fix(deps): update all non-major dependencies - #396
Conversation
|
Workflow Scan🔴 6 Critical · 🟠 12 High · 🟡 23 Medium · ⚪ 1 Info 🔴 Critical - 6 findings
75 | - name: Download rebrgen tool📍
80 | - name: Download brgen tool📍
126 | - name: Download shard results📍
21 | - name: Download artifact📍
32 | - name: Download rebrgen WASM artifacts📍
42 | - name: Download unictest results from triggering run🟠 High - 12 findings
75 | - name: "Upload to code-scanning"📍
1 | name: brgen-build📍
38 | - name: Cache rebrgen native📍
101 | - name: Cache rebrgen wasm📍
204 | - name: Cache📍
288 | - name: Cache📍
359 | - name: Cache📍
460 | - name: Cache📍
527 | - name: Cache📍
657 | - name: Cache📍
1 | name: brgen-test📍
39 | ref: ${{ github.event.workflow_run.head_sha }}🟡 Medium - 23 findings
18 | - name: Checkout repository📍
46 | - name: Checkout repository📍
124 | - name: Checkout repository📍
23 | - name: Checkout repository📍
83 | - name: Checkout repository📍
151 | - name: Checkout repository📍
188 | - name: Checkout repository📍
263 | - name: Checkout repository📍
268 | uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0📍
346 | - name: Checkout repository📍
373 | shell: cmd📍
387 | shell: cmd📍
413 | - name: Checkout repository📍
416 | uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0📍
449 | - name: Checkout repository📍
515 | - name: Checkout repository📍
586 | - name: Checkout repository📍
613 | uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0📍
643 | - name: Checkout📍
715 | - name: Checkout📍
14 | - name: Checkout repository📍
19 | - name: Checkout repository📍
36 | - name: Checkout tested commit⚪ Info - 1 finding
1 | # This workflow uses actions that are not certified by GitHub. They are providedComment ✅ 3 clean files
|
f5cfa2d to
a0fcf36
Compare
575da3c to
c3d0dbf
Compare
51b8616 to
58f51d7
Compare
845e25b to
22b9a40
Compare
22b9a40 to
90b308d
Compare
This PR contains the following updates:
2.0.10→2.1.11.29.0→1.30.0v3.1→v3.2v7.0.0→v7.0.12.6.0→2.13.1v0.0.36→v0.0.384.6.2→4.6.610.7.0→10.8.10.3.33→0.3.34v0.57.0→v0.58.00.9.0→0.10.0v4.2.1→v4.2.5^0.55.0→^0.56.0v2.4.3→v2.4.410.29.7→10.29.8v1.319.0→v1.321.01.15.0→1.16.01.0.204→1.0.2291.0.204→1.0.2291.0.120→1.0.1511.53.0→1.53.14.23.1→4.23.128.64.0→8.67.00.2.126→0.2.1275.0.14→5.0.15Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
honojs/node-server (@hono/node-server)
v2.1.1Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.1.0...v2.1.1
v2.1.0Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v2.0.12...v2.1.0
v2.0.12Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.0.11...v2.0.12
v2.0.11Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.0.10...v2.0.11
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk)
v1.30.0Compare Source
Kesin11/actions-timeline (Kesin11/actions-timeline)
v3.2.0Compare Source
Changes
Support new
parallelsyntax.Similar to composite action expansion, an overall parent span is created for steps executed in parallel. Child span names for steps running in parallel in the background are prefixed with (bg).
Sample screenshot:
https://github.com/user-attachments/assets/d92027fc-ded2-4b6e-9ab0-e3923b698ec3
Features
Fixes
Dependencies
13 changes
Internal improvement
v3.2Compare Source
actions/checkout (actions/checkout)
v7.0.1Compare Source
bitflags/bitflags (bitflags)
v2.13.1Compare Source
What's Changed
New Contributors
Full Changelog: bitflags/bitflags@2.13.0...2.13.1
v2.13.0Compare Source
What's Changed
MyFlags::Abc::iter_equal_names()method by @ssrlive in #489Full Changelog: bitflags/bitflags@2.12.1...2.13.0
v2.12.1Compare Source
What's Changed
#[flag_name]feature and re-stabilize as#[bitflags(flag_name)]by @KodrAus in #487Full Changelog: bitflags/bitflags@2.12.0...2.12.1
v2.12.0Compare Source
Yanked
This release has been yanked because the
#[flag_name]processing noticeably increases macro recursion, hitting the default limit in cases that are already close to it.What's Changed
#[flag_name]attribute by @KodrAus in #483Full Changelog: bitflags/bitflags@2.11.1...2.12.0
v2.11.1Compare Source
What's Changed
New Contributors
Full Changelog: bitflags/bitflags@2.11.0...2.11.1
v2.11.0Compare Source
What's Changed
New Contributors
Full Changelog: bitflags/bitflags@2.10.0...2.11.0
v2.10.0Compare Source
What's Changed
New Contributors
Full Changelog: bitflags/bitflags@2.9.4...2.10.0
v2.9.4Compare Source
What's Changed
Full Changelog: bitflags/bitflags@2.9.3...2.9.4
v2.9.3Compare Source
What's Changed
New Contributors
Full Changelog: bitflags/bitflags@2.9.2...2.9.3
v2.9.2Compare Source
What's Changed
Full Changelog: bitflags/bitflags@2.9.1...2.9.2
v2.9.1Compare Source
What's Changed
Full Changelog: bitflags/bitflags@2.9.0...2.9.1
v2.9.0Compare Source
What's Changed
Flagstrait: addclear(&mut self)method by @wysiwys in #437Full Changelog: bitflags/bitflags@2.8.0...2.9.0
v2.8.0Compare Source
What's Changed
New Contributors
Full Changelog: bitflags/bitflags@2.7.0...2.8.0
v2.7.0Compare Source
What's Changed
clippy::doc_lazy_continuationlints by @waywardmonkeys in #414truncate(&mut self)method to unset unknown bits by @wysiwys in #428New Contributors
Full Changelog: bitflags/bitflags@2.6.0...2.7.0
cicd-sensor/cicd-sensor-action (cicd-sensor/cicd-sensor-action)
v0.0.38Compare Source
Released by @rung via workflow run.
Highlights
Reliable log delivery during runner teardown
The systemd stop window is extended (
TimeoutStopSec=30s, agent--shutdown-grace=20s) so the agent can finish sending buffered logs and the Summary Log before the runner VM is destroyed — verified on GitHub-hostedubuntu-24.04runners. Combined with the bundled agent v0.0.45 (cicd-sensor/cicd-sensor#143), this fixes the silent log loss on short jobs.What's Changed
Full Changelog: cicd-sensor/cicd-sensor-action@v0.0.37...v0.0.38
v0.0.37Compare Source
Released by @rung via workflow run.
Highlights
Third-party Manager token support
This release updates the bundled cicd-sensor to v0.0.44. The Agent now treats Manager bearer tokens as opaque credentials and no longer validates their format. Token format and value validation are delegated to the Manager, allowing third-party Manager implementations to use JWTs, short-lived tokens, custom API keys, or other authentication formats.
The built-in cicd-sensor Manager continues to require the
sk_cs_token format generated bycicd-sensorctl token generate.What's Changed
Full Changelog: cicd-sensor/cicd-sensor-action@v0.0.36...v0.0.37
clap-rs/clap (clap)
v4.6.6Compare Source
Features
Command::get_overridden_usagev4.6.5Compare Source
v4.6.4Compare Source
Internal
v4.6.3Compare Source
Fixes
"literal".function()as attribute valueseslint/eslint (eslint)
v10.8.1Compare Source
Bug Fixes
18eb0a7fix: prevent ASI hazard inno-unused-labelsautofix (#21173) (dongkyu lee)151ba3ffix: false positives ingetter-returnandaccessor-pairs(#21163) (Grit)6898df9fix: ignore meta-property names inid-denylist(#21166) (Pixel)4d7db66fix: ignore meta-property names inid-match(#21167) (Pixel)677214efix: handle ASI hazards in no-unused-vars removeVar suggestion (#20935) (kuldeep kumar)Documentation
7d0cbf8docs: Update README (GitHub Actions Bot)0a05812docs: add missing backticks tono-duplicate-imports.js(#21183) (Lee Daeun)678c90bdocs: Update README (GitHub Actions Bot)8a10424docs: Update README (GitHub Actions Bot)69bb948docs: Update README (GitHub Actions Bot)Chores
0a14800chore: update github/codeql-action action to v4.37.4 (#21196) (renovate[bot])05adcb1test: fix failing ecosystem test foreslint-plugin-unicorn(#21191) (Lazizbek Ergashev)5611035test: add error locations info tono-void(#21185) (Lee Daeun)ee47333ci: bump github/codeql-action from 4 to 4.37.3 (#21176) (dependabot[bot])f131c03chore: improve ecosystem test failure reporting (#20937) (crimsonjay0)1f6eddechore: update ecosystem plugins (#21182) (ESLint Bot)d3266fbchore: unpinwebpackdependency (#21172) (Francesco Trotta)65a6519chore: add allowScripts field to package.json (#21092) (GiHoon Noh)22e5256ci: addtriage:nolabel to Dependabot PRs (#21141) (lumir)55c9038ci: bump actions/labeler from 6 to 7 (#21159) (dependabot[bot])7280e78chore: update dependency prettier to v3.9.6 (#21162) (renovate[bot])eddbad6test: fix failing ecosystem test foreslint-plugin-unicorn(#21156) (Francesco Trotta)60a178dchore: update ecosystem plugins (#21150) (ESLint Bot)f9f61dctest: add error locations tono-unreachable(#21151) (JIYEON)d086293test: add error locations tono-undef(#21147) (JIYEON)cc01b67test: add error locations tono-useless-catch(#21144) (devoil)688e75echore: add missing backticks in JSDoc (#21143) (Bo Hyun Kim)7c1e175test: add error locations torequire-await(#21145) (Grit)588a26dtest: add error locations tono-extra-label(#21139) (dongkyu lee)059aa89test: add error locations tono-useless-concat(#21140) (dongkyu lee)5a452a8test: add error locations tono-const-assign(#21138) (dongkyu lee)v10.8.0Compare Source
Features
2fee9bbfeat: exportConfigObjectfromeslint/config(#21082) (sethamus)Bug Fixes
6b8d2f7fix: escape reserved characters in rule id inhtmlformatter (#21129) (Francesco Trotta)9091071fix: preventno-unreachable-loopcrash when all loop types are ignored (#21116) (Pixel)e23fafefix: prefer-object-spread add semicolon when adding parenthesis (#21081) (synthex-byte)20b5ad0fix: quadratic-time regex inprefer-template(#21096) (Milos Djermanovic)8b6f6c0fix: apply ignore configs to computed methods in class-methods-use-this (#21094) (Pixel)b2c608cfix: NewExpression with parenthesized callee inpreserve-caught-error(#21083) (Francesco Trotta)Documentation
6ddf858docs: fix broken Specify Parser Options anchor link (#21106) (Minsu)784dfbedocs: Clarifyno-eq-nulldescription (#21120) (Park Harin)7ec733adocs: Fix typos and grammar in glossary (#21095) (Marry (Subin Yang))92bb13fdocs: replace quake link (#21108) (Jung Hyeon Jun)68eb4a5docs: fix broken Specify Globals anchor links in rule pages (#21103) (Minsu)d28f697docs: replace Code Climate CLI links with Qlty CLI links (#21099) (Jung Hyeon Jun)eccc68ddocs: correct --suppressions-location option description (#21093) (Ga eun Lee)c5963f7docs: Update README (GitHub Actions Bot)Chores
4fbf46dtest: pinwebpackversion to 5.108.4 (#21137) (Francesco Trotta)2d063e2chore: update HTTP URLs to HTTPS in JSDoc and comments (#21101) (Bo Hyun Kim)eccbe7btest: add error locations tono-class-assign(#21123) (devoil)e7d1e43ci: bump actions/setup-go from 6 to 7 (#21118) (dependabot[bot])e9d66d0ci: bump actions/setup-node from 6 to 7 (#21119) (dependabot[bot])ee225b6test: Add error location details tono-eq-nullrule (#21117) (Park Harin)044a627chore: update minimatch to ^10.2.5 (#21107) (김채영)fb09aa8chore: update ecosystem plugins (#21115) (ESLint Bot)5abd878test: add error locations tono-proto(#21114) (Gihyeon Jeong / 정기현)9715887test: Add error location details tono-div-regex(#21110) (Park Harin)a746ec6test: add error locations tono-new-wrappers(#21109) (Gihyeon Jeong / 정기현)8dde645test: add error locations tono-ex-assign(#21102) (devoil)13ab0ectest: add error locations tono-label-var(#21098) (Gihyeon Jeong / 정기현)a99906ftest: Add error location details tono-delete-varrule (#21105) (Park Harin)c47e8dcchore: add missing backticks tolanguages/js/index.js(#21104) (beeen)0174428chore: add missing backticks totranslate-cli-options.js(#21097) (dongkyu lee)3d36589chore: add missing backticks toserialization.js(#21091) (이규환)dcc9312test: add error locations toeqeqeq(#21090) (Ga eun Lee)2710b18ci: Add explicit permissions to rebuild-docs-sites workflow (#21089) (Marry (Subin Yang))5d2f866chore: update dependency prettier to v3.9.5 (#21086) (renovate[bot])d584e31chore: fix failing ecosystem test foreslint-plugin-unicorn(#21084) (Francesco Trotta)bf3eda0chore: update ecosystem plugins (#21079) (ESLint Bot)rust-lang/futures-rs (futures)
v0.3.34Compare Source
synto 3. (#3028)TheDan64/inkwell (inkwell)
v0.10.0Compare Source
What's Changed
91b30c0New Contributors
Full Changelog: TheDan64/inkwell@0.9.0...0.10.0
jdx/mise-action (jdx/mise-action)
v4.2.5: : Resilient mise downloads with automatic retriesCompare Source
A small patch release that makes setup more resilient to transient network failures when downloading mise.
Fixed
Retry mise downloads after transient failures (#597 by @jdx)
The download helpers previously made a single
curlorwgetattempt, so a transient GitHub release-asset HTTP or TLS failure would abort setup before mise or any user command could run (see #596).Downloads now run through a retry wrapper that makes up to five attempts with a 2s pause between failures, logging a warning on each retry. This applies consistently to binary, checksum, signature, and version fetches. Checksum and minisign verification still run only after a successful download — never inside the retry loop — so integrity guarantees are unchanged.
Full Changelog: jdx/mise-action@v4.2.4...v4.2.5
v4.2.4: : Reliable locking detection under forced colorCompare Source
A small patch release that fixes locking-support detection when workflows force colored output.
Fixed
Detect
mise install --lockedreliably under forced color (#580 by @scop)When colored output was forced globally (for example via
CLICOLOR_FORCE=1), ANSI escape codes inmise install --helpprevented the action from matching--lockedin the help text, so locking support was reported as unavailable even on versions of mise that supported it.The help probe now runs with
NO_COLOR=1in its environment, which overridesCLICOLOR_FORCEand guarantees plain-text output for the feature detection — regardless of the surrounding workflow's color settings.Full Changelog: jdx/mise-action@v4.2.3...v4.2.4
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.