Skip to content

build(deps): bump the npm-dependencies group across 1 directory with 17 updates - #652

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-f660bdbc1d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-f660bdbc1d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-dependencies group with 17 updates in the / directory:

Package From To
fast-xml-parser 5.10.1 5.11.2
js-yaml 4.3.2 5.4.2
p-limit 7.3.0 7.3.3
smol-toml 1.7.1 1.9.0
tree-sitter-containerfile 0.8.1 0.9.2
web-tree-sitter 0.26.10 0.27.0
yargs 18.0.0 18.2.0
@cyclonedx/cyclonedx-library 10.2.0 10.3.0
@types/node 25.9.4 26.6.4
c8 11.0.0 12.0.0
chai 6.2.2 6.3.0
eslint 10.6.0 10.12.0
globals 17.7.0 17.13.0
mocha 11.7.6 12.0.3
msw 2.14.6 3.0.2
sinon 22.0.0 22.1.0
typescript 6.0.3 7.0.2

Updates fast-xml-parser from 5.10.1 to 5.11.2

Release notes

Sourced from fast-xml-parser's releases.

v5.11.2

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.11.1...v5.11.2

v5.11.1

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.11.0...v5.11.1

v5.11.0

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.10.1...v5.11.0

Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

5.11.2 / 2026-09-29

  • fix (#875): decode Uint8Array XML input as UTF-8 (By emme1t)
  • fix (#880) :type EntityDecoderOptions.setXmlVersion's version as a number (By Yevhenii Kotyrlo)

5.11.1 / 2026-08-27

  • fix: validator; Replace regex with a single-pass scanner for attribute tokens, eliminating quadratic behavior on long whitespace runs.

5.11.0 / 2026-08-16

  • feat: support for endIndex in node metadata (#850) [By Pavel Dranichnikov]
  • fix: don't crash on a closing tag with no matching opening tag (#861) [By Haïm Dimer]
  • fix: DOCTYPE to read SYSTEM/PUBLIC
  • deps: strnum v2.4.2

5.10.1 / 2026-07-17

  • fix: multiple DOCTYPE declarations.
  • deps: @nodable/entities for treeshaking

5.10.0 / 2026-07-11

  • upgrade:
    • xml-naming v0.3.0: cache support
    • PEM v1.6.2: sibling bug fix
    • is-unsafe v2.0.0: tree shaking

*5.9.3 / 2026-06-19

  • update strnum

*5.9.2 / 2026-06-17

  • dummy release to test changes in github action

*5.9.1 / 2026-06-17

  • dummy release to test release from github action

*5.9.0 / 2026-06-15

  • update strnum to 2.3.0
    • you can set hex, binary, enotation, infinity, unicode
  • validate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library. User can override rules by overriding EntityDecoder.

*5.8.0 / 2026-05-12

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is bydeault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid

... (truncated)

Commits

Updates js-yaml from 4.3.2 to 5.4.2

Changelog

Sourced from js-yaml's changelog.

[5.4.2] - 2026-09-13

Fixed

  • forceQuotes no longer quotes non-string scalars, #798.

[5.4.1] - 2026-08-26

Changed

  • Hard-limit merge sequence size to 100.

Security

  • Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.

[5.4.0] - 2026-08-25

Added

  • Added the scalarStyleRules dumper option to customize string formatting. See Scalar styling for details.

Changed

  • [breaking] Flattened the low-level AST node style representation. Scalar and collection nodes now use SCALAR_STYLE and COLLECTION_STYLE values; explicit tags use the separate tagged property. Alias nodes now contain only kind and anchor. This only affects code that directly constructs or edits AST nodes.
  • [breaking] The sortKeys option was rewritten using AST mutation to avoid side effects.
  • Reworked scalar style selection. This can change formatting without changing loaded values; in particular, whitespace-only strings are now double-quoted.

Fixed

  • Accept a byte order mark at the start of each document in a stream, #791.
  • Produce valid flow mappings with quoteFlowKeys and flowSkipColonSpace, including alias and property-only keys, #786.
  • Preserve empty scalar items when converting block sequences to flow style.
  • Do not apply the 1024-character simple-key limit to flow mapping keys.
  • Count Unicode code points, rather than UTF-16 code units, for the 1024-character simple-key limit.
  • Add an explicit document-end marker after keep-chomped block scalars when needed to preserve trailing newlines.

[5.3.0] - 2026-08-14

This release focuses on reworking the documentation and making small architectural improvements before moving forward.

... (truncated)

Commits

Updates p-limit from 7.3.0 to 7.3.3

Release notes

Sourced from p-limit's releases.

v7.3.3

  • Fix unhandled rejections in limit.map() when the iterable throws 9df0d27

sindresorhus/p-limit@v7.3.2...v7.3.3

v7.3.2

  • Fix limitFunction queue clearing (#109) f3e7f9b

sindresorhus/p-limit@v7.3.1...v7.3.2

v7.3.1

  • Fix detached limit.map calls (#108) ef37eb2

sindresorhus/p-limit@v7.3.0...v7.3.1

Commits

Updates smol-toml from 1.7.1 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

v1.8.0

What's Changed

Full Changelog: squirrelchat/smol-toml@v1.7.2...v1.8.0

v1.7.2

What's Changed

... (truncated)

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates tree-sitter-containerfile from 0.8.1 to 0.9.2

Release notes

Sourced from tree-sitter-containerfile's releases.

v0.9.2

What's Changed

Full Changelog: wharflab/tree-sitter-containerfile@v0.9.1...v0.9.2

v0.9.1

Full Changelog: wharflab/tree-sitter-containerfile@v0.9.0...v0.9.1

v0.9.0

What's Changed

Full Changelog: wharflab/tree-sitter-containerfile@v0.8.1...v0.9.0

Commits
  • 1df9124 chore: v0.9.2
  • d06c52d fix(grammar): reject glued instruction keywords (FROMalpine) via scanner word...
  • cfd2634 chore: v0.9.1
  • 39ebc34 fix(grammar): close 13 syntax gaps (CRLF, quoting, expansions, heredocs, imag...
  • 4ff2892 Update dependency node-addon-api to v8.9.0
  • c7fa574 Update dependency eslint to v10.6.0
  • 8fb1f75 Update dependency tree-sitter-cli to v0.26.10
  • 97bd84f Update Rust crate tree-sitter to v0.26.10
  • 3043b21 Update dependency globals to v17.7.0
  • See full diff in compare view

Updates web-tree-sitter from 0.26.10 to 0.27.0

Release notes

Sourced from web-tree-sitter's releases.

v0.27.0

What's Changed

... (truncated)

Commits
  • 8933cb7 docs(web): add WASM version compatibility section
  • 8263917 docs: specify Emscripten version constraints for web binding builds
  • 129d8cd build(deps): bump eslint
  • 0be5f89 fix(web): map Node-only specifiers to false via browser field
  • 95eaaa2 build(deps): bump the npm group across 1 directory with 3 updates
  • dff1fd8 build(deps): bump esbuild and vite in /lib/binding_web
  • 7be497a fix(web)!: report null when lookahead iterator is not positioned
  • 6ea9a7c build(deps): bump the npm group across 1 directory with 4 updates
  • fecce45 build(deps): bump @​types/node
  • 4deef2d build(deps): bump eslint
  • Additional commits viewable in compare view

Updates yargs from 18.0.0 to 18.2.0

Changelog

Sourced from yargs's changelog.

18.2.0 (2026-09-20)

Features

  • support creating completions for fish shell (#2568) (34d833a)

Bug Fixes

  • completion: remove spurious single-quote in zsh loadautofunc detection (#2548) (224e285)

18.1.0 (2026-07-26)

Features

  • ignore bun when getting bin name (b77831c)

Bug Fixes

  • lang: 'count' for de locale (#2476) (971e351)
  • local prototype pollution vulnerability in apply-extends (437f3a4)
  • locale: add Georgian translation (#2474) (086aeaa)

17.7.3 (2026-06-19)

Bug Fixes

  • fix: use entry point with file extension for anything that supports exports (#2514) (c7597e3)

16.2.2 (2026-06-19)

Bug Fixes

  • fix: use entry point with .cjs file extension for yargs export (#2546) (6feb819)
Commits
  • e49b60a chore(main): release 18.2.0 (#2569)
  • 3ed7095 Set up staged trusted publishing, and remove stale deno workflow (#2591)
  • 224e285 fix(completion): remove spurious single-quote in zsh loadautofunc detection (...
  • fb9c055 Add SECURITY.md
  • 2a4378b Add FUNDING.yml with funding sources
  • 34d833a feat: support creating completions for fish shell (#2568)
  • 3a49608 Remove copy-pasted email address (#2566)
  • 8878a89 chore(main): release 18.1.0 (#2475)
  • db916b4 chore: add workflow_dispatch for release-please (#2564)
  • 4153e0f chore: improve build robustness (#2554)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for yargs since your current version.


Updates @cyclonedx/cyclonedx-library from 10.2.0 to 10.3.0

Release notes

Sourced from @​cyclonedx/cyclonedx-library's releases.

10.3.0

Added

  • Support CycloneDX 1.7.2 (#1519 via #1520)
  • Pulled SPDX license IDs v1.0-3.29.0 (via #1395)

#1519: CycloneDX/cyclonedx-javascript-library#1519 #1520: CycloneDX/cyclonedx-javascript-library#1520


What's Changed

Full Changelog: CycloneDX/cyclonedx-javascript-library@v10.2.0...v10.3.0

Changelog

Sourced from @​cyclonedx/cyclonedx-library's changelog.

10.3.0 -- 2026-09-17

  • Added
    • Support CycloneDX 1.7.2 (#1519 via #1520)
    • Pulled SPDX license IDs v1.0-3.29.0 (via #1395)

#1519: CycloneDX/cyclonedx-javascript-library#1519 #1520: CycloneDX/cyclonedx-javascript-library#1520

Commits
  • 6d2a52f 10.3.0
  • 01293cf chore: prep v10.3.0
  • 877a821 feat: support CycloneDX 1.7.2 (#1520)
  • d152d99 chore(deps-dev): bump c8 from 11.0.0 to 12.0.0 (#1496)
  • d81d47f chore(deps): bump knip from 6.32.2 to 6.34.0 in /tools/test-dependencies (#1518)
  • 42f6658 chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#1516)
  • 6b9adad chore(deps): bump knip from 6.32.1 to 6.32.2 in /tools/test-dependencies (#1512)
  • See full diff in compare view

Updates @types/node from 25.9.4 to 26.6.4

Commits

Updates c8 from 11.0.0 to 12.0.0

Release notes

Sourced from c8's releases.

v12.0.0

12.0.0 (2026-07-14)

⚠ BREAKING CHANGES

  • yargs enforces a stricter range of Node versions ^20.19.0 || ^22.12.0 || >=23

Features

Changelog

Sourced from c8's changelog.

12.0.0 (2026-07-14)

⚠ BREAKING CHANGES

  • yargs enforces a stricter range of Node versions ^20.19.0 || ^22.12.0 || >=23

Features

Commits

Updates chai from 6.2.2 to 6.3.0

Release notes

Sourced from chai's releases.

v6.3.0

What's Changed

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
…17 updates

Bumps the npm-dependencies group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.10.1` | `5.11.2` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `4.3.2` | `5.4.2` |
| [p-limit](https://github.com/sindresorhus/p-limit) | `7.3.0` | `7.3.3` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.7.1` | `1.9.0` |
| [tree-sitter-containerfile](https://github.com/wharflab/tree-sitter-containerfile) | `0.8.1` | `0.9.2` |
| [web-tree-sitter](https://github.com/tree-sitter/tree-sitter/tree/HEAD/lib/binding_web) | `0.26.10` | `0.27.0` |
| [yargs](https://github.com/yargs/yargs) | `18.0.0` | `18.2.0` |
| [@cyclonedx/cyclonedx-library](https://github.com/CycloneDX/cyclonedx-javascript-library) | `10.2.0` | `10.3.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.9.4` | `26.6.4` |
| [c8](https://github.com/bcoe/c8) | `11.0.0` | `12.0.0` |
| [chai](https://github.com/chaijs/chai) | `6.2.2` | `6.3.0` |
| [eslint](https://github.com/eslint/eslint) | `10.6.0` | `10.12.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.7.0` | `17.13.0` |
| [mocha](https://github.com/mochajs/mocha) | `11.7.6` | `12.0.3` |
| [msw](https://github.com/mswjs/msw) | `2.14.6` | `3.0.2` |
| [sinon](https://github.com/sinonjs/sinon) | `22.0.0` | `22.1.0` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |



Updates `fast-xml-parser` from 5.10.1 to 5.11.2
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.10.1...v5.11.2)

Updates `js-yaml` from 4.3.2 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.2...5.4.2)

Updates `p-limit` from 7.3.0 to 7.3.3
- [Release notes](https://github.com/sindresorhus/p-limit/releases)
- [Commits](sindresorhus/p-limit@v7.3.0...v7.3.3)

Updates `smol-toml` from 1.7.1 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.7.1...v1.9.0)

Updates `tree-sitter-containerfile` from 0.8.1 to 0.9.2
- [Release notes](https://github.com/wharflab/tree-sitter-containerfile/releases)
- [Commits](wharflab/tree-sitter-containerfile@v0.8.1...v0.9.2)

Updates `web-tree-sitter` from 0.26.10 to 0.27.0
- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)
- [Commits](https://github.com/tree-sitter/tree-sitter/commits/v0.27.0/lib/binding_web)

Updates `yargs` from 18.0.0 to 18.2.0
- [Release notes](https://github.com/yargs/yargs/releases)
- [Changelog](https://github.com/yargs/yargs/blob/main/CHANGELOG.md)
- [Commits](yargs/yargs@v18.0.0...v18.2.0)

Updates `@cyclonedx/cyclonedx-library` from 10.2.0 to 10.3.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-javascript-library/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-javascript-library/blob/main/HISTORY.md)
- [Commits](CycloneDX/cyclonedx-javascript-library@v10.2.0...v10.3.0)

Updates `@types/node` from 25.9.4 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `c8` from 11.0.0 to 12.0.0
- [Release notes](https://github.com/bcoe/c8/releases)
- [Changelog](https://github.com/bcoe/c8/blob/main/CHANGELOG.md)
- [Commits](bcoe/c8@v11.0.0...v12.0.0)

Updates `chai` from 6.2.2 to 6.3.0
- [Release notes](https://github.com/chaijs/chai/releases)
- [Changelog](https://github.com/chaijs/chai/blob/main/History.md)
- [Commits](chaijs/chai@v6.2.2...v6.3.0)

Updates `eslint` from 10.6.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.6.0...v10.12.0)

Updates `globals` from 17.7.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.7.0...v17.13.0)

Updates `mocha` from 11.7.6 to 12.0.3
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md)
- [Commits](mochajs/mocha@v11.7.6...v12.0.3)

Updates `msw` from 2.14.6 to 3.0.2
- [Release notes](https://github.com/mswjs/msw/releases)
- [Changelog](https://github.com/mswjs/msw/blob/main/CHANGELOG.md)
- [Commits](mswjs/msw@v2.14.6...v3.0.2)

Updates `sinon` from 22.0.0 to 22.1.0
- [Release notes](https://github.com/sinonjs/sinon/releases)
- [Changelog](https://github.com/sinonjs/sinon/blob/main/CHANGES.md)
- [Commits](sinonjs/sinon@v22.0.0...v22.1.0)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v6.0.3...v7.0.2)

---
updated-dependencies:
- dependency-name: "@cyclonedx/cyclonedx-library"
  dependency-version: 10.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: c8
  dependency-version: 12.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: chai
  dependency-version: 6.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: fast-xml-parser
  dependency-version: 5.11.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: mocha
  dependency-version: 12.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: msw
  dependency-version: 3.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: p-limit
  dependency-version: 7.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: sinon
  dependency-version: 22.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: tree-sitter-containerfile
  dependency-version: 0.9.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: web-tree-sitter
  dependency-version: 0.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: yargs
  dependency-version: 18.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-dependencies-f660bdbc1d branch from d71089c to aaa152a Compare October 6, 2026 16:29

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants