Skip to content

Update all non-major dependencies#567

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch
Open

Update all non-major dependencies#567
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 16, 2026

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/setup-node action minor v6.3.0v6.4.0 age confidence
alpine final patch 3.23.33.23.4 age confidence
axios (source) resolutions patch 1.15.01.15.2 age confidence
axios (source) dependencies patch 1.15.01.15.2 age confidence
node-sarif-builder dependencies minor 4.0.04.1.0 age confidence
nvuillam/github-dependents-info action minor v3.0.0v3.1.0 age confidence

Release Notes

actions/setup-node (actions/setup-node)

v6.4.0

Compare Source

axios/axios (axios)

v1.15.2

Compare Source

This release delivers prototype-pollution hardening for the Node HTTP adapter, adds an opt-in allowedSocketPaths allowlist to mitigate SSRF via Unix domain sockets, fixes a keep-alive socket memory leak, and ships supply-chain hardening across CI and security docs.

🔒 Security Fixes

  • Prototype Pollution Hardening (HTTP Adapter): Hardened the Node HTTP adapter and resolveConfig/mergeConfig/validator paths to read only own properties and use null-prototype config objects, preventing polluted auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser from influencing requests. (#​10779)
  • SSRF via socketPath: Rejects non-string socketPath values and adds an opt-in allowedSocketPaths config option to restrict permitted Unix domain socket paths, returning AxiosError ERR_BAD_OPTION_VALUE on mismatch. (#​10777)
  • Supply-chain Hardening: Added .npmrc with ignore-scripts=true, lockfile lint CI, non-blocking reproducible build diff, scoped CODEOWNERS, expanded SECURITY.md/THREATMODEL.md with provenance verification (npm audit signatures), 60-day resolution policy, and maintainer incident-response runbook. (#​10776)

🚀 New Features

  • allowedSocketPaths Config Option: New request config option (and TypeScript types) to allowlist Unix domain socket paths used by the Node http adapter; backwards compatible when unset. (#​10777)

🐛 Bug Fixes

  • Keep-alive Socket Memory Leak: Installs a single per-socket error listener tracking the active request via kAxiosSocketListener/kAxiosCurrentReq, eliminating per-request listener accumulation, MaxListenersExceededWarning, and linear heap growth under concurrent or long-running keep-alive workloads (fixes #​10780). (#​10788)

🔧 Maintenance & Chores

  • Changelog: Updated CHANGELOG.md with v1.15.1 release notes. (#​10781)

Full Changelog

v1.15.1

Compare Source

nvuillam/node-sarif-builder (node-sarif-builder)

v4.1.0

Compare Source

  • Upgrade to Typescript v6
  • Upgrade NPM dependencies
nvuillam/github-dependents-info (nvuillam/github-dependents-info)

v3.1.0

Compare Source

What's Changed

Full Changelog: nvuillam/github-dependents-info@v3.0.0...v3.1.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 16, 2026

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ DOCKERFILE hadolint 1 0 0 0.04s
✅ GROOVY npm-groovy-lint 10 3 0 0 24.13s
✅ JAVASCRIPT prettier 100 100 0 0 3.79s
✅ JSON jsonlint 9 0 0 0.38s
✅ JSON npm-package-json-lint yes no no 0.58s
✅ JSON prettier 9 4 0 0 1.85s
✅ JSON v8r 9 0 0 10.94s
⚠️ MARKDOWN markdownlint 8 3 3 0 2.7s
✅ MARKDOWN markdown-table-formatter 8 6 0 0 0.75s
✅ REPOSITORY checkov yes no no 17.35s
✅ REPOSITORY gitleaks yes no no 8.12s
✅ REPOSITORY git_diff yes no no 0.09s
✅ REPOSITORY grype yes no no 32.04s
✅ REPOSITORY secretlint yes no no 0.95s
✅ REPOSITORY trivy yes no no 6.64s
✅ REPOSITORY trufflehog yes no no 2.53s
✅ SPELL cspell 140 0 0 7.62s
⚠️ SPELL lychee 20 16 0 43.59s
✅ XML xmllint 1 0 0 0 0.22s
✅ YAML prettier 3 0 0 0 1.19s
✅ YAML v8r 3 0 0 6.9s
✅ YAML yamllint 3 0 0 0.74s

Detailed Issues

⚠️ SPELL / lychee - 16 errors
[WARN ] Error creating request: InvalidPathToUri("/lib/java/logback.xml")
[403] https://www.npmjs.com/package/amplitude | Network error: Forbidden
[403] https://npmjs.org/package/npm-groovy-lint | Network error: Forbidden
[403] https://nicolas.vuillamy.fr/a-groovy-journey-to-open-source-during-covid-19-npm-groovy-lint-8d88c7eecebc | Network error: Forbidden
[403] https://www.npmjs.com/package/java-caller | Network error: Forbidden
[403] https://nicolas.vuillamy.fr/a-groovy-journey-to-open-source-during-covid-19-npm-groovy-lint-8d88c7eecebc | Error (cached)
[403] https://www.npmjs.com/package/java-caller | Error (cached)
[403] https://www.npmjs.com/package/amplitude | Error (cached)
[403] https://npmjs.org/package/npm-groovy-lint | Error (cached)
[403] https://www.npmjs.com/package/java-caller | Error (cached)
[403] https://www.npmjs.com/package/analytics | Network error: Forbidden
[403] https://www.npmjs.com/package/analytics | Error (cached)
[403] https://www.npmjs.com/package/insight | Network error: Forbidden
[403] https://www.npmjs.com/package/java-caller | Error (cached)
[403] https://www.npmjs.com/package/insight | Error (cached)
[404] https://github.com/vafgoettlich | Network error: Not Found
[IGNORED] git+https://github.com/nvuillam/npm-groovy-lint.git | Unsupported: Error creating request client: builder error for url (git+https://github.com/nvuillam/npm-groovy-lint.git)
[404] https://github.com/vafgoettlich/checkmk | Network error: Not Found
📝 Summary
---------------------
🔍 Total..........455
✅ Successful.....430
⏳ Timeouts.........0
🔀 Redirected.......0
👻 Excluded.........8
❓ Unknown..........0
🚫 Errors..........16

Errors in README.md
[403] https://npmjs.org/package/npm-groovy-lint | Network error: Forbidden
[403] https://www.npmjs.com/package/java-caller | Network error: Forbidden
[403] https://www.npmjs.com/package/amplitude | Network error: Forbidden
[403] https://nicolas.vuillamy.fr/a-groovy-journey-to-open-source-during-covid-19-npm-groovy-lint-8d88c7eecebc | Network error: Forbidden

Errors in CHANGELOG.md
[403] https://www.npmjs.com/package/analytics | Network error: Forbidden
[403] https://www.npmjs.com/package/java-caller | Error (cached)
[403] https://www.npmjs.com/package/insight | Network error: Forbidden

Errors in docs/CHANGELOG.md
[403] https://www.npmjs.com/package/java-caller | Error (cached)
[403] https://www.npmjs.com/package/analytics | Error (cached)
[403] https://www.npmjs.com/package/insight | Error (cached)

Errors in docs/github-dependents-info.md
[404] https://github.com/vafgoettlich | Network error: Not Found
[404] https://github.com/vafgoettlich/checkmk | Network error: Not Found

Errors in docs/index.md
[403] https://www.npmjs.com/package/amplitude | Error (cached)
[403] https://nicolas.vuillamy.fr/a-groovy-journey-to-open-source-during-covid-19-npm-groovy-lint-8d88c7eecebc | Error (cached)
[403] https://npmjs.org/package/npm-groovy-lint | Error (cached)
[403] https://www.npmjs.com/package/java-caller | Error (cached)
⚠️ MARKDOWN / markdownlint - 3 errors
docs/github-dependents-info.md:11:3 MD051/link-fragments Link fragments should be valid [Context: "[github.com/nvuillam/npm-groovy-lint](#package-github.comnvuillamnpm-groovy-lint)"]
docs/index.md:39:65 MD059/descriptive-link-text Link text should be descriptive [Context: "[**here**]"]
README.md:39:65 MD059/descriptive-link-text Link text should be descriptive [Context: "[**here**]"]

See detailed reports in MegaLinter artifacts

MegaLinter is graciously provided by OX Security

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from bd524a2 to 20096a1 Compare April 19, 2026 21:44
@renovate renovate Bot changed the title Update alpine Docker tag to v3.23.4 Update all non-major dependencies Apr 19, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 19, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednode-sarif-builder@​4.0.0 ⏵ 4.1.0100 +1100100 +191 +3100
Updatedaxios@​1.15.0 ⏵ 1.15.299 +910010095100

View full report

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 11b3e58 to 70a707d Compare April 20, 2026 06:05
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 70a707d to 8641756 Compare April 21, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants