Skip to content

chore(deps): update pnpm/action-setup action to v6.0.8#1615

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pnpm-action-setup-6.x
Open

chore(deps): update pnpm/action-setup action to v6.0.8#1615
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pnpm-action-setup-6.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 2, 2026

This PR contains the following updates:

Package Type Update Change
pnpm/action-setup action patch v6.0.4v6.0.8

Release Notes

pnpm/action-setup (pnpm/action-setup)

v6.0.8

Compare Source

v6.0.7

Compare Source

v6.0.6

Compare Source

What's Changed
  • fix: bin_dest output points to self-updated pnpm, not bootstrap by @​zkochan in #​249

Full Changelog: pnpm/action-setup@v6.0.5...v6.0.6

v6.0.5

Compare Source

What's Changed
  • fix: append (not prepend) action node dir to PATH for npm bootstrap by @​zkochan in #​241

Full Changelog: pnpm/action-setup@v6.0.4...v6.0.5


Configuration

📅 Schedule: (in timezone Europe/Oslo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

@renovate renovate Bot added auto-merge Renovate auto-merges dependencies Updates one or more dependencies labels May 2, 2026
@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages Bot commented May 2, 2026

Deploying countr with  Cloudflare Pages  Cloudflare Pages

Latest commit: 7073906
Status: ✅  Deploy successful!
Preview URL: https://97dfc173.countr.pages.dev
Branch Preview URL: https://renovate-pnpm-action-setup-6.countr.pages.dev

View logs

@renovate renovate Bot enabled auto-merge (squash) May 2, 2026 21:45
@renovate renovate Bot force-pushed the renovate/pnpm-action-setup-6.x branch 10 times, most recently from 0ea9cce to 15a84b0 Compare May 8, 2026 09:48
@renovate renovate Bot changed the title chore(deps): update pnpm/action-setup action to v6.0.5 chore(deps): update pnpm/action-setup action to v6.0.6 May 9, 2026
@renovate renovate Bot force-pushed the renovate/pnpm-action-setup-6.x branch 4 times, most recently from 19172df to 20bfb98 Compare May 11, 2026 04:26
@renovate renovate Bot changed the title chore(deps): update pnpm/action-setup action to v6.0.6 chore(deps): update pnpm/action-setup action to v6.0.7 May 11, 2026
@renovate renovate Bot force-pushed the renovate/pnpm-action-setup-6.x branch from 20bfb98 to 37f16a9 Compare May 11, 2026 15:50
@renovate renovate Bot changed the title chore(deps): update pnpm/action-setup action to v6.0.7 chore(deps): update pnpm/action-setup action to v6.0.8 May 12, 2026
@renovate renovate Bot force-pushed the renovate/pnpm-action-setup-6.x branch 7 times, most recently from 2aa6957 to 3106214 Compare May 15, 2026 17:57
@renovate renovate Bot force-pushed the renovate/pnpm-action-setup-6.x branch 2 times, most recently from 7d20973 to c8eb124 Compare May 17, 2026 08:31
@renovate renovate Bot force-pushed the renovate/pnpm-action-setup-6.x branch from c8eb124 to 7073906 Compare May 18, 2026 09:54
@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
High CVE: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() in npm serialize-javascript

CVE: GHSA-5c6j-r48x-rmvq Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() (HIGH)

Affected versions: < 7.0.3

Patched version: 7.0.3

From: pnpm-lock.yamlnpm/serialize-javascript@6.0.2

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/serialize-javascript@6.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm svgo is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/svgo@3.3.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/svgo@3.3.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm node-exports-info

Location: Package overview

From: pnpm-lock.yamlnpm/node-exports-info@1.6.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/node-exports-info@1.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Deprecated by its maintainer: npm uuid

Reason: uuid@10 and below is no longer supported. For ESM codebases, update to uuid@latest. For CommonJS codebases, use uuid@11 (but be aware this version will likely be deprecated in 2028).

From: pnpm-lock.yamlnpm/uuid@8.3.2

ℹ Read more on: This package | This alert | What is a deprecated package?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/uuid@8.3.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-merge Renovate auto-merges dependencies Updates one or more dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant