Skip to content

chore(studio-deps)(deps): bump the security-critical group in /studio with 4 updates#3287

Merged
mergify[bot] merged 1 commit intomainfrom
dependabot/npm_and_yarn/studio/main/security-critical-19c8a80465
Feb 2, 2026
Merged

chore(studio-deps)(deps): bump the security-critical group in /studio with 4 updates#3287
mergify[bot] merged 1 commit intomainfrom
dependabot/npm_and_yarn/studio/main/security-critical-19c8a80465

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 1, 2026

Bumps the security-critical group in /studio with 4 updates: datatables.net, datatables.net-bs5, datatables.net-responsive and datatables.net-responsive-bs5.

Updates datatables.net from 2.3.6 to 2.3.7

Release notes

Sourced from datatables.net's releases.

2.3.7

DataTables 2.3.7

Commits
  • 8372073 Sync tag release - 2.3.7
  • 7b7cd74 f44b4cd038bcea7370ae08c2858bfaf4e878dea1 Release 2.3.7
  • 08d4de0 dc059e94f5d8c679149dda517009402c3073f816 Dev: Update browser mapping
  • f2f3898 bef31e92a24adf1bf698c7fb359703dcaf38c9f5 Fix: :visible selector will no lon...
  • 2c3b55b f8181845f754e5e79dd9b6f142c2887e8215f98d Fix: tfoot should be the last elem...
  • See full diff in compare view

Updates datatables.net-bs5 from 2.3.6 to 2.3.7

Release notes

Sourced from datatables.net-bs5's releases.

2.3.7

DataTables Bootstrap5 2.3.7

Commits
  • 449af85 Sync tag release - 2.3.7
  • 3d5abf1 f44b4cd038bcea7370ae08c2858bfaf4e878dea1 Release 2.3.7
  • ab236b5 dc059e94f5d8c679149dda517009402c3073f816 Dev: Update browser mapping
  • 810ba16 bef31e92a24adf1bf698c7fb359703dcaf38c9f5 Fix: :visible selector will no lon...
  • 44659b9 f8181845f754e5e79dd9b6f142c2887e8215f98d Fix: tfoot should be the last elem...
  • See full diff in compare view

Updates datatables.net-responsive from 3.0.7 to 3.0.8

Release notes

Sourced from datatables.net-responsive's releases.

3.0.8

Responsive 3.0.8

Commits
  • 167a35b Include ESM files in Nuget packages
  • 0a24048 Sync tag release - 3.0.2
  • de20416 7021a47d3ee7f0838260950dc7f49b62fe76649b Release 3.0.2
  • e2b20f4 1ef7cec246f5be1a03cbec3aaac6831f41abb4ca Dev: Update test case - happy with t...
  • 6d79db1 9828377f157cb25b239a4dd95e218e23373aed16 Fix: Sizing table was incorrectly in...
  • 10a5877 5cef001d85ad066031fb4febbbca666f9eadc533 Fix: Newly added rows did not have `...
  • fffd8fc f1cb9b4d4a0326f7df38642506e3ade5d6506b9e Dev version
  • See full diff in compare view

Updates datatables.net-responsive-bs5 from 3.0.7 to 3.0.8

Release notes

Sourced from datatables.net-responsive-bs5's releases.

3.0.8

Responsive Bootstrap5 3.0.8

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the security-critical group in /studio with 4 updates: [datatables.net](https://github.com/DataTables/Dist-DataTables), [datatables.net-bs5](https://github.com/DataTables/Dist-DataTables-Bootstrap5), [datatables.net-responsive](https://github.com/DataTables/Dist-DataTables-Responsive) and [datatables.net-responsive-bs5](https://github.com/DataTables/Dist-DataTables-Responsive-Bootstrap5).


Updates `datatables.net` from 2.3.6 to 2.3.7
- [Release notes](https://github.com/DataTables/Dist-DataTables/releases)
- [Commits](DataTables/Dist-DataTables@2.3.6...2.3.7)

Updates `datatables.net-bs5` from 2.3.6 to 2.3.7
- [Release notes](https://github.com/DataTables/Dist-DataTables-Bootstrap5/releases)
- [Commits](DataTables/Dist-DataTables-Bootstrap5@2.3.6...2.3.7)

Updates `datatables.net-responsive` from 3.0.7 to 3.0.8
- [Release notes](https://github.com/DataTables/Dist-DataTables-Responsive/releases)
- [Commits](DataTables/Dist-DataTables-Responsive@3.0.7...3.0.8)

Updates `datatables.net-responsive-bs5` from 3.0.7 to 3.0.8
- [Release notes](https://github.com/DataTables/Dist-DataTables-Responsive-Bootstrap5/releases)
- [Commits](DataTables/Dist-DataTables-Responsive-Bootstrap5@3.0.7...3.0.8)

---
updated-dependencies:
- dependency-name: datatables.net
  dependency-version: 2.3.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-critical
- dependency-name: datatables.net-bs5
  dependency-version: 2.3.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-critical
- dependency-name: datatables.net-responsive
  dependency-version: 3.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-critical
- dependency-name: datatables.net-responsive-bs5
  dependency-version: 3.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-critical
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 1, 2026

Labels

The following labels could not be found: frontend, studio. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file security labels Feb 1, 2026
@mergify
Copy link
Contributor

mergify bot commented Feb 1, 2026

🧪 CI Insights

Here's what we observed from your CI run for c5ebf54.

🟢 All jobs passed!

But CI Insights is watching 👀

@mergify mergify bot merged commit c7cd6d7 into main Feb 2, 2026
15 of 21 checks passed
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/studio/main/security-critical-19c8a80465 branch February 2, 2026 23:24
Nenzyz pushed a commit to Nenzyz/arcadedb that referenced this pull request Feb 5, 2026
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.31.9 to 4.31.10.
Release notes

*Sourced from [github/codeql-action's releases](https://github.com/github/codeql-action/releases).*

> v4.31.10
> --------
>
> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> 4.31.10 - 12 Jan 2026
> ---------------------
>
> * Update default CodeQL bundle version to 2.23.9. [ArcadeData#3393](https://redirect.github.com/github/codeql-action/pull/3393)
>
> See the full [CHANGELOG.md](https://github.com/github/codeql-action/blob/v4.31.10/CHANGELOG.md) for more information.


Changelog

*Sourced from [github/codeql-action's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*

> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> No user facing changes.
>
> 4.31.10 - 12 Jan 2026
> ---------------------
>
> * Update default CodeQL bundle version to 2.23.9. [ArcadeData#3393](https://redirect.github.com/github/codeql-action/pull/3393)
>
> 4.31.9 - 16 Dec 2025
> --------------------
>
> No user facing changes.
>
> 4.31.8 - 11 Dec 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.8. [ArcadeData#3354](https://redirect.github.com/github/codeql-action/pull/3354)
>
> 4.31.7 - 05 Dec 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.7. [ArcadeData#3343](https://redirect.github.com/github/codeql-action/pull/3343)
>
> 4.31.6 - 01 Dec 2025
> --------------------
>
> No user facing changes.
>
> 4.31.5 - 24 Nov 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.6. [ArcadeData#3321](https://redirect.github.com/github/codeql-action/pull/3321)
>
> 4.31.4 - 18 Nov 2025
> --------------------
>
> No user facing changes.
>
> 4.31.3 - 13 Nov 2025
> --------------------
>
> * CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see [Upcoming deprecation of CodeQL Action v3](https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/).
> * Update default CodeQL bundle version to 2.23.5. [ArcadeData#3288](https://redirect.github.com/github/codeql-action/pull/3288)
>
> 4.31.2 - 30 Oct 2025
> --------------------
>
> No user facing changes.
>
> 4.31.1 - 30 Oct 2025
> --------------------
>
> * The `add-snippets` input has been removed from the `analyze` action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.
>
> 4.31.0 - 24 Oct 2025
> --------------------

... (truncated)


Commits

* [`cdefb33`](github/codeql-action@cdefb33) Merge pull request [ArcadeData#3394](https://redirect.github.com/github/codeql-action/issues/3394) from github/update-v4.31.10-0fa411efd
* [`cfa77c6`](github/codeql-action@cfa77c6) Update changelog for v4.31.10
* [`0fa411e`](github/codeql-action@0fa411e) Merge pull request [ArcadeData#3393](https://redirect.github.com/github/codeql-action/issues/3393) from github/update-bundle/codeql-bundle-v2.23.9
* [`c284324`](github/codeql-action@c284324) Add changelog note
* [`83e7d00`](github/codeql-action@83e7d00) Update default bundle to codeql-bundle-v2.23.9
* [`f6a16be`](github/codeql-action@f6a16be) Merge pull request [ArcadeData#3391](https://redirect.github.com/github/codeql-action/issues/3391) from github/dependabot/npm\_and\_yarn/npm-minor-f1cdf5...
* [`c1f5f1a`](github/codeql-action@c1f5f1a) Rebuild
* [`1805d8d`](github/codeql-action@1805d8d) Bump the npm-minor group with 2 updates
* [`b2951d2`](github/codeql-action@b2951d2) Merge pull request [ArcadeData#3353](https://redirect.github.com/github/codeql-action/issues/3353) from github/kaspersv/bump-min-cli-v-for-overlay
* [`41448d9`](github/codeql-action@41448d9) Merge pull request [ArcadeData#3287](https://redirect.github.com/github/codeql-action/issues/3287) from github/henrymercer/generate-mergeback-last
* Additional commits viewable in [compare view](github/codeql-action@5d4e8d1...cdefb33)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=github/codeql-action&package-manager=github\_actions&previous-version=4.31.9&new-version=4.31.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant