Skip to content

chore(deps): update all non-major dependencies#25

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

chore(deps): update all non-major dependencies#25
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@antfu/eslint-config ^7.4.3^7.7.3 age confidence pnpm.catalog.dev minor
@commitlint/cli (source) ^20.4.1^20.5.3 age confidence pnpm.catalog.dev minor
@commitlint/config-conventional (source) ^20.4.1^20.5.3 age confidence pnpm.catalog.dev minor
@vitest/browser-playwright (source) ^4.0.18^4.1.9 age confidence pnpm.catalog.test minor
@vitest/coverage-v8 (source) ^4.0.18^4.1.9 age confidence pnpm.catalog.test minor
eslint (source) ^9.39.2^9.39.4 age confidence pnpm.catalog.dev patch
lint-staged ^16.2.7^16.4.0 age confidence pnpm.catalog.dev minor
node (source) >=24.13.1>=24.16.0 age confidence engines minor
playwright (source) ^1.58.2^1.61.0 age confidence pnpm.catalog.test minor
pnpm (source) 10.29.310.34.3 age confidence packageManager minor
pnpm (source) >=10.29.3>=10.34.3 age confidence engines minor
vitest (source) ^4.0.18^4.1.9 age confidence pnpm.catalog.test minor

Release Notes

antfu/eslint-config (@​antfu/eslint-config)

v7.7.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v7.7.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v7.7.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v7.6.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v7.6.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v7.5.0

Compare Source

   🚀 Features
    View changes on GitHub
conventional-changelog/commitlint (@​commitlint/cli)

v20.5.3

Compare Source

Note: Version bump only for package @​commitlint/cli

v20.5.2

Compare Source

Note: Version bump only for package @​commitlint/cli

v20.5.0

Compare Source

Bug Fixes

20.4.4 (2026-03-12)

Note: Version bump only for package @​commitlint/cli

20.4.3 (2026-03-03)

Bug Fixes

20.4.2 (2026-02-19)

Note: Version bump only for package @​commitlint/cli

20.4.1 (2026-02-02)

Note: Version bump only for package @​commitlint/cli

v20.4.4

Compare Source

Note: Version bump only for package @​commitlint/cli

v20.4.3

Compare Source

Bug Fixes

v20.4.2

Compare Source

Note: Version bump only for package @​commitlint/cli

conventional-changelog/commitlint (@​commitlint/config-conventional)

v20.5.3

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

v20.5.0

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

20.4.4 (2026-03-12)

Note: Version bump only for package @​commitlint/config-conventional

20.4.3 (2026-03-03)

Bug Fixes

20.4.2 (2026-02-19)

Note: Version bump only for package @​commitlint/config-conventional

20.4.1 (2026-02-02)

Note: Version bump only for package @​commitlint/config-conventional

v20.4.4

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

v20.4.3

Compare Source

Bug Fixes

v20.4.2

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

vitest-dev/vitest (@​vitest/browser-playwright)

v4.1.8

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v4.1.7

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v4.1.6

Compare Source

   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub

v4.1.5

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.4

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.3

Compare Source

   🚀 Experimental Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.2

Compare Source

This release bumps Vitest's flatted version and removes version pinning to resolve flatted's CVE related issues (#​9975).

   🐞 Bug Fixes
    View changes on GitHub

v4.1.1

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v4.1.0

Compare Source

Vitest 4.1 is out!

This release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our blog post.

   🚀 Features
   🐞 Bug Fixes

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 2am and before 3am"
  • Automerge
    • "after 1am and before 2am"

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from hmbanan666 as a code owner February 24, 2026 02:55

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 16821b7 to 9f4483e Compare February 24, 2026 12:39
@socket-security

socket-security Bot commented Feb 24, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@antfu/eslint-config@7.7.3npm/@typescript-eslint/eslint-plugin@8.61.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.61.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm eslint-plugin-jsdoc is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@antfu/eslint-config@7.7.3npm/eslint-plugin-jsdoc@62.9.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-jsdoc@62.9.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm js-yaml is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/eslint@9.39.4npm/js-yaml@4.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/js-yaml@4.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 7 times, most recently from 068a6ba to 01263a1 Compare March 3, 2026 18:14
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from c53b049 to ce5929e Compare March 12, 2026 13:56
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from f4daaa0 to cf60081 Compare March 17, 2026 05:30
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from e878a45 to 2fa4bd9 Compare March 26, 2026 18:46
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from d107de4 to 855022d Compare April 8, 2026 16:48
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 855022d to c313865 Compare April 9, 2026 11:05
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 2a445ee to 2cfd8bc Compare April 22, 2026 12:05
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 00da4e6 to 40d6f3d Compare April 30, 2026 10:26
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 3a0e9d5 to 5a11c68 Compare May 11, 2026 21:42
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 2a28e3b to 9d9b162 Compare May 18, 2026 10:52
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 2779b35 to 66f3d28 Compare May 21, 2026 14:39
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from ad86532 to 9b24c98 Compare June 1, 2026 20:13
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 9b24c98 to 738cd9e Compare June 10, 2026 14:07
@socket-security

socket-security Bot commented Jun 10, 2026

Copy link
Copy Markdown

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 80c05be to 95c1625 Compare June 15, 2026 07:43
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 95c1625 to 525ef10 Compare June 15, 2026 10:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants