Skip to content

fix(deps): update patch updates (patch) - #1144

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/patch-patch-updates
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/patch-patch-updates

Conversation

@renovate

@renovate renovate Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@anolilab/eslint-config (source) 30.0.1 → 30.0.2 age confidence
@anolilab/multi-semantic-release (source) 4.4.7 → 4.4.21 age confidence
@anolilab/semantic-release-pnpm (source) 8.1.18 → 8.1.31 age confidence
@anolilab/semantic-release-preset (source) 13.4.19 → 13.4.32 age confidence
@e18e/eslint-plugin 0.8.0 → 0.8.1 age confidence
@eslint-react/eslint-plugin (source) 5.18.6 → 5.18.10 age confidence
@eslint/compat (source) 2.1.0 → 2.1.1 age confidence
@hono/node-server@<2.0.5 >=2.1.1 → >=2.1.3 age confidence
browserslist 4.28.8 → 4.28.9 age confidence
browserslist@<=4.28.6 >=4.28.7 → >=4.28.9 age confidence
caniuse-lite 1.0.30001809 → 1.0.30001813 age confidence
hono@<4.12.27 (source) >=4.13.2 → >=4.13.11 age confidence
ip-address@<=10.1.0 >=10.5.0 → >=10.5.1 age confidence
js-yaml@>=3.0.0 <3.15.1 [^3.15.1 → ^3.15.2](https://renovatebot.com/diffs/npm/js-yaml@>=3.0.0 <3.15.1/3.15.1/3.15.2) age confidence
js-yaml@>=4.0.0 <4.3.0 [^4.3.1 → ^4.3.2](https://renovatebot.com/diffs/npm/js-yaml@>=4.0.0 <4.3.0/4.3.1/4.3.2) age confidence
picomatch@>=4.0.0 <4.0.4 [>=4.0.5 → >=4.0.7](https://renovatebot.com/diffs/npm/picomatch@>=4.0.0 <4.0.4/4.0.5/4.0.7) age confidence
publint (source) 0.3.23 → 0.3.24 age confidence
tsx (source) ^4.23.12 → ^4.23.15 age confidence
yaml@>=2.0.0 <2.8.3 (source) [>=2.9.0 → >=2.9.1](https://renovatebot.com/diffs/npm/yaml@>=2.0.0 <2.8.3/2.9.0/2.9.1) age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

anolilab/javascript-style-guide (@​anolilab/eslint-config)

v30.0.2

Compare Source

anolilab/semantic-release (@​anolilab/multi-semantic-release)

v4.4.21

Compare Source

Dependencies

v4.4.20

Compare Source

Dependencies

v4.4.19

Compare Source

Dependencies

v4.4.18

Compare Source

Dependencies

v4.4.17

Compare Source

Dependencies

v4.4.16

Compare Source

Dependencies

v4.4.15

Compare Source

Dependencies

v4.4.14

Compare Source

Dependencies

v4.4.13

Compare Source

Bug Fixes
  • keep the repository url when forking (400495f)
Tests
  • msr: fix lint errors and cover the prepare step in the repo URL tests (9866e16)

v4.4.12

Compare Source

v4.4.11

Compare Source

v4.4.10

Compare Source

Bug Fixes
  • lint: revert eslint-config to v28 and relax unsafe-type rules (#​435) (33999ea)
Miscellaneous Chores
  • point every Discord link at the anolilab server (8cee2ca)
Code Refactoring
  • serialize manifests through one shared helper (18c6e0a)
Dependencies

v4.4.9

Compare Source

Bug Fixes
  • ci: unbreak eslint on main (b60faae)
  • multi-semantic-release: make the git fixtures ignore the developer's git setup (32eac4d)
Dependencies

v4.4.8

Compare Source

Bug Fixes
  • deps: pin conventionalcommits preset below v10 (365c7b2)
  • semantic-release-preset: emit real newlines in release commits (59de04c)
Dependencies
anolilab/semantic-release (@​anolilab/semantic-release-pnpm)

v8.1.31

Compare Source

v8.1.30

Compare Source

v8.1.29

Compare Source

v8.1.28

Compare Source

v8.1.27

Compare Source

v8.1.26

Compare Source

v8.1.25

Compare Source

v8.1.24

Compare Source

v8.1.23

Compare Source

Bug Fixes
  • lint: revert eslint-config to v28 and relax unsafe-type rules (#​435) (33999ea)
Dependencies

v8.1.22

Compare Source

Miscellaneous Chores
  • point every Discord link at the anolilab server (8cee2ca)
Dependencies

v8.1.21

Compare Source

Bug Fixes
  • semantic-release-pnpm: bump the version without invoking npm (e0cb740), closes #​375
Code Refactoring
  • semantic-release-pnpm: write the bumped manifest in a single pass (106794a)
  • serialize manifests through one shared helper (18c6e0a)

v8.1.20

Compare Source

Dependencies

v8.1.19

Compare Source

Bug Fixes
  • semantic-release-preset: emit real newlines in release commits (59de04c)
Dependencies
anolilab/semantic-release (@​anolilab/semantic-release-preset)

v13.4.32

Compare Source

Dependencies

v13.4.31

Compare Source

Dependencies

v13.4.30

Compare Source

Dependencies

v13.4.29

Compare Source

Dependencies

v13.4.28

Compare Source

Dependencies

v13.4.27

Compare Source

Dependencies

v13.4.26

Compare Source

Dependencies

v13.4.25

Compare Source

Dependencies

v13.4.24

Compare Source

Dependencies

v13.4.23

Compare Source

Miscellaneous Chores
  • point every Discord link at the anolilab server (8cee2ca)
Dependencies

v13.4.22

Compare Source

Dependencies

v13.4.21

Compare Source

Dependencies

v13.4.20

Compare Source

Bug Fixes
  • semantic-release-preset: emit real newlines in release commits (59de04c)
Dependencies
e18e/eslint-plugin (@​e18e/eslint-plugin)

v0.8.1

Compare Source

What's Changed

  • chore(deps): bump module-replacements from 3.1.0 to 3.2.0 in the production-dependencies group by @​dependabot[bot] in #​153
  • chore(deps): bump module-replacements from 3.2.0 to 3.3.0 in the production-dependencies group by @​dependabot[bot] in #​154
  • fix(prefer-timer-args): check UpdateExpressions & TemplateLiterals by @​43081j in #​158
  • fix(prefer-array-from-map): don't flag mappers with >2 params by @​43081j in #​159

Full Changelog: e18e/eslint-plugin@0.8.0...0.8.1

Rel1cx/eslint-react (@​eslint-react/eslint-plugin)

v5.18.10

Compare Source

🐞 Fixes
  • The remaining disable-* preset configs in react-x and react-rsc now also register the same plugin object as the package's default export, so ESLint no longer reports a "Cannot redefine plugin" error when combining them with a manually registered plugin. (follow-up to #​1947, see #​1946)
🏗️ Internal
  • Website: removed fumadocs-twoslash from serverExternalPackages to fix a prerender error.

Full Changelog: Rel1cx/eslint-react@v5.18.9...v5.18.10

v5.18.9

Compare Source

🏗️ Internal
  • Bumped eslint to 10.10.0, vitest to 5.0.0, tsdown to 0.23.0, nx to 23.2.0, dprint to 0.57.4, @types/react-dom to 19.2.7, @eslint/compat to 2.1.1, and @nubjs/nub to 0.8.3.

Full Changelog: Rel1cx/eslint-react@v5.18.8...v5.18.9

v5.18.8

Compare Source

🐞 Fixes
  • Preset configs (recommended, strict, etc.) now register the same plugin object as the package's default export, so ESLint no longer reports a "Cannot redefine plugin" error when the plugin is registered manually and a preset is extended at the same time. (#​1947, closes #​1946)
🏗️ Internal
  • Re-enabled the import-integrity-lint plugin and patched its path prefix check so sibling directories like examples/preact and examples/preact-compat no longer collide.
  • Pinned fast-uri to ^3.1.5 to fix CVE-2026-18446 (GHSA-7p8r-x3mc-p8w7).
  • Bumped @effect/language-service to 0.87.2, @effect/platform to 0.97.1, @effect/platform-node to 0.108.1, @nubjs/nub to 0.8.2, @types/node to 26.4.1, dprint to 0.57.0, and lucide-react to 1.39.0.

Full Changelog: Rel1cx/eslint-react@v5.18.7...v5.18.8

v5.18.7

Compare Source

🐞 Fixes
  • react-x/set-state-in-effect: no longer misattributes render-phase setState calls to effects when the state updater is passed through a prop function. (#​1945)
🏗️ Internal
  • Bumped typescript-eslint to 8.69.0, eslint to 10.9.1, vitest to 4.1.11, @types/node to 26.4.0, @types/react-dom to 19.2.5, eslint-plugin-package-json to 1.8.0, import-integrity-lint to 1.3.0, nx to 23.1.3, publint to 0.3.24, typedoc-plugin-markdown to 4.13.0, and pnpm to 11.25.0.
New Contributors

Full Changelog: Rel1cx/eslint-react@v5.18.6...v5.18.7

eslint/rewrite (@​eslint/compat)

v2.1.1

Compare Source

Bug Fixes
  • preserve markVariableAsUsed return value in compat context (#​503) (66d9790)
honojs/node-server (@​hono/node-server@<2.0.5)

v2.1.3

Compare Source

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

Compare Source

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

browserslist/browserslist (browserslist)

v4.28.9

Compare Source

browserslist/caniuse-lite (caniuse-lite)

v1.0.30001813

Compare Source

v1.0.30001812

Compare Source

v1.0.30001810

Compare Source

honojs/hono (hono@<4.12.27)

v4.13.11

Compare Source

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Compare Source

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

  • chore: migrate the package manager from bun to pnpm in #​5433
  • chore(package.json): invoke package scripts through pnpm instead of bun in #​5434
  • chore: replace prettier with oxfmt in #​5435
  • chore(deps): upgrade vitest to 5.0.1 in #​5437
  • chore: let oxfmt sort imports instead of eslint in #​5442
  • chore: replace eslint with oxlint in #​5443
  • chore: introduce Vite+ in #​5444
  • fix(types): allow returning a Blob as a response body in #​5446
  • chore: convert build scripts into plugins in #​5448
  • chore: stop editorconfig-checker from checking Markdown indent size in #​5455
  • ci: remove empty step left in cr.yml by the pnpm migration in #​5456
  • chore(deps): upgrade vite-plus to 1.0.0-rc.1 in #​5459
  • feat(adapters): add @​hono/bun as a workspace package in #​5447
  • chore(adapters/bun): ship ESM only in #​5462
  • feat(adapters): add the seven adapters as workspace packages in #​5463
  • feat(adapters/deno): publish to JSR in #​5465
  • test: move adapter runtime tests into adapters/* in #​5466

Full Changelog: honojs/hono@v4.13.9...v4.13.10

v4.13.9

Compare Source

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in #​5380
  • fix(accepts): match media types and language tags case-insensitively in #​5376
  • fix(linear-router): don't match an empty path segment as a param in #​5373
  • fix(pretty-json): don't break responses with unparseable JSON bodies in #​5377
  • fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url in #​5379
  • fix(aws-lambda): treat binary +xml archive media types as binary in #​5424
  • fix(aws-lambda): preserve empty query parameters in #​5292
  • fix(lambda-edge): sync content type detection with aws-lambda in #​5426
  • fix(lambda-edge): fail with a descriptive error on a malformed event in #​5358

Full Changelog: honojs/hono@v4.13.8...v4.13.9

v4.13.8

Compare Source

What's Changed

  • docs: fix typos in code comments and link third-party middleware section in #​5343
  • perf(jsx/dom): reduce lookup work for large keyed updates in #​5340
  • fix(aws-lambda): respect backpressure when streaming the response body in #​5351
  • fix(accepts, language): skip accept entries with quality 0 when matching in #​5311
  • fix(accept): treat the q parameter name as case-insensitive in #​5349
  • fix(accept): clamp a negative q to 0, not 1 in #​5357
  • fix(request): keep the request media type when reusing a cached body in #​5366
  • docs(combine): fix except() JSDoc param and add missing @​returns in #​5346
  • perf(jsx/dom): optimize matching-head child lookup during reconciliation in #​5329

Full Changelog: honojs/hono@v4.13.7...v4.13.8

v4.13.7

Compare Source

v4.13.6

Compare Source

v4.13.5

Compare Source

v4.13.4

Compare Source

v4.13.3

Compare Source

What's Changed

  • fix(client): prevent URL corruption when replaceUrlParam contains $ replacement tokens in #​5227
  • fix(etag): copy pending stream bytes in #​5239
  • fix(etag): avoid skipping headers when filtering 304 response headers in #​5234
  • fix(cors): append Origin to Vary header on OPTIONS preflight in #​5235
  • docs(context): add custom headers append option example to Context JSDoc in #​5248
  • fix(trie-router): match suffix wildcard routes in #​5236
  • fix(pattern-router/linear-router): prevent prefix overmatch on wildcard routes in #​5252
  • fix(csrf): exempt OPTIONS request from CSRF validation in #​5250
  • fix(utils/ipaddr): avoid truncation on embedded IPv4 addresses in expand IPv6 in #​5247
  • feat(pretty-json): support structured JSON content-types (+json) in #​5226

Full Changelog: honojs/hono@v4.13.2...v4.13.3

beaugunderson/ip-address (ip-address@<=10.1.0)

v10.5.1

Compare Source

nodeca/js-yaml (js-yaml@>=3.0.0 <3.15.1)

v3.15.2

Compare Source

micromatch/picomatch (picomatch@>=4.0.0 <4.0.4)

v4.0.7

Compare Source

Fixed
  • Fixed terminal globstars in parenthesized patterns (#​142, e279bd7).

v4.0.6

Compare Source

Fixed
  • scan() now scans the full pattern when tokens are requested, instead of merging the remaining path segments into the final token (#​62, 5f5819d).
  • scan() now returns complete pattern parts, including leading and trailing empty segments, and handles nested and escaped parentheses correctly (#​58, f201165).
publint/publint (publint)

v0.3.24

Compare Source

Patch Changes
  • #​257 7c4d25a - Check the repository.url value even when repository.type is omitted. type is optional and defaults to git, so packages using the object form without it were previously skipped for the deprecated-protocol, invalid-git-url, and shorthand-URL checks.
privatenumber/tsx (tsx)

v4.23.15

Compare Source

Bug Fixes
  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

Compare Source

eemeli/yaml (yaml@>=2.0.0 <2.8.3)

v2.9.1

Compare Source

  • Limit recursive merge aliases (#​685, #​713)
  • Simplify line unfolding during quoted string parsing (#​714)

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "after 10:00 before 19:00 every weekday except after 13:00 before 14:00"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from prisis as a code owner September 7, 2026 15:12
@renovate renovate Bot added the c: dependencies Pull requests that adds/updates a dependency label Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@socket-security

socket-security Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/patch-patch-updates branch 3 times, most recently from 3f68514 to 820977e Compare September 11, 2026 15:43
@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 354721d0-7288-4f59-b2c1-0cbed297c677

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/patch-patch-updates branch 3 times, most recently from 77f4a52 to 5565d3d Compare September 18, 2026 14:18
@renovate
renovate Bot force-pushed the renovate/patch-patch-updates branch 2 times, most recently from 0fbf410 to 54a6e06 Compare September 29, 2026 16:20
Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate
renovate Bot force-pushed the renovate/patch-patch-updates branch from 54a6e06 to 7045501 Compare October 2, 2026 10:27
@prisis

prisis commented Oct 3, 2026

Copy link
Copy Markdown
Member

Superseded by the consolidated dependency update now on main.

@prisis prisis closed this Oct 3, 2026
@prisis
prisis deleted the renovate/patch-patch-updates branch October 3, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c: dependencies Pull requests that adds/updates a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant