An open index of dependabot pull requests across open source projects.

build(deps): bump the npm_and_yarn group across 1 directory with 8 updates

Open
Number: #174
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 2
Created: November 14, 2025 at 03:41 PM UTC
(5 days ago)
Updated: November 14, 2025 at 03:41 PM UTC
(5 days ago)
Labels:
dependencies dependabot-semver-unknown alert-severity-MODERATE javascript
Description:

Bumps the npm_and_yarn group with 1 update in the / directory: semantic-release.

Updates semantic-release from 17.4.7 to 19.0.3

Commits
  • 58a226f fix(log-repo): use the original form of the repo url to remove the need to ma...
  • 17d60d3 build(deps): bump npm from 8.3.1 to 8.12.0 (#2447)
  • ab45ab1 chore(lint): disabled rules that dont apply to this project (#2408)
  • ea389c3 chore(deps): update dependency yargs-parser to 13.1.2 [security] (#2402)
  • fa994db build(deps): bump node-fetch from 2.6.1 to 2.6.7 (#2399)
  • b79116b build(deps): bump trim-off-newlines from 1.0.1 to 1.0.3
  • 6fd7e56 build(deps): bump minimist from 1.2.5 to 1.2.6
  • 2b94bb4 docs: update broken link to CI config recipes (#2378)
  • b4bc191 docs: Correct circleci workflow (#2365)
  • 2c30e26 Merge pull request #2333 from semantic-release/next
  • Additional commits viewable in compare view

Updates @octokit/plugin-paginate-rest from 2.11.0 to 6.1.2

Release notes

Sourced from @​octokit/plugin-paginate-rest's releases.

v6.1.2

6.1.2 (2023-05-19)

Bug Fixes

  • build: replace Pika with esbuild and tsc (#527) (3ba0db6)

v6.1.1

6.1.1 (2023-05-19)

Bug Fixes

v6.1.0

6.1.0 (2023-05-12)

Features

v6.0.0

6.0.0 (2023-01-20)

Features

BREAKING CHANGES

  • remove defunct endpoints

v5.0.1

5.0.1 (2022-10-13)

Bug Fixes

  • release: use org secret for npm token to fix publishing to npm (d2ab1b5)

v5.0.0

5.0.0 (2022-10-13)

Bug Fixes

... (truncated)

Commits

Updates @octokit/request-error from 2.0.5 to 3.0.3

Release notes

Sourced from @​octokit/request-error's releases.

v3.0.3

3.0.3 (2023-01-20)

Bug Fixes

  • deps: update dependency @​octokit/types to v9 (#307) (82c78fc)

v3.0.2

3.0.2 (2022-10-13)

Bug Fixes

  • deps: update dependency @​octokit/types to v8 (4cabbec)

v3.0.1

3.0.1 (2022-08-15)

Bug Fixes

  • deps: update dependency @​octokit/types to v7 (#254) (5abe81a)

v3.0.0

3.0.0 (2022-07-08)

Continuous Integration

  • stop testing against NodeJS v10, v12 (#236) (0a86afe)

BREAKING CHANGES

  • Drop support for NodeJS v10, v12

v2.1.0

2.1.0 (2021-06-11)

Features

  • error.response. Deprecates error.headers (#194) (487082b)

v2.0.6

2.0.6 (2021-06-11)

Bug Fixes

... (truncated)

Commits

Updates @octokit/request from 5.4.14 to 6.2.8

Release notes

Sourced from @​octokit/request's releases.

v6.2.8

6.2.8 (2023-06-16)

Reverts

  • Revert "fix(deps): update dependency @​octokit/request-error to v4 (#593)" (9c9c6d7), closes #593

v6.2.7

6.2.7 (2023-06-16)

Bug Fixes

  • deps: update dependency @​octokit/request-error to v4 (#593) (62f51d6)

v6.2.6

6.2.6 (2023-06-13)

Bug Fixes

  • deps: update dependency @octokit/tsconfig to v2, explicitly mark type imports (#588) (71d7488)

v6.2.5

6.2.5 (2023-05-18)

Bug Fixes

  • build: replace pika with esbuild and tsc (#584) (947d7a5)

v6.2.4

6.2.4 (2023-05-16)

Bug Fixes

  • addsduplex option when sending a body (3df1556), closes #570

v6.2.3

6.2.3 (2023-01-21)

Bug Fixes

  • deps: update dependency @​octokit/types to v9 (9247e87)

v6.2.2

6.2.2 (2022-10-13)

... (truncated)

Commits
  • 9c9c6d7 Revert "fix(deps): update dependency @​octokit/request-error to v4 (#593)"
  • 62f51d6 fix(deps): update dependency @​octokit/request-error to v4 (#593)
  • cbd121f docs: replace references to Skypack CDN with esm.sh (#595)
  • 71d7488 fix(deps): update dependency @octokit/tsconfig to v2, explicitly mark type ...
  • ab33ea2 chore(deps): update dependency esbuild to ^0.18.0 (#590)
  • 947d7a5 fix(build): replace pika with esbuild and tsc (#584)
  • 3df1556 fix: addsduplex option when sending a body
  • 792a68f chore(deps): update dependency prettier to v2.8.8
  • 2970f68 ci(action): update actions/add-to-project action to v0.5.0 (#578)
  • cdf3701 [fix] addsduplex option when sending a body
  • Additional commits viewable in compare view

Updates http-cache-semantics from 3.8.1 to 4.2.0

Commits

Updates marked from 2.0.1 to 4.3.0

Release notes

Sourced from marked's releases.

v4.3.0

4.3.0 (2023-03-22)

Bug Fixes

Features

v4.2.12

4.2.12 (2023-01-14)

Sorry for all of the quick releases. We were testing out different ways to build the files for releases. v4.2.5 - v4.2.12 have no changes to how marked works. The only addition is the version number in the comment in the build files.

Bug Fixes

  • revert to build script in ci (d2ab474)

v4.2.11

4.2.11 (2023-01-14)

Bug Fixes

v4.2.10

4.2.10 (2023-01-14)

Bug Fixes

v4.2.9

4.2.9 (2023-01-14)

Bug Fixes

... (truncated)

Commits
  • d65cf63 chore(release): 4.3.0 [skip ci]
  • 28f4342 🗜️ build v4.3.0 [skip ci]
  • 9b452bc feat: add preprocess and postprocess hooks (#2730)
  • 042dcc5 fix: always return promise if async (#2728)
  • 3acbb7f fix: fenced code doesn't need a trailing newline (#2756)
  • d1f1319 chore(deps-dev): Bump rollup from 3.19.1 to 3.20.0 (#2760)
  • 0ced8a5 chore(deps-dev): Bump jasmine from 4.5.0 to 4.6.0 (#2758)
  • a5bbe19 chore(deps-dev): Bump @​babel/core from 7.21.0 to 7.21.3 (#2761)
  • 00f6e2a chore(deps-dev): Bump semantic-release from 20.1.1 to 20.1.3 (#2759)
  • 8c7bca8 chore(deps-dev): Bump node-fetch from 3.3.0 to 3.3.1 (#2754)
  • Additional commits viewable in compare view

Updates tar from 4.4.19 to 6.2.1

Release notes

Sourced from tar's releases.

v6.1.13

6.1.13 (2022-12-07)

Dependencies

v6.1.12

6.1.12 (2022-10-31)

Bug Fixes

Documentation

Changelog

Sourced from tar's changelog.

Changelog

7.5

  • Added zstd compression support.

7.4

  • Deprecate onentry in favor of onReadEntry for clarity.

7.3

  • Add onWriteEntry option

7.2

  • DRY the command definitions into a single makeCommand method, and update the type signatures to more appropriately infer the return type from the options and arguments provided.

7.1

  • Update minipass to v7.1.0
  • Update the type definitions of write() and end() methods on Unpack and Parser classes to be compatible with the NodeJS.WritableStream type in the latest versions of @types/node.

7.0

  • Drop support for node <18
  • Rewrite in TypeScript, provide ESM and CommonJS hybrid interface
  • Add tree-shake friendly exports, like import('tar/create') and import('tar/read-entry') to get individual functions or classes.
  • Add chmod option that defaults to false, and deprecate noChmod. That is, reverse the default option regarding explicitly setting file system modes to match tar entry settings.
  • Add processUmask option to avoid having to call process.umask() when chmod: true (or noChmod: false) is set.

6.2

  • Add support for brotli compression
  • Add maxDepth option to prevent extraction into excessively deep folders.

... (truncated)

Commits

Updates yargs-parser from 7.0.0 to 18.1.3

Release notes

Sourced from yargs-parser's releases.

yargs-parser yargs-parser-v15.0.3

Bug Fixes

  • build: should use releases_created when using manifest (49ea4ef)

yargs-parser yargs-parser-v15.0.2

Bug Fixes

  • perf: address slow parse when using unknown-options-as-args (#400) (bc387ec)
Changelog

Sourced from yargs-parser's changelog.

18.1.3 (2020-04-16)

Bug Fixes

  • setArg: options using camel-case and dot-notation populated twice (#268) (f7e15b9)

18.1.2 (2020-03-26)

Bug Fixes

  • array, nargs: support -o=--value and --option=--value format (#262) (41d3f81)

18.1.1 (2020-03-16)

Bug Fixes

  • __proto__ will now be replaced with ___proto___ in parse (#258), patching a potential prototype pollution vulnerability. This was reported by the Snyk Security Research Team.(63810ca)

18.1.0 (2020-03-07)

Features

  • introduce single-digit boolean aliases (#255) (9c60265)

18.0.0 (2020-03-02)

⚠ BREAKING CHANGES

  • the narg count is now enforced when parsing arrays.

Features

  • NaN can now be provided as a value for nargs, indicating "at least" one value is expected for array (#251) (9db4be8)

17.1.0 (2020-03-01)

Features

  • introduce greedy-arrays config, for specifying whether arrays consume multiple positionals (#249) (60e880a)

17.0.1 (2020-02-29)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by oss-bot, a new releaser for yargs-parser since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Ecosystem:
npm
Version Change:
17.4.7 → 19.0.3
Update Type:
Major
Package:
marked
Ecosystem:
npm
Version Change:
2.0.1 → 4.3.0
Update Type:
Major
Package:
tar
Ecosystem:
npm
Version Change:
4.4.19 → 6.2.1
Update Type:
Major
Ecosystem:
npm
Version Change:
3.8.1 → 4.2.0
Update Type:
Major
Ecosystem:
npm
Version Change:
2.11.0 → 6.1.2
Update Type:
Major
Ecosystem:
npm
Version Change:
5.4.14 → 6.2.8
Update Type:
Major
Ecosystem:
npm
Version Change:
2.0.5 → 3.0.3
Update Type:
Major
Ecosystem:
npm
Version Change:
7.0.0 → 18.1.3
Update Type:
Major
Technical Details
ID: 11032223
UUID: 3626131388
Node ID: PR_kwDOCmOt5s6ze-VT
Host: GitHub
Repository: intercom/contentful-typescript-codegen