chore(deps): Bump the npm-security-updates group across 1 directory with 10 updates#52
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
This was referenced May 7, 2026
Closed
…ith 10 updates Bumps the npm-security-updates group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [minimatch](https://github.com/isaacs/minimatch) | `3.1.2` | `10.2.5` | | [@hono/node-server](https://github.com/honojs/node-server) | `1.19.9` | `1.19.14` | | [ajv](https://github.com/ajv-validator/ajv) | `6.12.6` | `8.20.0` | | [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.2.1` | `8.5.2` | | [flatted](https://github.com/WebReflection/flatted) | `3.3.3` | `3.4.2` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.7.8` | `4.7.9` | | [hono](https://github.com/honojs/hono) | `4.11.9` | `4.12.18` | | [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `4.0.4` | | [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `8.3.0` | `8.4.2` | Updates `minimatch` from 3.1.2 to 10.2.5 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v10.2.5) Updates `@hono/node-server` from 1.19.9 to 1.19.14 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.9...v1.19.14) Updates `ajv` from 6.12.6 to 8.20.0 - [Release notes](https://github.com/ajv-validator/ajv/releases) - [Commits](ajv-validator/ajv@v6.12.6...v8.20.0) Updates `express-rate-limit` from 8.2.1 to 8.5.2 - [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases) - [Commits](express-rate-limit/express-rate-limit@v8.2.1...v8.5.2) Updates `flatted` from 3.3.3 to 3.4.2 - [Commits](WebReflection/flatted@v3.3.3...v3.4.2) Updates `handlebars` from 4.7.8 to 4.7.9 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.7.8...v4.7.9) Updates `hono` from 4.11.9 to 4.12.18 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.11.9...v4.12.18) Updates `ip-address` from 10.0.1 to 10.2.0 - [Commits](https://github.com/beaugunderson/ip-address/commits) Updates `picomatch` from 2.3.1 to 4.0.4 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.3.1...4.0.4) Updates `path-to-regexp` from 8.3.0 to 8.4.2 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v8.3.0...v8.4.2) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 1.19.14 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: ajv dependency-version: 6.15.0 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: express-rate-limit dependency-version: 8.5.1 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: flatted dependency-version: 3.4.2 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: handlebars dependency-version: 4.7.9 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: hono dependency-version: 4.12.18 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: ip-address dependency-version: 10.2.0 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: minimatch dependency-version: 3.1.5 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: path-to-regexp dependency-version: 8.4.2 dependency-type: indirect dependency-group: npm-security-updates - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect dependency-group: npm-security-updates ... Signed-off-by: dependabot[bot] <support@github.com>
cb0066a to
1e80c94
Compare
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-security-updates group with 9 updates in the / directory:
3.1.210.2.51.19.91.19.146.12.68.20.08.2.18.5.23.3.33.4.24.7.84.7.94.11.94.12.182.3.14.0.48.3.08.4.2Updates
minimatchfrom 3.1.2 to 10.2.5Changelog
Sourced from minimatch's changelog.
... (truncated)
Commits
693c82310.2.57953af1do not allow .. to consume drive letter on Windows1caf918lint and format7783ed6ignore docs6d9b356update deps etcc36addb10.2.426b9002docs: add warning about ReDoS3a0d83bfix partial matching of globstar patternsea9484010.2.30873fbaupdate depsInstall script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
@hono/node-serverfrom 1.19.9 to 1.19.14Release notes
Sourced from @hono/node-server's releases.
Commits
b5e63a31.19.14c02d777fix: add custom inspect to lightweight Request/Response to prevent TypeError ...fd64e651.19.13025c30fMerge commit from fork6cdb5a71.19.1270250f7fix: request draining for early 413 responses (#329)cfc08b3chore: ignore claude setting (#314)ecd4d6b1.19.11c944899fix: do not overwrite Content-Length in the fast path pattern if Content-Leng...2f8ca361.19.10Updates
ajvfrom 6.12.6 to 8.20.0Release notes
Sourced from ajv's releases.
... (truncated)
Commits
0fba0b88.20.09caf8d6fix: add ES2022.RegExp for RegExpIndicesArray; fixes ajv-validator/ajv#2603 (...2065350fix: add support for node 22/24, drop node 16/21 (#2580)154b58d8.19.0e8d2bdctest/fix prototype pollution via $data ref with format keyword (#2607)142ce848.18.0720a23ffix(pattern): use configured RegExp engine with $data keyword to mitigate ReD...82735a1fix: typos in schema-language.md (#2507)b17ec32fix: small grammatical error in managing-schemas.md (#2508)69568d0fix: #2482 Infinity and NaN serialise to null (#2487)Install script changes
This version modifies
prepublishscript that runs during installation. Review the package contents before updating.Updates
express-rate-limitfrom 8.2.1 to 8.5.2Release notes
Sourced from express-rate-limit's releases.
Commits
97746938.5.20e94cc0v8.5.2 changelog9a583c5feat: simplify IPv6 key generation (#633)4f4b3fbchore(deps-dev): bump lint-staged from 16.4.0 to 17.0.4 (#632)3c1d6c5chore(deps-dev): bump the development-dependencies group with 7 updates (#631)18884b6chore(deps): bump basic-ftp from 5.2.0 to 5.3.1 (#630)dacc980chore(deps): bump handlebars from 4.7.8 to 4.7.9 (#629)486d0c6chore(deps): bump follow-redirects from 1.15.11 to 1.16.0 (#627)50cc3f68.5.192c8e3echore: bump ip-address library to latest (#626)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for express-rate-limit since your current version.
Updates
flattedfrom 3.3.3 to 3.4.2Commits
3bf09093.4.2885ddccfix CWE-13210bdba70added flatted-view to the benchmark2a02dce3.4.1fba4e8fMerge pull request #89 from WebReflection/python-fix5fe8648added "when in Rome" also a test for PHP53517adsome minor improvementb3e2a0cFixing recursion issue in Python tooc4b46dbAdd SECURITY.md for security policy and reportingf86d071Create dependabot.yml for version updatesUpdates
handlebarsfrom 4.7.8 to 4.7.9Release notes
Sourced from handlebars's releases.
Changelog
Sourced from handlebars's changelog.
Commits
dce542cv4.7.98a41389Update release notes68d8df5Fix security issuesb2a0831Fix browser tests9f98c16Fix release script45443b4Revert "Improve partial indenting performance"8841a5fFix CI errors with lintinge0137c2fix: enable shell mode for spawn to resolve Windows EINVAL issuee914d60Improve rendering performance7de4b41Upgrade GitHub Actions checkout and setup-node on 4.x branchUpdates
honofrom 4.11.9 to 4.12.18Release notes
Sourced from hono's releases.
... (truncated)
Commits
f10dee84.12.18a5bd9ebMerge commit from fork58d3d3aMerge commit from fork568c2ecMerge commit from forkff2b3d34.12.1752aaaf9fix(types): propagate middleware response types to app.on overloads (#4906)76d5589fix(cors): make origin optional in CORSOptions (#4905)8f027e5fix(ssg): addatom+xmlandrss+xmltodefaultExtensionMap(#4899)bfba97cfix(jsx): normalize SVG attributes on the <svg> root element (#4893)90d41824.12.16Updates
ip-addressfrom 10.0.1 to 10.2.0Commits
Updates
picomatchfrom 2.3.1 to 4.0.4Release notes
Sourced from picomatch's releases.
Changelog
Sourced from picomatch's changelog.
... (truncated)
Commits
e5474fcPublish 4.0.44516eb5Merge commit from fork5eceecdMerge commit from fork0db7dd7Run benchmark again against latest minimatch version (#161)9500377docs: clarify what brace expansion syntax is and isn't supported (#134)2661f23fix typo in globstars.js test name (#138)1798b07docs: fixmakeReexample (#143)9d76bc5chore: undocument removed options (#146)e4d718bRemove unused time-require (#160)38dffebchore(deps): pin dependencies (#158)Updates
path-to-regexpfrom 8.3.0 to 8.4.2Release notes
Sourced from path-to-regexp's releases.
Commits
cbf30258.4.2937c02dMinimize array allocations (#437)57247e6Improve compile performance (#436)5844988Remove internal tokenization during parse (#435)9a78879Error on trailing backslash (#434)7f058768.4.16bc8e84Remove trie deduplication (#431)5bcd30bAllow backtrack handling to match itself (#427)9f9c6c5Add parsing to benchmarks (#418)9fd31e0Addtrailing: falsetests (#428)