Skip to content

deps: bump tough-cookie from 5.1.2 to 6.0.1#141

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tough-cookie-6.0.1
Open

deps: bump tough-cookie from 5.1.2 to 6.0.1#141
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tough-cookie-6.0.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 21, 2026

Bumps tough-cookie from 5.1.2 to 6.0.1.

Release notes

Sourced from tough-cookie's releases.

v6.0.1

Notable

What's Changed

Full Changelog: salesforce/tough-cookie@v6.0.0...v6.0.1

v6.0.0

Summary

Breaking Changes

  • Localhost connections over http will now be considered secure by default. For more information, see the README documentation and API Docs for how to configure this feature.

Other Notable Changes

  • Dual publishing of ESM+CJS

What's Changed

... (truncated)

Commits
  • 3a4fae6 Prepare v6.0.1 (#572)
  • 1d24f0b chore(deps): bump tldts in the production-dependencies group (#573)
  • 510f5ab chore: group eslint deps in dependabot config (#563)
  • 712e2c7 Adopt npm trusted publishing (OIDC) (#571)
  • afec4e5 Fix api-documenter CRLF line endings in generated docs (#570)
  • 5d52808 chore(deps-dev): bump the dev-dependencies group with 5 updates (#560)
  • 7f3803f Review Section 5.1.1. Dates (#547)
  • f559b02 chore(deps): bump tldts in the production-dependencies group (#559)
  • b028956 chore(deps): bump rollup from 4.44.2 to 4.59.0 (#558)
  • 6123930 chore(deps-dev): bump the dev-dependencies group across 1 directory with 10 u...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for tough-cookie since your current version.


@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 21, 2026

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 21, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedtough-cookie@​5.1.2 ⏵ 6.0.19910010084100

View full report

Bumps [tough-cookie](https://github.com/salesforce/tough-cookie) from 5.1.2 to 6.0.1.
- [Release notes](https://github.com/salesforce/tough-cookie/releases)
- [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md)
- [Commits](salesforce/tough-cookie@v5.1.2...v6.0.1)

---
updated-dependencies:
- dependency-name: tough-cookie
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/tough-cookie-6.0.1 branch from d164151 to d8c5e84 Compare May 26, 2026 16:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants