chore(deps-dev): Bump immutable from 4.3.8 to 4.3.9 - #913
Conversation
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 4.3.8 to 4.3.9. - [Release notes](https://github.com/immutable-js/immutable-js/releases) - [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md) - [Commits](immutable-js/immutable-js@v4.3.8...v4.3.9) --- updated-dependencies: - dependency-name: immutable dependency-version: 4.3.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Re-ran the failed job — the Evidence:
This PR only changes one transitive lockfile entry, Worth taking anyway: 4.3.9 fixes GHSA-v56q-mh7h-f735 (oversized bounds in One ordering note: #924 also touches Separately, that flaky spec is worth a follow-up. Pinning the block timestamp or widening the order window in the multi-listing tests would stop |
ryanio
left a comment
There was a problem hiding this comment.
Approving — passes on re-run, confirming the earlier failure was the timing flake described above and not related to this bump. All checks green.
Worth taking for GHSA-v56q-mh7h-f735, even though the package is dev-only and reached transitively through seaport → hardhat@2.28.6. It also clears the finding from npm audit.
ryanio
left a comment
There was a problem hiding this comment.
Approving — coverage passes on re-run, confirming the earlier failure was the timing flake described above rather than anything to do with this bump. All checks green.
Worth taking for GHSA-v56q-mh7h-f735, even though the package is dev-only and reached transitively via seaport → hardhat@2.28.6. It also clears the finding from npm audit.
Bumps immutable from 4.3.8 to 4.3.9.
Release notes
Sourced from immutable's releases.
Changelog
Sourced from immutable's changelog.
... (truncated)
Commits
5da79194.3.9794a1a9Merge commit from fork3dd7e56perf(Map): index large hash-collision buckets for faster lookups62d0b58fix ts in tests8c0e5f8Merge commit from forkf0bc997Merge commit from fork8ac83f4change tagf7373e5use id-token to deploy 4.x version2f545adchangelogDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.