chore(deps): update all non-major dependencies - #818
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 4, 2026 19:55
dc21d08 to
f8e6be6
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 4, 2026 23:19
f8e6be6 to
470909c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 5, 2026 03:22
470909c to
4146598
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 5, 2026 11:11
4146598 to
8c3dc0c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 6, 2026 02:52
8c3dc0c to
97e98b9
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 6, 2026 18:51
97e98b9 to
c29ffa7
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 6, 2026 22:59
c29ffa7 to
1d21386
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 7, 2026 03:54
1d21386 to
3b2d90c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 7, 2026 15:06
3b2d90c to
f78c58e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 8, 2026 09:58
f78c58e to
a321d93
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 9, 2026 03:54
a321d93 to
2bedcfa
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 9, 2026 13:03
2bedcfa to
80f573e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 10, 2026 00:52
80f573e to
b06fef5
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 12, 2026 23:00
9018197 to
9c82645
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 13, 2026 02:51
9c82645 to
66e7a53
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 13, 2026 14:52
66e7a53 to
39df8da
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 13, 2026 18:57
39df8da to
e5daf9e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 03:15
e5daf9e to
e662a8a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 20:37
e662a8a to
4a15a48
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 15, 2026 10:01
4a15a48 to
0c94640
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 15, 2026 22:46
0c94640 to
b13831c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 16, 2026 03:23
b13831c to
2e51188
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 16, 2026 17:49
2e51188 to
b9e46b4
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 17, 2026 04:45
b9e46b4 to
b111ced
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 17, 2026 21:51
b111ced to
11ad8e9
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 18, 2026 03:23
11ad8e9 to
ec50e6c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 18, 2026 22:43
ec50e6c to
c6e246b
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.12.1→^1.13.0^4.10.0→^4.10.1^4.13.2→^4.13.3^12.33.0→^12.34.0^5.20260819.1→^5.20261002.1^0.5.5→^0.5.8^0.17.4→^0.18.0^11→^11.1.3^1.20.1→^1.20.2^26.2.0→^26.6.4^1.38.2→^1.39.0^3.9.3→^3.9.11^3.36.0→^3.37.0^0.3.4→^0.4.1^30.0.1→^30.1.1^11.5.2→^11.5.3^7.5.0→^7.7.0^11.2.0→^11.3.0^0.4.38→^0.4.43^0.64.0→^0.71.0^1.79.0→^1.86.011.22.0→11.28.3^0.12.5→^0.12.80.10.1-20260818-142856-3b64b18→0.10.1-20260922-215730-10f5034^8.2.1→^8.3.2^4.124.0→^4.147.0bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
Azure/azure-sdk-for-js (@azure/app-configuration)
v1.13.0Compare Source
Bugs Fixed
?. #39670Other Changes
TokenCredential. Whenaudienceis not set, the client now infers it from the App Configuration endpoint. An explicitly configured audience continues to override the inferred value. #39775Azure/azure-sdk-for-js (@azure/cosmos)
v4.10.1Compare Source
Bugs Fixed
ORDER BYqueries that could hang indefinitely for zero results or stop early when an empty page still had a continuation token.Other Changes
Azure/azure-sdk-for-js (@azure/identity)
v4.13.3Compare Source
Azure/azure-sdk-for-js (@azure/storage-blob)
v12.34.0Compare Source
cloudflare/workerd (@cloudflare/workers-types)
v5.20261002.1Compare Source
v5.20261001.1Compare Source
v5.20260930.2Compare Source
v5.20260930.1Compare Source
v5.20260929.1Compare Source
v5.20260928.1Compare Source
v5.20260927.1Compare Source
v5.20260926.1Compare Source
v5.20260925.2Compare Source
v5.20260925.1Compare Source
v5.20260924.1Compare Source
v5.20260923.1Compare Source
v5.20260922.1Compare Source
v5.20260921.1Compare Source
v5.20260920.1Compare Source
v5.20260919.1Compare Source
v5.20260918.1Compare Source
v5.20260917.1Compare Source
v5.20260916.1Compare Source
v5.20260915.1Compare Source
v5.20260914.1Compare Source
v5.20260911.1Compare Source
v5.20260910.1Compare Source
v5.20260908.1Compare Source
v5.20260907.1Compare Source
v5.20260906.1Compare Source
v5.20260905.1Compare Source
v5.20260904.1Compare Source
v5.20260903.1Compare Source
v5.20260902.1Compare Source
v5.20260901.1Compare Source
v5.20260831.1Compare Source
v5.20260830.1Compare Source
v5.20260829.1Compare Source
v5.20260828.1Compare Source
v5.20260827.1Compare Source
v5.20260826.1Compare Source
v5.20260825.1Compare Source
v5.20260823.1Compare Source
v5.20260822.1Compare Source
v5.20260821.1Compare Source
v5.20260820.1Compare Source
electric-sql/pglite (@electric-sql/pglite)
v0.5.8Compare Source
Patch Changes
c771db3: Do not set process.exitCode at allv0.5.7Compare Source
Patch Changes
2f9cf75: Fix convert_tov0.5.6Compare Source
Patch Changes
69b7d87: Apply the second options argument when callingPGlite.create(undefined, options).6c14380: fixes for process.exitCodetursodatabase/libsql-client-ts (@libsql/client)
v0.18.0Compare Source
netlify/primitives (@netlify/blobs)
v11.1.3Compare Source
Bug Fixes
Dependencies
v11.1.2Compare Source
Dependencies
v11.1.1Compare Source
Bug Fixes
getStore(#788) (e8bddcc)v11.1.0Compare Source
Features
v11.0.3Compare Source
Bug Fixes
v11.0.2Compare Source
Dependencies
planetscale/database-js (@planetscale/database)
v1.20.2Compare Source
What's Changed
npm auditwarnings by @joshmgross in #205undiciby @joshmgross in #206jestby @joshmgross in #207New Contributors
Full Changelog: planetscale/database-js@v1.20.1...v1.20.2
upstash/redis-js (@upstash/redis)
v1.39.0Compare Source
Minor Changes
6801501: Add array commands:arset,armset,arget,armget,argetrange,arscan,argrep,ardel,ardelrange,arcount,arlen,arinsert,arring,arlastitems,arnext,arseek,aropandarinfo, available on the client, in pipelines and in transactions.3f6e286: Support search indexes over Redis streams:redis.search.createIndex({ dataType: "stream", stream: "events", schema })indexes every entry of the stream as a document keyed by its entry ID.describe()reportsdataType: "stream"with the stream key inprefixes.33658bc: Add vector index support:redis.vector.createIndex()/redis.vector.index()return aVectorIndexwithadd,get,query,delete,count,infoanddrop, backed by the newVECTOR.CREATE,VECTOR.ADD,VECTOR.GET,VECTOR.QUERY,VECTOR.DEL,VECTOR.COUNT,VECTOR.INFOandVECTOR.DROPcommands.v1.38.4Compare Source
Patch Changes
7ac8182: Fix read-your-writes sending a staleupstash-sync-tokenA read issued straight after a write travelled with the token from before that
write, so the server was under no obligation to serve the write and
readYourWritessilently did not hold.HttpClient.request()snapshotted the outgoing headers withmergeHeaders(this.headers, ...)and only afterwards wrote the freshest token intothis.headers, so the token learned from response N first shipped with requestN+2. The assignment now happens before the merge.
This regressed in 1.34.5. In 1.34.0–1.34.4 the request options held
headers: this.headersby reference, so the late write was still picked up beforefetch; 1.34.5 introduced per-request header merging, which turned that referenceinto a copy without moving the assignment.
v1.38.3Compare Source
Patch Changes
f020866: Send anUpstash-Telemetry-Retryheader with the retry count on retried requests so retry rates are visible in server-side telemetry777dc30: Trim telemetry header values before deduplicating so whitespace around existing values does not defeat the dedup checkvercel/vercel (@vercel/functions)
v3.9.5Patch Changes
282f1c0: Use the current invocation deadline when waiting for database pool idle timers.azure/azurite (azurite)
v3.37.0Compare Source
General:
@typescript-eslint/parserversion from 8.66.0 to 8.67.0; added an ESLint TypeScript parsing smoke test to validate the updated parser configuration.always-authsetting.picomatchpeer dependency.@azure/storage-blobdev dependency from 12.28.0 to 12.33.0.overridesentry to pin the transitiveserialize-javascriptdependency (viamocha) to 7.0.3, remediating GHSA-5c6j-r48x-rmvq.vscedev dependency with@vscode/vsce3.9.2, updating the VS Code packaging toolchain to resolvelinkify-it5.0.2 and remediate GHSA-v245-v573-v5vm / CVE-2026-59887.@typescript-eslint/parserdev dependency from 5.62.0 to 8.65.0, and aligned@typescript-eslint/eslint-pluginto 8.65.0 to match. Updated.eslintrc.jsfor v8 compatibility (no-extra-semiandno-unused-expressionsrules).@azure/storage-queuedev dependency from 12.27.0 to 12.31.0.applicationinsightsfrom 2.9.6 to 3.15.1 and updated telemetry SDK type usage for compatibility.expressfrom^4.16.4to^5.2.1, updated@types/expressfrom^4.16.0to^5.0.6, and added@types/mimeas an explicit dev dependency because it is no longer provided transitively by the Express type packages.cross-varwithcross-env-shellto remove the vulnerable Babel 6 dependency chain while preserving cross-platform npm package version expansion.@types/argsdev dependency from 5.0.3 to 5.0.4 (patch update).@types/mimedev dependency from1.3.5to4.0.0.@types/mimev4 is a stub package; removedmimefrom the explicittypeslist intsconfig.jsonto avoid a missing type-definition error.typescriptdev dependency from 5.9.3 to 7.0.2 for the main build, while keeping a TypeScript 6.0.3 install (pinned exactly, aliased as thetypescriptpackage) for@typescript-eslint, which only supports TypeScript>=4.8.4 <6.1.0. Updatedtsconfig.jsonto remove compiler options removed in TypeScript 7 (moduleResolution: "node",downlevelIteration) and to explicitly list all@typespackages (e.g. mocha, node) undertypes, since TypeScript 7 no longer auto-includes@types/*packages when the option is omitted.eslintdev dependency from 8.57.1 to 10.9.0 and migrated ESLint configuration from legacy.eslintrc.jsto the flat config format (eslint.config.js) required by ESLint v9+. Added@eslint/jsandglobalsas dev dependencies to support the flat config.applicationinsightsfrom 3.15.1 to 3.16.0 to address CVE-2026-54285.@types/vscodedev dependency from 1.103.0 to 1.134.0.tediousfrom 18.6.2 to 20.0.0.to-readable-streamdependency; replaced all usages with Node.js built-inReadable.from()for Node stream compatibility and added unit coverage for the readable body stream path.2026-06-06.2026-04-06and2026-02-06for Blob, Queue, and Table endpoints.multistreamfrom^2.1.1to^4.1.0and@types/multistreamfrom^2.1.2to^4.1.4. UpdatedFSExtentStore.readExtents()andMemoryExtentStore.readExtents()to callmultistreamwithnew(now a class in v4) and added unit test coverage for merging multiple extents into a single stream.rceditdev dependency from 4.0.1 to 5.0.2 (pinned exact version due to major bump) and updatedscripts/buildExe.jsto use rcedit's new named export since v5 is ESM-only and no longer exposes a default export.@types/mochadev dependency from^9.0.0to^10.0.10, and added a Mocha context typing smoke test.--skipApiVersionCheckvia theAZURITE_SKIP_API_VERSION_CHECK=trueenvironment variable across theazurite,azurite-blob,azurite-queue, andazurite-tablecommand-line entrypoints. Only the exact, case-sensitive valuetrueenables it.@types/nodedev dependency from^14.14.24to^26.1.2(resolved 14.18.63 to 26.1.2), and fixed the resulting type errors in the extent stores and binary tests. Added unit tests coveringFSExtentStore.appendExtent()andMemoryExtentStore.appendExtent()for the Buffer input path. Also fixedMemoryExtentStore.appendExtent()to convert stream chunks toBufferso extentcount/offsetare measured in bytes rather than characters for multi-byte string chunks.huskydev dependency entirely. It was never configured (the"husky": {}config was empty, no.husky/hooks directory existed, andpreparenever calledhusky).find-processdev dependency from^1.4.4to^2.1.1.tests/upgrade/, run vianpm run test:upgrade,test:upgrade:docker,test:upgrade:vsix) that installs the latest published Azurite (npm, Docker/MCR image, and VS Code Marketplace VSIX), seeds blob (block/append/page, txt/json/csv/xml/binary), queue, and table data, upgrades in place to the local build, and verifies byte-for-byte / value-for-value integrity across all three distribution channels. The VSIX suite additionally has a standalone lifecycle test that installs/activates/starts/stops the latest published Marketplace VSIX and the locally packaged VSIX. Added dev dependency@vscode/test-electronfor the VSIX tests, and a dedicated.github/workflows/UpgradeCompatibility.ymlCI workflow that runs on merge tomainand on demand.rimrafdependency with Node.js built-infs.rm()/fs.rmSync():rimrafAsyncnow wrapsfs.rmwith Windows retry handling, test cleanup retries and then tolerates transient errors, and theclean/clean:deepnpm scripts use a newscripts/clean.js. Removes the deprecatedrimraf→glob@7→inflightdependency.cross-envdev dependency from^7.0.3to^10.1.0. Cross-env 10 is ESM-only and moved its bin scripts fromsrc/bin/todist/bin/. Updatedtests/packageScripts.test.tsto resolve thecross-env-shellscript from cross-env's declaredbinmapping.lint-stageddev dependency from^15.0.1to^17.3.0. The.lintstagedrcconfiguration was still using the deprecatedlinters/ignoreformat removed inlint-stagedv10+, so it was migrated to the flat glob-to-command format and a.prettierignorefile was added (mirroring the previousignorepatterns fordist,swagger,generated,ChangeLog.md, andBreakingChanges.md) soprettiercontinues to skip those paths.@vscode/test-electrondev dependency from^2.4.1to^3.1.0.@types/nodedev dependency from26.1.2to26.2.0(declaredpackage.jsonrange remains^26.1.2).serialize-javascriptoverride from the exact7.0.3pin to^7.0.7(resolves to 7.1.0) to remediate GHSA-qj8w-gfj5-8c6v (CPU-exhaustion DoS, affects 5.0.0 - 7.0.4), bumpedmochadev dependency from12.0.0-rc.5to12.0.0-rc.6and deduped the transitiveserialize-javascript/iconv-litecopies.esbuilddev dependency from 0.28.1 to 0.28.2.@typescript-eslint/eslint-pluginand@typescript-eslint/parserdev dependencies from 8.66.0 to 8.67.0 (declaredpackage.jsonranges remain^8.65.0).mysql2from 3.23.2 to 3.23.3 for SQL metadata-store connection-pool fixes; added driver and pool coverage.globalsdev dependency from 17.9.0 to 17.11.0.@azure/identitydev dependency lockfile resolution from 4.13.1 to 4.13.2 (declaredpackage.jsonrange remains^4.2.1).mysql2version from 3.23.3 to 3.23.4 (declaredpackage.jsonrange remains^3.10.1; fixes leading-zero truncation in TIME fractional seconds and aligns callbackPool/PoolConnectiontypings with runtime behavior).Blob:
Content-Encoding: gzip(related to issue #646).=, and aligned missing, empty, or duplicate boundary error handling with Azure Storage.contentMD5formats.StageBlock,PutBlock,PutBlob,AppendBlock, andPutPage(x-ms-content-crc64).PutBlob,StageBlock,AppendBlock, andPutPage: unified MD5/CRC64 validation logic with accurateInvalidMd5/InvalidHeaderValue(malformed) andMd5Mismatch/Crc64Mismatch(mismatch) errors, matching real Azure semantics verified against live.PutBlockFromURL(Put Block From URL), which previously returned 501. The source is fetched over loopback so that SAS authentication,x-ms-source-range, and thex-ms-source-if-*conditions are enforced by the existing download path; unmet source conditions return 412SourceConditionNotMet. As withCopyBlobFromURL, only sources on the same Azurite instance are supported.x-ms-blob-content-md5precedence overContent-MD5forPutBlobtransit integrity verification, matching real Azure behavior.CopyBlobFromURLecho back the sourceContent-MD5when supplied viax-ms-source-content-md5, matching real Azure behavior.startFromquery parameter onList Blobs(service version2026-02-06), which begins a flat or hierarchical listing at the given blob name. Unlikemarker, which is exclusive,startFromis inclusive, and the two compose when paging a listing that began atstartFrom. Previously the parameter was accepted but ignored.Queue:
close()calls while server status isStarting.unjs/db0 (db0)
v0.4.1Compare Source
compare changes
🚀 Enhancements
importspecifier to connector dependencies (f3e2e93)🏡 Chore
❤️ Contributors
v0.4.0Compare Source
compare changes
🚀 Enhancements
neonfor serverless postgres (#191)🩹 Fixes
?placeholders outside string literals and comments (#248)📖 Documentation
sqlite3not being maintained (#220)📦 Build
🏡 Chore
❤️ Contributors
jsdom/jsdom (jsdom)
v30.1.1Compare Source
v30.1.0Compare Source
isaacs/node-lru-cache (lru-cache)
v11.5.3Compare Source
mongodb/node-mongodb-native (mongodb)
v7.7.0Compare Source
Features
Bug Fixes
v7.6.0Compare Source
Features
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.