Skip to content

chore(deps): rolling dependency update - #16

Open
socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update
Open

socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update

Conversation

@socket-pr-bot

@socket-pr-bot socket-pr-bot Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Rolling dependency update

One long-lived PR, rebuilt from main on every run so it stays
mergeable. Each run appends its dependency delta below, newest first.

2026-09-21 — run · 5 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-20 — run · 5 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-19 — run · 5 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-18 — run · 4 updated
package from to
@mdn/browser-compat-data 8.1.0 8.1.1
compromise 14.16.0 14.17.0
fast-check 4.9.0 4.10.0
magic-string 1.2.3 1.3.1
commits
  • chore(deps): apply weekly update fixes

Note

Low Risk
Routine version bumps to dev/tooling and test dependencies with no application logic changes; minor HTTP client patch via undici.

Overview
This rolling dependency update bumps the fleet Node pin in .node-version from 26.8.1 to 26.8.2 and refreshes pnpm-lock.yaml from the catalog changes in pnpm-workspace.yaml.

Catalog pins move @mdn/browser-compat-data (8.1.0 → 8.1.1), compromise (14.16.0 → 14.17.0, including the judgment-nudge hook), fast-check (4.9.0 → 4.10.0), and magic-string (1.2.3 → 1.3.1, with @jridgewell/sourcemap-codec following for Vitest/mocker). The fleet undici override is also bumped 6.28.0 → 6.28.1 for @actions/* HTTP clients. The lockfile reflects a pnpm package-manager entry at 12.4.1 (down from 12.4.2) alongside these resolutions.

Reviewed by Cursor Bugbot for commit 8d2e0e4. Configure here.

@socket-pr-bot socket-pr-bot Bot added dependencies Pull requests that update a dependency file automation Automated maintenance labels Sep 18, 2026
@socket-security

socket-security Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedyaml@​2.9.0 ⏵ 2.9.1100 +110010090100
Updatedfast-check@​4.9.0 ⏵ 4.10.0100 +1100100 +190 -2100
Updatedcompromise@​14.16.0 ⏵ 14.17.09810010092 +1100
Updatedmagic-string@​1.2.3 ⏵ 1.3.1100100100 +197 +1100
Updated@​mdn/​browser-compat-data@​8.1.0 ⏵ 8.1.110010010098100

View full report

@socket-security-staging

socket-security-staging Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcompromise@​14.16.0 ⏵ 14.17.09810010090 -1100
Updatedfast-check@​4.9.0 ⏵ 4.10.0100 +110010090100
Updatedyaml@​2.9.0 ⏵ 2.9.1100 +110010092 +6100
Updatedmagic-string@​1.2.3 ⏵ 1.3.1100100100 +197 +1100
Updated@​mdn/​browser-compat-data@​8.1.0 ⏵ 8.1.110010010098100

View full report

@socket-pr-bot
socket-pr-bot Bot force-pushed the weekly-update branch 3 times, most recently from 98ad35e to 159071f Compare September 21, 2026 08:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation Automated maintenance dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants