An open index of dependabot pull requests across open source projects.

fix(deps): bump @salesforce/core from 8.23.4 to 8.24.0

Closed
Number: #1042
Type: Pull Request
State: Closed
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: December 06, 2025 at 02:01 PM UTC
(6 months ago)
Updated: December 07, 2025 at 05:45 AM UTC
(6 months ago)
Closed: December 07, 2025 at 05:45 AM UTC
(6 months ago)
Time to Close: about 16 hours
Labels:
dependencies
Description:

Bumps @salesforce/core from 8.23.4 to 8.24.0.

Release notes

Sourced from @​salesforce/core's releases.

8.24.0

Features

8.23.7

Bug Fixes

  • bump jsonwebtoken for security fix (f049410)

8.23.6

Bug Fixes

8.23.5

Bug Fixes

  • auth: log scopes associated to the access token (7ec3bea)

8.23.5-qaext.0

Bug Fixes

  • correctly classify even with space (59f492e)

Features

  • move schema for project/scratch-def into this repo (55a6e54)
  • script to update features (38c0bc3)
  • script to update settings with their documentation (cd498fd)

8.23.5-dev.0

Bug Fixes

Changelog

Sourced from @​salesforce/core's changelog.

8.24.0 (2025-12-05)

Features

8.23.7 (2025-12-04)

Bug Fixes

  • bump jsonwebtoken for security fix (f049410)

8.23.6 (2025-12-03)

Bug Fixes

8.23.5 (2025-12-02)

Bug Fixes

  • auth: log scopes associated to the access token (7ec3bea)
Commits
  • 5564069 chore(release): 8.24.0 [skip ci]
  • 82a26a0 feat: add sfdx-project/scratch-def schemas W-20268457 (#1249)
  • bc2c065 chore(release): 8.23.7 [skip ci]
  • 2247664 Merge pull request #1253 from forcedotcom/sh/bump-jsonwebtoken
  • f049410 fix: bump jsonwebtoken for security fix
  • 8966c91 chore(release): 8.23.6 [skip ci]
  • e245a66 fix: refreshAuth does a GET request W-19992404 (#1248)
  • 589302e chore(release): 8.23.5 [skip ci]
  • 61aab42 Merge pull request #1251 from forcedotcom/cd/log-token-scopes
  • 9c3c95e chore: bump jsforce
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Ecosystem:
npm
Version Change:
8.23.4 → 8.24.0
Update Type:
Minor
Technical Details
ID: 11799429
UUID: 3701755557
Node ID: PR_kwDODoFgtc63cLid
Host: GitHub
Repository: salesforcecli/plugin-command-reference