chore(deps-dev): bump the changelog group across 1 directory with 2 updates - #2669
dependabot[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
01aa6f2 to
2928a80
Compare
2928a80 to
5b13c48
Compare
5b13c48 to
8282cd1
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
8282cd1 to
3535398
Compare
3535398 to
cc42fd4
Compare
cc42fd4 to
4f30d99
Compare
4f30d99 to
13972b6
Compare
13972b6 to
1bf900d
Compare
1bf900d to
b8ba888
Compare
There was a problem hiding this comment.
Stale comment
Security review
No medium, high, or critical vulnerabilities identified in this update.
This Dependabot PR only bumps devDependencies
@changesets/changelog-github(0.7.0→1.0.1) and@changesets/cli(2.31.1→3.0.2), plus lockfile resolution. There is no application/runtime code change.Checked:
- No published GitHub Advisories for the targeted Changesets packages
- New lockfile packages (
@changesets/format,@manypkg/tools,jju,es-module-lexer,picomatch@4.0.7) are expected Changesets v3 / pnpm graph deps, not typosquats- Introduced
picomatch@4.0.7is past GHSA-3v7f-55p6-f55p / GHSA-c2c7-rcm5-vvqj (< 4.0.4)- Transitive churn (
undici6.28.1 / 7.29.1,h32.0.1-rc.31,srvx1.0.3,terser5.51.2) is at or above patched advisory ranges- Integrity hashes present; usage remains local/CI changelog and release tooling (
.changeset/config.jsonalready pinsrepo: shopware/frontends)No inline findings.
Sent by Cursor Automation: Review pull requests for exploitable security issues and flag only validated findings before merge
…pdates Bumps the changelog group with 2 updates in the / directory: [@changesets/changelog-github](https://github.com/changesets/changesets/tree/HEAD/packages/changelog-github) and [@changesets/cli](https://github.com/changesets/changesets/tree/HEAD/packages/cli). Updates `@changesets/changelog-github` from 0.7.0 to 1.0.1 - [Release notes](https://github.com/changesets/changesets/releases) - [Changelog](https://github.com/changesets/changesets/blob/main/packages/changelog-github/CHANGELOG.md) - [Commits](https://github.com/changesets/changesets/commits/@changesets/changelog-github@1.0.1/packages/changelog-github) Updates `@changesets/cli` from 2.31.1 to 3.0.2 - [Release notes](https://github.com/changesets/changesets/releases) - [Changelog](https://github.com/changesets/changesets/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/changesets/changesets/commits/@changesets/cli@3.0.2/packages/cli) --- updated-dependencies: - dependency-name: "@changesets/changelog-github" dependency-version: 1.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: changelog - dependency-name: "@changesets/cli" dependency-version: 3.0.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: changelog ... Signed-off-by: dependabot[bot] <support@github.com>
b8ba888 to
23acd9b
Compare
There was a problem hiding this comment.
Security review
No medium, high, or critical vulnerabilities identified.
This Dependabot recreate still only bumps root devDependencies @changesets/changelog-github (0.7.0 → 1.0.1) and @changesets/cli (2.31.1 → 3.0.2), plus lockfile resolution. There is no application or runtime code change.
Checked on 23acd9bb:
- No published GitHub Advisories for the targeted Changesets packages
- npm
dist.integritymatches the lockfile for both direct deps - Introduced Changesets v3 graph (
@changesets/format,picomatch@4.0.7,launch-editor@2.14.1,yaml@2.9.0) is at or above patched advisory ranges - Usage remains local/CI changelog and release tooling;
.changeset/config.jsonalready pinsrepo: shopware/frontends
No prior unresolved automation finding threads. No inline findings.
Sent by Cursor Automation: Review pull requests for exploitable security issues and flag only validated findings before merge
|
Looks like these dependencies are no longer updatable, so this is no longer needed. |


Bumps the changelog group with 2 updates in the / directory: @changesets/changelog-github and @changesets/cli.
Updates
@changesets/changelog-githubfrom 0.7.0 to 1.0.1Release notes
Sourced from @changesets/changelog-github's releases.
... (truncated)
Changelog
Sourced from @changesets/changelog-github's changelog.
... (truncated)
Commits
d7e4a2dVersion Packages (#2266)f442221Version Packages (#2235)baa658dVersion Packages (next) (#2192)1b9687fAdd new docs site (#1979)7fd0d91Version Packages (next) (#2173)180833eVersion Packages (next) (#2142)162419dadd or modifyfiles(#2160)c35c350Version Packages (next) (#2122)070f531Addtemplateoption tochangelog-github(#2059)dfefc4eUseGITHUB_REPOSITORYas the default repo when norepooption is configur...Updates
@changesets/clifrom 2.31.1 to 3.0.2Release notes
Sourced from @changesets/cli's releases.
... (truncated)
Changelog
Sourced from @changesets/cli's changelog.
... (truncated)
Commits
d7e4a2dVersion Packages (#2266)68affeeUpgrade to Vitest 5 (#2281)5eeb012Build(deps): Bump human-id in the production-dependencies group (#2279)a0a4dc6Add review message on pre exit (#2270)1f4eb61Add default changelog message for empty release (#2265)2eb65baAdd script to run unit and e2e tests separately (#2267)ff2b075Build(deps-dev): Bump@lydell/node-pty(#2254)8eff462Build(deps-dev): Bump the development-dependencies group across 1 directory w...bed4581Version Packages (#2242)fdfdc93Update default generated readme (#2239)