build(deps): Bump @docusaurus/core from 3.10.0 to 3.10.1#997
build(deps): Bump @docusaurus/core from 3.10.0 to 3.10.1#997dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@docusaurus/core](https://github.com/facebook/docusaurus/tree/HEAD/packages/docusaurus) from 3.10.0 to 3.10.1. - [Release notes](https://github.com/facebook/docusaurus/releases) - [Changelog](https://github.com/facebook/docusaurus/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/docusaurus/commits/v3.10.1/packages/docusaurus) --- updated-dependencies: - dependency-name: "@docusaurus/core" dependency-version: 3.10.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
🤖 Cursor Dependency AnalysisSupply-Chain Malware ReviewVerifying declared Docusaurus versions in the repo for accuracy. Verdict: benign Why this looks safe
Scanner vs interpretation: The report’s status: warn reflects noisy rules on a broad upstream diff (59 files including website/blog assets and monorepo yarn.lock), not evidence of compromise in this npm bump. If anything in the PR changed Actionable (non-security): After merge, consider bumping all Compatibility AnalysisGathering usage sites and verifying upstream changes for this patch release. 1) Where
|
Bumps @docusaurus/core from 3.10.0 to 3.10.1.
Release notes
Sourced from @docusaurus/core's releases.
Changelog
Sourced from @docusaurus/core's changelog.
Commits
41c1a45v3.10.1d4164aechore: cherry-pick commits for v3.10.1 patch release (#11982)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Low Risk
Low risk dependency bump for the docs site; main risk is unexpected build/runtime regressions from the updated Docusaurus toolchain (notably
webpackbarand transitive deps).Overview
Bumps
@docusaurus/corefrom3.10.0to3.10.1inpackage.json.Regenerates
package-lock.jsonto align with the new Docusaurus release, pulling in updated transitive packages (includingwebpackbar7.0.0and related dependencies).Reviewed by Cursor Bugbot for commit da984fb. Bugbot is set up for automated code reviews on this repo. Configure here.