Skip to content

chore(deps): lock file maintenance - #1026

Open
renovate-coveo[bot] wants to merge 1 commit into
masterfrom
renovate/lock-file-maintenance
Open

chore(deps): lock file maintenance#1026
renovate-coveo[bot] wants to merge 1 commit into
masterfrom
renovate/lock-file-maintenance

chore(deps): lock file maintenance

3eff0d9
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Required Checks succeeded Aug 19, 2026 in 0s

StepSecurity Required Checks

Finished StepSecurity Required Checks

  • Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
  • Script Injection Check - Checks for script injection vulnerabilities in the PR
  • NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
  • NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
  • PyPI Compromised Packages Check - Checks for compromised PyPI package versions in the PR

Approve a check

If you need to approve a check, [please open a ticket with the SOC](https://coveord.atlassian.net/servicedesk/customer/portal/116/group/640/create/1324) Unsure whether the check should be approved? Open a ticket as well

Please include a link to the check.

We can create an exclusion if the call is expected. In the ticket, please specify the expected scope of the call: job, workflow, repository, or the entire org.

Re-run a check

To re-run a check, go to Conversation and add the following comment:

@stepsecurity-app checks re-run

The check should re-run automatically. If it does not, open a ticket with the SOC

Please include a link to the check.

No check should take more than 15 minutes. You can re-run a check if it does.

Details

✅ PyPI Compromised Packages Check

No compromised PyPI package versions found in current PR.

✅ Script Injection Vulnerabilities Check

No Script Injection vulnerabilities found in this PR.

✅ Pwn Request Vulnerabilities Check

No Pwn Request vulnerabilities found in this PR.

✅ NPM Compromised Packages Check

No Compromised npm packages are added in current PR.

✅ NPM Package Cooldown Check

No npm package upgrades to recent releases found in current PR.

The following npm packages are inspected in current PR (showing first 10 of 39 packages)

Package Name Previous Version Current Version file Current Version Release Date
electron-to-chromium 1.5.389 1.5.405 package-lock.json 2026-08-11T22:05:02Z
@typescript-eslint/scope-manager 8.64.0 8.67.0 package-lock.json 2026-08-10T17:26:09Z
@typescript-eslint/visitor-keys 8.64.0 8.67.0 package-lock.json 2026-08-10T17:25:54Z
@typescript-eslint/tsconfig-utils 8.64.0 8.67.0 package-lock.json 2026-08-10T17:25:44Z
@typescript-eslint/typescript-estree 8.64.0 8.67.0 package-lock.json 2026-08-10T17:22:00Z
@typescript-eslint/utils 8.64.0 8.67.0 package-lock.json 2026-08-10T17:21:13Z
@typescript-eslint/project-service 8.64.0 8.67.0 package-lock.json 2026-08-10T17:20:49Z
@typescript-eslint/types 8.64.0 8.67.0 package-lock.json 2026-08-10T17:20:43Z
update-browserslist-db 1.2.3 1.3.1 package-lock.json 2026-08-10T13:50:14Z
baseline-browser-mapping 2.10.43 2.11.13 package-lock.json 2026-08-08T14:35:21Z