Skip to content

chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /frontend - #2419

Merged
JSv4 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/source-map-js-1.2.2
Oct 9, 2026
Merged

JSv4 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/source-map-js-1.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps source-map-js from 1.2.1 to 1.2.2.

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 9, 2026
@claude

claude Bot commented Oct 9, 2026

Copy link
Copy Markdown

Review: lockfile-only Dependabot bump of source-map-js 1.2.1 → 1.2.2 (frontend/yarn.lock, one entry).

  • Scope: Only the resolution and integrity hash change. package.json is untouched, and the existing ^1.2.1 range already covers 1.2.2. It is a transitive dependency (PostCSS/Vite tooling), so it doesn't ship in runtime code.
  • Security: Per the release notes, 1.2.2 fixes a DoS from malicious indexed source maps and a CSP unsafe-eval crash. Both are worth having.
  • Risk: Low. It is a patch release. I didn't check the new integrity hash against the registry.
  • Tests and changelog: No new tests are needed. A changelog.d/ fragment isn't needed for a transitive lockfile bump, though a .security.md one would be reasonable if you want the CVE fix recorded.

I didn't run the build myself. Approve once CI (frontend build and tests) is green.

@JSv4
JSv4 merged commit b38c6ac into main Oct 9, 2026
13 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/source-map-js-1.2.2 branch October 9, 2026 13:57
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant