Skip to content

chore(deps): lock file maintenance#1177

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance
Open

chore(deps): lock file maintenance#1177
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented Jan 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • On day 1 of the month, every 12 months (* * 1 */12 *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here

@renovate
renovate Bot requested a review from a team January 1, 2026 07:39
@vercel

vercel Bot commented Jan 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
tsdocs-client Ignored Ignored Jul 24, 2026 5:10pm

Request Review

@socket-security

socket-security Bot commented Jan 1, 2026

Copy link
Copy Markdown

@socket-security

socket-security Bot commented Jan 1, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @mswjs/interceptors is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/[email protected]npm/@mswjs/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@mswjs/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/[email protected]npm/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Install-time scripts: npm msw during postinstall

Install script: postinstall

Source: node -e "import('./config/scripts/postinstall.js').catch(() => void 0)"

From: package-lock.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

github-actions Bot commented Jan 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 88.74% 4069 / 4585
🔵 Statements 88.74% 4069 / 4585
🔵 Functions 86.29% 321 / 372
🔵 Branches 90.55% 1227 / 1355
File CoverageNo changed files found.
Generated in workflow #4526 for commit 38d9660 by the Vitest Coverage Report Action

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from cb7f99f to 786a610 Compare January 8, 2026 21:09
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from b1c75cc to 8872002 Compare January 23, 2026 16:27
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 8872002 to 220ec4c Compare February 2, 2026 18:40
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 27608d6 to ec43f62 Compare February 17, 2026 20:28
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 93dd442 to 8daf3c4 Compare March 5, 2026 18:57
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 8daf3c4 to 8421440 Compare March 13, 2026 17:14
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 8421440 to a14a99c Compare April 1, 2026 16:11
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from e7bf1fe to b8d7475 Compare April 10, 2026 12:32
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from b8d7475 to c11765b Compare April 29, 2026 19:46
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from a6abe02 to 2bdce51 Compare May 18, 2026 16:34
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 60415c5 to 0d22d28 Compare June 2, 2026 01:50
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 5d5edc1 to 699d26d Compare June 11, 2026 12:46
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 721afce to afc26f5 Compare July 16, 2026 21:41
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from afc26f5 to 4f8fbf0 Compare July 21, 2026 03:42
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 4f8fbf0 to 38d9660 Compare July 24, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants