Skip to content

build(deps): Bump @dicebear/core from 9.4.0 to 9.4.2#9

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dicebear/core-9.4.2
Open

build(deps): Bump @dicebear/core from 9.4.0 to 9.4.2#9
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dicebear/core-9.4.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 14, 2026

Bumps @dicebear/core from 9.4.0 to 9.4.2.

Commits
  • 73e2dd6 v9.4.2
  • b17dbd0 Update: CodeQL workflow to v3 and add explicit permissions
  • 2bc32fc Fix: Limit seed length in PRNG to prevent CPU exhaustion
  • 0095778 Fix: Harden converter against entity expansion and oversized metadata
  • c9e45cf Fix: Use XML parser for SVG dimension capping in converter
  • 0e4857b Add: v5-v8 deprecation note in docs
  • 8df173a v9.4.1
  • cbfe86c Update dependencies
  • af18af9 Fix: Escape XML attribute values in SVG output
  • 1cc202d Add: Query string env variables to API docs
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 14, 2026
Bumps [@dicebear/core](https://github.com/dicebear/dicebear) from 9.4.0 to 9.4.2.
- [Release notes](https://github.com/dicebear/dicebear/releases)
- [Changelog](https://github.com/dicebear/dicebear/blob/10.x/CHANGELOG.md)
- [Commits](dicebear/dicebear@v9.4.0...v9.4.2)

---
updated-dependencies:
- dependency-name: "@dicebear/core"
  dependency-version: 9.4.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/dicebear/core-9.4.2 branch from 712fb3f to 7ac70aa Compare April 14, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants