Skip to content

chore(deps): bump the npm-production group across 1 directory with 14 updates - #179

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-production-6f90b7f821
Open

chore(deps): bump the npm-production group across 1 directory with 14 updates#179
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-production-6f90b7f821

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026

Copy link
Copy Markdown

Updates the requirements on @eslint/js, @secretlint/secretlint-rule-preset-recommend, @types/node, isolated-vm, secretlint, semver, @types/semver, typescript-language-server, yaml, zod-to-json-schema, strip-ansi, rimraf, ajv and ts-jest to permit the latest version.
Updates @eslint/js from 9.39.2 to 9.39.5

Release notes

Sourced from @​eslint/js's releases.

v9.39.5

Bug Fixes

Documentation

  • 74930ed docs: switch build to Node.js 24 (#20894) (Milos Djermanovic)
  • eaec8bb docs: Add ESLint v9.x EOL notice (#20828) (Milos Djermanovic)

Chores

  • 458205f chore: update @eslint/eslintrc and @eslint/js for v9.39.5 (#21077) (Francesco Trotta)
  • 202117b chore: package.json update for @​eslint/js release (Jenkins)
  • d9eb6ed test: disable warning for vm.constants.USE_MAIN_CONTEXT_DEFAULT_LOADER (#21074) (Francesco Trotta)
  • 7b431a7 chore: override re2 dependency for @metascraper/helpers (#21068) (Milos Djermanovic)
  • daf7791 chore: pin fflate@0.8.2 (#20895) (Milos Djermanovic)
  • daee8ba ci: use pnpm in eslint-flat-config-utils type integration test (#20829) (Milos Djermanovic)
  • 116d4be ci: unpin Node.js 25.x in CI (#20619) (Copilot)

v9.39.4

Bug Fixes

  • f18f6c8 fix: update dependency minimatch to ^3.1.5 (#20564) (Milos Djermanovic)
  • a3c868f fix: update dependency @​eslint/eslintrc to ^3.3.4 (#20554) (Milos Djermanovic)
  • 234d005 fix: minimatch security vulnerability patch for v9.x (#20549) (Andrej Beles)
  • b1b37ee fix: update ajv to 6.14.0 to address security vulnerabilities (#20538) (루밀LuMir)

Documentation

  • 4675152 docs: add deprecation notice partial (#20520) (Milos Djermanovic)

Chores

  • b8b4eb1 chore: update dependencies for ESLint v9.39.4 (#20596) (Francesco Trotta)
  • 71b2f6b chore: package.json update for @​eslint/js release (Jenkins)
  • 1d16c2f ci: pin Node.js 25.6.1 (#20563) (Milos Djermanovic)

v9.39.3

Bug Fixes

  • 791bf8d fix: restore TypeScript 4.0 compatibility in types (#20504) (sethamus)

Chores

  • 8594a43 chore: upgrade @​eslint/js@​9.39.3 (#20529) (Milos Djermanovic)
  • 9ceef92 chore: package.json update for @​eslint/js release (Jenkins)
  • af498c6 chore: ignore /docs/v9.x in link checker (#20453) (Milos Djermanovic)
Commits
  • 202117b chore: package.json update for @​eslint/js release
  • 71b2f6b chore: package.json update for @​eslint/js release
  • 9ceef92 chore: package.json update for @​eslint/js release
  • See full diff in compare view

Updates @secretlint/secretlint-rule-preset-recommend from 11.2.5 to 11.7.1

Release notes

Sourced from @​secretlint/secretlint-rule-preset-recommend's releases.

v11.7.1

What's Changed

Service Package PR
Notion @secretlint/secretlint-rule-notion #1471
Figma @secretlint/secretlint-rule-figma #1472
Hugging Face @secretlint/secretlint-rule-huggingface #1473
Grafana @secretlint/secretlint-rule-grafana #1474
Groq @secretlint/secretlint-rule-groq #1475
GitLab @secretlint/secretlint-rule-gitlab #1476
HashiCorp Vault @secretlint/secretlint-rule-hashicorp-vault #1477
Databricks @secretlint/secretlint-rule-databricks #1478
Docker @secretlint/secretlint-rule-docker #1481

Features

Bug Fixes

Documentation

CI

Dependency Updates

Other Changes

Full Changelog: secretlint/secretlint@v11.6.0...v11.7.1

v11.6.0

... (truncated)

Commits
  • bad9176 v11.7.1 (#1487)
  • 2ddd70e Remove npm upgrade step from release workflow (#1486)
  • cd79345 v11.7.0 (#1484)
  • 4e607ba ci: add npm environment to release workflow (#1483)
  • d4cb771 fix(rules): add regex boundary assertions to 8 existing scanner rules (#1482)
  • ab0869f Add Docker Personal Access Token detection rule (#1481)
  • 222fd0a chore(deps): update textlint to ^15.5.4 (patch) (#1480)
  • 020c903 feat(secretlint-rule-gitlab): add rule for GitLab Personal Access Tokens (#1476)
  • 2fc5b28 feat(rule): add @​secretlint/secretlint-rule-hashicorp-vault (#1477)
  • ad8f273 feat(grafana): add new rule for Grafana API tokens (#1474)
  • Additional commits viewable in compare view

Updates @types/node from 20.19.26 to 20.19.43

Commits

Updates isolated-vm from 6.0.2 to 6.2.0

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for isolated-vm since your current version.

Install script changes

This version modifies install script that runs during installation. Review the package contents before updating.


Updates secretlint from 11.2.5 to 11.7.1

Release notes

Sourced from secretlint's releases.

v11.7.1

What's Changed

Service Package PR
Notion @secretlint/secretlint-rule-notion #1471
Figma @secretlint/secretlint-rule-figma #1472
Hugging Face @secretlint/secretlint-rule-huggingface #1473
Grafana @secretlint/secretlint-rule-grafana #1474
Groq @secretlint/secretlint-rule-groq #1475
GitLab @secretlint/secretlint-rule-gitlab #1476
HashiCorp Vault @secretlint/secretlint-rule-hashicorp-vault #1477
Databricks @secretlint/secretlint-rule-databricks #1478
Docker @secretlint/secretlint-rule-docker #1481

Features

Bug Fixes

Documentation

CI

Dependency Updates

Other Changes

Full Changelog: secretlint/secretlint@v11.6.0...v11.7.1

v11.6.0

... (truncated)

Commits
  • bad9176 v11.7.1 (#1487)
  • 2ddd70e Remove npm upgrade step from release workflow (#1486)
  • cd79345 v11.7.0 (#1484)
  • 4e607ba ci: add npm environment to release workflow (#1483)
  • d4cb771 fix(rules): add regex boundary assertions to 8 existing scanner rules (#1482)
  • ab0869f Add Docker Personal Access Token detection rule (#1481)
  • 222fd0a chore(deps): update textlint to ^15.5.4 (patch) (#1480)
  • 020c903 feat(secretlint-rule-gitlab): add rule for GitLab Personal Access Tokens (#1476)
  • 2fc5b28 feat(rule): add @​secretlint/secretlint-rule-hashicorp-vault (#1477)
  • ad8f273 feat(grafana): add new rule for Grafana API tokens (#1474)
  • Additional commits viewable in compare view

Updates semver from 7.7.3 to 7.8.5

Release notes

Sourced from semver's releases.

v7.8.5

7.8.5 (2026-06-19)

Bug Fixes

v7.8.4

7.8.4 (2026-06-09)

Bug Fixes

v7.8.3

7.8.3 (2026-06-08)

Bug Fixes

Chores

v7.8.2

7.8.2 (2026-06-04)

Bug Fixes

v7.8.1

7.8.1 (2026-05-21)

Bug Fixes

v7.8.0

7.8.0 (2026-05-08)

Features

Bug Fixes

Documentation

Chores

v7.7.4

7.7.4 (2026-01-16)

Bug Fixes

Documentation

Dependencies

... (truncated)

Changelog

Sourced from semver's changelog.

7.8.5 (2026-06-19)

Bug Fixes

7.8.4 (2026-06-09)

Bug Fixes

7.8.3 (2026-06-08)

Bug Fixes

Chores

7.8.2 (2026-06-04)

Bug Fixes

7.8.1 (2026-05-21)

Bug Fixes

7.8.0 (2026-05-08)

Features

Bug Fixes

Documentation

Chores

7.7.4 (2026-01-16)

Bug Fixes

Documentation

Dependencies

Chores

Commits

Updates @types/semver from 7.7.1 to 7.8.0

Commits

Updates typescript-language-server from 5.1.3 to 5.3.0

Release notes

Sourced from typescript-language-server's releases.

v5.3.0

5.3.0 (2026-05-21)

Features

  • hover info verbosity (#1092) (b73207c)
  • refresh inlay hints and code lens on relevant configuration change (#1095) (fd53d0e)

v5.2.0

5.2.0 (2026-05-10)

Features

Refactors

  • pass ITypeScriptServiceClient around instead of TsClient (e91bd52)
Changelog

Sourced from typescript-language-server's changelog.

5.3.0 (2026-05-21)

Features

  • hover info verbosity (#1092) (b73207c)
  • refresh inlay hints and code lens on relevant configuration change (#1095) (fd53d0e)

5.2.0 (2026-05-10)

Features

Refactors

  • pass ITypeScriptServiceClient around instead of TsClient (e91bd52)
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for typescript-language-server since your current version.


Updates yaml from 2.8.3 to 2.9.0

Release notes

Sourced from yaml's releases.

v2.9.0

The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".

It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.

Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.

  • fix: Avoid calling Array.prototype.push.apply() with large source array
  • fix(lexer): Avoid recursive calls that may exhaust the call stack

v2.8.4

  • Disable alias resolution with maxAliasCount:0 (#677)
  • Handle invalid unicode escapes (e1a1a77)
  • Apply minFractionDigits only to decimal strings (#676)
Commits
  • ddb21b0 2.9.0
  • 167365b docs: Clarify that not all errors can be avoided
  • 6eca2a7 fix: Avoid calling Array.prototype.push.apply() with large source array
  • 0543cd5 fix(lexer): Avoid recursive calls that may exhaust the call stack
  • ccdf743 2.8.4
  • f625789 fix: Disable alias resolution with maxAliasCount:0 (#677)
  • e1a1a77 fix: Handle invalid unicode escapes
  • a163ea0 style: Satify Prettier
  • b2a5a6c fix: Apply minFractionDigits only to decimal strings (#676)
  • 93c951b chore: Bump JSR version to v2.8.3 (#673)
  • Additional commits viewable in compare view

Updates zod-to-json-schema from 3.25.0 to 3.25.2

Changelog

Sourced from zod-to-json-schema's changelog.

Changelog

Version Change
3.25.2 Bumps the peer dependency of Zod 3 to 3.25.28 - Versions before patch 13 caused OOM issues and versions between that and 28 removed the /v3 import alias.
3.25.1 Fixes large install size due to accidental inclusion of test files. Thanks, Felix Mosheev!
3.25.0 Adds support for v3.25 and v3 through v4 (import { z } from "zod/v3"). Big thank you to both Andrey Gubanovs and especially to Faïz Hernawan Abdillah, whose more minimal implementation was merged. This will likely be the final release of zod-to-json-schema, as v4 now supports JSON schema natively.
3.24.6 Removed use of instanceOf to check for optional properties as differing package versions could p...

Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 19, 2026
… updates

Updates the requirements on [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js), [@secretlint/secretlint-rule-preset-recommend](https://github.com/secretlint/secretlint), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [isolated-vm](https://github.com/laverdet/isolated-vm), [secretlint](https://github.com/secretlint/secretlint), [semver](https://github.com/npm/node-semver), [@types/semver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/semver), [typescript-language-server](https://github.com/typescript-language-server/typescript-language-server), [yaml](https://github.com/eemeli/yaml), [zod-to-json-schema](https://github.com/StefanTerdell/zod-to-json-schema), [strip-ansi](https://github.com/chalk/strip-ansi), [rimraf](https://github.com/isaacs/rimraf), [ajv](https://github.com/ajv-validator/ajv) and [ts-jest](https://github.com/kulshekhar/ts-jest) to permit the latest version.

Updates `@eslint/js` from 9.39.2 to 9.39.5
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/commits/v9.39.5/packages/js)

Updates `@secretlint/secretlint-rule-preset-recommend` from 11.2.5 to 11.7.1
- [Release notes](https://github.com/secretlint/secretlint/releases)
- [Commits](secretlint/secretlint@v11.2.5...v11.7.1)

Updates `@types/node` from 20.19.26 to 20.19.43
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `isolated-vm` from 6.0.2 to 6.2.0
- [Release notes](https://github.com/laverdet/isolated-vm/releases)
- [Changelog](https://github.com/laverdet/isolated-vm/blob/main/CHANGELOG.md)
- [Commits](laverdet/isolated-vm@v6.0.2...v6.2.0)

Updates `secretlint` from 11.2.5 to 11.7.1
- [Release notes](https://github.com/secretlint/secretlint/releases)
- [Commits](secretlint/secretlint@v11.2.5...v11.7.1)

Updates `semver` from 7.7.3 to 7.8.5
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)
- [Commits](npm/node-semver@v7.7.3...v7.8.5)

Updates `@types/semver` from 7.7.1 to 7.8.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/semver)

Updates `typescript-language-server` from 5.1.3 to 5.3.0
- [Release notes](https://github.com/typescript-language-server/typescript-language-server/releases)
- [Changelog](https://github.com/typescript-language-server/typescript-language-server/blob/master/CHANGELOG.md)
- [Commits](typescript-language-server/typescript-language-server@v5.1.3...v5.3.0)

Updates `yaml` from 2.8.3 to 2.9.0
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.3...v2.9.0)

Updates `zod-to-json-schema` from 3.25.0 to 3.25.2
- [Release notes](https://github.com/StefanTerdell/zod-to-json-schema/releases)
- [Changelog](https://github.com/StefanTerdell/zod-to-json-schema/blob/master/changelog.md)
- [Commits](https://github.com/StefanTerdell/zod-to-json-schema/commits)

Updates `@types/semver` from 7.7.1 to 7.8.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/semver)

Updates `strip-ansi` from 7.1.2 to 7.2.0
- [Release notes](https://github.com/chalk/strip-ansi/releases)
- [Commits](chalk/strip-ansi@v7.1.2...v7.2.0)

Updates `rimraf` from 6.1.2 to 6.1.3
- [Changelog](https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md)
- [Commits](isaacs/rimraf@v6.1.2...v6.1.3)

Updates `ajv` from 8.18.0 to 8.20.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v8.18.0...v8.20.0)

Updates `ts-jest` to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.2.5...v29.4.12)

---
updated-dependencies:
- dependency-name: "@eslint/js"
  dependency-version: 9.39.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@secretlint/secretlint-rule-preset-recommend"
  dependency-version: 11.7.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@types/node"
  dependency-version: 20.19.43
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@types/semver"
  dependency-version: 7.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@types/semver"
  dependency-version: 7.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: ajv
  dependency-version: 8.20.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: isolated-vm
  dependency-version: 6.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: rimraf
  dependency-version: 6.1.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: secretlint
  dependency-version: 11.7.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: semver
  dependency-version: 7.8.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: strip-ansi
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  dependency-group: npm-production
- dependency-name: typescript-language-server
  dependency-version: 5.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: zod-to-json-schema
  dependency-version: 3.25.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-production-6f90b7f821 branch from 081fed3 to 92b425a Compare August 24, 2026 06:24
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants