build(deps): bump uuid from 11.1.0 to 14.0.0 in /agentex-ui#207
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump uuid from 11.1.0 to 14.0.0 in /agentex-ui#207dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
ccdad02 to
eb91982
Compare
Bumps [uuid](https://github.com/uuidjs/uuid) from 11.1.0 to 14.0.0. - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v11.1.0...v14.0.0) --- updated-dependencies: - dependency-name: uuid dependency-version: 14.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
eb91982 to
885b4d4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps uuid from 11.1.0 to 14.0.0.
Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
Commits
7c1ea08chore(main): release 14.0.0 (#926)3d2c5b0Merge commit from forkf2c235ffix!: expectcryptoto be global everywhere (requires node@20+) (#935)529ef08chore: upgrade TypeScript and fixup types (#927)086fd79chore: update dependencies (#933)dc4ddb8feat!: drop node@18 support (#934)0f1f9c9chore: switch to Biome for parsing and linting (#932)e2879e6chore: use maintained version of npm-run-all (#930)ffa3138fix: Use GITHUB_TOKEN for release-please and enable npm provenance (#925)0423d49docs: remove obsolete v1 option notes (#915)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Greptile Summary
uuidfrom 11.1.0 to 14.0.0 across three major versions (12, 13, 14), which includes a security fix for GHSA-w5hq-g745-h8pq — out-of-bounds writes inv3(),v5(), andv6()when an invalidoffsetwas supplied.cryptomust be globally available (Node ≥ 20), CommonJS support removed (ESM only from v12), and browser exports made the default in v13. All are compatible with this project: the Dockerfile already usesnode:20, and Next.js 15's bundler handles ESM dependencies.package.jsonandpackage-lock.jsonare touched; no application code changes.Confidence Score: 5/5
Safe to merge — breaking changes are fully compatible with the existing project environment
No application code changes; all uuid 14 breaking changes (Node ≥ 20, ESM-only, crypto global) are satisfied by the existing Docker base image (node:20) and Next.js 15 bundler. The upgrade also includes a security patch (GHSA-w5hq-g745-h8pq).
No files require special attention
Important Files Changed
Flowchart
%%{init: {'theme': 'neutral'}}%% flowchart TD A["uuid 11.1.0"] -->|"v12.0.0: drop CJS, ESM only\ndrop Node 16"| B["uuid 12.x"] B -->|"v13.0.0: browser exports default"| C["uuid 13.x"] C -->|"v14.0.0: require Node ≥ 20\nfix GHSA-w5hq-g745-h8pq"| D["uuid 14.0.0 ✅"] subgraph Compatibility["Project compatibility"] N["Node 20 (Dockerfile ✅)"] T["TypeScript 5.9.2 ≥ 5.4.3 ✅"] B2["Next.js 15 bundler handles ESM ✅"] end D --> CompatibilityReviews (3): Last reviewed commit: "build(deps): bump uuid from 11.1.0 to 14..." | Re-trigger Greptile