Skip to content

Bump flatted, rewire and gts in /functions#91

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/functions/multi-79d9e33a7f
Open

Bump flatted, rewire and gts in /functions#91
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/functions/multi-79d9e33a7f

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 20, 2026

Bumps flatted to 3.4.2 and updates ancestor dependencies flatted, rewire and gts. These dependencies need to be updated together.

Updates flatted from 2.0.2 to 3.4.2

Commits
  • 3bf0909 3.4.2
  • 885ddcc fix CWE-1321
  • 0bdba70 added flatted-view to the benchmark
  • 2a02dce 3.4.1
  • fba4e8f Merge pull request #89 from WebReflection/python-fix
  • 5fe8648 added "when in Rome" also a test for PHP
  • 53517ad some minor improvement
  • b3e2a0c Fixing recursion issue in Python too
  • c4b46db Add SECURITY.md for security policy and reporting
  • f86d071 Create dependabot.yml for version updates
  • Additional commits viewable in compare view

Updates rewire from 5.0.0 to 9.0.1

Release notes

Sourced from rewire's releases.

v9.0.1

  • Fix: Use pirates for proper load extensions install/uninstall handling #219

v9.0.0

  • Breaking: Update ESLint runtime dependency to v9 #218. This is most likely not a breaking change for rewire users but we can't know for certain.

v8.0.0

  • Breaking: Remove official Node v18 support. There is no known issue but our CI won't test against it anymore.
  • Fix Node v22 issues

v7.0.0

v6.0.0

  • Breaking: Remove Node v8 support. We had to do this because one of our dependencies had security issues and the version with the fix dropped Node v8 as well.
  • Update dependencies #193
  • Fix Modifying globals within module leaks to global with Node >=10 #167
  • Fixed import errors on modules with shebang declarations #179
Changelog

Sourced from rewire's changelog.

9.0.1

  • Fix: Use pirates for proper load extensions install/uninstall handling #219

9.0.0

  • Breaking: Update ESLint runtime dependency to v9 #218. This is most likely not a breaking change for rewire users but we can't know for certain.

8.0.0

  • Breaking: Remove official Node v18 support. There is no known issue but our CI won't test against it anymore.
  • Fix Node v22 issues

7.0.0

6.0.0

  • Breaking: Remove Node v8 support. We had to do this because one of our dependencies had security issues and the version with the fix dropped Node v8 as well.
  • Update dependencies #193
  • Fix Modifying globals within module leaks to global with Node >=10 #167
  • Fixed import errors on modules with shebang declarations #179
Commits

Updates gts from 2.0.2 to 7.0.0

Release notes

Sourced from gts's releases.

v7.0.0

7.0.0 (2025-12-04)

⚠ BREAKING CHANGES

  • eslint use new config format (plus update deps) (#935)

Features

  • eslint use new config format (plus update deps) (#935) (625836a)

v6.0.2

6.0.2 (2024-10-25)

Bug Fixes

v6.0.1

6.0.1 (2024-10-22)

Bug Fixes

  • Allow typescript v5+ as a peer dependency (#909) (996aaec)

v6.0.0

6.0.0 (2024-10-10)

⚠ BREAKING CHANGES

  • Update '.prettierrc.json' to include trailingComma: "all" to match internal Google config (#822)
  • Update typescript and other dependencies (#902)
  • Set no-floating-promises to error (#901)
  • Set composite: true in tsconfig-google.json (#899)
  • Set stripInternal in tsconfig-google.json (#900)
  • Support Node 18+ (#896)

Features

  • Set composite: true in tsconfig-google.json (#899) (71972dc)
  • Set no-floating-promises to error (#901) (1d28f92)
  • Set stripInternal in tsconfig-google.json (#900) (9b37243)
  • Support Node 18+ (#896) (f011fa3)
  • Update '.prettierrc.json' to include trailingComma: "all" to match internal Google config (#822) (27d0d93)
  • Update typescript and other dependencies (#902) (1c18b3a)

... (truncated)

Changelog

Sourced from gts's changelog.

7.0.0 (2025-12-04)

⚠ BREAKING CHANGES

  • eslint use new config format (plus update deps) (#935)

Features

  • eslint use new config format (plus update deps) (#935) (625836a)

6.0.2 (2024-10-25)

Bug Fixes

6.0.1 (2024-10-22)

Bug Fixes

  • Allow typescript v5+ as a peer dependency (#909) (996aaec)

6.0.0 (2024-10-10)

⚠ BREAKING CHANGES

  • Update '.prettierrc.json' to include trailingComma: "all" to match internal Google config (#822)
  • Update typescript and other dependencies (#902)
  • Set no-floating-promises to error (#901)
  • Set composite: true in tsconfig-google.json (#899)
  • Set stripInternal in tsconfig-google.json (#900)
  • Support Node 18+ (#896)

Features

  • Set composite: true in tsconfig-google.json (#899) (71972dc)
  • Set no-floating-promises to error (#901) (1d28f92)
  • Set stripInternal in tsconfig-google.json (#900) (9b37243)
  • Support Node 18+ (#896) (f011fa3)
  • Update '.prettierrc.json' to include trailingComma: "all" to match internal Google config (#822) (27d0d93)
  • Update typescript and other dependencies (#902) (1c18b3a)

Bug Fixes

  • deps: update dependency eslint to v8.57.1 (#903) (23da8ef)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [flatted](https://github.com/WebReflection/flatted) to 3.4.2 and updates ancestor dependencies [flatted](https://github.com/WebReflection/flatted), [rewire](https://github.com/jhnns/rewire) and [gts](https://github.com/google/gts). These dependencies need to be updated together.


Updates `flatted` from 2.0.2 to 3.4.2
- [Commits](WebReflection/flatted@v2.0.2...v3.4.2)

Updates `rewire` from 5.0.0 to 9.0.1
- [Release notes](https://github.com/jhnns/rewire/releases)
- [Changelog](https://github.com/jhnns/rewire/blob/master/CHANGELOG.md)
- [Commits](jhnns/rewire@v5.0.0...v9.0.1)

Updates `gts` from 2.0.2 to 7.0.0
- [Release notes](https://github.com/google/gts/releases)
- [Changelog](https://github.com/google/gts/blob/main/CHANGELOG.md)
- [Commits](google/gts@v2.0.2...v7.0.0)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
- dependency-name: rewire
  dependency-version: 9.0.1
  dependency-type: direct:production
- dependency-name: gts
  dependency-version: 7.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants