Chore/batch dependabot security - #1113
Merged
Merged
Conversation
…endabot PRs) Bumps 16 flagged dependencies (plus 4 of their sub-deps) to the latest in-range patched versions. Lockfile-only: no workspace package.json changed and no resolutions/overrides added, so this triggers no version bump or npm publish. Consolidates the open Dependabot security PRs into a single change. Updated: @tootallnate/once, @xmldom/xmldom, axios, defu, flatted, follow-redirects, h3, handlebars, hono, ip-address, lodash, node-forge, picomatch (2.x line only), socket.io-parser, undici, yaml (1.x line only). Sub-deps: form-data, proxy-from-env, hasown, cookie-es. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Enables scheduled version updates and groups them so future bumps arrive as a single PR instead of one-per-dependency: security alerts collapse into one grouped PR, and routine minor/patch bumps are batched weekly. Majors still open individually for isolated review. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Ethella
approved these changes
Aug 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📦 Pull Request
Consolidates the open Dependabot security PRs into one lockfile-only change.
Closes #1094, closes #1091, closes #1090, closes #1088, closes #1082,
closes #1077, closes #1072, closes #1070, closes #1067, closes #1066,
closes #1065, closes #1064, closes #1063, closes #1058, closes #1056,
closes #1055
✅ Fixed Issues
🚨 Test instructions
[Describe any additional context required to test the PR/feature/bug fix.]
Please 🚨 ONLY ADD ONE 🚨 of the following labels, failing to do so may lead to adverse versioning of your changes when published:
patch: Bug Fix?minor: New Feature?major: Breaking Change?skip-release: It's unnecessary to publish this change.Special Note
Please avoid adding any of the
Prioritylabels as they conflict with the labels above ☝️