Skip to content

chore(actions):(deps): bump actions/setup-node from 4 to 7 - #162

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7
Open

chore(actions):(deps): bump actions/setup-node from 4 to 7#162
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-node from 4 to 7.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

⚠️ Major version update detected! Please review this PR manually before merging.

@github-actions

Copy link
Copy Markdown

⚠️ Security Alert: Vulnerabilities detected in dependencies

Security Audit Report

npm audit results

# npm audit report

@babel/core  <=7.29.0
@babel/core: Arbitrary File Read via sourceMappingURL Comment - https://github.com/advisories/GHSA-4x5r-pxfx-6jf8
fix available via `npm audit fix`
node_modules/@babel/core

dompurify  <=3.4.10
Severity: moderate
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects - https://github.com/advisories/GHSA-x4vx-rjvf-j5p4
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` - https://github.com/advisories/GHSA-76mc-f452-cxcm
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks - https://github.com/advisories/GHSA-hpcv-96wg-7vj8
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM - https://github.com/advisories/GHSA-r47g-fvhr-h676
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output - https://github.com/advisories/GHSA-vxr8-fq34-vvx9
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes - https://github.com/advisories/GHSA-gvmj-g25r-r7wr
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content - https://github.com/advisories/GHSA-rp9w-3fw7-7cwq
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) - https://github.com/advisories/GHSA-cmwh-pvxp-8882
fix available via `npm audit fix`
node_modules/dompurify
  monaco-editor  0.54.0-dev-20250909 - 0.56.0-dev-20260211
  Depends on vulnerable versions of dompurify
  node_modules/monaco-editor

js-yaml  4.0.0 - 4.1.1
Severity: moderate
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases - https://github.com/advisories/GHSA-h67p-54hq-rp68
fix available via `npm audit fix`
node_modules/js-yaml

protobufjs  <=7.6.2
Severity: moderate
protobufjs : Schema-derived names can shadow runtime-significant properties - https://github.com/advisories/GHSA-f38q-mgvj-vph7
fix available via `npm audit fix`
node_modules/protobufjs
  @google/genai  
  Depends on vulnerable versions of protobufjs
  node_modules/@google/genai

vite  8.0.0 - 8.0.15
Severity: high
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows - https://github.com/advisories/GHSA-v6wh-96g9-6wx3
vite: `server.fs.deny` bypass on Windows alternate paths - https://github.com/advisories/GHSA-fx2h-pf6j-xcff
fix available via `npm audit fix`
node_modules/vite

7 vulnerabilities (2 low, 4 moderate, 1 high)

To address all issues, run:
  npm audit fix

⚠️ Vulnerabilities detected - please review

Outdated Dependencies

Package                           Current   Wanted   Latest  Location                                       Depended by
@eslint/js                         9.39.4   9.39.5   10.0.1  node_modules/@eslint/js                        Omni-Grid-2.0
@google/genai                      1.46.0   1.52.0   2.12.0  node_modules/@google/genai                     Omni-Grid-2.0
@testing-library/react             16.3.1   16.3.2   16.3.2  node_modules/@testing-library/react            Omni-Grid-2.0
@types/node                        25.5.0   25.9.5   26.1.1  node_modules/@types/node                       Omni-Grid-2.0
@types/react                      19.2.14  19.2.17  19.2.17  node_modules/@types/react                      Omni-Grid-2.0
@types/react-grid-layout            2.1.0    2.1.0    1.3.6  node_modules/@types/react-grid-layout          Omni-Grid-2.0
@typescript-eslint/eslint-plugin   8.57.1   8.64.0   8.64.0  node_modules/@typescript-eslint/eslint-plugin  Omni-Grid-2.0
@typescript-eslint/parser          8.57.1   8.64.0   8.64.0  node_modules/@typescript-eslint/parser         Omni-Grid-2.0
@vitejs/plugin-react                6.0.1    6.0.3    6.0.3  node_modules/@vitejs/plugin-react              Omni-Grid-2.0
@vitest/coverage-v8                 4.1.0   4.1.10   4.1.10  node_modules/@vitest/coverage-v8               Omni-Grid-2.0
@vitest/ui                          4.1.0   4.1.10   4.1.10  node_modules/@vitest/ui                        Omni-Grid-2.0
eslint                             9.39.2   9.39.5   10.7.0  node_modules/eslint                            Omni-Grid-2.0
eslint-plugin-react-hooks           7.0.1    7.1.1    7.1.1  node_modules/eslint-plugin-react-hooks         Omni-Grid-2.0
jsdom                              27.4.0   27.4.0   29.1.1  node_modules/jsdom                             Omni-Grid-2.0
lucide-react                      0.577.0  0.577.0   1.25.0  node_modules/lucide-react                      Omni-Grid-2.0
prettier                            3.7.4    3.9.5    3.9.5  node_modules/prettier                          Omni-Grid-2.0
react-grid-layout                   1.4.4    1.4.4    2.2.3  node_modules/react-grid-layout                 Omni-Grid-2.0
typescript                          5.9.3    5.9.3    7.0.2  node_modules/typescript                        Omni-Grid-2.0
vite                                8.0.8    8.1.5    8.1.5  node_modules/vite                              Omni-Grid-2.0
vitest                              4.1.0   4.1.10   4.1.10  node_modules/vitest                            Omni-Grid-2.0
zustand                            5.0.12   5.0.12   5.0.14  node_modules/zustand                           Omni-Grid-2.0

Installed Packages

copy-of-omni-grid@0.0.0 /home/runner/work/Omni-Grid-2.0/Omni-Grid-2.0
├── @eslint/js@9.39.4
├── @google/genai@1.46.0
├── @monaco-editor/react@4.7.0
├── @testing-library/dom@10.4.1
├── @testing-library/jest-dom@6.9.1
├── @testing-library/react@16.3.1
├── @types/node@25.5.0
├── @types/react-dom@19.2.3
├── @types/react-grid-layout@2.1.0
├── @types/react@19.2.14
├── @typescript-eslint/eslint-plugin@8.57.1
├── @typescript-eslint/parser@8.57.1
├── @vitejs/plugin-react@6.0.1
├── @vitest/coverage-v8@4.1.0
├── @vitest/ui@4.1.0
├── eslint-config-prettier@10.1.8
├── eslint-plugin-react-hooks@7.0.1
├── eslint-plugin-react@7.37.5
├── eslint@9.39.2
├── jsdom@27.4.0
├── lucide-react@0.577.0
├── prettier@3.7.4
├── react-dom@19.2.7
├── react-grid-layout@1.4.4
├── react@19.2.7
├── typescript@5.9.3
├── vite@8.0.8
├── vitest@4.1.0
└── zustand@5.0.12


Report generated on Mon Jul 20 09:11:48 UTC 2026

@github-actions

Copy link
Copy Markdown

Build Performance Report

Frontend Build

  • Duration: 1s
  • Status: ✅ Built successfully
  • Bundle Size: 996K

Largest Assets

968K	dist/assets/index-yXMczT2r.js
8.0K	dist/sw.js
8.0K	dist/index.html
4.0K	dist/manifest.json

⚠️ Warning: 1 file(s) larger than 500KB detected

C++ Server Build

  • Duration: 1s
  • Binary Size: 76K
  • Status: ✅ Built successfully

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-node-7 branch from 63ae11b to 46e7dd8 Compare August 15, 2026 05:15
@github-actions

Copy link
Copy Markdown

⚠️ Major version update detected! Please review this PR manually before merging.

@github-actions

Copy link
Copy Markdown

⚠️ Security Alert: Vulnerabilities detected in dependencies

Security Audit Report

npm audit results

# npm audit report

dompurify  <=3.4.12
Severity: moderate
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS - https://github.com/advisories/GHSA-55q2-fjhq-7xh7
fix available via `npm audit fix`
node_modules/dompurify
  monaco-editor  >=0.54.0-dev-20250909
  Depends on vulnerable versions of dompurify
  node_modules/monaco-editor

js-yaml  4.0.0 - 4.3.0
Severity: high
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported - https://github.com/advisories/GHSA-5p4m-2wfm-xmqj
fix available via `npm audit fix`
node_modules/js-yaml

nanoid  <3.3.18
Severity: high
nanoid: custom generators can loop indefinitely when size is zero - https://github.com/advisories/GHSA-2v37-7h3g-55p8
fix available via `npm audit fix`
node_modules/nanoid

4 vulnerabilities (2 moderate, 2 high)

To address all issues, run:
  npm audit fix

⚠️ Vulnerabilities detected - please review

Outdated Dependencies

Package                           Current   Wanted   Latest  Location                                       Depended by
@eslint/js                         9.39.4   9.39.5   10.0.1  node_modules/@eslint/js                        Omni-Grid-2.0
@google/genai                      1.52.0   1.52.0   2.17.1  node_modules/@google/genai                     Omni-Grid-2.0
@testing-library/react             16.3.1   16.3.2   16.3.2  node_modules/@testing-library/react            Omni-Grid-2.0
@types/node                        25.5.0   25.9.5   26.2.0  node_modules/@types/node                       Omni-Grid-2.0
@types/react                      19.2.14  19.2.18  19.2.18  node_modules/@types/react                      Omni-Grid-2.0
@types/react-dom                   19.2.3   19.2.4   19.2.4  node_modules/@types/react-dom                  Omni-Grid-2.0
@types/react-grid-layout            2.1.0    2.1.0    1.3.6  node_modules/@types/react-grid-layout          Omni-Grid-2.0
@typescript-eslint/eslint-plugin   8.57.1   8.67.0   8.67.0  node_modules/@typescript-eslint/eslint-plugin  Omni-Grid-2.0
@typescript-eslint/parser          8.57.1   8.67.0   8.67.0  node_modules/@typescript-eslint/parser         Omni-Grid-2.0
@vitejs/plugin-react                6.0.1    6.0.5    6.0.5  node_modules/@vitejs/plugin-react              Omni-Grid-2.0
@vitest/coverage-v8                 4.1.0   4.1.10   4.1.10  node_modules/@vitest/coverage-v8               Omni-Grid-2.0
@vitest/ui                          4.1.0   4.1.10   4.1.10  node_modules/@vitest/ui                        Omni-Grid-2.0
eslint                             9.39.2   9.39.5   10.8.1  node_modules/eslint                            Omni-Grid-2.0
eslint-plugin-react-hooks           7.0.1    7.1.1    7.1.1  node_modules/eslint-plugin-react-hooks         Omni-Grid-2.0
jsdom                              27.4.0   27.4.0   29.1.1  node_modules/jsdom                             Omni-Grid-2.0
lucide-react                      0.577.0  0.577.0   1.31.0  node_modules/lucide-react                      Omni-Grid-2.0
prettier                            3.7.4    3.9.6    3.9.6  node_modules/prettier                          Omni-Grid-2.0
react                              19.2.7   19.2.7   19.2.8  node_modules/react                             Omni-Grid-2.0
react-dom                          19.2.7   19.2.7   19.2.8  node_modules/react-dom                         Omni-Grid-2.0
react-grid-layout                   1.4.4    1.4.4    2.2.4  node_modules/react-grid-layout                 Omni-Grid-2.0
typescript                          5.9.3    5.9.3    7.0.2  node_modules/typescript                        Omni-Grid-2.0
vite                                8.1.5    8.2.1    8.2.1  node_modules/vite                              Omni-Grid-2.0
vitest                              4.1.0   4.1.10   4.1.10  node_modules/vitest                            Omni-Grid-2.0
zustand                            5.0.12   5.0.12   5.0.15  node_modules/zustand                           Omni-Grid-2.0

Installed Packages

omni-grid-2.0@2.5.7 /home/runner/work/Omni-Grid-2.0/Omni-Grid-2.0
├── @eslint/js@9.39.4
├── @google/genai@1.52.0
├── @monaco-editor/react@4.7.0
├── @testing-library/dom@10.4.1
├── @testing-library/jest-dom@6.9.1
├── @testing-library/react@16.3.1
├── @types/node@25.5.0
├── @types/react-dom@19.2.3
├── @types/react-grid-layout@2.1.0
├── @types/react@19.2.14
├── @typescript-eslint/eslint-plugin@8.57.1
├── @typescript-eslint/parser@8.57.1
├── @vitejs/plugin-react@6.0.1
├── @vitest/coverage-v8@4.1.0
├── @vitest/ui@4.1.0
├── eslint-config-prettier@10.1.8
├── eslint-plugin-react-hooks@7.0.1
├── eslint-plugin-react@7.37.5
├── eslint@9.39.2
├── jsdom@27.4.0
├── lucide-react@0.577.0
├── prettier@3.7.4
├── react-dom@19.2.7
├── react-grid-layout@1.4.4
├── react@19.2.7
├── typescript@5.9.3
├── vite@8.1.5
├── vitest@4.1.0
└── zustand@5.0.12


Report generated on Sat Aug 15 05:15:47 UTC 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants