fix(deps): update all non-major dependencies - #5566
Conversation
|
Size Report 1Affected ProductsNo changes between base commit (6a02778) and merge commit (0747f3e).Test Logs |
Size Analysis Report 1Affected ProductsNo changes between base commit (6a02778) and merge commit (0747f3e).Test Logs |
bf50472 to
d526749
Compare
c2979ca to
6cf7147
Compare
99ceda6 to
5d1f27e
Compare
|
@dwyfrequency either make a copy of this PR and try to remove problematic PRs or do a blank branch and one by one add in updates |
Changeset File Check ✅
|
| @@ -25,7 +25,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
| @@ -26,7 +26,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
| @@ -26,7 +26,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
| @@ -26,7 +26,7 @@ | |||
| <script src="/firebase-messaging.js"></script> | |||
| <script src="../app.js"></script> | |||
| <script src="../constants.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.1.3/sinon.min.js"></script> | |||
| <script src="https://cdnjs.cloudflare.com/ajax/libs/sinon.js/4.5.0/sinon.min.js"></script> | |||
Check warning
Code scanning / CodeQL
Inclusion of functionality from an untrusted source Medium test
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
| "@rushstack/node-core-library": "5.19.1", | ||
| "@rushstack/ts-command-line": "4.23.3", | ||
| "@rushstack/node-core-library": "5.23.1", | ||
| "@rushstack/ts-command-line": "4.23.7", |
There was a problem hiding this comment.
The following vulnerability impacts ajv versions <5.3.3: CVE-2025-69873.
It can be remediated by updating to version 5.3.3 or higher.
Dependency Tree
@rushstack/ts-command-line@4.23.7
└── @rushstack/terminal@0.15.2
└── @rushstack/node-core-library@5.13.0
├── ajv-formats@3.0.1
│ └── ajv@8.13.0
└── ajv@8.13.0
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| "@rushstack/ts-command-line": "4.23.7", | |
| "@rushstack/ts-command-line": "5.3.3", |
Vertex AI Mock Responses Check
|
This PR contains the following updates:
7.29.6→7.29.77.26.3→7.29.77.26.8→7.29.77.26.0→7.29.77.25.9→7.29.70.5.0→0.7.02.27.12→2.31.10.6.0→0.8.0~1.9.0→~1.14.0^0.7.8→^0.8.016.0.0→16.0.316.0.0→16.0.36.0.2→6.0.35.19.1→5.23.34.23.3→4.23.74.17.21→4.17.258.2.10→8.2.130.14.9→0.14.1018.19.83→18.19.13018.19.83→18.19.13017.0.33→17.0.35v5.6.0→v5.7.030.2.0→30.4.1^150.0.0→^150.0.32.8.5→2.8.64.1.0→4.4.02.31.0→2.32.015.24.0→15.25.18.2.6→8.2.730.2.0→30.4.230.2.0→30.4.14.3.0→4.3.14.3.0→4.3.11.2.1→1.3.09.0.6→9.0.74.57.2→4.66.11.1.6→1.1.722.12.0→22.23.21.55.1→1.62.13.9.4→3.9.64.62.2→4.62.44.62.2→4.62.43.5.3→3.7.14.30.0→4.46.07.7.1→7.8.54.1.3→4.5.05.37.0→5.49.05.38.1→5.49.010.0.4→10.2.10.2.8→0.2.95.104.1→5.109.25.104.1→5.109.217.7.2→17.7.317.7.2→17.7.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
babel/babel (@babel/core)
v7.29.7Compare Source
v7.29.7 (2026-05-25)
Re-release all packages with npm provenance attestations
changesets/changesets (@changesets/changelog-github)
v0.7.0Compare Source
Minor Changes
94578cfThanks @Kauhsa! - AddeddisableThanksoptionv0.6.0Compare Source
Minor Changes
fd0bc2eThanks @mixelburg! - Linkify issue references in changelog entries.Patch Changes
#1810
27fd8f4Thanks @hirasso! - Replace deprecatedString.prototype.trimRightwithString.prototype.trimEndUpdated dependencies [
d4b8ad8,e462d89]:v0.5.2Compare Source
v0.5.1Compare Source
Patch Changes
84a4a1b]:grpc/grpc-node (@grpc/grpc-js)
v1.14.4: @grpc/grpc-js 1.14.4Compare Source
v1.14.3: @grpc/grpc-js 1.14.3Compare Source
v1.14.2: @grpc/grpc-js 1.14.2Compare Source
v1.14.1: @grpc/grpc-js 1.14.1Compare Source
v1.14.0: @grpc/grpc-js 1.14.0Compare Source
Changelog
getAuthContextmethod to client and server call classes (more details can be found in gRFC L35) (#2920)getConnectionInfomethod to theServerInterceptingCallclass (#2922)weighted_round_robinload balancing policy (#2998)round_robinLB policy (#2979)Experimental API Changes
Added:
CHANNEL_ARGS_CONFIG_SELECTOR_KEYStatusOr<T>CallStreamstatusOrFromValuestatusOrFromErrorModified:
ResolverListener#onSuccessfulResolutionnow has the signature(endpointList: StatusOr<Endpoint[]>, attributes: { [key: string]: unknown }, serviceConfig: StatusOr<ServiceConfig> | null, resolutionNote: string): booleanLoadBalancer#updateAddressListnow has the signature `updateAddressList(endpointList: StatusOr<Endpoint[]>,lbConfig: TypedLoadBalancingConfig, channelOptions: ChannelOptions, resolutionNote: string): booleanv1.13.5: @grpc/grpc-js 1.13.5Compare Source
v1.13.4: @grpc/grpc-js 1.13.4Compare Source
ssl_target_name_overrideoption (#2956)v1.13.3: @grpc/grpc-js 1.13.3Compare Source
http2.getDefaultSettings(#2937)v1.13.2: @grpc/grpc-js 1.13.2Compare Source
v1.13.1: @grpc/grpc-js 1.13.1Compare Source
rejectUnauthorizedchannel credentials option to be handled incorrectly (#2926)retryThrottlingconfig was set (#2927)v1.13.0: @grpc/grpc-js 1.13.0Compare Source
Changelog
grpc-node.flow_control_windowto control HTTP/2 flow control window size (#2864 contributed by @rickihastings)no_proxyenvironment variable (#2876 contributed by @melkouri)sendMetadatamethods to not be called if the server interceptor did not explicitly send metadata (#2897)Experimental API changes
Added:
SecureConnectorSecureConnectResultSUBCHANNEL_ARGS_EXCLUDE_KEY_PREFIXServer#experimentalRegisterListenerToChannelzprotected methodServerexperimentalUnregisterListenerFromChannelzprotected methodServer#experimentalCreateConnectionInjectorWithChannelzRefprotected methodModified:
LoadBalancer: Removed theChannelCredentialsconstructor argumentLoadBalancer: Removed theChannelOptionsconstructor argumentLoadBalancer#updateAddressList: Replaced theattributesargument with one of typeChannelOptions.ChannelControlHelper#createSubchannel: Removed theChannelCredentialsargumentLeafLoadBalancer: Removed theChannelCredentialsconstructor argumentv1.12.7: @grpc/grpc-js 1.12.7Compare Source
v1.12.6Compare Source
v1.12.5: @grpc/grpc-js 1.12.5Compare Source
v1.12.4: @grpc/grpc-js 1.12.4Compare Source
v1.12.3: @grpc/grpc-js 1.12.3Compare Source
v1.12.2: @grpc/grpc-js 1.12.2Compare Source
util.promisifyinstead offs/promisesfor Node 12 compatibility (#2838)v1.12.1: @grpc/grpc-js 1.12.1Compare Source
v1.12.0: @grpc/grpc-js 1.12.0Compare Source
Changelog
rejectUnauthorizedfield to theVerifyOptionsinterface, which can be passed as an argument tocredentials.createSslandcreateFromSecureContext(#2812 contributed by @vinothsa4891)Experimental API changes
Added:
CaCertificateUpdateCaCertificateUpdateListenerIdentityCertificateUpdateIdentityCertificateUpdateListenerCertificateProviderFileWatcherCertificateProviderFileWatcherCertificateProviderConfigcreateCertificateProviderChannelCredentialscreateCertificateProviderServerCredentialsModified:
LoadBalancer: The constructor now takes an additional argument of typeChannelCredentials.ChannelControlHelper#createSubchannel: Now takes an additional argument of typeChannelCredentials | null. This should be passed along if overriding this function.LeafLoadBalancer: The constructor now takes an additional argument of typeChannelCredentials.v1.11.4: @grpc/grpc-js 1.11.4Compare Source
v1.11.3: @grpc/grpc-js 1.11.3Compare Source
v1.11.2: @grpc/grpc-js 1.11.2Compare Source
v1.11.1: @grpc/grpc-js 1.11.1Compare Source
v1.11.0: @grpc/grpc-js 1.11.0Compare Source
Changelog
getHostmethod to server call objects (#2783, #2793)Experimental API changes
Added:
splitHostPortHostPortcreateServerCredentialsWithInterceptorsv1.10.12: @grpc/grpc-js 1.10.12Compare Source
v1.10.11: @grpc/grpc-js 1.10.11Compare Source
v1.10.10: @grpc/grpc-js 1.10.10Compare Source
grpc.max_send_message_lengthchannel option (#2779)v1.10.9: @grpc/grpc-js 1.10.9Compare Source
grpc.max_receive_message_sizeper received message.v1.10.8: @grpc/grpc-js 1.10.8Compare Source
unix:targets to not reconnect after the channel goes idle (#2750)v1.10.7: @grpc/grpc-js 1.10.7Compare Source
@grpc/proto-loaderto the latest version (#2732)v1.10.6: @grpc/grpc-js 1.10.6Compare Source
v1.10.5: @grpc/grpc-js 1.10.5Compare Source
Error.stackTraceLimitisundefined(#2701 contributed by @davidfiala)checkServerIdentitywhengrpc.ssl_target_name_overrideis set (#2704)v1.10.4: @grpc/grpc-js 1.10.4Compare Source
ResponderBuilderandListenerBuilderobjects (#2696)v1.10.3: @grpc/grpc-js 1.10.3Compare Source
v1.10.2: @grpc/grpc-js 1.10.2Compare Source
v1.10.1: @grpc/grpc-js 1.10.1Compare Source
round_robinLB policy to fail to reconnect after a connection drops (#2667)v1.10.0: @grpc/grpc-js 1.10.0Compare Source
Changelog
Server#start(#2597) (details in gRFC L107)Server#unbind(#2612) (details in gRFC L109)Server#drain(#2616) (details in gRFC L111)VerifyOptions(#2637 contributed by @chakhsu)Experimental API Changes
EndpointendpointToStringendpointHasAddressLeafLoadBalancerHealthListenerSubchannelInterface#isHealthySubchannelInterface#addHealthStateWatcherSubchannelInterface#removeHealthStateWatcherSubchannelWrapper#setHealthyselectLbConfigFromListparseLoadBalancingConfigOutlierDetectionRawConfigEndpointMapexperimentalnamespace:ServiceConfigMethodConfigLoadBalancingConfig(now a simple raw object type)RetryPolicygetFirstUsableConfigvalidateLoadBalancingConfigOutlierDetectionLoadBalancingConfigLoadBalancer#updateAddressList: The first argument now has typeEndpoint[]instead ofSubchannelAddress[]ResolverListener#onSuccessfulResolution: The first argument now has typeEndpoint[]instead ofSubchannelAddress[]registerLoadBalancerType: The second argument, aLoadBalancerConstructornow takes a second argumentoptions: ChannelOptionsConfigSelector: Now accepts an additional argumentchannelId: numberQueuePicker: The constructor now accepts an additional optional argumentchildPicker: Picker, which theQueuePickerinstance will delegate to if provided.rollup/plugins (@rollup/plugin-node-resolve)
v16.0.32025-10-13
Bugfixes
v16.0.22025-10-04
Bugfixes
v16.0.12025-03-11
Bugfixes
ignoreSideEffectsForRootto exported interface (#1841)rollup/plugins (@rollup/plugin-replace)
v6.0.32025-10-29
Bugfixes
microsoft/rushstack (@rushstack/node-core-library)
v5.23.3Compare Source
Fri, 17 Jul 2026 00:15:59 GMT
Patches
@overridewith theoverridekeyword.v5.23.2Compare Source
Thu, 16 Jul 2026 00:16:13 GMT
Patches
ajvdependency to~8.20.0to resolve vulnerable transitivefast-uriversions.[
v5.23.1](https://redirect.githConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.