Skip to content

chore(deps): bump nanotar from 0.2.0 to 0.3.0#1091

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/nanotar-0.3.0
Closed

chore(deps): bump nanotar from 0.2.0 to 0.3.0#1091
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/nanotar-0.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 23, 2026

Copy link
Copy Markdown
Contributor

Bumps nanotar from 0.2.0 to 0.3.0.

Release notes

Sourced from nanotar's releases.

v0.3.0

compare changes

Changes in #31 also backported to v0.2.1; however, it WAS NOT a security issue (see #59 for appeal).

🚀 Enhancements

  • parse: ⚠️ Support extended item types and headers (#30)
  • parse: Handle long file names (#31)

🩹 Fixes

  • Sanitise paths (#58)

✅ Tests

  • Add additional tests for different formats (f13b802)
  • Update fixture (6fa56df)

❤️ Contributors

Changelog

Sourced from nanotar's changelog.

v0.3.0

compare changes

🚀 Enhancements

  • parse: ⚠️ Support extended item types and headers (#30)
  • parse: Handle long file names (#31)

🩹 Fixes

  • Sanitise paths (#58)

🏡 Chore

✅ Tests

  • Add additional tests for different formats (f13b802)
  • Update fixture (6fa56df)

⚠️ Breaking Changes

  • parse: ⚠️ Support extended item types and headers (#30)

❤️ Contributors

Commits
  • 32ffc34 chore(release): v0.3.0
  • 322f967 fix: sanitise paths (#58)
  • a52e49e chore(deps): update devdependency @​types/node to ^22.19.1 (#52)
  • d7feb9f chore(deps): update all non-major dependencies (#48)
  • e7138db chore(deps): update all non-major dependencies (#47)
  • a7d7452 chore(deps): update all non-major dependencies (#44)
  • d36693d chore(deps): update all non-major dependencies (#43)
  • 2872f34 chore(deps): update all non-major dependencies (#41)
  • 0649ee1 chore(deps): update autofix-ci/action digest to 635ffb0 (#42)
  • 4fe65ab chore(deps): update devdependency vitest to v3.0.5 [security] (#37)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 23, 2026
@socket-security-staging

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​nanotar@​0.2.0 ⏵ 0.3.0100 +1100 +2100 +187100

View full report

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​nanotar@​0.2.0 ⏵ 0.3.0100 +1100 +2100 +186 -2100

View full report

Bumps [nanotar](https://github.com/unjs/nanotar) from 0.2.0 to 0.3.0.
- [Release notes](https://github.com/unjs/nanotar/releases)
- [Changelog](https://github.com/unjs/nanotar/blob/main/CHANGELOG.md)
- [Commits](unjs/nanotar@v0.2.0...v0.3.0)

---
updated-dependencies:
- dependency-name: nanotar
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nanotar-0.3.0 branch from fea3f0e to 22df3af Compare February 24, 2026 01:30
@dependabot @github

dependabot Bot commented on behalf of github Feb 24, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/nanotar-0.3.0 branch February 24, 2026 01:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Development

Successfully merging this pull request may close these issues.

1 participant