chore(deps): bump the security group across 4 directories with 16 updates - #1772
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump the security group across 4 directories with 16 updates#1772dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. 2 Skipped Deployments
|
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/security-7053fa539f
branch
5 times, most recently
from
August 27, 2026 13:00
d435686 to
c9d4e25
Compare
…ates Bumps the security group with 16 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.20.12` | `7.29.6` | | [svgo](https://github.com/svg/svgo) | `2.8.0` | `2.8.3` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `3.2.10` | `6.4.3` | | [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common) | `19.2.23` | `20.3.27` | | [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) | `19.2.23` | `20.3.27` | | [next](https://github.com/vercel/next.js) | `14.2.35` | `15.5.21` | | [postcss](https://github.com/postcss/postcss) | `8.4.33` | `8.5.23` | | [@hono/node-server](https://github.com/honojs/node-server) | `1.19.9` | `1.19.17` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.18` | | [fast-uri](https://github.com/fastify/fast-uri) | `3.0.6` | `3.1.7` | | [hono](https://github.com/honojs/hono) | `4.12.3` | `4.13.5` | | [http-proxy-middleware](https://github.com/chimurai/http-proxy-middleware) | `2.0.9` | `2.0.10` | | [immutable](https://github.com/immutable-js/immutable-js) | `5.1.3` | `5.1.9` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.1` | `3.15.2` | | [undici](https://github.com/nodejs/undici) | `5.28.4` | `5.29.0` | | [websocket-driver](https://github.com/faye/websocket-driver-node) | `0.7.4` | `0.7.5` | Bumps the security group with 2 updates in the /apps/swirl-docs directory: [next](https://github.com/vercel/next.js) and [postcss](https://github.com/postcss/postcss). Bumps the security group with 3 updates in the /packages/swirl-components directory: [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core), [svgo](https://github.com/svg/svgo) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the security group with 2 updates in the /packages/swirl-components-angular directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common) and [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler). Updates `@babel/core` from 7.20.12 to 7.29.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core) Updates `svgo` from 2.8.0 to 2.8.3 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v2.8.0...v2.8.3) Updates `vite` from 3.2.10 to 6.4.3 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.4.3/packages/vite) Updates `@angular/common` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/common) Updates `@angular/compiler` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/compiler) Updates `next` from 14.2.35 to 15.5.21 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v14.2.35...v15.5.21) Updates `postcss` from 8.4.33 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.33...8.5.23) Updates `@hono/node-server` from 1.19.9 to 1.19.17 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.9...v1.19.17) Updates `brace-expansion` from 1.1.11 to 1.1.18 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.18) Updates `fast-uri` from 3.0.6 to 3.1.7 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.0.6...v3.1.7) Updates `hono` from 4.12.3 to 4.13.5 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.3...v4.13.5) Updates `http-proxy-middleware` from 2.0.9 to 2.0.10 - [Release notes](https://github.com/chimurai/http-proxy-middleware/releases) - [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v2.0.10/CHANGELOG.md) - [Commits](chimurai/http-proxy-middleware@v2.0.9...v2.0.10) Updates `immutable` from 5.1.3 to 5.1.9 - [Release notes](https://github.com/immutable-js/immutable-js/releases) - [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md) - [Commits](immutable-js/immutable-js@v5.1.3...v5.1.9) Updates `js-yaml` from 3.14.1 to 3.15.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.14.1...3.15.2) Updates `undici` from 5.28.4 to 5.29.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v5.28.4...v5.29.0) Updates `websocket-driver` from 0.7.4 to 0.7.5 - [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-driver-node@0.7.4...0.7.5) Updates `next` from 14.2.35 to 15.5.21 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v14.2.35...v15.5.21) Updates `postcss` from 8.4.33 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.33...8.5.23) Updates `@babel/core` from 7.20.12 to 7.29.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core) Updates `svgo` from 2.8.0 to 2.8.3 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v2.8.0...v2.8.3) Updates `vite` from 3.2.10 to 6.4.3 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.4.3/packages/vite) Updates `@angular/common` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/common) Updates `@angular/compiler` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/compiler) Updates `next` from 14.2.35 to 15.5.21 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v14.2.35...v15.5.21) Updates `postcss` from 8.4.33 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.33...8.5.23) Updates `next` from 14.2.35 to 15.5.21 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v14.2.35...v15.5.21) Updates `postcss` from 8.4.33 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.33...8.5.23) Updates `@babel/core` from 7.23.0 to 7.29.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core) Updates `svgo` from 2.8.0 to 2.8.3 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v2.8.0...v2.8.3) Updates `vite` from 5.4.0 to 6.4.3 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.4.3/packages/vite) Updates `@babel/core` from 7.23.0 to 7.29.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core) Updates `svgo` from 2.8.0 to 2.8.3 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v2.8.0...v2.8.3) Updates `vite` from 5.4.0 to 6.4.3 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.4.3/packages/vite) Updates `@angular/common` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/common) Updates `@angular/compiler` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/compiler) Updates `@angular/common` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/common) Updates `@angular/compiler` from 19.2.23 to 20.3.27 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v20.3.27/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v20.3.27/packages/compiler) --- updated-dependencies: - dependency-name: "@angular/common" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/common" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/common" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/common" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/compiler" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/compiler" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/compiler" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@angular/compiler" dependency-version: 20.3.27 dependency-type: direct:production dependency-group: security - dependency-name: "@babel/core" dependency-version: 7.29.6 dependency-type: direct:development dependency-group: security - dependency-name: "@babel/core" dependency-version: 7.29.6 dependency-type: direct:development dependency-group: security - dependency-name: "@babel/core" dependency-version: 7.29.6 dependency-type: direct:development dependency-group: security - dependency-name: "@babel/core" dependency-version: 7.29.6 dependency-type: direct:development dependency-group: security - dependency-name: "@hono/node-server" dependency-version: 1.19.17 dependency-type: indirect dependency-group: security - dependency-name: brace-expansion dependency-version: 1.1.18 dependency-type: indirect dependency-group: security - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect dependency-group: security - dependency-name: hono dependency-version: 4.13.3 dependency-type: indirect dependency-group: security - dependency-name: http-proxy-middleware dependency-version: 2.0.10 dependency-type: indirect dependency-group: security - dependency-name: immutable dependency-version: 5.1.9 dependency-type: indirect dependency-group: security - dependency-name: js-yaml dependency-version: 3.15.1 dependency-type: indirect dependency-group: security - dependency-name: next dependency-version: 15.5.21 dependency-type: direct:production dependency-group: security - dependency-name: next dependency-version: 15.5.21 dependency-type: direct:production dependency-group: security - dependency-name: next dependency-version: 15.5.21 dependency-type: direct:production dependency-group: security - dependency-name: next dependency-version: 15.5.21 dependency-type: direct:production dependency-group: security - dependency-name: postcss dependency-version: 8.5.23 dependency-type: direct:development dependency-group: security - dependency-name: postcss dependency-version: 8.5.23 dependency-type: direct:development dependency-group: security - dependency-name: postcss dependency-version: 8.5.23 dependency-type: direct:development dependency-group: security - dependency-name: postcss dependency-version: 8.5.23 dependency-type: direct:development dependency-group: security - dependency-name: svgo dependency-version: 2.8.3 dependency-type: direct:development dependency-group: security - dependency-name: svgo dependency-version: 2.8.3 dependency-type: direct:development dependency-group: security - dependency-name: svgo dependency-version: 2.8.3 dependency-type: direct:development dependency-group: security - dependency-name: svgo dependency-version: 2.8.3 dependency-type: direct:development dependency-group: security - dependency-name: undici dependency-version: 5.29.0 dependency-type: indirect dependency-group: security - dependency-name: vite dependency-version: 6.4.3 dependency-type: direct:development dependency-group: security - dependency-name: vite dependency-version: 6.4.3 dependency-type: direct:development dependency-group: security - dependency-name: vite dependency-version: 6.4.3 dependency-type: direct:development dependency-group: security - dependency-name: vite dependency-version: 6.4.3 dependency-type: direct:development dependency-group: security - dependency-name: websocket-driver dependency-version: 0.7.5 dependency-type: indirect dependency-group: security ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/security-7053fa539f
branch
from
September 3, 2026 07:52
c9d4e25 to
e5c86dc
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the security group with 16 updates in the / directory:
7.20.127.29.62.8.02.8.33.2.106.4.319.2.2320.3.2719.2.2320.3.2714.2.3515.5.218.4.338.5.231.19.91.19.171.1.111.1.183.0.63.1.74.12.34.13.52.0.92.0.105.1.35.1.93.14.13.15.25.28.45.29.00.7.40.7.5Bumps the security group with 2 updates in the /apps/swirl-docs directory: next and postcss.
Bumps the security group with 3 updates in the /packages/swirl-components directory: @babel/core, svgo and vite.
Bumps the security group with 2 updates in the /packages/swirl-components-angular directory: @angular/common and @angular/compiler.
Updates
@babel/corefrom 7.20.12 to 7.29.6Release notes
Sourced from @babel/core's releases.
... (truncated)
Commits
04ea6b2v7.29.699f498a[7.x packport]Improve input source map handling (#18001)feba0a3Preserve original identifier names from input sourcemaps (#17992) (#17998)aa8394ev7.29.0ad0d03f[7.x backport] feat: Allow specifying startLine in code frame (#17739)d7f4008v7.28.6e130225Polish(standalone): improve message on invalid preset/plugin (#17606)99dcba5chore: enable some ts-eslint rules (#17592)c92c491Improve Unicode handling in code-frame tokenizer (#17589)d725e39AddBABEL_7_TO_8_DANGEROUSLY_DISABLE_VERSION_CHECK(#17569)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@babel/coresince your current version.Updates
svgofrom 2.8.0 to 2.8.3Release notes
Sourced from svgo's releases.
... (truncated)
Commits
628e3bcMerge commit from forkf706b07deps: upgrade to sax v1.5.0Maintainer changes
This version was pushed to npm by sethiii, a new releaser for svgo since your current version.
Updates
vitefrom 3.2.10 to 6.4.3Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
6c2c881release: v6.4.396b0c10fix: backport #22572, reject windows alternate paths (#22576)8fed5cffix(deps): backport #22571, reject UNC paths for launch-editor-middleware (#2...6b3fad0release: v6.4.2ca4da5dfix: avoid path traversal with optimize deps sourcemap handler (#22161)fe28e47fix: apply server.fs check to env transport (#22159) (#22163)5487f4frelease: v6.4.11114b5dfix(dev): trim trailing slash beforeserver.fs.denycheck (#20968) (#20969)f12697crelease: v6.4.0ca6455efeat: allow passing down resolved config to vite's createServer (#20932)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for vite since your current version.
Updates
@angular/commonfrom 19.2.23 to 20.3.27Release notes
Sourced from @angular/common's releases.
... (truncated)
Changelog
Sourced from @angular/common's changelog.
... (truncated)
Commits
a64e288fix(http): distinguish repeated transfer cache paramsb963f61fix(http): prevent caching of responses with Set-Cookie headers06be298fix(http): preserve empty referrer option in HttpRequest9f443bcfix(common): Limits date format string lengthfa940e1fix(http): Rejects non-HTTP(S) URLs in JSONP requests1a62130fix(common): use cryptographically secure SHA-256 for transfer cache key gene...566ad05fix(common): skip transfer cache for uncacheable HTTP traffice2ef1cefix(http): skip transfer cache for fetch credentialed requests3d135cefix(common): add upper bounds for digitsInfo39a4b4cfix(common): sanitize placeholderUpdates
@angular/compilerfrom 19.2.23 to 20.3.27Release notes
Sourced from @angular/compiler's releases.
... (truncated)
Changelog
Sourced from @angular/compiler's changelog.
... (truncated)
Commits
db0d4a1fix(compiler): restrict possible event handler check to property names longer...5dbcd0efix(compiler): disallow i18n event attributesa68ec70fix(compiler): sanitize two-way propertiesd40acc6fix(compiler): prevent namespaced SVG <style> elements from being stripped7ae6381test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...36200bdtest(core): update spec files to match 20.3.x limits and actual contexts (#68...823b37ftest(compiler): remove obsolete schema_extractor import (#68926)e345a58fix(core): normalize tag names in runtime i18n attribute security context loo...8f35b18fix(compiler): normalize tag names with custom namespaces in DomElementSchema...64a89e9fix(compiler): sanitize dynamic href and xlink:href bindings on SVG a element...Updates
nextfrom 14.2.35 to 15.5.21Release notes
Sourced from next's releases.
Commits
e26f6ffv15.5.217f5deeb[15.x] Improve performance of checking valid MPA form submissions57c31f7[15.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimee3e5666[15.x] Set correct origin for internal redirects in custom server35f5013[15.x] Ensure exotic rewrite param values are properly encoded062f667[15.x] fix(fetch-cache): key fetch(Request, init) by the effective request577c9dc[15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies530d4fa[15.x] fix(next/image): improve performance of detectContentType()8fabaf3[15.x] Performance improvements when decoding React Server function payloadsff12a61[15.x] Validate server reference IDs during manifest lookupMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.
Updates
postcssfrom 8.4.33 to 8.5.23Release notes
Sourced from postcss's releases.
... (truncated)
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
eb9e1feRelease 8.5.23 version9d19c78Update dependencies7beca13Does no load source map file without opts.fromdecea51Typoc18e30dUpdate EM banner98a39adUpdate EM bannera3e48c4Release 8.5.22 versionf49d691Fix custom property losing its semicolon before a comment (#2117)28e0dafRelease 8.5.21 version3d2b4e4Update dependenciesMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.
Updates
@hono/node-serverfrom 1.19.9 to 1.19.17Release notes
Sourced from @hono/node-server's releases.
Commits
71941da1.19.170208500ci: addstageoption for publishing (#386)cbdf7131.19.1686e96c2ci: add an action for trusted publisher (#385)99c1a1aci: run on v1.x branch pushes84cb2eeMerge commit from forkb5e63a31.19.14c02d777fix: add custom inspect to lightweight Request/Response to prevent TypeError ...fd64e651.19.13025c30fMerge commit from forkMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Updates
brace-expansionfrom 1.1.11 to 1.1.18Release notes
Sourced from brace-expansion's releases.
Commits
758fcd61.1.1827fbeedMerge commit from fork5c57cc21.1.17d757f1dnpm ignore.claudecb4b9e4fix: backport GHSA-mh99-v99m-4gvg (#129)447763a1.1.16d74e630fix: v1 backport for CVE-2026-13149 (#122)2203f4f1.1.150b09384Backport v5.0.6 change to v1 (#111)10c05fc1.1.14Updates
fast-urifrom 3.0.6 to 3.1.7Release notes
Sourced from fast-uri's releases.