Repository navigation
build(deps): bump compression from 1.8.1 to 1.8.2 - #313
Conversation
Bumps [compression](https://github.com/expressjs/compression) from 1.8.1 to 1.8.2. - [Release notes](https://github.com/expressjs/compression/releases) - [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md) - [Commits](expressjs/compression@v1.8.1...v1.8.2) --- updated-dependencies: - dependency-name: compression dependency-version: 1.8.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM — straightforward dependabot lockfile bump.
What was reviewed: the yarn.lock diff only touches the compression entry, bumping it from 1.8.1 to 1.8.2 (resolution + checksum updated) and adding destroy@ npm:1.2.0 as a new transitive dependency it now pulls in. No source files changed, and the new dependency is a well-known small utility package consistent with compression's own package.json requirement. This is a routine security-fix patch bump (per upstream release notes) with no ambiguity in scope.
Extended reasoning...
Single-file change (yarn.lock) with no source code touched; it is a dependabot patch-version bump of the compression package plus one new transitive dependency entry, matching the PR description exactly. No security-sensitive application code, auth, or permissions logic is involved — only lockfile metadata. Change is small, mechanical, and self-contained, so a human need not review it.
Bumps compression from 1.8.1 to 1.8.2.
Release notes
Sourced from compression's releases.
Changelog
Sourced from compression's changelog.
Commits
0f970741.8.2 (#287)151f63efix: destroy compression stream on response close0a76495fix: match Cache-Control no-transform directive case-insensitively (#286)c17b6e5docs: update outdated Brotli note and fix npm install docs URL (#276)112911achore(ci): npm-publish via reusable workflows (#269)1bf5eb0build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#267)d8fe64dbuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#266)b218ff5build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (#265)8a1cf8ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#268)4a19855build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#257)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for compression since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.