chore(deps): bump the production-dependencies group across 1 directory with 4 updates (#85)

* chore(deps): bump the production-dependencies group across 1 directory with 4 updates

Bumps the production-dependencies group with 4 updates in the / directory: [@napi-rs/canvas](https://github.com/Brooooooklyn/canvas), [axios](https://github.com/axios/axios), [koa-compress](https://github.com/koajs/compress) and [undici](https://github.com/nodejs/undici).


Updates `@napi-rs/canvas` from 1.0.0 to 1.0.2
- [Release notes](https://github.com/Brooooooklyn/canvas/releases)
- [Changelog](https://github.com/Brooooooklyn/canvas/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Brooooooklyn/canvas/compare/v1.0.0...v1.0.2)

Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](https://github.com/axios/axios/compare/v1.18.0...v1.18.1)

Updates `koa-compress` from 5.2.1 to 5.2.2
- [Release notes](https://github.com/koajs/compress/releases)
- [Changelog](https://github.com/koajs/compress/blob/master/HISTORY.md)
- [Commits](https://github.com/koajs/compress/compare/5.2.1...5.2.2)

Updates `undici` from 8.4.1 to 8.6.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v8.4.1...v8.6.0)

---
updated-dependencies:
- dependency-name: "@napi-rs/canvas"
  dependency-version: 1.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: axios
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: koa-compress
  dependency-version: 5.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: undici
  dependency-version: 8.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): resolve npm audit findings

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: xixu-me <i@xi-xu.me>
This commit is contained in:
dependabot[bot]andxixu-me authored and GitHub committed 2026-07-04 07:32:44 +00:00
1 parent 616a315645
commit f21b9f7dc2
3 files changed
+137 -89

No files matched your search

+25 -5
View File
@@ -3,11 +3,11 @@ name: Dependabot Auto Merge
on:
workflow_run:
workflows:
- "CI"
- "CodeQL"
- "Container Image"
- "Dependabot Updates"
- "Security Governance"
- CI
- CodeQL
- Container Image
- Dependabot Updates
- Security Governance
types:
- completed
workflow_dispatch:
@@ -22,12 +22,32 @@ permissions:
checks: read
statuses: read
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
merge:
name: Auto-merge Dependabot PRs
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Update stale Dependabot branches
env:
GH_TOKEN: ${{ github.token }}
HEAD_BRANCH: ${{ github.event.workflow_run.head_branch || '' }}
run: |
set -euo pipefail
if [ -n "$HEAD_BRANCH" ]; then
pr_numbers="$(gh pr list --state open --author "dependabot[bot]" --head "$HEAD_BRANCH" --json number,mergeStateStatus --jq '.[] | select(.mergeStateStatus == "BEHIND") | .number')"
else
pr_numbers="$(gh pr list --state open --author "dependabot[bot]" --json number,mergeStateStatus --jq '.[] | select(.mergeStateStatus == "BEHIND") | .number')"
fi
for pr_number in $pr_numbers; do
gh pr update-branch "$pr_number" || true
done
- name: Merge Dependabot PRs when checks pass
uses: actions/github-script@v9
with: