Skip to content

Conversation

@ernscht
Copy link
Member

@ernscht ernscht commented Sep 29, 2025

snyk-top-banner

Snyk has created this PR to upgrade config from 4.1.0 to 4.1.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released a month ago.

Release notes
Package name: config
  • 4.1.1 - 2025-08-15

    What's Changed

    This release includes only test and devDependency changes

    Full Changelog: v4.1.0...v4.1.1

  • 4.1.0 - 2025-07-23

    Breaking Changes

    Several bugs were fixed that a user code might theoretically rely on, but most likely not:

    • Config.getSources() no longer contains files read by parseFile outside of the load process
    • when setModuleDefaults('modulename', ...) is called twice, the second call can overwrite values from the first
    • Config.getSources() now agrees with setModuleDefaults, no matter how often it is called

    What's Changed

    Bugs fixed:

    • #687 - you can now have deferConfig lines in submodules
    • #822 - setModuleDefaults calls are now additive (slightly higher memory usage for defaults as a consequence)
    • #827 - more accurate tracking of sources
from config GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade config from 4.1.0 to 4.1.1.

See this package in npm:
config

See this project in Snyk:
https://app.snyk.io/org/ernscht/project/528bf7dc-4689-4905-b044-0848bbc5280a?utm_source=github&utm_medium=referral&page=upgrade-pr
@ernscht
Copy link
Member Author

ernscht commented Oct 8, 2025

outdated

@ernscht ernscht closed this Oct 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants