Skip to content

Bump the npm group across 2 directories with 10 updates - #8

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-09b0a94b61
Nov 4, 2025
Merged

Bump the npm group across 2 directories with 10 updates#8
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-09b0a94b61

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Nov 4, 2025

Copy link
Copy Markdown
Contributor

Bumps the npm group with 3 updates in the / directory: vitest, aws-cdk-lib and @vitest/coverage-v8.
Bumps the npm group with 3 updates in the /example directory: vitest, aws-cdk-lib and @vitest/coverage-v8.

Updates vitest from 4.0.6 to 4.0.7

Release notes

Sourced from vitest's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits
  • 1f5d9d2 chore: release v4.0.7
  • a1b7361 fix(jsdom): support URL.createObjectURL, FormData.set(prop, blob) (#8935)
  • 751c392 fix(cli): parse --execArgv as array (#8924)
  • c9078a2 fix: create environment once per worker with isolate: false (#8915)
  • 9d2b4d5 fix(browser): inherit isolate option, deprecate browser.isolate/`browser....
  • 680a612 perf(pool): sort test files by project by default (#8914)
  • fdb2e79 fix(typecheck): handle re-runs outside tsc (#8920)
  • 6240d51 fix: bind process in case global is overwritten (#8916)
  • d41fa74 fix(pool): avoid --require argument when running in deno (#8897)
  • b60149b perf(reporters): remove unnecessary Array.from call (#8907)
  • Additional commits viewable in compare view

Updates aws-cdk-lib from 2.221.1 to 2.222.0

Release notes

Sourced from aws-cdk-lib's releases.

v2.222.0

⚠ BREAKING CHANGES

  • bedrock-agentcore: The signature of RuntimeAuthorizerConfiguration.usingCognito() has changed to accept IUserPool and IUserPoolClient constructs instead of string parameters, and now supports multiple clients.

Features

Bug Fixes


Alpha modules (2.222.0-alpha.0)

Features

  • eks-v2-alpha: eks-v2-alpha is now in developer preview (#35801) (32afc0f)

Bug Fixes

  • bedrock-alpha: apply permission dependency to existing and non-existing roles (#35123) (b39ccf3), closes #35120
  • eks-v2-alpha: remove hyphen from Go package name (#35927) (2cdfc8a)
Changelog

Sourced from aws-cdk-lib's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

2.222.0-alpha.0 (2025-11-04)

Features

  • eks-v2-alpha: eks-v2-alpha is now in developer preview (#35801) (32afc0f)

Bug Fixes

  • bedrock-alpha: apply permission dependency to existing and non-existing roles (#35123) (b39ccf3), closes #35120
  • eks-v2-alpha: remove hyphen from Go package name (#35927) (2cdfc8a)

2.221.1-alpha.0 (2025-10-29)

2.221.0-alpha.0 (2025-10-24)

Features

Bug Fixes

  • elasticache-alpha: cannot import Redis 7 serverless cache (#35629) (2bde1a0)

2.220.0-alpha.0 (2025-10-14)

Bug Fixes

2.219.0-alpha.0 (2025-10-01)

2.218.0-alpha.0 (2025-09-29)

  • elasticache-alpha: implement Serverless ElastiCache L2 Construct (#35424) (0e08c8c)

2.217.0-alpha.0 (2025-09-25)

2.216.0-alpha.0 (2025-09-22)

2.215.0-alpha.0 (2025-09-15)

Bug Fixes

... (truncated)

Commits
  • cfc74ed chore: update analytics metadata blueprints
  • 1ee40ad chore(release): 2.222.0
  • dad112e feat(apigatewayv2): WebSocketStage support accessLogSettings (#34766)
  • f618638 chore: fix Python TypeError: Cannot create a consistent method resolution ord...
  • ebef303 feat(lambda): add Python 3.14 runtime for Lambda (#35869)
  • db71fac feat(lambda): add Java25 runtime for Lambda (#35867)
  • db057e1 docs: fix typos and wording in feature flags description (#35789)
  • 75139b2 chore(bedrock): support Amazon Nova Multimodal Embeddings (#35904)
  • bf10d94 feat(apigateway): add binaryMediaTypes property to SpecRestApi (#35502)
  • 5dec21e feat(kinesisfirehose): add built-in data processors to decompress CloudWatch ...
  • Additional commits viewable in compare view

Updates @vitest/coverage-v8 from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/coverage-v8's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/expect from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/expect's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/mocker from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/mocker's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/pretty-format from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/pretty-format's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/runner from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/runner's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/snapshot from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/snapshot's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/spy from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/spy's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates @vitest/utils from 4.0.6 to 4.0.7

Release notes

Sourced from @​vitest/utils's releases.

v4.0.7

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Bumps the npm group with 3 updates in the / directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest), [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) and [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8).
Bumps the npm group with 3 updates in the /example directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest), [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) and [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8).


Updates `vitest` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/vitest)

Updates `aws-cdk-lib` from 2.221.1 to 2.222.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.222.0/packages/aws-cdk-lib)

Updates `@vitest/coverage-v8` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/coverage-v8)

Updates `@vitest/expect` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/expect)

Updates `@vitest/mocker` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/mocker)

Updates `@vitest/pretty-format` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/pretty-format)

Updates `@vitest/runner` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/runner)

Updates `@vitest/snapshot` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/snapshot)

Updates `@vitest/spy` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/spy)

Updates `@vitest/utils` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/utils)

Updates `vitest` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/vitest)

Updates `aws-cdk-lib` from 2.221.1 to 2.222.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.222.0/packages/aws-cdk-lib)

Updates `@vitest/coverage-v8` from 4.0.6 to 4.0.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/coverage-v8)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.0.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: aws-cdk-lib
  dependency-version: 2.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.0.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/expect"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/mocker"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/pretty-format"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/runner"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/snapshot"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/spy"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/utils"
  dependency-version: 4.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: vitest
  dependency-version: 4.0.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: aws-cdk-lib
  dependency-version: 2.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.0.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot assigned poad Nov 4, 2025
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Nov 4, 2025
@github-actions

github-actions Bot commented Nov 4, 2025

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@vitest/coverage-v8 ^4.0.7 UnknownUnknown
npm/aws-cdk-lib ^2.222.0 🟢 4.8
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
SAST🟢 9SAST tool detected but not run on all commits
Binary-Artifacts⚠️ 0binaries present in source code
Vulnerabilities⚠️ 19 existing vulnerabilities detected
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
npm/vitest ^4.0.7 UnknownUnknown
npm/vitest ^4.0.7 UnknownUnknown
npm/@vitest/coverage-v8 4.0.7 UnknownUnknown
npm/@vitest/expect 4.0.7 UnknownUnknown
npm/@vitest/mocker 4.0.7 UnknownUnknown
npm/@vitest/pretty-format 4.0.7 UnknownUnknown
npm/@vitest/runner 4.0.7 UnknownUnknown
npm/@vitest/snapshot 4.0.7 UnknownUnknown
npm/@vitest/spy 4.0.7 UnknownUnknown
npm/@vitest/utils 4.0.7 UnknownUnknown
npm/aws-cdk-lib 2.222.0 🟢 4.8
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
SAST🟢 9SAST tool detected but not run on all commits
Binary-Artifacts⚠️ 0binaries present in source code
Vulnerabilities⚠️ 19 existing vulnerabilities detected
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
npm/vitest 4.0.7 UnknownUnknown

Scanned Files

  • example/package.json
  • package/package.json
  • pnpm-lock.yaml

@github-actions
github-actions Bot enabled auto-merge (squash) November 4, 2025 22:52
@github-actions
github-actions Bot merged commit f9f7e84 into main Nov 4, 2025
4 checks passed
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/npm-09b0a94b61 branch November 4, 2025 22:53
@github-actions github-actions Bot mentioned this pull request Nov 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant