Skip to content

chore(deps): update dependency nanoid@<3.3.18 to v4 - #1133

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/nanoid-3.3.18-4.x
Open

chore(deps): update dependency nanoid@<3.3.18 to v4#1133
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/nanoid-3.3.18-4.x

Conversation

@renovate

@renovate renovate Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
nanoid@<3.3.18 ^3.3.18^4.0.2 age confidence

Release Notes

ai/nanoid (nanoid@<3.3.18)

v4.0.2

Compare Source

  • Added link to Github Sponsors.

v4.0.1

Compare Source

v4.0.0

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "after 10:00 before 19:00 every weekday except after 13:00 before 14:00"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

BREAKING CHANGE: updated dependencies to major versions
@renovate renovate Bot added the c: dependencies Pull requests that adds/updates a dependency label Aug 20, 2026
@renovate
renovate Bot requested a review from prisis as a code owner August 20, 2026 08:36
@renovate renovate Bot added the c: dependencies Pull requests that adds/updates a dependency label Aug 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Vulnerabilities

pnpm-lock.yaml

NameVersionVulnerabilitySeverity
nanoid4.0.2nanoid: custom generators can loop indefinitely when size is zerohigh
nanoid: non-secure generators can loop indefinitely with negative sizehigh
Predictable results in nanoid generation when given non-integer valuesmoderate
Only included vulnerabilities with severity moderate or higher.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/nanoid 4.0.2 🟢 6.5
Details
CheckScoreReason
Code-Review⚠️ 0Found 1/30 approved changesets -- score normalized to 0
Maintained🟢 1030 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 10all dependencies are pinned
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
SAST🟢 6SAST tool is not run on all commits -- score normalized to 6
Branch-Protection⚠️ 0branch protection not enabled on development/release branches

Scanned Files

  • pnpm-lock.yaml

@github-actions

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c: dependencies Pull requests that adds/updates a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants