chore(deps): bump ajv and @microsoft/api-extractor
Type: Pull Request
State: Open
Association: Unknown
Comments: 5
(4 months ago)
(3 months ago)
type: dependencies
Bumps ajv to 6.14.0 and updates ancestor dependencies ajv and @microsoft/api-extractor. These dependencies need to be updated together.
Updates ajv from 6.12.6 to 6.14.0
Commits
e3af0a76.14.0b552ed6add regExp option to address $data exploit via a regular expression (CVE-2025...72f2286docs: update v7 info231e52bMerge pull request #1320 from philsturgeon/patch-1d3475fcAdd spectral, an AJV util from a sponsor413afe0docs: v7.0.0-beta.311e997bupdate readme for v7- See full diff in compare view
Updates ajv from 8.11.0 to 8.18.0
Commits
e3af0a76.14.0b552ed6add regExp option to address $data exploit via a regular expression (CVE-2025...72f2286docs: update v7 info231e52bMerge pull request #1320 from philsturgeon/patch-1d3475fcAdd spectral, an AJV util from a sponsor413afe0docs: v7.0.0-beta.311e997bupdate readme for v7- See full diff in compare view
Updates ajv from 8.7.1 to 8.18.0
Commits
e3af0a76.14.0b552ed6add regExp option to address $data exploit via a regular expression (CVE-2025...72f2286docs: update v7 info231e52bMerge pull request #1320 from philsturgeon/patch-1d3475fcAdd spectral, an AJV util from a sponsor413afe0docs: v7.0.0-beta.311e997bupdate readme for v7- See full diff in compare view
Updates @microsoft/api-extractor from 7.36.3 to 7.57.2
Changelog
Sourced from @microsoft/api-extractor's changelog.
7.57.2
Fri, 20 Feb 2026 16:14:49 GMT
Patches
- Bump minimatch from 10.1.2 to 10.2.1
7.57.1
Fri, 20 Feb 2026 00:15:03 GMT
Patches
- Add
"node"condition before"import"in the"exports"map so that Node.js uses the CJS output (which handles extensionless imports), while bundlers still use ESM via"import". Fixes microsoft/rushstack#5644.7.57.0
Thu, 19 Feb 2026 00:04:52 GMT
Minor changes
- Normalize package layout. CommonJS is now under
lib-commonjs, DTS is now underlib-dts, and ESM is now underlib-esm. Imports tolibstill work as before, handled by the"exports"field inpackage.json.7.56.3
Sat, 07 Feb 2026 01:13:26 GMT
Patches
- Upgrade
lodashdependency from~4.17.15to~4.17.23.7.56.2
Wed, 04 Feb 2026 20:42:47 GMT
Patches
- Update minimatch dependency from 10.0.3 to 10.1.2
7.56.1
Wed, 04 Feb 2026 16:13:27 GMT
Version update only
7.56.0
Fri, 30 Jan 2026 01:16:12 GMT
Minor changes
- Fix an issue where destructured parameters produced an incorrect parameter name
7.55.5
Thu, 08 Jan 2026 01:12:30 GMT
... (truncated)
Commits
b06e297Bump versions [skip ci]2a59a81Update changelogs [skip ci]08cf3deBump minimatch in /webpack/webpack4-localization-plugin (#5651)53b1eaaBump versions [skip ci]618c203Update changelogs [skip ci]7e14cdafix: remove "import" entries from exports in package.json files (#5650)95ca0b5Bump decoupled local dependencies and fix some issues with projects' `rush-pr...4444a90Bump versions [skip ci]2e69104Update changelogs [skip ci]6d669f1Normalize the output folders tolib-commonjs,lib-dts, andlib-esmfor ...- Additional commits viewable in compare view
Most Recent Ignore Conditions Applied to This Pull Request
| Dependency Name | Ignore Conditions |
|---|---|
| @microsoft/api-extractor | [< 7.25, > 7.24.0] |
| @microsoft/api-extractor | [< 7.29, > 7.28.4] |
| @microsoft/api-extractor | [< 7.30, > 7.29.3] |
| @microsoft/api-extractor | [< 7.33, > 7.32.0] |
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Technical Details
| ID: | 14012091 |
| UUID: | 3973049155 |
| Node ID: | PR_kwDOG5lbN87FY5XF |
| Host: | GitHub |
| Repository: | OpenFunction/functions-framework-nodejs |