Conversation
guibranco
left a comment
There was a problem hiding this comment.
Automatically approved by gstraccini[bot]
|
@depfu merge |
|
|
Infisical secrets check: ✅ No secrets leaked! 💻 Scan logs2026-04-21T05:41:03Z INF scanning for exposed secrets...
5:41AM INF 567 commits scanned.
2026-04-21T05:41:04Z INF scan completed in 696ms
2026-04-21T05:41:04Z INF no leaks found
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Apr 21, 2026 5:40a.m. | Review ↗ | |
| Secrets | Apr 21, 2026 5:40a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|



Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ vite (8.0.8 → 8.0.9) · Repo · Changelog
Release Notes
8.0.9
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 30 commits:
release: v8.0.9docs: update build CLI defaults (#22261)docs(create-vite): list overwrite flag in help (#22262)fix(deps): update all non-major dependencies (#22268)chore(deps): update dependency dotenv-expand to v13 (#22271)chore(deps): update actions/upload-pages-artifact action to v5 (#22270)chore(deps): update dependency tsdown to ^0.21.9 (#22267)fix(bundled-dev): reject requests to HMR patch files in non potentially trustworthy origins (#22269)fix: skip fallback sourcemap generation for `?raw` imports (#22148)docs: mention minor comment differences in migration guide (#22255)fix(optimizer): handle more chars that will be sanitized (#22208)test(glob-import): add follow symlinks test (#22196)fix: detect Deno workspace root (fix #22237) (#22238)fix(dev): handle errors in `watchChange` hook (#22188)fix(css): use unique key for cssEntriesMap to prevent same-basename collision (#22039)feat: update rolldown to 1.0.0-rc.16 (#22248)docs: update patak links (#22246)docs: align the descriptions in READMEs (#22231)docs: add ambiguous default import from CJS section in troubleshooting (#22232)fix(create-vite): add missing quotes around viteLogo src attribute (#22216)fix(build): emptyOutDir should happen for watch rebuilds (#22207)docs: update sponsors source (#22224)docs: fix Vite 5 migration blog links (#22206)docs: fix wording in sass error comment (#22214)fix(deps): update all non-major dependencies (#22219)chore(deps): update actions/github-script action to v9 (#22220)test: replace lodash dependencies with local test packages (#22191)fix: allow binding when strictPort is set but wildcard port is in use (#22150)docs: fix reuses wording in dev environment comment (#22173)refactor(create-vite): optimize hero.png (#22203)Sorry, we couldn't find anything useful about this release.
Release Notes
0.2.16
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 23 commits:
release 0.2.16bump deps once moredo not import the whole `fs` modulefix root being too broadchore(deps): update all non-major dependencies (#191)chore(deps): update pnpm/action-setup action to v5 (#192)upgrade picomatch (and everything else)chore(deps): update dependency picomatch to v4.0.4 [security] (#193)enable pnpm `trustPolicy`chore(deps): update all non-major dependencies (#181)chore(deps): update dependency tinybench to v6 (#183)chore(deps): update actions/checkout action to v6 (#180)avoid compiling ignore patterns twice (#190)chore(deps): update all non-major dependencies (#175)chore(deps): update dependency glob to v13 (#177)update readme mention of `globby` to 16.0.0process patterns and misc optimizations (#179)overhaul crawler options building and handling (#174)chore(deps): update dependency glob to v11.1.0 [security] (#176)chore(deps): update actions/setup-node action to v6 (#172)chore(deps): update all non-major dependencies (#165)refactor `GlobOptions` to center option processing (#170)outsource types to separate file (#169)Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands
Go to the Depfu Dashboard to see the state of your dependencies and to customize how Depfu works.