Skip to content

build(deps): bump uuid from 7.0.3 to 14.0.0#808

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/uuid-14.0.0
Open

build(deps): bump uuid from 7.0.3 to 14.0.0#808
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/uuid-14.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Bumps uuid from 7.0.3 to 14.0.0.

Release notes

Sourced from uuid's releases.

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

v12.0.1

12.0.1 (2026-04-29)

Bug Fixes

v12.0.0

12.0.0 (2025-09-05)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

11.1.0 (2025-02-19)

... (truncated)

Commits
  • 7c1ea08 chore(main): release 14.0.0 (#926)
  • 3d2c5b0 Merge commit from fork
  • f2c235f fix!: expect crypto to be global everywhere (requires node@20+) (#935)
  • 529ef08 chore: upgrade TypeScript and fixup types (#927)
  • 086fd79 chore: update dependencies (#933)
  • dc4ddb8 feat!: drop node@18 support (#934)
  • 0f1f9c9 chore: switch to Biome for parsing and linting (#932)
  • e2879e6 chore: use maintained version of npm-run-all (#930)
  • ffa3138 fix: Use GITHUB_TOKEN for release-please and enable npm provenance (#925)
  • 0423d49 docs: remove obsolete v1 option notes (#915)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 23, 2026
@greptile-apps
Copy link
Copy Markdown
Contributor

greptile-apps Bot commented Apr 23, 2026

Greptile Summary

This PR bumps uuid from 7.0.3 to 14.0.0, spanning 7 major versions. The update addresses a security advisory (GHSA-w5hq-g745-h8pq) for missing buffer bounds checks in v3()/v5()/v6() when a caller-supplied buffer is provided. No source files import uuid directly, so no application code changes are required.

Confidence Score: 5/5

Safe to merge — uuid is not directly imported in any source file and the breaking changes (ESM-only, browser-first exports, node@20+) do not affect this browser-targeted Vue app.

No P0 or P1 findings. The dependency is not directly used in source code, the package.json already declares type=module (compatible with ESM-only uuid v12+), and the build targets browsers which are unaffected by the node@20+ requirement. The security fix is a welcome improvement.

No files require special attention.

Important Files Changed

Filename Overview
package.json Bumps uuid version constraint from ^7.0.3 to ^14.0.0; no other changes
package-lock.json Lockfile updated to resolve uuid 14.0.0 with new integrity hash and updated bin path (dist-node/bin/uuid)

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A["uuid v7.0.3\n(old)"] -->|"bump"| B["uuid v14.0.0\n(new)"]
    B --> C["Breaking Changes"]
    C --> D["v12: CommonJS removed\n(ESM only)"]
    C --> E["v13: Browser exports\nare now default"]
    C --> F["v14: node@20+ required\n(global crypto)"]
    B --> G["Security Fix\nGHSA-w5hq-g745-h8pq"]
    G --> H["v3/v5/v6 buffer\nbounds check added"]
    D --> I{"Impact on\naw-webui?"}
    E --> I
    F --> I
    I -->|"package.json has type=module\nbuild targets browser\nno direct uuid imports"| J["✅ No code\nchanges needed"]
Loading

Reviews (2): Last reviewed commit: "build(deps): bump uuid from 7.0.3 to 14...." | Re-trigger Greptile

Bumps [uuid](https://github.com/uuidjs/uuid) from 7.0.3 to 14.0.0.
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v7.0.3...v14.0.0)

---
updated-dependencies:
- dependency-name: uuid
  dependency-version: 14.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/uuid-14.0.0 branch from 6499317 to fc939ef Compare May 4, 2026 09:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants