Skip to content

Bump the dependencies group across 1 directory with 7 updates - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-79d0ef551a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-79d0ef551a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 7 updates in the / directory:

Package From To
@bjorn3/browser_wasi_shim 0.3.0 0.4.2
@zip.js/zip.js 2.7.57 2.18.2
monaco-editor 0.52.2 0.57.0
tar-stream 3.1.7 3.2.1
@types/tar-stream 3.1.3 3.1.4
@types/tar-stream 3.1.3 3.1.4
esbuild 0.28.0 0.28.2
vitest 3.0.7 5.0.2

Updates @bjorn3/browser_wasi_shim from 0.3.0 to 0.4.2

Release notes

Sourced from @​bjorn3/browser_wasi_shim's releases.

v0.4.2

What's Changed

New Contributors

Full Changelog: bjorn3/browser_wasi_shim@v0.4.1...v0.4.2

v0.4.1

What's Changed

Full Changelog: bjorn3/browser_wasi_shim@v0.4.0...v0.4.1

v0.4.0

What's Changed

New Contributors

Full Changelog: bjorn3/browser_wasi_shim@v0.3.0...v0.4.0

Commits
  • 4a55f2a Bump to v0.4.2
  • 910395b Add blocking-based poll_oneoff to support clock_nanosleep (#88)
  • 1d0b60c encode environ before getting length to fix environ_sizes_get breaking on uni...
  • c807dae Bump to v0.4.1
  • b152b3e Handle absence of SharedArrayBuffer (#87)
  • 29eea8c Avoid packaging the test and threads subdirectories
  • c9deb6d Bump to v0.4.0
  • 168313f Merge pull request #86 from kateinoigakukun/yt/issue-ino
  • a267bd6 Remove InoIssuer abstraction
  • c488d4b Return unique ino for each node for Filestat and Dirent
  • Additional commits viewable in compare view

Updates @zip.js/zip.js from 2.7.57 to 2.18.2

Release notes

Sourced from @​zip.js/zip.js's releases.

v2.18.2

What's Changed in v2.18.2

Bug fixes

  • With checkOverlappingEntry set, a data descriptor whose CRC-32 disagrees with the central directory, a corrupt CRC-32 for instance, is now reported in localDirectory.dataDescriptor with its own fields, its CRC-32 differing from entry.crc32 as LocalDataDescriptor#crc32 documents. Until now the signed layout was kept only when its CRC-32 and sizes agreed with the central directory, since 2.18.1 among 4- or 8-byte sizes, and otherwise the record was read at the width the Zip64 extra field of either record announces without the signature, i.e. at a layout known not to match, so a signed descriptor with a corrupt CRC-32 came back with signature false, the signature bytes as crc32 and its sizes shifted by four bytes. The layout is now the one whose sizes agree with the central directory, its CRC-32 breaking ties when the central directory stores one; when no layout agrees, the record is read at the announced width as before, with the signature when it starts with one. The tie-break applies to AES entries that store a CRC-32 (AE-1, what WinZip writes for most files) like to any other entry; the CRC-32 of an AES entry used to be ignored. Reading the data of the entry is unchanged, and reading without checkOverlappingEntry never consulted the descriptor

Documentation

  • The remarks of LocalDataDescriptor#signature and LocalDataDescriptor#zip64 describe how the layout is chosen

Tests and continuous integration

  • The data descriptor width test now reads a signed descriptor whose CRC-32 alone is corrupt and one whose compressed size is corrupt, and a new test writes an AE-2 entry with a signed data descriptor, patches it into an AE-1 entry with a disagreeing and then an agreeing descriptor CRC-32, and checks the layout reported for each and for the AE-2 entry

Full Changelog: gildas-lormeau/zip.js@v2.18.1...v2.18.2

Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com

v2.18.1

What's Changed in v2.18.1

New features

  • LocalDataDescriptor has a zip64 property, true when the sizes of the data descriptor read with checkOverlappingEntry are stored as 8-byte values

Bug fixes

  • With checkOverlappingEntry set, an entry placed past 4 GB whose data descriptor stores 4-byte sizes now reads; getData() used to fail with ERR_UNSUPPORTED_UINT64. The width of the sizes was taken from the presence of a Zip64 extra field in either record, but neither record tells it reliably: the local file header is written before a streaming writer knows the sizes, and the Zip64 extra field of the central directory record, written last, describes that record, not the descriptor. Go's archive/zip, for instance, gives a small entry placed past 4 GB a Zip64 extra field in its central directory record for the offset alone and a 4-byte descriptor, while its large streamed entries get an 8-byte descriptor with no local Zip64 extra field, which is why the central directory record was consulted; the descriptor of the small entry was therefore read as 8 bytes wide, across the next record. The descriptor is now read with the layout, among the two widths with and without the signature, whose CRC-32, when the entry stores one, and sizes agree with the central directory; when none does, it is read at the width the Zip64 extra field of either record announces, without the signature, as before. Reading without checkOverlappingEntry never depended on the descriptor and is unchanged

Tests and continuous integration

  • A new test builds the archives by hand, behind a reader that fakes a 4 GB prefix so the offsets are real, and reads a 4-byte descriptor below and past 4 GB, signed and unsigned, and an 8-byte descriptor whose Zip64 extra field is in the central directory only or in neither record, each in both read orders, and a descriptor agreeing with no layout

Full Changelog: gildas-lormeau/zip.js@v2.18.0...v2.18.1

Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com

v2.18.0

What's Changed in v2.18.0

Bug fixes

  • A Zip64 extra field of a local file header that is too short for the 0xFFFFFFFF sentinels of the header or holds a value above Number.MAX_SAFE_INTEGER no longer fails getData() with ERR_EXTRAFIELD_ZIP64_NOT_FOUND or ERR_UNSUPPORTED_UINT64: the sizes of an entry come from the central directory, so the field is reported as WARNING_MALFORMED_EXTRA_FIELD on entry.warnings and the entry is read. A local file header whose sizes hold the sentinels with no Zip64 extra field behind them, which used to pass silently, is reported the same way. In the three cases an entry without a data descriptor keeps the sentinels as its local sizes, which the local file header check reports as WARNING_MISMATCHED_LOCAL_FILE_HEADER_CRC32_OR_SIZES, i.e. ERR_AMBIGUOUS_ARCHIVE under the default strictness and a warning with strictness: "tolerant". Both errors are still raised by getEntries() for a central directory record whose field is too short or holds such a value, where the sizes and the offset have no other source, and a record whose sizes, offset or disk number hold the sentinel with no Zip64 extra field behind it now fails getEntries() with ERR_EXTRAFIELD_ZIP64_NOT_FOUND too, at every strictness, so none of the entries is listed: it used to be listed with sizes of 4 GB and fail later, with a local file header mismatch or ERR_ENTRY_DATA_OUT_OF_BOUNDS, or with ERR_LOCAL_FILE_HEADER_NOT_FOUND for an offset
  • An AES extra field on a record that is not encrypted and whose compression method is not 99 is ignored and reported as WARNING_MALFORMED_EXTRA_FIELD, on ZipReader#warnings with the filename for the central directory record and on entry.warnings for the local file header, and the entry is read with the method its record declares; the field used to override the method and getData() failed with ERR_UNSUPPORTED_COMPRESSION. An AES extra field shorter than 7 bytes, which was ignored silently, is reported the same way. On an encrypted record the field still overrides the method and the conflict is still rejected with ERR_UNSUPPORTED_COMPRESSION, since the data may be AES behind a wrong method
  • The encrypted flag of an entry follows its central directory record. A local file header whose bit 0 is cleared is still ERR_AMBIGUOUS_ARCHIVE under the default strictness, and a reader with strictness: "tolerant" now decrypts the entry and deposits WARNING_MISMATCHED_LOCAL_FILE_HEADER_BIT_FLAG, where it used to follow the local file header, read the ciphertext as plaintext and fail
  • An entry whose strong encryption bit (bit 6 of the general purpose bit flag) differs between the two records is ERR_AMBIGUOUS_ARCHIVE under the default strictness, like the encrypted bit, and the ERR_UNSUPPORTED_ENCRYPTION check reads the central directory record. A bit set in the local file header only used to reject an encrypted entry, AES or ZipCrypto, as unsupported, and a bit set in the central directory only was ignored; a reader with strictness: "tolerant" now decrypts the first with WARNING_MISMATCHED_LOCAL_FILE_HEADER_BIT_FLAG and reports the second as ERR_UNSUPPORTED_ENCRYPTION
  • The cause of an error raised in a worker keeps its code property, e.g. "Z_MEM_ERROR" on the cause of ERR_CODEC_OUT_OF_MEMORY. A structured clone never copies that property, so it was undefined with workers on every host, while the code of the error itself was already carried by the message posted by the worker

Documentation

... (truncated)

Commits
  • dd9e5b4 choose the descriptor layout by its sizes, crc32 breaking ties
  • 24f1a40 bump up version
  • caf7dbe compare the descriptor crc32 whenever the central directory stores one
  • 07cb717 fix the wording of the data descriptor width remark
  • b8508b0 bump up version
  • 737aa2b read the data descriptor with the layout matching the central directory
  • 3b17c72 bump up version
  • 3fe78a8 gate the worker cause test on module workers
  • e2aa07a keep the cause code across workers and report missing zip64 fields
  • a0f59dd compare the strong encryption bit between both records
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​zip.js/zip.js since your current version.


Updates monaco-editor from 0.52.2 to 0.57.0

Release notes

Sourced from monaco-editor's releases.

v0.57.0

Changes:

  • #5487: Prepare Monaco Editor 0.57.0 release
  • #5415: Bump uuid and webpack-dev-server in /website
  • #5476: Bump baseline-browser-mapping from 2.9.19 to 2.11.21 in /website
  • #5474: Bump svgo from 2.8.3 to 2.8.4 in /samples/browser-esm-parcel
  • #5479: Bump actions/deploy-pages from 5.0.0 to 5.0.1 in the github-actions group
  • #5468: Bump browserslist from 4.28.1 to 4.28.8 in /website
  • #5475: Bump js-yaml from 4.3.1 to 4.3.2
  • #5470: Bump fast-uri from 3.1.2 to 3.1.7 in /webpack-plugin
  • #5469: Bump nanoid from 3.3.11 to 3.3.18 in /webpack-plugin
  • #5467: Bump fast-uri from 3.1.5 to 3.1.7 in /samples/browser-esm-webpack-typescript-react
  • #5466: Bump fast-uri from 3.1.2 to 3.1.7 in /samples
  • #5465: Bump fast-uri from 3.1.4 to 3.1.7 in /website
  • #5463: Bump postcss-selector-parser from 7.1.0 to 7.1.5 in /website
  • #5416: Bump @​babel/core from 7.17.8 to 7.29.7 in /samples/browser-esm-vite-react
  • #5438: Bump electron from 39.8.5 to 39.8.10 in /samples
  • #5460: Bump the github-actions group with 7 updates
  • #5456: Pin GitHub Actions to full-length commit SHAs
  • #5450: Bump postcss from 8.5.12 to 8.5.26
  • #5449: Bump js-yaml from 4.2.0 to 4.3.1
  • #5439: Bump postcss from 8.5.13 to 8.5.26 in /samples
  • #5441: Bump postcss from 8.5.15 to 8.5.26 in /samples/browser-esm-vite-react
  • #5432: Bump undici from 7.28.0 to 7.29.0
  • #5440: Bump brace-expansion in /website
  • #5436: Bump fast-uri from 3.1.4 to 3.1.5 in /samples/browser-esm-webpack-typescript-react
  • #5437: Bump fast-uri from 3.1.2 to 3.1.5
  • #5413: Bump svgo from 2.8.2 to 2.8.3 in /samples/browser-esm-parcel
  • #5419: Bump launch-editor from 2.12.0 to 2.14.1 in /website
  • #5414: Bump fast-uri from 3.1.2 to 3.1.4 in /samples/browser-esm-webpack-typescript-react
  • #5417: Bump minimatch from 3.1.2 to 3.1.5 in /webpack-plugin
  • #5420: Bump ws from 8.18.0 to 8.21.1 in /samples
  • #5418: Bump http-proxy-middleware from 2.0.9 to 2.0.10 in /samples
  • #5412: Bump fast-uri from 3.1.2 to 3.1.4 in /website
  • #5411: Bump shell-quote from 1.8.4 to 1.10.0 in /website
  • #5409: Bump webpack-dev-server from 5.2.5 to 5.2.6 in /samples
  • #5410: Bump postcss from 8.5.14 to 8.5.23 in /website
  • #5407: Bump immutable from 5.1.5 to 5.1.9 in /website
  • #5401: Bump brace-expansion from 1.1.11 to 1.1.16 in /samples

This list of changes was auto generated.

v0.57.0-rc.2

... (truncated)

Changelog

Sourced from monaco-editor's changelog.

[0.57.0]

New Features and APIs

  • Adds editor.wordWrapIndicator to display an indicator at the wrapping column of soft-wrapped lines.
  • Adds editor.fullwidthCharacterWidth, with font and twoCells modes for rendering full-width characters.
  • Adds languages.score to score a language selector against a URI and language.
  • Exports the editor.DiffEditorViewMode type.
  • Adds isForAnotherDocument to the inline completion languages.LifetimeSummary type.

Updates

  • Updates the editor core to VS Code commit 6a598d4a13031703d483d103c1d934a36ad27971, validated in 0.57.0-rc.2.
  • Updates bundled DOMPurify from 3.4.8 to 3.4.15.

[0.56.0]

Breaking Changes

  • Reorganizes the exported ESM modules to provide supported, tree-shakeable entry points (#5155). The monaco-editor entry point continues to load all features and languages. Custom bundles can now import monaco-editor/editor and opt into:
    • all editor features with monaco-editor/features/register.all, or individual features with monaco-editor/features/<feature>/register;
    • all language definitions with monaco-editor/languages/definitions/register.all, or individual definitions with monaco-editor/languages/definitions/<language>/register;
    • the CSS, HTML, JSON, and TypeScript language features with monaco-editor/languages/features/register.all, or their individual register entry points.
  • Renames the misspelled IOverlayWidgetPosition.stackOridinal property to stackOrdinal.
  • Removes the deprecated IMirrorModel and IWorkerContext worker API types.

New Features and APIs

  • Adds editor.doubleClickSelectsBlock.
  • Adds editor.find.closeOnResult and editor.inlayHints.showLongLineWarning.
  • Adds offWhenInlineCompletions to QuickSuggestionsValue.
  • Adds model and provider option support to inline completion providers.
  • Adds ICodeEditor.revealAllCursors, ICodeEditor.getWidthOfLine, and ICodeEditor.renderAsync.
  • Adds advanced-external and advanced-wasm diff algorithms.
  • Exposes typed native LSP client and transport APIs.

Fixes

  • Treats Markdown returned by language servers as untrusted (#5280).
  • Updates the editor core to the version used by 0.56.0-dev-20260625.

[0.55.1]

  • Fixes missing language exports (monaco.json/typescript/...) due to wrong "types" path - #5123

[0.55.0]

Breaking Changes

  • Moves nested namespaces (languages.css, languages.html, languages.json, languages.typescript) to top level namespaces (css, html, json, typescript) to simplify the build process and align with typescript recommendations.

... (truncated)

Commits
  • d618242 Merge pull request #5487 from microsoft/hediet/b/release-0.57.0
  • ef061ff Prepare Monaco Editor 0.57.0 release
  • 8e9b0f7 Keep editor release version stable across task retries
  • 3f31304 Prepare VS Code native headers before installing dependencies
  • ebd1312 Use authenticated Foundry Local installer for core builds
  • 176408b Align release build Node version with VS Code 1.139
  • 97d81ca Bump uuid and webpack-dev-server in /website (#5415)
  • f7c7f4c Bump baseline-browser-mapping from 2.9.19 to 2.11.21 in /website (#5476)
  • 36f4fe6 Bump svgo from 2.8.3 to 2.8.4 in /samples/browser-esm-parcel (#5474)
  • f24cd7f Bump actions/deploy-pages in the github-actions group (#5479)
  • Additional commits viewable in compare view

Updates tar-stream from 3.1.7 to 3.2.1

Commits

Updates @types/tar-stream from 3.1.3 to 3.1.4

Commits

Updates @types/tar-stream from 3.1.3 to 3.1.4

Commits

Updates esbuild from 0.28.0 to 0.28.2

Release notes

Sourced from esbuild's releases.

v0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})

... (truncated)

Changelog

Sourced from esbuild's changelog.

0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x

... (truncated)

Commits
  • 609683d publish 0.28.2 to npm
  • 11b1fe4 add to release notes
  • ab50d91 css: fix green/blue channel swap in oklch gamut mapping (#4488)
  • 04627b6 fix #4498: async TLA checks need a worklist
  • 5c15177 disable gopls in the go folder
  • fc2ee9b css: adjust parser to allow --foo: {...}
  • 209db54 release notes for css nesting bugfix
  • c625d31 fix #4497: preserve nested ampersands during minification (#4500)
  • 34474e2 better isolation of current part in js parser
  • 07f6e8c fix #4507: import assignment tree-shaking bug
  • Additional commits viewable in compare view

Updates vitest from 3.0.7 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub

v5.0.1

   🚀 Features

   🐞 Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for vitest since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dependencies-79d0ef551a branch from fceff19 to 185ca28 Compare July 31, 2026 17:05
Bumps the dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@bjorn3/browser_wasi_shim](https://github.com/bjorn3/browser_wasi_shim) | `0.3.0` | `0.4.2` |
| [@zip.js/zip.js](https://github.com/gildas-lormeau/zip.js) | `2.7.57` | `2.18.2` |
| [monaco-editor](https://github.com/microsoft/monaco-editor) | `0.52.2` | `0.57.0` |
| [tar-stream](https://github.com/mafintosh/tar-stream) | `3.1.7` | `3.2.1` |
| [@types/tar-stream](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/tar-stream) | `3.1.3` | `3.1.4` |
| [@types/tar-stream](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/tar-stream) | `3.1.3` | `3.1.4` |
| [esbuild](https://github.com/evanw/esbuild) | `0.28.0` | `0.28.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `3.0.7` | `5.0.2` |



Updates `@bjorn3/browser_wasi_shim` from 0.3.0 to 0.4.2
- [Release notes](https://github.com/bjorn3/browser_wasi_shim/releases)
- [Commits](bjorn3/browser_wasi_shim@v0.3.0...v0.4.2)

Updates `@zip.js/zip.js` from 2.7.57 to 2.18.2
- [Release notes](https://github.com/gildas-lormeau/zip.js/releases)
- [Commits](gildas-lormeau/zip.js@v2.7.57...v2.18.2)

Updates `monaco-editor` from 0.52.2 to 0.57.0
- [Release notes](https://github.com/microsoft/monaco-editor/releases)
- [Changelog](https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md)
- [Commits](microsoft/monaco-editor@v0.52.2...v0.57.0)

Updates `tar-stream` from 3.1.7 to 3.2.1
- [Commits](mafintosh/tar-stream@v3.1.7...v3.2.1)

Updates `@types/tar-stream` from 3.1.3 to 3.1.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/tar-stream)

Updates `@types/tar-stream` from 3.1.3 to 3.1.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/tar-stream)

Updates `esbuild` from 0.28.0 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](evanw/esbuild@v0.28.0...v0.28.2)

Updates `vitest` from 3.0.7 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: "@bjorn3/browser_wasi_shim"
  dependency-version: 0.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@types/tar-stream"
  dependency-version: 3.1.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@types/tar-stream"
  dependency-version: 3.1.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@zip.js/zip.js"
  dependency-version: 2.8.26
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: esbuild
  dependency-version: 0.28.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: monaco-editor
  dependency-version: 0.55.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: tar-stream
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: vitest
  dependency-version: 4.1.9
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dependencies-79d0ef551a branch from 185ca28 to f7d0500 Compare October 1, 2026 17:25

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants