Skip to content

deps: update ncm-ng to 2.9.9 - #478

Merged
santigimeno merged 1 commit into
node-v24.x-nsolid-v6.xfrom
santi/dep_updates
Jun 10, 2026
Merged

deps: update ncm-ng to 2.9.9#478
santigimeno merged 1 commit into
node-v24.x-nsolid-v6.xfrom
santi/dep_updates

Conversation

@santigimeno

@santigimeno santigimeno commented Jun 10, 2026

Copy link
Copy Markdown
Member

Addresses GHSA-ph9p-34f9-6g65.

Summary by CodeRabbit

  • Chores
    • Bumped package version.
    • Updated a transitive utility dependency to a newer minor release to address maintenance and stability.
    • No functional or public API changes; user-facing behavior remains unchanged.

@coderabbitai

coderabbitai Bot commented Jun 10, 2026

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 1a51428d-1d7a-41e5-851d-107f35d6e089

📥 Commits

Reviewing files that changed from the base of the PR and between e9aa793 and e9d6fc1.

📒 Files selected for processing (1)
  • deps/ncm-ng/package.json

Walkthrough

This PR updates deps/ncm-ng/package.json: bumps the package version 2.9.8 → 2.9.9 and updates the tmp dependency ^0.2.1 → ^0.2.6.

Changes

Package and Dependency Update

Layer / File(s) Summary
NCM-NG package version and tmp dependency bump
deps/ncm-ng/package.json
Version incremented to 2.9.9 and tmp dependency updated to ^0.2.6.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

  • nodesource/nsolid#455: Previous version bump of @ns-private/ncm-ng in the same file, part of the same dependency update chain.

Suggested reviewers

  • RafaelGSS

Poem

🐰 I hopped through JSON, neat and spry,
Pushed a tiny bump to catch the eye,
Two.nine.nine now leads the trail,
tmp updated — a little tale,
Cheers from the rabbit with a hop and a sigh.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'deps: update ncm-ng to 2.9.9' directly and clearly summarizes the main change in the pull request, which is updating the ncm-ng dependency version.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch santi/dep_updates

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @mswjs/interceptors is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@mswjs/interceptors@0.41.9

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@mswjs/interceptors@0.41.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the vendored deps/ncm-ng package metadata to address security advisory GHSA-ph9p-34f9-6g65 by bumping the package version and updating a vulnerable dependency.

Changes:

  • Bump @ns-private/ncm-ng version from 2.9.8 to 2.9.9.
  • Update tmp dependency from ^0.2.1 to ^0.2.6.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Addresses `GHSA-ph9p-34f9-6g65`.

Signed-off-by: Santiago Gimeno <santiago.gimeno@gmail.com>
PR-URL: #478
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
@santigimeno
santigimeno merged commit e9d6fc1 into node-v24.x-nsolid-v6.x Jun 10, 2026
10 of 11 checks passed
@santigimeno
santigimeno deleted the santi/dep_updates branch June 10, 2026 21:33
santigimeno pushed a commit that referenced this pull request Jun 15, 2026
Addresses `GHSA-ph9p-34f9-6g65`.

Signed-off-by: Santiago Gimeno <santiago.gimeno@gmail.com>
PR-URL: #478
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
flynnjustin24 pushed a commit to flynnjustin24/nsolid that referenced this pull request Aug 1, 2026
Addresses `GHSA-ph9p-34f9-6g65`.

Signed-off-by: Santiago Gimeno <santiago.gimeno@gmail.com>
PR-URL: nodesource#478
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants