Skip to content

fix(lambda): bump cron-parser from 5.3.0 to 5.3.1 in /lambdas#4744

Merged
npalm merged 1 commit intomainfrom
dependabot/npm_and_yarn/lambdas/cron-parser-5.3.1
Sep 3, 2025
Merged

fix(lambda): bump cron-parser from 5.3.0 to 5.3.1 in /lambdas#4744
npalm merged 1 commit intomainfrom
dependabot/npm_and_yarn/lambdas/cron-parser-5.3.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Sep 2, 2025

Bumps cron-parser from 5.3.0 to 5.3.1.

Release notes

Sourced from cron-parser's releases.

v5.3.1

What's Changed

Full Changelog: harrisiirak/cron-parser@v5.3.0...v5.3.1

Commits
  • a8267e2 Bump version
  • 1c32a84 Update luxon to the latest version
  • 5f41fbf Include pre-defined hashSeed for benchmark runs
  • 4b16aa9 CronFieldCollection.from should allow passing in special chars (#387)
  • d88c64c Fix invalid start and end time span validation logic (#386)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cron-parser](https://github.com/harrisiirak/cron-parser) from 5.3.0 to 5.3.1.
- [Release notes](https://github.com/harrisiirak/cron-parser/releases)
- [Commits](harrisiirak/cron-parser@v5.3.0...v5.3.1)

---
updated-dependencies:
- dependency-name: cron-parser
  dependency-version: 5.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 2, 2025
@dependabot dependabot Bot requested a review from a team as a code owner September 2, 2025 14:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 2, 2025
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Sep 2, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/cron-parser ^5.3.1 🟢 4.1
Details
CheckScoreReason
Maintained🟢 95 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 9
Code-Review⚠️ 1Found 5/30 approved changesets -- score normalized to 1
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities🟢 64 existing vulnerabilities detected
npm/cron-parser ^5.3.1 🟢 4.1
Details
CheckScoreReason
Maintained🟢 95 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 9
Code-Review⚠️ 1Found 5/30 approved changesets -- score normalized to 1
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities🟢 64 existing vulnerabilities detected
npm/cron-parser 5.3.1 🟢 4.1
Details
CheckScoreReason
Maintained🟢 95 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 9
Code-Review⚠️ 1Found 5/30 approved changesets -- score normalized to 1
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities🟢 64 existing vulnerabilities detected

Scanned Files

  • lambdas/functions/ami-housekeeper/package.json
  • lambdas/functions/control-plane/package.json
  • lambdas/yarn.lock

@npalm npalm merged commit 6ea4bca into main Sep 3, 2025
6 checks passed
@npalm npalm deleted the dependabot/npm_and_yarn/lambdas/cron-parser-5.3.1 branch September 3, 2025 20:09
npalm pushed a commit that referenced this pull request Sep 4, 2025
🤖 I have created a release *beep* *boop*
---


##
[6.7.6](v6.7.5...v6.7.6)
(2025-09-04)


### Bug Fixes

* **lambda:** bump @octokit/auth-app from 8.0.2 to 8.1.0 in /lambdas in
the octokit group
([#4740](#4740))
([6f2e4b1](6f2e4b1))
* **lambda:** bump cron-parser from 5.3.0 to 5.3.1 in /lambdas
([#4744](#4744))
([6ea4bca](6ea4bca))
* **lambda:** bump the aws group in /lambdas with 6 updates
([#4739](#4739))
([7639ceb](7639ceb))
* **lambda:** bump the aws-powertools group in /lambdas with 4 updates
([#4743](#4743))
([4997f31](4997f31))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
LudovicTOURMAN pushed a commit to doctolib-lab/terraform-aws-github-runner that referenced this pull request Apr 7, 2026
…-aws-runners#4744)

Bumps [cron-parser](https://github.com/harrisiirak/cron-parser) from
5.3.0 to 5.3.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/harrisiirak/cron-parser/releases">cron-parser's
releases</a>.</em></p>
<blockquote>
<h2>v5.3.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Fix invalid start and end time span validation logic by <a
href="https://github.com/harrisiirak"><code>@​harrisiirak</code></a> in
<a
href="https://redirect.github.com/harrisiirak/cron-parser/pull/386">harrisiirak/cron-parser#386</a></li>
<li>CronFieldCollection.from should allow passing in special chars by <a
href="https://github.com/harrisiirak"><code>@​harrisiirak</code></a> in
<a
href="https://redirect.github.com/harrisiirak/cron-parser/pull/387">harrisiirak/cron-parser#387</a></li>
<li>Update luxon to the latest version
1c32a8498cd71a8eaa8bc114754a6470f08b6305</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/harrisiirak/cron-parser/compare/v5.3.0...v5.3.1">https://github.com/harrisiirak/cron-parser/compare/v5.3.0...v5.3.1</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/harrisiirak/cron-parser/commit/a8267e25fba5a545aea05c392c9f86f7d83b7124"><code>a8267e2</code></a>
Bump version</li>
<li><a
href="https://github.com/harrisiirak/cron-parser/commit/1c32a8498cd71a8eaa8bc114754a6470f08b6305"><code>1c32a84</code></a>
Update luxon to the latest version</li>
<li><a
href="https://github.com/harrisiirak/cron-parser/commit/5f41fbf37fda34c8f0ad4288a42b7a3ddb328ec9"><code>5f41fbf</code></a>
Include pre-defined hashSeed for benchmark runs</li>
<li><a
href="https://github.com/harrisiirak/cron-parser/commit/4b16aa93ca387fa0efff8a22b35a33470744b755"><code>4b16aa9</code></a>
CronFieldCollection.from should allow passing in special chars (<a
href="https://redirect.github.com/harrisiirak/cron-parser/issues/387">#387</a>)</li>
<li><a
href="https://github.com/harrisiirak/cron-parser/commit/d88c64c7e256535615310fd866bddc0a1bd42998"><code>d88c64c</code></a>
Fix invalid start and end time span validation logic (<a
href="https://redirect.github.com/harrisiirak/cron-parser/issues/386">#386</a>)</li>
<li>See full diff in <a
href="https://github.com/harrisiirak/cron-parser/compare/v5.3.0...v5.3.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cron-parser&package-manager=npm_and_yarn&previous-version=5.3.0&new-version=5.3.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
LudovicTOURMAN pushed a commit to doctolib-lab/terraform-aws-github-runner that referenced this pull request Apr 7, 2026
🤖 I have created a release *beep* *boop*
---


##
[6.7.6](github-aws-runners/terraform-aws-github-runner@v6.7.5...v6.7.6)
(2025-09-04)


### Bug Fixes

* **lambda:** bump @octokit/auth-app from 8.0.2 to 8.1.0 in /lambdas in
the octokit group
([github-aws-runners#4740](github-aws-runners#4740))
([6f2e4b1](github-aws-runners@6f2e4b1))
* **lambda:** bump cron-parser from 5.3.0 to 5.3.1 in /lambdas
([github-aws-runners#4744](github-aws-runners#4744))
([6ea4bca](github-aws-runners@6ea4bca))
* **lambda:** bump the aws group in /lambdas with 6 updates
([github-aws-runners#4739](github-aws-runners#4739))
([7639ceb](github-aws-runners@7639ceb))
* **lambda:** bump the aws-powertools group in /lambdas with 4 updates
([github-aws-runners#4743](github-aws-runners#4743))
([4997f31](github-aws-runners@4997f31))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant