Skip to content

chore(deps): bump the dependencies group across 1 directory with 4 updates - #763

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/dependencies-10e3e050ec
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/dependencies-10e3e050ec

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 4 updates in the / directory: @nodesecure/js-x-ray, @openally/mutex, @npmcli/arborist and @openally/httpie.

Updates @nodesecure/js-x-ray from 16.0.0 to 16.1.0

Release notes

Sourced from @​nodesecure/js-x-ray's releases.

@​nodesecure/js-x-ray@​16.1.0

Minor Changes

  • #685 19202ec Thanks @​clemgbld! - feat: follow CallExpression chain

  • #689 54a7dff Thanks @​Edneam! - feat(tracer): resolve identifiers assigned an object literal, so log-usage detects pino()/winston.createLogger() config passed via a variable instead of only inline

  • #699 652abd7 Thanks @​HoyeongJeon! - Add weak-argon2 detection probe for crypto.argon2() misuse

  • #707 a832844 Thanks @​HoyeongJeon! - Measure the scrypt salt length in bytes and report one warning per call with every failing check joined in the value

Patch Changes

  • #703 eceb98a Thanks @​HoyeongJeon! - match quoted and computed string keys in findPropertyMatch, so { "cost": 1 } and { ["cost"]: 1 } are no longer skipped

  • #708 a0ec458 Thanks @​VictorMartins3! - resolve require specifiers written as a template literal with no expression, so require(`http`) records the dependency instead of reporting unsafe-import

  • #709 515797f Thanks @​VictorMartins3! - decode Buffer.from(payload, "base64") in require specifiers, so require(Buffer.from("aHR0cA==", "base64").toString()) records http like the hex and atob forms already do

  • #701 669146a Thanks @​ErwanRaulo! - refactor probes to extract helper functions

Changelog

Sourced from @​nodesecure/js-x-ray's changelog.

16.1.0

Minor Changes

  • #685 19202ec Thanks @​clemgbld! - feat: follow CallExpression chain

  • #689 54a7dff Thanks @​Edneam! - feat(tracer): resolve identifiers assigned an object literal, so log-usage detects pino()/winston.createLogger() config passed via a variable instead of only inline

  • #699 652abd7 Thanks @​HoyeongJeon! - Add weak-argon2 detection probe for crypto.argon2() misuse

  • #707 a832844 Thanks @​HoyeongJeon! - Measure the scrypt salt length in bytes and report one warning per call with every failing check joined in the value

Patch Changes

  • #703 eceb98a Thanks @​HoyeongJeon! - match quoted and computed string keys in findPropertyMatch, so { "cost": 1 } and { ["cost"]: 1 } are no longer skipped

  • #708 a0ec458 Thanks @​VictorMartins3! - resolve require specifiers written as a template literal with no expression, so require(`http`) records the dependency instead of reporting unsafe-import

  • #709 515797f Thanks @​VictorMartins3! - decode Buffer.from(payload, "base64") in require specifiers, so require(Buffer.from("aHR0cA==", "base64").toString()) records http like the hex and atob forms already do

  • #701 669146a Thanks @​ErwanRaulo! - refactor probes to extract helper functions

Commits
  • 208e9ac chore: update versions (#686)
  • a0ec458 fix(js-x-ray): resolve template literal require specifiers (#708)
  • 515797f fix(js-x-ray): decode base64 in Buffer.from require specifiers (#709)
  • a832844 fix(js-x-ray): measure scrypt salt in bytes and merge warnings into one per c...
  • f167cc3 chore(deps): bump the dependencies group with 2 updates (#706)
  • 652abd7 feat(js-x-ray): add weak-argon2 detection probe (#699)
  • 2458af7 chore(deps): bump @​typescript-eslint/typescript-estree (#704)
  • eceb98a fix(js-x-ray): match quoted property keys in findPropertyMatch (#703)
  • 669146a refactor(probes): reduce complexity by extracting logic into helper functions...
  • 243ef1d chore(deps): bump @​typescript-eslint/typescript-estree (#700)
  • Additional commits viewable in compare view

Updates @openally/mutex from 3.0.0 to 4.0.0

Release notes

Sourced from @​openally/mutex's releases.

@​openally/mutex@​4.0.0

Major Changes

Changelog

Sourced from @​openally/mutex's changelog.

4.0.0

Major Changes

Commits
  • 5286c6f chore: update versions (#313)
  • 2f7532e refactor: enable TS composite for workspaces
  • 2216a41 refactor(mutex)!: enhance Mutex implementation & introduce new TaskGroup API ...
  • See full diff in compare view

Updates @npmcli/arborist from 10.0.2 to 10.0.3

Release notes

Sourced from @​npmcli/arborist's releases.

arborist: v10.0.3

10.0.3 (2026-09-21)

Bug Fixes

libnpmpack: v10.0.3

10.0.3 (2026-09-21)

Bug Fixes

Dependencies

Changelog

Sourced from @​npmcli/arborist's changelog.

10.0.3 (2026-09-21)

Bug Fixes

Commits
  • c039090 chore: release 12.1.0
  • d6c6122 fix(arborist): match allowScripts keys for local paths (#9914)
  • da50c34 fix(arborist): reject uninstall args that carry a version (#9881)
  • dc43591 fix(arborist): don't fetch packuments for uninstallable optional peer depende...
  • See full diff in compare view

Updates @openally/httpie from 1.1.4 to 2.0.0

Release notes

Sourced from @​openally/httpie's releases.

v2.0.0

What's Changed

Full Changelog: OpenAlly/httpie@v1.1.4...v2.0.0

Commits
  • 328ca48 2.0.0
  • 969ebac Merge pull request #12 from OpenAlly/improve-implementation
  • cf9de75 refactor(response): replace HttpieResponseHandler with internal functions
  • 14dcf3c chore: update dependencies
  • f4db16a refactor: use custom and minimal LRU-cache implementation
  • b054d2b refactor(typescript): migrate to esm-ts-next
  • 5bf5edf refactor: revamp folders and tests architecture
  • 8a332c6 refactor(errors): brand httpie errors with a registered symbol
  • 6b1392d refactor(utils): tighten getEncodingCharset
  • 4a9fe0c refactor(request): use node's STATUS_CODES and fix the getData contract
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the dependencies group with 4 updates in the / directory: [@nodesecure/js-x-ray](https://github.com/NodeSecure/js-x-ray/tree/HEAD/workspaces/js-x-ray), [@openally/mutex](https://github.com/OpenAlly/npm-packages/tree/HEAD/src/mutex), [@npmcli/arborist](https://github.com/npm/cli/tree/HEAD/workspaces/arborist) and [@openally/httpie](https://github.com/OpenAlly/httpie).


Updates `@nodesecure/js-x-ray` from 16.0.0 to 16.1.0
- [Release notes](https://github.com/NodeSecure/js-x-ray/releases)
- [Changelog](https://github.com/NodeSecure/js-x-ray/blob/master/workspaces/js-x-ray/CHANGELOG.md)
- [Commits](https://github.com/NodeSecure/js-x-ray/commits/@nodesecure/js-x-ray@16.1.0/workspaces/js-x-ray)

Updates `@openally/mutex` from 3.0.0 to 4.0.0
- [Release notes](https://github.com/OpenAlly/npm-packages/releases)
- [Changelog](https://github.com/OpenAlly/npm-packages/blob/main/src/mutex/CHANGELOG.md)
- [Commits](https://github.com/OpenAlly/npm-packages/commits/@openally/mutex@4.0.0/src/mutex)

Updates `@npmcli/arborist` from 10.0.2 to 10.0.3
- [Release notes](https://github.com/npm/cli/releases)
- [Changelog](https://github.com/npm/cli/blob/latest/workspaces/arborist/CHANGELOG.md)
- [Commits](https://github.com/npm/cli/commits/arborist-v10.0.3/workspaces/arborist)

Updates `@openally/httpie` from 1.1.4 to 2.0.0
- [Release notes](https://github.com/OpenAlly/httpie/releases)
- [Commits](OpenAlly/httpie@v1.1.4...v2.0.0)

---
updated-dependencies:
- dependency-name: "@nodesecure/js-x-ray"
  dependency-version: 16.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@openally/mutex"
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: "@npmcli/arborist"
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@openally/httpie"
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 28, 2026 09:35
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Sep 28, 2026
@changeset-bot

changeset-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: f70f736

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​openally/​mutex@​3.0.0 ⏵ 4.0.07510095 -489 +2100
Updatednpm/​@​openally/​httpie@​1.1.4 ⏵ 2.0.07710010092 +2100
Addednpm/​@​nodesecure/​js-x-ray@​16.1.08210010096100
Addednpm/​@​npmcli/​arborist@​10.0.39710010097100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants