Skip to content

Upgrade: Bump flatted from 3.3.1 to 3.4.2#736

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/flatted-3.4.2
Closed

Upgrade: Bump flatted from 3.3.1 to 3.4.2#736
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/flatted-3.4.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 19, 2026

Bumps flatted from 3.3.1 to 3.4.2.

Commits
  • 3bf0909 3.4.2
  • 885ddcc fix CWE-1321
  • 0bdba70 added flatted-view to the benchmark
  • 2a02dce 3.4.1
  • fba4e8f Merge pull request #89 from WebReflection/python-fix
  • 5fe8648 added "when in Rome" also a test for PHP
  • 53517ad some minor improvement
  • b3e2a0c Fixing recursion issue in Python too
  • c4b46db Add SECURITY.md for security policy and reporting
  • f86d071 Create dependabot.yml for version updates
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 19, 2026
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.1 to 3.4.2.
- [Commits](WebReflection/flatted@v3.3.1...v3.4.2)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/flatted-3.4.2 branch from 1470fbb to ca040ea Compare April 14, 2026 19:06
brafdlog added a commit that referenced this pull request Apr 17, 2026
- qs 6.14.1 → 6.14.2 (#730)
- rollup 4.41.1 → 4.59.0 (#733)
- flatted 3.3.1 → 3.4.2 (#736)
- picomatch 2.3.1 → 2.3.2 (#737)
- handlebars 4.7.8 → 4.7.9 (#739)
- node-forge 1.3.3 → 1.4.0 (#740)
- @xmldom/xmldom 0.8.10 → 0.8.12 (#742)
- lodash-es 4.17.23 → 4.18.1 (#743)
- electron 39.2.7 → 39.8.5 (#746)
- basic-ftp 5.0.5 → 5.3.0 (#752)

All within existing semver ranges — lockfile only.
brafdlog added a commit that referenced this pull request Apr 17, 2026
Consolidates 10 Dependabot PRs into a single lockfile update. All bumps
are within existing semver ranges — no package.json changes needed.

- qs 6.14.1 → 6.14.2 (#730)
- rollup 4.41.1 → 4.59.0 (#733)
- flatted 3.3.1 → 3.4.2 (#736)
- picomatch 2.3.1 → 2.3.2 (#737)
- handlebars 4.7.8 → 4.7.9 (#739)
- node-forge 1.3.3 → 1.4.0 (#740)
- @xmldom/xmldom 0.8.10 → 0.8.12 (#742)
- lodash-es 4.17.23 → 4.18.1 (#743)
- electron 39.2.7 → 39.8.5 (#746)
- basic-ftp 5.0.5 → 5.3.0 (#752)

Verified locally: `yarn install`, `yarn typecheck`, `yarn build`, `yarn
test:main`, `yarn test:renderer` all pass.

Svelte 5 (#734) and Vite 6 (#749) are major-version bumps with breaking
changes and are intentionally left for separate follow-up PRs. Once this
merges, Dependabot should auto-close #730, #733, #736, #737, #739, #740,
#742, #743, #746, #752.
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 17, 2026

Looks like flatted is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Apr 17, 2026
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/flatted-3.4.2 branch April 17, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants