-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): Bump the arcjet-apps-minor group across 1 directory with 23 updates #143
chore(deps): Bump the arcjet-apps-minor group across 1 directory with 23 updates #143
Conversation
… 23 updates Bumps the arcjet-apps-minor group with 23 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@astrojs/check](https://github.com/withastro/language-tools/tree/HEAD/packages/astro-check) | `0.9.3` | `0.9.4` | | [@astrojs/starlight](https://github.com/withastro/starlight/tree/HEAD/packages/starlight) | `0.28.2` | `0.28.3` | | [@clerk/nextjs](https://github.com/clerk/javascript/tree/HEAD/packages/nextjs) | `5.7.1` | `5.7.3` | | [@fontsource-variable/figtree](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/figtree) | `5.1.0` | `5.1.1` | | [@fontsource-variable/jost](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/jost) | `5.1.0` | `5.1.1` | | [@hono/node-server](https://github.com/honojs/node-server) | `1.13.1` | `1.13.2` | | [@langchain/community](https://github.com/langchain-ai/langchainjs) | `0.3.4` | `0.3.5` | | [@nestjs/common](https://github.com/nestjs/nest/tree/HEAD/packages/common) | `10.4.4` | `10.4.5` | | [@nestjs/core](https://github.com/nestjs/nest/tree/HEAD/packages/core) | `10.4.4` | `10.4.5` | | [@sveltejs/kit](https://github.com/sveltejs/kit/tree/HEAD/packages/kit) | `2.6.1` | `2.7.1` | | [ai](https://github.com/vercel/ai) | `3.4.7` | `3.4.12` | | [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `4.15.10` | `4.16.5` | | [astro-embed](https://github.com/delucis/astro-embed/tree/HEAD/packages/astro-embed) | `0.7.2` | `0.7.4` | | [express](https://github.com/expressjs/express) | `4.21.0` | `4.21.1` | | [hono](https://github.com/honojs/hono) | `4.6.3` | `4.6.5` | | [next](https://github.com/vercel/next.js) | `14.2.14` | `14.2.15` | | [openai](https://github.com/openai/openai-node) | `4.67.1` | `4.67.3` | | [pino](https://github.com/pinojs/pino) | `9.4.0` | `9.5.0` | | [pino-pretty](https://github.com/pinojs/pino-pretty) | `11.2.2` | `11.3.0` | | [sass](https://github.com/sass/dart-sass) | `1.79.4` | `1.79.5` | | [starlight-links-validator](https://github.com/HiDeoo/starlight-links-validator) | `0.12.2` | `0.12.3` | | [@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun) | `1.1.10` | `1.1.11` | | [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `18.3.0` | `18.3.1` | Updates `@astrojs/check` from 0.9.3 to 0.9.4 - [Release notes](https://github.com/withastro/language-tools/releases) - [Changelog](https://github.com/withastro/language-tools/blob/main/packages/astro-check/CHANGELOG.md) - [Commits](https://github.com/withastro/language-tools/commits/@astrojs/check@0.9.4/packages/astro-check) Updates `@astrojs/starlight` from 0.28.2 to 0.28.3 - [Release notes](https://github.com/withastro/starlight/releases) - [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md) - [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.28.3/packages/starlight) Updates `@clerk/nextjs` from 5.7.1 to 5.7.3 - [Release notes](https://github.com/clerk/javascript/releases) - [Changelog](https://github.com/clerk/javascript/blob/main/packages/nextjs/CHANGELOG.md) - [Commits](https://github.com/clerk/javascript/commits/@clerk/nextjs@5.7.3/packages/nextjs) Updates `@fontsource-variable/figtree` from 5.1.0 to 5.1.1 - [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md) - [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/figtree) Updates `@fontsource-variable/jost` from 5.1.0 to 5.1.1 - [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md) - [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/jost) Updates `@hono/node-server` from 1.13.1 to 1.13.2 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.13.1...v1.13.2) Updates `@langchain/community` from 0.3.4 to 0.3.5 - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Changelog](https://github.com/langchain-ai/langchainjs/blob/main/release_workspace.js) - [Commits](https://github.com/langchain-ai/langchainjs/commits) Updates `@nestjs/common` from 10.4.4 to 10.4.5 - [Release notes](https://github.com/nestjs/nest/releases) - [Commits](https://github.com/nestjs/nest/commits/v10.4.5/packages/common) Updates `@nestjs/core` from 10.4.4 to 10.4.5 - [Release notes](https://github.com/nestjs/nest/releases) - [Commits](https://github.com/nestjs/nest/commits/v10.4.5/packages/core) Updates `@sveltejs/kit` from 2.6.1 to 2.7.1 - [Release notes](https://github.com/sveltejs/kit/releases) - [Changelog](https://github.com/sveltejs/kit/blob/main/packages/kit/CHANGELOG.md) - [Commits](https://github.com/sveltejs/kit/commits/@sveltejs/kit@2.7.1/packages/kit) Updates `ai` from 3.4.7 to 3.4.12 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/compare/ai@3.4.7...ai@3.4.12) Updates `astro` from 4.15.10 to 4.16.5 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@4.16.5/packages/astro) Updates `astro-embed` from 0.7.2 to 0.7.4 - [Release notes](https://github.com/delucis/astro-embed/releases) - [Changelog](https://github.com/delucis/astro-embed/blob/main/packages/astro-embed/CHANGELOG.md) - [Commits](https://github.com/delucis/astro-embed/commits/astro-embed@0.7.4/packages/astro-embed) Updates `express` from 4.21.0 to 4.21.1 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.21.1/History.md) - [Commits](expressjs/express@4.21.0...4.21.1) Updates `hono` from 4.6.3 to 4.6.5 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.6.3...v4.6.5) Updates `next` from 14.2.14 to 14.2.15 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v14.2.14...v14.2.15) Updates `openai` from 4.67.1 to 4.67.3 - [Release notes](https://github.com/openai/openai-node/releases) - [Changelog](https://github.com/openai/openai-node/blob/master/CHANGELOG.md) - [Commits](openai/openai-node@v4.67.1...v4.67.3) Updates `pino` from 9.4.0 to 9.5.0 - [Release notes](https://github.com/pinojs/pino/releases) - [Commits](pinojs/pino@v9.4.0...v9.5.0) Updates `pino-pretty` from 11.2.2 to 11.3.0 - [Release notes](https://github.com/pinojs/pino-pretty/releases) - [Commits](pinojs/pino-pretty@v11.2.2...v11.3.0) Updates `sass` from 1.79.4 to 1.79.5 - [Release notes](https://github.com/sass/dart-sass/releases) - [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md) - [Commits](sass/dart-sass@1.79.4...1.79.5) Updates `starlight-links-validator` from 0.12.2 to 0.12.3 - [Release notes](https://github.com/HiDeoo/starlight-links-validator/releases) - [Commits](HiDeoo/starlight-links-validator@v0.12.2...v0.12.3) Updates `@types/bun` from 1.1.10 to 1.1.11 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/bun) Updates `@types/react-dom` from 18.3.0 to 18.3.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) --- updated-dependencies: - dependency-name: "@astrojs/check" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@astrojs/starlight" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@clerk/nextjs" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@fontsource-variable/figtree" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@fontsource-variable/jost" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@hono/node-server" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@langchain/community" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@nestjs/common" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@nestjs/core" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@sveltejs/kit" dependency-type: direct:production update-type: version-update:semver-minor dependency-group: arcjet-apps-minor - dependency-name: ai dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: astro dependency-type: direct:production update-type: version-update:semver-minor dependency-group: arcjet-apps-minor - dependency-name: astro-embed dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: express dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: hono dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: next dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: openai dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: pino dependency-type: direct:production update-type: version-update:semver-minor dependency-group: arcjet-apps-minor - dependency-name: pino-pretty dependency-type: direct:production update-type: version-update:semver-minor dependency-group: arcjet-apps-minor - dependency-name: sass dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: starlight-links-validator dependency-type: direct:production update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@types/bun" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: arcjet-apps-minor - dependency-name: "@types/react-dom" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: arcjet-apps-minor ... Signed-off-by: dependabot[bot] <support@github.com>
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is new author?A new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package. Scrutinize new collaborator additions to packages because they now have the ability to publish code into your dependency tree. Packages should avoid frequent or unnecessary additions or changes to publishing rights. What is unstable ownership?A new collaborator has begun publishing package versions. Package stability and security risk may be elevated. Try to reduce the amount of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm. What is an install script?Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts. Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
Will run this manually now we've merged in #82 |
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the arcjet-apps-minor group with 23 updates in the / directory:
0.9.3
0.9.4
0.28.2
0.28.3
5.7.1
5.7.3
5.1.0
5.1.1
5.1.0
5.1.1
1.13.1
1.13.2
0.3.4
0.3.5
10.4.4
10.4.5
10.4.4
10.4.5
2.6.1
2.7.1
3.4.7
3.4.12
4.15.10
4.16.5
0.7.2
0.7.4
4.21.0
4.21.1
4.6.3
4.6.5
14.2.14
14.2.15
4.67.1
4.67.3
9.4.0
9.5.0
11.2.2
11.3.0
1.79.4
1.79.5
0.12.2
0.12.3
1.1.10
1.1.11
18.3.0
18.3.1
Updates
@astrojs/check
from 0.9.3 to 0.9.4Release notes
Sourced from
@astrojs/check
's releases.Changelog
Sourced from
@astrojs/check
's changelog.Commits
a38afdd
Version Packages (#959)6e62aaa
chore: upgrade chokidar (#956)99ec87f
chore(astro-check): remove unused fast-glob dep (#944)Updates
@astrojs/starlight
from 0.28.2 to 0.28.3Release notes
Sourced from
@astrojs/starlight
's releases.Changelog
Sourced from
@astrojs/starlight
's changelog.Commits
27feccd
[ci] release (#2382)a0f40b3
fix bottom padding in search dialog (#2443)6bba3d8
Fix type-checking issue (#2388)0b4823d
Fix link formatting issue withbuild.format
set tofile
and abase
(#2408)45d2ed7
[ci] format7b451cf
Loosen i18n schema to pass through unknown keys by default (#2380)Updates
@clerk/nextjs
from 5.7.1 to 5.7.3Release notes
Sourced from
@clerk/nextjs
's releases.Changelog
Sourced from
@clerk/nextjs
's changelog.Commits
0d923c1
ci(repo): Version packages (#4323)d724a36
ci(repo): Version packages (#4307)0d56455
fix(nextjs): do not build test file declarations (#4286)3b6d510
chore(repo): Node 20 / attw change (#4283)Updates
@fontsource-variable/figtree
from 5.1.0 to 5.1.1Commits
Updates
@fontsource-variable/jost
from 5.1.0 to 5.1.1Commits
Updates
@hono/node-server
from 1.13.1 to 1.13.2Release notes
Sourced from
@hono/node-server
's releases.Commits
cd4d4d7
v1.13.22357641
fix(serve): support ipv6 by default (#206)Updates
@langchain/community
from 0.3.4 to 0.3.5Release notes
Sourced from
@langchain/community
's releases.... (truncated)
Commits
Updates
@nestjs/common
from 10.4.4 to 10.4.5Release notes
Sourced from
@nestjs/common
's releases.Commits
ed644e9
chore(@nestjs
) publish v10.4.5 release78b3f0c
test(common): add tests for validation pipe on 'custom' typesUpdates
@nestjs/core
from 10.4.4 to 10.4.5Release notes
Sourced from
@nestjs/core
's releases.Commits
ed644e9
chore(@nestjs
) publish v10.4.5 releaseUpdates
@sveltejs/kit
from 2.6.1 to 2.7.1Release notes
Sourced from
@sveltejs/kit
's releases.... (truncated)
Changelog
Sourced from
@sveltejs/kit
's changelog.... (truncated)
Commits
9d55410
Version Packages (#12805)dbc9c94
chore: upgrade to sirv 3.0 (#12796)96642d2
fix: add warning for form action responses lost without SSR (#12063)f3b638e
Version Packages (#12789)df48fc6
fix: handle relative assets paths in serverfetch
correctly (#12113)5780deb
fix: decode hash when clicking on same hash to correctly scroll on non ascii ...989949a
docs: add report uri directive to CSP example (#12788)8aa95b4
feat: update service worker when new version is detected (#12448)6f9aefd
fix: page response missing CSP and Link headers when return promise inload
...4c1e3c0
chore: add code comment explaining empty catch block (#12780)Updates
ai
from 3.4.7 to 3.4.12Release notes
Sourced from ai's releases.
Commits
f1bc444
Version Packages (#3281)a23da5b
feat (ai/core): forward abort signal to tools (#3277)5817da3
Version Packages (#3280)b13ecf7
chore (provider/mistral): update model ids (#3279)b62e86f
chore (docs): remove rsc notes from next examples (#3276)ec6031c
Version Packages (#3275)6fd6f9a
chore (docs): link migration guide to rsc note (#3274)caedcda
feat (ai/ui): add setData helper to useChat (#3271)9aa5a2b
chore (docs): add migration guide from rsc to ui (#3267)d9d2a8f
chore (docs): update openai dimensions description (#3269)Updates
astro
from 4.15.10 to 4.16.5Release notes
Sourced from astro's releases.
... (truncated)
Changelog
Sourced from astro's changelog.
... (truncated)
Commits
5a4edeb
[ci] release (#12234)ff68ba5
Fixes an issue with cssesc in dev mode when setting vite.ssr.noExternal: true...6df5bba
[ci] release (#12225)64bb796
Use real filesystem for unit testing (#12172)5ab2d98
fix(deps): update all non-major dependencies (#12218)79ffa5d
fix(dev-toolbar): false positive in Audit with a11y check on labels (#12223)fb55695
fix(middleware): compute client address (#12222)d6f03e4
[ci] formatc351352
fix(i18n): correctly compute the current locale (#12199)a338041
[ci] release (#12221)Updates
astro-embed
from 0.7.2 to 0.7.4Release notes
Sourced from astro-embed's releases.