Skip to content

chore(deps-dev): bump proxy-addr from 2.0.7 to 2.0.8 in /frontend - #2851

Merged
osmontero merged 2 commits into
v11from
dependabot/npm_and_yarn/frontend/proxy-addr-2.0.8
Oct 8, 2026
Merged

osmontero merged 2 commits into
v11from
dependabot/npm_and_yarn/frontend/proxy-addr-2.0.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps proxy-addr from 2.0.7 to 2.0.8.

Release notes

Sourced from proxy-addr's releases.

2.0.8

Important

What's Changed

New Contributors

Full Changelog: jshttp/proxy-addr@v2.0.7...v2.0.8

Changelog

Sourced from proxy-addr's changelog.

2.0.8

Commits
  • a11ad82 2.0.8 (#70)
  • 780911d fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix
  • 92e103e fix(ci): use publised as release trigger event (#71)
  • 3e5ac75 ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (#69)
  • 4b9db81 chore(ci): npm-publish via workflows (#54)
  • 655e895 build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#39)
  • 50ce4d0 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#45)
  • 0fd347f build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#63)
  • 6a517fa build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (#64)
  • 0d45e2a Fix "arugment" typo in README (#61)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for proxy-addr since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from a team October 7, 2026 14:50
Bumps [proxy-addr](https://github.com/jshttp/proxy-addr) from 2.0.7 to 2.0.8.
- [Release notes](https://github.com/jshttp/proxy-addr/releases)
- [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md)
- [Commits](jshttp/proxy-addr@v2.0.7...v2.0.8)

---
updated-dependencies:
- dependency-name: proxy-addr
  dependency-version: 2.0.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/proxy-addr-2.0.8 branch from e26c3c1 to 3eb8a98 Compare October 8, 2026 16:34
@osmontero
osmontero merged commit a75d815 into v11 Oct 8, 2026
5 checks passed
@osmontero
osmontero deleted the dependabot/npm_and_yarn/frontend/proxy-addr-2.0.8 branch October 8, 2026 16:37
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - google.golang.org/api: v0.299.0 → v0.301.0

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.7
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.7
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.1

  📁 ./plugins/alerts:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/events:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/modules-config:
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.7
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.7
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.1
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.2
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0
     - google.golang.org/api: v0.299.0 → v0.301.0

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.3
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2

  📁 ./plugins/crowdstrike:
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0

  📁 ./plugins/geolocation:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./agent:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

✅ AI review — Approved

No issues detected in this diff.

✅ architecture (silas-1.7-pro) — clean

Summary: No reviewable changes in this diff (excluded paths only).

No findings.

✅ bugs (silas-1.7-pro) — clean

Summary: No reviewable changes in this diff (excluded paths only).

No findings.

✅ security (silas-1.7-pro) — clean

Summary: No reviewable changes in this diff (excluded paths only).

No findings.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

⛔ Permission denied

Only members of @utmstack/administrators or @utmstack/core-developers can merge PRs into this repository.

PR author: @dependabot[bot]

The comments above (deps + AI review) are still valid — if you address them, the checks will re-run automatically, but final approval is left to an administrator.

@utmstack/administrators please review.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Author is not in @utmstack/administrators nor @utmstack/core-developers — admin review required.

osmontero added a commit that referenced this pull request Oct 8, 2026
…build

The six frontend dependabot bumps (#2848, #2849, #2850, #2851, #2852, #2853)
re-resolved package-lock.json from lockfileVersion 1 to 3, dragging in
incompatible transitive deps (@types/node 8→18, echarts 4.9→3.8.5, moment
2.29→2.31) that the Angular 7 / TS 3.2 / Node 14 stack cannot compile.

Reverts frontend/package.json + package-lock.json to the last known-good
state (800dede). The backend/Go dependabot bumps (snakeyaml 2.0, gRPC
1.83.2, OTel 1.45.0) are fine — they don't affect the frontend build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant