-
-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update all non-major dependencies #10
Conversation
Run & review this pull request in StackBlitz Codeflow. |
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/@sxzz/[email protected], npm/@types/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected] |
644c15e
to
498c3c8
Compare
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is a typosquat?Package name is similar to other popular packages and may not be the package you want. Use care when consuming similarly named packages and ensure that you did not intend to consume a different package. Malicious packages often publish using similar names as existing popular packages. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
498c3c8
to
ad5e331
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. ⚠ Warning: custom changes will be lost. |
This PR contains the following updates:
^3.8.7
->^3.9.0
^20.12.2
->^20.12.6
^0.30.8
->^0.30.9
8.15.5
->8.15.6
0.10.0
->0.10.1
^4.13.2
->^4.14.1
^4.7.1
->^4.7.2
^5.4.3
->^5.4.4
^5.2.7
->^5.2.8
Release Notes
sxzz/eslint-config (@sxzz/eslint-config)
v3.9.0
Compare Source
Minor Changes
eslint-plugin-i
witheslint-plugin-import-x
for supporting ESLint v9.🚀 Features
🐞 Bug Fixes
View changes on GitHub
rich-harris/magic-string (magic-string)
v0.30.9
Compare Source
Performance Improvements
replace
(a1b857c)pnpm/pnpm (pnpm)
v8.15.6
Compare Source
Patch Changes
pnpm run
#7817.peerDependencies
#7813.--ignore-scripts
argument toprune
command #7836.Platinum Sponsors
Gold Sponsors
Silver Sponsors
rolldown/rolldown (rolldown)
v0.10.1
Compare Source
Bug Fixes
rolldown
node api should create graph (#302) (c7749ba)Symbol
should only be declared in one chunk (#338) (340cd27)output.format: 'esm'
tooutput.format: 'es'
(#625) (70b6cfd)[email protected]
(1af4b86)release-canary.yml
(6fc0430)release.yml
(#651) (6e68b1a)@rollup/plugin-commonjs
on rollup (#523) (181422a)__export()
when it's needed (670dbb6)OutputOptions.format
(#224) (0a79036)outputOptions
optional (#223) (b2439b1)prepare-publish-node
folder (14d2cd5)SimpleAssignmentTarget
(1d24efc)AssignmentTargetProperty
(5605fc2)RUNTIME_PATH
(#274) (c93a2fb)just bump packages
(778ae11)export default xxx
(#377) (7fa642f)export default import(...)
correctly (#220) (cd8ad5e)Resolver
everywhere (#253) (cbcee58)Features
ChunkRenderReturn
struct to make code clear (87f02c2)ExportsKind::None
(#315) (efdd252)generateBundle
hook (#403) (21fe501)OutputChunk
is_entry and facade_module_id (#230) (8fcfda3)PluginContext#resolve
(#670) (43f5173)referenced_symbols
toStmtInfo
(#75) (465e6e7)Renamer
(#123) (7709cd4)resolve
option (#392) (cd52449)RuntimeNormalModuleTask
(#40) (2401386)renderChunk
hook (#401) (b7ea28b)StmtInfo
in visiting ast (#370) (d962268)generateBundle
andwriteBundle
(#708) (343cfb9)release-semver.yml
(bb27d40)NormalModuleTask
(#298) (4d7d595)build
api (#266) (4430a89)ExportsKind::None
(#317) (b15ff14)cwd
in input options (#692) (ba42b29)Extend
forBatchedErrors
(e22acce)SideEffectDetector
(#497) (04a1e3c)MemberExpression
(#374) (abbc8aa)ChunkGraph
(#90) (0f7c82c)rolldown_rstr
(a97e444), closes #427trait BuildErrorLike
(#327) (158b11d)visit_top_level_stmt
while visiting ast (#371) (7bc5f92)BuildError
newtype (#326) (475907e)rollup-plugin-esbuild
(#711) (73f4c5e)scan
api (#340) (ba5257a)SourceType
(#179) (aeaf38b)buildStart
,resolveId
,buildEnd
,load
,transform
,renderChunk
hook (#680) (3dd1d7c)Symbols
and remove a lot ofReferenceId
(#93) (5b980d5)build
api (65b9bd6)VirtualStmtInfo
(#99) (344be1a)SymbolId
withSymbolRef
(#95) (9c90067)RenderedModule
(#503) (1cc0fbe)PluginContext
to JS (#628) (e4d33fd)OutputFormat::Cjs
(#358) (44c6331), closes #45print
inOxcCompiler
(#281) (ad962af)NormalModuleTask#resolve_dependencies
(#270) (fdbf290)InputOptions
andOutputOptions
together (#596) (d2c63d7)source
inBuildError
(#328) (c34d3cd)Configuration
📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.