Skip to content

chore(deps): bump mime from 1.6.0 to 4.1.0 - #30

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mime-4.1.0
Open

chore(deps): bump mime from 1.6.0 to 4.1.0#30
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mime-4.1.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJul 20, 2026

Copy link
Copy Markdown

Bumps mime from 1.6.0 to 4.1.0.

Release notes

Sourced from mime's releases.

v4.1.0

4.1.0 (2025-09-12)

Features

  • enable literal type access to MIME types in Typescript (#339) (7de528d)

Bug Fixes

v4.0.7

4.0.7 (2025-04-03)

Bug Fixes

v4.0.6

4.0.6 (2024-12-17)

Bug Fixes

v4.0.5

4.0.5 (2024-12-17)

Bug Fixes

Changelog

Sourced from mime's changelog.

4.1.0 (2025-09-12)

Features

  • enable literal type access to MIME types in Typescript (#339) (7de528d)

Bug Fixes

4.0.7 (2025-04-03)

Bug Fixes

4.0.6 (2024-12-17)

Bug Fixes

4.0.5 (2024-12-17)

Bug Fixes

4.0.4 (2024-07-06)

4.0.3 (2024-04-25)

Bug Fixes

  • add types dir to package.json#files, fixes #310 (a547ca7)

4.0.2 (2024-04-24)

Bug Fixes

... (truncated)

Commits

@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 20, 2026
@dependabot@github

dependabotBot commented on behalf of githubJul 20, 2026

Copy link
Copy Markdown
Author

Assignees

The following users could not be added as assignees: @maw629. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 20, 2026
@github-actions

github-actionsBot commented Jul 20, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/mime 4.1.0🟢 3.9
Details
CheckScoreReason
Code-Review⚠️ 0Found 2/28 approved changesets -- score normalized to 0
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Packaging🟢 10packaging workflow detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/mime 1.6.0🟢 3.9
Details
CheckScoreReason
Code-Review⚠️ 0Found 2/28 approved changesets -- score normalized to 0
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Packaging🟢 10packaging workflow detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • package-lock.json

@socket-security

socket-securityBot commented Jul 20, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addedmime@​4.1.010010010081100

View full report

@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/mime-4.1.0 branch 2 times, most recently from 8727084 to 26ce69bCompareJuly 21, 2026 09:27
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/mime-4.1.0 branch 4 times, most recently from 97a627b to ee257a8CompareAugust 5, 2026 07:45
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/mime-4.1.0 branch from ee257a8 to 0d795a6CompareAugust 8, 2026 03:33
Bumps [mime](https://github.com/broofa/mime) from 1.6.0 to 4.1.0.
- [Release notes](https://github.com/broofa/mime/releases)
- [Changelog](https://github.com/broofa/mime/blob/main/CHANGELOG.md)
- [Commits](broofa/mime@v1.6.0...v4.1.0)
---
updated-dependencies:
- dependency-name: mime
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/mime-4.1.0 branch from 0d795a6 to dbda78fCompareAugust 8, 2026 09:28
@sonarqubecloud

Copy link
Copy Markdown

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants