D

Dependabot

D
Dependabot Security v0.396.0

v0.396.0

What's Changed Remove fully rolled out feature flags by @ruben-pachecocaldera in #16046 build(deps): bump hcl2json to v0.6.9 by @JamieMagee in #16188 build(deps): bump PowerShell to 7.6.5 by @JamieMagee in #16189 build(deps): bump Yarn to 4.18.0 by @JamieMagee in #16187 build(deps): bump git-shim to v1.5.0 by @JamieMagee in #16186 Add shared delivery for unavailable cooldown warnings by @v-robaike…

D
Dependabot Security v0.395.0

v0.395.0

What's Changed fix: handle nil hash results from unavailable Python package indexes by @sachin-sandhu in #16078 Skip unsupported Maven wrappers instead of failing the Maven job by @kbukum1 in #16090 Migrate test runner to turbo_tests2 by @jeffwidman in #15991 Bump the dev-dependencies group across 2 directories with 5 updates by @dependabot[bot] in #16085 Bump the prod-dependencies group across 2…

D
Dependabot Security v0.394.0

v0.394.0

What's Changed Remove enable_corepack_for_npm_and_yarn and preserve direct execution by @ruben-pachecocaldera with @Copilot in #15945 Remove enable_private_registry_for_corepack flag and make private-registry corepack env permanent by @ruben-pachecocaldera with @Copilot in #15946 Nix: lock the selected revision by @JamieMagee in #15984 Remove allow_refresh_for_existing_pr_dependencies feature flag…

D
Dependabot Security v0.393.0

v0.393.0

What's Changed Type common runtime boundaries by @JamieMagee in #15916 Type common provider clients by @JamieMagee in #15917 Type common repository fetching by @JamieMagee in #15918 Type common metadata boundaries by @JamieMagee in #15919 Type common pull request reads by @JamieMagee in #15920 Type common pull request writes by @JamieMagee in #15921 Bump erb from 6.0.1 to 6.0.1.1 in /updater by @d…

D
Dependabot Security v0.392.0

v0.392.0

What's Changed Type shared Python requirement boundaries by @JamieMagee in #15837 Type Python requirement consumers by @JamieMagee in #15838 Type UV requirement access by @JamieMagee in #15839 Type Conda requirement access by @JamieMagee in #15840 Roll pub. Fix flutter/dart sdk constraint rewritten in lockfile by @svartalfheim in #15654 Use GitHub Artifact Attestations for container image signing…

D
Dependabot Security v0.391.0

v0.391.0

What's Changed Add typed requirement metadata readers by @JamieMagee in #15740 Type common requirement access by @JamieMagee in #15741 gracefully handle exceptions generated during package detail fetch by @brettfo in #15762 Bump the dev-dependencies group across 2 directories with 7 updates by @dependabot[bot] in #15563 Upgrade uv to 0.11.31 by @ABruihler in #15424 Bump ip-address from 10.2.0 to 1…

D
Dependabot Security v0.390.0

v0.390.0

What's Changed Add typed requirement source API by @JamieMagee in #15705 Reland "Cargo: handle crates locked at multiple versions" (#15638) by @p-linnane in #15668 Preserve original absence of the bundler self-checksum on lockfile updates by @p-linnane in #15669 Support security updates for vcpkg ports by @JamieMagee in #15676 Beta support of PNPM 11 by @v-robaiken in #15710 Remove enable_cooldown…

D
Dependabot Security v0.389.0

v0.389.0

What's Changed Rescue errors in metadata_cascades_for_dep to prevent PR message loss by @yeikel in #14905 Bump sigstore from 4.1.0 to 4.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15484 Bump handlebars from 4.7.8 to 4.7.9 in /npm_and_yarn/helpers by @dependabot[bot] in #14547 Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14605 fix: use canonical LOCKF…

D
Dependabot Security v0.388.0

v0.388.0

What's Changed Type GitHub release metadata by @JamieMagee in #15597 Make GitCommitChecker strongly typed by @JamieMagee in #15598 Retry corepack prepare and install on signature metadata errors from private registries by @kbukum1 in #15606 Fix UV DependencyGrapher to detect nested uv.lock in monorepos by @thavaahariharangit with @Copilot in #15520 Bump library/rust from 1.95.0-bookworm to 1.97.0-…

D
Dependabot Security v0.387.0

v0.387.0

What's Changed Type the gradle, swift, and pre_commit ecosystems by @JamieMagee in #15534 Default cooldown to 3 days when default-days is not specified (behind a feature flag) by @robaiken with @Copilot in #15344 Use shared base cooldown in git_submodules by @robaiken in #15537 [Update graph] Avoid PathDependenciesNotReachable killing the whole job by @brrygrdn in #15522 [Update Graph] Ensure that…

D
Dependabot Security v0.386.0

v0.386.0

What's Changed Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512 Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513 [Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508 Handle global.json with no SDK version in dotnet_sdk parser by @brettfo in #15510 Type the cargo ecosystem and…

D
Dependabot Security v0.385.0

v0.385.0

What's Changed Support package-scoped NuGet release notes by @Cjewett in #15211 Filter null entries from job directories by @brettfo in #15457 devcontainers: preserve major-only Feature pins when precision-matching tags are absent by @thavaahariharangit with @Copilot in #15445 Type opaque hashes in common with T.anything by @JamieMagee in #15458 Type the options passthrough in base classes with T.…

D
Dependabot Security v0.384.0

v0.384.0

What's Changed Bazel: Fix prerelease filtering with same-release-line scoping by @v-HaripriyaC in #15332 Respect cooldown for Docker digest updates and suppress multi-arch no-ops by @robaiken in #15354 Bypass npmrc min-release-age for transitive npm security updates by @robaiken in #15386 Ratchet the Sorbet T.untyped burndown by @JamieMagee in #15399 feat(docker): implement single-platform image d…

D
Dependabot Security v0.383.0

v0.383.0

What's Changed Bump bundled npm from 11.8.0 to 11.17.0 by @kbukum1 in #15335 Fix composer specs failure due to block-insecure feature by @AbhishekBhaskar in #15334 Add blocked_versions.ignored metric for Security-blocked update checks by @kbukum1 in #15333 Preserve original bundler checksum on Bundler 4.0.11+ lockfile updates by @lucasmazza in #15249 Generate .npmrc from scope property when lockfi…

D
Dependabot Security v0.382.0

v0.382.0

What's Changed Add support for scope property in npm_registry credentials by @AbhishekBhaskar in #15219 uv: Remove dead add_auth_env_vars code and add credential matching diagnostics by @kbukum1 in #15209 Fix npm registry credential leak to sibling paths on the same host by @Copilot in #15248 Fix pnpm lockfileVersion 9.0 parsing error with optional chaining by @markhallen in #13959 Parse remaining…

D
Dependabot Security v0.381.0

v0.381.0

What's Changed Disable npmMinimalAgeGate for Yarn Berry security updates by @yeikel in #15191 Add Bundler 4 support by @JamieMagee in #15180 Bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /maven/lib/dependabot/maven by @dependabot[bot] in #15190 Add GONOPROXY/GONOSUMDB env vars to go_modules FileParser by @Nishnha in #15159 fix(go_modules): include advisory pseudo-v…

D
Dependabot Security v0.380.0

v0.380.0

What's Changed bundler: avoid adding Bundler checksum for lockfiles using 4.0.0-4.0.10 by @thavaahariharangit in #15164 Remove beta ecosystem flag handling for Deno by @markhallen in #15173 [bun] Add lockfile generator for bun by @brrygrdn in #14882 Pass --config.minimumReleaseAge=0 for pnpm security updates to bypass pnpm-workspace.yaml by @yeikel in #15170 build(deps): bump terraform to 1.15.3 b…

D
Dependabot Security v0.379.0

v0.379.0

What's Changed Fix duplicate updated dependencies in multi-directory group refresh by @markhallen in #15098 Recategorise lockfile generation errors as known types by @brrygrdn in #15084 [Graph Job] Do not treat Dependabot::UnexpectedExternalCode as a hard failure by @brrygrdn in #15075 [Graph] Fix handling of multiple version resolution by @brrygrdn in #15099 Bun: Upgrade to Node JS 24 by @yeikel…

D
Dependabot Security v0.378.0

v0.378.0

What's Changed fix(opentofu): strip v prefix in cooldown version comparison by @diofeher in #15044 Use POM last-modified as Gradle plugin release date fallback by @thavaahariharangit in #15006 Add blocked versions support to updater job by @kbukum1 in #14915 Add blocked versions support to dry-run script by @kbukum1 in #14916 Strip surrounding quotes from go.env values before writing by @yeikel in…

D
Dependabot Security v0.377.0

v0.377.0

What's Changed Implement sbt metadata finder by @AbhishekBhaskar in #15011 Bump NuGet.Client to release/7.6.x and pin dotnet-core to v10.0.8 by @JamieMagee in #14995 feat(opentofu): resolve locals references in module version constraints by @diofeher in #15009 simplify line indent detection by @brettfo in #14980 Fix flaky test: use unique git.store path to avoid parallel race condition by @brettfo…

D
Dependabot Security v0.376.0

v0.376.0

What's Changed Julia: filter yanked versions from get_available_versions by @IanButterworth in #14939 Add blob_oid metadata to manifests in dependency snapshots by @juxtin in #14857 Fix Maven released? check for non-jar packaging types (e.g., aar) by @kbukum1 in #14886 (Python): Move Pip file filtering to grapher by @Copilot in #14856 detect central package version scheme by @brettfo in #14927 all…

D
Dependabot Security v0.375.0

v0.375.0

What's Changed Implement SBT UpdateChecker to fetch available versions by @AbhishekBhaskar in #14918 Handle Artifactory directory listings for Gradle release dates by @thavaahariharangit in #14938 feat: Add Deno support to Dependabot Omnibus Gem Spec by @kbukum1 in #14941 v0.375.0 by @dependabot-core-action-automation[bot] in #14942 Full Changelog: v0.374.0...v0.375.0