chore(deps): bump the production-dependencies group in /web with 3 updates - #1240
Conversation
Bumps the production-dependencies group in /web with 3 updates: [jose](https://github.com/panva/jose), [marked](https://github.com/markedjs/marked) and [sharp](https://github.com/lovell/sharp). Updates `jose` from 6.2.9 to 6.2.10 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](panva/jose@v6.2.9...v6.2.10) Updates `marked` from 18.0.10 to 18.0.11 - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@v18.0.10...v18.0.11) Updates `sharp` from 0.35.3 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) --- updated-dependencies: - dependency-name: jose dependency-version: 6.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: marked dependency-version: 18.0.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: sharp dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
…dencies-82100a2b87
|
Claude finished @dependabot[bot]'s task —— View job Pull Request Review: Dependency UpdatesI've completed a thorough review of these dependency updates. Here's my analysis: 🔒 Security AssessmentHIGHLY RECOMMENDED - All three updates include important security and stability fixes:
|
…dencies-82100a2b87
…dencies-82100a2b87
…dencies-82100a2b87
- Updated from 0.164.2 to 0.164.3 - Based on PR #1240: chore(deps): bump the production-dependencies group in /web with 3 updates - Bump type: patch 🤖 Generated by automatic versioning workflow
Bumps the production-dependencies group in /web with 3 updates: jose, marked and sharp.
Updates
josefrom 6.2.9 to 6.2.10Release notes
Sourced from jose's releases.
Changelog
Sourced from jose's changelog.
Commits
3eab152chore(release): 6.2.10021abf4refactor(jws): specialize compact processinga998927refactor(jwe): specialize compact processingeedb124refactor(jose): share binary input validation52ba159refactor(jwt): share producer claim state85e30edrefactor(jose): share compact token processing internals0bd81d2test(jose): cover hidden critical-header options9cf7876test(jose): reject callable object impostorsf23cafdtest(jose): preserve resolved key data properties1ee6f61refactor(jwe): consolidate CBC decryption failuresUpdates
markedfrom 18.0.10 to 18.0.11Release notes
Sourced from marked's releases.
Commits
53cb13fchore(release): 18.0.11 [skip ci]0c6b2a6docs: add adaptable bullet point (#4058)c430a64chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#4069)b699db3fix: keep emphasis in the text of a rejected reference link (#4059)0653c24fix: inlineTokens rebuilds the reflink-mask preamble per call (#4040)e250e31fix: do not nest a link inside a link (#4051)Updates
sharpfrom 0.35.3 to 0.35.4Release notes
Sourced from sharp's releases.
Commits
7f1a0a2Release v0.35.4f927818Upgrade to sharp-libvips v1.3.3e802092Prerelease v0.35.4-rc.0e13eb2fCI: Fix wasm32 build (#4589)a82a0b3Upgrade to libvips v8.18.68044fe4Bound resize dimensions to coordinate limit147f859Docs: changelog entries for #4578 #4584ee5bfb8Tests: use yauzl directly rather than via extract-zip wrapper7a77889Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)ea5bef2Improve support for input Streams finishing before output is requested (#4584)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions