Skip to content

chore(deps): bump svgo from 4.0.1 to 4.0.2 in /docs - #194

Merged
Roger-luo merged 1 commit into
mainfrom
dependabot/npm_and_yarn/docs/svgo-4.0.2
Jul 30, 2026
Merged

chore(deps): bump svgo from 4.0.1 to 4.0.2 in /docs#194
Roger-luo merged 1 commit into
mainfrom
dependabot/npm_and_yarn/docs/svgo-4.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps svgo from 4.0.1 to 4.0.2.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-07-30 20:10 UTC

@Roger-luo
Roger-luo enabled auto-merge (squash) July 30, 2026 19:52
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/docs/svgo-4.0.2 branch from 0e43cfd to 17c7619 Compare July 30, 2026 19:54
@Roger-luo

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Bumps [svgo](https://github.com/svg/svgo) from 4.0.1 to 4.0.2.
- [Commits](https://github.com/svg/svgo/commits)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 4.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/docs/svgo-4.0.2 branch from 17c7619 to 8869ba8 Compare July 30, 2026 20:03
@Roger-luo
Roger-luo merged commit ff6bbb5 into main Jul 30, 2026
13 checks passed
@Roger-luo
Roger-luo deleted the dependabot/npm_and_yarn/docs/svgo-4.0.2 branch July 30, 2026 20:10
Roger-luo added a commit that referenced this pull request Jul 30, 2026
…arp 0.35.3) (#203)

Bumps the two direct `docs/` dependencies to their latest releases and
regenerates the lockfile, pulling transitive deps forward.

| Package | From | To |
|---------|------|-----|
| astro | 7.1.1 | **7.1.6** |
| marked | 18.0.3 | **18.0.7** |
| sharp (transitive) | 0.34.5 | **0.35.3** |

### Why sharp matters
sharp 0.34.5 carries a **high-severity** libvips advisory —
[GHSA-f88m-g3jw-g9cj](GHSA-f88m-g3jw-g9cj)
(CVE-2026-33327 / 33328 / 35590 / 35591). Bumping astro alone did not
pull sharp forward, so `npm audit fix` was used to force 0.35.3. `npm
audit` now reports **0 vulnerabilities**.

### Supersedes
Consolidates the Dependabot updates that were auto-closed as "updatable
in another way" after the lockfile shifted:
- #197 (sharp + astro)
- #192 (esbuild + astro) — the esbuild 0.28.1 security fix already
landed transitively via #202.

The postcss (#201), astro→7.1.1 (#202), svgo (#194), and vite bumps
already merged / resolved on main.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant