Skip to content

Bump ts-migrate-mongoose from 4.2.0 to 5.3.2#205

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/ts-migrate-mongoose-5.3.2
Open

Bump ts-migrate-mongoose from 4.2.0 to 5.3.2#205
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/ts-migrate-mongoose-5.3.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps ts-migrate-mongoose from 4.2.0 to 5.3.2.

Release notes

Sourced from ts-migrate-mongoose's releases.

v5.3.2

  • Dual attestation sidecars on release: Sigstore bundle + in-toto JSONL (#483) 5b2c5fc

ilovepixelart/ts-migrate-mongoose@v5.3.1...v5.3.2

v5.3.1

  • Attach Sigstore bundle to Release as third provenance channel (#481) 8c53dc0

ilovepixelart/ts-migrate-mongoose@v5.3.0...v5.3.1

v5.3.0

  • Runtime security gaps + migrate publish to actions/attest v4 (#480) 2168383
  • Security: reject traversal names + error cause chaining (#479) 0678210
  • Raise test coverage and document Branch-Protection finding (#478) 572dfbc
  • Merge pull request #477 from ilovepixelart/feature/fuzzing-property-tests 9da1f32
  • Rewrite feature_request template for ts-migrate-mongoose context 0d1ba56
  • Add fast-check property tests for env.parse 13ecfa8
  • Merge pull request #476 from ilovepixelart/feature/bestpractices-12477 126aa99
  • Add OpenSSF Best Practices project 12477 + Fuzzing accepted finding 196399e
  • Merge pull request #475 from ilovepixelart/feature/hardening 439c6b0
  • Switch Dependabot to github-actions ecosystem bf74743
  • Supply-chain hardening and packaging hygiene e984e9a
  • Update changelog for v5.2.0 3283153

ilovepixelart/ts-migrate-mongoose@v5.2.0...v5.3.0

v5.2.0

  • Lock f1e5628
  • Merge pull request #468 from ilovepixelart/feature/refactor 51a5ed8
  • Remove Node 18 from supports section (tested on 20+) 07b8c60
  • Simplify installation section, reorder Example after Installation 2eb4314
  • Remove Node 18.x from CI matrix (vitest coverage requires Node 20+) 347bf03
  • Bump to Node >=18, ES2022, update README and CI matrix 76459f0
  • Update changelog for v5.1.0 5836ffc

ilovepixelart/ts-migrate-mongoose@v5.1.0...v5.2.0

v5.1.0

  • Merge pull request #466 from ilovepixelart/feature/nest d3159c4
  • Biome 0f3734a
  • Coverage 48dac69
  • Nest 85a4453

... (truncated)

Commits
  • 8222e7f 5.3.2
  • 5b2c5fc Dual attestation sidecars on release: Sigstore bundle + in-toto JSONL (#483)
  • 36b047b 5.3.1
  • 8c53dc0 Attach Sigstore bundle to Release as third provenance channel (#481)
  • 76e92cc 5.3.0
  • 2168383 Runtime security gaps + migrate publish to actions/attest v4 (#480)
  • 0678210 Security: reject traversal names + error cause chaining (#479)
  • 572dfbc Raise test coverage and document Branch-Protection finding (#478)
  • 9da1f32 Merge pull request #477 from ilovepixelart/feature/fuzzing-property-tests
  • 0d1ba56 Rewrite feature_request template for ts-migrate-mongoose context
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for ts-migrate-mongoose since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ts-migrate-mongoose](https://github.com/ilovepixelart/ts-migrate-mongoose) from 4.2.0 to 5.3.2.
- [Release notes](https://github.com/ilovepixelart/ts-migrate-mongoose/releases)
- [Commits](ilovepixelart/ts-migrate-mongoose@v4.2.0...v5.3.2)

---
updated-dependencies:
- dependency-name: ts-migrate-mongoose
  dependency-version: 5.3.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Updates to dependencies label Apr 21, 2026
@dependabot dependabot Bot requested a review from cmenon12 as a code owner April 21, 2026 02:10
@dependabot dependabot Bot added the dependencies Updates to dependencies label Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Updates to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant