1.1.18 to 1.1.21
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/juliangruber/brace-expansion/commit/8e81e187b6e9c6c723d16c042657c00acefc2483";><code>8e81e18</code></a>
 1.1.21</li>
   <li><a 
href="https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e";><code>ffdfa3e</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/juliangruber/brace-expansion/commit/c6513ad31e08edb56dc414a629e39cba724b7548";><code>c6513ad</code></a>
 1.1.20</li>
   <li><a 
href="https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b";><code>1efee7c</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/juliangruber/brace-expansion/commit/a34340a053abb475cc226aeb3f71887018e71bd0";><code>a34340a</code></a>
 1.1.19</li>
   <li><a 
href="https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc";><code>0bcbfc0</code></a>
 Merge commit from fork</li>
   <li>See full diff in <a 
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.18...v1.1.21";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `compression` from 1.8.1 to 1.8.2
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/expressjs/compression/releases";>compression's 
releases</a>.</em></p>
   <blockquote>
   <h2>v1.8.2</h2>
   <h2>Important</h2>
   <ul>
   <li>Fix <a 
href="https://www.cve.org/CVERecord?id=CVE-2026-87776";>CVE-2026-87776</a> (<a 
href="https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95";>GHSA-vc2v-76pw-4v95</a>)</li>
   </ul>
   <h2>What's Changed</h2>
   <ul>
   <li>chore: add funding to package.json by <a 
href="https://github.com/bjohansebas";><code>@​bjohansebas</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/248";>expressjs/compression#248</a></li>
   <li>build(deps): bump github/codeql-action from 3.29.2 to 3.29.5 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/249";>expressjs/compression#249</a></li>
   <li>build(deps): bump actions/checkout from 4.2.2 to 5.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/253";>expressjs/compression#253</a></li>
   <li>build(deps): bump github/codeql-action from 3.29.7 to 3.29.11 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/252";>expressjs/compression#252</a></li>
   <li>build(deps): bump actions/download-artifact from 4.3.0 to 5.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/251";>expressjs/compression#251</a></li>
   <li>build(deps): bump actions/setup-node from 4.4.0 to 6.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/261";>expressjs/compression#261</a></li>
   <li>build(deps): bump github/codeql-action from 3.29.11 to 4.31.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/260";>expressjs/compression#260</a></li>
   <li>build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/259";>expressjs/compression#259</a></li>
   <li>build(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/258";>expressjs/compression#258</a></li>
   <li>build(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/264";>expressjs/compression#264</a></li>
   <li>build(deps): bump actions/checkout from 5.0.0 to 6.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/263";>expressjs/compression#263</a></li>
   <li>build(deps): bump github/codeql-action from 4.31.2 to 4.31.5 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/262";>expressjs/compression#262</a></li>
   <li>chore: up node version to 25.x in CI by <a 
href="https://github.com/imangas";><code>@​imangas</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/272";>expressjs/compression#272</a></li>
   <li>doc(package): remove history.md and add readme.md to published files by 
<a href="https://github.com/sheplu";><code>@​sheplu</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/270";>expressjs/compression#270</a></li>
   <li>Update link to CONTRIBUTING.md by <a 
href="https://github.com/krzysdz";><code>@​krzysdz</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/281";>expressjs/compression#281</a></li>
   <li>test: run CI on Windows and macOS by <a 
href="https://github.com/kilisamemarisaaa";><code>@​kilisamemarisaaa</code></a> 
in <a 
href="https://redirect.github.com/expressjs/compression/pull/283";>expressjs/compression#283</a></li>
   <li>build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/257";>expressjs/compression#257</a></li>
   <li>build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/268";>expressjs/compression#268</a></li>
   <li>build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/265";>expressjs/compression#265</a></li>
   <li>build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/266";>expressjs/compression#266</a></li>
   <li>build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/expressjs/compression/pull/267";>expressjs/compression#267</a></li>
   <li>chore(ci): npm-publish via reusable workflows by <a 
href="https://github.com/sheplu";><code>@​sheplu</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/269";>expressjs/compression#269</a></li>
   <li>docs: update outdated Brotli note and fix npm install docs URL by <a 
href="https://github.com/Vansh1811";><code>@​Vansh1811</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/276";>expressjs/compression#276</a></li>
   <li>fix: match Cache-Control no-transform directive case-insensitively by <a 
href="https://github.com/vaibhavmashal";><code>@​vaibhavmashal</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/286";>expressjs/compression#286</a></li>
   <li>1.8.2 by <a 
href="https://github.com/UlisesGascon";><code>@​UlisesGascon</code></a> in <a 
href="https://redirect.github.com/expressjs/compression/pull/287";>expressjs/compression#287</a></li>
   </ul>
   <h2>New Contributors</h2>
   <ul>
   <li><a href="https://github.com/imangas";><code>@​imangas</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/expressjs/compression/pull/272";>expressjs/compression#272</a></li>
   <li><a href="https://github.com/sheplu";><code>@​sheplu</code></a> made their 
first contribution in <a 
href="https://redirect.github.com/expressjs/compression/pull/270";>expressjs/compression#270</a></li>
   <li><a href="https://github.com/krzysdz";><code>@​krzysdz</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/expressjs/compression/pull/281";>expressjs/compression#281</a></li>
   <li><a 
href="https://github.com/kilisamemarisaaa";><code>@​kilisamemarisaaa</code></a> 
made their first contribution in <a 
href="https://redirect.github.com/expressjs/compression/pull/283";>expressjs/compression#283</a></li>
   <li><a href="https://github.com/Vansh1811";><code>@​Vansh1811</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/expressjs/compression/pull/276";>expressjs/compression#276</a></li>
   <li><a 
href="https://github.com/vaibhavmashal";><code>@​vaibhavmashal</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/expressjs/compression/pull/286";>expressjs/compression#286</a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2";>https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/expressjs/compression/blob/master/HISTORY.md";>compression's
 changelog</a>.</em></p>
   <blockquote>
   <h1>1.8.2</h1>
   <ul>
   <li>Fix <a 
href="https://www.cve.org/CVERecord?id=CVE-2026-87776";>CVE-2026-87776</a> (<a 
href="https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95";>GHSA-vc2v-76pw-4v95</a>)</li>
   <li>deps: add [email protected]</li>
   <li>Match <code>Cache-Control: no-transform</code> directive 
case-insensitively</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/expressjs/compression/commit/0f9707417bd53d41a319fce8bdb80dfa08b435c8";><code>0f97074</code></a>
 1.8.2 (<a 
href="https://redirect.github.com/expressjs/compression/issues/287";>#287</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff";><code>151f63e</code></a>
 fix: destroy compression stream on response close</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/0a764956691bede2b62c711598ee65ea643d3b1e";><code>0a76495</code></a>
 fix: match Cache-Control no-transform directive case-insensitively (<a 
href="https://redirect.github.com/expressjs/compression/issues/286";>#286</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/c17b6e58ac914c84d9e3a64130dcc428e0e26887";><code>c17b6e5</code></a>
 docs: update outdated Brotli note and fix npm install docs URL (<a 
href="https://redirect.github.com/expressjs/compression/issues/276";>#276</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/112911abc46e0d8fa6c9793ef5005ca1d53ccb7c";><code>112911a</code></a>
 chore(ci): npm-publish via reusable workflows (<a 
href="https://redirect.github.com/expressjs/compression/issues/269";>#269</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/1bf5eb0b5eaf5001af9782ade18c6cca690ccaad";><code>1bf5eb0</code></a>
 build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (<a 
href="https://redirect.github.com/expressjs/compression/issues/267";>#267</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/d8fe64d50081d4a13a8ea5c25a852ca27fde0b7b";><code>d8fe64d</code></a>
 build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (<a 
href="https://redirect.github.com/expressjs/compression/issues/266";>#266</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/b218ff54eb8e211100d8a6697d13cdc73fdb13b3";><code>b218ff5</code></a>
 build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (<a 
href="https://redirect.github.com/expressjs/compression/issues/265";>#265</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/8a1cf8ecf948c28ffd3d29f942c9a310bc36e5c1";><code>8a1cf8e</code></a>
 build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (<a 
href="https://redirect.github.com/expressjs/compression/issues/268";>#268</a>)</li>
   <li><a 
href="https://github.com/expressjs/compression/commit/4a19855442b7ebfcea4f95caf491968108dc15b8";><code>4a19855</code></a>
 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (<a 
href="https://redirect.github.com/expressjs/compression/issues/257";>#257</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2";>compare 
view</a></li>
   </ul>
   </details>
   <details>
   <summary>Maintainer changes</summary>
   <p>This version was pushed to npm by <a 
href="https://www.npmjs.com/~GitHub%20Actions";>GitHub Actions</a>, a new 
releaser for compression since your current version.</p>
   </details>
   <br />
   
   Updates `proxy-addr` from 2.0.7 to 2.0.8
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/jshttp/proxy-addr/releases";>proxy-addr's 
releases</a>.</em></p>
   <blockquote>
   <h2>2.0.8</h2>
   <h2>Important</h2>
   <ul>
   <li>Fix <a 
href="https://www.cve.org/CVERecord?id=CVE-2026-90711";>CVE-2026-90711</a> (<a 
href="https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h";>GHSA-jqcg-44mw-7w3h</a>)</li>
   </ul>
   <h2>What's Changed</h2>
   <ul>
   <li>Add OSSF scorecard action by <a 
href="https://github.com/carpasse";><code>@​carpasse</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/27";>jshttp/proxy-addr#27</a></li>
   <li>Fix ci pipeline and add missing Node.JS versions by <a 
href="https://github.com/carpasse";><code>@​carpasse</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/26";>jshttp/proxy-addr#26</a></li>
   <li>[StepSecurity] Apply security best practices by <a 
href="https://github.com/step-security-bot";><code>@​step-security-bot</code></a>
 in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/29";>jshttp/proxy-addr#29</a></li>
   <li>build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/30";>jshttp/proxy-addr#30</a></li>
   <li>build(deps): bump github/codeql-action from 2.23.2 to 3.28.18 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/31";>jshttp/proxy-addr#31</a></li>
   <li>build(deps-dev): bump eslint-plugin-import from 2.23.4 to 2.31.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/32";>jshttp/proxy-addr#32</a></li>
   <li>build(deps): bump ossf/scorecard-action from 2.0.6 to 2.4.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/33";>jshttp/proxy-addr#33</a></li>
   <li>build(deps): bump actions/upload-artifact from 3.1.3 to 4.6.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/35";>jshttp/proxy-addr#35</a></li>
   <li>build(deps-dev): bump deep-equal from 1.0.1 to 1.1.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/34";>jshttp/proxy-addr#34</a></li>
   <li>build(deps-dev): bump eslint-plugin-markdown from 2.2.0 to 2.2.1 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/36";>jshttp/proxy-addr#36</a></li>
   <li>chore: add funding to package.json by <a 
href="https://github.com/Phillip9587";><code>@​Phillip9587</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/40";>jshttp/proxy-addr#40</a></li>
   <li>build(deps): bump github/codeql-action from 3.28.18 to 3.29.5 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/41";>jshttp/proxy-addr#41</a></li>
   <li>build(deps): bump github/codeql-action from 3.29.7 to 3.29.11 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/43";>jshttp/proxy-addr#43</a></li>
   <li>build(deps): bump actions/checkout from 3.6.0 to 5.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/42";>jshttp/proxy-addr#42</a></li>
   <li>build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/47";>jshttp/proxy-addr#47</a></li>
   <li>build(deps): bump github/codeql-action from 3.29.11 to 4.31.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/46";>jshttp/proxy-addr#46</a></li>
   <li>build(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/50";>jshttp/proxy-addr#50</a></li>
   <li>build(deps): bump github/codeql-action from 4.31.2 to 4.31.5 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/49";>jshttp/proxy-addr#49</a></li>
   <li>build(deps): bump actions/checkout from 5.0.0 to 6.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/48";>jshttp/proxy-addr#48</a></li>
   <li>build(deps): bump actions/checkout from 6.0.0 to 6.0.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/56";>jshttp/proxy-addr#56</a></li>
   <li>build(deps): bump github/codeql-action from 4.31.5 to 4.32.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/55";>jshttp/proxy-addr#55</a></li>
   <li>build(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/57";>jshttp/proxy-addr#57</a></li>
   <li>build(deps): bump actions/upload-artifact from 5.0.0 to 7.0.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/58";>jshttp/proxy-addr#58</a></li>
   <li>Fix &quot;arugment&quot; typo in README by <a 
href="https://github.com/schiwekM";><code>@​schiwekM</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/61";>jshttp/proxy-addr#61</a></li>
   <li>build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/64";>jshttp/proxy-addr#64</a></li>
   <li>build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/63";>jshttp/proxy-addr#63</a></li>
   <li>build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/45";>jshttp/proxy-addr#45</a></li>
   <li>build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/39";>jshttp/proxy-addr#39</a></li>
   <li>chore(ci): npm-publish via reusable workflows by <a 
href="https://github.com/sheplu";><code>@​sheplu</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/54";>jshttp/proxy-addr#54</a></li>
   <li>refresh CI by <a 
href="https://github.com/UlisesGascon";><code>@​UlisesGascon</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/69";>jshttp/proxy-addr#69</a></li>
   <li>fix: typo by <a 
href="https://github.com/UlisesGascon";><code>@​UlisesGascon</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/71";>jshttp/proxy-addr#71</a></li>
   <li>Release: 2.0.8 by <a 
href="https://github.com/UlisesGascon";><code>@​UlisesGascon</code></a> in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/70";>jshttp/proxy-addr#70</a></li>
   </ul>
   <h2>New Contributors</h2>
   <ul>
   <li><a href="https://github.com/carpasse";><code>@​carpasse</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/27";>jshttp/proxy-addr#27</a></li>
   <li><a 
href="https://github.com/step-security-bot";><code>@​step-security-bot</code></a>
 made their first contribution in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/29";>jshttp/proxy-addr#29</a></li>
   <li><a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] made 
their first contribution in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/30";>jshttp/proxy-addr#30</a></li>
   <li><a href="https://github.com/Phillip9587";><code>@​Phillip9587</code></a> 
made their first contribution in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/40";>jshttp/proxy-addr#40</a></li>
   <li><a href="https://github.com/schiwekM";><code>@​schiwekM</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/61";>jshttp/proxy-addr#61</a></li>
   <li><a href="https://github.com/sheplu";><code>@​sheplu</code></a> made their 
first contribution in <a 
href="https://redirect.github.com/jshttp/proxy-addr/pull/54";>jshttp/proxy-addr#54</a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/jshttp/proxy-addr/compare/v2.0.7...v2.0.8";>https://github.com/jshttp/proxy-addr/compare/v2.0.7...v2.0.8</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md";>proxy-addr's 
changelog</a>.</em></p>
   <blockquote>
   <h1>2.0.8</h1>
   <ul>
   <li>Fix <a 
href="https://www.cve.org/CVERecord?id=CVE-2026-90711";>CVE-2026-90711</a> (<a 
href="https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h";>GHSA-jqcg-44mw-7w3h</a>)</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/a11ad82545698af5c33e59f3ed0b52eab79bf610";><code>a11ad82</code></a>
 2.0.8 (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/70";>#70</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/780911d84d18e2c5fa008ed0c0d387631ec11965";><code>780911d</code></a>
 fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/92e103e3f3ab0467c8846cacea71f27dfc81091d";><code>92e103e</code></a>
 fix(ci): use publised as release trigger event (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/71";>#71</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/3e5ac75d275d82606d33d6ac47c0ff43c2eccee9";><code>3e5ac75</code></a>
 ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/69";>#69</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/4b9db8190923840eb732b752a70f3e5ff713768c";><code>4b9db81</code></a>
 chore(ci): npm-publish via workflows (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/54";>#54</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/655e8950435ac457c586e8287da4d5993b7d0db5";><code>655e895</code></a>
 build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/39";>#39</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/50ce4d09132a4c34f5485b52740ce879a9223b1f";><code>50ce4d0</code></a>
 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/45";>#45</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/0fd347f5b342e7502da58a512dc998d4a59cea24";><code>0fd347f</code></a>
 build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/63";>#63</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/6a517fa25c741cc107a90019df458b34f580ce55";><code>6a517fa</code></a>
 build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/64";>#64</a>)</li>
   <li><a 
href="https://github.com/jshttp/proxy-addr/commit/0d45e2a88e82a2faf1148956b6457e3a6c99ebcd";><code>0d45e2a</code></a>
 Fix &quot;arugment&quot; typo in README (<a 
href="https://redirect.github.com/jshttp/proxy-addr/issues/61";>#61</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/jshttp/proxy-addr/compare/v2.0.7...v2.0.8";>compare 
view</a></li>
   </ul>
   </details>
   <details>
   <summary>Maintainer changes</summary>
   <p>This version was pushed to npm by <a 
href="https://www.npmjs.com/~GitHub%20Actions";>GitHub Actions</a>, a new 
releaser for proxy-addr since your current version.</p>
   </details>
   <br />
   
   Updates `shell-quote` from 1.10.0 to 1.12.0
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md";>shell-quote's
 changelog</a>.</em></p>
   <blockquote>
   <h2><a 
href="https://github.com/ljharb/shell-quote/compare/v1.11.0...v1.12.0";>v1.12.0</a>
 - 2026-10-02</h2>
   <h3>Fixed</h3>
   <ul>
   <li>[New] <code>parse</code>: support here-documents 
(<code>&amp;lt;&amp;lt;</code>) <a 
href="https://redirect.github.com/ljharb/shell-quote/issues/31";><code>[#31](https://github.com/ljharb/shell-quote/issues/31)</code></a></li>
   </ul>
   <h3>Commits</h3>
   <ul>
   <li>[New] <code>parse</code>: support tab-stripping here-documents 
(<code>&amp;lt;&amp;lt;-</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/dbfac376d4065d37539d3abdb5e76847f93797d3";><code>dbfac37</code></a></li>
   <li>[New] <code>parse</code>: support output process substitution 
(<code>&amp;gt;(</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/20533154bb57809c80f55318b8493aef49505f4e";><code>2053315</code></a></li>
   <li>[New] <code>parse</code>: support the <code>case</code> test-next 
terminator (<code>;;&amp;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/7d688b9bec1917a22cccd4d4c887128a9c66e8a0";><code>7d688b9</code></a></li>
   <li>[New] <code>parse</code>: support the <code>case</code> fall-through 
terminator (<code>;&amp;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/f27010ed04bcd925795b350afb1c49e36bbd1ba3";><code>f27010e</code></a></li>
   <li>[New] <code>parse</code>: support redirecting output despite 
<code>noclobber</code> (<code>&amp;gt;|</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/b78d19c14da6356cc12c46b3478203247ab8a295";><code>b78d19c</code></a></li>
   <li>[New] <code>parse</code>: support opening a file for reading and writing 
(<code>&amp;lt;&amp;gt;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/21cc333eb0ce5bf094f595b7fdc01b3447ffd4b0";><code>21cc333</code></a></li>
   <li>[New] <code>parse</code>: support redirecting stdout and stderr 
(<code>&amp;&amp;gt;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/6ad6cd215f89adcc29dd601e085fa54083c2f911";><code>6ad6cd2</code></a></li>
   <li>[New] <code>parse</code>: support appending stdout and stderr 
(<code>&amp;&amp;gt;&amp;gt;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/90cde9cfd8af30fcb65e9fd2cb2f9e181d3f103b";><code>90cde9c</code></a></li>
   <li>[Dev Deps] update <code>@ljharb/eslint-config</code> <a 
href="https://github.com/ljharb/shell-quote/commit/3a7b4ae3960c3ff4413932e276c5b0ecb3a2b456";><code>3a7b4ae</code></a></li>
   </ul>
   <h2><a 
href="https://github.com/ljharb/shell-quote/compare/v1.10.0...v1.11.0";>v1.11.0</a>
 - 2026-09-29</h2>
   <h3>Fixed</h3>
   <ul>
   <li>[Refactor] <code>quote</code>: drop a replace that can never match in 
the single-quote branch <a 
href="https://redirect.github.com/ljharb/shell-quote/issues/15";><code>[#15](https://github.com/ljharb/shell-quote/issues/15)</code></a></li>
   <li>[New] <code>parse</code>: support bash ANSI-C quoting 
(<code>$'...'</code>) <a 
href="https://redirect.github.com/ljharb/shell-quote/issues/32";><code>[#32](https://github.com/ljharb/shell-quote/issues/32)</code></a></li>
   </ul>
   <h3>Commits</h3>
   <ul>
   <li>[Fix] <code>quote</code>: reject line terminators in tokens after a 
<code>comment</code> <a 
href="https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc";><code>6002b2e</code></a></li>
   <li>[Fix] <code>parse</code>: preserve text after special shell parameters 
<a 
href="https://github.com/ljharb/shell-quote/commit/81b08a532e898a3627f9305fa13d643ffa82a9d3";><code>81b08a5</code></a></li>
   <li>[Fix] <code>parse</code>: an escaped backslash does not escape the 
character after it <a 
href="https://github.com/ljharb/shell-quote/commit/d708019016ce26e1a8a05af4b296e35ef8095c9e";><code>d708019</code></a></li>
   <li>[Fix] <code>quote</code>: preserve <code>!</code> in arguments that also 
contain <code>'</code> <a 
href="https://github.com/ljharb/shell-quote/commit/ad399279dbbbd086967d2040c1558b4888b074e6";><code>ad39927</code></a></li>
   <li>[Fix] <code>parse</code>: treat <code>$_name</code> as a variable name, 
not <code>$_</code> followed by text <a 
href="https://github.com/ljharb/shell-quote/commit/28f88cd422ae4046aca9556c4b74ca90b0ea7f6b";><code>28f88cd</code></a></li>
   <li>[Fix] <code>quote</code>: preserve empty glob patterns <a 
href="https://github.com/ljharb/shell-quote/commit/35c9b97a744211091b772f145bef0b6a5562b68e";><code>35c9b97</code></a></li>
   <li>[Fix] <code>quote</code>: escape <code>~</code> in glob patterns to 
prevent shell tilde-expansion <a 
href="https://github.com/ljharb/shell-quote/commit/239d49cae6d231436ea4e676850037018c790c49";><code>239d49c</code></a></li>
   <li>[Dev Deps] update <code>@ljharb/eslint-config</code>, 
<code>auto-changelog</code>, <code>eslint</code>, <code>evalmd</code> <a 
href="https://github.com/ljharb/shell-quote/commit/b1e406ed4287a134cc649db47b9a59e21b304472";><code>b1e406e</code></a></li>
   <li>[meta] npmignore some files <a 
href="https://github.com/ljharb/shell-quote/commit/ebfc3080cf5f68db5edfddfba49dc8c4ccacd2d5";><code>ebfc308</code></a></li>
   <li>[actions] add permissions <a 
href="https://github.com/ljharb/shell-quote/commit/3429b0d349211786765e9e68478e029d96ad44e9";><code>3429b0d</code></a></li>
   <li>[actions] set least-privilege <code>cache-mode</code> <a 
href="https://github.com/ljharb/shell-quote/commit/36f23944db50dd3f0df4da9c7cba0bb63df05f64";><code>36f2394</code></a></li>
   <li>[Dev Deps] update <code>eslint</code> <a 
href="https://github.com/ljharb/shell-quote/commit/6de9a41ecfc4fe9f9546df08866c8ead039f8909";><code>6de9a41</code></a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/6ecb8aa618ba6dc6c3b087fce6d7660320d2adeb";><code>6ecb8aa</code></a>
 v1.12.0</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/3a7b4ae3960c3ff4413932e276c5b0ecb3a2b456";><code>3a7b4ae</code></a>
 [Dev Deps] update <code>@ljharb/eslint-config</code></li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/7d688b9bec1917a22cccd4d4c887128a9c66e8a0";><code>7d688b9</code></a>
 [New] <code>parse</code>: support the <code>case</code> test-next terminator 
(<code>;;&amp;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/f27010ed04bcd925795b350afb1c49e36bbd1ba3";><code>f27010e</code></a>
 [New] <code>parse</code>: support the <code>case</code> fall-through 
terminator (<code>;&amp;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/90cde9cfd8af30fcb65e9fd2cb2f9e181d3f103b";><code>90cde9c</code></a>
 [New] <code>parse</code>: support appending stdout and stderr 
(<code>&amp;&gt;&gt;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/6ad6cd215f89adcc29dd601e085fa54083c2f911";><code>6ad6cd2</code></a>
 [New] <code>parse</code>: support redirecting stdout and stderr 
(<code>&amp;&gt;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/20533154bb57809c80f55318b8493aef49505f4e";><code>2053315</code></a>
 [New] <code>parse</code>: support output process substitution 
(<code>&gt;(</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/b78d19c14da6356cc12c46b3478203247ab8a295";><code>b78d19c</code></a>
 [New] <code>parse</code>: support redirecting output despite 
<code>noclobber</code> (<code>&gt;|</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/21cc333eb0ce5bf094f595b7fdc01b3447ffd4b0";><code>21cc333</code></a>
 [New] <code>parse</code>: support opening a file for reading and writing 
(<code>\&lt;&gt;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/dbfac376d4065d37539d3abdb5e76847f93797d3";><code>dbfac37</code></a>
 [New] <code>parse</code>: support tab-stripping here-documents 
(<code>&lt;&lt;-</code>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/ljharb/shell-quote/compare/v1.10.0...v1.12.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `source-map-js` from 1.2.1 to 1.2.2
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/7rulnik/source-map-js/releases";>source-map-js's 
releases</a>.</em></p>
   <blockquote>
   <h2>v1.2.2</h2>
   <ul>
   <li>
   <p>Fix crash when executing in browser with CSP script-src that don't permit 
unsafe-eval (<a 
href="https://redirect.github.com/7rulnik/source-map-js/pull/29";>#29</a>) <a 
href="https://github.com/xfournet";><code>@​xfournet</code></a></p>
   </li>
   <li>
   <p>Fix denial of service from malicious indexed source maps (CVE-2026-93749) 
(<a 
href="https://redirect.github.com/7rulnik/source-map-js/pull/79";>#79</a>)</p>
   <p>Reported by <a 
href="https://github.com/waydeshi";><code>@​waydeshi</code></a> in <a 
href="https://redirect.github.com/7rulnik/source-map-js/issues/76";>#76</a>. A 
fix was also proposed by <a 
href="https://github.com/aniebiet";><code>@​aniebiet</code></a> in <a 
href="https://redirect.github.com/7rulnik/source-map-js/pull/78";>#78</a>.</p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md";>source-map-js's
 changelog</a>.</em></p>
   <blockquote>
   <h2>1.2.2</h2>
   <ul>
   <li>
   <p>Fix crash when executing in browser with CSP script-src that don't permit 
unsafe-eval (<a 
href="https://redirect.github.com/7rulnik/source-map-js/pull/29";>#29</a>) <a 
href="https://github.com/xfournet";><code>@​xfournet</code></a></p>
   </li>
   <li>
   <p>Fix denial of service from malicious indexed source maps (CVE-2026-93749) 
(<a 
href="https://redirect.github.com/7rulnik/source-map-js/pull/79";>#79</a>)</p>
   <p>Reported by <a 
href="https://github.com/waydeshi";><code>@​waydeshi</code></a> in <a 
href="https://redirect.github.com/7rulnik/source-map-js/issues/76";>#76</a>. A 
fix was also proposed by <a 
href="https://github.com/aniebiet";><code>@​aniebiet</code></a> in <a 
href="https://redirect.github.com/7rulnik/source-map-js/pull/78";>#78</a>.</p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a";><code>0a1d334</code></a>
 1.2.2</li>
   <li><a 
href="https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739";><code>4c6fa26</code></a>
 Update changelog</li>
   <li><a 
href="https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016";><code>cf76580</code></a>
 Fix denial of service from malicious indexed source maps (CVE-2026-93749) (<a 
href="https://redirect.github.com/7rulnik/source-map-js/issues/79";>#79</a>)</li>
   <li><a 
href="https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df";><code>7899a86</code></a>
 Fix crash when executing browser with CSP script-src that don't permit 
unsafe...</li>
   <li>See full diff in <a 
href="https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore <dependency name> major version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
major version (unless you unignore this specific dependency's major version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name> minor version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
minor version (unless you unignore this specific dependency's minor version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name>` will close this group update PR and 
stop Dependabot creating any more for the specific dependency (unless you 
unignore this specific dependency or upgrade to it yourself)
   - `@dependabot unignore <dependency name>` will remove all of the ignore 
conditions of the specified dependency
   - `@dependabot unignore <dependency name> <ignore condition>` will remove 
the ignore condition of the specified dependency and ignore conditions
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/airflow-site/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to