chore(deps): bump the frontend-compatible group across 1 directory with 5 updates - #3133
Conversation
…th 5 updates Bumps the frontend-compatible group with 5 updates in the /arcane/home/honeypot-dashboard/frontend-next directory: | Package | From | To | | --- | --- | --- | | [openid-client](https://github.com/panva/openid-client) | `6.8.7` | `6.8.8` | | [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.0` | `26.4.1` | | [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.5` | `19.2.7` | Updates `openid-client` from 6.8.7 to 6.8.8 - [Release notes](https://github.com/panva/openid-client/releases) - [Changelog](https://github.com/panva/openid-client/blob/main/CHANGELOG.md) - [Commits](panva/openid-client@v6.8.7...v6.8.8) Updates `undici` from 8.10.0 to 8.10.2 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v8.10.0...v8.10.2) Updates `@playwright/test` from 1.62.1 to 1.63.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.62.1...v1.63.0) Updates `@types/node` from 26.4.0 to 26.4.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@types/react-dom` from 19.2.5 to 19.2.7 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) --- updated-dependencies: - dependency-name: openid-client dependency-version: 6.8.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-compatible - dependency-name: undici dependency-version: 8.10.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-compatible - dependency-name: "@playwright/test" dependency-version: 1.63.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-compatible - dependency-name: "@types/node" dependency-version: 26.4.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-compatible - dependency-name: "@types/react-dom" dependency-version: 19.2.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-compatible ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Strix Security ReviewNo security issues found. Updated for Reviewed by Strix |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF ScorecardScorecard details
Scanned Files
|
There was a problem hiding this comment.
This is a Dependabot dependency bump PR touching only package.json and package-lock.json in the frontend-next dashboard. It upgrades openid-client 6.8.7→6.8.8, undici 8.10.0→8.10.2, @playwright/test 1.62.1→1.63.0, @types/node 26.4.0→26.4.1, and @types/react-dom 19.2.5→19.2.7. No application source code is modified. The undici and openid-client patch bumps include upstream security fixes and introduce no new vulnerable code. No security-relevant code changes were found in the diff.
Reviewed by Strix
Configure security review settings
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the frontend-compatible group with 5 updates in the /arcane/home/honeypot-dashboard/frontend-next directory:
6.8.76.8.88.10.08.10.21.62.11.63.026.4.026.4.119.2.519.2.7Updates
openid-clientfrom 6.8.7 to 6.8.8Release notes
Sourced from openid-client's releases.
Changelog
Sourced from openid-client's changelog.
Commits
04c5982chore(release): 6.8.85eccf2echore: bump packagesd730f80fix(passport): handle rejected async verification callbacksb931c40refactor: share grant polling lifecycle and retry handlingd687796fix: isolate lazy client authentication handler cachese816bf0fix: calculate token lifetimes using elapsed time10ba026fix: select a unique decryption key when kid is omittedb26170efix: retain polling abort signals through response processingaf32783fix: apply the default HTTP request timeout5433d68fix: preserve clock settings across DCR nonce retriesUpdates
undicifrom 8.10.0 to 8.10.2Release notes
Sourced from undici's releases.
... (truncated)
Commits
5e541e0Bumped v8.10.2 (#5771)eb04cc3fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (#5738)e905b5bfix(retry): settle exposed body on terminal failure0160a71fix(retry): validate resumed response framing66e1281fix(websocket): reject unrequested subprotocols7aac7f1fix(decompress): limit decompressed response sizecb75bbbfix(cache): do not cache Set-Cookie in shared caches6d58312fix(interceptor/dump): abort oversized chunked responses8f5868ffix: preserve BalancedPool connection options2be07bffix(cache): reject unsafe method response cachingUpdates
@playwright/testfrom 1.62.1 to 1.63.0Release notes
Sourced from @playwright/test's releases.
... (truncated)
Commits
1b025d7chore: mark v1.63.0 (#42569)0b9956dcherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.6313dbf10cherry-pick(#42552): docs: release notes for v1.63e93b64echerry-pick(#42566): feat(test): add subtitle option to test.step (#42567)2b7a5f2test: response.body() for content-encoding:identity (#42537)648a67cfix(mcp): create parent directories for explicitly named files (#42540)7894f56docs(mcp): clarify how tool file names are resolved (#42538)52900a1devops: restore npm publishing from GitHub Actions (#42550)8c47f59docs(csharp): fix nonexistent method names in guide examples (#42507)bd6e552chore(video): emit frames with real timestamps, drop frame number quantizatio...Updates
@types/nodefrom 26.4.0 to 26.4.1Commits
Updates
@types/react-domfrom 19.2.5 to 19.2.7Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions