fix(deps): update minor updates (minor) - #367
Merged
Merged
Conversation
Contributor
|
Thank you for following the naming conventions! 🙏 |
@anolilab/multi-semantic-release
@anolilab/rc
@anolilab/semantic-release-clean-package-json
@anolilab/semantic-release-pnpm
@anolilab/semantic-release-preset
commit: |
renovate
Bot
force-pushed
the
renovate/minor-updates
branch
5 times, most recently
from
July 27, 2026 09:48
9784313 to
80d798b
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
renovate
Bot
force-pushed
the
renovate/minor-updates
branch
3 times, most recently
from
July 31, 2026 10:05
d364689 to
37c260f
Compare
renovate
Bot
force-pushed
the
renovate/minor-updates
branch
12 times, most recently
from
August 10, 2026 10:28
c6fcf89 to
3a482ea
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
renovate
Bot
force-pushed
the
renovate/minor-updates
branch
from
August 10, 2026 10:34
3a482ea to
1392b25
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=2.0.12→>=2.1.0>=1.29.0→>=1.30.0>=1.29.0→>=1.30.0](https://renovatebot.com/diffs/npm/@modelcontextprotocol%2fsdk@>=1.10.0 <=1.25.3/1.29.0/1.30.0)>=1.17.0→>=1.19.0>=1.17.0→>=1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.0.0 <1.15.0/1.17.0/1.19.0)^1.18.1→^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.0.0 <1.18.0/1.18.1/1.19.0)>=1.17.0→>=1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.0.0 <=1.13.4/1.17.0/1.19.0)^1.18.1→^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.13.0 <1.18.0/1.18.1/1.19.0)^1.18.1→^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.15.0 <1.18.0/1.18.1/1.19.0)^1.18.1→^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.15.1 <1.18.0/1.18.1/1.19.0)^1.18.1→^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.15.2 <1.18.0/1.18.1/1.19.0)^1.18.1→^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.7.0 <1.18.0/1.18.1/1.19.0)>=2.2.2→>=2.3.0](https://renovatebot.com/diffs/npm/body-parser@>=2.2.0 <2.2.1/2.2.2/2.3.0)>=2.9.2→>=2.10.1>=4.12.34→>=4.13.1^4.12.34→^4.13.1](https://renovatebot.com/diffs/npm/hono@>=4.0.0 <4.12.27/4.12.34/4.13.1)^4.12.34→^4.13.1](https://renovatebot.com/diffs/npm/hono@>=4.11.8 <4.12.27/4.12.34/4.13.1)^4.12.34→^4.13.1](https://renovatebot.com/diffs/npm/hono@>=4.3.3 <4.12.27/4.12.34/4.13.1)>=4.1.2→>=4.3.117.1.1→17.3.0>=14.2.0→>=14.3.0](https://renovatebot.com/diffs/npm/markdown-it@>=13.0.0 <14.1.1/14.2.0/14.3.0)11.8.0→11.20.0^1.8.5→^1.10.0^1.8.4→^1.10.0](https://renovatebot.com/diffs/npm/shell-quote@>=1.1.0 <=1.8.3/1.8.4/1.10.0)19.16.0→19.17.2>=8.5.0→>=8.10.0>=8.5.0→>=8.10.0>=8.5.0→>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=6.0.0 <6.24.0/8.5.0/8.10.0)>=8.5.0→>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=7.0.0 <7.18.2/8.5.0/8.10.0)>=8.5.0→>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=7.0.0 <7.24.0/8.5.0/8.10.0)>=8.5.0→>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=7.17.0 <7.24.0/8.5.0/8.10.0)18.0.0→18.1.0bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
honojs/node-server (@hono/node-server)
v2.1.0Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v2.0.12...v2.1.0
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk@<1.25.2)
v1.30.0Compare Source
axios/axios (axios@<1.15.0)
v1.19.0Compare Source
This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.
v1.18.1Compare Source
v1.18.1 — June 21, 2026
This release focuses on Node HTTP adapter fixes, safer AxiosError serialisation, runtime/type correctness fixes, documentation updates, and dependency maintenance.
🐛 Bug Fixes
encoder.call(this)receives theAxiosURLSearchParamsinstance correctly. (#11019)🔧 Maintenance & Chores
Documentation: Documented sensitive headers and status transition behaviour, prepared cleaned-up docs, added Deno install instructions, and clarified that request data is request-specific (#11007, #11010, #11023, #11025)
Dependencies: Bumped vite, rollup, form-data, js-yaml, and multer across the root project, docs, smoke tests, and module test workspaces. (#11011, #11012, #11013, #11014, #11015, #11016, #11017, #11026)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
Full Changelog
v1.18.0Compare Source
This release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.
expressjs/body-parser (body-parser@>=2.2.0 <2.2.1)
v2.3.0Compare Source
========================
limitoption validation (#698)limitvalues (e.g. unparseable strings orNaN) now throw instead of being silently ignored, which previously disabled size limit enforcementnullandundefinedfall back to the default 100kb limitwanasit/chrono (chrono-node@<2.2.4)
v2.10.1Compare Source
it) relative times, timezone offsets, and improve Italian language parsinga0ac654f15d1a841ee4e8v2.10.0Compare Source
Minor version changes:
5b13e0a)distandsrc(668509f) reported by @JounQin on #647honojs/hono (hono@<4.12.25)
v4.13.1Compare Source
v4.13.0Compare Source
Hono v4.13.0 is now available!
The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.
Performance improvements
This release includes a series of small optimizations: skipping unnecessary
Headersallocations, replacing regex tests withindexOf, allocating internal state lazily, and more.Here is
benchmarks/fetchcomparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):ping—GET /query—GET /id/1?name=bunjson—GET /userbody—POST /jsonThe individual changes:
for..in#5118indexOf#5121Headerscreation when there are no headers to merge #5122tryDecodeURIComponent#5158#validatedDatalazily #5175In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.
Thanks @kibertoad for the contributions!
First-class QUERY method support
The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with
app.query():Thanks @shellhaki!
QUERY support across built-in middleware
The built-in middleware has been updated to handle QUERY requests properly:
Cache Middleware
The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately:
Note: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form
/.hono/cache?__hono_cache_key=.... If you purge cache entries by URL outside of the middleware (e.g. callingcaches.delete()with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched.ETag Middleware
The ETag Middleware now handles conditional requests for QUERY, returning
304 Not ModifiedwhenIf-None-Matchmatches.CORS Middleware
The CORS Middleware now includes QUERY in the default
Access-Control-Allow-Methods, which is nowGET, HEAD, PUT, POST, DELETE, PATCH, QUERY. If you specifyallowMethodsexplicitly, nothing changes for you.Thanks @usualoma and @Cherry!
Method Not Allowed Middleware
The new Method Not Allowed Middleware returns a
405 Method Not Allowedresponse with a properAllowheader when the request path matches a registered route but the method does not:You can customize the response with the
onMethodNotAllowedoption:Thanks @usualoma!
RegExpRouter throws
UnsupportedPathErrorat registration timeThe RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster.
Thanks @usualoma!
Other improvements
hono/utils/headershas been synced with the IANA HTTP Field Name Registry, adding newly registered fields such asAccept-Query. Thanks @akahoshi1421!realmoption for theWWW-Authenticatechallenge on401responses, and challenge values are properly escaped. Thanks @arhxam!useRefandRefObjectare now aligned with React 19. Note that this is a type-level change —RefObject<T>is now{ current: T }, so type a nullable ref asRefObject<T | null>, and passuseRef(undefined)instead ofuseRef(). Thanks @ashunar0!Vary: Accept-Encodingon negotiated responses. Thanks @arhxam!All changes
fetchby @yusukebe in #5113indexOfby @yusukebe in #5121tryDecodeURIComponentby @yusukebe in #5158envfield initializer by @kibertoad in #5174#validatedDatalazily by @kibertoad in #5175fetchby @yusukebe in #5184envfield initializer by @yusukebe in #5186Full Changelog: honojs/hono@v4.12.34...v4.13.0
Thank you to all contributors!
nodeca/js-yaml (js-yaml@<=4.1.1)
v4.3.1Compare Source
v4.3.0Compare Source
lint-staged/lint-staged (lint-staged)
v17.3.0Compare Source
Minor Changes
#1825
16b3f74- It is now possible to run multiple tasks in parallel for a single glob by configuring it with an array of tasks (which run sequentially), and then placing another array inside it (where the tasks will run in parallel). The following demonstrates the order tasks will start in:{ "*.ts": ["first", "second", ["third", "third"], "fourth"] }As a concrete example, lint-staged's own configuration is:
which means:
oxfmt --check --no-error-on-unmatched-pattern lib/index.jsoxlint --no-error-on-unmatched-pattern lib/index.js*.tsfiles are staged, runtscwithout appending any argumentsPatch Changes
15f7e53- During an in-progress merge, files that are unchanged from the branch being merged are now skipped. Technically, files are only included if there are staged changes against bothHEADandMERGE_HEAD.v17.2.0Compare Source
Minor Changes
#1823
ee156cc- The chunking of tasks based on maximum command line argument length has been re-implemented to be more precise. Now the chunking happens based on the final generated command string, instead of just the list of staged files like previously. This benefits mainly Windows platforms and function commands like:Where the spawned command is literally
"tsc"without any extra arguments. Previously, this was still chunked when a lot of files were staged. Now, it probably won't be chunked because the length of the command is just three letters.Also, native JavaScript/Node.js function tasks won't be chunked at all, when previously they were run multiple times when chunked:
markdown-it/markdown-it (markdown-it@>=13.0.0 <14.1.1)
v14.3.0Compare Source
Changed
linkify-itto 5.0.2.Fixed
pnpm/pnpm (pnpm)
v11.20.0: pnpm 11.20Compare Source
Minor Changes
Security fix. Affects projects using
namedRegistrieson pnpm 11.1.0–11.19.x. It is semi-breaking for those projects — see "If you use named registries" below.The lockfile recorded no marker for which registry a package came from. Packages were keyed by
name@versionalone, and entry lookup went throughrefToRelative(ref, name), so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a singlepackages:entry and whichever resolved first decided the tarball every consumer got.That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell.
Packages resolved from a named registry are now recorded under registry-qualified keys (
<name>@<registryName>:<version>, e.g.foo@work:1.0.0), so each registry gets its own entry and the lockfile pins which one a dependency came from.The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use
namedRegistriessees no difference, and older pnpm versions keep reading the file.If you use named registries
Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating.
Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it.
There is no setting to keep the old behavior: the old shape is the vulnerability.
Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the
namedRegistriessetting on demand.To use named registries, map your aliases in
pnpm-workspace.yaml:New built-in
npmjs:aliasnpmjs:now resolves tohttps://registry.npmjs.org/with no configuration, alongside the existinggh:alias for GitHub Packages. It pins a dependency to the public registry even whenregistrypoints elsewhere, such as an internal proxy:{ "dependencies": { "left-pad": "npmjs:^1.3.0" } }npm:cannot do this — it is the alias protocol (npm:<name>@<range>) and resolves through whateverregistrypoints at.If you mirror or proxy npmjs, point the alias at your mirror:
Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on
registry.npmjs.orgis verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL,minimumReleaseAge, ortrustPolicycheck runs. Overriding the alias is the same escape hatch GHES users already have forgh.Every alias the lockfile references must stay in
namedRegistries: reading an entry whose alias is gone fails withERR_PNPM_MISSING_NAMED_REGISTRYrather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it.Named registry aliases that shadow a reserved dependency specifier prefix (
file,link,workspace,runtime,npm,jsr, ...) are now rejected withERR_PNPM_RESERVED_NAMED_REGISTRY_NAMEinstead of being silently shadowed by the corresponding resolver.pnpm licensesandpnpm sbomnow keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purlrepository_urlqualifier.Patch Changes
An empty
http-proxy,https-proxy,proxy, orno-proxyvalue — from the.npmrc,pnpm-workspace.yaml, the CLI, or theHTTP_PROXY/HTTPS_PROXY/PROXY/NO_PROXYenvironment variables — no longer fails the install withERR_PNPM_INVALID_PROXY. Empty settings read as unset, so a shell exportingHTTP_PROXY=disables the proxy, and an emptyproxy=in the.npmrcno longer suppressesHTTPS_PROXY#13533.proxy=falsein the.npmrcorproxy: falseinpnpm-workspace.yamlnow turns proxying off instead of being read as a proxy host namedfalse.falseandnullonhttps-proxy/http-proxy/no-proxyread as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim.The env lockfile no longer pins
@pnpm/exealongsidepnpmwhen the wanted pnpm version is 12 or newer. From v12 the unscopedpnpmpackage is itself the native executable, so@pnpm/exeis not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it.lexCompareandnerfDartare now published as@pnpm/text.ordinal-comparatorand@pnpm/config.registry-auth-key. Use these instead of@pnpm/util.lex-comparatorand@pnpm/config.nerf-dart.Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs.
Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when
minimumReleaseAgeis active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison.Security:
pnpm rebuildnow refuses a lockfile whosepackageskey carries a path traversal in the package name (e.g.../../../escaped@1.0.0), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected withERR_PNPM_INVALID_DEPENDENCY_NAME.Platinum Sponsors
Gold Sponsors
v11.19.0: pnpm 11.19Compare Source
Minor Changes
pnpm loginno longer requires an interactive terminal when the registry supports web-based login: without a TTY it prints the authentication URL (skipping the QR code and the "Press ENTER to open the URL in your browser" prompt) and polls the registry until the browser approval completes. Only the classic username/password login still fails withERR_PNPM_LOGIN_NON_INTERACTIVEin a non-interactive terminal.The
save-prefixsetting now accepts=: newly added dependencies are saved with an explicit=operator (=1.2.3) instead of the setting being silently treated as the default^.Patch Changes
allowBuildsentries can now approve git-hosted packages that pnpm downloads as a tarball, such asgithub:dependencies (which are fetched fromcodeload.github.comrather than cloned), by their repository URL without the resolved commit hash. This matches the hashlessgit+matching already supported for cloned git dependencies. For example:This approves the package whether pnpm clones it or downloads a tarball, so the entry no longer has to be updated every time the pinned commit changes. GitLab and Bitbucket tarball downloads are matched the same way. Approving or denying a specific resolved commit by its full tarball dep path continues to work.
pnpm outdated --include-github-actionsno longer blocks on an interactive git credential prompt when a workflow uses a private action repo.Prevented
minimumReleaseAgefrom replacinglatestwith a SemVer-greater version than the registry tag target #13034.Fixed empty
bundledDependenciesandbundleDependenciesarrays causing nondeterministic lockfile changes. See #13123.The install summary no longer prints
(X is available)when the registry'sdist-tags.latestis still held back by the activeminimumReleaseAgepolicy. The hint only ever names the actual latest tag, so an immature latest suppresses the hint instead of advertising the version pnpm just refused to install #11698.pnpm updatekeeps the explicit=operator of an exact version pin: a dependency saved as=3.5.1now updates to=3.5.2instead of the bare3.5.2. See #13168.Preserve a workspace dependency's
link:entry when a run does not target it — e.g.pnpm update <other-pkg>(with or without--recursive), or a plain install after a root/catalog dependency change — withinjectWorkspacePackages, instead of spuriously rewriting it to a peer-suffixedfile:protocol. See #10433.Workspace dependencies declared with a relative path (e.g.
"foo": "workspace:../foo") are no longer silently dropped from the workspace projects graph, so--filterselection and the topological order of recursive commands take them into account.Platinum Sponsors
Gold Sponsors
This PR was generated by Mend Renovate. View the repository job log.