Commit bb3a6b7
authored
deps: bump pacote from 21.3.1 to 21.4.0 in the dependency-updates group (#1086)
Bumps the dependency-updates group with 1 update:
[pacote](https://github.com/npm/pacote).
Updates `pacote` from 21.3.1 to 21.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/npm/pacote/releases">pacote's
releases</a>.</em></p>
<blockquote>
<h2>v21.4.0</h2>
<h2><a
href="https://github.com/npm/pacote/compare/v21.3.1...v21.4.0">21.4.0</a>
(2026-02-24)</h2>
<h3>Features</h3>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/6912f249599e9e27ed0b79ab0652cc60f6d2f755"><code>6912f24</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/451">#451</a> add
allowRegistry option (<a
href="https://redirect.github.com/npm/pacote/issues/451">#451</a>) (<a
href="https://github.com/wraithgar"><code>@wraithgar</code></a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/ab37bc1e7d0f1c0a590770e650f93500caa9b206"><code>ab37bc1</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/452">#452</a>
prevent path duplication in attestation URL for registries with … (<a
href="https://redirect.github.com/npm/pacote/issues/452">#452</a>) (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/ab37bc1e7d0f1c0a590770e650f93500caa9b206"><code>ab37bc1</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/452">#452</a>
prevent path duplication in attestation URL for registries with (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/8b8ea3b27f49097806fc798b478c5179bea21266"><code>8b8ea3b</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/454">#454</a> skip
registry key check for keyless (Sigstore/Fulcio) attestations (<a
href="https://redirect.github.com/npm/pacote/issues/454">#454</a>) (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/8b8ea3b27f49097806fc798b478c5179bea21266"><code>8b8ea3b</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/454">#454</a> skip
registry key check for keyless (Sigstore/Fulcio) attestations (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/0dfd1cdc15cf8586d0d7c1f4b30bffe73d5277dc"><code>0dfd1cd</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/456">#456</a>
remove git config from tests (<a
href="https://redirect.github.com/npm/pacote/issues/456">#456</a>) (<a
href="https://github.com/wraithgar"><code>@wraithgar</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/npm/pacote/blob/main/CHANGELOG.md">pacote's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/npm/pacote/compare/v21.3.1...v21.4.0">21.4.0</a>
(2026-02-24)</h2>
<h3>Features</h3>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/6912f249599e9e27ed0b79ab0652cc60f6d2f755"><code>6912f24</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/451">#451</a> add
allowRegistry option (<a
href="https://redirect.github.com/npm/pacote/issues/451">#451</a>) (<a
href="https://github.com/wraithgar"><code>@wraithgar</code></a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/ab37bc1e7d0f1c0a590770e650f93500caa9b206"><code>ab37bc1</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/452">#452</a>
prevent path duplication in attestation URL for registries with … (<a
href="https://redirect.github.com/npm/pacote/issues/452">#452</a>) (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/ab37bc1e7d0f1c0a590770e650f93500caa9b206"><code>ab37bc1</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/452">#452</a>
prevent path duplication in attestation URL for registries with (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/8b8ea3b27f49097806fc798b478c5179bea21266"><code>8b8ea3b</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/454">#454</a> skip
registry key check for keyless (Sigstore/Fulcio) attestations (<a
href="https://redirect.github.com/npm/pacote/issues/454">#454</a>) (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/8b8ea3b27f49097806fc798b478c5179bea21266"><code>8b8ea3b</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/454">#454</a> skip
registry key check for keyless (Sigstore/Fulcio) attestations (<a
href="https://github.com/ajayk"><code>@ajayk</code></a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/0dfd1cdc15cf8586d0d7c1f4b30bffe73d5277dc"><code>0dfd1cd</code></a>
<a href="https://redirect.github.com/npm/pacote/pull/456">#456</a>
remove git config from tests (<a
href="https://redirect.github.com/npm/pacote/issues/456">#456</a>) (<a
href="https://github.com/wraithgar"><code>@wraithgar</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/npm/pacote/commit/e3871d830ad0d9e4c3a71502dc77c309804671f9"><code>e3871d8</code></a>
chore: release 21.4.0 (<a
href="https://redirect.github.com/npm/pacote/issues/455">#455</a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/0dfd1cdc15cf8586d0d7c1f4b30bffe73d5277dc"><code>0dfd1cd</code></a>
chore: remove git config from tests (<a
href="https://redirect.github.com/npm/pacote/issues/456">#456</a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/bfe6f232ea169ddf884203128e5bac1c131706d0"><code>bfe6f23</code></a>
Update to newer promise-retry library (<a
href="https://redirect.github.com/npm/pacote/issues/449">#449</a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/6912f249599e9e27ed0b79ab0652cc60f6d2f755"><code>6912f24</code></a>
feat: add allowRegistry option (<a
href="https://redirect.github.com/npm/pacote/issues/451">#451</a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/ab37bc1e7d0f1c0a590770e650f93500caa9b206"><code>ab37bc1</code></a>
fix: prevent path duplication in attestation URL for registries with …
(<a
href="https://redirect.github.com/npm/pacote/issues/452">#452</a>)</li>
<li><a
href="https://github.com/npm/pacote/commit/8b8ea3b27f49097806fc798b478c5179bea21266"><code>8b8ea3b</code></a>
fix: skip registry key check for keyless (Sigstore/Fulcio) attestations
(<a
href="https://redirect.github.com/npm/pacote/issues/454">#454</a>)</li>
<li>See full diff in <a
href="https://github.com/npm/pacote/compare/v21.3.1...v21.4.0">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent 29d048d commit bb3a6b7
1 file changed
+26
-5
lines changedSome generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments