Skip to content

chore(deps): bump adm-zip and @module-federation/enhanced in /clients/ui/frontend - #3307

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/clients/ui/frontend/multi-f81055401b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/clients/ui/frontend/multi-f81055401b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps adm-zip to 0.6.1 and updates ancestor dependency @module-federation/enhanced. These dependencies need to be updated together.

Updates adm-zip from 0.6.0 to 0.6.1

Release notes

Sourced from adm-zip's releases.

v0.6.1

Full Changelog: cthackers/adm-zip@v0.6.0...v0.6.1

  • Updated dev dependencies
  • Fixed uncaught crash in async decompression on malformed DEFLATE data
  • Fixed addLocalFolder following symlinks out of the archived folder
  • Stripped setuid/setgid/sticky bits from extracted file permissions
  • Enforced the decompression size cap on the async path and for size 0
  • Rejected archives with duplicate entry names
  • Blocked extraction from writing through symlinks inside the target
  • Routed malformed-header parse errors through the async callback
  • Rejected zip entries whose declared data extent runs past the buffer
  • Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • Fixed addLocalFolderAsync2 mangling local paths on Windows
Commits
  • cb2cf9b Fixed addLocalFolderAsync2 mangling local paths on Windows
  • 54902b6 Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • 73131bd Fixed CI
  • 758898d Rejected zip entries whose declared data extent runs past the buffer
  • 74b6e9f Routed malformed-header parse errors through the async callback
  • eaa35fa Blocked extraction from writing through symlinks inside the target
  • 1e015e3 Increment version
  • 05101d4 Rejected archives with duplicate entry names
  • 4916006 Enforced the decompression size cap on the async path and for size 0
  • 6a63c33 Stripped setuid/setgid/sticky bits from extracted file permissions
  • Additional commits viewable in compare view

Updates @module-federation/enhanced from 2.8.2 to 2.9.2

Release notes

Sourced from @​module-federation/enhanced's releases.

Release v2.9.2

What's Changed

Bug Fixes 🐞

Document 📖

Other Changes

New Contributors

Full Changelog: module-federation/core@v2.9.1...v2.9.2

Browser extension

Download Browser extension

For extension-capable embedded browsers. Extract the ZIP, load the directory containing manifest.json, and refresh the page.

Installation and WebMCP guide

Extension version: 2.9.2. Source commit: b78935690208c1a75ecb23969a514597543c20c1.

SHA-256: 436e021c800533808c5dd57b3587b3eacf6b67454fbb6ad9d96f9633b98d1bcc

Release v2.9.1

What's Changed

New Features 🎉

... (truncated)

Changelog

Sourced from @​module-federation/enhanced's changelog.

2.9.2

Patch Changes

  • 412f62e: Restore BUILD-001 logging and diagnostic context when an expose cannot resolve. Webpack still reports the build error, and container.get() rejects the missing expose.
  • c130946: An exposed module that fails to resolve no longer exits the Node process during code generation. The build finishes with webpack's "Module not found" error in compilation.errors, and the container's get() for that expose throws MODULE_NOT_FOUND, as in upstream webpack. Watch mode and dev servers keep running.
  • 923b55d: Fix the tree-shaking shared entry build finishing its make phase before the shared entry module tree was built. Large shared packages with a filesystem cache could crash in createModuleAssets or emit a fallback bundle with missing modules, and an entry error was thrown instead of reported.
  • Updated dependencies [000f3fa]
  • Updated dependencies [7f0ac8b]
    • @​module-federation/dts-plugin@​2.9.2
    • @​module-federation/cli@​2.9.2
    • @​module-federation/manifest@​2.9.2
    • @​module-federation/rspack@​2.9.2
    • @​module-federation/runtime-tools@​2.9.2
    • @​module-federation/webpack-bundler-runtime@​2.9.2
    • @​module-federation/inject-external-runtime-core-plugin@​2.9.2
    • @​module-federation/sdk@​2.9.2
    • @​module-federation/managers@​2.9.2
    • @​module-federation/bridge-react-webpack-plugin@​2.9.2
    • @​module-federation/error-codes@​2.9.2

2.9.1

Patch Changes

  • Updated dependencies [796d6ad]
    • @​module-federation/dts-plugin@​2.9.1
    • @​module-federation/cli@​2.9.1
    • @​module-federation/manifest@​2.9.1
    • @​module-federation/rspack@​2.9.1
    • @​module-federation/runtime-tools@​2.9.1
    • @​module-federation/webpack-bundler-runtime@​2.9.1
    • @​module-federation/inject-external-runtime-core-plugin@​2.9.1
    • @​module-federation/sdk@​2.9.1
    • @​module-federation/managers@​2.9.1
    • @​module-federation/bridge-react-webpack-plugin@​2.9.1
    • @​module-federation/error-codes@​2.9.1

2.9.0

Patch Changes

  • Updated dependencies [df8b40f]
    • @​module-federation/webpack-bundler-runtime@​2.9.0
    • @​module-federation/dts-plugin@​2.9.0
    • @​module-federation/runtime-tools@​2.9.0
    • @​module-federation/rspack@​2.9.0
    • @​module-federation/inject-external-runtime-core-plugin@​2.9.0
    • @​module-federation/sdk@​2.9.0
    • @​module-federation/managers@​2.9.0

... (truncated)

Commits
  • b789356 chore: release v2.9.2
  • 412f62e fix(enhanced): restore missing expose diagnostics (#5146)
  • 923b55d fix(enhanced): wait for addEntry in SharedContainerPlugin make (#5122)
  • c130946 fix(enhanced): report a missing expose as a build error instead of exiting (#...
  • 07a2157 chore: release v2.9.1 (#5108)
  • dc7be59 Release v2.9.0 (#5003)
  • 51ae6c3 chore: remove dead code and stale commented blocks (#4985)
  • 2120d66 refactor: reuse normalizeSharedOptions and shared createBundlerLogger (#4987)
  • 219315c chore(deps): bump nanoid from 5.1.6 to 5.1.16 in /packages/enhanced/test/conf...
  • b022032 Release v2.8.2 (#4967)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependency [@module-federation/enhanced](https://github.com/module-federation/core/tree/HEAD/packages/enhanced). These dependencies need to be updated together.


Updates `adm-zip` from 0.6.0 to 0.6.1
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.6.0...v0.6.1)

Updates `@module-federation/enhanced` from 2.8.2 to 2.9.2
- [Release notes](https://github.com/module-federation/core/releases)
- [Changelog](https://github.com/module-federation/core/blob/main/packages/enhanced/CHANGELOG.md)
- [Commits](https://github.com/module-federation/core/commits/v2.9.2/packages/enhanced)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: indirect
- dependency-name: "@module-federation/enhanced"
  dependency-version: 2.9.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@google-oss-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign ederign for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area/UI dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants