Skip to content

build(deps): bump js-cookie from 3.0.5 to 3.0.7#1625

Closed
dependabot[bot] wants to merge 1 commit into
dependency-updatesfrom
dependabot/npm_and_yarn/js-cookie-3.0.7
Closed

build(deps): bump js-cookie from 3.0.5 to 3.0.7#1625
dependabot[bot] wants to merge 1 commit into
dependency-updatesfrom
dependabot/npm_and_yarn/js-cookie-3.0.7

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 21, 2026

Bumps js-cookie from 3.0.5 to 3.0.7.

Release notes

Sourced from js-cookie's releases.

v3.0.7

  • Prevent cookie attribute injection: CVE-2026-46625 (eb3c40e)
  • Add Partitioned attribute to readme (b994768)
  • Publish to npm registry via trusted publisher exclusively (4dc71be)
  • Ensure consistent behaviour for get('name') + get() (1953d30)
Commits
  • 17bacba Craft v3.0.7 release
  • adb823c Fix release workflow halting at git tag
  • 5f9e759 May remove Git user config from release workflow
  • 6ac9211 Fix release workflow not able to push commit + tag
  • 2278bc5 Fix missing package version bump
  • eb3c40e Prevent cookie attribute injection
  • f6f157f Bump globals from 17.5.0 to 17.6.0
  • f409d02 Bump eslint from 10.2.0 to 10.3.0
  • a686883 Bump protobufjs in the npm_and_yarn group across 1 directory
  • c6112d2 Bump @​protobufjs/utf8 in the npm_and_yarn group across 1 directory
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for js-cookie since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 21, 2026
@coveralls
Copy link
Copy Markdown

coveralls commented May 21, 2026

Coverage Status

Coverage is 94.901%dependabot/npm_and_yarn/js-cookie-3.0.7 into dependency-updates. No base build found for dependency-updates.

@MyPyDavid MyPyDavid changed the base branch from main to 2.4.5/dependency-updates May 22, 2026 05:55
@MyPyDavid
Copy link
Copy Markdown
Member

@dependabot recreate

Bumps [js-cookie](https://github.com/js-cookie/js-cookie) from 3.0.5 to 3.0.7.
- [Release notes](https://github.com/js-cookie/js-cookie/releases)
- [Commits](js-cookie/js-cookie@v3.0.5...v3.0.7)

---
updated-dependencies:
- dependency-name: js-cookie
  dependency-version: 3.0.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the base branch from 2.4.5/dependency-updates to main May 22, 2026 12:31
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/js-cookie-3.0.7 branch from 2282f29 to 2f3aa39 Compare May 22, 2026 12:31
@MyPyDavid MyPyDavid changed the base branch from main to dependency-updates May 22, 2026 12:33
@MyPyDavid
Copy link
Copy Markdown
Member

part of #1613

@MyPyDavid MyPyDavid closed this May 22, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 22, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/js-cookie-3.0.7 branch May 22, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants