Skip to content

build(deps-dev): bump picomatch from 2.3.1 to 2.3.2#999

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/picomatch-2.3.2
Open

build(deps-dev): bump picomatch from 2.3.1 to 2.3.2#999
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/picomatch-2.3.2

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 26, 2026

Bumps picomatch from 2.3.1 to 2.3.2.

Release notes

Sourced from picomatch's releases.

2.3.2

This is a security release fixing several security relevant issues.

What's Changed

Full Changelog: micromatch/picomatch@2.3.1...2.3.2

Changelog

Sourced from picomatch's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

4.0.0 (2024-02-07)

Fixes

Changed

3.0.1

Fixes

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [picomatch](https://github.com/micromatch/picomatch) from 2.3.1 to 2.3.2.
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/picomatch@2.3.1...2.3.2)

---
updated-dependencies:
- dependency-name: picomatch
  dependency-version: 2.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 26, 2026
@vercel
Copy link

vercel bot commented Mar 26, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
pro-react-admin Ready Ready Preview, Comment Mar 26, 2026 0:51am
pro-react-admin-projecta Ready Ready Preview, Comment Mar 26, 2026 0:51am
pro-react-admin-projectb Ready Ready Preview, Comment Mar 26, 2026 0:51am
pro-react-admin-shell Ready Ready Preview, Comment Mar 26, 2026 0:51am

@what-the-diff
Copy link

what-the-diff bot commented Mar 26, 2026

PR摘要

  • 更改了"babel-plugin-react-compiler"的版本规范
    我们已经将"babel-plugin-react-compiler"的版本规范从“最新”更改为“任意”。这项更改将使我们能够更加灵活地对其版本进行管理。
  • 更改了"eslint-plugin-react-hooks"的版本规范
    我们还将"eslint-plugin-react-hooks"的版本规范从“最新”更改为“任意”。同样,这也是为了提高我们对其版本管理的灵活性。
  • 更新了包"@noble/hashes"的"dev"属性
    包"@noble/hashes"的"dev"属性已被更新为"devOptional"。这意味着在开发过程中,该包变为可选,这有助于节省存储空间以及改善应用程序的效率。
  • 添加了多个与"@tailwindcss/oxide-wasm32-wasi"相关的新包
    我们添加了好几个与"@tailwindcss/oxide-wasm32-wasi"相关的新包作为依赖项,包括"@emnapi/core","@emnapi/runtime"等等,并设置为可选。这将有助于我们在编译时拥有更多的选择,来提升代码的运行效率。
  • 更新了”picomatch“包的版本
    我们在多个位置将"picomatch"包的版本从"2.3.1"更新为"2.3.2",并且将其从"4.0.3"更新为"4.0.4"。这次更新将会解决一些已经存在的问题,并提高应用程序的稳定性。

@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants