Skip to content

chore(deps): update all non-major dependencies - #80

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jul 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@antfu/ni ^30.3.0 → ^30.6.0 age confidence
@types/node (source) ^22.20.1 → ^22.20.5 age confidence
eslint (source) ^10.8.0 → ^10.11.0 age confidence
minimatch@>=7.0.0 <7.4.8 [7.4.8 → 7.4.9](https://renovatebot.com/diffs/npm/minimatch@>=7.0.0 <7.4.8/7.4.8/7.4.9) age confidence
pnpm (source) 10.34.5 → 10.34.6 age confidence
pnpm (source) ^10.34.5 → ^10.34.6 age confidence
simple-git-hooks ^2.13.1 → ^2.14.0 age confidence
tsx (source) ^4.23.5 → ^4.23.15 age confidence
typescript-eslint (source) ^8.66.0 → ^8.71.0 age confidence
verdaccio (source) ^6.9.2 → ^6.10.4 age confidence
yaml (source) ^2.9.0 → ^2.9.1 age confidence

Release Notes

antfu-collective/ni (@​antfu/ni)

v30.6.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v30.5.0

Compare Source

   🚀 Features
    View changes on GitHub

v30.4.0

Compare Source

   🚀 Features
    View changes on GitHub
eslint/eslint (eslint)

v10.11.0

Compare Source

v10.10.0

Compare Source

v10.9.1

Compare Source

v10.9.0

Compare Source

v10.8.1

Compare Source

Bug Fixes

  • 18eb0a7 fix: prevent ASI hazard in no-unused-labels autofix (#​21173) (dongkyu lee)
  • 151ba3f fix: false positives in getter-return and accessor-pairs (#​21163) (Grit)
  • 6898df9 fix: ignore meta-property names in id-denylist (#​21166) (Pixel)
  • 4d7db66 fix: ignore meta-property names in id-match (#​21167) (Pixel)
  • 677214e fix: handle ASI hazards in no-unused-vars removeVar suggestion (#​20935) (kuldeep kumar)

Documentation

  • 7d0cbf8 docs: Update README (GitHub Actions Bot)
  • 0a05812 docs: add missing backticks to no-duplicate-imports.js (#​21183) (Lee Daeun)
  • 678c90b docs: Update README (GitHub Actions Bot)
  • 8a10424 docs: Update README (GitHub Actions Bot)
  • 69bb948 docs: Update README (GitHub Actions Bot)

Chores

isaacs/minimatch (minimatch@>=7.0.0 <7.4.8)

v7.4.9

Compare Source

pnpm/pnpm (pnpm)

v10.34.6

Compare Source

Patch Changes
  • e7888e5: pnpm self-update now resolves and verifies pnpm through registry, authentication, proxy, and TLS settings from trusted non-project configuration. Project configuration and the default project pnpmfile can no longer redirect the pnpm download or disable engine identity verification.

  • 46bc7c9: pnpm no longer tells you to update itself with Corepack or with pnpm add -g:

    • The update notification now suggests pnpm self-update, or the standalone install script when pnpm is running under Corepack. It used to suggest corepack use pnpm@<version>, or pnpm add -g pnpm / pnpm add -g @pnpm/exe when pnpm was not installed by the standalone script — but pnpm add -g refuses to install pnpm and points at pnpm self-update anyway, and @pnpm/exe is not published for pnpm v12 or newer, where the unscoped pnpm package is itself the native executable.
    • pnpm self-update under Corepack now points at the standalone install script too, instead of telling you to update pnpm with Corepack.
  • 46bc7c9: Updated adm-zip to v0.6.0, which fixes a memory-exhaustion vulnerability where a crafted ZIP file could make it allocate 4 GB of memory. adm-zip is used to extract the Node.js, Bun, and Deno archives that pnpm downloads on Windows.

  • Updated the embedded Node.js release keys to the current canonical nodejs/release-keys list.

  • Updated the embedded npm registry signing keys to the set currently advertised by npm.

  • 702ad5f: Update the embedded Node.js release keys with the new key added to nodejs/release-keys (Stewart X Addison, 655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD).

Platinum Sponsors

Bit

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx
toplenboren/simple-git-hooks (simple-git-hooks)

v2.14.0

Compare Source

Minor Changes
Patch Changes
  • #​146 e9e9367 Thanks @​colinhacks! - fix: resolve the project root from INIT_CWD during postinstall so hooks install correctly on isolated node_modules layouts (pnpm, yarn, bun, and other package managers) regardless of the store directory name

  • #​149 f071064 Thanks @​wmaurer! - fix: install and remove hooks correctly inside a git worktree, including worktrees created with git worktree add --relative-paths

  • #​151 eb795de Thanks @​DanMat! - fix: don't crash postinstall when the resolved project directory has no package.json — skip instead of throwing an uncaught ENOENT

privatenumber/tsx (tsx)

v4.23.15

Compare Source

Bug Fixes
  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

Compare Source

v4.23.13

Compare Source

v4.23.12

Compare Source

Bug Fixes

This release is also available on:

v4.23.11

Compare Source

v4.23.10

Compare Source

Bug Fixes

This release is also available on:

v4.23.9

Compare Source

Bug Fixes
  • map Node test locations (2f55884)
  • support data URLs in tsImport (b94f46f)

This release is also available on:

v4.23.8

Compare Source

Bug Fixes
  • preserve package subpath resolution (be1315e)
  • preserve typeless ESM dependency exports (70dfc5e)

This release is also available on:

v4.23.7

Compare Source

Bug Fixes
  • prevent tsImport cache collisions (4e5a138)

This release is also available on:

v4.23.6

Compare Source

typescript-eslint/typescript-eslint (typescript-eslint)

v8.71.0

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.1

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

🩹 Fixes
  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#​12780)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.67.0

Compare Source

🚀 Features
  • typescript-eslint: export basic globs for using tseslint (#​12105)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

verdaccio/verdaccio (verdaccio)

v6.10.4

Compare Source

Patch Changes
  • 7730e60: Update express to 4.22.3 — directly and through @verdaccio/middleware 8.1.4,
    verdaccio-audit 13.1.4 and @verdaccio/test-helper 4.1.4 — so the registry's entire HTTP
    stack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string
    handling: a remotely triggerable crash in qs.stringify (TypeError on crafted input), an
    arrayLimit bypass through bracket-key comma parsing that allows memory exhaustion, and a
    DoS via an attacker-controlled isBuffer check (GHSA-4mjr-xmp4-gh2g). A body-parser/qs
    resolution covers the one remaining consumer that pins qs below the fix. Query-string
    parsing behaviour is otherwise unchanged and no configuration change is needed.

    The same update refreshes the development dependency tree, clearing every high-severity
    yarn npm audit finding (stale transitive resolutions of tar, minimatch, socks/ip, js-yaml,
    form-data, nanoid, postcss, picomatch, tmp and systeminformation, plus vitest 4.1.11 for the
    @vitest/mocker path-traversal advisory) — none of these ship in the published package.

  • aabb0b4: Fix npm publish failing with request size did not match content length when authenticating with a token created by npm token create.

    The JSON body parser was registered by the API router, which runs after apiJWTmiddleware() and after enforceGeneratedTokenMetadata(). The latter awaits a storage lookup for tokens that carry a server-issued key, so the request body was partially consumed before the parser attached. It is now registered before both, as it already is on master.

  • e2602b3: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.30 → 9.0.0-next-9.31

v6.10.3

Compare Source

Patch Changes
  • 98b58ef: fix: do not fetch client-controlled dist.tarball urls off-uplink @​cOmrade3267

    Only fetch a tarball url that a configured uplink actually serves. Off-uplink urls are
    fetched without uplink credentials and only for uplink-synced packages (recorded in
    _distfiles); a locally published package returns 404 instead of being fetched. Prevents
    sending an uplink Authorization header to an unrelated host.

v6.10.2

Compare Source

Patch Changes
  • 6d972d1: fix: resolve fast-uri and brace-expansion security advisories

    fast-uri 3.1.6. Bumps the ajv/fast-uri resolution from 3.1.5 to 3.1.6, which
    fixes four high-severity advisories in the URI parser used by ajv for schema
    format validation: host confusion via skipped IDN canonicalization
    (GHSA-5jgf-p345-68v8),
    SSRF via malformed IPv6 normalization
    (GHSA-f65p-4m7j-42xc),
    SSRF via repeated hostname percent-decoding
    (GHSA-fph4-wmhf-6fwf),
    and host confusion via percent-encoded scheme normalization
    (GHSA-jqff-g426-hqxp).

    brace-expansion DoS cleanup. Updates the remaining vulnerable
    brace-expansion trees (1.1.11 → 1.1.18, 2.0.1 → 2.1.4) for
    GHSA-mh99-v99m-4gvg and
    drops the temporary audit ignores that covered them while the patched
    releases were still quarantined by the minimal-age gate.

  • 6d972d1: chore: update e2e library

  • ca00ee0: fix: stop re-compressing tarballs for gzip-accepting clients

    mime-db marks application/octet-stream as compressible, so the compression
    middleware re-gzipped every (already gzipped) .tgz download for clients
    that accept gzip — npm and undici do by default — wasting CPU on every
    download and stripping the Content-Length header. Tarball responses are
    now excluded from compression; JSON metadata responses stay compressed.

    Measured on a 30 MB tarball: ~18x less server CPU and ~20x faster downloads,
    with slightly fewer bytes on the wire (gzip over gzip nets negative).

  • d4b8199: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.28 → 9.0.0-next-9.30
  • d94ebff: fix: validate the scope segment on the web package endpoints

    The readme and sidebar web endpoints now validate the :scope route segment
    and return 404 for malformed requests.

v6.10.1

Compare Source

Patch Changes
  • 90d5c20: Import shared helpers from @verdaccio/core and drop the deprecated @verdaccio/utils dependency

    All internal usages of @verdaccio/utils now resolve the same helpers from
    @verdaccio/core (validation, auth, crypto, package and author utilities), and
    the @verdaccio/utils dependency has been removed.

  • 7805d50: Limit web UI search responses to 20 packages.

  • c84070b: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.27 → 9.0.0-next-9.28

v6.10.0

Compare Source

Minor Changes
  • 51c2733: Expose the optional legacy authentication cache for Verdaccio 6.x through server.legacyAuthCache.

    This feature is intended for performance-sensitive installations that still use legacy bearer tokens. When enabled, Verdaccio caches successful legacy token authentication results for a short period of time, so repeated requests using the same token do not need to run password verification through the authentication plugin every time. Concurrent requests for the same legacy token can also share the same in-flight authentication result.

    The cache is disabled by default, so existing installations keep their current authentication behavior unless they explicitly opt in. Basic authentication is not cached. If the cache is enabled, changed or revoked credentials may remain valid until the cached entry expires.

    Enable it in config.yaml:

    server:
      legacyAuthCache:
        enabled: true
        ttlMs: 15000
        maxEntries: 1000

    Options:

    • enabled: enables the legacy token authentication cache. Default: false.
    • ttlMs: time in milliseconds before a cached validation expires. Default: 15000.
    • maxEntries: maximum number of cached legacy tokens. Default: 1000.

    See #​6147 and the original 8.x backport in #​6143.

v6.9.3

Compare Source

Patch Changes
  • 3c8f391: Reject wildcard characters in package and tarball path validation.

  • ebc08ba: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    This dependency refresh includes @verdaccio/package-filter 13.2.0 with excludeDeprecated support from #​6142 by @​jotadeveloper, based on the original work by @​davidus27. It also includes the @verdaccio/ui-theme update containing the homepage action hover fix from #​6135 by @​pranshuchittora.

    • @verdaccio/auth: 8.1.1 → 8.1.2
    • @verdaccio/config: 8.2.1 → 8.2.2
    • @verdaccio/core: 8.2.1 → 8.2.2
    • @verdaccio/hooks: 8.1.2 → 8.1.3
    • @verdaccio/loaders: 8.1.1 → 8.1.2
    • @verdaccio/local-storage-legacy: 11.4.1 → 11.4.2
    • @verdaccio/logger: 8.1.1 → 8.1.2
    • @verdaccio/middleware: 8.1.1 → 8.1.2
    • @verdaccio/package-filter: 13.1.1 → 13.2.0
    • @verdaccio/signature: 8.1.1 → 8.1.2
    • @verdaccio/tarball: 13.1.1 → 13.1.2
    • @verdaccio/ui-theme: 9.0.0-next-9.23 → 9.0.0-next-9.26
    • @verdaccio/url: 13.1.1 → 13.1.2
    • @verdaccio/utils: 8.2.1 → 8.2.2
    • verdaccio-audit: 13.1.1 → 13.1.2
    • verdaccio-htpasswd: 13.1.1 → 13.1.2
eemeli/yaml (yaml)

v2.9.1

Compare Source

  • Limit recursive merge aliases (#​685, #​713)
  • Simplify line unfolding during quoted string parsing (#​714)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Jul 1, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 1cf2c9a to d9ec198 Compare July 9, 2026 10:40
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from cbe4494 to 271d782 Compare July 14, 2026 21:37
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 5729bc7 to d1411c7 Compare July 27, 2026 22:02
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 7 times, most recently from d5d7cd9 to d87df3a Compare August 4, 2026 06:05
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies chore(deps): update dependency minimatch@>=7.0.0 <7.4.8 to v7.4.9 Aug 4, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from d87df3a to 1fea0d1 Compare August 6, 2026 05:50
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 19d5170 to 5b7778b Compare August 25, 2026 20:09
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 72e13ff to f5f9a7d Compare September 3, 2026 22:53
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from a7ecaa0 to 6fa780d Compare September 10, 2026 23:34
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 7a265e0 to e7228db Compare September 19, 2026 01:26
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 29370ff to c3fac44 Compare September 23, 2026 00:50
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 78accb6 to dbab7b3 Compare September 29, 2026 21:23
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from dbab7b3 to 1a7b1bd Compare October 3, 2026 00:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants