Skip to content

chore(deps): lock file maintenance npm packages#6366

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/npm-packages
Sep 28, 2025
Merged

chore(deps): lock file maintenance npm packages#6366
renovate[bot] merged 1 commit intomainfrom
renovate/npm-packages

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 28, 2025

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
lockFileMaintenance All locks refreshed
@types/react (source) pnpm.catalog.default patch 19.1.13 -> 19.1.15 age adoption passing confidence
ansis pnpm.catalog.default minor =4.1.0 -> =4.2.0 age adoption passing confidence
rollup (source) pnpm.catalog.default patch 4.52.2 -> 4.52.3 age adoption passing confidence
tsx (source) pnpm.catalog.default patch 4.20.5 -> 4.20.6 age adoption passing confidence
vue (source) pnpm.catalog.default patch 3.5.21 -> 3.5.22 age adoption passing confidence
zx (source) pnpm.catalog.default patch 8.8.3 -> 8.8.4 age adoption passing confidence
knip (source) devDependencies patch 5.64.0 -> 5.64.1 age adoption passing confidence
lint-staged devDependencies patch 16.2.0 -> 16.2.3 age adoption passing confidence
oxlint (source) devDependencies minor 1.17.0 -> 1.18.0 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Release Notes

webdiscus/ansis (ansis)

v4.2.0

Compare Source

  • feat: add support named truecolor via ansis.extend().
    Foreground methods are created from the provided color names, and matching background methods bg* are generated automatically.
    Example:
    import ansis from 'ansis';
    import colorNames from 'css-color-names';
    
    const color = ansis.extend(colorNames);
    
    console.log(color.orange('Orange foreground'));
    console.log(color.bgOrange('Orange background')); // auto-generated from "orange"
    This release removes the last barrier for projects migrating from Chalk v4 that used named truecolor, e.g.
    chalk.keyword('orange')('text'). Ansis now provides this feature with a simpler, more intuitive API.
rollup/rollup (rollup)

v4.52.3

Compare Source

2025-09-27

Bug Fixes
  • Fix check in native loader for environments that do not support reports (#​6123)
Pull Requests
privatenumber/tsx (tsx)

v4.20.6

Compare Source

Bug Fixes
  • properly hide relaySignal from process.listeners() (#​741) (710a424)

This release is also available on:

vuejs/core (vue)

v3.5.22

Compare Source

Bug Fixes
Features
  • custom-element: allow specifying additional options for shadowRoot in custom elements (#​12965) (47e628d), closes #​12964
Reverts
  • Revert "fix(hmr): prevent VUE_HMR_RUNTIME from being overwritten by vue runtime in 3rd-party libraries" (#​13925) (6b68f72), closes #​13925
google/zx (zx)

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344 webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

webpro-nl/knip (knip)

v5.64.1

Compare Source

lint-staged/lint-staged (lint-staged)

v16.2.3

Compare Source

Patch Changes
  • #​1669 27cd541 Thanks @​iiroj! - When using --fail-on-changes, automatically hidden (partially) unstaged changes are no longer counted to make lint-staged fail.

v16.2.2

Compare Source

Patch Changes
  • #​1667 699f95d Thanks @​iiroj! - The backup stash will not be dropped when using --fail-on-changes and there are errors. When reverting to original state is disabled (via --no-revert or --fail-on-changes), hidden (partially) unstaged changes are still restored automatically so that it's easier to resolve the situation manually.

    Additionally, the example for using the backup stash manually now uses the correct backup hash, if available:

    % npx lint-staged --fail-on-changes
    ✔ Backed up original state in git stash (c18d55a3)
    ✔ Running tasks for staged files...
    ✖ Tasks modified files and --fail-on-changes was used!
    ↓ Cleaning up temporary files...
    
    ✖ lint-staged failed because `--fail-on-changes` was used.
    
    Any lost modifications can be restored from a git stash:
    
      > git stash list --format="%h %s"
      c18d55a3 On main: lint-staged automatic backup
      > git apply --index c18d55a3

v16.2.1

Compare Source

Patch Changes
  • #​1664 8277b3b Thanks @​iiroj! - The built-in TypeScript types have been updated to more closely match the implementation. Notably, the list of staged files supplied to task functions is readonly string[] and can't be mutated. Thanks @​outslept!

    export default {
    ---  "*": (files: string[]) => void console.log('staged files', files)
    +++  "*": (files: readonly string[]) => void console.log('staged files', files)
    }
  • #​1654 70b9af3 Thanks @​iiroj! - This version has been published from GitHub Actions using Trusted Publishing for npm packages.

  • #​1659 4996817 Thanks @​iiroj! - Fix searching configuration files when the working directory is a subdirectory of a git repository, and there are package.json files in the working directory. This situation might happen when running lint-staged for a single package in a monorepo.

  • #​1654 7021f0a Thanks @​iiroj! - Return the caret semver range (^) to direct dependencies so that future patch and minor versions are allowed. This enables projects to better maintain and deduplicate their own transitive dependencies while not requiring direct updates to lint-staged. This was changed in 16.2.0 after the vulnerability issues with chalk and debug, which were also removed in the same version.

    Given the recent vulnerabilities in the npm ecosystem, it's best to be very careful when updating dependencies.

oxc-project/oxc (oxlint)

v1.18.0: oxlint v1.18.0

Compare Source

[1.18.0] - 2025-09-24

This release should fix a critical memory leak when import plugin is enabled in IDEs.

🚀 Features
  • 2481964 linter/exhaustive-deps: Add support for useEffectEvent (#​14041) (Cody Olsen)
🐛 Bug Fixes
  • 444fcf0 linter: Fix false positive in vue/no-required-prop-with-default (#​14066) (yefan)
  • 2186b28 linter: Fix Arc memory leak and lifecycle issues (#​14049) (Boshen)
  • 314c27d linter/plugins: definePlugin apply defineRule to rules (#​14065) (overlookmotel)
  • 7bd01ed linter/plugins: defineRule call createOnce lazily (#​14062) (overlookmotel)
  • fb3e7e3 linter/plugins: defineRule accept visitor with no before / after hooks (#​14060) (overlookmotel)
🚜 Refactor
⚡ Performance
  • ce538c7 linter/plugins: Load methods of globals into local vars (#​14073) (overlookmotel)
  • c2f7459 language_server: Avoid cloning on message conversion (#​14058) (Sysix)
🧪 Testing
  • 2fd4b1e linter/plugins: Rename test (#​14064) (overlookmotel)
  • f2b3934 linter/plugins: Test returning false from before hook skips visitation in ESLint (#​14061) (overlookmotel)
  • b109419 linter/plugins: Align ESLint plugin with Oxlint (#​14059) (overlookmotel)

Configuration

📅 Schedule: Branch creation - "before 9am on monday" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) September 28, 2025 16:13
@graphite-app
Copy link
Contributor

graphite-app bot commented Sep 28, 2025

How to use the Graphite Merge Queue

Add the label graphite: merge to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

@socket-security
Copy link

socket-security bot commented Sep 28, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedansis@​4.1.0 ⏵ 4.2.01001005595 +2100
Updated@​types/​react@​19.1.13 ⏵ 19.1.151001007996 +2100
Addedis-even@​1.0.01001008579100
Addedis-odd@​0.1.21001008279100
Addedkind-of@​3.2.210010010080100
Addedis-number@​3.0.01001009881100
Updatedknip@​5.64.0 ⏵ 5.64.199 -110092 -895 -5100
Updatedrollup@​4.52.2 ⏵ 4.52.397 +110010099 +1100
Updatedoxlint@​1.17.0 ⏵ 1.18.0100100100100100
Updatedlint-staged@​16.2.0 ⏵ 16.2.3100 +1100100100 +6100

View full report

@netlify
Copy link

netlify bot commented Sep 28, 2025

Deploy Preview for rolldown-rs canceled.

Name Link
🔨 Latest commit 940db10
🔍 Latest deploy log https://app.netlify.com/projects/rolldown-rs/deploys/68d9a24575f3190008fae512

@renovate renovate bot force-pushed the renovate/npm-packages branch from 3a21b51 to eb819af Compare September 28, 2025 16:26
@renovate renovate bot force-pushed the renovate/npm-packages branch from eb819af to 940db10 Compare September 28, 2025 21:01
@renovate renovate bot merged commit 5fc213f into main Sep 28, 2025
60 of 63 checks passed
@renovate renovate bot deleted the renovate/npm-packages branch September 28, 2025 23:57
shulaoda added a commit that referenced this pull request Sep 30, 2025
## [1.0.0-beta.41] - 2025-09-29

### 🚀 Features

- support `output.generatedCode.symbols` (#6335) by @IWANABETHATGUY
- rolldown: oxc v0.93.0 (#6364) by @Boshen
- rolldown_plugin_vite_html: finish script tag logic (#6355) by @shulaoda
- rolldown_plugin_vite_html: support inline html proxy (#6353) by @shulaoda
- rolldown_plugin_vite_html: transform script tag into js import (#6351) by @shulaoda
- rolldown_plugin_vite_html: overwrite script src url (#6349) by @shulaoda
- rolldown_plugin_vite_html: remove `vite-ignore` attribute (#6348) by @shulaoda
- rolldown_plugin_vite_html: use `html5ever` and `markup5ever_rcdom` (#6327) by @shulaoda
- rust/dev: support `on_output` callback (#6330) by @hyf0
- rust/dev: support `disable_watcher` (#6329) by @hyf0
- dev: introduce client/session concept into dev engine (#6297) by @hyf0

### 🐛 Bug Fixes

- 'asset' module type and CJS format produces warnings and wrong output (#6369) by @IWANABETHATGUY
- inlining constants in CJS by optimization.inlineConst incorrectly inlines non-constant values if the value is assigned more than once (#6328) by @IWANABETHATGUY
- dev: add `hasLatestBuildOutput` instead of `scheduleBuildIfStale` and add edit-reload test (#6321) by @sapphi-red

### 🚜 Refactor

- rust/dev: rename `HmrManager` to `HmrState` and tweak namings (#6358) by @hyf0
- rust/dev: use `Bundler` to expose hmr related methods (#6356) by @hyf0
- rolldown_plugin_vite_html: use `html5gum` instead (#6343) by @shulaoda
- dev: remove deprecated `new` field from HMR options and related configurations (#6337) by @hyf0
- dev: remove unused hmr API (#6336) by @hyf0
- make `cjs_ast_analyzer` immutable for better reuse (#6326) by @IWANABETHATGUY
- simplify logic for determining entry is_lived (#6325) by @IWANABETHATGUY

### ⚡ Performance

- dev: compute depended data incrementally (#6357) by @hyf0

### 🧪 Testing

- rust/hmr: use dev engine to test hmr (#6334) by @hyf0

### ⚙️ Miscellaneous Tasks

- deps: update notify (#6368) by @sapphi-red
- deps: lock file maintenance npm packages (#6366) by @renovate[bot]
- deps: update github-actions (#6365) by @renovate[bot]
- deps: update dependency rolldown-plugin-dts to v0.16.9 (#6354) by @renovate[bot]
- deps: update dependency tsdown to v0.15.5 (#6350) by @renovate[bot]
- node: use `catalog:` to unify version of all dependencies (#6339) by @hyf0
- ci: unify node installation via oxc-project/setup-node (#6338) by @Boshen
- deps: update crate-ci/typos action to v1.36.3 (#6341) by @renovate[bot]
- remove unused snapshots (#6331) by @IWANABETHATGUY

Co-authored-by: shulaoda <165626830+shulaoda@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants