Skip to content

[pull] main from renovatebot:main#1032

Merged
pull[bot] merged 5 commits intoryrodriguez25:mainfrom
renovatebot:main
Apr 9, 2026
Merged

[pull] main from renovatebot:main#1032
pull[bot] merged 5 commits intoryrodriguez25:mainfrom
renovatebot:main

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Apr 9, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

renovate bot and others added 5 commits April 9, 2026 07:33
….19 (main) (#42498)

fix(deps): update ghcr.io/renovatebot/base-image docker tag to v13.33.19

| datasource | package                        | from     | to       |
| ---------- | ------------------------------ | -------- | -------- |
| docker     | ghcr.io/renovatebot/base-image | 13.33.18 | 13.33.19 |

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…ce of truth (#42494)

* refactor(github/vulnerability): use Zod-inferred types as single source of truth

* revert to false, since undefined means something else on GHES
As part of future work, we'll need this to mark explicitly malicious
packages as skipped, with their own distinct reason.
…2504)

As part of future changes, we'll be introducing `skipReason: malicious`
against dependencies that have been found to be actively malicious.

Once we've looked up all our dependencies, we should then - centrally -
log any malicious package usages as a WARN, to highlight this to users.
@pull pull bot locked and limited conversation to collaborators Apr 9, 2026
@pull pull bot added the ⤵️ pull label Apr 9, 2026
@pull pull bot merged commit 1caa918 into ryrodriguez25:main Apr 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants