Skip to content

Bump convict from 6.2.4 to 6.2.5#229

Merged
seladb merged 1 commit intomasterfrom
dependabot/npm_and_yarn/convict-6.2.5
Mar 27, 2026
Merged

Bump convict from 6.2.4 to 6.2.5#229
seladb merged 1 commit intomasterfrom
dependabot/npm_and_yarn/convict-6.2.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 26, 2026

Bumps convict from 6.2.4 to 6.2.5.

Changelog

Sourced from convict's changelog.

6.2.5 (2026-03-19)

Bug Fixes

  • Consistent use of quotes in output (#405) (de1629a)
  • prevent prototype pollution bypass via String.prototype.startsWith override (d9a5491)
  • prevent prototype pollution via load() and loadFile() (3d7d836)
  • prevent prototype pollution via schema initialization (d251c47)
Commits
Maintainer changes

This version was pushed to npm by clouserw, a new releaser for convict since your current version.


@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 26, 2026
@argos-ci
Copy link
Copy Markdown

argos-ci bot commented Mar 26, 2026

The latest updates on your projects. Learn more about Argos notifications ↗︎

Build Status Details Updated (UTC)
default (Inspect) 👍 Changes approved 1 changed Mar 27, 2026, 2:35 AM

@seladb
Copy link
Copy Markdown
Member

seladb commented Mar 27, 2026

@dependabot recreate

Bumps [convict](https://github.com/mozilla/node-convict) from 6.2.4 to 6.2.5.
- [Changelog](https://github.com/mozilla/node-convict/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mozilla/node-convict/commits)

---
updated-dependencies:
- dependency-name: convict
  dependency-version: 6.2.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/convict-6.2.5 branch from fafb221 to c0563bd Compare March 27, 2026 02:31
@seladb seladb merged commit 1704b43 into master Mar 27, 2026
4 checks passed
@seladb seladb deleted the dependabot/npm_and_yarn/convict-6.2.5 branch March 27, 2026 02:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant