Bump the production-dependencies group across 1 directory with 6 updates#145
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the production-dependencies group across 1 directory with 6 updates#145dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Updates the requirements on [@commander-js/extra-typings](https://github.com/commander-js/extra-typings), [@napi-rs/keyring](https://github.com/Brooooooklyn/keyring-node), [commander](https://github.com/tj/commander.js), [make-fetch-happen](https://github.com/npm/make-fetch-happen), [smol-toml](https://github.com/squirrelchat/smol-toml) and [yaml](https://github.com/eemeli/yaml) to permit the latest version. Updates `@commander-js/extra-typings` from 14.0.0 to 15.0.0 - [Release notes](https://github.com/commander-js/extra-typings/releases) - [Changelog](https://github.com/commander-js/extra-typings/blob/main/CHANGELOG.md) - [Commits](commander-js/extra-typings@v14.0.0...v15.0.0) Updates `@napi-rs/keyring` to 1.3.0 - [Release notes](https://github.com/Brooooooklyn/keyring-node/releases) - [Commits](Brooooooklyn/keyring-node@v1.2.0...v1.3.0) Updates `commander` from 14.0.3 to 15.0.0 - [Release notes](https://github.com/tj/commander.js/releases) - [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md) - [Commits](tj/commander.js@v14.0.3...v15.0.0) Updates `make-fetch-happen` to 15.0.6 - [Release notes](https://github.com/npm/make-fetch-happen/releases) - [Changelog](https://github.com/npm/make-fetch-happen/blob/v15.0.6/CHANGELOG.md) - [Commits](npm/make-fetch-happen@v15.0.3...v15.0.6) Updates `smol-toml` to 1.6.1 - [Release notes](https://github.com/squirrelchat/smol-toml/releases) - [Commits](squirrelchat/smol-toml@v1.6.0...v1.6.1) Updates `yaml` to 2.9.0 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.8.2...v2.9.0) --- updated-dependencies: - dependency-name: "@commander-js/extra-typings" dependency-version: 15.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: "@napi-rs/keyring" dependency-version: 1.3.0 dependency-type: direct:production dependency-group: production-dependencies - dependency-name: commander dependency-version: 15.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: make-fetch-happen dependency-version: 15.0.6 dependency-type: direct:production dependency-group: production-dependencies - dependency-name: smol-toml dependency-version: 1.6.1 dependency-type: direct:production dependency-group: production-dependencies - dependency-name: yaml dependency-version: 2.9.0 dependency-type: direct:production dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
609d99d to
14ca509
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on @commander-js/extra-typings, @napi-rs/keyring, commander, make-fetch-happen, smol-toml and yaml to permit the latest version.
Updates
@commander-js/extra-typingsfrom 14.0.0 to 15.0.0Release notes
Sourced from @commander-js/extra-typings's releases.
Changelog
Sourced from @commander-js/extra-typings's changelog.
Commits
5a1af3dMerge develop to main for 15.0.04bed262Merge branch 'main' into develop73ad76dUpdate Commander dependency to 15.0.006f0b4fAdd Changelog entry for move to ESMb8f81f3Recognise negative then positive combo (#179)6d0ea59Switch to esm (#178)1c37944Pin GitHub actions with hash (#180)3df3727Revert "Recognise negative then positive combo"48fff8aRecognise negative then positive combo686c1f3Update docs and prepare for 15.0.0 (#177)Updates
@napi-rs/keyringto 1.3.0Release notes
Sourced from @napi-rs/keyring's releases.
Commits
e46be751.3.0da34399chore: bump up ava version to v8 (#122)477749echore: bump up Rust crate keyring to v4 (#121)e511bd2chore: bump up Yarn to v4.14.1 (#120)b759a1achore: upgrade Node version to 24 in publish CI (#119)ae5070achore: bump up cross-platform-actions/action action to v1 (#118)6b22fd2chore: bump up@oxc-node/coreversion to ^0.1.0 (#117)966a1bdchore: bump up typescript version to v6 (#116)d6611b0chore: bump up Yarn to v4.13.0 (#115)273bb8dchore: bump up ava version to v7 (#114)Updates
commanderfrom 14.0.3 to 15.0.0Release notes
Sourced from commander's releases.
... (truncated)
Changelog
Sourced from commander's changelog.
Commits
ba6d13dFix release dates in changelog (#2523)a752ed9Pin GitHub actions with hash (#2521)74d5dfeDrop EOL node 20 from test matrix, and add node 26 (#2520)6df9b68Update details for 15.0.0 release (#2519)01ce5d0Remove jest esm examples (#2517)d785d8bUpdate dependencies (#2518)9098b48Update dependencies (#2506)373f660Use node:util stripVTControlCharacters instead of own code (#2486)987f289Use simple match in test (to avoid warning about expensive regex) (#2485)0ea3bb3Update dependecies and lint (#2489)Updates
make-fetch-happento 15.0.6Release notes
Sourced from make-fetch-happen's releases.
Changelog
Sourced from make-fetch-happen's changelog.
... (truncated)
Commits
a5a170cchore: release 15.0.6 (#366)db5a15dfix: remove unused CI system badge84e50fbchore: add backport branch3370665fix: empty commit to force@npmcli/agentrelease update91d58dachore: release 15.0.5 (#344)321e370fix: url logging npm credentials5eba860deps:@npmcli/redact@4.0.04638d5cchore: release 15.0.4 (#341)57684bbdeps: add@gar/promise-retry@1.0.05bc5715deps: remove promise-retryUpdates
smol-tomlto 1.6.1Release notes
Sourced from smol-toml's releases.
Commits
072b64fchore: version bump19a5dc7chore: upgrade dependencies and actionsf286f87fix: don't use recursion in skipVoidUpdates
yamlto 2.9.0Release notes
Sourced from yaml's releases.
Commits
ddb21b02.9.0167365bdocs: Clarify that not all errors can be avoided6eca2a7fix: Avoid calling Array.prototype.push.apply() with large source array0543cd5fix(lexer): Avoid recursive calls that may exhaust the call stackccdf7432.8.4f625789fix: Disable alias resolution with maxAliasCount:0 (#677)e1a1a77fix: Handle invalid unicode escapesa163ea0style: Satify Prettierb2a5a6cfix: Apply minFractionDigits only to decimal strings (#676)93c951bchore: Bump JSR version to v2.8.3 (#673)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions