fix(deps): update patch updates (patch) - #1144
renovate[bot] wants to merge 1 commit into
Conversation
|
Thank you for following the naming conventions! 🙏 |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
3f68514 to
820977e
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
77f4a52 to
5565d3d
Compare
0fbf410 to
54a6e06
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
54a6e06 to
7045501
Compare
|
Superseded by the consolidated dependency update now on |
This PR contains the following updates:
30.0.1→30.0.24.4.7→4.4.218.1.18→8.1.3113.4.19→13.4.320.8.0→0.8.15.18.6→5.18.102.1.0→2.1.1>=2.1.1→>=2.1.34.28.8→4.28.9>=4.28.7→>=4.28.91.0.30001809→1.0.30001813>=4.13.2→>=4.13.11>=10.5.0→>=10.5.1^3.15.1→^3.15.2](https://renovatebot.com/diffs/npm/js-yaml@>=3.0.0 <3.15.1/3.15.1/3.15.2)^4.3.1→^4.3.2](https://renovatebot.com/diffs/npm/js-yaml@>=4.0.0 <4.3.0/4.3.1/4.3.2)>=4.0.5→>=4.0.7](https://renovatebot.com/diffs/npm/picomatch@>=4.0.0 <4.0.4/4.0.5/4.0.7)0.3.23→0.3.24^4.23.12→^4.23.15>=2.9.0→>=2.9.1](https://renovatebot.com/diffs/npm/yaml@>=2.0.0 <2.8.3/2.9.0/2.9.1)bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
anolilab/javascript-style-guide (@anolilab/eslint-config)
v30.0.2Compare Source
anolilab/semantic-release (@anolilab/multi-semantic-release)
v4.4.21Compare Source
Dependencies
v4.4.20Compare Source
Dependencies
v4.4.19Compare Source
Dependencies
v4.4.18Compare Source
Dependencies
v4.4.17Compare Source
Dependencies
v4.4.16Compare Source
Dependencies
v4.4.15Compare Source
Dependencies
v4.4.14Compare Source
Dependencies
v4.4.13Compare Source
Bug Fixes
Tests
v4.4.12Compare Source
v4.4.11Compare Source
v4.4.10Compare Source
Bug Fixes
Miscellaneous Chores
Code Refactoring
Dependencies
v4.4.9Compare Source
Bug Fixes
Dependencies
v4.4.8Compare Source
Bug Fixes
Dependencies
anolilab/semantic-release (@anolilab/semantic-release-pnpm)
v8.1.31Compare Source
v8.1.30Compare Source
v8.1.29Compare Source
v8.1.28Compare Source
v8.1.27Compare Source
v8.1.26Compare Source
v8.1.25Compare Source
v8.1.24Compare Source
v8.1.23Compare Source
Bug Fixes
Dependencies
v8.1.22Compare Source
Miscellaneous Chores
Dependencies
v8.1.21Compare Source
Bug Fixes
Code Refactoring
v8.1.20Compare Source
Dependencies
v8.1.19Compare Source
Bug Fixes
Dependencies
anolilab/semantic-release (@anolilab/semantic-release-preset)
v13.4.32Compare Source
Dependencies
v13.4.31Compare Source
Dependencies
v13.4.30Compare Source
Dependencies
v13.4.29Compare Source
Dependencies
v13.4.28Compare Source
Dependencies
v13.4.27Compare Source
Dependencies
v13.4.26Compare Source
Dependencies
v13.4.25Compare Source
Dependencies
v13.4.24Compare Source
Dependencies
v13.4.23Compare Source
Miscellaneous Chores
Dependencies
v13.4.22Compare Source
Dependencies
v13.4.21Compare Source
Dependencies
v13.4.20Compare Source
Bug Fixes
Dependencies
e18e/eslint-plugin (@e18e/eslint-plugin)
v0.8.1Compare Source
What's Changed
Full Changelog: e18e/eslint-plugin@0.8.0...0.8.1
Rel1cx/eslint-react (@eslint-react/eslint-plugin)
v5.18.10Compare Source
🐞 Fixes
disable-*preset configs inreact-xandreact-rscnow also register the same plugin object as the package's default export, so ESLint no longer reports a "Cannot redefine plugin" error when combining them with a manually registered plugin. (follow-up to #1947, see #1946)🏗️ Internal
fumadocs-twoslashfromserverExternalPackagesto fix a prerender error.Full Changelog: Rel1cx/eslint-react@v5.18.9...v5.18.10
v5.18.9Compare Source
🏗️ Internal
eslintto10.10.0,vitestto5.0.0,tsdownto0.23.0,nxto23.2.0,dprintto0.57.4,@types/react-domto19.2.7,@eslint/compatto2.1.1, and@nubjs/nubto0.8.3.Full Changelog: Rel1cx/eslint-react@v5.18.8...v5.18.9
v5.18.8Compare Source
🐞 Fixes
recommended,strict, etc.) now register the same plugin object as the package's default export, so ESLint no longer reports a "Cannot redefine plugin" error when the plugin is registered manually and a preset is extended at the same time. (#1947, closes #1946)🏗️ Internal
import-integrity-lintplugin and patched its path prefix check so sibling directories likeexamples/preactandexamples/preact-compatno longer collide.fast-urito^3.1.5to fix CVE-2026-18446 (GHSA-7p8r-x3mc-p8w7).@effect/language-serviceto0.87.2,@effect/platformto0.97.1,@effect/platform-nodeto0.108.1,@nubjs/nubto0.8.2,@types/nodeto26.4.1,dprintto0.57.0, andlucide-reactto1.39.0.Full Changelog: Rel1cx/eslint-react@v5.18.7...v5.18.8
v5.18.7Compare Source
🐞 Fixes
react-x/set-state-in-effect: no longer misattributes render-phasesetStatecalls to effects when the state updater is passed through a prop function. (#1945)🏗️ Internal
typescript-eslintto8.69.0,eslintto10.9.1,vitestto4.1.11,@types/nodeto26.4.0,@types/react-domto19.2.5,eslint-plugin-package-jsonto1.8.0,import-integrity-lintto1.3.0,nxto23.1.3,publintto0.3.24,typedoc-plugin-markdownto4.13.0, andpnpmto11.25.0.New Contributors
Full Changelog: Rel1cx/eslint-react@v5.18.6...v5.18.7
eslint/rewrite (@eslint/compat)
v2.1.1Compare Source
Bug Fixes
honojs/node-server (@hono/node-server@<2.0.5)
v2.1.3Compare Source
Security fixes
serveStaticdecodes the request path a second time, leading to bypass of middleware on static pathsAffects:
@hono/node-server/serve-static. FixesserveStaticdecoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4fserveStaticnow rejects request paths that still contain%after decoding. To serve files whose names contain a literal%, setallowPercentInPath: true.The same fix ships in
honov4.13.11.v2.1.2Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.1.1...v2.1.2
browserslist/browserslist (browserslist)
v4.28.9Compare Source
orparsing performance (by @NotAFlightRisk).browserslist/caniuse-lite (caniuse-lite)
v1.0.30001813Compare Source
v1.0.30001812Compare Source
v1.0.30001810Compare Source
honojs/hono (hono@<4.12.27)
v4.13.11Compare Source
Security fixes
serveStaticdecodes the request path a second time, leading to bypass of middleware on static pathsAffects:
hono/serve-staticand the adapters built on it (hono/bun,hono/deno,hono/cloudflare-workers,@hono/bun,@hono/deno,@hono/cloudflare-workers). FixesserveStaticdecoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7serveStaticnow rejects request paths that still contain%after decoding. To serve files whose names contain a literal%, setallowPercentInPath: true.The same fix ships in
@hono/node-serverv2.1.3.v4.13.10Compare Source
Adapters are now separate packages
The runtime adapters are now published as their own packages:
@hono/bun,@hono/deno,@hono/cloudflare-workers,@hono/aws-lambda,@hono/lambda-edge,@hono/netlify,@hono/vercel, and@hono/service-worker.@hono/denois also on JSR.hono/<adapter>still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.
What's Changed
cr.ymlby the pnpm migration in #54561.0.0-rc.1in #5459adapters/*in #5466Full Changelog: honojs/hono@v4.13.9...v4.13.10
v4.13.9Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.8...v4.13.9
v4.13.8Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.7...v4.13.8
v4.13.7Compare Source
v4.13.6Compare Source
v4.13.5Compare Source
v4.13.4Compare Source
v4.13.3Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.2...v4.13.3
beaugunderson/ip-address (ip-address@<=10.1.0)
v10.5.1Compare Source
nodeca/js-yaml (js-yaml@>=3.0.0 <3.15.1)
v3.15.2Compare Source
micromatch/picomatch (picomatch@>=4.0.0 <4.0.4)
v4.0.7Compare Source
Fixed
v4.0.6Compare Source
Fixed
scan()now scans the full pattern when tokens are requested, instead of merging the remaining path segments into the final token (#62, 5f5819d).scan()now returns complete pattern parts, including leading and trailing empty segments, and handles nested and escaped parentheses correctly (#58, f201165).publint/publint (publint)
v0.3.24Compare Source
Patch Changes
7c4d25a- Check therepository.urlvalue even whenrepository.typeis omitted.typeis optional and defaults to git, so packages using the object form without it were previously skipped for the deprecated-protocol, invalid-git-url, and shorthand-URL checks.privatenumber/tsx (tsx)
v4.23.15Compare Source
Bug Fixes
This release is also available on:
v4.23.14Compare Source
eemeli/yaml (yaml@>=2.0.0 <2.8.3)
v2.9.1Compare Source
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.