Skip to content

Bump @shgysk8zer0/rollup-import from 2.0.3 to 2.1.0#241

Merged
shgysk8zer0 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/shgysk8zer0/rollup-import-2.1.0
Jun 18, 2026
Merged

Bump @shgysk8zer0/rollup-import from 2.0.3 to 2.1.0#241
shgysk8zer0 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/shgysk8zer0/rollup-import-2.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor

Bumps @shgysk8zer0/rollup-import from 2.0.3 to 2.1.0.

Release notes

Sourced from @​shgysk8zer0/rollup-import's releases.

Release v2.1.0

See Changelog

Changelog

Sourced from @​shgysk8zer0/rollup-import's changelog.

[v2.1.0]

Added

  • Add Security policy
  • Add npm config to harden installs

Changed

  • Update Workflows with permissions
  • Update contributiing guidelines
  • Update to node 26.3.0 & npm 11.16.0
Commits
  • 5fd8fce Merge pull request #151 from shgysk8zer0/feature/ci-security
  • 425363e Security Hardening
  • 2ed0f81 Merge pull request #150 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • cfd41e1 Bump eslint from 10.4.0 to 10.4.1 in the all-dependencies group
  • 9f2924b Merge pull request #149 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • 8ec881a Bump eslint from 10.3.0 to 10.4.0 in the all-dependencies group
  • 7e4ba6c Merge pull request #148 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • b4f8114 Bump eslint from 10.2.1 to 10.3.0 in the all-dependencies group
  • a5fbf67 Merge pull request #147 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • 89060a8 Bump eslint from 10.2.0 to 10.2.1 in the all-dependencies group
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

socket-security Bot commented Jun 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​shgysk8zer0/​rollup-import@​2.0.3 ⏵ 2.1.07310010089 -2100

View full report

@socket-security

socket-security Bot commented Jun 18, 2026

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/shgysk8zer0/rollup-import-2.1.0 branch 3 times, most recently from 35833c5 to e045b8c Compare June 18, 2026 18:36
Bumps [@shgysk8zer0/rollup-import](https://github.com/shgysk8zer0/rollup-import) from 2.0.3 to 2.1.0.
- [Release notes](https://github.com/shgysk8zer0/rollup-import/releases)
- [Changelog](https://github.com/shgysk8zer0/rollup-import/blob/master/CHANGELOG.md)
- [Commits](shgysk8zer0/rollup-import@v2.0.3...v2.1.0)

---
updated-dependencies:
- dependency-name: "@shgysk8zer0/rollup-import"
  dependency-version: 2.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/shgysk8zer0/rollup-import-2.1.0 branch from e045b8c to 09264bb Compare June 18, 2026 18:56
@shgysk8zer0 shgysk8zer0 merged commit 42a1120 into master Jun 18, 2026
6 checks passed
@shgysk8zer0 shgysk8zer0 deleted the dependabot/npm_and_yarn/shgysk8zer0/rollup-import-2.1.0 branch June 18, 2026 20:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant