Skip to content

chore(deps): bump uuid from 13.0.0 to 14.0.0 in /src/microsoft-trydotnet#241

Merged
intellitect-bot merged 1 commit intomainfrom
dependabot/npm_and_yarn/src/microsoft-trydotnet/uuid-14.0.0
Apr 23, 2026
Merged

chore(deps): bump uuid from 13.0.0 to 14.0.0 in /src/microsoft-trydotnet#241
intellitect-bot merged 1 commit intomainfrom
dependabot/npm_and_yarn/src/microsoft-trydotnet/uuid-14.0.0

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Apr 22, 2026

Bumps uuid from 13.0.0 to 14.0.0.

Release notes

Sourced from uuid's releases.

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)
Changelog

Sourced from uuid's changelog.

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years
Commits
  • 7c1ea08 chore(main): release 14.0.0 (#926)
  • 3d2c5b0 Merge commit from fork
  • f2c235f fix!: expect crypto to be global everywhere (requires node@20+) (#935)
  • 529ef08 chore: upgrade TypeScript and fixup types (#927)
  • 086fd79 chore: update dependencies (#933)
  • dc4ddb8 feat!: drop node@18 support (#934)
  • 0f1f9c9 chore: switch to Biome for parsing and linting (#932)
  • e2879e6 chore: use maintained version of npm-run-all (#930)
  • ffa3138 fix: Use GITHUB_TOKEN for release-please and enable npm provenance (#925)
  • 0423d49 docs: remove obsolete v1 option notes (#915)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file npm labels Apr 22, 2026
@dependabot dependabot Bot temporarily deployed to BuildAndUploadImage April 22, 2026 15:36 Inactive
Bumps [uuid](https://github.com/uuidjs/uuid) from 13.0.0 to 14.0.0.
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v13.0.0...v14.0.0)

---
updated-dependencies:
- dependency-name: uuid
  dependency-version: 14.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/src/microsoft-trydotnet/uuid-14.0.0 branch from cfafc1d to ead84aa Compare April 22, 2026 15:56
@dependabot dependabot Bot temporarily deployed to BuildAndUploadImage April 22, 2026 15:56 Inactive
@github-actions github-actions Bot added the ai-approved-major-update AI-reviewed major dependency update safe to merge label Apr 23, 2026
@github-actions
Copy link
Copy Markdown

🤖 Automated Major Version Review — APPROVED

Package: uuid
Ecosystem: npm
Version change: 13.0.0 → 14.0.0 (major bump)

Research Summary

Breaking Changes Analysis

uuid v14.0.0 introduces the following breaking changes:

  1. Requires Node.js ≥ 20 (drops Node 18): The CI/CD pipeline uses node-version: '20' (confirmed in .github/actions/setup-node/action.yml). This breaking change does not affect this repository.
  2. crypto must be globally defined (requires node@20+): Satisfied since CI runs on Node 20, where crypto is globally available.
  3. Minimum TypeScript version bumped to 5.4.3: uuid is not directly imported in any TypeScript or JavaScript source file in this repository, so this constraint is not relevant.

uuid is listed as a runtime dependency in src/microsoft-trydotnet/package.json but is not directly imported in any TypeScript or JavaScript source files. The breaking changes are therefore moot for this project's code.

Security Check

uuid v14.0.0 fixes security advisory GHSA-w5hq-g745-h8pq: versions prior to v14 allowed out-of-bounds writes in v3(), v5(), and v6() when an invalid offset parameter was provided. Upgrading to v14 resolves this vulnerability. No known security advisories affect uuid v14.0.0.

Decision

✅ This major version update is safe to merge. CI checks pass, the diff contains only version file changes (package.json and package-lock.json), the Node 20 environment requirement is satisfied, and the security fix makes this upgrade desirable.

Note

🔒 Integrity filter blocked 1 item

The following item were blocked because they don't meet the GitHub integrity level.

  • #145 list_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

To allow these resources, lower min-integrity in your GitHub frontmatter:

tools:
  github:
    min-integrity: approved  # merged | approved | unapproved | none

Generated by Dependabot Major Version Reviewer · ● 2.6M ·

@intellitect-bot intellitect-bot merged commit 2eb3700 into main Apr 23, 2026
9 checks passed
@intellitect-bot intellitect-bot deleted the dependabot/npm_and_yarn/src/microsoft-trydotnet/uuid-14.0.0 branch April 23, 2026 02:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-approved-major-update AI-reviewed major dependency update safe to merge dependencies Pull requests that update a dependency file npm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant