build(deps-dev): Bump @types/node from 26.1.1 to 26.1.2 - #648
build(deps-dev): Bump @types/node from 26.1.1 to 26.1.2#648dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.1 to 26.1.2. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.1.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
The Supply Chain (OSV-Scanner) gate was red on every open PR, including all nine Dependabot bumps, on a finding none of them introduced: five undici advisories published after main's last green scan. undici is transitive under the jsdom test environment and already pinned via `overrides` from the previous round of this same fix (#446), so the repair is a one-line bump of that pin to 7.29.0. With the shared blocker gone, the nine bumps are folded in here rather than merged one at a time: #641 actions/download-artifact 4 -> 8 #642 docker/login-action 4.5.1 -> 4.6.0 #643 actions/upload-artifact 4 -> 7 #644 posthog-node 5.46.1 -> 5.47.7 #645 jsdom 30.0.0 -> 30.0.1 #646 @tanstack/react-virtual 3.14.8 -> 3.14.9 #647 lucide-react 1.27.0 -> 1.28.0 #648 @types/node 26.1.1 -> 26.1.2 #649 @vitejs/plugin-react 6.0.3 -> 6.0.5 The two artifact actions are major bumps and have to land together, because build-daemon.yml uploads the failproofaid-* binaries that publish.yml downloads. Every input in use was checked against each target's action.yml rather than assumed: name/path/if-no-files-found and pattern/path/merge-multiple all survive, and the new `archive` input defaults to true so the zip round trip is unchanged. translate-docs.yml was already on v7/v8, so this leaves the repo on one major instead of straddling two. Verified with CI's own scanner image (osv-scanner-action:v2.3.8) against the updated lockfile: No issues found, exit 0, with osv-scanner.toml still holding zero ignored vulnerabilities. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013zdtoUrNwGKm7ZYpQTdBZy
|
Superseded by #650, which lands this bump along with the other eight open Dependabot PRs (#641–#649). This PR's CI was red only on the Supply Chain (OSV-Scanner) gate, and on a finding it did not introduce: five advisories against Verified there: CI's own scanner image reports Closing in favour of #650 — no change is lost. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps @types/node from 26.1.1 to 26.1.2.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)