Skip to content

deps(hardhat): bump the hardhat-utilities group in /hardhat with 2 updates - #180

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/hardhat/hardhat-utilities-87b5777a6f
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/hardhat/hardhat-utilities-87b5777a6f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the hardhat-utilities group in /hardhat with 2 updates: dotenv and fs-extra.

Updates dotenv from 18.0.2 to 18.0.3

Changelog

Sourced from dotenv's changelog.

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)
Commits
  • f6390d1 18.0.3
  • 456da68 changelog
  • 12ea34b Merge pull request #1059 from motdotla/config-quiet
  • a654bc2 patch DOTENV_QUIET
  • a0ae3e0 Merge pull request #1058 from SulimanAbdulrazzaq/fix/fast-parser-lone-export-...
  • d6b3a1d demonstrate DOTENV_QUIET failing
  • d57e0bc fix: keep assignments after a bare export line in the fast parser
  • See full diff in compare view

Updates fs-extra from 11.4.0 to 11.4.1

Changelog

Sourced from fs-extra's changelog.

11.4.1 / 2026-09-22

  • Properly handle read errors (e.g. due to permissions) in emptyDir*() (#1080)
  • Allow renaming with only Unicode normalization difference in the filename (APFS-specific) (#859, #1079)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the hardhat-utilities group in /hardhat with 2 updates: [dotenv](https://github.com/motdotla/dotenv) and [fs-extra](https://github.com/jprichardson/node-fs-extra).


Updates `dotenv` from 18.0.2 to 18.0.3
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v18.0.2...v18.0.3)

Updates `fs-extra` from 11.4.0 to 11.4.1
- [Changelog](https://github.com/jprichardson/node-fs-extra/blob/master/CHANGELOG.md)
- [Commits](jprichardson/node-fs-extra@11.4.0...11.4.1)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hardhat-utilities
- dependency-name: fs-extra
  dependency-version: 11.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hardhat-utilities
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, hardhat. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedfs-extra@​11.4.110010010091100
Addeddotenv@​18.0.39910010095100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants