Skip to content

Bump serialize-javascript from 6.0.1 to 6.0.2 in /docs/utils/webpack#119

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/docs/utils/webpack/serialize-javascript-6.0.2
Closed

Bump serialize-javascript from 6.0.1 to 6.0.2 in /docs/utils/webpack#119
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/docs/utils/webpack/serialize-javascript-6.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 9, 2026

Copy link
Copy Markdown

Bumps serialize-javascript from 6.0.1 to 6.0.2.

Release notes

Sourced from serialize-javascript's releases.

v6.0.2

  • fix: serialize URL string contents to prevent XSS (#173) f27d65d
  • Bump @​babel/traverse from 7.10.1 to 7.23.7 (#171) 02499c0
  • docs: update readme with URL support (#146) 0d88527
  • chore: update node version and lock file e2a3a91
  • fix typo (#164) 5a1fa64

yahoo/serialize-javascript@v6.0.1...v6.0.2

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [serialize-javascript](https://github.com/yahoo/serialize-javascript) from 6.0.1 to 6.0.2.
- [Release notes](https://github.com/yahoo/serialize-javascript/releases)
- [Commits](yahoo/serialize-javascript@v6.0.1...v6.0.2)

---
updated-dependencies:
- dependency-name: serialize-javascript
  dependency-version: 6.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 9, 2026
@negz

negz commented Jun 10, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jun 10, 2026

Copy link
Copy Markdown
Author

None of your dependencies match this group anymore, you may need to update your configuration file to remove it or change its rules.

@dependabot dependabot Bot closed this Jun 10, 2026
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/docs/utils/webpack/serialize-javascript-6.0.2 branch June 10, 2026 20:19
negz added a commit that referenced this pull request Jun 15, 2026
Generating Python schemas for an XRD that declares a scale subresource
produces a model of the autoscaling Scale type in place of the
resource's own model, breaking the composition functions that import it.
crossplane/cli#119 fixes this.

This pins the crossplane-cli flake input to that PR branch so schema
generation works. Repin to crossplane/cli main once #119 merges.

Signed-off-by: Nic Cope <nicc@rk0n.org>
negz added a commit that referenced this pull request Jun 20, 2026
The flake pinned crossplane-cli to the negz/cli default-to-go branch
because the CLI changes modelplane depends on weren't yet merged
upstream. They now are: #126 (host-native default flake package) merged,
joining the already-merged #24, #64, and #119, and #127 (decompress
function runtime tarballs once when loading) merged on top.

This change repoints the input at crossplane/cli main and bumps the lock
to that commit, so we no longer depend on a personal fork. It stays on
main rather than a tag because the fixes aren't in a release yet.

Signed-off-by: Nic Cope <nicc@rk0n.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant