Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency three to ^0.166.0 #120

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 2, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
three (source) ^0.158.0 -> ^0.166.0 age adoption passing confidence
@types/three (source) ^0.158.2 -> ^0.166.0 age adoption passing confidence

Release Notes

mrdoob/three.js (three)

v0.166.0

Compare Source

v0.165.0

Compare Source

v0.164.1

Compare Source

v0.164.0

Compare Source

v0.163.0

Compare Source

v0.162.0

Compare Source

v0.161.0

Compare Source

v0.160.1

Compare Source

v0.160.0

Compare Source

v0.159.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - "after 10pm every weekday,before 5am every weekday,every weekend" in timezone America/New_York.

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies label Dec 2, 2023
@renovate renovate bot force-pushed the dep/three-0.x branch 3 times, most recently from b1caad5 to 77bb88e Compare December 16, 2023 04:49
@renovate renovate bot changed the title chore(deps): update dependency three to ^0.159.0 chore(deps): update dependency three to ^0.160.0 Dec 22, 2023
@renovate renovate bot force-pushed the dep/three-0.x branch 2 times, most recently from 1a419f2 to 61ea044 Compare December 23, 2023 00:05
@renovate renovate bot force-pushed the dep/three-0.x branch 11 times, most recently from 83bcd04 to 847ed6f Compare January 12, 2024 06:32
@renovate renovate bot force-pushed the dep/three-0.x branch 11 times, most recently from 44f3494 to c1609e7 Compare January 29, 2024 13:46
@renovate renovate bot enabled auto-merge (rebase) March 29, 2024 08:20
@renovate renovate bot changed the title chore(deps): update dependency three to ^0.162.0 chore(deps): update dependency three to ^0.163.0 Mar 29, 2024
auto-merge was automatically disabled March 29, 2024 08:20

Base branch requires signed commits

@renovate renovate bot changed the title chore(deps): update dependency three to ^0.163.0 chore(deps): update dependency three to ^0.164.0 Apr 25, 2024
Copy link

socket-security bot commented Apr 25, 2024

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Install scripts npm/canvas@2.11.2
  • Install script: install
  • Source: node-pre-gyp install --fallback-to-build --update-binary
🚫
Install scripts npm/core-js@3.37.1
  • Install script: postinstall
  • Source: node -e "try{require('./postinstall')}catch(e){}"
  • orphan: npm/core-js@3.37.1
🚫
Install scripts npm/core-js-pure@3.37.1
  • Install script: postinstall
  • Source: node -e "try{require('./postinstall')}catch(e){}"
🚫
Install scripts npm/cypress@13.12.0
  • Install script: postinstall
  • Source: node index.js --exec install
🚫

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/canvas@2.11.2
  • @SocketSecurity ignore npm/core-js@3.37.1
  • @SocketSecurity ignore npm/core-js-pure@3.37.1
  • @SocketSecurity ignore npm/cypress@13.12.0

@renovate renovate bot enabled auto-merge (rebase) April 26, 2024 16:43
auto-merge was automatically disabled April 26, 2024 16:43

Base branch requires signed commits

@renovate renovate bot enabled auto-merge (rebase) May 31, 2024 12:32
@renovate renovate bot changed the title chore(deps): update dependency three to ^0.164.0 chore(deps): update dependency three to ^0.165.0 May 31, 2024
auto-merge was automatically disabled May 31, 2024 12:32

Base branch requires signed commits

@renovate renovate bot enabled auto-merge (rebase) June 4, 2024 13:04
auto-merge was automatically disabled June 4, 2024 13:04

Base branch requires signed commits

@renovate renovate bot enabled auto-merge (rebase) June 28, 2024 13:03
@renovate renovate bot changed the title chore(deps): update dependency three to ^0.165.0 chore(deps): update dependency three to ^0.166.0 Jun 28, 2024
auto-merge was automatically disabled June 28, 2024 13:04

Base branch requires signed commits

Copy link

socket-security bot commented Jun 28, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@babel/core@7.24.7 environment, filesystem, unsafe +39 10.8 MB nicolo-ribaudo
npm/@babel/plugin-transform-modules-commonjs@7.24.7 Transitive: environment +29 6.64 MB nicolo-ribaudo
npm/@babel/preset-env@7.24.7 environment, filesystem Transitive: unsafe +122 16.4 MB nicolo-ribaudo
npm/@cypress/code-coverage@3.12.39 Transitive: environment, eval, filesystem, shell, unsafe +15 2.19 MB cypress-npm-publisher
npm/@headlessui/react@1.7.19 environment +3 819 kB malfaitrobin
npm/@heroicons/react@2.1.4 None 0 3.37 MB thecrypticace
npm/@next/bundle-analyzer@14.2.4 None 0 3.38 kB vercel-release-bot
npm/@next/env@14.2.4 environment, filesystem 0 11.7 kB vercel-release-bot
npm/@percy/cli@1.28.8 environment, filesystem, unsafe Transitive: eval, network, shell +32 2.39 MB percy-admin
npm/@sentry/nextjs@7.118.0 environment, filesystem, network Transitive: shell, unsafe +29 15.8 MB sentry-bot
npm/@swc/core@1.6.5 environment, filesystem, shell +13 433 MB kdy1
npm/@swc/jest@0.2.36 filesystem Transitive: environment +13 643 kB kdy1
npm/@testing-library/cypress@10.0.2 Transitive: environment, eval, filesystem +19 4.82 MB testing-library-bot
npm/@testing-library/jest-dom@6.4.6 Transitive: environment, eval, filesystem +10 2.64 MB testing-library-bot
npm/@testing-library/react@14.3.1 environment Transitive: eval +26 9.63 MB testing-library-bot
npm/@types/jest@29.5.12 None +4 701 kB types
npm/@types/node@20.14.9 None 0 2.09 MB types
npm/@types/react@18.3.3 None +2 1.69 MB types
npm/@types/semver@7.5.8 None 0 23.3 kB types
npm/@types/three@0.166.0 None +3 2.02 MB types
npm/@typescript-eslint/eslint-plugin@7.14.1 Transitive: environment +13 5.43 MB jameshenry
npm/@typescript-eslint/parser@7.14.1 Transitive: environment +9 1.49 MB jameshenry
npm/apexcharts@3.49.2 None +1 4.62 MB junedchhipa
npm/autoprefixer@10.4.19 environment Transitive: filesystem +4 2.72 MB ai
npm/babel-plugin-istanbul@6.1.1 environment, filesystem, shell +6 206 kB oss-bot
npm/babel-plugin-transform-import-meta@2.2.1 Transitive: environment +13 4.59 MB javiertury
npm/canvas@2.11.2 filesystem Transitive: environment, shell +4 742 kB calebhearon
npm/commitlint-config-monorepo@2.0.2 None 0 4.07 kB pskfyi
npm/concurrently@8.2.2 environment, filesystem +8 7.12 MB gustavohenke
npm/cross-env@7.0.3 environment Transitive: filesystem, shell +1 50.3 kB kentcdodds
npm/cypress@13.12.0 environment, filesystem, shell, unsafe Transitive: eval, network +45 11 MB cypress-npm-publisher
npm/dotenv-defaults@5.0.2 Transitive: environment, filesystem +1 41 kB mrsteele
npm/dotenv-mono@1.3.14 environment, filesystem +2 159 kB marcocesarato
npm/eslint-config-airbnb-typescript@17.1.0 Transitive: environment +11 4 MB iamturns
npm/eslint-config-next@14.2.4 unsafe Transitive: environment, filesystem, shell +26 3.37 MB vercel-release-bot
npm/eslint-config-prettier@9.1.0 None 0 20.8 kB lydell
npm/eslint-plugin-cypress@2.15.2 None 0 51.9 kB cypress-npm-publisher
npm/eslint-plugin-import@2.29.1 filesystem, unsafe Transitive: eval +29 4.28 MB ljharb
npm/eslint-plugin-jest-dom@5.4.0 Transitive: environment, eval, filesystem +19 4.86 MB benmonro
npm/eslint-plugin-jest-formatting@3.1.0 None 0 75.6 kB dangreenleipciger
npm/eslint-plugin-jest@27.9.0 filesystem Transitive: environment +12 2.83 MB simenb
npm/eslint-plugin-jsx-a11y@6.9.0 Transitive: eval +31 6.97 MB ljharb
npm/eslint-plugin-node@11.1.0 filesystem +3 793 kB mysticatea
npm/eslint-plugin-prettier@5.1.3 None +3 284 kB jounqin
npm/eslint-plugin-react-hooks@4.6.2 environment 0 118 kB react-bot
npm/eslint-plugin-react@7.34.3 filesystem Transitive: environment, eval +29 4.04 MB ljharb
npm/eslint-plugin-simple-import-sort@12.1.0 None 0 38.2 kB lydell
npm/eslint-plugin-sonarjs@0.24.0 None 0 314 kB sonartech
npm/eslint-plugin-tailwindcss@3.17.4 Transitive: filesystem +5 401 kB francoismassart
npm/eslint-plugin-testing-library@6.2.2 filesystem Transitive: environment +6 793 kB testing-library-bot
npm/eslint-plugin-unicorn@51.0.1 Transitive: environment, eval, filesystem, unsafe +24 8 MB sindresorhus
npm/eslint-plugin-unused-imports@3.2.0 None +1 31.9 kB sweepline
npm/eslint@8.57.0 environment, filesystem Transitive: eval, shell, unsafe +41 8.32 MB eslintbot
npm/execa@8.0.1 environment Transitive: filesystem, shell +9 257 kB ehmicky
npm/flowbite-react@0.6.4 Transitive: environment +9 86.8 MB rluders
npm/flowbite@2.4.1 None +1 6.71 MB zoliszogyenyi

🚮 Removed packages: npm/prettier@3.1.0, npm/typescript@5.2.2

View full report↗︎

@renovate renovate bot enabled auto-merge (rebase) June 28, 2024 22:02
auto-merge was automatically disabled June 28, 2024 22:02

Base branch requires signed commits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants