Skip to content

chore(deps): update semantic-release to v20#38

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-20-semantic-release
Open

chore(deps): update semantic-release to v20#38
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-20-semantic-release

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2023

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
semantic-release ^19.0.2^20.1.3 age confidence

Release Notes

semantic-release/semantic-release (semantic-release)

v20.1.3

Compare Source

Bug Fixes
  • deps: update dependency execa to v7.1.1 (c38b53a)

v20.1.2

Compare Source

Bug Fixes
  • deps: update dependency cosmiconfig to v8.1.2 (fbede54)

v20.1.1

Compare Source

Bug Fixes

v20.1.0

Compare Source

Features

v20.0.4

Compare Source

Bug Fixes
  • windows: fixed issues preventing execution from windows (#​2672) (5df624c)

v20.0.3

Compare Source

Reverts

v20.0.2

Compare Source

Bug Fixes

v20.0.1

Compare Source

Bug Fixes
  • deps: update dependency cosmiconfig to v8 (f914c1e)
  • deps: update dependency hosted-git-info to v6 (c4da008)

v20.0.0

Compare Source

BREAKING CHANGES
  • esm: semantic-release is now ESM-only. since it is used through its own executable, the impact on consuming projects should be minimal
  • esm: references to plugin files in configs need to include the file extension because of executing in an ESM context
  • node-versions: node v18 is now the minimum required version of node. this is in line with our node support policy. please see our recommendations for releasing with a different node version than your project normally uses, if necessary.
Features
Bug Fixes
  • env-ci: updated to the stable esm-only version (#​2632) (918eb59)
  • secrets-masking: used the proper named import from hook-std to enable masking for stderr (#​2619) (cf6befa)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 3am on the first day of the month"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here

@socket-security

socket-security Bot commented Oct 1, 2023

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedsemantic-release@​19.0.5 ⏵ 20.1.397 +110010097100

View full report

@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from e1b70a3 to 7630090 Compare August 10, 2025 14:34
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from 7630090 to d5bb605 Compare October 21, 2025 10:51
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from d5bb605 to 4bb1453 Compare November 19, 2025 00:43
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from 4bb1453 to f2f4a83 Compare December 31, 2025 16:34
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from f2f4a83 to dd5ff77 Compare January 23, 2026 18:33
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch 2 times, most recently from 19378a4 to 3fdca91 Compare April 8, 2026 17:56
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from 3fdca91 to 95819c0 Compare April 29, 2026 14:43
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from 95819c0 to 1d56bfd Compare May 12, 2026 12:29
@renovate renovate Bot changed the title chore(deps): update dependency semantic-release to v20 chore(deps): update semantic-release to v20 Jun 2, 2026
@renovate renovate Bot force-pushed the renovate/major-20-semantic-release branch from 1d56bfd to 4d132a6 Compare June 11, 2026 19:35
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm js-yaml is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/semantic-release@20.1.3npm/js-yaml@4.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/js-yaml@4.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants