Skip to content

chore(deps-dev): Bump @cyclonedx/cyclonedx-npm from 4.1.2 to 4.2.1#725

Merged
bheisig merged 1 commit intomainfrom
dependabot/npm_and_yarn/cyclonedx/cyclonedx-npm-4.2.1
Mar 9, 2026
Merged

chore(deps-dev): Bump @cyclonedx/cyclonedx-npm from 4.1.2 to 4.2.1#725
bheisig merged 1 commit intomainfrom
dependabot/npm_and_yarn/cyclonedx/cyclonedx-npm-4.2.1

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 9, 2026

Bumps @cyclonedx/cyclonedx-npm from 4.1.2 to 4.2.1.

Release notes

Sourced from @​cyclonedx/cyclonedx-npm's releases.

4.2.1

Fixed

  • Properly generate PackageURLs for private packages (#1425 via #1426)

#1425: CycloneDX/cyclonedx-node-npm#1425 #1426: CycloneDX/cyclonedx-node-npm#1426


What's Changed

Full Changelog: CycloneDX/cyclonedx-node-npm@v4.2.0...v4.2.1

4.2.0

Fixed

  • Qualified PackageURLs (via #1416)

Changed

  • Take care of PackageURL generation ourselves, now (via #1416)
    Previously, this was done at best-effort by a 3rd-party library.

Dependencies

  • Bumped dependency @cyclonedx/cyclonedx-library@^10.0.0 now, was @^8.4.0||^9.0.0 (via #1416)
  • Added dependency packageurl-js@^2.0.1 (via #1416)
  • Added dependency spdx-expression-parse@^3.0.1||^4.0.0 (via #1416)

#1416: CycloneDX/cyclonedx-node-npm#1416


What's Changed

Full Changelog: CycloneDX/cyclonedx-node-npm@v4.1.2...v4.2.0

Changelog

Sourced from @​cyclonedx/cyclonedx-npm's changelog.

4.2.1 - 2026-03-00

  • Fixed
    • Properly generate PackageURLs for private packages (#1425 via #1426)

#1425: CycloneDX/cyclonedx-node-npm#1425 #1426: CycloneDX/cyclonedx-node-npm#1426

4.2.0 - 2026-03-03

  • Fixed
    • Qualified PackageURLs (via #1416)
  • Changed
    • Take care of PackageURL generation ourselves, now (via #1416)
      Previously, this was done at best-effort by a 3rd-party library.
  • Dependencies
    • Bumped dependency @cyclonedx/cyclonedx-library@^10.0.0 now, was @^8.4.0||^9.0.0 (via #1416)
    • Added dependency packageurl-js@^2.0.1 (via #1416)
    • Added dependency spdx-expression-parse@^3.0.1||^4.0.0 (via #1416)

#1416: CycloneDX/cyclonedx-node-npm#1416

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​cyclonedx/cyclonedx-npm since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@cyclonedx/cyclonedx-npm](https://github.com/CycloneDX/cyclonedx-node-npm) from 4.1.2 to 4.2.1.
- [Release notes](https://github.com/CycloneDX/cyclonedx-node-npm/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-node-npm/blob/main/HISTORY.md)
- [Commits](CycloneDX/cyclonedx-node-npm@v4.1.2...v4.2.1)

---
updated-dependencies:
- dependency-name: "@cyclonedx/cyclonedx-npm"
  dependency-version: 4.2.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner March 9, 2026 16:05
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 9, 2026
@bheisig bheisig merged commit c1c951b into main Mar 9, 2026
12 checks passed
@bheisig bheisig deleted the dependabot/npm_and_yarn/cyclonedx/cyclonedx-npm-4.2.1 branch March 9, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant