Skip to content

Bump ip-address from 9.0.5 to 10.3.1#5000

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/ip-address-10.3.1
Open

Bump ip-address from 9.0.5 to 10.3.1#5000
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/ip-address-10.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps ip-address from 9.0.5 to 10.3.1.

Release notes

Sourced from ip-address's releases.

v10.3.1

Full Changelog: beaugunderson/ip-address@v10.3.0...v10.3.1

v10.3.0

Full Changelog: beaugunderson/ip-address@v10.2.2...v10.3.0

v10.2.2

Full Changelog: beaugunderson/ip-address@v10.2.1...v10.2.2

v10.2.1

Full Changelog: beaugunderson/ip-address@v10.2.0...v10.2.1

Commits
  • be7e626 10.3.1
  • 56368cb Reject octal-ambiguous IPv4 octets and stacked subnet suffixes (GHSA-mwp4-54f...
  • 9ed7949 10.3.0
  • fd0687e fix: pad Address6#toByteArray to a full 16 bytes
  • c697eaa fix: Address6.fromURL squelches port 65536 as valid
  • d46eb43 Fix repository URL protocol
  • 4da4295 Bump vulnerable transitive dev dependencies
  • f7314db 10.2.2
  • 488fe9b Merge commit from fork
  • e86ab3e 10.2.1
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for ip-address since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 9.0.5 to 10.3.1.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v9.0.5...v10.3.1)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 27, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot merge

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The pull request currently contains no file changes, leaving the intended dependency upgrade unimplemented. As this transition involves a major version bump, there is a risk of breaking changes. The update to the configuration files must be included, and compatibility with existing parsing logic should be verified before this can be merged.

About this PR

  • The pull request does not contain any file changes. The expected configuration updates are missing.
  • This transition represents a major version upgrade. Verification is required to ensure that existing logic remains compatible with the new version behavior.

Test suggestions

  • Verify the dependency version update in the configuration file\n- [ ] Regression test existing logic to ensure compatibility with the major version upgrade
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the dependency version update in the configuration file\n- [ ] Regression test existing logic to ensure compatibility with the major version upgrade

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants