Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 1, 2024

This PR contains the following updates:

Package Change Age Confidence
@sanity/pkg-utils (source) ^2.2.5^4.4.4 age confidence

Release Notes

sanity-io/pkg-utils (@​sanity/pkg-utils)

v4.4.4

Compare Source

v4.4.3

Compare Source

v4.4.2

Compare Source

v4.4.1

Compare Source

Bug Fixes

v4.4.0

Compare Source

Features
Bug Fixes

v4.3.1

Compare Source

Bug Fixes

v4.3.0

Compare Source

Features
  • make [hash] in chunk file names opt-in (5181ac4)
Bug Fixes

v4.2.11

Compare Source

Bug Fixes
  • deps: update dependency prettier-plugin-packagejson to ^2.4.12 (#​525) (502e2a5)

v4.2.10

Compare Source

Bug Fixes

v4.2.9

Compare Source

Bug Fixes
  • only minifyInternalExports when compact is true (8a9d83d)

v4.2.8

Compare Source

Bug Fixes

v4.2.7

Compare Source

Bug Fixes
  • minify syntax by default (09ffc73)

v4.2.6

Compare Source

Bug Fixes
  • set terser compress directives to false (b707e4d)

v4.2.5

Compare Source

Bug Fixes

v4.2.4

Compare Source

Bug Fixes

v4.2.3

Compare Source

Bug Fixes
  • deps: update dependency prettier-plugin-packagejson to ^2.4.11 (#​497) (e938910)

v4.2.2

Compare Source

Bug Fixes

v4.2.0

Compare Source

Features

v4.1.5

Compare Source

Bug Fixes

v4.1.4

Compare Source

Bug Fixes

v4.1.3

Compare Source

Bug Fixes

v4.1.2

Compare Source

Bug Fixes
  • deps: update dependency prettier-plugin-packagejson to ^2.4.10 (#​446) (269ca72)

v4.1.1

Compare Source

Bug Fixes

v4.1.0

Compare Source

Features
Bug Fixes

v4.0.0

Compare Source

⚠ BREAKING CHANGES
  • only run babel if a custom babel plugin is specified
  • remove @babel/preset-env
Bug Fixes

v3.3.8

Compare Source

Bug Fixes

v3.3.7

Compare Source

Bug Fixes

v3.3.6

Compare Source

Bug Fixes

v3.3.5

Compare Source

Bug Fixes

v3.3.4

Compare Source

Bug Fixes

v3.3.3

Compare Source

Bug Fixes

v3.3.2

Compare Source

Bug Fixes

v3.3.1

Compare Source

Bug Fixes
  • deps: update dependency browserslist to ^4.22.2 (#​358) (2fbbe8e)
  • deps: update dependency prettier-plugin-packagejson to ^2.4.7 (#​360) (eed9ca1)
  • deps: update dependency rollup to ^4.6.1 (#​353) (fe3e0c5)

v3.3.0

Compare Source

Features
  • allow setting experimental rollup output options (a4b80c6)

v3.2.5

Compare Source

Bug Fixes

v3.2.4

Compare Source

Bug Fixes

v3.2.3

Compare Source

Bug Fixes

v3.2.2

Compare Source

Bug Fixes
  • template: add eslint rules (be1f151)

v3.2.1

Compare Source

Bug Fixes

v3.2.0

Compare Source

Features
  • allow setting bundledPackages in api extractor (3f7fce8)

v3.1.1

Compare Source

Bug Fixes

v3.1.0

Compare Source

Features
Bug Fixes
  • remove experimental preserveModuleDirectives option (fadf008)

v3.0.0

Compare Source

⚠ BREAKING CHANGES
  • deps: update dependency rollup to v4 (#​256)
Bug Fixes

v2.4.10

Compare Source

Bug Fixes

v2.4.9

Compare Source

Bug Fixes
  • node.module: stop warning about missing node.module (5e6cee5)
  • throw DtsError with errors only (#​221) (983cf10)

v2.4.8

Compare Source

Bug Fixes

v2.4.7

Compare Source

Bug Fixes

v2.4.6

Compare Source

Bug Fixes

v2.4.5

Compare Source

Bug Fixes
  • build: include recast (commonjs) module in bundle (402e95f)

v2.4.4

Compare Source

Bug Fixes

v2.4.3

Compare Source

Bug Fixes

v2.4.2

Compare Source

Bug Fixes
  • make node.module optional (0896d7a)

v2.4.1

Compare Source

Bug Fixes

v2.4.0

Compare Source

Features

v2.3.14

Compare Source

Bug Fixes

v2.3.13

Compare Source

Bug Fixes
  • make "node.require" optional when re-exporting CJS (#​171) (a75f377)

v2.3.12

Compare Source

Bug Fixes
  • handle edge case for default exports (17158bd)

v2.3.11

Compare Source

Bug Fixes
  • don't add cjs.default if there is no default export in source (ea7b53c)

v2.3.10

Compare Source

Bug Fixes

v2.3.9

Compare Source

Bug Fixes

v2.3.8

Compare Source

Bug Fixes

v2.3.7

Compare Source

Bug Fixes

v2.3.6

Compare Source

Bug Fixes
  • deps: bump prettier to v3 (4728158)

v2.3.5

Compare Source

Bug Fixes

v2.3.4

Compare Source

Bug Fixes
  • build: print bundles nicely (85c5eeb)
  • build: use correct target for extra bundles (13f242f)
  • check: filter and print esbuild messages nicely (f0d6501)

v2.3.3

Compare Source

Bug Fixes

v2.3.2

Compare Source

Bug Fixes

v2.3.1

Compare Source

Bug Fixes

v2.3.0

Compare Source

Features
Bug Fixes
  • init: add package.config.ts to template (0374445)

v2.2.17

Compare Source

Bug Fixes
  • add alias to check command (28a85fd)
  • deps: update dependencies (b6253d7)
  • support latest maintained Node.js version (2df5924)

v2.2.16

Compare Source

Bug Fixes
  • deps: update dependencies (9229fd0)

v2.2.15

Compare Source

Bug Fixes

Configuration

📅 Schedule: Branch creation - "before 3am on the first day of the month" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here

@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch 3 times, most recently from 14fced0 to 1d7ae06 Compare March 6, 2024 13:30
@socket-security
Copy link

socket-security bot commented Mar 6, 2024

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpuppeteer@​19.8.59210010050100
Addedprettier-plugin-packagejson@​2.5.201001007788100
Addedprettier@​2.8.7991009895100
Updated@​sanity/​pkg-utils@​2.2.14 ⏵ 4.4.496 +1100100100 +1100

View full report

@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch 2 times, most recently from d987af3 to 1ddd157 Compare March 19, 2024 10:01
@socket-security
Copy link

socket-security bot commented Mar 19, 2024

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Critical
Malicious package: npm acorn

Note: This VS Code extension is classified as malware because it exhibits high-confidence brandjacking and typosquatting indicators that strongly imply deceptive distribution and user impersonation:

  • Publisher impersonation: The VSIX claims to be “JFrog VSCode Extension,” but it is published by Artifactory-Software-Studio, not the official JFrog publisher.
  • Typosquatted identifier: The extension’s identity is vscode-jrrog-extension (note the “jrrog” typo), which is a look-alike of the official JFrog extension identifier and consistent with marketplace typosquat tactics.
  • Abuse of trust via branding: The manifest and package metadata deliberately reuse JFrog’s brand name (“JFrog VSCode Extension”) to induce installation under false provenance.
  • High-risk capability overlap: The extension’s functionality includes reading JFrog CLI configuration/credentials and initiating outbound network connections for scanning workflows. In a typosquatted/impersonating package, these capabilities materially increase the likelihood of credential theft or sensitive project metadata leakage, regardless of whether the current bundle contains overt C2 logic.

Together, the deceptive provenance (non-official publisher + typo-lookalike ID + brand reuse) is sufficient to classify the extension as malicious because it is designed to obtain installs by masquerading as a trusted vendor extension, a common precursor to credential harvesting and supply-chain compromise.

From: package-lock.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is known malware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: It is strongly recommended that malware is removed from your codebase.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from 1ddd157 to 4ef3bcd Compare March 19, 2024 23:08
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch 2 times, most recently from 3405c26 to b66ca1c Compare August 13, 2025 16:53
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from b66ca1c to 9c2972c Compare August 19, 2025 19:04
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from 9c2972c to 7dd3998 Compare August 31, 2025 12:29
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from 7dd3998 to 83ecd3b Compare September 25, 2025 20:08
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from 83ecd3b to ab695e2 Compare October 21, 2025 15:44
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from ab695e2 to d75ff7b Compare November 10, 2025 20:15
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from d75ff7b to 1af8c7f Compare November 18, 2025 13:11
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from 1af8c7f to b96e4eb Compare December 3, 2025 17:13
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from b96e4eb to 7321151 Compare December 31, 2025 14:04
@renovate renovate bot force-pushed the renovate/sanity-pkg-utils-4.x branch from 7321151 to 2fb72b9 Compare January 8, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant