Skip to content

Bump the production-dependencies group across 1 directory with 4 updates - #3

Merged
Daniel-Ric merged 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-de5b0c6c5d
Jul 30, 2026
Merged

Bump the production-dependencies group across 1 directory with 4 updates#3
Daniel-Ric merged 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-de5b0c6c5d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 4 updates in the / directory: @openai/codex-security, @opentelemetry/api, @opentelemetry/semantic-conventions and better-sqlite3.

Updates @openai/codex-security from 0.1.1 to 0.1.4

Commits
  • ab3b91c release: bump Codex Security to 0.1.4 (#111)
  • 3e863a7 fix: harden npm package lifecycle and Node support (#104)
  • dd74cdb fix: support managed Codex credential keyrings (#101)
  • 4357b1e fix: harden Node CI and Windows package smoke (#84)
  • b26d4c3 fix(windows): preserve sandbox override compatibility (#96)
  • 1a9fc9b fix: document CLI help and deep-scan configuration (#105)
  • 8d9eb30 fix: preserve authoritative security scan targets (#103)
  • f89633a release: bump Codex Security to 0.1.3 (#94)
  • a3e4c7a Fix "Could not save the Codex Security scan" (#67)
  • 010ccaa docs: define the trusted-local Codex Security threat model (#61)
  • Additional commits viewable in compare view

Updates @opentelemetry/api from 1.9.0 to 1.9.1

Release notes

Sourced from @​opentelemetry/api's releases.

api/v1.9.1

1.9.1

🐛 (Bug Fix)

  • fix(api): prioritize esnext export condition as it is more specific #5458
  • fix(api): update diag consoleLogger to use original console methods to prevent infinite loop when a console instrumentation is present #6395
  • fix(api): use Attributes instead of deprecated SpanAttributes in SpanOptions #6478 @​overbalance
  • fix(diag): change types in DiagComponentLogger from any to unknown#5478 @​loganrosen
  • fix(api): re-introduce fallback chain for global utils #6523 @​pichlermarc

🏠 (Internal)

Changelog

Sourced from @​opentelemetry/api's changelog.

1.9.1

🐛 (Bug Fix)

🏠 (Internal)

  • chore: fix cross project links and missing implicitly exported types #3533 @​legendecas
  • feat(sdk-metrics): add exponential histogram mapping functions #3504 @​mwear
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​opentelemetry/api since your current version.


Updates @opentelemetry/semantic-conventions from 1.38.0 to 1.43.0

Release notes

Sourced from @​opentelemetry/semantic-conventions's releases.

semconv/v1.43.0

1.43.0

🚀 Features

  • feat: update semantic conventions to v1.43.0 #6883
    • Semantic Conventions v1.43.0: changelog | latest docs
    • @opentelemetry/semantic-conventions (stable) changes: 1 added export
    • @opentelemetry/semantic-conventions/incubating (unstable) changes: 1 added export

Stable changes in v1.43.0

TELEMETRY_SDK_LANGUAGE_VALUE_KOTLIN // "kotlin"

Unstable changes in v1.43.0

ATTR_AZURE_RESOURCE_GROUP_NAME // azure.resource_group.name

semconv/v1.42.0

1.42.0

🚀 Features

Stable changes in v1.42.0

</tr></table> 

... (truncated)

Commits
  • 9b05f66 chore: prepare next release (#6906)
  • 0f18798 feat(semantic-conventions): update semantic conventions to v1.43.0 (#6883)
  • bbcdfa8 chore: update workflow to the shared one (#6904)
  • e6a5776 chore(deps): update dependency typedoc to v0.28.20 (#6898)
  • 8bec662 feat(propagator-jaeger): deprecate JaegerPropagator (#6893)
  • 20e3abe chore: add workflow for first time contributor (#6896)
  • fda8f31 chore: bump to typescript@5.2.2 (#6888)
  • 3394c3e fix(sdk-trace): sample ratio 1 upper-bound trace IDs (#6890)
  • 2568ac1 chore: clean up some deps and devDeps in exporter packages (#6892)
  • 0fd7fac test(exporter-metrics-otlp-*): return response to allow process exit (#6889)
  • Additional commits viewable in compare view

Updates better-sqlite3 from 12.11.1 to 13.0.2

Release notes

Sourced from better-sqlite3's releases.

v13.0.2

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v13.0.1...v13.0.2

v13.0.1

Full Changelog: WiseLibs/better-sqlite3@v13.0.0...v13.0.1

Fixed a regression in parameter binding where it would be overly strict and reject plain objects from other realms (e.g., in jest tests).

v13.0.0

Version 13.0.0 marks a major milestone, as it's the first version of better-sqlite3 to run on the N-API. This means prebuilt binaries should theoretically work across different versions of Node.js and Electron, and perhaps even other runtimes like Bun. As a result, we've removed the deprecated prebuild-install dependency, and now prebuilt binaries are published directly with the better-sqlite3 code itself. If your platform/architecture doesn't have a prebuilt binary, it should compile during install as before.

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v12.12.0...v13.0.0

v12.12.0

What's Changed

[!WARNING]

BREAKING: Starting with Electron v43, binary assets will require glibc 2.41 or higher on Linux hosts.

Full Changelog: WiseLibs/better-sqlite3@v12.11.2...v12.12.0

v12.11.2

What's Changed

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 29, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot dependabot Bot changed the title Bump the production-dependencies group with 4 updates Bump the production-dependencies group across 1 directory with 4 updates Jul 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-de5b0c6c5d branch from a9aecc9 to efecbcc Compare July 30, 2026 12:30

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-de5b0c6c5d branch from efecbcc to 94b9f75 Compare July 30, 2026 12:38

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps the production-dependencies group with 4 updates in the / directory: [@openai/codex-security](https://github.com/openai/codex-security/tree/HEAD/sdk/typescript), [@opentelemetry/api](https://github.com/open-telemetry/opentelemetry-js), [@opentelemetry/semantic-conventions](https://github.com/open-telemetry/opentelemetry-js) and [better-sqlite3](https://github.com/WiseLibs/better-sqlite3).


Updates `@openai/codex-security` from 0.1.1 to 0.1.4
- [Commits](https://github.com/openai/codex-security/commits/npm-v0.1.4/sdk/typescript)

Updates `@opentelemetry/api` from 1.9.0 to 1.9.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v1.9.0...v1.9.1)

Updates `@opentelemetry/semantic-conventions` from 1.38.0 to 1.43.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@semconv/v1.38.0...semconv/v1.43.0)

Updates `better-sqlite3` from 12.11.1 to 13.0.2
- [Release notes](https://github.com/WiseLibs/better-sqlite3/releases)
- [Commits](WiseLibs/better-sqlite3@v12.11.1...v13.0.2)

---
updated-dependencies:
- dependency-name: "@openai/codex-security"
  dependency-version: 0.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/api"
  dependency-version: 1.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/semantic-conventions"
  dependency-version: 1.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: better-sqlite3
  dependency-version: 13.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-de5b0c6c5d branch from 94b9f75 to 918027a Compare July 30, 2026 12:43
@Daniel-Ric
Daniel-Ric merged commit 6dcc406 into main Jul 30, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-de5b0c6c5d branch July 30, 2026 12:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant