Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependencies #394

Merged
merged 1 commit into from
Feb 3, 2025

Conversation

tradeshift-renovate-bulk[bot]
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
@types/node (source) devDependencies minor 22.10.7 -> 22.13.0
eslint-plugin-github devDependencies patch 5.1.5 -> 5.1.7
node (source) patch 22.13.0 -> 22.13.1
semver dependencies minor 7.6.3 -> 7.7.0

Release Notes

github/eslint-plugin-github (eslint-plugin-github)

v5.1.7

Compare Source

What's Changed

New Contributors

Full Changelog: github/eslint-plugin-github@v5.1.6...v5.1.7

v5.1.6

Compare Source

What's Changed

New Contributors

Full Changelog: github/eslint-plugin-github@v5.1.5...v.5.1.6

nodejs/node (node)

v22.13.1: 2025-01-21, Version 22.13.1 'Jod' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2025-23083 - src,loader,permission: throw on InternalWorker use when permission model is enabled (High)
  • CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium)
  • CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)

Dependency update:

  • CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)
Commits
npm/node-semver (semver)

v7.7.0

Compare Source

Features
Bug Fixes
Documentation
Chores

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - "every weekday in 2125" in timezone Europe/Copenhagen.

🚦 Automerge: Enabled.

♻️ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@tradeshift-renovate-bulk tradeshift-renovate-bulk bot requested review from a team as code owners February 3, 2025 06:04
@tradeshift-renovatebot tradeshift-renovatebot merged commit cb6e48c into master Feb 3, 2025
1 check passed
@tradeshift-renovatebot tradeshift-renovatebot deleted the renovate/dependencies branch February 3, 2025 08:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants