⬆️ deps: Update dependencies (non-major) - #57
Merged
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
zrr-website-root | 520ae0c | Commit Preview URL Branch Preview URL |
Aug 03 2026, 12:36 AM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9.9→0.9.107.2.1→7.2.27.0.3→7.0.56.0.1→6.0.26.0.1→6.0.21.27.0→1.28.019.2.17→19.2.1824.18.0→24.18.11.75.0→1.76.011.17.0→11.18.010.29.7→10.29.80.2.6→0.2.70.2.6→0.2.74.114.0→4.118.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
withastro/astro (@astrojs/check)
v0.9.10Compare Source
Patch Changes
b01a692Thanks @ocavue! - Update dependencyyargsto version 18. See the yargs changelog for details.withastro/astro (@astrojs/markdown-remark)
v7.2.2Compare Source
Patch Changes
c895b12]:withastro/astro (@astrojs/mdx)
v7.0.5Compare Source
Patch Changes
c895b12]:v7.0.4Compare Source
Patch Changes
41a00ddThanks @gtritchie! - Fixes a bug where the integration was emitting React-cased attribute names.withastro/astro (@astrojs/preact)
v6.0.2Compare Source
Patch Changes
c895b12]:withastro/astro (@astrojs/react)
v6.0.2Compare Source
Patch Changes
c895b12]:lucide-icons/lucide (@lucide/astro)
v1.28.0: Version 1.28.0Compare Source
What's Changed
Full Changelog: lucide-icons/lucide@1.27.0...1.28.0
nodejs/node (node)
v24.18.1: 2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbolCompare Source
This is a security release.
Notable Changes
Commits
6cb0475751] - deps: update llhttp to 9.4.3 (Paolo Insogna) nodejs-private/node-private#935bcfe21d3dc] - deps: update undici to 7.29.0 (Node.js GitHub Bot) #647139d0d36cffd] - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) nodejs-private/node-private#9298a008fb523] - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) nodejs-private/node-private#922a77c7f7354] - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) nodejs-private/node-private#92134ed88a069] - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) #6375295ba2cfde7] - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) nodejs-private/node-private#904fcbdbe47ea] - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) nodejs-private/node-private#930ea26c12b56] - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) nodejs-private/node-private#9119a6b7e343a] - (CVE-2026-58039) permission: check final report output path (RafaelGSS) nodejs-private/node-private#9266c0c990880] - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) nodejs-private/node-private#927af9ff0490c] - (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) nodejs-private/node-private#89605f541b5c0] - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) nodejs-private/node-private#931oxc-project/oxc (oxlint)
v1.76.0Compare Source
🚀 Features
8d31dfalinter: Verify eslint/no-restricted-globals config schema (#24598) (vigneshwar)7069621linter: Verify jest/vitest prefer-lowercase-title config schema (#24724) (Bartok)016cf2alinter/oxc: Add bad-match-all-arg rule (#24900) (camc314)cdc941elinter/n: Implementexports-stylerule (#24087) (Mikhail Baev)1ad6f6clinter/eslint: Implementid-denylistrule (#24632) (Mikhail Baev)📚 Documentation
3ff2e0elinter: Clarify config extends types (#24936) (Boshen)pnpm/pnpm (pnpm)
v11.18.0: pnpm 11.18Compare Source
Minor Changes
Fixed an installed optional dependency being left without one of its own required dependencies. When a package reached through
optionalDependenciesis installable on the current system but one of its regulardependenciesis not, a lockfile-based install skipped that dependency and installed the parent anyway, so importing the parent failed withMODULE_NOT_FOUND. The dependency is now installed, and an install-check warning reports the incompatibility. A dependency is still only skipped when every path to it is optional, or when the package that pulls it in was itself skipped #13286.pnpm setupnow appendsPNPM_HOMEand the global bin directory to the GitHub Actions environment files (GITHUB_ENVandGITHUB_PATH), so later steps in the same job can runpnpm add --globaland other global commands #9191.Added support for
publishConfig.name, which publishes a package under a different name than the one its manifest carries in the workspace. It is for a project whose published name is already taken by a sibling project, which otherwise has to be renamed by a build step just before publishing. Only the published artifact is renamed — dependents,pnpm-lock.yaml, and release tooling keep addressing the project by its manifest name — and the new name reaches the packed manifest, the tarball filename, and everything that addresses the package at the registry: the already-published check ofpnpm publish -r, its registry selection, and the release-planning probes ofpnpm change statusandpnpm version -r#13345.pnpm self-updateno longer takes any instruction from the project it is run in:.npmrcorpnpm-workspace.yamlcan no longer redirect the download or attach credentials to it, and the project's default.pnpmfile.(c|m)jsis no longer loaded. Pnpmfiles from trusted sources (thepnpmfilesetting, the global pnpmfile, config dependencies) still apply.minimumReleaseAgesettings inpnpm-workspace.yamlno longer affectself-update. They still govern the project's own dependencies; forself-updatethe cooldown now comes from the built-in default, your global config, aPNPM_CONFIG_*environment variable, or a command-line flag. This fixesself-updatefailing inside a workspace that raises the cutoff while succeeding everywhere else, and stops a repository from either waiving the cooldown or keeping you on an outdated pnpm by raising it.trustPolicysettings and toci: a project can no longer weaken the trust check that guards the pnpm download, nor re-enable the confirmation prompt that a CI run suppresses.When
self-updaterefuses a version that is younger than the cutoff, an interactive run now offers to update anyway; non-interactive runs still fail. CI never prompts, even on a runner that attaches a TTY.Patch Changes
Fixed
pnpm licenses listto report every version when the same package is installed under multiple aliases pnpm/pnpm#13438.Sort
pnpm dedupe --checksnapshot changes for stable output across pnpm implementations.Strip Unicode formatting characters from registry- and manifest-derived terminal output.
Speed up installs after compatible catalog or direct dependency range changes by retaining the locked version without resolving the dependency graph again.
Speed up installs after safe override changes by reusing unambiguous compatible dependency resolutions, pruning obsolete dependencies, applying independent replacements and removals together, and handling parent-scoped
"-"overrides without full lockfile resolution.Installing a local
file:directory dependency with the global virtual store enabled no longer fails withTypeError: Cannot read properties of undefined (reading 'split')#13335.Local directory dependencies —
file:directories and injected workspace packages — now get a global-virtual-store slot of their own per project. They used to share one slot across every project that depended on a directory of the same name, so a project could end up linked to another project's copy of the dependency.The
Workspacecolumn ofpnpm update --interactivenow falls back to the project's path when itsnameis only whitespace, as it already did for a missing or empty one — all three render an equally blank label otherwise.Checking GitHub Actions dependencies for updates is now opt-in for every command. Neither
pnpm outdatednorpnpm updatereads the workflow files unless--include-github-actionsis passed orupdate.githubActionsis set totrueinpnpm-workspace.yaml. Reading them runsgit ls-remoteagainst every referenced repository, which fails in environments where GitHub is not reachable the way pnpm assumes (a GitHub Enterprise Server, a custom certificate authority, or an offline network) #13254.pnpm outdatedaccepts the--include-github-actionsoption too.pnpm update --interactivenow measures its table in terminal columns rather than in characters. A package name, workspace name, or version containing wide characters (CJK, most emoji) no longer knocks its row's columns out of line with the rest of the group, and a wide character in a version no longer aborts the command withSubject parameter value width cannot be greater than the container width#13357.The
Workspacecolumn ofpnpm update --interactiveis more informative in two cases. A dependency outdated at the same version in several workspace projects is offered as one choice, since selecting it updates every project — that choice now names all of them instead of only the first. And a workspace project without anameis now labelled with its path rather than left blank, so several unnamed projects can be told apart.An auto-installed optional peer is no longer hoisted at a version the workspace root's own dependency on that package excludes.
resolvePeersFromWorkspaceRootalready made the workspace root's specifier decide which version a missing required peer is installed at; the optional-peer picker ignored it and always took the highest version present anywhere in the graph. In a workspace whose root pinspostcss: 8.5.10, an importer that depends onwebpackand declares nopostcssof its own gotpostcss@8.5.22hoisted forterser-webpack-plugin's optionalpostcsspeer, leaving twopostcss@8.5.xinstances in the graph #13320.overridesnow also govern peers that pnpm auto-installs. Previously an override only rewrote dependencies declared in a manifest, so a peer nobody declares — installed becauseautoInstallPeersis on — resolved against its declared peer range and could bring in a second copy of the very package the override pinned. For example, withoverrides: { react: npm:react@19.2.0 }and a lonelucide-reactdependency, pnpm installedreact@18.3.1; it now installs the pinnedreact@19.2.0#13320.Under
resolvePeersFromWorkspaceRoot, a workspace root dependency declared withlink:orfile:(or the path form ofworkspace:, such asworkspace:../pkg) now satisfies another project's missing peer dependency at the linked package's own version, instead of being hoisted as a path. Those specifiers are relative to the project that declares them, so the same specifier reached a different directory — or none — from the project the peer was hoisted into, leaving a broken link. The root now has the same authority over the peer as it has when it declares the package with a version range #13373.Installs through a pnpr server now apply the project's whole verification policy.
minimumReleaseAgeExclude,minimumReleaseAgeIgnoreMissingTime,trustPolicy,trustPolicyExclude,trustPolicyIgnoreAfter, andtrustLockfilewere ignored, so excluded packages were still held back and a lockfile containing them could be rejected.trustPolicy: no-downgradeno longer fails withTRUST_POLICY_INCOMPATIBLE_WITH_PNPRwhen a pnpr server is configured.--frozen-lockfileand--no-prefer-frozen-lockfileare now honored on the pnpr path, instead of resolving and rewriting the lockfile anyway. SincefrozenLockfiledefaults totrueon CI, a CI install through a pnpr server now fails on an out-of-date lockfile rather than updating it.Workspace installs through a pnpr server no longer crash with
Cannot read properties of undefined (reading 'filter')after linking, whenminimumReleaseAgeis active #13275.Fixed
pnpm dedupeupdating valid catalog resolutions when another matching version exists in the lockfile.pnpm -r run "/pattern/" --no-bailno longer exits zero when one of a project's matched scripts fails and a later one passes. The run summary carries a single status per project, and the passing script overwrote the recorded failure.Restored the store block a first install prints, naming how packages were materialized and where the stores live #13315:
The root project's
pnpm:devPreinstallscript now runs before resolution and linking, as it does in pnpm 11. It is skipped under--ignore-scripts,--lockfile-onlyand--dry-run, bypnpm fetchandpnpm rebuild, and by a repeat install that is already up to date. Workspaces that use the hook to prepare state the install depends on — such as next.js, which generates a placeholdernextbin with it — were left with dependents linked against files that were never created #13313.Prevented
pnpm dedupe --checkfrom removing an incompatiblenode_modulesdirectory.pnpm update --workspaceno longer links dependencies the user never named:updateConfig.ignoreDependenciesconfigured no longer fails withERR_PNPM_WORKSPACE_PACKAGE_NOT_FOUNDfor a dependency that is only published to the registry. Such dependencies keep their specifiers, as they already did when no dependencies were ignored.Platinum Sponsors
Gold Sponsors
preactjs/preact (preact)
v10.29.8Compare Source
Performance
voidzero-dev/vite-plus (vite)
v0.2.7: vite-plus v0.2.7: Clearer guidance for built-in commands and scriptsCompare Source
This release points users to
vpr <name>when a Vite+ built-in command and package script share a name, adds concurrency control tovp pack, and smooths migrations and package-manager setup.Highlights
vpr <name>when a Vite+ built-in command andpackage.jsonscript share a name (#2259, #2262, #2265, vite-task#570), by @wan9chi--concurrencytovp packto limit parallel Rolldown builds, and update tsdown0.22.13->0.22.14and Vite DevTools0.4.2->0.4.5(#2233), by @voidzero-guard[bot]no-undeferrors (#2192), by @naokihabaFixes & Enhancements
Docs
vpcommands versus package scripts throughvp runorvpr, including migration and agent guidance (#2255), by @wan9chisetup-vptemplate (#2258), by @naokihabaChore
main(#2223), by @Boshenjs/ts.*names (#2246), by @jong-kyungBundled Versions
8.1.55e7fe121.2.003e1e340.22.144.1.101.75.07.0.20010.60.0Upgrade
Full Changelog: voidzero-dev/vite-plus@v0.2.6...v0.2.7
Published Packages
@voidzero-dev/vite-plus-core@0.2.7vite-plus@0.2.7Installation
macOS/Linux:
curl -fsSL https://vite.plus | bashWindows:
Or download and run
vp-setup.exefrom the assets below.View the full commit:
c17e1c3Docker:
docker run --rm -it -v "$PWD:/app" -w /app ghcr.io/voidzero-dev/vite-plus:0.2.7 vp buildRun any
vpcommand without installing it; see the Docker guide for more.cloudflare/workers-sdk (wrangler)
v4.118.0Compare Source
Minor Changes
#14057
cc63aaeThanks @matingathani! - Add--jsonflag towrangler containers infofor consistent JSON output with sibling commandslistandinstances#14944
a249591Thanks @nickpatt! - Enable local observability capture by default in devwrangler devand the Vite plugin now capture request traces and console logs into the Local Explorer's Observability tab out of the box — previously this was opt-in behindX_LOCAL_OBSERVABILITY=true. SetX_LOCAL_OBSERVABILITY=falseto opt out (for example if the extra per-worker collector/streaming-tail services cause trouble in a multi-process dev-registry setup).#14919
e0bbf55Thanks @avenceslau! - Add additional triggers to WorkflowsWorkers can now declaratively start a locally defined Workflow. Configure event subscriptions under
triggers.events; Wrangler validates each target and updates the script's event triggers during deployment.{ "triggers": { "events": [ { "type": "cf.artifacts.repo.pushed", "filter": { "namespace": "my-namespace", "repo_name": "my-repo" }, "targets": [ { "type": "workflow", "workflow_name": "my-workflow" } ] } ] } }Patch Changes
#14936
f92d1fcThanks @petebacondarwin! - Fixjsx_fragmentbeing ignored whenwrangler devruns a custom buildIf your project uses a custom build and sets both
jsx_factoryandjsx_fragment,wrangler devused yourjsx_factoryvalue for JSX fragments as well, so fragments compiled incorrectly. Yourjsx_fragmentvalue is now used.#14936
f92d1fcThanks @petebacondarwin! - Stopwrangler devstarting new work after you stop it or it reloadsStopping
wrangler dev, or having it reload after a configuration change, could still leave it starting work for the state it had just left behind: your custom build command could run once more after dev had stopped, a change to a file in your assets directory could be reported against configuration that had already been replaced, and in some cases the process could stay alive instead of exiting.That work is now discarded, so stopping or reloading
wrangler devleaves nothing running behind it.#14936
f92d1fcThanks @petebacondarwin! - Stopwrangler devfrom running custom builds concurrentlyWhen several watched files changed at once — for example during a
git pullor a "save all" —wrangler devstarted a custom build for every file that changed, so multiple copies of your build command ran at the same time and fought over the same output files.A burst of file changes now results in a single build, and a build only starts once the previous one has finished.
#13746
cec9d88Thanks @edmundhung! - Report a clear error for account IDs that can't be used in a Cloudflare API requestAccount IDs are substituted straight into Cloudflare API URL paths, so a value containing non-ASCII characters previously failed deep inside the request layer with an opaque
Cannot convert argument to a ByteStringerror that gave no hint about which setting was at fault. Account IDs read fromCLOUDFLARE_ACCOUNT_IDand from theaccount_idconfiguration field are now validated up front, and an invalid value fails with a message naming both the offending value and where it came from.v4.117.0Compare Source
Minor Changes
#14586
5a56ddaThanks @emily-shen! - RemovecontainerEnginefrom the worker options returned byunstable_getMiniflareWorkerOptionsunstable_getMiniflareWorkerOptionsno longer includescontainerEnginein the returnedworkerOptions, since the container engine is a Miniflare instance-wide setting rather than a per-worker one. Callers that build a Miniflare instance from these options should setcontainerEngineat the top level instead.Patch Changes
#14586
5a56ddaThanks @emily-shen! - Rewrite local testing paths (/cdn-cgi/*)Miniflare v5 moved its internal local testing endpoints to
/cdn-cgi/local/*(and/__cf_local/*for endpoints that must remain reachable over tunnels) to prevent any potential collision with production routes.wrangler devand the Vite plugin now transparently rewrite the old paths to the new ones, meaning you can continue to use the old paths without issue.These are the new paths:
/cdn-cgi/handler/scheduled→/cdn-cgi/local/scheduled/cdn-cgi/handler/email→/cdn-cgi/local/email/cdn-cgi/explorer/*→/cdn-cgi/local/explorer/*/cdn-cgi/mf/scheduled→/cdn-cgi/local/scheduled(Note/cdn-cgi/mf/scheduledis already deprecated)/cdn-cgi/mf/stream/*→/__cf_local/stream/*/cdn-cgi/mf/imagedelivery/*→/__cf_local/imagedelivery/*Updated dependencies [
5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda]:v4.116.0Compare Source
Minor Changes
#14907
beec0fbThanks @NuroDev! - Avoid Worker and workers.dev naming prompts in agent-driven deploysWrangler now derives the Worker name from the project and automatically registers the same project-derived workers.dev account subdomain on a first deploy when running in a detected agent environment. The deploy output explains how to change both names.
#14905
b21eac2Thanks @jamesopstad! - The experimental build output directory now includes the Worker's configuration at.cloudflare/output/v0/workers/default/config.jsoninstead of.cloudflare/output/v0/workers/<worker-name>/worker.config.json#14893
bb09f1bThanks @apeacock1991! - Graduatewrangler check startupfrom alpha and show bundle size and a local timing summaryThe command no longer prints an alpha warning. It now reports its local profile window, sampled active, garbage collection, and idle time alongside the raw and compressed bundle sizes. The existing measurement warning continues to distinguish these local measurements from startup time measured on Cloudflare.
#14685
01d7020Thanks @edmundhung! - Add support for dispatching email handlers withcreateTestHarnessYou can now call
server.getWorker().email({ from, to, raw })to dispatch directly to a Worker'semail()handler and inspect its outcome, rejection reason, forwarded messages, and replies.Patch Changes
#14929
48f0c6cThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14838
8049ca4Thanks @TheSaiEaranti! - Fix ctrl+c not being able to interrupt wrangler while waiting for Cloudflare Access authorizationWhen a domain is behind Cloudflare Access (for example during remote bindings startup), wrangler runs
cloudflared access login, which only returns once the user completes the authorization flow in the browser. This was invoked synchronously, blocking Node's event loop, so wrangler could not react to ctrl+c (or anything else) until the authorization completed — abandoning the browser flow left a hung wrangler process that had to be killed externally.cloudflaredis now spawned asynchronously, keeping wrangler responsive while it waits. The remote runtime passes its abort signal through to the spawn, so tearing down the session kills a still-pendingcloudflaredimmediately, with process exit as a last-resort cleanup.#14871
1394867Thanks @nickpatt! - Include the local observability query endpoint in the agent-facing Local Explorer hintThe hint
wrangler devprints for AI-agent sessions now listsPOST /cdn-cgi/explorer/api/local/observability/query, so agents can discover the read-only SQL endpoint for captured request traces and console logs (thespansandlogstables) alongside the existing binding and storage routes.#14918
cc54478Thanks @nickpatt! - Improve the agent-facing Local Explorer hint for the observability query endpointWhen a
wrangler devsession is detected as running inside an AI agent, the hint forPOST /local/observability/querynow explains that the endpoint takes a read-only SQL query (SELECT/WITH only) over the capturedspansandlogstables, notes thatattributesis JSON (read viajson(attributes)), and includes a copy-pasteablecurlexample. The full OpenAPI schema is demoted to a last-resort footer so agents reach for the small, actionable example first instead of fetching the large schema.#14897
e31ab0fThanks @ericclemmons! - Fixwrangler triggers deployto use Vite-generated redirected configurationThe command now reads
.wrangler/deploy/config.json, matchingwrangler deployandwrangler versions upload, so generated Worker names and triggerConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.