fix(deps): update dependency ssri to v13 (#870)
This PR contains the following updates: | Package | Change | Age | Confidence | |---|---|---|---| | [ssri](https://redirect.github.com/npm/ssri) | [`^8.0.1` -> `^13.0.0`](https://renovatebot.com/diffs/npm/ssri/8.0.1/13.0.0) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | --- ### Release Notes <details> <summary>npm/ssri (ssri)</summary> ### [`v13.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1300-2025-10-22) [Compare Source](https://redirect.github.com/npm/ssri/compare/v12.0.0...v13.0.0) ##### ⚠️ BREAKING CHANGES - `ssri` now supports node `^20.17.0 || >=22.9.0` ##### Bug Fixes - [`46a2520`](46a2520214) [#​155](https://redirect.github.com/npm/ssri/pull/155) align to npm 11 node engine range ([#​155](https://redirect.github.com/npm/ssri/issues/155)) ([@​owlstronaut](https://redirect.github.com/owlstronaut)) - [`8f0bbf2`](8f0bbf2717) [#​151](https://redirect.github.com/npm/ssri/pull/151) improve `SRI_REGEX` ([#​151](https://redirect.github.com/npm/ssri/issues/151)) ([@​ericcornelissen](https://redirect.github.com/ericcornelissen)) ##### Chores - [`79e0018`](79e0018941) [#​146](https://redirect.github.com/npm/ssri/pull/146) postinstall workflow updates ([#​146](https://redirect.github.com/npm/ssri/issues/146)) ([@​owlstronaut](https://redirect.github.com/owlstronaut)) - [`89b775a`](89b775a9cf) [#​154](https://redirect.github.com/npm/ssri/pull/154) bump [@​npmcli/template-oss](https://redirect.github.com/npmcli/template-oss) from 4.26.0 to 4.27.1 ([#​154](https://redirect.github.com/npm/ssri/issues/154)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot], [@​npm-cli-bot](https://redirect.github.com/npm-cli-bot)) ### [`v12.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1200-2024-09-24) [Compare Source](https://redirect.github.com/npm/ssri/compare/v11.0.0...v12.0.0) ##### ⚠️ BREAKING CHANGES - `ssri` now supports node `^18.17.0 || >=20.5.0` ##### Bug Fixes - [`b7a3f9a`](b7a3f9ad35) [#​141](https://redirect.github.com/npm/ssri/pull/141) align to npm 10 node engine range ([@​hashtagchris](https://redirect.github.com/hashtagchris)) ##### Chores - [`f8121e9`](f8121e9e5e) [#​141](https://redirect.github.com/npm/ssri/pull/141) run template-oss-apply ([@​hashtagchris](https://redirect.github.com/hashtagchris)) ### [`v11.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1100-2024-09-03) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.6...v11.0.0) ##### ⚠️ BREAKING CHANGES - `ssri` is now compatible with the following semver range for node: `^16.14.0 || >=18.0.0` ##### Bug Fixes - [`29a6e2c`](29a6e2c2e0) Address breaking engine change in dependency ([@​hashtagchris](https://redirect.github.com/hashtagchris)) ##### Chores - [`db4219f`](db4219f28a) bump [@​npmcli/eslint-config](https://redirect.github.com/npmcli/eslint-config) from 4.0.5 to 5.0.0 ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`f2dd012`](f2dd0125e4) template-oss-apply ([@​hashtagchris](https://redirect.github.com/hashtagchris)) - [`f2a2a9d`](f2a2a9d09f) postinstall for dependabot template-oss PR ([@​hashtagchris](https://redirect.github.com/hashtagchris)) - [`4508f71`](4508f71d8a) bump [@​npmcli/template-oss](https://redirect.github.com/npmcli/template-oss) from 4.22.0 to 4.23.3 ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) ### [`v10.0.6`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1006-2024-05-04) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.5...v10.0.6) ##### Bug Fixes - [`f3773e2`](f3773e21f9) [#​127](https://redirect.github.com/npm/ssri/pull/127) linting: no-unused-vars ([@​lukekarrys](https://redirect.github.com/lukekarrys)) ##### Chores - [`55e7dfb`](55e7dfbe3f) [#​127](https://redirect.github.com/npm/ssri/pull/127) bump [@​npmcli/template-oss](https://redirect.github.com/npmcli/template-oss) to 4.22.0 ([@​lukekarrys](https://redirect.github.com/lukekarrys)) - [`96d1795`](96d1795b93) [#​127](https://redirect.github.com/npm/ssri/pull/127) postinstall for dependabot template-oss PR ([@​lukekarrys](https://redirect.github.com/lukekarrys)) - [`10d5e8a`](10d5e8ae49) [#​125](https://redirect.github.com/npm/ssri/pull/125) bump [@​npmcli/template-oss](https://redirect.github.com/npmcli/template-oss) from 4.21.3 to 4.21.4 ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) ### [`v10.0.5`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1005-2023-08-14) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.4...v10.0.5) ##### Dependencies - [`00dacfd`](00dacfd5e9) [#​94](https://redirect.github.com/npm/ssri/pull/94) bump minipass from 5.0.0 to 7.0.3 ### [`v10.0.4`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1004-2023-04-26) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.3...v10.0.4) ##### Dependencies - [`152e2bc`](152e2bce43) [#​78](https://redirect.github.com/npm/ssri/pull/78) bump minipass from 4.2.7 to 5.0.0 ([#​78](https://redirect.github.com/npm/ssri/issues/78)) ### [`v10.0.3`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1003-2023-04-11) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.2...v10.0.3) ##### Bug Fixes - [`7fef846`](7fef8463d4) [#​79](https://redirect.github.com/npm/ssri/pull/79) optimize adding this.algorithm to algorithms list ([@​wraithgar](https://redirect.github.com/wraithgar)) - [`d90f674`](d90f674cd5) [#​79](https://redirect.github.com/npm/ssri/pull/79) prevent DEFAULT\_ALGORITHM mutation ([@​wraithgar](https://redirect.github.com/wraithgar)) - [`4e94d15`](4e94d15dd9) [#​79](https://redirect.github.com/npm/ssri/pull/79) Integrity#match prioritizes overlapping hashes ([@​wraithgar](https://redirect.github.com/wraithgar)) - [`dce3dab`](dce3dab846) [#​79](https://redirect.github.com/npm/ssri/pull/79) faster stream verification ([@​H4ad](https://redirect.github.com/H4ad)) ### [`v10.0.2`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1002-2023-04-03) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.1...v10.0.2) ##### Bug Fixes - [`8e80eca`](8e80eca497) [#​74](https://redirect.github.com/npm/ssri/pull/74) move from symbols to private methods ([#​74](https://redirect.github.com/npm/ssri/issues/74)) ([@​wraithgar](https://redirect.github.com/wraithgar)) - [`a316b12`](a316b12e0c) [#​75](https://redirect.github.com/npm/ssri/pull/75) faster toString for integrity ([#​75](https://redirect.github.com/npm/ssri/issues/75)) ([@​H4ad](https://redirect.github.com/H4ad)) - [`6e6877d`](6e6877d55c) [#​72](https://redirect.github.com/npm/ssri/pull/72) remove spread of defaultOpts ([#​72](https://redirect.github.com/npm/ssri/issues/72)) ([@​H4ad](https://redirect.github.com/H4ad)) ### [`v10.0.1`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1001-2022-12-07) [Compare Source](https://redirect.github.com/npm/ssri/compare/v10.0.0...v10.0.1) ##### Dependencies - [`4f6ba1e`](4f6ba1e5cc) [#​64](https://redirect.github.com/npm/ssri/pull/64) bump minipass from 3.3.6 to 4.0.0 ### [`v10.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1000-2022-10-10) [Compare Source](https://redirect.github.com/npm/ssri/compare/v9.0.1...v10.0.0) ##### ⚠️ BREAKING CHANGES - `ssri` is now compatible with the following semver range for node: `^14.17.0 || ^16.13.0 || >=18.0.0` ##### Features - [`3de0c45`](3de0c4502d) [#​52](https://redirect.github.com/npm/ssri/pull/52) postinstall for dependabot template-oss PR ([@​lukekarrys](https://redirect.github.com/lukekarrys)) ##### Bug Fixes - [`2e876d1`](2e876d12a6) [#​48](https://redirect.github.com/npm/ssri/pull/48) properly handle missing algorithm type ([#​48](https://redirect.github.com/npm/ssri/issues/48)) ([@​ahmedwelhakim](https://redirect.github.com/ahmedwelhakim)) ##### [9.0.1](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1) (2022-05-19) ##### Bug Fixes - store emitted events and re-emit them for late listeners ([#​39](https://redirect.github.com/npm/ssri/issues/39)) ([c5421f1](c5421f1fb4)) ### [`v9.0.1`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1000-2022-10-10) [Compare Source](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1) ##### ⚠️ BREAKING CHANGES - `ssri` is now compatible with the following semver range for node: `^14.17.0 || ^16.13.0 || >=18.0.0` ##### Features - [`3de0c45`](3de0c4502d) [#​52](https://redirect.github.com/npm/ssri/pull/52) postinstall for dependabot template-oss PR ([@​lukekarrys](https://redirect.github.com/lukekarrys)) ##### Bug Fixes - [`2e876d1`](2e876d12a6) [#​48](https://redirect.github.com/npm/ssri/pull/48) properly handle missing algorithm type ([#​48](https://redirect.github.com/npm/ssri/issues/48)) ([@​ahmedwelhakim](https://redirect.github.com/ahmedwelhakim)) ##### [9.0.1](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1) (2022-05-19) ##### Bug Fixes - store emitted events and re-emit them for late listeners ([#​39](https://redirect.github.com/npm/ssri/issues/39)) ([c5421f1](c5421f1fb4)) ### [`v9.0.0`](https://redirect.github.com/npm/ssri/blob/HEAD/CHANGELOG.md#1000-2022-10-10) [Compare Source](https://redirect.github.com/npm/ssri/compare/v8.0.1...v9.0.0) ##### ⚠️ BREAKING CHANGES - `ssri` is now compatible with the following semver range for node: `^14.17.0 || ^16.13.0 || >=18.0.0` ##### Features - [`3de0c45`](3de0c4502d) [#​52](https://redirect.github.com/npm/ssri/pull/52) postinstall for dependabot template-oss PR ([@​lukekarrys](https://redirect.github.com/lukekarrys)) ##### Bug Fixes - [`2e876d1`](2e876d12a6) [#​48](https://redirect.github.com/npm/ssri/pull/48) properly handle missing algorithm type ([#​48](https://redirect.github.com/npm/ssri/issues/48)) ([@​ahmedwelhakim](https://redirect.github.com/ahmedwelhakim)) ##### [9.0.1](https://redirect.github.com/npm/ssri/compare/v9.0.0...v9.0.1) (2022-05-19) ##### Bug Fixes - store emitted events and re-emit them for late listeners ([#​39](https://redirect.github.com/npm/ssri/issues/39)) ([c5421f1](c5421f1fb4)) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/cnpm/cnpmcore). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNTkuNCIsInVwZGF0ZWRJblZlciI6IjQxLjE1OS40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This commit is contained in:
@@ -119,7 +119,7 @@
|
||||
"pg": "^8.13.1",
|
||||
"read-env-value": "^2.0.0",
|
||||
"semver": "^7.3.5",
|
||||
"ssri": "^8.0.1",
|
||||
"ssri": "^13.0.0",
|
||||
"type-fest": "^5.0.0",
|
||||
"ua-parser-js": "^1.0.34",
|
||||
"validate-npm-package-name": "^7.0.0"
|
||||
|
||||
Reference in New Issue
Block a user