chore(deps): bump js-cookie from 3.0.5 to 3.0.7 in /04-infrastructure-as-code/cdk/typescript/knowledge-base-rag-agent#1550
Conversation
Bumps [js-cookie](https://github.com/js-cookie/js-cookie) from 3.0.5 to 3.0.7. - [Release notes](https://github.com/js-cookie/js-cookie/releases) - [Commits](js-cookie/js-cookie@v3.0.5...v3.0.7) --- updated-dependencies: - dependency-name: js-cookie dependency-version: 3.0.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Latest scan for commit: Security Scan ResultsScan Metadata
SummaryScanner ResultsThe table below shows findings by scanner, with status based on severity thresholds and dependencies: Column Explanations: Severity Levels (S/C/H/M/L/I):
Other Columns:
Scanner Results:
Severity Thresholds (Thresh Column):
Threshold Source: Values in parentheses indicate where the threshold is configured:
Statistics calculation:
Detailed FindingsShow 64 actionable findingsFinding 1: GHSA-c4j6-fc7j-m34r-next
Description: Finding 2: GHSA-pf86-5x62-jrwf-axios
Description: Finding 3: GHSA-6chq-wfr3-2hj9-axios
Description: Finding 4: GHSA-3w6x-2g7m-8v23-axios
Description: Finding 5: GHSA-w9j2-pvgh-6h63-axios
Description: Finding 6: GHSA-q8qp-cvcw-x6jj-axios
Description: Finding 7: GHSA-43fc-jf86-j433-axios
Description: Finding 8: GHSA-37qj-frw5-hhjh-fast-xml-parser
Description: Finding 9: GHSA-mg66-mrh9-m8jx-next
Description: Finding 10: GHSA-pmwg-cvhr-8vh7-axios
Description: Finding 11: GHSA-445q-vr5w-6q77-axios
Description: Finding 12: GHSA-62hf-57xw-28j9-axios
Description: Finding 13: GHSA-36qx-fr4f-26g5-next
Description: Finding 14: GHSA-r5fr-rjxr-66jc-lodash
Description: Finding 15: GHSA-5c9x-8gcm-mpgx-axios
Description: Finding 16: GHSA-vf2m-468p-8v99-axios
Description: Finding 17: GHSA-m7pr-hjqh-92cm-axios
Description: Finding 18: GHSA-26hh-7cqf-hhc6-next
Description: Finding 19: GHSA-267c-6grr-h53f-next
Description: Finding 20: GHSA-48c2-rrv3-qjmp-yaml
Description: Finding 21: GHSA-q3j6-qgpj-74h6-fast-uri
Description: Finding 22: GHSA-7r86-cg39-jmmj-minimatch
Description: Finding 23: GHSA-v39h-62p7-jpjc-fast-uri
Description: Finding 24: GHSA-492v-c6pp-mqqv-next
Description: Finding 25: GHSA-jp2q-39xq-3w4g-fast-xml-parser
Description: Finding 26: GHSA-jp2q-39xq-3w4g-fast-xml-parser
Description: Finding 27: GHSA-jp2q-39xq-3w4g-fast-xml-parser
Description: Finding 28: GHSA-jp2q-39xq-3w4g-fast-xml-parser
Description: Finding 29: GHSA-jmr7-xgp7-cmfj-fast-xml-parser
Description: Finding 30: GHSA-jmr7-xgp7-cmfj-fast-xml-parser
Description: Finding 31: GHSA-jmr7-xgp7-cmfj-fast-xml-parser
Description: Finding 32: GHSA-jmr7-xgp7-cmfj-fast-xml-parser
Description: Finding 33: GHSA-3p68-rc4w-qgx5-axios
Description: Finding 34: GHSA-xx6v-rp6x-q39c-axios
Description: Finding 35: GHSA-w5hq-g745-h8pq-uuid
Description: Finding 36: GHSA-xxjr-mmjv-4gpg-lodash
Description: Finding 37: GHSA-3ppc-4f35-3m26-minimatch
Description: Finding 38: GHSA-8gc5-j5rx-235r-fast-xml-parser
Description: Finding 39: GHSA-8gc5-j5rx-235r-fast-xml-parser
Description: Finding 40: GHSA-8gc5-j5rx-235r-fast-xml-parser
Description: Finding 41: GHSA-8gc5-j5rx-235r-fast-xml-parser
Description: Finding 42: GHSA-23c5-xmqv-rm74-minimatch
Description: Finding 43: GHSA-gh4j-gqv2-49f6-fast-xml-parser
Description: Finding 44: GHSA-gh4j-gqv2-49f6-fast-xml-parser
Description: Finding 45: GHSA-gh4j-gqv2-49f6-fast-xml-parser
Description: Finding 46: GHSA-gh4j-gqv2-49f6-fast-xml-parser
Description: Finding 47: GHSA-m7jm-9gc2-mpf2-fast-xml-parser
Description: Finding 48: GHSA-m7jm-9gc2-mpf2-fast-xml-parser
Description: Finding 49: GHSA-m7jm-9gc2-mpf2-fast-xml-parser
Description: Finding 50: GHSA-m7jm-9gc2-mpf2-fast-xml-parser
Description: Finding 51: GHSA-fvcv-3m26-pcqx-axios
Description: Finding 52: GHSA-ggv3-7p47-pfv8-next
Description: Finding 53: GHSA-qx2v-qp2m-jg93-postcss
Description: Finding 54: GHSA-ffhc-5mcf-pf4q-next
Description: Finding 55: GHSA-f23m-r3pf-42rh-lodash
Description: Finding 56: GHSA-f886-m6hf-6m8v-brace-expansion
Description: Finding 57: GHSA-3x4c-7xq6-9pq8-next
Description: Finding 58: GHSA-h64f-5h5j-jqjh-next
Description: Finding 59: GHSA-wfc6-r584-vfw7-next
Description: Finding 60: GHSA-2g4f-4pwh-qvx6-ajv
Description: Finding 61: GHSA-gx5p-jg67-6x7h-next
Description: Finding 62: GHSA-8h8q-6873-q5fj-next
Description: Finding 63: GHSA-q4gf-8mx6-v5v3-next
Description: Finding 64: GHSA-r4q5-vmmm-2653-follow-redirects
Description: Report generated by Automated Security Helper (ASH) at 2026-05-21T23:16:49+00:00 |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps js-cookie from 3.0.5 to 3.0.7.
Release notes
Sourced from js-cookie's releases.
Commits
17bacbaCraft v3.0.7 releaseadb823cFix release workflow halting atgit tag5f9e759May remove Git user config from release workflow6ac9211Fix release workflow not able to push commit + tag2278bc5Fix missing package version bumpeb3c40ePrevent cookie attribute injectionf6f157fBump globals from 17.5.0 to 17.6.0f409d02Bump eslint from 10.2.0 to 10.3.0a686883Bump protobufjs in the npm_and_yarn group across 1 directoryc6112d2Bump@protobufjs/utf8in the npm_and_yarn group across 1 directoryMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for js-cookie since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.