fix(deps): update patch updates (patch)#1035
Closed
renovate[bot] wants to merge 1 commit into
Closed
Conversation
Contributor
|
Thank you for following the naming conventions! 🙏 |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
b31c75f to
212063c
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
212063c to
282afd4
Compare
prisis
added a commit
that referenced
this pull request
Jun 11, 2026
… patch roll-up) Consolidates the three open Renovate PRs directly to main (local merge + lockfile regen, audit clean, frozen install verified): - #1034 @commitlint/cli|config-conventional|core 21.0.1 -> 21.0.2 - #1036 secretlint / @secretlint/secretlint-rule-preset-recommend 13.0.0 -> 13.0.2 - #1035 patch roll-up: multi-semantic-release 4.4.4, semantic-release-pnpm 8.1.15, semantic-release-preset 13.4.16, lint-staged 17.0.7, eslint plugins, textlint types, publint 0.3.21, tsx, tinyglobby, caniuse-lite, tailwind-csstree, plus brace-expansion override >=5.0.6 and hono override >=4.12.24. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Member
|
Applied directly to main (consolidated local merge + lockfile regen, audit clean, frozen install verified). Closing as merged-by-hand. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.4.1→4.4.48.1.9→8.1.1513.4.10→13.4.16^0.18.2→^0.18.34.7.1→4.7.25.7.3→5.7.102.0.0→2.0.18.0.1→8.0.215.6.0→15.6.115.6.0→15.6.11.6.16→1.6.19>=5.0.5→>=5.0.6](https://renovatebot.com/diffs/npm/brace-expansion@>=4.0.0 <5.0.5/5.0.5/5.0.6)1.0.30001792→1.0.30001797>=4.12.18→>=4.12.24>=4.12.21→>=4.12.2417.0.5→17.0.70.0.70→0.0.750.3.19→0.3.210.3.1→0.3.26.2.1→6.2.30.2.16→0.2.17^4.21.0→^4.21.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
anolilab/semantic-release (@anolilab/multi-semantic-release)
v4.4.4Compare Source
Miscellaneous Chores
Dependencies
v4.4.3Compare Source
Dependencies
v4.4.2Compare Source
Miscellaneous Chores
Code Refactoring
Dependencies
anolilab/semantic-release (@anolilab/semantic-release-pnpm)
v8.1.15Compare Source
Bug Fixes
Miscellaneous Chores
Dependencies
v8.1.14Compare Source
v8.1.13Compare Source
v8.1.12Compare Source
v8.1.11Compare Source
v8.1.10Compare Source
Miscellaneous Chores
anolilab/semantic-release (@anolilab/semantic-release-preset)
v13.4.16Compare Source
Dependencies
v13.4.15Compare Source
Dependencies
v13.4.14Compare Source
Dependencies
v13.4.13Compare Source
Dependencies
v13.4.12Compare Source
Dependencies
v13.4.11Compare Source
Dependencies
arethetypeswrong/arethetypeswrong.github.io (@arethetypeswrong/cli)
v0.18.3Patch Changes
14e61d5: Update @types/node, use @typescript/native-preview for local build/check14e61d5]25031aa]eslint-community/eslint-plugin-eslint-comments (@eslint-community/eslint-plugin-eslint-comments)
v4.7.2Compare Source
Bug Fixes
modern-monacoversion to 0.4.0 (#320) (62a2c3a)modern-monacoinstead ofmonaco-editor(#311) (42919d0)Rel1cx/eslint-react (@eslint-react/eslint-plugin)
v5.7.10🐞 Fixes
react-x/no-leaked-conditional-rendering,react-x/set-state-in-effect: Added cycle detection to prevent stack overflow in recursive function analysis (#1769).📝 Documentation
third-party-plugins.mdxdocumentation page.react-x/globalsrule.🏗️ Internal
react-x/error-boundaries: SimplifiedgetEnclosingTryBlockimplementation.minimumReleaseAgeandminimumReleaseAgeExcludeentries topnpm-workspace.yaml.fumadocs-coreandfumadocs-uito 16.8.11.facebook/reactas git subtree under.repos" in v5.7.9 (re-released as v5.7.10, closes #1772).Full Changelog: Rel1cx/eslint-react@v5.7.8...v5.7.10
v5.7.8Compare Source
🐞 Fixes
react-x/no-missing-key: Fixed the rule not detectingConditionalExpression/LogicalExpressionreturned from block-bodied.map/Array.fromcallbacks. The rule now reports both branches when both lack akey, instead of only the first (#1767, #1766).📝 Documentation
[NEEDS VERIFICATION]markers to spec diffs for React Compiler aligned rules.Hintcomponent to the website and used it on the home page.🏗️ Internal
@effect/language-serviceto 0.86.0.dompurifyto 3.4.3.fumadocs-mdxto 15.0.4 and related dependencies.pnpmfrom 11.1.0 to 11.1.1.experimental.useFlatConfigfrom Zed settings.dprint.json.v5.7.7Compare Source
🐞 Fixes
eslint-plugin-react-jsxandeslint-plugin-react-rscto include thejsx-/rsc-prefixes so editorOpen documentationlinks resolve correctly (#1757) — by @kasmacioma.🏗️ Internal
@types/nodefrom 25.6.2 to 25.7.0.pnpmfrom 11.0.9 to 11.1.0.mermaidfrom 11.14.0 to 11.15.0 and pinned it viapnpm-workspace.yamloverrides, dropping the transitivechevrotain@12.0.0chain in favor of@chevrotain/types@11.1.2.trustPolicy: "no-downgrade"inpnpm-workspace.yaml.v5.7.6Compare Source
📝 Documentation
Versionsaccordion sourced from per-ruleCHANGELOG.md.mikotoproject to the community showcase.@eslint-react/core.🏗️ Internal
@typescript-eslintpackages from 8.59.2 to 8.59.3.fumadocs-coreandfumadocs-uifrom 16.8.7 to 16.8.10.fumadocs-mdxfrom 14.3.2 to 15.0.3.tailwindcssand@tailwindcss/postcssfrom 4.2.4 to 4.3.0.tailwind-mergefrom 3.5.0 to 3.6.0.vitestfrom 4.1.5 to 4.1.6.ansisfrom 4.2.0 to 4.3.0.semverfrom 7.7.4 to 7.8.0.pnpmfrom 11.0.8 to 11.0.9.nxfrom a 23.0.0 canary back to 22.7.1 stable.verify:rule-docsscript toverify:docs.assets/logo.htmlandassets/react-icon.html(#1755, #1756).Full Changelog: Rel1cx/eslint-react@v5.7.5...v5.7.6
v5.7.5Compare Source
🏗️ Internal
@eslint/compatfrom 2.0.5 to 2.1.0.@types/nodefrom 25.6.0 to 25.6.2.nextfrom 16.2.5 to 16.2.6.publintfrom 0.3.19 to 0.3.20.tsdownfrom 0.21.10 to 0.22.0.pnpmfrom 10.33.4 to 11.0.8.Full Changelog: Rel1cx/eslint-react@v5.7.4...v5.7.5
v5.7.4Compare Source
🏗️ Internal
@typescript-eslintpackages from 8.59.1 to 8.59.2.reactandreact-domfrom 19.2.5 to 19.2.6.nextfrom 16.2.4 to 16.2.5.nxfrom 22.7.1 to 23.0.0-canary.20260506-b594537.fumadocs-coreandfumadocs-uifrom 16.8.5 to 16.8.7.postcssfrom 8.5.13 to 8.5.14.publintfrom 0.3.18 to 0.3.19.pnpmfrom 10.33.2 to 10.33.4.Full Changelog: Rel1cx/eslint-react@v5.7.3...v5.7.4
eslint/config-inspector (@eslint/config-inspector)
v2.0.1Compare Source
Bug Fixes
baseURLin cli (#235) (2eec296)eslint/markdown (@eslint/markdown)
v8.0.2Compare Source
Bug Fixes
InlineConfigCommentnode to be reported (#652) (65aaadf)getParent(#637) (2573a54)textlint/textlint (@textlint/ast-node-types)
v15.6.1Compare Source
What's Changed
CI
Dependency Updates
Other Changes
New Contributors
Full Changelog: textlint/textlint@v15.6.0...v15.6.1
vitest-dev/eslint-plugin-vitest (@vitest/eslint-plugin)
v1.6.19Compare Source
No significant changes
View changes on GitHub
v1.6.18Compare Source
🐞 Bug Fixes
requiresTypeCheckingmetadata for four rules - by @inglec-arista in #905 (e06a3)View changes on GitHub
v1.6.17Compare Source
🐞 Bug Fixes
toBeTypeOfinstead ofexpectTypeOfinprefer-expect-type-of- by @sheremet-va in #896 (a4bcd)View changes on GitHub
juliangruber/brace-expansion (brace-expansion@>=4.0.0 <5.0.5)
v5.0.6Compare Source
browserslist/caniuse-lite (caniuse-lite)
v1.0.30001797Compare Source
v1.0.30001793Compare Source
honojs/hono (hono@<4.12.14)
v4.12.24Compare Source
v4.12.23Compare Source
What's Changed
COMPRESSIBLE_CONTENT_TYPE_REGEXre-export by @na-trium-144 in #4961::by @yusukebe in #4971Full Changelog: honojs/hono@v4.12.22...v4.12.23
v4.12.22Compare Source
What's Changed
New Contributors
Full Changelog: honojs/hono@v4.12.21...v4.12.22
v4.12.21Compare Source
Security fixes
This release includes fixes for the following security issues:
app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
Affects:
app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3IP Restriction bypasses static deny rules for non-canonical IPv6
Affects:
hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Affects:
hono/cookie. Fixes missing validation ofsameSiteandpriorityoptions against injection characters (;,\r,\n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5xJWT middleware accepts any Authorization scheme, not only Bearer
Affects:
hono/jwt,hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474Users who use
app.mount(),hono/ip-restriction,hono/cookie, orhono/jwt/hono/jwkare encouraged to upgrade to this version.v4.12.20Compare Source
What's Changed
New Contributors
Full Changelog: honojs/hono@v4.12.19...v4.12.20
v4.12.19Compare Source
What's Changed
bytes()by @yusukebe in #4921@hono/node-serverto v2 and fix abort handling by @yusukebe in #4940New Contributors
Full Changelog: honojs/hono@v4.12.18...v4.12.19
lint-staged/lint-staged (lint-staged)
v17.0.7Compare Source
Patch Changes
e692e58- Update dependencytinyexec@^1.2.4.v17.0.6Compare Source
Patch Changes
#1803
bdf2770- Run all tests with Deno, in addition to Node.js and Bun.#1796
7508272- Fix performance regression of lint-staged v17 by going back to usinggit addto stage task modifications. This was changed togit update-index --againin v17 for less manual work, but unfortunately theupdate-indexcommand gets slower in very large Git repos.#1797
7b2505a- This version of lint-staged uses the new staged publishing for npm packages feature. Releases are already published from GitHub Actions with trusted publishing, but now an additional approval with two-factor authentication is also required.#1802
321b0a9- Downgrade dependencytinyexec@1.2.2to avoid issues in version 1.2.3.stackblitz-labs/pkg.pr.new (pkg-pr-new)
v0.0.75Compare Source
v0.0.74Compare Source
v0.0.73Compare Source
v0.0.72Compare Source
v0.0.71Compare Source
publint/publint (publint)
v0.3.21Compare Source
Patch Changes
"sideEffects": falsewhen bundler-oriented package fields or conditions are detected and the field is missing. (#228)v0.3.20Compare Source
Patch Changes
Suggest adding
engines.nodewhen it is missing from detected Node.js packages (#226)Loosen "breaking change" wording in lint messages (
7bb3f4f)humanwhocodes/tailwind-csstree (tailwind-csstree)
v0.3.2Compare Source
Bug Fixes
[@theme](https://redirect.github.com/theme)inline/static preludes (#60) (31286c3)textlint-rule/textlint-rule-no-dead-link (textlint-rule-no-dead-link)
v6.2.3Compare Source
What's Changed
Bug Fixes
Full Changelog: textlint-rule/textlint-rule-no-dead-link@v6.2.2...v6.2.3
v6.2.2Compare Source
What's Changed
Bug Fixes
New Contributors
Full Changelog: textlint-rule/textlint-rule-no-dead-link@v6.2.1...v6.2.2
SuperchupuDev/tinyglobby (tinyglobby)
v0.2.17Compare Source
Changed
Fixed
undefinedis passed to any of the options by chloeelimFileSystemAdapteris now exported againprivatenumber/tsx (tsx)
v4.21.1Compare Source
Bug Fixes
This release is also available on:
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.