Skip to content

chore: hourcekeeping, bump all (dev) deps#200

Merged
JounQin merged 2 commits intomainfrom
chore/housekeeping
Mar 19, 2025
Merged

chore: hourcekeeping, bump all (dev) deps#200
JounQin merged 2 commits intomainfrom
chore/housekeeping

Conversation

@JounQin
Copy link
Copy Markdown
Member

@JounQin JounQin commented Mar 19, 2025

No description provided.

@changeset-bot
Copy link
Copy Markdown

changeset-bot bot commented Mar 19, 2025

⚠️ No Changeset found

Latest commit: 42cb886

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@codesandbox-ci
Copy link
Copy Markdown

codesandbox-ci bot commented Mar 19, 2025

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 19, 2025

Report too large to display inline

View full report↗︎

@codecov
Copy link
Copy Markdown

codecov bot commented Mar 19, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 100.00%. Comparing base (b1d5004) to head (42cb886).
Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff            @@
##              main      #200   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            1         1           
  Lines          218       219    +1     
  Branches       105       104    -1     
=========================================
+ Hits           218       219    +1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread test/fixtures/yarn-pnp/.pnp.cjs Fixed
Comment thread test/fixtures/yarn-pnp/.pnp.cjs Fixed
@JounQin JounQin force-pushed the chore/housekeeping branch from cc7fba1 to b56795c Compare March 19, 2025 15:27
@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new bot commented Mar 19, 2025

Open in Stackblitz

npm i https://pkg.pr.new/un-ts/synckit@200

commit: 42cb886

@JounQin
Copy link
Copy Markdown
Member Author

JounQin commented Mar 19, 2025

image

https://github.com/un-ts/synckit/actions/runs/13950404720/job/39048154153?pr=200

cc @fisker

@fisker
Copy link
Copy Markdown
Contributor

fisker commented Mar 19, 2025

Passed?

@fisker
Copy link
Copy Markdown
Contributor

fisker commented Mar 19, 2025

Ran on Windows/Linux several times, can't reproduce.

@JounQin JounQin force-pushed the chore/housekeeping branch from f65ee08 to ed81fa6 Compare March 19, 2025 16:02
@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 19, 2025

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Protestware or potentially unwanted behavior npm/es5-ext@0.10.64
  • Note: The script attempts to run a local post-install script, which could potentially contain malicious code. The error handling suggests that it is designed to fail silently, which is a common tactic in malicious scripts.
⚠︎

View full report↗︎

Next steps

What is protestware?

This package is a joke, parody, or includes undocumented or hidden behavior unrelated to its primary function.

Consider that consuming this package may come along with functionality unrelated to its primary purpose.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/es5-ext@0.10.64

@JounQin
Copy link
Copy Markdown
Member Author

JounQin commented Mar 19, 2025

Passed?

I enabled continue-on-error: true.

@JounQin JounQin force-pushed the chore/housekeeping branch from ed81fa6 to 42cb886 Compare March 19, 2025 16:13
@fisker
Copy link
Copy Markdown
Contributor

fisker commented Mar 19, 2025

@JounQin JounQin enabled auto-merge (squash) March 19, 2025 16:17
@JounQin JounQin merged commit 6ec33e2 into main Mar 19, 2025
34 of 35 checks passed
@JounQin JounQin deleted the chore/housekeeping branch March 19, 2025 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants