Skip to content

fix(deps): bump npm from 10.9.4 to 10.9.8#1233

Merged
svc-cli-bot merged 1 commit into
mainfrom
dependabot-npm_and_yarn-npm-10.9.8
Apr 11, 2026
Merged

fix(deps): bump npm from 10.9.4 to 10.9.8#1233
svc-cli-bot merged 1 commit into
mainfrom
dependabot-npm_and_yarn-npm-10.9.8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 11, 2026

Bumps npm from 10.9.4 to 10.9.8.

Release notes

Sourced from npm's releases.

v10.9.8

Dependencies

v10.9.7

10.9.7 (2026-03-18)

Bug Fixes

Dependencies

Chores

v10.9.6

10.9.6 (2026-03-10)

Bug Fixes

Dependencies

v10.9.5

10.9.5 (2026-03-04)

Bug Fixes

Dependencies

... (truncated)

Commits
  • dd3c80e chore: release 10.9.8
  • 8aa9c82 fix: eagerly require promise-retry to survive self-upgrade
  • 58c302d chore: release 10.9.7
  • e5c1309 chore: dev dependency updates
  • cc9a4de deps: hoist production @​sigstore dependencies
  • bbcd455 fix(arborist): v10 - backport store, lock-only, and override sibling fixes (#...
  • 49a764e chore: release 10.9.6
  • d6fe671 fix(arborist): v10 - backport multiple fixes for linked install (#9098)
  • ebd09c3 fix(arborist): backport linked strategy hoisting fixes to v10 (#9084)
  • a5dadad deps: tar@7.5.11
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [npm](https://github.com/npm/cli) from 10.9.4 to 10.9.8.
- [Release notes](https://github.com/npm/cli/releases)
- [Changelog](https://github.com/npm/cli/blob/latest/CHANGELOG.md)
- [Commits](npm/cli@v10.9.4...v10.9.8)

---
updated-dependencies:
- dependency-name: npm
  dependency-version: 10.9.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Apr 11, 2026
@svc-cli-bot svc-cli-bot merged commit 4d36ecd into main Apr 11, 2026
18 checks passed
@svc-cli-bot svc-cli-bot deleted the dependabot-npm_and_yarn-npm-10.9.8 branch April 11, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant