Repository navigation
fix(deps): update all non-major dependencies - #413
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF ScorecardScorecard details
Scanned Files
|
Contributor
Merge Protections🟢 All 3 merge protections satisfied — ready to merge. Show 3 satisfied protections🟢 Do not merge outdated PRsMake sure PRs are almost up to date before merging
🟢 Enforce conventional commitMake sure that we follow https://www.conventionalcommits.org/en/v1.0.0/
🟢 🚦 Auto-queueWhen all merge protections are satisfied, this pull request will be queued automatically. |
Coverage Report
File Coverage
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
June 25, 2026 13:58
79f7065 to
536ff36
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
4 times, most recently
from
July 1, 2026 23:48
d79b1c7 to
861b866
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
6 times, most recently
from
July 4, 2026 18:00
054863f to
bf7c5d0
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 5, 2026 01:27
bf7c5d0 to
de4d5f1
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 5, 2026 06:27
de4d5f1 to
bda33e2
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 21, 2026 20:07
deb816e to
1e55410
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 23, 2026 18:44
1e55410 to
bc07b52
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 24, 2026 16:37
bc07b52 to
8e7f862
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 25, 2026 01:50
8e7f862 to
560cac5
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 25, 2026 08:34
560cac5 to
c8c8ba2
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major
branch
from
July 26, 2026 09:39
c8c8ba2 to
3d73072
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.11.3→4.13.05.2.1→5.4.021.0.2→21.2.321.0.2→21.2.321.0.1→21.2.30.4.1→0.5.00.13.11→0.13.140.16.1→0.16.31.3.2→1.3.510.4.6→10.6.110.4.6→10.6.110.4.6→10.6.14.3.1→4.3.314.6.1→14.6.725.9.4→25.9.94.1.9→4.1.114.1.9→4.1.111.3.14→1.4.21.4.3v5.0.5→v5.1.0v6.0.3→v6.1.0v8.0.1→v8.0.2v7.0.1→v7.0.2v2.12.1→v2.13.087999aa→4edf897v7.2.0→v7.4.0v4.2.0→v4.6.0v4.36.2→v4.38.2v4.38.32.1.9→2.2.02.2.11.21.0→1.52.01.55.0(+2)v2.4.3→v2.4.41.3.14-alpine→1.4.2-alpine1.4.3-alpine0.55.0→0.72.01.9.13→1.9.17v2.19.4→v2.22.110.4.6→10.6.110.5.2→10.7.23.6.0→3.7.04.3.1→4.3.32.12.2→2.12.38.0.16→8.3.38.3.42.11.12→2.11.14v0.5.6→v0.6.4Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
dequelabs/axe-core-npm (@axe-core/playwright)
v4.13.0Compare Source
Features
v4.12.1Compare Source
Features
4.11.3 (2026-04-29)
Bug Fixes
4.11.2 (2026-04-14)
Bug Fixes
4.11.1 (2026-01-09)
Bug Fixes
chromaui/addon-visual-tests (@chromatic-com/storybook)
v5.4.0Compare Source
🚀 Enhancement
Ignored,Auto-ignored,QuarantinedandUnstablebadges #456 (@ghengeveld)🐛 Bug Fix
Authors: 1
v5.3.1Compare Source
🐛 Bug Fix
Authors: 3
v5.3.0Compare Source
🚀 Enhancement
🐛 Bug Fix
Authors: 5
conventional-changelog/commitlint (@commitlint/cli)
v21.2.3Compare Source
Bug Fixes
v21.2.2Compare Source
Note: Version bump only for package @commitlint/cli
v21.2.1Compare Source
Note: Version bump only for package @commitlint/cli
v21.2.0Compare Source
Features
v21.1.0Compare Source
Features
21.0.2 (2026-05-29)
Bug Fixes
21.0.1 (2026-05-12)
Note: Version bump only for package @commitlint/cli
conventional-changelog/commitlint (@commitlint/config-conventional)
v21.2.3Compare Source
Bug Fixes
v21.2.2Compare Source
Note: Version bump only for package @commitlint/config-conventional
v21.2.0Compare Source
Features
v21.1.0Compare Source
Note: Version bump only for package @commitlint/config-conventional
21.0.2 (2026-05-29)
Note: Version bump only for package @commitlint/config-conventional
21.0.1 (2026-05-12)
Note: Version bump only for package @commitlint/config-conventional
conventional-changelog/commitlint (@commitlint/types)
v21.2.3Compare Source
Bug Fixes
v21.2.0Compare Source
Features
v21.1.0Compare Source
Features
21.0.1 (2026-05-12)
Bug Fixes
dubzzz/fast-check (@fast-check/vitest)
v0.5.0Support for plugins and for Vitest v5
[Code][Diff]
Features
kobaltedev/kobalte (@kobalte/core)
v0.13.14Compare Source
Patch Changes
3d32663: ## v0.13.14 (September 7, 2026)Bug fixes
v0.13.13Patch Changes
cb89022: ## v0.13.13 (August 10, 2026)New features
Bug fixes
solidjs/solid-router (@solidjs/router)
v0.16.3Compare Source
Patch Changes
31501fd: Add opt-in explicit scroll restoration for back/forward navigation:<Router scrollRestoration>(#577). The browser's native same-document heuristic loses the saved offset when the destination route forces a layout while the document is still short — any component that measures itself on mount is enough to trigger it. When enabled the router setshistory.scrollRestoration = "manual", captures positions continuously keyed by the history entry depth it already tracks, persists them across reloads, and restores after the navigation settles — retrying as the document grows if the target offset isn't reachable yet, cancelled by the first user scroll. Off by default on 0.x; no behavior changes unless enabled.v0.16.2Patch Changes
676db85: fix #451 - dispose per-route roots when the route tree unmounts; leaked roots stayed subscribed to route matches and crashed withTypeError: ... (evaluating 'match().path')on a later navigation (e.g. when a<Show>in the root component hid the outlet during login/logout flows)cae1d15: Fix a batch of long-standing bugs:useSubmission().retrywas always a no-op due to an operator-precedence bug (#504)useBeforeLeavelisteners now observedefaultPreventedset by other listeners (#530)<A>active state now ignores trailing slashes onhref(#532)useCurrentMatchesreturns a copy so user mutation can't corrupt router state (#516)+,@,:,$,&,,,;,=), so routes like/+fooor/@usermatch the browser's raw pathname (#559, #509)setSearchParamscalls now compose: the merge applies to the in-flight navigation target instead of the stale committed location (#547)e9acd69: fix #454 - defaultRouteDefinition's data generic toanyso typed components and preload functions are assignable in annotated configs likeconst routes: RouteDefinition[], where no inference site for the generic exists9d80d4e: Paths with empty interior segments (doubled slashes, e.g.//dashor/foo//bar) no longer match routes and now render the not-found state instead of silently matching their collapsed form (#567). A single trailing slash is still tolerated. Doubled leading slashes are also no longer normalized away by the browser integration and parse correctly instead of being treated as protocol-relative URLs.b308c21: fix #497 -revalidatenow forces the cache miss synchronously instead of deferring it into the transition microtask, so a same-tickrefetch()after an un-awaitedrevalidate()refetches fresh datae9acd69: fix #347 - acceptVoidComponentpages as route components;componentnow takes aRouteSectionComponentunion so components that don't declarechildrentype-check, while components requiring props the router doesn't pass are still rejectedsolidjs/solid-start (@solidjs/start)
v1.3.5Compare Source
Patch Changes
1e7fcf8: Update seroval and seroval-plugins to 1.6.8.seroval 1.6.8 validates decoded nodes more strictly (a promise cannot settle to another promise, and stream, sequence, and plugin inputs must have the expected shape) and lets
maxBase64Lengthconfigure the 1,000,000-character limit on binary values that 1.5 already enforced. It also enables theTemporalfeature by default. Apps onsolid-js1.9.16 or later share a single seroval copy with@solidjs/start; oldersolid-jsversions pin seroval 1.5 and will install a second copy.1e7fcf8: SendCache-Control: no-storeon server function responses by default.Server function responses, including calls made with GET, carried no
Cache-Control, so a shared cache configured to store them could serve one caller's result to another. Every response from the server function handler now defaults tono-store: results, errors, redirects, no-JS redirects, rawResponsepassthroughs, and the handler's own refusals. ACache-Controlthe function sets itself, on a returnedResponseor on the event's response headers, replaces the default rather than being combined with it, and a304is never given one.1e7fcf8: Reject cross-site server function requests with a403.A
"use server"function could be invoked from another site with the visitor's cookies, over a GET or a form POST, because the request's origin was not checked. Server function requests are now allowed only from the same origin or the same site. The check trusts theSec-Fetch-Siteheader (cross-siteis refused;same-origin,same-siteandnoneare allowed) and, when it is absent, comparesOriginagainst the request host. AnOrigin: nullwithoutSec-Fetch-Site, as sent by sandboxed iframes and some cross-origin redirect chains, is refused. Requests that carry neither header, such as those from non-browser clients, are still allowed, as are same-origin calls, user-initiated navigations, and no-JS form submissions. A separate origin that needs to call your backend should use an API route with explicit CORS.1e7fcf8: Reject server function argument values that are still pending when the request body ends.A seroval request body can describe a promise or stream that it never settles. Such a value stayed pending forever, so a server function awaiting that argument never answered. Arguments are now decoded with seroval's cross-reference decoder, and once the body has been decoded every promise it left pending rejects with "Server function stream ended unexpectedly." and every stream it left open errors. Arguments the client serializes normally (promises, errors, async iterators, streams,
FormData,Request,Headers,URLand the other supported values) decode as before. Decoded promises that nobody awaits no longer report unhandled rejections; code that awaits them still sees the rejection.storybookjs/storybook (@storybook/addon-docs)
v10.6.1Compare Source
v10.6.0Compare Source
Storybook 10.6 contains hundreds of fixes and improvements:
List of all updates
@storybook/angular-vitepeers that nothing else brings in - #36002, thanks @valentinpalkovic!@angular/corethrough the package manager, not the raw specifier - #35999, thanks @valentinpalkovic!stylesthe way the Angular builders do - #35998, thanks @valentinpalkovic!Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.