Skip to content

chore(deps-dev): Bump the minor-and-patch group across 1 directory with 10 updates - #1662

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/bun/minor-and-patch-9a1b7590ca
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/bun/minor-and-patch-9a1b7590ca

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 10 updates in the / directory:

Package From To
@fastify/static 10.1.4 10.1.5
@fastify/websocket 11.3.1 11.3.3
@hono/node-server 2.1.1 2.1.3
@types/node 24.13.5 24.19.1
fast-check 4.10.1 4.10.2
knip 6.37.0 6.39.0
publint 0.3.24 0.3.25
hono 4.13.8 4.13.13
ws 8.21.3 8.22.0
@types/ws 8.18.1 8.18.2

Updates @fastify/static from 10.1.4 to 10.1.5

Release notes

Sourced from @​fastify/static's releases.

v10.1.5

What's Changed

New Contributors

Full Changelog: fastify/fastify-static@v10.1.4...v10.1.5

Commits

Updates @fastify/websocket from 11.3.1 to 11.3.3

Release notes

Sourced from @​fastify/websocket's releases.

v11.3.3

What's Changed

Full Changelog: fastify/fastify-websocket@v11.3.2...v11.3.3

v11.3.2

What's Changed

New Contributors

Full Changelog: fastify/fastify-websocket@v11.3.1...v11.3.2

Commits
  • 8b58c9f Bumped v11.3.3
  • 51a121c fix(types): type handler as websocket handler in route() with websocket: true...
  • 6e034a4 Bumped v11.3.2
  • 5adf931 fix: handle socket errors during upgrade hooks
  • See full diff in compare view

Updates @hono/node-server from 2.1.1 to 2.1.3

Release notes

Sourced from @​hono/node-server's releases.

v2.1.3

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

Commits

Updates @types/node from 24.13.5 to 24.19.1

Commits

Updates fast-check from 4.10.1 to 4.10.2

Release notes

Sourced from fast-check's releases.

v4.10.2

Fix interrupt plugin (throwing) [Code][Diff]

Fixes

  • (PR#7333) Bug: Plugin interruptAfterTimeLimit crashes
Changelog

Sourced from fast-check's changelog.

4.10.2

Fix interrupt plugin (throwing) [Code][Diff]

Fixes

  • (PR#7333) Bug: Plugin interruptAfterTimeLimit crashes
Commits

Updates knip from 6.37.0 to 6.39.0

Release notes

Sourced from knip's releases.

Release 6.39.0

  • Add Railway plugin (#2026) (6da55767eb419701dd32f93789a00e8bdc915276) - thanks @​jonahsnider!
  • Update query snapshot (8877d3cf35943e17a617e1197fa46c5a43342479)
  • Fix excluded tags on entry re-exports (#2062) (b22e27543cb8dd4ba7ec97c70ccfd06bc8f16614) - thanks @​devYRPauli!
  • Update rolldown snapshot (3a45c806e1c1b7ceb078903652c8631566400096)
  • Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067) (d912d807e41f140bbc79bafce6882b3c05dec6ff) - thanks @​bytedoe!
  • fix(angular): keep other projects' inputs when one has no architect (#2064) (af3f42e9772e9937fd71b7557d3b54aee1db339a) - thanks @​Cayan!
  • fix(vite): resolve nested HTML entry points in multi-page apps (#1988) (4648aefe56e7bac521bb6f17189473b46f8ff00f) - thanks @​DreamLongYT!
  • Improve Rstest plugin support (#2068) (add87992e9dfe2f3c22e4c6ba7fa257d7f0151cf) - thanks @​fi3ework!
  • Handle profiles, formatters and require paths in Cucumber plugin (#2065) (2ad39fcf02e067b4bdfc06a658bf4bf5abeea764) - thanks @​giaBaoJS!
  • fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076) (7060bb968339680d694275413aba2833e4521ed9) - thanks @​alokn!
  • fix: read entry export tags under the re-exported names (#2069) (1698683df95a96b3515795eb664aacf030042d7b) - thanks @​devYRPauli!

Release 6.38.0

  • Include co-authors in docs contributor list (0c334100df59d89a512ad598ec50e7f62f6da0c3)
  • Filter bots and agents from docs contributors (617f70d8179c6b8668ca41fe5df77ced5e2b37c0)
  • Update Eve plugin conventions (#2049) (260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks @​matchai!
  • Add args example to that doc page (50b271b98fc930a05a3b045a2f691486f9f06528)
  • Add Turborepo plugin (#2055) (e49d3db05f1d69ce7db3efcb8467a4af63c27379) - thanks @​changbaebang!
  • Support import-x/* settings in ESLint plugin (#2050) (1a34cf82a3d6a1202717ef910bedba55838e9dd9) - thanks @​bytedoe!
  • Resolve file option in Mocha configuration files (#2051) (9b5c5f60468c8a92a3e74adca5c0931f008677af) - thanks @​giaBaoJS!
  • Support oxlint extends (#2054) (a149a98219bb14b15f446fc5f8c4f815e28b2183) - thanks @​matthewnitschke-wk!
  • Fix import.meta handling in built-in compilers (#2059) (8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded) - thanks @​vdavid!
  • Fix tag hints for enum and namespace members (#2061) (8a8805e48945863248429d18b7f6c4e4b7dc9ebd) - thanks @​devYRPauli!
  • Flag unused member tags in tagged enums and namespaces (584e53ff3e0846fbfe04fa5b5bfefe2420576a34)
  • feat: resolve MDX content mapper remarkPlugins (#2060) (34dbccf25359f9e9fefe9d0be6ef2ec0252223cc) - thanks @​gioboa!
  • Refactor and separate concerns w/ new typescript-content-mapper plugin (11e94509bd0f350d747facf4003fc5b248d1b02d)
  • Resolve mdx content mapper providerImportSource (7b5825117f97f2f87b7141509a254f88d0957cf7)
  • Fix config → entry in plop plugin (25a380c9e1165b76583d69b48b5fa7cdf5db0ae2)
Commits
  • ed30e5b Release knip@6.39.0
  • 1698683 fix: read entry export tags under the re-exported names (#2069)
  • 7060bb9 fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076)
  • 2ad39fc Handle profiles, formatters and require paths in Cucumber plugin (#2065)
  • add8799 Improve Rstest plugin support (#2068)
  • 4648aef fix(vite): resolve nested HTML entry points in multi-page apps (#1988)
  • af3f42e fix(angular): keep other projects' inputs when one has no architect (#2064)
  • d912d80 Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067)
  • b22e275 Fix excluded tags on entry re-exports (#2062)
  • 6da5576 Add Railway plugin (#2026)
  • Additional commits viewable in compare view

Updates publint from 0.3.24 to 0.3.25

Release notes

Sourced from publint's releases.

publint@0.3.25

Patch Changes

  • #260 54aebea - Fix FILE_INVALID_JSX_EXTENSION not detecting the .ctsx extension

  • #265 78604f3 - Skip file existence check for browser field values that point at another package

Changelog

Sourced from publint's changelog.

0.3.25

Patch Changes

  • #260 54aebea - Fix FILE_INVALID_JSX_EXTENSION not detecting the .ctsx extension

  • #265 78604f3 - Skip file existence check for browser field values that point at another package

Commits

Updates hono from 4.13.8 to 4.13.13

Release notes

Sourced from hono's releases.

v4.13.13

Mount Middleware

app.mount() is now available as the Mount Middleware, hono/mount. It is just a handler, so you register it with app.all():

import { Router as IttyRouter } from 'itty-router'
import { Hono } from 'hono'
import { mount } from 'hono/mount'
const ittyRouter = IttyRouter()
ittyRouter.get('/hello', () => new Response('Hello from itty-router'))
const app = new Hono()
app.all('/itty-router/*', mount(ittyRouter.handle))

app.mount() still works in v4 but is deprecated and will be removed in v5. Migrating is a one-line change:

- app.mount('/itty-router', ittyRouter.handle)
+ app.all('/itty-router/*', mount(ittyRouter.handle))

What's Changed

  • test(client): simulate network error for undefined route in parseResponse test in honojs/hono#5439
  • docs(request): fix jsdoc comments for some getters in honojs/hono#5445
  • fix(jsx): allow JSXNode function component results in honojs/hono#5476
  • feat(mount): introduce Mount Middleware and deprecate app.mount in honojs/hono#5221

Full Changelog: honojs/hono@v4.13.12...v4.13.13

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

... (truncated)

Commits
  • 08a023c 4.13.13
  • ae595de feat(mount): introduce Mount Middleware and deprecate app.mount (#5221)
  • f23b146 fix(jsx): allow JSXNode function component results (#5476)
  • 6d73a74 docs(request): fix jsdoc comments for some getters (#5445)
  • deff529 test(client): simulate network error for undefined route in parseResponse tes...
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • Additional commits viewable in compare view

Updates ws from 8.21.3 to 8.22.0

Release notes

Sourced from ws's releases.

8.22.0

Features

  • Introduced the protocols option (8b918b01).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the state to WebSocket.CLOSING (#2337).
Commits
  • 297202c [dist] 8.22.0
  • 8b918b0 [feature] Introduce the protocols option
  • 73e03eb [ci] Update actions/setup-node action to v7
  • d9b8954 [fix] Change the ready state after validating the arguments (#2337)
  • See full diff in compare view

Updates @types/ws from 8.18.1 to 8.18.2

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 10 updates

Bumps the minor-and-patch group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@fastify/static](https://github.com/fastify/fastify-static) | `10.1.4` | `10.1.5` |
| [@fastify/websocket](https://github.com/fastify/fastify-websocket) | `11.3.1` | `11.3.3` |
| [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.5` | `24.19.1` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.10.1` | `4.10.2` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.37.0` | `6.39.0` |
| [publint](https://github.com/publint/publint/tree/HEAD/packages/publint) | `0.3.24` | `0.3.25` |
| [hono](https://github.com/honojs/hono) | `4.13.8` | `4.13.13` |
| [ws](https://github.com/websockets/ws) | `8.21.3` | `8.22.0` |
| [@types/ws](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/ws) | `8.18.1` | `8.18.2` |



Updates `@fastify/static` from 10.1.4 to 10.1.5
- [Release notes](https://github.com/fastify/fastify-static/releases)
- [Commits](fastify/fastify-static@v10.1.4...v10.1.5)

Updates `@fastify/websocket` from 11.3.1 to 11.3.3
- [Release notes](https://github.com/fastify/fastify-websocket/releases)
- [Commits](fastify/fastify-websocket@v11.3.1...v11.3.3)

Updates `@hono/node-server` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v2.1.1...v2.1.3)

Updates `@types/node` from 24.13.5 to 24.19.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `fast-check` from 4.10.1 to 4.10.2
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.2/packages/fast-check)

Updates `knip` from 6.37.0 to 6.39.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.39.0/packages/knip)

Updates `publint` from 0.3.24 to 0.3.25
- [Release notes](https://github.com/publint/publint/releases)
- [Changelog](https://github.com/publint/publint/blob/master/packages/publint/CHANGELOG.md)
- [Commits](https://github.com/publint/publint/commits/publint@0.3.25/packages/publint)

Updates `hono` from 4.13.8 to 4.13.13
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.8...v4.13.13)

Updates `ws` from 8.21.3 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.3...8.22.0)

Updates `@types/ws` from 8.18.1 to 8.18.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/ws)

---
updated-dependencies:
- dependency-name: "@fastify/static"
  dependency-version: 10.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@fastify/websocket"
  dependency-version: 11.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 24.19.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: fast-check
  dependency-version: 4.10.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: knip
  dependency-version: 6.39.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: publint
  dependency-version: 0.3.25
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: hono
  dependency-version: 4.13.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/ws"
  dependency-version: 8.18.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants