Bump the npm_and_yarn group across 1 directory with 21 updates#26
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
Bump the npm_and_yarn group across 1 directory with 21 updates#26dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 21 updates in the / directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.19` | `4.17.23` | | [koa](https://github.com/koajs/koa) | `2.11.0` | `3.1.2` | | [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) | `7.7.4` | `7.29.0` | | [@octokit/endpoint](https://github.com/octokit/endpoint.js) | `10.1.1` | `10.1.4` | | [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js) | `11.3.0` | `11.6.0` | | [@octokit/request-error](https://github.com/octokit/request-error.js) | `6.1.1` | `6.1.8` | | [@octokit/request](https://github.com/octokit/request.js) | `9.1.1` | `9.2.4` | | [ajv](https://github.com/ajv-validator/ajv) | `6.10.2` | `6.14.0` | | [async](https://github.com/caolan/async) | `2.6.3` | `2.6.4` | | [color-string](https://github.com/Qix-/color-string) | `1.5.3` | `1.9.1` | | [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component) | `0.2.0` | `0.2.2` | | [glob-parent](https://github.com/gulpjs/glob-parent) | `5.1.0` | `5.1.2` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.5.3` | `4.7.8` | | [json5](https://github.com/json5/json5) | `2.1.1` | `2.2.3` | | [path-parse](https://github.com/jbgutierrez/path-parse) | `1.0.6` | `1.0.7` | | [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `1.8.0` | `1.9.0` | | [tmpl](https://github.com/daaku/nodejs-tmpl) | `1.0.4` | `1.0.5` | | [undefsafe](https://github.com/remy/undefsafe) | `2.0.2` | `2.0.5` | | [urijs](https://github.com/medialize/URI.js) | `1.19.2` | `1.19.11` | | [word-wrap](https://github.com/jonschlinkert/word-wrap) | `1.2.3` | `1.2.5` | | [ws](https://github.com/websockets/ws) | `5.2.2` | `5.2.4` | Updates `lodash` from 4.17.19 to 4.17.23 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.19...4.17.23) Updates `koa` from 2.11.0 to 3.1.2 - [Release notes](https://github.com/koajs/koa/releases) - [Changelog](https://github.com/koajs/koa/blob/master/History.md) - [Commits](koajs/koa@2.11.0...v3.1.2) Updates `@babel/traverse` from 7.7.4 to 7.29.0 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.0/packages/babel-traverse) Updates `@octokit/endpoint` from 10.1.1 to 10.1.4 - [Release notes](https://github.com/octokit/endpoint.js/releases) - [Commits](octokit/endpoint.js@v10.1.1...v10.1.4) Updates `@octokit/plugin-paginate-rest` from 11.3.0 to 11.6.0 - [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases) - [Commits](octokit/plugin-paginate-rest.js@v11.3.0...v11.6.0) Updates `@octokit/request-error` from 6.1.1 to 6.1.8 - [Release notes](https://github.com/octokit/request-error.js/releases) - [Commits](octokit/request-error.js@v6.1.1...v6.1.8) Updates `@octokit/request` from 9.1.1 to 9.2.4 - [Release notes](https://github.com/octokit/request.js/releases) - [Commits](octokit/request.js@v9.1.1...v9.2.4) Updates `ajv` from 6.10.2 to 6.14.0 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.10.2...v6.14.0) Updates `async` from 2.6.3 to 2.6.4 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md) - [Commits](caolan/async@v2.6.3...v2.6.4) Updates `color-string` from 1.5.3 to 1.9.1 - [Release notes](https://github.com/Qix-/color-string/releases) - [Changelog](https://github.com/Qix-/color-string/blob/master/CHANGELOG.md) - [Commits](https://github.com/Qix-/color-string/commits/1.9.1) Updates `decode-uri-component` from 0.2.0 to 0.2.2 - [Release notes](https://github.com/SamVerschueren/decode-uri-component/releases) - [Commits](SamVerschueren/decode-uri-component@v0.2.0...v0.2.2) Updates `glob-parent` from 5.1.0 to 5.1.2 - [Release notes](https://github.com/gulpjs/glob-parent/releases) - [Changelog](https://github.com/gulpjs/glob-parent/blob/main/CHANGELOG.md) - [Commits](gulpjs/glob-parent@v5.1.0...v5.1.2) Updates `handlebars` from 4.5.3 to 4.7.8 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.8/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.5.3...v4.7.8) Updates `json5` from 2.1.1 to 2.2.3 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v2.1.1...v2.2.3) Updates `path-parse` from 1.0.6 to 1.0.7 - [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7) Updates `path-to-regexp` from 1.8.0 to 1.9.0 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v1.8.0...v1.9.0) Updates `tmpl` from 1.0.4 to 1.0.5 - [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5) Updates `undefsafe` from 2.0.2 to 2.0.5 - [Release notes](https://github.com/remy/undefsafe/releases) - [Commits](remy/undefsafe@v2.0.2...v2.0.5) Updates `urijs` from 1.19.2 to 1.19.11 - [Release notes](https://github.com/medialize/URI.js/releases) - [Changelog](https://github.com/medialize/URI.js/blob/gh-pages/CHANGELOG.md) - [Commits](medialize/URI.js@v1.19.2...v1.19.11) Updates `word-wrap` from 1.2.3 to 1.2.5 - [Release notes](https://github.com/jonschlinkert/word-wrap/releases) - [Commits](jonschlinkert/word-wrap@1.2.3...1.2.5) Updates `ws` from 5.2.2 to 5.2.4 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@5.2.2...5.2.4) --- updated-dependencies: - dependency-name: lodash dependency-version: 4.17.23 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: koa dependency-version: 3.1.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@babel/traverse" dependency-version: 7.29.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/endpoint" dependency-version: 10.1.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/plugin-paginate-rest" dependency-version: 11.6.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request-error" dependency-version: 6.1.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@octokit/request" dependency-version: 9.2.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ajv dependency-version: 6.14.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: async dependency-version: 2.6.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: color-string dependency-version: 1.9.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: decode-uri-component dependency-version: 0.2.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: glob-parent dependency-version: 5.1.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-version: 4.7.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: json5 dependency-version: 2.2.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-parse dependency-version: 1.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-to-regexp dependency-version: 1.9.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmpl dependency-version: 1.0.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: undefsafe dependency-version: 2.0.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: urijs dependency-version: 1.19.11 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: word-wrap dependency-version: 1.2.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 5.2.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Mar 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 21 updates in the / directory:
4.17.194.17.232.11.03.1.27.7.47.29.010.1.110.1.411.3.011.6.06.1.16.1.89.1.19.2.46.10.26.14.02.6.32.6.41.5.31.9.10.2.00.2.25.1.05.1.24.5.34.7.82.1.12.2.31.0.61.0.71.8.01.9.01.0.41.0.52.0.22.0.51.19.21.19.111.2.31.2.55.2.25.2.4Updates
lodashfrom 4.17.19 to 4.17.23Commits
dec55b7Bump main to v4.17.23 (#6088)19c9251fix: setCacheHas JSDoc return type should be boolean (#6071)b5e6729jsdoc: Add -0 and BigInt zeros to _.compact falsey values list (#6062)edadd45Prevent prototype pollution on baseUnset function4879a7adoc: fix autoLink function, conversion of source links (#6056)9648f69chore: removeyarn.lockfile (#6053)dfa407dci: remove legacy configuration files (#6052)156e196feat: add renovate setup (#6039)933e106ci: add pipeline for Bun (#6023)072a807docs: update links related to Open JS Foundation (#5968)Updates
koafrom 2.11.0 to 3.1.2Release notes
Sourced from koa's releases.
... (truncated)
Changelog
Sourced from koa's changelog.
... (truncated)
Commits
c5a52e03.1.255ab9baMerge commit from forkfecd464build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (#1922)d2066cfbuild(deps): bump content-disposition from 0.5.4 to 1.0.1 (#1917)8694a06docs: use correct term "Server-Sent Events" in guide (#1920)096682bbuild(deps): bump mime-types from 3.0.1 to 3.0.2 (#1918)8215c2ebuild(deps): bump http-errors from 2.0.0 to 2.0.1 (#1919)cfe5ec6build(deps-dev): bump qs from 6.14.0 to 6.14.1 (#1921)0a6afa5fix: typo in troubleshooting.md (#1916)2e52fb53.1.1Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for koa since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
@babel/traversefrom 7.7.4 to 7.29.0Release notes
Sourced from
@babel/traverse's releases.... (truncated)
Commits
aa8394ev7.29.084366a8fix(traverse): provide a hub when traversing a File or Program and no parentP...229eb45[7.x backport] fix: Rename switch discriminant references when body creates s...d7f4008v7.28.6905bc22fix: lint errors in main branch (#17612)a03e2b6fix:path.evaluatecorrectly returnsconfident(#17584)aac2c37chore: Use Gulpfile.mts (#17579)65c4a6b[Babel 8] fix: Improvetraversetypes (#17574)99dcba5chore: enable some ts-eslint rules (#17592)c92c491Improve Unicode handling in code-frame tokenizer (#17589)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for
@babel/traversesince your current version.Updates
@octokit/endpointfrom 10.1.1 to 10.1.4Release notes
Sourced from
@octokit/endpoint's releases.Commits
ca8c366fix(deps): update dependency@octokit/typesto v14 (#523)7b9a884maint: cleanuppackage.jsonand use Node LTS instead of v16 (#519)bcc0f97build(deps): bump vite from 6.1.0 to 6.2.5 (#522)255c59dci(action): update actions/create-github-app-token action to v2 (#521)adeee3echore(deps): update dependency prettier to v3.5.3 (#518)ea60e07chore(deps): update dependency semantic-release-plugin-update-version-in-file...8f43346chore(deps): update dependency prettier to v3.5.2 (#517)2209b07chore(deps): update dependency prettier to v3.5.1 (#513)d6cf1adfix: linting issues breaking ci (#514)6c9c5beMerge commit from forkUpdates
@octokit/plugin-paginate-restfrom 11.3.0 to 11.6.0Release notes
Sourced from
@octokit/plugin-paginate-rest's releases.... (truncated)
Commits
1f44b54feat: new/orgs/{org}/issue-types, `/orgs/{org}/issue-types/{issue_type_id}...ef30a05feat: newGET /orgs/{org}/actions/hosted-runners, `GET /orgs/{org}/actions/...fbadb74chore(deps): update dependency prettier to v3.5.3 (#665)1c297cachore(deps): update dependency semantic-release-plugin-update-version-in-file...60d26d9chore(deps): update dependency prettier to v3.5.2 (#664)9a51aadfix(types): correct pagination return type for data which is an array (#662)8b8c500fix(types): add back the pagination keys (#653)41876f4chore(deps): update dependency prettier to v3.5.1 (#658)7d1fadefix: mitigate ReDos issues & linting issues (#659)bb6c4f9Merge commit from forkUpdates
@octokit/request-errorfrom 6.1.1 to 6.1.8Release notes
Sourced from
@octokit/request-error's releases.... (truncated)
Commits
ab4ea7bfix(deps): update dependency@octokit/typesto v14 (#505)7eba3d2chore(deps): update dependency tinybench to v4 (#501)549624bbuild(deps): bump vite from 6.2.2 to 6.2.5 (#504)11c1adcbuild(deps): lock file maintenance (#502)de5f24dchore(deps): update dependency prettier to v3.5.3 (#499)ef66347build(deps): lock file maintenance (#500)787201dbuild(deps): lock file maintenance (#498)5ab6a76chore(deps): update dependency prettier to v3.5.2 (#497)f8f8c4abuild(deps): lock file maintenance (#496)eee2491chore(deps): update dependency prettier to v3.5.1 (#493)Updates
@octokit/requestfrom 9.1.1 to 9.2.4Release notes
Sourced from
@octokit/request's releases.... (truncated)
Commits
afa9d09fix(pkg): unreplaced version number indist-bundle/(#765)3773e64ci: replaceOCTOKITBOT_PROJECT_ACTION_TOKENandOCTOKITBOT_PATwith a tok...7d576b0fix(deps): update dependency@octokit/typesto v14 (#753)c9bfc37build(deps): bump vite from 6.1.0 to 6.2.5 (#750)f7b9616ci(prettier): use Node LTS instead of Node 16 (#748)1955847chore(deps): update dependency prettier to v3.5.3 (#745)b71107bchore(deps): update dependency semantic-release-plugin-update-version-in-file...c855943chore(deps): update dependency prettier to v3.5.2 (#743)4b2f485fix(deps): update dependency@octokit/request-errorto v6.1.7 [security] (#740)0320a42chore(deps): update dependency prettier to v3.5.1 (#737)Updates
ajvfrom 6.10.2 to 6.14.0Release notes
Sourced from ajv's releases.
Commits
e3af0a76.14.0b552ed6add regExp option to address $data exploit via a regular expression (CVE-2025...72f2286docs: update v7 info231e52bMerge pull request #1320 from philsturgeon/patch-1d3475fcAdd spectral, an AJV util from a sponsor413afe0docs: v7.0.0-beta.311e997bupdate readme for v7fe591436.12.6d580d3eMerge pull request #1298 from ajv-validator/fix-urlfd36389fix: regular expression for "url" formatUpdates
asyncfrom 2.6.3 to 2.6.4Changelog
Sourced from async's changelog.
Commits
c6bdacaVersion 2.6.48870da9Update built files4df6754update changelog8f7f903Fix prototype pollution vulnerability (#1828)Maintainer changes
This version was pushed to npm by hargasinski, a new releaser for async since your current version.
Updates
color-stringfrom 1.5.3 to 1.9.1Release notes
Sourced from color-string's releases.
... (truncated)
Commits
Updates
decode-uri-componentfrom 0.2.0 to 0.2.2Release notes
Sourced from decode-uri-component's releases.
Commits
a0eea460.2.2980e0bfPrevent overwriting previously decoded tokens3c8a3730.2.176abc93Switch to GitHub workflows746ca5dFix issue where decode throws - fixes #6486d7e2Update license (#1)a650457Tidelift tasks66e1c28Meta tweaksUpdates
glob-parentfrom 5.1.0 to 5.1.2Release notes
Sourced from glob-parent's releases.
Changelog
Sourced from glob-parent's changelog.
Commits
eb2c439chore: update changelog12bcb6cchore: release 5.1.2f923116fix: eliminate ReDoS (#36)0b014a7chore: add JSDoc returns information (#33)2b24ebdchore: generate initial changelog9b6e874chore: release 5.1.1749c35eci: try wrapping the JOB_ID in a string5d39defci: attempt to switch to published coveralls0b5b37fci: put the npm step back in for only Windows473f5d8ci: update azure build imagesUpdates
handlebarsfrom 4.5.3 to 4.7.8Release notes
Sourced from handlebars's releases.