Skip to content

chore(deps): lock file maintenance#27

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/lock-file-maintenance
Open

chore(deps): lock file maintenance#27
renovate[bot] wants to merge 1 commit intomainfrom
renovate/lock-file-maintenance

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 18, 2023

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "before 4am on monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (rebase) September 18, 2023 01:55
@changeset-bot
Copy link

changeset-bot bot commented Sep 18, 2023

⚠️ No Changeset found

Latest commit: cd5f8e8

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 4c059ba to 938996b Compare September 18, 2023 04:32
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 938996b to 27c8a67 Compare December 14, 2023 17:15
@socket-security
Copy link

socket-security bot commented Dec 14, 2023

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​13.5.1 ⏵ 13.5.1153 -850 +2594 +197 +4770
Updatednextra@​2.12.3 ⏵ 2.13.48210073 +389 -4100
Updatednextra-theme-docs@​2.12.3 ⏵ 2.13.499 +110074 +390 -4100
Updatedreact@​18.2.0 ⏵ 18.3.1100 +110084 +197100
Updatedtypescript@​5.2.2 ⏵ 5.9.31001009010090
Updatedreact-dom@​18.2.0 ⏵ 18.3.19210092 +198100

View full report

@socket-security
Copy link

socket-security bot commented Dec 14, 2023

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Telemetry collection: npm next

Note: The code contains potential security risks due to the use of execSync without proper error handling, which could lead to command injection vulnerabilities. It should be reviewed and modified to use safer alternatives.

From: package.jsonnpm/next@13.5.11

ℹ Read more on: This package | This alert | What is telemetry?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@13.5.11. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Telemetry collection: npm next

Note: The code includes functionality for collecting anonymous usage data, but the dynamic spawning of child processes raises red flags. The telemetry feature should be used with caution, and users should be informed about the potential security risk associated with child process spawning.

From: package.jsonnpm/next@13.5.11

ℹ Read more on: This package | This alert | What is telemetry?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@13.5.11. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 3416f8b to 7922045 Compare December 16, 2023 16:34
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 7922045 to 8573b19 Compare January 10, 2024 19:13
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 763c82f to 6410379 Compare January 26, 2024 23:03
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 6410379 to 5e44b2a Compare March 7, 2024 02:13
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 5e44b2a to 691f083 Compare March 31, 2024 16:41
@vercel
Copy link

vercel bot commented Mar 31, 2024

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
kiai-docs Ready Ready Preview, Comment Mar 5, 2026 6:07pm

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from d83136a to 0162b1e Compare September 20, 2025 02:13
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 0162b1e to 9c86046 Compare September 25, 2025 15:48
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 9c86046 to 702ac62 Compare October 21, 2025 15:52
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 702ac62 to 1970614 Compare November 10, 2025 14:07
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 1970614 to 39ae044 Compare November 18, 2025 20:01
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 39ae044 to c0d5d5f Compare December 3, 2025 17:37
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from c0d5d5f to 633badd Compare December 31, 2025 14:52
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 633badd to 39539d7 Compare January 8, 2026 20:00
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 39539d7 to 2afd4cf Compare January 19, 2026 15:01
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 2afd4cf to 6b9d53f Compare January 23, 2026 17:30
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 6b9d53f to 8624662 Compare February 2, 2026 20:38
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 8624662 to a0df182 Compare February 12, 2026 10:46
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from a0df182 to c0dee5d Compare February 17, 2026 20:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants