Skip to content

build(deps-dev): bump the npm-minor-patch group with 8 updates - #17

Closed
dependabot[bot] wants to merge 10 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-ed29ac0fac
Closed

dependabot[bot] wants to merge 10 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-ed29ac0fac

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown

Bumps the npm-minor-patch group with 8 updates:

Package From To
@biomejs/biome 2.5.13 2.5.15
@napi-rs/cli 3.10.4 3.10.5
@primer/octicons 19.36.0 19.38.0
@types/node 26.6.1 26.6.3
@vitest/coverage-v8 5.0.1 5.0.3
jsdom 30.0.1 30.1.1
tsc-alias 1.9.5 1.9.7
vitest 5.0.1 5.0.3

Updates @biomejs/biome from 2.5.13 to 2.5.15

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.15

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #11723 3b429d1 Thanks @​m1handr! - Fixed #11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

... (truncated)

Commits

Updates @napi-rs/cli from 3.10.4 to 3.10.5

Commits
  • 5ae5cf6 chore(release): publish
  • 0da138e feat(cli): self-sign OpenHarmony artifacts with --ohos-sign (#3539)
  • 2499a63 feat(async-runtime): offer the MultiThread flavor on wasm32-wasip1-threads (#...
  • 886bd07 chore(deps): update dependency oxc-parser to ^0.151.0 (#3542)
  • edb0a29 fix(napi): validate native payload provenance for External and instance data ...
  • 38162bb chore: release (#3529)
  • ec3d8ea fix(napi): guard AsyncTask completion against env teardown (#3536)
  • 96ed267 chore(deps): update release-plz/action action to v0.5.139 (#3537)
  • b2c9f3b chore(deps): update release-plz/action action to v0.5.138 (#3533)
  • f31c887 fix(cli): skip the reconciliation heal test on hosts whose identity probes fa...
  • See full diff in compare view

Updates @primer/octicons from 19.36.0 to 19.38.0

Release notes

Sourced from @​primer/octicons's releases.

@​primer/octicons-react@​19.38.0

Minor Changes

@​primer/octicons@​19.38.0

Minor Changes

@​primer/octicons-react@​19.37.0

Minor Changes

  • #1355 0b52df259a3e4df4396f7741e53438e9a022d46f Thanks @​janmaarten-a11y! - Add triangle, triangle-circle, triangle-fill, and git-pull-request-unlisted, and provide both 16px and 24px artwork for bookmark-fill and repo-delete. Preserve play as a supported circled alias, retain the deprecated bookmark-filled and repo-deleted names with their existing artwork, and keep existing helper defaults.

  • #1354 82b8e0639baabd45e63696a95deca007cff59235 Thanks @​janmaarten-a11y! - Add the comment-fill icon in 16px and 24px sizes for representing comments with a filled speech bubble. React and styled Octicons provide CommentFillIcon; @primer/octicons-react-symbols provides CommentFillSymbol and CommentFillIconReference.

@​primer/octicons@​19.37.0

Minor Changes

  • #1355 0b52df259a3e4df4396f7741e53438e9a022d46f Thanks @​janmaarten-a11y! - Add triangle, triangle-circle, triangle-fill, and git-pull-request-unlisted, and provide both 16px and 24px artwork for bookmark-fill and repo-delete. Preserve play as a supported circled alias, retain the deprecated bookmark-filled and repo-deleted names with their existing artwork, and keep existing helper defaults.

  • #1354 82b8e0639baabd45e63696a95deca007cff59235 Thanks @​janmaarten-a11y! - Add the comment-fill icon in 16px and 24px sizes for representing comments with a filled speech bubble. React and styled Octicons provide CommentFillIcon; @primer/octicons-react-symbols provides CommentFillSymbol and CommentFillIconReference.

  • #1356 d5d6d581a1f8ff88971979321e4953a23e08bbca Thanks @​janmaarten-a11y! - Add the terminal-locked and chat-add icons in 16px and 24px sizes for representing locked terminal access and adding chats or messages. React and styled Octicons provide TerminalLockedIcon and ChatAddIcon; @primer/octicons-react-symbols provides TerminalLockedSymbol and ChatAddSymbol.

Patch Changes

Commits

Updates @types/node from 26.6.1 to 26.6.3

Commits

Updates @vitest/coverage-v8 from 5.0.1 to 5.0.3

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Updates jsdom from 30.0.1 to 30.1.1

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)

v30.1.0

jsdom is feeling the AGI!

This release is dedicated to @​scttcper, who unleashed @​codex upon jsdom and found tons of performance improvements. Along the way, he found and fixed many correctness issues as well.

We really appreciate his thoughtful PRs, which did a great job following the project's contribution guidelines, and were clearly human-curated, with their PR descriptions edited to be brief and respectful of the maintainers' time.

Thanks to @​scttcper, as well as all the other contributors of this release (most of whom were AI-assisted).

  • Added named access to elements on document, such as document.myForm for <form name="myForm">. (@​vojtisprime11)
  • Added QuotaExceededError, including its use for storage quota errors and oversized crypto.getRandomValues() requests.
  • Added support for the relaxed DOM naming rules when creating elements, attributes, and document types.
  • Improved performance of DOM construction, tree mutations, range operations, and live collection access, especially on large documents. (@​scttcper, @​erezrokah)
  • Improved performance of getComputedStyle(), style changes, and CSS serialization. (@​scttcper, @​jhult)
  • Improved performance of event dispatch, form control and label lookups, and updates to <select> elements and radio button groups. (@​scttcper)
  • Reduced memory use when creating and working with DOM nodes, attributes, event listeners, and mutation observers. (@​scttcper)
  • Changed window.close() to preserve access to the document and its DOM through retained references.
  • Fixed element.querySelectorAll() returning no matches when the first part of the selector matches the element itself, which regressed in v30.0.0. (@​asamuzaK)
  • Fixed case sensitivity in CSS attribute selectors, including selectors matching data-state="", title="", and other case-sensitive values. (@​asamuzaK)
  • Fixed document.querySelector() failing to find a matching element when an earlier element has the same ID but does not match the rest of the selector. (@​vojtisprime11)
  • Fixed :focus matching in shadow trees. (@​asamuzaK)
  • Fixed DOM insertion and replacement, including valid document.replaceChildren() calls, invalid document element and doctype placements, and mutations during element.replaceWith().
  • Fixed the ordering of script execution, custom element callbacks, iframe loading, and mutation observer notifications during DOM insertion, including in shadow trees.
  • Fixed queued events and navigation continuing after window.close() or iframe removal, and prevented new scripts, resource loads, timers, and animation frames from starting in destroyed documents. (@​scttcper)
  • Fixed parent documents waiting indefinitely for loading to finish when a child iframe removes itself during loading.
  • Fixed request cancellation across redirects, during pending requestInterceptor() callbacks, and when reusing an XMLHttpRequest after aborting it.
  • Fixed resource loading and JSDOM.fromURL() potentially hanging when response handling throws and response stream cleanup does not finish.
  • Fixed successful cached resource loads being treated as aborted.
  • Fixed getComputedStyle() and document.styleSheets using the wrong stylesheet order after inserting or updating <style> elements.
  • Fixed getComputedStyle() ignoring nested @import and @media rules in imported stylesheets, and returning stale results after imports finish loading.
  • Fixed style invalidation, stylesheet removal, and frame source updates in shadow trees.
  • Fixed repeated getComputedStyle() calls changing case-sensitive background URLs, and inconsistent resolution of border shorthands containing system colors. (@​scttcper)
  • Fixed computed border widths, including borderless elements incorrectly reporting 16px, which regressed in v30.0.0. (@​Alberto-BaseNet)
  • Fixed getComputedStyle() to resolve 'font-weight' keywords to numeric values. (@​tianrking)
  • Fixed getComputedStyle() to convert lengths to pixels inside CSS math functions containing percentages, and to resolve percentages in 'font-size' math functions. (@​soroushm)

... (truncated)

Commits
  • 0a117f4 30.1.1
  • 103f67d Remove unnecessary window cleanup from API tests
  • cdda00a Test HTTP/2 document and subresource loading
  • 7ab92ce Update @​asamuzakjp/dom-selector to v9.2.1
  • d940c20 Share jsdom settings across descendant windows
  • 6ba40cb Fix and simplify option propagation
  • 3b3be70 Preserve CSS priorities across declaration updates
  • 97b2758 Align focusing and unfocusing with HTML
  • b7b460b Update w3c-xmlserializer to v6
  • 71d562f Update html-encoding-sniffer to v7
  • Additional commits viewable in compare view

Updates tsc-alias from 1.9.5 to 1.9.7

Release notes

Sourced from tsc-alias's releases.

v1.9.7(2026-09-30

Fixes #196

Full Changelog: justkey007/tsc-alias@v1.9.7...v1.9.7

v1.9.6(2026-09-30)

What's Changed

Full Changelog: justkey007/tsc-alias@v1.9.5...v1.9.6

Commits
  • 1c87891 1.9.7
  • 119fadc Merge pull request #285 from justkey007/issue196-2
  • 1e754dc fix: correctly resolve aliases between declaration files when using build wit...
  • 6d32952 1.9.6
  • 528be88 Merge pull request #282 from justkey007/issue196
  • 7d01d4f fix: correctly resolve aliases between declaration files when using build wit...
  • See full diff in compare view

Updates vitest from 5.0.1 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

dependabot Bot and others added 10 commits October 3, 2026 20:34
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.0.0 to 8.0.1.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4.0.0...v8.0.1)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.0.0...v7.0.1)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 4.2.0 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4.2.0...v6.1.0)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…g both ref fills

`loadCommits` was the one read the engine lost: 12.9 ms against the CLI's
10.8 ms on a 1,036-commit repository, even though the engine call itself
took 7.1 ms. The gap was two sequential `for-each-ref` spawns running
after it (16.5d3/d5), putting back two fields the engine's types did not
carry. Same defect as the repoInfo one fixed in 9fe6599, one layer down,
so the same fix: teach the engine the field, delete the fill.

`GitTagRef` and `GitCommitTag` gain `signed`. `refs.rs` reads it from the
tag object it was already peeling, and records it on both records of an
annotated tag, since the signature belongs to the tag rather than to
either hash. `find_header` settles the object kind first, so a
lightweight tag costs a header lookup, not a commit read.

The semantics were checked against git rather than assumed:
`%(contents:signature)` is non-empty only for a signed annotated tag
object. A lightweight tag over a genuinely signed commit (`%G?` = `G`)
reports unsigned, and the engine matches by construction.

`read_remote_refs` now resolves symbolic refs instead of dropping them,
which is what `%(objectname)` reports for the `refs/remotes/<remote>/HEAD`
every clone writes.

Verified on a clone carrying all four tag shapes and a symbolic
origin/HEAD: engine and CLI ref labels identical with the engine serving
the read, and the engine path down from 2 git spawns to 0 (the CLI uses
3). loadCommits 300: 11.5 ms CLI vs 7.7 ms engine, 0.8x -> 1.5x; view
load 4.4x. Two tests pin it, each mutation-checked to kill only its own.
The signed-tag fixture writes the tag object by hand, so CI needs no
keyring.

Also fixes a defaults drift found while answering why `initialLoadCommits`
is 300: `loadMoreCommits` is 100 in the manifest and README but fell back
to 75 in config.ts, with the test pinning the wrong value. It never fired
in a real install, since VS Code returns the manifest default for an unset
key. The 300 itself is left alone and documented as inherited from
upstream — the git read and the graph layout do not justify it, but DOM
row insertion was not measured and is the one cost that still could.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… at 300

The first page is the latency-critical one and stays at 300. The
follow-on page goes from 100 to 1000, which is the better trade for how
the table is actually rendered.

`renderTable` builds one HTML string over every loaded commit and assigns
it to `innerHTML`, so each "load more" rebuilds the whole table rather
than appending to it. Reaching 3,000 commits therefore costs about 27
growing rebuilds at a step of 100 and about 3 at a step of 1,000 - a
larger step is strictly less total work, not more. It also matters more
than it looks, because `autoLoadMoreCommitsOnScroll` fires whenever the
viewport comes within 96px of the bottom, so the small step stalls
repeatedly during ordinary scrolling rather than only on a click.

Measured through the webview harness, a full rebuild is 921 ms at 1,000
rows and 2,783 ms at 2,000. Those are jsdom figures and are not browser
figures - jsdom parses HTML far more slowly and does no layout or paint -
but they establish that the rebuild is at least linear in total rows with
a constant that is not small. The engine-side read is negligible by
comparison: 13.6 ms for 1,000 commits.

The real fix is to append new rows instead of regenerating the table,
making a page nearly free; that is a separate change to `renderTable` and
is recorded in the knowledge base rather than attempted here.

Manifest, accessor, README and the config test are set together, since
that table mirrors the manifest by hand and had already drifted once.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Replaces the 300/1000 set in 9751c15 at the maintainer's direction. The
reasoning there is unchanged - `renderTable` rebuilds the whole table on
every load, so a larger step is strictly less total work, and
`autoLoadMoreCommitsOnScroll` makes the small step stall repeatedly
during ordinary scrolling - only the two numbers move.

250 trims the latency-critical first paint slightly. 750 keeps the
follow-on page well clear of the old 100 while sitting below the 1,000
the render figures were taken at, which is the conservative direction
given those figures are jsdom's and not a browser's.

Manifest, accessor, README and the config test move together, since that
table mirrors the manifest by hand and had already drifted once.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…'s escaping

Slice 16.7 declined `search_history` because the engine's search and this
project's search answer different questions: a regex over messages across
every ref, against a literal substring search plus author matching, hash
resolution, ref filters and a position for each hit. The decline was
right; the conclusion that search therefore stays on four `git`
processes was not. The engine gains `search_commits`, which reproduces
these semantics. `search_history` stays where it is, unused.

The CLI runs `--fixed-strings --grep`, `--author`, a hash lookup and one
unbounded walk that numbers every commit, then merges by that numbering.
The numbering is also a filter - a hit with no position is dropped, which
is why a hash resolving to an unreachable commit is not a result. The
engine does the same three matches in a single walk, which is where the
speed comes from: 62.0 ms -> 7.8 ms (7.9x) on a 1,036-commit repository.

Pinned at the boundaries the two would disagree on - eight parity cases
and twelve engine-side tests: a literal dot a regex would widen, a query
that is not valid regex, case folding, a body-only term `--grep` reaches
and `%s` does not show, an author-only match, an abbreviated hash, a hash
that resolves but is unreachable, and a `--glob=` pattern that still
declines to the CLI.

The parity table then failed on the CLI side, which is the point of
having one. `searchCommits` escaped its `--author` query with a
JavaScript-style `escapeRegExp`, but `--author` takes a *basic* regular
expression, where `\(` opens a group rather than escaping a parenthesis.
The escaping inverted the meaning, and since the four runs share a
`Promise.all`, any query containing an unbalanced `(` or `[` failed the
whole Find dialogue with `fatal: header, '\(': Unmatched ( or \(`.
`--fixed-strings` expresses the literal match that was always intended,
and still matches name and email substrings ignoring case - verified
against git before changing anything.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…pping regex

Five exports whose consumers a permanent non-goal blocks forever, not
merely functions nothing calls today. `search_history` was superseded by
`search_commits` in the previous commit. `current_branch_name`,
`current_branch_upstream`, `remote_names` and `load_commit_subject` are
all read inside `kind: "action"` write flows, and "every write stays on
`runGitRaw`" is the first entry in the permanent non-goals - so none of
them had a reachable future.

This is worth doing rather than leaving alone because a `#[napi]`
function is an exported symbol, so it is a linker root and LTO cannot
strip it: a dead export is genuinely carried in every shipped binary.
`search_history` was also the only consumer of the `regex` crate, which
goes with it.

  before  6,183,072 bytes
  after   4,814,416 bytes
  saving  1,368,656 (22.1%) per platform, ~10.4 MB across all eight

Their `api::Engine` methods went too, along with the now-orphaned
`GitHistoryMatch`, `SEARCH_LIMIT` and `collapse_whitespace`, and their
tests. `Repo::remote_names` is a different function and stays -
`graph.rs` needs it for `load_commits`. The bare-repository test keeps
its object-read coverage and is renamed for what it now proves; the
`Engine` smoke test reads the checked-out branch from `info.head`.

TypeScript loses `currentBranchName`, which was declared on `EngineAddon`
*and* in the `isEngineAddon` load-time guard - it could have rejected a
good engine binary over a method nothing called.

The 13 exports still unwired are kept and inventoried in the knowledge
base with what each would serve, including `author_stats` and
`activity_heatmap`, which the maintainer intends to wire for a Statistics
tab. That slice has no CLI counterpart, so it is a deliberate exception
to the two-backends-agree rule and is recorded as one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps the npm-minor-patch group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.13` | `2.5.15` |
| [@napi-rs/cli](https://github.com/napi-rs/napi-rs) | `3.10.4` | `3.10.5` |
| [@primer/octicons](https://github.com/primer/octicons) | `19.36.0` | `19.38.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.1` | `26.6.3` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.1` | `5.0.3` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.0.1` | `30.1.1` |
| [tsc-alias](https://github.com/justkey007/tsc-alias) | `1.9.5` | `1.9.7` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.3` |


Updates `@biomejs/biome` from 2.5.13 to 2.5.15
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.15/packages/@biomejs/biome)

Updates `@napi-rs/cli` from 3.10.4 to 3.10.5
- [Release notes](https://github.com/napi-rs/napi-rs/releases)
- [Commits](https://github.com/napi-rs/napi-rs/compare/@napi-rs/cli@3.10.4...@napi-rs/cli@3.10.5)

Updates `@primer/octicons` from 19.36.0 to 19.38.0
- [Release notes](https://github.com/primer/octicons/releases)
- [Changelog](https://github.com/primer/octicons/blob/main/CHANGELOG.md)
- [Commits](https://github.com/primer/octicons/compare/@primer/octicons@19.36.0...@primer/octicons@19.38.0)

Updates `@types/node` from 26.6.1 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `jsdom` from 30.0.1 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.0.1...v30.1.1)

Updates `tsc-alias` from 1.9.5 to 1.9.7
- [Release notes](https://github.com/justkey007/tsc-alias/releases)
- [Commits](justkey007/tsc-alias@v1.9.5...v1.9.7)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@napi-rs/cli"
  dependency-version: 3.10.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@primer/octicons"
  dependency-version: 19.38.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tsc-alias
  dependency-version: 1.9.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 3, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-minor-patch-ed29ac0fac branch October 3, 2026 18:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant