Skip to content

[Deps] Safe dependency updates (2026-03-14)#1297

Closed
github-actions[bot] wants to merge 1 commit intomainfrom
deps/safe-updates-2026-03-14-5328dfc9179bcd06
Closed

[Deps] Safe dependency updates (2026-03-14)#1297
github-actions[bot] wants to merge 1 commit intomainfrom
deps/safe-updates-2026-03-14-5328dfc9179bcd06

Conversation

@github-actions
Copy link
Contributor

Automated Safe Dependency Updates

This PR contains safe patch/minor-level dependency updates that have been verified to pass all existing tests.

Updated Dependencies

Package Previous Updated Type
@commitlint/cli 20.4.3 20.4.4 patch
@commitlint/config-conventional 20.4.3 20.4.4 patch
@types/node 25.4.0 25.5.0 minor (types only)

Security Fixes Included

None — no HIGH or CRITICAL vulnerabilities were found. The 4 MODERATE vulnerabilities detected are in markdownlint-cli2 (a dev-only linting tool) and require a major version bump (0.17.x → 0.21.0) to resolve; they are excluded from this PR as they are not safe patch updates.

Verification

  • All tests pass (1078/1081 — 3 pre-existing failures unrelated to these updates)
  • No breaking changes detected
  • Updates are patch/types-only with no API changes

Vulnerability Summary

  • CRITICAL: 0 found
  • HIGH: 0 found
  • MODERATE: 4 noted (all in markdownlint-cli2 dev dependency — require major version bump)
  • LOW: 0 found

Generated by Dependency Security Monitor Workflow

AI generated by Dependency Security Monitor

- @commitlint/cli: 20.4.3 -> 20.4.4
- @commitlint/config-conventional: 20.4.3 -> 20.4.4
- @types/node: 25.4.0 -> 25.5.0

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant