Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
7fa5537
Bump lodash from 4.17.21 to 4.17.23 in /bun/helpers
dependabot[bot] Jan 23, 2026
cd6d109
Merge pull request #3 from JaclynCodes/dependabot/npm_and_yarn/bun/he…
JaclynCodes Jan 23, 2026
3f4f9d3
Bump tar, @npmcli/arborist and npm in /bun/helpers
dependabot[bot] Jan 23, 2026
82a0666
Merge pull request #4 from JaclynCodes/dependabot/npm_and_yarn/bun/he…
JaclynCodes Jan 23, 2026
98c3cea
Bump symfony/process from 7.3.0 to 7.4.5 in /composer/helpers/v2
dependabot[bot] Jan 28, 2026
8379397
Bump nuget/helpers/lib/NuGet.Client from `2948e02` to `53c7a9c`
dependabot[bot] Jan 28, 2026
d0e8f6b
Bump library/rust from 1.88.0-bookworm to 1.93.0-bookworm in /cargo
dependabot[bot] Jan 28, 2026
b73e3e9
Bump golang.org/x/mod from 0.26.0 to 0.32.0 in /go_modules/helpers
dependabot[bot] Jan 28, 2026
f42a4a1
Bump dotnet-sdk in /nuget/helpers/lib/NuGetUpdater
dependabot[bot] Jan 28, 2026
e870168
Bump pip-tools in /python/helpers in the pip-tools group
dependabot[bot] Jan 28, 2026
3909d20
Merge pull request #11 from JaclynCodes/dependabot/dotnet_sdk/nuget/h…
JaclynCodes Jan 29, 2026
044211a
Merge pull request #17 from JaclynCodes/dependabot/pip/python/helpers…
JaclynCodes Jan 29, 2026
d32e152
Merge pull request #8 from JaclynCodes/dependabot/docker/cargo/librar…
JaclynCodes Jan 29, 2026
c931ab1
Merge pull request #5 from JaclynCodes/dependabot/composer/composer/h…
JaclynCodes Jan 29, 2026
96b1e3d
Merge pull request #9 from JaclynCodes/dependabot/go_modules/go_modul…
JaclynCodes Jan 29, 2026
716bdde
Merge pull request #6 from JaclynCodes/dependabot/submodules/nuget/he…
JaclynCodes Jan 29, 2026
57ce1d6
Bump lodash from 4.17.21 to 4.17.23 in /npm_and_yarn/helpers
dependabot[bot] Jan 29, 2026
9c97e4c
Bump brace-expansion in /npm_and_yarn/helpers
dependabot[bot] Jan 29, 2026
b2aa71f
Merge pull request #36 from JaclynCodes/dependabot/npm_and_yarn/npm_a…
JaclynCodes Jan 29, 2026
7e11852
Merge pull request #37 from JaclynCodes/dependabot/npm_and_yarn/npm_a…
JaclynCodes Jan 29, 2026
969a15b
Bump the npm-dependencies group in /npm_and_yarn/helpers with 3 updates
dependabot[bot] Jan 29, 2026
ff55ac1
Merge pull request #16 from JaclynCodes/dependabot/npm_and_yarn/npm_a…
JaclynCodes Jan 29, 2026
5af292a
Bump composer/composer
dependabot[bot] Feb 1, 2026
c718a32
Merge pull request #10 from JaclynCodes/dependabot/composer/composer/…
JaclynCodes Feb 1, 2026
a719f0e
Bump the prod-dependencies group across 1 directory with 30 updates (…
dependabot[bot] Feb 1, 2026
bdec2f5
Bump npm from 6.14.18 to 11.9.0 in /npm_and_yarn/helpers (#51)
dependabot[bot] Feb 6, 2026
5f122db
Bump the pnpm-dependencies group in /npm_and_yarn/helpers with 2 upda…
dependabot[bot] Feb 6, 2026
da9fa89
Bump nuget/helpers/lib/dotnet-core from `218ef74` to `d9ecafa` (#59)
dependabot[bot] Feb 15, 2026
ea7a455
Bump nuget/helpers/lib/NuGet.Client from `53c7a9c` to `acc6c0e` (#58)
dependabot[bot] Feb 15, 2026
ccb69a5
Bump ajv from 6.12.6 to 6.14.0 in /npm_and_yarn/helpers (#68)
dependabot[bot] Feb 23, 2026
0503af1
Bump the prod-dependencies group across 1 directory with 8 updates
dependabot[bot] Feb 22, 2026
b9d1c8e
Bump gitlab from 5.1.0 to 6.1.0 in /updater
dependabot[bot] Feb 23, 2026
7c2315a
Bump rexml from 3.4.1 to 3.4.2 in /updater
dependabot[bot] Feb 26, 2026
a7768e9
Bump the dev-dependencies group across 1 directory with 2 updates
dependabot[bot] Mar 1, 2026
c219f4d
Bump parser from 3.3.10.1 to 3.3.10.2 in /updater
dependabot[bot] Mar 1, 2026
54ad3c6
Bump the dev-dependencies group across 1 directory with 11 updates
dependabot[bot] Mar 1, 2026
50eb356
Bump poetry from 2.1.1 to 2.3.1 in /python/helpers in the poetry group
dependabot[bot] Mar 1, 2026
83b32da
Bump prettier
dependabot[bot] Mar 1, 2026
f83ccc2
Bump the prod-dependencies group across 1 directory with 2 updates
dependabot[bot] Mar 1, 2026
93eca1e
Bump cython from 3.1.2 to 3.2.4 in /python/helpers in the common group
dependabot[bot] Mar 1, 2026
5f6c3d7
Bump tomli from 2.2.1 to 2.4.0 in /python/helpers
dependabot[bot] Mar 1, 2026
ef15f02
Bump pip from 24.2 to 26.0 in /python/helpers
dependabot[bot] Mar 1, 2026
bc88cc3
Bump library/golang in /go_modules
dependabot[bot] Mar 8, 2026
e71afb7
Bump library/rust from 1.93.0-bookworm to 1.94.0-bookworm in /cargo
dependabot[bot] Mar 8, 2026
67eb6a3
Bump nuget/helpers/lib/NuGet.Client from `acc6c0e` to `e6283f3`
dependabot[bot] Mar 8, 2026
3595d99
Bump pip-tools in /python/helpers in the pip-tools group
dependabot[bot] Mar 8, 2026
adce6dd
Bump rubocop
dependabot[bot] Mar 8, 2026
81aae69
Bump terminal-table from 3.0.2 to 4.0.0 in /updater
dependabot[bot] Mar 8, 2026
56ae0e5
Bump the prod-dependencies group across 1 directory with 9 updates
dependabot[bot] Mar 14, 2026
1b1cc10
Bump json from 2.19.1 to 2.19.2 in /updater
dependabot[bot] Mar 19, 2026
75484fa
Bump phpstan/phpstan
dependabot[bot] Mar 22, 2026
3df37df
Bump nuget/helpers/lib/NuGet.Client from `e6283f3` to `e7ef15e`
dependabot[bot] Apr 19, 2026
b88aaea
Bump library/rust from 1.94.0-bookworm to 1.95.0-bookworm in /cargo
dependabot[bot] Apr 19, 2026
2c56e80
Bump composer/composer
dependabot[bot] Apr 19, 2026
b8150ff
Bump brace-expansion from 1.1.12 to 1.1.14 in /npm_and_yarn/helpers
dependabot[bot] Apr 21, 2026
39e7e17
Bump poetry from 2.3.2 to 2.3.4 in /python/helpers
dependabot[bot] Apr 22, 2026
0941869
Bump nuget/helpers/lib/dotnet-core from `d9ecafa` to `e903085`
dependabot[bot] Apr 19, 2026
a88fca9
Bump tomli from 2.4.0 to 2.4.1 in /python/helpers
dependabot[bot] Apr 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25,431 changes: 9,666 additions & 15,765 deletions bun/helpers/package-lock.json

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions bun/helpers/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,10 @@
},
"dependencies": {
"@dependabot/yarn-lib": "^1.22.22",
"@npmcli/arborist": "^8.0.0",
"@npmcli/arborist": "^9.1.10",
"detect-indent": "^6.1.0",
"nock": "^13.5.6",
"npm": "6.14.18",
"npm": "11.8.0",
"@pnpm/lockfile-file": "^9.1.2",
"@pnpm/dependency-path": "^5.1.1",
"semver": "^7.6.3",
Expand Down
2 changes: 1 addition & 1 deletion cargo/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM docker.io/library/rust:1.88.0-bookworm AS rust
FROM docker.io/library/rust:1.95.0-bookworm AS rust

FROM ghcr.io/dependabot/dependabot-updater-core

Expand Down
4 changes: 2 additions & 2 deletions common/dependabot-common.gemspec
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,8 @@ Gem::Specification.new do |spec|
spec.add_dependency "excon", "~> 1.2"
spec.add_dependency "faraday", "~> 2.7"
spec.add_dependency "faraday-retry", "~> 2.2"
spec.add_dependency "gitlab", "~> 5.0"
spec.add_dependency "json", "< 2.12"
spec.add_dependency "gitlab", ">= 5", "< 7"
spec.add_dependency "json", "< 2.20"
spec.add_dependency "nokogiri", "~> 1.8"
spec.add_dependency "octokit", "~> 7.2"
spec.add_dependency "opentelemetry-api", "~> 1.5"
Expand Down
674 changes: 398 additions & 276 deletions composer/helpers/v2/composer.lock

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion git_submodules/dependabot-git_submodules.gemspec
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Gem::Specification.new do |spec|
spec.files = Dir["lib/**/*"]

spec.add_dependency "dependabot-common", Dependabot::VERSION
spec.add_dependency "parseconfig", "~> 1.0", "< 1.1.0"
spec.add_dependency "parseconfig", "~> 1.0", "< 1.2.0"

common_gemspec.development_dependencies.each do |dep|
spec.add_development_dependency dep.name, *dep.requirement.as_list
Expand Down
2 changes: 1 addition & 1 deletion go_modules/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM docker.io/library/golang:1.24.5-bookworm AS go
FROM docker.io/library/golang:1.26.1-bookworm AS go

FROM ghcr.io/dependabot/dependabot-updater-core
ARG TARGETARCH
Expand Down
4 changes: 2 additions & 2 deletions go_modules/helpers/go.mod
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
module github.com/dependabot/dependabot-core/go_modules/helpers

go 1.23.0
go 1.24.0

require (
github.com/Masterminds/vcs v1.13.3
golang.org/x/mod v0.26.0
golang.org/x/mod v0.32.0
)
4 changes: 2 additions & 2 deletions go_modules/helpers/go.sum
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
github.com/Masterminds/vcs v1.13.3 h1:IIA2aBdXvfbIM+yl/eTnL4hb1XwdpvuQLglAix1gweE=
github.com/Masterminds/vcs v1.13.3/go.mod h1:TiE7xuEjl1N4j016moRd6vezp6e6Lz23gypeXfzXeW8=
golang.org/x/mod v0.26.0 h1:EGMPT//Ezu+ylkCijjPc+f4Aih7sZvaAr+O3EHBxvZg=
golang.org/x/mod v0.26.0/go.mod h1:/j6NAhSk8iQ723BGAUyoAcn7SlD7s15Dp9Nd/SfeaFQ=
golang.org/x/mod v0.32.0 h1:9F4d3PHLljb6x//jOyokMv3eX+YDeepZSEo3mFJy93c=
golang.org/x/mod v0.32.0/go.mod h1:SgipZ/3h2Ci89DlEtEXWUk/HteuRin+HHhN+WbNhguU=
Loading
Loading