Skip to content

chore(deps): upgrade dev dependencies#1147

Open
rexxars wants to merge 1 commit intomainfrom
chore/dep-upgrades-oct-25
Open

chore(deps): upgrade dev dependencies#1147
rexxars wants to merge 1 commit intomainfrom
chore/dep-upgrades-oct-25

Conversation

@rexxars
Copy link
Copy Markdown
Member

@rexxars rexxars commented Oct 3, 2025

Description

Aside from a bump in get-it, this is all patch/minor dev dependency upgrades - but silences some security audit warnings.

What to review

As long as tests pass, we should be good to go.

Testing

Let 'em run.

@vercel
Copy link
Copy Markdown

vercel bot commented Oct 3, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Preview Comments Updated (UTC)
tsdocs-client Ignored Ignored Oct 3, 2025 6:11pm

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
msw@2.11.3 has Install scripts.

Install script: postinstall

Source: node -e "import('./config/scripts/postinstall.js').catch(() => void 0)"

From: package-lock.jsonnpm/msw@2.11.3

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/msw@2.11.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
sharp@0.34.4 has Install scripts.

Install script: install

Source: node install/check.js

From: package-lock.jsonnpm/next@15.5.4npm/sharp@0.34.4

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/sharp@0.34.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Oct 3, 2025

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 88.46% 3796 / 4291
🔵 Statements 88.46% 3796 / 4291
🔵 Functions 88.18% 306 / 347
🔵 Branches 90.22% 1135 / 1258
File CoverageNo changed files found.
Generated in workflow #3788 for commit 79c41af by the Vitest Coverage Report Action

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant