Open dependabot[bot] opened 1 week ago
Dependabot tried to add @lseppala
, @courtneycl
and @advanced-security/oss-maintainers
as reviewers to this PR, but received the following error from GitHub:
POST https://api.github.com/repos/advanced-security/spdx-dependency-submission-action/pulls/66/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the advanced-security/spdx-dependency-submission-action repository. // See: https://docs.github.com/rest/pulls/review-requests#request-reviewers-for-a-pull-request
✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.
Package | Version | Score | Details | ||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
npm/@eslint-community/regexpp | 4.12.1 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@eslint/config-array | 0.19.0 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@eslint/core | 0.9.0 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@eslint/eslintrc | 3.2.0 | :green_circle: 5.9 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@eslint/js | 9.15.0 | :green_circle: 6.9 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@eslint/object-schema | 2.1.4 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@eslint/plugin-kit | 0.2.3 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@humanfs/core | 0.19.1 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@humanfs/node | 0.16.6 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@humanwhocodes/retry | 0.3.1 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@humanwhocodes/retry | 0.4.1 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@types/estree | 1.0.6 | :green_circle: 6.9 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@types/json-schema | 7.0.15 | :green_circle: 6.9 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@vercel/ncc | 0.38.3 | :green_circle: 5.8 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/acorn | 8.14.0 | :green_circle: 5.4 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/cross-spawn | 7.0.6 | :green_circle: 3.6 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/eslint | 9.15.0 | :green_circle: 6.9 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/eslint-scope | 8.2.0 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/eslint-visitor-keys | 4.2.0 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/espree | 10.3.0 | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
npm/file-entry-cache | 8.0.0 | :green_circle: 4.2 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/flat-cache | 4.0.1 | :green_circle: 4 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/flatted | 3.3.2 | :green_circle: 3.5 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/globals | 14.0.0 | :green_circle: 5.4 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/ignore | 5.3.2 | :green_circle: 4.2 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/@vercel/ncc | ^0.38.3 | :green_circle: 5.8 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
npm/eslint | ^9.15.0 | :green_circle: 6.9 | Details
|
Bumps the development-dependencies group with 2 updates in the / directory: @vercel/ncc and eslint.
Updates
@vercel/ncc
from 0.36.1 to 0.38.3Release notes
Sourced from
@vercel/ncc
's releases.Commits
84f8c52
fix: add missing--asset-builds
to cli help message (#1228)0ff93c6
chore(deps): Bump elliptic from 6.5.7 to 6.6.0 (#1223)ae5bf16
chore(deps): Bump amannn/action-semantic-pull-request from 5.3.0 to 5.5.3 (#1...738a2bf
chore(deps-dev): Bump axios from 0.21.4 to 1.7.7 (#1209)158a1fd
fix(deps): update webpack to v5.94.0, terser to v5.33.0 (#1213)c1c9c65
chore(deps): Bump fast-xml-parser from 4.2.7 to 4.5.0 (#1219)6ef9a48
chore(deps-dev): Bump express from 4.18.2 to 4.20.0 (#1214)9e7451b
ci: ignore failing test on macOS + run in band test-coverage (#1216)b2a325d
chore(ci): drop node@16 from ci (#1164)3c68358
chore(deps): Bump crypto-js from 4.1.1 to 4.2.0 (#1130)Updates
eslint
from 8.57.0 to 9.15.0Release notes
Sourced from eslint's releases.
... (truncated)
Changelog
Sourced from eslint's changelog.
... (truncated)
Commits
6f37b07
9.15.01d99f29
Build: changelog update for 9.15.02967d91
chore: upgrade@eslint/js
@9
.15.0 (#19133)b441bee
chore: package.json update for@eslint/js
release7d6bf4a
chore: upgrade@eslint/core
@0
.9.0 (#19131)01557ce
feat: Implement Language#normalizeLanguageOptions() (#19104)902e707
chore: upgrade@eslint/plugin-kit
@0
.2.3 (#19130)2edc0e2
feat: add meta.defaultOptions (#17656)fd33f13
fix: update types forno-restricted-imports
rule (#19060)5ff6c1d
chore: bump cross-spawn (#19125)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show