Skip to content

chore(monorepo): update auto-merge non-major dependencies#11

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/auto-merge-non-major-dependencies
Open

chore(monorepo): update auto-merge non-major dependencies#11
renovate[bot] wants to merge 1 commit intomainfrom
renovate/auto-merge-non-major-dependencies

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Feb 12, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@cloudflare/workers-types ^4.20260405.1^4.20260417.1 age confidence pnpm.catalog.default minor
@dotenvx/dotenvx 1.35.01.61.0 age confidence pnpm.catalog.default minor
@microsoft/api-extractor (source) ^7.49.2^7.58.2 age confidence pnpm.catalog.default minor
@nx/devkit (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@nx/eslint (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@nx/eslint-plugin (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@nx/jest (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@nx/js (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@nx/plugin (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@nx/react (source) ^22.5.4^22.6.5 age confidence pnpm.catalog.default minor
@nx/workspace (source) 22.6.122.6.5 age confidence pnpm.catalog.default patch
@prisma/client (source) ^6.5.0^6.19.3 age confidence pnpm.catalog.default minor
@prisma/prisma-schema-wasm (source) ^6.6.0-41.9061db3b0058e3d3731c6fe68a1b77061bed4861^6.6.0-53.f676762280b54cd07c770017ed3711ddde35f37a age confidence pnpm.catalog.default patch
@storm-software/build-tools (source) ^0.158.153^0.158.158 age confidence pnpm.catalog.default patch
@storm-software/config (source) ^1.137.26^1.137.31 age confidence pnpm.catalog.default patch
@storm-software/config-tools (source) ^1.189.72^1.189.77 age confidence pnpm.catalog.default patch
@storm-software/cspell (source) ^0.46.62^0.46.67 age confidence pnpm.catalog.default patch
@storm-software/esbuild (source) ^0.53.154^0.53.159 age confidence pnpm.catalog.default patch
@storm-software/eslint (source) ^0.170.14^0.170.19 age confidence pnpm.catalog.default patch
@storm-software/git-tools (source) ^2.130.30^2.130.35 age confidence pnpm.catalog.default patch
@storm-software/linting-tools (source) ^1.133.23^1.133.28 age confidence pnpm.catalog.default patch
@storm-software/markdownlint (source) ^0.30.150^0.30.155 age confidence pnpm.catalog.default patch
@storm-software/pnpm-tools (source) ^0.7.0^0.7.5 age confidence pnpm.catalog.default patch
@storm-software/prettier (source) ^0.59.46^0.59.51 age confidence pnpm.catalog.default patch
@storm-software/testing-tools (source) ^1.119.147^1.119.152 age confidence pnpm.catalog.default patch
@storm-software/tsconfig (source) ^0.48.61^0.48.66 age confidence pnpm.catalog.default patch
@storm-software/tsdoc (source) ^0.13.147^0.13.152 age confidence pnpm.catalog.default patch
@storm-software/unbuild (source) ^0.57.154^0.57.159 age confidence pnpm.catalog.default patch
@storm-software/untyped (source) ^0.24.135^0.24.140 age confidence pnpm.catalog.default patch
@storm-software/workspace-tools (source) ^1.295.48^1.295.55 age confidence pnpm.catalog.default patch
@swc/core (source) ^1.15.24^1.15.26 age confidence pnpm.catalog.default patch
@swc/wasm ^1.10.14^1.15.26 age confidence pnpm.catalog.default minor
@tanstack/react-query (source) ^5.96.2^5.99.0 age confidence pnpm.catalog.default minor
@tanstack/react-query-devtools (source) ^5.70.0^5.99.0 age confidence pnpm.catalog.default minor
@​types/react-native 0.72.80.73.0 age confidence pnpm.catalog.default minor
GitGuardian/ggshield v1.39.0v1.49.0 age confidence action minor
capnp-es ^0.0.11^0.0.14 age confidence pnpm.catalog.default patch
conventional-changelog-storm-software (source) ^0.3.153^0.3.158 age confidence pnpm.catalog.default patch
cookie >=0.7.0>=0.7.2 age confidence pnpm-workspace.overrides patch
debug >=4.4.0>=4.4.3 age confidence pnpm-workspace.overrides patch
defu ^6.1.6^6.1.7 age confidence pnpm.catalog.default patch
esbuild ^0.25.12^0.28.0 age confidence pnpm.catalog.default minor
got >=14.4.5>=14.6.6 age confidence pnpm-workspace.overrides minor
jest (source) 30.0.530.3.0 age confidence pnpm.catalog.default minor
jest-environment-jsdom (source) 30.0.530.3.0 age confidence pnpm.catalog.default minor
jest-util (source) 30.0.530.3.0 age confidence pnpm.catalog.default minor
knip (source) 5.43.65.88.1 age confidence pnpm.catalog.default minor
markdown-it >=14.1.0>=14.1.1 age confidence pnpm-workspace.overrides patch
markdownlint-cli2 ^0.17.2^0.22.0 age confidence pnpm.catalog.default minor
mlly 1.7.41.8.2 age confidence pnpm.catalog.default minor
nanotar ^0.2.1^0.3.0 age confidence pnpm.catalog.default minor
node (source) 24.11.124.15.0 age confidence minor
node (source) >=22.21.1>=22.22.2 age confidence engines minor
parse-path >=7.0.0>=7.1.0 age confidence pnpm-workspace.overrides minor
path-to-regexp >=0.1.12>=0.2.5 age confidence pnpm-workspace.overrides minor
pnpm (source) 10.26.010.33.0 age confidence packageManager minor
pnpm (source) >=10.24.0>=10.33.0 age confidence engines minor
postcss (source) >=8.5.1>=8.5.10 age confidence pnpm-workspace.overrides patch
prettier (source) ^3.8.1^3.8.3 age confidence pnpm.catalog.default patch
semver 7.7.17.7.4 age confidence pnpm.catalog.default patch
shell-quote >=1.8.2>=1.8.3 age confidence pnpm-workspace.overrides patch
sherif 1.3.01.11.1 age confidence pnpm.catalog.default minor
simple-git (source) >=3.27.0>=3.36.0 age confidence pnpm-workspace.overrides minor
styfle/cancel-workflow-action 0.12.10.13.1 age confidence action minor
superjson 2.2.22.2.6 age confidence pnpm.catalog.default patch
tsdown (source) ^0.17.2^0.21.9 age confidence pnpm.catalog.default minor
unbuild ^3.3.1^3.6.1 age confidence pnpm.catalog.default minor
undici (source) ^7.24.7^7.25.0 age confidence pnpm.catalog.default minor
undici-types (source) ^7.24.7^7.25.0 age confidence pnpm.catalog.default minor
verdaccio (source) ^6.3.2^6.5.1 age confidence pnpm.catalog.default minor

Release Notes

cloudflare/workerd (@​cloudflare/workers-types)

v4.20260417.1

Compare Source

v4.20260416.2

Compare Source

v4.20260416.1

Compare Source

v4.20260415.1

Compare Source

v4.20260414.1

Compare Source

v4.20260413.1

Compare Source

v4.20260412.2

Compare Source

v4.20260412.1

Compare Source

v4.20260411.1

Compare Source

v4.20260410.1

Compare Source

v4.20260409.1

Compare Source

v4.20260408.1

Compare Source

dotenvx/dotenvx (@​dotenvx/dotenvx)

v1.61.0

Compare Source

Added
  • Add login and logout method that proxy to dotenvx-ops login/logout (#​780)
  • Note: dotenvx continues to make zero outgoing HTTP requests and includes no telemetry. Outgoing requests occur only if you explicitly install the dotenvx-ops SDK or CLI.

v1.60.2

Compare Source

Changed
  • Communicate local key and armored key (for Ops stored keys) (#​778)

v1.60.1

Compare Source

Added
  • Added missing + key ⛨ for Ops stored keys (#​777)

v1.60.0

Compare Source

Added
  • Add spinner with loading messages
    • injecting (run)
    • encrypting (encrypt, set)
    • decrypting (decrypt, get)
    • rotating (rotate)
    • retrieving (keypair)

v1.59.1

Compare Source

Added
  • add HELLO key to the kit sample to match most of our examples in the README

v1.59.0

Compare Source

Changed
  • encrypt and set now create a .env file if one does not exist (#​771)
  • pass --no-create to prevent file creation

v1.58.0

Compare Source

Changed
  • Changed runtime injection message to format ⟐ injecting env (N) from FILE · dotenvx@VERSION (#​770)

v1.57.5

Compare Source

Changes
  • Improve already installed message (#​768)

v1.57.4

Compare Source

Changes

v1.57.3

Compare Source

Changes
  • Simplify installed success message (#​766)

v1.57.2

Compare Source

Changes
  • Ran npm audit to update package-lock.json (#​763)

v1.57.1

Compare Source

Changes
  • improved error logs and compacted most to a single line (#​755)

  • introduced leading log glyphs as a visual status language:

    • success action (encrypted)
    • success action (set plain value, decrypted)
    • success action (rotated)
    • informational no-op (no changes)
    • success action for generated/updated support files
    • warning
    • error

v1.57.0

Compare Source

Changed
  • color and formatting changes to outputs (#​754)

v1.56.0

Compare Source

Changed
  • ops off flag — now respected by get, keypair, rotate, and encrypt (#​750)
  • --pp alias — added as shorthand for --pretty-print; toward sunsetting -pp (#​750)
Removed
  • Remove support for .env.vault files (#​750)

v1.55.1

Compare Source

Added
  • Respect dotenvx-ops status (on|off) (#​749)

v1.55.0

Compare Source

Added
Removed
  • Remove ProKeypair logic

v1.54.1

Compare Source

Changed
  • Fix npm publish

v1.53.0

Compare Source

Removed
  • Remove radar. It has been a year since replaced by ops. (#​743)

v1.52.0

Compare Source

Added
  • Pass log level options to main.set (#​731)

v1.51.4

Compare Source

Changed
  • Change description of dotenvx-ops to better reflect its tooling as operational primitives on top of dotenvx for production use cases. (#​721)

v1.51.3

Compare Source

Added
  • Add hint on .env.keys for dotenvx ops backup. Dotenvx Ops Backup lets you back up your private keys securely with just a single command. It's a convenient alterantive to manually copy/pasting them in and out of 1Password. (#​718)

v1.51.2

Compare Source

Changed

This will allow us to start dogfooding our own solution for third-party API key rotation. Third-party API key rotation would drastically improve security industry wide. Please get in touch if this is interesting to you.

v1.51.1

Compare Source

Added
  • Add opsOff type information

v1.51.0

Compare Source

Added
  • Add config({opsOff: true}) options and --ops-off flag for turning off Dotenvx Ops features. (#​680)

v1.50.1

Compare Source

Removed
  • Remove listed command to radar (now ops) (#​678)

v1.50.0

Compare Source

Added
  • Add optional dotenvx ops command (#​677)
  • Ops is a coming rename of Radar. Radar will become a feature inside ops.
  • With dotenvx ops use dotenvx across your team, infrastructure, agents, and more.
 _______________________________________________________________________
|                                                                       |
|  Dotenvx Ops: Commercial Tooling for Dotenvx                          |
|                                                                       |
|  ░▒▓██████▓▒░░▒▓███████▓▒░ ░▒▓███████▓▒░                              |
| ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░                                     |
| ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░                                     |
| ░▒▓█▓▒░░▒▓█▓▒░▒▓███████▓▒░ ░▒▓██████▓▒░                               |
| ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░             ░▒▓█▓▒░                              |
| ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░             ░▒▓█▓▒░                              |
|  ░▒▓██████▓▒░░▒▓█▓▒░      ░▒▓███████▓▒░                               |
|                                                                       |
|  Use dotenvx across your team, infrastructure, agents, and more.      |
|                                                                       |
|  Learn more at https://dotenvx.com/ops                                |
|_______________________________________________________________________|

v1.49.1

Compare Source

Changed
  • 🐞 patch bug with variable expansion of single quoted values (#​675)

v1.49.0

Compare Source

Added
  • For precommit and prebuild, ignore .env.x file like we do with .env.vault file. (#​666)

v1.48.4

Compare Source

Removed
  • Remove unnecessary use of eval in proKeypair helper (#​654)

v1.48.3

Compare Source

Changed
  • Include privateKeyName and privateKey on internal processedEnv object (#​649)

v1.48.2

Compare Source

Changed
  • Check radar status before sending (#​646)

v1.48.1

Compare Source

Changed
  • Send beforEnv and afterEnv to Radar if user has installed (#​645)

v1.48.0

Compare Source

Added
  • Include beforeEnv and afterEnv for user debugging (#​644)

v1.47.7

Compare Source

Changed
  • src should be in internal processEnv object (#​643)

v1.47.6

Compare Source

Changed
  • Make Radar call non-blocking (#​642)

v1.47.5

Compare Source

Changed
  • Add resilient handling of any Radar failures (#​639)

v1.47.4

Compare Source

Changed

v1.47.3

Compare Source

Added
  • Send to radar#observe if Radar installed by user (#​631)
Removed
  • Remove cli in package.json (#​632)

v1.47.2

Compare Source

Added
  • Export cli in package.json (#​629)

v1.47.1

Compare Source

Added
  • Add convenience log that radar active 📡 when dotenvx-radar is installed (#​625)

v1.47.0

Compare Source

Added
  • Add optional dotenvx radar command (#​624)
  • Radar is an early access commercial extension for dotenvx that will auto backup your .env files.
 _______________________________________________________________________
|                                                                       |
|  Dotenvx Radar: Env Observability                                     |
|                                                                       |
|  ░▒▓███████▓▒░ ░▒▓██████▓▒░░▒▓███████▓▒░ ░▒▓██████▓▒░░▒▓███████▓▒░    |
|  ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░   |
|  ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░   |
|  ░▒▓███████▓▒░░▒▓████████▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓████████▓▒░▒▓███████▓▒░    |
|  ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░   |
|  ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░   |
|  ░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓███████▓▒░░▒▓█▓▒░░▒▓█▓▒░▒▓█▓▒░░▒▓█▓▒░   |
|                                                                       |
|  Observe, version, and back up your environment variables at runtime. |
|                                                                       |
|  Purchase lifetime access at https://dotenvx.com/radar                |
|                                                                       |
| --------------------------------------------------------------------- |
| - thank you for using dotenvx! - @​motdotla                            |
|_______________________________________________________________________|

v1.46.0

Compare Source

Added
  • Add error when hoisting issue experienced around commander.js (#​623)
Removed
  • Remove git-dotenvx and git dotenvx shorthand (#​621)

v1.45.2

Compare Source

Changed
  • Minor README updates

v1.45.1

Compare Source

Changed
  • Include setLogName and setLogVersion in config (#​613)

v1.45.0

Compare Source

Added
  • Add logger.setName and logger.setVersion for customization of logger (#​612)

v1.44.2

Compare Source

Changed
  • Clarify license is BSD-3.

v1.44.1

Compare Source

Changed

v1.44.0

Compare Source

Added

v1.43.0

Compare Source

Removed
  • Remove errorv, errornocolor, blank from logger options (#​584)
Changed
  • Replace instances of console.error with logger.error (#​584)

v1.42.2

Compare Source

Changed
  • Fix --force flag work with ?force=true (2776715)

v1.42.1

Compare Source

Added
  • Add --force flag to install.sh (0b8d21c)

v1.42.0

Compare Source

Added
  • Add ability to override the os and arch via install.sh and dotenvx.sh (3ded752)

v1.41.0

Compare Source

Added
  • Add [directory] argument to precommit and prebuild (#​572)

v1.40.1

[Compare Source](https://redirect.github.com/dotenvx/dotenvx


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "after 2am and before 3am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from sullivanpj as a code owner February 12, 2025 09:04
@renovate renovate bot added the dependencies Upgrade or downgrade of project dependencies. label Feb 12, 2025
@renovate renovate bot requested a review from a team as a code owner February 12, 2025 09:04
@renovate renovate bot enabled auto-merge February 12, 2025 09:04
@renovate
Copy link
Copy Markdown
Contributor Author

renovate bot commented Feb 12, 2025

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate renovate bot force-pushed the renovate/auto-merge-non-major-dependencies branch 19 times, most recently from 68221d7 to 769bd1f Compare February 19, 2025 17:01
@renovate renovate bot force-pushed the renovate/auto-merge-non-major-dependencies branch 6 times, most recently from 3be4251 to 96371f2 Compare February 23, 2025 00:24
@renovate renovate bot force-pushed the renovate/auto-merge-non-major-dependencies branch 8 times, most recently from b664b6b to 5b4af5f Compare March 7, 2025 10:19
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
@socket-security
Copy link
Copy Markdown

socket-security bot commented Sep 8, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @react-native/debugger-frontend is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: pnpm-lock.yamlnpm/@react-native/debugger-frontend@0.77.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@react-native/debugger-frontend@0.77.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/gitguardian.yml Fixed
Comment thread .github/workflows/codeql.yml Fixed
@renovate
Copy link
Copy Markdown
Contributor Author

renovate bot commented Jan 15, 2026

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
Installing config dependencies...
Installed config dependencies: pnpm-plugin-storm-software@0.1.5
Scope: all 29 workspace projects
Fetching Node.js 24.11.1 ...
Packages are hard linked from the content-addressable store to the virtual store.
  Content-addressable store is at: /runner/cache/others/pnpm/store/v10
  Virtual store is at:             node_modules/.pnpm
Progress: resolved 1, reused 0, downloaded 1, added 0
Progress: resolved 37, reused 0, downloaded 1, added 0
packages/hooks                           |  WARN  deprecated @types/react-native@0.73.0
Progress: resolved 68, reused 0, downloaded 1, added 0
packages/fs                              |  WARN  deprecated glob@11.1.0
Progress: resolved 107, reused 0, downloaded 1, added 0
Progress: resolved 113, reused 0, downloaded 1, added 0
Progress: resolved 117, reused 0, downloaded 1, added 0
Progress: resolved 193, reused 0, downloaded 1, added 0
Progress: resolved 242, reused 0, downloaded 1, added 0
Progress: resolved 275, reused 0, downloaded 1, added 0
Progress: resolved 308, reused 0, downloaded 1, added 0
Progress: resolved 337, reused 0, downloaded 1, added 0
Progress: resolved 367, reused 0, downloaded 1, added 0
Progress: resolved 437, reused 0, downloaded 1, added 0
Progress: resolved 554, reused 0, downloaded 1, added 0
Progress: resolved 592, reused 0, downloaded 1, added 0
Progress: resolved 688, reused 0, downloaded 1, added 0
Progress: resolved 827, reused 0, downloaded 1, added 0
Progress: resolved 873, reused 0, downloaded 1, added 0
Progress: resolved 917, reused 0, downloaded 1, added 0
Progress: resolved 951, reused 0, downloaded 1, added 0
Progress: resolved 1012, reused 0, downloaded 1, added 0
Progress: resolved 1067, reused 0, downloaded 1, added 0
Progress: resolved 1071, reused 0, downloaded 1, added 0
 WARN  Request took 12107ms: https://registry.npmjs.org/@prisma%2Ffetch-engine
Progress: resolved 1119, reused 0, downloaded 1, added 0
Progress: resolved 1293, reused 0, downloaded 1, added 0
Progress: resolved 1502, reused 0, downloaded 1, added 0
Progress: resolved 1769, reused 0, downloaded 1, added 0
Progress: resolved 1973, reused 0, downloaded 1, added 0
Progress: resolved 2158, reused 0, downloaded 1, added 0
Progress: resolved 2291, reused 0, downloaded 1, added 0
Progress: resolved 2350, reused 0, downloaded 1, added 0
Progress: resolved 2379, reused 0, downloaded 1, added 0
Progress: resolved 2398, reused 0, downloaded 1, added 0
Progress: resolved 2406, reused 0, downloaded 1, added 0
Progress: resolved 2411, reused 0, downloaded 1, added 0
Progress: resolved 2421, reused 0, downloaded 1, added 0
packages/trpc-next                       |  WARN  deprecated next@15.2.4
Progress: resolved 2423, reused 0, downloaded 1, added 0
Progress: resolved 2425, reused 0, downloaded 1, added 0
Progress: resolved 2436, reused 0, downloaded 1, added 0
Progress: resolved 2442, reused 0, downloaded 1, added 0
Progress: resolved 2447, reused 0, downloaded 1, added 0
Progress: resolved 2483, reused 0, downloaded 1, added 0
Progress: resolved 2484, reused 0, downloaded 1, added 0
 ERR_PNPM_UNUSED_PATCH  The following patches were not used: capnp-es@0.0.11

Either remove them from "patchedDependencies" or update them to match packages in your dependencies.

Comment thread .github/workflows/gitguardian.yml Fixed
steps:
- name: Cancel Previous Runs
uses: styfle/cancel-workflow-action@0.12.1
uses: styfle/cancel-workflow-action@0.13.1

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'CodeQL Scan' step
Uses Step
uses 'styfle/cancel-workflow-action' with ref '0.13.1', not a pinned commit hash
Comment thread .github/workflows/gitguardian.yml Fixed

- name: GitGuardian scan
uses: GitGuardian/ggshield/actions/secret@v1.39.0
uses: GitGuardian/ggshield/actions/secret@v1.49.0

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'GitGuardian Scan' step
Uses Step
uses 'GitGuardian/ggshield/actions/secret' with ref 'v1.49.0', not a pinned commit hash
@socket-security
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Upgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant