eslint-config-standard icon indicating copy to clipboard operation
eslint-config-standard copied to clipboard

chore(deps): update dependency editorconfig-checker to v5.1.9

Open renovate[bot] opened this issue 9 months ago • 1 comments

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
editorconfig-checker 5.1.8 -> 5.1.9 age adoption passing confidence

Release Notes

editorconfig-checker/editorconfig-checker.javascript (editorconfig-checker)

v5.1.9

Compare Source

Performance Improvements
  • reduce package size by updating dependencies, from 700Kb to 650Kb + fixes security issues with dependencies (f8f4bba)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • [ ] If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

renovate[bot] avatar Feb 21 '25 19:02 renovate[bot]

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatededitorconfig-checker@​5.1.8 ⏵ 5.1.992 -6100100 +181 -5100

View full report

socket-security[bot] avatar Feb 21 '25 19:02 socket-security[bot]

[!WARNING] Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm editorconfig-checker is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

socket-security[bot] avatar Nov 11 '25 05:11 socket-security[bot]