Skip to content

build(deps-dev): bump typescript to v5.9.3 - #209

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/typescript-5.x
Open

build(deps-dev): bump typescript to v5.9.3#209
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/typescript-5.x

Conversation

@renovate

@renovate renovate Bot commented Jun 20, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
typescript (source) 5.4.55.9.3 age adoption passing confidence

Release Notes

microsoft/TypeScript (typescript)

v5.9.3: TypeScript 5.9.3

Compare Source

Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.

For release notes, check out the release announcement

Downloads are available on:

v5.9.2: TypeScript 5.9

Compare Source

Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.

For release notes, check out the release announcement

Downloads are available on:

v5.8.3: TypeScript 5.8.3

Compare Source

Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.

For release notes, check out the release announcement.

Downloads are available on:

v5.8.2: TypeScript 5.8

Compare Source

For release notes, check out the release announcement.

Downloads are available on:

v5.7.3: TypeScript 5.7.3

Compare Source

For release notes, check out the release announcement.

Downloads are available on npm

v5.7.2: TypeScript 5.7

Compare Source

For release notes, check out the release announcement.

Downloads are available on:

v5.6.3: TypeScript 5.6.3

Compare Source

For release notes, check out the release announcement.

For the complete list of fixed issues, check out the

Downloads are available on:

v5.6.2: TypeScript 5.6

Compare Source

For release notes, check out the release announcement.

For the complete list of fixed issues, check out the

Downloads are available on:

v5.5.4: TypeScript 5.5.4

Compare Source

For release notes, check out the release announcement.

For the complete list of fixed issues, check out the

Downloads are available on:

v5.5.3: TypeScript 5.5.3

Compare Source

For release notes, check out the release announcement.

For the complete list of fixed issues, check out the

Downloads are available on:

v5.5.2: TypeScript 5.5

Compare Source

For release notes, check out the release announcement.

For the complete list of fixed issues, check out the

Downloads are available on:


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.5.2 build(deps-dev): bump typescript to v5.5.3 Jul 1, 2024
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 34c2ec7 to a843127 Compare July 1, 2024 20:08
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from a843127 to 1559816 Compare July 22, 2024 23:29
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.5.3 build(deps-dev): bump typescript to v5.5.4 Jul 22, 2024
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 1559816 to 793df1e Compare September 9, 2024 19:14
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.5.4 build(deps-dev): bump typescript to v5.6.2 Sep 9, 2024
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.6.2 build(deps-dev): bump typescript to v5.6.3 Oct 8, 2024
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 793df1e to f7262e9 Compare October 8, 2024 23:09
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.6.3 build(deps-dev): bump typescript to v5.7.2 Nov 22, 2024
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from f7262e9 to 7cf6773 Compare November 22, 2024 17:52
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 7cf6773 to b6adc87 Compare January 8, 2025 22:25
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.7.2 build(deps-dev): bump typescript to v5.7.3 Jan 8, 2025
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from b6adc87 to 27164f8 Compare February 28, 2025 18:02
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.7.3 build(deps-dev): bump typescript to v5.8.2 Feb 28, 2025
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 27164f8 to c5b6463 Compare April 5, 2025 01:41
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.8.2 build(deps-dev): bump typescript to v5.8.3 Apr 5, 2025
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from c5b6463 to 90e0811 Compare August 1, 2025 01:10
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.8.3 build(deps-dev): bump typescript to v5.9.2 Aug 1, 2025
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from 22f26ea to 77bd2a6 Compare August 19, 2025 13:14
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from f96ce0f to db19b43 Compare September 30, 2025 22:32
@renovate renovate Bot changed the title build(deps-dev): bump typescript to v5.9.2 build(deps-dev): bump typescript to v5.9.3 Sep 30, 2025
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from db19b43 to 381dc87 Compare October 21, 2025 17:35
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 381dc87 to f6538a6 Compare November 10, 2025 20:48
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from f6538a6 to eac9880 Compare November 18, 2025 22:36
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from eac9880 to 26a2c04 Compare December 3, 2025 18:35
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 26a2c04 to 6fcc1d2 Compare February 2, 2026 21:35
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from 08f60e0 to 484dfe2 Compare February 17, 2026 21:51
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 484dfe2 to 934df5c Compare March 5, 2026 14:53
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 934df5c to b86a90a Compare March 13, 2026 15:14
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from 887a5ed to b048dac Compare April 1, 2026 19:47
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from b048dac to 6d381c8 Compare April 8, 2026 17:27
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 6d381c8 to c941c89 Compare April 29, 2026 10:54
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from 8d97e36 to 4dbd963 Compare May 18, 2026 11:02
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from 4dcc7ff to 9d5022c Compare June 1, 2026 21:48
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 9d5022c to d76f99e Compare June 11, 2026 17:52
Comment thread pnpm-lock.yaml
resolution: {integrity: sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==}
hasBin: true

js-yaml@3.6.1:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium severity vulnerability may affect your project—review required:
Line 558 lists a dependency (js-yaml) with a known Medium severity vulnerability.

ℹ️ Why this matters

Affected versions of js-yaml are vulnerable to Uncontrolled Resource Consumption. js-yaml is vulnerable to denial of service when parsing untrusted YAML: a document that uses nested arrays as mapping keys combined with anchors and aliases triggers exponential string expansion during parsing, stalling the Node.js process and exhausting memory. Any call to a js-yaml load function (load, loadAll, safeLoad, safeLoadAll) on attacker-controlled input is affected.

References: GHSA

To resolve this comment:
Check if you are using js-yaml on the CLI.

  • If you're affected, upgrade this dependency to at least version 3.13.0 at pnpm-lock.yaml.
  • If you're not affected, comment /fp we don't use this [condition]
💬 Ignore this finding

To ignore this, reply with:

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

You can view more details on this finding in the Semgrep AppSec Platform here.

Comment thread pnpm-lock.yaml
resolution: {integrity: sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==}
hasBin: true

js-yaml@3.6.1:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium severity vulnerability may affect your project—review required:
Line 558 lists a dependency (js-yaml) with a known Medium severity vulnerability.

ℹ️ Why this matters

Affected versions of js-yaml are vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). js-yaml is vulnerable to prototype pollution through its YAML merge key (<<) handling. When parsing untrusted YAML with load, loadAll, safeLoad, or safeLoadAll, a crafted document containing a __proto__ key inside a merged mapping can modify the prototype of the resulting object, leading to integrity violations in the application.

References: GHSA, CVE

To resolve this comment:
Check if you are using js-yaml on the CLI.

  • If you're affected, upgrade this dependency to at least version 3.14.2 at pnpm-lock.yaml.
  • If you're not affected, comment /fp we don't use this [condition]
💬 Ignore this finding

To ignore this, reply with:

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

You can view more details on this finding in the Semgrep AppSec Platform here.

@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from c250f13 to f883173 Compare July 16, 2026 17:13
@socket-security

socket-security Bot commented Jul 16, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedtypescript@​5.9.31001009010090

View full report

@socket-security

socket-security Bot commented Jul 16, 2026

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch 2 times, most recently from ed3ecaf to e1a8433 Compare July 24, 2026 16:43
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from e1a8433 to 23805cb Compare July 30, 2026 16:13
Comment thread pnpm-lock.yaml
resolution: {integrity: sha512-ttBQIIQPDeLjpPOohtUdXuXUVoA2uIB6fEH9HyJ7234s5mBJ5wTx20njxplLZQgLaOfpmPQA7X2t5AX6tIPbog==}
hasBin: true

js-yaml@3.6.1:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High severity vulnerability may affect your project—review required:
Line 551 lists a dependency (js-yaml) with a known High severity vulnerability.

ℹ️ Why this matters

Affected versions of js-yaml are vulnerable to Inefficient Algorithmic Complexity / Uncontrolled Resource Consumption. An attacker can supply a YAML document containing a chain of mappings that each merge the previous one via the merge key (<<), causing js-yaml to spend quadratic CPU time while parsing input whose size grows only linearly, resulting in a denial of service.

References: GHSA, CVE

To resolve this comment:
Check if you are using js-yaml on the CLI.

  • If you're affected, upgrade this dependency to at least version 3.15.0 at pnpm-lock.yaml.
  • If you're not affected, comment /fp we don't use this [condition]
💬 Ignore this finding

To ignore this, reply with:

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

You can view more details on this finding in the Semgrep AppSec Platform here.

@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 23805cb to 392876a Compare August 11, 2026 23:34
Comment thread pnpm-lock.yaml
resolution: {integrity: sha512-S99WuO3HlhO3XN41EtYUNl9zzXjoJx7QvmipxsJVxtCBT0YHEFy+iOJhjSvrmV12nYhWpZaM8lPHkJm0yUMbag==}
hasBin: true

js-yaml@3.6.1:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High severity vulnerability may affect your project—review required:
Line 551 lists a dependency (js-yaml) with a known High severity vulnerability.

ℹ️ Why this matters

Affected versions of js-yaml are vulnerable to Inefficient Algorithmic Complexity. An attacker can supply a YAML document containing a large !!omap sequence, which js-yaml resolves with a linear duplicate-key scan inside its per-element loop. Resolution is therefore quadratic in the number of entries, so a modestly sized document consumes disproportionate CPU inside the load call and blocks the event loop, resulting in a denial of service.

References: GHSA

To resolve this comment:
Check if you are using js-yaml on the CLI.

  • If you're affected, upgrade this dependency to at least version 3.15.1 at pnpm-lock.yaml.
  • If you're not affected, comment /fp we don't use this [condition]
💬 Ignore this finding

To ignore this, reply with:

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

You can view more details on this finding in the Semgrep AppSec Platform here.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/typescript-5.x branch from 392876a to 29bc8a1 Compare August 14, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants