build(deps): bump the npm_and_yarn group across 4 directories with 4 updates - #1518
Merged
pathosDev merged 1 commit intoSep 10, 2026
Conversation
…updates Bumps the npm_and_yarn group with 1 update in the /examples/chat/frontend-angular directory: [hono](https://github.com/honojs/hono). Bumps the npm_and_yarn group with 3 updates in the /examples/chat/frontend-next directory: [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping), [next](https://github.com/vercel/next.js) and [sharp](https://github.com/lovell/sharp). Bumps the npm_and_yarn group with 1 update in the /examples/voice/frontend-angular directory: [hono](https://github.com/honojs/hono). Bumps the npm_and_yarn group with 3 updates in the /examples/voice/frontend-next directory: [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping), [next](https://github.com/vercel/next.js) and [sharp](https://github.com/lovell/sharp). Updates `hono` from 4.13.0 to 4.13.7 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.13.0...v4.13.7) Updates `baseline-browser-mapping` from 2.10.24 to 2.11.21 - [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases) - [Commits](web-platform-dx/baseline-browser-mapping@v2.10.24...v2.11.21) Updates `next` from 16.3.0 to 16.3.3 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.3.0...v16.3.3) Updates `sharp` from 0.35.3 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) Updates `hono` from 4.13.0 to 4.13.7 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.13.0...v4.13.7) Updates `baseline-browser-mapping` from 2.10.27 to 2.11.21 - [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases) - [Commits](web-platform-dx/baseline-browser-mapping@v2.10.24...v2.11.21) Updates `next` from 16.3.0 to 16.3.3 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.3.0...v16.3.3) Updates `sharp` from 0.35.3 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) --- updated-dependencies: - dependency-name: hono dependency-version: 4.13.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: baseline-browser-mapping dependency-version: 2.11.21 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: next dependency-version: 16.3.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: sharp dependency-version: 0.35.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: hono dependency-version: 4.13.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: baseline-browser-mapping dependency-version: 2.11.21 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: next dependency-version: 16.3.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: sharp dependency-version: 0.35.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Sep 9, 2026
pathosDev
added a commit
that referenced
this pull request
Sep 10, 2026
…n half Angular 22.0.6 -> 22.1.5 with its CLI and builder at 22.1.7 and zone.js ~0.16.3; next ^16.3.4, react and react-dom ^19.2.8 with their type packages; vite ^8.2.2 and @vitejs/plugin-react ^6.1.1; svelte ^5.57.0 with svelte-check ^4.7.6 and @sveltejs/vite-plugin-svelte ^7.3.0. TypeScript stays where each toolchain pins it — Angular peers `>=6.0 <6.1`, the others are on the 5.9 line. **The Angular bump is bigger than its version number.** `@angular/build` 22.0.8 -> 22.1.7 drags 26 transitive majors with it — Babel 7 -> 8, vite 7.3.6 -> 8.1.5, chokidar 4 -> 5, lru-cache 5 -> 11, magic-string 0.30 -> 1.0, listr2 10 -> 11, plus a rollup-to-oxc binding swap — which raw line counts hide and a package-inventory diff shows. So it was verified by building rather than by resolving: `npm ci` followed by a real `ng build` in `examples/chat/frontend-angular`, and the same for one Svelte, one React and one Next directory. All four toolchains build; CI covers the four `voice` twins, which are near-identical. **#1518's other half.** That merge patched hono 4.13.0 -> 4.13.7 (a `hono/jsx` XSS, a query parser reading past the URL fragment, an incomplete CVE-2026-39408 fix, and unbounded `parseBody()` nesting) in the two Angular `package-lock.json` files only, because Dependabot's npm updater never writes a `bun.lock`. Both bun halves kept 4.12.16 and 4.12.17. `bun install --lockfile-only` does not fix that — it preserves an existing resolution while the range still admits it — so the sync is `bun update hono baseline-browser-mapping --lockfile-only`, the recipe `246bbb9d` established. `baseline-browser-mapping` was stale in both too. Measuring that gap turned up a wider one, reported on #1402 rather than papered over here: **six of the eight directories' two lockfiles disagree even when both are regenerated in the same minute** — 54 packages in each Angular directory, some across a major, and not one-directional (`react` resolves to 19.2.8 under npm and 19.3.0 under bun). The frozen-lockfile leg from `dc766f27` is green throughout and structurally cannot see it, since it compares a `bun.lock` against the manifest beside it and a stale transitive contradicts neither. Verified: `npm ci` plus a build in one directory per toolchain, and `bun install --frozen-lockfile --dry-run` green in all eight. Refs #1520, #1402, #1518. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
pathosDev
added a commit
that referenced
this pull request
Sep 10, 2026
The 2026-09 dependency sweep (#1520): root and broker manifests, the eight example frontends with #1518's bun half finished, the DevTools UI, and the docs site. Peer floors deliberately unmoved; the five optional peers with a new major upstream, and the deprecated `nats` package, are not in it. Carries the fix for #1525 as well — the documentation site could not build at all, which is what the docs half of the sweep ran into. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
dependabot
Bot
deleted the
dependabot/npm_and_yarn/examples/chat/frontend-angular/npm_and_yarn-37f60c4a40
branch
September 10, 2026 11:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 1 update in the /examples/chat/frontend-angular directory: hono.
Bumps the npm_and_yarn group with 3 updates in the /examples/chat/frontend-next directory: baseline-browser-mapping, next and sharp.
Bumps the npm_and_yarn group with 1 update in the /examples/voice/frontend-angular directory: hono.
Bumps the npm_and_yarn group with 3 updates in the /examples/voice/frontend-next directory: baseline-browser-mapping, next and sharp.
Updates
honofrom 4.13.0 to 4.13.7Release notes
Sourced from hono's releases.
... (truncated)
Commits
eebdf7b4.13.72b8ed40Merge commit from forkcac0c4d4.13.6dac5d57refactor(on-handler): use forEach for consistent handler iteration (#5326)ec648d6chore: bumpeditorconfig-checker(#5336)e2740d5fix(types): allow symbol keys in Context<any> get and set fallbacks (#5300)499c35efix(client): normalize root WebSocket URLs (#5291)50b8788fix(client): keep a param value of "index" in $url() and $path() (#5297)06880c44.13.5531e9c5Merge commit from forkUpdates
baseline-browser-mappingfrom 2.10.24 to 2.11.21Release notes
Sourced from baseline-browser-mapping's releases.
Commits
0e5ed80Patch to 2.11.21 because browser or feature data changed11da0b6Browser or feature data changed69fcc81Updating static siteb964de0Patch to 2.11.20 because browser or feature data changed723099fBrowser or feature data changedf44163dUpdating static site8966043Patch to 2.11.19 because browser or feature data changede18601dBrowser or feature data changed28cb50aUpdating static sitecb33a83Patch to 2.11.18 because browser or feature data changedUpdates
nextfrom 16.3.0 to 16.3.3Release notes
Sourced from next's releases.
... (truncated)
Commits
a9a1cb7v16.3.3968b9fc[16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows3a15b4a[16.3.x] [next/image]: disable avif image optimization7378b51Backport/docs fixes 16.3 (#97649)528c1cd[16.3.x] Stop generating error codes (#97780)d0ac882v16.3.281deb92[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...cd714d9[16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)5ac2327[16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)0ccb3e7[16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)Updates
sharpfrom 0.35.3 to 0.35.4Release notes
Sourced from sharp's releases.
Commits
7f1a0a2Release v0.35.4f927818Upgrade to sharp-libvips v1.3.3e802092Prerelease v0.35.4-rc.0e13eb2fCI: Fix wasm32 build (#4589)a82a0b3Upgrade to libvips v8.18.68044fe4Bound resize dimensions to coordinate limit147f859Docs: changelog entries for #4578 #4584ee5bfb8Tests: use yauzl directly rather than via extract-zip wrapper7a77889Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)ea5bef2Improve support for input Streams finishing before output is requested (#4584)Updates
honofrom 4.13.0 to 4.13.7Release notes
Sourced from hono's releases.
... (truncated)
Commits
eebdf7b4.13.72b8ed40Merge commit from forkcac0c4d4.13.6dac5d57refactor(on-handler): use forEach for consistent handler iteration (#5326)ec648d6chore: bumpeditorconfig-checker(#5336)e2740d5fix(types): allow symbol keys in Context<any> get and set fallbacks (#5300)499c35efix(client): normalize root WebSocket URLs (#5291)50b8788fix(client): keep a param value of "index" in $url() and $path() (#5297)06880c44.13.5531e9c5Merge commit from forkUpdates
baseline-browser-mappingfrom 2.10.27 to 2.11.21Release notes
Sourced from baseline-browser-mapping's releases.
Commits
0e5ed80Patch to 2.11.21 because browser or feature data changed11da0b6Browser or feature data changed69fcc81Updating static siteb964de0Patch to 2.11.20 because browser or feature data changed723099fBrowser or feature data changedf44163dUpdating static site8966043Patch to 2.11.19 because browser or feature data changede18601dBrowser or feature data changed28cb50aUpdating static sitecb33a83Patch to 2.11.18 because browser or feature data changedUpdates
nextfrom 16.3.0 to 16.3.3Release notes
Sourced from next's releases.
... (truncated)
Commits
a9a1cb7v16.3.3968b9fc[16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows3a15b4a[16.3.x] [next/image]: disable avif image optimization7378b51Backport/docs fixes 16.3 (#97649)528c1cd[16.3.x] Stop generating error codes (#97780)d0ac882v16.3.281deb92[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...cd714d9[16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)5ac2327[16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)0ccb3e7[16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)Updates
sharpfrom 0.35.3 to 0.35.4Release notes
Sourced from sharp's releases.
Commits
7f1a0a2Release v0.35.4f927818Upgrade to sharp-libvips v1.3.3e802092Prerelease v0.35.4-rc.0e13eb2fCI: Fix wasm32 build (#4589)a82a0b3Upgrade to libvips v8.18.68044fe4Bound resize dimensions to coordinate limit147f859Docs: changelog entries for #4578 #4584ee5bfb8Tests: use yauzl directly rather than via extract-zip wrapper7a77889Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)ea5bef2Improve support for input Streams finishing before output is requested (#4584)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.