Skip to content

chore(deps): rolling dependency update - #16

Open
socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update
Open

socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update

Conversation

@socket-pr-bot

@socket-pr-bot socket-pr-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown

Rolling dependency update

One long-lived PR, rebuilt from main on every run so it stays
mergeable. Each run appends its dependency delta below, newest first.

2026-09-20 — run · 5 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-19 — run · 5 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-18 — run · 4 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
commits
  • chore(deps): apply weekly update fixes

Note

Low Risk
Routine version bumps to dev/tooling and test dependencies with no application logic changes; minor HTTP client patch via undici.

Overview
This rolling dependency update bumps the fleet Node pin in .node-version from 26.8.1 to 26.8.2 and refreshes pnpm-lock.yaml from the catalog changes in pnpm-workspace.yaml.

Catalog pins move @mdn/browser-compat-data (8.1.0 → 8.1.1), compromise (14.16.0 → 14.17.0, including the judgment-nudge hook), fast-check (4.9.0 → 4.10.0), and magic-string (1.2.3 → 1.3.1, with @jridgewell/sourcemap-codec following for Vitest/mocker). The fleet undici override is also bumped 6.28.0 → 6.28.1 for @actions/* HTTP clients. The lockfile reflects a pnpm package-manager entry at 12.4.1 (down from 12.4.2) alongside these resolutions.

Reviewed by Cursor Bugbot for commit 8d2e0e4. Configure here.

@socket-pr-bot socket-pr-bot Bot added dependencies Pull requests that update a dependency file automation Automated maintenance labels Sep 18, 2026
@socket-security

socket-security Bot commented Sep 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedyaml@​2.9.0 ⏵ 2.9.1100 +110010090100
Updatedfast-check@​4.9.0 ⏵ 4.10.0100 +1100100 +190 -2100
Updatedcompromise@​14.16.0 ⏵ 14.17.09810010092 +1100
Updatedmagic-string@​1.2.3 ⏵ 1.3.1100100100 +197 +1100
Updated@​mdn/​browser-compat-data@​8.1.0 ⏵ 8.1.110010010098100

View full report

@socket-security-staging

socket-security-staging Bot commented Sep 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcompromise@​14.16.0 ⏵ 14.17.09810010090 -1100
Updatedfast-check@​4.9.0 ⏵ 4.10.0100 +110010090100
Updatedyaml@​2.9.0 ⏵ 2.9.1100 +110010092 +6100
Updatedmagic-string@​1.2.3 ⏵ 1.3.1100100100 +197 +1100
Updated@​mdn/​browser-compat-data@​8.1.0 ⏵ 8.1.110010010098100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation Automated maintenance dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants