chore(deps): update dependencies-non-major (patch)#30
Conversation
12f61a3 to
3367f76
Compare
3367f76 to
0a17a43
Compare
0a17a43 to
065be16
Compare
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Jun 8, 2026 1:38a.m. | Review ↗ | |
| Shell | Jun 8, 2026 1:38a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
a515467 to
83c30f2
Compare
83c30f2 to
86fb47c
Compare
0319c70 to
2f2a215
Compare
2f2a215 to
7ce56bb
Compare
7ce56bb to
c3a5fa7
Compare
c3a5fa7 to
3d8af52
Compare
3d8af52 to
d3ed51c
Compare
75a95a4 to
51d31d0
Compare
51d31d0 to
ffdceff
Compare
969799e to
3046e1d
Compare
3046e1d to
b3bc152
Compare
b3bc152 to
53867fc
Compare
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
53867fc to
1ec1074
Compare
This PR contains the following updates:
22.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.322.3.1→22.3.320.9.0→20.9.520.11.0→20.11.122.3.1→22.3.310.26.0→10.26.28.10.2→8.10.5v2.4.0→v2.4.129.4.1→29.4.11Release Notes
nrwl/nx (@nx/devkit)
v22.3.3Compare Source
22.3.3 (2025-12-19)
🩹 Fixes
❤️ Thank You
v22.3.2Compare Source
22.3.2 (2025-12-19)
🚀 Features
🩹 Fixes
@angular/clipackage update duringnx migrate(#33918)setParserOptionsProjectin flat config (#33953, #33944)❤️ Thank You
nodejs/node (node)
v20.11.1: 2024-02-14, Version 20.11.1 'Iron' (LTS), @RafaelGSS prepared by @marco-ippolitoCompare Source
Notable changes
This is a security release.
Notable changes
Commits
7079c062bb] - crypto: disable PKCS#1 padding for privateDecrypt (Michael Dawson) nodejs-private/node-private#525186a6e1ffb] - deps: fix GHSA-f74f-cvh7-c6q6/CVE-2024-24806 (Santiago Gimeno) #51737686da19abb] - deps: disable io_uring support in libuv by default (Tobias Nießen) nodejs-private/node-private#529f7b44bfbce] - deps: update archs files for openssl-3.0.13+quic1 (Node.js GitHub Bot) #516147a30fecea2] - deps: upgrade openssl sources to quictls/openssl-3.0.13+quic1 (Node.js GitHub Bot) #51614480fc169a8] - fs: protect against modified Buffer internals in possiblyTransformPath (Tobias Nießen) nodejs-private/node-private#49777ac7c3153] - http: add maximum chunk extension size (Paolo Insogna) nodejs-private/node-private#519ed7d149675] - lib: use cache fs internals against path traversal (RafaelGSS) nodejs-private/node-private#51689bd5fc38f] - lib: update undici to v5.28.3 (Matteo Collina) nodejs-private/node-private#539d01dd4291d] - permission: fix wildcard when children > 1 (Rafael Gonzaga) #5120940ff37dfcc] - src: fix HasOnly(capability) in node::credentials (Tobias Nießen) nodejs-private/node-private#5053f6addd590] - src,deps: disable setuid() etc if io_uring enabled (Tobias Nießen) nodejs-private/node-private#529d6da413aa4] - test,doc: clarify wildcard usage (RafaelGSS) nodejs-private/node-private#517c213910aea] - zlib: pause stream if outgoing buffer is full (Matteo Collina) nodejs-private/node-private#541pnpm/pnpm (pnpm)
v10.26.2: pnpm 10.26.2Compare Source
Patch Changes
Improve error message when a package version exists but does not meet the
minimumReleaseAgeconstraint. The error now clearly states that the version exists and shows a human-readable time since release (e.g., "released 6 hours ago") #10307.Fix installation of Git dependencies using annotated tags #10335.
Previously, pnpm would store the annotated tag object's SHA in the lockfile instead of the actual commit SHA. This caused
ERR_PNPM_GIT_CHECKOUT_FAILEDerrors because the checked-out commit hash didn't match the stored tag object hash.Binaries of runtime engines (Node.js, Deno, Bun) are written to
node_modules/.binbefore lifecycle scripts (install, postinstall, prepare) are executed #10244.Try to avoid making network calls with preferOffline #10334.
Platinum Sponsors
Gold Sponsors
v10.26.1: pnpm 10.26.1Compare Source
Patch Changes
pnpm add, whenblockExoticSubdepsis set totrue#10324.HEADpoints to the commit after checkout #10310.Platinum Sponsors
Gold Sponsors
pnpm/action-setup (pnpm/action-setup)
v2.4.1Compare Source
Updated the bundled pnpm version to v7 to fix the ERR_INVALID_THIS error.
kulshekhar/ts-jest (ts-jest)
v29.4.11Compare Source
Bug Fixes
v29.4.10Compare Source
Bug Fixes
resolutionModetots.resolveModuleNamefor hybrid module support (b557a85)Programwhen consecutive compiles need different module kinds (a82a2b3), closes #4774moduleResolutioninstead of forcingNode10(1bffffc)mjsfiles fromnode_modulesfor CJS mode (96d025d)v29.4.9Compare Source
v29.4.8Compare Source
v29.4.7Compare Source
Features
v29.4.6Compare Source
Bug Fixes
v29.4.5Compare Source
Bug Fixes
v29.4.4Compare Source
Bug Fixes
v29.4.3Compare Source
Bug Fixes
v29.4.2Compare Source
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.