Skip to content

build(deps): bump uuid from 11.1.0 to 14.0.0 in /agentex-ui#207

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/agentex-ui/uuid-14.0.0
Open

build(deps): bump uuid from 11.1.0 to 14.0.0 in /agentex-ui#207
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/agentex-ui/uuid-14.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Bumps uuid from 11.1.0 to 14.0.0.

Release notes

Sourced from uuid's releases.

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

v12.0.1

12.0.1 (2026-04-29)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

Commits
  • 7c1ea08 chore(main): release 14.0.0 (#926)
  • 3d2c5b0 Merge commit from fork
  • f2c235f fix!: expect crypto to be global everywhere (requires node@20+) (#935)
  • 529ef08 chore: upgrade TypeScript and fixup types (#927)
  • 086fd79 chore: update dependencies (#933)
  • dc4ddb8 feat!: drop node@18 support (#934)
  • 0f1f9c9 chore: switch to Biome for parsing and linting (#932)
  • e2879e6 chore: use maintained version of npm-run-all (#930)
  • ffa3138 fix: Use GITHUB_TOKEN for release-please and enable npm provenance (#925)
  • 0423d49 docs: remove obsolete v1 option notes (#915)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.


Greptile Summary

  • Bumps uuid from 11.1.0 to 14.0.0 across three major versions (12, 13, 14), which includes a security fix for GHSA-w5hq-g745-h8pq — out-of-bounds writes in v3(), v5(), and v6() when an invalid offset was supplied.
  • Breaking changes include: dropped Node.js 16/18 support (requires Node ≥ 20), crypto must be globally available (Node ≥ 20), CommonJS support removed (ESM only from v12), and browser exports made the default in v13. All are compatible with this project: the Dockerfile already uses node:20, and Next.js 15's bundler handles ESM dependencies.
  • Only package.json and package-lock.json are touched; no application code changes.

Confidence Score: 5/5

Safe to merge — breaking changes are fully compatible with the existing project environment

No application code changes; all uuid 14 breaking changes (Node ≥ 20, ESM-only, crypto global) are satisfied by the existing Docker base image (node:20) and Next.js 15 bundler. The upgrade also includes a security patch (GHSA-w5hq-g745-h8pq).

No files require special attention

Important Files Changed

Filename Overview
agentex-ui/package.json uuid version constraint updated from ^11.1.0 to ^14.0.0; compatible with existing Node 20 and TypeScript 5.9.2 setup
agentex-ui/package-lock.json Lock file updated to uuid 14.0.0 with corrected integrity hash and updated bin path (dist-node/bin/uuid)

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A["uuid 11.1.0"] -->|"v12.0.0: drop CJS, ESM only\ndrop Node 16"| B["uuid 12.x"]
    B -->|"v13.0.0: browser exports default"| C["uuid 13.x"]
    C -->|"v14.0.0: require Node ≥ 20\nfix GHSA-w5hq-g745-h8pq"| D["uuid 14.0.0 ✅"]

    subgraph Compatibility["Project compatibility"]
        N["Node 20 (Dockerfile ✅)"]
        T["TypeScript 5.9.2 ≥ 5.4.3 ✅"]
        B2["Next.js 15 bundler handles ESM ✅"]
    end

    D --> Compatibility
Loading

Reviews (3): Last reviewed commit: "build(deps): bump uuid from 11.1.0 to 14..." | Re-trigger Greptile

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 23, 2026
@dependabot dependabot Bot requested a review from a team as a code owner April 23, 2026 21:01
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 23, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 23, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​uuid@​11.1.0 ⏵ 14.0.0100 +1100 +210092 -1100

View full report

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/agentex-ui/uuid-14.0.0 branch from ccdad02 to eb91982 Compare May 7, 2026 17:27
Bumps [uuid](https://github.com/uuidjs/uuid) from 11.1.0 to 14.0.0.
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v11.1.0...v14.0.0)

---
updated-dependencies:
- dependency-name: uuid
  dependency-version: 14.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/agentex-ui/uuid-14.0.0 branch from eb91982 to 885b4d4 Compare May 12, 2026 01:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants