chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1 - #20

Merged
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1
Aug 11, 2026
Merged

chore(deps): Bump lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1#20
notheotherben merged 1 commit into
mainfrom
dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps lumaxis/shellcheck-problem-matchers from 2.1.0 to 2.3.1.

Release notes

Sourced from lumaxis/shellcheck-problem-matchers's releases.

v2.3.1

What's Changed

Patch release. No functional changeindex.js, action.yml and all matcher behaviour are identical to v2.3.0. No workflow changes are required.

Regenerates package-lock.json against https://registry.npmjs.org/. The v2.3.0 lockfile was generated on a machine configured against a Microsoft package-feed proxy, so 71 of its resolved URLs pointed at ms-feed-*.pkgs.visualstudio.com instead of the public npm registry. Those feeds are publicly readable so installs still worked, but a public project's lockfile shouldn't route contributors' installs through a third-party mirror.

This affects contributors only. The action has no runtime dependencies — action.yml runs index.js directly — so users of the action were never impacted.

The dependency graph is unchanged: same 71 packages, same versions.

Runner requirement (unchanged)

node24 requires Actions runner v2.327.1 or newer.

Full Changelog: lumaxis/shellcheck-problem-matchers@v2.3.0...v2.3.1

v2.3.0

What's Changed

Internal cleanup release. No workflow changes are required — the format input and all matcher behaviour are unchanged.

The action is now dependency-free

@actions/core was the only runtime dependency, and it was used for exactly two calls (getInput and setFailed). Both are now inlined with plain Node, leaving path (a builtin) as the only require.

That let us delete the dist/ bundle entirely — the action runs index.js directly from the repository root. This also fixes a long-standing problem: the bundler (@zeit/ncc) had been broken since Node 17 (ERR_OSSL_EVP_UNSUPPORTED), so dist/ had not been rebuilt since March 2023 and dependency updates never actually reached users.

Security

npm audit goes from 8 vulnerabilities to 0, and all open Dependabot alerts are cleared. Dependency count dropped from 103 packages to 72.

Also in this release

  • Migrated to ESLint 10 with flat config
  • CI now runs actions/checkout@v7 and actions/setup-node@v7 pinned to Node 24

... (truncated)

Commits
  • bf6e086 Regenerate package-lock.json against the public npm registry (#148)
  • 76712f8 Migrate to ESLint 9+ flat config and upgrade to ESLint 10 (#147)
  • 492adb6 Drop @​actions/core and remove the dist/ bundle (#145)
  • e29d580 Modernize CI action versions and fix README badge (#144)
  • 0a0e558 Fix typo in test fixture filename (#143)
  • 321c8e1 Merge pull request #138 from jrfnl/feature/update-to-node-24
  • 1a8d8cc Merge pull request #137 from lumaxis/dependabot/github_actions/actions-0bd136...
  • 6952dba Update from Node 16 to Node 24
  • b8b24a0 Bump actions/checkout in the actions group across 1 directory
  • 54048fb Merge pull request #131 from lumaxis/dependabot/npm_and_yarn/dev-dependencies...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lumaxis/shellcheck-problem-matchers](https://github.com/lumaxis/shellcheck-problem-matchers) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/lumaxis/shellcheck-problem-matchers/releases)
- [Commits](lumaxis/shellcheck-problem-matchers@v2.1.0...v2.3.1)
---
updated-dependencies:
- dependency-name: lumaxis/shellcheck-problem-matchers
dependency-version: 2.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@notheotherben
notheotherben merged commit ae5e063 into mainAug 11, 2026
5 checks passed

@automate-by-sierra-softworksautomate-by-sierra-softworksBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically approved because it was raised by a trusted account.

@dependabot
dependabotBot deleted the dependabot/github_actions/lumaxis/shellcheck-problem-matchers-2.3.1 branch August 11, 2026 19:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@notheotherben