WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 8, 2024

This PR contains the following updates:

Package Change Age Confidence
@hapi/boom ^9.1.4^10.0.0 age confidence
@hapi/hapi (source) ^20.2.1^21.0.0 age confidence
joi ^17.13.3^18.0.0 age confidence

Release Notes

hapijs/boom (@​hapi/boom)

v10.0.1

Compare Source

What's Changed

New Contributors

Full Changelog: hapijs/boom@v10.0.0...v10.0.1

v10.0.0

Compare Source

What's Changed

New Contributors

Full Changelog: hapijs/boom@v9.1.4...v10.0.0

hapijs/hapi (@​hapi/hapi)

v21.4.4

Compare Source

v21.4.3

Compare Source

v21.4.2

Compare Source

v21.4.1

Compare Source

v21.4.0

Compare Source

v21.3.12

Compare Source

v21.3.11

Compare Source

v21.3.10

Compare Source

v21.3.9

Compare Source

v21.3.8

Compare Source

v21.3.7

Compare Source

v21.3.6

Compare Source

v21.3.5

Compare Source

v21.3.4

Compare Source

v21.3.3

Compare Source

v21.3.2

Compare Source

v21.3.1

Compare Source

v21.3.0: 20.3.0

Compare Source

⚠️ This release contains security fixes, for more information see #​4425.

v21.2.2

Compare Source

v21.2.1

Compare Source

v21.2.0

Compare Source

v21.1.0

Compare Source

v21.0.0

Compare Source

Release notes: #​4386

hapi v21.0.0 is a medium-sized release focused on modernization and miscellaneous API improvements. All modules in the hapi.js ecosystem have been updated to officially support Node.js v18, be compatible with ESM projects, and drop support for Node.js v12. Plugins in the hapi.js ecosystem now support hapi v20+.

hapijs/joi (joi)

v18.0.2

Compare Source

v18.0.1

Compare Source

v18.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 3 times, most recently from d6c63df to 1feac99 Compare January 24, 2024 15:29
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 4 times, most recently from 3307489 to 680b96b Compare January 26, 2024 21:44
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 3 times, most recently from 5ce3e7c to 7a0fac8 Compare February 11, 2024 19:49
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 2 times, most recently from e8aa113 to 8831490 Compare February 12, 2024 11:11
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from 8831490 to 8c915ca Compare March 18, 2024 05:04
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from 8c915ca to b3709bf Compare April 4, 2024 01:41
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from b3709bf to 067d131 Compare May 13, 2024 07:31
@socket-security
Copy link

socket-security bot commented May 13, 2024

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm form-data uses unsafe random function in form-data for choosing boundary

CVE: GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary (CRITICAL)

Affected versions: < 2.5.4; >= 3.0.0 < 3.0.4; >= 4.0.0 < 4.0.4

Patched version: 4.0.4

From: pnpm-lock.yamlnpm/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm ioredis is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: packages/plugin-dlock/package.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm npm is 94.0% likely obfuscated

Confidence: 0.94

Location: Package overview

From: pnpm-lock.yamlnpm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 2 times, most recently from ac98196 to 6e35c0e Compare July 3, 2024 13:11
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 5 times, most recently from b7a462b to d93a1d1 Compare August 5, 2024 03:51
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 3 times, most recently from 73ebfc2 to d91ec60 Compare January 28, 2025 05:25
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch 2 times, most recently from baf8dc6 to 3dea0e2 Compare February 17, 2025 23:41
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from 3dea0e2 to bde92f4 Compare August 3, 2025 17:47
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from bde92f4 to cf61ca3 Compare August 20, 2025 17:11
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from cf61ca3 to 0a7dcd2 Compare August 31, 2025 10:20
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from 0a7dcd2 to 4eea42f Compare November 6, 2025 10:00
@socket-security
Copy link

socket-security bot commented Nov 6, 2025

@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from 4eea42f to fb40f2f Compare November 19, 2025 17:30
@renovate renovate bot force-pushed the renovate/major-hapijs-monorepo branch from fb40f2f to 3b67412 Compare January 1, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant