Skip to content

chore(deps): bump dotenv from 17.3.1 to 17.4.2#404

Closed
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/npm_and_yarn/dotenv-17.4.2
Closed

chore(deps): bump dotenv from 17.3.1 to 17.4.2#404
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/npm_and_yarn/dotenv-17.4.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 13, 2026

Bumps dotenv from 17.3.1 to 17.4.2.

Changelog

Sourced from dotenv's changelog.

17.4.2 (2026-04-12)

Changed

  • Improved skill files - tightened up details (#1009)

17.4.1 (2026-04-05)

Changed

  • Change text injecting to injected (#1005)

17.4.0 (2026-04-01)

Added

  • Add skills/ folder with focused agent skills: skills/dotenv/SKILL.md (core usage) and skills/dotenvx/SKILL.md (encryption, multiple environments, variable expansion) for AI coding agent discovery via the skills.sh ecosystem (npx skills add motdotla/dotenv)

Changed

  • Tighten up logs: ◇ injecting env (14) from .env (#1003)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.3.1 to 17.4.2.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.3.1...v17.4.2)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 17.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 13, 2026
@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 13, 2026

Deploy Preview for graypaper-reader ready!

Name Link
🔨 Latest commit 9c1ec8c
🔍 Latest deploy log https://app.netlify.com/projects/graypaper-reader/deploys/69dd76f114054c0008a23387
😎 Deploy Preview https://deploy-preview-404--graypaper-reader.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions
Copy link
Copy Markdown
Contributor

Visual Regression Test Report ✅ Passed

Github run id: 24371342158

🔗 Artifacts: Download

@tomusdrw
Copy link
Copy Markdown
Member

https://github.com/dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 14, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

tomusdrw added a commit that referenced this pull request Apr 17, 2026
Bumps dompurify, dotenv, jsdom, react, react-dom, react-tooltip,
@playwright/test, @types/node, typescript, vite, vitest, and
@biomejs/biome (root) to their latest compatible versions via
npm update. Also updates biome.jsonc schema URL to match 2.4.12.

Supersedes dependabot PRs #403, #404, #405, #406, #408.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@tomusdrw
Copy link
Copy Markdown
Member

Superseded by #410, which bundles this bump with other dependency updates.

@tomusdrw tomusdrw closed this Apr 17, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 17, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/dotenv-17.4.2 branch April 17, 2026 14:21
tomusdrw added a commit that referenced this pull request Apr 17, 2026
* chore(deps): update minor and patch versions across workspaces

Bumps dompurify, dotenv, jsdom, react, react-dom, react-tooltip,
@playwright/test, @types/node, typescript, vite, vitest, and
@biomejs/biome (root) to their latest compatible versions via
npm update. Also updates biome.jsonc schema URL to match 2.4.12.

Supersedes dependabot PRs #403, #404, #405, #406, #408.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test: auto-update visual regression snapshots

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant