Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 5, 2025

This PR contains the following updates:

Package Change Age Confidence
eslint-plugin-react 7.37.4 -> 7.37.5 age confidence

Release Notes

jsx-eslint/eslint-plugin-react (eslint-plugin-react)

v7.37.5

Compare Source

Fixed
Changed

Configuration

📅 Schedule: Branch creation - Only on Sunday and Saturday ( * * * * 0,6 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Apr 5, 2025
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 3 times, most recently from ace9e4c to f164a87 Compare April 14, 2025 09:43
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from f164a87 to 4a88a4a Compare April 19, 2025 05:58
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 3 times, most recently from 338c995 to 74468ad Compare April 30, 2025 19:04
Copy link

socket-security bot commented Apr 30, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
@babel/[email protected] has a Critical CVE.

CVE: GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code (CRITICAL)

Affected versions: < 7.23.2; >= 8.0.0-alpha.0 < 8.0.0-alpha.4

Patched version: 7.23.2

From: package-lock.jsonnpm/[email protected]npm/@babel/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 2 times, most recently from af52bea to 3195366 Compare May 10, 2025 05:54
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 2 times, most recently from ebae13e to 9db9c95 Compare May 17, 2025 06:24
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from 9db9c95 to e0697c7 Compare May 31, 2025 06:27
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from e0697c7 to 2ff5b30 Compare June 14, 2025 16:51
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 4 times, most recently from 6ce7b9c to de3ff4e Compare July 5, 2025 05:34
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from de3ff4e to 78ead74 Compare July 5, 2025 10:48
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 4 times, most recently from 1530bae to 37517a6 Compare July 26, 2025 05:00
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from 37517a6 to ff32c86 Compare July 28, 2025 13:06
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from ff32c86 to e69a6dc Compare August 16, 2025 05:47
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 4 times, most recently from 40bf82c to 434716e Compare September 6, 2025 20:02
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch 2 times, most recently from 0ef3478 to b58ff51 Compare September 14, 2025 08:14
Copy link

socket-security bot commented Sep 14, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedjest@​29.7.01001006897100
Addedeslint-config-prettier@​8.10.21001007287100
Added@​types/​jest@​29.5.141001007779100
Addedhusky@​8.0.31001007979100
Addedeslint-plugin-react@​7.37.59910010083100
Addedlint-staged@​15.5.29910010096100
Addedaxios@​1.12.29910010097100

View full report

@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from b58ff51 to f595da4 Compare September 14, 2025 18:10
@renovate renovate bot force-pushed the renovate/eslint-plugin-react-7.x branch from f595da4 to cfe9db0 Compare October 4, 2025 05:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants