Skip to content

build(deps-dev): bump all#1695

Merged
renovate[bot] merged 1 commit intolivefrom
renovate/all
Oct 27, 2025
Merged

build(deps-dev): bump all#1695
renovate[bot] merged 1 commit intolivefrom
renovate/all

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Oct 27, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update
@types/gulp (source) 4.0.17 -> 4.0.18 age adoption passing confidence devDependencies patch
@types/node (source) 22.18.11 -> 22.18.12 age adoption passing confidence devDependencies patch
editorconfig-checker 6.1.0 -> 6.1.1 age adoption passing confidence devDependencies patch
github/codeql-action v3.30.9 -> v3.31.0 age adoption passing confidence action minor
node (source) 22.20.0 -> 22.21.0 age adoption passing confidence engines minor
pnpm (source) 10.18.3 -> 10.19.0 age adoption passing confidence packageManager minor
pnpm (source) 10.18.3 -> 10.19.0 age adoption passing confidence engines minor
returntocorp/semgrep ee3c01c -> 4372a1d container digest

Release Notes

editorconfig-checker/editorconfig-checker.javascript (editorconfig-checker)

v6.1.1

Compare Source

Bug Fixes
github/codeql-action (github/codeql-action)

v3.31.0

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.0 - 24 Oct 2025
  • Bump minimum CodeQL bundle version to 2.17.6. #​3223
  • When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #​3222

See the full CHANGELOG.md for more information.

nodejs/node (node)

v22.21.0: 2025-10-20, Version 22.21.0 'Jod' (LTS), @​aduh95

Compare Source

Notable Changes
  • [1486fedea1] - (SEMVER-MINOR) cli: add --use-env-proxy (Joyee Cheung) #​59151
  • [bedaaa11fc] - (SEMVER-MINOR) http: support http proxy for fetch under NODE_USE_ENV_PROXY (Joyee Cheung) #​57165
  • [af8b5fa29d] - (SEMVER-MINOR) http: add shouldUpgradeCallback to let servers control HTTP upgrades (Tim Perry) #​59824
  • [42102594b1] - (SEMVER-MINOR) http,https: add built-in proxy support in http/https.request and Agent (Joyee Cheung) #​58980
  • [686ac49b82] - (SEMVER-MINOR) src: add percentage support to --max-old-space-size (Asaf Federman) #​59082
Commits
pnpm/pnpm (pnpm)

v10.19.0

Compare Source

Minor Changes
  • You can now allow specific versions of dependencies to run postinstall scripts. onlyBuiltDependencies now accepts package names with lists of trusted versions. For example:

    onlyBuiltDependencies:
      - nx@21.6.4 || 21.6.5
      - esbuild@0.25.1

    Related PR: #​10104.

  • Added support for exact versions in minimumReleaseAgeExclude #​9985.

    You can now list one or more specific versions that pnpm should allow to install, even if those versions don’t satisfy the maturity requirement set by minimumReleaseAge. For example:

    minimumReleaseAge: 1440
    minimumReleaseAgeExclude:
      - nx@21.6.5
      - webpack@4.47.0 || 5.102.1

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@netlify
Copy link
Copy Markdown

netlify Bot commented Oct 27, 2025

Deploy Preview for gh-pages-openinf ready!

Name Link
🔨 Latest commit 7f20328
🔍 Latest deploy log https://app.netlify.com/projects/gh-pages-openinf/deploys/68febe9a26b0c90008fee7e1
😎 Deploy Preview https://deploy-preview-1695--gh-pages-openinf.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​gulp@​4.0.17 ⏵ 4.0.181001007085 +8100
Updated@​types/​node@​22.18.11 ⏵ 22.18.12100 +110081 +196100
Updatededitorconfig-checker@​6.1.0 ⏵ 6.1.19710010088 +7100

View full report

@renovate renovate Bot merged commit 6b4f73f into live Oct 27, 2025
13 checks passed
@renovate renovate Bot deleted the renovate/all branch October 27, 2025 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants