chore(deps): update web-ui npm dependencies#153
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
12 times, most recently
from
February 16, 2026 10:59
36d3c59 to
41ba948
Compare
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
9 times, most recently
from
February 23, 2026 17:55
5975b4e to
0fa3bc0
Compare
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
6 times, most recently
from
March 1, 2026 21:38
661c2c2 to
37b0d6e
Compare
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
2 times, most recently
from
March 4, 2026 09:19
69f1c7f to
e15388b
Compare
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
6 times, most recently
from
March 17, 2026 13:39
ac3394f to
86f1e16
Compare
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
17 times, most recently
from
March 25, 2026 13:54
81e353d to
0452fcb
Compare
renovate
Bot
force-pushed
the
renovate/web-ui-npm-dependencies
branch
6 times, most recently
from
March 27, 2026 01:43
0775102 to
51b29a0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
9.39.2→9.39.51.9.0→1.9.1^0.56.0→^0.65.0^0.211.0→^0.221.02.5.0→2.10.01.39.0→1.43.08.14.0→8.20.25.90.20→5.101.424.10.10→24.13.319.2.10→19.2.175.1.3→5.2.03.33.1→3.34.04.1.0→4.4.09.39.2→9.39.57.0.1→7.1.10.5.0→0.5.317.3.0→17.7.025.8.1→25.10.108.2.0→8.2.128.0.0→28.1.02.12.8→2.15.019.2.4→19.2.819.2.4→19.2.816.5.4→16.6.68.14.0→8.20.27.13.0→7.18.13.7.0→3.10.01.97.3→1.101.38.54.0→8.65.01.2.0→1.3.07.4.0→7.4.17.4.0→7.4.1Release Notes
eslint/eslint (@eslint/js)
v9.39.5Compare Source
Bug Fixes
253be16fix: handle unavailable require cache (backport of #20812 to v9.x) (#21065) (Eric)Documentation
74930eddocs: switch build to Node.js 24 (#20894) (Milos Djermanovic)eaec8bbdocs: Add ESLint v9.x EOL notice (#20828) (Milos Djermanovic)Chores
458205fchore: update@eslint/eslintrcand@eslint/jsfor v9.39.5 (#21077) (Francesco Trotta)202117bchore: package.json update for @eslint/js release (Jenkins)d9eb6edtest: disable warning forvm.constants.USE_MAIN_CONTEXT_DEFAULT_LOADER(#21074) (Francesco Trotta)7b431a7chore: overridere2dependency for@metascraper/helpers(#21068) (Milos Djermanovic)daf7791chore: pin fflate@0.8.2 (#20895) (Milos Djermanovic)daee8baci: use pnpm ineslint-flat-config-utilstype integration test (#20829) (Milos Djermanovic)116d4beci: unpin Node.js 25.x in CI (#20619) (Copilot)v9.39.4Compare Source
Bug Fixes
f18f6c8fix: update dependency minimatch to ^3.1.5 (#20564) (Milos Djermanovic)a3c868ffix: update dependency @eslint/eslintrc to ^3.3.4 (#20554) (Milos Djermanovic)234d005fix: minimatch security vulnerability patch for v9.x (#20549) (Andrej Beles)b1b37eefix: updateajvto6.14.0to address security vulnerabilities (#20538) (루밀LuMir)Documentation
4675152docs: add deprecation notice partial (#20520) (Milos Djermanovic)Chores
b8b4eb1chore: update dependencies for ESLint v9.39.4 (#20596) (Francesco Trotta)71b2f6bchore: package.json update for @eslint/js release (Jenkins)1d16c2fci: pin Node.js 25.6.1 (#20563) (Milos Djermanovic)v9.39.3Compare Source
Bug Fixes
791bf8dfix: restore TypeScript 4.0 compatibility in types (#20504) (sethamus)Chores
8594a43chore: upgrade @eslint/js@9.39.3 (#20529) (Milos Djermanovic)9ceef92chore: package.json update for @eslint/js release (Jenkins)af498c6chore: ignore/docs/v9.xin link checker (#20453) (Milos Djermanovic)open-telemetry/opentelemetry-js (@opentelemetry/api)
v1.9.1Compare Source
🐛 (Bug Fix)
#3562 @scheler
🏠 (Internal)
open-telemetry/opentelemetry-js-contrib (@opentelemetry/auto-instrumentations-web)
v0.65.0Compare Source
Features
Dependencies
v0.64.0Compare Source
Features
Dependencies
v0.63.0Compare Source
Features
Dependencies
v0.62.0Compare Source
Features
Dependencies
v0.61.0Compare Source
Features
Dependencies
v0.60.0Compare Source
Features
Dependencies
v0.59.0Compare Source
Features
Dependencies
v0.58.0Compare Source
Features
Dependencies
v0.57.0Compare Source
Features
Dependencies
react-querybuilder/react-querybuilder (@react-querybuilder/bootstrap)
v8.20.2Compare Source
Added
@react-querybuilder/datetime/uientry point containing all React components and utilities (QueryBuilderDateTime,RelativeDateTimeValueEditor, the relative-date mode controllers, etc.).Changed
@react-querybuilder/datetime/uiinstead of the package root. The root and per-library entry points (/dayjs,/date-fns,/jsdate,/luxon) no longer importreactorreact-querybuilder, so their rule/value processors can be used in non-React/server environments. (reactandreact-querybuilderare now optional peer dependencies;@react-querybuilder/coreis required.)QueryBuilderDateTimenow uses the native JavaScriptDateAPI by default instead ofdayjs. Override with thedateTimeAPIprop.Fixed
dayjsto an optional peer dependency for@react-querybuilder/datetime. It was accidentally made a direct dependency in v8.19.0.v8.20.1Compare Source
Added
v8.20.0Compare Source
Added
queryBuilder-responsiveclass, now included in the default stylesheet. Apply it via thecontrolClassnamesprop (or to any ancestor element) to let rule and group header rows wrap onto multiple lines—with a hanging indent for the wrapped content—instead of overflowing when horizontal space runs short. No media or container queries are involved, so the layout reflows based on the actual available width, even for deeply nested groups. These styles are intentionally minimal and only lightly opinionated; think of them as a convenient starting point for responsive behavior rather than a canonical or prescribed approach, and feel free to override or replace them to suit your design.dragHandleAttributesprop on theDragHandlecomponent. The@dnd-kitadapter uses it to pass drag-handle ARIA attributes and sensor listeners through as JSX props; itsuseRuleDnD/useRuleGroupDnDhooks now return adragHandleAttributesobject.Changed
@dnd-kitadapter now applies drag-handle ARIA attributes and sensor listeners as JSX props (viadragHandleAttributes) instead of through imperative DOM manipulation. CustomdragHandlecomponents used with the dnd-kit adapter must now spreaddragHandleAttributesonto their root element to remain draggable. Disabled rule groups now expose drag-handle ARIA attributes (without activator listeners).Fixed
useAsyncOptionListno longer recomputes cache validity during render or includes it in its effect dependencies, avoiding redundant option-list refetches when a cached entry expires (cache TTL is still enforced by the loader).v8.19.1Compare Source
Added
showBranchesprop onRulesEngineBuilder, with accompanying styles.showShiftActionsprop onRulesEngineBuilder, with accompanying component and styles.RulesEngineBuilderconsequent types can now define editableproperties. When aconsequentTypesoption carries apropertiesarray (ConsequentPropertyDef[]), the built-inConsequentBuilderBodyrenders an input ("text","textarea","number","checkbox", or"select") for each one, storing the values on the consequent underparams[name]. New types:ConsequentTypeOption,FullConsequentTypeOption,ConsequentPropertyDef, andConsequentPropertyInputType.addConsequentToNewConditionsprop onRulesEngineBuilder. Whentrue, newly added conditions are seeded with a consequent of the default consequent type for that condition.Fixed
RulesEngineBuilder, the top-level "Add condition" button is not hidden whenallowNestedConditionsisfalse.v8.19.0Compare Source
Added
@react-querybuilder/datetime.RelativeDateTimeValueEditorcomponent. Relative mode edits a structured value (anchor + signed offset + unit, e.g. "3 months ago" or "start of year"); absolute values remain plain ISO 8601 strings for backward compatibility.RelativeDateTimeModeController. Ships withtoggleModeController(the zero-config default absolute/relative toggle button) and an operator-driven option built withcreateOperatorModeController+withRelativeOperators(the operator selector chooses the mode, no toggle rendered). Operator-driven values export via thecontext.relativeOperatorMapoption, which maps mode-signaling operator names to real comparison operators at format time.between/notBetweenoperators render two independent bounds, each individually absolute or relative (mixable), stored as a two-element array.QueryBuilderDateTimenow renders the relative-capable editor for date/datetime fields. Non-date fields delegate to the surrounding compatibility/theme value editor (falling back to the standard editor), and that themed editor is also used for the absolute date input and the relative offset input.dateTimeAPIprop onQueryBuilderDateTime(typeRQBDateTimeLibraryAPI, default Day.js adapter) controls how the absolute date editor parses and validates input. Pass the adapter matching your export processor (Luxon, date-fns, nativeDate, etc.) to keep editor parsing and export consistent.formatQueryrule processors handle relative values: SQL emits live, dialect-specific symbolic expressions and JsonLogic stays live via adateRelativeoperation, while other formats materialize to ISO strings. NewcontextoptionsmaterializeRelativeDateTime(force materialization for all formats) andrelativeDateTimeBase(pin "now" for deterministic output).Dateobjects for ORM formats) andbetween/notBetweenbounds are reordered chronologically.RQBDateTimeLibraryAPIgainsstartOf,endOf, andaddmethods (implemented for the Day.js, date-fns, Luxon, and JS Date plugins).QueryBuilderDateTimefor interactive relative editing.@react-querybuilder/rules-engine:@react-querybuilder/rules-engine). A newevaluationModeproperty (typeEvaluationMode, i.e."cascade" | "cumulative") can be set onRulesEngine/RulesEngineICobjects, or passed as aformatRulesEngineoption to override the object-level value at export time. Defaults to"cascade"."cascade": conditions are evaluated in order; a later sibling only fires if all prior siblings' antecedents failed (if/else-if/else semantics)."cumulative": every condition is evaluated independently and any number may fire.RulesEngineBuilderrenders an evaluation mode toggle in its header, configurable via newevaluationMode,evaluationModeCascade, andevaluationModeCumulativetranslation keys and anevaluationModeclassname.RulesEngineBuilderlabels condition headers "When" and the default consequent "Always" (instead of "If"/"Else If"/"Else"). New translation keysblockLabelWhen/blockLabelAlwaysand standard classesblockLabel-when/blockLabel-always."json-rules-engine"export (@react-querybuilder/rules-engine).formatRulesEngine(re, 'json-rules-engine')now supports the React Query Builder operators thatjson-rules-enginehas no built-in equivalent for, via supplemental evaluators exported asjsonRulesEngineAdditionalOperators:beginsWith/doesNotBeginWith,endsWith/doesNotEndWith,contains/doesNotContain(mapped tocontainsGeneric/doesNotContainGenericto bypass the built-in array-onlycontains), andbetween/notBetween.between/notBetweenmirrorformatQuery's robustness: bounds may be an array ([lo, hi]) or a comma-separated string ("lo,hi"), and numeric bounds are parsed and reordered ascending.contextoption forformatRulesEngine. For the"json-rules-engine"format, passingcontext: { engine }registers every additional operator on theEngineas a side effect, so exported rules that use them run without manualengine.addOperator(...)calls.formatRulesEngineexport targets for the rules engine (@react-querybuilder/rules-engine):"native","node-rules", and"rulepilot"(joining the existing"json-rules-engine")."native"returns a dependency-free in-processRulesEngineEvaluator—(facts) => Consequent[]—that yields the consequents of every condition that fires, in order, honoring theevaluationMode."node-rules"returns an array of live node-rulesRuleobjects (with realcondition/consequencefunctions) ready to pass tonew RuleEngine(...). Antecedents reuse the"native"predicates, so evaluation needs no operator registration, and each fired consequent is pushed ontofact.events(mirroring the"json-rules-engine"result shape)."rulepilot"returns a single rulepilotRule. BecauseRulePilot.evaluatereturns a single (first-matched) result, this target models single-outcome decisioning: nested or overlapping conditions that would fire multiple consequents under the other targets yield only the first match, cumulative evaluation mode throws, and the substring operators (contains/beginsWith/endsWithand their negations) are omitted as they have no faithful mapping. Evaluate withRulePilot.evaluate(rule, criteria, true)to skip pre-validation of the always-true guards.Changed
anywithunknownon input parameters of ~20 core utility functions (type guards, array utils, string escape helpers,clsx). Return types preserved or tightened to avoid breaking consumers.Fixed
@react-querybuilder/rules-engine):useRulesEngineBuilderno longer enters an infinite update loop. The hook now honors thedefaultRulesEngineprop and preserves edits in uncontrolled mode (previously the prop-sync effect could overwrite them on each render).v8.18.0Compare Source
Changed
defaultValueProcessoris now marked@deprecated(preferdefaultValueProcessorByRule).Added
thresholdPlaceholderprop onMatchModeEditorProps, configurable viatranslations.matchThreshold.placeholderName.parseJsonLogicnow supports subproperty references in "all"/"some"/"none" operations (e.g.,{"var": "name"}scoped to array elements).Fixed
count(*)::floatfor decimal match mode thresholds (was integer division).filteredCountindouble()for decimal match mode thresholds (was int/double type mismatch).v8.17.0Compare Source
Changed
@react-querybuilder/drizzlepackage. UseformatQuery(query, 'drizzle')fromreact-querybuilderor@react-querybuilder/coreinstead.Added
onRuleDropcallback prop forQueryBuilderDnD— fires after any drag-and-drop operation completes (same-QB or cross-QB) with source/target qbIds, paths, drop effect, and group mode.v8.16.2Compare Source
Added
.where()function.Fixed
parseNumbers.v8.16.1Compare Source
Added
QueryBuilderShadcn,shadcnControlElements, and individualShadcn*components) installable vianpx shadcn add https://react-querybuilder.js.org/r/query-builder.json.@react-querybuilder/prime(released 2026-05-21).Fixed
translationkeys for "natural_language" export allow more natural, grammatically correct output for non-English languages.ruleSeparator,listSeparator,betweenAnd,afterSubject,afterVerb,afterObject.?where appropriate.IN/NOT INsyntax where appropriate.v8.16.0Compare Source
Added
formatQueryformats:"cypher"(alias"gql"),"gremlin","sparql".@react-querybuilder/datetime.parseCypher(aliasparseGQL),parseGremlin,parseSPARQL.Fixed
"contains","beginsWith", and"endsWith"operators combined withvalueSource: "field".v8.15.0Compare Source
Changed
@react-querybuilder/dnd,react-dndis now an optional peer dependency (it was previously required).react-dndexports as thedndprop (e.g.,dnd={{ ...ReactDnD, ...ReactDnDHTML5Backend }}) still works—they are auto-detected and wrapped in areact-dndadapter—butcreateReactDnDAdapteris preferred.useReactDnDhook — usecreateReactDnDAdapterinstead.Added
@react-querybuilder/dndis now DnD-library-agnostic via an adapter pattern.DndAdapterinterface — implementDndProvider,useRuleDnD,useRuleGroupDnD, anduseInlineCombinatorDnDto integrate any drag-and-drop library.createReactDnDAdapterfactory wrapsreact-dndexports into aDndAdapter. This is the recommended way to enable drag-and-drop going forward.createDndKitAdapterfactory wraps@dnd-kit/coreexports into aDndAdapter, providing a first-class alternative toreact-dnd.canDropOnRule,canDropOnRuleGroup,canDropOnInlineCombinator,buildDropResult,handleDrop,getDragItem) are exported for use in custom adapters.updateWhileDraggingprop forQueryBuilderDnD. When enabled, the query tree visually rearranges in real-time as rules and groups are dragged (using a shadow query that commits on drop). Supported by the@atlaskit/pragmatic-drag-and-dropand@dnd-kit/coreadapters.copyModeAfterHoverMsandgroupModeAfterHoverMsprops forQueryBuilderDnD. When set to a value greater than zero, the drop mode will switch to "copy" or "group" automatically after hovering over a valid rule or group for the specified number of milliseconds. Supported by the@atlaskit/pragmatic-drag-and-dropand@dnd-kit/coreadapters.formatQuery(query, 'diagnostics')) which returns:query: annotated copy of the query tree withvalid,reasons,path, andlevelon every rule and group.diagnostics: flat array of all issues (placeholder checks, muted nodes, custom validator failures, value/type mismatches, undefined/unreferenced fields).stats: aggregate counts (totalRules,totalGroups,validRules,invalidRules,validGroups,invalidGroups).fieldSummary: per-fieldruleCountandinvalidCount.Fixed
useValueSelectornormalizes multiselect values to strings so they match option names, which are always strings.v8.14.4Compare Source
Fixed
"mongodb_query"/"mongodb") now use$norinstead of$notfor rule group negation, fixing theunknown top level operator: $notruntime error.v8.14.3Compare Source
Fixed
v8.14.2Compare Source
Fixed
transformQueryandmerge[Any]Translation[s]now guard against prototype pollution.v8.14.1Compare Source
Fixed
"mongodb_query"/"mongodb") now properly support rule groups withnot: true.TanStack/query (@tanstack/react-query)
v5.101.4Compare Source
Patch Changes
v5.101.3Compare Source
Patch Changes
7e3c822]:v5.101.2Compare Source
Patch Changes
v5.101.1Compare Source
Patch Changes
9eff92e]:v5.101.0Compare Source
Patch Changes
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.