Skip to content

fix(deps): update non-major - #339

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major
Closed

fix(deps): update non-major#339
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major

Conversation

@renovate

@renovate renovate Bot commented Apr 15, 2024

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@heroicons/react 2.1.32.2.0 age confidence
@sanity/client (source) 6.15.116.29.1 age confidence
@sanity/icons (source) 2.11.72.11.8 age confidence
@sanity/ui (source) 2.1.12.16.26 age confidence
@sanity/vision (source) 3.37.13.99.0 age confidence
@types/jest (source) 29.5.1229.5.14 age confidence
@types/node (source) 18.17.1118.19.130 age confidence
@types/react (source) 18.2.7518.3.31 age confidence
culori 4.0.14.0.2 age confidence
esbuild 0.20.20.28.1 age confidence
eslint (source) 8.57.08.57.1 age confidence
eslint-config-next (source) 14.1.414.2.35 age confidence
eslint-config-prettier 9.1.09.1.2 age confidence
eslint-plugin-simple-import-sort 12.0.012.1.1 age confidence
motion 10.17.010.18.0 age confidence
prettier (source) 3.2.53.9.6 age confidence
prettier-plugin-packagejson 2.4.142.5.22 age confidence
react (source) 18.2.018.3.1 age confidence
react-dom (source) 18.2.018.3.1 age confidence
react-icons 5.0.15.7.0 age confidence
react-is (source) 18.2.018.3.1 age confidence
sanity (source) 3.37.13.99.0 age confidence
sanity-plugin-asset-source-unsplash (source) 3.0.03.1.0 age confidence
sanity-plugin-mux-input (source) 2.3.42.19.1 age confidence
slugify 1.6.61.6.9 age confidence
styled-components (source) 6.1.86.4.4 age confidence
turbo (source) 1.13.21.13.4 age confidence
type-fest 4.15.04.41.0 age confidence
typescript (source) 5.4.25.9.3 age confidence

Release Notes

tailwindlabs/heroicons (@​heroicons/react)

v2.2.0

Compare Source

Added
Fixed
  • Removed unnecessary clipping path from solid/arrow-left-circle (#​1211)

v2.1.5

Compare Source

Added
  • Add new icons (arrow-turn-*, bold, calendar-date-range, divide, document-currency-*, equals, h1, h2, h3, italic, link-slash, numbered-list, percent-badge, slash, strikethrough, underline)

v2.1.4

Compare Source

Fixed
  • Improve tree-shakability of React package (#​1192)
sanity-io/client (@​sanity/client)

v6.29.1

Compare Source

Bug Fixes
  • dependency update, import condition (d8109b9)

v6.29.0

Compare Source

Features

v6.28.4

Compare Source

Bug Fixes

v6.28.3

Compare Source

Bug Fixes

v6.28.2

Compare Source

Bug Fixes

v6.28.1

Compare Source

Bug Fixes

v6.28.0

Compare Source

Features
Bug Fixes

v6.27.2

Compare Source

Bug Fixes

v6.27.1

Compare Source

Bug Fixes
  • csm: handle Cannot read properties of undefined (cb80d68)

v6.27.0

Compare Source

Features

v6.26.1

Compare Source

Bug Fixes

v6.26.0

Compare Source

Features

v6.25.0

Compare Source

Features
  • request: add flag to disable logging api warnings (#​925) (3f90ab0)

v6.24.4

Compare Source

Bug Fixes

v6.24.3

Compare Source

Bug Fixes

v6.24.2

Compare Source

Bug Fixes

v6.24.1

Compare Source

Bug Fixes

v6.24.0

Compare Source

Features
Bug Fixes
  • export validateApiPerspective (b73ae46)

v6.23.0

Compare Source

Features
Bug Fixes
  • types: add (abort) signal to raw request typings (#​926) (fcd9a16)

v6.22.5

Compare Source

Bug Fixes

v6.22.4

Compare Source

Bug Fixes
  • stega: add textTheme to deny list (39edfe1)
  • stega: ignore paths that end with Id (81aa664)

v6.22.3

Compare Source

Bug Fixes

v6.22.2

Compare Source

Bug Fixes

v6.22.1

Compare Source

Bug Fixes
  • add missing listenerName property on welcome event (#​894) (6173089)

v6.22.0

Compare Source

Features
Bug Fixes

v6.21.3

Compare Source

Bug Fixes
  • deprecate studioHost, externalStudioHost in typings (#​879) (ebe840b)
  • support signal on getDocument(s) to cancel requests (#​881) (13d71bb)

v6.21.2

Compare Source

Bug Fixes

v6.21.1

Compare Source

Bug Fixes
  • add support for includeMutations listen parameter (#​872) (5f0a991)

v6.21.0

Compare Source

Features
  • codegen: Allow query reponse types to be overridden through SanityQueries (#​858) (c25d51a)

v6.20.2

Compare Source

Bug Fixes

v6.20.1

Compare Source

Bug Fixes
  • add warning about setting both useCdn and withCredentials to true (#​849) (ae01edb)
  • deps: update dependency get-it to ^8.6.1 (#​856) (ced69bc)

v6.20.0

Compare Source

Features

v6.19.2

Compare Source

Bug Fixes

v6.19.1

Compare Source

Bug Fixes
  • types: adjust action types to reflect Actions API (#​830) (e116c62)

v6.19.0

Compare Source

Features

v6.18.3

Compare Source

Bug Fixes

v6.18.2

Compare Source

Bug Fixes

v6.18.1

Compare Source

Bug Fixes

v6.18.0

Compare Source

Features

v6.17.3

Compare Source

Bug Fixes

v6.17.2

Compare Source

Bug Fixes

v6.17.1

Compare Source

Bug Fixes

v6.17.0

Compare Source

Features
  • update SanityProject to include metadata.cliInitializedAt (#​779) (77bf6f6)

v6.16.0

Compare Source

Features
  • add stegaClean method, deprecate vercelStegaCleanAll (#​773) (2749586)
Bug Fixes

v6.15.20

Compare Source

Bug Fixes

v6.15.19

Compare Source

Bug Fixes
  • handle bug affecting next 14.2.2 during static pregeneration (#​748) (28493e2)

v6.15.18

Compare Source

Bug Fixes

v6.15.17

Compare Source

Bug Fixes
  • deps: update dependency get-it to ^8.4.26 (96ea964)

v6.15.16

Compare Source

Bug Fixes
  • createClient from @sanity/client/stega is deprecated (4d0a03f)
  • requester from @sanity/client/stega is deprecated (f29263d)
  • use the correct stega export conditions for react-native (06af163)

v6.15.15

Compare Source

Bug Fixes
  • add react-native export conditions (cc0fd76)
  • deps: update dependency get-it to ^8.4.24 (0d5952c)

v6.15.14

Compare Source

Bug Fixes

v6.15.13

Compare Source

Bug Fixes

v6.15.12

Compare Source

Bug Fixes
sanity-io/ui (@​sanity/icons)

v2.11.8

Compare Source

Bug Fixes
sanity-io/ui (@​sanity/ui)

v2.16.26

Compare Source

Patch Changes

v2.16.25

Compare Source

Patch Changes

v2.16.24

Compare Source

Patch Changes

v2.16.23

Compare Source

Patch Changes

v2.16.22

Compare Source

Bug Fixes
  • deps: replace framer-motion with motion/react (0e9b84d)

This release is also available on:

v2.16.21

Compare Source

Bug Fixes
  • deps: upgrade to React Compiler v1 (c86cdf1)

This release is also available on:

v2.16.20

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.24 (v2) (#​2123) (38d695c)

This release is also available on:

v2.16.19

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.22 (v2) (#​2106) (459b0d9)

This release is also available on:

v2.16.18

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.19 (v2) (#​2096) (d1de26d)

This release is also available on:

v2.16.17

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.18 (v2) (#​2083) (bdc26bb)

This release is also available on:

v2.16.16

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.16 (v2) (#​2078) (83c2782)

This release is also available on:

v2.16.15

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.15 (v2) (#​2063) (bb7f012)

This release is also available on:

v2.16.14

Compare Source

Bug Fixes

This release is also available on:

v2.16.13

Compare Source

Bug Fixes

This release is also available on:

v2.16.12

Compare Source

Bug Fixes

This release is also available on:

v2.16.11

Compare Source

Bug Fixes

This release is also available on:

v2.16.10

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.11 (v2) (#​1844) (9404122)

This release is also available on:

v2.16.9

Compare Source

Bug Fixes
  • deps: update dependency framer-motion to ^12.23.9 (v2) (#​1790) (276f753)

This release is also available on:

v2.16.8

Compare Source

Bug Fixes
  • deps: update dependency use-effect-event to ^2.0.3 (v2) (#​1784) (7ee8496)

This release is also available on:

v2.16.7

Compare Source

Bug Fixes

v2.16.6

Compare Source

Bug Fixes

v2.16.5

Compare Source

Bug Fixes

v2.16.4

Compare Source

Bug Fixes

v2.16.3

Compare Source

Bug Fixes

v2.16.2

Compare Source

Bug Fixes

v2.16.1

Compare Source

Bug Fixes

v2.16.0

Compare Source

Features

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 3am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here

@renovate
renovate Bot requested a review from a team as a code owner April 15, 2024 06:31
@vercel

vercel Bot commented Apr 15, 2024

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
themer Error Error Jul 24, 2026 11:44pm
themer-example-advanced Error Error Jul 24, 2026 11:44pm
themer-example-basic Ready Ready Preview, Comment Jul 24, 2026 11:44pm
themer-example-next-dynamic Ready Ready Preview, Comment Jul 24, 2026 11:44pm
themer-example-next-static Ready Ready Preview, Comment Jul 24, 2026 11:44pm
themer-v2 Ready Ready Preview, Comment Jul 24, 2026 11:44pm

Request Review

@renovate
renovate Bot force-pushed the renovate/non-major branch from f02bfdf to a255ea1 Compare April 15, 2024 23:00
@renovate
renovate Bot force-pushed the renovate/non-major branch from a255ea1 to 65d72de Compare April 16, 2024 17:18
@renovate
renovate Bot force-pushed the renovate/non-major branch from 65d72de to 2acfbe4 Compare April 17, 2024 14:14
@renovate
renovate Bot force-pushed the renovate/non-major branch from c546a79 to f43bdc2 Compare April 18, 2024 02:17
@renovate
renovate Bot force-pushed the renovate/non-major branch from f4ec0e1 to d5228e3 Compare April 18, 2024 07:26
@renovate
renovate Bot force-pushed the renovate/non-major branch from d5228e3 to 3f14675 Compare April 19, 2024 16:02
@renovate
renovate Bot force-pushed the renovate/non-major branch from 3f14675 to 950b317 Compare April 19, 2024 18:08
@socket-security

socket-security Bot commented Jun 6, 2024

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @esbuild/aix-ppc64 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/@esbuild/aix-ppc64@0.25.6

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@esbuild/aix-ppc64@0.25.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @tanstack/table-core is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/@tanstack/table-core@8.21.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tanstack/table-core@8.21.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm css-tree is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/css-tree@3.2.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/css-tree@3.2.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm culori is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/v1/package.jsonnpm/culori@4.0.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/culori@4.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm data-urls is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/data-urls@7.0.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/data-urls@7.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/jsdom@28.1.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@28.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/jsdom@28.1.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@28.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm rimraf is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/rimraf@5.0.10

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/rimraf@5.0.10. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm typescript

License: LicenseRef-W3C-Community-Final-Specification-Agreement - The applicable license policy does not permit this license (5) (package/ThirdPartyNoticeText.txt)

From: apps/v1/package.jsonnpm/typescript@5.9.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/typescript@5.9.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Install-time scripts: npm esbuild during postinstall

Install script: postinstall

Source: node install.js

From: pnpm-lock.yamlnpm/sanity@3.99.0npm/esbuild@0.25.6

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/esbuild@0.25.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Install-time scripts: npm esbuild during postinstall

Install script: postinstall

Source: node install.js

From: apps/v1/package.jsonnpm/esbuild@0.28.1

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/esbuild@0.28.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant