Skip to content

build(deps): bump flatted from 3.4.1 to 3.4.2 in the npm-security group across 1 directory#12

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm-security-e5a595f223
Closed

build(deps): bump flatted from 3.4.1 to 3.4.2 in the npm-security group across 1 directory#12
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm-security-e5a595f223

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Mar 25, 2026

Bumps the npm-security group with 1 update in the / directory: flatted.

Updates flatted from 3.4.1 to 3.4.2

Commits

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Mar 25, 2026

Labels

The following labels could not be found: dependencies, intake, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-security-e5a595f223 branch from ff226e4 to 284afe1 Compare March 30, 2026 14:16
@dependabot dependabot Bot changed the title build(deps): bump flatted from 3.3.3 to 3.4.2 in the npm-security group across 1 directory build(deps): bump flatted from 3.4.1 to 3.4.2 in the npm-security group across 1 directory Apr 13, 2026
Bumps the npm-security group with 1 update in the / directory: [flatted](https://github.com/WebReflection/flatted).


Updates `flatted` from 3.3.3 to 3.4.2
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
  dependency-group: npm-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@saagpatel
Copy link
Copy Markdown
Owner

Superseded by #35 which bumps flatted to 3.4.2 via pnpm.overrides (minimal-diff approach vs Dependabot's full lockfile regeneration). Closing per docs/SECURITY.md.

@saagpatel saagpatel closed this Apr 21, 2026
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Apr 21, 2026

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/npm-security-e5a595f223 branch April 21, 2026 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant