Skip to content

fix(deps): update type dependencies (patch)#254

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/patch-types
Open

fix(deps): update type dependencies (patch)#254
renovate[bot] wants to merge 1 commit intomainfrom
renovate/patch-types

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Dec 27, 2025

This PR contains the following updates:

Package Change Age Confidence
@types/debug (source) 4.1.124.1.13 age confidence
@types/node (source) 24.10.924.10.15 age confidence
type-fest 5.4.35.4.4 age confidence

Release Notes

sindresorhus/type-fest (type-fest)

v5.4.4

Compare Source

  • PackageJson: Use LiteralUnion for engines field (#​1354) fc9e2bb
  • IsUnion: Fix behavior when the entire union extends all individual members (#​1353) b0321a5
  • Paths: Fix leavesOnly behavior with never leaves (#​1350) 2c34128
  • Paths: Fix behavior with WeakMaps / WeakSets (#​1348) ac3b50e
  • Paths: Fix behavior with tuples containing optional elements with a rest element (#​1346) 7c82a21


Configuration

📅 Schedule: Branch creation - "after 1am and before 5am every weekend" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the c: dependencies Pull requests that adds/updates a dependency label Dec 27, 2025
@renovate renovate bot requested a review from prisis as a code owner December 27, 2025 02:07
@renovate renovate bot enabled auto-merge (squash) December 27, 2025 02:07
@renovate renovate bot added the c: dependencies Pull requests that adds/updates a dependency label Dec 27, 2025
@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai bot commented Dec 27, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 27, 2025

Thank you for following the naming conventions! 🙏

@socket-security
Copy link
Copy Markdown

socket-security bot commented Dec 27, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​node@​24.10.9 ⏵ 24.10.1510010081 +196 +2100
Added@​types/​debug@​4.1.131001008885100
Addedgot@​14.6.69910010085100

View full report

@renovate renovate bot force-pushed the renovate/patch-types branch from 40ba353 to df3ae48 Compare January 10, 2026 02:00
prisis
prisis previously approved these changes Jan 11, 2026
@prisis prisis disabled auto-merge January 11, 2026 19:39
@renovate renovate bot enabled auto-merge (squash) January 11, 2026 19:39
@renovate renovate bot force-pushed the renovate/patch-types branch 2 times, most recently from 86d7c2e to d6c8e29 Compare January 17, 2026 00:36
@renovate renovate bot force-pushed the renovate/patch-types branch from d6c8e29 to debcf12 Compare January 24, 2026 01:14
@renovate renovate bot changed the title fix(deps): update type dependencies (patch) fix(deps): update type dependencies (patch) - autoclosed Feb 2, 2026
@renovate renovate bot closed this Feb 2, 2026
auto-merge was automatically disabled February 2, 2026 11:00

Pull request was closed

@renovate renovate bot deleted the renovate/patch-types branch February 2, 2026 11:00
@renovate renovate bot changed the title fix(deps): update type dependencies (patch) - autoclosed fix(deps): update dependency @types/node to v24.10.10 Feb 7, 2026
@renovate renovate bot reopened this Feb 7, 2026
@renovate renovate bot force-pushed the renovate/patch-types branch 2 times, most recently from debcf12 to 1d3d741 Compare February 7, 2026 01:43
@socket-security
Copy link
Copy Markdown

socket-security bot commented Feb 7, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Handlebars.js has JavaScript Injection via AST Type Confusion

CVE: GHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type Confusion (CRITICAL)

Affected versions: >= 4.0.0 < 4.7.9

Patched version: 4.7.9

From: pnpm-lock.yamlnpm/@semantic-release/commit-analyzer@13.0.1npm/@semantic-release/release-notes-generator@14.1.0npm/handlebars@4.7.8

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/handlebars@4.7.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot enabled auto-merge (squash) February 8, 2026 02:00
@renovate renovate bot force-pushed the renovate/patch-types branch from 1d3d741 to 5c0d8d7 Compare February 14, 2026 02:07
@renovate renovate bot changed the title fix(deps): update dependency @types/node to v24.10.10 fix(deps): update type dependencies (patch) Feb 14, 2026
@renovate renovate bot force-pushed the renovate/patch-types branch 2 times, most recently from 5f4f11a to fbf95e8 Compare March 7, 2026 03:02
Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate renovate bot force-pushed the renovate/patch-types branch from fbf95e8 to db9222f Compare March 28, 2026 01:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c: dependencies Pull requests that adds/updates a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant