Bump the packages group with 12 updates#220
Conversation
Bumps the packages group with 12 updates: | Package | From | To | | --- | --- | --- | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.1.0` | `24.2.0` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.38.0` | `8.39.0` | | [vercel](https://github.com/vercel/vercel/tree/HEAD/packages/cli) | `44.7.0` | `44.7.2` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.38.0` | `8.39.0` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.38.0` | `8.39.0` | | [@typescript-eslint/type-utils](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/type-utils) | `8.38.0` | `8.39.0` | | [@typescript-eslint/utils](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/utils) | `8.38.0` | `8.39.0` | | [@typescript-eslint/visitor-keys](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/visitor-keys) | `8.38.0` | `8.39.0` | | [@vercel/hono](https://github.com/vercel/vercel/tree/HEAD/packages/hono) | `0.0.8` | `0.0.9` | | [@vercel/node](https://github.com/vercel/vercel/tree/HEAD/packages/node) | `5.3.10` | `5.3.11` | | [electron-to-chromium](https://github.com/kilian/electron-to-chromium) | `1.5.194` | `1.5.195` | | [undici-types](https://github.com/nodejs/undici) | `7.8.0` | `7.10.0` | Updates `@types/node` from 24.1.0 to 24.2.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `typescript-eslint` from 8.38.0 to 8.39.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/typescript-eslint) Updates `vercel` from 44.7.0 to 44.7.2 - [Release notes](https://github.com/vercel/vercel/releases) - [Changelog](https://github.com/vercel/vercel/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/vercel/vercel/commits/vercel@44.7.2/packages/cli) Updates `@typescript-eslint/eslint-plugin` from 8.38.0 to 8.39.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 8.38.0 to 8.39.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/parser) Updates `@typescript-eslint/type-utils` from 8.38.0 to 8.39.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/type-utils/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/type-utils) Updates `@typescript-eslint/utils` from 8.38.0 to 8.39.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/utils/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/utils) Updates `@typescript-eslint/visitor-keys` from 8.38.0 to 8.39.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/visitor-keys/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/visitor-keys) Updates `@vercel/hono` from 0.0.8 to 0.0.9 - [Release notes](https://github.com/vercel/vercel/releases) - [Changelog](https://github.com/vercel/vercel/blob/main/packages/hono/CHANGELOG.md) - [Commits](https://github.com/vercel/vercel/commits/@vercel/hono@0.0.9/packages/hono) Updates `@vercel/node` from 5.3.10 to 5.3.11 - [Release notes](https://github.com/vercel/vercel/releases) - [Changelog](https://github.com/vercel/vercel/blob/main/packages/node/CHANGELOG.md) - [Commits](https://github.com/vercel/vercel/commits/@vercel/node@5.3.11/packages/node) Updates `electron-to-chromium` from 1.5.194 to 1.5.195 - [Changelog](https://github.com/Kilian/electron-to-chromium/blob/master/CHANGELOG.md) - [Commits](https://github.com/kilian/electron-to-chromium/commits) Updates `undici-types` from 7.8.0 to 7.10.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.8.0...v7.10.0) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 24.2.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: packages - dependency-name: typescript-eslint dependency-version: 8.39.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: packages - dependency-name: vercel dependency-version: 44.7.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: packages - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.39.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: packages - dependency-name: "@typescript-eslint/parser" dependency-version: 8.39.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: packages - dependency-name: "@typescript-eslint/type-utils" dependency-version: 8.39.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: packages - dependency-name: "@typescript-eslint/utils" dependency-version: 8.39.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: packages - dependency-name: "@typescript-eslint/visitor-keys" dependency-version: 8.39.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: packages - dependency-name: "@vercel/hono" dependency-version: 0.0.9 dependency-type: indirect update-type: version-update:semver-patch dependency-group: packages - dependency-name: "@vercel/node" dependency-version: 5.3.11 dependency-type: indirect update-type: version-update:semver-patch dependency-group: packages - dependency-name: electron-to-chromium dependency-version: 1.5.195 dependency-type: indirect update-type: version-update:semver-patch dependency-group: packages - dependency-name: undici-types dependency-version: 7.10.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: packages ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
|
⏳ I'm reviewing this pull request for security vulnerabilities and code quality issues. I'll provide an update when I'm done |
|
|
||
| undici-types@7.8.0: | ||
| resolution: {integrity: sha512-9UJ2xGDvQ43tYyVMpuHlsgApydB8ZKfVYTsLDhXkFL/6gfkp+U8xTGdh8pMJv1SpZna0zxG1DwsKZsreLbXBxw==} | ||
| undici-types@7.10.0: |
There was a problem hiding this comment.
Description: Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.
Relevant link: GHSA-cxrh-j4jr-qwg3
Severity: Low
There was a problem hiding this comment.
The vulnerability is addressed by updating the version of undici to 5.29.0, which includes the fix for the memory leak issue in webhook-like systems.
| undici-types@7.10.0: | |
| undici-types@7.10.0: | |
| resolution: {integrity: sha512-t5Fy/nfn+14LuOc2KNYg75vZqClpAiqscVvMygNnlsHBFpSXdJaYtXMcdNLpl/Qvc3P2cB3s6lOV51nqsFq4ag==} | |
| undici@5.29.0: | |
| resolution: {integrity: sha512-raqeBD6NQK4SkWhQzeYKd1KmIG6dllBOTt55Rmkt4HtI9mwdWtJljnrXjAFUBLTSN67HWrOIZ3EPF4kjUw80Bg==} | |
| engines: {node: '>=14.0'} | |
| undici@5.29.0: |
|
✅ I finished the code review, and left comments with the issues I found. I will now generate code fix suggestions. |
Bumps the packages group with 12 updates:
24.1.024.2.08.38.08.39.044.7.044.7.28.38.08.39.08.38.08.39.08.38.08.39.08.38.08.39.08.38.08.39.00.0.80.0.95.3.105.3.111.5.1941.5.1957.8.07.10.0Updates
@types/nodefrom 24.1.0 to 24.2.0Commits
Updates
typescript-eslintfrom 8.38.0 to 8.39.0Release notes
Sourced from typescript-eslint's releases.
Changelog
Sourced from typescript-eslint's changelog.
Commits
c98d513chore(release): publish 8.39.02112d58feat: update to TypeScript 5.9.2 (#11445)Updates
vercelfrom 44.7.0 to 44.7.2Release notes
Sourced from vercel's releases.
Changelog
Sourced from vercel's changelog.
Commits
fa84f26Version Packages (#13676)a18cc09Version Packages (#13669)9655b7aremove duplicate teamId query param (#13674)Updates
@typescript-eslint/eslint-pluginfrom 8.38.0 to 8.39.0Release notes
Sourced from
@typescript-eslint/eslint-plugin's releases.Changelog
Sourced from
@typescript-eslint/eslint-plugin's changelog.Commits
c98d513chore(release): publish 8.39.0a8def4bfix(eslint-plugin): [no-unsafe-assignment] add anunsafeObjectPatternmessa...422e3e2feat(eslint-plugin): [only-throw-error] support yield/await expressions (#11417)e901ad8fix(eslint-plugin): revert #11127 (#11447)8dc8340feat(eslint-plugin): add no-unnecessary-type-conversion to strict-type-checke...2112d58feat: update to TypeScript 5.9.2 (#11445)b872e2bfeat(eslint-plugin): [naming-convention] add enumMember PascalCase default op...757f9eefix(eslint-plugin): [prefer-optional-chain] ignorecheckoption for most RH...5b24864chore: fix dangling reference to generate:configs in comments (#11431)Updates
@typescript-eslint/parserfrom 8.38.0 to 8.39.0Release notes
Sourced from
@typescript-eslint/parser's releases.Changelog
Sourced from
@typescript-eslint/parser's changelog.Commits
c98d513chore(release): publish 8.39.02112d58feat: update to TypeScript 5.9.2 (#11445)Updates
@typescript-eslint/type-utilsfrom 8.38.0 to 8.39.0Release notes
Sourced from
@typescript-eslint/type-utils's releases.Changelog
Sourced from
@typescript-eslint/type-utils's changelog.Commits
c98d513chore(release): publish 8.39.02112d58feat: update to TypeScript 5.9.2 (#11445)Updates
@typescript-eslint/utilsfrom 8.38.0 to 8.39.0Release notes
Sourced from
@typescript-eslint/utils's releases.Changelog
Sourced from
@typescript-eslint/utils's changelog.Commits
c98d513chore(release): publish 8.39.02112d58feat: update to TypeScript 5.9.2 (#11445)Updates
@typescript-eslint/visitor-keysfrom 8.38.0 to 8.39.0Release notes
Sourced from
@typescript-eslint/visitor-keys's releases.Changelog
Sourced from
@typescript-eslint/visitor-keys's changelog.Commits
c98d513chore(release): publish 8.39.0Updates
@vercel/honofrom 0.0.8 to 0.0.9Release notes
Sourced from
@vercel/hono's releases.Changelog
Sourced from
@vercel/hono's changelog.Commits
a18cc09Version Packages (#13669)a4e72c3Support fetchable apps out of the box for Node dev server (#13664)Updates
@vercel/nodefrom 5.3.10 to 5.3.11Release notes
Sourced from
@vercel/node's releases.Changelog
Sourced from
@vercel/node's changelog.Commits
a18cc09Version Packages (#13669)a4e72c3Support fetchable apps out of the box for Node dev server (#13664)Updates
electron-to-chromiumfrom 1.5.194 to 1.5.195Commits
Updates
undici-typesfrom 7.8.0 to 7.10.0Release notes
Sourced from undici-types's releases.
Commits
5ad8998Bumped v7.10.0 (#4231)9e0cfcbdocs: correct example in FormData request (#4226)95fd9d3feat(ProxyAgent): match Curl behavior in HTTP->HTTP Proxy connections (#4180)a8d280cAdd ability to detect when MemoryCacheStore reaches max size (#4224)59940c8fix: agent memory leak (#4223)1262f61Revert "chore: update WPT (#4172)"d6deb77chore: addpnpm-lock.yamlto.gitignore(#4227)dcf82a7chore: update WPT (#4172)2ed2a8aadd node v24 workflow (#4206)bf4c199remove spurious only (#4207)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions