fix(deps): update all non-major dependencies#560
Open
renovate[bot] wants to merge 2 commits intomainfrom
Open
Conversation
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.2.86→^1.2.90^3.10.1→^3.11.01.0.0-alpha.11→1.0.0-beta.1^0.211.0→^0.212.0^0.211.0→^0.212.0^2.5.0→^2.5.1^0.211.0→^0.212.0^0.211.0→^0.212.0^0.211.0→^0.212.0^0.211.0→^0.212.0^2.5.0→^2.5.1^0.211.0→^0.212.0^2.5.0→^2.5.1^0.211.0→^0.212.0^2.5.0→^2.5.1^25.0.10→^25.2.3^6.0.3→^6.0.4^8.0.5→^8.0.6^14.1.0→^14.2.1^14.1.0→^14.2.1^0.4.2→^0.4.3^0.4.2→^0.4.3^10.4.0→^10.4.1^0.4.3→^0.4.4^0.31.8→^0.31.9^1.39.3→^1.40.0^2.0.1-rc.11→^2.0.1-rc.14^20.3.9→^20.6.1>=24.13.0→>=24.13.124.13.0-alpine→24.13.1-alpine24.13.0-alpine→24.13.1-alpine10.28.1→10.29.3^1.335.2→^1.347.1^2.7.0→^2.8.0^0.20.1→^0.20.3^0.48.4→^0.48.5^8.0.0-beta.10→^8.0.0-beta.14^8.0.5→^8.0.6^3.5.27→^3.5.28^3.5.27→^3.5.28^0.4.2→^0.4.3Release Notes
adobe/react-spectrum (@internationalized/date)
v3.11.0Compare Source
moeru-ai/eventa (@moeru/eventa)
v1.0.0-beta.1Compare Source
No significant changes
View changes on GitHub
v1.0.0-alpha.16Compare Source
🚀 Features
View changes on GitHub
v1.0.0-alpha.15Compare Source
🚀 Features
View changes on GitHub
v1.0.0-alpha.14Compare Source
🚀 Features
View changes on GitHub
v1.0.0-alpha.13Compare Source
🐞 Bug Fixes
View changes on GitHub
v1.0.0-alpha.12Compare Source
🚀 Features
View changes on GitHub
open-telemetry/opentelemetry-js (@opentelemetry/api-logs)
v0.212.0Compare Source
vitejs/vite-plugin-vue (@vitejs/plugin-vue)
v6.0.4Bug Fixes
Miscellaneous Chores
vuejs/devtools (@vue/devtools-kit)
v8.0.6Compare Source
🚀 Features
View changes on GitHub
vueuse/vueuse (@vueuse/core)
v14.2.1Compare Source
🚀 Features
@vueuse/skills- by @serkodev in #5286 (532ac)🐞 Bug Fixes
View changes on GitHub
v14.2.0Compare Source
🚀 Features
useCssSupports- by @OrbisK in #5266 (c1282)rootMarginfromuseIntersectionObserver- by @9romise in #5207 (46682)rootMarginreactive - by @doyuli, @ilyaliao and @9romise in #4934 (53abe)watchElementoption for auto-reinitialize on element change - by @Mini-ghost and @ilyaliao in #5189 (17ea2)🐞 Bug Fixes
executereturn the actual data - by @9romise in #5167 (0c346)focus-traprange to^7 - by ** ^8(#5270)** ()View changes on GitHub
moeru-ai/xsai (@xsai/embed)
v0.4.3Compare Source
🏎 Performance
Promise.allfor tool calling - by @dsh0416 in #264 (9241e)View changes on GitHub
antfu-collective/bumpp (bumpp)
v10.4.1Compare Source
🚀 Features
View changes on GitHub
h3js/crossws (crossws)
v0.4.4Compare Source
compare changes
🩹 Fixes
AbortControllerforStubRequest.signal(#175)🏡 Chore
❤️ Contributors
drizzle-team/drizzle-orm (drizzle-kit)
v0.31.9Compare Source
grammyjs/grammY (grammy)
v1.40.0Compare Source
What's Changed
Full Changelog: grammyjs/grammY@v1.39.3...v1.40.0
h3js/h3 (h3)
v2.0.1-rc.14Compare Source
compare changes
💅 Refactors
.fetchto.request(#1294)🏡 Chore
❤️ Contributors
v2.0.1-rc.13Compare Source
compare changes
💅 Refactors
❤️ Contributors
v2.0.1-rc.12Compare Source
compare changes
🚀 Enhancements
h3cli (#1293)Link: rel:preloadheaders as fallback (#1288)💅 Refactors
headers are frozen(#1287)📖 Documentation
event.res.headers.set(#1289)📦 Build
🏡 Chore
🤖 CI
❤️ Contributors
capricorn86/happy-dom (happy-dom)
v20.6.1Compare Source
v20.6.0Compare Source
v20.5.5Compare Source
v20.5.4Compare Source
👷♂️ Patch fixes
v20.5.3Compare Source
v20.5.2Compare Source
v20.5.1Compare Source
v20.5.0Compare Source
v20.4.0Compare Source
🎨 Features
nodejs/node (node)
v24.13.1Compare Source
pnpm/pnpm (pnpm)
v10.29.3Compare Source
v10.29.2Compare Source
v10.29.1: pnpm 10.29.1Compare Source
Minor Changes
pnpm dlx/pnpxcommand now supports thecatalog:protocol. Example:pnpm dlx shx@catalog:.auditLevelin thepnpm-workspace.yamlfile #10540.workspace:protocol without version specifier. It is now treated asworkspace:*and resolves to the concrete version during publish #10436.Patch Changes
Fixed
pnpm list --jsonreturning incorrect paths when using global virtual store #10187.Fix
pnpm store pathandpnpm store statususing workspace root for path resolution whenstoreDiris relative #10290.Fixed
pnpm run -rfailing with "No projects matched the filters" when an emptypnpm-workspace.yamlexists #10497.Fixed a bug where
catalogMode: strictwould write the literal string"catalog:"topnpm-workspace.yamlinstead of the resolved version specifier when re-adding an existing catalog dependency #10176.Fixed the documentation URL shown in
pnpm completion --helpto point to the correct page at https://pnpm.io/completion #10281.Skip local
file:protocol dependencies duringpnpm fetch. This fixes an issue wherepnpm fetchwould fail in Docker builds when local directory dependencies were not available #10460.Fixed
pnpm audit --jsonto respect the--audit-levelsetting for both exit code and output filtering #10540.update tar to version 7.5.7 to fix security issue
Updating the version of dependency tar to 7.5.7 because the previous one have a security vulnerability reported here: CVE-2026-24842
Fix
pnpm audit --fixreplacing reference overrides (e.g.$foo) with concrete versions #10325.Fix
shamefullyHoistset viaupdateConfigin.pnpmfile.cjsnot being converted topublicHoistPattern#10271.pnpm helpshould correctly report if the currently running pnpm CLI is bundled with Node.js #10561.Add a warning when the current directory contains the PATH delimiter character. On macOS, folder names containing forward slashes (/) appear as colons (:) at the Unix layer. Since colons are PATH separators in POSIX systems, this breaks PATH injection for
node_modules/.bin, causing binaries to not be found when running commands likepnpm exec#10457.Platinum Sponsors
Gold Sponsors
v10.28.2: pnpm 10.28.2Compare Source
Patch Changes
Security fix: prevent path traversal in
directories.binfield.When pnpm installs a
file:orgit:dependency, it now validates that symlinks point within the package directory. Symlinks to paths outside the package root are skipped to prevent local data from being leaked intonode_modules.This fixes a security issue where a malicious package could create symlinks to sensitive files (e.g.,
/etc/passwd,~/.ssh/id_rsa) and have their contents copied when the package is installed.Note: This only affects
file:andgit:dependencies. Registry packages (npm) have symlinks stripped during publish and are not affected.Fixed optional dependencies to request full metadata from the registry to get the
libcfield, which is required for proper platform compatibility checks #9950.Platinum Sponsors
Gold Sponsors
PostHog/posthog-js (posthog-js)
v1.347.1Compare Source
v1.347.0Compare Source
v1.346.0Compare Source
1.346.0
Minor Changes
0d730bdThanks @adboio! - enable tours by default(2026-02-12)
Patch Changes
v1.345.5Compare Source
1.345.5
Patch Changes
7437982Thanks @pauldambra! - Add missingfeatureFlagsproperty andOverrideFeatureFlagsOptionstype toPostHoginterface, restoreset_configto the loaded callback type, and addfeatureFlagsReloadingtoon()event types(2026-02-11)
7437982]:v1.345.4Compare Source
1.345.4
Patch Changes
4e7fda9Thanks @marandaneto! - fix: session replay respects the network_timing remote config(2026-02-11)
v1.345.3Compare Source
1.345.3
Patch Changes
50ebdfbThanks @jordanm-posthog! - Fixed an issue where Dead Clicks could continue being captured after being disabled via remote config.(2026-02-10)
0acf16f]:v1.345.2Compare Source
v1.345.1Compare Source
1.345.1
Patch Changes
de43d70Thanks @adboio! - add survey shown tracking to useThumbSurvey + option to disable shown tracking in displaySurvey(2026-02-10)
v1.345.0Compare Source
1.345.0
Minor Changes
fe8090cThanks @dustinbyrne! - Add$feature_flag_errorproperty to `$feature_flag_caConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.