Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): lock file maintenance node dependencies #1809

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

ggrossetie
Copy link
Member

@ggrossetie ggrossetie commented Nov 21, 2024

This PR contains the following updates:

Package Type Update Change
lockFileMaintenance All locks refreshed
mermaid devDependencies patch 11.4.0 -> 11.4.1
node (source) volta patch 20.18.0 -> 20.18.2
bpmn-js dependencies minor 18.0.0 -> 18.2.0
nomnoml (source) dependencies minor 1.6.2 -> 1.7.0
pino (source) dependencies minor 9.5.0 -> 9.6.0
vega dependencies minor 5.30.0 -> 5.31.0
vega-lite (source) dependencies minor 5.21.0 -> 5.23.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Release Notes

mermaid-js/mermaid (mermaid)

v11.4.1

Compare Source

Patch Changes
  • #​6059 01b5079 Thanks @​knsv! - fix: Kanban diagrams will not render when adding a number as ticket id or assigned for a task

  • #​6038 1388662 Thanks @​knsv! - fix: Intersection calculations for tilted cylinder/DAS when using handdrawn look. Some random seeds could cause the calculations to break.

  • #​6079 fe3cffb Thanks @​aloisklink! - Bump dompurify to ^3.2.1. This removes the need for @types/dompurify.

nodejs/node (node)

v20.18.2: 2025-01-21, Version 20.18.2 'Iron' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2025-23083 - throw on InternalWorker use when permission model is enabled (High)
  • CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium)
  • CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)

Dependency update:

  • CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)
Commits

v20.18.1: 2024-11-20, Version 20.18.1 'Iron' (LTS), @​marco-ippolito

Compare Source

Notable Changes
Commits
bpmn-io/bpmn-js (bpmn-js)

v18.2.0

Compare Source

  • FEAT: add ad-hoc subprocess option to replace menu (#​2276)

v18.1.2

Compare Source

v18.1.1

Compare Source

v18.1.0

Compare Source

skanaar/nomnoml (nomnoml)

v1.7.0

Compare Source

  • Add data-compartment attribute to SVG output for identifying the compartment index when building interactivity.

v1.6.3

Compare Source

  • Fix bug when running nomnoml-cli with input files in the same directory.
pinojs/pino (pino)

v9.6.0

Compare Source

What's Changed
New Contributors

Full Changelog: pinojs/pino@v9.5.0...v9.6.0

vega/vega (vega)

v5.31.0

Compare Source

changes since v5.30.0

vega-utils

  • use Object.hasOwn instead of Object.prototype.hasOwnProperty (via #​3951). (Thanks @​domoritz!)

vega-parser

vega-functions

vega-selections

monorepo

docs

vega/vega-lite (vega-lite)

v5.23.0

Compare Source

Bug Fixes
Features

v5.22.0

Compare Source


Configuration

📅 Schedule: Branch creation - "before 4am on monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@ggrossetie ggrossetie added the 🔗 dependencies Pull requests that update a dependency file label Nov 21, 2024
@ggrossetie ggrossetie changed the title chore(deps): update dependency bpmn-js to v18.1.0 chore(deps): update dependency bpmn-js to v18.1.1 Nov 22, 2024
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch 2 times, most recently from 0a4cd8c to 9daa4dd Compare November 28, 2024 02:33
@ggrossetie ggrossetie changed the title chore(deps): update dependency bpmn-js to v18.1.1 chore(deps): update node dependencies Nov 28, 2024
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch 2 times, most recently from c9698da to 4cf7b23 Compare December 4, 2024 02:34
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch 2 times, most recently from f4b03dc to eb8dfb2 Compare December 15, 2024 02:36
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch from eb8dfb2 to 3037716 Compare December 21, 2024 02:27
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch 4 times, most recently from 265741a to f7ac7b2 Compare January 27, 2025 17:09
@ggrossetie ggrossetie changed the title chore(deps): update node dependencies chore(deps): lock file maintenance node dependencies Jan 27, 2025
@ggrossetie ggrossetie force-pushed the renovate/node-dependencies branch from f7ac7b2 to 11078c5 Compare January 27, 2025 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🔗 dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant