Skip to content

chore(deps): bump uuid from 9.0.1 to 11.1.0 in the npm_and_yarn group across 1 directory#1

Merged
roll merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-eabade7528
May 15, 2026
Merged

chore(deps): bump uuid from 9.0.1 to 11.1.0 in the npm_and_yarn group across 1 directory#1
roll merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-eabade7528

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 15, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the / directory: uuid.

Updates uuid from 9.0.1 to 11.1.0

Release notes

Sourced from uuid's releases.

v11.1.0

11.1.0 (2025-02-19)

Features

  • update TS types to allowUint8Array subtypes for buffer option (#865) (a5231e7)

v11.0.5

11.0.5 (2025-01-09)

Bug Fixes

  • add TS unit test, pin to typescript@5.0.4 (#860) (24ac2fd)

v11.0.4

11.0.4 (2025-01-05)

Bug Fixes

  • docs: insure -> ensure (#843) (d2a61e1)
  • exclude tests from published package (#840) (f992ff4)
  • Test for invalid byte array sizes and ranges in v1(), v4(), and v7() (#845) (e0ee900)

v11.0.3

11.0.3 (2024-11-04)

Bug Fixes

v11.0.2

11.0.2 (2024-10-28)

Bug Fixes

v11.0.1

11.0.1 (2024-10-27)

... (truncated)

Changelog

Sourced from uuid's changelog.

11.1.0 (2025-02-19)

Features

  • update TS types to allowUint8Array subtypes for buffer option (#865) (a5231e7)

11.0.5 (2025-01-09)

Bug Fixes

  • add TS unit test, pin to typescript@5.0.4 (#860) (24ac2fd)

11.0.4 (2025-01-05)

Bug Fixes

  • docs: insure -> ensure (#843) (d2a61e1)
  • exclude tests from published package (#840) (f992ff4)
  • Test for invalid byte array sizes and ranges in v1(), v4(), and v7() (#845) (e0ee900)

11.0.3 (2024-11-04)

Bug Fixes

11.0.2 (2024-10-28)

Bug Fixes

11.0.1 (2024-10-27)

Bug Fixes

11.0.0 (2024-10-26)

⚠ BREAKING CHANGES

  • refactor v1 internal state and options logic (#780)

... (truncated)

Commits
  • 3d1eba0 chore(main): release 11.1.0 (#866)
  • a5231e7 feat: update TS types to allowUint8Array subtypes for buffer option (#865)
  • aeabb60 docs: docs housecleaning (#864)
  • 46ada3c chore(main): release 11.0.5 (#861)
  • 24ac2fd fix: add TS unit test, pin to typescript@5.0.4 (#860)
  • e426aaa build: use npm pack tarball for local examples and testing instead of .loca...
  • 050cd5b chore(main): release 11.0.4 (#842)
  • e0ee900 fix: Test for invalid byte array sizes and ranges in v1(), v4(), and `v7(...
  • 6e83b3a chore: update deps (#848)
  • 5f58b43 docs: Ensure link to getrandomvalues-not-supported is maintained (#844)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by broofa, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the / directory: [uuid](https://github.com/uuidjs/uuid).


Updates `uuid` from 9.0.1 to 11.1.0
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v9.0.1...v11.1.0)

---
updated-dependencies:
- dependency-name: uuid
  dependency-version: 11.1.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 15, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 15, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
testdocs d346b47 Commit Preview URL

Branch Preview URL
May 15 2026, 10:32 AM

@claude

claude Bot commented May 15, 2026

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 1m 6s —— View job


PR Review: uuid 9.0.1 → 11.1.0

  • Gather context
  • Analyze uuid usage in codebase
  • Review breaking changes impact
  • Security analysis
  • Post findings

Summary

This PR updates uuid from 9.0.1 to 11.1.1 (the lockfile resolves to 11.1.1, not 11.1.0 as the title states). uuid is not a direct dependency — it's a transitive dep pulled in by livemark or similar. No application code uses it directly.

The lockfile update also includes several other transitive bumps: seroval 1.5.2 → 1.5.4, seroval-plugins 1.5.2 → 1.5.4, tinyexec 1.1.1 → 1.1.2.


Findings

MEDIUM — @ungap/structured-clone@1.3.0 exposes CWE-502 (not introduced, but now surfaced)

+    deprecated: Potential CWE-502 - Update to 1.3.1 or higher

The refreshed lockfile now surfaces a deprecation warning on @ungap/structured-clone@1.3.0 indicating a CWE-502 (Deserialization of Untrusted Data) vulnerability. This package is not updated by this PR — it was already present. However, since it's now explicitly flagged, it should be addressed in a follow-up.

Recommendation: Identify which package requires @ungap/structured-clone and update or override to >=1.3.1.


LOW — uuid@9.0.1 remains in the lockfile as a transitive dependency

+    deprecated: uuid@10 and below is no longer supported.

After this bump, uuid@9.0.1 is still present alongside uuid@11.1.1 in the lockfile. Some package in the tree still pins the old version. The deprecated notice could produce noisy install warnings.

Recommendation: Run pnpm why uuid to identify which package pulls in v9, and consider whether it can be updated or overridden.


LOW — New prepare script in uuid@11

The PR body notes: "This version adds prepare script that runs during installation." For a widely-used, audited package like uuid this is low risk, but worth noting for supply chain awareness policy.


Code Quality

No application code changes — lockfile only. No breaking change impact on this codebase since uuid is not directly imported anywhere in src/.

Verdict

Safe to merge. The CWE-502 item in @ungap/structured-clone is a pre-existing issue now surfaced — worth a follow-up issue but not a blocker for this PR.

@roll
roll merged commit 0cba215 into main May 15, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-eabade7528 branch May 15, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant