Skip to content

chore(deps): update all non-major dependencies#77

Merged
yyxi merged 1 commit intotrunkfrom
renovate/all-minor-patch
May 19, 2025
Merged

chore(deps): update all non-major dependencies#77
yyxi merged 1 commit intotrunkfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 3, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@actions/github (source) 6.0.0 -> 6.0.1 age adoption passing confidence
@commitlint/cli (source) 19.7.1 -> 19.8.1 age adoption passing confidence
@commitlint/config-conventional (source) 19.7.1 -> 19.8.1 age adoption passing confidence
@ls-lint/ls-lint 2.2.3 -> 2.3.0 age adoption passing confidence
@pnpm/workspace.find-packages (source) 1000.0.10 -> 1000.0.23 age adoption passing confidence
@pnpm/workspace.read-manifest (source) 1000.0.2 -> 1000.1.4 age adoption passing confidence
@types/node (source) 22.13.4 -> 22.15.17 age adoption passing confidence
@types/semver (source) 7.5.8 -> 7.7.0 age adoption passing confidence
@vitest/coverage-v8 (source) 3.0.6 -> 3.1.3 age adoption passing confidence
changelogen 0.5.7 -> 0.6.1 age adoption passing confidence
changelogithub 13.12.1 -> 13.13.0 age adoption passing confidence
execa 9.5.2 -> 9.5.3 age adoption passing confidence
knip (source) 5.44.4 -> 5.55.1 age adoption passing confidence
lefthook 1.10.10 -> 1.11.12 age adoption passing confidence
prettier (source) 3.5.1 -> 3.5.3 age adoption passing confidence
semver 7.7.1 -> 7.7.2 age adoption passing confidence
syncpack 13.0.2 -> 13.0.4 age adoption passing confidence
tsx (source) 4.19.3 -> 4.19.4 age adoption passing confidence
typescript (source) 5.7.3 -> 5.8.3 age adoption passing confidence

Release Notes

actions/toolkit (@​actions/github)

v6.0.1

conventional-changelog/commitlint (@​commitlint/cli)

v19.8.1

Compare Source

Bug Fixes

v19.8.0

Compare Source

Performance Improvements
  • use node: prefix to bypass require.cache call for builtins (#​4302) (0cd8f41)

19.7.1 (2025-02-02)

Note: Version bump only for package @​commitlint/cli

19.6.1 (2024-12-15)

Note: Version bump only for package @​commitlint/cli

conventional-changelog/commitlint (@​commitlint/config-conventional)

v19.8.1

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

v19.8.0

Compare Source

Performance Improvements
  • use node: prefix to bypass require.cache call for builtins (#​4302) (0cd8f41)

19.7.1 (2025-02-02)

Note: Version bump only for package @​commitlint/config-conventional

loeffel-io/ls-lint (@​ls-lint/ls-lint)

v2.3.0

Compare Source

Please see the v2.3.0 announcement for more informations: https://ls-lint.org/blog/announcements/v2.3.0.html

What's Changed

New Contributors

Full Changelog: loeffel-io/ls-lint@v2.2.3...v2.3.0

vitest-dev/vitest (@​vitest/coverage-v8)

v3.1.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub

v3.1.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.0

Compare Source

🚀 Features
🐞 Bug Fixes
🏎 Performance
View changes on GitHub

v3.0.9

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.0.8

Compare Source

   🐞 Bug Fixes

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

@renovate renovate bot added the dependencies label Mar 3, 2025
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 29b4f43 to b76f039 Compare March 10, 2025 18:27
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 7e2122c to 1af793d Compare March 20, 2025 07:02
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from d62b9c5 to 903052a Compare March 26, 2025 15:37
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from e3747e4 to 1461d42 Compare April 2, 2025 08:39
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from f3a7930 to bc13625 Compare April 14, 2025 19:14
@socket-security
Copy link

socket-security bot commented Apr 14, 2025

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert (click for details)
Block High
cross-spawn@7.0.3 has a High CVE.

CVE: GHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawn (HIGH)

Affected versions: >= 7.0.0, < 7.0.5

Patched version: 7.0.5

From: pnpm-lock.yamlnpm/@pnpm/workspace.find-packages@1000.0.23npm/cross-spawn@7.0.3

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/cross-spawn@7.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 606aa69 to 20db4b9 Compare April 22, 2025 05:37
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from a9eae85 to 7b00d5f Compare April 28, 2025 12:31
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from 0fd8b1c to daf02cf Compare May 8, 2025 12:34
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 3983eec to 03fa197 Compare May 13, 2025 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

1 participant