chore(deps): bump the sec-updates group across 2 directories with 4 updates#556
chore(deps): bump the sec-updates group across 2 directories with 4 updates#556dependabot[bot] wants to merge 1 commit into
Conversation
…pdates Bumps the sec-updates group with 2 updates in the / directory: [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the sec-updates group with 1 update in the /docsite directory: [lodash-es](https://github.com/lodash/lodash). Updates `storybook` from 10.2.0 to 10.3.5 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.3.5/code/core) Updates `vite` from 5.4.21 to 8.0.8 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.8/packages/vite) Updates `esbuild` from 0.21.5 to 0.27.7 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md) - [Commits](evanw/esbuild@v0.21.5...v0.27.7) Updates `lodash-es` from 4.17.23 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.23...4.18.1) --- updated-dependencies: - dependency-name: storybook dependency-version: 10.3.5 dependency-type: direct:development dependency-group: sec-updates - dependency-name: vite dependency-version: 8.0.8 dependency-type: direct:development dependency-group: sec-updates - dependency-name: esbuild dependency-version: 0.27.7 dependency-type: indirect dependency-group: sec-updates - dependency-name: lodash-es dependency-version: 4.18.1 dependency-type: indirect dependency-group: sec-updates ... Signed-off-by: dependabot[bot] <support@github.com>
❌ Deploy Preview for multi-scrobbler failed.
|
|
@dependabot ignore storybook |
|
OK, I won't notify you about storybook again, unless you unignore it. |
|
Dependabot cannot update to the required version as all versions were ignored. Because of this, Dependabot cannot update this pull request. |
5 similar comments
|
Dependabot cannot update to the required version as all versions were ignored. Because of this, Dependabot cannot update this pull request. |
|
Dependabot cannot update to the required version as all versions were ignored. Because of this, Dependabot cannot update this pull request. |
|
Dependabot cannot update to the required version as all versions were ignored. Because of this, Dependabot cannot update this pull request. |
|
Dependabot cannot update to the required version as all versions were ignored. Because of this, Dependabot cannot update this pull request. |
|
Dependabot cannot update to the required version as all versions were ignored. Because of this, Dependabot cannot update this pull request. |
Bumps the sec-updates group with 2 updates in the / directory: storybook and vite.
Bumps the sec-updates group with 1 update in the /docsite directory: lodash-es.
Updates
storybookfrom 10.2.0 to 10.3.5Release notes
Sourced from storybook's releases.
... (truncated)
Changelog
Sourced from storybook's changelog.
... (truncated)
Commits
e486d38Bump version from "10.3.4" to "10.3.5" [skip ci]0b3ac65Merge pull request #34408 from storybookjs/yann/disable-component-manifest-de...ee73b65Merge pull request #34455 from seojcarlos/fix/remove-duplicate-words4eff9cdBump version from "10.3.3" to "10.3.4" [skip ci]21d37fdMerge pull request #34224 from storybookjs/chore/removeprettierrc4eb227bBuild: Move prettier to oxfmtff9d121Merge pull request #34316 from storybookjs/jeppe/fix-error-reports-on-init5bc8686Merge pull request #34281 from storybookjs/fix-stackblitz-websocketb0acfb4Bump version from "10.3.2" to "10.3.3" [skip ci]6a398c5Merge pull request #34193 from storybookjs/valentin/streamline-config-validat...Updates
vitefrom 5.4.21 to 8.0.8Release notes
Sourced from vite's releases.
... (truncated)
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
6e585dcrelease: v8.0.8e137601fix(ssr): class property keys hoisting matching imports (#22199)15f1c15fix: avoiddns.getDefaultResultOrdertemporary (#22202)6baf587feat: update rolldown to 1.0.0-rc.15 (#22201)fdb2e6frelease: v8.0.75c05b04fix: use sync dns.getDefaultResultOrder instead of dns.promises (#22185)7b3086frelease: v8.0.6af71fb2chore: replace remaining prettier script (#22179)51d3e48feat: update rolldown to 1.0.0-rc.13 (#22097)17a8f9efix(optimize-deps): hoist CJS interop assignment (#22156)Updates
esbuildfrom 0.21.5 to 0.27.7Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
2025c9fpublish 0.27.7 to npmc6b586efix typo inMakefilefor@esbuild/win32-x649785e14publish 0.27.6 to npmb169d8cRevert "update go 1.25.7 => 1.26.1"7ac8762runmake update-compat-table8b5ff53remove an incorrectelsee955268fix #4421: lower generated class fields if neededa5a2500ci: movemake test-old-tsb71e7acomit go'sbuildvcsfor more reproducible builds7406b09organizemake platform-alloutput inMakefileMaintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for esbuild since your current version.
Updates
lodash-esfrom 4.17.23 to 4.18.1Release notes
Sourced from lodash-es's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.