Skip to content

chore(deps): bump pusher from 5.3.3 to 5.3.4#122

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pusher-5.3.4
Open

chore(deps): bump pusher from 5.3.3 to 5.3.4#122
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pusher-5.3.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps pusher from 5.3.3 to 5.3.4.

Release notes

Sourced from pusher's releases.

v5.3.4

5.3.4

  • [SECURITY] Redact the encryption master key value from config validation error messages (#239)
  • [FIXED] Update CI Node.js test matrix to 18/20/22 and fix gyp build failure (#237)
  • [CHANGED] Pin GitHub Actions to commit SHAs and bump actions/checkout, actions/setup-node, actions/stale, and softprops/action-gh-release
Changelog

Sourced from pusher's changelog.

5.3.4

  • [SECURITY] Redact the encryption master key value from config validation error messages (#239)
  • [FIXED] Update CI Node.js test matrix to 18/20/22 and fix gyp build failure (#237)
  • [CHANGED] Pin GitHub Actions to commit SHAs and bump actions/checkout, actions/setup-node, actions/stale, and softprops/action-gh-release
Commits
  • 076bc1f Merge pull request #240 from pusher/release-5.3.4
  • 1b869fb Bump to version 5.3.4
  • edcf90e Revert manual CHANGELOG edit; the release action generates it from the PR body
  • a3e5667 Update CHANGELOG for 5.3.4
  • be7cea3 Merge pull request #239 from pusher/security/redact-encryption-master-key-in-...
  • d2041b8 Redact encryption master key value from config validation error messages
  • 7492d8d Merge pull request #237 from pusher/fix/update-ci-node-versions
  • f98da60 Pin softprops/action-gh-release to commit SHA
  • f683d91 Bump actions/stale to v10 and softprops/action-gh-release to v3
  • 0274310 Bump actions/checkout and actions/setup-node to v6
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pusher](https://github.com/pusher/pusher-http-node) from 5.3.3 to 5.3.4.
- [Release notes](https://github.com/pusher/pusher-http-node/releases)
- [Changelog](https://github.com/pusher/pusher-http-node/blob/master/CHANGELOG.md)
- [Commits](pusher/pusher-http-node@v5.3.3...v5.3.4)

---
updated-dependencies:
- dependency-name: pusher
  dependency-version: 5.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 15, 2026
@dependabot dependabot Bot requested a review from leagames0221-sys as a code owner June 15, 2026 00:10
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 15, 2026
@vercel

vercel Bot commented Jun 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
craftstack-collab Ready Ready Preview, Comment Jun 15, 2026 12:12am
craftstack-knowledge Ready Ready Preview, Comment Jun 15, 2026 12:12am

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​pusher@​5.3.49910010089100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants