Skip to content

chore(deps): lock file maintenance#830

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance
Open

chore(deps): lock file maintenance#830
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Jun 3, 2024

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from e01e7e8 to 857348f Compare June 28, 2024 22:35
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 857348f to b7b6d0d Compare July 31, 2024 02:06
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from b7b6d0d to 95c2054 Compare September 24, 2024 18:25
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Sep 24, 2024

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​types/​node@​20.12.12 ⏵ 20.19.4110010081 +196 +1100
Updatedgem/​jekyll@​4.3.3 ⏵ 4.3.484 +1100100100100
Updatedgem/​webrick@​1.8.2 ⏵ 1.9.293100100100100
Updatedgem/​github-linguist@​7.29.0 ⏵ 7.30.095 -1100100100100
Updatedgem/​dotenv@​3.1.2 ⏵ 3.2.096100100100100
Updatedgem/​rb-inotify@​0.10.1 ⏵ 0.11.198 +1100100100100

View full report

@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from a9b708b to 23283a7 Compare August 13, 2025 17:16
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 23283a7 to 158b822 Compare August 19, 2025 14:35
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 158b822 to dd98156 Compare August 31, 2025 10:39
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from dd98156 to 33f2ecf Compare September 25, 2025 19:06
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 33f2ecf to aa123fc Compare October 25, 2025 04:00
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from aa123fc to cb1bd18 Compare November 10, 2025 13:38
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from cb1bd18 to 45eff06 Compare November 18, 2025 12:00
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 45eff06 to a84d7fd Compare December 3, 2025 19:40
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from a84d7fd to 0831349 Compare December 31, 2025 17:50
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 0831349 to 4832aac Compare January 8, 2026 20:34
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Jan 8, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/eslint-plugin-import@2.29.1npm/es-abstract@1.24.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-abstract@1.24.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm string.prototype.trimend is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/eslint-plugin-import@2.29.1npm/string.prototype.trimend@1.0.9

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/string.prototype.trimend@1.0.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm ts-api-utils is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@typescript-eslint/eslint-plugin@7.9.0npm/@typescript-eslint/parser@7.9.0npm/ts-api-utils@1.4.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ts-api-utils@1.4.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm ts-api-utils is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@typescript-eslint/eslint-plugin@7.9.0npm/@typescript-eslint/parser@7.9.0npm/ts-api-utils@1.4.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ts-api-utils@1.4.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from b4648f6 to b9d352e Compare January 23, 2026 16:55
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from b9d352e to afdb0e8 Compare February 2, 2026 21:04
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 864dba7 to dfa8dc6 Compare February 17, 2026 15:42
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from dfa8dc6 to a3af84c Compare March 5, 2026 18:05
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from a3af84c to b79b015 Compare March 13, 2026 19:02
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from b79b015 to bf2d272 Compare April 1, 2026 18:05
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from bf2d272 to be0e738 Compare April 8, 2026 19:03
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from be0e738 to ca5c682 Compare April 29, 2026 11:04
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from ca5c682 to a8a0a27 Compare May 12, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants