Repository navigation
chore(deps): update all non-major dependencies - #1865
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
commit: |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
8 times, most recently
from
July 19, 2026 20:13
232aecb to
49015bf
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
13 times, most recently
from
July 27, 2026 23:52
4da8fab to
01cba3e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
July 30, 2026 07:13
1fc29b1 to
b48d04c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
13 times, most recently
from
August 12, 2026 04:51
bb3f0cd to
99e0ed3
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
7 times, most recently
from
August 19, 2026 21:40
b49c770 to
c35bde9
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
9 times, most recently
from
August 26, 2026 22:49
8e21c06 to
fbbaa48
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^7.29.7→^7.29.9^8.0.2→^8.2.3^3.5.38→^3.5.43v2.0.1→v2.5.0^8.17.0→^8.19.0v7.0.0→v7.0.1v0.1.1→v0.2.06.0.0→6.0.2^5.24.0→^5.26.09.39.4→9.39.5^4.16.2→^4.17.1^10.9.2→^10.11.1^1.0.8→^1.1.3^17.6.0→^17.13.016.2.0→16.2.4^20.10.6→^20.14.56.17.1→6.39.06.40.0^1.1.0→^1.4.3^0.6.7→^0.6.10^2.0.11→^2.0.12^2.3.1→^2.3.31.61.0→1.63.010.34.4→10.34.6^4.62.2→^4.64.04.64.1^4.1.0→^4.3.04.1.0→4.3.0^5.48.0→^5.51.2^8.61.1→^8.71.1~7.3.5→~7.3.7~7.3.5→~7.3.7^2.2.0→^2.4.0Release Notes
babel/babel (@babel/plugin-transform-typescript)
v7.29.9Compare Source
v7.29.9 (2026-09-18)
🐛 Bug Fix
babel-plugin-transform-typescriptenuminto anamespace(@nicolo-ribaudo)babel-parser🏠 Internal
babel-parserCommitters: 4
vitejs/vite (@vitejs/plugin-legacy)
v8.2.3Bug Fixes
sharedPlugins: true(#23184) (15f0307)v8.2.2Compare Source
Features
Bug Fixes
v8.2.1Compare Source
Bug Fixes
v8.2.0Compare Source
Features
Bug Fixes
Code Refactoring
babel-plugin-polyfill-*consistently (#22874) (9dddae6)v8.1.0Compare Source
Features
Bug Fixes
Miscellaneous Chores
Code Refactoring
Beta Changelogs
8.1.0-beta.0 (2026-06-15)
See 8.1.0-beta.0 changelog
vuejs/core (@vue/reactivity)
v3.5.43Compare Source
Bug Fixes
v3.5.42Compare Source
Bug Fixes
v3.5.41Compare Source
Bug Fixes
v3.5.40Compare Source
Bug Fixes
v3.5.39Compare Source
Bug Fixes
MatteoGabriele/agentscan-action (MatteoGabriele/agentscan-action)
v2.5.0Compare Source
Identity update:
Full Changelog: MatteoGabriele/agentscan-action@v2.4.0...v2.5.0
v2.4.0Compare Source
What's Changed
New Contributors
Full Changelog: MatteoGabriele/agentscan-action@v2.3.0...v2.4.0
v2.3.0Compare Source
What's Changed
Full Changelog: MatteoGabriele/agentscan-action@v2.2.0...v2.3.0
v2.2.0Compare Source
What's Changed
Full Changelog: MatteoGabriele/agentscan-action@v2.1.0...v2.2.0
v2.1.0Compare Source
What's Changed
Full Changelog: MatteoGabriele/agentscan-action@v2.0.1...v2.1.0
acornjs/acorn (acorn)
v8.19.0Compare Source
v8.18.0Compare Source
actions/checkout (actions/checkout)
v7.0.1Compare Source
danielroe/provenance-action (danielroe/provenance-action)
v0.2.0Compare Source
compare changes
🚀 Enhancements
📖 Documentation
🏡 Chore
✅ Tests
🤖 CI
❤️ Contributors
sveltejs/devalue (devalue)
v6.0.2Compare Source
Patch Changes
12ad9d6: chore: remove dts-buddyv6.0.1Compare Source
Patch Changes
c13cf6a: fix: populateerror.pathfor values reached through a promise instringifyAsync6156b2e: perf:stringifyandunevalskip per-character escaping for strings with nothing to escapee7a9a73: fix: throwInvalid inputinstead of a rawTypeErrorfor malformed typed array and boxed primitive payloads6156b2e: perf: only format path when an error is raised6156b2e: perf: cache quoted property names9e44253: Fixunevalfor typed array views whose backing buffer ends with a partial elementwebpack/enhanced-resolve (enhanced-resolve)
v5.26.0Compare Source
Minor Changes
Add experimental support for Node.js package maps through a new
packageMapoption, which takes the path of the configuration file (or afile:URL) or an already-parsedpackagesobject. When it is set, a bare specifier is resolved through the importing package'sdependenciestable and the target package's location is handed to the regular pipeline, instead of walkingnode_modules; relative and absolute requests andnode:builtins are unaffected. Because several package entries may share oneurl, the package a request resolved into is exposed aspackageIdon the result and can be passed back in ascontext.packageIdto resolve from that package unambiguously. Package maps are stability 1 (experimental) in Node.js, and this option tracks that specification and may change with it. (by @alexander-akait in #667)Explain an
exports/importsfield whose conditions wrap subpaths, instead of failing with a message that points at the request. A field shaped like{ "import": { ".": "./esm/index.js", "./*": "./esm/*.js" }, "require": "./build/bundle.js" }is not supported by Node.js: the subpaths inside a condition are read as condition names, so they match nothing, and every request into the package failed as"./foo" is not exported under the conditions [...]— which reads as though the package forgot to export./foo. Such a failure now names the offending keys and shows the arrangement that works, with the subpaths at the top level and the conditions nested inside them. Resolution itself is unchanged: the diagnosis runs only on a request that has already failed, so nothing that resolves today starts failing, and a successful resolve does no extra work. Errors raised while processing either field also name thepackage.jsonthey came from, which previously only appeared in the resolver log. (by @alexander-akait in #676)Generate the published type declarations with TypeScript instead of
webpack/tooling, which is no longer a dependency. Every name the package exported before is still exported, andtypes.d.tsis still the entry point, but the declarations themselves now live intypes/and are emitted bytscfrom the JSDoc inlib/. Two shapes follow the sources more closely than the previous generator did: the object form ofPluginno longer declaresthis: Resolveronapply(it is called asplugin.apply(resolver), sothisis the plugin), and the entries ofResolveContext.stackdeclarename: string | undefinedrather than an optionalname. Class fields that the old generator dropped, such as the cache backends onCachedInputFileSystem, are now part of the declarations. (by @alexander-akait in #675)Patch Changes
getPathsCachedkeeps to what they actually hold: apush-built store keeps room for 17 entries while a path has a handful, and the cache holds these for the filesystem's lifetime. (by @alexander-akait in #681)v5.25.1Compare Source
Patch Changes
file:URL the way Node does when parsing a request. (by @alexander-akait in #670)v5.25.0Compare Source
Minor Changes
file:URL strings wherever an option or the context path takes a path. (by @alexander-akait in #668)v5.24.5Compare Source
Patch Changes
extendspaths relative. (by @xiaoxiaojx in #645)v5.24.4Compare Source
Patch Changes
Keep the original request resolvable when
extensionAliaslists its own extension. (by @alexander-akait in #641)Fix string
restrictionsboundary checks: a restriction ending with a separator no longer rejects everything inside it, restrictions are normalized before they are compared, and a Windows path now matches the waypath.win32does, treating/and\as interchangeable and comparing case-insensitively, while\stays a filename character in a posix path. The same comparison backstsconfigpath matching. (by @alexander-akait in #643)Treat a UNC path (
\\server\share\…) as a Windows path, so it normalizes, joins and walks up withpath.win32semantics instead of being taken for a bare module request. (by @alexander-akait in #644)v5.24.3Compare Source
Patch Changes
extendspackage specifiers from ancestor node_modules directories (workspace hoisting). (by @alexander-akait in #631)v5.24.2Compare Source
Patch Changes
v5.24.1Compare Source
Patch Changes
eslint/eslint (eslint)
v9.39.5Compare Source
Bug Fixes
253be16fix: handle unavailable require cache (backport of #20812 to v9.x) (#21065) (Eric)Documentation
74930eddocs: switch build to Node.js 24 (#20894) (Milos Djermanovic)eaec8bbdocs: Add ESLint v9.x EOL notice (#20828) (Milos Djermanovic)Chores
458205fchore: update@eslint/eslintrcand@eslint/jsfor v9.39.5 (#21077) (Francesco Trotta)202117bchore: package.json update for @eslint/js release (Jenkins)d9eb6edtest: disable warning forvm.constants.USE_MAIN_CONTEXT_DEFAULT_LOADER(#21074) (Francesco Trotta)7b431a7chore: overridere2dependency for@metascraper/helpers(#21068) (Milos Djermanovic)daf7791chore: pin fflate@0.8.2 (#20895) (Milos Djermanovic)daee8baci: use pnpm ineslint-flat-config-utilstype integration test (#20829) (Milos Djermanovic)116d4beci: unpin Node.js 25.x in CI (#20619) (Copilot)un-ts/eslint-plugin-import-x (eslint-plugin-import-x)
v4.17.1Compare Source
Patch Changes
cf25a01Thanks @marcalexiei! - fix(extensions): don't require an extension forConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.