An open index of dependabot pull requests across open source projects.

Bump tar, auditjs and fsevents

Closed
Number: #22
Type: Pull Request
State: Closed
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: May 23, 2025 at 09:04 PM UTC
(about 1 year ago)
Updated: January 17, 2026 at 05:51 AM UTC
(5 months ago)
Closed: January 17, 2026 at 05:51 AM UTC
(5 months ago)
Time to Close: 8 months
Labels:
dependencies javascript
Description:

Removes tar. It's no longer used after updating ancestor dependencies tar, auditjs and fsevents. These dependencies need to be updated together.

Removes tar

Updates auditjs from 3.2.4 to 4.0.46

Release notes

Sourced from auditjs's releases.

v4.0.46

4.0.46 (2024-11-13)

Bug Fixes

  • latest mock-fs fixes failing unit tests after other updates, resolve CVE-2024-21538 in cross-spawn 7.0.3 (7a66cbb)
  • resolve CVE-2024-21538 in cross-spawn : 7.0.3 (4ade2a7)
  • resolve CVE-2024-21538 in cross-spawn : 7.0.3 (update CI node version) (d3378f5)
  • resolve CVE-2024-4068 in braces : 3.0.2 (d065149)
  • update CI 'release' target to use latest semantic-release, now that we use newer node version (e2ac821)

v4.0.45

4.0.45 (2024-01-17)

Bug Fixes

  • use semantic-release version that works with node 18 (newer node causes build errors). (a122b0e)

v4.0.44

4.0.44 (2024-01-10)

Bug Fixes

  • minor change to trigger release of PR# 276 (f676f91)

v4.0.43

4.0.43 (2023-12-13)

Bug Fixes

  • minor change to trigger release of fix for sonatype-2023-4801 (032b20a)

v4.0.42

4.0.42 (2023-12-13)

Bug Fixes

  • error TS2688: Cannot find type definition file for 'node'. (#274) (2d79b85)

v4.0.41

4.0.41 (2023-07-12)

Bug Fixes

... (truncated)

Changelog

Sourced from auditjs's changelog.

4.0.46 (2024-11-13)

Bug Fixes

  • latest mock-fs fixes failing unit tests after other updates, resolve CVE-2024-21538 in cross-spawn 7.0.3 (7a66cbb)
  • resolve CVE-2024-21538 in cross-spawn : 7.0.3 (4ade2a7)
  • resolve CVE-2024-21538 in cross-spawn : 7.0.3 (update CI node version) (d3378f5)
  • resolve CVE-2024-4068 in braces : 3.0.2 (d065149)
  • update CI 'release' target to use latest semantic-release, now that we use newer node version (e2ac821)

4.0.45 (2024-01-17)

Bug Fixes

  • use semantic-release version that works with node 18 (newer node causes build errors). (a122b0e)

4.0.44 (2024-01-10)

Bug Fixes

  • minor change to trigger release of PR# 276 (f676f91)

4.0.43 (2023-12-13)

Bug Fixes

  • minor change to trigger release of fix for sonatype-2023-4801 (032b20a)

4.0.42 (2023-12-13)

Bug Fixes

  • error TS2688: Cannot find type definition file for 'node'. (#274) (2d79b85)

4.0.41 (2023-07-12)

Bug Fixes

  • sonatype-2022-3677 in node-fetch 2.6.7 (d1b15ab)

4.0.40 (2023-06-22)

Bug Fixes

... (truncated)

Commits
  • d18ff4c chore(release): 4.0.46 [skip ci]
  • 20b4052 Merge branch 'main' of github.com:sonatype-nexus-community/auditjs
  • 7a66cbb fix: latest mock-fs fixes failing unit tests after other updates, resolve CVE...
  • e2ac821 fix: update CI 'release' target to use latest semantic-release, now that we u...
  • d3378f5 fix: resolve CVE-2024-21538 in cross-spawn : 7.0.3 (update CI node version)
  • 4ade2a7 fix: resolve CVE-2024-21538 in cross-spawn : 7.0.3
  • d065149 fix: resolve CVE-2024-4068 in braces : 3.0.2
  • cb7efa2 CI internal - use new IQ [skip ci]
  • 83760f2 CI internal - use new IQ [skip ci]
  • 3d08df0 revert fix for intermittent Jenkins build error. [skip ci]
  • Additional commits viewable in compare view

Updates fsevents from 1.2.9 to 1.2.13

Release notes

Sourced from fsevents's releases.

Release v1.2.13

Only build on Mac-OSX

Release v1.2.11

Removing node-pre-gyp so that building fsevents becomes easier and enabled without the download of binaries.

The credentials to the AWS store have been lost. Releasing to AWS is both insecure and no longer possible due to the lost credentials.

Intermediate Release

No release notes provided.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Package:
fsevents
Ecosystem:
npm
Version Change:
1.2.9 → 1.2.13
Update Type:
Patch
Ecosystem:
npm
Technical Details
ID: 12842920
UUID: 3087534539
Node ID: PR_kwDODRLP_s6Xc0qe
Host: GitHub
Repository: madjava/security-validation