Skip to content

chore(deps): bump serialize-javascript from 6.0.0 to 6.0.2#7276

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/serialize-javascript-6.0.2
Open

chore(deps): bump serialize-javascript from 6.0.0 to 6.0.2#7276
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/serialize-javascript-6.0.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 1, 2026

Bumps serialize-javascript from 6.0.0 to 6.0.2.

Release notes

Sourced from serialize-javascript's releases.

v6.0.2

  • fix: serialize URL string contents to prevent XSS (#173) f27d65d
  • Bump @​babel/traverse from 7.10.1 to 7.23.7 (#171) 02499c0
  • docs: update readme with URL support (#146) 0d88527
  • chore: update node version and lock file e2a3a91
  • fix typo (#164) 5a1fa64

yahoo/serialize-javascript@v6.0.1...v6.0.2

v6.0.1

What's Changed

New Contributors

Full Changelog: yahoo/serialize-javascript@v6.0.0...v6.0.1

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added dependencies javascript Pull requests that update javascript code labels Mar 1, 2026
@greptile-apps
Copy link
Copy Markdown
Contributor

greptile-apps bot commented Mar 1, 2026

PR author is in the excluded authors list.

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

https://github.com/open-condo-software/condo/blob/f71229fadd57fb54449072c7a4ba053dd67926c6/yarn.lock#L1354-L1356
P1 Badge Restore removed workspace lock entries

This change drops the @app/pos-integration workspace block (and many other @app/* workspaces) from the monorepo lockfile while those apps are still part of the repository, so the committed yarn.lock becomes a partial/focused install snapshot rather than a full-repo lock. In CI or any full-repo setup that runs immutable installs, Yarn will need to regenerate these missing workspace entries and fail immutability checks, breaking installs for non-condo workspaces.

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from f71229f to c0b778b Compare March 2, 2026 11:36
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from c0b778b to 0e08756 Compare March 2, 2026 13:17
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 0e08756 to 8839703 Compare March 4, 2026 08:17
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 8839703 to a6218fb Compare March 4, 2026 23:48
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from a6218fb to ae6dcb8 Compare March 13, 2026 06:16
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from ae6dcb8 to d18adf8 Compare March 16, 2026 13:22
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from d18adf8 to 03cf1c8 Compare March 17, 2026 20:13
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 03cf1c8 to c848aa9 Compare March 20, 2026 15:57
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from c848aa9 to 9794eec Compare March 20, 2026 17:52
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 9794eec to 9fdf46b Compare March 23, 2026 18:54
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 9fdf46b to 7e1369c Compare March 29, 2026 08:02
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 7e1369c to de71c88 Compare March 29, 2026 18:09
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from de71c88 to 7bb1508 Compare March 30, 2026 06:12
Bumps [serialize-javascript](https://github.com/yahoo/serialize-javascript) from 6.0.0 to 6.0.2.
- [Release notes](https://github.com/yahoo/serialize-javascript/releases)
- [Commits](yahoo/serialize-javascript@v6.0.0...v6.0.2)

---
updated-dependencies:
- dependency-name: serialize-javascript
  dependency-version: 6.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/serialize-javascript-6.0.2 branch from 7bb1508 to 9abd674 Compare March 30, 2026 07:01
@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants