Skip to content

chore(deps-dev): bump the development-dependencies group across 1 directory with 6 updates - #719

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/development-dependencies-ced195059c
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/development-dependencies-ced195059c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 6 updates in the / directory:

Package From To
@openally/config.eslint 2.4.2 3.0.1
@types/node 26.1.1 26.6.1
c8 11.0.0 12.0.0
typescript 6.0.2 7.0.2
@nodesecure/i18n 4.1.0 4.1.1
@nodesecure/mama 2.3.1 2.4.0

Updates @openally/config.eslint from 2.4.2 to 3.0.1

Release notes

Sourced from @​openally/config.eslint's releases.

@​openally/config.eslint@3.0.1

Patch Changes

@​openally/config.eslint@3.0.0

Major Changes

@​openally/config.eslint@2.4.3

Patch Changes

Changelog

Sourced from @​openally/config.eslint's changelog.

3.0.1

Patch Changes

3.0.0

Major Changes

2.4.3

Patch Changes

Commits
  • 5e403f6 chore: update versions (#198)
  • c207b1b fix(eslint): @​stylistic/function-paren-newline to multiline-arguments (#197)
  • aa608e7 chore: update versions (#186)
  • 3130c62 chore(deps): bump the dependencies group with 6 updates (#192)
  • a0565ac refactor(eslint): re-enforce strict rules for agentic (IA) era
  • 9d75a12 refactor(eslint)!: enhance CustomRules and fix TSLint deprecation (#184)
  • f7d0668 chore: update versions (#171)
  • 79ecbc8 fix(eslint/imports): classify # as internal dependency because of Node subimp...
  • 3230eff chore: update typescript and @​types/node manually
  • df87072 chore(deps): bump the dependencies group across 1 directory with 3 updates (#...
  • Additional commits viewable in compare view

Updates @types/node from 26.1.1 to 26.6.1

Commits

Updates c8 from 11.0.0 to 12.0.0

Release notes

Sourced from c8's releases.

v12.0.0

12.0.0 (2026-07-14)

⚠ BREAKING CHANGES

  • yargs enforces a stricter range of Node versions ^20.19.0 || ^22.12.0 || >=23

Features

Changelog

Sourced from c8's changelog.

12.0.0 (2026-07-14)

⚠ BREAKING CHANGES

  • yargs enforces a stricter range of Node versions ^20.19.0 || ^22.12.0 || >=23

Features

Commits

Updates typescript from 6.0.2 to 7.0.2

Release notes

Sourced from typescript's releases.

TypeScript 7.0.2

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

Commits
  • 1e4744d Merge branch 'main' into ts7-release
  • a5a219cmicrosoft/typescript-go#4558
  • ecfe30d Update status localization
  • 5de25b5 Hide executable name in TypeScript status
  • d7ce74a Show bundled TypeScript version for packaged servers
  • 29be66a Correct TS 7 release version to 7.0.2
  • ed2bd1b Merge branch 'main' into ts7-release
  • 8873075 Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...
  • 9427131 Set up stable / nightly extension split, other prep (microsoft/typescript-go#...
  • d4eaca5microsoft/typescript-go#4549
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Updates @nodesecure/i18n from 4.1.0 to 4.1.1

Changelog

Sourced from @​nodesecure/i18n's changelog.

4.1.1

Patch Changes

Commits
  • 25121d2 chore: update versions
  • 17c3bcd feat(i18n): merge warnings and sast warnings from js-x-ray pkg (#748)
  • d9e51cf chore(deps): bump the dependencies group across 1 directory with 6 updates (#...
  • b4053af fix(ci): properly execute tests with glob for Windows and UNIX
  • 64502bf chore: update @​openally/config.eslint (#674)
  • See full diff in compare view

Updates @nodesecure/mama from 2.3.1 to 2.4.0

Release notes

Sourced from @​nodesecure/mama's releases.

@​nodesecure/mama@​2.4.0

Minor Changes

  • #741 53c60c1 Thanks @​fraxken! - Refactor highlight extractors to make them work in a web env. Add unit-test to scanner to ensure compatibility and CI break.
  • #735 f17981a Thanks @​clemgbld! - feat: extend contact with free email service flag

Patch Changes

Changelog

Sourced from @​nodesecure/mama's changelog.

2.4.0

Minor Changes

  • #741 53c60c1 Thanks @​fraxken! - Refactor highlight extractors to make them work in a web env. Add unit-test to scanner to ensure compatibility and CI break.
  • #735 f17981a Thanks @​clemgbld! - feat: extend contact with free email service flag

Patch Changes

Commits
  • 4b182ad chore: update versions (#742)
  • 52be58f chore: update versions (#738)
  • 53c60c1 fix(scanner): ensure extractors are working in a web env (#741)
  • f17981a feat: extend contact with free email service flag (#735)
  • d9e51cf chore(deps): bump the dependencies group across 1 directory with 6 updates (#...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ectory with 6 updates

Bumps the development-dependencies group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@openally/config.eslint](https://github.com/OpenAlly/configs/tree/HEAD/src/eslint) | `2.4.2` | `3.0.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.6.1` |
| [c8](https://github.com/bcoe/c8) | `11.0.0` | `12.0.0` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.2` | `7.0.2` |
| [@nodesecure/i18n](https://github.com/NodeSecure/scanner/tree/HEAD/workspaces/i18n) | `4.1.0` | `4.1.1` |
| [@nodesecure/mama](https://github.com/NodeSecure/scanner/tree/HEAD/workspaces/mama) | `2.3.1` | `2.4.0` |



Updates `@openally/config.eslint` from 2.4.2 to 3.0.1
- [Release notes](https://github.com/OpenAlly/configs/releases)
- [Changelog](https://github.com/OpenAlly/configs/blob/main/src/eslint/CHANGELOG.md)
- [Commits](https://github.com/OpenAlly/configs/commits/@openally/config.eslint@3.0.1/src/eslint)

Updates `@types/node` from 26.1.1 to 26.6.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `c8` from 11.0.0 to 12.0.0
- [Release notes](https://github.com/bcoe/c8/releases)
- [Changelog](https://github.com/bcoe/c8/blob/main/CHANGELOG.md)
- [Commits](bcoe/c8@v11.0.0...v12.0.0)

Updates `typescript` from 6.0.2 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v6.0.2...v7.0.2)

Updates `@nodesecure/i18n` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/NodeSecure/scanner/releases)
- [Changelog](https://github.com/NodeSecure/scanner/blob/master/workspaces/i18n/CHANGELOG.md)
- [Commits](https://github.com/NodeSecure/scanner/commits/@nodesecure/i18n@4.1.1/workspaces/i18n)

Updates `@nodesecure/mama` from 2.3.1 to 2.4.0
- [Release notes](https://github.com/NodeSecure/scanner/releases)
- [Changelog](https://github.com/NodeSecure/scanner/blob/master/workspaces/mama/CHANGELOG.md)
- [Commits](https://github.com/NodeSecure/scanner/commits/@nodesecure/mama@2.4.0/workspaces/mama)

---
updated-dependencies:
- dependency-name: "@openally/config.eslint"
  dependency-version: 3.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: c8
  dependency-version: 12.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: "@nodesecure/i18n"
  dependency-version: 4.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: "@nodesecure/mama"
  dependency-version: 2.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 21, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 21, 2026 09:03
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Sep 21, 2026
@changeset-bot

changeset-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 6753473

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​nodesecure/​mama@​2.3.1 ⏵ 2.4.07510099 +193 -3100
Updated@​nodesecure/​i18n@​4.1.0 ⏵ 4.1.177 -110010090 +3100
Updated@​openally/​config.eslint@​2.4.2 ⏵ 3.0.178 +11009393 +1100
Updated@​types/​node@​26.1.1 ⏵ 26.6.1100 +110081 +196100
Added@​nodesecure/​js-x-ray@​16.1.08210010096100
Updatedc8@​11.0.0 ⏵ 12.0.09910010085100
Updatedtypescript@​6.0.2 ⏵ 7.0.29910089 -1100100 +10

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm typescript

License: LicenseRef-W3C-Community-Final-Specification-Agreement - The applicable license policy does not permit this license (5) (package/ThirdPartyNoticeText.txt)

From: package-lock.jsonnpm/@nodesecure/i18n@4.1.1npm/@typescript-eslint/typescript-estree@8.70.0npm/@openally/config.eslint@3.0.1npm/typescript@6.0.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/typescript@6.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants