Skip to content

deps: lock file maintenance#6016

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance
Open

deps: lock file maintenance#6016
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented Apr 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Change
All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.

@renovate renovate Bot enabled auto-merge April 27, 2026 02:17
@renovate renovate Bot requested a review from a team as a code owner April 27, 2026 02:17
@socket-security

socket-security Bot commented Apr 27, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​arcjet/​node@​1.5.0 ⏵ 1.5.000000
Updated@​nestjs/​schematics@​11.0.10 ⏵ 11.1.09910084 +191 +10
Updatednext@​15.5.18 ⏵ 15.5.195210091 +19970
Updatedeslint-config-next@​15.5.18 ⏵ 15.5.19991006598100
Updated@​radix-ui/​react-label@​2.1.8 ⏵ 2.1.9100 +11006699100
Updated@​radix-ui/​react-slot@​1.2.4 ⏵ 1.2.5100 +110069 +199100
Updatedtypescript-eslint@​8.58.0 ⏵ 8.61.010010074 +198100
Updated@​types/​react@​19.2.14 ⏵ 19.2.171001007995100
Updated@​types/​react@​19.2.14 ⏵ 18.3.3110010079 +195100
Updated@​types/​node@​24.12.4 ⏵ 24.13.2100 +110081 +196100
Updated@​sveltejs/​kit@​2.61.1 ⏵ 2.65.199 +110081 +198 +1100
Updated@​astrojs/​node@​10.0.5 ⏵ 10.1.410010082 +197 +1100
Updatedtailwindcss@​4.2.2 ⏵ 4.3.11001008498100
Addedreact@​19.2.71001008497100
Updated@​nestjs/​cli@​11.0.17 ⏵ 11.0.2399 +110086 +196 +3100
Updated@​nestjs/​config@​4.0.3 ⏵ 4.0.4991008688 -2100
Added@​connectrpc/​connect-web@​2.1.2981008790100
Updatedsvelte@​5.56.0 ⏵ 5.56.388 +110088 +197 -1100
Updated@​hookform/​resolvers@​5.2.2 ⏵ 5.4.099100100 +189100
Added@​connectrpc/​connect@​2.1.21001009190100
Added@​connectrpc/​connect-node@​2.1.210010010090100
Updatedvue@​3.5.35 ⏵ 3.5.38100 +110091 +197100
Updatedvue-tsc@​3.2.6 ⏵ 3.3.51001009297 +1100
Addedreact-dom@​19.2.71001009298100
Updatedeslint-plugin-prettier@​5.5.5 ⏵ 5.5.610010010093100
Updatedeslint-plugin-tailwindcss@​3.18.2 ⏵ 3.18.39910010093 +1100
Updatedprettier-plugin-svelte@​3.5.1 ⏵ 3.5.2100 +110010094100
Updatedsvelte-check@​4.4.6 ⏵ 4.6.010010010094 -1100
Updatedisbot@​5.1.37 ⏵ 5.1.42100 +110010095100
Updatedreact-hook-form@​7.72.0 ⏵ 7.79.0100 +1100100 +196100
Added@​nestjs/​common@​11.1.2610010010096100
Updated@​nestjs/​core@​11.1.18 ⏵ 11.1.2699 +610010096 +2100
Updatedeslint-plugin-svelte@​3.16.0 ⏵ 3.19.099 +110010096 -1100
See 2 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Apr 27, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: examples/nextjs-app-dir-validate-email/package-lock.jsonnpm/next@16.2.6npm/vite@8.0.16npm/eslint-config-next@15.5.19npm/next@15.5.19npm/astro@6.4.6npm/@tailwindcss/postcss@4.3.1npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: examples/nextjs-app-dir-validate-email/package-lock.jsonnpm/eslint-config-next@15.5.19npm/typescript-eslint@8.61.0npm/@typescript-eslint/eslint-plugin@8.61.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.61.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: examples/nextjs-app-dir-validate-email/package-lock.jsonnpm/eslint-config-next@15.5.19npm/eslint-plugin-jsx-a11y@6.10.2npm/eslint-plugin-react@7.37.5npm/es-abstract@1.24.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-abstract@1.24.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm next is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: examples/nextjs-app-dir-validate-email/package-lock.jsonnpm/next@15.5.19

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@15.5.19. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: examples/nestjs/package-lock.jsonnpm/@nestjs/cli@11.0.23npm/webpack@5.106.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.106.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from 539d46d to a08114d Compare May 4, 2026 01:14
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from a08114d to 16158cc Compare May 11, 2026 01:39
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 4111b76 to 6dda7a2 Compare May 25, 2026 01:04
@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from bbeb1c4 to ae45a7c Compare June 15, 2026 01:55
@renovate

renovate Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: arcjet-guard/package-lock.json

npm --before could not be enforced because existing locked packages were published after the minimumReleaseAge cutoff. This will resolve after the next lock file maintenance run.

@renovate renovate Bot force-pushed the renovate/lock-file-maintenance branch from ae45a7c to c1a18e6 Compare June 22, 2026 00:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant