Skip to content

build(deps-dev): bump semantic-release from 25.0.5 to 25.0.8#310

Merged
roebi merged 1 commit into
masterfrom
dependabot/npm_and_yarn/semantic-release-25.0.6
Jul 21, 2026
Merged

build(deps-dev): bump semantic-release from 25.0.5 to 25.0.8#310
roebi merged 1 commit into
masterfrom
dependabot/npm_and_yarn/semantic-release-25.0.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps semantic-release from 25.0.5 to 25.0.8.

Release notes

Sourced from semantic-release's releases.

v25.0.8

25.0.8 (2026-07-18)

Bug Fixes

  • handle potential null values in commit message and gitTags trimming (0a60004)
  • hide-sensitive: mask key/auth/webhook env vars (973d763)
  • mask sensitive environment variables and improve commit handling (#4252) (1bfdc52)
  • prevent template evaluation syntax in branch expansion and tag formatting (f121540)

v25.0.7

25.0.7 (2026-07-13)

Bug Fixes

  • argument Injection via repositoryUrl in package.json (#4245) (c46dbda)

v25.0.6

25.0.6 (2026-07-10)

Bug Fixes

  • ensure encoded secrets get masked (8e28dd3)
Commits
  • 1bfdc52 fix: mask sensitive environment variables and improve commit handling (#4252)
  • 0a60004 fix: handle potential null values in commit message and gitTags trimming
  • f121540 fix: prevent template evaluation syntax in branch expansion and tag formatting
  • 973d763 fix(hide-sensitive): mask key/auth/webhook env vars
  • 474e5a3 ci(action): update github/codeql-action action to v4.37.1 (#4254)
  • fc9382c docs: fix issue template links (#4251)
  • e34c52d ci(action): update actions/setup-node action to v7 (#4250)
  • 8020ec6 ci(action): update actions/setup-node action to v6.5.0 (#4249)
  • 956baf4 chore(deps): update npm to v12.0.1 (#4247)
  • c46dbda fix: argument Injection via repositoryUrl in package.json (#4245)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 13, 2026
@socket-security

socket-security Bot commented Jul 13, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedsemantic-release@​25.0.5 ⏵ 25.0.89710010097 +2100

View full report

Bumps [semantic-release](https://github.com/semantic-release/semantic-release) from 25.0.5 to 25.0.8.
- [Release notes](https://github.com/semantic-release/semantic-release/releases)
- [Commits](semantic-release/semantic-release@v25.0.5...v25.0.8)

---
updated-dependencies:
- dependency-name: semantic-release
  dependency-version: 25.0.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps-dev): bump semantic-release from 25.0.5 to 25.0.6 build(deps-dev): bump semantic-release from 25.0.5 to 25.0.8 Jul 21, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/semantic-release-25.0.6 branch from 2ecd988 to d5bd97c Compare July 21, 2026 05:55
@roebi roebi self-assigned this Jul 21, 2026
@roebi
roebi merged commit 9527da6 into master Jul 21, 2026
4 checks passed
@roebi
roebi deleted the dependabot/npm_and_yarn/semantic-release-25.0.6 branch July 21, 2026 06:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant