Skip to content

chore(deps): bump date-fns from 4.2.1 to 4.3.0#1014

Merged
escapedcat merged 1 commit into
mainfrom
dependabot/npm_and_yarn/date-fns-4.2.1
May 24, 2026
Merged

chore(deps): bump date-fns from 4.2.1 to 4.3.0#1014
escapedcat merged 1 commit into
mainfrom
dependabot/npm_and_yarn/date-fns-4.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 20, 2026

Bumps date-fns from 4.2.1 to 4.3.0.

Release notes

Sourced from date-fns's releases.

v4.3.0

Kudos to @​ImRodry and @​puneetdixit200 for their contributions.

Fixed

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 20, 2026
@netlify
Copy link
Copy Markdown

netlify Bot commented May 20, 2026

Deploy Preview for btcmap ready!

Name Link
🔨 Latest commit 3380264
🔍 Latest deploy log https://app.netlify.com/projects/btcmap/deploys/6a12f981925e4600087854c5
😎 Deploy Preview https://deploy-preview-1014--btcmap.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 50 (🔴 down 20 from production)
Accessibility: 97 (no change from production)
Best Practices: 92 (🔴 down 8 from production)
SEO: 96 (no change from production)
PWA: 90 (no change from production)
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 20, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​sveltejs/​kit@​2.61.1991008198100
Addeddate-fns@​4.3.0881009290100
Addedsvelte-preprocess@​6.0.49210010089100

View full report

Bumps [date-fns](https://github.com/date-fns/date-fns) from 4.2.1 to 4.3.0.
- [Release notes](https://github.com/date-fns/date-fns/releases)
- [Commits](date-fns/date-fns@v4.2.1...v4.3.0)

---
updated-dependencies:
- dependency-name: date-fns
  dependency-version: 4.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump date-fns from 4.1.0 to 4.2.1 chore(deps): bump date-fns from 4.2.1 to 4.3.0 May 24, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/date-fns-4.2.1 branch from 64ae1b3 to 3380264 Compare May 24, 2026 13:13
@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm date-fns is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/date-fns@4.3.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/date-fns@4.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@escapedcat escapedcat merged commit 4933d1a into main May 24, 2026
11 checks passed
@escapedcat escapedcat deleted the dependabot/npm_and_yarn/date-fns-4.2.1 branch May 24, 2026 13:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant