Skip to content

chore(deps): update all non-major dependencies#1662

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
buddy-bot/update-non-major-updates
Open

chore(deps): update all non-major dependencies#1662
github-actions[bot] wants to merge 1 commit into
mainfrom
buddy-bot/update-non-major-updates

Conversation

@github-actions

@github-actions github-actions Bot commented Apr 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Updates Summary

Type Count
📦 NPM Packages 30
🔧 System Dependencies 1
Total 31

📦 npm Dependencies

npm

30 packages will be updated

Package Change Age Adoption Passing Confidence
@capacitor/android (source) 8.3.0 -> 8.4.0 age adoption passing confidence
@capacitor/cli (source) 8.3.0 -> 8.4.0 age adoption passing confidence
@capacitor/core (source) 8.3.0 -> 8.4.0 age adoption passing confidence
@capacitor/ios (source) 8.3.0 -> 8.4.0 age adoption passing confidence
@types/vscode (source) 1.110.0 -> 1.120.0 age adoption passing confidence
@vscode/vsce (source) 3.7.2-12 -> 3.9.2 age adoption passing confidence
dompurify (source) 3.3.3 -> 3.4.8 age adoption passing confidence
happy-dom (source) 20.8.9 -> 20.10.2 age adoption passing confidence
isomorphic-dompurify (source) 3.7.1 -> 3.16.0 age adoption passing confidence
js-yaml (source) 4.1.1 -> 4.2.0 age adoption passing confidence
jsdom (source) 29.0.1 -> 29.1.1 age adoption passing confidence
liquidjs (source) 10.25.2 -> 10.27.0 age adoption passing confidence
markdown-it (source) 14.1.1 -> 14.2.0 age adoption passing confidence
vscode-languageserver-types (source) 3.17.5 -> 3.18.0 age adoption passing confidence
ws (source) 8.20.0 -> 8.21.0 age adoption passing confidence
@11ty/eleventy (source) 3.1.5 -> 3.1.6 age adoption passing confidence
@capacitor/keyboard (source) 8.0.2 -> 8.0.3 age adoption passing confidence
@cwcss/crosswind (source) 0.2.0 -> 0.2.4 age adoption passing confidence
@iconify/json (source) 2.2.463 -> 2.2.484 age adoption passing confidence
@stacksjs/clapp (source) 0.2.0 -> 0.2.10 age adoption passing confidence
@stacksjs/ts-cloud (source) 0.2.3 -> 0.2.26 age adoption passing confidence
@types/bun (source) 1.3.11 -> 1.3.14 age adoption passing confidence
bun (source) =1.3.11 -> 1.3.14 age adoption passing confidence
bunfig (source) 0.15.6 -> 0.15.13 age adoption passing confidence
pickier (source) 0.1.33 -> 0.1.34 age adoption passing confidence
prettier (source) 3.8.1 -> 3.8.4 age adoption passing confidence
sanitize-html (source) 2.17.2 -> 2.17.4 age adoption passing confidence
tinybench (source) 6.0.0 -> 6.0.2 age adoption passing confidence
ts-broadcasting 0.0.4 -> 0.0.5 age adoption passing confidence
vscode-languageserver-textdocument (source) 1.0.12 -> 1.0.13 age adoption passing confidence

🔧 System Dependencies

system

Package Change Type File
bun.com ^1.3.4^1.3.11 🟢 patch deps.yaml

Release Notes

ionic-team/capacitor (@capacitor/android)

8.3.0 -> 8.4.0

9.0.0-alpha.3

Compare Source

9.0.0-alpha.3 (2026-06-02)

Bug Fixes

  • android: show only the requested system bar (#8480) (4c6c321)
  • cli: revert live reload config on failure (#8485) (1d031a4)
  • SystemBars: make safe-area-inset-x available on API <= 34 (#8424) (e456de0)
  • SystemBars: respect insetsHandling disable (#8481) (d4ad7ff)

Features

[View full release notes]

Released by jcesarmobile on 6/2/2026

8.4.0

Compare Source

8.4.0 (2026-06-02)

Bug Fixes

  • android: show only the requested system bar (#8480) (4c6c321)
  • cli: revert live reload config on failure (#8485) (1d031a4)
  • SystemBars: make safe-area-inset-x available on API <= 34 (#8424) (e456de0)
  • SystemBars: respect insetsHandling disable (#8481) (d4ad7ff)

Features

  • add method getDouble to plugin config (#7638) ([93c72de](https://...

[View full release notes]

Released by jcesarmobile on 6/2/2026

9.0.0-alpha.2

Compare Source

9.0.0-alpha.2 (2026-05-12)

Note: Version bump only for package capacitor

Released by jcesarmobile on 5/12/2026

ionic-team/capacitor (@capacitor/cli)

8.3.0 -> 8.4.0

Compare Source

Capacitor: Cross-platform apps with JavaScript and the web

📖 View Release Notes

🔗 View Changelog

Release Notes

Changelog

ionic-team/capacitor (@capacitor/core)

8.3.0 -> 8.4.0

9.0.0-alpha.3

Compare Source

9.0.0-alpha.3 (2026-06-02)

Bug Fixes

  • android: show only the requested system bar (#8480) (4c6c321)
  • cli: revert live reload config on failure (#8485) (1d031a4)
  • SystemBars: make safe-area-inset-x available on API <= 34 (#8424) (e456de0)
  • SystemBars: respect insetsHandling disable (#8481) (d4ad7ff)

Features

[View full release notes]

Released by jcesarmobile on 6/2/2026

8.4.0

Compare Source

8.4.0 (2026-06-02)

Bug Fixes

  • android: show only the requested system bar (#8480) (4c6c321)
  • cli: revert live reload config on failure (#8485) (1d031a4)
  • SystemBars: make safe-area-inset-x available on API <= 34 (#8424) (e456de0)
  • SystemBars: respect insetsHandling disable (#8481) (d4ad7ff)

Features

  • add method getDouble to plugin config (#7638) ([93c72de](https://...

[View full release notes]

Released by jcesarmobile on 6/2/2026

9.0.0-alpha.2

Compare Source

9.0.0-alpha.2 (2026-05-12)

Note: Version bump only for package capacitor

Released by jcesarmobile on 5/12/2026

ionic-team/capacitor (@capacitor/ios)

8.3.0 -> 8.4.0

9.0.0-alpha.3

Compare Source

9.0.0-alpha.3 (2026-06-02)

Bug Fixes

  • android: show only the requested system bar (#8480) (4c6c321)
  • cli: revert live reload config on failure (#8485) (1d031a4)
  • SystemBars: make safe-area-inset-x available on API <= 34 (#8424) (e456de0)
  • SystemBars: respect insetsHandling disable (#8481) (d4ad7ff)

Features

[View full release notes]

Released by jcesarmobile on 6/2/2026

8.4.0

Compare Source

8.4.0 (2026-06-02)

Bug Fixes

  • android: show only the requested system bar (#8480) (4c6c321)
  • cli: revert live reload config on failure (#8485) (1d031a4)
  • SystemBars: make safe-area-inset-x available on API <= 34 (#8424) (e456de0)
  • SystemBars: respect insetsHandling disable (#8481) (d4ad7ff)

Features

  • add method getDouble to plugin config (#7638) ([93c72de](https://...

[View full release notes]

Released by jcesarmobile on 6/2/2026

9.0.0-alpha.2

Compare Source

9.0.0-alpha.2 (2026-05-12)

Note: Version bump only for package capacitor

Released by jcesarmobile on 5/12/2026

DefinitelyTyped/DefinitelyTyped (@types/vscode)

1.110.0 -> 1.120.0

Compare Source

TypeScript definitions for vscode

📖 View Release Notes

🔗 View Changelog

Release Notes

Changelog

Microsoft/vsce (@vscode/vsce)

3.7.2-12 -> 3.9.2

v3.9.2

Compare Source

Changes:

  • #1283: fix: skip APIScan
  • #1282: chore: bump CI to Node 22 and fix build
  • #1279: Bump the uuid test fixture version to 100.0.0
  • #1278: Bump tmp from 0.2.4 to 0.2.6
  • #1277: Bump qs from 6.14.2 to 6.15.2
  • #1276: Bump uuid and azure/msal-node
  • #1274: Run npm audit fix
  • #1272: Bump fast-uri from 3.0.6 to 3.1.2
  • #1267: Bump minimatch from 10.2.2 to 10.2.3
  • #1247: Update minimatch dependency to v10

This list of changes was auto generated.

Released by joaomoreno on 6/3/2026

v3.9.2-4

Compare Source

Changes:

  • #1283: fix: skip APIScan
  • #1282: chore: bump CI to Node 22 and fix build
  • #1279: Bump the uuid test fixture version to 100.0.0
  • #1278: Bump tmp from 0.2.4 to 0.2.6
  • #1277: Bump qs from 6.14.2 to 6.15.2
  • #1276: Bump uuid and azure/msal-node

This list of changes was auto generated.

Released by joaomoreno on 6/3/2026

v3.9.2-3

Compare Source

Changes:

  • #1274: Run npm audit fix

This list of changes was auto generated.

Released by joaomoreno on 5/14/2026

cure53/DOMPurify (dompurify)

3.3.3 -> 3.4.8

3.4.8

Compare Source

  • Cleaned up the repository root, renamed some and removed unneeded files
  • Fixed an issue with handling of Trusted Types policies, thanks fulstadev
  • Fixed the node iterator for better template scrubbing, thanks IamLeandrooooo
  • Included formerly missing LICENSE-MPL in published npm package, thanks asamuzaK
  • Bumped several dependencies where possible

Released by cure53 on 6/3/2026

3.4.7

Compare Source

  • Hardened the handling of Shadow Roots when using IN_PLACE, thanks GameZoneHacker
  • Removed a problem leading to permanent hook pollution, thanks offset
  • Refactored the test suite and expanded test coverage significantly

Released by cure53 on 5/27/2026

3.4.6

Compare Source

  • Fixed several issues with DOM Clobbering in IN_PLACE mode, thanks offset & Bankde
  • Hardened the checks for cross-realm IN_PLACE and Shadow DOM sanitization, thanks offset & Bankde
  • Added more test coverage for IN_PLACE and general DOM Clobbering attacks
  • Bumped several dependencies where possible

Released by cure53 on 5/26/2026

capricorn86/happy-dom (happy-dom)

20.8.9 -> 20.10.2

v20.10.2

Compare Source

👷‍♂️ Patch fixes

  • Updates external dependencies - By capricorn86 in task #2163

Released by github-actions[bot] on 6/6/2026

v20.10.0

Compare Source

🎨 Features

[View full release notes]

Released by capricorn86 on 6/3/2026

v20.9.0

Compare Source

🎨 Features

  • Adds support for event listener properties on Window (e.g. Window.onkeydown) - By capricorn86 in task #2131

Released by capricorn86 on 4/13/2026

kkomelin/isomorphic-dompurify (isomorphic-dompurify)

3.7.1 -> 3.16.0

Makes it possible to use DOMPurify on server and client in the same way.

📖 View Release Notes

🔗 View Changelog

nodeca/js-yaml (js-yaml)

4.1.1 -> 4.2.0

Compare Source

YAML 1.2 parser and serializer

📖 View Release Notes

🔗 View Changelog

Release Notes

Changelog

jsdom/jsdom (jsdom)

29.0.1 -> 29.1.1

v29.1.1

Compare Source

  • Fixed 'border-radius' computed style serialization. (asamuzaK)
  • Fixed computed style computation when using 'background-origin' and 'background-clip' CSS properties. (asamuzaK)
  • Significantly optimized initial calls to getComputedStyle(), before the cache warms up. (asamuzaK)

Released by domenic on 4/30/2026

v29.1.0

Compare Source

  • Added basic support for the ratio CSS type. (asamuzaK)
  • Fixed getComputedStyle() sometimes returning outdated results after CSS was modified. (asamuzaK)

Released by domenic on 4/27/2026

v29.0.2

Compare Source

  • Significantly improved and sped up getComputedStyle(). Computed value rules are now applied across a broader set of properties, and include fixes related to inheritance, defaulting keywords, custom properties, and color-related values such as currentcolor and system colors. (asamuzaK)
  • Fixed CSS 'background' and 'border' shorthand parsing. (asamuzaK)

Released by domenic on 4/7/2026

harttle/liquidjs (liquidjs)

10.25.2 -> 10.27.0

v10.27.0

Compare Source

10.27.0 (2026-05-15)

Features

  • context: null-prototype scope frames via createScope (#899) (47d3f1b)

Released by github-actions[bot] on 5/15/2026

v10.26.0

Compare Source

10.26.0 (2026-05-14)

Bug Fixes

[View full release notes]

Released by github-actions[bot] on 5/14/2026

v10.25.7

Compare Source

10.25.7 (2026-04-23)

Bug Fixes

  • filters: support Buffer input in base64_encode to prevent binary data corruption (#881) (0ee6dbb)

Released by github-actions[bot] on 4/23/2026

markdown-it/markdown-it (markdown-it)

14.1.1 -> 14.2.0

Compare Source

Markdown-it - modern pluggable markdown parser.

📖 View Release Notes

🔗 View Changelog

Release Notes

Changelog

Microsoft/vscode-languageserver-node (vscode-languageserver-types)

3.17.5 -> 3.18.0

release/types/3.18.0

Compare Source

Changes:

Feature Requests:

  • #1691: Use NoInfer for better typing
  • #1692: setImmediate Implementation in browser RAL for json-rpc is not ideal.
  • #1698: RenameParams does not reference TextDocumentPositionParams interface in the JSON metamodel

Bugs:

  • #752: Edits are applied twice
  • #1717: Client requests textDocument/diagnostics before textDocument/didOpen
  • #1693: Output channel leak when stopping LanguageClient
  • #1581: Client error 'Failed to determine file type' after undoing rename with Cmd+Z
  • #1548: Extra true in the output log when a language server disconnects
See More

Others:

  • #1785: Allow returning null in SemanticTokensFeatureShape.on handler
  • #1784: SemanticTokensFeatureShape.on handler does not allow returning null
  • #1780: Add getMessageString function to Diagnostic namespace
  • #1779: Add 3.17 version check method for Diagnostic
  • #1778: Merge next release into main
  • #1777: U...

[View full release notes]

Released by joaomoreno on 6/3/2026

release/server/10.0.0

Compare Source

Released by joaomoreno on 6/3/2026

release/protocol/3.18.0

Compare Source

Released by joaomoreno on 6/3/2026

websockets/ws (ws)

8.20.0 -> 8.21.0

8.21.0

Compare Source

Features

  • Introduced the maxBufferedChunks and maxFragments options (2b2abd45).

Bug fixes

  • Fixed a remote memory exhaustion DoS vulnerability (2b2abd45).

A high volume of tiny fragments and data chunks could be sent by a peer, using
modest network traffic, to crash a ws server or client due to OOM.

import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebSocketServer({ port: 0 }, function () {
  const data = Buffer.alloc(1);
  const options = { fin: false };
  const { port } = wss.address();
  const ws = new WebSocket(`ws://localhost:${port}`);

  ws.on('open', function () {
    (function send() {
      ws.send(data, options, function (err) {
        if (err) return;
        send();
      });
    })();
  });

  ws.on('error', console.error);
  ws.on('close', function (code, reason) {
    console.log(`client close - code: ${code} reason: ${reason.toString()}`);
  });
});

wss.on('connection', function (ws) {
  ws.on('error', console.error);
  ws.on('c...

*[View full release notes]*

*Released by [lpinca](https://github.com/lpinca) on 5/22/2026*

### [`8.20.1`](https://github.com/websockets/ws/releases/tag/8.20.1)

[Compare Source](https://github.com/websockets/ws/compare/v8.20.0...v8.21.0)

# Bug fixes

- Fixed an uninitialized memory disclosure issue in `websocket.close()`
  (c0327ec1).

Providing a `TypedArray` (e.g. `Float32Array`) as the `reason` argument for
`websocket.close()`, rather than the supported string or `Buffer` types, caused
uninitialized memory to be disclosed to the remote peer.

```js
import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebSocketServer(
  { port: 0, skipUTF8Validation: true },
  function () {
    const { port } = wss.address();
    const ws = new WebSocket(`ws://localhost:${port}`, {
      skipUTF8Validation: true
    });

    ws.on('close', function (code, reason) {
      deepStrictEqual(reason, Buffer.alloc(80));
    });
  }
);

wss.on('connection', function (ws) {
  ws.close(1000, new Float32Array(20));
});

The issue was privately reported by Nikita Skovoroda.

Released by lpinca on 5/12/2026

11ty/eleventy (@11ty/eleventy)

3.1.5 -> 3.1.6

v3.1.6

Compare Source

  • Fixes Node 26 module.register deprecation warning shown in console #4283 (fixed in v4 alphas in #4271)
  • Minor dependency upgrades for npm audit fixes
    • liquidjs upgrade from 1.25.0 to 1.27.0
    • markdown-it upgrade from 14.1.1 to 14.2.0
  • Adds Node 26 to CI for v3 branch
  • Opt out of package manager cache for GitHub Actions CI release workflow (hardening security)

Milestone: https://github.com/11ty/eleventy/milestone/52?closed=1
Full Changelog: 11ty/eleventy@v3.1.5...v3.1.6

Released by zachleat on 6/2/2026

v4.0.0-alpha.7

Compare Source

Installation: npm install @11ty/eleventy@canary --save-exact
v4.0 Milestone: https://github.com/11ty/eleventy/milestone/46?closed=1
Commit log (from last canary): 11ty/eleventy@v4.0.0-alpha.6...v4.0.0-alpha.7

Fairi warning: this may be one of the last canary releases before you see some names start to change to Build Awesome.

What’s New?

  • Enables Node’s compile cache by default (opt-out available) #3499
  • Update error messaging around require(esm) Node versions 2018d43351d4bf20e2ce1907ec6fe02d229988eb
  • <meta> elements need closing slash when using HTML Transformer plugins (workaround for garbage parsers) #4200
  • Very experimental support for zero-config TypeScript (type stripping) support for Configuration Files, Data Files, Template files, Dependency mapping (when using --watch or --serve) on Node 22.6+ and newer #4194 #4195
  • Show configuration file in use on console output #3654
  • Fre...

[View full release notes]

Released by zachleat on 3/20/2026

v4.0.0-alpha.6

Compare Source

Bug Fixes

  • Breaking (very low-risk): Fixes #2766. Changes how boolean attributes are rendered in the HTML Base plugin (and other plugins using the HTML Transformer API). e.g. <input disabled> now outputs as <input disabled> instead of <input disabled="">
  • Fixes #4188 bug with setLiquidOptions addding global data by paulrobertlloyd in 11ty/eleventy#4189
  • Fixes #4187 canary bug with CDATA wrapper on Markdown files
  • Fixes #4191 error with Eleventy layout resolution without file extensions (when key conflicted with a directory name in the includes or layouts folders)
  • Fixes #1645 issue with JavaScript 11ty.js templates that assign data or render callbacks using [Public cl...

[View full release notes]

Released by zachleat on 12/11/2025

ionic-team/capacitor-keyboard (@capacitor/keyboard)

8.0.2 -> 8.0.3

v8.0.3

Compare Source

8.0.3 (2026-04-10)

Bug Fixes

  • android: fixing Keyboard interaction with SystemBars (#62) (4afd89b)

This release is also available on:

Released by capacitor-bot on 4/10/2026

cwcss/crosswind (@cwcss/crosswind)

0.2.0 -> 0.2.4

v0.2.4

Compare Source

Compare changes

🚀 Features

  • rules: table display family, flow-root/list-item/contents, arbitrary accent/caret (f31d55c)

🧹 Chores

Contributors

Released by github-actions[bot] on 5/1/2026

v0.2.3

Compare Source

Compare changes

🧹 Chores

Contributors

Released by github-actions[bot] on 5/1/2026

v0.2.2

Compare Source

Compare changes

🐛 Bug Fixes

  • build: emit dist/index.js + dist/cli.js to match exports/bin paths (1544b47)

🧹 Chores

Contributors

Released by github-actions[bot] on 5/1/2026

iconify/icon-sets (@iconify/json)

2.2.463 -> 2.2.484

Compare Source

Hundreds of open source icon sets in IconifyJSON format

📖 View Release Notes

🔗 View Changelog

Release Notes

Changelog

stacksjs/clapp (@stacksjs/clapp)

0.2.0 -> 0.2.10

v0.2.10

Compare Source

Released by github-actions[bot] on 5/14/2026

v0.2.9

Compare Source

Released by github-actions[bot] on 5/11/2026

v0.2.8

Compare Source

Released by github-actions[bot] on 5/6/2026


Note: This PR body was truncated due to GitHub's character limit. View the full details in the individual commits.

This PR was generated by Buddy 🤖

@netlify

netlify Bot commented Apr 5, 2026

Copy link
Copy Markdown

👷 Deploy Preview for stacks-stx processing.

Name Link
🔨 Latest commit 0d5318a
🔍 Latest deploy log https://app.netlify.com/projects/stacks-stx/deploys/6a287fa4b9202e0008ba2513

@github-actions github-actions Bot force-pushed the buddy-bot/update-non-major-updates branch 26 times, most recently from 46150f7 to d7bfe98 Compare April 7, 2026 10:37
@github-actions github-actions Bot force-pushed the buddy-bot/update-non-major-updates branch 28 times, most recently from ec87c1c to cf05f1a Compare April 10, 2026 20:26
@glennmichael123 glennmichael123 mentioned this pull request May 20, 2026
7 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants