fix(deps): update all non-major dependencies - #5566
Conversation
|
Size Report 1Affected ProductsNo changes between base commit (6a02778) and merge commit (0747f3e).Test Logs |
Size Analysis Report 1Affected ProductsNo changes between base commit (6a02778) and merge commit (0747f3e).Test Logs |
bf50472 to
d526749
Compare
c2979ca to
6cf7147
Compare
99ceda6 to
5d1f27e
Compare
|
@dwyfrequency either make a copy of this PR and try to remove problematic PRs or do a blank branch and one by one add in updates |
Changeset File Check ✅
|
| @@ -25,7 +25,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
| @@ -26,7 +26,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
| @@ -26,7 +26,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
| @@ -26,7 +26,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
| "@rushstack/node-core-library": "5.19.1", | ||
| "@rushstack/ts-command-line": "4.23.3", | ||
| "@rushstack/node-core-library": "5.23.1", | ||
| "@rushstack/ts-command-line": "4.23.7", |
There was a problem hiding this comment.
The following vulnerability impacts ajv versions <5.3.3: CVE-2025-69873.
It can be remediated by updating to version 5.3.3 or higher.
Dependency Tree
@rushstack/ts-command-line@4.23.7
└── @rushstack/terminal@0.15.2
└── @rushstack/node-core-library@5.13.0
├── ajv-formats@3.0.1
│ └── ajv@8.13.0
└── ajv@8.13.0
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| "@rushstack/ts-command-line": "4.23.7", | |
| "@rushstack/ts-command-line": "5.3.3", |
Vertex AI Mock Responses Check
|
This PR contains the following updates:
0.5.0→0.7.02.27.12→2.31.10.6.0→0.8.0~1.9.0→~1.14.0^0.7.8→^0.8.016.0.0→16.0.316.0.0→16.0.36.0.2→6.0.35.19.1→5.24.04.23.3→4.23.74.17.21→4.17.258.2.10→8.2.130.14.9→0.14.1018.19.83→18.19.13018.19.83→18.19.13017.0.33→17.0.35v5.6.0→v5.7.02.8.5→2.8.64.1.0→4.4.02.31.0→2.32.012.17.1→12.18.015.26.0→15.28.18.2.6→8.2.71.2.1→1.3.010.0.0→10.0.14.57.2→4.68.11.1.6→1.1.71.55.1→1.62.13.9.4→3.9.64.62.2→4.62.54.62.2→4.62.54.30.0→4.47.07.7.1→7.8.54.1.3→4.5.05.37.0→5.50.05.38.1→5.50.010.0.4→10.2.10.2.8→0.2.95.104.1→5.109.25.104.1→5.109.217.7.2→17.7.317.7.2→17.7.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
changesets/changesets (@changesets/changelog-github)
v0.7.0Compare Source
Minor Changes
94578cfThanks @Kauhsa! - AddeddisableThanksoptionv0.6.0Compare Source
Minor Changes
fd0bc2eThanks @mixelburg! - Linkify issue references in changelog entries.Patch Changes
#1810
27fd8f4Thanks @hirasso! - Replace deprecatedString.prototype.trimRightwithString.prototype.trimEndUpdated dependencies [
d4b8ad8,e462d89]:v0.5.2Compare Source
Patch Changes
#1783
398b3feThanks @mrginglymus! - RespectGITHUB_SERVER_URLenvironment variable when constructing URLsUpdated dependencies [
398b3fe]:v0.5.1Compare Source
Patch Changes
84a4a1b]:changesets/changesets (@changesets/cli)
v2.31.1Compare Source
Patch Changes
15cf592Thanks @ingvaldlorentzen! - Fixed already-published version detection with npm 12, which always wraps successfulnpm info --jsonoutput in an array. The unwrapped output madechangeset publishtreat every package as unpublished and fail attempting to republish existing versions.v2.31.0Compare Source
Minor Changes
#1889
96ca062Thanks @mixelburg! - Error on unsupported flags for individual CLI commands and print the matching command usage to make mistakes easier to spot.#1873
42943b7Thanks @mixelburg! - Respond to--helpon all subcommands. Previously,--helpwas only handled when it was the sole argument; passing it alongside a subcommand (e.g.changeset version --help) would silently execute the command instead. Now--helpalways exits early and prints per-command usage when a known subcommand is provided, or the general help text otherwise.Patch Changes
d2121dcThanks @Andarist! - Fix npm auth for path-based registries during publish by preserving configured registry URLs instead of normalizing them.#1888
036fdd4Thanks @mixelburg! - Fix severalchangeset versionissues with workspace protocol dependencies. Valid explicitworkspace:ranges and aliases are no longer rewritten unnecessarily, and workspace path references are handled correctly during versioning.#1903
5c4731fThanks @Andarist! - Gracefully handle stalenpm infodata leading to duplicate publish attempts.#1867
f61e716Thanks @Andarist! - Improved detection forpublishedstate of prerelease-only packages withoutlatestdist-tag on GitHub Packages registry.Updated dependencies [
036fdd4,036fdd4,036fdd4]:v2.30.0Compare Source
Minor Changes
#1840
057cca2Thanks @wotan-allfather! - Add--sinceflag toaddcommandThe
addcommand now supports a--sinceflag that allows you to specify which branch, tag, or git ref to use when detecting changed packages. This is useful for gitflow workflows where you have multiple target branches and thebaseBranchconfig option doesn't cover all use cases.Example:
changeset add --since=developIf not provided, the command falls back to the
baseBranchvalue in your.changeset/config.json.#1845
2b4a66aThanks @Andarist! - Delegate OTP prompting to the package manager instead of handling it in-process. This allows Changesets to use the package manager's native web auth support.#1774
667fe5aThanks @bluwy! - Support importing customcommitoption ES module. Previously, it usedrequire()which only worked for CJS modules, however now it usesimport()which supports both CJS and ES modules.#1839
73b1809Thanks @leochiu-a! - Add a--message(-m) flag tochangeset add(and defaultchangeset) so the changeset summary can be provided from the command line. When--messageis present, the summary prompt is skipped while the final confirmation step is kept.#1806
0e8e01eThanks @luisadame! - Changeset CLI can now be run from the nested directories in the project, where the.changesetdirectory has to be found in one of the parent directoriesPatch Changes
#1849
9dc3230Thanks @Andarist! - Compute the terminal's size lazily to avoid spurious stderr output in non-interactive mode#1857
2a73025Thanks @mixelburg! - Fix confusing prompt labels when entering changeset summary after external editor fallback#1842
6df3a5eThanks @RodrigoHamuy! - Allow private packages to depend on skipped packages without requiring them to also be skipped. Private packages are not published to npm, so it is safe for them to have dependencies on ignored or unversioned packages.#1776
503fcaaThanks @bluwy! - Support absolute paths inchangeset status --output <path>Updated dependencies [
667fe5a,1772598,b6f4c74,6df3a5e,6df3a5e,27fd8f4]:v2.29.8Compare Source
Patch Changes
#1437
aa68d54Thanks @with-heart! - Tweaked a hint text printed when one confirms an empty set of packages to be releasedUpdated dependencies [
cc28222,e520bf5,13dace8]:v2.29.7Compare Source
Patch Changes
957f24e]:v2.29.6Compare Source
Patch Changes
a3563b0Thanks @benmccann! - Switch to maintained fork ofexternal-editorv2.29.5Compare Source
Patch Changes
#1693
6352819Thanks @Andarist! - Fixed an issue withworkspace:^andworkspace:~dependency ranges not being semantically treated as, respectively,^CURRENT_VERSIONand~CURRENT_VERSION. This led to dependent packages being, at times, bumped too often when their dependencies with those ranges were bumped.Updated dependencies [
6352819]:v2.29.4Compare Source
Patch Changes
#1668
65d6632Thanks @Andarist! - Fixed a crash in pre mode when trying to version private packages when tagging for private package is disabledUpdated dependencies [
65d6632]:v2.29.3Compare Source
Patch Changes
#1589
de8bebcThanks @remorses, @vzt7! - Fixed a crash in prerelease mode when a package misses the version field in itspackage.json#1619
c1e8a78Thanks @manucorporat! - Support../inpublishConfig.directorywhen publishing packagesUpdated dependencies [
de8bebc]:v2.29.2Compare Source
Patch Changes
#1636
f73f84aThanks @Netail! - Correctly resolve new changesets withsinceoption when the.changesetdirectory is not directly in the git rootUpdated dependencies [
f73f84a]:v2.29.1Compare Source
Patch Changes
#1620
b15e629Thanks @Netail! - Correctly fetch new changesets with since if the git option diff.relative has been set to trueUpdated dependencies [
b15e629]:v2.29.0Compare Source
Minor Changes
29f34a3Thanks @JounQin! - Support scoped registries configured usingpackage.json#publishConfigv2.28.1Compare Source
Patch Changes
b9df596]:v2.28.0Compare Source
Minor Changes
84a4a1bThanks @bennypowers! - Added a new config option to opt-out from formatting with Prettier usingprettier: false.Patch Changes
84a4a1b,84a4a1b]:changesets/changesets (@changesets/get-github-info)
v0.8.0Compare Source
Minor Changes
e462d89Thanks @jdeniau! - Add scopes automatically in the GitHub new token link in the printed error messagePatch Changes
d4b8ad8Thanks @bluwy! - Improve error messages when fail to fetch data from GitHubv0.7.0Compare Source
Minor Changes
#1783
398b3feThanks @mrginglymus! - Support GitHub URL environment variables@changesets/get-github-infowill now respect environment variables set by GitHub Actions, specifically:GITHUB_GRAPHQL_URLGITHUB_SERVER_URLThis means GitHub Enterprise Server will be supported without any additional configuration or patching.
grpc/grpc-node (@grpc/grpc-js)
v1.14.4: @grpc/grpc-js 1.14.4Compare Source
v1.14.3: @grpc/grpc-js 1.14.3Compare Source
v1.14.2: @grpc/grpc-js 1.14.2Compare Source
v1.14.1: @grpc/grpc-js 1.14.1Compare Source
v1.14.0: @grpc/grpc-js 1.14.0Compare Source
Changelog
getAuthContextmethod to client and server call classes (more details can be found in gRFC L35) (#2920)getConnectionInfomethod to theServerInterceptingCallclass (#2922)weighted_round_robinload balancing policy (#2998)round_robinLB policy (#2979)Experimental API Changes
Added:
CHANNEL_ARGS_CONFIG_SELECTOR_KEYStatusOr<T>CallStreamstatusOrFromValuestatusOrFromErrorModified:
ResolverListener#onSuccessfulResolutionnow has the signature(endpointList: StatusOr<Endpoint[]>, attributes: { [key: string]: unknown }, serviceConfig: StatusOr<ServiceConfig> | null, resolutionNote: string): booleanLoadBalancer#updateAddressListnow has the signature `updateAddressList(endpointList: StatusOr<Endpoint[]>,lbConfig: TypedLoadBalancingConfig, channelOptions: ChannelOptions, resolutionNote: string): booleanv1.13.5: @grpc/grpc-js 1.13.5Compare Source
v1.13.4: @grpc/grpc-js 1.13.4Compare Source
ssl_target_name_overrideoption (#2956)v1.13.3: @grpc/grpc-js 1.13.3Compare Source
http2.getDefaultSettings(#2937)v1.13.2: @grpc/grpc-js 1.13.2Compare Source
v1.13.1: @grpc/grpc-js 1.13.1Compare Source
rejectUnauthorizedchannel credentials option to be handled incorrectly (#2926)retryThrottlingconfig was set (#2927)v1.13.0: @grpc/grpc-js 1.13.0Compare Source
Changelog
grpc-node.flow_control_windowto control HTTP/2 flow control window size (#2864 contributed by @rickihastings)no_proxyenvironment variable (#2876 contributed by @melkouri)sendMetadatamethods to not be called if the server interceptor did not explicitly send metadata (#2897)Experimental API changes
Added:
SecureConnectorSecureConnectResultSUBCHANNEL_ARGS_EXCLUDE_KEY_PREFIXServer#experimentalRegisterListenerToChannelzprotected methodServerexperimentalUnregisterListenerFromChannelzprotected methodServer#experimentalCreateConnectionInjectorWithChannelzRefprotected methodModified:
LoadBalancer: Removed theChannelCredentialsconstructor argumentLoadBalancer: Removed theChannelOptionsconstructor argumentLoadBalancer#updateAddressList: Replaced theattributesargument with one of typeChannelOptions.ChannelControlHelper#createSubchannel: Removed theChannelCredentialsargumentLeafLoadBalancer: Removed theChannelCredentialsconstructor argumentv1.12.7: @grpc/grpc-js 1.12.7Compare Source
v1.12.6Compare Source
v1.12.5: @grpc/grpc-js 1.12.5Compare Source
v1.12.4: @grpc/grpc-js 1.12.4Compare Source
v1.12.3: @grpc/grpc-js 1.12.3Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.