Skip to content

chore(deps): bump compressing from 1.10.4 to 1.10.5#235

Merged
kodiakhq[bot] merged 2 commits into
mainfrom
dependabot/npm_and_yarn/compressing-1.10.5
May 7, 2026
Merged

chore(deps): bump compressing from 1.10.4 to 1.10.5#235
kodiakhq[bot] merged 2 commits into
mainfrom
dependabot/npm_and_yarn/compressing-1.10.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

Bumps compressing from 1.10.4 to 1.10.5.

Release notes

Sourced from compressing's releases.

v1.10.5

1.10.5 (2026-04-13)

  • fix: prevent symlink path traversal via pre-existing symlinks during tar extraction (18def23)

This release is also available on:

Changelog

Sourced from compressing's changelog.

1.10.5 (2026-04-13)

  • fix: prevent symlink path traversal via pre-existing symlinks during tar extraction (18def23)
Commits
  • 40d5f1f Release 1.10.5
  • 18def23 fix: prevent symlink path traversal via pre-existing symlinks during tar extr...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 17, 2026
@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 17, 2026

⚠️ No Changeset found

Latest commit: cf8353a

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/compressing-1.10.5 branch 2 times, most recently from d3fa1c6 to ad69f73 Compare April 21, 2026 14:58
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/compressing-1.10.5 branch from ad69f73 to e323518 Compare May 5, 2026 20:06
Bumps [compressing](https://github.com/node-modules/compressing) from 1.10.4 to 1.10.5.
- [Release notes](https://github.com/node-modules/compressing/releases)
- [Changelog](https://github.com/node-modules/compressing/blob/v1.10.5/CHANGELOG.md)
- [Commits](node-modules/compressing@v1.10.4...v1.10.5)

---
updated-dependencies:
- dependency-name: compressing
  dependency-version: 1.10.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/compressing-1.10.5 branch from e323518 to 41e5c0d Compare May 7, 2026 18:37
@kodiakhq kodiakhq Bot merged commit 2b59946 into main May 7, 2026
6 checks passed
@kodiakhq kodiakhq Bot deleted the dependabot/npm_and_yarn/compressing-1.10.5 branch May 7, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automerge dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant