Skip to content

fix(deps): update all dependencies#64

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

fix(deps): update all dependencies#64
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 1, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@1stg/lib-config (source) ^10.3.0^13.0.0 age confidence devDependencies major
@changesets/changelog-github (source) ^0.4.8^0.7.0 age confidence devDependencies minor
@types/node (source) ^18.7.18^24.0.0 age confidence devDependencies major
@vitest/coverage-istanbul (source) ^0.34.6^4.0.0 age confidence devDependencies major
actions/checkout v4v6 age confidence action major
actions/setup-node v4v6 age confidence action major
codecov/codecov-action v3v6 age confidence action major
commander ^9.4.1^14.0.0 age confidence dependencies major
github/codeql-action v2v4 age confidence action major
hast-util-is-element ^2.1.3^3.0.0 age confidence dependencies major
pnpm (source) 7.33.611.1.3 age confidence packageManager major
pnpm/action-setup v2v6 age confidence action major
rehype-format ^4.0.1^5.0.0 age confidence dependencies major
rehype-parse ^8.0.5^9.0.0 age confidence dependencies major
rehype-preset-minify (source) ^6.0.0^7.0.0 age confidence dependencies major
rehype-stringify ^9.0.4^10.0.0 age confidence dependencies major
typescript (source) ^4.9.5^6.0.0 age confidence devDependencies major
unified (source) ^10.1.2^11.0.0 age confidence dependencies major
unified-stream ^2.0.0^3.0.0 age confidence dependencies major
unist-util-remove ^3.1.1^4.0.0 age confidence dependencies major
unist-util-visit ^4.1.1^5.0.0 age confidence dependencies major
unplugin-auto-import ^0.16.7^21.0.0 age confidence devDependencies major
vitest (source) ^0.34.6^4.0.0 age confidence devDependencies major

Release Notes

1stG/configs (@​1stg/lib-config)

v13.0.1

Compare Source

Patch Changes

v13.0.0

Compare Source

Major Changes
Patch Changes

v12.0.1

Compare Source

Patch Changes

v12.0.0

Compare Source

Major Changes
Patch Changes

v11.1.0

Compare Source

Minor Changes
Patch Changes

v11.0.1

Compare Source

Patch Changes

v11.0.0

Compare Source

Major Changes
  • d03df9f Thanks @​JounQin! - feat!: migrate to eslint-community packages, bump stylelint
Patch Changes
changesets/changesets (@​changesets/changelog-github)

v0.7.0

Compare Source

Minor Changes

v0.6.0

Compare Source

Minor Changes
Patch Changes

v0.5.2

Compare Source

v0.5.1

Compare Source

Patch Changes

v0.5.0

Compare Source

Minor Changes
  • #​1185 a971652 Thanks @​Andarist! - package.json#exports have been added to limit what (and how) code might be imported from the package.
Patch Changes
vitest-dev/vitest (@​vitest/coverage-istanbul)

v4.1.7

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v4.1.6

Compare Source

   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub

v4.1.5

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.4

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.3

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.2

Compare Source

This release bumps Vitest's flatted version and removes version pinning to resolve flatted's CVE related issues (#​9975).

   🐞 Bug Fixes
    View changes on GitHub

v4.1.1

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.0

Compare Source

Vitest 4.1 is out!

This release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our blog post.

   🚀 Features
   🐞 Bug Fixes

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 1, 2025

⚠️ No Changeset found

Latest commit: e10736a

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Apr 1, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 1, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@6.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from d87208d to 65e1c41 Compare April 7, 2025 17:08
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 8a196c2 to bed0aeb Compare April 14, 2025 16:06
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 9e308a5 to 1f57ff0 Compare April 28, 2025 02:32
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 50fa6b0 to 87b6a7c Compare May 18, 2025 06:14
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 9abeba5 to 1c5b652 Compare June 8, 2025 17:56
@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from 1f873b2 to 3230f39 Compare June 26, 2025 18:00
@renovate renovate Bot force-pushed the renovate/all branch from 3230f39 to 62416f3 Compare July 9, 2025 16:58
@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from 02b9c1f to 1c3c704 Compare July 28, 2025 12:34
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from 6f7e632 to b9b3e47 Compare August 5, 2025 09:42
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from d825218 to 5aa1136 Compare August 10, 2025 13:25
@renovate renovate Bot force-pushed the renovate/all branch 4 times, most recently from f335f2e to 11e8f30 Compare September 12, 2025 08:12
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from f1924d3 to fb2f5c8 Compare September 18, 2025 02:10
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from 0128fe9 to ab43908 Compare September 26, 2025 18:04
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from 1685f72 to 7bf0a12 Compare October 6, 2025 13:47
@renovate renovate Bot force-pushed the renovate/all branch 9 times, most recently from 0a4f4aa to 24d6010 Compare October 14, 2025 14:53
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Mar 20, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​node@​25.9.1 ⏵ 24.12.4100 +110081 +196100
Updated@​vitest/​coverage-istanbul@​4.1.7 ⏵ 4.1.699 +11008299100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants