Skip to content

fix(deps): update javascript dependencies - #698

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/javascript-dependencies
Open

fix(deps): update javascript dependencies#698
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/javascript-dependencies

Conversation

@renovate

@renovate renovate Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
@kenn-io/kit-ui (changelog) dependencies digest 4d90fdf695cbf4
@lucide/svelte (source) dependencies minor 1.23.01.24.0 1.25.0 age confidence
@sveltejs/vite-plugin-svelte (source) devDependencies minor 7.1.27.2.0 age confidence
@tiptap/core (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/extension-document (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/extension-hard-break (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/extension-paragraph (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/extension-placeholder (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/extension-text (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/pm (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@tiptap/suggestion (source) dependencies patch 3.27.13.27.3 3.28.0 (+1) age confidence
@vitest/browser-playwright (source) devDependencies patch 4.1.94.1.10 age confidence
dompurify dependencies patch 3.4.113.4.12 age confidence
dompurify overrides patch 3.4.113.4.12 age confidence
marked (source) dependencies patch 18.0.518.0.6 age confidence
shiki (source) dependencies patch 4.3.04.3.1 age confidence
svelte-check devDependencies patch 4.7.14.7.2 4.7.3 age confidence
vite (source) devDependencies patch 8.1.38.1.4 8.1.5 age confidence
vite-plus (source) devDependencies patch 0.2.30.2.4 0.2.5 age confidence
vitest (source) devDependencies patch 4.1.94.1.10 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔡 If you wish to disable git hash updates, add ":disableDigestUpdates" to the extends array in your config.


Release Notes

lucide-icons/lucide (@​lucide/svelte)

v1.24.0: Version 1.24.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.23.0...1.24.0

sveltejs/vite-plugin-svelte (@​sveltejs/vite-plugin-svelte)

v7.2.0

Compare Source

Minor Changes
  • feat(inspector): add a context menu with current component stack (#​1370)

v7.1.4

Compare Source

Patch Changes
  • fix: enforce ltr styles for inspector (#​1324)

v7.1.3

Compare Source

Patch Changes
  • fix: ensure the inspector is injected into the client correctly for Vite+ projects (#​1355)
ueberdosis/tiptap (@​tiptap/core)

v3.27.3

Compare Source

Patch Changes
  • 023f98c: Fix deleteSelection to delete content across all selection ranges instead of only the first range. This restores multi-cell table selections and other custom selections with multiple ranges.

v3.27.2

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/extension-document)

v3.27.3

Compare Source

Patch Changes

v3.27.2

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/extension-hard-break)

v3.27.3

Compare Source

Patch Changes

v3.27.2

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/extension-paragraph)

v3.27.3

Compare Source

Patch Changes

v3.27.2

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/extension-placeholder)

v3.27.3

Compare Source

Patch Changes

v3.27.2

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/extension-text)

v3.27.3

Compare Source

Patch Changes

v3.27.2

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/pm)

v3.27.3

Compare Source

v3.27.2

Compare Source

Patch Changes
  • ceebb31: Updated all ProseMirror packages to the latest publicly available versions
ueberdosis/tiptap (@​tiptap/suggestion)

v3.27.3

Compare Source

Patch Changes

v3.27.2

Compare Source

Patch Changes
vitest-dev/vitest (@​vitest/browser-playwright)

v4.1.10

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
cure53/DOMPurify (dompurify)

v3.4.12: DOMPurify 3.4.12

Compare Source

  • Fixed an issue where a hook would not get called for custom elements, thanks @​Rikuxx0
  • Hardened the handling of hooks removing elements, @​mkrause-bee360
  • Added support for a few new SVG attributes, thanks @​cbn-falias & @​Develop-KIM
  • Hardened the handling of declarative partial updates
  • Updated the documentation is several spots, README, wiki, etc.
  • Bumped several dependencies where possible
markedjs/marked (marked)

v18.0.6

Compare Source

shikijs/shiki (shiki)

v4.3.1

Compare Source

   🚀 Features
    View changes on GitHub
sveltejs/language-tools (svelte-check)

v4.7.2

Compare Source

Patch Changes
  • fix: resolve tsgo bin path with package.json (#​3074)

  • fix: report tsconfig errors in --tsgo-experimental-api (#​3070)

vitejs/vite (vite)

v8.1.4

Compare Source

Features
Bug Fixes
Documentation
Miscellaneous Chores
Code Refactoring
Tests
Build System
voidzero-dev/vite-plus (vite-plus)

v0.2.4: vite-plus v0.2.4: Vitest security hotfix

Compare Source

This hotfix updates the bundled Vitest Browser Mode packages to 4.1.10, which includes the fix for GHSA-p63j-vcc4-9vmv. The advisory is critical and affects @vitest/browser <=4.1.9.

Highlights
  • Critical Vitest Browser Mode advisory fixed: bundled vitest and @vitest/browser* move from 4.1.9 to 4.1.10, addressing GHSA-p63j-vcc4-9vmv, where provider commands could bypass the file access permission gate (#​2089), by @​voidzero-guard[bot]
Chore
  • Add the standard release-manager skill for vite-plus release operations (#​2019), by @​fengmk2
Bundled Versions
Tool Version Source
vite 8.1.3 578ffb8
rolldown 1.1.4 6cbd233
tsdown 0.22.3 npm
vitest 4.1.10 npm
oxlint 1.72.0 npm
oxlint-tsgolint 0.24.0 npm
oxfmt 0.57.0 npm
Upgrade
vp upgrade
New Contributors

No new contributors in this release.

Full Changelog: voidzero-dev/vite-plus@v0.2.3...v0.2.4

Published Packages
  • @voidzero-dev/vite-plus-core@0.2.4
  • vite-plus@0.2.4
Installation

macOS/Linux:

curl -fsSL https://vite.plus | bash

Windows:

irm https://vite.plus/ps1 | iex

Or download and run vp-setup.exe from the assets below.

Docker:

docker run --rm -it -v "$PWD:/app" -w /app ghcr.io/voidzero-dev/vite-plus:0.2.4 vp build

Run any vp command without installing it; see the Docker guide for more.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@roborev-ci

roborev-ci Bot commented Jul 19, 2026

Copy link
Copy Markdown

roborev: Combined Review (3189c3a)

One medium-severity issue found; no critical or high-severity findings.

Medium

  • Duplicate @kenn-io/kit-ui instances may split flash statebun.lock:1315
    The lockfile installs a frontend-scoped copy alongside the root copy. App.svelte imports FlashBanner from the frontend copy, while @middleman/ui/stores/flash uses the root copy. This splits the module-local flash singleton, so action errors may not appear in the mounted banner. Ensure both APIs use one package instance—for example, re-export FlashBanner from @middleman/ui, or deduplicate the dependency across workspaces.

Reviewers: 2 done | Synthesis: codex, 9s | Total: 3m47s

The updated shared Typeahead treats partial input as an available custom value and highlights that custom row. These interaction tests are intended to exercise selection of the matching canonical owner and platform values, so they now navigate to the matched option before confirming it.\n\nValidation: ../node_modules/.bin/vp test run (from frontend; 3235 passed, 2 skipped)

Generated with Codex (GPT-5)\nCo-authored-by: Codex <noreply@openai.com>
@roborev-ci

roborev-ci Bot commented Jul 19, 2026

Copy link
Copy Markdown

roborev: Combined Review (668fe72)

No issues found.


Reviewers: 2 done | Synthesis: codex | Total: 3m15s

@renovate

renovate Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@wesm

wesm commented Jul 19, 2026

Copy link
Copy Markdown
Member

NB: kit-ui is being updated separately

@roborev-ci

roborev-ci Bot commented Jul 24, 2026

Copy link
Copy Markdown

roborev: Combined Review (668fe72)

No issues found.


Reviewers: 2 done | Synthesis: codex | Total: 2m1s

@roborev-ci

roborev-ci Bot commented Aug 1, 2026

Copy link
Copy Markdown

roborev: Combined Review (668fe72)

No issues found.


Reviewers: 2 done | Synthesis: codex | Total: 2m39s

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants