Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency eslint to v9 #2785

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 8, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
eslint (source) ^8.57.0 -> ^9.4.0 age adoption passing confidence

Release Notes

eslint/eslint (eslint)

v9.4.0

Compare Source

v9.3.0

Compare Source

v9.2.0

Compare Source

v9.1.1

Compare Source

v9.1.0

Compare Source

v9.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the c: dependencies Pull requests that adds/updates a dependency label Apr 8, 2024
Copy link

stackblitz bot commented Apr 8, 2024

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

Copy link

netlify bot commented Apr 8, 2024

Deploy Preview for elk-zone ready!

Name Link
🔨 Latest commit e09eae3
🔍 Latest deploy log https://app.netlify.com/sites/elk-zone/deploys/665a5d28b4c9d300082dfc3a
😎 Deploy Preview https://deploy-preview-2785--elk-zone.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Copy link

netlify bot commented Apr 8, 2024

Deploy Preview for elk-docs canceled.

Name Link
🔨 Latest commit e09eae3
🔍 Latest deploy log https://app.netlify.com/sites/elk-docs/deploys/665a5d283650b100082cb3b0

Copy link

socket-security bot commented Apr 8, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@antfu/eslint-config@2.19.1 environment Transitive: filesystem +2 1.59 MB antfu
npm/@emoji-mart/data@1.2.1 None 0 27.9 MB etiennelem
npm/@iconify/json@2.2.215 filesystem 0 353 MB cyberalien
npm/@iconify/utils@2.1.24 Transitive: filesystem +1 371 kB cyberalien
npm/@nuxt/devtools@1.3.2 environment, network 0 8.71 MB antfu
npm/@nuxt/test-utils@3.13.1 None 0 90.9 kB danielroe
npm/@nuxtjs/color-mode@3.4.1 None 0 25.8 kB danielroe
npm/@nuxtjs/i18n@8.3.1 eval 0 230 kB rchl
npm/@tiptap/pm@2.4.0 None 0 23.8 kB _bdbch
npm/@unlazy/nuxt@0.11.3 None 0 11.2 kB johannschopplich
npm/@upstash/redis@1.31.3 environment, network 0 283 kB hezarfen
npm/@vue-macros/nuxt@1.9.35 None 0 0 B
npm/@vueuse/core@10.10.0 environment, network 0 1.37 MB vueuse-bot
npm/@vueuse/integrations@10.10.0 None 0 336 kB vueuse-bot
npm/@vueuse/math@10.10.0 None 0 35.5 kB vueuse-bot
npm/@vueuse/nuxt@10.10.0 None 0 0 B
npm/blurhash@2.0.5 None 0 58.8 kB thisen
npm/browser-fs-access@0.35.0 None 0 46.7 kB tomayac
npm/bumpp@9.4.1 environment, filesystem, unsafe 0 179 kB antfu
npm/chroma-js@2.4.2 None 0 309 kB gka
npm/consola@3.2.3 environment 0 228 kB pi0
npm/emoji-mart@5.6.0 network 0 1.63 MB etiennelem
npm/eslint-plugin-format@0.1.1 None 0 20.9 kB antfu
npm/eslint@9.3.0 environment Transitive: eval, filesystem, unsafe +20 5.74 MB eslintbot
npm/file-saver@2.0.5 None 0 36 kB endless
npm/flat@6.0.1 None 0 12 kB jkoops
npm/floating-vue@5.2.2 None 0 233 kB akryum
npm/focus-trap@7.5.4 None 0 637 kB stefcameron
npm/form-data@4.0.0 filesystem, network +5 314 kB niftylettuce
npm/fs-extra@11.2.0 None 0 54.9 kB ryanzim
npm/fuse.js@6.6.2 None 0 392 kB krisk
npm/github-reserved-names@2.0.5 None 0 17.1 kB mottie
npm/happy-dom@10.11.2 eval, filesystem, network, shell, unsafe +4 6.99 MB davidortner
npm/idb-keyval@6.2.1 None 0 53.8 kB jaffathecake
npm/ignore-dependency-scripts@1.0.1 filesystem, shell 0 7.5 kB douglasjunior
npm/iso-639-1@3.1.2 None 0 36.3 kB meikidd
npm/js-yaml@4.1.0 Transitive: environment, filesystem +1 576 kB vitaly
npm/lint-staged@15.2.5 Transitive: environment, filesystem, shell +1 296 kB okonet
npm/masto@6.7.7 network 0 454 kB neetshin
npm/node-emoji@2.1.3 None 0 59.8 kB omnidan
npm/nuxt-security@0.13.1 None 0 34.5 kB baroshem
npm/nuxt@3.11.2 None +1 512 kB danielroe
npm/page-lifecycle@0.1.2 None 0 131 kB philipwalton
npm/pinia@2.1.7 environment 0 379 kB posva
npm/postcss-nested@6.0.1 None 0 13.9 kB ai
npm/prosemirror-highlight@0.5.0 None 0 24.5 kB ocavue
npm/rollup-plugin-node-polyfills@0.2.1 environment, unsafe 0 1.48 MB manucorporat
npm/sharp-ico@0.1.5 filesystem 0 11.5 kB ssnangua
npm/sharp@0.33.4 environment 0 498 kB lovell
npm/shiki@1.6.1 None 0 9.17 MB antfu
npm/simple-git-hooks@2.11.1 filesystem 0 10.9 kB toplenboren
npm/simple-git@3.24.0 shell Transitive: filesystem +2 968 kB steveukx
npm/slimeform@0.9.1 environment 0 59 kB oikawa_rizumu
npm/stale-dep@0.7.0 filesystem +4 101 kB sxzz
npm/std-env@3.7.0 None 0 26.2 kB pi0
npm/string-length@5.0.1 None 0 4.63 kB sindresorhus
npm/theme-vitesse@0.7.9 None 0 147 kB antfu
npm/tiny-decode@0.1.3 None 0 3.51 kB natemoo-re
npm/tippy.js@6.3.7 environment 0 2.07 MB atomiks
npm/tsx@4.11.0 None 0 397 kB hirokiosame
npm/ufo@1.5.3 None 0 103 kB pi0
npm/ultrahtml@1.5.3 None 0 357 kB natemoo-re
npm/unimport@3.7.2 None 0 176 kB antfu
npm/vite-plugin-pwa@0.19.8 filesystem 0 227 kB userquin
npm/vitest@1.4.0 environment, eval 0 1.41 MB vitestbot
npm/vue-advanced-cropper@2.8.8 None 0 380 kB norserium
npm/vue-tsc@2.0.19 None 0 4.9 kB johnsoncodehk
npm/vue-virtual-scroller@2.0.0-beta.8 None 0 488 kB akryum
npm/workbox-build@7.1.1 filesystem Transitive: environment, eval +14 4.19 MB tomayac
npm/workbox-window@7.1.0 environment 0 577 kB tropicadri

View full report↗︎

@renovate renovate bot force-pushed the renovate/major-lint branch 2 times, most recently from 4feb086 to c2abf11 Compare April 22, 2024 21:39
Copy link

socket-security bot commented May 27, 2024

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Install scripts npm/simple-git-hooks@2.11.1
  • Install script: postinstall
  • Source: node ./postinstall.js
Install scripts npm/sharp@0.33.4
  • Install script: install
  • Source: node install/check

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/simple-git-hooks@2.11.1
  • @SocketSecurity ignore npm/sharp@0.33.4

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c: dependencies Pull requests that adds/updates a dependency
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants