{"id":24759,"name":"source-map-js","ecosystem":"npm","repository_url":"https://github.com/7rulnik/source-map-js","issues_count":90,"created_at":"2025-06-07T04:01:52.266Z","updated_at":"2025-06-07T04:01:52.266Z","purl":"pkg:npm/source-map-js","metadata":{"id":2385371,"name":"source-map-js","ecosystem":"npm","description":"Generates and consumes source maps","homepage":"https://github.com/7rulnik/source-map-js","licenses":"BSD-3-Clause","normalized_licenses":["BSD-3-Clause"],"repository_url":"https://github.com/7rulnik/source-map-js","keywords_array":[],"namespace":null,"versions_count":8,"first_release_published_at":"2021-02-07T21:53:50.369Z","latest_release_published_at":"2024-09-08T16:22:55.645Z","latest_release_number":"1.2.1","last_synced_at":"2025-06-06T09:31:22.305Z","created_at":"2022-04-10T01:02:18.631Z","updated_at":"2025-06-06T09:34:02.405Z","registry_url":"https://www.npmjs.com/package/source-map-js","install_command":"npm install source-map-js","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"1.2.1"}},"repo_metadata":{"id":44918632,"uuid":"330043541","full_name":"7rulnik/source-map-js","owner":"7rulnik","description":"Consume and generate source maps.","archived":false,"fork":true,"pushed_at":"2024-09-08T16:24:06.000Z","size":7800,"stargazers_count":100,"open_issues_count":6,"forks_count":14,"subscribers_count":0,"default_branch":"patch-0.6.1","last_synced_at":"2025-05-30T07:56:23.452Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"benthemonkey/source-map","license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/7rulnik.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-01-15T23:19:53.000Z","updated_at":"2025-05-17T13:46:21.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/7rulnik/source-map-js","commit_stats":null,"previous_names":[],"tags_count":54,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/7rulnik","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/refs/heads/patch-0.6.1","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":258379896,"owners_count":22691764,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"7rulnik","name":"Valentin Semirulnik","uuid":"5969049","kind":"user","description":"JS developer at aviasales.com\r\n\r\nhttps://t.me/valya_reads_issue","email":"","website":null,"location":"Tbilisi, Georgia","twitter":"7rulnik","company":"@KosyanMedia","icon_url":"https://avatars.githubusercontent.com/u/5969049?u=d63a29fdfe6de1d4a62053d43110239e8c4dc8ac\u0026v=4","repositories_count":93,"last_synced_at":"2024-04-14T06:40:27.691Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/7rulnik","funding_links":[],"total_stars":472,"followers":279,"following":465,"created_at":"2022-11-02T16:20:42.935Z","updated_at":"2024-04-14T06:40:39.502Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/7rulnik","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/7rulnik/repositories"},"tags":[{"name":"v1.0.3","sha":"2ab15d9fa829677bb627fb6127f658f319e0cbcb","kind":"tag","published_at":"2024-03-17T18:30:47.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/v1.0.3","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/v1.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.3/manifests"},{"name":"v1.0.2","sha":"04907d5b2dc88bef63e5399452fa6a696f90bf66","kind":"tag","published_at":"2022-01-18T16:22:59.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/v1.0.2","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/v1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.2/manifests"},{"name":"v1.0.1","sha":"47654d26c5bbca04b9fb5008a550ed4529c2e94e","kind":"tag","published_at":"2021-11-08T19:45:06.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/v1.0.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"895d9cc038968d3eef5edd63140db847d196663a","kind":"tag","published_at":"2021-11-04T20:49:01.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/v1.0.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v1.0.0/manifests"},{"name":"v0.6.2","sha":"a14498cda8215caa8473f25b5ffba774ffc5da66","kind":"tag","published_at":"2021-02-07T21:52:10.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/v0.6.2","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/v0.6.2/manifests"},{"name":"0.6.2-beta.0","sha":"829bc1fc3a9a62c1f68a4d725d06e7b2c9142835","kind":"commit","published_at":"2018-11-05T19:17:10.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.6.2-beta.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.6.2-beta.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.2-beta.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.2-beta.0/manifests"},{"name":"0.6.2-beta.1","sha":"7356bcbc56565beac748f8bddcf3bc3151f2c798","kind":"commit","published_at":"2018-10-18T14:03:02.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.6.2-beta.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.6.2-beta.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.2-beta.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.2-beta.1/manifests"},{"name":"0.7.3","sha":"b2171d58e90e64472b0e858013c0cc5f6772a83d","kind":"commit","published_at":"2018-05-16T17:25:17.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.7.3","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.3/manifests"},{"name":"0.7.2","sha":"43b2687e6e2f3cf6c22926aa473d5031fb7df89d","kind":"commit","published_at":"2018-02-26T23:29:23.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.7.2","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.2/manifests"},{"name":"0.7.1","sha":"3181bacfb8d449ecdb7d3da8ffcd59e29bfe98d7","kind":"commit","published_at":"2018-02-14T18:58:07.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.7.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.1/manifests"},{"name":"0.7.0","sha":"86d105bfda30fc71aba95c21f2e665a384b5b69f","kind":"commit","published_at":"2018-01-19T21:36:54.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.7.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.7.0/manifests"},{"name":"0.6.1","sha":"ac518d2f21818146f3310557bd51c13d8cff2ba8","kind":"commit","published_at":"2017-09-29T14:40:58.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.6.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.1/manifests"},{"name":"0.6.0","sha":"83d389f62d80344aec4f60aaba649c76cdc002bb","kind":"commit","published_at":"2017-09-27T14:30:58.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.6.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.6.0/manifests"},{"name":"0.5.7","sha":"326dd955a366569759d9537ef5f0f167c89d92d2","kind":"commit","published_at":"2017-08-21T13:31:20.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.7","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.7/manifests"},{"name":"0.5.6","sha":"aa0398ced67beebea34f0d36f766505656c344f6","kind":"commit","published_at":"2016-05-02T17:25:30.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.6","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.6/manifests"},{"name":"0.5.5","sha":"d90ac8b806d4130b4bfdf2fc9482dfd5f7930692","kind":"commit","published_at":"2016-04-25T16:47:34.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.5","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.5/manifests"},{"name":"0.5.4","sha":"7c4905497b5f0a62fd6a3d3f786ba8eac0db4615","kind":"commit","published_at":"2016-04-22T20:07:55.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.4","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.4/manifests"},{"name":"0.5.3","sha":"3d8b134049f45aaab09bf83f061f9010d509ef98","kind":"commit","published_at":"2015-10-23T15:38:41.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.3","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.3/manifests"},{"name":"0.5.2","sha":"05211de6d4eb137ecbc0c67b2ade910b534fd2f3","kind":"commit","published_at":"2015-10-21T15:42:30.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.2","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.2/manifests"},{"name":"0.5.1","sha":"92fbfc86a9d5de98c1e66b0fc8aa8bc19cac2648","kind":"commit","published_at":"2015-09-23T23:05:51.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.1/manifests"},{"name":"0.5.0","sha":"09b95c173760bbd05de8f7ac82805c2c9158a2b8","kind":"commit","published_at":"2015-09-10T15:11:50.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.5.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.5.0/manifests"},{"name":"0.4.4","sha":"c3bfecb8359019b70654c35bfac31f42ed41bf93","kind":"commit","published_at":"2015-07-13T19:07:22.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.4.4","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.4/manifests"},{"name":"0.4.3","sha":"f28eb32f801eac6e8cbd2f44cf7b3aadc3946de2","kind":"commit","published_at":"2015-07-07T20:28:11.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.4.3","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.3/manifests"},{"name":"0.4.2","sha":"41bad3a34a237c074be74a312e7cae2026ef277a","kind":"commit","published_at":"2015-03-12T17:18:59.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.4.2","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.2/manifests"},{"name":"0.4.1","sha":"6b1429955e44fd131839e5180fdaf094539b0d68","kind":"commit","published_at":"2015-03-02T19:04:38.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.4.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.1/manifests"},{"name":"0.4.0","sha":"07f6b812c1999ba9778b1c71f50ea3bfbc4add98","kind":"commit","published_at":"2015-02-25T19:03:42.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.4.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.4.0/manifests"},{"name":"0.3.0","sha":"b9a3db6c1f293b759d831ea85af5f68c79f86299","kind":"commit","published_at":"2015-02-10T18:24:30.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.3.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.3.0/manifests"},{"name":"0.2.0","sha":"0314b55e6cad0a3462070123bfdb2dffc05a83e9","kind":"commit","published_at":"2015-01-26T23:06:34.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.2.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.2.0/manifests"},{"name":"0.1.43","sha":"bfa5bb2600109f702f29be70fc9fc73527e0434e","kind":"commit","published_at":"2015-01-08T18:22:15.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.43","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.43","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.43/manifests"},{"name":"0.1.42","sha":"38e67ecd9fbcdeffcc06afea716afa7795c158f9","kind":"commit","published_at":"2014-12-31T20:41:48.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.42","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.42","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.42/manifests"},{"name":"0.1.41","sha":"c9b866964114c5445f4bfb135ec8120d5c7ffa58","kind":"commit","published_at":"2014-12-17T19:22:14.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.41","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.41","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.41/manifests"},{"name":"0.1.40","sha":"40788a219393675cd28e942f9af39f921facc187","kind":"commit","published_at":"2014-10-02T15:31:27.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.40","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.40","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.40/manifests"},{"name":"0.1.39","sha":"4e79b16a30b12ac456c54b66ae99499d9e5a7277","kind":"commit","published_at":"2014-09-09T21:01:30.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.39","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.39","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.39/manifests"},{"name":"0.1.38","sha":"22c8185c1b77696fc1186cb36813e0b2300205df","kind":"commit","published_at":"2014-08-03T16:55:27.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.38","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.38","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.38/manifests"},{"name":"0.1.37","sha":"ae10401d1af0bd58aff4099bdc3f6d9e221fae55","kind":"commit","published_at":"2014-07-11T18:05:53.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.37","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.37","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.37/manifests"},{"name":"0.1.36","sha":"2b8eca6bbfe42dc4234a28442f18ac40e0e2e22c","kind":"commit","published_at":"2014-07-09T18:17:43.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.36","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.36","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.36/manifests"},{"name":"0.1.35","sha":"8dbaabeae3b7825dd79a047809b335ef8fe5a386","kind":"commit","published_at":"2014-07-08T17:00:59.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.35","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.35","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.35/manifests"},{"name":"0.1.34","sha":"b42f02e4dd0b4c0b2899338d9d0ac112a2d597c5","kind":"commit","published_at":"2014-06-09T23:24:39.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.34","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.34","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.34/manifests"},{"name":"0.1.33","sha":"d42b3e6faca85804c4883c775fd82205d6f04ed7","kind":"commit","published_at":"2014-02-27T02:25:57.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.33","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.33","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.33/manifests"},{"name":"0.1.32","sha":"f18d1beec96737d1fcf0e0502d1cebfa467cfccd","kind":"commit","published_at":"2014-02-11T23:10:03.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.32","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.32","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.32/manifests"},{"name":"0.1.31","sha":"874b58d2e6b578784f97f877089c48dedaa40915","kind":"commit","published_at":"2013-11-01T18:39:27.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.31","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.31","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.31/manifests"},{"name":"0.1.30","sha":"6fe6dcdf0671c5c2952bc152d7e795f9ab93dfe3","kind":"commit","published_at":"2013-09-30T23:08:19.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.30","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.30","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.30/manifests"},{"name":"0.1.29","sha":"ab74523ec0f7d16a0f4318bcbd3cd3dbd502525a","kind":"commit","published_at":"2013-08-22T00:28:54.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.29","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.29","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.29/manifests"},{"name":"0.1.28","sha":"58dd0c223d8a626f0d72a5a184bd807beba89655","kind":"commit","published_at":"2013-08-16T21:12:04.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.28","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.28","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.28/manifests"},{"name":"0.1.27","sha":"4929429eafb7354defe3176f477babeeebc2d9ce","kind":"commit","published_at":"2013-07-22T20:36:37.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.27","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.27","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.27/manifests"},{"name":"0.1.26","sha":"319f899b57e499f6dbb32a05d3e779362ae4e48c","kind":"commit","published_at":"2013-07-15T18:50:40.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.26","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.26","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.26/manifests"},{"name":"0.1.25","sha":"99490930b0e47a5ccac3ff8cce46164e2336dff2","kind":"commit","published_at":"2013-06-27T19:03:59.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.25","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.25","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.25/manifests"},{"name":"0.1.24","sha":"d33ac8e438c16ea26cb6d103331bf9b3968d6b2e","kind":"commit","published_at":"2013-06-24T21:28:20.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.24","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.24","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.24/manifests"},{"name":"0.1.23","sha":"22c54294c41024062f10a1b5af47fee443ff8d2d","kind":"commit","published_at":"2013-06-14T00:23:12.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.23","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.23","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.23/manifests"},{"name":"0.1.22","sha":"1f4201959f032ef47338049e14bacf2ba2b8fe9a","kind":"commit","published_at":"2013-04-04T18:44:45.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.22","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.22","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.22/manifests"},{"name":"0.1.21","sha":"2fdddf498771bae9467434bc930054a11a4f8066","kind":"commit","published_at":"2013-04-02T04:33:56.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.21","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.21","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.21/manifests"},{"name":"0.1.20","sha":"9c0bd852b06c0252e20fecd2f45fd2b2bc873607","kind":"commit","published_at":"2013-04-02T01:20:50.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.20","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.20","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.20/manifests"},{"name":"0.1.1","sha":"5cac2204396d50175b3fe8e450156fc60bd1be75","kind":"commit","published_at":"2012-06-19T20:17:11.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.1","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.1/manifests"},{"name":"0.1.0","sha":"c2ffd0d7e67dee9891ec8041e3f80cf5c9ab8ca8","kind":"commit","published_at":"2011-09-08T23:34:47.000Z","download_url":"https://codeload.github.com/7rulnik/source-map-js/tar.gz/0.1.0","html_url":"https://github.com/7rulnik/source-map-js/releases/tag/0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/7rulnik%2Fsource-map-js/tags/0.1.0/manifests"}]},"repo_metadata_updated_at":"2025-06-06T09:34:02.405Z","dependent_packages_count":737,"downloads":192509878,"downloads_period":"last-month","dependent_repos_count":1275432,"rankings":{"downloads":0.014702967206633364,"dependent_repos_count":0.027407207027635005,"dependent_packages_count":0.08660239343497456,"stargazers_count":5.2512865780801485,"forks_count":6.113643289490004,"docker_downloads_count":0.013908952217820764,"average":1.9179252312428694},"purl":"pkg:npm/source-map-js","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/source-map-js","docker_dependents_count":18600,"docker_downloads_count":7865388562,"usage_url":"https://repos.ecosyste.ms/usage/npm/source-map-js","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/source-map-js/dependencies","status":null,"funding_links":[],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/source-map-js/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/source-map-js/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/source-map-js/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/source-map-js/related_packages","maintainers":[{"uuid":"7rulnik","login":"7rulnik","name":null,"email":"v7rulnik@gmail.com","url":null,"packages_count":8,"html_url":"https://www.npmjs.com/~7rulnik","role":null,"created_at":"2022-11-21T13:51:21.094Z","updated_at":"2022-11-21T13:51:21.094Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/7rulnik/packages"}],"registry":{"name":"npmjs.org","url":"https://registry.npmjs.org","ecosystem":"npm","default":true,"packages_count":5007759,"maintainers_count":1013018,"namespaces_count":295512,"keywords_count":700181,"github":"npm","metadata":{"funded_packages_count":150239},"icon_url":"https://github.com/npm.png","created_at":"2022-04-04T15:19:23.081Z","updated_at":"2025-06-06T05:58:05.971Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/namespaces"}},"unique_repositories_count":86,"unique_repositories_count_past_30_days":79,"recent_issues":[{"uuid":"5737597971","node_id":"PR_kwDORbkv688AAAABHBqWbA","number":130,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-07T00:58:04.000Z","updated_at":"2026-10-07T00:58:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"sharp","old_version":"0.35.4","new_version":"0.35.5","repository_url":"https://github.com/lovell/sharp"},{"name":"http-cache-semantics","old_version":"4.2.0","new_version":"4.3.0","repository_url":"https://github.com/kornelski/http-cache-semantics"},{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 3 updates in the /docs-site directory: [sharp](https://github.com/lovell/sharp), [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) and [source-map-js](https://github.com/7rulnik/source-map-js).\n\nUpdates `sharp` from 0.35.4 to 0.35.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.5\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.4\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdd upper bounds check on length of \u003ccode\u003elinear\u003c/code\u003e and GIF \u003ccode\u003edelay\u003c/code\u003e arrays.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error handing when WebAssembly fallback also fails.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4593\"\u003e#4593\u003c/a\u003e\n\u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Allow multi-frame options for JXL output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4602\"\u003e#4602\u003c/a\u003e\n\u003ca href=\"https://github.com/ramin-010\"\u003e\u003ccode\u003e@​ramin-010\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Remove non-existent named export.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4604\"\u003e#4604\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIncrease accepted dimensions when extending an image.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4605\"\u003e#4605\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove gain map support for \u003ccode\u003eextract\u003c/code\u003e and \u003ccode\u003erotate\u003c/code\u003e operations.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTests: Ensure composite tests pass on big endian platforms.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4609\"\u003e#4609\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.5-rc.1\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdd upper bounds check on length of \u003ccode\u003elinear\u003c/code\u003e and GIF \u003ccode\u003edelay\u003c/code\u003e arrays.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error handing when WebAssembly fallback also fails.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4593\"\u003e#4593\u003c/a\u003e\n\u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Allow multi-frame options for JXL output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4602\"\u003e#4602\u003c/a\u003e\n\u003ca href=\"https://github.com/ramin-010\"\u003e\u003ccode\u003e@​ramin-010\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Remove non-existent named export.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4604\"\u003e#4604\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIncrease accepted dimensions when extending an image.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4605\"\u003e#4605\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove gain map support for \u003ccode\u003eextract\u003c/code\u003e operation.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/51a990faa26ade5586a4934ac9673c98d8893326\"\u003e\u003ccode\u003e51a990f\u003c/code\u003e\u003c/a\u003e Release v0.35.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236\"\u003e\u003ccode\u003e96de105\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/3a61390260e0aa017046af9ad107abd62f3c98c0\"\u003e\u003ccode\u003e3a61390\u003c/code\u003e\u003c/a\u003e CI: Configure Dependabot with all package.json locations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/4940c500a63a9193b1ad5d3804a2d241ca36995b\"\u003e\u003ccode\u003e4940c50\u003c/code\u003e\u003c/a\u003e Improve gain map support for rotate/flip/flop ops\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/20654aa60eaa85a37369ef69a7ca6506b65f8c85\"\u003e\u003ccode\u003e20654aa\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.5-rc.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ef4f9348a97053ceddacd23dcb6e39cce5a1fc7d\"\u003e\u003ccode\u003eef4f934\u003c/code\u003e\u003c/a\u003e CI: Upgrade to Ubuntu 26.04\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/358df954c5f58487392e1a9af743e112e8998d67\"\u003e\u003ccode\u003e358df95\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/49f4903d34eddcd68b79872c511c198f124885a3\"\u003e\u003ccode\u003e49f4903\u003c/code\u003e\u003c/a\u003e Improve gain map support for rotate-then-extract \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/0e2e55eb3a44da5d602adedd6b51a03e652e3b20\"\u003e\u003ccode\u003e0e2e55e\u003c/code\u003e\u003c/a\u003e Silence a couple of compiler/static analysis warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/cef3b8c467c21f7e84bd51d5e53f2d115669f8d8\"\u003e\u003ccode\u003ecef3b8c\u003c/code\u003e\u003c/a\u003e Improve gain map support for extract operation \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.35.4...v0.35.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `http-cache-semantics` from 4.2.0 to 4.3.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/kornelski/http-cache-semantics/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/mlorentedev/garsync/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/mlorentedev/garsync/pull/130","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mlorentedev%2Fgarsync/issues/130","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/130/packages"},{"uuid":"5737112759","node_id":"PR_kwDOTGgQTc8AAAABHBRdjw","number":23,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-07T00:06:17.000Z","updated_at":"2026-10-07T00:08:26.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/lemduc/wings-vs-claws/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/lemduc/wings-vs-claws/pull/23","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/lemduc%2Fwings-vs-claws/issues/23","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/23/packages"},{"uuid":"5737079811","node_id":"PR_kwDONNFxvc8AAAABHBPzEQ","number":431,"state":"closed","title":"chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /frontend","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-10-07T00:30:52.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-07T00:02:28.000Z","updated_at":"2026-10-07T00:32:22.000Z","time_to_close":1704,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/frontend","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/msgmate-io/open-chat-go/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/msgmate-io/open-chat-go/pull/431","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/msgmate-io%2Fopen-chat-go/issues/431","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/431/packages"},{"uuid":"5736784693","node_id":"PR_kwDOA0RAO88AAAABHBA4PA","number":3731,"state":"open","title":"build(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in the npm_and_yarn group across 1 directory","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T23:30:36.000Z","updated_at":"2026-10-06T23:38:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps-dev)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"the npm_and_yarn group across 1 directory","ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [source-map-js](https://github.com/7rulnik/source-map-js).\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolanmiu/docx/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/dolanmiu/docx/pull/3731","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dolanmiu%2Fdocx/issues/3731","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3731/packages"},{"uuid":"5736265529","node_id":"PR_kwDOQGK4a88AAAABHAmmYg","number":32,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T22:29:56.000Z","updated_at":"2026-10-06T22:30:27.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/byjg/shellscript-download/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/byjg/shellscript-download/pull/32","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/byjg%2Fshellscript-download/issues/32","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/32/packages"},{"uuid":"5736254090","node_id":"PR_kwDOHHUq_M8AAAABHAmBRg","number":1850,"state":"closed","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-10-06T22:36:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-06T22:28:41.000Z","updated_at":"2026-10-06T22:36:22.000Z","time_to_close":459,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ArnaudFlaesch/CashManager/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ArnaudFlaesch/CashManager/pull/1850","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ArnaudFlaesch%2FCashManager/issues/1850","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1850/packages"},{"uuid":"5735867609","node_id":"PR_kwDOB5fEFs8AAAABHASQ9g","number":1123,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:48:40.000Z","updated_at":"2026-10-06T22:25:44.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/doctrine/doctrine-website/pull/1123","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/doctrine%2Fdoctrine-website/issues/1123","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1123/packages"},{"uuid":"5735768352","node_id":"PR_kwDOUx7v_M8AAAABHANOUw","number":6,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:39:06.000Z","updated_at":"2026-10-06T21:40:28.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/an0n7os/goodwill-new/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/an0n7os/goodwill-new/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/an0n7os%2Fgoodwill-new/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"5735761445","node_id":"PR_kwDOTcn5Ts8AAAABHAM3sQ","number":33,"state":"open","title":"chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:38:26.000Z","updated_at":"2026-10-06T21:38:27.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps-dev)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/discrete-event-systems/discrete-event-systems.github.io/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/discrete-event-systems/discrete-event-systems.github.io/pull/33","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/discrete-event-systems%2Fdiscrete-event-systems.github.io/issues/33","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/33/packages"},{"uuid":"5735570377","node_id":"PR_kwDOSWmRmc8AAAABHADH-Q","number":1061,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2 in /docs","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:20:35.000Z","updated_at":"2026-10-06T21:25:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/docs","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/amiantos/lurker/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/amiantos/lurker/pull/1061","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/amiantos%2Flurker/issues/1061","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1061/packages"},{"uuid":"5735155958","node_id":"PR_kwDOADgiC88AAAABG_uFeA","number":22481,"state":"open","title":"fix(deps): bump source-map-js from 1.2.1 to 1.2.2 in /tooling/comparison/html-tool-comparison","user":"dependabot[bot]","labels":["dependencies","area: tooling"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T20:44:33.000Z","updated_at":"2026-10-06T20:46:53.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"fix(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/tooling/comparison/html-tool-comparison","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/webpack/webpack/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/webpack/webpack/pull/22481","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpack%2Fwebpack/issues/22481","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22481/packages"},{"uuid":"5735155158","node_id":"PR_kwDOADgiC88AAAABG_uC4Q","number":22480,"state":"closed","title":"fix(deps): bump source-map-js from 1.2.1 to 1.2.2 in /tooling/comparison/js-tool-comparison","user":"dependabot[bot]","labels":["dependencies","area: tooling"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":"2026-10-06T20:52:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-06T20:44:30.000Z","updated_at":"2026-10-06T21:03:25.000Z","time_to_close":501,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"fix(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/tooling/comparison/js-tool-comparison","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/webpack/webpack/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/webpack/webpack/pull/22480","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpack%2Fwebpack/issues/22480","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22480/packages"},{"uuid":"5734738254","node_id":"PR_kwDORujkJ88AAAABG_Yotg","number":23,"state":"open","title":"chore(deps): Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T20:09:42.000Z","updated_at":"2026-10-06T20:10:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dota1337/metastats/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Dota1337/metastats/pull/23","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dota1337%2Fmetastats/issues/23","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/23/packages"},{"uuid":"5734427942","node_id":"PR_kwDOQpCEsc8AAAABG_Im7g","number":1,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 17 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:44:07.000Z","updated_at":"2026-10-06T19:48:51.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":17,"packages":[{"name":"ai","old_version":"4.3.19","new_version":"5.0.52","repository_url":"https://github.com/vercel/ai"},{"name":"next","old_version":"16.0.10","new_version":"16.3.6","repository_url":"https://github.com/vercel/next.js"},{"name":"postcss","old_version":"8.5.6","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"@ai-sdk/provider-utils","old_version":"2.2.8","new_version":"5.0.54","repository_url":"https://github.com/vercel/ai"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.21","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"minimatch","old_version":"3.1.2","new_version":"3.1.5","repository_url":"https://github.com/isaacs/minimatch"},{"name":"baseline-browser-mapping","old_version":"2.9.7","new_version":"2.11.27","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.1","new_version":"4.29.3","repository_url":"https://github.com/browserslist/browserslist"},{"name":"flatted","old_version":"3.3.3","new_version":"3.4.4","repository_url":"https://github.com/WebReflection/flatted"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"lodash","old_version":"4.17.21","new_version":"4.18.1","repository_url":"https://github.com/lodash/lodash"},{"name":"nanoid","old_version":"3.3.11","new_version":"3.3.20","repository_url":"https://github.com/ai/nanoid"},{"name":"picomatch","old_version":"2.3.1","new_version":"2.3.2","repository_url":"https://github.com/micromatch/picomatch"},{"name":"picomatch","old_version":"4.0.3","new_version":"4.0.7","repository_url":"https://github.com/micromatch/picomatch"},{"name":"postcss-selector-parser","old_version":"6.1.2","new_version":"removed","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.5","repository_url":"https://github.com/lovell/sharp"},{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 17 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `4.3.19` | `5.0.52` |\n| [next](https://github.com/vercel/next.js) | `16.0.10` | `16.3.6` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.6` | `8.5.23` |\n| [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils) | `2.2.8` | `5.0.54` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.21` |\n| [minimatch](https://github.com/isaacs/minimatch) | `3.1.2` | `3.1.5` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.9.7` | `2.11.27` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.29.3` |\n| [flatted](https://github.com/WebReflection/flatted) | `3.3.3` | `3.4.4` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.20` |\n| [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` |\n| [picomatch](https://github.com/micromatch/picomatch) | `4.0.3` | `4.0.7` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `removed` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.5` |\n| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |\n\n\nUpdates `ai` from 4.3.19 to 5.0.52\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md\"\u003eai's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eai\u003c/h1\u003e\n\u003ch2\u003e7.0.128\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e0fe8c67: fix: preserve tool approval state when resuming streams\u003c/li\u003e\n\u003cli\u003e2959d35: feat: rename \u003ccode\u003eevaluate\u003c/code\u003e to \u003ccode\u003edecide\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e0ca1ab9: Add durable non-streaming \u003ccode\u003eWorkflowAgent.generate()\u003c/code\u003e with a shared tool loop, a 20-step default, typed output, and core generation result semantics. Reuse core result and content construction through internal exports while preserving existing Workflow streaming behavior. Transport-independent approval creation remains separate follow-up work.\u003c/li\u003e\n\u003cli\u003ed6b42fd: feat(ai): support custom reasoning delimiters in extractReasoningMiddleware\u003c/li\u003e\n\u003cli\u003eed6e72d: fix(ai): return successful empty transcripts for silent audio\u003c/li\u003e\n\u003cli\u003e2136151: Throw \u003ccode\u003eInvalidResponseDataError\u003c/code\u003e instead of a generic \u003ccode\u003eError\u003c/code\u003e when a generated audio file's format cannot be determined from its media type, so callers can identify the failure with \u003ccode\u003eAISDKError.isInstance\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [131532b]\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [2959d35]\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [59116e6]\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [6ac923a]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/gateway\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.104\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.22\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider-utils\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.0.54\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.127\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e158a718: feat(ai): select and rank eligible deferred tools via 'search()' callback in tool search\u003c/li\u003e\n\u003cli\u003ebb8d33e: fix(ai): cancel merged UI message streams when the consumer disconnects\u003c/li\u003e\n\u003cli\u003e284dc11: fix(ai): accept unchanged tool approval inputs created in another JavaScript realm\u003c/li\u003e\n\u003cli\u003eba8afe9: feat(ai): add a configurable maxResults for number of tools returned in tool search\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [d1bb9e8]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/gateway\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.103\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.126\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e4f3d236: fix: clear tool approvals when \u003ccode\u003eaddToolOutput\u003c/code\u003e runs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.125\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eff3dcef: feat(ai): add \u003ccode\u003econvertDataPart\u003c/code\u003e to agent UI stream helpers\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.124\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e8c65988: feat(ai): add telemetry to speech generation and transcription, including\nprovider usage propagation and experimental streaming lifecycle callbacks\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [8c65988]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/63d5f669098343a49173d788fe1490127e882bd1\"\u003e\u003ccode\u003e63d5f66\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8895\"\u003e#8895\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed\"\u003e\u003ccode\u003e930399b\u003c/code\u003e\u003c/a\u003e Backport: fix(ai): download files when intermediate file cannot be downloaded...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/85909a9f6448c7e6eb52d780abcca4f96679e719\"\u003e\u003ccode\u003e85909a9\u003c/code\u003e\u003c/a\u003e Backport: chore(ai): update test message (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8875\"\u003e#8875\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/c56822dd81d5d70bcd5ef230a875f96a224849a4\"\u003e\u003ccode\u003ec56822d\u003c/code\u003e\u003c/a\u003e Backport: fix(ai): update \u003ccode\u003euiMessageChunkSchema\u003c/code\u003e to satisfy the `UIMessageChu...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/6bd07df02d9f954b389e44da128fc6d1358462d9\"\u003e\u003ccode\u003e6bd07df\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8853\"\u003e#8853\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/27645bb653b24dd7e285df7848154f86af309451\"\u003e\u003ccode\u003e27645bb\u003c/code\u003e\u003c/a\u003e Backport: Export \u003ccode\u003eparseJsonEventStream\u003c/code\u003e and \u003ccode\u003euiMessageChunkSchema\u003c/code\u003e from \u0026quot;ai\u0026quot; ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/8b7f0d2eac987a0066befd46a0119d533b1e65e2\"\u003e\u003ccode\u003e8b7f0d2\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8843\"\u003e#8843\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/9eef1982d2d40e190300b3b02d7edafbf5a8b0af\"\u003e\u003ccode\u003e9eef198\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8831\"\u003e#8831\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/20bca657c4ebd3cbef370e4a093818cbf0f84eca\"\u003e\u003ccode\u003e20bca65\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8799\"\u003e#8799\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/4254096b7ffb1d96e3f6a1926ccfffaa1799280f\"\u003e\u003ccode\u003e4254096\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8753\"\u003e#8753\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/ai/commits/ai@5.0.52/packages/ai\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.0.10 to 16.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.6\u003c/h2\u003e\n\u003cp\u003eThis release contains a security fix for \u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j\"\u003eGHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a758ffcf501f6f1ddb03175bd1033508424c261e\"\u003e\u003ccode\u003ea758ffc\u003c/code\u003e\u003c/a\u003e v16.3.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e\"\u003e\u003ccode\u003e868fad3\u003c/code\u003e\u003c/a\u003e [active-lts] Harden next/og SVG serialization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/8c81cbb30a7f667ed74806d984f8117ee97f4665\"\u003e\u003ccode\u003e8c81cbb\u003c/code\u003e\u003c/a\u003e [lts-active] test: remove unsupported deployment ID builder cases (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98821\"\u003e#98821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.0.10...v16.3.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.6 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.6...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@ai-sdk/provider-utils` from 2.2.8 to 5.0.54\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/ai/releases\"\u003e@​ai-sdk/provider-utils's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​ai-sdk/provider-utils\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.0.54\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e2959d35: feat: rename \u003ccode\u003eevaluate\u003c/code\u003e to \u003ccode\u003edecide\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e59116e6: fix(groq,google): use JSON response tool for structured outputs with tool calling\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [2959d35]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.22\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/ai/blob/main/packages/provider-utils/CHANGELOG.md\"\u003e@​ai-sdk/provider-utils's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.54\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e2959d35: feat: rename \u003ccode\u003eevaluate\u003c/code\u003e to \u003ccode\u003edecide\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e59116e6: fix(groq,google): use JSON response tool for structured outputs with tool calling\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [2959d35]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.22\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.53\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e8c65988: feat(ai): add telemetry to speech generation and transcription, including\nprovider usage propagation and experimental streaming lifecycle callbacks\u003c/li\u003e\n\u003cli\u003e527a163: fix: validate hostname parts using \u003ccode\u003eisValidHostnamePart\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [8c65988]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.21\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.52\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eede5b89: chore: migrate package builds from tsup to tsdown\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [ede5b89]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.20\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.51\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ec2511c1: fix: use standards-compliant User-Agent header\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.50\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ee3605f6: Fix streamed tool calls with missing, blank, or repeated IDs.\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [525efc5]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.19\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.49\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eaf9597b: Compile packages for ES2022 runtime target\u003c/li\u003e\n\u003cli\u003ebc49f78: Preserve original opaque URI strings in tagged file URLs during prompt conversion. Match explicit supported URL MIME types exactly so unsupported subtypes are not forwarded to providers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.48\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/92e2a4b31bd7982e960c142de1081be3e112cea7\"\u003e\u003ccode\u003e92e2a4b\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21938\"\u003e#21938\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/2959d35d2ffd1eea92311a4f21811fbd0181ce05\"\u003e\u003ccode\u003e2959d35\u003c/code\u003e\u003c/a\u003e refactor(ai): rename experimental_evaluate to experimental_decide (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21935\"\u003e#21935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/59116e6952784647bcf50f493319b52fc9463417\"\u003e\u003ccode\u003e59116e6\u003c/code\u003e\u003c/a\u003e fix(groq,google): use JSON response tool for structured outputs with tool cal...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/eb93c81f2d6200e0732745d0cd582600fe4c5055\"\u003e\u003ccode\u003eeb93c81\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21822\"\u003e#21822\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/527a1637bfbc1df92a708f5cc78a8011521711eb\"\u003e\u003ccode\u003e527a163\u003c/code\u003e\u003c/a\u003e fix: validate hostname parts (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21842\"\u003e#21842\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/8c659885c52ef519b21b3af1ff266d843e3c157f\"\u003e\u003ccode\u003e8c65988\u003c/code\u003e\u003c/a\u003e feat: support telemetry for speech generation and streaming and non-streaming...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/161a7fdb9783d88b0ea25fe522fbda0233d83427\"\u003e\u003ccode\u003e161a7fd\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21718\"\u003e#21718\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/ede5b890d6760ead18da248a97861d7bba9a4703\"\u003e\u003ccode\u003eede5b89\u003c/code\u003e\u003c/a\u003e chore: move from \u003ccode\u003etsup\u003c/code\u003e to \u003ccode\u003etsdown\u003c/code\u003e (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21642\"\u003e#21642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/1040e97e72cab8a443aeed818520d8b8161d4c1c\"\u003e\u003ccode\u003e1040e97\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21638\"\u003e#21638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/c2511c1d65c1756ef70887de0c8baae4bcc77bf8\"\u003e\u003ccode\u003ec2511c1\u003c/code\u003e\u003c/a\u003e fix: use standards-compliant User-Agent header (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21344\"\u003e#21344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/ai/commits/@ai-sdk/provider-utils@5.0.54/packages/provider-utils\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​ai-sdk/provider-utils\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.21\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/8e81e187b6e9c6c723d16c042657c00acefc2483\"\u003e\u003ccode\u003e8e81e18\u003c/code\u003e\u003c/a\u003e 1.1.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e\"\u003e\u003ccode\u003effdfa3e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c6513ad31e08edb56dc414a629e39cba724b7548\"\u003e\u003ccode\u003ec6513ad\u003c/code\u003e\u003c/a\u003e 1.1.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b\"\u003e\u003ccode\u003e1efee7c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/a34340a053abb475cc226aeb3f71887018e71bd0\"\u003e\u003ccode\u003ea34340a\u003c/code\u003e\u003c/a\u003e 1.1.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc\"\u003e\u003ccode\u003e0bcbfc0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.21\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `minimatch` from 3.1.2 to 3.1.5\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/7bba97888a27a6162983056bcce2a6e28f668712\"\u003e\u003ccode\u003e7bba978\u003c/code\u003e\u003c/a\u003e 3.1.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/bd259425b2ca17b42897997f93e890314155522d\"\u003e\u003ccode\u003ebd25942\u003c/code\u003e\u003c/a\u003e docs: add warning about ReDoS\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/1a9c27c75725474dbde57db2995b6281b267756d\"\u003e\u003ccode\u003e1a9c27c\u003c/code\u003e\u003c/a\u003e fix partial matching of globstar patterns\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/1a2e084af579731af66c221214e3ca8222c9bf23\"\u003e\u003ccode\u003e1a2e084\u003c/code\u003e\u003c/a\u003e 3.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/ae24656237c3d58067442f790ce17eff84463a47\"\u003e\u003ccode\u003eae24656\u003c/code\u003e\u003c/a\u003e update lockfile\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/b1003749228b2a79e1f237963a0d559ef7a0941e\"\u003e\u003ccode\u003eb100374\u003c/code\u003e\u003c/a\u003e limit recursion for **, improve perf considerably\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/26ffeaa091b9f660833e23f42e07165b33e85c13\"\u003e\u003ccode\u003e26ffeaa\u003c/code\u003e\u003c/a\u003e lockfile update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/9eca892a4e5dbb20534f9f30483b85cdeee6c2eb\"\u003e\u003ccode\u003e9eca892\u003c/code\u003e\u003c/a\u003e lock node version to 14\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/00c323b188b704e5d4bc534ecec2268cfa70a32a\"\u003e\u003ccode\u003e00c323b\u003c/code\u003e\u003c/a\u003e 3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/30486b2048929264f44d18822891cfffa02af78b\"\u003e\u003ccode\u003e30486b2\u003c/code\u003e\u003c/a\u003e update CI matrix and actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `baseline-browser-mapping` from 2.9.7 to 2.11.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/releases\"\u003ebaseline-browser-mapping's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed in 2.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Adds a new \u003ccode\u003egetTimeline()\u003c/code\u003e method for getting the series of minimum browser changes, either grouped by date or by browser.\u003c/li\u003e\n\u003cli\u003erefactor: Substantial refactoring of the data compression process that replaces the full list of browsers from \u003ccode\u003e@mdn/browser-compat-data\u003c/code\u003e and \u003ccode\u003edownstream-browsers.json\u003c/code\u003e and features from \u003ccode\u003eweb-features\u003c/code\u003e (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date.  Thanks to \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e for the idea!\u003c/li\u003e\n\u003cli\u003erefactor: Some common functions have been moved to a \u003ccode\u003eutil.ts\u003c/code\u003e module for use in other scripts.\u003c/li\u003e\n\u003cli\u003efix: Removes \u003ccode\u003eprocess.exit()\u003c/code\u003e calls when unsupported option combinations are passed to getCompatibleVersions() and \u003ccode\u003egetAllVersions()\u003c/code\u003e in favour of throwing an \u003ccode\u003eError\u003c/code\u003e.  There is a small security risk with \u003ccode\u003eprocess.exit()\u003c/code\u003e calls that sites accepting unsanitised inputs could be the subject of attacks.  Unsupported config options now throw and Error which should allow for more graceful handling.  Thanks to \u003ca href=\"https://github.com/bnbdr\"\u003e\u003ccode\u003e@​bnbdr\u003c/code\u003e\u003c/a\u003e for flagging this as vulnerability CVE-2026-45819 .\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes \u003ca href=\"https://redirect.github.com/web-platform-dx/baseline-browser-mapping/issues/134\"\u003e#134\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduces support for Node 6 by refactoring all \u003ccode\u003eObject.entries\u003c/code\u003e and \u003ccode\u003eObject.values\u003c/code\u003e instances and lowering ES target in Rollup to \u003ccode\u003ees2015\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdds specified Node version support in package.json for \u0026gt;=6.0.0.\u003c/li\u003e\n\u003cli\u003eRefactors CLI code to avoid \u003ccode\u003eparseArgs\u003c/code\u003e which is not supported by versions of Node prior to 18, changes \u003ccode\u003eimport\u003c/code\u003e to \u003ccode\u003erequire\u003c/code\u003e and changes Rollup export to \u003ccode\u003ecjs\u003c/code\u003e to allow execution on older versions of Node.\u003c/li\u003e\n\u003cli\u003eAdds a new \u003ccode\u003elegacy-test.js\u003c/code\u003e file that allows basic testing on older versions of Node where current versions of Jasmine and ESLint are not supported.\u003c/li\u003e\n\u003cli\u003eAdds a test matrix to run tests on all even-numbered Node versions from 6 to 24.\u003c/li\u003e\n\u003cli\u003erefactor publish workflows to support NPM's new OIDC integration\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.9.24...v2.10.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.9.24...v2.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/6141d06f254525dcc3902ee1b153a835fc845522\"\u003e\u003ccode\u003e6141d06\u003c/code\u003e\u003c/a\u003e Patch to 2.11.27 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/e1d166be08e0eab6f6d71533772d1c9202798abb\"\u003e\u003ccode\u003ee1d166b\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/42972a7ab3bad1c0c74edda376443010dbaa127c\"\u003e\u003ccode\u003e42972a7\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/c1934c691d39aa9cf0c25626b91e1e5c6efd53ce\"\u003e\u003ccode\u003ec1934c6\u003c/code\u003e\u003c/a\u003e Patch to 2.11.26 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/487368484af4ff9aba321be0ac65bf9a8dab3d34\"\u003e\u003ccode\u003e4873684\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/9030798a5922aa76e94db887aeed97daaf2dfb1b\"\u003e\u003ccode\u003e9030798\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/a5df351eb505078f62bf07477d3583fa9df51e5b\"\u003e\u003ccode\u003ea5df351\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ecc5b5451be2d79318b261366f19e0ca387c268d\"\u003e\u003ccode\u003eecc5b54\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/719bf7ab47f710422fc87bb722f87b93ddb745d8\"\u003e\u003ccode\u003e719bf7a\u003c/code\u003e\u003c/a\u003e Patch to 2.11.25 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/c4f5b49cebb0fdd301619124224f92f19e80543f\"\u003e\u003ccode\u003ec4f5b49\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.9.7...v2.11.27\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for baseline-browser-mapping since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.1 to 4.29.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.29.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed ignoring \u003ccode\u003enull\u003c/code\u003e usage in \u003ccode\u003ecover X in Y\u003c/code\u003e query (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed config name loading protection on Windows (by \u003ca href=\"https://github.com/oss-security-shop\"\u003e\u003ccode\u003e@​oss-security-shop\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed case-insensitive negation queries (by \u003ca href=\"https://github.com/jakezwang\"\u003e\u003ccode\u003e@​jakezwang\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed percentage and supports queries case-insensitive (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed old Node.js tests (by \u003ca href=\"https://github.com/aaron-belenky\"\u003e\u003ccode\u003e@​aaron-belenky\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eReduced code (by \u003ca href=\"https://github.com/charmander\"\u003e\u003ccode\u003e@​charmander\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded query continuations across lines and array entries (by \u003ca href=\"https://github.com/fzlzjerry\"\u003e\u003ccode\u003e@​fzlzjerry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix prototype pollution (by \u003ca href=\"https://github.com/chluo1997\"\u003e\u003ccode\u003e@​chluo1997\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.29.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed ignoring \u003ccode\u003enull\u003c/code\u003e usage in \u003ccode\u003ecover X in Y\u003c/code\u003e query (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed config name loading protection on Windows (by \u003ca href=\"https://github.com/oss-security-shop\"\u003e\u003ccode\u003e@​oss-security-shop\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed case-insensitive negation queries (by \u003ca href=\"https://github.com/jakezwang\"\u003e\u003ccode\u003e@​jakezwang\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed percentage and supports queries case-insensitive (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed old Node.js tests (by \u003ca href=\"https://github.com/aaron-belenky\"\u003e\u003ccode\u003e@​aaron-belenky\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eReduced code (by \u003ca href=\"https://github.com/charmander\"\u003e\u003ccode\u003e@​charmander\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded query continuations across lines and array entries (by \u003ca href=\"https://github.com/fzlzjerry\"\u003e\u003ccode\u003e@​fzlzjerry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b4809dd2a2a11fbff492258f968130e9b470067f\"\u003e\u003ccode\u003eb4809dd\u003c/code\u003e\u003c/a\u003e Release 4.29.3 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/9d844f8d09c872e2f22e07daa8566fb53585c190\"\u003e\u003ccode\u003e9d844f8\u003c/code\u003e\u003c/a\u003e Update Firefox ESR\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/0033f344c3be446c935f9e515a366738fc0942a5\"\u003e\u003ccode\u003e0033f34\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/906d329968d968479474aab97ae2ab712bf18b5f\"\u003e\u003ccode\u003e906d329\u003c/code\u003e\u003c/a\u003e Release 4.29.2 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/ff8c83f72dd22e3331e89404487a19ec4ea6d5fc\"\u003e\u003ccode\u003eff8c83f\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/067f4a1fa37047e8a53b369cb1fd837399f5d5d5\"\u003e\u003ccode\u003e067f4a1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/952\"\u003e#952\u003c/a\u003e from wahidrizka/fix-cover-null-usage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f760921db5e420bd8c10e31d0278ab16fdbb9a2d\"\u003e\u003ccode\u003ef760921\u003c/code\u003e\u003c/a\u003e Do not add versions without usage data to cover queries\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5be63f54fc37cef2db22930bdabfafcb22b6fd46\"\u003e\u003ccode\u003e5be63f5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/953\"\u003e#953\u003c/a\u003e from wahidrizka/docs-android-latest-version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/1e5356f16429cb8a30dfa5415c7d0beddff8548f\"\u003e\u003ccode\u003e1e5356f\u003c/code\u003e\u003c/a\u003e Note that Android version queries return only the latest version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5b7e94169750cedd9e63fdb8d2419542d3aa185f\"\u003e\u003ccode\u003e5b7e941\u003c/code\u003e\u003c/a\u003e Add missed changes to ChangeLog\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.1...4.29.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for browserslist since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `flatted` from 3.3.3 to 3.4.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/e6f5ca700c4ca8104a6a83472c8219e267bd5e84\"\u003e\u003ccode\u003ee6f5ca7\u003c/code\u003e\u003c/a\u003e 3.4.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/47f14fac0b1a41989f216b0cda4c50596ca339f6\"\u003e\u003ccode\u003e47f14fa\u003c/code\u003e\u003c/a\u003e removed E_STRICT from PHP\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/40505688464c49fe6374e7bc4cdd9bd2e9e6f330\"\u003e\u003ccode\u003e4050568\u003c/code\u003e\u003c/a\u003e fixced go-lang issues in CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/4303f4db38ba0ba8d5e2ed6e9689cefc74c46b63\"\u003e\u003ccode\u003e4303f4d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/101\"\u003e#101\u003c/a\u003e from mfinelli/gocriticfixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/106735b609c15df51539a0d7c0a270182efd904c\"\u003e\u003ccode\u003e106735b\u003c/code\u003e\u003c/a\u003e updated package-lock.json\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/670a1bdf9dcfba02111c3034294366f10696fb53\"\u003e\u003ccode\u003e670a1bd\u003c/code\u003e\u003c/a\u003e 3.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/50a61a90ea5ca64c114f0aa040ad127e3a97feff\"\u003e\u003ccode\u003e50a61a9\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/104\"\u003e#104\u003c/a\u003e - allow \u003ccode\u003enull\u003c/code\u003e as replacer value\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/8aa64f460cf0c4dac9cc214c831aade28f8f2c6e\"\u003e\u003ccode\u003e8aa64f4\u003c/code\u003e\u003c/a\u003e solved crytical errors over dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/b85577f39ff85959d02e8862cc0dde8114b43762\"\u003e\u003ccode\u003eb85577f\u003c/code\u003e\u003c/a\u003e Fix go-critic errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/bb8c63cea5befd4315519cb4458c6fc07bb9cf7b\"\u003e\u003ccode\u003ebb8c63c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/100\"\u003e#100\u003c/a\u003e from WebReflection/WebReflection-patch-1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/WebReflection/flatted/compare/v3.3.3...v3.4.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lodash` from 4.17.21 to 4.18.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lodash/lodash/releases\"\u003elodash's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.18.1\u003c/h2\u003e\n\u003ch2\u003eBugs\u003c/h2\u003e\n\u003cp\u003eFixes a \u003ccode\u003eReferenceError\u003c/code\u003e issue in \u003ccode\u003elodash\u003c/code\u003e \u003ccode\u003elodash-es\u003c/code\u003e \u003ccode\u003elodash-amd\u003c/code\u003e and \u003ccode\u003elodash.template\u003c/code\u003e when using the \u003ccode\u003etemplate\u003c/code\u003e and \u003ccode\u003efromPairs\u003c/code\u003e functions from the modular builds. See \u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769\"\u003elodash/lodash#6167\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThese defects were related to how lodash distributions are built from the main branch using \u003ca href=\"https://github.com/lodash-archive/lodash-cli\"\u003ehttps://github.com/lodash-archive/lodash-cli\u003c/a\u003e. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.\u003c/p\u003e\n\u003cp\u003eThere is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elodash\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-es\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-amd\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash.template\u003c/code\u003e\u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.18.0\u003c/h2\u003e\n\u003ch2\u003ev4.18.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.23...4.18.0\"\u003ehttps://github.com/lodash/lodash/compare/4.17.23...4.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.unset\u003c/code\u003e / \u003ccode\u003e_.omit\u003c/code\u003e\u003c/strong\u003e: Fixed prototype pollution via \u003ccode\u003econstructor\u003c/code\u003e/\u003ccode\u003eprototype\u003c/code\u003e path traversal (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh\"\u003eGHSA-f23m-r3pf-42rh\u003c/a\u003e, \u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003efe8d32e\u003c/a\u003e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now \u003ccode\u003econstructor\u003c/code\u003e and \u003ccode\u003eprototype\u003c/code\u003e are blocked unconditionally as non-terminal path keys, matching \u003ccode\u003ebaseSet\u003c/code\u003e. Calls that previously returned \u003ccode\u003etrue\u003c/code\u003e and deleted the property now return \u003ccode\u003efalse\u003c/code\u003e and leave the target untouched.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.template\u003c/code\u003e\u003c/strong\u003e: Fixed code injection via \u003ccode\u003eimports\u003c/code\u003e keys (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc\"\u003eGHSA-r5fr-rjxr-66jc\u003c/a\u003e, CVE-2026-4800, \u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e879aaa9\u003c/a\u003e). Fixes an incomplete patch for CVE-2021-23337. The \u003ccode\u003evariable\u003c/code\u003e option was validated against \u003ccode\u003ereForbiddenIdentifierChars\u003c/code\u003e but \u003ccode\u003eimportsKeys\u003c/code\u003e was left unguarded, allowing code injection via the same \u003ccode\u003eFunction()\u003c/code\u003e constructor sink. \u003ccode\u003eimports\u003c/code\u003e keys containing forbidden identifier characters now throw \u003ccode\u003e\u0026quot;Invalid imports option passed into _.template\u0026quot;\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd security notice for \u003ccode\u003e_.template\u003c/code\u003e in threat model and API docs (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6099\"\u003e#6099\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocument \u003ccode\u003elower \u0026gt; upper\u003c/code\u003e behavior in \u003ccode\u003e_.random\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6115\"\u003e#6115\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix quotes in \u003ccode\u003e_.compact\u003c/code\u003e jsdoc (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6090\"\u003e#6090\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003elodash.*\u003c/code\u003e modular packages\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6157\"\u003eDiff\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe have also regenerated and published a select number of the \u003ccode\u003elodash.*\u003c/code\u003e modular packages.\u003c/p\u003e\n\u003cp\u003eThese modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.orderby\"\u003elodash.orderby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.tonumber\"\u003elodash.tonumber\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trim\"\u003elodash.trim\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trimend\"\u003elodash.trimend\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.sortedindexby\"\u003elodash.sortedindexby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.zipobjectdeep\"\u003elodash.zipobjectdeep\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.unset\"\u003elodash.unset\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.omit\"\u003elodash.omit\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.template\"\u003elodash.template\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e\"\u003e\u003ccode\u003ecb0b9b9\u003c/code\u003e\u003c/a\u003e release(patch): bump main to 4.18.1 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6177\"\u003e#6177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51\"\u003e\u003ccode\u003e75535f5\u003c/code\u003e\u003c/a\u003e chore: prune stale advisory refs (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6170\"\u003e#6170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4\"\u003e\u003ccode\u003e62e91bc\u003c/code\u003e\u003c/a\u003e docs: remove n_ Node.js \u0026lt; 6 REPL note from README (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6165\"\u003e#6165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4\"\u003e\u003ccode\u003e59be2de\u003c/code\u003e\u003c/a\u003e release(minor): bump to 4.18.0 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6161\"\u003e#6161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d\"\u003e\u003ccode\u003eaf63457\u003c/code\u003e\u003c/a\u003e fix: broken tests for _.template 879aaa9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0\"\u003e\u003ccode\u003e1073a76\u003c/code\u003e\u003c/a\u003e fix: linting issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e\u003ccode\u003e879aaa9\u003c/code\u003e\u003c/a\u003e fix: validate imports keys in _.template\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003e\u003ccode\u003efe8d32e\u003c/code\u003e\u003c/a\u003e fix: block prototype pollution in baseUnset via constructor/prototype traversal\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d\"\u003e\u003ccode\u003e18ba0a3\u003c/code\u003e\u003c/a\u003e refactor(fromPairs): use baseAssignValue for consistent assignment (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6153\"\u003e#6153\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2\"\u003e\u003ccode\u003eb819080\u003c/code\u003e\u003c/a\u003e ci: add dist sync validation workflow (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6137\"\u003e#6137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.21...4.18.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.20\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/johnemau\"\u003e\u003ccode\u003e@​johnemau\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/johnemau\"\u003e\u003ccode\u003e@​johnemau\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/d76f633e0201c1299d735a6544c4c4a05c882f0b\"\u003e\u003ccode\u003ed76f633\u003c/code\u003e\u003c/a\u003e Release 3.3.20 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/ac09ff646dd64de1d03827c288ce30bb26c4315c\"\u003e\u003ccode\u003eac09ff6\u003c/code\u003e\u003c/a\u003e Fix: async return types are synchronous in v3 (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/615\"\u003e#615\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/co...\n\n_Description has been truncated_","html_url":"https://github.com/jmsmuigai/upili-app/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jmsmuigai%2Fupili-app/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5734152262","node_id":"PR_kwDOPUh5388AAAABG-6a_g","number":2102,"state":"open","title":"chore(deps): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":["CarmenDou"],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:22:06.000Z","updated_at":"2026-10-06T19:22:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/InsForge/InsForge/network/alerts).\n\n\u003c/details\u003e\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps `source-map-js` from 1.2.1 to 1.2.2 to fix CVE-2026-93749, a denial-of-service vulnerability in malicious indexed source maps. Also fixes a crash in browsers with CSP that disallows `unsafe-eval`. No breaking changes; only `package-lock.json` is updated.\n\n\u003csup\u003eWritten for commit c37547444f7fa506222243454b9de5e2737cc83e. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/InsForge/InsForge/pull/2102?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e \u003ca href=\"https://www.cubic.dev/action/auto-fix/pr/InsForge/InsForge/2102?returnTo=https%3A%2F%2Fgithub.com%2FInsForge%2FInsForge%2Fpull%2F2102\u0026source=description\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/turn-on-auto-fix-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/turn-on-auto-fix-light.svg\"\u003e\u003cimg alt=\"Turn on auto-fix\" src=\"https://www.cubic.dev/buttons/turn-on-auto-fix-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/InsForge/InsForge/pull/2102","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/InsForge%2FInsForge/issues/2102","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2102/packages"},{"uuid":"5733959373","node_id":"PR_kwDORsHvZs8AAAABG-wfnQ","number":42,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2 in the npm_and_yarn group across 1 directory","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:07:31.000Z","updated_at":"2026-10-06T19:08:12.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"the npm_and_yarn group across 1 directory","ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [source-map-js](https://github.com/7rulnik/source-map-js).\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Devam759/Sabrang-26/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Devam759/Sabrang-26/pull/42","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Devam759%2FSabrang-26/issues/42","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/42/packages"},{"uuid":"5733938226","node_id":"PR_kwDONuoEHs8AAAABG-vaXA","number":758,"state":"open","title":"chore(package.json): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:05:49.000Z","updated_at":"2026-10-06T19:06:12.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(package.json)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/diegocasmo/findmomentum.xyz/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/diegocasmo/findmomentum.xyz/pull/758","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/diegocasmo%2Ffindmomentum.xyz/issues/758","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/758/packages"},{"uuid":"5733548990","node_id":"PR_kwDOB5PDcM8AAAABG-buaQ","number":77,"state":"open","title":"chore(deps): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","npm"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T18:35:46.000Z","updated_at":"2026-10-06T18:37:51.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ctftnks/ctftnks.github.io/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ctftnks/ctftnks.github.io/pull/77","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ctftnks%2Fctftnks.github.io/issues/77","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/77/packages"},{"uuid":"5733392850","node_id":"PR_kwDOTJYz_s8AAAABG-TrRg","number":131,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-10-06T18:26:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-06T18:23:45.000Z","updated_at":"2026-10-06T18:26:01.000Z","time_to_close":136,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"},{"name":"compression","old_version":"1.8.1","new_version":"1.8.2","repository_url":"https://github.com/expressjs/compression"},{"name":"moment","old_version":"2.30.1","new_version":"2.31.0","repository_url":"https://github.com/moment/moment"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 3 updates in the /artifacts/aurora-mobile directory: [source-map-js](https://github.com/7rulnik/source-map-js), [compression](https://github.com/expressjs/compression) and [moment](https://github.com/moment/moment).\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `compression` from 1.8.1 to 1.8.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/compression/releases\"\u003ecompression's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.8.2\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-87776\"\u003eCVE-2026-87776\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95\"\u003eGHSA-vc2v-76pw-4v95\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: add funding to package.json by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/248\"\u003eexpressjs/compression#248\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 3.29.2 to 3.29.5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/249\"\u003eexpressjs/compression#249\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 4.2.2 to 5.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/253\"\u003eexpressjs/compression#253\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 3.29.7 to 3.29.11 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/252\"\u003eexpressjs/compression#252\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 4.3.0 to 5.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/251\"\u003eexpressjs/compression#251\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 4.4.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/261\"\u003eexpressjs/compression#261\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 3.29.11 to 4.31.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/260\"\u003eexpressjs/compression#260\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/259\"\u003eexpressjs/compression#259\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/258\"\u003eexpressjs/compression#258\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/264\"\u003eexpressjs/compression#264\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/263\"\u003eexpressjs/compression#263\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.2 to 4.31.5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/262\"\u003eexpressjs/compression#262\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: up node version to 25.x in CI by \u003ca href=\"https://github.com/imangas\"\u003e\u003ccode\u003e@​imangas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/272\"\u003eexpressjs/compression#272\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edoc(package): remove history.md and add readme.md to published files by \u003ca href=\"https://github.com/sheplu\"\u003e\u003ccode\u003e@​sheplu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/270\"\u003eexpressjs/compression#270\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate link to CONTRIBUTING.md by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/281\"\u003eexpressjs/compression#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: run CI on Windows and macOS by \u003ca href=\"https://github.com/kilisamemarisaaa\"\u003e\u003ccode\u003e@​kilisamemarisaaa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/283\"\u003eexpressjs/compression#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/257\"\u003eexpressjs/compression#257\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/268\"\u003eexpressjs/compression#268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.5 to 4.31.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/265\"\u003eexpressjs/compression#265\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/266\"\u003eexpressjs/compression#266\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/267\"\u003eexpressjs/compression#267\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): npm-publish via reusable workflows by \u003ca href=\"https://github.com/sheplu\"\u003e\u003ccode\u003e@​sheplu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/269\"\u003eexpressjs/compression#269\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update outdated Brotli note and fix npm install docs URL by \u003ca href=\"https://github.com/Vansh1811\"\u003e\u003ccode\u003e@​Vansh1811\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/276\"\u003eexpressjs/compression#276\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: match Cache-Control no-transform directive case-insensitively by \u003ca href=\"https://github.com/vaibhavmashal\"\u003e\u003ccode\u003e@​vaibhavmashal\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/286\"\u003eexpressjs/compression#286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.8.2 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/287\"\u003eexpressjs/compression#287\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/imangas\"\u003e\u003ccode\u003e@​imangas\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/272\"\u003eexpressjs/compression#272\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sheplu\"\u003e\u003ccode\u003e@​sheplu\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/270\"\u003eexpressjs/compression#270\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/281\"\u003eexpressjs/compression#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kilisamemarisaaa\"\u003e\u003ccode\u003e@​kilisamemarisaaa\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/283\"\u003eexpressjs/compression#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Vansh1811\"\u003e\u003ccode\u003e@​Vansh1811\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/276\"\u003eexpressjs/compression#276\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vaibhavmashal\"\u003e\u003ccode\u003e@​vaibhavmashal\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/286\"\u003eexpressjs/compression#286\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2\"\u003ehttps://github.com/expressjs/compression/compare/v1.8.1...v1.8.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/compression/blob/master/HISTORY.md\"\u003ecompression's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.8.2\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-87776\"\u003eCVE-2026-87776\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95\"\u003eGHSA-vc2v-76pw-4v95\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edeps: add destroy@1.2.0\u003c/li\u003e\n\u003cli\u003eMatch \u003ccode\u003eCache-Control: no-transform\u003c/code\u003e directive case-insensitively\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/0f9707417bd53d41a319fce8bdb80dfa08b435c8\"\u003e\u003ccode\u003e0f97074\u003c/code\u003e\u003c/a\u003e 1.8.2 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/287\"\u003e#287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff\"\u003e\u003ccode\u003e151f63e\u003c/code\u003e\u003c/a\u003e fix: destroy compression stream on response close\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/0a764956691bede2b62c711598ee65ea643d3b1e\"\u003e\u003ccode\u003e0a76495\u003c/code\u003e\u003c/a\u003e fix: match Cache-Control no-transform directive case-insensitively (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/286\"\u003e#286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/c17b6e58ac914c84d9e3a64130dcc428e0e26887\"\u003e\u003ccode\u003ec17b6e5\u003c/code\u003e\u003c/a\u003e docs: update outdated Brotli note and fix npm install docs URL (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/276\"\u003e#276\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/112911abc46e0d8fa6c9793ef5005ca1d53ccb7c\"\u003e\u003ccode\u003e112911a\u003c/code\u003e\u003c/a\u003e chore(ci): npm-publish via reusable workflows (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/269\"\u003e#269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/1bf5eb0b5eaf5001af9782ade18c6cca690ccaad\"\u003e\u003ccode\u003e1bf5eb0\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/267\"\u003e#267\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/d8fe64d50081d4a13a8ea5c25a852ca27fde0b7b\"\u003e\u003ccode\u003ed8fe64d\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/266\"\u003e#266\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/b218ff54eb8e211100d8a6697d13cdc73fdb13b3\"\u003e\u003ccode\u003eb218ff5\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/265\"\u003e#265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/8a1cf8ecf948c28ffd3d29f942c9a310bc36e5c1\"\u003e\u003ccode\u003e8a1cf8e\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/268\"\u003e#268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/4a19855442b7ebfcea4f95caf491968108dc15b8\"\u003e\u003ccode\u003e4a19855\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/257\"\u003e#257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for compression since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `moment` from 2.30.1 to 2.31.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/moment/moment/releases\"\u003emoment's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.31.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003eReleased Sep 14, 2026\u003c/em\u003e\u003c/p\u003e\n\u003ch4\u003eSecurity fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-17495\"\u003eCVE-2026-17495\u003c/a\u003e (\u003ca href=\"https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw\"\u003eGHSA-4p3w-j4w9-5jqw\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eBug fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6376\"\u003e#6376\u003c/a\u003e Prevent object prototype properties from being used as format tokens\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6386\"\u003e#6386\u003c/a\u003e Normalize lazy-loaded locale names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6404\"\u003e#6404\u003c/a\u003e Fix parsing issue with \u003ccode\u003eeHHmm\u003c/code\u003e format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6433\"\u003e#6433\u003c/a\u003e Ignore non-Moment arguments in min and max\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6434\"\u003e#6434\u003c/a\u003e Fix inherited lowercase long date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6436\"\u003e#6436\u003c/a\u003e Reset locale parsing caches after updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6437\"\u003e#6437\u003c/a\u003e Fix weekday mismatch when the format only has part of a date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6442\"\u003e#6442\u003c/a\u003e Fix \u003ccode\u003elocale('__proto__')\u003c/code\u003e corrupting the global locale\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6443\"\u003e#6443\u003c/a\u003e Avoid \u003ccode\u003eObject.assign\u003c/code\u003e in \u003ccode\u003eduration.humanize\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6446\"\u003e#6446\u003c/a\u003e Validate range when parsing a time zone offset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6447\"\u003e#6447\u003c/a\u003e Include metadata in all-locales bundle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6448\"\u003e#6448\u003c/a\u003e Apply postformat to locale relative time methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6450\"\u003e#6450\u003c/a\u003e Add stack traces to conditional deprecation warnings\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eNew features\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6451\"\u003e#6451\u003c/a\u003e Add internal date-default hook for Moment Timezone\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eNew locales\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6000\"\u003e#6000\u003c/a\u003e: Pashto ('ps')\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6278\"\u003e#6278\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/moment/moment/pull/6379\"\u003e#6379\u003c/a\u003e: Amharic (Ethiopia) ('am-et')\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eUpdates to existing locales\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/5404\"\u003e#5404\u003c/a\u003e Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6197\"\u003e#6197\u003c/a\u003e Indonesian ('id'): Correct the abbreviation for August\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6217\"\u003e#6217\u003c/a\u003e Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct \u003ccode\u003eL\u003c/code\u003e date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6289\"\u003e#6289\u003c/a\u003e Swedish ('sv'): Correct the abbreviation for Thursday\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6306\"\u003e#6306\u003c/a\u003e Catalan ('ca'): Use typographic apostrophes in relative time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6347\"\u003e#6347\u003c/a\u003e Swahili ('sw'): Correct the spelling of hour in calendar output\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6360\"\u003e#6360\u003c/a\u003e Ukrainian ('uk'): Use ISO week numbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6370\"\u003e#6370\u003c/a\u003e Ukrainian ('uk'): Use U+02BC apostrophes in Friday names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6371\"\u003e#6371\u003c/a\u003e Hungarian ('hu'): Preserve numeric values in relative seconds\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6391\"\u003e#6391\u003c/a\u003e Swahili ('sw'): Fix weekday and relative-time grammar\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6396\"\u003e#6396\u003c/a\u003e German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6409\"\u003e#6409\u003c/a\u003e Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6410\"\u003e#6410\u003c/a\u003e Polish ('pl'): Use genitive month names in dotted day formats\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/moment/moment/blob/develop/CHANGELOG.md\"\u003emoment's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2.31.0\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eReleased Sep 14, 2026\u003c/em\u003e\u003c/p\u003e\n\u003ch4\u003eSecurity fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-17495\"\u003eCVE-2026-17495\u003c/a\u003e (\u003ca href=\"https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw\"\u003eGHSA-4p3w-j4w9-5jqw\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eBug fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6376\"\u003e#6376\u003c/a\u003e Prevent object prototype properties from being used as format tokens\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6386\"\u003e#6386\u003c/a\u003e Normalize lazy-loaded locale names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6404\"\u003e#6404\u003c/a\u003e Fix parsing issue with \u003ccode\u003eeHHmm\u003c/code\u003e format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6433\"\u003e#6433\u003c/a\u003e Ignore non-Moment arguments in min and max\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6434\"\u003e#6434\u003c/a\u003e Fix inherited lowercase long date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6436\"\u003e#6436\u003c/a\u003e Reset locale parsing caches after updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6437\"\u003e#6437\u003c/a\u003e Fix weekday mismatch when the format only has part of a date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6442\"\u003e#6442\u003c/a\u003e Fix \u003ccode\u003elocale('__proto__')\u003c/code\u003e corrupting the global locale\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6443\"\u003e#6443\u003c/a\u003e Avoid \u003ccode\u003eObject.assign\u003c/code\u003e in \u003ccode\u003eduration.humanize\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6446\"\u003e#6446\u003c/a\u003e Validate range when parsing a time zone offset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6447\"\u003e#6447\u003c/a\u003e Include metadata in all-locales bundle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6448\"\u003e#6448\u003c/a\u003e Apply postformat to locale relative time methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6450\"\u003e#6450\u003c/a\u003e Add stack traces to conditional deprecation warnings\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eNew features\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6451\"\u003e#6451\u003c/a\u003e Add internal date-default hook for Moment Timezone\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eNew locales\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6000\"\u003e#6000\u003c/a\u003e: Pashto ('ps')\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6278\"\u003e#6278\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/moment/moment/pull/6379\"\u003e#6379\u003c/a\u003e: Amharic (Ethiopia) ('am-et')\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eUpdates to existing locales\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/5404\"\u003e#5404\u003c/a\u003e Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6197\"\u003e#6197\u003c/a\u003e Indonesian ('id'): Correct the abbreviation for August\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6217\"\u003e#6217\u003c/a\u003e Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct \u003ccode\u003eL\u003c/code\u003e date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6289\"\u003e#6289\u003c/a\u003e Swedish ('sv'): Correct the abbreviation for Thursday\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6306\"\u003e#6306\u003c/a\u003e Catalan ('ca'): Use typographic apostrophes in relative time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6347\"\u003e#6347\u003c/a\u003e Swahili ('sw'): Correct the spelling of hour in calendar output\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6360\"\u003e#6360\u003c/a\u003e Ukrainian ('uk'): Use ISO week numbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6370\"\u003e#6370\u003c/a\u003e Ukrainian ('uk'): Use U+02BC apostrophes in Friday names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6371\"\u003e#6371\u003c/a\u003e Hungarian ('hu'): Preserve numeric values in relative seconds\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6391\"\u003e#6391\u003c/a\u003e Swahili ('sw'): Fix weekday and relative-time grammar\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6396\"\u003e#6396\u003c/a\u003e German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6409\"\u003e#6409\u003c/a\u003e Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6410\"\u003e#6410\u003c/a\u003e Polish ('pl'): Use genitive month names in dotted day formats\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/15b45d48a176312e8f34143c5a800090abf4787f\"\u003e\u003ccode\u003e15b45d4\u003c/code\u003e\u003c/a\u003e [pkg] Build 2.31.0 (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6452\"\u003e#6452\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/631cd81454ee001e1f508e21270eae0b6bb62974\"\u003e\u003ccode\u003e631cd81\u003c/code\u003e\u003c/a\u003e [pkg] Update changelog for upcoming release (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6394\"\u003e#6394\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/6caff9e0d54e85a63a6eb97d7361f1da35bc58f4\"\u003e\u003ccode\u003e6caff9e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/710703b7eac93535ad125cbf4feb3d42afed6fb3\"\u003e\u003ccode\u003e710703b\u003c/code\u003e\u003c/a\u003e [feature] Add internal date-default hook for Moment Timezone (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6451\"\u003e#6451\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/863ed940556e6e63c43de23981a4853036a003ac\"\u003e\u003ccode\u003e863ed94\u003c/code\u003e\u003c/a\u003e [bugfix] Add stack traces to conditional deprecation warnings (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6450\"\u003e#6450\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/2c7abe1c42ee15445d30c2c5d536750a1e43a09a\"\u003e\u003ccode\u003e2c7abe1\u003c/code\u003e\u003c/a\u003e [bugfix] Apply postformat to locale relative time methods (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6448\"\u003e#6448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/9c45ac38690c649c95e19923276b63da5fe2be26\"\u003e\u003ccode\u003e9c45ac3\u003c/code\u003e\u003c/a\u003e [bugfix] Include metadata in all-locales bundle (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6447\"\u003e#6447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/f6eefc5fc7b44ceccbd007aeffc48ebc5eac30fa\"\u003e\u003ccode\u003ef6eefc5\u003c/code\u003e\u003c/a\u003e [bugfix] Validate timezone offset range (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6446\"\u003e#6446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/136b441794a3bb207d593add3b59e9de0e062523\"\u003e\u003ccode\u003e136b441\u003c/code\u003e\u003c/a\u003e [bugfix] Avoid Object.assign in duration.humanize (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6443\"\u003e#6443\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/0d1050437b40f66ac47e14b285bb3d09676cf2e0\"\u003e\u003ccode\u003e0d10504\u003c/code\u003e\u003c/a\u003e [bugfix] Fix locale('\u003cstrong\u003eproto\u003c/strong\u003e') corrupting the global locale (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6442\"\u003e#6442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/moment/moment/compare/2.30.1...2.31.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for moment since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/josephcrown920/Auroraglobal/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/josephcrown920/Auroraglobal/pull/131","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/josephcrown920%2FAuroraglobal/issues/131","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/131/packages"},{"uuid":"5733183112","node_id":"PR_kwDOACBxpM8AAAABG-JLtg","number":42986,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["v5","dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T18:07:39.000Z","updated_at":"2026-10-06T18:18:21.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/twbs/bootstrap/pull/42986","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/twbs%2Fbootstrap/issues/42986","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/42986/packages"}],"issue_packages":[{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-07T00:58:04.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5737597971","node_id":"PR_kwDORbkv688AAAABHBqWbA","number":130,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-07T00:58:04.000Z","updated_at":"2026-10-07T00:58:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"sharp","old_version":"0.35.4","new_version":"0.35.5","repository_url":"https://github.com/lovell/sharp"},{"name":"http-cache-semantics","old_version":"4.2.0","new_version":"4.3.0","repository_url":"https://github.com/kornelski/http-cache-semantics"},{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 3 updates in the /docs-site directory: [sharp](https://github.com/lovell/sharp), [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) and [source-map-js](https://github.com/7rulnik/source-map-js).\n\nUpdates `sharp` from 0.35.4 to 0.35.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.5\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.4\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdd upper bounds check on length of \u003ccode\u003elinear\u003c/code\u003e and GIF \u003ccode\u003edelay\u003c/code\u003e arrays.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error handing when WebAssembly fallback also fails.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4593\"\u003e#4593\u003c/a\u003e\n\u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Allow multi-frame options for JXL output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4602\"\u003e#4602\u003c/a\u003e\n\u003ca href=\"https://github.com/ramin-010\"\u003e\u003ccode\u003e@​ramin-010\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Remove non-existent named export.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4604\"\u003e#4604\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIncrease accepted dimensions when extending an image.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4605\"\u003e#4605\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove gain map support for \u003ccode\u003eextract\u003c/code\u003e and \u003ccode\u003erotate\u003c/code\u003e operations.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTests: Ensure composite tests pass on big endian platforms.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4609\"\u003e#4609\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.5-rc.1\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdd upper bounds check on length of \u003ccode\u003elinear\u003c/code\u003e and GIF \u003ccode\u003edelay\u003c/code\u003e arrays.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error handing when WebAssembly fallback also fails.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4593\"\u003e#4593\u003c/a\u003e\n\u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Allow multi-frame options for JXL output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4602\"\u003e#4602\u003c/a\u003e\n\u003ca href=\"https://github.com/ramin-010\"\u003e\u003ccode\u003e@​ramin-010\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTypeScript: Remove non-existent named export.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4604\"\u003e#4604\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIncrease accepted dimensions when extending an image.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4605\"\u003e#4605\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove gain map support for \u003ccode\u003eextract\u003c/code\u003e operation.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/51a990faa26ade5586a4934ac9673c98d8893326\"\u003e\u003ccode\u003e51a990f\u003c/code\u003e\u003c/a\u003e Release v0.35.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236\"\u003e\u003ccode\u003e96de105\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/3a61390260e0aa017046af9ad107abd62f3c98c0\"\u003e\u003ccode\u003e3a61390\u003c/code\u003e\u003c/a\u003e CI: Configure Dependabot with all package.json locations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/4940c500a63a9193b1ad5d3804a2d241ca36995b\"\u003e\u003ccode\u003e4940c50\u003c/code\u003e\u003c/a\u003e Improve gain map support for rotate/flip/flop ops\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/20654aa60eaa85a37369ef69a7ca6506b65f8c85\"\u003e\u003ccode\u003e20654aa\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.5-rc.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ef4f9348a97053ceddacd23dcb6e39cce5a1fc7d\"\u003e\u003ccode\u003eef4f934\u003c/code\u003e\u003c/a\u003e CI: Upgrade to Ubuntu 26.04\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/358df954c5f58487392e1a9af743e112e8998d67\"\u003e\u003ccode\u003e358df95\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/49f4903d34eddcd68b79872c511c198f124885a3\"\u003e\u003ccode\u003e49f4903\u003c/code\u003e\u003c/a\u003e Improve gain map support for rotate-then-extract \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/0e2e55eb3a44da5d602adedd6b51a03e652e3b20\"\u003e\u003ccode\u003e0e2e55e\u003c/code\u003e\u003c/a\u003e Silence a couple of compiler/static analysis warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/cef3b8c467c21f7e84bd51d5e53f2d115669f8d8\"\u003e\u003ccode\u003ecef3b8c\u003c/code\u003e\u003c/a\u003e Improve gain map support for extract operation \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4606\"\u003e#4606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.35.4...v0.35.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `http-cache-semantics` from 4.2.0 to 4.3.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/kornelski/http-cache-semantics/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/mlorentedev/garsync/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/mlorentedev/garsync/pull/130","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mlorentedev%2Fgarsync/issues/130","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/130/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-07T00:06:17.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5737112759","node_id":"PR_kwDOTGgQTc8AAAABHBRdjw","number":23,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-07T00:06:17.000Z","updated_at":"2026-10-07T00:08:26.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/lemduc/wings-vs-claws/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/lemduc/wings-vs-claws/pull/23","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/lemduc%2Fwings-vs-claws/issues/23","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/23/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":"/frontend","pr_created_at":"2026-10-07T00:02:28.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5737079811","node_id":"PR_kwDONNFxvc8AAAABHBPzEQ","number":431,"state":"closed","title":"chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /frontend","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-10-07T00:30:52.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-07T00:02:28.000Z","updated_at":"2026-10-07T00:32:22.000Z","time_to_close":1704,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/frontend","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/msgmate-io/open-chat-go/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/msgmate-io/open-chat-go/pull/431","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/msgmate-io%2Fopen-chat-go/issues/431","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/431/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":"the npm_and_yarn group across 1 directory","pr_created_at":"2026-10-06T23:30:36.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5736784693","node_id":"PR_kwDOA0RAO88AAAABHBA4PA","number":3731,"state":"open","title":"build(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in the npm_and_yarn group across 1 directory","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T23:30:36.000Z","updated_at":"2026-10-06T23:38:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps-dev)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"the npm_and_yarn group across 1 directory","ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [source-map-js](https://github.com/7rulnik/source-map-js).\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dolanmiu/docx/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/dolanmiu/docx/pull/3731","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dolanmiu%2Fdocx/issues/3731","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3731/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T22:29:56.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5736265529","node_id":"PR_kwDOQGK4a88AAAABHAmmYg","number":32,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T22:29:56.000Z","updated_at":"2026-10-06T22:30:27.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/byjg/shellscript-download/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/byjg/shellscript-download/pull/32","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/byjg%2Fshellscript-download/issues/32","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/32/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T22:28:41.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5736254090","node_id":"PR_kwDOHHUq_M8AAAABHAmBRg","number":1850,"state":"closed","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-10-06T22:36:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-06T22:28:41.000Z","updated_at":"2026-10-06T22:36:22.000Z","time_to_close":459,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ArnaudFlaesch/CashManager/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ArnaudFlaesch/CashManager/pull/1850","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ArnaudFlaesch%2FCashManager/issues/1850","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1850/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T21:48:40.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5735867609","node_id":"PR_kwDOB5fEFs8AAAABHASQ9g","number":1123,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:48:40.000Z","updated_at":"2026-10-06T22:25:44.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/doctrine/doctrine-website/pull/1123","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/doctrine%2Fdoctrine-website/issues/1123","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1123/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T21:39:06.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5735768352","node_id":"PR_kwDOUx7v_M8AAAABHANOUw","number":6,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:39:06.000Z","updated_at":"2026-10-06T21:40:28.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/an0n7os/goodwill-new/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/an0n7os/goodwill-new/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/an0n7os%2Fgoodwill-new/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T21:38:26.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5735761445","node_id":"PR_kwDOTcn5Ts8AAAABHAM3sQ","number":33,"state":"open","title":"chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:38:26.000Z","updated_at":"2026-10-06T21:38:27.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps-dev)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/discrete-event-systems/discrete-event-systems.github.io/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/discrete-event-systems/discrete-event-systems.github.io/pull/33","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/discrete-event-systems%2Fdiscrete-event-systems.github.io/issues/33","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/33/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":"/docs","pr_created_at":"2026-10-06T21:20:35.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5735570377","node_id":"PR_kwDOSWmRmc8AAAABHADH-Q","number":1061,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2 in /docs","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T21:20:35.000Z","updated_at":"2026-10-06T21:25:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/docs","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/amiantos/lurker/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/amiantos/lurker/pull/1061","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/amiantos%2Flurker/issues/1061","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1061/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":"/tooling/comparison/html-tool-comparison","pr_created_at":"2026-10-06T20:44:33.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5735155958","node_id":"PR_kwDOADgiC88AAAABG_uFeA","number":22481,"state":"open","title":"fix(deps): bump source-map-js from 1.2.1 to 1.2.2 in /tooling/comparison/html-tool-comparison","user":"dependabot[bot]","labels":["dependencies","area: tooling"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T20:44:33.000Z","updated_at":"2026-10-06T20:46:53.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"fix(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/tooling/comparison/html-tool-comparison","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/webpack/webpack/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/webpack/webpack/pull/22481","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpack%2Fwebpack/issues/22481","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22481/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":"/tooling/comparison/js-tool-comparison","pr_created_at":"2026-10-06T20:44:30.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5735155158","node_id":"PR_kwDOADgiC88AAAABG_uC4Q","number":22480,"state":"closed","title":"fix(deps): bump source-map-js from 1.2.1 to 1.2.2 in /tooling/comparison/js-tool-comparison","user":"dependabot[bot]","labels":["dependencies","area: tooling"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":"2026-10-06T20:52:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-06T20:44:30.000Z","updated_at":"2026-10-06T21:03:25.000Z","time_to_close":501,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"fix(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"/tooling/comparison/js-tool-comparison","ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/webpack/webpack/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/webpack/webpack/pull/22480","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpack%2Fwebpack/issues/22480","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22480/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T20:09:42.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5734738254","node_id":"PR_kwDORujkJ88AAAABG_Yotg","number":23,"state":"open","title":"chore(deps): Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T20:09:42.000Z","updated_at":"2026-10-06T20:10:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dota1337/metastats/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Dota1337/metastats/pull/23","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dota1337%2Fmetastats/issues/23","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/23/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T19:44:07.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5734427942","node_id":"PR_kwDOQpCEsc8AAAABG_Im7g","number":1,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 17 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:44:07.000Z","updated_at":"2026-10-06T19:48:51.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":17,"packages":[{"name":"ai","old_version":"4.3.19","new_version":"5.0.52","repository_url":"https://github.com/vercel/ai"},{"name":"next","old_version":"16.0.10","new_version":"16.3.6","repository_url":"https://github.com/vercel/next.js"},{"name":"postcss","old_version":"8.5.6","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"@ai-sdk/provider-utils","old_version":"2.2.8","new_version":"5.0.54","repository_url":"https://github.com/vercel/ai"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.21","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"minimatch","old_version":"3.1.2","new_version":"3.1.5","repository_url":"https://github.com/isaacs/minimatch"},{"name":"baseline-browser-mapping","old_version":"2.9.7","new_version":"2.11.27","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.1","new_version":"4.29.3","repository_url":"https://github.com/browserslist/browserslist"},{"name":"flatted","old_version":"3.3.3","new_version":"3.4.4","repository_url":"https://github.com/WebReflection/flatted"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"lodash","old_version":"4.17.21","new_version":"4.18.1","repository_url":"https://github.com/lodash/lodash"},{"name":"nanoid","old_version":"3.3.11","new_version":"3.3.20","repository_url":"https://github.com/ai/nanoid"},{"name":"picomatch","old_version":"2.3.1","new_version":"2.3.2","repository_url":"https://github.com/micromatch/picomatch"},{"name":"picomatch","old_version":"4.0.3","new_version":"4.0.7","repository_url":"https://github.com/micromatch/picomatch"},{"name":"postcss-selector-parser","old_version":"6.1.2","new_version":"removed","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.5","repository_url":"https://github.com/lovell/sharp"},{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 17 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `4.3.19` | `5.0.52` |\n| [next](https://github.com/vercel/next.js) | `16.0.10` | `16.3.6` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.6` | `8.5.23` |\n| [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils) | `2.2.8` | `5.0.54` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.21` |\n| [minimatch](https://github.com/isaacs/minimatch) | `3.1.2` | `3.1.5` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.9.7` | `2.11.27` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.29.3` |\n| [flatted](https://github.com/WebReflection/flatted) | `3.3.3` | `3.4.4` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.20` |\n| [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` |\n| [picomatch](https://github.com/micromatch/picomatch) | `4.0.3` | `4.0.7` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `removed` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.5` |\n| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |\n\n\nUpdates `ai` from 4.3.19 to 5.0.52\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md\"\u003eai's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eai\u003c/h1\u003e\n\u003ch2\u003e7.0.128\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e0fe8c67: fix: preserve tool approval state when resuming streams\u003c/li\u003e\n\u003cli\u003e2959d35: feat: rename \u003ccode\u003eevaluate\u003c/code\u003e to \u003ccode\u003edecide\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e0ca1ab9: Add durable non-streaming \u003ccode\u003eWorkflowAgent.generate()\u003c/code\u003e with a shared tool loop, a 20-step default, typed output, and core generation result semantics. Reuse core result and content construction through internal exports while preserving existing Workflow streaming behavior. Transport-independent approval creation remains separate follow-up work.\u003c/li\u003e\n\u003cli\u003ed6b42fd: feat(ai): support custom reasoning delimiters in extractReasoningMiddleware\u003c/li\u003e\n\u003cli\u003eed6e72d: fix(ai): return successful empty transcripts for silent audio\u003c/li\u003e\n\u003cli\u003e2136151: Throw \u003ccode\u003eInvalidResponseDataError\u003c/code\u003e instead of a generic \u003ccode\u003eError\u003c/code\u003e when a generated audio file's format cannot be determined from its media type, so callers can identify the failure with \u003ccode\u003eAISDKError.isInstance\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [131532b]\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [2959d35]\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [59116e6]\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [6ac923a]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/gateway\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.104\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.22\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider-utils\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.0.54\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.127\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e158a718: feat(ai): select and rank eligible deferred tools via 'search()' callback in tool search\u003c/li\u003e\n\u003cli\u003ebb8d33e: fix(ai): cancel merged UI message streams when the consumer disconnects\u003c/li\u003e\n\u003cli\u003e284dc11: fix(ai): accept unchanged tool approval inputs created in another JavaScript realm\u003c/li\u003e\n\u003cli\u003eba8afe9: feat(ai): add a configurable maxResults for number of tools returned in tool search\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [d1bb9e8]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/gateway\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.103\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.126\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e4f3d236: fix: clear tool approvals when \u003ccode\u003eaddToolOutput\u003c/code\u003e runs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.125\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eff3dcef: feat(ai): add \u003ccode\u003econvertDataPart\u003c/code\u003e to agent UI stream helpers\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.124\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e8c65988: feat(ai): add telemetry to speech generation and transcription, including\nprovider usage propagation and experimental streaming lifecycle callbacks\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [8c65988]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/63d5f669098343a49173d788fe1490127e882bd1\"\u003e\u003ccode\u003e63d5f66\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8895\"\u003e#8895\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed\"\u003e\u003ccode\u003e930399b\u003c/code\u003e\u003c/a\u003e Backport: fix(ai): download files when intermediate file cannot be downloaded...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/85909a9f6448c7e6eb52d780abcca4f96679e719\"\u003e\u003ccode\u003e85909a9\u003c/code\u003e\u003c/a\u003e Backport: chore(ai): update test message (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8875\"\u003e#8875\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/c56822dd81d5d70bcd5ef230a875f96a224849a4\"\u003e\u003ccode\u003ec56822d\u003c/code\u003e\u003c/a\u003e Backport: fix(ai): update \u003ccode\u003euiMessageChunkSchema\u003c/code\u003e to satisfy the `UIMessageChu...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/6bd07df02d9f954b389e44da128fc6d1358462d9\"\u003e\u003ccode\u003e6bd07df\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8853\"\u003e#8853\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/27645bb653b24dd7e285df7848154f86af309451\"\u003e\u003ccode\u003e27645bb\u003c/code\u003e\u003c/a\u003e Backport: Export \u003ccode\u003eparseJsonEventStream\u003c/code\u003e and \u003ccode\u003euiMessageChunkSchema\u003c/code\u003e from \u0026quot;ai\u0026quot; ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/8b7f0d2eac987a0066befd46a0119d533b1e65e2\"\u003e\u003ccode\u003e8b7f0d2\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8843\"\u003e#8843\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/9eef1982d2d40e190300b3b02d7edafbf5a8b0af\"\u003e\u003ccode\u003e9eef198\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8831\"\u003e#8831\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/20bca657c4ebd3cbef370e4a093818cbf0f84eca\"\u003e\u003ccode\u003e20bca65\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8799\"\u003e#8799\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/4254096b7ffb1d96e3f6a1926ccfffaa1799280f\"\u003e\u003ccode\u003e4254096\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/8753\"\u003e#8753\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/ai/commits/ai@5.0.52/packages/ai\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.0.10 to 16.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.6\u003c/h2\u003e\n\u003cp\u003eThis release contains a security fix for \u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j\"\u003eGHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a758ffcf501f6f1ddb03175bd1033508424c261e\"\u003e\u003ccode\u003ea758ffc\u003c/code\u003e\u003c/a\u003e v16.3.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e\"\u003e\u003ccode\u003e868fad3\u003c/code\u003e\u003c/a\u003e [active-lts] Harden next/og SVG serialization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/8c81cbb30a7f667ed74806d984f8117ee97f4665\"\u003e\u003ccode\u003e8c81cbb\u003c/code\u003e\u003c/a\u003e [lts-active] test: remove unsupported deployment ID builder cases (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98821\"\u003e#98821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.0.10...v16.3.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.6 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.6...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@ai-sdk/provider-utils` from 2.2.8 to 5.0.54\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/ai/releases\"\u003e@​ai-sdk/provider-utils's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​ai-sdk/provider-utils\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.0.54\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e2959d35: feat: rename \u003ccode\u003eevaluate\u003c/code\u003e to \u003ccode\u003edecide\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e59116e6: fix(groq,google): use JSON response tool for structured outputs with tool calling\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [2959d35]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.22\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/ai/blob/main/packages/provider-utils/CHANGELOG.md\"\u003e@​ai-sdk/provider-utils's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.54\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e2959d35: feat: rename \u003ccode\u003eevaluate\u003c/code\u003e to \u003ccode\u003edecide\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e59116e6: fix(groq,google): use JSON response tool for structured outputs with tool calling\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [2959d35]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.22\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.53\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e8c65988: feat(ai): add telemetry to speech generation and transcription, including\nprovider usage propagation and experimental streaming lifecycle callbacks\u003c/li\u003e\n\u003cli\u003e527a163: fix: validate hostname parts using \u003ccode\u003eisValidHostnamePart\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [8c65988]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.21\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.52\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eede5b89: chore: migrate package builds from tsup to tsdown\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [ede5b89]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.20\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.51\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ec2511c1: fix: use standards-compliant User-Agent header\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.50\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ee3605f6: Fix streamed tool calls with missing, blank, or repeated IDs.\u003c/li\u003e\n\u003cli\u003eUpdated dependencies [525efc5]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​ai-sdk/provider\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.0.19\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.49\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eaf9597b: Compile packages for ES2022 runtime target\u003c/li\u003e\n\u003cli\u003ebc49f78: Preserve original opaque URI strings in tagged file URLs during prompt conversion. Match explicit supported URL MIME types exactly so unsupported subtypes are not forwarded to providers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.48\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/92e2a4b31bd7982e960c142de1081be3e112cea7\"\u003e\u003ccode\u003e92e2a4b\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21938\"\u003e#21938\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/2959d35d2ffd1eea92311a4f21811fbd0181ce05\"\u003e\u003ccode\u003e2959d35\u003c/code\u003e\u003c/a\u003e refactor(ai): rename experimental_evaluate to experimental_decide (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21935\"\u003e#21935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/59116e6952784647bcf50f493319b52fc9463417\"\u003e\u003ccode\u003e59116e6\u003c/code\u003e\u003c/a\u003e fix(groq,google): use JSON response tool for structured outputs with tool cal...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/eb93c81f2d6200e0732745d0cd582600fe4c5055\"\u003e\u003ccode\u003eeb93c81\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21822\"\u003e#21822\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/527a1637bfbc1df92a708f5cc78a8011521711eb\"\u003e\u003ccode\u003e527a163\u003c/code\u003e\u003c/a\u003e fix: validate hostname parts (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21842\"\u003e#21842\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/8c659885c52ef519b21b3af1ff266d843e3c157f\"\u003e\u003ccode\u003e8c65988\u003c/code\u003e\u003c/a\u003e feat: support telemetry for speech generation and streaming and non-streaming...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/161a7fdb9783d88b0ea25fe522fbda0233d83427\"\u003e\u003ccode\u003e161a7fd\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21718\"\u003e#21718\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/ede5b890d6760ead18da248a97861d7bba9a4703\"\u003e\u003ccode\u003eede5b89\u003c/code\u003e\u003c/a\u003e chore: move from \u003ccode\u003etsup\u003c/code\u003e to \u003ccode\u003etsdown\u003c/code\u003e (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21642\"\u003e#21642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/1040e97e72cab8a443aeed818520d8b8161d4c1c\"\u003e\u003ccode\u003e1040e97\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21638\"\u003e#21638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/ai/commit/c2511c1d65c1756ef70887de0c8baae4bcc77bf8\"\u003e\u003ccode\u003ec2511c1\u003c/code\u003e\u003c/a\u003e fix: use standards-compliant User-Agent header (\u003ca href=\"https://github.com/vercel/ai/tree/HEAD/packages/provider-utils/issues/21344\"\u003e#21344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/ai/commits/@ai-sdk/provider-utils@5.0.54/packages/provider-utils\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​ai-sdk/provider-utils\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.21\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/8e81e187b6e9c6c723d16c042657c00acefc2483\"\u003e\u003ccode\u003e8e81e18\u003c/code\u003e\u003c/a\u003e 1.1.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e\"\u003e\u003ccode\u003effdfa3e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c6513ad31e08edb56dc414a629e39cba724b7548\"\u003e\u003ccode\u003ec6513ad\u003c/code\u003e\u003c/a\u003e 1.1.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b\"\u003e\u003ccode\u003e1efee7c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/a34340a053abb475cc226aeb3f71887018e71bd0\"\u003e\u003ccode\u003ea34340a\u003c/code\u003e\u003c/a\u003e 1.1.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc\"\u003e\u003ccode\u003e0bcbfc0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.21\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `minimatch` from 3.1.2 to 3.1.5\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/7bba97888a27a6162983056bcce2a6e28f668712\"\u003e\u003ccode\u003e7bba978\u003c/code\u003e\u003c/a\u003e 3.1.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/bd259425b2ca17b42897997f93e890314155522d\"\u003e\u003ccode\u003ebd25942\u003c/code\u003e\u003c/a\u003e docs: add warning about ReDoS\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/1a9c27c75725474dbde57db2995b6281b267756d\"\u003e\u003ccode\u003e1a9c27c\u003c/code\u003e\u003c/a\u003e fix partial matching of globstar patterns\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/1a2e084af579731af66c221214e3ca8222c9bf23\"\u003e\u003ccode\u003e1a2e084\u003c/code\u003e\u003c/a\u003e 3.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/ae24656237c3d58067442f790ce17eff84463a47\"\u003e\u003ccode\u003eae24656\u003c/code\u003e\u003c/a\u003e update lockfile\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/b1003749228b2a79e1f237963a0d559ef7a0941e\"\u003e\u003ccode\u003eb100374\u003c/code\u003e\u003c/a\u003e limit recursion for **, improve perf considerably\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/26ffeaa091b9f660833e23f42e07165b33e85c13\"\u003e\u003ccode\u003e26ffeaa\u003c/code\u003e\u003c/a\u003e lockfile update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/9eca892a4e5dbb20534f9f30483b85cdeee6c2eb\"\u003e\u003ccode\u003e9eca892\u003c/code\u003e\u003c/a\u003e lock node version to 14\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/00c323b188b704e5d4bc534ecec2268cfa70a32a\"\u003e\u003ccode\u003e00c323b\u003c/code\u003e\u003c/a\u003e 3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/isaacs/minimatch/commit/30486b2048929264f44d18822891cfffa02af78b\"\u003e\u003ccode\u003e30486b2\u003c/code\u003e\u003c/a\u003e update CI matrix and actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `baseline-browser-mapping` from 2.9.7 to 2.11.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/releases\"\u003ebaseline-browser-mapping's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed in 2.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Adds a new \u003ccode\u003egetTimeline()\u003c/code\u003e method for getting the series of minimum browser changes, either grouped by date or by browser.\u003c/li\u003e\n\u003cli\u003erefactor: Substantial refactoring of the data compression process that replaces the full list of browsers from \u003ccode\u003e@mdn/browser-compat-data\u003c/code\u003e and \u003ccode\u003edownstream-browsers.json\u003c/code\u003e and features from \u003ccode\u003eweb-features\u003c/code\u003e (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date.  Thanks to \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e for the idea!\u003c/li\u003e\n\u003cli\u003erefactor: Some common functions have been moved to a \u003ccode\u003eutil.ts\u003c/code\u003e module for use in other scripts.\u003c/li\u003e\n\u003cli\u003efix: Removes \u003ccode\u003eprocess.exit()\u003c/code\u003e calls when unsupported option combinations are passed to getCompatibleVersions() and \u003ccode\u003egetAllVersions()\u003c/code\u003e in favour of throwing an \u003ccode\u003eError\u003c/code\u003e.  There is a small security risk with \u003ccode\u003eprocess.exit()\u003c/code\u003e calls that sites accepting unsanitised inputs could be the subject of attacks.  Unsupported config options now throw and Error which should allow for more graceful handling.  Thanks to \u003ca href=\"https://github.com/bnbdr\"\u003e\u003ccode\u003e@​bnbdr\u003c/code\u003e\u003c/a\u003e for flagging this as vulnerability CVE-2026-45819 .\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes \u003ca href=\"https://redirect.github.com/web-platform-dx/baseline-browser-mapping/issues/134\"\u003e#134\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduces support for Node 6 by refactoring all \u003ccode\u003eObject.entries\u003c/code\u003e and \u003ccode\u003eObject.values\u003c/code\u003e instances and lowering ES target in Rollup to \u003ccode\u003ees2015\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdds specified Node version support in package.json for \u0026gt;=6.0.0.\u003c/li\u003e\n\u003cli\u003eRefactors CLI code to avoid \u003ccode\u003eparseArgs\u003c/code\u003e which is not supported by versions of Node prior to 18, changes \u003ccode\u003eimport\u003c/code\u003e to \u003ccode\u003erequire\u003c/code\u003e and changes Rollup export to \u003ccode\u003ecjs\u003c/code\u003e to allow execution on older versions of Node.\u003c/li\u003e\n\u003cli\u003eAdds a new \u003ccode\u003elegacy-test.js\u003c/code\u003e file that allows basic testing on older versions of Node where current versions of Jasmine and ESLint are not supported.\u003c/li\u003e\n\u003cli\u003eAdds a test matrix to run tests on all even-numbered Node versions from 6 to 24.\u003c/li\u003e\n\u003cli\u003erefactor publish workflows to support NPM's new OIDC integration\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.9.24...v2.10.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.9.24...v2.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/6141d06f254525dcc3902ee1b153a835fc845522\"\u003e\u003ccode\u003e6141d06\u003c/code\u003e\u003c/a\u003e Patch to 2.11.27 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/e1d166be08e0eab6f6d71533772d1c9202798abb\"\u003e\u003ccode\u003ee1d166b\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/42972a7ab3bad1c0c74edda376443010dbaa127c\"\u003e\u003ccode\u003e42972a7\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/c1934c691d39aa9cf0c25626b91e1e5c6efd53ce\"\u003e\u003ccode\u003ec1934c6\u003c/code\u003e\u003c/a\u003e Patch to 2.11.26 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/487368484af4ff9aba321be0ac65bf9a8dab3d34\"\u003e\u003ccode\u003e4873684\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/9030798a5922aa76e94db887aeed97daaf2dfb1b\"\u003e\u003ccode\u003e9030798\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/a5df351eb505078f62bf07477d3583fa9df51e5b\"\u003e\u003ccode\u003ea5df351\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ecc5b5451be2d79318b261366f19e0ca387c268d\"\u003e\u003ccode\u003eecc5b54\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/719bf7ab47f710422fc87bb722f87b93ddb745d8\"\u003e\u003ccode\u003e719bf7a\u003c/code\u003e\u003c/a\u003e Patch to 2.11.25 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/c4f5b49cebb0fdd301619124224f92f19e80543f\"\u003e\u003ccode\u003ec4f5b49\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.9.7...v2.11.27\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for baseline-browser-mapping since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.1 to 4.29.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.29.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed ignoring \u003ccode\u003enull\u003c/code\u003e usage in \u003ccode\u003ecover X in Y\u003c/code\u003e query (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed config name loading protection on Windows (by \u003ca href=\"https://github.com/oss-security-shop\"\u003e\u003ccode\u003e@​oss-security-shop\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed case-insensitive negation queries (by \u003ca href=\"https://github.com/jakezwang\"\u003e\u003ccode\u003e@​jakezwang\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed percentage and supports queries case-insensitive (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed old Node.js tests (by \u003ca href=\"https://github.com/aaron-belenky\"\u003e\u003ccode\u003e@​aaron-belenky\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eReduced code (by \u003ca href=\"https://github.com/charmander\"\u003e\u003ccode\u003e@​charmander\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded query continuations across lines and array entries (by \u003ca href=\"https://github.com/fzlzjerry\"\u003e\u003ccode\u003e@​fzlzjerry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix prototype pollution (by \u003ca href=\"https://github.com/chluo1997\"\u003e\u003ccode\u003e@​chluo1997\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.29.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed ignoring \u003ccode\u003enull\u003c/code\u003e usage in \u003ccode\u003ecover X in Y\u003c/code\u003e query (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed config name loading protection on Windows (by \u003ca href=\"https://github.com/oss-security-shop\"\u003e\u003ccode\u003e@​oss-security-shop\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed case-insensitive negation queries (by \u003ca href=\"https://github.com/jakezwang\"\u003e\u003ccode\u003e@​jakezwang\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed percentage and supports queries case-insensitive (by \u003ca href=\"https://github.com/wahidrizka\"\u003e\u003ccode\u003e@​wahidrizka\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed old Node.js tests (by \u003ca href=\"https://github.com/aaron-belenky\"\u003e\u003ccode\u003e@​aaron-belenky\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eReduced code (by \u003ca href=\"https://github.com/charmander\"\u003e\u003ccode\u003e@​charmander\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.29.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded query continuations across lines and array entries (by \u003ca href=\"https://github.com/fzlzjerry\"\u003e\u003ccode\u003e@​fzlzjerry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b4809dd2a2a11fbff492258f968130e9b470067f\"\u003e\u003ccode\u003eb4809dd\u003c/code\u003e\u003c/a\u003e Release 4.29.3 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/9d844f8d09c872e2f22e07daa8566fb53585c190\"\u003e\u003ccode\u003e9d844f8\u003c/code\u003e\u003c/a\u003e Update Firefox ESR\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/0033f344c3be446c935f9e515a366738fc0942a5\"\u003e\u003ccode\u003e0033f34\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/906d329968d968479474aab97ae2ab712bf18b5f\"\u003e\u003ccode\u003e906d329\u003c/code\u003e\u003c/a\u003e Release 4.29.2 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/ff8c83f72dd22e3331e89404487a19ec4ea6d5fc\"\u003e\u003ccode\u003eff8c83f\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/067f4a1fa37047e8a53b369cb1fd837399f5d5d5\"\u003e\u003ccode\u003e067f4a1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/952\"\u003e#952\u003c/a\u003e from wahidrizka/fix-cover-null-usage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f760921db5e420bd8c10e31d0278ab16fdbb9a2d\"\u003e\u003ccode\u003ef760921\u003c/code\u003e\u003c/a\u003e Do not add versions without usage data to cover queries\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5be63f54fc37cef2db22930bdabfafcb22b6fd46\"\u003e\u003ccode\u003e5be63f5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/953\"\u003e#953\u003c/a\u003e from wahidrizka/docs-android-latest-version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/1e5356f16429cb8a30dfa5415c7d0beddff8548f\"\u003e\u003ccode\u003e1e5356f\u003c/code\u003e\u003c/a\u003e Note that Android version queries return only the latest version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5b7e94169750cedd9e63fdb8d2419542d3aa185f\"\u003e\u003ccode\u003e5b7e941\u003c/code\u003e\u003c/a\u003e Add missed changes to ChangeLog\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.1...4.29.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for browserslist since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `flatted` from 3.3.3 to 3.4.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/e6f5ca700c4ca8104a6a83472c8219e267bd5e84\"\u003e\u003ccode\u003ee6f5ca7\u003c/code\u003e\u003c/a\u003e 3.4.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/47f14fac0b1a41989f216b0cda4c50596ca339f6\"\u003e\u003ccode\u003e47f14fa\u003c/code\u003e\u003c/a\u003e removed E_STRICT from PHP\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/40505688464c49fe6374e7bc4cdd9bd2e9e6f330\"\u003e\u003ccode\u003e4050568\u003c/code\u003e\u003c/a\u003e fixced go-lang issues in CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/4303f4db38ba0ba8d5e2ed6e9689cefc74c46b63\"\u003e\u003ccode\u003e4303f4d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/101\"\u003e#101\u003c/a\u003e from mfinelli/gocriticfixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/106735b609c15df51539a0d7c0a270182efd904c\"\u003e\u003ccode\u003e106735b\u003c/code\u003e\u003c/a\u003e updated package-lock.json\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/670a1bdf9dcfba02111c3034294366f10696fb53\"\u003e\u003ccode\u003e670a1bd\u003c/code\u003e\u003c/a\u003e 3.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/50a61a90ea5ca64c114f0aa040ad127e3a97feff\"\u003e\u003ccode\u003e50a61a9\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/104\"\u003e#104\u003c/a\u003e - allow \u003ccode\u003enull\u003c/code\u003e as replacer value\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/8aa64f460cf0c4dac9cc214c831aade28f8f2c6e\"\u003e\u003ccode\u003e8aa64f4\u003c/code\u003e\u003c/a\u003e solved crytical errors over dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/b85577f39ff85959d02e8862cc0dde8114b43762\"\u003e\u003ccode\u003eb85577f\u003c/code\u003e\u003c/a\u003e Fix go-critic errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/bb8c63cea5befd4315519cb4458c6fc07bb9cf7b\"\u003e\u003ccode\u003ebb8c63c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/100\"\u003e#100\u003c/a\u003e from WebReflection/WebReflection-patch-1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/WebReflection/flatted/compare/v3.3.3...v3.4.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lodash` from 4.17.21 to 4.18.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lodash/lodash/releases\"\u003elodash's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.18.1\u003c/h2\u003e\n\u003ch2\u003eBugs\u003c/h2\u003e\n\u003cp\u003eFixes a \u003ccode\u003eReferenceError\u003c/code\u003e issue in \u003ccode\u003elodash\u003c/code\u003e \u003ccode\u003elodash-es\u003c/code\u003e \u003ccode\u003elodash-amd\u003c/code\u003e and \u003ccode\u003elodash.template\u003c/code\u003e when using the \u003ccode\u003etemplate\u003c/code\u003e and \u003ccode\u003efromPairs\u003c/code\u003e functions from the modular builds. See \u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769\"\u003elodash/lodash#6167\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThese defects were related to how lodash distributions are built from the main branch using \u003ca href=\"https://github.com/lodash-archive/lodash-cli\"\u003ehttps://github.com/lodash-archive/lodash-cli\u003c/a\u003e. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.\u003c/p\u003e\n\u003cp\u003eThere is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elodash\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-es\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-amd\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash.template\u003c/code\u003e\u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.18.0\u003c/h2\u003e\n\u003ch2\u003ev4.18.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.23...4.18.0\"\u003ehttps://github.com/lodash/lodash/compare/4.17.23...4.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.unset\u003c/code\u003e / \u003ccode\u003e_.omit\u003c/code\u003e\u003c/strong\u003e: Fixed prototype pollution via \u003ccode\u003econstructor\u003c/code\u003e/\u003ccode\u003eprototype\u003c/code\u003e path traversal (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh\"\u003eGHSA-f23m-r3pf-42rh\u003c/a\u003e, \u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003efe8d32e\u003c/a\u003e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now \u003ccode\u003econstructor\u003c/code\u003e and \u003ccode\u003eprototype\u003c/code\u003e are blocked unconditionally as non-terminal path keys, matching \u003ccode\u003ebaseSet\u003c/code\u003e. Calls that previously returned \u003ccode\u003etrue\u003c/code\u003e and deleted the property now return \u003ccode\u003efalse\u003c/code\u003e and leave the target untouched.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.template\u003c/code\u003e\u003c/strong\u003e: Fixed code injection via \u003ccode\u003eimports\u003c/code\u003e keys (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc\"\u003eGHSA-r5fr-rjxr-66jc\u003c/a\u003e, CVE-2026-4800, \u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e879aaa9\u003c/a\u003e). Fixes an incomplete patch for CVE-2021-23337. The \u003ccode\u003evariable\u003c/code\u003e option was validated against \u003ccode\u003ereForbiddenIdentifierChars\u003c/code\u003e but \u003ccode\u003eimportsKeys\u003c/code\u003e was left unguarded, allowing code injection via the same \u003ccode\u003eFunction()\u003c/code\u003e constructor sink. \u003ccode\u003eimports\u003c/code\u003e keys containing forbidden identifier characters now throw \u003ccode\u003e\u0026quot;Invalid imports option passed into _.template\u0026quot;\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd security notice for \u003ccode\u003e_.template\u003c/code\u003e in threat model and API docs (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6099\"\u003e#6099\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocument \u003ccode\u003elower \u0026gt; upper\u003c/code\u003e behavior in \u003ccode\u003e_.random\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6115\"\u003e#6115\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix quotes in \u003ccode\u003e_.compact\u003c/code\u003e jsdoc (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6090\"\u003e#6090\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003elodash.*\u003c/code\u003e modular packages\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6157\"\u003eDiff\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe have also regenerated and published a select number of the \u003ccode\u003elodash.*\u003c/code\u003e modular packages.\u003c/p\u003e\n\u003cp\u003eThese modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.orderby\"\u003elodash.orderby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.tonumber\"\u003elodash.tonumber\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trim\"\u003elodash.trim\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trimend\"\u003elodash.trimend\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.sortedindexby\"\u003elodash.sortedindexby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.zipobjectdeep\"\u003elodash.zipobjectdeep\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.unset\"\u003elodash.unset\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.omit\"\u003elodash.omit\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.template\"\u003elodash.template\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e\"\u003e\u003ccode\u003ecb0b9b9\u003c/code\u003e\u003c/a\u003e release(patch): bump main to 4.18.1 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6177\"\u003e#6177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51\"\u003e\u003ccode\u003e75535f5\u003c/code\u003e\u003c/a\u003e chore: prune stale advisory refs (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6170\"\u003e#6170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4\"\u003e\u003ccode\u003e62e91bc\u003c/code\u003e\u003c/a\u003e docs: remove n_ Node.js \u0026lt; 6 REPL note from README (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6165\"\u003e#6165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4\"\u003e\u003ccode\u003e59be2de\u003c/code\u003e\u003c/a\u003e release(minor): bump to 4.18.0 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6161\"\u003e#6161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d\"\u003e\u003ccode\u003eaf63457\u003c/code\u003e\u003c/a\u003e fix: broken tests for _.template 879aaa9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0\"\u003e\u003ccode\u003e1073a76\u003c/code\u003e\u003c/a\u003e fix: linting issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e\u003ccode\u003e879aaa9\u003c/code\u003e\u003c/a\u003e fix: validate imports keys in _.template\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003e\u003ccode\u003efe8d32e\u003c/code\u003e\u003c/a\u003e fix: block prototype pollution in baseUnset via constructor/prototype traversal\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d\"\u003e\u003ccode\u003e18ba0a3\u003c/code\u003e\u003c/a\u003e refactor(fromPairs): use baseAssignValue for consistent assignment (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6153\"\u003e#6153\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2\"\u003e\u003ccode\u003eb819080\u003c/code\u003e\u003c/a\u003e ci: add dist sync validation workflow (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6137\"\u003e#6137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.21...4.18.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.20\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/johnemau\"\u003e\u003ccode\u003e@​johnemau\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/johnemau\"\u003e\u003ccode\u003e@​johnemau\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/d76f633e0201c1299d735a6544c4c4a05c882f0b\"\u003e\u003ccode\u003ed76f633\u003c/code\u003e\u003c/a\u003e Release 3.3.20 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/ac09ff646dd64de1d03827c288ce30bb26c4315c\"\u003e\u003ccode\u003eac09ff6\u003c/code\u003e\u003c/a\u003e Fix: async return types are synchronous in v3 (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/615\"\u003e#615\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/co...\n\n_Description has been truncated_","html_url":"https://github.com/jmsmuigai/upili-app/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jmsmuigai%2Fupili-app/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T19:22:06.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5734152262","node_id":"PR_kwDOPUh5388AAAABG-6a_g","number":2102,"state":"open","title":"chore(deps): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":["CarmenDou"],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:22:06.000Z","updated_at":"2026-10-06T19:22:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/InsForge/InsForge/network/alerts).\n\n\u003c/details\u003e\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps `source-map-js` from 1.2.1 to 1.2.2 to fix CVE-2026-93749, a denial-of-service vulnerability in malicious indexed source maps. Also fixes a crash in browsers with CSP that disallows `unsafe-eval`. No breaking changes; only `package-lock.json` is updated.\n\n\u003csup\u003eWritten for commit c37547444f7fa506222243454b9de5e2737cc83e. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/InsForge/InsForge/pull/2102?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e \u003ca href=\"https://www.cubic.dev/action/auto-fix/pr/InsForge/InsForge/2102?returnTo=https%3A%2F%2Fgithub.com%2FInsForge%2FInsForge%2Fpull%2F2102\u0026source=description\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/turn-on-auto-fix-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/turn-on-auto-fix-light.svg\"\u003e\u003cimg alt=\"Turn on auto-fix\" src=\"https://www.cubic.dev/buttons/turn-on-auto-fix-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/InsForge/InsForge/pull/2102","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/InsForge%2FInsForge/issues/2102","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2102/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":"the npm_and_yarn group across 1 directory","pr_created_at":"2026-10-06T19:07:31.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5733959373","node_id":"PR_kwDORsHvZs8AAAABG-wfnQ","number":42,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2 in the npm_and_yarn group across 1 directory","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:07:31.000Z","updated_at":"2026-10-06T19:08:12.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":"the npm_and_yarn group across 1 directory","ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [source-map-js](https://github.com/7rulnik/source-map-js).\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Devam759/Sabrang-26/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Devam759/Sabrang-26/pull/42","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Devam759%2FSabrang-26/issues/42","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/42/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T19:05:49.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5733938226","node_id":"PR_kwDONuoEHs8AAAABG-vaXA","number":758,"state":"open","title":"chore(package.json): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T19:05:49.000Z","updated_at":"2026-10-06T19:06:12.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(package.json)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/diegocasmo/findmomentum.xyz/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/diegocasmo/findmomentum.xyz/pull/758","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/diegocasmo%2Ffindmomentum.xyz/issues/758","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/758/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T18:35:46.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5733548990","node_id":"PR_kwDOB5PDcM8AAAABG-buaQ","number":77,"state":"open","title":"chore(deps): bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["dependencies","npm"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T18:35:46.000Z","updated_at":"2026-10-06T18:37:51.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js\u0026package-manager=npm_and_yarn\u0026previous-version=1.2.1\u0026new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ctftnks/ctftnks.github.io/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ctftnks/ctftnks.github.io/pull/77","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ctftnks%2Fctftnks.github.io/issues/77","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/77/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T18:23:45.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5733392850","node_id":"PR_kwDOTJYz_s8AAAABG-TrRg","number":131,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-10-06T18:26:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-10-06T18:23:45.000Z","updated_at":"2026-10-06T18:26:01.000Z","time_to_close":136,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"},{"name":"compression","old_version":"1.8.1","new_version":"1.8.2","repository_url":"https://github.com/expressjs/compression"},{"name":"moment","old_version":"2.30.1","new_version":"2.31.0","repository_url":"https://github.com/moment/moment"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 3 updates in the /artifacts/aurora-mobile directory: [source-map-js](https://github.com/7rulnik/source-map-js), [compression](https://github.com/expressjs/compression) and [moment](https://github.com/moment/moment).\n\nUpdates `source-map-js` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `compression` from 1.8.1 to 1.8.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/compression/releases\"\u003ecompression's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.8.2\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-87776\"\u003eCVE-2026-87776\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95\"\u003eGHSA-vc2v-76pw-4v95\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: add funding to package.json by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/248\"\u003eexpressjs/compression#248\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 3.29.2 to 3.29.5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/249\"\u003eexpressjs/compression#249\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 4.2.2 to 5.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/253\"\u003eexpressjs/compression#253\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 3.29.7 to 3.29.11 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/252\"\u003eexpressjs/compression#252\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 4.3.0 to 5.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/251\"\u003eexpressjs/compression#251\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 4.4.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/261\"\u003eexpressjs/compression#261\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 3.29.11 to 4.31.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/260\"\u003eexpressjs/compression#260\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/259\"\u003eexpressjs/compression#259\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/258\"\u003eexpressjs/compression#258\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/264\"\u003eexpressjs/compression#264\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/263\"\u003eexpressjs/compression#263\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.2 to 4.31.5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/262\"\u003eexpressjs/compression#262\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: up node version to 25.x in CI by \u003ca href=\"https://github.com/imangas\"\u003e\u003ccode\u003e@​imangas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/272\"\u003eexpressjs/compression#272\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edoc(package): remove history.md and add readme.md to published files by \u003ca href=\"https://github.com/sheplu\"\u003e\u003ccode\u003e@​sheplu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/270\"\u003eexpressjs/compression#270\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate link to CONTRIBUTING.md by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/281\"\u003eexpressjs/compression#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: run CI on Windows and macOS by \u003ca href=\"https://github.com/kilisamemarisaaa\"\u003e\u003ccode\u003e@​kilisamemarisaaa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/283\"\u003eexpressjs/compression#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/257\"\u003eexpressjs/compression#257\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/268\"\u003eexpressjs/compression#268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.5 to 4.31.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/265\"\u003eexpressjs/compression#265\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/266\"\u003eexpressjs/compression#266\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/267\"\u003eexpressjs/compression#267\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): npm-publish via reusable workflows by \u003ca href=\"https://github.com/sheplu\"\u003e\u003ccode\u003e@​sheplu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/269\"\u003eexpressjs/compression#269\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update outdated Brotli note and fix npm install docs URL by \u003ca href=\"https://github.com/Vansh1811\"\u003e\u003ccode\u003e@​Vansh1811\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/276\"\u003eexpressjs/compression#276\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: match Cache-Control no-transform directive case-insensitively by \u003ca href=\"https://github.com/vaibhavmashal\"\u003e\u003ccode\u003e@​vaibhavmashal\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/286\"\u003eexpressjs/compression#286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.8.2 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/287\"\u003eexpressjs/compression#287\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/imangas\"\u003e\u003ccode\u003e@​imangas\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/272\"\u003eexpressjs/compression#272\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sheplu\"\u003e\u003ccode\u003e@​sheplu\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/270\"\u003eexpressjs/compression#270\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/281\"\u003eexpressjs/compression#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kilisamemarisaaa\"\u003e\u003ccode\u003e@​kilisamemarisaaa\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/283\"\u003eexpressjs/compression#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Vansh1811\"\u003e\u003ccode\u003e@​Vansh1811\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/276\"\u003eexpressjs/compression#276\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vaibhavmashal\"\u003e\u003ccode\u003e@​vaibhavmashal\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/compression/pull/286\"\u003eexpressjs/compression#286\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2\"\u003ehttps://github.com/expressjs/compression/compare/v1.8.1...v1.8.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/compression/blob/master/HISTORY.md\"\u003ecompression's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.8.2\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-87776\"\u003eCVE-2026-87776\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95\"\u003eGHSA-vc2v-76pw-4v95\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edeps: add destroy@1.2.0\u003c/li\u003e\n\u003cli\u003eMatch \u003ccode\u003eCache-Control: no-transform\u003c/code\u003e directive case-insensitively\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/0f9707417bd53d41a319fce8bdb80dfa08b435c8\"\u003e\u003ccode\u003e0f97074\u003c/code\u003e\u003c/a\u003e 1.8.2 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/287\"\u003e#287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff\"\u003e\u003ccode\u003e151f63e\u003c/code\u003e\u003c/a\u003e fix: destroy compression stream on response close\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/0a764956691bede2b62c711598ee65ea643d3b1e\"\u003e\u003ccode\u003e0a76495\u003c/code\u003e\u003c/a\u003e fix: match Cache-Control no-transform directive case-insensitively (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/286\"\u003e#286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/c17b6e58ac914c84d9e3a64130dcc428e0e26887\"\u003e\u003ccode\u003ec17b6e5\u003c/code\u003e\u003c/a\u003e docs: update outdated Brotli note and fix npm install docs URL (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/276\"\u003e#276\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/112911abc46e0d8fa6c9793ef5005ca1d53ccb7c\"\u003e\u003ccode\u003e112911a\u003c/code\u003e\u003c/a\u003e chore(ci): npm-publish via reusable workflows (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/269\"\u003e#269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/1bf5eb0b5eaf5001af9782ade18c6cca690ccaad\"\u003e\u003ccode\u003e1bf5eb0\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/267\"\u003e#267\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/d8fe64d50081d4a13a8ea5c25a852ca27fde0b7b\"\u003e\u003ccode\u003ed8fe64d\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/266\"\u003e#266\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/b218ff54eb8e211100d8a6697d13cdc73fdb13b3\"\u003e\u003ccode\u003eb218ff5\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/265\"\u003e#265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/8a1cf8ecf948c28ffd3d29f942c9a310bc36e5c1\"\u003e\u003ccode\u003e8a1cf8e\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/268\"\u003e#268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/compression/commit/4a19855442b7ebfcea4f95caf491968108dc15b8\"\u003e\u003ccode\u003e4a19855\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (\u003ca href=\"https://redirect.github.com/expressjs/compression/issues/257\"\u003e#257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for compression since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `moment` from 2.30.1 to 2.31.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/moment/moment/releases\"\u003emoment's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.31.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003eReleased Sep 14, 2026\u003c/em\u003e\u003c/p\u003e\n\u003ch4\u003eSecurity fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-17495\"\u003eCVE-2026-17495\u003c/a\u003e (\u003ca href=\"https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw\"\u003eGHSA-4p3w-j4w9-5jqw\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eBug fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6376\"\u003e#6376\u003c/a\u003e Prevent object prototype properties from being used as format tokens\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6386\"\u003e#6386\u003c/a\u003e Normalize lazy-loaded locale names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6404\"\u003e#6404\u003c/a\u003e Fix parsing issue with \u003ccode\u003eeHHmm\u003c/code\u003e format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6433\"\u003e#6433\u003c/a\u003e Ignore non-Moment arguments in min and max\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6434\"\u003e#6434\u003c/a\u003e Fix inherited lowercase long date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6436\"\u003e#6436\u003c/a\u003e Reset locale parsing caches after updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6437\"\u003e#6437\u003c/a\u003e Fix weekday mismatch when the format only has part of a date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6442\"\u003e#6442\u003c/a\u003e Fix \u003ccode\u003elocale('__proto__')\u003c/code\u003e corrupting the global locale\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6443\"\u003e#6443\u003c/a\u003e Avoid \u003ccode\u003eObject.assign\u003c/code\u003e in \u003ccode\u003eduration.humanize\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6446\"\u003e#6446\u003c/a\u003e Validate range when parsing a time zone offset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6447\"\u003e#6447\u003c/a\u003e Include metadata in all-locales bundle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6448\"\u003e#6448\u003c/a\u003e Apply postformat to locale relative time methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6450\"\u003e#6450\u003c/a\u003e Add stack traces to conditional deprecation warnings\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eNew features\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6451\"\u003e#6451\u003c/a\u003e Add internal date-default hook for Moment Timezone\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eNew locales\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6000\"\u003e#6000\u003c/a\u003e: Pashto ('ps')\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6278\"\u003e#6278\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/moment/moment/pull/6379\"\u003e#6379\u003c/a\u003e: Amharic (Ethiopia) ('am-et')\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eUpdates to existing locales\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/5404\"\u003e#5404\u003c/a\u003e Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6197\"\u003e#6197\u003c/a\u003e Indonesian ('id'): Correct the abbreviation for August\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6217\"\u003e#6217\u003c/a\u003e Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct \u003ccode\u003eL\u003c/code\u003e date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6289\"\u003e#6289\u003c/a\u003e Swedish ('sv'): Correct the abbreviation for Thursday\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6306\"\u003e#6306\u003c/a\u003e Catalan ('ca'): Use typographic apostrophes in relative time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6347\"\u003e#6347\u003c/a\u003e Swahili ('sw'): Correct the spelling of hour in calendar output\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6360\"\u003e#6360\u003c/a\u003e Ukrainian ('uk'): Use ISO week numbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6370\"\u003e#6370\u003c/a\u003e Ukrainian ('uk'): Use U+02BC apostrophes in Friday names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6371\"\u003e#6371\u003c/a\u003e Hungarian ('hu'): Preserve numeric values in relative seconds\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6391\"\u003e#6391\u003c/a\u003e Swahili ('sw'): Fix weekday and relative-time grammar\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6396\"\u003e#6396\u003c/a\u003e German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6409\"\u003e#6409\u003c/a\u003e Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6410\"\u003e#6410\u003c/a\u003e Polish ('pl'): Use genitive month names in dotted day formats\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/moment/moment/blob/develop/CHANGELOG.md\"\u003emoment's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2.31.0\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eReleased Sep 14, 2026\u003c/em\u003e\u003c/p\u003e\n\u003ch4\u003eSecurity fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-17495\"\u003eCVE-2026-17495\u003c/a\u003e (\u003ca href=\"https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw\"\u003eGHSA-4p3w-j4w9-5jqw\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eBug fixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6376\"\u003e#6376\u003c/a\u003e Prevent object prototype properties from being used as format tokens\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6386\"\u003e#6386\u003c/a\u003e Normalize lazy-loaded locale names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6404\"\u003e#6404\u003c/a\u003e Fix parsing issue with \u003ccode\u003eeHHmm\u003c/code\u003e format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6433\"\u003e#6433\u003c/a\u003e Ignore non-Moment arguments in min and max\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6434\"\u003e#6434\u003c/a\u003e Fix inherited lowercase long date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6436\"\u003e#6436\u003c/a\u003e Reset locale parsing caches after updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6437\"\u003e#6437\u003c/a\u003e Fix weekday mismatch when the format only has part of a date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6442\"\u003e#6442\u003c/a\u003e Fix \u003ccode\u003elocale('__proto__')\u003c/code\u003e corrupting the global locale\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6443\"\u003e#6443\u003c/a\u003e Avoid \u003ccode\u003eObject.assign\u003c/code\u003e in \u003ccode\u003eduration.humanize\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6446\"\u003e#6446\u003c/a\u003e Validate range when parsing a time zone offset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6447\"\u003e#6447\u003c/a\u003e Include metadata in all-locales bundle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6448\"\u003e#6448\u003c/a\u003e Apply postformat to locale relative time methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6450\"\u003e#6450\u003c/a\u003e Add stack traces to conditional deprecation warnings\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eNew features\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6451\"\u003e#6451\u003c/a\u003e Add internal date-default hook for Moment Timezone\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eNew locales\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6000\"\u003e#6000\u003c/a\u003e: Pashto ('ps')\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6278\"\u003e#6278\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/moment/moment/pull/6379\"\u003e#6379\u003c/a\u003e: Amharic (Ethiopia) ('am-et')\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eUpdates to existing locales\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/5404\"\u003e#5404\u003c/a\u003e Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6197\"\u003e#6197\u003c/a\u003e Indonesian ('id'): Correct the abbreviation for August\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6217\"\u003e#6217\u003c/a\u003e Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct \u003ccode\u003eL\u003c/code\u003e date formats\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6289\"\u003e#6289\u003c/a\u003e Swedish ('sv'): Correct the abbreviation for Thursday\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6306\"\u003e#6306\u003c/a\u003e Catalan ('ca'): Use typographic apostrophes in relative time\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6347\"\u003e#6347\u003c/a\u003e Swahili ('sw'): Correct the spelling of hour in calendar output\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6360\"\u003e#6360\u003c/a\u003e Ukrainian ('uk'): Use ISO week numbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6370\"\u003e#6370\u003c/a\u003e Ukrainian ('uk'): Use U+02BC apostrophes in Friday names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6371\"\u003e#6371\u003c/a\u003e Hungarian ('hu'): Preserve numeric values in relative seconds\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6391\"\u003e#6391\u003c/a\u003e Swahili ('sw'): Fix weekday and relative-time grammar\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6396\"\u003e#6396\u003c/a\u003e German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6409\"\u003e#6409\u003c/a\u003e Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/moment/moment/pull/6410\"\u003e#6410\u003c/a\u003e Polish ('pl'): Use genitive month names in dotted day formats\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/15b45d48a176312e8f34143c5a800090abf4787f\"\u003e\u003ccode\u003e15b45d4\u003c/code\u003e\u003c/a\u003e [pkg] Build 2.31.0 (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6452\"\u003e#6452\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/631cd81454ee001e1f508e21270eae0b6bb62974\"\u003e\u003ccode\u003e631cd81\u003c/code\u003e\u003c/a\u003e [pkg] Update changelog for upcoming release (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6394\"\u003e#6394\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/6caff9e0d54e85a63a6eb97d7361f1da35bc58f4\"\u003e\u003ccode\u003e6caff9e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/710703b7eac93535ad125cbf4feb3d42afed6fb3\"\u003e\u003ccode\u003e710703b\u003c/code\u003e\u003c/a\u003e [feature] Add internal date-default hook for Moment Timezone (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6451\"\u003e#6451\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/863ed940556e6e63c43de23981a4853036a003ac\"\u003e\u003ccode\u003e863ed94\u003c/code\u003e\u003c/a\u003e [bugfix] Add stack traces to conditional deprecation warnings (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6450\"\u003e#6450\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/2c7abe1c42ee15445d30c2c5d536750a1e43a09a\"\u003e\u003ccode\u003e2c7abe1\u003c/code\u003e\u003c/a\u003e [bugfix] Apply postformat to locale relative time methods (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6448\"\u003e#6448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/9c45ac38690c649c95e19923276b63da5fe2be26\"\u003e\u003ccode\u003e9c45ac3\u003c/code\u003e\u003c/a\u003e [bugfix] Include metadata in all-locales bundle (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6447\"\u003e#6447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/f6eefc5fc7b44ceccbd007aeffc48ebc5eac30fa\"\u003e\u003ccode\u003ef6eefc5\u003c/code\u003e\u003c/a\u003e [bugfix] Validate timezone offset range (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6446\"\u003e#6446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/136b441794a3bb207d593add3b59e9de0e062523\"\u003e\u003ccode\u003e136b441\u003c/code\u003e\u003c/a\u003e [bugfix] Avoid Object.assign in duration.humanize (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6443\"\u003e#6443\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moment/moment/commit/0d1050437b40f66ac47e14b285bb3d09676cf2e0\"\u003e\u003ccode\u003e0d10504\u003c/code\u003e\u003c/a\u003e [bugfix] Fix locale('\u003cstrong\u003eproto\u003c/strong\u003e') corrupting the global locale (\u003ca href=\"https://redirect.github.com/moment/moment/issues/6442\"\u003e#6442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/moment/moment/compare/2.30.1...2.31.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for moment since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/josephcrown920/Auroraglobal/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/josephcrown920/Auroraglobal/pull/131","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/josephcrown920%2FAuroraglobal/issues/131","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/131/packages"}},{"old_version":"1.2.1","new_version":"1.2.2","update_type":"patch","path":null,"pr_created_at":"2026-10-06T18:07:39.000Z","version_change":"1.2.1 → 1.2.2","issue":{"uuid":"5733183112","node_id":"PR_kwDOACBxpM8AAAABG-JLtg","number":42986,"state":"open","title":"Bump source-map-js from 1.2.1 to 1.2.2","user":"dependabot[bot]","labels":["v5","dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-06T18:07:39.000Z","updated_at":"2026-10-06T18:18:21.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"source-map-js","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/7rulnik/source-map-js"}],"path":null,"ecosystem":"npm"},"body":"Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/releases\"\u003esource-map-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md\"\u003esource-map-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix crash when executing in browser with CSP script-src that don't permit unsafe-eval (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/29\"\u003e#29\u003c/a\u003e) \u003ca href=\"https://github.com/xfournet\"\u003e\u003ccode\u003e@​xfournet\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/79\"\u003e#79\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eReported by \u003ca href=\"https://github.com/waydeshi\"\u003e\u003ccode\u003e@​waydeshi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/76\"\u003e#76\u003c/a\u003e. A fix was also proposed by \u003ca href=\"https://github.com/aniebiet\"\u003e\u003ccode\u003e@​aniebiet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/pull/78\"\u003e#78\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a\"\u003e\u003ccode\u003e0a1d334\u003c/code\u003e\u003c/a\u003e 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739\"\u003e\u003ccode\u003e4c6fa26\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016\"\u003e\u003ccode\u003ecf76580\u003c/code\u003e\u003c/a\u003e Fix denial of service from malicious indexed source maps (CVE-2026-93749) (\u003ca href=\"https://redirect.github.com/7rulnik/source-map-js/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df\"\u003e\u003ccode\u003e7899a86\u003c/code\u003e\u003c/a\u003e Fix crash when executing browser with CSP script-src that don't permit unsafe...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/twbs/bootstrap/pull/42986","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/twbs%2Fbootstrap/issues/42986","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/42986/packages"}}]}