chore(deps-dev): bump @electron/asar from 3.4.1 to 4.3.0 - #3957
chore(deps-dev): bump @electron/asar from 3.4.1 to 4.3.0#3957dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@electron/asar](https://github.com/electron/asar) from 3.4.1 to 4.3.0. - [Release notes](https://github.com/electron/asar/releases) - [Changelog](https://github.com/electron/asar/blob/main/CHANGELOG.md) - [Commits](electron/asar@v3.4.1...v4.3.0) --- updated-dependencies: - dependency-name: "@electron/asar" dependency-version: 4.3.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
I reviewed this PR at exact head Spec: GO — no P0–P3
The lockfile growth is the expected npm representation after the v4 root can no longer be deduplicated with nested consumers that still need v3. Standards: 2×P3 — non-blocking but needs housekeeping
No Fowler judgment smell; the package/lock delta is mechanical and entropy-neutral. Title, bot identification, Signed-off-by, Node floor, and API compatibility otherwise pass. Other checks: What I did not check: full local suite beyond the focused 18/18 archive checks. Gate: exact head has no P0–P2 and all required checks are green. The two P3 template/branch findings are non-blocking housekeeping; the PR can be approved and merged once the automation exception is acknowledged, or the template is completed.
|
Bumps @electron/asar from 3.4.1 to 4.3.0.
Release notes
Sourced from @electron/asar's releases.
... (truncated)
Commits
01bc908feat: store duplicated file contents only once when packing (#465)2bf3408build(deps): bump postcss from 8.5.20 to 8.5.24 (#463)ab7bc41build(deps): bump undici from 7.28.0 to 7.29.0 (#462)d934f9abuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#459)1ce80a7build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#460)9428c25build(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#461)c4354aeci: stop setting the Opened project field (#456)8e12da2build(deps): bump postcss from 8.5.15 to 8.5.20 (#458)4d5d687build(deps): bump linkify-it from 5.0.1 to 5.0.2 (#457)0959a13build(deps): bump brace-expansion from 5.0.6 to 5.0.7 (#455)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@electron/asarsince your current version.Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)