Skip to content

chore(deps): update all non-major dependencies - #151

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 21, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@types/node (source) ^26.2.0 → ^26.6.4 age confidence
eslint (source) ^10.8.1 → ^10.12.0 age confidence
magic-string ^1.2.1 → ^1.4.3 age confidence
obuild ^0.4.38 → ^0.4.43 age confidence
oxc-parser (source) >=0.140.0 → >=0.153.0 age confidence
oxc-parser (source) ^0.146.0 → ^0.153.0 age confidence
pnpm (source) 11.12.0 → 11.28.5 age confidence
prettier (source) ^3.9.6 → ^3.9.9 age confidence
rolldown (source) ^1.1.5 → ^1.2.12 age confidence
rolldown (source) ^1.2.4 → ^1.2.12 age confidence
unplugin (source) ^3.3.0 → ^3.4.0 age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

eslint/eslint (eslint)

v10.12.0

Compare Source

Features

  • 4618052 feat: handle astral letters in new-cap (#​21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#​21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#​21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#​21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#​21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#​21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#​21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#​21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#​21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#​21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#​21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#​21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#​21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#​21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#​21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#​21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#​21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#​21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#​21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#​21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#​21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#​21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#​21342) (ESLint Bot)

v10.11.0

Compare Source

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#​21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#​21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#​21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#​21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#​21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#​21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#​21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#​21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#​21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#​21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#​21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#​21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#​21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#​21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#​21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#​21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#​20395) (Nitin Kumar)

v10.10.0

Compare Source

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#​21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#​21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#​21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#​20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#​21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#​21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#​21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#​21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#​21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#​21286) (한국)
  • 8724829 docs: update compat table links (#​21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#​21256) (Müslüm Yılmaz)

Chores

v10.9.1

Compare Source

Bug Fixes

  • 1e641c9 fix: no-loss-of-precision false positive with trailing decimal point (#​21251) (Aleksandr Shoronov)

Documentation

  • ad74a8d docs: add deprecation steps for EOL package versions (#​21248) (Francesco Trotta)

Chores

v10.9.0

Compare Source

Features

  • 08de88e feat: handle underflow in no-loss-of-precision (#​21218) (Rithish S)
  • 55db479 feat: add checkConditionalExpressions to no-unmodified-loop-condition (#​21175) (sethamus)

Bug Fixes

  • 2ba3025 fix: prevent unsafe no-var autofix with hoisted functions (#​21213) (sethamus)
  • 8e69622 fix: Prevent no-var autofix when var is shadowed by catch parameter (#​21204) (Yang Hyeonjong)
  • 684b579 fix: prefer-template invalid autofix creates a tagged template call (#​21207) (김채영)

Documentation

  • 9ef407a docs: use eslint.config.* wherever config file names are listed (#​21216) (Marry (Subin Yang))
  • 87f66f4 docs: Update README (GitHub Actions Bot)
  • 585ef37 docs: update architecture documentation (#​21112) (Francesco Trotta)
  • f3993b0 docs: Update README (GitHub Actions Bot)
  • ffc87d6 docs: fix broken links in Further Reading sections (#​21203) (Minsu)
  • 1a761e1 docs: update moved JSX specification links (#​21198) (Imran Mustafa)
  • 4d00ca4 docs: update ESLint peer dependency to ^10.0.0 in shareable configs (#​21202) (lumir)
  • 510d1a2 docs: Update README (GitHub Actions Bot)

Chores

Rich-Harris/magic-string (magic-string)

v1.4.3

Compare Source

Bug Fixes

v1.4.2

Compare Source

Bug Fixes
  • keep the outro when splitting a removed chunk (#​358) (2a665f6)
  • skip empty matches inside removed content in replaceAll (#​359) (2eb0f6f)
Performance Improvements
  • look up removed content without scanning every chunk (#​357) (ca9e867)

v1.4.1

Compare Source

Bug Fixes
  • flush the shared encoder buffer at the end of every drain (#​356) (f682ccf)

v1.4.0

Compare Source

Bug Fixes
  • don't resurrect removed content in replace/replaceAll (#​352) (c847b0e)
Features
Performance Improvements
  • encode mappings incrementally in generateMap to cut peak memory (#​350) (1401f6c)

1.3.2 (2026-09-15)

Bug Fixes
  • carry trimStart and trimEnd into the outro and intro (#​348) (07d2fcb)
  • preserve inserts anchored to the edges of a removed range (#​282) (#​349) (bd7ee85)
  • return an empty slice when the end index resolves to zero (#​346) (5531971)
  • treat moving a range to where it already sits as a no-op (#​347) (22ed11b)

1.3.1 (2026-09-10)

v1.3.2

Compare Source

Bug Fixes
  • don't resurrect removed content in replace/replaceAll (#​352) (c847b0e)
Features
Performance Improvements
  • encode mappings incrementally in generateMap to cut peak memory (#​350) (1401f6c)

1.3.2 (2026-09-15)

Bug Fixes
  • carry trimStart and trimEnd into the outro and intro (#​348) (07d2fcb)
  • preserve inserts anchored to the edges of a removed range (#​282) (#​349) (bd7ee85)
  • return an empty slice when the end index resolves to zero (#​346) (5531971)
  • treat moving a range to where it already sits as a no-op (#​347) (22ed11b)

1.3.1 (2026-09-10)

v1.3.1

Compare Source

Bug Fixes
  • don't resurrect removed content in replace/replaceAll (#​352) (c847b0e)
Features
Performance Improvements
  • encode mappings incrementally in generateMap to cut peak memory (#​350) (1401f6c)

1.3.2 (2026-09-15)

Bug Fixes
  • carry trimStart and trimEnd into the outro and intro (#​348) (07d2fcb)
  • preserve inserts anchored to the edges of a removed range (#​282) (#​349) (bd7ee85)
  • return an empty slice when the end index resolves to zero (#​346) (5531971)
  • treat moving a range to where it already sits as a no-op (#​347) (22ed11b)

1.3.1 (2026-09-10)

v1.2.3

Compare Source

Bug Fixes
Features
  • add hires mode source map mode using range mappings (#​317) (708e379)
  • support a function for includeContent in Bundle (#​165) (ead0c08)
Performance Improvements

1.2.3 (2026-08-26)

Bug Fixes

1.2.2 (2026-08-20)

Bug Fixes
  • hasChanged reports a change when an edit spans a chunk boundary (#​331) (811de46)
  • keep the ignore-list hint and stored names when cloning (#​329) (ddf02ca)
Performance Improvements

1.2.1 (2026-08-19)

Bug Fixes

v1.2.2

Compare Source

Bug Fixes
Features
  • add hires mode source map mode using range mappings (#​317) (708e379)
  • support a function for includeContent in Bundle (#​165) (ead0c08)
Performance Improvements

1.2.3 (2026-08-26)

Bug Fixes

1.2.2 (2026-08-20)

Bug Fixes
  • hasChanged reports a change when an edit spans a chunk boundary (#​331) (811de46)
  • keep the ignore-list hint and stored names when cloning (#​329) (ddf02ca)
Performance Improvements

1.2.1 (2026-08-19)

Bug Fixes
oxc-project/oxc (oxc-parser)

v0.153.0

🐛 Bug Fixes

v0.152.0

🚀 Features
🐛 Bug Fixes
📚 Documentation

v0.151.0

🚀 Features

v0.149.0

🐛 Bug Fixes
  • c966aca parser: Do not omit < token opening type argument list (#​26328) (overlookmotel)

v0.147.0

🐛 Bug Fixes
  • 8a9bdbd estree: Include decorators in FormalParameterRest spans (#​26021) (camc314)

v0.145.0

🐛 Bug Fixes

v0.144.0

💥 BREAKING CHANGES
  • a33788e ast: [BREAKING] Group class heritage into ClassHeritage (#​25360) (camc314)
  • 5c5cdcd ast: [BREAKING] Narrow TSInterfaceHeritage::expression to TSTypeName (#​24360) (camc314)
  • 6be314f ast: [BREAKING] Remove duplicated VariableDeclarator::kind (#​25319) (camc314)
  • 44fd320 ast: [BREAKING] Split TS external modules & Namespace Declarations (#​25284) (camc314)
🐛 Bug Fixes

v0.143.0

💥 BREAKING CHANGES
  • 067da8c ast: [BREAKING] Store single parameter in TSIndexSignature::parameter (#​25154) (camc314)
  • 1bdedd1 ast: [BREAKING] Introduce ExportDeclaration, ExportFromDeclaration (#​25095) (camc314)
  • c917f20 ast: [BREAKING] Introduce ArrowFunctionBody enum (#​24987) (camc314)

v0.142.0

🚀 Features
  • 11f5d1f ast_visit: Add Utf8ToUtf16::convert_program_and_comments (#​24859) (overlookmotel)
🐛 Bug Fixes
  • e80574f estree: Handle empty spans serializing ImportMeta and NewTarget (#​24775) (overlookmotel)

v0.141.0

💥 BREAKING CHANGES
  • 54cc121 ast: [BREAKING] Split MetaProperty into ImportMeta and NewTarget (#​24557) (camc314)
🚀 Features
pnpm/pnpm (pnpm)

v11.28.5: pnpm 11.28.5

Compare Source

This release reads cached registry metadata faster and makes pnpm config get --global ignore project settings. It also carries several security fixes for package archives, git dependencies, and config dependencies.

Patch Changes
Security
  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm now rejects a git dependency whose lockfile repository is empty, begins with -, or contains a null byte. Git can no longer read such a value as a command-line option pnpm/tasks#84.

  • A git dependency with a #path: subpath can no longer reach files outside the repository through a symlink in the subpath.

  • pnpm pack, pnpm publish, and installs of git and local directory dependencies now leave out files that a directory symlink or a bundleDependencies entry points to outside the package directory pnpm/tasks#83 pnpm/tasks#93.

  • pnpm deploy with deployAllFiles now rejects symlinks that point outside the package directory. Local package installs with this setting apply the same check.

  • pnpm no longer hangs on a package archive with a negative PAX record length or an entry of 4 GiB or more pnpm/tasks#78 pnpm/tasks#79.

  • Large package downloads and large files inside gzip and bzip2 package archives now use bounded memory during installation. Package manifests and archive metadata larger than 64 MiB are rejected. pnpm publish also rejects manifests and README files larger than 64 MiB in pre-built tarballs before reading them into memory.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • pnpm licenses now removes terminal control characters from package metadata in table output.

  • The warnings about ignored project .npmrc registry and auth settings no longer print the username and password of a URL-scoped key such as //user:password@registry.example.com/:_authToken.

Installing and resolving dependencies
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set #​13512.

  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. pnpm linked su

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 1am and before 5am"
  • Automerge
    • "after 2am and before 5am"

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.28%. Comparing base (6586739) to head (64f7013).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #151   +/-   ##
=======================================
  Coverage   93.28%   93.28%           
=======================================
  Files           3        3           
  Lines         268      268           
  Branches      100      100           
=======================================
  Hits          250      250           
  Misses         18       18           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 37505bb to 7ab4355 Compare August 28, 2026 00:53
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from 264ab84 to 513d58d Compare September 4, 2026 23:19
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from b57d4f9 to 0cf739f Compare September 10, 2026 00:41
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 15135caf-0f15-4549-a6bb-3002ef1dba14

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from f80f69b to 3a789d7 Compare September 15, 2026 22:47
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from c434c09 to b12fbec Compare September 22, 2026 04:31
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from de4fa1b to 6944fbf Compare September 29, 2026 03:01
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from e3075ff to 2ab1b43 Compare October 8, 2026 13:28
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 2ab1b43 to 74b0500 Compare October 9, 2026 08:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants