Skip to content

Bump the production-dependencies group across 1 directory with 4 updates#142

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-ee1b290fdb
Open

Bump the production-dependencies group across 1 directory with 4 updates#142
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-ee1b290fdb

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 5, 2026

Updates the requirements on @napi-rs/keyring, make-fetch-happen, smol-toml and yaml to permit the latest version.
Updates @napi-rs/keyring to 1.3.0

Release notes

Sourced from @​napi-rs/keyring's releases.

v1.3.0

What's Changed

New Contributors

Full Changelog: Brooooooklyn/keyring-node@v1.2.0...v1.3.0

Commits

Updates make-fetch-happen from 15.0.5 to 16.0.0

Release notes

Sourced from make-fetch-happen's releases.

v16.0.0

16.0.0 (2026-05-19)

⚠️ BREAKING CHANGES

  • make-fetch-happen now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • template-oss-apply

Features

Dependencies

Chores

Changelog

Sourced from make-fetch-happen's changelog.

16.0.0 (2026-05-19)

⚠️ BREAKING CHANGES

  • make-fetch-happen now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • template-oss-apply

Features

Dependencies

Chores

Commits

Updates smol-toml to 1.6.1

Release notes

Sourced from smol-toml's releases.

v1.6.1

This release addresses a minor security vulnerability where an attacker-controlled TOML document can exploit an unrestricted recustion and cause a stack overflow error with a document that contains thousands of sucessive commented lines. Security advisory: GHSA-v3rj-xjv7-4jmq

Commits

Updates yaml to 2.9.0

Release notes

Sourced from yaml's releases.

v2.9.0

The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".

It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.

Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.

  • fix: Avoid calling Array.prototype.push.apply() with large source array
  • fix(lexer): Avoid recursive calls that may exhaust the call stack
Commits
  • ddb21b0 2.9.0
  • 167365b docs: Clarify that not all errors can be avoided
  • 6eca2a7 fix: Avoid calling Array.prototype.push.apply() with large source array
  • 0543cd5 fix(lexer): Avoid recursive calls that may exhaust the call stack
  • ccdf743 2.8.4
  • f625789 fix: Disable alias resolution with maxAliasCount:0 (#677)
  • e1a1a77 fix: Handle invalid unicode escapes
  • a163ea0 style: Satify Prettier
  • b2a5a6c fix: Apply minFractionDigits only to decimal strings (#676)
  • 93c951b chore: Bump JSR version to v2.8.3 (#673)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 5, 2026
@snyk-io
Copy link
Copy Markdown

snyk-io Bot commented May 5, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions github-actions Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-ee1b290fdb branch from 7934a95 to 40bc5ef Compare May 5, 2026 20:34
@codacy-production
Copy link
Copy Markdown

codacy-production Bot commented May 5, 2026

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-ee1b290fdb branch from 40bc5ef to 5e095f3 Compare May 20, 2026 03:31
Updates the requirements on [@napi-rs/keyring](https://github.com/Brooooooklyn/keyring-node), [make-fetch-happen](https://github.com/npm/make-fetch-happen), [smol-toml](https://github.com/squirrelchat/smol-toml) and [yaml](https://github.com/eemeli/yaml) to permit the latest version.

Updates `@napi-rs/keyring` to 1.3.0
- [Release notes](https://github.com/Brooooooklyn/keyring-node/releases)
- [Commits](Brooooooklyn/keyring-node@v1.2.0...v1.3.0)

Updates `make-fetch-happen` from 15.0.5 to 16.0.0
- [Release notes](https://github.com/npm/make-fetch-happen/releases)
- [Changelog](https://github.com/npm/make-fetch-happen/blob/main/CHANGELOG.md)
- [Commits](npm/make-fetch-happen@v15.0.5...v16.0.0)

Updates `smol-toml` to 1.6.1
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.6.0...v1.6.1)

Updates `yaml` to 2.9.0
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.2...v2.9.0)

---
updated-dependencies:
- dependency-name: "@napi-rs/keyring"
  dependency-version: 1.3.0
  dependency-type: direct:production
  dependency-group: production-dependencies
- dependency-name: make-fetch-happen
  dependency-version: 15.0.5
  dependency-type: direct:production
  dependency-group: production-dependencies
- dependency-name: smol-toml
  dependency-version: 1.6.1
  dependency-type: direct:production
  dependency-group: production-dependencies
- dependency-name: yaml
  dependency-version: 2.8.4
  dependency-type: direct:production
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@github-actions github-actions Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-ee1b290fdb branch from 5e095f3 to 9bf3183 Compare May 20, 2026 03:31
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedmake-fetch-happen@​16.0.09910010087100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants