Skip to content

fix(deps): update npm dependencies updates (major) - #125

Open
renovate[bot] wants to merge 1 commit into
developfrom
renovate/major-npm-dependencies-updates
Open

fix(deps): update npm dependencies updates (major)#125
renovate[bot] wants to merge 1 commit into
developfrom
renovate/major-npm-dependencies-updates

Conversation

@renovate

@renovate renovate Bot commented Oct 27, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
create-strapi-app (source) 4.6.*5.52.* age confidence
jscpd (source) 4.0.*5.0.* age confidence
release-it 19.0.*21.0.* age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

strapi/strapi (create-strapi-app)

v5.52.0

Compare Source

5.52.0 (2026-08-12)

🚀 New feature
  • record MCP actions in audit logs (#​27151)
  • i18n: add locale codes for Corsican (#​27099)
  • server: enhance Koa app configuration with proxy settings (#​26409)
🔥 Bug fix
  • typescript pipeline issue (99a723d024)
  • admin: dedupe react-dnd in the admin bundle (#​27217)
  • admin: address filter entries by position so duplicate filter chips behave (#​27188)
  • content-manager: merge query populate paths to preserve nested populate (#​27236)
  • content-type-builder: editing relations removes inverse field conditions (#​27226)
  • content-type-builder: clear stale validation errors when the form data is replaced (#​27222)
  • data-transfer: skip orphaned links and isolate FK failures on restore (#​26852)
  • permissions: skip unregistered RBAC conditions during ability generation (#​27282)
  • strapi: allowlist Vite optimizeDeps.exclude for plugin UI kits (#​27264)
  • upload: refresh folder header count on upload & delete (CMS-1563) (#​27231)
  • upload: guard cache-buster on signed URLs in new-ML AssetCropEditor (#​27228)
  • upload: target current asset in drawer actions (#​27259)
  • upload: keep infinite scroll loading when the sentinel stays visible (CMS-1562) (#​27230)
⚙️ Chore
  • release v5.51.2 update develop (101643bcfb)
  • bump design system version (#​27292)
  • cloud-cli: migrate unit tests from jest to vitest (#​27218)
  • database: replace umzug with internal migration runner (#​26824)
  • deps: bump ip-address from 10.2.0 to 10.4.0 (#​27238)
  • deps: bump ws from 8.21.1 to 8.21.2 (#​27239)
  • deps: bump hono from 4.12.27 to 4.13.0 (#​27243)
  • deps: bump prettier from 3.3.3 to 3.6.2 (#​27244)
  • deps: bump direct deps and yarn dedupe (#​27291)
  • deps: bump nanoid from 3.3.16 to 3.3.18 (#​27329)
  • permissions: migrate unit tests from jest to vitest (#​27219)
  • sentry: migrate unit tests from jest to vitest (#​27252)
  • tooling: add admin translation verification (#​26960)
  • upload-aws-s3: migrate unit tests from jest to vitest (#​27216)
💅 Enhancement
  • utils: memoize private attributes in sanitizeOutput (#​27140)
  • utils: stop using a thrown Error to test for boolean-like populate keys (#​27234)
  • utils: memoize scope decisions and keep the relation visitor sync (#​27145)
🚨 Security
❤️ Thank You

v5.51.2

Compare Source

5.51.2 (2026-08-05)

🚀 New feature
  • content-manager: add optional component screenshots to DZ picker (#​26863)
🔥 Bug fix
  • use radio roles for accessibility and improve aria attributes (#​27139)
  • handle i18n conflict and local rights (6519f4d5db)
  • admin: interpolate min/max values in validation error messages (#​27172)
  • admin: pin react-colorful to prevent optimizeDeps include/exclude conflict (#​27203)
  • content-manager: relation creation discards parent changes (#​27081)
  • content-manager: relation order changes after saving dynamic-zone components (#​27135)
  • content-manager: keep document status accurate on mixed-locale batches (#​27035)
  • core: use configured default pageSize when only page is provided (#​27132)
  • database: escape LIKE wildcards in filters and use equality for $eqi/$nei (#​26476)
  • i18n: use fractional temp_key when filling from locale (#​26296)
  • upload: stream URL imports to disk instead of buffering in memory (#​27176)
  • upload: keep cursor position while editing asset details fields (CMS-1536) (2c6edbfacb)
  • upload: apply asset permissions to media library actions (CMS-434) (e8099188e2)
  • upload: keep crop drag tracking on touch devices (CMS-1538) (7807ea83dc)
  • upload: keep asset drawer header visible on mobile (CMS-1539) (4edad7ca75)
  • upload: media library MVP fixes (7a4012c65a)
📚 Documentation Changes
  • add contributor documentation for the MCP server (#​27160)
⚙️ Chore
  • deps: bump @​hono/node-server from 1.19.14 to 1.19.17 (#​27166)
  • deps: bump postcss from 8.5.14 to 8.5.25 (#​27195)
  • deps: bump brace-expansion from 1.1.16 to 1.1.18 (#​27196)
  • deps: bump js-yaml from 3.15.0 to 3.15.1 (#​27197)
  • deps: bump motion from 12.23.24 to 12.40.0 (#​27133)
  • deps: bump tar from 7.5.21 to 7.5.22 (#​27165)
  • deps: bump react-router-dom from 6.30.3 to 6.30.4 (#​27134)
  • deps: bump undici from 6.27.0 to 6.28.0 (#​27164)
  • deps: bump axios from 1.18.1 to 1.19.0 (#​27198)
  • deps: align app-template react-router-dom with admin 6.30.4 (#​27210)
  • jest: run unit/front tests via nx, drop root jest config and dep (#​26701)
  • lint: add non-blocking oxlint setup (#​26923)
  • users-permissions: move server code into server/src (#​26105)
💅 Enhancement
  • content-type-builder: support required on relation attributes (#​27080)
  • core: look models up on the registries in getModel (#​27143)
  • database: reduce per-column work when mapping rows to entities (#​27144)
⚠️ Changes to be aware of
Filter operators: literal wildcards and true case-insensitive equality

$eqi / $nei now do real case-insensitive equality (= LOWER(?)), not LIKE, so values with %, _, or a trailing \ no longer act as wildcards or crash some databases. Substring operators ($contains, $startsWith, $endsWith, and case-insensitive variants) now treat %, _, and \ in the filter value as literal characters. If you relied on % / _ inside those filters as SQL wildcards, update filters to match the new literal semantics.
(#​26476)

❤️ Thank You

v5.51.1

Compare Source

5.51.1 (2026-07-29)

🔥 Bug fix
  • respect field length constraints in AI localizations and isolate… (#​26880)
  • wording and merging sort options (844c8d625d)
  • preserve sorting on view change (6ed616ab9a)
  • admin: scope audit logs user filter to log authors (#​27047)
  • content-manager: homepage recent-documents dates serialize as empty objects (#​27066)
  • core: enforce required media and relations via api.documents.strictRelations (#​27028)
  • database: return [] for empty morphMany on read (#​27090)
  • strapi: prevent duplicate public assets in Vite builds (#​27089)
⚙️ Chore
  • admin: allow RFC 6265 control-char regex under develop eslint rules (e8338bb6ba)
  • ci: remove admin bundle-size workflow (#​27070)
  • deps: bump brace-expansion from 1.1.14 to 1.1.16 (#​27071)
  • deps: bump shell-quote from 1.8.4 to 1.10.0 (#​27072)
  • deps: bump body-parser from 1.20.4 to 1.20.6 (#​27094)
  • deps: bump dompurify from 3.4.11 to 3.4.12 (#​27095)
  • deps: bump fast-uri from 3.1.2 to 3.1.4 (#​27098)
  • deps: bump use-context-selector from 1.4.1 to 1.4.4 (#​27061)
  • deps: bump cropperjs from 1.6.1 to 1.6.2 (#​27060)
  • deps: upgrade handlebars, axios, tar, and related transitive deps (#​27091)
  • deps: bump @​radix-ui/react-toolbar from 1.0.4 to 1.1.11 (#​27059)
  • email-nodemailer: migrate unit tests from jest to vitest (#​27074)
  • email-sendmail: migrate unit tests from jest to vitest (#​27075)
  • upload-local: migrate unit tests from jest to vitest (#​27073)
⚠️ Changes to be aware of
Required media and relations: opt-in strictRelations

New config api.documents.strictRelations enforces required media and relations on publish (drafts can still be empty). On by default for new projects; existing apps are unchanged until you set it. To opt in, set documents.strictRelations: true in config/api.
(#​27028)

Empty multiple media / morphMany now returns []

Populated empty morphMany relations (including type: 'media', multiple: true) serialize as [] instead of null, matching other to-many relations. This is unconditional and not gated by strictRelations. If clients, webhooks, or integrations check field === null for empty galleries / morphMany, treat [] as empty instead (e.g. !field?.length).
(#​27090)

❤️ Thank You

v5.51.0

Compare Source

5.51.0 (2026-07-23)

🚀 New feature
  • data-transfer: add exclude/only content type CLI filters (#​26915)
  • i18n: add locale codes for Abkhazian and Circassian (Adyghe and Kabardian) (#​26255)
🔥 Bug fix
  • preserve order when reordering a relation to the start of a list (#​26112)
  • singleton modules for consistent runtime instances (#​27064)
  • admin: admin session token respects configured admin-cookie-path (#​25478, #​26300)
  • admin: make plugin/setting "Select all" work in admin token permissions (#​27027)
  • admin: revalidate SPA shell to avoid stale chunk imports (#​27039)
  • admin: expire admin reset-password tokens (#​27020)
  • admin: improve SSO session metadata and logout revocation (#​26872)
  • admin: blank admin in develop from prism language prebundle (#​27086)
  • admin: SSO remote logout infinite redirect (cookie path) (#​27100)
  • content-manager: pre-bundle prism language plugins for all apps (#​26978)
  • content-manager: respect disconnected draft relations in publish warning (#​26871)
  • content-manager: validate items passed to plugin action APIs (#​27008)
  • content-manager: skip blocks editor remount on equal value echoes (#​27042)
  • content-manager: keep preview button mounted during document churn (#​27043)
  • content-releases: normalise release id so rescheduling cancels the stale job #/strapi/pull/27063))
  • core: enforce default maxLength 255 for string fields (#​26128)
  • core: preserve draft relation order in discard-drafts migration (#​26851)
  • core: propagate server updatedAt in addFirstPublishedAtToDraft to avoid false modified flag (#​26525)
  • create-strapi-app: npm ci fails on fresh npm scaffold (#​27038)
  • create-strapi-app: missing @​strapi/database dependency breaks pnpm builds (#​27083)
  • database: apply MySQL dialect configure to resolved connection functions (#​26646)
  • graphql: include private fields in mutation inputs (#​26489)
  • types: update LoadedPlugin type to understand factories (#​25298)
  • upload: report real upload progress in the media library (#​27045)
  • users-permissions: use correct i18n ids for role notifications (#​27044)
  • users-permissions: fix role notification translations (#​26933)
⚙️ Chore
  • merge main into develop after 5.50.2 release (9d93244f7e)
  • deps: bump ws from 8.21.0 to 8.21.1 (#​27030)
  • deps: bump tar from 7.5.18 to 7.5.20 (#​27029)
  • deps: bump linkify-it from 5.0.0 to 5.0.2 (#​26886)
  • email-mailgun: migrate unit tests from jest to vitest (#​27069)
  • types: per-client database connection types (#​26949)
  • users-permissions: replace grant/purest/jwk-to-pem with fetch and crypto (#​26820)
  • utils: upgrade preferred-pm to v5 with dynamic import (#​26822)
❤️ Thank You

v5.50.2

Compare Source

5.50.2 (2026-07-15)

🚀 New feature
  • admin: make admin auth cookie name configurable (#​26931)
  • i18n: complete Korean (ko) translation (#​26941)
🔥 Bug fix
  • admin: prevent deprecated CJS Vite Node API warning on startup (#​26947)
  • admin: pre-commit fails when staging files ignored by ESLint (#​26958)
  • admin: show plan label instead of edition in dashboard (#​26891)
  • admin: restore runtime default for context helper (#​26809)
  • ci: reduce false positives in issue template checker (#​26955)
  • ci: use npm install in issue template checker workflow (#​26974)
  • content-manager: clear stale Blocks editor selection on external value change (#​26959)
  • core: backward compat - reject 'status' attribute when draftAndPublish is enabled (#​26890)
  • core: validate license registry responses with zod (#​26935)
  • core: preserve duplicate form relation edits when cloning (#​26961)
  • data-transfer: bump ws to 8.21.0 to fix CVE-2026-48779 (#​26898)
  • database: include status sort expression in SELECT when using DISTINCT (#​26751)
  • database: lint script does not run type check (#​26819)
  • email: only warn about sendmail provider in development (#​26893)
  • openapi: add bearerAuth and bracket pagination query params (#​26948)
  • strapi: auto-exclude pre-built plugin UI libs from Vite optimizeDeps (#​26944)
  • strapi: fix develop blank admin from optimizeDeps auto-exclude (#​27014)
  • upgrade: prompt to pin ranged @​strapi/* dependencies before upgrading (#​26929)
  • upload: load remote asset thumbnails with crossOrigin to prevent CORS preview failures (#​26581, #​26901)
  • utils: align remaining convert-query-params errors with ValidationError (#​26908)
⚙️ Chore
⚠️ Changes to be aware of
Admin auth cookie name

You can set admin.auth.cookie.name in admin config to rename the access-token cookie (default remains jwtToken). Useful when another app on a shared parent domain sets a jwtToken cookie and breaks admin login.

(#​26931)

status attribute with Draft & Publish

In v5, status is reserved for draft/published filtering. If a content type has Draft & Publish enabled and a custom status field, Strapi now logs a startup warning instead of failing boot. The Content-Type Builder still blocks adding status or enabling D&P when status already exists.

(#​26890)

Upgrade tool and ranged @strapi/* versions

@strapi/upgrade now warns and offers to pin ranged @strapi/* dependencies (e.g. ^5.50.0) before upgrading, so upgrades don't silently report "already up-to-date" when node_modules resolved ahead of package.json.

(#​26929)

❤️ Thank You

v5.50.1

Compare Source

5.50.1 (2026-07-08)

🚀 New feature
  • i18n: complete Japanese (ja) translations (#​26855)
  • i18n: update Polish translation (#​26592)
🔥 Bug fix
  • give the ability to open a list item in a new tab (#​26853)
  • admin: translate enumeration option labels in the content manager (#​26837)
  • admin: seat limit billing links (#​26728)
  • cloud: hide deploy menu in production using currentEnvironment (#​26733)
  • content-manager: allow reading hidden content types for relation targets (#​26844)
  • content-manager: preserve i18n locale on navigation and guard component schema race condition (#​26167)
  • core: preserve self-referential relation order on child publish (#​26838)
  • core: preserve published self-referential relation state (#​26932)
  • database: prevent crash when reordering and removing a relation in the same save (#​26210)
  • documentation: allow array populate parameter (#​26358)
  • examples: enable strict TypeScript in dev sandboxes (#​26780)
  • generators: detect plugin language from output path (#​26750)
  • review-workflows: add server eslint config and declare server deps (#​26800)
  • strapi: resolve admin Vite aliases from @​strapi/admin closure (#​26756)
  • typescript-utils: emit namespace keyword instead of deprecated module (#​26195)
  • upload: accept single-file arrays on replacement (#​26405)
  • utils: align polymorphic populate validation with conversion (#​26848)
  • utils: return 400 instead of 500 for invalid sort order/params (#​26907)
📚 Documentation Changes
  • Highlight destructive operation in transfer engine (#​25081)
⚙️ Chore
💅 Enhancement
  • ci: block community PRs targeting main (#​26854)
  • content-manager: keep sidebar primary actions and search bar fixed… (#​26867)
❤️ Thank You

v5.50.0

Compare Source

5.50.0 (2026-07-02)

🚀 New feature
  • admin: add active devices session management (#​26628)
  • cli: add security defaults to create-strapi-app templates (#​26737)
  • database: export lifecycle event type (#​25637)
  • provider-email-sendgrid: add region option for EU data residency (#​25907)
  • provider-upload-aws-s3: accept a credential provider function (#​26796)
  • translations: comprehensive Japanese (ja) translation update for admin and 9 plugins (#​26687)
  • ts: augment all context error response methods (#​25424)
🔥 Bug fix
  • refresh token cookies missing Max-Age when sessions.cookie.maxAg… (#​26747)
  • add test database healthchecks (#​26511)
  • generate apis in named directories (#​26354)
  • admin: retry lazy chunk loads and improve loading and error UX (#​25954)
  • admin: open "Upgrade your admin panel" link in new tab (#​26510)
  • admin: remove @​ts-expect-error in useQueryParams hook (#​25006)
  • admin: hide boolean clear action when field is disabled (#​26294)
  • admin: restore default locale in permissions when adding i18n to ct (#​26548)
  • admin: keep static fallback paths url-safe (#​26518)
  • admin: stop storing IP addresses in session metadata (#​26873)
  • ci: use allowlisted thollander action ref in experimental publish workflow (#​26768)
  • content-api: validate populate for polymorphic structures (#​25854)
  • content-manager: warn before publishing with draft relations (#​26736)
  • content-manager: use ListViewTable relation-loaded translation key (#​26798)
  • content-manager: serve live preview script from server endpoint (#​26732)
  • content-manager: capitalize component category names in dynamic zone (#​24426, #​26337)
  • content-manager: add Japanese EditView shortcut hint translations (#​26814)
  • content-manager: prevent dynamic zone crash when value is null (#​26816)
  • content-manager: skip publish warning for M2M links to published entries (#​26858)
  • content-type-builder: improve component category validation error message (#​25455)
  • core: preserve M2M relation order on published version after reo… (#​26791)
  • core: maxFileSize error not detected in body middleware (#​25011)
  • core: resolve relations on non-localized entries with stale locale column (#​26805)
  • create-strapi-app: scaffold pnpm 11 allowBuilds for Strapi Cloud (#​26757)
  • create-strapi-app: enable strict TypeScript in app scaffolds (#​26779)
  • create-strapi-app: limit odd Node major warning to versions before 26 (#​26810)
  • data-transfer: restore localizations links that use document_id refs (#​26870)
  • graphql: preserve M2M relation order with pagination (#​26577, #​26785)
  • test: tighten jest ignore patterns to match path segments (#​26753)
  • translations: correct ja "characters" mistranslation in WYSIWYG controls (#​26845)
  • types: tighten Core.Config typings with backward-compatible deprecations (#​26787)
  • upload: disable asset editing and deletion on published entries (#​26127)
  • users-permissions: accept documentId for the role relation on user create/update (#​26715)
  • users-permissions: correct "occured" → "occurred" typo in error notifications (#​26508)
  • utils: prevent crash on null dynamic zone entry during traversal (#​24303, #​26842)
📚 Documentation Changes
  • fix typos and grammar slips in content-manager docs (#​26600)
⚙️ Chore
  • add ai-tooling sync script for skill symlinks (#​26594)
  • rename ai-tooling yarn scripts to ai:* (#​26767)
  • reduce Vercel noise on PRs (contributor-docs ignore step) (#​26772)
  • cloud plugin updates (#​26801)
  • update cli deploy copies (f0fa460525)
  • deps: hoist @​types/node to root and align with 20, min supported engine (#​26291)
  • deps: upgrade TypeScript to 5.9.3 (#​26782)
  • deps: bump hono from 4.12.23 to 4.12.27 (#​26761)
  • deps: bump design-system to v2.2.1 (#​26788)
  • deps: bump axios from 1.18.0 to 1.18.1 (#​26762)
  • deps: upgrade lint-staged to 16 and scope linting to staged files (#​26765)
  • deps: remove unused @​strapi/ts-zen dev dependency (#​26759)
  • typescript: enable erasableSyntaxOnly and noUncheckedSideEffectImports (#​26790)
  • workflows: make documentation flag name more obvious (#​26649)
💅 Enhancement
  • admin: add uz-Cyrl native name to languageNativeNames (#​24920)
  • strapi: lazy-load TypeScript chain for non-build CLI commands (#​26265)
  • utils: add env.required for strict scaffold secrets (#​26830)
🚨 Security
  • users-permissions: default legacy JWT verify to HS256 (#​26752)
❤️ Thank You

v5.49.0

Compare Source

5.49.0 (2026-06-24)

🚀 New feature
  • mcp: export defineTool/defineResource/definePrompt builders (#​26603)
🔥 Bug fix
  • add support for initiallySelectedAssets (#​26679)
  • homepage dashboard duplicates entries for users with multiple roles (#​25860)
  • avoid buffering large uploads for MIME detection (#​26678)
  • throw ValidationError when populate exceeds qs arrayLimit (#​25632, #​25916)
  • push anchor into view to prevent off-screen tooltips (#​26303)
  • admin: support array of links in StrapiApp.addSettingsLink (#​26433)
  • admin: admin users logged out mid-session by access-token expiry timer (#​26680)
  • content-manager: use top-level Core type import in MCP types (#​26681)
  • content-manager: save draft with Cmd/Ctrl+Enter, publish with Cmd/Ctrl+Shift+Enter (#​26621)
  • content-manager: reduce MCP relation output to identity-only shape (#​26560)
  • content-manager: deduplicate MCP tool names when plugin has multiple content types (#​26710)
  • core/core: mcp misleading lifecycle docs (#​26698)
  • create-strapi-app: allow pnpm to build better-sqlite3 for SQLite scaffolds (#​26675)
  • data-transfer: transfer admin menu and auth logos with configuration (#​26425)
  • database: stop full-schema component_type IN on dynamic zone populate (#​26734)
  • document-service: preserve published relations from non-dp sources (#​26654)
  • strapi: default allowedHosts and pin Vite HMR to main server in dev (#​26244)
  • types: add explicit return types to recursive functions (#​26704)
📚 Documentation Changes
  • fix spelling typos in content-manager relations guide (#​26724)
⚙️ Chore
  • removing coderabbit status (#​26703)
  • core: upgrade package-json to 10.0.1 + rollup interop 'auto' (#​26673)
  • deps: bump markdown-it from 14.1.1 to 14.2.0 in the richtext-editor-security group across 1 directory (#​26688)
  • deps: bump dompurify from 3.4.5 to 3.4.9 (#​26684)
  • deps: bump nodemailer from 8.0.5 to 8.0.9 (#​26689)
  • deps: bump tar from 7.5.11 to 7.5.16 (#​26691)
  • deps: bump form-data from 4.0.4 to 4.0.6 (#​26692)
  • deps: bump anthropics/claude-code-action from 1.0.123 to 1.0.132 (#​26727)
  • deps: bump piscina from 4.9.2 to 4.9.3 (#​26716)
  • deps: bump undici from 6.25.0 to 6.27.0 (#​26714)
  • deps: bump dompurify from 3.4.9 to 3.4.11 (#​26719)
  • deps-dev: bump @​babel/core (#​26667)
💅 Enhancement
  • upload: add optional replace method to upload providers (#​26582)
❤️ Thank You
⚠️ Changes to be aware of
Content Manager keyboard shortcuts

Save a draft with Cmd/Ctrl+Enter (or Cmd/Ctrl+S). Publish with Cmd/Ctrl+Shift+Enter. Since v5.31.3, plain Cmd/Ctrl+Enter published immediately — that shortcut now saves instead. (#​26621)

v5.48.1

Compare Source

5.48.1 (2026-06-17)

🚀 New feature
  • linking to the Billing Portal (3df113f545)
  • pointing Upsell Banner to Strapi Billing (06b0c31f47)
  • add optional openapi spec route (#​26239)
  • updating billing portal address (2d3fea21ff)
  • openapi: gate endpoint access with config (#​26574)
  • upload: add paginated GET /api/upload/files/page endpoint (#​26597)
🔥 Bug fix
  • upload returns unsigned URL on update media info (#​25195)
  • widgets show error when role has no access to mainfield of ct (#​26537)
  • correct IME Enter key handling in BlocksInput (#​24997)
  • admin: return empty object for empty json body in fetch client (#​26277)
  • admin: exclude disabled plugins from admin build (#​26448)
  • admin: rate limit and serialize first admin registration (#​26576)
  • admin: validate current user email updates (#​26591)
  • admin: guard stale admin configuration (#​26625)
  • build: build does not run install; add install-deps arg (#​26483)
  • ci: run build:size as full command for compressed-size-action v3 (#​26556)
  • ci: restore allowed paths-filter pin (#​26575)
  • ci: avoid syncing CPR labels to CMS tickets (#​26648)
  • content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#​26522)
  • content-manager: raise z-index of code block language selector (#​25010, #​26324)
  • content-manager: dedupe bulk delete document ids (#​26613)
  • content-manager: replace sanitize-html with dompurify in Wysiwyg preview (#​26150)
  • core: validate numeric inputs before DB unique checks (#​26101)
  • **core/admin | content-m

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Paris)

  • Branch creation
    • "before 8am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 3 times, most recently from 552df15 to 631b146 Compare November 5, 2025 19:38
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from 4e1aa45 to c9da5af Compare November 18, 2025 22:53
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from 1d13147 to e3b2bd3 Compare November 20, 2025 14:08
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from e3b2bd3 to c87fe97 Compare December 3, 2025 17:37
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from 05acf37 to aba4860 Compare December 17, 2025 20:55
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from aba4860 to 1c50fe0 Compare December 29, 2025 12:04
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from a4a36d6 to 740ae4c Compare January 14, 2026 13:12
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 3 times, most recently from 3157106 to 917ab47 Compare January 23, 2026 18:36
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from 917ab47 to c929600 Compare January 28, 2026 17:58
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from 3082488 to c872031 Compare February 11, 2026 18:00
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from c872031 to 75a273a Compare February 18, 2026 18:51
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 3 times, most recently from 84b5bb7 to 20d2e0c Compare March 4, 2026 16:47
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from e4b459c to fe7c266 Compare March 11, 2026 13:21
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from fe7c266 to 9b59465 Compare March 18, 2026 17:27
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from a43adcc to 3290226 Compare April 1, 2026 14:06
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from 3290226 to add3f3e Compare April 8, 2026 15:00
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from add3f3e to 2d1053a Compare April 15, 2026 17:18
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 5 times, most recently from 7a17a29 to 1f4bad1 Compare June 3, 2026 16:10
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 4 times, most recently from 3fbf6bd to 9c526ae Compare June 13, 2026 19:55
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 3 times, most recently from fdd69f1 to a55c479 Compare June 24, 2026 14:14
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 2 times, most recently from c25b34e to e29aa08 Compare July 2, 2026 13:07
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 4 times, most recently from 01b6b80 to 1052362 Compare July 15, 2026 11:40
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 4 times, most recently from e9c73e8 to 0359f15 Compare July 29, 2026 12:44
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 3 times, most recently from 679fe5b to 8cf4a5a Compare August 5, 2026 14:58
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch 3 times, most recently from 4742bb7 to e03e745 Compare August 12, 2026 08:51
@renovate
renovate Bot force-pushed the renovate/major-npm-dependencies-updates branch from e03e745 to b2c8fb3 Compare August 13, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants