Skip to content

chore: refresh lockfile (transitive dep bumps)#10

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
chore/lockfile-refresh
Open

chore: refresh lockfile (transitive dep bumps)#10
github-actions[bot] wants to merge 1 commit into
masterfrom
chore/lockfile-refresh

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Jun 1, 2026

Automated weekly npm update — bumps transitive deps within
their existing semver ranges. Catches drift between the
committed lockfile and current npm advisories before it
hits a release.

Includes a npm audit --audit-level=moderate clean
confirmation. If audit failed, this PR would not have
been opened — investigate manually instead.

Tests run on Node 24 against the updated lockfile.

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​react@​19.2.14 ⏵ 19.2.151001007995100
Updatedvitest@​4.1.6 ⏵ 4.1.7961007998100
Updated@​vitest/​coverage-v8@​4.1.6 ⏵ 4.1.7991007998100
Updatedtsx@​4.22.1 ⏵ 4.22.410010082 +193100
Updatedink@​7.0.3 ⏵ 7.0.59810010096100
Updated@​biomejs/​biome@​2.4.15 ⏵ 2.4.16100 +110010099100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant