Skip to content

Commit 85f9beb

Browse files
Bump turbo from 2.5.2 to 2.9.14 (#4314)
Bumps [turbo](https://github.com/vercel/turborepo) from 2.5.2 to 2.9.14. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vercel/turborepo/releases">turbo's releases</a>.</em></p> <blockquote> <h2>Turborepo v2.9.14</h2> <blockquote> <p>[!NOTE] This release contains important security fixes.</p> </blockquote> <h3>High:</h3> <ul> <li><a href="https://github.com/vercel/turborepo/security/advisories/GHSA-5xc8-49mv-x4mm">GHSA-5xc8-49mv-x4mm: Turborepo VSCode Extension command injection</a></li> </ul> <h3>Low:</h3> <ul> <li><a href="https://github.com/vercel/turborepo/security/advisories/GHSA-hcf7-66rw-9f5r">GHSA-hcf7-66rw-9f5r: Login callback CSRF/session fixation</a></li> <li><a href="https://github.com/vercel/turborepo/security/advisories/GHSA-3qcw-2rhx-2726">GHSA-3qcw-2rhx-2726: Unexpected local code execution during Yarn Berry detection</a></li> </ul> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Changelog</h3> <ul> <li>release(turborepo): 2.9.12 by <a href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li> <li>fix: Restore docs mobile menu by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li> <li>ci: Use <code>pull_request</code> for PR title linting by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li> <li>ci: Scope GitHub Actions caches by branch by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li> <li>test: Validate lockfiles without dependency downloads by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li> <li>Removed unneeded import form hash creation script in docs by <a href="https://github.com/dancrumb"><code>@​dancrumb</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li> <li>fix: Validate auth callback state by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li> <li>fix: Harden VS Code extension command execution by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li> <li>fix: Avoid project-local Yarn during detection by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li> <li>chore: Release 2.9.13 by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12803">vercel/turborepo#12803</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/dancrumb"><code>@​dancrumb</code></a> made their first contribution in <a href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14">https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14</a></p> <h2>Turborepo v2.9.13-canary.1</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Changelog</h3> <ul> <li>release(turborepo): 2.9.11-canary.7 by <a href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12768">vercel/turborepo#12768</a></li> <li>fix: Allow <code>$TURBO_EXTENDS$</code> in LSP diagnostics by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12770">vercel/turborepo#12770</a></li> <li>release(turborepo): 2.9.11 by <a href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12771">vercel/turborepo#12771</a></li> <li>fix: Allow transit nodes in LSP diagnostics by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12773">vercel/turborepo#12773</a></li> <li>release(turborepo): 2.9.12 by <a href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li> <li>fix: Restore docs mobile menu by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li> <li>ci: Use <code>pull_request</code> for PR title linting by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li> <li>ci: Scope GitHub Actions caches by branch by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li> <li>test: Validate lockfiles without dependency downloads by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li> <li>Removed unneeded import form hash creation script in docs by <a href="https://github.com/dancrumb"><code>@​dancrumb</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li> <li>fix: Validate auth callback state by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li> <li>fix: Harden VS Code extension command execution by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li> <li>fix: Avoid project-local Yarn during detection by <a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vercel/turborepo/commit/fc62fe0d9c347d1d24f0ed8946284856593ddb93"><code>fc62fe0</code></a> publish 2.9.14 to registry</li> <li><a href="https://github.com/vercel/turborepo/commit/fb8c9aec0f9e83f95783659a5ce9c4478cf62cb9"><code>fb8c9ae</code></a> chore: Release 2.9.13 (<a href="https://redirect.github.com/vercel/turborepo/issues/12803">#12803</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/e8e629da4e1fb75231089e91b19be9d327a3e649"><code>e8e629d</code></a> fix: Avoid project-local Yarn during detection (<a href="https://redirect.github.com/vercel/turborepo/issues/12801">#12801</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/91c90cbf12f524c5c29b713d6472dd5fcdecb309"><code>91c90cb</code></a> fix: Harden VS Code extension command execution (<a href="https://redirect.github.com/vercel/turborepo/issues/12800">#12800</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/84f450894e87da1eed864d51f6f637f26980d560"><code>84f4508</code></a> fix: Validate auth callback state (<a href="https://redirect.github.com/vercel/turborepo/issues/12802">#12802</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/1779ad7901384f106236a6e196059e4929745514"><code>1779ad7</code></a> Removed unneeded import form hash creation script in docs (<a href="https://redirect.github.com/vercel/turborepo/issues/12799">#12799</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/71f8c90a807ffb9b9876ea8a04f523f473bf5c8d"><code>71f8c90</code></a> test: Validate lockfiles without dependency downloads (<a href="https://redirect.github.com/vercel/turborepo/issues/12789">#12789</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/5fcb96024d503127bb0ed760ebe159b7716c52b3"><code>5fcb960</code></a> ci: Scope GitHub Actions caches by branch (<a href="https://redirect.github.com/vercel/turborepo/issues/12788">#12788</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/4cf9fabc9a6f6c99fe4e2f2da9f35be631be062a"><code>4cf9fab</code></a> ci: Use <code>pull_request</code> for PR title linting (<a href="https://redirect.github.com/vercel/turborepo/issues/12787">#12787</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/859c629bc401f239ac7980a132746ca90478e17c"><code>859c629</code></a> fix: Restore docs mobile menu (<a href="https://redirect.github.com/vercel/turborepo/issues/12782">#12782</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vercel/turborepo/compare/v2.5.2...v2.9.14">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for turbo since your current version.</p> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=turbo&package-manager=npm_and_yarn&previous-version=2.5.2&new-version=2.9.14)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/graphql/graphiql/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent ea8d0da commit 85f9beb

2 files changed

Lines changed: 60 additions & 60 deletions

File tree

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@
101101
"patch-package": "^7.0.2",
102102
"postinstall-postinstall": "^2.1.0",
103103
"rimraf": "^3.0.2",
104-
"turbo": "^2.5.2",
104+
"turbo": "^2.9.14",
105105
"typedoc": "^0.28.19",
106106
"typescript": "^5.8.0",
107107
"vitest": "^4.1.6",

yarn.lock

Lines changed: 59 additions & 59 deletions
Original file line numberDiff line numberDiff line change
@@ -6095,6 +6095,48 @@ __metadata:
60956095
languageName: node
60966096
linkType: hard
60976097

6098+
"@turbo/darwin-64@npm:2.9.14":
6099+
version: 2.9.14
6100+
resolution: "@turbo/darwin-64@npm:2.9.14"
6101+
conditions: os=darwin & cpu=x64
6102+
languageName: node
6103+
linkType: hard
6104+
6105+
"@turbo/darwin-arm64@npm:2.9.14":
6106+
version: 2.9.14
6107+
resolution: "@turbo/darwin-arm64@npm:2.9.14"
6108+
conditions: os=darwin & cpu=arm64
6109+
languageName: node
6110+
linkType: hard
6111+
6112+
"@turbo/linux-64@npm:2.9.14":
6113+
version: 2.9.14
6114+
resolution: "@turbo/linux-64@npm:2.9.14"
6115+
conditions: os=linux & cpu=x64
6116+
languageName: node
6117+
linkType: hard
6118+
6119+
"@turbo/linux-arm64@npm:2.9.14":
6120+
version: 2.9.14
6121+
resolution: "@turbo/linux-arm64@npm:2.9.14"
6122+
conditions: os=linux & cpu=arm64
6123+
languageName: node
6124+
linkType: hard
6125+
6126+
"@turbo/windows-64@npm:2.9.14":
6127+
version: 2.9.14
6128+
resolution: "@turbo/windows-64@npm:2.9.14"
6129+
conditions: os=win32 & cpu=x64
6130+
languageName: node
6131+
linkType: hard
6132+
6133+
"@turbo/windows-arm64@npm:2.9.14":
6134+
version: 2.9.14
6135+
resolution: "@turbo/windows-arm64@npm:2.9.14"
6136+
conditions: os=win32 & cpu=arm64
6137+
languageName: node
6138+
linkType: hard
6139+
60986140
"@types/argparse@npm:1.0.38":
60996141
version: 1.0.38
61006142
resolution: "@types/argparse@npm:1.0.38"
@@ -12941,7 +12983,7 @@ __metadata:
1294112983
postinstall-postinstall: "npm:^2.1.0"
1294212984
rimraf: "npm:^3.0.2"
1294312985
svgo: "npm:^4.0.1"
12944-
turbo: "npm:^2.5.2"
12986+
turbo: "npm:^2.9.14"
1294512987
typedoc: "npm:^0.28.19"
1294612988
typescript: "npm:^5.8.0"
1294712989
vitest: "npm:^4.1.6"
@@ -20790,74 +20832,32 @@ __metadata:
2079020832
languageName: node
2079120833
linkType: hard
2079220834

20793-
"turbo-darwin-64@npm:2.5.2":
20794-
version: 2.5.2
20795-
resolution: "turbo-darwin-64@npm:2.5.2"
20796-
conditions: os=darwin & cpu=x64
20797-
languageName: node
20798-
linkType: hard
20799-
20800-
"turbo-darwin-arm64@npm:2.5.2":
20801-
version: 2.5.2
20802-
resolution: "turbo-darwin-arm64@npm:2.5.2"
20803-
conditions: os=darwin & cpu=arm64
20804-
languageName: node
20805-
linkType: hard
20806-
20807-
"turbo-linux-64@npm:2.5.2":
20808-
version: 2.5.2
20809-
resolution: "turbo-linux-64@npm:2.5.2"
20810-
conditions: os=linux & cpu=x64
20811-
languageName: node
20812-
linkType: hard
20813-
20814-
"turbo-linux-arm64@npm:2.5.2":
20815-
version: 2.5.2
20816-
resolution: "turbo-linux-arm64@npm:2.5.2"
20817-
conditions: os=linux & cpu=arm64
20818-
languageName: node
20819-
linkType: hard
20820-
20821-
"turbo-windows-64@npm:2.5.2":
20822-
version: 2.5.2
20823-
resolution: "turbo-windows-64@npm:2.5.2"
20824-
conditions: os=win32 & cpu=x64
20825-
languageName: node
20826-
linkType: hard
20827-
20828-
"turbo-windows-arm64@npm:2.5.2":
20829-
version: 2.5.2
20830-
resolution: "turbo-windows-arm64@npm:2.5.2"
20831-
conditions: os=win32 & cpu=arm64
20832-
languageName: node
20833-
linkType: hard
20834-
20835-
"turbo@npm:^2.5.2":
20836-
version: 2.5.2
20837-
resolution: "turbo@npm:2.5.2"
20835+
"turbo@npm:^2.9.14":
20836+
version: 2.9.14
20837+
resolution: "turbo@npm:2.9.14"
2083820838
dependencies:
20839-
turbo-darwin-64: "npm:2.5.2"
20840-
turbo-darwin-arm64: "npm:2.5.2"
20841-
turbo-linux-64: "npm:2.5.2"
20842-
turbo-linux-arm64: "npm:2.5.2"
20843-
turbo-windows-64: "npm:2.5.2"
20844-
turbo-windows-arm64: "npm:2.5.2"
20839+
"@turbo/darwin-64": "npm:2.9.14"
20840+
"@turbo/darwin-arm64": "npm:2.9.14"
20841+
"@turbo/linux-64": "npm:2.9.14"
20842+
"@turbo/linux-arm64": "npm:2.9.14"
20843+
"@turbo/windows-64": "npm:2.9.14"
20844+
"@turbo/windows-arm64": "npm:2.9.14"
2084520845
dependenciesMeta:
20846-
turbo-darwin-64:
20846+
"@turbo/darwin-64":
2084720847
optional: true
20848-
turbo-darwin-arm64:
20848+
"@turbo/darwin-arm64":
2084920849
optional: true
20850-
turbo-linux-64:
20850+
"@turbo/linux-64":
2085120851
optional: true
20852-
turbo-linux-arm64:
20852+
"@turbo/linux-arm64":
2085320853
optional: true
20854-
turbo-windows-64:
20854+
"@turbo/windows-64":
2085520855
optional: true
20856-
turbo-windows-arm64:
20856+
"@turbo/windows-arm64":
2085720857
optional: true
2085820858
bin:
2085920859
turbo: bin/turbo
20860-
checksum: 10c0/3eed6eba8bace18ed767785c83cd572985214e79d267f3eb631b2c147e941203746b241869fe629776704d3e69c37da90c5356c3b9506e08c468c9cab52f120c
20860+
checksum: 10c0/77a20c05ef588a9bac02500108af644ac1129b23f6f8db53054c9c7af98ed6a71e019172a0dd6d03920c6068c1a93ea80e6b2fb857bf70ba09616381bf07ea47
2086120861
languageName: node
2086220862
linkType: hard
2086320863

0 commit comments

Comments
 (0)