grafana / grafana/pyroscope-nodejs

Dependency Dashboard

Open
#139 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
51
Forks
36
PR merge metrics
No merged PRs in 30d

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.

## Repository Problems

Renovate tried to run on this repository, but found these problems.

- ⚠️ WARN: Package lookup failures

## Deprecations / Replacements
> [!WARNING]
The following dependencies are either deprecated or have replacements available.

| Datasource | Package | Replacement PR? |
|------------|------|--------------|
| npm | [@types/source-map](https://redirect.github.com/mozilla/source-map) | ![Unavailable](https://img.shields.io/badge/unavailable-orange?style=flat-square) |

## Abandoned Dependencies

The following dependencies have not received updates for an extended period and may be unmaintained.

View abandoned dependencies (2)

> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
| Datasource | Package | Last Updated |
|------------|------|-------------|
| npm | [pinst](https://redirect.github.com/typicode/pinst) | `2022-02-21` |
| npm | [regenerator-runtime](https://redirect.github.com/facebook/regenerator) | `2023-12-15` |

---

> [!WARNING]
> Renovate failed to look up the following dependencies: `Could not determine new digest for update (github-tags package grafana/shared-workflows)`.
>
> Files affected: `.github/workflows/renovate.yml`

---

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [fix(security/high/): update dependency fast-uri to v3.1.6 [security]](../pull/324)
- [ ] [fix(security/medium/): update dependency fastify to v5.12.1 [security]](../pull/325)
- [ ] [chore(deps): lock file maintenance](../pull/322)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## Vulnerabilities

> [!IMPORTANT]
> `8`/`8` CVEs have Renovate fixes.

npm

package.json

fastify

- [GHSA-3m5p-2c4r-xxw2](https://osv.dev/vulnerability/GHSA-3m5p-2c4r-xxw2) (fixed in >= 5.12.1)
- [GHSA-w2qp-rph6-63g4](https://osv.dev/vulnerability/GHSA-w2qp-rph6-63g4) (fixed in >= 5.12.1)
- [GHSA-3m5p-2c4r-xxw2](https://osv.dev/vulnerability/GHSA-3m5p-2c4r-xxw2) (fixed in >= 5.12.1)
- [GHSA-w2qp-rph6-63g4](https://osv.dev/vulnerability/GHSA-w2qp-rph6-63g4) (fixed in >= 5.12.1)

fast-uri

- [GHSA-5jgf-p345-68v8](https://osv.dev/vulnerability/GHSA-5jgf-p345-68v8) (fixed in >= 3.1.6)
- [GHSA-f65p-4m7j-42xc](https://osv.dev/vulnerability/GHSA-f65p-4m7j-42xc) (fixed in >= 3.1.6)
- [GHSA-fph4-wmhf-6fwf](https://osv.dev/vulnerability/GHSA-fph4-wmhf-6fwf) (fixed in >= 3.1.6)
- [GHSA-jqff-g426-hqxp](https://osv.dev/vulnerability/GHSA-jqff-g426-hqxp) (fixed in >= 3.1.6)

## Detected Dependencies

github-actions (3)

.github/workflows/release-please.yml (8)

- `grafana/shared-workflows create-github-app-token/v0.3.1@46f48da11e78ebdba7a8747ae456b11062fac83e` → [Updates: `create-github-app-token/v1.0`]
- `googleapis/release-please-action v5@45996ed1f6d02564a971a2fa1b5860e934307cf7`
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `node 26.4.0`
- `node 26.4.0`

.github/workflows/renovate.yml (1)

- `grafana/shared-workflows validate-renovate-config/v0.3.1@46f48da11e78ebdba7a8747ae456b11062fac83e`

.github/workflows/test.yml (6)

- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `node 26.x`
- `node ${{ matrix.node }}`

mise (1)

mise.toml (2)

- `node 26.4.0` → [Updates: `26.8.2`]
- `npm:corepack 0.35.0` → [Updates: `0.36.0`]

npm (1)

package.json (31)

- `@datadog/pprof 5.14.4` → [Updates: `5.18.1`]
- `debug ^4.4.3`
- `p-limit ^7.3.0` → [Updates: `^7.3.0`]
- `pprof-format ^2.2.1`
- `regenerator-runtime ^0.14.1`
- `source-map ^0.7.6` → [Updates: `^0.8.0`]
- `@types/debug ^4.1.12` → [Updates: `4.1.13`]
- `@types/node ^24` → [Updates: `24.13.3`, `^24.13.3`]
- `@types/source-map ^0.5.7` → [Updates: `0.5.7`]
- `@typescript-eslint/eslint-plugin ^8.60.1` → [Updates: `8.66.0`, `^8.66.0`]
- `@typescript-eslint/parser ^8.60.1` → [Updates: `8.66.0`, `^8.66.0`]
- `eslint ^10.4.1` → [Updates: `10.8.1`, `^10.10.0`]
- `eslint-config-prettier ^10.1.8` → [Updates: `10.1.8`]
- `eslint-plugin-prettier ^5.5.5` → [Updates: `5.5.6`]
- `express ^5.2.1` → [Updates: `5.2.1`]
- `fastify ^5.8.5` → [Updates: `^5.8.5`]
- `husky ^9.1.7` → [Updates: `9.1.7`]
- `pinst ^3.0.0` → [Updates: `3.0.0`]
- `prettier ^3.8.1` → [Updates: `3.9.6`, `^3.9.6`]
- `typescript ^5.9.3` → [Updates: `5.9.3`, `^7.0.0`]
- `express ^4.0.0 || ^5.0.0`
- `fastify ^5.8.5` → [Updates: `^5.8.5`]
- `node >=20.20.2`
- `brace-expansion ^5.0.6` → [Updates: `^5.0.6`]
- `body-parser 2.3.0`
- `fast-uri 3.1.5` → [Updates: `3.1.6`]
- `find-my-way 9.7.0` → [Updates: `9.9.0`]
- `flatted ^3.4.2`
- `path-to-regexp 8.4.0` → [Updates: `8.4.2`]
- `picomatch ^4.0.4` → [Updates: `^4.0.4`]
- `yarn 4.15.0+sha512.07ec708ac11e2eaa4ea2b04cfbb272812f7e74a753f1595eaef4486c663a98306a30cca3e6fc40f7a0b168dcfb3a2490b6a5e0501e20fb69cc36f563dd161c53` → [Updates: `4.18.0`]

renovate-config (1)

renovate.json

---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.