Skip to content

WEB-818: Update all non-major dependencies - #4054

Open
renovate[bot] wants to merge 1 commit into
devfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
devfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@angular/build 20.3.32 → 20.3.37 age confidence devDependencies patch
@angular/cli 20.3.27 → 20.3.37 age confidence devDependencies patch
@angular/compiler-cli (source) 20.3.24 → 20.3.32 age confidence devDependencies patch
@angular/language-service (source) 20.3.24 → 20.3.32 age confidence devDependencies patch
@playwright/test (source) 1.62.0 → 1.63.0 age confidence devDependencies minor
@types/d3-shape (source) 3.1.8 → 3.2.0 age confidence devDependencies minor
@types/leaflet (source) 1.9.21 → 1.9.22 age confidence devDependencies patch
@types/lodash (source) 4.17.24 → 4.17.25 age confidence devDependencies patch
@types/node (source) 24.13.1 → 24.19.0 age confidence devDependencies minor
@typescript-eslint/eslint-plugin (source) 8.65.0 → 8.70.1 age confidence devDependencies minor
@typescript-eslint/parser (source) 8.65.0 → 8.70.1 age confidence devDependencies minor
actions/checkout v6.0.3 → v6.1.0 age confidence action minor
lycheeverse/lychee-action v2.8.0 → v2.9.0 age confidence action minor
node (source) 24.16.0 → 24.21.0 age confidence minor
node 24.16.0 → 24.21.0 age confidence uses-with minor
postgres (source) 18.4-alpine → 18.6-alpine age confidence minor
prettier (source) 3.9.6 → 3.9.9 age confidence devDependencies patch
prettier-plugin-multiline-arrays 4.1.10 → 4.1.11 age confidence devDependencies patch
step-security/harden-runner v2.19.4 → v2.21.1 age confidence action minor

Release Notes

angular/angular-cli (@​angular/build)

v20.3.37

Compare Source

@​angular-devkit/build-angular
Commit Type Description
c37642011e fix update undici to 7.29.1

v20.3.36

Compare Source

@​angular-devkit/build-angular
Commit Type Description
b4059cdc7 fix update less to 4.9.0
@​angular/ssr
Commit Type Description
c3e5982e4 fix ensure public directory containment in CommonEngine

v20.3.35

Compare Source

@​angular-devkit/build-angular
Commit Type Description
94b620acd7 fix update webpack-dev-server to 5.2.6

v20.3.34: 20.3.34

Compare Source

@​angular/cli
Commit Description
fix - 3962517b9 update dependency @​modelcontextprotocol/sdk to v1.30.0
@​angular-devkit/build-angular
Commit Description
fix - f348efe8b bump undici to 7.29.0

v20.3.33

Compare Source

@​angular-devkit/build-angular
Commit Type Description
0b4008f17d fix upgrade postcss to 8.5.23
@​angular/build
Commit Type Description
fc861affcd fix upgrade postcss to 8.5.23
angular/angular (@​angular/compiler-cli)

v20.3.32

Compare Source

router
Commit Type Description
ddfe21072b fix avoid dense elements allocation for numeric URL keys

v20.3.31

Compare Source

platform-server
Commit Type Description
3db26e2544 fix update domino to latest version

v20.3.30

Compare Source

platform-server
Commit Type Description
9339a7a2de fix avoid stripping unicode whitespace during url resolution
89b20568df fix update domino to latest version

v20.3.29

Compare Source

platform-browser
Commit Type Description
7538744c10 fix disallow event handler attributes in Meta

v20.3.28

Compare Source

core
Commit Type Description
2f96c8020f fix sanitize host bindings on concrete hosts
http
Commit Type Description
969133d426 fix match header values exactly when deleting
29dd26bd71 fix preserve immutability of materialized clones
e4c416c20a fix run root interceptors in the terminal request chain

v20.3.27

Compare Source

compiler
Commit Type Description
5dbcd0ee16 fix disallow i18n event attributes
db0d4a1a39 fix restrict possible event handler check to property names longer than 2 characters
http
Commit Type Description
a64e2883e9 fix distinguish repeated transfer cache params
platform-server
Commit Type Description
6f80cca0b8 fix update domino to latest version

v20.3.26

Compare Source

compiler-cli
Commit Type Description
406aaa31e6 fix update babel dependencies to latest v7
core
Commit Type Description
26831d0cbd fix avoid caching missing locale data
8eb7aea08b fix reject dynamic script host elements
http
Commit Type Description
b963f61028 fix prevent caching of responses with Set-Cookie headers
service-worker
Commit Type Description
1fdf234168 fix preserve referrer in asset requests
baa093ba68 fix preserve referrer policy in asset requests

v20.3.25

Compare Source

Deprecations

platform-server
  • XHR support in @angular/platform-server is deprecated. Use standard fetch APIs instead.
common
Commit Type Description
9f443bc24c fix Limits date format string length
566ad05f20 fix skip transfer cache for uncacheable HTTP traffic
1a62130a6b fix use cryptographically secure SHA-256 for transfer cache key generation
compiler
Commit Type Description
a68ec702a0 fix sanitize two-way properties
core
Commit Type Description
768a349e6e fix harden TransferState restoration against DOM clobbering
ca48b4728d fix validate lowercase SVG animation attribute names (#​69270)
http
Commit Type Description
06be298267 fix preserve empty referrer option in HttpRequest
fa940e1f4d fix Rejects non-HTTP(S) URLs in JSONP requests
e2ef1ce72a fix skip transfer cache for fetch credentialed requests
platform-server
Commit Type Description
49368c1859 fix harden platform location origin validation during SSR
d55c94ad81 refactor deprecate ServerXhr (#​69256)
service-worker
Commit Type Description
d65a5f457b fix Strips sensitive headers on cross-origin redirects
microsoft/playwright (@​playwright/test)

v1.63.0

Compare Source

v1.62.1

Compare Source

typescript-eslint/typescript-eslint (@​typescript-eslint/eslint-plugin)

v8.70.1

Compare Source

🩹 Fixes
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#​12904)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#​12826)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#​12747)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#​12845)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#​12880)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#​12716)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#​12873)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#​12869)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#​12850)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#​12854)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#​12818)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#​12637)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#​12768)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

🚀 Features
  • eslint-plugin: [no-generated-empty-object-type] add rule (#​12730)
🩹 Fixes
  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#​12780)
  • eslint-plugin: [no-unnecessary-condition] no false positive on RHS of a nested logical expression (#​12728)
  • eslint-plugin: [member-ordering] don't report fields that read fields declared before them (#​12729)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

🚀 Features
  • eslint-plugin: [no-misused-promises] add flagUnions option for checkConditionals (#​12603)
🩹 Fixes
  • eslint-plugin: [no-meaningless-void-operator] report void on non-call expressions (#​12727)
  • eslint-plugin: [unified-signatures] compare type parameters by constraint instead of name (#​12741)
  • eslint-plugin: [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (#​12731)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

🚀 Features
  • eslint-plugin: [strict-void-return] add fix suggestions (#​12086)
🩹 Fixes
  • eslint-plugin: [no-empty-object-type] ignore suggestions that result in invalid interfaces and export defaults (#​12739)
  • eslint-plugin: [no-floating-promises] setting ignoreVoid: false results in false negative in ArrowFunctionExpression (#​12646)
  • eslint-plugin: [no-unnecessary-type-assertion] prevent stack overflow in recursive types (#​12711)
  • eslint-plugin: [unified-signatures] report identical signatures (#​12678)
  • eslint-plugin: [return-await] prevent autofix from breaking code in arrow-functions (#​12707)
  • eslint-plugin: [unified-signatures] deduplicate types in report (#​12656)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.67.0

Compare Source

This was a version bump only for eslint-plugin to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.66.0

Compare Source

🩹 Fixes
  • eslint-plugin: [class-literal-property-style] preserve type annotations and don't drop decorators (#​12617)
  • eslint-plugin: [no-unnecessary-type-parameters] check MappedType key remapping (#​12588)
  • eslint-plugin: [no-useless-default-assignment] don't report defaults used by other overloads (#​12607)
  • eslint-plugin: [prefer-nullish-coalescing] handle shadowed Boolean calls (#​12591)
  • eslint-plugin: [no-unnecessary-type-conversion] ignore shadowed built-ins (#​12590)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

typescript-eslint/typescript-eslint (@​typescript-eslint/parser)

v8.70.1

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.67.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.66.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

actions/checkout (actions/checkout)

v6.1.0

Compare Source

lycheeverse/lychee-action (lycheeverse/lychee-action)

v2.9.0

Compare Source

Summary

This release updates the default lychee version from v0.23.0 to v0.24.2.

The main reason for this release is compatibility with the new lychee 0.24.x release artifacts. Starting with lychee v0.24.0, the archive layout changed, and the lychee binary may now be packaged inside a subdirectory. lychee-action now detects that layout automatically, so users can upgrade without changing their workflows.

If you use:

uses: lycheeverse/lychee-action@v2

you will get the new version once the floating v2 tag has been updated. If you pin exact versions, update to:

uses: lycheeverse/lychee-action@v2.9.0

What’s new from lychee v0.24.x

Better diagnostics

lychee now reports line and column numbers for detected links. This makes broken link reports easier to act on, especially in larger documentation sites or generated reports.

Text fragment checking

lychee can now check URL text fragments, such as links containing #:~:text=.... This helps catch links that point to a valid page but no longer points to the intended highlighted text.

Sitemap support

lychee can now read sitemap.xml inputs. This is useful for checking published websites or generated documentation sites where the sitemap is the easiest source of URLs to validate.

JUnit output

lychee now supports JUnit output. This makes it easier to integrate link checking results with CI systems and test reporting tools that understand JUnit XML.

Redirect and remap visibility

lychee can now show redirects and remaps more clearly. This helps explain why a URL was checked as a different final URL and makes debugging link-checking behavior easier.

Multiple config files

lychee now supports multiple configuration files and expanded config handling. This is useful for repositories that split documentation, website, or package-specific link-checking settings.

Timeout handling

lychee can now accept timeouts explicitly. This gives users more control over how strict their link checks should be for flaky or slow endpoints.

Fixes and reliability improvements

Fixed lychee 0.24.x archive compatibility

lychee-action now handles the new lychee release archive layout by detecting whether the lychee binary is inside a subdirectory.

This fixes compatibility with lychee 0.24.x.

More stable installation path

The action now installs lychee into $RUNNER_TEMP/lychee/bin instead of $HOME.

This avoids failures on runners where $HOME differs between composite action steps. In those environments, the action could add one directory to PATH but install the binary somewhere else, causing lychee: command not found.

Safer automatic lychee version updates

The workflow that checks for new lychee releases now guards against null release versions before creating update PRs. This prevents invalid automated PRs such as “Update lycheeVersion to null”.

Dependency updates
  • Updated actions/checkout from v6 to v7
  • Updated actions/cache from v5 to v6

Upstream lychee changelog

For the full lychee changelog, see:

What’s Changed

Full Changelog: lycheeverse/lychee-action@v2.8.0...v2.9.0

nodejs/node (node)

v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #​65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #​63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #​65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #​65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #​65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #​64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #​65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #​64965
Commits

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team September 28, 2026 01:57
@renovate renovate Bot added the renovate label Sep 28, 2026
@renovate

renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm warn Unknown env config "store". This will stop working in the next major version of npm. See `npm help npmrc` for supported config options.
npm error code ERESOLVE
npm error ERESOLVE unable to resolve dependency tree
npm error
npm error While resolving: mifosx-web-app@1.0.0
npm error Found: @angular/compiler@20.3.24
npm error node_modules/@angular/compiler
npm error   @angular/compiler@"20.3.24" from the root project
npm error   peer @angular/compiler@"20.3.24" from @angular/localize@20.3.24
npm error   node_modules/@angular/localize
npm error     @angular/localize@"20.3.24" from the root project
npm error
npm error Could not resolve dependency:
npm error peer @angular/compiler@"20.3.32" from @angular/compiler-cli@20.3.32
npm error node_modules/@angular/compiler-cli
npm error   dev @angular/compiler-cli@"20.3.32" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry this command with --force or --legacy-peer-deps to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /runner/cache/others/npm/_logs/2026-09-28T01_56_49_095Z-eresolve-report.txt
npm error A complete log of this run can be found in: /runner/cache/others/npm/_logs/2026-09-28T01_56_49_095Z-debug-0.log

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants