Skip to content

chore(deps): update dependency lefthook to v2#249

Open
renovate[bot] wants to merge 1 commit intotrunkfrom
renovate/lefthook-2.x
Open

chore(deps): update dependency lefthook to v2#249
renovate[bot] wants to merge 1 commit intotrunkfrom
renovate/lefthook-2.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Nov 3, 2025

This PR contains the following updates:

Package Change Age Confidence
lefthook 1.12.22.1.4 age confidence

Release Notes

evilmartians/lefthook (lefthook)

v2.1.4

Compare Source

v2.1.3

Compare Source

v2.1.2

Compare Source

v2.1.1

Compare Source

v2.1.0

Compare Source

v2.0.16

Compare Source

v2.0.15

Compare Source

v2.0.14

Compare Source

v2.0.13

Compare Source

v2.0.12

Compare Source

v2.0.11

Compare Source

v2.0.10

Compare Source

v2.0.9

Compare Source

v2.0.8

Compare Source

v2.0.7

Compare Source

v2.0.6

Compare Source

v2.0.5

Compare Source

v2.0.4

Compare Source

v2.0.3

Compare Source

v2.0.2

Compare Source

v2.0.1

Compare Source

v2.0.0

Compare Source

Breaking changes

  • exclude option no longer accepts regexp, only globs.
  • skip_output option is dropped, use output instead.
  • Some CLI arguments have changed their names to make it more consistent. See lefthook run -h for details.
  • for only and skip options with - run: '...' values the command executer was changed to Bourne Shell.

Commits

v1.13.6

Compare Source

v1.13.5

Compare Source

v1.13.4

Compare Source

v1.13.3

Compare Source

v1.13.2

Compare Source

v1.13.1

Compare Source

v1.13.0

Compare Source

v1.12.4

Compare Source

v1.12.3

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

@renovate renovate bot added the dependencies label Nov 3, 2025
@socket-security
Copy link
Copy Markdown

socket-security bot commented Nov 3, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedutility-types@​3.11.010010010080100
Addedtweakpane@​4.0.5991009980100
Addedtsx@​4.20.31001008185100
Addedtypescript@​5.9.31001009010090
Updatedlefthook@​1.12.2 ⏵ 2.1.492 +110010095 +1100

View full report

@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 3 times, most recently from af504a6 to 8fbb112 Compare November 10, 2025 13:17
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 3 times, most recently from 61a905e to 5d28e76 Compare November 20, 2025 09:48
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 5 times, most recently from acf3af5 to b41c078 Compare December 15, 2025 11:05
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 3 times, most recently from c2cb706 to 8192030 Compare December 22, 2025 09:40
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 2 times, most recently from 21932ab to eb0a5d7 Compare January 2, 2026 08:43
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 3 times, most recently from 37181c1 to 46030ec Compare January 20, 2026 14:12
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 2 times, most recently from c90cb33 to 8821e71 Compare February 3, 2026 10:55
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 4 times, most recently from a7c88eb to 5a5216a Compare February 11, 2026 02:26
@renovate renovate bot removed the dependencies label Feb 11, 2026
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 2 times, most recently from ebda6d4 to ec15d03 Compare February 20, 2026 21:43
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch from ec15d03 to a619fcd Compare February 21, 2026 00:44
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 4 times, most recently from 3d7012f to d8206f3 Compare March 11, 2026 09:23
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 3 times, most recently from 11247e0 to d5670c6 Compare March 19, 2026 08:53
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch 3 times, most recently from a492d5e to b497e8c Compare March 27, 2026 13:46
@renovate renovate bot force-pushed the renovate/lefthook-2.x branch from b497e8c to d926d11 Compare March 27, 2026 18:02
@socket-security
Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block High
High CVE: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

CVE: GHSA-f269-vfmq-vjvj Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client (HIGH)

Affected versions: >= 6.0.0 < 6.24.0; >= 7.0.0 < 7.24.0

Patched version: 7.24.0

From: pnpm-lock.yamlnpm/pointe@5.15.1npm/undici@7.16.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/undici@7.16.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block High
High CVE: Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation

CVE: GHSA-v9p9-hfj2-hcw8 Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation (HIGH)

Affected versions: < 6.24.0; >= 7.0.0 < 7.24.0

Patched version: 7.24.0

From: pnpm-lock.yamlnpm/pointe@5.15.1npm/undici@7.16.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/undici@7.16.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block High
High CVE: Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

CVE: GHSA-vrm6-8vpv-qv8q Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression (HIGH)

Affected versions: < 6.24.0; >= 7.0.0 < 7.24.0

Patched version: 7.24.0

From: pnpm-lock.yamlnpm/pointe@5.15.1npm/undici@7.16.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/undici@7.16.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants