chore(deps-dev): bump dotenv from 17.2.0 to 17.4.2#785
chore(deps-dev): bump dotenv from 17.2.0 to 17.4.2#785dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
LGTM — routine Dependabot dev-dependency bump with no breaking changes.
Extended reasoning...
Overview
This PR bumps dotenv from 17.2.0 to 17.4.1 in package.json and pnpm-lock.yaml. It is a dev-dependency only, used for loading environment variables in tests/local development. The changes are two lines in package.json and the corresponding lock file hash/version updates.
Security risks
None. dotenv is a dev dependency not shipped in production bundles. The intermediate releases (17.2.4, 17.3.x, 17.4.0, 17.4.1) contain only a TypeScript type fix, README rewrites, minor log text tweaks, and documentation additions — no security-relevant changes.
Level of scrutiny
Very low. This is a mechanical Dependabot version bump of a well-known, widely-used library with no breaking or behavioral changes between the current and target versions. The changes are entirely in configuration/lock files.
Other factors
No bugs were reported by the automated bug-hunting system. No prior reviewer comments are outstanding. The PR is fresh with only the Vercel bot comment. This class of change (minor/patch dev-dep bump) is safe to auto-approve.
0ddc2ee to
839ec65
Compare
839ec65 to
dfe49f2
Compare
dfe49f2 to
a0e6d27
Compare
a0e6d27 to
1e5fa1a
Compare
1e5fa1a to
a795be7
Compare
a795be7 to
70dd913
Compare
70dd913 to
f210448
Compare
f210448 to
84b5b38
Compare
Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.2.0 to 17.4.2. - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v17.2.0...v17.4.2) --- updated-dependencies: - dependency-name: dotenv dependency-version: 17.4.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
84b5b38 to
e8854ed
Compare
Bumps dotenv from 17.2.0 to 17.4.2.
Changelog
Sourced from dotenv's changelog.
... (truncated)
Commits
f116f7017.4.23a81612fix visual order of faq13f55a8Merge branch 'skill'4bbbf73reorganize faqc3da64bMerge pull request #1009 from motdotla/skill6f743b1update sourcefc2c624update skill972315bTighten up skill2795fcereorganize faqd5495d4adjust skill