grafana / grafana/pyroscope-nodejs
Dependency Dashboard
- Dominant language
- TypeScript
- Stars
- 51
- Forks
- 36
- PR merge metrics
- No merged PRs in 30d
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
## Repository Problems
Renovate tried to run on this repository, but found these problems.
- ⚠️ WARN: Package lookup failures
## Deprecations / Replacements
> [!WARNING]
The following dependencies are either deprecated or have replacements available.
| Datasource | Package | Replacement PR? |
|------------|------|--------------|
| npm | [@types/source-map](https://redirect.github.com/mozilla/source-map) |  |
## Abandoned Dependencies
The following dependencies have not received updates for an extended period and may be unmaintained.
View abandoned dependencies (2)
> [!NOTE]
Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.
>
| Datasource | Package | Last Updated |
|------------|------|-------------|
| npm | [pinst](https://redirect.github.com/typicode/pinst) | `2022-02-21` |
| npm | [regenerator-runtime](https://redirect.github.com/facebook/regenerator) | `2023-12-15` |
---
> [!WARNING]
> Renovate failed to look up the following dependencies: `Could not determine new digest for update (github-tags package grafana/shared-workflows)`.
>
> Files affected: `.github/workflows/renovate.yml`
---
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [fix(security/high/): update dependency fast-uri to v3.1.6 [security]](../pull/324)
- [ ] [fix(security/medium/): update dependency fastify to v5.12.1 [security]](../pull/325)
- [ ] [chore(deps): lock file maintenance](../pull/322)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## Vulnerabilities
> [!IMPORTANT]
> `8`/`8` CVEs have Renovate fixes.
npm
package.json
fastify
- [GHSA-3m5p-2c4r-xxw2](https://osv.dev/vulnerability/GHSA-3m5p-2c4r-xxw2) (fixed in >= 5.12.1)
- [GHSA-w2qp-rph6-63g4](https://osv.dev/vulnerability/GHSA-w2qp-rph6-63g4) (fixed in >= 5.12.1)
- [GHSA-3m5p-2c4r-xxw2](https://osv.dev/vulnerability/GHSA-3m5p-2c4r-xxw2) (fixed in >= 5.12.1)
- [GHSA-w2qp-rph6-63g4](https://osv.dev/vulnerability/GHSA-w2qp-rph6-63g4) (fixed in >= 5.12.1)fast-uri
- [GHSA-5jgf-p345-68v8](https://osv.dev/vulnerability/GHSA-5jgf-p345-68v8) (fixed in >= 3.1.6)
- [GHSA-f65p-4m7j-42xc](https://osv.dev/vulnerability/GHSA-f65p-4m7j-42xc) (fixed in >= 3.1.6)
- [GHSA-fph4-wmhf-6fwf](https://osv.dev/vulnerability/GHSA-fph4-wmhf-6fwf) (fixed in >= 3.1.6)
- [GHSA-jqff-g426-hqxp](https://osv.dev/vulnerability/GHSA-jqff-g426-hqxp) (fixed in >= 3.1.6)
## Detected Dependencies
github-actions (3)
.github/workflows/release-please.yml (8)
- `grafana/shared-workflows create-github-app-token/v0.3.1@46f48da11e78ebdba7a8747ae456b11062fac83e` → [Updates: `create-github-app-token/v1.0`]
- `googleapis/release-please-action v5@45996ed1f6d02564a971a2fa1b5860e934307cf7`
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `node 26.4.0`
- `node 26.4.0`.github/workflows/renovate.yml (1)
- `grafana/shared-workflows validate-renovate-config/v0.3.1@46f48da11e78ebdba7a8747ae456b11062fac83e`
.github/workflows/test.yml (6)
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0` → [Updates: `v7.0.1`]
- `actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e` → [Updates: `v6.5.0`, `v7.0.0`]
- `node 26.x`
- `node ${{ matrix.node }}`
mise (1)
mise.toml (2)
- `node 26.4.0` → [Updates: `26.8.2`]
- `npm:corepack 0.35.0` → [Updates: `0.36.0`]
npm (1)
package.json (31)
- `@datadog/pprof 5.14.4` → [Updates: `5.18.1`]
- `debug ^4.4.3`
- `p-limit ^7.3.0` → [Updates: `^7.3.0`]
- `pprof-format ^2.2.1`
- `regenerator-runtime ^0.14.1`
- `source-map ^0.7.6` → [Updates: `^0.8.0`]
- `@types/debug ^4.1.12` → [Updates: `4.1.13`]
- `@types/node ^24` → [Updates: `24.13.3`, `^24.13.3`]
- `@types/source-map ^0.5.7` → [Updates: `0.5.7`]
- `@typescript-eslint/eslint-plugin ^8.60.1` → [Updates: `8.66.0`, `^8.66.0`]
- `@typescript-eslint/parser ^8.60.1` → [Updates: `8.66.0`, `^8.66.0`]
- `eslint ^10.4.1` → [Updates: `10.8.1`, `^10.10.0`]
- `eslint-config-prettier ^10.1.8` → [Updates: `10.1.8`]
- `eslint-plugin-prettier ^5.5.5` → [Updates: `5.5.6`]
- `express ^5.2.1` → [Updates: `5.2.1`]
- `fastify ^5.8.5` → [Updates: `^5.8.5`]
- `husky ^9.1.7` → [Updates: `9.1.7`]
- `pinst ^3.0.0` → [Updates: `3.0.0`]
- `prettier ^3.8.1` → [Updates: `3.9.6`, `^3.9.6`]
- `typescript ^5.9.3` → [Updates: `5.9.3`, `^7.0.0`]
- `express ^4.0.0 || ^5.0.0`
- `fastify ^5.8.5` → [Updates: `^5.8.5`]
- `node >=20.20.2`
- `brace-expansion ^5.0.6` → [Updates: `^5.0.6`]
- `body-parser 2.3.0`
- `fast-uri 3.1.5` → [Updates: `3.1.6`]
- `find-my-way 9.7.0` → [Updates: `9.9.0`]
- `flatted ^3.4.2`
- `path-to-regexp 8.4.0` → [Updates: `8.4.2`]
- `picomatch ^4.0.4` → [Updates: `^4.0.4`]
- `yarn 4.15.0+sha512.07ec708ac11e2eaa4ea2b04cfbb272812f7e74a753f1595eaef4486c663a98306a30cca3e6fc40f7a0b168dcfb3a2490b6a5e0501e20fb69cc36f563dd161c53` → [Updates: `4.18.0`]
renovate-config (1)
renovate.json
---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.