Skip to content

Pin dependencies#11

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/typescript
Open

Pin dependencies#11
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/typescript

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Oct 28, 2025

This PR contains the following updates:

Package Type Update Change
typescript (source) devDependencies pin ^5.5.3 -> 5.6.3
typescript (source) devDependencies pin ^5.5.3 -> 5.9.3

Add the preset :preserveSemverRanges to your config if you don't want to pin your dependencies.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Copy Markdown
Author

renovate Bot commented Oct 28, 2025

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package.json
Post-upgrade command 'npm audit fix --package-lock-only' has not been added to the allowed list in allowedCommands
File name: package.json
Post-upgrade command 'npm run lint:fix || true' has not been added to the allowed list in allowedCommands
File name: out/package/package.json
Post-upgrade command 'npm audit fix --package-lock-only' has not been added to the allowed list in allowedCommands
File name: out/package/package.json
Post-upgrade command 'npm run lint:fix || true' has not been added to the allowed list in allowedCommands
File name: out/package.json
Post-upgrade command 'npm audit fix --package-lock-only' has not been added to the allowed list in allowedCommands
File name: out/package.json
Post-upgrade command 'npm run lint:fix || true' has not been added to the allowed list in allowedCommands
File name: gurdip-portfolio-2.1.14.61555/package/package.json
Post-upgrade command 'npm audit fix --package-lock-only' has not been added to the allowed list in allowedCommands
File name: gurdip-portfolio-2.1.14.61555/package/package.json
Post-upgrade command 'npm run lint:fix || true' has not been added to the allowed list in allowedCommands
File name: gurdip-portfolio-2.1.14.61555/package/dist/package.json
Post-upgrade command 'npm audit fix --package-lock-only' has not been added to the allowed list in allowedCommands
File name: gurdip-portfolio-2.1.14.61555/package/dist/package.json
Post-upgrade command 'npm run lint:fix || true' has not been added to the allowed list in allowedCommands

@safedep
Copy link
Copy Markdown

safedep Bot commented Oct 28, 2025

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

Package Details
Package Malware Vulnerability Risky License Report
icon typescript @ 5.6.3
package-lock.json
ok icon
ok icon
ok icon
🔗

This report is generated by SafeDep Github App

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Oct 28, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch renovate/typescript

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate Bot force-pushed the renovate/typescript branch from 7a91ac1 to 6c873cb Compare October 29, 2025 03:52
@renovate renovate Bot changed the title chore(deps): pin dependency typescript to 5.6.3 chore(deps): pin dependencies Oct 29, 2025
@renovate renovate Bot force-pushed the renovate/typescript branch 4 times, most recently from 6c6b169 to a492aab Compare October 31, 2025 17:31
@renovate renovate Bot changed the title chore(deps): pin dependencies Pin dependencies Oct 31, 2025
@renovate renovate Bot force-pushed the renovate/typescript branch from a492aab to 3f4355b Compare November 2, 2025 11:49
@safedep
Copy link
Copy Markdown

safedep Bot commented Nov 2, 2025

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

Package Details
Package Malware Vulnerability Risky License Report
icon @types/node @ 22.0.2
package-lock.json
ok icon
ok icon
ok icon
🔗
icon typescript @ 5.6.3
package-lock.json
ok icon
ok icon
ok icon
🔗

This report is generated by SafeDep Github App

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants