Skip to content

chore(deps): batch dependency updates - security patches + minor bumps#1340

Merged
dzbo merged 1 commit intomainfrom
chore/batch-deps-update-1-1
Mar 6, 2026
Merged

chore(deps): batch dependency updates - security patches + minor bumps#1340
dzbo merged 1 commit intomainfrom
chore/batch-deps-update-1-1

Conversation

@dzbo
Copy link
Contributor

@dzbo dzbo commented Mar 6, 2026

Consolidates 7 open Dependabot PRs into one. Build verified locally ✅

Closes

What changed

  • package.json: updated @emotion/react, prettier direct deps + added resolutions block for transitive deps (tar, lodash, ajv@^6, svgo, immutable)
  • yarn.lock: regenerated with updated versions

Not included (Batch 2 — needs separate testing)

Consolidates 7 Dependabot PRs into a single update:

Security patches (transitive):
- tar: 7.4.3 → 7.5.10 (closes #1337)
- lodash: 4.17.21 → 4.17.23 (closes #1314)
- ajv@^6: 6.12.6 → 6.14.0 (closes #1328)

Minor updates (direct):
- @emotion/react: 11.13.5 → 11.14.0 (closes #1311)
- prettier: 3.7.4 → 3.8.1 (closes #1309)

Minor updates (transitive, via resolutions):
- svgo: 3.3.2 → 3.3.3 (closes #1335)
- immutable: 5.0.3 → 5.1.5 (closes #1334)

Build verified locally.
@dzbo dzbo requested a review from CJ42 March 6, 2026 15:15
@github-actions
Copy link
Contributor

github-actions bot commented Mar 6, 2026

Deployed with Cloudflare Pages ☁️ 🚀 🆗

@dzbo dzbo enabled auto-merge March 6, 2026 15:27
@dzbo dzbo merged commit 72be739 into main Mar 6, 2026
4 of 5 checks passed
@dzbo dzbo deleted the chore/batch-deps-update-1-1 branch March 6, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants