Skip to content

chore(deps): update weekly dependency update - #106

Open
have-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/weekly-dependency-update
Open

chore(deps): update weekly dependency update#106
have-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/weekly-dependency-update

Conversation

@have-renovate

@have-renovate have-renovate Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/cache action digest 2c8a9bd -> 55cc834
actions/checkout action digest 9c091bb -> 3d3c42e
actions/checkout action major v5 -> v7
actions/setup-node action major v4 -> v7
node (source) engines minor >=24 -> >=24.18.0
oras-project/setup-oras action major v1 -> v2

Release Notes

actions/checkout (actions/checkout)

v7

Compare Source

v6

Compare Source

actions/setup-node (actions/setup-node)

v7

Compare Source

v6

Compare Source

v5

Compare Source

nodejs/node (node)

v24.18.0: 2026-06-23, Version 24.18.0 'Krypton' (LTS), @​richardlau prepared by @​sxa

Compare Source

Notable Changes
  • [e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #​63527
  • [44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #​64004
  • [d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #​63597
  • [bb2857b85a] - (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #​62527
  • [b9d5e87880] - (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #​62527
  • [ccd756d61e] - (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #​62183
  • [4c9251fc09] - (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #​63155
  • [8c989ec4a3] - (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #​63079
  • [3f54c8ba32] - Revert "stream: noop pause/resume on destroyed streams" (Stewart X Addison) #​63834
Commits

v24.17.0: 2026-06-18, Version 24.17.0 'Krypton' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

v24.16.0: 2026-05-21, Version 24.16.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [b267f6bca3] - (SEMVER-MINOR) crypto: implement randomUUIDv7() (nabeel378) #​62553
  • [ec2451b9cd] - (SEMVER-MINOR) debugger: add edit-free runtime expression probes to node inspect (Joyee Cheung) #​62713
  • [9705f628d9] - (SEMVER-MINOR) fs: add signal option to fs.stat() (Mert Can Altin) #​57775
  • [40ccfdecf9] - (SEMVER-MINOR) fs: expose frsize field in statfs (Jinho Jang) #​62277
  • [d7188af5c9] - (SEMVER-MINOR) http: harden ClientRequest options merge (Matteo Collina) #​63082
  • [aa1d8a9afc] - (SEMVER-MINOR) http: add req.signal to IncomingMessage (Akshat) #​62541
  • [6f37f7e240] - (SEMVER-MINOR) stream: propagate destruction in duplexPair (Ahmed Elhor) #​61098
  • [d14029be7f] - (SEMVER-MINOR) test_runner: support test order randomization (Pietro Marchini) #​61747
  • [d142c584cd] - (SEMVER-MINOR) test_runner: align mock timeout api (sangwook) #​62820
  • [01a9552585] - (SEMVER-MINOR) test_runner: add mock-timers support for AbortSignal.timeout (DeveloperViraj) #​60751
  • [00705a459a] - (SEMVER-MINOR) util: colorize text with hex colors (Guilherme Araújo) #​61556
Commits

Configuration

📅 Schedule: Branch creation - Between 09:00 PM and 11:59 PM, only on Saturday ( * 21-23 * * 6 ) in timezone America/Edmonton, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@have-renovate

have-renovate Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
[WARN] Ignored project-level auth setting "//npm.pkg.github.com/:_authToken" in "/tmp/renovate/repos/github/happyvertical/ocr/.npmrc": environment variables are not expanded in registry credentials that come from a project .npmrc, because that file is committed to the repository and could leak the secret to an attacker-controlled registry. Move this credential to a trusted source that pnpm still expands — put the line in your user-level ~/.npmrc, or set it with pnpm config set (for example, run: pnpm config set "//npm.pkg.github.com/:_authToken" <value>). See https://pnpm.io/npmrc

@github-actions

Copy link
Copy Markdown
Contributor

Version Bump Preview

When this PR is merged, @happyvertical/ocr will receive a patch version bump based on your conventional commits.

What happens on merge?

  1. Tests run on main branch
  2. Package is built
  3. Version is bumped automatically
  4. Package is published to npm
  5. Git tag is created

No manual intervention needed!

@willgriffin

Copy link
Copy Markdown
Contributor

Queue triage: blocked, do not merge. Exact-head runs 29181080060 and 29181080133 fail before repository tests because pnpm/action-setup cannot self-install the proposed pnpm 11.12.0 (Cannot use in operator to search for integrity in undefined). The changeset checks are also red. Let Renovate refresh the branch or split/fix the package-manager transition, then require a fresh full current-policy run and final review.

@willgriffin willgriffin added the status: blocked Reviewable but blocked from merge label Jul 13, 2026
@have-renovate
have-renovate Bot force-pushed the renovate/weekly-dependency-update branch from fdf930c to 77dc54c Compare July 19, 2026 03:54
@have-renovate
have-renovate Bot force-pushed the renovate/weekly-dependency-update branch from 77dc54c to 29281c5 Compare July 26, 2026 04:22
@have-renovate
have-renovate Bot force-pushed the renovate/weekly-dependency-update branch from 29281c5 to bc315f5 Compare August 2, 2026 04:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies renovate status: blocked Reviewable but blocked from merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant