Skip to content

chore(deps): update all dependencies#239

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all
Open

chore(deps): update all dependencies#239
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Apr 16, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@1stg/app-config (source) ^4.1.3^15.0.0 age confidence devDependencies major
@1stg/lib-config (source) ^6.1.3^13.0.0 age confidence devDependencies major
@changesets/changelog-github (source) ^0.5.0^0.7.0 age confidence devDependencies minor
@types/node (source) ^17.0.45^24.0.0 age confidence devDependencies major
@types/react (source) ^18.3.18^19.0.0 age confidence devDependencies major
@types/react-dom (source) ^18.3.5^19.0.0 age confidence devDependencies major
actions/checkout v3v6 age confidence action major
actions/setup-node v3v6 age confidence action major
node 16.x24.x age confidence uses-with major
patch-package ^6.5.1^8.0.0 age confidence devDependencies major
prettier (source) ^2.8.8^3.0.0 age confidence resolutions major
react (source) ^18.3.1^19.0.0 age confidence devDependencies major
react-dom (source) ^18.3.1^19.0.0 age confidence devDependencies major
react-router-dom (source) ^6.28.1^7.0.0 age confidence devDependencies major
sirv-cli ^2.0.2^3.0.0 age confidence devDependencies major
typescript (source) ^4.9.5^6.0.0 age confidence devDependencies major

Release Notes

1stG/configs (@​1stg/app-config)

v15.0.0

Compare Source

Major Changes
Patch Changes

v14.3.0

Compare Source

Minor Changes
Patch Changes

v14.2.0

Compare Source

Minor Changes
Patch Changes

v14.1.0

Compare Source

Minor Changes
Patch Changes

v14.0.0

Compare Source

Major Changes
Patch Changes

v13.1.0

Compare Source

Minor Changes
Patch Changes

v13.0.1

Compare Source

Patch Changes

v13.0.0

Compare Source

Major Changes
Patch Changes

v12.0.1

Compare Source

Patch Changes

v12.0.0

Compare Source

Major Changes
Patch Changes

v11.1.2

Compare Source

Patch Changes

v11.1.1

Compare Source

Patch Changes

v11.1.0

Compare Source

Minor Changes
Patch Changes

v11.0.3

Compare Source

Patch Changes

v11.0.2

Compare Source

Patch Changes

v11.0.1

Compare Source

Patch Changes

v11.0.0

Compare Source

Major Changes
  • d03df9f Thanks @​JounQin! - feat!: migrate to eslint-community packages, bump stylelint
Patch Changes

v10.0.1

Compare Source

Patch Changes

v10.0.0

Compare Source

Major Changes
Patch Changes

v9.0.1

Compare Source

Patch Changes

v9.0.0

Compare Source

Major Changes
Patch Changes

v8.1.0

Compare Source

Minor Changes
Patch Changes

v8.0.1

Compare Source

Patch Changes

v8.0.0

Compare Source

Major Changes
  • d03df9f Thanks @​JounQin! - feat!: migrate to eslint-community packages, bump stylelint
Minor Changes
Patch Changes

v7.3.0

Compare Source

Minor Changes
Patch Changes

v7.2.1

Compare Source

Patch Changes

v7.2.0

Compare Source

Minor Changes
Patch Changes

v7.1.1

Compare Source

Patch Changes

v7.1.0

Compare Source

Minor Changes
Patch Changes

v7.0.0

Compare Source

Major Changes
Patch Changes

v6.2.0

Compare Source

Minor Changes
Patch Changes

v6.1.5

Compare Source

Patch Changes

v6.1.4

Compare Source

Patch Changes

v6.1.3

Compare Source

Patch Changes

v6.1.2

Compare Source

Patch Changes

v6.1.1

Compare Source

Patch Changes

v6.1.0

Compare Source

Minor Changes
Patch Changes

v6.0.0

Compare Source

Major Changes
  • #​126 48d7542 Thanks @​JounQin! - build!: migrate to pnpm, yarn-deduplicate has been removed, you'll need to install it manually if you're still using yarn@v1
Patch Changes

v5.2.7

Compare Source

Patch Changes

v5.2.6

Compare Source

Patch Changes

v5.2.5

Compare Source

Patch Changes

v5.2.4

Compare Source

Patch Changes

v5.2.3

Compare Source

Patch Changes

v5.2.2

Compare Source

Patch Changes

v5.2.1

Compare Source

Patch Changes

v5.2.0

Compare Source

Minor Changes
Patch Changes

v5.1.0

Compare Source

Minor Changes
Patch Changes

v5.0.0

Compare Source

Major Changes
Patch Changes

v4.4.0

Compare Source

Minor Changes
Patch Changes

v4.3.0

Compare Source

Minor Changes
Patch Changes

v4.2.3

Compare Source

Patch Changes

v4.2.2

Compare Source

Patch Changes
  • 27662c4 Thanks @​JounQin! - fix(prettier): ignore .nvmrc, use sh for .*shrc

  • Updated dependencies

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot

changeset-bot Bot commented Apr 16, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: ef570f6

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Apr 16, 2025

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate Bot force-pushed the renovate/all branch from 5ac8a91 to 078f221 Compare May 18, 2025 13:54
@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from 9abfae3 to 5ec133d Compare July 28, 2025 16:30
@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from 6dc097f to ed96315 Compare August 8, 2025 20:39
@renovate renovate Bot force-pushed the renovate/all branch 6 times, most recently from f58984b to bdf53d4 Compare August 15, 2025 21:30
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from 1e17e5a to f3cb292 Compare August 26, 2025 16:41
@socket-security

socket-security Bot commented Aug 26, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Prototype pollution in webpack npm loader-utils

CVE: GHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utils (CRITICAL)

Affected versions: >= 2.0.0 < 2.0.3; < 1.4.1

Patched version: 1.4.1

From: ?npm/@pkgr/webpack@3.4.0npm/loader-utils@1.4.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/loader-utils@1.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@1stg/app-config@15.0.0npm/@1stg/lib-config@13.0.1npm/@typescript-eslint/eslint-plugin@8.61.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.61.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm diff-sequences is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@1stg/app-config@15.0.0npm/@1stg/lib-config@13.0.1npm/diff-sequences@27.5.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/diff-sequences@27.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm micromark-core-commonmark is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@pkgr/webpack-mdx@2.2.0npm/micromark-core-commonmark@1.0.6

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/micromark-core-commonmark@1.0.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm uvu is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@pkgr/webpack-mdx@2.2.0npm/uvu@0.5.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/uvu@0.5.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/webpack@5.107.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.107.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/webpack-plugins/package.jsonnpm/webpack@5.85.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.85.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from e52c64c to c033b48 Compare August 31, 2025 09:15
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from 5fdb3b4 to 7806e00 Compare September 4, 2025 14:47
@renovate renovate Bot force-pushed the renovate/all branch 3 times, most recently from fd81780 to 779fdc8 Compare September 17, 2025 00:59
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from c753a01 to b138a76 Compare October 14, 2025 04:36
@renovate renovate Bot force-pushed the renovate/all branch 4 times, most recently from b2799c8 to bc30335 Compare October 21, 2025 16:52
@renovate renovate Bot force-pushed the renovate/all branch 5 times, most recently from 9c3f8fe to 9ad6593 Compare November 3, 2025 06:05
@renovate renovate Bot force-pushed the renovate/all branch 7 times, most recently from 58bfc86 to 90354d4 Compare November 15, 2025 00:31
@renovate renovate Bot force-pushed the renovate/all branch 4 times, most recently from 24b4b35 to 4ae0d26 Compare November 24, 2025 14:00
@renovate renovate Bot force-pushed the renovate/all branch 4 times, most recently from 33514ec to eae2460 Compare November 29, 2025 19:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants