Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 29, 2026

This PR contains the following updates:

Package Change Age Confidence
@types/node (source) 25.0.925.0.10 age confidence
algoliasearch (source) 5.46.35.47.0 age confidence
cheerio (source) 1.1.21.2.0 age confidence
eslint-config-upleveled 9.4.29.4.6 age confidence
pnpm (source) 10.28.0+sha512.05df71d1421f21399e053fde567cea34d446fa02c76571441bfc1c7956e98e363088982d940465fd34480d4d90a0668bc12362f8aa88000a64e83d0b0e47be4810.28.2 age confidence
prettier (source) 3.8.03.8.1 age confidence
top-user-agents (source) 2.1.902.1.92 age confidence
typescript-eslint (source) 8.53.08.54.0 age confidence
vitest (source) 4.0.174.0.18 age confidence

Release Notes

algolia/algoliasearch-client-javascript (algoliasearch)

v5.47.0

Compare Source

v5.46.4

Compare Source

cheeriojs/cheerio (cheerio)

v1.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: cheeriojs/cheerio@v1.1.2...v1.2.0

upleveled/eslint-config-upleveled (eslint-config-upleveled)

v9.4.6

Compare Source


v9.4.5

Compare Source


v9.4.4

Compare Source


v9.4.3

Compare Source

pnpm/pnpm (pnpm)

v10.28.2: pnpm 10.28.2

Compare Source

Patch Changes

  • Security fix: prevent path traversal in directories.bin field.

  • When pnpm installs a file: or git: dependency, it now validates that symlinks point within the package directory. Symlinks to paths outside the package root are skipped to prevent local data from being leaked into node_modules.

    This fixes a security issue where a malicious package could create symlinks to sensitive files (e.g., /etc/passwd, ~/.ssh/id_rsa) and have their contents copied when the package is installed.

    Note: This only affects file: and git: dependencies. Registry packages (npm) have symlinks stripped during publish and are not affected.

  • Fixed optional dependencies to request full metadata from the registry to get the libc field, which is required for proper platform compatibility checks #​9950.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.28.1

Compare Source

prettier/prettier (prettier)

v3.8.1

Compare Source

microlinkhq/top-user-agents (top-user-agents)

v2.1.92

Compare Source

v2.1.91

Compare Source

typescript-eslint/typescript-eslint (typescript-eslint)

v8.54.0

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

You can read about our versioning strategy and releases on our website.

v8.53.1

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

You can read about our versioning strategy and releases on our website.

vitest-dev/vitest (vitest)

v4.0.18

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

Configuration

📅 Schedule: Branch creation - "after 4pm on thursday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) January 29, 2026 16:29
@coderabbitai
Copy link

coderabbitai bot commented Jan 29, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@codesandbox-ci
Copy link

codesandbox-ci bot commented Jan 29, 2026

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

@socket-security
Copy link

socket-security bot commented Jan 29, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedtypescript-eslint@​8.53.0 ⏵ 8.54.01001007498 +1100
Updatedeslint-config-upleveled@​9.4.2 ⏵ 9.4.67510098 +195100
Updatedtop-user-agents@​2.1.90 ⏵ 2.1.92791008896100
Updatedvitest@​4.0.17 ⏵ 4.0.1896 +110079 +199 +1100
Updated@​types/​node@​25.0.9 ⏵ 25.0.10100 +110081 +196100
Updatedcheerio@​1.1.2 ⏵ 1.2.099 +110010088100
Updatedprettier@​3.8.0 ⏵ 3.8.19010097 +197 -1100
Updatedalgoliasearch@​5.46.3 ⏵ 5.47.0991009699 -1100

View full report

@renovate renovate bot force-pushed the renovate/dependency-upgrades-non-major branch 5 times, most recently from ae0abee to cde445f Compare February 2, 2026 04:53
@renovate renovate bot force-pushed the renovate/dependency-upgrades-non-major branch from cde445f to 8a5a902 Compare February 2, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants