Skip to content

chore(deps): update dependency dayjs to v1.11.20#3699

Open
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/dayjs-1.x-lockfile
Open

chore(deps): update dependency dayjs to v1.11.20#3699
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/dayjs-1.x-lockfile

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Mar 13, 2026

This PR contains the following updates:

Package Change Age Confidence
dayjs (source) 1.11.191.11.20 age confidence

Release Notes

iamkun/dayjs (dayjs)

v1.11.20

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/dayjs-1.x-lockfile branch 3 times, most recently from b4629c3 to 1f99895 Compare March 24, 2026 22:18
@renovate renovate Bot force-pushed the renovate/dayjs-1.x-lockfile branch from 1f99895 to eaeafc0 Compare April 1, 2026 17:15
@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 duplication

Metric Results
Duplication 0

View in Codacy

TIP This summary will be updated as you push new changes. Give us feedback

@renovate renovate Bot force-pushed the renovate/dayjs-1.x-lockfile branch from eaeafc0 to 30e9dc4 Compare April 8, 2026 14:42
@renovate renovate Bot force-pushed the renovate/dayjs-1.x-lockfile branch from 30e9dc4 to 95c800b Compare April 29, 2026 11:53
Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review (automation): PR #3699

Scope: Diff updates web/package-lock.json only—dayjs 1.11.191.11.20 with matching npm resolved URL and Subresource Integrity hash.

Findings: No medium, high, or critical issues identified in this change.

  • Application security: No added or modified application code; no new attacker-controlled sinks, auth paths, or escaping surfaces introduced by the diff.
  • Supply chain: Same official registry artifact pattern (registry.npmjs.org); integrity field updated for the new tarball, which supports verification on install.
  • Advisory check: Public databases (e.g. Snyk) list no direct CVEs for dayjs@1.11.20; release notes describe bug fixes (locale / updateLocale merge behavior), not security advisories.

Conclusion: No high-confidence vulnerability introduced or exposed by this PR. Prior automation assessment threads are cleared in favor of this review.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants