Update devDependencies (non-major) - #1404
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
requested review from
lukasIO and
thomasyuill-livekit
as code owners
August 1, 2026 00:57
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
size-limit report 📦
|
renovate
Bot
force-pushed
the
renovate/devdependencies-(non-major)
branch
from
August 1, 2026 13:46
8430efc to
42a4dcd
Compare
renovate
Bot
force-pushed
the
renovate/devdependencies-(non-major)
branch
from
August 1, 2026 13:51
42a4dcd to
7bfd33f
Compare
renovate
Bot
force-pushed
the
renovate/devdependencies-(non-major)
branch
from
August 1, 2026 13:59
7bfd33f to
001d135
Compare
renovate
Bot
force-pushed
the
renovate/devdependencies-(non-major)
branch
from
August 1, 2026 17:48
001d135 to
be7f53c
Compare
renovate
Bot
force-pushed
the
renovate/devdependencies-(non-major)
branch
from
August 2, 2026 18:12
be7f53c to
dcbfd65
Compare
renovate
Bot
force-pushed
the
renovate/devdependencies-(non-major)
branch
from
August 2, 2026 20:49
dcbfd65 to
5d0a9bd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.31.0→2.31.15.8.23→5.8.264.13.0→4.14.14.23.0→4.23.12.10.4→2.10.65.108.4→5.109.0Release Notes
changesets/changesets (@changesets/cli)
v2.31.1Compare Source
Patch Changes
15cf592Thanks @ingvaldlorentzen! - Fixed already-published version detection with npm 12, which always wraps successfulnpm info --jsonoutput in an array. The unwrapped output madechangeset publishtreat every package as unpublished and fail attempting to republish existing versions.vercel/vercel (@vercel/node)
v5.8.26Compare Source
Patch Changes
238543c]v5.8.25Compare Source
Patch Changes
def07fc]v5.8.24Compare Source
Patch Changes
607f0ef]shadcn-ui/ui (shadcn)
v4.14.1Compare Source
Patch Changes
6cd3f4c65c361ab6554e06a77e6a0af9cf8b6e37Thanks @shadcn! - Add Base UI Toast support.v4.14.0Compare Source
Minor Changes
3c26ee2dbd3a772c1cddc2c76249cc1cb0a250d5Thanks @shadcn! - add support for icon migrationv4.13.1Compare Source
Patch Changes
#11196
c49c3061b5b86b130736d36bf20008349f89b416Thanks @shadcn! - Drop custom registry headers on cross-origin redirects to prevent credential leakage.#11191
df2656111fc8ca030eb768ade2da26cef2fd11b5Thanks @shadcn! - Validate file paths for registry items without an explicit target to prevent path traversal.#11195
b8a8e9209659fa810514b61c60ad593bc81973f9Thanks @shadcn! - Prevent flag injection from registry-supplied dependency strings during install.#11208
2b89d67e19ceda27381477e127b349f9aaa25355Thanks @shadcn! - Add React Aria support.privatenumber/tsx (tsx)
v4.23.1Compare Source
Bug Fixes
Performance Improvements
This release is also available on:
vercel/turborepo (turbo)
v2.10.6: Turborepo v2.10.6Compare Source
What's Changed
Changelog
node@runtime:lockfile entries by @anthonyshew in #13408turbo watchby @anthonyshew in #13423New Contributors
Full Changelog: vercel/turborepo@v2.10.5...v2.10.6
v2.10.5: Turborepo v2.10.5Compare Source
What's Changed
Changelog
Toolchainoutput availability by @anthonyshew in #13360New Contributors
Full Changelog: vercel/turborepo@v2.10.4...v2.10.5
webpack/webpack (webpack)
v5.109.0Compare Source
Minor Changes
Default
experiments.typescriptto"auto", enabling built-in TypeScript support on Node.js >= 22.6 when no TypeScript loader is registered. (by @alexander-akait in #21477)Default
experiments.css,experiments.htmlandexperiments.asyncWebAssemblyto"auto", enabling built-in support unless a loader is registered for those files; modules with inline or hook-injected loaders (e.g. html-webpack-plugin templates) keep being parsed as JavaScript. (by @alexander-akait in #21477)Add
output.resourceHintsto emit resource hints (preload/prefetch/modulepreload/preconnect), on by default for ESM output, plusmodule.parser.<type>.urlHints,css.fontPreloadandjavascript.dynamicImportCssPreload. (by @alexander-akait in #21477)Add built-in build progress via
infrastructureLogging.progress, plusestimatedTime,phaseTimings, progress barwidthandprogressBar: "auto"onProgressPlugin. (by @alexander-akait in #21477)Concatenate CommonJS modules with statically analyzable exports; opt out via
optimization.concatenateModules: { commonjs: false }. (by @alexander-akait in #21477)Wrap "weird" CommonJS modules into module concatenation instead of bailing out. (by @alexander-akait in #21477)
Add
output.html.inline(true | "script" | "style") and thewebpackInlinemagic comment to inline chunk content into HTML. (by @alexander-akait in #21477)Add
output.html.injectto control where chunk tags are injected. (by @alexander-akait in #21477)Add
output.html.title,output.html.metaandoutput.html.baseoptions for head generation. (by @alexander-akait in #21477)Support per-icon link attributes (
sizes,media,color,type,crossorigin) and arrays inoutput.html.favicon. (by @alexander-akait in #21487)Add
output.html.manifestto generate and link a web app manifest with hashed icons. (by @alexander-akait in #21487)Add
output.html.cspto inject a Content-Security-Policy meta with inline-content hashes and an optional nonce. (by @alexander-akait in #21487)Add the
output.htmlinjectTagscompilation hook to inject tags (script/link/meta/…) withinjectToplacement. (by @alexander-akait in #21487)Add the
output.htmltransformTagscompilation hook to mutate, remove, or move (between<head>and<body>) a page's existing<script>/<link>/<style>/<meta>tags. (by @alexander-akait in #21487)Extend the HTML pipeline with
htmllink sources (bundled as their own emitted page) andrel="preload"/"prefetch"links bundled as chunks. (by @alexander-akait in #21477)Recognize more asset-bearing HTML sources: the
twitter:player:streammeta, legacy SVG references, and Web App Manifesticons/screenshots/shortcutsURLs. (by @alexander-akait in #21477)Add
module.parser.html.asto parse HTML as a document or an element fragment. (by @alexander-akait in #21477)Allow disabling a built-in HTML parser source via
type: falseinsources. (by @alexander-akait in #21477)Export
webpack.html.HtmlModulesPluginwithtransformHtml/htmlEmittedcompilation hooks. (by @alexander-akait in #21477)Resolve
@custom-media(including media-type values) and@custom-selectorin native CSS. (by @alexander-akait in #21477)Scope
view-transition-name/-group/-classnames and::view-transition-*()pseudo references in CSS modules undercustomIdents. (by @alexander-akait in #21486)Add
import.meta.globsupport, with acaseSensitiveoption and consistent hidden/node_modulesmatching. (by @alexander-akait in #21477)Resolve
import.meta.resolve("./asset")to the emitted asset URL via theimportMeta.resolveparser option. (by @alexander-akait in #21477)Add
import.meta.envdefaults:MODE,DEV,PROD,SSRandBASE_URL. (by @alexander-akait in #21477)Add fine-grained
import.metaparser options. (by @alexander-akait in #21477)Deprecate the
importMetaContextparser option in favor ofimportMeta.webpackContext. (by @alexander-akait in #21477)Emit analyzable
new URL(…, import.meta.url), worker/worklet URL andimport()references with literal specifiers for ESM module output. (by @alexander-akait in #21477)Compile async modules to generators for targets without async/await. (by @alexander-akait in #21477)
Evaluate and validate the second argument of dynamic
import(specifier, options). (by @alexander-akait in #21477)Add
module.parser.javascript.workletto bundle WorkletaddModule()entries. (by @alexander-akait in #21477)Add
?raw,?url,?inlineand?no-inlineasset query suffixes underexperiments.futureDefaults. (by @alexander-akait in #21477)Add an
interop("default" | "esModule") hint for object externals to control default-export interop. (by @alexander-akait in #21477)Add an
amd-asyncexternals type that loads AMD externals without an AMD library wrapper. (by @alexander-akait in #21477)Support
cache.compression: "zstd"for the filesystem cache. (by @alexander-akait in #21477)Warn on strict-mode-only syntax and semantic hazards in ES module output, configurable via the
strictModeViolationsparser option. (by @alexander-akait in #21477)Support parsers without location APIs: locations derive from node offsets and AST nodes no longer carry
loc. (by @alexander-akait in #21477)Attach the original DOM event to
ChunkLoadErrorandScriptExternalLoadErroraserror.event. (by @alexander-akait in #21477)Add
output.wasmStreamingFallbackfor wasm fallback on a wrong MIME type. (by @alexander-akait in #21477)Show why a module was marked as not cacheable in stats output. (by @alexander-akait in #21477)
Expose the active
MultiWatchingonMultiCompiler.watching. (by @alexander-akait in #21477)Resolve git merge conflicts when parsing the build-http lockfile. (by @alexander-akait in #21477)
Patch Changes
Fix broken HMR with
output.moduleand non-importchunk loading by emitting a plain-JSON hot-update manifest. (by @alexander-akait in #21477)Fix unused CSS module exports leaking into the JS wrapper. (by @alexander-akait in #21477)
Fix deferred import evaluation: re-throw cached errors, guard forcing a still-evaluating module, keep re-exported deferred namespaces identical, and evaluate initial-chunk deferred context imports lazily. (by @alexander-akait in #21477)
Keep ESM live bindings for a module library's entry exports, including when the runtime is emitted as a separate chunk. (by @alexander-akait in #21477)
Fix SplitChunks merging undersized modules into the wrong result group. (by @alexander-akait in #21477)
Fix named id assignment reusing an already-used numbered suffix, which could produce duplicate module/chunk ids. (by @alexander-akait in #21477)
Fix inlined non-binary asset modules with
encoding: falseemitting "undefined" instead of their content. (by @alexander-akait in #21477)Decode non-base64 data URIs as UTF-8 so multi-byte characters are preserved. (by @alexander-akait in #21477)
Keep required JSON data intact when a prototype method (e.g.
arr.includes()) is called on it. (by @alexander-akait in #21477)Recognize modern RegExp flags (
d,s,u,v) when statically evaluatingnew RegExp(...). (by @alexander-akait in #21477)Merge object-form and dotted DefinePlugin definitions so
import.meta.env/process.envare consistent across direct, whole-object and destructured access. (by @alexander-akait in #21477)Emit an error when an object external has no entry for the used externals type. (by @alexander-akait in #21477)
Fix a persistent cache restore crash when a content section starts exactly on a content-buffer boundary. (by @alexander-akait in #21477)
Restore missing
internalSerializablesentries (webpack/lib/Module and cold filesystem cache). (by @alexander-akait in #21477)Fix watch rebuild crash when context symlink targets lack
timestampHash. (by @alexander-akait in #21477)Fix lazy compilation backend leaking idle module entries and hanging on exit. (by @alexander-akait in #21477)
Stop logging benign ECONNRESET client errors from the lazy compilation server. (by @alexander-akait in #21477)
Accept compilations from another webpack copy in
getCompilationHooksagain. (by @alexander-akait in #21477)Fix
output.htmlinjection edge cases: escaping, head detection, duplicate meta tags, resource-hint/entry-tag retention withinject: false, and stylesheet placement. (by @alexander-akait in #21477)Ignore a
<base>inside an inert<template>when resolving HTML URLs. (by @alexander-akait in #21477)Bust an HTML page's
[contenthash]when its inlined chunk content changes. (by @alexander-akait in #21477)Fix a dangling stylesheet
<link>for a JS-only chunk in an HTML entry. (by @alexander-akait in #21477)Fix a malformed HTML magic comment leaking a pending
webpackInlinedirective onto the next element. (by @alexander-akait in #21477)Fix off-by-one dropping the last character of an unterminated
url(...)at end-of-input. (by @alexander-akait in #21477)Consume the trailing whitespace of a CSS hex escape when unescaping identifiers. (by @alexander-akait in #21477)
Fix
[fullhash]inoutput.webassemblyModuleFilenameby dropping a stray brace and requesting thegetFullHashruntime module. (by @alexander-akait in #21477)Fix duplicated errors/warnings in stats output when detail-less entries exceed
errorsSpace/warningsSpace. (by @alexander-akait in #21477)Improve module parse errors with a babel-style code frame and the module type. (by @alexander-akait in #21485)
Fix
formatSizerendering sizes of 1 TiB or larger as "undefined". (by @alexander-akait in #21477)Skip the anonymous default export
.namefix-up whennameis non-configurable, instead of throwing on pre-ES2015 engines. (by @alexander-akait in #21477)Escape
?and#in context module regexp identifiers so source map names are not truncated. (by @alexander-akait in #21477)Resolve directory requests to their index module in scoped
DllReferencePlugin. (by @alexander-akait in #21477)Skip the
hasSymbolcheck in the async module runtime whenenvironment.symbolis set. (by @alexander-akait in #21477)Use a shared
__webpack_require__.cjshelper for wrapped CommonJS modules. (by @alexander-akait in #21477)Derive ASI positions from source text instead of acorn's
onInsertedSemicolon, so custom parsers need not collect semicolons. (by @alexander-akait in #21477)Avoid a second full parse for
autosource type by downgrading module to script in place on a top-level return. (by @alexander-akait in #21477)Fix exponential-time side-effects analysis on cyclic module graphs by memoizing cycle-free results via Tarjan lowlink. (by @alexander-akait in #21477)
Speed up JavaScript parsing and AST walking and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up CSS and HTML parsing and code generation and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up snapshot creation and reduce its memory usage. (by @alexander-akait in #21477)
Reduce allocations in JS codegen, concatenation, queues and parser setup. (by @alexander-akait in #21477)
Speed up stats generation on large builds by reusing the item context across array items. (by @alexander-akait in #21477)
Memoize loader resolution per compilation to avoid re-resolving the same loader for every matching module. (by @alexander-akait in #21477)
Reuse and harden webpack's shared resource parser in the loader runner. (by @alexander-akait in #21477)
Update webpack-sources to 3.5.1 and enhanced-resolve to 5.24.2 to cut peak memory. (by @alexander-akait in #21477)
Inline the loader-runner package into core. (by @alexander-akait in #21477)
Fix context hash crash on unsupported directory entries like FIFOs and sockets. (by @hai-x in #21484)
Verify internalSerializables in lint:special and regenerate it in fix:special. (by @alexander-akait in #21476)
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.