Skip to content

Dependency Dashboard#17

Description

@chrisbbreuer

This issue lists Buddy Bot updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Caution

5 known vulnerabilities affect 3 dependencies in this repository.

Severity Package Current Advisory Fixed in
馃煚 High image-size ^2.0.2 GHSA-5p2g-fcmc-qvqq n/a
馃煚 High image-size ^2.0.2 GHSA-w3rx-r6r6-pgpr n/a
馃煚 High sharp ^0.34.5 GHSA-f88m-g3jw-g9cj 0.35.0
馃煚 High svgo ^4.0.0 GHSA-2p49-hgcm-8545 2.8.3
馃煚 High svgo ^4.0.0 GHSA-xpqw-6gx7-v673 2.8.1

Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

  • chore(deps): update actions/cache action to v6 (@actions/cache, @actions/core)
  • chore(deps): update actions/checkout action to v7
  • chore(deps): update all non-major dependencies
  • chore(deps): update dependency vite to v8 - abandoned (vite, hmrClient.logger.debug, hmrClient.logger.error, watchChange, dns.getDefaultResultOrder, getLocalhostAddressIfDiffersFromDNS, verbatim, server.fs, hasBothRollupOptionsAndRolldownOptions, false, vite/modulepreload-polyfill, environment.fetchModule, meta, import.meta, getCssFilesForChunk, inlineConst, no-cors, @vitejs/devtools, vite-tsconfig-paths, bindCLIShortcuts, indexOfMatchInSlice, findPreloadMarker, getBuiltins, server.fs.deny, //, fileToBuiltUrl, WebSocket, create-react-app, import.meta.hot.prune, skipLibCheck, fs.strict, minify, finalizeCss, generateCodeFrame, resolveConfig, import, checkNodeVersion, @jridgewell/remapping, @ampproject/remapping, import.meta.main, removeServerPluginContainer, removeServerReloadModule, server.warmupRequest, ssrFixStacktrace, ssrRewriteStacktrace, removeSsrLoadModule, this.fs, defaultExternalConditions, removePluginHookSsrArgument, removeServerHot, resolve.externalConditions, module-sync, import.meta.resolve, image-set, entryCssAssetFileNames, resolvedUrls, cssScopeTo)
  • chore(deps): update dependency vite to ^5.4.21 [security] - abandoned (vite, server.host, readFile, ../, server.fs.strict, to, and, in, returns, with)
  • chore(deps): update all non-major dependencies (@actions/cache, @actions/core, oven-sh/setup-bun, actions/checkout@v6.0.2, autofix.ci, form-data, no-cache, shivammathur/php, shivammathur/extensions)
  • Click on this checkbox to rebase all open PRs at once

Detected dependencies

npm
package.json
  • @stacksjs/bunpress ^0.2.11
  • better-dx ^0.2.22
package.json
  • @stacksjs/ts-avif ^0.1.4
  • @stacksjs/ts-bmp ^0.1.0
  • @stacksjs/ts-png ^0.1.2
  • @stacksjs/ts-svg ^0.1.1
  • @stacksjs/ts-webp ^0.1.2
  • ts-gif ^0.1.2
  • ts-jpeg ^0.3.1
  • @stacksjs/clapp ^0.2.0
  • bunfig ^0.15.9
package.json
package.json
  • ts-images workspace:*
  • bun-plugin-dtsx ^0.21.12
github-actions
.github/workflows/release.yml
  • actions/checkout v6
  • home-lang/pantry/packages/action main
  • stacksjs/action-releaser v1.2.9
.github/workflows/buddy-bot.yml
  • actions/checkout v6
  • oven-sh/setup-bun v2
  • shivammathur/setup-php 2.37.1
.github/workflows/ci.yml
  • actions/checkout v6
  • oven-sh/setup-bun v2.0.2
  • actions/cache v5.0.2
  • home-lang/pantry/packages/action main
dependency-files
deps.yaml
  • bun.sh ^1.3.14
pantry.lock
  • @stacksjs/clapp ^0.2.0
  • better-dx ^0.2.7
  • bun-plugin-dtsx ^0.21.12
  • bunfig ^0.15.0
  • cac ^7.0.0
  • changelogen ^0.6.2
  • image-size ^2.0.2
  • sharp ^0.34.5
  • svgo ^4.0.0
  • ts-potrace ^0.1.0

  • Check this box to trigger a request for Buddy Bot to run again on this repository

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions