Skip to content

build(deps): bump joi from 18.2.3 to 18.2.5 - #254

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/joi-18.2.5
Open

build(deps): bump joi from 18.2.3 to 18.2.5#254
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/joi-18.2.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps joi from 18.2.3 to 18.2.5.

Commits
  • 58ce83e 18.2.5
  • 120672d Merge pull request #3131 from Hashim1999164/fix/email-allow-underscore
  • 5bd73b8 fix: allow allowUnderscore option on string().email()
  • 2b4f443 Merge pull request #3138 from hapijs/fix/messages-proto-injection
  • 90d0757 fix: prevent messages proto injection
  • 82ff29f Merge pull request #3136 from hapijs/chore/improve-unique-documentation
  • ad308cc chore: improve unique documentation
  • ea3e156 18.2.4
  • 262c4f1 Merge pull request #3134 from hapijs/fix/rename-proto
  • 162f367 fix: prevent proto on renames
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [joi](https://github.com/hapijs/joi) from 18.2.3 to 18.2.5.
- [Commits](hapijs/joi@v18.2.3...v18.2.5)

---
updated-dependencies:
- dependency-name: joi
  dependency-version: 18.2.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@dependabot
dependabot Bot requested a review from Rumblingb as a code owner September 9, 2026 03:22
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
agentpay-docs Ready Ready Preview Sep 9, 2026 3:23am UTC
agentpay-host-native-restore Ready Ready Preview Sep 9, 2026 3:23am UTC
1 Skipped Deployment
Project Deployment Actions Updated
agentpay-dashboard Ignored Ignored Preview Sep 9, 2026 3:23am UTC

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

package-lock.json

PackageVersionLicenseIssue Type
packages/mcp-server0.2.1NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
npm/joi 18.2.5 🟢 6.2
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Code-Review⚠️ 1Found 2/19 approved changesets -- score normalized to 1
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 9license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/packages/mcp-server 0.2.1 UnknownUnknown

Scanned Files

  • package-lock.json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants