This PR contains the following updates:
Release Notes
microsoft/TypeScript (typescript)
Compare Source
Compare Source
v5.5.4: TypeScript 5.5.4
Compare Source
For release notes, check out the release announcement.
For the complete list of fixed issues, check out the
Downloads are available on:
v5.5.3: TypeScript 5.5.3
Compare Source
For release notes, check out the release announcement.
For the complete list of fixed issues, check out the
Downloads are available on:
v5.5.2: TypeScript 5.5
Compare Source
For release notes, check out the release announcement.
For the complete list of fixed issues, check out the
Downloads are available on:
Configuration
📅 Schedule: Branch creation - "after 7pm every weekday,before 5am every weekday" in timezone Europe/Madrid, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.
The latest updates on your projects. Learn more about Vercel for Git ↗︎
1 Skipped Deployment
| Name |
Status |
Preview |
Comments |
Updated (UTC) |
| unleash-docs |
⬜️ Ignored (Inspect) |
Visit Preview |
|
May 29, 2025 10:45am |
Dependency Review
✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.
OpenSSF Scorecard
| Package | Version | Score | Details |
| npm/typescript | 5.8.3 |
:green_circle: 8.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 10 | all changesets reviewed | | Dependency-Update-Tool | :green_circle: 10 | update tool detected | | Packaging | :warning: -1 | packaging workflow not detected | | Maintained | :green_circle: 10 | 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10 | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | License | :green_circle: 10 | license file detected | | Branch-Protection | :green_circle: 6 | branch protection is not maximal on development and all release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 6 | dependency not pinned by hash detected -- score normalized to 6 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :green_circle: 9 | SAST tool detected but not run on all commits | | Fuzzing | :green_circle: 10 | project is fuzzed | | CI-Tests | :green_circle: 9 | 29 out of 30 merged PRs checked by a CI test -- score normalized to 9 | | Contributors | :green_circle: 10 | project has 35 contributing companies or organizations |
|
| npm/typescript | 5.8.3 |
:green_circle: 8.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 10 | all changesets reviewed | | Dependency-Update-Tool | :green_circle: 10 | update tool detected | | Packaging | :warning: -1 | packaging workflow not detected | | Maintained | :green_circle: 10 | 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10 | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | License | :green_circle: 10 | license file detected | | Branch-Protection | :green_circle: 6 | branch protection is not maximal on development and all release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 6 | dependency not pinned by hash detected -- score normalized to 6 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :green_circle: 9 | SAST tool detected but not run on all commits | | Fuzzing | :green_circle: 10 | project is fuzzed | | CI-Tests | :green_circle: 9 | 29 out of 30 merged PRs checked by a CI test -- score normalized to 9 | | Contributors | :green_circle: 10 | project has 35 contributing companies or organizations |
|
| npm/typescript | 5.8.3 |
:green_circle: 8.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 10 | all changesets reviewed | | Dependency-Update-Tool | :green_circle: 10 | update tool detected | | Packaging | :warning: -1 | packaging workflow not detected | | Maintained | :green_circle: 10 | 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10 | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | License | :green_circle: 10 | license file detected | | Branch-Protection | :green_circle: 6 | branch protection is not maximal on development and all release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 6 | dependency not pinned by hash detected -- score normalized to 6 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :green_circle: 9 | SAST tool detected but not run on all commits | | Fuzzing | :green_circle: 10 | project is fuzzed | | CI-Tests | :green_circle: 9 | 29 out of 30 merged PRs checked by a CI test -- score normalized to 9 | | Contributors | :green_circle: 10 | project has 35 contributing companies or organizations |
|
| npm/typescript | 5.8.3 |
:green_circle: 8.4 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 10 | all changesets reviewed | | Dependency-Update-Tool | :green_circle: 10 | update tool detected | | Packaging | :warning: -1 | packaging workflow not detected | | Maintained | :green_circle: 10 | 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10 | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | License | :green_circle: 10 | license file detected | | Branch-Protection | :green_circle: 6 | branch protection is not maximal on development and all release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :green_circle: 6 | dependency not pinned by hash detected -- score normalized to 6 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | SAST | :green_circle: 9 | SAST tool detected but not run on all commits | | Fuzzing | :green_circle: 10 | project is fuzzed | | CI-Tests | :green_circle: 9 | 29 out of 30 merged PRs checked by a CI test -- score normalized to 9 | | Contributors | :green_circle: 10 | project has 35 contributing companies or organizations |
|
Scanned Files
- frontend/package.json
- frontend/yarn.lock
- website/package.json
- website/yarn.lock
Edited/Blocked Notification
Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.
You can manually request rebase by checking the rebase/retry box above.
⚠️ Warning: custom changes will be lost.