fix(deps): update dependency ssri to v13 (#870)

This PR contains the following updates:

| Package | Change | Age | Confidence |
|---|---|---|---|
| [ssri](https://redirect.github.com/npm/ssri) | [`^8.0.1` ->
`^13.0.0`](https://renovatebot.com/diffs/npm/ssri/8.0.1/13.0.0) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/ssri/13.0.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/ssri/8.0.1/13.0.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>npm/ssri (ssri)</summary>

###
[`v13.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1300-2025-10-22)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v12.0.0...v13.0.0)

##### ⚠️ BREAKING CHANGES

- `ssri` now supports node `^20.17.0 || >=22.9.0`

##### Bug Fixes

-
[`46a2520`](46a2520214)
[#&#8203;155](https://redirect.github.com/npm/ssri/pull/155) align to
npm 11 node engine range
([#&#8203;155](https://redirect.github.com/npm/ssri/issues/155))
([@&#8203;owlstronaut](https://redirect.github.com/owlstronaut))
-
[`8f0bbf2`](8f0bbf2717)
[#&#8203;151](https://redirect.github.com/npm/ssri/pull/151) improve
`SRI_REGEX`
([#&#8203;151](https://redirect.github.com/npm/ssri/issues/151))
([@&#8203;ericcornelissen](https://redirect.github.com/ericcornelissen))

##### Chores

-
[`79e0018`](79e0018941)
[#&#8203;146](https://redirect.github.com/npm/ssri/pull/146) postinstall
workflow updates
([#&#8203;146](https://redirect.github.com/npm/ssri/issues/146))
([@&#8203;owlstronaut](https://redirect.github.com/owlstronaut))
-
[`89b775a`](89b775a9cf)
[#&#8203;154](https://redirect.github.com/npm/ssri/pull/154) bump
[@&#8203;npmcli/template-oss](https://redirect.github.com/npmcli/template-oss)
from 4.26.0 to 4.27.1
([#&#8203;154](https://redirect.github.com/npm/ssri/issues/154))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot],
[@&#8203;npm-cli-bot](https://redirect.github.com/npm-cli-bot))

###
[`v12.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1200-2024-09-24)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v11.0.0...v12.0.0)

##### ⚠️ BREAKING CHANGES

- `ssri` now supports node `^18.17.0 || >=20.5.0`

##### Bug Fixes

-
[`b7a3f9a`](b7a3f9ad35)
[#&#8203;141](https://redirect.github.com/npm/ssri/pull/141) align to
npm 10 node engine range
([@&#8203;hashtagchris](https://redirect.github.com/hashtagchris))

##### Chores

-
[`f8121e9`](f8121e9e5e)
[#&#8203;141](https://redirect.github.com/npm/ssri/pull/141) run
template-oss-apply
([@&#8203;hashtagchris](https://redirect.github.com/hashtagchris))

###
[`v11.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1100-2024-09-03)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.6...v11.0.0)

##### ⚠️ BREAKING CHANGES

- `ssri` is now compatible with the following semver range for node:
`^16.14.0 || >=18.0.0`

##### Bug Fixes

-
[`29a6e2c`](29a6e2c2e0)
Address breaking engine change in dependency
([@&#8203;hashtagchris](https://redirect.github.com/hashtagchris))

##### Chores

-
[`db4219f`](db4219f28a)
bump
[@&#8203;npmcli/eslint-config](https://redirect.github.com/npmcli/eslint-config)
from 4.0.5 to 5.0.0
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`f2dd012`](f2dd0125e4)
template-oss-apply
([@&#8203;hashtagchris](https://redirect.github.com/hashtagchris))
-
[`f2a2a9d`](f2a2a9d09f)
postinstall for dependabot template-oss PR
([@&#8203;hashtagchris](https://redirect.github.com/hashtagchris))
-
[`4508f71`](4508f71d8a)
bump
[@&#8203;npmcli/template-oss](https://redirect.github.com/npmcli/template-oss)
from 4.22.0 to 4.23.3
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])

###
[`v10.0.6`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1006-2024-05-04)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.5...v10.0.6)

##### Bug Fixes

-
[`f3773e2`](f3773e21f9)
[#&#8203;127](https://redirect.github.com/npm/ssri/pull/127) linting:
no-unused-vars
([@&#8203;lukekarrys](https://redirect.github.com/lukekarrys))

##### Chores

-
[`55e7dfb`](55e7dfbe3f)
[#&#8203;127](https://redirect.github.com/npm/ssri/pull/127) bump
[@&#8203;npmcli/template-oss](https://redirect.github.com/npmcli/template-oss)
to 4.22.0 ([@&#8203;lukekarrys](https://redirect.github.com/lukekarrys))
-
[`96d1795`](96d1795b93)
[#&#8203;127](https://redirect.github.com/npm/ssri/pull/127) postinstall
for dependabot template-oss PR
([@&#8203;lukekarrys](https://redirect.github.com/lukekarrys))
-
[`10d5e8a`](10d5e8ae49)
[#&#8203;125](https://redirect.github.com/npm/ssri/pull/125) bump
[@&#8203;npmcli/template-oss](https://redirect.github.com/npmcli/template-oss)
from 4.21.3 to 4.21.4
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])

###
[`v10.0.5`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1005-2023-08-14)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.4...v10.0.5)

##### Dependencies

-
[`00dacfd`](00dacfd5e9)
[#&#8203;94](https://redirect.github.com/npm/ssri/pull/94) bump minipass
from 5.0.0 to 7.0.3

###
[`v10.0.4`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1004-2023-04-26)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.3...v10.0.4)

##### Dependencies

-
[`152e2bc`](152e2bce43)
[#&#8203;78](https://redirect.github.com/npm/ssri/pull/78) bump minipass
from 4.2.7 to 5.0.0
([#&#8203;78](https://redirect.github.com/npm/ssri/issues/78))

###
[`v10.0.3`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1003-2023-04-11)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.2...v10.0.3)

##### Bug Fixes

-
[`7fef846`](7fef8463d4)
[#&#8203;79](https://redirect.github.com/npm/ssri/pull/79) optimize
adding this.algorithm to algorithms list
([@&#8203;wraithgar](https://redirect.github.com/wraithgar))
-
[`d90f674`](d90f674cd5)
[#&#8203;79](https://redirect.github.com/npm/ssri/pull/79) prevent
DEFAULT\_ALGORITHM mutation
([@&#8203;wraithgar](https://redirect.github.com/wraithgar))
-
[`4e94d15`](4e94d15dd9)
[#&#8203;79](https://redirect.github.com/npm/ssri/pull/79)
Integrity#match prioritizes overlapping hashes
([@&#8203;wraithgar](https://redirect.github.com/wraithgar))
-
[`dce3dab`](dce3dab846)
[#&#8203;79](https://redirect.github.com/npm/ssri/pull/79) faster stream
verification ([@&#8203;H4ad](https://redirect.github.com/H4ad))

###
[`v10.0.2`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1002-2023-04-03)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.1...v10.0.2)

##### Bug Fixes

-
[`8e80eca`](8e80eca497)
[#&#8203;74](https://redirect.github.com/npm/ssri/pull/74) move from
symbols to private methods
([#&#8203;74](https://redirect.github.com/npm/ssri/issues/74))
([@&#8203;wraithgar](https://redirect.github.com/wraithgar))
-
[`a316b12`](a316b12e0c)
[#&#8203;75](https://redirect.github.com/npm/ssri/pull/75) faster
toString for integrity
([#&#8203;75](https://redirect.github.com/npm/ssri/issues/75))
([@&#8203;H4ad](https://redirect.github.com/H4ad))
-
[`6e6877d`](6e6877d55c)
[#&#8203;72](https://redirect.github.com/npm/ssri/pull/72) remove spread
of defaultOpts
([#&#8203;72](https://redirect.github.com/npm/ssri/issues/72))
([@&#8203;H4ad](https://redirect.github.com/H4ad))

###
[`v10.0.1`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1001-2022-12-07)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v10.0.0...v10.0.1)

##### Dependencies

-
[`4f6ba1e`](4f6ba1e5cc)
[#&#8203;64](https://redirect.github.com/npm/ssri/pull/64) bump minipass
from 3.3.6 to 4.0.0

###
[`v10.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1000-2022-10-10)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v9.0.1...v10.0.0)

##### ⚠️ BREAKING CHANGES

- `ssri` is now compatible with the following semver range for node:
`^14.17.0 || ^16.13.0 || >=18.0.0`

##### Features

-
[`3de0c45`](3de0c4502d)
[#&#8203;52](https://redirect.github.com/npm/ssri/pull/52) postinstall
for dependabot template-oss PR
([@&#8203;lukekarrys](https://redirect.github.com/lukekarrys))

##### Bug Fixes

-
[`2e876d1`](2e876d12a6)
[#&#8203;48](https://redirect.github.com/npm/ssri/pull/48) properly
handle missing algorithm type
([#&#8203;48](https://redirect.github.com/npm/ssri/issues/48))
([@&#8203;ahmedwelhakim](https://redirect.github.com/ahmedwelhakim))

#####
[9.0.1](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1)
(2022-05-19)

##### Bug Fixes

- store emitted events and re-emit them for late listeners
([#&#8203;39](https://redirect.github.com/npm/ssri/issues/39))
([c5421f1](c5421f1fb4))

###
[`v9.0.1`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1000-2022-10-10)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1)

##### ⚠️ BREAKING CHANGES

- `ssri` is now compatible with the following semver range for node:
`^14.17.0 || ^16.13.0 || >=18.0.0`

##### Features

-
[`3de0c45`](3de0c4502d)
[#&#8203;52](https://redirect.github.com/npm/ssri/pull/52) postinstall
for dependabot template-oss PR
([@&#8203;lukekarrys](https://redirect.github.com/lukekarrys))

##### Bug Fixes

-
[`2e876d1`](2e876d12a6)
[#&#8203;48](https://redirect.github.com/npm/ssri/pull/48) properly
handle missing algorithm type
([#&#8203;48](https://redirect.github.com/npm/ssri/issues/48))
([@&#8203;ahmedwelhakim](https://redirect.github.com/ahmedwelhakim))

#####
[9.0.1](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1)
(2022-05-19)

##### Bug Fixes

- store emitted events and re-emit them for late listeners
([#&#8203;39](https://redirect.github.com/npm/ssri/issues/39))
([c5421f1](c5421f1fb4))

###
[`v9.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1000-2022-10-10)

[Compare
Source](https://redirect.github.com/npm/ssri/compare/v8.0.1...v9.0.0)

##### ⚠️ BREAKING CHANGES

- `ssri` is now compatible with the following semver range for node:
`^14.17.0 || ^16.13.0 || >=18.0.0`

##### Features

-
[`3de0c45`](3de0c4502d)
[#&#8203;52](https://redirect.github.com/npm/ssri/pull/52) postinstall
for dependabot template-oss PR
([@&#8203;lukekarrys](https://redirect.github.com/lukekarrys))

##### Bug Fixes

-
[`2e876d1`](2e876d12a6)
[#&#8203;48](https://redirect.github.com/npm/ssri/pull/48) properly
handle missing algorithm type
([#&#8203;48](https://redirect.github.com/npm/ssri/issues/48))
([@&#8203;ahmedwelhakim](https://redirect.github.com/ahmedwelhakim))

#####
[9.0.1](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1)
(2022-05-19)

##### Bug Fixes

- store emitted events and re-emit them for late listeners
([#&#8203;39](https://redirect.github.com/npm/ssri/issues/39))
([c5421f1](c5421f1fb4))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/cnpm/cnpmcore).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNTkuNCIsInVwZGF0ZWRJblZlciI6IjQxLjE1OS40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This commit is contained in:
renovate[bot]
2025-10-29 23:36:35 +08:00
committed by GitHub
parent 0d32146562
commit 0f11e7730a

View File

@@ -119,7 +119,7 @@
"pg": "^8.13.1",
"read-env-value": "^2.0.0",
"semver": "^7.3.5",
"ssri": "^8.0.1",
"ssri": "^13.0.0",
"type-fest": "^5.0.0",
"ua-parser-js": "^1.0.34",
"validate-npm-package-name": "^7.0.0"