chore(deps): update all non-major dependencies - #80
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
6 times, most recently
from
July 9, 2026 10:40
1cf2c9a to
d9ec198
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
July 14, 2026 21:37
cbe4494 to
271d782
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
9 times, most recently
from
July 27, 2026 22:02
5729bc7 to
d1411c7
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
7 times, most recently
from
August 4, 2026 06:05
d5d7cd9 to
d87df3a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 6, 2026 05:50
d87df3a to
1fea0d1
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
August 25, 2026 20:09
19d5170 to
5b7778b
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
6 times, most recently
from
September 3, 2026 22:53
72e13ff to
f5f9a7d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
September 10, 2026 23:34
a7ecaa0 to
6fa780d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
September 19, 2026 01:26
7a265e0 to
e7228db
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
6 times, most recently
from
September 23, 2026 00:50
29370ff to
c3fac44
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
September 29, 2026 21:23
78accb6 to
dbab7b3
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 3, 2026 00:21
dbab7b3 to
1a7b1bd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^30.3.0→^30.6.0^22.20.1→^22.20.5^10.8.0→^10.11.07.4.8→7.4.9](https://renovatebot.com/diffs/npm/minimatch@>=7.0.0 <7.4.8/7.4.8/7.4.9)10.34.5→10.34.6^10.34.5→^10.34.6^2.13.1→^2.14.0^4.23.5→^4.23.15^8.66.0→^8.71.0^6.9.2→^6.10.4^2.9.0→^2.9.1Release Notes
antfu-collective/ni (@antfu/ni)
v30.6.0Compare Source
🚀 Features
existingmode to only reuse existing catalog entries - by @unrevised6419, Claude Opus 5 (1M context) and @antfu in #361 (a3f76)🐞 Bug Fixes
name@versionbefore using it as a catalog key - by @unrevised6419 and Claude Opus 5 (1M context) in #359 (094bb).nircoptions - by @unrevised6419 and Claude Opus 5 (1M context) in #364 (daad8)View changes on GitHub
v30.5.0Compare Source
🚀 Features
View changes on GitHub
v30.4.0Compare Source
🚀 Features
View changes on GitHub
eslint/eslint (eslint)
v10.11.0Compare Source
v10.10.0Compare Source
v10.9.1Compare Source
v10.9.0Compare Source
v10.8.1Compare Source
Bug Fixes
18eb0a7fix: prevent ASI hazard inno-unused-labelsautofix (#21173) (dongkyu lee)151ba3ffix: false positives ingetter-returnandaccessor-pairs(#21163) (Grit)6898df9fix: ignore meta-property names inid-denylist(#21166) (Pixel)4d7db66fix: ignore meta-property names inid-match(#21167) (Pixel)677214efix: handle ASI hazards in no-unused-vars removeVar suggestion (#20935) (kuldeep kumar)Documentation
7d0cbf8docs: Update README (GitHub Actions Bot)0a05812docs: add missing backticks tono-duplicate-imports.js(#21183) (Lee Daeun)678c90bdocs: Update README (GitHub Actions Bot)8a10424docs: Update README (GitHub Actions Bot)69bb948docs: Update README (GitHub Actions Bot)Chores
0a14800chore: update github/codeql-action action to v4.37.4 (#21196) (renovate[bot])05adcb1test: fix failing ecosystem test foreslint-plugin-unicorn(#21191) (Lazizbek Ergashev)5611035test: add error locations info tono-void(#21185) (Lee Daeun)ee47333ci: bump github/codeql-action from 4 to 4.37.3 (#21176) (dependabot[bot])f131c03chore: improve ecosystem test failure reporting (#20937) (crimsonjay0)1f6eddechore: update ecosystem plugins (#21182) (ESLint Bot)d3266fbchore: unpinwebpackdependency (#21172) (Francesco Trotta)65a6519chore: add allowScripts field to package.json (#21092) (GiHoon Noh)22e5256ci: addtriage:nolabel to Dependabot PRs (#21141) (lumir)55c9038ci: bump actions/labeler from 6 to 7 (#21159) (dependabot[bot])7280e78chore: update dependency prettier to v3.9.6 (#21162) (renovate[bot])eddbad6test: fix failing ecosystem test foreslint-plugin-unicorn(#21156) (Francesco Trotta)60a178dchore: update ecosystem plugins (#21150) (ESLint Bot)f9f61dctest: add error locations tono-unreachable(#21151) (JIYEON)d086293test: add error locations tono-undef(#21147) (JIYEON)cc01b67test: add error locations tono-useless-catch(#21144) (devoil)688e75echore: add missing backticks in JSDoc (#21143) (Bo Hyun Kim)7c1e175test: add error locations torequire-await(#21145) (Grit)588a26dtest: add error locations tono-extra-label(#21139) (dongkyu lee)059aa89test: add error locations tono-useless-concat(#21140) (dongkyu lee)5a452a8test: add error locations tono-const-assign(#21138) (dongkyu lee)isaacs/minimatch (minimatch@>=7.0.0 <7.4.8)
v7.4.9Compare Source
pnpm/pnpm (pnpm)
v10.34.6Compare Source
Patch Changes
e7888e5:pnpm self-updatenow resolves and verifies pnpm through registry, authentication, proxy, and TLS settings from trusted non-project configuration. Project configuration and the default project pnpmfile can no longer redirect the pnpm download or disable engine identity verification.46bc7c9: pnpm no longer tells you to update itself with Corepack or withpnpm add -g:pnpm self-update, or the standalone install script when pnpm is running under Corepack. It used to suggestcorepack use pnpm@<version>, orpnpm add -g pnpm/pnpm add -g @pnpm/exewhen pnpm was not installed by the standalone script — butpnpm add -grefuses to install pnpm and points atpnpm self-updateanyway, and@pnpm/exeis not published for pnpm v12 or newer, where the unscopedpnpmpackage is itself the native executable.pnpm self-updateunder Corepack now points at the standalone install script too, instead of telling you to update pnpm with Corepack.46bc7c9: Updatedadm-zipto v0.6.0, which fixes a memory-exhaustion vulnerability where a crafted ZIP file could make it allocate 4 GB of memory.adm-zipis used to extract the Node.js, Bun, and Deno archives that pnpm downloads on Windows.Updated the embedded Node.js release keys to the current canonical
nodejs/release-keyslist.Updated the embedded npm registry signing keys to the set currently advertised by npm.
702ad5f: Update the embedded Node.js release keys with the new key added to nodejs/release-keys (Stewart X Addison,655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD).Platinum Sponsors
Gold Sponsors
toplenboren/simple-git-hooks (simple-git-hooks)
v2.14.0Compare Source
Minor Changes
2f3ec3fThanks @younggglcy! - feat: silent success if nothing has changedPatch Changes
#146
e9e9367Thanks @colinhacks! - fix: resolve the project root fromINIT_CWDduring postinstall so hooks install correctly on isolatednode_moduleslayouts (pnpm, yarn, bun, and other package managers) regardless of the store directory name#149
f071064Thanks @wmaurer! - fix: install and remove hooks correctly inside a git worktree, including worktrees created withgit worktree add --relative-paths#151
eb795deThanks @DanMat! - fix: don't crashpostinstallwhen the resolved project directory has no package.json — skip instead of throwing an uncaught ENOENTprivatenumber/tsx (tsx)
v4.23.15Compare Source
Bug Fixes
This release is also available on:
v4.23.14Compare Source
v4.23.13Compare Source
v4.23.12Compare Source
Bug Fixes
import.metawhen tokens are split by comments or newlines (#829) (ed9d330), closes #828This release is also available on:
v4.23.11Compare Source
v4.23.10Compare Source
Bug Fixes
This release is also available on:
v4.23.9Compare Source
Bug Fixes
This release is also available on:
v4.23.8Compare Source
Bug Fixes
This release is also available on:
v4.23.7Compare Source
Bug Fixes
This release is also available on:
v4.23.6Compare Source
typescript-eslint/typescript-eslint (typescript-eslint)
v8.71.0Compare Source
This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.70.1Compare Source
This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.70.0Compare Source
🩹 Fixes
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.69.0Compare Source
This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.68.0Compare Source
This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.67.0Compare Source
🚀 Features
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
verdaccio/verdaccio (verdaccio)
v6.10.4Compare Source
Patch Changes
7730e60: Update express to 4.22.3 — directly and through@verdaccio/middleware8.1.4,verdaccio-audit13.1.4 and@verdaccio/test-helper4.1.4 — so the registry's entire HTTPstack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string
handling: a remotely triggerable crash in
qs.stringify(TypeError on crafted input), anarrayLimitbypass through bracket-key comma parsing that allows memory exhaustion, and aDoS via an attacker-controlled
isBuffercheck (GHSA-4mjr-xmp4-gh2g). Abody-parser/qsresolution covers the one remaining consumer that pins qs below the fix. Query-string
parsing behaviour is otherwise unchanged and no configuration change is needed.
The same update refreshes the development dependency tree, clearing every high-severity
yarn npm auditfinding (stale transitive resolutions of tar, minimatch, socks/ip, js-yaml,form-data, nanoid, postcss, picomatch, tmp and systeminformation, plus vitest 4.1.11 for the
@vitest/mockerpath-traversal advisory) — none of these ship in the published package.aabb0b4: Fixnpm publishfailing withrequest size did not match content lengthwhen authenticating with a token created bynpm token create.The JSON body parser was registered by the API router, which runs after
apiJWTmiddleware()and afterenforceGeneratedTokenMetadata(). The latter awaits a storage lookup for tokens that carry a server-issued key, so the request body was partially consumed before the parser attached. It is now registered before both, as it already is onmaster.e2602b3: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.30→9.0.0-next-9.31v6.10.3Compare Source
Patch Changes
98b58ef: fix: do not fetch client-controlled dist.tarball urls off-uplink @cOmrade3267Only fetch a tarball url that a configured uplink actually serves. Off-uplink urls are
fetched without uplink credentials and only for uplink-synced packages (recorded in
_distfiles); a locally published package returns 404 instead of being fetched. Preventssending an uplink
Authorizationheader to an unrelated host.v6.10.2Compare Source
Patch Changes
6d972d1: fix: resolve fast-uri and brace-expansion security advisoriesfast-uri 3.1.6. Bumps the
ajv/fast-uriresolution from 3.1.5 to 3.1.6, whichfixes four high-severity advisories in the URI parser used by
ajvfor schemaformat validation: host confusion via skipped IDN canonicalization
(GHSA-5jgf-p345-68v8),
SSRF via malformed IPv6 normalization
(GHSA-f65p-4m7j-42xc),
SSRF via repeated hostname percent-decoding
(GHSA-fph4-wmhf-6fwf),
and host confusion via percent-encoded scheme normalization
(GHSA-jqff-g426-hqxp).
brace-expansion DoS cleanup. Updates the remaining vulnerable
brace-expansiontrees (1.1.11 → 1.1.18, 2.0.1 → 2.1.4) forGHSA-mh99-v99m-4gvg and
drops the temporary audit ignores that covered them while the patched
releases were still quarantined by the minimal-age gate.
6d972d1: chore: update e2e libraryca00ee0: fix: stop re-compressing tarballs for gzip-accepting clientsmime-db marks
application/octet-streamas compressible, so the compressionmiddleware re-gzipped every (already gzipped)
.tgzdownload for clientsthat accept gzip — npm and undici do by default — wasting CPU on every
download and stripping the
Content-Lengthheader. Tarball responses arenow excluded from compression; JSON metadata responses stay compressed.
Measured on a 30 MB tarball: ~18x less server CPU and ~20x faster downloads,
with slightly fewer bytes on the wire (gzip over gzip nets negative).
d4b8199: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.28→9.0.0-next-9.30d94ebff: fix: validate the scope segment on the web package endpointsThe readme and sidebar web endpoints now validate the
:scoperoute segmentand return 404 for malformed requests.
v6.10.1Compare Source
Patch Changes
90d5c20: Import shared helpers from@verdaccio/coreand drop the deprecated@verdaccio/utilsdependencyAll internal usages of
@verdaccio/utilsnow resolve the same helpers from@verdaccio/core(validation, auth, crypto, package and author utilities), andthe
@verdaccio/utilsdependency has been removed.7805d50: Limit web UI search responses to 20 packages.c84070b: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.27→9.0.0-next-9.28v6.10.0Compare Source
Minor Changes
51c2733: Expose the optional legacy authentication cache for Verdaccio 6.x throughserver.legacyAuthCache.This feature is intended for performance-sensitive installations that still use legacy bearer tokens. When enabled, Verdaccio caches successful legacy token authentication results for a short period of time, so repeated requests using the same token do not need to run password verification through the authentication plugin every time. Concurrent requests for the same legacy token can also share the same in-flight authentication result.
The cache is disabled by default, so existing installations keep their current authentication behavior unless they explicitly opt in. Basic authentication is not cached. If the cache is enabled, changed or revoked credentials may remain valid until the cached entry expires.
Enable it in
config.yaml:Options:
enabled: enables the legacy token authentication cache. Default:false.ttlMs: time in milliseconds before a cached validation expires. Default:15000.maxEntries: maximum number of cached legacy tokens. Default:1000.See #6147 and the original 8.x backport in #6143.
v6.9.3Compare Source
Patch Changes
3c8f391: Reject wildcard characters in package and tarball path validation.ebc08ba: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):This dependency refresh includes
@verdaccio/package-filter13.2.0withexcludeDeprecatedsupport from #6142 by @jotadeveloper, based on the original work by @davidus27. It also includes the@verdaccio/ui-themeupdate containing the homepage action hover fix from #6135 by @pranshuchittora.@verdaccio/auth:8.1.1→8.1.2@verdaccio/config:8.2.1→8.2.2@verdaccio/core:8.2.1→8.2.2@verdaccio/hooks:8.1.2→8.1.3@verdaccio/loaders:8.1.1→8.1.2@verdaccio/local-storage-legacy:11.4.1→11.4.2@verdaccio/logger:8.1.1→8.1.2@verdaccio/middleware:8.1.1→8.1.2@verdaccio/package-filter:13.1.1→13.2.0@verdaccio/signature:8.1.1→8.1.2@verdaccio/tarball:13.1.1→13.1.2@verdaccio/ui-theme:9.0.0-next-9.23→9.0.0-next-9.26@verdaccio/url:13.1.1→13.1.2@verdaccio/utils:8.2.1→8.2.2verdaccio-audit:13.1.1→13.1.2verdaccio-htpasswd:13.1.1→13.1.2eemeli/yaml (yaml)
v2.9.1Compare Source
Configuration
📅 Schedule: (UTC)
* 0-3 1 * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.