chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates - #96
dependabot[bot] wants to merge 1 commit into
Conversation
…dates Bumps the npm_and_yarn group with 1 update in the / directory: [@faker-js/faker](https://github.com/faker-js/faker). Updates `@faker-js/faker` from 10.4.0 to 10.5.0 - [Release notes](https://github.com/faker-js/faker/releases) - [Changelog](https://github.com/faker-js/faker/blob/next/CHANGELOG.md) - [Commits](faker-js/faker@v10.4.0...v10.5.0) Updates `fast-uri` from 4.1.2 to 4.1.4 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v4.1.2...v4.1.4) --- updated-dependencies: - dependency-name: "@faker-js/faker" dependency-version: 10.5.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: fast-uri dependency-version: 4.1.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Manual review required. This Dependabot PR bumps a |
…t.io-parser/brace-expansion/postcss/fast-uri/ws) (#99) Adds/tightens pnpm overrides at the workspace root for six packages, clearing 15 high-severity Dependabot alerts: - fast-uri: floor raised 3.1.2 -> 4.1.3 (resolved 4.1.2 -> 4.1.4; already a transitive-only dep with no direct import, safe patch-equivalent bump) - engine.io >=6.6.7 (was 6.6.6), socket.io-parser >=4.2.7 (was 4.2.6) - brace-expansion >=5.0.9 (was 5.0.5), postcss >=8.5.18 (8.5.23 instance already satisfied it, 8.5.8 instance did not) - ws: two range-scoped overrides so the 7.x line resolves to >=7.5.11 and the 8.x line to >=8.21.0 without forcing a 7->8 major bump Deliberately NOT touched: - @faker-js/faker (alert #173): Dependabot's own PR #96 already bumps 10.4.0 -> 10.5.0 directly; not duplicating that diff here. - linkify-it (alerts #124/#130): hard-pinned at 3.0.3 by ansi-to-react, fix needs 5.0.2 (two-major jump on a dependency with no test coverage here) -- left for manual review, logged in the P6 residue register. Ticket: P6 DEPENDABOT-HIGH-SWEEP unit (nself PPI phase P6)
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
@dependabot rebase |
|
Looks like these dependencies are no longer updatable, so this is no longer needed. |
|
@dependabot rebase |
|
Looks like this PR is closed. If the branch still exists, you can re-open the PR and then use |
|
@dependabot recreate |
|
Looks like this PR is closed. If the branch still exists, you can re-open the PR and then use |
|
@dependabot recreate |
|
Looks like this PR is closed. If the branch still exists, you can re-open the PR and then use |
Bumps the npm_and_yarn group with 1 update in the / directory: @faker-js/faker.
Updates
@faker-js/fakerfrom 10.4.0 to 10.5.0Release notes
Sourced from @faker-js/faker's releases.
... (truncated)
Changelog
Sourced from @faker-js/faker's changelog.
... (truncated)
Commits
5fb3b2dchore(release): 10.5.0 (#3898)f89348fchore(deps): lock file maintenance (#3861)e157511chore(deps): pin dependencies (#3896)77dbfaechore(deps): update prettier to v3.8.4 (#3893)123193achore(deps): update pnpm/action-setup action to v6 (#3894)8244a24chore(deps): update devdependencies (#3871)68bc79achore(deps): update eslint (major) (#3875)e43b21bchore(deps): update all non-major dependencies (#3870)b6aca31chore(deps): update vitest (#3872)a7e8c4fchore(deps): update mcr.microsoft.com/devcontainers/typescript-node:24 docker...Updates
fast-urifrom 4.1.2 to 4.1.4Release notes
Sourced from fast-uri's releases.
Commits
a34ced2Bumped v4.1.4c3386a9fix: reject malformed IPv6 zone identifiers (#213)506b155Merge commit from fork820e847Merge commit from forke008152fix: treat unterminated bracket hosts as reg-names again (#214)4e99790Bumped v4.1.35a77ac7fix: never run IDN canonicalization on bracketed IP literalsc6a74bfMerge commit from fork3728465Merge commit from fork2642290Merge commit from forkDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.