Skip to content

chore(deps): update dependency @changesets/changelog-github to ^0.7.0 - #35

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/changesets-changelog-github-0.x
Open

chore(deps): update dependency @changesets/changelog-github to ^0.7.0#35
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/changesets-changelog-github-0.x

Conversation

@renovate

@renovate renovate Bot commented Aug 1, 2022

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@changesets/changelog-github (source) ^0.4.4^0.7.0 age confidence

Release Notes

changesets/changesets (@​changesets/changelog-github)

v0.7.0

Compare Source

Minor Changes

v0.6.0

Compare Source

Minor Changes
Patch Changes

v0.5.2

Compare Source

v0.5.1

Compare Source

Patch Changes

v0.5.0

Compare Source

Minor Changes
  • #​1185 a971652 Thanks @​Andarist! - package.json#exports have been added to limit what (and how) code might be imported from the package.
Patch Changes

v0.4.8

Compare Source

Patch Changes

v0.4.7

Compare Source

Patch Changes

v0.4.6

Compare Source

Patch Changes

v0.4.5

Compare Source

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot

changeset-bot Bot commented Aug 1, 2022

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: eaf4147

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@codesandbox-ci

codesandbox-ci Bot commented Aug 1, 2022

Copy link
Copy Markdown

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

@codecov

codecov Bot commented Aug 1, 2022

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (738061e) 100.00% compared to head (e062067) 100.00%.
Report is 1 commits behind head on main.

❗ Current head e062067 differs from pull request most recent head 7841b64. Consider uploading reports for the commit 7841b64 to get more accurate results

Additional details and impacted files
@@            Coverage Diff            @@
##              main       #35   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            1         1           
  Lines           46        46           
  Branches        11        11           
=========================================
  Hits            46        46           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from e0a3c6f to e062067 Compare November 20, 2022 13:04
@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.4.6 chore(deps): update dependency @changesets/changelog-github to ^0.4.7 Nov 20, 2022
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from e062067 to 6d7cdbc Compare March 16, 2023 07:17
@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.4.7 chore(deps): update dependency @changesets/changelog-github to ^0.4.8 Mar 16, 2023
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from 6d7cdbc to 2e8bff2 Compare November 28, 2023 09:53
@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.4.8 chore(deps): update dependency @changesets/changelog-github to ^0.5.0 Nov 28, 2023
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from 2e8bff2 to 7841b64 Compare January 4, 2024 17:55
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from 7841b64 to a155a18 Compare February 17, 2025 12:00
@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.5.0 chore(deps): update dependency @changesets/changelog-github to ^0.5.1 Feb 17, 2025
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from a155a18 to 4815992 Compare November 27, 2025 17:02
@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.5.1 chore(deps): update dependency @changesets/changelog-github to ^0.5.2 Nov 27, 2025
@coderabbitai

coderabbitai Bot commented Nov 27, 2025

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security

socket-security Bot commented Nov 27, 2025

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​changesets/​changelog-github@​0.4.4 ⏵ 0.7.010010068 +194 +2100

View full report

@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.5.2 chore(deps): update dependency @changesets/changelog-github to ^0.6.0 Mar 3, 2026
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from 4815992 to 93ca427 Compare March 3, 2026 14:11
@renovate
renovate Bot force-pushed the renovate/changesets-changelog-github-0.x branch from 93ca427 to eaf4147 Compare May 5, 2026 11:15
@renovate renovate Bot changed the title chore(deps): update dependency @changesets/changelog-github to ^0.6.0 chore(deps): update dependency @changesets/changelog-github to ^0.7.0 May 5, 2026
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm form-data uses unsafe random function in form-data for choosing boundary

CVE: GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary (CRITICAL)

Affected versions: < 2.5.4; >= 3.0.0 < 3.0.4; >= 4.0.0 < 4.0.4

Patched version: 3.0.4

From: ?npm/form-data@3.0.1

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/form-data@3.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants