[CSR-0] chore: Bump nanoid from 3.3.16 to 6.0.0 - #399
Conversation
Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.16 to 6.0.0. - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@3.3.16...6.0.0) --- updated-dependencies: - dependency-name: nanoid dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
AssigneesThe following users could not be added as assignees: Please fix the above issues or remove invalid values from |
|
Security triage — Tier B. Needs a decision, and there is a cheaper fix that closes the same alert. What and why
That is Dependabot alert 178, Vanta This PR does not actually close the alertThere are two
This PR edits only The vulnerable 3.3.16 stays in The narrow fix, verified
Resulting tree — one copy, patched, and the advisory is gone: Lockfile-only, no manifest change, no new major, same result for the compliance clock. Why the major is Tier B on its own termsIndependent of the above, 3.3.16 → 6.0.0 would need a decision rather than a merge:
Verification
Note the last row: this PR has no CI results at all, so there is no evidence either way about whether What a human should decide
See also #402, which proposes the same Generated by Claude Code |
|
@dependabot ignore this major version we need to stay on the 3.x line for now for commonJS |
|
OK, I won't notify you about version 6.x.x again, unless you re-open this PR. |
Bumps nanoid from 3.3.16 to 6.0.0.
Release notes
Sourced from nanoid's releases.
... (truncated)
Changelog
Sourced from nanoid's changelog.
... (truncated)
Commits
4dacb10Release 6.0.0 version09545eaSimplify CLI for modern Node.js0966ccbRemove obvious commentb5a0590Update docs0501d9cFix alphabet duplication87f2821Remove unnecessary import for modern Node.js6a73bf8Simplfy strings57a250cSimplify code1a97659Fix formatting1fda937Remove build filesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)