Skip to content

Bump the production-dependencies group with 6 updates - #226

Merged
felickz merged 7 commits into
mainfrom
dependabot/npm_and_yarn/production-dependencies-9813dc4c69
Sep 4, 2026
Merged

Bump the production-dependencies group with 6 updates#226
felickz merged 7 commits into
mainfrom
dependabot/npm_and_yarn/production-dependencies-9813dc4c69

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 6 updates:

Package From To
@actions/core 1.10.0 3.0.1
@actions/github 6.0.0 9.1.1
@jest/globals 29.5.0 30.5.1
@octokit/action 4.0.10 8.0.4
@vercel/ncc 0.34.0 0.45.0
dotenv 16.0.3 17.4.2

Updates @actions/core from 1.10.0 to 3.0.1

Changelog

Sourced from @​actions/core's changelog.

3.0.1

  • Bump undici from 6.23.0 to 6.24.1 #2348

3.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

2.0.3

  • Bump @actions/http-client to 3.0.2

2.0.1

  • Bump @​actions/exec from 1.1.1 to 2.0.0 #2199

2.0.0

  • Add support for Node 24 #2110
  • Bump @​actions/http-client from 2.0.1 to 3.0.0

1.11.1

  • Fix uses of crypto.randomUUID on Node 18 and earlier #1842

1.11.0

  • Add platform info utilities #1551
  • Remove dependency on uuid package #1824

1.10.1

  • Fix error message reference in oidc utils #1511
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​actions/core since your current version.


Updates @actions/github from 6.0.0 to 9.1.1

Changelog

Sourced from @​actions/github's changelog.

9.1.1

  • Bump undici from 6.23.0 to 6.24.0 #2346

9.1.0

  • Append actions_orchestration_id to user-agent when the ACTIONS_ORCHESTRATION_ID environment variable is set #2364

9.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()
    • Example: const { getOctokit, context } = await import('@actions/github')
  • Fix TypeScript compilation by migrating to ESM, enabling proper imports from @octokit/core/types

8.0.1

  • Update undici to 6.23.0
  • Update @actions/http-client to 3.0.2

8.0.0

  • Update @​octokit dependencies
    • @octokit/core ^7.0.6
    • @octokit/plugin-paginate-rest ^14.0.0
    • @octokit/plugin-rest-endpoint-methods ^17.0.0
    • @octokit/request ^10.0.7
    • @octokit/request-error ^7.1.0
  • Breaking change: Minimum Node.js version is now 20 (previously 18)

7.0.0

  • Update to v3.0.1 of @actions/http-client

6.0.1

  • Dependency updates #2043
  • Add context.runAttempt #1588
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​actions/github since your current version.


Updates @jest/globals from 29.5.0 to 30.5.1

Release notes

Sourced from @​jest/globals's releases.

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

v30.5.0

On a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴


This is a big release. It touches jest-runtime, jest-resolve and jest-haste-map in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please open an issue.

Highlights

whenCalledWith

Mock functions can now configure return values per argument list, contributed by @​timkindberg (#16053):

const fn = jest.fn();
fn.whenCalledWith('apple').mockReturnValue('red');
fn.whenCalledWith('banana').mockReturnValue('yellow');
fn.whenCalledWith(expect.any(Number)).mockReturnValue('numeric');
fn('apple'); // 'red'
fn('banana'); // 'yellow'
fn(42); // 'numeric'
fn('grape'); // undefined

The returned object is a real Mock, so mockReturnValueOnce, mockResolvedValue, mockImplementation etc. all chain here too. Argument slots accept literals or any asymmetric matcher, with the same equality semantics as toHaveBeenCalledWith(). Calls that match nothing fall through to the base mock. See the Mock Functions docs for matching and precedence details.

Describe-level retries

jest.retryTimes() can now retry a whole describe block instead of a single test, contributed by @​soltonigiri (#16322). Each attempt reruns the block's beforeAll/afterAll hooks, child tests and nested describes, which helps when tests in a block depend on shared state:

</tr></table> 

... (truncated)

Changelog

Sourced from @​jest/globals's changelog.

30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

30.5.0

Features

  • [@jest/expect-utils, jest-mock] Add mockFn.whenCalledWith(...args) for configuring return values per argument list, with first-class asymmetric-matcher support (#16053)
  • [@jest/expect-utils] Export AsymmetricMatcher and FunctionParameters types (previously private to expect) (#16053)
  • [jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types] --collectTests now expands test.each/describe.each cases and reports per-status counts (skipped/todo via the new wouldRun flag for selected tests) plus a summary line that match a real run, including under --testNamePattern and .only/fdescribe focus on both the circus and jasmine2 runners (#16259)
  • [jest-circus, jest-environment, jest-runtime, jest-types] Add describe-level retries via jest.retryTimes(..., {entireDescribe: true}) (#16322)
  • [jest-circus, jest-message-util, jest-reporters, jest-types] Add retryMessages to AssertionResult and export formatErrorStack, so the retry log renders nested cause and AggregateError sections with code frames instead of serialized [cause]:/[errors]: markers (#16316)
  • [jest-circus, jest-types] Add unhandledErrorsDetailed to Circus.RunResult, so an unhandled rejection reports its cause chain and AggregateError entries with code frames instead of a pre-serialized stack (#16316)
  • [jest-haste-map] Replace NodeWatcher and FSEventsWatcher with @parcel/watcher for the non-watchman watch path (#16188)
  • [jest-resolve] Bump unrs-resolver to 1.12.1, remove jest-pnp-resolver and unnecessary checks (#15721)
  • [jest-resolve] Honor Node's --preserve-symlinks / NODE_PRESERVE_SYMLINKS in the default resolver by passing symlinks: false to unrs-resolver (#16260)
  • [jest-runtime] Apply automocking and manual __mocks__ files to synchronously evaluable ESM graphs on Node 24.9+ - static imports, dynamic import() and require() of an ESM file now generate an automock from the real module's namespace instead of failing with "Attempting to import a mock without a factory". Graphs that need async evaluation (top-level await) or an async-only resolver or transformer still throw (#16391)
  • [jest-runtime] Route process.getBuiltinModule through the sandbox, so it returns the sandbox process and the hooked node:module instead of the host's (#16391)
  • [jest-runtime] Throw an actionable error from module.register() and module.registerHooks() inside a test - the hooks attached to the loader running Jest itself, never saw the sandboxed requires they were meant for, and stayed registered for every later test file in the worker (#16391)
  • [jest-runtime] Surface resolution and import-attribute errors in an ESM graph before executing any of its CJS dependencies on Node 24.9+, matching Node's run-nothing-on-a-broken-graph behavior; the legacy loader on older versions keeps its linking-time execution order (#16391)
  • [jest-runtime] Throw ERR_SOURCE_PHASE_NOT_DEFINED with an actionable message for import source and import.source(), instead of failing at instantiation with V8's bare "Source phase import object is not defined" (#16391)
  • [jest-runtime] Emit the JSON-without-import-attribute deprecation warning once per test file instead of once per worker, so it is no longer silently swallowed for every file after the first (#16391)
  • [jest-runtime] Set import.meta.main to true in the test file and false in every module it loads, matching Node 24+ (#16367)
  • [jest-runtime] Resolve the module-sync export condition, so a package that exposes its ESM entry point for require() loads the same file Node would (#16336)
  • [jest-snapshot] Add external snapshot paths to custom reporter failure details (#16374)

Fixes

  • [jest-console, jest-reporters] CustomConsole now buffers console output so TestResult.console is populated for reporters when verbose is enabled, while GitHubActionsReporter avoids replaying buffered output in verbose mode (#16155)
  • [expect, jest-message-util, jest-pattern, jest-regex-util, jest-util] Revert node: protocol imports to restore webpack/browser-bundle compatibility (#16167)
  • [expect] Widen toMatchObject and objectContaining parameter type from Record<string, unknown> to object so class instances are accepted (#16196)
  • [jest-circus] Call a generator test body with the shared test context, so this matches what a regular test function receives (#16347)
  • [jest-circus] Capture the error listeners of the parent process instead of the in-sandbox process, so listeners registered before the test file survive teardown and sandbox listeners no longer leak onto the parent (#16347)
  • [jest-circus] Clear currentlyRunningTest after skipped and todo tests (#16342)
  • [jest-circus] Prevent late done() callbacks from affecting later test or hook invocations (#16343)
  • [jest-circus, jest-jasmine2] Honor --expand when formatting node:assert failures, instead of always collapsing the diff (#16347)
  • [jest-circus, jest-jasmine2, jest-message-util] Serialize the inner errors of an AggregateError into failureMessages, retryReasons and unhandledErrors, so --json output and reporter annotations include them (#16316)
  • [jest-circus, jest-snapshot] Keep snapshot state and counts correct when a test retries (#16344)
  • [@jest/create-cache-key-function] Include the caller support flags in the generated key, so a transformer that emits ESM or CJS based on them no longer shares one cache entry between the two (#16331)

... (truncated)

Commits

Updates @octokit/action from 4.0.10 to 8.0.4

Release notes

Sourced from @​octokit/action's releases.

v8.0.4

8.0.4 (2025-11-04)

Bug Fixes

  • deps: update dependency undici to v7 (#662) (48feb05)

v8.0.3

8.0.3 (2025-11-03)

Bug Fixes

  • deps: update octokit monorepo (major) (#710) (385e049)

v8.0.2

8.0.2 (2025-05-26)

Bug Fixes

  • deps: update dependency @​octokit/plugin-rest-endpoint-methods to v16 (#703) (25f537f)

v8.0.1

8.0.1 (2025-05-21)

Bug Fixes

  • deps: update octokit monorepo (major) (#702) (76679e4)

v8.0.0

8.0.0 (2025-05-20)

Continuous Integration

BREAKING CHANGES

  • Drop support for NodeJS v18

  • build: set minimal node version in build script to v20

  • ci: stop testing against NodeJS v18

v7.0.2

... (truncated)

Commits
  • 1c4486a chore(deps): update dependency prettier to v3.6.2 (#705)
  • 24ae278 chore(deps): update dependency @​types/node to v24 (#718)
  • 48feb05 fix(deps): update dependency undici to v7 (#662)
  • f394dee chore(deps): update vitest monorepo to v4 (major) (#717)
  • ce067a1 build(deps): lock file maintenance (#712)
  • 77396df ci(action): update actions/checkout action to v5 (#707)
  • 385e049 fix(deps): update octokit monorepo (major) (#710)
  • f0edfd1 ci(action): update actions/setup-node action to v6 (#715)
  • 3e52577 ci(action): update peter-evans/create-or-update-comment action to v5 (#713)
  • 99dc11f ci(action): update github/codeql-action action to v4 (#714)
  • Additional commits viewable in compare view

Updates @vercel/ncc from 0.34.0 to 0.45.0

Release notes

Sourced from @​vercel/ncc's releases.

0.45.0

0.45.0 (2026-08-13)

Features

  • update @​vercel/webpack-asset-relocator-loader to 1.10.3 (#1342) (cb1f1f0)

0.44.1

0.44.1 (2026-06-29)

Bug Fixes

0.44.0

0.44.0 (2026-06-09)

Features

0.43.0

0.43.0 (2026-06-09)

Changes

  • BREAKING CHANGE: add Node 24 and 26 support, remove 20 (#1318) (#1305)
  • switch npm releases to trusted publishing (OIDC) (#1325) (#1327) (#1328) (#1329) (#1330) (#1331) (#1332)
  • switch package management to pnpm (#1321)
  • fix predictable global cache directory in /tmp enables symlink/hijack risks (#1314)
  • reorder extension resolution to prioritise TypeScript over JSON (#1315)
  • support TypeScript 6 transpile builds (#1316)

0.38.4

0.38.4 (2025-09-18)

Bug Fixes

0.38.3

0.38.3 (2024-11-15)

Bug Fixes

... (truncated)

Commits
  • cb1f1f0 feat: update @​vercel/webpack-asset-relocator-loader to 1.10.3 (#1342)
  • cfec24e chore(deps): Bump actions/setup-python from 6 to 7 (#1338)
  • b037995 chore(deps): Bump actions/setup-node from 6 to 7 (#1339)
  • 063c592 chore(deps): Bump actions/checkout from 6 to 7 (#1335)
  • 8f0aefd fix: preserve runtime createRequire in ESM builds (#1334)
  • b9c6310 chore: Update vm2 to latest version (3.11.5) (#1333)
  • 88be21f chore(deps): Bump actions/checkout from 5 to 6 (#1300)
  • 5ea625e feat: read permissions pr.yml (#1323)
  • a1ff315 feat: remove npm devDependency (#1332)
  • 9e077ab feat: add publishConfig to package.json (#1331)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​vercel/ncc since your current version.


Updates dotenv from 16.0.3 to 17.4.2

Changelog

Sourced from dotenv's changelog.

17.4.2 (2026-04-12)

Changed

  • Improved skill files - tightened up details (#1009)

17.4.1 (2026-04-05)

Changed

  • Change text injecting to injected (#1005)

17.4.0 (2026-04-01)

Added

  • Add skills/ folder with focused agent skills: skills/dotenv/SKILL.md (core usage) and skills/dotenvx/SKILL.md (encryption, multiple environments, variable expansion) for AI coding agent discovery via the skills.sh ecosystem (npx skills add motdotla/dotenv)

Changed

  • Tighten up logs: ◇ injecting env (14) from .env (#1003)

17.3.1 (2026-02-12)

Changed

  • Fix as2 example command in README and update spanish README

17.3.0 (2026-02-12)

Added

  • Add a new README section on dotenv’s approach to the agentic future.

Changed

  • Rewrite README to get humans started more quickly with less noise while simultaneously making more accessible for llms and agents to go deeper into details.

17.2.4 (2026-02-05)

Changed

  • Make DotenvPopulateInput accept NodeJS.ProcessEnv type (#915)
  • Give back to dotenv by checking out my newest project vestauth. It is auth for agents. Thank you for using my software.

17.2.3 (2025-09-29)

Changed

  • Fixed typescript error definition (#912)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core) | `1.10.0` | `3.0.1` |
| [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github) | `6.0.0` | `9.1.1` |
| [@jest/globals](https://github.com/jestjs/jest/tree/HEAD/packages/jest-globals) | `29.5.0` | `30.5.1` |
| [@octokit/action](https://github.com/octokit/action.js) | `4.0.10` | `8.0.4` |
| [@vercel/ncc](https://github.com/vercel/ncc) | `0.34.0` | `0.45.0` |
| [dotenv](https://github.com/motdotla/dotenv) | `16.0.3` | `17.4.2` |


Updates `@actions/core` from 1.10.0 to 3.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md)
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core)

Updates `@actions/github` from 6.0.0 to 9.1.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md)
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github)

Updates `@jest/globals` from 29.5.0 to 30.5.1
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest-globals)

Updates `@octokit/action` from 4.0.10 to 8.0.4
- [Release notes](https://github.com/octokit/action.js/releases)
- [Commits](octokit/action.js@v4.0.10...v8.0.4)

Updates `@vercel/ncc` from 0.34.0 to 0.45.0
- [Release notes](https://github.com/vercel/ncc/releases)
- [Commits](vercel/ncc@0.34.0...0.45.0)

Updates `dotenv` from 16.0.3 to 17.4.2
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v16.0.3...v17.4.2)

---
updated-dependencies:
- dependency-name: "@actions/core"
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@actions/github"
  dependency-version: 9.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@jest/globals"
  dependency-version: 30.5.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@octokit/action"
  dependency-version: 8.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@vercel/ncc"
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: dotenv
  dependency-version: 17.4.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 4, 2026
Copilot AI and others added 2 commits September 4, 2026 22:47
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>
@felickz

felickz commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Copilot AI commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

@copilot fix the failing CI (https://github.com/advanced-security/secret-scanning-notifications/actions/runs/33926645375/job/101196515494?pr=226 https://github.com/advanced-security/secret-scanning-no...

Fixed in commit 7f8948f. I investigated the linked failing jobs, then updated dependencies to CommonJS-compatible versions that pass this repo’s current toolchain: @actions/core ^1.11.1, @actions/github ^6.0.0, and @octokit/action ^6.1.0, with regenerated dist artifacts. I also re-ran npm test, npm run build, and npm run package successfully.

Copilot AI and others added 3 commits September 4, 2026 22:51
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>

Copilot AI commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

@copilot fix the failing CI (https://github.com/advanced-security/secret-scanning-notifications/actions/runs/33926973909/job/101197554456?pr=226) for this PR

Fixed in commit 9e72a55. I investigated the linked failing job and updated .github/workflows/check-dist.yml to run on Node 22.x instead of Node 16.x. The failure was TypeError: N.hash is not a function from @vercel/ncc during npm run build, and this now passes with npm run build, npm run package, and npm test.

@felickz
felickz merged commit b2f0f7f into main Sep 4, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-9813dc4c69 branch September 4, 2026 22:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants