Skip to content

chore: bump the npm_and_yarn group across 2 directories with 4 updates#250

Open
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/npm_and_yarn/npm_and_yarn-b6e405db17
Open

chore: bump the npm_and_yarn group across 2 directories with 4 updates#250
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/npm_and_yarn/npm_and_yarn-b6e405db17

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 4, 2026

Bumps the npm_and_yarn group with 4 updates in the / directory: minimatch, flatted, undici and rollup.
Bumps the npm_and_yarn group with 1 update in the /workers/tmdb-cron directory: undici.

Updates minimatch from 3.1.2 to 3.1.5

Commits

Updates flatted from 3.3.3 to 3.4.2

Commits
  • 3bf0909 3.4.2
  • 885ddcc fix CWE-1321
  • 0bdba70 added flatted-view to the benchmark
  • 2a02dce 3.4.1
  • fba4e8f Merge pull request #89 from WebReflection/python-fix
  • 5fe8648 added "when in Rome" also a test for PHP
  • 53517ad some minor improvement
  • b3e2a0c Fixing recursion issue in Python too
  • c4b46db Add SECURITY.md for security policy and reporting
  • f86d071 Create dependabot.yml for version updates
  • Additional commits viewable in compare view

Updates undici from 7.22.0 to 7.24.7

Release notes

Sourced from undici's releases.

v7.24.7

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.6...v7.24.7

v7.24.6

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.5...v7.24.6

v7.24.5

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.4...v7.24.5

v7.24.4

What's Changed

... (truncated)

Commits
  • 84f23e2 Bumped v7.24.7 (#4947)
  • a770b10 ignore AGENTS.md (#4942)
  • 6acd19b fix: correctly handle multi-value rawHeaders in fetch (#4938)
  • 1da1c74 test: skip IPv6 tests when IPv6 is not available (#4939)
  • 04cb773 fix(types): Fix clone method type declaration to be an instance method rather...
  • 5145a7c fix(types): align Response with DOM fetch types (#4867)
  • ec23620 test: skip flaky macOS Node 20 cookie fetch cases
  • 5559235 doc: remove unused parameter redirectionLimitReached (#4933)
  • a4e4b84 docs: update broken links in file "Dispatcher.md" (#4924)
  • 38eab36 Bumped v7.24.6 (#4931)
  • Additional commits viewable in compare view

Updates rollup from 4.58.0 to 4.60.1

Release notes

Sourced from rollup's releases.

v4.60.1

4.60.1

2026-03-30

Bug Fixes

  • Resolve a situation where side effect imports could be dropped due to a caching issue (#6286)

Pull Requests

v4.60.0

4.60.0

2026-03-22

Features

  • Support source phase imports as long as they are external (#6279)

Pull Requests

v4.59.1

4.59.1

2026-03-21

Bug Fixes

  • Fix a crash when using lazy dynamic imports with moduleSideEffects:false (#6306)

Pull Requests

... (truncated)

Changelog

Sourced from rollup's changelog.

4.60.1

2026-03-30

Bug Fixes

  • Resolve a situation where side effect imports could be dropped due to a caching issue (#6286)

Pull Requests

4.60.0

2026-03-22

Features

  • Support source phase imports as long as they are external (#6279)

Pull Requests

4.59.1

2026-03-21

Bug Fixes

  • Fix a crash when using lazy dynamic imports with moduleSideEffects:false (#6306)

Pull Requests

... (truncated)

Commits

Updates undici from 7.18.2 to 7.24.4

Release notes

Sourced from undici's releases.

v7.24.7

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.6...v7.24.7

v7.24.6

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.5...v7.24.6

v7.24.5

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.4...v7.24.5

v7.24.4

What's Changed

... (truncated)

Commits
  • 84f23e2 Bumped v7.24.7 (#4947)
  • a770b10 ignore AGENTS.md (#4942)
  • 6acd19b fix: correctly handle multi-value rawHeaders in fetch (#4938)
  • 1da1c74 test: skip IPv6 tests when IPv6 is not available (#4939)
  • 04cb773 fix(types): Fix clone method type declaration to be an instance method rather...
  • 5145a7c fix(types): align Response with DOM fetch types (#4867)
  • ec23620 test: skip flaky macOS Node 20 cookie fetch cases
  • 5559235 doc: remove unused parameter redirectionLimitReached (#4933)
  • a4e4b84 docs: update broken links in file "Dispatcher.md" (#4924)
  • 38eab36 Bumped v7.24.6 (#4931)
  • Additional commits viewable in compare view

Updates undici from 7.18.2 to 7.24.4

Release notes

Sourced from undici's releases.

v7.24.7

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.6...v7.24.7

v7.24.6

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.5...v7.24.6

v7.24.5

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.4...v7.24.5

v7.24.4

What's Changed

... (truncated)

Commits
  • 84f23e2 Bumped v7.24.7 (#4947)
  • a770b10 ignore AGENTS.md (#4942)
  • 6acd19b fix: correctly handle multi-value rawHeaders in fetch (#4938)
  • 1da1c74 test: skip IPv6 tests when IPv6 is not available (#4939)
  • 04cb773 fix(types): Fix clone method type declaration to be an instance method rather...
  • 5145a7c fix(types): align Response with DOM fetch types (#4867)
  • ec23620 test: skip flaky macOS Node 20 cookie fetch cases
  • 5559235 doc: remove unused parameter redirectionLimitReached (#4933)
  • a4e4b84 docs: update broken links in file "Dispatcher.md" (#4924)
  • 38eab36 Bumped v7.24.6 (#4931)
  • Additional commits viewable in compare view

Updates undici from 7.18.2 to 7.24.4

Release notes

Sourced from undici's releases.

v7.24.7

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.6...v7.24.7

v7.24.6

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.5...v7.24.6

v7.24.5

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.4...v7.24.5

v7.24.4

What's Changed

... (truncated)

Commits
  • 84f23e2 Bumped v7.24.7 (#4947)
  • a770b10 ignore AGENTS.md (#4942)
  • 6acd19b fix: correctly handle multi-value rawHeaders in fetch (#4938)
  • 1da1c74 test: skip IPv6 tests when IPv6 is not available (#4939)
  • 04cb773 fix(types): Fix clone method type declaration to be an instance method rather...
  • 5145a7c fix(types): align Response with DOM fetch types (#4867)
  • ec23620 test: skip flaky macOS Node 20 cookie fetch cases
  • 5559235 doc: remove unused parameter redirectionLimitReached (#4933)
  • a4e4b84 docs: update broken links in file "Dispatcher.md" (#4924)
  • 38eab36 Bumped v7.24.6 (#4931)
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 4, 2026
@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages bot commented Apr 4, 2026

Deploying boxdbud with  Cloudflare Pages  Cloudflare Pages

Latest commit: 168c47c
Status: ✅  Deploy successful!
Preview URL: https://54619331.boxdbud.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-npm-s6hp.boxdbud.pages.dev

View logs

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 4, 2026
@Wootehfook
Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps the npm_and_yarn group with 4 updates in the / directory: [minimatch](https://github.com/isaacs/minimatch), [flatted](https://github.com/WebReflection/flatted), [undici](https://github.com/nodejs/undici) and [rollup](https://github.com/rollup/rollup).
Bumps the npm_and_yarn group with 1 update in the /workers/tmdb-cron directory: [undici](https://github.com/nodejs/undici).


Updates `minimatch` from 3.1.2 to 3.1.5
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.1.2...v3.1.5)

Updates `flatted` from 3.3.3 to 3.4.2
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

Updates `undici` from 7.22.0 to 7.24.7
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.22.0...v7.24.7)

Updates `rollup` from 4.58.0 to 4.60.1
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.58.0...v4.60.1)

Updates `undici` from 7.18.2 to 7.24.4
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.22.0...v7.24.7)

Updates `undici` from 7.18.2 to 7.24.4
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.22.0...v7.24.7)

Updates `undici` from 7.18.2 to 7.24.4
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.22.0...v7.24.7)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 3.1.5
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.24.7
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: rollup
  dependency-version: 4.60.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.24.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.24.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.24.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-b6e405db17 branch from eef5fbc to 168c47c Compare April 4, 2026 01:22
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Apr 4, 2026

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates npm dependencies/lockfiles across the root project and the workers/tmdb-cron subproject, primarily to refresh Cloudflare tooling (wrangler) and associated transitive packages used for local dev/build and worker deployment.

Changes:

  • Bump wrangler devDependency to ^4.80.0 in both the root project and workers/tmdb-cron.
  • Refresh lockfiles, updating transitive packages including undici, minimatch, flatted, and rollup (plus Cloudflare-related deps like miniflare/workerd).
  • Align workers/tmdb-cron lockfile with the updated wrangler toolchain.

Reviewed changes

Copilot reviewed 2 out of 4 changed files in this pull request and generated 3 comments.

File Description
package.json Bumps root wrangler devDependency to ^4.80.0.
package-lock.json Updates resolved versions for transitive deps (e.g., undici/minimatch/flatted/rollup) and wrangler toolchain.
workers/tmdb-cron/package.json Bumps worker wrangler devDependency to ^4.80.0.
workers/tmdb-cron/package-lock.json Updates resolved wrangler toolchain and transitive deps for the worker project.
Files not reviewed (1)
  • workers/tmdb-cron/package-lock.json: Language not supported

"vite": "^7.3.1",
"vitest": "^4.0.16",
"wrangler": "^4.63.0"
"wrangler": "^4.80.0"
Copy link

Copilot AI Apr 12, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR description lists bumps for minimatch/flatted/undici/rollup, but this change also bumps the direct devDependency wrangler (root package.json) to ^4.80.0. Please update the PR description to reflect this additional direct dependency update, since it can affect local dev and CI behavior.

Copilot uses AI. Check for mistakes.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot apply changes based on this feedback

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the PR description to reflect both wrangler bumps:

  • Root: ^4.63.0^4.80.0
  • workers/tmdb-cron: ^4.0.0^4.80.0

Comment on lines 65 to +67
"vite": "^7.3.1",
"vitest": "^4.0.16",
"wrangler": "^4.63.0"
"wrangler": "^4.80.0"
Copy link

Copilot AI Apr 12, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bumping to wrangler@^4.80.0 pulls in a stricter Node engine requirement (wrangler now requires Node >=20.3.0, and the resolved undici dependency requires >=20.18.1 per package-lock). Since the repo currently does not declare an engines.node in package.json, developers following older Node versions may hit runtime/install issues. Consider adding an explicit Node engine constraint (and aligning any documented Node version) to prevent mismatches.

Copilot uses AI. Check for mistakes.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot apply changes based on this feedback

"@cloudflare/workers-types": "^4.20250101.0",
"typescript": "^5.9.3",
"wrangler": "^4.0.0"
"wrangler": "^4.80.0"
Copy link

Copilot AI Apr 12, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR bumps the worker's direct wrangler devDependency to ^4.80.0, but the PR description only mentions an undici update for /workers/tmdb-cron. Please update the PR description to reflect the wrangler bump as well (it changes the worker tooling/runtime expectations).

Copilot uses AI. Check for mistakes.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot apply changes based on this feedback

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants