Skip to content

chore(deps-dev): Bump flatted from 3.3.3 to 3.4.2 in /frontend#363

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/flatted-3.4.2
Closed

chore(deps-dev): Bump flatted from 3.3.3 to 3.4.2 in /frontend#363
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/flatted-3.4.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 21, 2026

Copy link
Copy Markdown
Contributor

Bumps flatted from 3.3.3 to 3.4.2.

Commits
  • 3bf0909 3.4.2
  • 885ddcc fix CWE-1321
  • 0bdba70 added flatted-view to the benchmark
  • 2a02dce 3.4.1
  • fba4e8f Merge pull request #89 from WebReflection/python-fix
  • 5fe8648 added "when in Rome" also a test for PHP
  • 53517ad some minor improvement
  • b3e2a0c Fixing recursion issue in Python too
  • c4b46db Add SECURITY.md for security policy and reporting
  • f86d071 Create dependabot.yml for version updates
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 21, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Update Analysis

Update Type: patch
Security Update: false
Risk Level: low
Auto-merge Eligible: true

Analysis Details

  • PR Title: chore(deps-dev): Bump flatted from 3.3.3 to 3.4.2 in /frontend
  • Updated by: dependabot[bot]
  • Branch: dependabot/npm_and_yarn/frontend/flatted-3.4.2

Security Audit Results

Frontend (npm audit)

INFO - Unable to parse npm audit results

Backend (safety check)

INFO - Unable to parse safety check results

@github-actions

Copy link
Copy Markdown
Contributor

Manual Review Required

This dependency update requires manual review:

Reason:

  • Update Type: patch
  • Risk Level: low
  • Auto-merge Eligible: true

Review Checklist:

  • Review changelog for breaking changes
  • Test critical application paths
  • Verify security implications
  • Check for API compatibility
  • Validate configuration changes

Next Steps:

  1. Review the changes thoroughly
  2. Test locally if needed
  3. Approve and merge when ready

cc: @maintainers

Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.2.
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/flatted-3.4.2 branch from 5339421 to 3ca1ff0 Compare April 14, 2026 01:35
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Update Analysis

Update Type: patch
Security Update: false
Risk Level: low
Auto-merge Eligible: true

Analysis Details

  • PR Title: chore(deps-dev): Bump flatted from 3.3.3 to 3.4.2 in /frontend
  • Updated by: dependabot[bot]
  • Branch: dependabot/npm_and_yarn/frontend/flatted-3.4.2

Security Audit Results

Frontend (npm audit)

INFO - Unable to parse npm audit results

Backend (safety check)

INFO - Unable to parse safety check results

@github-actions

Copy link
Copy Markdown
Contributor

Manual Review Required

This dependency update requires manual review:

Reason:

  • Update Type: patch
  • Risk Level: low
  • Auto-merge Eligible: true

Review Checklist:

  • Review changelog for breaking changes
  • Test critical application paths
  • Verify security implications
  • Check for API compatibility
  • Validate configuration changes

Next Steps:

  1. Review the changes thoroughly
  2. Test locally if needed
  3. Approve and merge when ready

cc: @maintainers

@remyluslosius

Copy link
Copy Markdown
Contributor

Closing as Dependabot queue cleanup: this individual PR predates the grouped Dependabot config and is months behind main. Dependabot will re-propose any still-outstanding update for this package at its current version in the next grouped run (see #489 production / #488 development). Closing avoids the stale-version + package-lock conflict cascade.

@dependabot @github

dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/frontend/flatted-3.4.2 branch June 11, 2026 03:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code manual-review-required risk-low update-patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant