Skip to content

chore: refresh lockfile (transitive dep bumps)#11

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
chore/lockfile-refresh
Open

chore: refresh lockfile (transitive dep bumps)#11
github-actions[bot] wants to merge 1 commit into
masterfrom
chore/lockfile-refresh

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated weekly npm update — bumps transitive deps within
their existing semver ranges. Catches drift between the
committed lockfile and current npm advisories before it
hits a release.

Includes a npm audit --audit-level=moderate clean
confirmation. If audit failed, this PR would not have
been opened — investigate manually instead.

Tests run on Node 24 against the updated lockfile.

@socket-security

socket-security Bot commented Jun 12, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​react@​19.2.14 ⏵ 19.2.171001007995100
Updated@​vitest/​coverage-v8@​4.1.6 ⏵ 4.1.9991007998100
Updated@​types/​node@​22.19.19 ⏵ 22.19.2110010081 +196100
Updatedtsx@​4.22.1 ⏵ 4.22.4100 +110082 +192100
Updatedreact@​19.2.6 ⏵ 19.2.71001008497100
Updatedink@​7.0.3 ⏵ 7.0.698 +1100100 +196 +2100
Updated@​biomejs/​biome@​2.4.15 ⏵ 2.5.0100 +110010099100
Updatedvitest@​4.1.6 ⏵ 4.1.9100 +3100100 +22100 +3100

View full report

@github-actions github-actions Bot force-pushed the chore/lockfile-refresh branch from ee421ab to a582f7b Compare June 15, 2026 07:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant