Skip to content

chore(deps): bump pino from 9.14.0 to 10.3.1#9

Merged
cryptoxdog merged 5 commits into
mainfrom
dependabot/npm_and_yarn/pino-10.3.1
Jul 23, 2026
Merged

chore(deps): bump pino from 9.14.0 to 10.3.1#9
cryptoxdog merged 5 commits into
mainfrom
dependabot/npm_and_yarn/pino-10.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown

Bumps pino from 9.14.0 to 10.3.1.

Release notes

Sourced from pino's releases.

v10.3.1

What's Changed

Full Changelog: pinojs/pino@v10.3.0...v10.3.1

v10.3.0

What's Changed

Full Changelog: pinojs/pino@v10.2.1...v10.3.0

v10.2.1

What's Changed

Full Changelog: pinojs/pino@v10.2.0...v10.2.1

v10.2.0

What's Changed

New Contributors

Full Changelog: pinojs/pino@v10.1.1...v10.2.0

v10.1.1

What's Changed

... (truncated)

Commits
  • 6b34498 Bumped v10.3.1
  • f1203e6 fix(transport): sanitize invalid NODE_OPTIONS preloads for workers (#2391)
  • 6a8e598 docs: clarify transport level filtering behavior (#2390)
  • 49a4807 Merge branch 'main' of github.com:pinojs/pino
  • 960bbbb build(deps-dev): bump eslint-plugin-n from 17.23.1 to 17.23.2 (#2386)
  • e2a5b4a build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#2385)
  • 04859e2 chore: update gitignore for ai assistant files
  • d6adf03 Bumped v10.3.0
  • 06d55b1 feat: set worker thread name for transport identification (#2380)
  • a728702 fix: fix multistream().clone() return type (#2377)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, npm. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@cryptoxdog
cryptoxdog force-pushed the dependabot/npm_and_yarn/pino-10.3.1 branch from 13062ce to 7362b37 Compare July 22, 2026 02:25
Comment thread scripts/verify-package.mjs Fixed
@cryptoxdog
cryptoxdog force-pushed the dependabot/npm_and_yarn/pino-10.3.1 branch 3 times, most recently from 66aaa4f to 7e921cb Compare July 22, 2026 02:52
Transplanted-From: 7653e0e (remediation pack 2026-07-20)
@cryptoxdog
cryptoxdog force-pushed the dependabot/npm_and_yarn/pino-10.3.1 branch from 7e921cb to 074af66 Compare July 22, 2026 03:03
cryptoxdog and others added 3 commits July 22, 2026 20:33
- pin pip/semgrep versions in l9-analysis.yml (githubactions:S8544)
- add initial value to consensus reduce() (typescript:S6959)
- use explicit comparators for sorts (typescript:S2871)
- invoke npm without PATH lookup in verify-package.mjs (javascript:S4036)
- commit package-lock.json and restore npm ci (githubactions:S8543, text:S8564)
Resolve the npm CLI script to an absolute path (npm_execpath or the npm
installation shipped alongside the Node binary) and always spawn it via
process.execPath. Eliminates the bare-name 'npm' spawn flagged by Sonar
javascript:S4036 (OS command search path vulnerability).
@cryptoxdog
cryptoxdog enabled auto-merge July 23, 2026 01:20
@cryptoxdog
cryptoxdog force-pushed the dependabot/npm_and_yarn/pino-10.3.1 branch from 7e5131e to ce54a0f Compare July 23, 2026 01:26
@cryptoxdog
cryptoxdog merged commit 1fb3503 into main Jul 23, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/pino-10.3.1 branch July 23, 2026 01:27
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant