deps(npm): bump the dev-deps group across 1 directory with 8 updates#89
Open
dependabot[bot] wants to merge 1 commit into
Open
deps(npm): bump the dev-deps group across 1 directory with 8 updates#89dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
a0620fd to
956c7a9
Compare
956c7a9 to
bc86714
Compare
Bumps the dev-deps group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@playwright/test](https://github.com/microsoft/playwright) | `1.59.1` | `1.61.0` | | [@sveltejs/kit](https://github.com/sveltejs/kit/tree/HEAD/packages/kit) | `2.56.1` | `2.67.0` | | [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) | `7.0.0` | `7.1.2` | | [@tauri-apps/cli](https://github.com/tauri-apps/tauri) | `2.10.1` | `2.11.3` | | [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte) | `5.55.1` | `5.56.3` | | [svelte-check](https://github.com/sveltejs/language-tools) | `4.4.6` | `4.6.0` | | [typescript](https://github.com/microsoft/TypeScript) | `6.0.2` | `6.0.3` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.5` | `8.0.16` | Updates `@playwright/test` from 1.59.1 to 1.61.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.59.1...v1.61.0) Updates `@sveltejs/kit` from 2.56.1 to 2.67.0 - [Release notes](https://github.com/sveltejs/kit/releases) - [Changelog](https://github.com/sveltejs/kit/blob/main/packages/kit/CHANGELOG.md) - [Commits](https://github.com/sveltejs/kit/commits/@sveltejs/kit@2.67.0/packages/kit) Updates `@sveltejs/vite-plugin-svelte` from 7.0.0 to 7.1.2 - [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases) - [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.1.2/packages/vite-plugin-svelte) Updates `@tauri-apps/cli` from 2.10.1 to 2.11.3 - [Release notes](https://github.com/tauri-apps/tauri/releases) - [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.10.1...@tauri-apps/cli-v2.11.3) Updates `svelte` from 5.55.1 to 5.56.3 - [Release notes](https://github.com/sveltejs/svelte/releases) - [Changelog](https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/svelte/commits/svelte@5.56.3/packages/svelte) Updates `svelte-check` from 4.4.6 to 4.6.0 - [Release notes](https://github.com/sveltejs/language-tools/releases) - [Commits](https://github.com/sveltejs/language-tools/compare/svelte-check@4.4.6...svelte-check@4.6.0) Updates `typescript` from 6.0.2 to 6.0.3 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v6.0.2...v6.0.3) Updates `vite` from 8.0.5 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) --- updated-dependencies: - dependency-name: "@playwright/test" dependency-version: 1.60.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-deps - dependency-name: "@sveltejs/kit" dependency-version: 2.59.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-deps - dependency-name: "@sveltejs/vite-plugin-svelte" dependency-version: 7.1.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-deps - dependency-name: "@tauri-apps/cli" dependency-version: 2.11.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-deps - dependency-name: svelte dependency-version: 5.55.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-deps - dependency-name: svelte-check dependency-version: 4.4.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-deps - dependency-name: typescript dependency-version: 6.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-deps - dependency-name: vite dependency-version: 8.0.12 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-deps ... Signed-off-by: dependabot[bot] <support@github.com>
bc86714 to
87dadc9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the dev-deps group with 8 updates in the / directory:
1.59.11.61.02.56.12.67.07.0.07.1.22.10.12.11.35.55.15.56.34.4.64.6.06.0.26.0.38.0.58.0.16Updates
@playwright/testfrom 1.59.1 to 1.61.0Release notes
Sourced from @playwright/test's releases.
... (truncated)
Commits
1cc5a90cherry-pick(#41295): chore: PLAYWRIGHT_TRACING_NO_WEBSOCKET_FRAMES and PLAYWR...a6772bdcherry-pick(#41280): Revert "fix(trace-viewer): add keyboard navigation to `N...8133dcfcherry-pick(#41283): docs: add Ubuntu 26.04 and Node.js 26.x to system requir...812432echore: mark v1.61.0 (#41277)ac05145fix(fetch): report serverAddr and securityDetails for reused sockets (#41267)056efc9fix(trace-viewer): add keyboard navigation toNetworkFilterscomponent (#41...41f7b9achore: fixes uncovered by the .NET 1.61 roll (#41266)ba50778fix(mcp): assign caps as array for legacy --vision flag (#41253)b8ee5aedocs: release notes for v1.61 (#41261)49c1f69fix(trace viewer): load trace from a local file (#41263)Updates
@sveltejs/kitfrom 2.56.1 to 2.67.0Release notes
Sourced from @sveltejs/kit's releases.
... (truncated)
Changelog
Sourced from @sveltejs/kit's changelog.
... (truncated)
Commits
c5d0e83Version Packages (#16086)cf15fa0fix: add handleInvalidUrl prerender option for non-HTTP URL schemes (#16088)2992e17fix: avoid overwritingcodeSplittingfor split apps (#16118)d71dabbchore: fix internal types export target (#16113)7b43b29chore: fix more flaky tests (#16061)5c76121fix: allow optional remote form schema fields under `{exactOptionalPropertyTy...4c9b8f1Version Packages (#16062)276744dfix: preflight schemas apply correctly when chained beforefor(#15863)e8c8d84chore: DRY out __sveltekit_xyz123 stuff (#16085)4eabadcfix: fail early if a route with+pageand+serveris marked as prerendera...Updates
@sveltejs/vite-plugin-sveltefrom 7.0.0 to 7.1.2Release notes
Sourced from @sveltejs/vite-plugin-svelte's releases.
Changelog
Sourced from @sveltejs/vite-plugin-svelte's changelog.
Commits
471f822Version Packages (#1344)1a9bc08fix: always retrieve CSS using component filename first (#1342)508d91bVersion Packages (#1339)990e58cfix: correctly resolve Svelte CSS on the server during development (#1336)d5458a9fix: restore value imports stripped by oxc in script preprocessing (#1326)1c85126Version Packages (#1331)1a4d225feat: enable optimizer for server environments during dev (#1328)d91be5ffix: use correct pnpm catalog syntax4d3afb4chore: fix audit CI (#1327)8b3687buse modern JSDoc imports (#1309)Updates
@tauri-apps/clifrom 2.10.1 to 2.11.3Release notes
Sourced from @tauri-apps/cli's releases.
... (truncated)
Commits
6f6ab12apply version updates (#15409)728c8d4fix(cli): skip building bundles when usingtauri android run(#15473)e25f45crefactor: remove impl clone on inner menus (#15553)fbcf1b0chore(deps): update dependency eslint-plugin-security to v4.0.1 (#15545)828f710fix(cli): respect src/bin required-features (fix: #15325) (#15427)ed8fd41chore(cli): lesser verboseureq_protolog (#15552)50b0237fix(android): escape special characters instrings.xml(#15549)800223ddocs: fix some missing and wrong docs (#15548)5075c81fix: checkis_maximizableininternal_toggle_maximize(#15550)532c22achore(deps-dev): bump vite from 8.0.5 to 8.0.16 (#15547)Updates
sveltefrom 5.55.1 to 5.56.3Release notes
Sourced from svelte's releases.
... (truncated)
Changelog
Sourced from svelte's changelog.
... (truncated)
Commits
a9f4854Version Packages (#18389)71a6515fix: check boundary exists before calling error handler in async derived (#18...3d83c9afix: add bigint to Primitive type for $state.snapshot (#18388)51baf1cVersion Packages (#18357)3d5c4abfix: prevent false-positive reactivity loss warning (#18373)bdb1a0ffix: ensure async block assigns correct nodes to effect (#18371)e4bfc5fchore: bump esrap dependency (#18372)1b4c43bfix: ignore declaration tags for animation directive (#18366)85dcb91chore: upgrade to vitest v4 (#18265)a81f965fix: reject pending async deriveds on discard (#18308)Updates
svelte-checkfrom 4.4.6 to 4.6.0Release notes
Sourced from svelte-check's releases.
Commits
20d5ab2Version Packages (#3040)0ecf6c3fix: adjust rollup config (#3047)151cf45fix: adjust paths in PKG.json (#3046)6099462chore: fix changeset (#3045)5b13da1feat: support reading Svelte config from vite.config.js/ts (#3031)f2bcbdafix: mark optional members with a trailing ? in completion labels (#3043) (#3...e5ed88ffix: don't show type inlay hint for component inside snippets (#3041)b118dd3fix: correct 'occured' typo in svelte:boundary onerror description (#3039)67fbcaeVersion Packages (#3018)3474048fix(emitDts): drop declarations emitted outside declarationDir (#2965)Updates
typescriptfrom 6.0.2 to 6.0.3Release notes
Sourced from typescript's releases.
Commits
050880cBump version to 6.0.3 and LKGeeae9dd🤖 Pick PR #63401 (Also check package name validity in...) into release-6.0 (#...ad1c695🤖 Pick PR #63368 (Harden ATA package name filtering) into release-6.0 (#63372)0725fb4🤖 Pick PR #63310 (Mark class property initializers as...) into release-6.0 (#...Updates
vitefrom 8.0.5 to 8.0.16Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
f94df87release: v8.0.16dc245c7fix: reject windows alternate paths (#22572)50b9512fix(deps): reject UNC paths for launch-editor-middleware (#22571)8d1b019release: v8.0.152686d7dfix(deps): update all non-major dependencies (#22511)3052a67chore(deps): update rolldown-related dependencies (#22566)e3cfb9dfix(optimizer): close the rolldown bundle when write() rejects (#22528)6978a9crefactor: correct logic incollectAllModulesfunction (#22562)646dbedfeat: update rolldown to 1.0.3 (#22538)85a0efffix: capitalize error messages and remove spurious space in parse error (#22488)Greptile Summary
Routine dependabot bump of 8 dev dependencies, all staying within their existing semver ranges. No production dependencies are changed.
vite8.0.5 → 8.0.16 is the most security-relevant update: versions 8.0.15–16 patch path-traversal issues by rejecting UNC paths and Windows alternate device paths in the dev-server'slaunch-editor-middleware.@sveltejs/kit2.56.1 → 2.67.0 brings a run of bug fixes plus two minor features (prerender.handleInvalidUrl,.md/.mdxpre-compression); no breaking changes listed.typescript6.0.2 → 6.0.3 andsvelte/svelte-checkare patch/minor bumps with no breaking changes.Confidence Score: 5/5
Safe to merge — all changes are dev-only dependency version bumps with no breaking changes and a welcome security fix in vite.
All 8 packages are devDependencies that do not ship to end users. The vite 8.0.16 update carries two path-traversal security fixes for the dev server, making the bump actively beneficial. The remaining updates are patch or minor releases with no breaking changes noted in the release notes.
No files require special attention.
Important Files Changed
Flowchart
%%{init: {'theme': 'neutral'}}%% flowchart TD A[dependabot PR] --> B[package.json version range bumps] B --> C[playwright-test 1.59.1 to 1.61.0] B --> D[sveltejs-kit 2.56.1 to 2.67.0] B --> E[vite-plugin-svelte 7.0.0 to 7.1.2] B --> F[svelte 5.55.1 to 5.56.3] B --> G[svelte-check 4.4.6 to 4.6.0] B --> H[typescript 6.0.2 to 6.0.3] B --> I[vite 8.0.5 to 8.0.16 security patches] B --> J[package-lock.json regenerated]%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%% flowchart TD A[dependabot PR] --> B[package.json version range bumps] B --> C[playwright-test 1.59.1 to 1.61.0] B --> D[sveltejs-kit 2.56.1 to 2.67.0] B --> E[vite-plugin-svelte 7.0.0 to 7.1.2] B --> F[svelte 5.55.1 to 5.56.3] B --> G[svelte-check 4.4.6 to 4.6.0] B --> H[typescript 6.0.2 to 6.0.3] B --> I[vite 8.0.5 to 8.0.16 security patches] B --> J[package-lock.json regenerated]Reviews (1): Last reviewed commit: "deps(npm): bump the dev-deps group acros..." | Re-trigger Greptile