Skip to content

chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates#559

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/npm_and_yarn/app/staging/npm-minor-patch-5b75ea1b92
Closed

chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates#559
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/npm_and_yarn/app/staging/npm-minor-patch-5b75ea1b92

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 3, 2026

Bumps the npm-minor-patch group with 3 updates in the /app directory: @falkordb/canvas, react-router-dom and postcss.

Updates @falkordb/canvas from 0.0.45 to 0.0.49

Release notes

Sourced from @​falkordb/canvas's releases.

v0.0.49

Release v0.0.49

v0.0.48

What's Changed

Full Changelog: FalkorDB/falkordb-canvas@v0.0.47...v0.0.48

v0.0.47

What's Changed

Full Changelog: FalkorDB/falkordb-canvas@v0.0.46...v0.0.47

v0.0.46

What's Changed

New Contributors

Full Changelog: FalkorDB/falkordb-canvas@v0.0.45...v0.0.46

Commits
  • 4d19461 ci: move publish workflow to Node 24
  • 82d3b78 Fix CI npm install conflict on PR #100
  • ba81774 Merge main into feature/analysis-layout-modes-expansion
  • ab84190 Merge pull request #114 from FalkorDB/fix-node-size
  • 33b4779 Merge pull request #110 from FalkorDB/feature/expand-collapse-animation-handling
  • dd57d98 fix: add promise-retry dependency to improve retry logic
  • 4944bb6 Merge pull request #113 from FalkorDB/fix-node-size
  • 7d9f3c9 fix: adjust text alignment for accurate measurement in node rendering
  • 1de7843 fix: update node size handling and improve text measurement logic
  • 900f938 Merge pull request #112 from FalkorDB/chore/combine-dependabot-updates-v2
  • Additional commits viewable in compare view

Updates react-router-dom from 7.14.0 to 7.14.2

Changelog

Sourced from react-router-dom's changelog.

v7.14.2

Patch Changes

v7.14.1

Patch Changes

Commits

Updates postcss from 8.5.8 to 8.5.13

Release notes

Sourced from postcss's releases.

8.5.13

  • Fixed postcss-scss commend regression.

8.5.12

  • Fixed reading any file via user-generated CSS.
  • Added opts.unsafeMap to disable checks.

8.5.11

  • Fixed nested brackets parsing performance (by @​offset).

8.5.10

  • Fixed XSS via unescaped </style> in non-bundler cases (by @​TharVid).

8.5.9

  • Speed up source map encoding paring in case of the error.
Changelog

Sourced from postcss's changelog.

8.5.13

  • Fixed postcss-scss commend regression.

8.5.12

  • Fixed reading any file via user-generated CSS.
  • Added opts.unsafeMap to disable checks.

8.5.11

  • Fixed nested brackets parsing performance (by @​offset).

8.5.10

  • Fixed XSS via unescaped </style> in non-bundler cases (by @​TharVid).

8.5.9

  • Speed up source map encoding paring in case of the error.
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 3, 2026
@overcut-ai
Copy link
Copy Markdown

overcut-ai Bot commented May 3, 2026

Completed Working on "Code Review"

✅ Code review complete. No issues found - all changes look good! ✅

✅ Workflow completed successfully.


👉 View complete log

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 3, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@falkordb/canvas 0.0.49 UnknownUnknown
npm/postcss 8.5.13 🟢 6
Details
CheckScoreReason
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST🟢 7SAST tool is not run on all commits -- score normalized to 7
npm/react-router 7.14.2 🟢 5.1
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 1Found 4/30 approved changesets -- score normalized to 1
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/react-router-dom 7.14.2 🟢 5.1
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 1Found 4/30 approved changesets -- score normalized to 1
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • app/package-lock.json

… updates

Bumps the npm-minor-patch group with 3 updates in the /app directory: [@falkordb/canvas](https://github.com/FalkorDB/falkordb-canvas), [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) and [postcss](https://github.com/postcss/postcss).


Updates `@falkordb/canvas` from 0.0.45 to 0.0.49
- [Release notes](https://github.com/FalkorDB/falkordb-canvas/releases)
- [Commits](FalkorDB/falkordb-canvas@v0.0.45...v0.0.49)

Updates `react-router-dom` from 7.14.0 to 7.14.2
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.14.2/packages/react-router-dom)

Updates `postcss` from 8.5.8 to 8.5.13
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.8...8.5.13)

---
updated-dependencies:
- dependency-name: "@falkordb/canvas"
  dependency-version: 0.0.49
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: postcss
  dependency-version: 8.5.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: react-router-dom
  dependency-version: 7.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/app/staging/npm-minor-patch-5b75ea1b92 branch from fc79802 to 8e47e16 Compare May 4, 2026 15:05
@gkorland
Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 10, 2026

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this May 10, 2026
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/app/staging/npm-minor-patch-5b75ea1b92 branch May 10, 2026 11:51
Copilot stopped work on behalf of gkorland due to an error May 10, 2026 11:51
Copilot AI requested a review from gkorland May 10, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant