Skip to content

chore(deps): bump verdaccio from 6.7.3 to 6.7.4#1855

Merged
github-actions[bot] merged 1 commit into
update-dependenciesfrom
dependabot/npm_and_yarn/update-dependencies/verdaccio-6.7.4
Jun 22, 2026
Merged

chore(deps): bump verdaccio from 6.7.3 to 6.7.4#1855
github-actions[bot] merged 1 commit into
update-dependenciesfrom
dependabot/npm_and_yarn/update-dependencies/verdaccio-6.7.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bumps verdaccio from 6.7.3 to 6.7.4.

Release notes

Sourced from verdaccio's releases.

v6.7.4

Patch Changes

  • 0205c78: fix: run jwt middleware before middleware plugins

    Register the JWT middleware before middleware plugins are loaded so that req.remote_user (anonymous by default) is available inside a plugin's register_middlewares. The API router keeps its own JWT middleware behind a guard so it is not executed twice.

    Backport of verdaccio/verdaccio#5697

    Closes #5167

Changelog

Sourced from verdaccio's changelog.

6.7.4

Patch Changes

  • 0205c78: fix: run jwt middleware before middleware plugins

    Register the JWT middleware before middleware plugins are loaded so that req.remote_user (anonymous by default) is available inside a plugin's register_middlewares. The API router keeps its own JWT middleware behind a guard so it is not executed twice.

    Backport of verdaccio/verdaccio#5697

    Closes #5167

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jun 22, 2026
@github-actions github-actions Bot enabled auto-merge June 22, 2026 20:34
@socket-security

socket-security Bot commented Jun 22, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedverdaccio@​6.7.3 ⏵ 6.7.49710010098100

View full report

Base automatically changed from update-dependencies to master June 22, 2026 20:36
Bumps [verdaccio](https://github.com/verdaccio/verdaccio) from 6.7.3 to 6.7.4.
- [Release notes](https://github.com/verdaccio/verdaccio/releases)
- [Changelog](https://github.com/verdaccio/verdaccio/blob/v6.7.4/CHANGELOG.md)
- [Commits](verdaccio/verdaccio@v6.7.3...v6.7.4)

---
updated-dependencies:
- dependency-name: verdaccio
  dependency-version: 6.7.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the base branch from master to update-dependencies June 22, 2026 22:34
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/update-dependencies/verdaccio-6.7.4 branch from d9898a9 to 4933f0d Compare June 22, 2026 22:34
@github-actions github-actions Bot merged commit 7ad3dc7 into update-dependencies Jun 22, 2026
20 checks passed
@github-actions github-actions Bot deleted the dependabot/npm_and_yarn/update-dependencies/verdaccio-6.7.4 branch June 22, 2026 22:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants