Skip to content

chore(deps): bump actions/setup-node from 4 to 6 - #894

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown

Bumps actions/setup-node from 4 to 6.

Release notes

Sourced from actions/setup-node's releases.

v6.0.0

What's Changed

Breaking Changes

Dependency Upgrades

Full Changelog: actions/setup-node@v5...v6.0.0

v5.0.0

What's Changed

Breaking Changes

This update, introduces automatic caching when a valid packageManager field is present in your package.json. This aims to improve workflow performance and make dependency management more seamless. To disable this automatic caching, set package-manager-cache: false

steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v5
  with:
    package-manager-cache: false

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades

New Contributors

Full Changelog: actions/setup-node@v4...v5.0.0

v4.4.0

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 6.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🛡️ Frontend Security Scan

npm audit
# npm audit report

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
# npm audit report

@vitest/mocker  2.1.0 - 4.1.10
Severity: moderate
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
fix available via `npm audit fix --force`
Will install storybook@10.6.1, which is a breaking change
node_modules/@vitest/mocker
  storybook  9.1.0-alpha.0 - 10.1.0-beta.6
  Depends on vulnerable versions of @vitest/mocker
  node_modules/storybook
    @storybook/addon-docs  <=0.0.0-pr-35259-sha-153697da || 9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/csf-plugin
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-docs
    @storybook/addon-links  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-links
    @storybook/builder-webpack5  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of fork-ts-checker-webpack-plugin
    Depends on vulnerable versions of storybook
    Depends on vulnerable versions of webpack-dev-middleware
    node_modules/@storybook/builder-webpack5
      @storybook/nextjs  *
      Depends on vulnerable versions of @storybook/builder-webpack5
      Depends on vulnerable versions of @storybook/preset-react-webpack
      Depends on vulnerable versions of @storybook/react
      Depends on vulnerable versions of node-polyfill-webpack-plugin
      Depends on vulnerable versions of storybook
      node_modules/@storybook/nextjs
    @storybook/core-webpack  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/core-webpack
    @storybook/csf-plugin  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/csf-plugin
    @storybook/preset-react-webpack  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of @storybook/react-docgen-typescript-plugin
    Depends on vulnerable versions of storybook
    node_modules/@storybook/preset-react-webpack
    @storybook/react  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react
    @storybook/react-dom-shim  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react-dom-shim

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/braces
  chokidar  2.0.0 - 3.6.0
  Depends on vulnerable versions of braces
  node_modules/chokidar
    fork-ts-checker-webpack-plugin  0.4.7 - 4.0.0-beta.5 || 6.0.0-alpha.1 - 9.0.3
    Depends on vulnerable versions of chokidar
    node_modules/fork-ts-checker-webpack-plugin
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    @storybook/react-docgen-typescript-plugin  *
    Depends on vulnerable versions of micromatch
    node_modules/@storybook/react-docgen-typescript-plugin
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/@shadcn/registry/node_modules/fast-glob
    node_modules/@ts-morph/common/node_modules/fast-glob
    node_modules/fast-glob
    node_modules/shadcn/node_modules/fast-glob
      @next/eslint-plugin-next  >=14.3.0-canary.0
      Depends on vulnerable versions of fast-glob
      node_modules/@next/eslint-plugin-next
      @shadcn/registry  <=0.0.0-rc-20261007105214 || >=0.1.0
      Depends on vulnerable versions of fast-glob
      Depends on vulnerable versions of ts-morph
      node_modules/@shadcn/registry
        shadcn  <=0.0.0-rc-20261007105214 || >=2.0.0
        Depends on vulnerable versions of @shadcn/registry
        Depends on vulnerable versions of fast-glob
        Depends on vulnerable versions of ts-morph
        node_modules/shadcn
      @ts-morph/common  0.2.0 - 0.24.0 || 0.26.0 - 0.27.0
      Depends on vulnerable versions of fast-glob
      node_modules/@ts-morph/common
        ts-morph  6.0.1 - 23.0.0 || 25.0.0 - 26.0.0
        Depends on vulnerable versions of @ts-morph/common
        node_modules/ts-morph

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/elliptic
  browserify-sign  >=2.4.0
  Depends on vulnerable versions of elliptic
  node_modules/browserify-sign
    crypto-browserify  >=3.4.0
    Depends on vulnerable versions of browserify-sign
    Depends on vulnerable versions of create-ecdh
    node_modules/crypto-browserify
      node-polyfill-webpack-plugin  <=4.0.0
      Depends on vulnerable versions of crypto-browserify
      node_modules/node-polyfill-webpack-plugin
  create-ecdh  *
  Depends on vulnerable versions of elliptic
  node_modules/create-ecdh

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

webpack-dev-middleware  <7.4.5
Severity: high
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath - https://github.com/advisories/GHSA-g84c-rxfj-3j2c
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/webpack-dev-middleware

31 vulnerabilities (5 low, 11 moderate, 15 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force
ESLint
> flowstar@0.1.0 lint
> eslint .


/home/runner/work/FlowStar/FlowStar/next.config.mjs
  15:5  warning  Unexpected console statement  no-console

/home/runner/work/FlowStar/FlowStar/scripts/check-secrets.mjs
  28:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
  31:16  warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  47:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  52:9   warning  Unexpected console statement                                               no-console
  60:3   warning  Unexpected console statement                                               no-console
  63:3   warning  Unexpected console statement                                               no-console

/home/runner/work/FlowStar/FlowStar/scripts/soroban-security-check.mjs
   14:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
   16:9   warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  135:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  142:7   warning  Unexpected console statement                                               no-console
  150:3   warning  Unexpected console statement                                               no-console
  154:3   warning  Unexpected console statement                                               no-console
  159:3   warning  Unexpected console statement                                               no-console

✖ 14 problems (0 errors, 14 warnings)
Hardcoded secrets check
✅ No hardcoded secrets found.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1294 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

This branch was successfully deployed

1 active deployment
staging — 5bbc1d2f Deployed Oct 8, 2026 by dependabot[bot] via deploy-staging #310
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants