Skip to content

chore(deps): lock file maintenance (master)#1246

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/master-lock-file-maintenance
Mar 7, 2026
Merged

chore(deps): lock file maintenance (master)#1246
renovate[bot] merged 1 commit into
masterfrom
renovate/master-lock-file-maintenance

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Dec 1, 2025

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Dec 1, 2025

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.


  • Branch has one or more failed status checks

@renovate renovate Bot enabled auto-merge December 1, 2025 10:50
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Dec 1, 2025

@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 5 times, most recently from f0ff9c3 to 5100591 Compare December 6, 2025 03:13
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 6 times, most recently from db52106 to 3997894 Compare December 17, 2025 02:38
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 6 times, most recently from 8b5e529 to 435b183 Compare December 23, 2025 16:35
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 2 times, most recently from e6e2c0a to 282d425 Compare December 31, 2025 14:43
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 2 times, most recently from 9152d9d to 3e719df Compare January 8, 2026 20:10
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 2 times, most recently from 19c15b6 to b39e6b6 Compare January 23, 2026 16:45
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch from b39e6b6 to 1dba6f1 Compare February 2, 2026 20:39
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Feb 2, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Prototype Pollution in npm minimist

CVE: GHSA-xvch-5gv4-984h Prototype Pollution in minimist (CRITICAL)

Affected versions: >= 1.0.0 < 1.2.6; < 0.2.4

Patched version: 0.2.4

From: package-lock.jsonnpm/ban-sensitive-files@1.10.11npm/minimist@0.0.10

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/minimist@0.0.10. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 2 times, most recently from 4f2aab3 to ad701ea Compare February 17, 2026 22:02
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch 3 times, most recently from 8a427f2 to 2815a31 Compare March 7, 2026 22:07
@renovate renovate Bot force-pushed the renovate/master-lock-file-maintenance branch from 2815a31 to 9cc2aa6 Compare March 7, 2026 22:17
@renovate renovate Bot merged commit 3d5e00d into master Mar 7, 2026
16 checks passed
@renovate renovate Bot deleted the renovate/master-lock-file-maintenance branch March 7, 2026 22:18
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Mar 8, 2026

🎉 This PR is included in version 15.1.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions github-actions Bot added the released This issue or pull-request was included in a version released by semantic-release label Mar 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released This issue or pull-request was included in a version released by semantic-release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants