Skip to content

Bump the node group across 1 directory with 5 updates#15

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/node-60ab43481c
Open

Bump the node group across 1 directory with 5 updates#15
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/node-60ab43481c

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Mar 19, 2026

Bumps the node group with 5 updates in the / directory:

Package From To
@actions/core 1.10.1 3.0.0
@octokit/plugin-retry 7.0.3 8.1.0
@octokit/plugin-throttling 9.0.3 11.0.3
@octokit/rest 20.0.2 22.0.1
@vercel/ncc 0.38.1 0.38.4

Updates @actions/core from 1.10.1 to 3.0.0

Changelog

Sourced from @​actions/core's changelog.

3.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

2.0.3

  • Bump @actions/http-client to 3.0.2

2.0.1

  • Bump @​actions/exec from 1.1.1 to 2.0.0 #2199

2.0.0

  • Add support for Node 24 #2110
  • Bump @​actions/http-client from 2.0.1 to 3.0.0

1.11.1

  • Fix uses of crypto.randomUUID on Node 18 and earlier #1842

1.11.0

  • Add platform info utilities #1551
  • Remove dependency on uuid package #1824
Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​actions/core since your current version.


Updates @octokit/plugin-retry from 7.0.3 to 8.1.0

Release notes

Sourced from @​octokit/plugin-retry's releases.

v8.1.0

8.1.0 (2026-02-18)

Features

v8.0.3

8.0.3 (2025-10-31)

Bug Fixes

  • deps: update dependency @​octokit/types to v16 (#650) (03f2add)

v8.0.2

8.0.2 (2025-09-29)

Bug Fixes

  • deps: update dependency @​octokit/types to v15 (#641) (7a9080f)

v8.0.1

8.0.1 (2025-05-20)

Bug Fixes

  • deps: update octokit monorepo to v7 (major) (#634) (f5fe899)

v8.0.0

8.0.0 (2025-05-20)

Continuous Integration

BREAKING CHANGES

  • Drop support for NodeJS v18

  • build: set minimal node version in build script to v20

  • ci: stop testing against NodeJS v18

v7.2.1

... (truncated)

Commits
  • e8bdeb7 feat: add types (#661)
  • 96f572f chore(deps): replace glob with tinyglobby (#657)
  • 2b9b2ea build(deps): bump glob (#656)
  • 31bd239 build(deps): lock file maintenance (#643)
  • 58b66d1 chore(deps): update dependency node to v24 (#649)
  • 927b598 chore(deps): update dependency prettier to v3.6.2 (#636)
  • 03f2add fix(deps): update dependency @​octokit/types to v16 (#650)
  • 112467a ci(action): update actions/checkout action to v5 (#638)
  • fef5474 ci(action): update peter-evans/create-or-update-comment action to v5 (#644)
  • 7c99a5e chore(deps): update vitest monorepo to v4 (major) (#648)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​octokit/plugin-retry since your current version.


Updates @octokit/plugin-throttling from 9.0.3 to 11.0.3

Release notes

Sourced from @​octokit/plugin-throttling's releases.

v11.0.3

11.0.3 (2025-10-31)

Bug Fixes

  • deps: update dependency @​octokit/types to v16 (#811) (d87092d)

v11.0.2

11.0.2 (2025-09-29)

Bug Fixes

  • deps: update dependency @​octokit/types to v15 (#802) (c9ecfea)

v11.0.1

11.0.1 (2025-05-20)

Bug Fixes

  • deps: update octokit monorepo (major) (#795) (a6781b0)

v11.0.0

11.0.0 (2025-05-20)

Continuous Integration

BREAKING CHANGES

  • Drop support for NodeJS v18

  • build: set minimal node version in build script to v20

  • ci: stop testing against NodeJS v18

v10.0.0

10.0.0 (2025-04-10)

Features

  • new org campaign endpoints, remove deprecated Copilot usage endpoints (#784) (0520476)

... (truncated)

Commits
  • c253528 chore(deps): update dependency node to v24 (#809)
  • d87092d fix(deps): update dependency @​octokit/types to v16 (#811)
  • e3de64b ci(action): update github/codeql-action action to v4 (#805)
  • 0673f3e ci(action): update actions/setup-node action to v6 (#806)
  • c9ecfea fix(deps): update dependency @​octokit/types to v15 (#802)
  • 790adf6 build(deps): lock file maintenance (#796)
  • 9395a23 ci(action): update actions/checkout action to v5 (#799)
  • a6781b0 fix(deps): update octokit monorepo (major) (#795)
  • 40245a8 ci: stop testing against NodeJS v18 (#793)
  • c49c814 build(deps): lock file maintenance (#792)
  • Additional commits viewable in compare view

Updates @octokit/rest from 20.0.2 to 22.0.1

Release notes

Sourced from @​octokit/rest's releases.

v22.0.1

22.0.1 (2025-10-31)

Bug Fixes

  • deps: update octokit monorepo (major) (#538) (ded2f17)

v22.0.0

22.0.0 (2025-05-25)

Bug Fixes

  • deps: update octokit monorepo (major) (#504) (77530ab)

BREAKING CHANGES

  • deps: Drop support for NodeJS v18
  • deps: Remove deprecated Projects endpoints
  • deps: Remove deprecated Copilot usage metrics endpoints

v21.1.1

21.1.1 (2025-02-14)

Bug Fixes

  • deps: update Octokit dependencies to mitigate ReDos [security] (#484) (ca256c3)

v21.1.0

21.1.0 (2025-01-08)

Features

  • new endpoints, bump Octokit deps to fix Deno (#477) (908b1c8)

v21.0.2

21.0.2 (2024-08-16)

Bug Fixes

... (truncated)

Commits
  • daa3ec9 ci(action): update actions/setup-node action to v6 (#534)
  • 1dec0c7 ci(action): update peter-evans/create-or-update-comment action to v5 (#531)
  • ded2f17 fix(deps): update octokit monorepo (major) (#538)
  • 0e0eaea chore(deps): update dependency @​types/node to v24 (#537)
  • c04acc8 chore(deps): update vitest monorepo to v4 (major) (#536)
  • e6dd306 chore(deps): update dependency undici to v7 (#474)
  • 5f380d0 build(deps-dev): Bump form-data from 4.0.2 to 4.0.4 in /docs (#520)
  • dc6827d build(deps-dev): Bump tar-fs from 2.1.2 to 2.1.3 in /docs (#516)
  • 77530ab fix(deps): update octokit monorepo (major) (#504)
  • d07b719 build(deps): Bump vite from 6.2.5 to 6.3.4 (#509)
  • Additional commits viewable in compare view

Updates @vercel/ncc from 0.38.1 to 0.38.4

Release notes

Sourced from @​vercel/ncc's releases.

0.38.4

0.38.4 (2025-09-18)

Bug Fixes

0.38.3

0.38.3 (2024-11-15)

Bug Fixes

  • add missing --asset-builds to cli help message (#1228) (84f8c52)

0.38.2

0.38.2 (2024-09-23)

Bug Fixes

Huge thanks to @​theoludwig 🎉

Commits
  • e72d34d fix(cjs-build): enable evaluating import.meta in cjs build (#1236)
  • 186af2b chore(deps): Bump amannn/action-semantic-pull-request from 5.5.3 to 6.1.1 (#1...
  • 162c7d4 chore(deps): Bump actions/checkout from 4 to 5 (#1283)
  • 24734b5 chore(deps): Bump cipher-base from 1.0.4 to 1.0.6 (#1280)
  • 7bf44d5 chore(deps): Bump sha.js from 2.4.11 to 2.4.12 (#1281)
  • 50f1851 chore(deps): Bump tmp from 0.2.3 to 0.2.4 (#1278)
  • d797f1b chore(deps-dev): Bump koa from 2.16.1 to 3.0.1 (#1272)
  • 9bdbd47 chore(deps): Bump pbkdf2 from 3.1.2 to 3.1.3 (#1266)
  • cbfd660 chore(deps-dev): bump test deps for aws-sdk (#1263)
  • d17397f chore(deps-dev): Bump axios from 1.7.7 to 1.8.2 (#1262)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the node group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core) | `1.10.1` | `3.0.0` |
| [@octokit/plugin-retry](https://github.com/octokit/plugin-retry.js) | `7.0.3` | `8.1.0` |
| [@octokit/plugin-throttling](https://github.com/octokit/plugin-throttling.js) | `9.0.3` | `11.0.3` |
| [@octokit/rest](https://github.com/octokit/rest.js) | `20.0.2` | `22.0.1` |
| [@vercel/ncc](https://github.com/vercel/ncc) | `0.38.1` | `0.38.4` |



Updates `@actions/core` from 1.10.1 to 3.0.0
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md)
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core)

Updates `@octokit/plugin-retry` from 7.0.3 to 8.1.0
- [Release notes](https://github.com/octokit/plugin-retry.js/releases)
- [Commits](octokit/plugin-retry.js@v7.0.3...v8.1.0)

Updates `@octokit/plugin-throttling` from 9.0.3 to 11.0.3
- [Release notes](https://github.com/octokit/plugin-throttling.js/releases)
- [Commits](octokit/plugin-throttling.js@v9.0.3...v11.0.3)

Updates `@octokit/rest` from 20.0.2 to 22.0.1
- [Release notes](https://github.com/octokit/rest.js/releases)
- [Commits](octokit/rest.js@v20.0.2...v22.0.1)

Updates `@vercel/ncc` from 0.38.1 to 0.38.4
- [Release notes](https://github.com/vercel/ncc/releases)
- [Commits](vercel/ncc@0.38.1...0.38.4)

---
updated-dependencies:
- dependency-name: "@actions/core"
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: node
- dependency-name: "@octokit/plugin-retry"
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: node
- dependency-name: "@octokit/plugin-throttling"
  dependency-version: 11.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: node
- dependency-name: "@octokit/rest"
  dependency-version: 22.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: node
- dependency-name: "@vercel/ncc"
  dependency-version: 0.38.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: node
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 19, 2026
@github-actions
Copy link
Copy Markdown

Code Scanning Analysis Not Found

Your repository default branch has not been scanned with CodeQL in the last 7 days. Per VA policy your repository must use CodeQL to scan your source code for vulnerabilities at least once every 7 days against your default branch.

Once you have completed the scan against your default branch, follow this link to re-run the policy check and select Re-run all jobs at the top of the page: https://github.com/department-of-veterans-affairs/security-tools/actions/runs/23320443604

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants