Skip to content

ci(deps): update bfra-me/.github to v4.13.8#377

Merged
fro-bot[bot] merged 1 commit intomainfrom
renovate/bfra-me-.github-4.x
Mar 24, 2026
Merged

ci(deps): update bfra-me/.github to v4.13.8#377
fro-bot[bot] merged 1 commit intomainfrom
renovate/bfra-me-.github-4.x

Conversation

@fro-bot
Copy link
Contributor

@fro-bot fro-bot bot commented Mar 23, 2026

This PR contains the following updates:

Package Type Update Change OpenSSF
bfra-me/.github action patch v4.13.6v4.13.8 OpenSSF Scorecard

Release Notes

bfra-me/.github (bfra-me/.github)

v4.13.8

Compare Source

Patch Changes
  • ⚠️ Update GitHub Actions workflow dependency fro-bot/agent from v0.31.2 to v0.32.0 (#​1872)

  • ⚙️ Update GitHub Actions workflow dependency bfra-me/renovate-action from 9.10.1 to 9.11.0 (#​1874)

  • ⚙️ Update GitHub Actions workflow dependency bfra-me/renovate-action from 9.11.0 to 9.12.0 (#​1875)

v4.13.7

Compare Source

Patch Changes
  • Force flatted to 3.4.2 to fix prototype pollution vulnerability (CVE-2026-33228) (#​1859)

    This addresses a HIGH severity security vulnerability in flatted <=3.4.1
    discovered via Dependabot alert #​39. The vulnerability allows prototype
    pollution via the parse() function in NodeJS.

    Since flatted is a transitive dependency of eslint via flat-cache and
    file-entry-cache, we add a pnpm override to ensure the patched version
    is used throughout the dependency tree.

  • ⚙️ Update GitHub Actions workflow dependency bfra-me/renovate-action from 9.10.0 to 9.10.1 (#​1868)

  • ⚙️ Update GitHub Actions workflow dependency fro-bot/agent from v0.31.1 to v0.31.2 (#​1863)

  • 📦 Update npm dependency eslint from 10.0.3 to 10.1.0 (#​1869)

  • 📦 Update npm dependency pnpm (#​1867)


Configuration

📅 Schedule: Branch creation - "" in timezone America/Phoenix, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@fro-bot fro-bot bot requested review from fro-bot and marcusrbrown as code owners March 23, 2026 20:31
@fro-bot fro-bot bot added automerge dependencies Dependency updates or security alerts patch renovate Universal dependency update tool <https://mend.io/renovate> action labels Mar 23, 2026
@fro-bot fro-bot bot enabled auto-merge (squash) March 23, 2026 20:31
@fro-bot fro-bot bot removed action labels Mar 24, 2026
@fro-bot fro-bot bot force-pushed the renovate/bfra-me-.github-4.x branch from a80a5d0 to d8a03f1 Compare March 24, 2026 06:55
@fro-bot fro-bot bot changed the title ci(deps): update bfra-me/.github to v4.13.7 ci(deps): update bfra-me/.github to v4.13.8 Mar 24, 2026
@fro-bot fro-bot mentioned this pull request Mar 24, 2026
25 tasks
@fro-bot fro-bot bot merged commit 7b32d6f into main Mar 24, 2026
11 checks passed
@fro-bot fro-bot bot deleted the renovate/bfra-me-.github-4.x branch March 24, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automerge dependencies Dependency updates or security alerts patch renovate Universal dependency update tool <https://mend.io/renovate>

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant