Skip to content

fix(deps): update minor updates (minor) - #1150

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/minor-updates
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/minor-updates

Conversation

@renovate

@renovate renovate Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@eslint-community/eslint-plugin-eslint-comments 4.7.2 → 4.8.1 age confidence
@eslint-react/eslint-plugin (source) 5.18.6 → 5.22.1 age confidence
@eslint/config-inspector 3.2.0 → 3.5.0 age confidence
astro-eslint-parser 3.1.0 → 3.2.0 age confidence
browserslist 4.28.8 → 4.29.2 age confidence
browserslist@<=4.28.6 >=4.28.7 → >=4.29.2 age confidence
globals 17.11.0 → 17.12.0 age confidence
ip-address@<=10.1.0 >=10.5.0 → >=10.7.2 age confidence
lint-staged 17.3.0 → 17.6.0 age confidence
oxfmt (source) 0.63.0 → 0.71.0 age confidence
pnpm (source) 11.22.0 → 11.28.2 age confidence
shell-quote ^1.10.0 → ^1.11.0 age confidence
shell-quote@>=1.1.0 <=1.8.3 [>=1.10.0 → >=1.11.0](https://renovatebot.com/diffs/npm/shell-quote@>=1.1.0 <=1.8.3/1.10.0/1.11.0) age confidence
svgo@>=4.0.0 <4.0.2 (source) [>=4.0.2 → >=4.1.0](https://renovatebot.com/diffs/npm/svgo@>=4.0.0 <4.0.2/4.0.2/4.1.0) age confidence
tailwind-csstree 0.3.3 → 0.4.0 age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

eslint-community/eslint-plugin-eslint-comments (@​eslint-community/eslint-plugin-eslint-comments)

v4.8.1

Compare Source

Bug Fixes
  • no-use, require-description: key directive-comment cache on additionalDirectives (#​329) (de11b0e)

v4.8.0

Compare Source

Features
  • no-use, require-description: additionalDirectives option (#​267) (d9a7e4d)
Rel1cx/eslint-react (@​eslint-react/eslint-plugin)

v5.22.1

Compare Source

🐞 Fixes
  • react-x/use-state: directly returning the useState result (ex: return React.useState()) is now allowed regardless of the rule's options, matching the exemption in the original react/hook-use-state rule. Covers explicit, implicit (arrow function), and type-asserted returns; lazy initialization checks still apply. (#​1974, closes #​1963)
📝 Documentation
  • Added a note about eslint being an optional peer dependency to the READMEs and the website's getting-started guides.
  • Simplified the @eslint-react/kit README to point to the full documentation.

Full Changelog: Rel1cx/eslint-react@v5.22.0...v5.22.1

v5.22.0

Compare Source

✨ New
  • react-dom/no-unknown-property: added React 19.3 properties to the known property allowlist. (#​1973)
    • closedby on dialog
    • onFullscreenChange, onFullscreenError (and their Capture variants), credentialless, and maskType — gated on React version >= 19.3.0
    • onLoad on body
    • onScrollEnd (and its Capture variant)
    • shadowrootmode, shadowrootclonable, shadowrootdelegatesfocus, and shadowrootserializable on template
🏗️ Internal
  • Bumped fumadocs-core and fumadocs-ui to 16.15.15.

Full Changelog: Rel1cx/eslint-react@v5.21.3...v5.22.0

v5.21.3

Compare Source

🐞 Fixes
  • react-x/purity: reverted the v5.21.2 exemption for impure calls in useRef initializer arguments (ex: useRef(document.createElement("div"))); such calls are reported again. (#​1972)

Full Changelog: Rel1cx/eslint-react@v5.21.2...v5.21.3

v5.21.2

Compare Source

🐞 Fixes
  • react-x/no-unnecessary-use-prefix: hooks that call other hooks only within nested callbacks, functions named exactly use, and hooks defined in test mock module registrations are no longer reported. (#​1971)
  • react-x/no-unused-class-component-members: methods invoked by host environments through refs (React Native's NativeMethods) are no longer reported as unused. (#​1971)
  • react-x/purity: async function components in modules without a use client directive and impure calls in useRef initializer arguments are no longer reported. (#​1971)
  • react-x/set-state-in-effect: local variables initialized from nested member expressions rooted at a ref are now recognized as ref-derived values and no longer reported. (#​1971)
🏗️ Internal
  • @eslint-react/ast: predefined and exported common node-type helpers in the Check namespace and migrated call sites to them.
📝 Documentation
  • Website rule docs no longer include the per-rule ## Versions section; a rule's changelog can be viewed directly via the Rule Changelog link under the ## Resources section of each rule doc.

Full Changelog: Rel1cx/eslint-react@v5.21.1...v5.21.2

v5.21.1

Compare Source

🐞 Fixes
  • Fixed missed reports where a timer, fetch controller, or observer created in one effect was treated as cleaned up because an unrelated cleanup in another effect referenced a different variable with the same name; identifier matching now resolves both sides to their variables by scope instead of comparing names only. (#​1969) Affected rules:
    • react-web-api/no-leaked-timeout
    • react-web-api/no-leaked-interval
    • react-web-api/no-leaked-fetch
    • react-web-api/no-leaked-resize-observer
    • react-web-api/no-leaked-intersection-observer
🏗️ Internal
  • Simplified the react-web-api leaked-resource rules by replacing manual function-context stack tracking with Traverse.findParent ancestor lookup, and added boundary tests covering deeply nested callbacks, cross-effect pairing, and wrapped or referenced setup callbacks. (#​1969) Affected rules:
    • react-web-api/no-leaked-timeout
    • react-web-api/no-leaked-interval
    • react-web-api/no-leaked-fetch
    • react-web-api/no-leaked-event-listener
    • react-web-api/no-leaked-resize-observer
    • react-web-api/no-leaked-intersection-observer
  • @eslint-react/var: isAssignmentTargetEqual no longer short-circuits same-name identifiers through structural equality; identifier pairs are compared with scope-aware value equality. (#​1969)
  • react-x/no-unused-class-component-members: removed the manual class and method context stacks; the enclosing class and method are now resolved at the hit point with Traverse.findParent ancestor lookup, and the per-class member definition/usage maps are initialized lazily. (#​1970)

Full Changelog: Rel1cx/eslint-react@v5.21.0...v5.21.1

v5.21.0

Compare Source

✨ New
  • The plugins can now be used with Oxlint without an eslint installation: eslint is now an optional peer dependency across all published packages, and the rule utilities no longer eagerly load the eslint package at import time. (#​1965)
🏗️ Internal
  • @eslint-react/core: removed the unused isAssignmentToThisState helper, and simplified the react-x class-component rules (no-access-state-in-setstate, no-class-component, no-direct-mutation-state, no-set-state-in-*) accordingly.
  • @eslint-react/eslint: added a local getConstrainedTypeAtLocation helper (adapted from @typescript-eslint/type-utils) so consumers don't need to load @typescript-eslint/type-utils, whose entry point eagerly loads the eslint package. (#​1965)
  • Bumped typescript-eslint to 8.70.1, fumadocs to 16.15.14, fumadocs-mdx to 15.4.5, vite to 8.3.1, and other dependencies.
New Contributors

Full Changelog: Rel1cx/eslint-react@v5.20.8...v5.21.0

v5.20.8

🐞 Fixes
  • @eslint-react/core: isJsxLike now recognizes JSX wrapped in TypeScript expressions (as, satisfies, type assertions, and non-null assertions) and await expressions.
  • @eslint-react/jsx: isFragmentElement now requires the configured jsxFragmentFactory, avoiding an implicit React fragment factory for custom JSX runtimes.
🏗️ Internal
  • @eslint-react/jsx: exported the AttributeValue type from the package entry point.
  • @eslint-react/var: renamed the AssignmentTarget type to EnclosingAssignmentTarget and inlined getRequireExpressionArguments into its sole consumer.

Full Changelog: Rel1cx/eslint-react@v5.20.6...v5.20.8

v5.20.6

Compare Source

🐞 Fixes
  • react-x/globals: for...in/for...of loop targets without a declaration (e.g. for (globalValue of items)) are now collected as writes instead of being missed.
  • react-x/immutability: destructuring assignment targets (e.g. ({ a: props.x } = value)) and for...in/for...of loop targets without a declaration are now collected as mutations instead of being missed.
  • react-x/purity: builtin alias resolution now preserves the property path, so aliases of impure builtins (const random = Math.random; random(), const { now } = Date; now(), window.Math.random()) are now detected instead of being missed; unknown-global roots are not followed, preventing speculative reports.
  • react-x/refs: destructuring assignments, for-in/of loop targets, and delete operations on ref.current are now classified as writes instead of being misreported as reads.
  • react-x/refs: refs passed to constructor calls (new Widget(ref)) and tagged templates are now checked for render-time exposure, same as refs passed to plain functions.
  • react-x/refs: the mergeRefs exemption for passing refs now survives simple variable aliases (const combine = mergeRefs), resolved position-aware so reassigned aliases lose it again.
  • react-x/use-memo: reassignments of outer variables through destructuring patterns and for...in/for...of loop targets inside useMemo callbacks are now reported instead of being missed; property mutation targets remain exempt, matching the React Compiler's StoreContext semantics.
🏗️ Internal
  • @eslint-react/var: split resolve into a value-based resolve and a new origin-based resolveOrigin, and updated the consumers in react-web-api and react-x rules accordingly. (#​1964)
  • Bumped fumadocs to 16.15.12, fumadocs-mdx to 15.4.3, tsl-dx to 0.13.6, eslint-plugin-de-morgan to 2.2.0, and eslint-plugin-regexp to 3.3.1.

Full Changelog: Rel1cx/eslint-react@v5.20.5...v5.20.6

v5.20.5

Compare Source

🐞 Fixes
  • react-web-api/no-leaked-fetch: fixed a false positive where an abort call nested in a callback within the cleanup function (e.g. setTimeout(() => ctrl.abort())) was not recognized, causing a spurious expectedAbortInCleanup report; the abort lookup now finds the nearest enclosing setup/cleanup function instead of requiring the innermost one. (#​1962)

Full Changelog: Rel1cx/eslint-react@v5.20.4...v5.20.5

v5.20.4

Compare Source

🐞 Fixes
  • react-web-api/no-leaked-event-listener: listeners that are only added inside the effect cleanup are now reported when the matching removeEventListener is in the setup (reversed setup/cleanup pairing), since a listener attached on unmount is never removed. (#​1961)
🏗️ Internal
  • react-jsx and react-web-api rules: unified rule code style and variable naming across the plugins. (#​1960, #​1961)

Full Changelog: Rel1cx/eslint-react@v5.20.3...v5.20.4

v5.20.3

Compare Source

🏗️ Internal
  • @eslint-react/ast: replaced getIdentifierAt with the new getMemberChain helper and moved getInnermostCall to its sole consumer in react-x/no-nested-component-definitions. (#​1959)
  • react-dom rules: unified rule code style and variable naming across the plugin, and switched no-find-dom-node to import-aware detection via createImportLookup. (#​1958)

Full Changelog: Rel1cx/eslint-react@v5.20.2...v5.20.3

v5.20.2

Compare Source

🐞 Fixes
  • Fixed false negatives in the JSX element resolver used by the react-dom rules: polymorphic components written as member expressions (e.g. <motion.div as="button">) were mistaken for host elements, so the polymorphic prop was ignored and these rules skipped them entirely; they are now resolved through the polymorphic prop and checked like the underlying DOM element. String values of the polymorphic prop are also normalized to lowercase, so as="BUTTON" is treated as button. Affected rules:
    • react-dom/no-missing-button-type
    • react-dom/no-missing-iframe-sandbox
    • react-dom/no-unsafe-iframe-sandbox
    • react-dom/no-unsafe-target-blank
    • react-dom/no-void-elements-with-children
🏗️ Internal
  • The normalized polymorphicPropName setting type is corrected from string | null to string — it could never be null at runtime — and the unreachable null branch in the JSX element resolver used by the react-dom rules is removed.

Full Changelog: Rel1cx/eslint-react@v5.20.1...v5.20.2

v5.20.1

Compare Source

🐞 Fixes
  • react-dom/no-flush-sync: flushSync calls are now detected by tracking react-dom imports directly instead of matching by name, so aliased named imports (e.g. import { flushSync as fs } from "react-dom") and default/namespace member calls (e.g. ReactDOM.flushSync()) are reported, while local functions, object methods, and same-named APIs from other packages (e.g. pino's destination().flushSync()) are no longer misreported. (#​1954, closes #​1943)
🏗️ Internal
  • react-dom/no-flush-sync and react-dom/no-find-dom-node: API call checks now use core.isAPICall; core.isJsxLike now uses isCreateElementCall.
  • Added Node types reference to all package tsl/tsdown configs.
  • Bumped eslint to 10.11.0, eslint-plugin-jsdoc to 64.5.4, eslint-plugin-package-json to 1.9.0, typedoc-plugin-markdown to 4.13.1, @types/node to 26.6.2, pnpm to 12.5.1, and the dprint JSON plugin to 0.24.0.
New Contributors

Full Changelog: Rel1cx/eslint-react@v5.20.0...v5.20.1

v5.20.0

Compare Source

✨ New
  • react-x/immutability: mutations on for...of iterator variables (e.g. for (const item of items) { item.done = true; }), including destructured iterator bindings, are now reported when the iterated collection resolves through its root identifier to a component's props, a state value, or a shallow copy of either, since the iterator variable is bound to each shared element of the original collection. Member-expression collections (for (const item of props.items)) are traced to their root; for...in loops and right sides without a root identifier are not traced. (#​1953, closes #​1764)
🏗️ Internal
  • Bumped @types/node to 26.6.1, tsl-dx to 0.13.5, eslint-plugin-jsdoc to 64.5.2, lucide-react to 1.47.0, and pnpm to 12.4.2.
New Contributors

Full Changelog: Rel1cx/eslint-react@v5.19.1...v5.20.0

v5.19.1

Compare Source

🐞 Fixes
  • react-x/immutability: the first parameter of a function is now classified as props only when the function is a confirmed component — one that returns JSX or calls hooks — so mutating the first parameter of a function that merely looks like a component (e.g. an event-handler factory whose returned function never renders and calls no hooks) is no longer reported. (#​1952, closes #​1951)
🏗️ Internal
  • react-x/immutability: renamed MUTATING_METHODS/NAVIGATION_HOOKS to KNOWN_MUTATING_METHODS/KNOWN_MUTATING_HOOKS and added precise behavior boundary tests.
  • react-x/globals: restructured internals (split into collect, effects, and origins modules) to match the in-progress feat/environment-config implementation; no behavior change.
  • Website: awaited the async llms.txt index generation and fixed the website data update step to run before building.
  • CI: removed the generated file verification step.
  • Bumped typescript-eslint to 8.70.0, react/react-dom to 19.3.0, next to 16.3.5, vite to 8.3.0, effect to 3.22.2, fumadocs to 16.15.10, eslint-plugin-jsdoc to 64.3.9, tailwind-merge to 3.7.0, ansis to 4.4.0, nx to 23.2.1, eslint-plugin-react-refresh to 0.5.6, eslint-plugin-package-json to 1.8.1, @types/node to 26.5.1, @types/react to 19.3.0, @types/react-dom to 19.3.0, and pnpm to 12.4.1.

Full Changelog: Rel1cx/eslint-react@v5.19.0...v5.19.1

v5.19.0

Compare Source

✨ New
  • react-x/immutability: direct mutations of props and state are now reported — member assignments, updates, deletions, and mutating method calls are flagged when the mutated value resolves (through variable-declarator aliases) to a component's props, a useState/useReducer state value, or a custom hook matching the additionalStateHooks setting, independent of whether the mutation happens inside a function that reaches a freeze sink. (#​1948, closes #​1941)
  • react-x/immutability: added shallow-copy awareness — nested mutations through an object/array literal built by spreading a props or state value (e.g. const copy = { ...state } / const copy = [...state]) are reported, since the nested values are still shared with the original; writes to the copy's own top-level slots are not reported. (#​1948)

Full Changelog: Rel1cx/eslint-react@v5.18.10...v5.19.0

v5.18.10

Compare Source

🐞 Fixes
  • The remaining disable-* preset configs in react-x and react-rsc now also register the same plugin object as the package's default export, so ESLint no longer reports a "Cannot redefine plugin" error when combining them with a manually registered plugin. (follow-up to #​1947, see #​1946)
🏗️ Internal
  • Website: removed fumadocs-twoslash from serverExternalPackages to fix a prerender error.

Full Changelog: Rel1cx/eslint-react@v5.18.9...v5.18.10

v5.18.9

Compare Source

🏗️ Internal
  • Bumped eslint to 10.10.0, vitest to 5.0.0, tsdown to 0.23.0, nx to 23.2.0, dprint to 0.57.4, @types/react-dom to 19.2.7, @eslint/compat to 2.1.1, and @nubjs/nub to 0.8.3.

Full Changelog: Rel1cx/eslint-react@v5.18.8...v5.18.9

v5.18.8

Compare Source

🐞 Fixes
  • Preset configs (recommended, strict, etc.) now register the same plugin object as the package's default export, so ESLint no longer reports a "Cannot redefine plugin" error when the plugin is registered manually and a preset is extended at the same time. (#​1947, closes #​1946)
🏗️ Internal
  • Re-enabled the import-integrity-lint plugin and patched its path prefix check so sibling directories like examples/preact and examples/preact-compat no longer collide.
  • Pinned fast-uri to ^3.1.5 to fix CVE-2026-18446 (GHSA-7p8r-x3mc-p8w7).
  • Bumped @effect/language-service to 0.87.2, @effect/platform to 0.97.1, @effect/platform-node to 0.108.1, @nubjs/nub to 0.8.2, @types/node to 26.4.1, dprint to 0.57.0, and lucide-react to 1.39.0.

Full Changelog: Rel1cx/eslint-react@v5.18.7...v5.18.8

v5.18.7

Compare Source

🐞 Fixes
  • react-x/set-state-in-effect: no longer misattributes render-phase setState calls to effects when the state updater is passed through a prop function. (#​1945)
🏗️ Internal
  • Bumped typescript-eslint to 8.69.0, eslint to 10.9.1, vitest to 4.1.11, @types/node to 26.4.0, @types/react-dom to 19.2.5, eslint-plugin-package-json to 1.8.0, import-integrity-lint to 1.3.0, nx to 23.1.3, publint to 0.3.24, typedoc-plugin-markdown to 4.13.0, and pnpm to 11.25.0.
New Contributors

Full Changelog: Rel1cx/eslint-react@v5.18.6...v5.18.7

eslint/config-inspector (@​eslint/config-inspector)

v3.5.0

Compare Source

Features
  • upgrade devframe to v1.0 (ec32c8f)

v3.4.1

Compare Source

Bug Fixes
  • don't crash stats when a pass has no parse timing (#​334) (48de2ef)

v3.4.0

Compare Source

Features
  • add --stats flag to the dev and build commands (#​332) (f5e983c)
  • add stats panel for on-demand ESLint timing analysis (#​329) (a006be1)

v3.3.0

Compare Source

Features
ota-meshi/astro-eslint-parser (astro-eslint-parser)

v3.2.0

Compare Source

Minor Changes
browserslist/browserslist (browserslist)

v4.29.2

Compare Source

  • Fixed ignoring null usage in cover X in Y query (by @​wahidrizka).

v4.29.1

Compare Source

v4.29.0

Compare Source

  • Added query continuations across lines and array entries (by @​fzlzjerry).

v4.28.9

Compare Source

sindresorhus/globals (globals)

v17.12.0

Compare Source


beaugunderson/ip-address (ip-address@<=10.1.0)

v10.7.2

Compare Source

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.1...v10.7.2

v10.7.1

Compare Source

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.0...v10.7.1

v10.7.0

Compare Source

What's Changed

  • Add offset() and nextNetwork(), accept prefix-length ip6.arpa names, correct the IPv6 end-address docs by @​beaugunderson in #​225

Full Changelog: beaugunderson/ip-address@v10.6.0...v10.7.0

v10.6.0

Compare Source

What's Changed

Full Changelog: beaugunderson/ip-address@v10.5.1...v10.6.0

v10.5.1

Compare Source

lint-staged/lint-staged (lint-staged)

v17.6.0

Compare Source

Minor Changes
  • #​1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    
    export default defineConfig({
      '*': {
        title: 'Fail if PDF files are committed',
        task: async (filepaths, { log }) => {
          const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
          if (pdfFiles.length > 0) {
            log('PDF files should not be committed: %s', pdfFiles)
            throw new Error('Failed')
          }
        },
      },
    })
  • #​1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes
  • #​1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #​1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    
    export default defineConfig({
      '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })
  • #​1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #​1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

v17.5.1

Compare Source

Patch Changes
  • #​1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

v17.5.0

Compare Source

Minor Changes
  • #​1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.
Patch Changes
  • #​1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #​1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #​1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

v17.4.1

Compare Source

Patch Changes
  • #​1840 efe5b63 - This is a version-bump-only release because the previous version 17.4.0 was not published to npmjs.com due to problems with GitHub Actions and Changesets.
oxc-project/oxc (oxfmt)

v0.71.0: oxfmt v0.71.0

Compare Source

🚀 Features
🐛 Bug Fixes
  • eeba1db formatter: Skip test-call layout when arguments have comments (#​27119) (leaysgur)
  • 1f7b8ad oxfmt: Allow repeated CLI calls in the same process (#​27051) (Liang)
  • 7bcb807 formatter_markdown: Keep blank line between HTML and nested list (#​27112) (leaysgur)
  • 10b10c5 formatter: Keep comments around = on their side and line (#​27041) (leaysgur)
  • 9aad365 formatter: Keep comments deferred before an assignment operator (#​26997) (waltu)
  • 8fbddb1 formatter/jsdoc: More alignment with original plugin (#​27039) (leaysgur)
  • 50be18e formatter: Keep trailing spaces on normal block comments (#​27037) (leaysgur)
  • 56d1880 formatter: Nestle adjacent block comments (#​27036) (leaysgur)
  • 3be5d94 formatter: Treat /*** comments as JSDoc (#​27035) (leaysgur)
  • cd45f71 formatter: Keep trailing double spaces on JSDoc lines (#​26861) (John Costa)
  • fd695f4 formatter_markdown: Fix more mismatches found in ecosystem-ci repos (#​27003) (leaysgur)
  • 4e77d59 formatter_markdown: Keep a math span after a kept line break from opening a block (#​27001) (leaysgur)
  • 584b8b0 formatter_markdown: Keep a shape line after a multi-line inline node or link title (#​27000) (leaysgur)
  • b939645 formatter_markdown: Keep a line break before an inline liquid tag under preserve (#​26998) (leaysgur)

v0.70.0: oxfmt v0.70.0

Compare Source

🚀 Features
  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#​26763) (leaysgur)

v0.69.0

Compare Source

v0.68.0

Compare Source

v0.67.0

Compare Source

🛡️ Security

v0.66.0

Compare Source

v0.65.0

Compare Source

v0.64.0

Compare Source

🚀 Features
📚 Documentation
pnpm/pnpm (pnpm)

v11.28.2: pnpm 11.28.2

Compare Source

pnpm 11.28.2 fixes pnpm install skipping every workspace project whose common ancestor is the filesystem root, and stops pnpm run from reinstalling or installing when nothing needs it.

Patch Changes
  • pnpm install reported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as / or a drive root like C:\. It now installs these projects #​16328.

  • verifyDepsBeforeRun no longer reports dependencies as outdated after a filtered install just because pnpm-lock.yaml has a newer modification time. It checks the lockfile against the packages that install put in place. Before, pnpm run reinstalled the whole workspace with lifecycle scripts on, for example after a Docker COPY brought in a lockfile with a newer mtime #​16322.

    After a filtered install, verifyDepsBeforeRun now also checks that the install put the selected projects' dependencies in place. A node_modules directory alone no longer counts as proof.

  • pnpm run and pnpm exec no longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies that autoInstallPeers would fetch, and no install lifecycle scripts. The command now runs without writing node_modules or pnpm-lock.yaml #​16313.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from prisis as a code owner September 8, 2026 15:46
@renovate renovate Bot added the c: dependencies Pull requests that adds/updates a dependency label Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@socket-security

socket-security Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

@pkg-pr-new

pkg-pr-new Bot commented Sep 8, 2026

Copy link
Copy Markdown

Open in StackBlitz

browserslist-config-anolilab

npm i https://pkg.pr.new/browserslist-config-anolilab@1150

@anolilab/commitlint-config

npm i https://pkg.pr.new/@anolilab/commitlint-config@1150

@anolilab/eslint-config

npm i https://pkg.pr.new/@anolilab/eslint-config@1150

@anolilab/lint-staged-config

npm i https://pkg.pr.new/@anolilab/lint-staged-config@1150

@anolilab/oxfmt-config

npm i https://pkg.pr.new/@anolilab/oxfmt-config@1150

@anolilab/oxlint-config

npm i https://pkg.pr.new/@anolilab/oxlint-config@1150

@anolilab/prettier-config

npm i https://pkg.pr.new/@anolilab/prettier-config@1150

@anolilab/stylelint-config

npm i https://pkg.pr.new/@anolilab/stylelint-config@1150

@anolilab/textlint-config

npm i https://pkg.pr.new/@anolilab/textlint-config@1150

commit: 0a896ff

@renovate
renovate Bot force-pushed the renovate/minor-updates branch 2 times, most recently from 6d04003 to aae075b Compare September 11, 2026 15:46
@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 80ce902b-054d-4b78-8541-4edb816d6c54

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/minor-updates branch 3 times, most recently from 54196b2 to fb7783b Compare September 18, 2026 14:20
@renovate
renovate Bot force-pushed the renovate/minor-updates branch 2 times, most recently from 210073e to 776b528 Compare September 29, 2026 16:25
@renovate
renovate Bot force-pushed the renovate/minor-updates branch from 776b528 to 1c8ea15 Compare October 1, 2026 16:21
Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate
renovate Bot force-pushed the renovate/minor-updates branch from 1c8ea15 to 81232a2 Compare October 2, 2026 10:30
@prisis

prisis commented Oct 3, 2026

Copy link
Copy Markdown
Member

Superseded by the consolidated dependency update now on main.

@prisis prisis closed this Oct 3, 2026
@prisis
prisis deleted the renovate/minor-updates branch October 3, 2026 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c: dependencies Pull requests that adds/updates a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant