Skip to content

chore(deps): update dependency conf to v15 - #29

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/conf-15.x
Open

chore(deps): update dependency conf to v15#29
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/conf-15.x

Conversation

@renovate

@renovate renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
conf ^13.1.0^15.0.0 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

sindresorhus/conf (conf)

v15.1.0

Compare Source

  • Add encryptionAlgorithm option ee03ae8

v15.0.2

Compare Source


v15.0.1

Compare Source


v15.0.0

Compare Source

There are no known breaking changes, but it's a major release since it contains a large refactor, and that introduces risk.

  • Add .appendToArray() method a1dbf86
  • Fix constructor validation preventing migrations from fixing invalid schema data a1b43e6
  • Fix clear() method to emit single change event 9b83a9d
  • Fix store setter to preserve internal migration data ceefe13

v14.0.0

Compare Source

Breaking
Improvements
  • Add TypeScript type definitions for dot notation property access (#​200) 83cb242


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@greptile-apps

greptile-apps Bot commented Aug 21, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@macroscopeapp

macroscopeapp Bot commented Aug 21, 2026

Copy link
Copy Markdown

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR updates conf from v13 to v15 (a major version bump that skips v14), which may introduce breaking changes. The modified file is owned by wave-av/core-team, and the designated owners should verify compatibility.

Not approved because:

  • Credit balance exhausted. Approvability relies on correctness review in order to determine eligibility

No code changes detected at d9952a7. Prior analysis still applies.

Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more.

@socket-security

socket-security Bot commented Aug 21, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​conf@​15.1.09910010083100

View full report

@socket-security

socket-security Bot commented Aug 21, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Low
Publisher changed: npm json-schema-typed is now published by remyrylan instead of jrylan

New Author: remyrylan

Previous Author: jrylan

From: package.jsonnpm/conf@15.1.0npm/json-schema-typed@8.0.2

ℹ Read more on: This package | This alert | What is new author?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Scrutinize new collaborator additions to packages because they now have the ability to publish code into your dependency tree. Packages should avoid frequent or unnecessary additions or changes to publishing rights.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/json-schema-typed@8.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/conf-15.x branch from b6e6f4e to d9952a7 Compare August 26, 2026 22:24
@codeant-ai

codeant-ai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Your free trial PR review limit of 300 PRs has been reached. Please upgrade your plan to continue using CodeAnt AI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants