Skip to content

chore(deps): rolling dependency update - #217

Open
socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update
Open

socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update

Conversation

@socket-pr-bot

@socket-pr-bot socket-pr-bot Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Rolling dependency update

One long-lived PR, rebuilt from main on every run so it stays
mergeable. Each run appends its dependency delta below, newest first.

2026-09-23 — run · 12 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.273
@types/node 26.5.1 26.6.1
@vitest/coverage-v8 5.0.0 5.0.1
@vitest/ui 5.0.0 5.0.1
fast-check 4.10.0 4.10.1
magic-string 1.3.1 1.4.1
rolldown-plugin-dts 0.28.4 0.28.6
typebox 1.3.30 1.3.32
untracked 1.6.5 1.6.7
vite 8.2.2 8.3.0
vitest 5.0.0 5.0.1
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-22 — run · 10 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.272
@socketregistry/packageurl-js 1.5.2 1.5.3
@socketregistry/packageurl-js-stable npm:@socketregistry/packageurl-js@1.5.2 npm:@socketregistry/packageurl-js@1.5.3
brace-expansion 5.0.9 5.0.12
magic-string 1.3.1 1.4.1
rolldown-plugin-dts 0.28.4 0.28.5
typebox 1.3.30 1.3.31
untracked 1.6.5 1.6.7
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-21 — run · 11 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.270
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
ecc-agentshield 1.4.0 1.6.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
npm-run-all2 9.0.2 9.0.3
rolldown-plugin-dts 0.28.4 0.28.5
untracked 1.6.5 1.6.7
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-20 — run · 11 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.270
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
ecc-agentshield 1.4.0 1.6.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
npm-run-all2 9.0.2 9.0.3
rolldown-plugin-dts 0.28.4 0.28.5
untracked 1.6.5 1.6.7
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-19 — run · 11 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.269
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
ecc-agentshield 1.4.0 1.6.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
npm-run-all2 9.0.2 9.0.3
rolldown-plugin-dts 0.28.4 0.28.5
untracked 1.6.5 1.6.7
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-18 — run · 10 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.268
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
ecc-agentshield 1.4.0 1.6.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
npm-run-all2 9.0.2 9.0.3
rolldown-plugin-dts 0.28.4 0.28.5
untracked 1.6.5 1.6.7
vite 8.2.2 8.3.0
commits
  • chore(deps): apply weekly update fixes

Note

Medium Risk
Updates verified external binaries (SFW) and a wide dev/CI dependency surface including Vite and security-pinned transitives; typical for a fleet rolling update but worth validating install and CI.

Overview
This rolling dependency refresh bumps the pnpm catalog, overrides, and lockfile together with a small Node pin and external binary updates.

Toolchain & binaries: .node-version moves to 26.8.2. In external-tools.json, Socket Firewall (sfw-free / sfw-enterprise) is updated to 1.15.2 with new per-platform sha512 integrity values and a dated soakBypass (published 2026-09-15, removable 2026-09-22). zizmor goes 1.30.0 → 1.30.1 with refreshed hashes. Several tool descriptions switch to normalized em dashes (encoding-only).

npm/pnpm deps: pnpm-workspace.yaml catalog bumps include vite 8.3.0, @anthropic-ai/claude-code, ecc-agentshield 1.6.0, magic-string, compromise, fast-check, untracked, npm-run-all2, rolldown-plugin-dts, and @mdn/browser-compat-data, with matching override pins (e.g. hono, qs, sharp, ip-address). pnpm-lock.yaml reflects the resolved tree (including the catalog-driven transitive updates).

Reviewed by Cursor Bugbot for commit b7bbe98. Configure here.

@socket-pr-bot socket-pr-bot Bot added dependencies Pull requests that update a dependency file automation labels Sep 18, 2026
@socket-security

socket-security Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

@socket-security-staging

socket-security-staging Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​vitest/​ui@​5.0.0 ⏵ 5.0.1991007598 -1100
Updateduntracked@​1.6.5 ⏵ 1.6.776 -210010089 -5100
Updated@​vitest/​coverage-v8@​5.0.0 ⏵ 5.0.1991007998 -1100
Updatedvitest@​5.0.0 ⏵ 5.0.198 +110079 +199100
Added@​types/​node@​26.6.11001008196100
Updatedyaml@​2.9.0 ⏵ 2.9.1100 +110010092 +6100
Updatedfast-check@​4.10.0 ⏵ 4.10.1100100100 +192 +2100
Updatedmagic-string@​1.2.3 ⏵ 1.4.1100100100 +196100
Updatedtypebox@​1.3.30 ⏵ 1.3.3210010099 +196100

View full report

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit b7bbe98. Configure here.

Comment thread pnpm-lock.yaml Outdated
pnpm:
specifier: ^11.25.0 || >=12.3.4
version: 12.4.2
version: 12.4.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile downgrades pnpm package manager

Medium Severity

packageManagerDependencies re-resolves pnpm from 12.4.2 to 12.4.1. That drops the 12.4.2 POSIX bin-shim takeover fix and moves backward under resolutionMode: highest and trustPolicy: no-downgrade. The weekly-update table does not list this change, and both releases are still inside the 7-day soak, so this is not a soak promotion.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit b7bbe98. Configure here.

@socket-pr-bot
socket-pr-bot Bot force-pushed the weekly-update branch 4 times, most recently from 1b1d295 to 76ffbf8 Compare September 22, 2026 08:22

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants