chore(deps): rolling dependency update - #217
socket-pr-bot[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit b7bbe98. Configure here.
| pnpm: | ||
| specifier: ^11.25.0 || >=12.3.4 | ||
| version: 12.4.2 | ||
| version: 12.4.1 |
There was a problem hiding this comment.
Lockfile downgrades pnpm package manager
Medium Severity
packageManagerDependencies re-resolves pnpm from 12.4.2 to 12.4.1. That drops the 12.4.2 POSIX bin-shim takeover fix and moves backward under resolutionMode: highest and trustPolicy: no-downgrade. The weekly-update table does not list this change, and both releases are still inside the 7-day soak, so this is not a soak promotion.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit b7bbe98. Configure here.
1b1d295 to
76ffbf8
Compare
76ffbf8 to
e66e5c9
Compare


Rolling dependency update
One long-lived PR, rebuilt from
mainon every run so it staysmergeable. Each run appends its dependency delta below, newest first.
2026-09-23 — run · 12 updated
@anthropic-ai/claude-code@types/node@vitest/coverage-v8@vitest/uifast-checkmagic-stringrolldown-plugin-dtstypeboxuntrackedvitevitestyamlcommits
2026-09-22 — run · 10 updated
@anthropic-ai/claude-code@socketregistry/packageurl-js@socketregistry/packageurl-js-stablebrace-expansionmagic-stringrolldown-plugin-dtstypeboxuntrackedviteyamlcommits
2026-09-21 — run · 11 updated
@anthropic-ai/claude-code@mdn/browser-compat-datacompromiseecc-agentshieldfast-checkmagic-stringnpm-run-all2rolldown-plugin-dtsuntrackedviteyamlcommits
2026-09-20 — run · 11 updated
@anthropic-ai/claude-code@mdn/browser-compat-datacompromiseecc-agentshieldfast-checkmagic-stringnpm-run-all2rolldown-plugin-dtsuntrackedviteyamlcommits
2026-09-19 — run · 11 updated
@anthropic-ai/claude-code@mdn/browser-compat-datacompromiseecc-agentshieldfast-checkmagic-stringnpm-run-all2rolldown-plugin-dtsuntrackedviteyamlcommits
2026-09-18 — run · 10 updated
@anthropic-ai/claude-code@mdn/browser-compat-datacompromiseecc-agentshieldfast-checkmagic-stringnpm-run-all2rolldown-plugin-dtsuntrackedvitecommits
Note
Medium Risk
Updates verified external binaries (SFW) and a wide dev/CI dependency surface including Vite and security-pinned transitives; typical for a fleet rolling update but worth validating install and CI.
Overview
This rolling dependency refresh bumps the pnpm catalog, overrides, and lockfile together with a small Node pin and external binary updates.
Toolchain & binaries:
.node-versionmoves to 26.8.2. Inexternal-tools.json, Socket Firewall (sfw-free/sfw-enterprise) is updated to 1.15.2 with new per-platformsha512integrity values and a datedsoakBypass(published 2026-09-15, removable 2026-09-22). zizmor goes 1.30.0 → 1.30.1 with refreshed hashes. Several tool descriptions switch to normalized em dashes (encoding-only).npm/pnpm deps:
pnpm-workspace.yamlcatalog bumps includevite8.3.0,@anthropic-ai/claude-code,ecc-agentshield1.6.0,magic-string,compromise,fast-check,untracked,npm-run-all2,rolldown-plugin-dts, and@mdn/browser-compat-data, with matching override pins (e.g.hono,qs,sharp,ip-address).pnpm-lock.yamlreflects the resolved tree (including the catalog-driven transitive updates).Reviewed by Cursor Bugbot for commit b7bbe98. Configure here.