build(deps-dev): bump nx, @nx/jest and @nx/js - #1634
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
Bumps [nx](https://github.com/nrwl/nx/tree/HEAD/packages/nx), [@nx/jest](https://github.com/nrwl/nx/tree/HEAD/packages/jest) and [@nx/js](https://github.com/nrwl/nx/tree/HEAD/packages/js). These dependencies needed to be updated together. Updates `nx` from 22.4.5 to 22.7.8 - [Release notes](https://github.com/nrwl/nx/releases) - [Commits](https://github.com/nrwl/nx/commits/22.7.8/packages/nx) Updates `@nx/jest` from 22.4.5 to 22.7.8 - [Release notes](https://github.com/nrwl/nx/releases) - [Commits](https://github.com/nrwl/nx/commits/22.7.8/packages/jest) Updates `@nx/js` from 22.4.5 to 22.7.8 - [Release notes](https://github.com/nrwl/nx/releases) - [Commits](https://github.com/nrwl/nx/commits/22.7.8/packages/js) --- updated-dependencies: - dependency-name: nx dependency-version: 22.7.8 dependency-type: direct:development - dependency-name: "@nx/jest" dependency-version: 22.7.8 dependency-type: direct:development - dependency-name: "@nx/js" dependency-version: 22.7.8 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps nx, @nx/jest and @nx/js. These dependencies needed to be updated together.
Updates
nxfrom 22.4.5 to 22.7.8Release notes
Sourced from nx's releases.
... (truncated)
Commits
f7afd77fix(core): bump pinned axios and brace-expansion past vulnerable versions (#3...983413bfix(core): keep real dependencies when omitting peers from npm temp installs ...4159295fix(core): stop passing git revisions through a shell in affected commands (#...cf99649fix(core): prevent shell injection in nx import (#36348)74311e7fix(core): omit peer dependencies when installing packages to a temp dir (#36...84beebcfix(core): use workspace package manager when fetching migrations via install...a328bf1fix(core): warn when the self-hosted remote cache disables TLS verification (...a828076fix(core): prevent path traversal / zip-slip in self-hosted remote cache (#36...dc849bbfix(core): update brace-expansion and yaml (#35790)8fd1febfix(core): allow local plugin subpath imports without custom conditions (#35751)Install script changes
This version modifies
postinstallscript that runs during installation. Review the package contents before updating.Updates
@nx/jestfrom 22.4.5 to 22.7.8Release notes
Sourced from @nx/jest's releases.
... (truncated)
Commits
b58ccd8fix(core): preserve input order in createNodes plugin results (#35595)ccb1f87fix(misc): stop inferringprojects: 'self'independsOnentries (#35686)0f6f117fix(testing): correct yargs-parser import in getJestProjectsAsync (#35672)d84f424fix(devkit): expand@nx/devkit/internal re-exports for cherry-picked v23 deep...ac81879fix(repo): revert deep-import rewrites that targeted v23-only@nx/devkit/inte...7e4bce9feat(testing): add migration for Jest 30 snapshot guide link (#35629)f1d849efix(testing): exclude dist and out-tsc from default jest module path scan (#3...fa5c8b6fix(testing): pin jest to ~30.3.0 to avoid jest-runtime 30.4 RN incompat (#35...fac25a2fix(testing): convert executor-based jest.config.ts and preserve type-only im...4bbd4b1chore(repo): migrate nx repo to eslint v9 flat config (#35359)Updates
@nx/jsfrom 22.4.5 to 22.7.8Release notes
Sourced from @nx/js's releases.
... (truncated)
Commits
7dbe7aafix(js): resolve the verdaccio bin through its package.json (#36479)fd9f84crevert(js): drop the typescript <7.0.0 supported-version bounddc80496fix(js): exclude typescript 7 from supported versions on 22.7.xeba3fbafeat(js): support pnpm 11.2.2 (#35772)8ce0683fix(js): fall back to npm publish when bun publish fails with auth error (#35...d84f424fix(devkit): expand@nx/devkit/internal re-exports for cherry-picked v23 deep...ac81879fix(repo): revert deep-import rewrites that targeted v23-only@nx/devkit/inte...c7c56d8chore(core): bump detect-port from ^1.5.1 to ^2.1.0 (#35533)37fb080chore(linter): bump ignore from ^5.0.4 to ^7.0.5 (#35508)0eef651fix(js): reference vitest.config in eslint dep-checks for vitest libs (#35460)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.