Skip to content

chore(deps): pin 41 dependency versions#8

Open
bagui-security-agent[bot] wants to merge 1 commit into
mainfrom
ananke-pin-deps-1778587043331
Open

chore(deps): pin 41 dependency versions#8
bagui-security-agent[bot] wants to merge 1 commit into
mainfrom
ananke-pin-deps-1778587043331

Conversation

@bagui-security-agent
Copy link
Copy Markdown

Supply Chain Fix

This PR was automatically generated by ananke to pin 41 unpinned dependencies to their latest stable versions.

Changes

File Dependency Before After Source
figma/Plugin-Centaury Contents/package.json react ^18.2.0 18.3.1 lockfile
figma/Plugin-Centaury Contents/package.json react-dom ^18.2.0 18.3.1 lockfile
figma/Plugin-Centaury Contents/package.json @figma/plugin-typings * 1.123.0 lockfile
figma/Plugin-Centaury Contents/package.json @types/figma ^1.0.8 1.0.8 lockfile
figma/Plugin-Centaury Contents/package.json @types/node ^16.7.1 16.18.126 lockfile
figma/Plugin-Centaury Contents/package.json @types/react ^18.2.55 18.3.28 lockfile
figma/Plugin-Centaury Contents/package.json @types/react-dom ^18.2.19 18.3.7 lockfile
figma/Plugin-Centaury Contents/package.json autoprefixer ^10.4.20 10.4.27 lockfile
figma/Plugin-Centaury Contents/package.json css-loader ^6.10.0 6.11.0 lockfile
figma/Plugin-Centaury Contents/package.json html-webpack-plugin ^5.6.0 5.6.6 lockfile
figma/Plugin-Centaury Contents/package.json postcss ^8.4.35 8.5.8 lockfile
figma/Plugin-Centaury Contents/package.json postcss-loader ^8.1.0 8.2.1 lockfile
figma/Plugin-Centaury Contents/package.json style-loader ^3.3.4 3.3.4 lockfile
figma/Plugin-Centaury Contents/package.json tailwindcss ^3.4.1 3.4.19 lockfile
figma/Plugin-Centaury Contents/package.json ts-loader ^9.5.1 9.5.4 lockfile
figma/Plugin-Centaury Contents/package.json typescript ^5.3.3 5.9.3 lockfile
figma/Plugin-Centaury Contents/package.json url-loader ^4.1.1 4.1.1 lockfile
figma/Plugin-Centaury Contents/package.json webpack ^5.105.4 5.105.4 lockfile
figma/Plugin-Centaury Contents/package.json webpack-cli ^5.1.4 5.1.4 lockfile
figma/Plugin-IconBridge/node_modules/typescript/package.json typescript ^5.6.2 5.7.3 lockfile
figma/Plugin-IconBridge/package.json @figma/plugin-typings ^1.108.0 1.108.0 lockfile
figma/Plugin-IconBridge/package.json typescript ^5.7.3 5.7.3 lockfile
figma/plugin-NornAI/package.json preact ^10.19.6 10.29.0 lockfile
figma/plugin-NornAI/package.json react-colorful ^5.6.1 5.6.1 lockfile
figma/plugin-NornAI/package.json react-masonry-css ^1.0.16 1.0.16 lockfile
figma/plugin-NornAI/package.json @figma/plugin-typings ^1.50.0 1.123.0 lockfile
figma/plugin-NornAI/package.json @tailwindcss/forms ^0.5.10 0.5.11 lockfile
figma/plugin-NornAI/package.json @types/react ^18.0.17 18.3.28 lockfile
figma/plugin-NornAI/package.json @types/react-dom ^18.0.6 18.3.7 lockfile
figma/plugin-NornAI/package.json autoprefixer ^10.4.20 10.4.27 lockfile
figma/plugin-NornAI/package.json css-loader ^6.7.1 6.11.0 lockfile
figma/plugin-NornAI/package.json html-webpack-plugin ^5.5.0 5.6.6 lockfile
figma/plugin-NornAI/package.json postcss ^8.5.3 8.5.8 lockfile
figma/plugin-NornAI/package.json postcss-loader ^8.1.1 8.2.1 lockfile
figma/plugin-NornAI/package.json style-loader ^3.3.1 3.3.4 lockfile
figma/plugin-NornAI/package.json tailwindcss ^3.4.17 3.4.19 lockfile
figma/plugin-NornAI/package.json terser-webpack-plugin ^5.3.11 5.4.0 lockfile
figma/plugin-NornAI/package.json ts-loader ^9.3.1 9.5.4 lockfile
figma/plugin-NornAI/package.json typescript ^4.7.4 4.9.5 lockfile
figma/plugin-NornAI/package.json webpack ^5.105.4 5.105.4 lockfile
figma/plugin-NornAI/package.json webpack-cli ^4.10.0 4.10.0 lockfile

Skipped

43 dependencies were skipped and require manual attention:

File Dependency Reason
figma/Plugin-IconBridge/node_modules/@figma/plugin-typings/package.json prettier No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @dprint/formatter No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @esfx/canceltoken No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @eslint/js No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @octokit/rest No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/chai No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/diff No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/minimist No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/mocha No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/ms No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/node No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/source-map-support No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @types/which No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @typescript-eslint/rule-tester No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @typescript-eslint/type-utils No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json @typescript-eslint/utils No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json azure-devops-node-api No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json c8 No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json chai No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json chalk No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json chokidar No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json diff No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json dprint No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json esbuild No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json eslint No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json eslint-formatter-autolinkable-stylish No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json eslint-plugin-regexp No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json fast-xml-parser No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json glob No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json globals No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json hereby No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json jsonc-parser No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json knip No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json minimist No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json mocha No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json mocha-fivemat-progress-reporter No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json monocart-coverage-reports No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json ms No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json playwright No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json source-map-support No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json tslib No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json typescript-eslint No lockfile version available (run with registry fallback to pin)
figma/Plugin-IconBridge/node_modules/typescript/package.json which No lockfile version available (run with registry fallback to pin)

Generated by ananke — automated supply chain security

Auto-generated by ananke supply chain detector.
Copy link
Copy Markdown

@cloudwalk-review-agent cloudwalk-review-agent Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly good dependency pinning pass; no concrete auth/permissions regression is visible from these package.json changes alone.

One important non-blocking concern: the PR modifies a vendored file under figma/Plugin-IconBridge/node_modules/typescript/package.json. Committing node_modules content is usually undesirable because it creates drift from declared dependencies and makes future updates/noise harder to manage. If node_modules is not intentionally vendored in this repo, I’d remove this file change and rely on lockfile/package manager resolution instead.

Aside from that, the direct dependency pins look internally consistent and reduce supply-chain variability as intended.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants