Skip to content

chore(deps): bump the npm group across 1 directory with 25 updates - #34

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/npm-4fee8b18ba
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/npm-4fee8b18ba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 25 updates in the /frontend directory:

Package From To
@capacitor/android 8.5.1 8.5.2
@capacitor/cli 8.5.1 8.5.2
@capacitor/core 8.5.1 8.5.2
@capacitor/ios 8.5.1 8.5.2
@capgo/capacitor-updater 8.51.15 8.51.16
@noble/curves 1.9.7 2.4.0
@noble/hashes 2.0.1 2.4.0
@scure/bip39 1.6.0 2.4.0
mediabunny 1.55.7 1.56.2
react 19.2.8 19.3.0
@types/react 19.2.18 19.3.0
react-dom 19.2.8 19.3.0
@types/react-dom 19.2.7 19.3.0
@eslint/js 9.39.1 10.0.1
@testing-library/jest-dom 6.9.1 7.0.1
@types/node 24.10.1 26.5.1
@types/react 19.2.18 19.3.0
@types/react-dom 19.2.7 19.3.0
@vitejs/plugin-react 5.1.1 6.1.1
eslint 9.39.1 10.10.0
eslint-plugin-react-hooks 7.0.1 7.1.1
eslint-plugin-react-refresh 0.4.24 0.5.6
globals 16.5.0 17.12.0
jsdom 27.3.0 30.0.1
typescript 5.9.3 7.0.2
vite 7.3.6 8.3.0
vitest 4.1.10 5.0.0

Updates @capacitor/android from 8.5.1 to 8.5.2

Release notes

Sourced from @​capacitor/android's releases.

8.5.2

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Changelog

Sourced from @​capacitor/android's changelog.

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Commits
  • 5e0f678 Release 8.5.2
  • e37d9c6 fix: resolve issues with safe area / systembars plugin (#8535)
  • 035b16a fix(android): add null checks for plugin annotation when retrieving permissio...
  • c567328 fix(ios): do not forward scene lifecycle events to the page before it has loa...
  • See full diff in compare view

Updates @capacitor/cli from 8.5.1 to 8.5.2

Release notes

Sourced from @​capacitor/cli's releases.

8.5.2

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Changelog

Sourced from @​capacitor/cli's changelog.

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Commits
  • 5e0f678 Release 8.5.2
  • e37d9c6 fix: resolve issues with safe area / systembars plugin (#8535)
  • 035b16a fix(android): add null checks for plugin annotation when retrieving permissio...
  • c567328 fix(ios): do not forward scene lifecycle events to the page before it has loa...
  • See full diff in compare view

Updates @capacitor/core from 8.5.1 to 8.5.2

Release notes

Sourced from @​capacitor/core's releases.

8.5.2

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Changelog

Sourced from @​capacitor/core's changelog.

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Commits
  • 5e0f678 Release 8.5.2
  • e37d9c6 fix: resolve issues with safe area / systembars plugin (#8535)
  • 035b16a fix(android): add null checks for plugin annotation when retrieving permissio...
  • c567328 fix(ios): do not forward scene lifecycle events to the page before it has loa...
  • See full diff in compare view

Updates @capacitor/ios from 8.5.1 to 8.5.2

Release notes

Sourced from @​capacitor/ios's releases.

8.5.2

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Changelog

Sourced from @​capacitor/ios's changelog.

8.5.2 (2026-09-11)

Bug Fixes

  • android: add null checks for plugin annotation when retrieving permissions (#8400) (035b16a)
  • ios: do not forward scene lifecycle events to the page before it has loaded (#8595) (c567328)
  • resolve issues with safe area / systembars plugin (#8535) (e37d9c6)
Commits
  • 5e0f678 Release 8.5.2
  • e37d9c6 fix: resolve issues with safe area / systembars plugin (#8535)
  • 035b16a fix(android): add null checks for plugin annotation when retrieving permissio...
  • c567328 fix(ios): do not forward scene lifecycle events to the page before it has loa...
  • See full diff in compare view

Updates @capgo/capacitor-updater from 8.51.15 to 8.51.16

Release notes

Sourced from @​capgo/capacitor-updater's releases.

8.51.16

🆕 Changelog

Changed

  • Improved signed-checksum recovery on iOS by using native RSA, making update integrity verification faster and more robust.

Removed

  • Removed the unused Guava dependency on Android, reducing package size and eliminating a potential dependency conflict.

Fixed

  • Fixed incomplete iOS update downloads stalling and never applying; downloads are now retried so updates finish correctly.
  • Fixed builtin files being decoded repeatedly for Brotli-compressed manifests on iOS, improving update performance and reliability.
  • Fixed Android background update delays being reset when the app returned to the foreground, so unexpired delays are preserved.
  • Fixed the updater starting a new download while cleanup from a previous update was still running; downloads now wait until cleanup completes.
  • Updated Android OkHttp handling so host apps can keep their own OkHttp 4.x version instead of being forced to a pinned version, avoiding dependency conflicts.

🔗 Full Changelog: Cap-go/capacitor-updater@8.51.15...8.51.16

Commits
  • ed8508c chore(release): 8.51.16
  • 1457af9 fix(ios): reuse decoded builtin files for Brotli manifests (#888)
  • 7cfc4ae chore(android): remove unused Guava dependency (#893)
  • 2d4ab4b ci: grant actions write and retry Maestro web asset uploads (#895)
  • 89b519f chore(deps): update dependency @​types/node to v26 (#899)
  • 79c2ee0 fix(deps): update dependency org.robolectric:robolectric to v4.17 (#898)
  • aa2ef07 fix(android): unpin OkHttp so host apps keep their 4.x version
  • 86a9b83 perf(ios): use native RSA for signed checksum recovery (#887)
  • bec22c3 chore(deps): update actions/setup-node action to v7 (#884)
  • d160408 chore(deps): update actions/setup-java action to v6 (#883)
  • Additional commits viewable in compare view

Updates @noble/curves from 1.9.7 to 2.4.0

Release notes

Sourced from @​noble/curves's releases.

2.4.0

  • Harden FROST distributed key generation against round-one transcript substitution.
    • This is not a vulnerability; it's protection against those who don't follow the FROST spec. Spec wants user to preserve rounds.
  • FROST: Enforced RFC 9591 point validation for BLS and BN
  • POPRF: replace inversion with const-time version
  • Weierstrass: harden public-key boundaries & infinity handling
    • ECDH and ECDSA now reject the identity even for point types whose generic codec permits it
    • Curves that disallow infinity cannot encode it, while opted-in curves use the canonical SEC 1 0x00 encoding.
  • DER: Bounded ECDSA signature and INTEGER sizes before bigint conversion, preventing malformed inputs from causing disproportionate parsing and allocation work
  • Snapshot all security-sensitive state (passed arguments) to ensure it can't be mutated

Special thanks to Red Team (Rob Hamilton, CalleBTC, Omer Talip) and 1Password's Off-by-1 Labs.

Full Changelog: paulmillr/noble-curves@2.3.0...2.4.0

2.3.0

Security & constant-timeness

  • Hardened constant-time execution from best-effort to actual guarantees: no measurable timing behavior on 200K samples. Scalar multiplication now uses secret-scalar blinding via CSPRNG, un-precomputed points now use a constant-time fixed-window multiply instead of variable-time fallbacks, and modular arithmetic helpers were hardened. New CT benchmarks track timing behavior.
  • General hardening across all modules
  • Fixes from the Trail of Bits review: recovered ECDSA signatures are now bound to their recovery id, non-canonical BLS signature encodings are rejected, Edwards <-> Montgomery conversion helpers were corrected, and FROST DKG round-2 retry handling was hardened.

X25519 hardening

It was possible to execute a remote timing attack on X25519, across many samples, and learn up to 4.036 bits of long-term private key. Other 247 bits were NOT affected.

The impact: mainly fingerprinting (recognition of key across deployments), NOT key recovery, NOT X25519 breakage. Maintainer was also not able to escalate to co-residency (SMT).

Reported and found by:

  • George Stergiopoulos, Department of Informatics, Athens University of Economics and Business, Greece (geostergiop@aueb.gr)
  • Constantinos Patsakis, Department of Informatics, University of Piraeus, 80 Karaoli & Dimitriou str., 18534 Piraeus, Greece (kpatsak@unipi.gr)

Performance

  • ECDSA/EdDSA verification up to +32%, Weierstrass ECDH up to +19%, x25519 getPublicKey 2.7×
  • BLS signatures 2x
  • Init time (first getPublicKey or sign) reduced ~2x for ed25519, p256, p384, p521
  • Also faster verification of recovered signatures, pairing tower / FFT / Pippenger optimizations, and joint-MSM paths in FROST and OPRF
  • getPublicKey / sign got slower because we've decreased window size (W=8 => W=6) and hardened CT execution (see above). Long-running apps that prefer 2.2.0-level speed can restore it with one line: secp256k1.Point.BASE.precompute(8) (likewise for other curves).

Misc

  • Smaller bundles: improved tree-shaking across modules
  • Better error messages and type checks
  • Upgrade noble-hashes to 2.3.0, with performance boost
  • Reduce on-disk size 1831kb → 1548kb (-282kb) by disabling source maps (they became less relevant).

Full Changelog: paulmillr/noble-curves@2.2.0...2.3.0

... (truncated)

Changelog

Sourced from @​noble/curves's changelog.

2.4.0 (2026-08-27)

  • Harden FROST distributed key generation against round-one transcript substitution.
    • This is not a vulnerability; it's protection against those who don't follow the FROST spec. Spec wants user to preserve rounds.
  • FROST: Enforced RFC 9591 point validation for BLS and BN
  • POPRF: replace inversion with const-time version
  • Weierstrass: harden public-key boundaries & infinity handling
    • ECDH and ECDSA now reject the identity even for point types whose generic codec permits it
    • Curves that disallow infinity cannot encode it, while opted-in curves use the canonical SEC 1 0x00 encoding.
  • DER: Bounded ECDSA signature and INTEGER sizes before bigint conversion, preventing malformed inputs from causing disproportionate parsing and allocation work
  • Snapshot all security-sensitive state (passed arguments) to ensure it can't be mutated

Special thanks to Red Team (Rob Hamilton, CalleBTC, Omer Talip) and 1Password's Off-by-1 Labs.

2.3.0 (2026-08-06)

Security and constant-timeness

  • Hardened constant-time execution from best-effort to actual guarantees, with no measurable timing behavior across 200,000 samples. Scalar multiplication now uses secret-scalar blinding via CSPRNG, unprecomputed points use a constant-time fixed-window multiply instead of variable-time fallbacks, and modular arithmetic helpers were hardened. New constant-time benchmarks track timing behavior.
  • General hardening across all modules.
  • Applied fixes from the Trail of Bits review: recovered ECDSA signatures are now bound to their recovery ID, non-canonical BLS signature encodings are rejected, Edwards-to-Montgomery conversion helpers were corrected, and FROST DKG round-two retry handling was hardened.

X25519 hardening

It was possible to execute a remote timing attack on X25519 across many samples and learn up to 4.036 bits of a long-term private key. The other 247 bits were not affected.

The impact is primarily fingerprinting—a key can be recognized across deployments—not key recovery or a break of X25519. The maintainer was also unable to escalate the attack to co-residency (SMT).

Reported and found by:

  • George Stergiopoulos, Department of Informatics, Athens University of Economics and Business, Greece (geostergiop@aueb.gr).
  • Constantinos Patsakis, Department of Informatics, University of Piraeus, 80 Karaoli & Dimitriou Street, 18534 Piraeus, Greece (kpatsak@unipi.gr).

Performance

  • Improved ECDSA and EdDSA verification by up to 32%, Weierstrass ECDH by up to 19%, and X25519 getPublicKey by 2.7×.
  • Improved BLS signature performance by 2×.
  • Reduced initialization time for the first getPublicKey or sign call by approximately 2× for Ed25519, P-256, P-384, and P-521.
  • Also improved verification of recovered signatures, pairing tower, FFT, and Pippenger performance, as well as joint-MSM paths in FROST and OPRF.
  • getPublicKey and sign became slower because the window size was decreased from 8 to 6 and constant-time execution was hardened. Long-running applications that prefer 2.2.0-level speed can restore it with secp256k1.Point.BASE.precompute(8), and likewise for other curves.

Miscellaneous

  • Improved tree-shaking for smaller bundles.
  • Improved error messages and type checks.
  • Upgraded noble-hashes to 2.3.0 for improved performance.
  • Reduced on-disk size from 1,831 KB to 1,548 KB by disabling source maps, which have become less relevant.

2.2.0 (2026-04-12)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​noble/curves since your current version.


Updates @noble/hashes from 2.0.1 to 2.4.0

Release notes

Sourced from @​noble/hashes's releases.

2.4.0

Security and correctness

  • Protect passed options against mutation / pollution
  • keccakprg: fail until entropy is added
  • webcrypto: reject output sizes which crashed engine
  • blake3: fix tree merging for multi-terabyte streams
  • Improve zeroization

Misc

  • Speed-up Argon2 by 20%
  • Argon2 cost options are now optional. The defaults are t: 3, m: 1024 ** 2 KiB (1 GiB), p: 1, dkLen: 32, and a 1 GiB maxmem limit; larger-memory calls must set maxmem explicitly.
  • Corrected scrypt's default maxmem to work for N: 2 ** 20, r: 8, and p: 1
  • nextTick and asyncLoop now yield through scheduler.yield() when available or setTimeout otherwise, allowing timers, I/O, and rendering to progress. They also accept optional rejection cleanup; async Argon2, PBKDF2, and scrypt use it to wipe work state if scheduling is aborted.

Full Changelog: paulmillr/noble-hashes@2.3.0...2.4.0

2.3.0

Improve speed:

  • +10-45% 32b inputs across all hashes
  • +40% SHA-3 / SHAKE, +50% 1mb KT128 / KT256 / TurboSHAKE, +20% kmac
  • 2.2x argon
  • +20% pbkdf2 and hkdf

Other changes:

  • Better error messages and stricter type checks everywhere
  • Bugfix: HMAC _cloneInto now preserves canXOF (#134, ChALkeR); Argon2d typo rename (#135).
  • blake2.compress renamed to _compress (marked internal).
  • Reduce on-disk unpacked size 869kb → 665kb (-204kb) by disabling source maps (they became less relevant).

Full Changelog: paulmillr/noble-hashes@2.2.0...2.3.0

2.2.0

  • March 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
    • Fix: dkLen=0 handling in pbkdf2, blake2, turboshake, kt
    • Fix: parallelHash with blockLen=0
    • Fix: argon2 progress callback now reaches 100%
    • Improve: digestInto no longer returns a value (better performance)
    • Improve: argon2, blake2 support non-4-divisible dkLen
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • sha3: speed-up by up to 50%. Contributed by @​ChALkeR in paulmillr/noble-hashes#126
  • Fix compilation issues on TypeScript v6

... (truncated)

Changelog

Sourced from @​noble/hashes's changelog.

2.4.0 (2026-08-27)

Security and correctness

  • Protect passed options against mutation / pollution
  • keccakprg: fail until entropy is added
  • webcrypto: reject output sizes which crashed engine
  • blake3: fix tree merging for multi-terabyte streams
  • Improve zeroization

Misc

  • Speed-up Argon2 by 20%
  • Argon2 cost options are now optional. The defaults are t: 3, m: 1024 ** 2 KiB (1 GiB), p: 1, dkLen: 32, and a 1 GiB maxmem limit; larger-memory calls must set maxmem explicitly.
  • Corrected scrypt's default maxmem to work for N: 2 ** 20, r: 8, and p: 1
  • nextTick and asyncLoop now yield through scheduler.yield() when available or setTimeout otherwise, allowing timers, I/O, and rendering to progress. They also accept optional rejection cleanup; async Argon2, PBKDF2, and scrypt use it to wipe work state if scheduling is aborted.

2.3.0 (2026-08-06)

Performance

  • Improved 32-byte input performance across all hashes by 10–45%.
  • Improved SHA-3 and SHAKE by 40%, one-megabyte KangarooTwelve, MarsupilamiFourteen, and TurboSHAKE by 50%, and KMAC by 20%.
  • Improved Argon2 performance by 2.2×.
  • Improved PBKDF2 and HKDF performance by 20%.

Other changes

  • Added better error messages and stricter type checks throughout the package.
  • Fixed HMAC._cloneInto so it preserves canXOF in issue #134, reported by @​ChALkeR, and corrected an Argon2d typo in issue #135.
  • Renamed blake2.compress to the internal _compress method.
  • Reduced unpacked on-disk size from 869 KB to 665 KB by disabling less-relevant source maps.

2.2.0 (2026-04-11)

  • March 2026 self-audit (all files): no major issues found.
    • Audited for specification compliance and security.
    • Fixed dkLen=0 handling in pbkdf2, blake2, turboshake, and kt.
    • Fixed parallelHash with blockLen=0.
    • Made the argon2 progress callback reach 100%.
    • Changed digestInto to return no value for better performance.
    • Added support for non-four-divisible dkLen values in argon2 and blake2.
  • Fixed all byte-array types for compatibility with both TypeScript 5.6 and TypeScript 5.9+.
    • TypeScript 5.6 uses Uint8Array, while TypeScript 5.9+ made it generic as Uint8Array<ArrayBuffer>.
    • This previously caused incompatibilities and errors such as TS2345.
    • See [TypeScript issue #62240](microsoft/TypeScript#62240) for more context.
  • Sped up SHA-3 by as much as 50%, contributed by @​ChALkeR in [pull request #126](paulmillr/noble-hashes#126).
  • Fixed compilation issues on TypeScript 6.
  • Added big-endian support; all tests pass on s390x.
  • Improved tree-shaking and reduced bundle sizes.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​noble/hashes since your current version.


Updates @scure/bip39 from 1.6.0 to 2.4.0

Release notes

Sourced from @​scure/bip39's releases.

2.4.0

  • Hardening: Unpaired UTF-16 surrogates are now rejected in mnemonics & passphrases. Normal input is unaffected
  • Upgrade noble-hashes to 2.4.0
  • Improve tests

Full Changelog: paulmillr/scure-bip39@2.3.0...2.4.0

2.3.0

  • Rewrite package: the logic is now declared in scure-bip39 instead of @scure/base dependency, which was removed.
  • Upgrade noble-hashes to 2.3.0.

Full Changelog: paulmillr/scure-bip39@2.2.0...2.3.0

2.2.0

  • April 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • Fix compilation issues on TypeScript v6
  • Improve tree-shaking, reduce bundle sizes
  • Fix wordlists/traditional-chinese.js: it was exported incorrectly
  • Wordlists: add PURE annotations to improve tree-shaking
  • Wordlists: freeze the arrays to improve security

New Contributors

(We're skipping v2.1, to align with other noble / scure packages)

Full Changelog: paulmillr/scure-bip39@2.0.1...2.2.0

2.0.1

  • .js extension must be used for all modules
    • Old: @scure/bip39/wordlists/english
    • New: @scure/bip39/wordlists/english.js
    • This simplifies working in browsers natively without transpilers
    • This was planned for 2.0.0, but was accidentally left out
  • Improve typescript autocompletion for imported submodules
  • Upgrade noble-hashes to 2.0.1
  • Upgrade noble-curves to 2.0.1

Full Changelog: paulmillr/scure-bip39@2.0.0...2.0.1

2.0.0

  • The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
    • Node v20.19 is now the minimum required version

... (truncated)

Changelog

Sourced from @​scure/bip39's changelog.

2.4.0 (2026-08-28)

  • Hardening: Unpaired UTF-16 surrogates are now rejected in mnemonics & passphrases. Normal input is unaffected
  • Upgrade noble-hashes to 2.4.0
  • Improve tests

2.3.0 (2026-08-08)

  • Rewrite package: the logic is now declared in scure-bip39 instead of @scure/base dependency, which was removed.
  • Upgrade noble-hashes to 2.3.0.

2.2.0 (2026-04-21)

  • April 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • Fix compilation issues on TypeScript v6
  • Improve tree-shaking, reduce bundle sizes
  • Fix wordlists/traditional-chinese.js: it was exported incorrectly
  • Wordlists: add PURE annotations to improve tree-shaking
  • Wordlists: freeze the arrays to improve security

New Contributors

(We're skipping v2.1, to align with other noble / scure packages)

2.0.1 (2025-10-07)

  • .js extension must be used for all modules
    • Old: @scure/bip39/wordlists/english
    • New: @scure/bip39/wordlists/english.js
    • This simplifies working in browsers natively without transpilers
    • This was planned for 2.0.0, but was accidentally left out
  • Improve typescript autocompletion for imported submodules
  • Upgrade noble-hashes to 2.0.1
  • Upgrade noble-curves to 2.0.1

2.0.0 (2025-08-25)

  • The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
    • Node v20.19 is now the minimum required version
    • Package imports now work correctly in bundler-less environments, such as browsers
    • Reduces npm package size (traffic consumed): 92KB => 78KB
    • Reduces unpacked npm size (on-disk space): 384KB => 201KB

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​scure/bip39 since your current version.


Updates mediabunny from 1.55.7 to 1.56.2

Release notes

Sourced from mediabunny's releases.

v1.56.2

  • Fixed upmixing from stereo to quad or 5:1 resulting in NaN samples (#497)

v1.56.1

  • Repeated metadata keys for Vorbis-style metadata (Ogg, FLAC) are now surfaced as string[] in raw (#490)
  • Fixed FLAC muxer preferring raw.date over date for metadata
  • Fixed AVC software decoder dropping B-frames (#488)

v1.56.0

The theme of this release is negative timestamps and better copy conversions, a long-requested feature! For more, check out Copying media data.

  • Conversion API can now do copy conversions for arbitrary trim ranges, allowing you to trim media without transcoding it (#149)
  • Added ConversionOptions.copy for controlling copy-specific behavior, such as the tolerated timestamp shift that's allowed to make copy conversions work
  • Added support for muxing negative timestamps for ISOBMFF, Matroska, and MPEG-TS. In the case of ISOBMFF, this generates an edit list that trims off the negative section of the media.
  • MPEG-TS demuxer now infers negative timestamps and handles one modulus wrap of timestamps
  • Added OutputFormat.negativeTimestampSupport
  • Added handleUnhandledError to most source options to enable better handling of otherwise unhandled errors that are thrown out of band (#489)
  • Fixed Matroska getDurationFromMetadata() computation logic
  • Fixed empty audio trim range crashing conversions (#486)
  • Fixed Content-Length being used incorrectly when the server returns compressed content (#487)
Commits
  • f486094 Bump patch
  • 7065955 Merge pull request #497 from meiiie/fix/stereo-upmix-nan
  • cee57d1 Bump patch
  • f767b6f Fix AVC software decoder sometimes dropping B-frames (fixes #488)
  • 4b140fe Change FLAC test
  • b2b4087 Surface repeated keys are string[] for Vorbis-style metadata (fixes #490)
  • 533c857 Bump minor
  • 4f88d71 Add handleUnhandledError to most sources (closes #489)
  • 6e6785e Add more conversion tests for trimming wholly outside of the available media ...
  • 450c5de Fix incorrect use of Content-Length when the server compresses the content (f...
  • Additional commits viewable in compare view

Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

Bumps the npm group with 25 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [@capacitor/android](https://github.com/ionic-team/capacitor) | `8.5.1` | `8.5.2` |
| [@capacitor/cli](https://github.com/ionic-team/capacitor) | `8.5.1` | `8.5.2` |
| [@capacitor/core](https://github.com/ionic-team/capacitor) | `8.5.1` | `8.5.2` |
| [@capacitor/ios](https://github.com/ionic-team/capacitor) | `8.5.1` | `8.5.2` |
| [@capgo/capacitor-updater](https://github.com/Cap-go/capacitor-updater) | `8.51.15` | `8.51.16` |
| [@noble/curves](https://github.com/paulmillr/noble-curves) | `1.9.7` | `2.4.0` |
| [@noble/hashes](https://github.com/paulmillr/noble-hashes) | `2.0.1` | `2.4.0` |
| [@scure/bip39](https://github.com/paulmillr/scure-bip39) | `1.6.0` | `2.4.0` |
| [mediabunny](https://github.com/Vanilagy/mediabunny) | `1.55.7` | `1.56.2` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.18` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.7` | `19.3.0` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js) | `9.39.1` | `10.0.1` |
| [@testing-library/jest-dom](https://github.com/testing-library/jest-dom) | `6.9.1` | `7.0.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.10.1` | `26.5.1` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.18` | `19.3.0` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.7` | `19.3.0` |
| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `5.1.1` | `6.1.1` |
| [eslint](https://github.com/eslint/eslint) | `9.39.1` | `10.10.0` |
| [eslint-plugin-react-hooks](https://github.com/facebook/react/tree/HEAD/packages/eslint-plugin-react-hooks) | `7.0.1` | `7.1.1` |
| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.4.24` | `0.5.6` |
| [globals](https://github.com/sindresorhus/globals) | `16.5.0` | `17.12.0` |
| [jsdom](https://github.com/jsdom/jsdom) | `27.3.0` | `30.0.1` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.6` | `8.3.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `5.0.0` |



Updates `@capacitor/android` from 8.5.1 to 8.5.2
- [Release notes](https://github.com/ionic-team/capacitor/releases)
- [Changelog](https://github.com/ionic-team/capacitor/blob/main/CHANGELOG.md)
- [Commits](ionic-team/capacitor@8.5.1...8.5.2)

Updates `@capacitor/cli` from 8.5.1 to 8.5.2
- [Release notes](https://github.com/ionic-team/capacitor/releases)
- [Changelog](https://github.com/ionic-team/capacitor/blob/main/CHANGELOG.md)
- [Commits](ionic-team/capacitor@8.5.1...8.5.2)

Updates `@capacitor/core` from 8.5.1 to 8.5.2
- [Release notes](https://github.com/ionic-team/capacitor/releases)
- [Changelog](https://github.com/ionic-team/capacitor/blob/main/CHANGELOG.md)
- [Commits](ionic-team/capacitor@8.5.1...8.5.2)

Updates `@capacitor/ios` from 8.5.1 to 8.5.2
- [Release notes](https://github.com/ionic-team/capacitor/releases)
- [Changelog](https://github.com/ionic-team/capacitor/blob/main/CHANGELOG.md)
- [Commits](ionic-team/capacitor@8.5.1...8.5.2)

Updates `@capgo/capacitor-updater` from 8.51.15 to 8.51.16
- [Release notes](https://github.com/Cap-go/capacitor-updater/releases)
- [Changelog](https://github.com/Cap-go/capacitor-updater/blob/main/CHANGELOG.md)
- [Commits](Cap-go/capacitor-updater@8.51.15...8.51.16)

Updates `@noble/curves` from 1.9.7 to 2.4.0
- [Release notes](https://github.com/paulmillr/noble-curves/releases)
- [Changelog](https://github.com/paulmillr/noble-curves/blob/main/CHANGELOG.md)
- [Commits](paulmillr/noble-curves@1.9.7...2.4.0)

Updates `@noble/hashes` from 2.0.1 to 2.4.0
- [Release notes](https://github.com/paulmillr/noble-hashes/releases)
- [Changelog](https://github.com/paulmillr/noble-hashes/blob/main/CHANGELOG.md)
- [Commits](paulmillr/noble-hashes@2.0.1...2.4.0)

Updates `@scure/bip39` from 1.6.0 to 2.4.0
- [Release notes](https://github.com/paulmillr/scure-bip39/releases)
- [Changelog](https://github.com/paulmillr/scure-bip39/blob/main/CHANGELOG.md)
- [Commits](paulmillr/scure-bip39@1.6.0...2.4.0)

Updates `mediabunny` from 1.55.7 to 1.56.2
- [Release notes](https://github.com/Vanilagy/mediabunny/releases)
- [Commits](Vanilagy/mediabunny@v1.55.7...v1.56.2)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `@types/react` from 19.2.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@types/react-dom` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `@eslint/js` from 9.39.1 to 10.0.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/commits/v10.0.1/packages/js)

Updates `@testing-library/jest-dom` from 6.9.1 to 7.0.1
- [Release notes](https://github.com/testing-library/jest-dom/releases)
- [Changelog](https://github.com/testing-library/jest-dom/blob/main/CHANGELOG.md)
- [Commits](testing-library/jest-dom@v6.9.1...v7.0.1)

Updates `@types/node` from 24.10.1 to 26.5.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/react` from 19.2.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@types/react-dom` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `@vitejs/plugin-react` from 5.1.1 to 6.1.1
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react)

Updates `eslint` from 9.39.1 to 10.10.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v9.39.1...v10.10.0)

Updates `eslint-plugin-react-hooks` from 7.0.1 to 7.1.1
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/react/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/eslint-plugin-react-hooks@7.1.1/packages/eslint-plugin-react-hooks)

Updates `eslint-plugin-react-refresh` from 0.4.24 to 0.5.6
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.4.24...v0.5.6)

Updates `globals` from 16.5.0 to 17.12.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v16.5.0...v17.12.0)

Updates `jsdom` from 27.3.0 to 30.0.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v27.3.0...v30.0.1)

Updates `typescript` from 5.9.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

Updates `vite` from 7.3.6 to 8.3.0
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite)

Updates `vitest` from 4.1.10 to 5.0.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest)

---
updated-dependencies:
- dependency-name: "@capacitor/android"
  dependency-version: 8.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@capacitor/cli"
  dependency-version: 8.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@capacitor/core"
  dependency-version: 8.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@capacitor/ios"
  dependency-version: 8.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@capgo/capacitor-updater"
  dependency-version: 8.51.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@noble/curves"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: "@noble/hashes"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@scure/bip39"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: mediabunny
  dependency-version: 1.56.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@eslint/js"
  dependency-version: 10.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: "@testing-library/jest-dom"
  dependency-version: 7.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: "@types/node"
  dependency-version: 26.5.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: eslint
  dependency-version: 10.10.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: eslint-plugin-react-hooks
  dependency-version: 7.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: eslint-plugin-react-refresh
  dependency-version: 0.5.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: globals
  dependency-version: 17.12.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: jsdom
  dependency-version: 30.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: vite
  dependency-version: 8.3.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 17, 2026

Copy link
Copy Markdown
Owner

Closing this one; routine version updates are turned off in this repository (.github/dependabot.yml sets open-pull-requests-limit: 0, keeping security updates only), and this grouped PR predates that setting.

Checked on its own terms against current main (1907294), it could not merge anyway:

  • npm ci fails with ERESOLVE. It moves TypeScript ~5.9.3 → ~7.0.2, and typescript-eslint@8.70.0 requires typescript <6.1.0.
  • It bundles about a dozen major-version jumps: ESLint 9→10, Vite 7→8, Vitest 4→5, jsdom 27→30, @vitejs/plugin-react 5→6, @testing-library/jest-dom 6→7, @types/node 24→26.
  • Two of those majors are cryptography libraries: @noble/curves 1→2 (end-to-end encryption) and @scure/bip39 1→2 (recovery codes). A major bump of either belongs in its own change, verified against the known-answer tests, not in a 25-package group.

The npm-advisory gate is green on main, so no security fix is waiting here. Routine updates should be done later as the deliberate batch that dependabot.yml describes.


Generated by Claude Code

@Fossferous Fossferous closed this Sep 24, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 24, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/npm-4fee8b18ba branch September 24, 2026 22:28
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant