chore(deps): bump lodash and verdaccio in /src - #760
Conversation
Bumps [lodash](https://github.com/lodash/lodash) to 4.18.1 and updates ancestor dependency [verdaccio](https://github.com/verdaccio/verdaccio). These dependencies need to be updated together. Updates `lodash` from 4.17.23 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.23...4.18.1) Updates `verdaccio` from 6.3.2 to 6.9.0 - [Release notes](https://github.com/verdaccio/verdaccio/releases) - [Changelog](https://github.com/verdaccio/verdaccio/blob/v6.9.0/CHANGELOG.md) - [Commits](verdaccio/verdaccio@v6.3.2...v6.9.0) --- updated-dependencies: - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect - dependency-name: verdaccio dependency-version: 6.9.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps lodash to 4.18.1 and updates ancestor dependency verdaccio. These dependencies need to be updated together.
Updates
lodashfrom 4.17.23 to 4.18.1Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)Updates
verdacciofrom 6.3.2 to 6.9.0Release notes
Sourced from verdaccio's releases.
... (truncated)
Changelog
Sourced from verdaccio's changelog.
... (truncated)
Commits
e327545chore: release 6.x (#6058)2969ec8fix: migrate uplink/storage URL parsing to the WHATWG URL API (#6066)b67a665feat: dual ESM/CJS build, require Node.js 22 (#6050)4071a51chore(deps): update yarn to v4.17.1 (#6055)4cede16chore(deps): update dependency fast-uri to v3.1.4 [security] (6.x) (#6043)b4ca2c5chore: release 6.x (#5981)962fba8feat: add publish/unpublish hook (#6020)e663cc4fix(deps): update dependency semver to v7.8.5 (#6013)808d916fix: pick the right uplink for tarballs and heal missing distfile rec… (#6009)a2de1d5chore: update verdaccio 6.x dependencies (#6003)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for verdaccio since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.