Skip to content

chore(deps): bump @types/node from 20.19.35 to 25.9.3 in /web - #16

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/types/node-25.9.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/types/node-25.9.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 3, 2026

Copy link
Copy Markdown
Contributor

Bumps @types/node from 20.19.35 to 25.9.3.

Commits

@dependabot @github

dependabot Bot commented on behalf of github Jun 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from acamarata as a code owner June 3, 2026 04:51
@vercel

vercel Bot commented Jun 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
islamwiki Ready Ready Preview, Comment Jun 13, 2026 2:42pm
ummat-islamwiki Ready Ready Preview, Comment Jun 13, 2026 2:42pm

Request Review

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 5 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later
vitest CRITICAL 1120011 Upgrade to version 4.1.0 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@dependabot dependabot Bot changed the title chore(deps): bump @types/node from 20.19.35 to 25.9.1 in /web chore(deps): bump @types/node from 20.19.35 to 25.9.2 in /web Jun 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/types/node-25.9.1 branch from 4e7c67b to 5be35b9 Compare June 9, 2026 22:59
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 20.19.35 to 25.9.3.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.9.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump @types/node from 20.19.35 to 25.9.2 in /web chore(deps): bump @types/node from 20.19.35 to 25.9.3 in /web Jun 13, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/types/node-25.9.1 branch from 5be35b9 to a228665 Compare June 13, 2026 14:39
@dependabot @github

dependabot Bot commented on behalf of github Jun 24, 2026

Copy link
Copy Markdown
Contributor Author

Looks like @types/node is no longer a dependency, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 24, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/web/types/node-25.9.1 branch June 24, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants