Skip to content

chore: update actions and deps#187

Merged
achou11 merged 19 commits into
mainfrom
deps/2026-06-22
Jun 22, 2026
Merged

chore: update actions and deps#187
achou11 merged 19 commits into
mainfrom
deps/2026-06-22

Conversation

@achou11

@achou11 achou11 commented Jun 22, 2026

Copy link
Copy Markdown
Member
  • Renames the lint job in CI to check
  • Updates the typechecking script to be a check and run during the check job in CI
  • Addresses easily fixable security audits

@awana-lockfile-bot

Copy link
Copy Markdown

package-lock.json changes

Summary

Status Count
ADDED 3
UPDATED 99
REMOVED 1
Click to toggle table visibility
Name Status Previous Current
@babel/code-frame UPDATED 7.29.0 7.29.7
@babel/compat-data UPDATED 7.29.0 7.29.7
@babel/core UPDATED 7.29.0 7.29.7
@babel/generator UPDATED 7.29.1 7.29.7
@babel/helper-compilation-targets UPDATED 7.28.6 7.29.7
@babel/helper-globals UPDATED 7.28.0 7.29.7
@babel/helper-module-imports UPDATED 7.28.6 7.29.7
@babel/helper-module-transforms UPDATED 7.28.6 7.29.7
@babel/helper-string-parser UPDATED 7.27.1 7.29.7
@babel/helper-validator-identifier UPDATED 7.28.5 7.29.7
@babel/helper-validator-option UPDATED 7.27.1 7.29.7
@babel/helpers UPDATED 7.28.6 7.29.7
@babel/parser UPDATED 7.29.0 7.29.7
@babel/template UPDATED 7.28.6 7.29.7
@babel/traverse UPDATED 7.29.0 7.29.7
@babel/types UPDATED 7.29.0 7.29.7
@comapeo/core UPDATED 7.2.0 7.3.0
@comapeo/map-server UPDATED 1.1.3 1.1.4
@commander-js/extra-typings ADDED - 14.0.0
@eslint/plugin-kit UPDATED 0.7.1 0.7.2
@oxc-project/types UPDATED 0.130.0 0.133.0
@protobufjs/eventemitter UPDATED 1.1.0 1.1.1
@protobufjs/inquire REMOVED 1.1.2 -
@rolldown/binding-android-arm64 UPDATED 1.0.1 1.0.3
@rolldown/binding-darwin-arm64 UPDATED 1.0.1 1.0.3
@rolldown/binding-darwin-x64 UPDATED 1.0.1 1.0.3
@rolldown/binding-freebsd-x64 UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-arm-gnueabihf UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-arm64-gnu UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-arm64-musl UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-ppc64-gnu UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-s390x-gnu UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-x64-gnu UPDATED 1.0.1 1.0.3
@rolldown/binding-linux-x64-musl UPDATED 1.0.1 1.0.3
@rolldown/binding-openharmony-arm64 UPDATED 1.0.1 1.0.3
@rolldown/binding-wasm32-wasi UPDATED 1.0.1 1.0.3
@rolldown/binding-win32-arm64-msvc UPDATED 1.0.1 1.0.3
@rolldown/binding-win32-x64-msvc UPDATED 1.0.1 1.0.3
@tanstack/eslint-plugin-query UPDATED 5.100.11 5.101.0
@tanstack/query-core UPDATED 5.100.11 5.101.0
@tanstack/react-query UPDATED 5.100.11 5.101.0
@tybys/wasm-util UPDATED 0.10.1 0.10.2
@types/node UPDATED 24.12.4 24.13.2
@types/react UPDATED 19.2.14 19.2.17
@typescript-eslint/eslint-plugin UPDATED 8.59.4 8.61.1
@typescript-eslint/parser UPDATED 8.59.4 8.61.1
@typescript-eslint/project-service UPDATED 8.59.4 8.61.1
@typescript-eslint/scope-manager UPDATED 8.59.4 8.61.1
@typescript-eslint/tsconfig-utils UPDATED 8.59.4 8.61.1
@typescript-eslint/type-utils UPDATED 8.59.4 8.61.1
@typescript-eslint/types UPDATED 8.59.4 8.61.1
@typescript-eslint/typescript-estree UPDATED 8.59.4 8.61.1
@typescript-eslint/utils UPDATED 8.59.4 8.61.1
@typescript-eslint/visitor-keys UPDATED 8.59.4 8.61.1
@vitest/eslint-plugin UPDATED 1.6.17 1.6.20
@vitest/expect UPDATED 4.1.6 4.1.9
@vitest/mocker UPDATED 4.1.6 4.1.9
@vitest/pretty-format UPDATED 4.1.6 4.1.9
@vitest/runner UPDATED 4.1.6 4.1.9
@vitest/snapshot UPDATED 4.1.6 4.1.9
@vitest/spy UPDATED 4.1.6 4.1.9
@vitest/utils UPDATED 4.1.6 4.1.9
argparse ADDED - 1.0.10
baseline-browser-mapping UPDATED 2.9.19 2.10.38
brace-expansion UPDATED 2.0.2 2.1.1
browserslist UPDATED 4.28.1 4.28.4
caniuse-lite UPDATED 1.0.30001769 1.0.30001799
comapeocat UPDATED 1.0.0 1.2.0
custom-error-creator UPDATED 1.1.1 1.4.0
electron-to-chromium UPDATED 1.5.286 1.5.376
eslint UPDATED 10.4.0 10.5.0
flatted UPDATED 3.3.3 3.4.2
globals UPDATED 17.6.0 17.7.0
iso-3166 UPDATED 4.3.0 4.4.0
js-yaml ADDED - 3.14.2
json-parse-even-better-errors UPDATED 4.0.0 6.0.0
lint-staged UPDATED 17.0.5 17.0.8
lodash UPDATED 4.17.23 4.18.1
nanoid UPDATED 3.3.12 3.3.15
node-releases UPDATED 2.0.27 2.0.48
npm-normalize-package-bin UPDATED 4.0.0 6.0.0
npm-run-all2 UPDATED 8.0.4 9.0.2
pidtree UPDATED 0.6.0 1.0.0
postcss UPDATED 8.5.14 8.5.15
prettier UPDATED 3.8.3 3.8.4
protobufjs UPDATED 7.6.0 7.6.4
react-dom UPDATED 19.2.6 19.2.7
react UPDATED 19.2.6 19.2.7
read-package-json-fast UPDATED 4.0.0 6.0.0
rolldown UPDATED 1.0.1 1.0.3
sax UPDATED 1.5.0 1.6.0
shell-quote UPDATED 1.8.3 1.8.4
tinyexec UPDATED 1.1.2 1.2.4
tinyglobby UPDATED 0.2.16 0.2.17
tshy UPDATED 4.1.2 4.1.3
type-fest UPDATED 5.6.0 5.7.0
typescript-eslint UPDATED 8.59.4 8.61.1
undici-types UPDATED 7.16.0 7.18.2
undici UPDATED 6.23.0 6.27.0
valibot UPDATED 1.2.0 1.4.1
vite UPDATED 8.0.13 8.0.16
vitest UPDATED 4.1.6 4.1.9
ws UPDATED 8.18.3 8.21.0

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@vitest/eslint-plugin@1.6.20npm/typescript-eslint@8.61.1npm/@typescript-eslint/eslint-plugin@8.61.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.61.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm tshy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/tshy@4.1.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/tshy@4.1.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@achou11 achou11 merged commit e953ee4 into main Jun 22, 2026
8 checks passed
@achou11 achou11 deleted the deps/2026-06-22 branch June 22, 2026 18:07
@achou11 achou11 mentioned this pull request Jun 22, 2026
achou11 added a commit that referenced this pull request Jun 22, 2026
Quick follow-up to #187 . Renames `check` to `checks`.
achou11 pushed a commit that referenced this pull request Jun 22, 2026
## Optic Release Automation

This **draft** PR is opened by Github action
[optic-release-automation-action](https://github.com/nearform-actions/optic-release-automation-action).

A new **draft** GitHub release
[v11.0.7](https://github.com/digidem/comapeo-core-react/releases/tag/untagged-f41c453fb12fb06dfd82)
has been created.

Release author: @achou11

#### If you want to go ahead with the release, please merge this PR.
When you merge:

- The GitHub release will be published

- The npm package with tag latest will be published according to the
publishing rules you have configured



- No major or minor tags will be updated as configured


#### If you close the PR

- The new draft release will be deleted and nothing will change

## What's Changed
* fix: narrow return type for useSingleDocByDocId by @achou11 in
#186
* chore: update actions and deps by @achou11 in
#187
* chore: minor CI cleanup by @achou11 in
#189


**Full Changelog**:
v11.0.6...v11.0.7

<!--

<release-meta>{"id":343091854,"version":"v11.0.7","npmTag":"latest","opticUrl":"https://optic-zf3votdk5a-ew.a.run.app/api/generate/"}</release-meta>
-->

Co-authored-by: achou11 <actions@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant