Skip to content

chore(deps): bump the dependencies group across 1 directory with 3 updates#109

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/dependencies-62f49367b5
Open

chore(deps): bump the dependencies group across 1 directory with 3 updates#109
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/dependencies-62f49367b5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 29, 2026

Bumps the dependencies group with 3 updates in the / directory: @nodesecure/ossf-scorecard-sdk, @nodesecure/scanner and @openally/httpie.

Updates @nodesecure/ossf-scorecard-sdk from 3.2.1 to 4.0.0

Release notes

Sourced from @​nodesecure/ossf-scorecard-sdk's releases.

v4.0.0

What's Changed

New Contributors

Full Changelog: NodeSecure/ossf-scorecard-sdk@v3.2.1...v4.0.0

Commits
  • 87c982d 4.0.0
  • 732420b chore(.npmrc): add allow-git=none (#145)
  • bee3e48 refactor: remove @​openally/httpie with native Node.js fetch (#144)
  • 5025622 chore(deps): bump @​nodesecure/npm-registry-sdk in the dependencies group (#143)
  • 37f8b31 chore(deps): bump github/codeql-action in the github-actions group (#142)
  • 12599d9 chore(deps): bump the github-actions group with 4 updates (#141)
  • 4498678 chore(deps): bump the github-actions group with 5 updates (#140)
  • d05f184 chore(deps-dev): bump @​types/node in the development-dependencies group (#139)
  • 06d148f feat: publish package using NPM OIDC trusted publisher (#138)
  • 3c8fa98 chore(deps): bump the github-actions group with 3 updates (#137)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​nodesecure/ossf-scorecard-sdk since your current version.


Updates @nodesecure/scanner from 8.2.0 to 10.6.0

Release notes

Sourced from @​nodesecure/scanner's releases.

@​nodesecure/scanner@​10.6.0

Minor Changes

Patch Changes

@​nodesecure/scanner@​10.5.1

Patch Changes

  • #669 6075920 Thanks @​fraxken! - Comment NPM avatar hydratation because the .user() API in the SDK is deprecated and cannot be used anymore

  • Updated dependencies [d6f9487]:

    • @​nodesecure/tarball@​3.6.1

@​nodesecure/scanner@​10.5.0

Minor Changes

Patch Changes

@​nodesecure/scanner@​10.4.0

Minor Changes

Patch Changes

... (truncated)

Changelog

Sourced from @​nodesecure/scanner's changelog.

10.6.0

Minor Changes

Patch Changes

10.5.1

Patch Changes

  • #669 6075920 Thanks @​fraxken! - Comment NPM avatar hydratation because the .user() API in the SDK is deprecated and cannot be used anymore

  • Updated dependencies [d6f9487]:

    • @​nodesecure/tarball@​3.6.1

10.5.0

Minor Changes

Patch Changes

10.4.0

Minor Changes

Patch Changes

... (truncated)

Commits
  • f1d0f9a chore: update versions (#672)
  • cef7c24 feat(scanner/depWalker): configure locker.concurrency with new maxConcurrency...
  • dc40fb3 feat(scanner): log error only in verbose mode (#675)
  • 64502bf chore: update @​openally/config.eslint (#674)
  • 11d5d16 chore: update versions (#668)
  • 6075920 fix(scanner): comment NPM avatar hydratation (#669)
  • d6f9487 fix(tarball): properly manage relativeFile across EFA and DependencyCollectab...
  • 51e7f10 chore: update versions (#657)
  • fe0a69f chore: update JS-X-Ray to v14.1.0 and fix broken tarball ws (#664)
  • 4b2b834 feat: update vulnera to v3.x.x (#662)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​nodesecure/scanner since your current version.


Updates @openally/httpie from 1.0.0 to 1.1.2

Release notes

Sourced from @​openally/httpie's releases.

v1.1.2

Fixing broken v1.1.1

Full Changelog: OpenAlly/httpie@v1.1.1...v1.1.2

v1.1.1

What's Changed

New Contributors

Full Changelog: OpenAlly/httpie@v1.1.0...v1.1.1

v1.1.0

What's Changed

New Contributors

Full Changelog: OpenAlly/httpie@v1.0.0...v1.1.0

Commits
  • 8175d5f 1.1.2
  • ceaeafd 1.1.1
  • b139a81 chore: update undici (#8)
  • 50732db 1.1.0
  • b9a6298 chore: update dependencies (vulns & breaking changes) (#7)
  • bae5610 ci: use NPM trusted OIDC publish (#6)
  • 1ee9f42 refactor: remove statuses dependency (#5)
  • 061e33c refactor: remove content-type in favor of undici.parseMIMEType (#4)
  • 5e07f4b fix(stream): implement TOpaque generic for .stream and .pipeline API (#3)
  • dbc03ac chore: implement undici options for blocking pipelining (#2)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​openally/httpie since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the dependencies group with 3 updates in the / directory: [@nodesecure/ossf-scorecard-sdk](https://github.com/NodeSecure/ossf-scorecard-sdk), [@nodesecure/scanner](https://github.com/NodeSecure/scanner/tree/HEAD/workspaces/scanner) and [@openally/httpie](https://github.com/OpenAlly/httpie).


Updates `@nodesecure/ossf-scorecard-sdk` from 3.2.1 to 4.0.0
- [Release notes](https://github.com/NodeSecure/ossf-scorecard-sdk/releases)
- [Commits](NodeSecure/ossf-scorecard-sdk@v3.2.1...v4.0.0)

Updates `@nodesecure/scanner` from 8.2.0 to 10.6.0
- [Release notes](https://github.com/NodeSecure/scanner/releases)
- [Changelog](https://github.com/NodeSecure/scanner/blob/master/workspaces/scanner/CHANGELOG.md)
- [Commits](https://github.com/NodeSecure/scanner/commits/@nodesecure/scanner@10.6.0/workspaces/scanner)

Updates `@openally/httpie` from 1.0.0 to 1.1.2
- [Release notes](https://github.com/OpenAlly/httpie/releases)
- [Commits](OpenAlly/httpie@v1.0.0...v1.1.2)

---
updated-dependencies:
- dependency-name: "@nodesecure/ossf-scorecard-sdk"
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: "@nodesecure/scanner"
  dependency-version: 10.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: "@openally/httpie"
  dependency-version: 1.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants