Skip to content

fix(deps): update minor updates (minor) - #367

Merged
prisis merged 1 commit into
mainfrom
renovate/minor-updates
Aug 10, 2026
Merged

fix(deps): update minor updates (minor)#367
prisis merged 1 commit into
mainfrom
renovate/minor-updates

Conversation

@renovate

@renovate renovate Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@hono/node-server >=2.0.12>=2.1.0 age confidence
@modelcontextprotocol/sdk@<1.25.2 (source) >=1.29.0>=1.30.0 age confidence
@modelcontextprotocol/sdk@>=1.10.0 <=1.25.3 (source) [>=1.29.0>=1.30.0](https://renovatebot.com/diffs/npm/@modelcontextprotocol%2fsdk@>=1.10.0 <=1.25.3/1.29.0/1.30.0) age confidence
axios@<1.15.0 (source) >=1.17.0>=1.19.0 age confidence
axios@>=1.0.0 <1.15.0 (source) [>=1.17.0>=1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.0.0 <1.15.0/1.17.0/1.19.0) age confidence
axios@>=1.0.0 <1.18.0 (source) [^1.18.1^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.0.0 <1.18.0/1.18.1/1.19.0) age confidence
axios@>=1.0.0 <=1.13.4 (source) [>=1.17.0>=1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.0.0 <=1.13.4/1.17.0/1.19.0) age confidence
axios@>=1.13.0 <1.18.0 (source) [^1.18.1^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.13.0 <1.18.0/1.18.1/1.19.0) age confidence
axios@>=1.15.0 <1.18.0 (source) [^1.18.1^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.15.0 <1.18.0/1.18.1/1.19.0) age confidence
axios@>=1.15.1 <1.18.0 (source) [^1.18.1^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.15.1 <1.18.0/1.18.1/1.19.0) age confidence
axios@>=1.15.2 <1.18.0 (source) [^1.18.1^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.15.2 <1.18.0/1.18.1/1.19.0) age confidence
axios@>=1.7.0 <1.18.0 (source) [^1.18.1^1.19.0](https://renovatebot.com/diffs/npm/axios@>=1.7.0 <1.18.0/1.18.1/1.19.0) age confidence
body-parser@>=2.2.0 <2.2.1 [>=2.2.2>=2.3.0](https://renovatebot.com/diffs/npm/body-parser@>=2.2.0 <2.2.1/2.2.2/2.3.0) age confidence
chrono-node@<2.2.4 >=2.9.2>=2.10.1 age confidence
hono@<4.12.25 (source) >=4.12.34>=4.13.1 age confidence
hono@>=4.0.0 <4.12.27 (source) [^4.12.34^4.13.1](https://renovatebot.com/diffs/npm/hono@>=4.0.0 <4.12.27/4.12.34/4.13.1) age confidence
hono@>=4.11.8 <4.12.27 (source) [^4.12.34^4.13.1](https://renovatebot.com/diffs/npm/hono@>=4.11.8 <4.12.27/4.12.34/4.13.1) age confidence
hono@>=4.3.3 <4.12.27 (source) [^4.12.34^4.13.1](https://renovatebot.com/diffs/npm/hono@>=4.3.3 <4.12.27/4.12.34/4.13.1) age confidence
js-yaml@<=4.1.1 >=4.1.2>=4.3.1 age confidence
lint-staged 17.1.117.3.0 age confidence
markdown-it@>=13.0.0 <14.1.1 [>=14.2.0>=14.3.0](https://renovatebot.com/diffs/npm/markdown-it@>=13.0.0 <14.1.1/14.2.0/14.3.0) age confidence
pnpm (source) 11.8.011.20.0 age confidence
shell-quote@<=1.8.4 ^1.8.5^1.10.0 age confidence
shell-quote@>=1.1.0 <=1.8.3 [^1.8.4^1.10.0](https://renovatebot.com/diffs/npm/shell-quote@>=1.1.0 <=1.8.3/1.8.4/1.10.0) age confidence
taze 19.16.019.17.2 age confidence
undici@<6.23.0 (source) >=8.5.0>=8.10.0 age confidence
undici@<6.24.0 (source) >=8.5.0>=8.10.0 age confidence
undici@>=6.0.0 <6.24.0 (source) [>=8.5.0>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=6.0.0 <6.24.0/8.5.0/8.10.0) age confidence
undici@>=7.0.0 <7.18.2 (source) [>=8.5.0>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=7.0.0 <7.18.2/8.5.0/8.10.0) age confidence
undici@>=7.0.0 <7.24.0 (source) [>=8.5.0>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=7.0.0 <7.24.0/8.5.0/8.10.0) age confidence
undici@>=7.17.0 <7.24.0 (source) [>=8.5.0>=8.10.0](https://renovatebot.com/diffs/npm/undici@>=7.17.0 <7.24.0/8.5.0/8.10.0) age confidence
yargs (source) 18.0.018.1.0 age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

honojs/node-server (@​hono/node-server)

v2.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/node-server@v2.0.12...v2.1.0

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk@<1.25.2)

v1.30.0

Compare Source

axios/axios (axios@<1.15.0)

v1.19.0

Compare Source

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

v1.18.1

Compare Source

v1.18.1 — June 21, 2026

This release focuses on Node HTTP adapter fixes, safer AxiosError serialisation, runtime/type correctness fixes, documentation updates, and dependency maintenance.

🐛 Bug Fixes

  • AxiosError Serialisation: Made AxiosError#cause non-enumerable to prevent circular JSON serialisation failures when errors include nested causes. (#​10913)
  • Node HTTP Adapter: Guarded socket.setKeepAlive for proxy agent streams, accepted path-only URLs when socketPath is configured, deferred environment proxy handling to Node, and explicitly passed maxBodyLength through to follow-redirects. (#​10917, #​10930, #​10942, #​10993)
  • Runtime and Type Correctness: Fixed several runtime crashes, type definition mismatches, and incorrect error handling paths. (#​10959, #​11021)
  • AxiosURLSearchParams: Switched the encoder callback to an arrow function so encoder.call(this) receives the AxiosURLSearchParams instance correctly. (#​11019)

🔧 Maintenance & Chores

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog

v1.18.0

Compare Source

This release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.

expressjs/body-parser (body-parser@>=2.2.0 <2.2.1)

v2.3.0

Compare Source

========================

  • fix: use static exports instead of lazy getters to improve ESM compatibility
  • feat: add subpath exports for individual parsers
  • fix: improve limit option validation (#​698)
    • Invalid limit values (e.g. unparseable strings or NaN) now throw instead of being silently ignored, which previously disabled size limit enforcement
    • null and undefined fall back to the default 100kb limit
  • deps:
    • content-type@^2.0.0
    • http-errors@^2.0.1
    • iconv-lite^0.7.2
    • qs@^6.15.2
    • raw-body@^3.0.2
    • type-is@^2.1.0
wanasit/chrono (chrono-node@<2.2.4)

v2.10.1

Compare Source

  • New: support Italian (it) relative times, timezone offsets, and improve Italian language parsing a0ac654
  • fix(en): support all 2-digit years in month name little endian parser (fixes #​163) f15d1a8
  • fix(fr): support standard month name abbreviations and accented variants (issue #​293) 41ee4e8

v2.10.0

Compare Source

Minor version changes:


honojs/hono (hono@<4.12.25)

v4.13.1

Compare Source

v4.13.0

Compare Source

Hono v4.13.0 is now available!

The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.

Performance improvements

This release includes a series of small optimizations: skipping unnecessary Headers allocations, replacing regex tests with indexOf, allocating internal state lazily, and more.

Here is benchmarks/fetch comparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):

Benchmark v4.12 v4.13 Speedup
pingGET / 165.83 ns 163.99 ns 1.01x
queryGET /id/1?name=bun 674.40 ns 616.99 ns 1.09x
jsonGET /user 528.99 ns 422.44 ns 1.25x
bodyPOST /json 1.16 µs 1.00 µs 1.15x

The individual changes:

  • perf(context): iterate the header record with for..in #​5118
  • perf(url): replace regex tests with indexOf #​5121
  • perf(context): skip Headers creation when there are no headers to merge #​5122
  • perf(urls): refactor tryDecodeURIComponent #​5158
  • perf(request): allocate #validatedData lazily #​5175
  • perf(request): probe the body cache without allocating #​5176

In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.

Thanks @​kibertoad for the contributions!

First-class QUERY method support

The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with app.query():

const app = new Hono()

app.query('/search', async (c) => {
  const conditions = await c.req.json()
  return c.json(await search(conditions))
})

Thanks @​shellhaki!

QUERY support across built-in middleware

The built-in middleware has been updated to handle QUERY requests properly:

Cache Middleware

The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately:

app.query(
  '/search',
  cache({
    cacheName: 'search-cache',
    cacheControl: 'max-age=3600',
  })
)

Note: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form /.hono/cache?__hono_cache_key=.... If you purge cache entries by URL outside of the middleware (e.g. calling caches.delete() with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched.

ETag Middleware

The ETag Middleware now handles conditional requests for QUERY, returning 304 Not Modified when If-None-Match matches.

CORS Middleware

The CORS Middleware now includes QUERY in the default Access-Control-Allow-Methods, which is now GET, HEAD, PUT, POST, DELETE, PATCH, QUERY. If you specify allowMethods explicitly, nothing changes for you.

Thanks @​usualoma and @​Cherry!

Method Not Allowed Middleware

The new Method Not Allowed Middleware returns a 405 Method Not Allowed response with a proper Allow header when the request path matches a registered route but the method does not:

import { methodNotAllowed } from 'hono/method-not-allowed'

const app = new Hono()

app.use(methodNotAllowed({ app }))

app.get('/hello', (c) => c.text('Hello!'))
app.post('/hello', (c) => c.text('Posted!'))

// PUT /hello -> 405 Method Not Allowed
// Allow: GET, HEAD, POST

You can customize the response with the onMethodNotAllowed option:

app.use(
  methodNotAllowed({
    app,
    onMethodNotAllowed: (c, methods) =>
      c.json({ error: 'Method Not Allowed' }, 405, { Allow: methods.join(', ') }),
  })
)

Thanks @​usualoma!

RegExpRouter throws UnsupportedPathError at registration time

The RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster.

Thanks @​usualoma!

Other improvements

  • hono/utils/headers has been synced with the IANA HTTP Field Name Registry, adding newly registered fields such as Accept-Query. Thanks @​akahoshi1421!
  • The JWT and JWK middleware now accept a realm option for the WWW-Authenticate challenge on 401 responses, and challenge values are properly escaped. Thanks @​arhxam!
  • JSX: useRef and RefObject are now aligned with React 19. Note that this is a type-level change — RefObject<T> is now { current: T }, so type a nullable ref as RefObject<T | null>, and pass useRef(undefined) instead of useRef(). Thanks @​ashunar0!
  • JSX: a function component can now return an array of children without throwing during server-side rendering. Thanks @​natsuki-engr!
  • The Compress Middleware now sets Vary: Accept-Encoding on negotiated responses. Thanks @​arhxam!

All changes

Full Changelog: honojs/hono@v4.12.34...v4.13.0

Thank you to all contributors!

nodeca/js-yaml (js-yaml@<=4.1.1)

v4.3.1

Compare Source

v4.3.0

Compare Source

lint-staged/lint-staged (lint-staged)

v17.3.0

Compare Source

Minor Changes
  • #​1825 16b3f74 - It is now possible to run multiple tasks in parallel for a single glob by configuring it with an array of tasks (which run sequentially), and then placing another array inside it (where the tasks will run in parallel). The following demonstrates the order tasks will start in:

    {
      "*.ts": ["first", "second", ["third", "third"], "fourth"]
    }

    As a concrete example, lint-staged's own configuration is:

    /** @type {import('./lib/index.js').Configuration} */
    export default {
      "*": [
        [
          "oxfmt --check --no-error-on-unmatched-pattern",
          "oxlint --no-error-on-unmatched-pattern",
        ],
      ],
      "*.ts": () => "tsc",
    };

    which means:

    1. for all staged files, run the two commands in parallel with staged filenames appended, for example:
      • oxfmt --check --no-error-on-unmatched-pattern lib/index.js
      • oxlint --no-error-on-unmatched-pattern lib/index.js
    2. additionally, if any *.ts files are staged, run tsc without appending any arguments
    3. The two sets of commands also run in parallel
Patch Changes
  • #​1829 15f7e53 - During an in-progress merge, files that are unchanged from the branch being merged are now skipped. Technically, files are only included if there are staged changes against both HEAD and MERGE_HEAD.

v17.2.0

Compare Source

Minor Changes
  • #​1823 ee156cc - The chunking of tasks based on maximum command line argument length has been re-implemented to be more precise. Now the chunking happens based on the final generated command string, instead of just the list of staged files like previously. This benefits mainly Windows platforms and function commands like:

    /** @type {import('lint-staged').Configuration} */
    export default {
      "*.ts": () => "tsc", // Run "tsc" when any TS file is changed (for entire project)
    };

    Where the spawned command is literally "tsc" without any extra arguments. Previously, this was still chunked when a lot of files were staged. Now, it probably won't be chunked because the length of the command is just three letters.

    Also, native JavaScript/Node.js function tasks won't be chunked at all, when previously they were run multiple times when chunked:

    /** @type {import('lint-staged').Configuration} */
    export default {
      "*.js": {
        title: "Log staged JS files to console",
        task: async (files) => {
          console.log("Staged JS files:", files);
        },
      },
    };
markdown-it/markdown-it (markdown-it@>=13.0.0 <14.1.1)

v14.3.0

Compare Source

Changed
  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.
Fixed
  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #​1185.
pnpm/pnpm (pnpm)

v11.20.0: pnpm 11.20

Compare Source

Minor Changes

  • Security fix. Affects projects using namedRegistries on pnpm 11.1.0–11.19.x. It is semi-breaking for those projects — see "If you use named registries" below.

    The lockfile recorded no marker for which registry a package came from. Packages were keyed by name@version alone, and entry lookup went through refToRelative(ref, name), so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a single packages: entry and whichever resolved first decided the tarball every consumer got.

    That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell.

    Packages resolved from a named registry are now recorded under registry-qualified keys (<name>@<registryName>:<version>, e.g. foo@work:1.0.0), so each registry gets its own entry and the lockfile pins which one a dependency came from.

    The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use namedRegistries sees no difference, and older pnpm versions keep reading the file.

If you use named registries

Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating.

Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it.

There is no setting to keep the old behavior: the old shape is the vulnerability.

Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the namedRegistries setting on demand.

To use named registries, map your aliases in pnpm-workspace.yaml:

namedRegistries:
  work: https://npm.enterprise.example.com/
New built-in npmjs: alias

npmjs: now resolves to https://registry.npmjs.org/ with no configuration, alongside the existing gh: alias for GitHub Packages. It pins a dependency to the public registry even when registry points elsewhere, such as an internal proxy:

{ "dependencies": { "left-pad": "npmjs:^1.3.0" } }

npm: cannot do this — it is the alias protocol (npm:<name>@<range>) and resolves through whatever registry points at.

If you mirror or proxy npmjs, point the alias at your mirror:

namedRegistries:
  npmjs: https://npm.internal.example.com/

Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on registry.npmjs.org is verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL, minimumReleaseAge, or trustPolicy check runs. Overriding the alias is the same escape hatch GHES users already have for gh.

Every alias the lockfile references must stay in namedRegistries: reading an entry whose alias is gone fails with ERR_PNPM_MISSING_NAMED_REGISTRY rather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it.

Named registry aliases that shadow a reserved dependency specifier prefix (file, link, workspace, runtime, npm, jsr, ...) are now rejected with ERR_PNPM_RESERVED_NAMED_REGISTRY_NAME instead of being silently shadowed by the corresponding resolver.

pnpm licenses and pnpm sbom now keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purl repository_url qualifier.

Patch Changes

  • An empty http-proxy, https-proxy, proxy, or no-proxy value — from the .npmrc, pnpm-workspace.yaml, the CLI, or the HTTP_PROXY / HTTPS_PROXY / PROXY / NO_PROXY environment variables — no longer fails the install with ERR_PNPM_INVALID_PROXY. Empty settings read as unset, so a shell exporting HTTP_PROXY= disables the proxy, and an empty proxy= in the .npmrc no longer suppresses HTTPS_PROXY #​13533.

    proxy=false in the .npmrc or proxy: false in pnpm-workspace.yaml now turns proxying off instead of being read as a proxy host named false. false and null on https-proxy / http-proxy / no-proxy read as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim.

  • The env lockfile no longer pins @pnpm/exe alongside pnpm when the wanted pnpm version is 12 or newer. From v12 the unscoped pnpm package is itself the native executable, so @pnpm/exe is not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it.

  • lexCompare and nerfDart are now published as @pnpm/text.ordinal-comparator and @pnpm/config.registry-auth-key. Use these instead of @pnpm/util.lex-comparator and @pnpm/config.nerf-dart.

  • Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs.

  • Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when minimumReleaseAge is active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison.

  • Security: pnpm rebuild now refuses a lockfile whose packages key carries a path traversal in the package name (e.g. ../../../escaped@1.0.0), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected with ERR_PNPM_INVALID_DEPENDENCY_NAME.

Platinum Sponsors

Bit
OpenAI

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx

v11.19.0: pnpm 11.19

Compare Source

Minor Changes

  • pnpm login no longer requires an interactive terminal when the registry supports web-based login: without a TTY it prints the authentication URL (skipping the QR code and the "Press ENTER to open the URL in your browser" prompt) and polls the registry until the browser approval completes. Only the classic username/password login still fails with ERR_PNPM_LOGIN_NON_INTERACTIVE in a non-interactive terminal.

  • The save-prefix setting now accepts =: newly added dependencies are saved with an explicit = operator (=1.2.3) instead of the setting being silently treated as the default ^.

Patch Changes

  • allowBuilds entries can now approve git-hosted packages that pnpm downloads as a tarball, such as github: dependencies (which are fetched from codeload.github.com rather than cloned), by their repository URL without the resolved commit hash. This matches the hashless git+ matching already supported for cloned git dependencies. For example:

    allowBuilds:
      "foo@git+https://github.com/org/foo.git": true

    This approves the package whether pnpm clones it or downloads a tarball, so the entry no longer has to be updated every time the pinned commit changes. GitLab and Bitbucket tarball downloads are matched the same way. Approving or denying a specific resolved commit by its full tarball dep path continues to work.

  • pnpm outdated --include-github-actions no longer blocks on an interactive git credential prompt when a workflow uses a private action repo.

  • Prevented minimumReleaseAge from replacing latest with a SemVer-greater version than the registry tag target #​13034.

  • Fixed empty bundledDependencies and bundleDependencies arrays causing nondeterministic lockfile changes. See #​13123.

  • The install summary no longer prints (X is available) when the registry's dist-tags.latest is still held back by the active minimumReleaseAge policy. The hint only ever names the actual latest tag, so an immature latest suppresses the hint instead of advertising the version pnpm just refused to install #​11698.

  • pnpm update keeps the explicit = operator of an exact version pin: a dependency saved as =3.5.1 now updates to =3.5.2 instead of the bare 3.5.2. See #​13168.

  • Preserve a workspace dependency's link: entry when a run does not target it — e.g. pnpm update <other-pkg> (with or without --recursive), or a plain install after a root/catalog dependency change — with injectWorkspacePackages, instead of spuriously rewriting it to a peer-suffixed file: protocol. See #​10433.

  • Workspace dependencies declared with a relative path (e.g. "foo": "workspace:../foo") are no longer silently dropped from the workspace projects graph, so --filter selection and the topological order of recursive commands take them into account.

Platinum Sponsors

Bit
OpenAI

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from prisis as a code owner July 23, 2026 14:00
@renovate renovate Bot added the c: dependencies Pull requests that adds/updates a dependency label Jul 23, 2026
@renovate
renovate Bot enabled auto-merge July 23, 2026 14:00
@github-actions

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@pkg-pr-new

pkg-pr-new Bot commented Jul 23, 2026

Copy link
Copy Markdown

Open in StackBlitz

@anolilab/multi-semantic-release

npm i https://pkg.pr.new/@anolilab/multi-semantic-release@367

@anolilab/rc

npm i https://pkg.pr.new/@anolilab/rc@367

@anolilab/semantic-release-clean-package-json

npm i https://pkg.pr.new/@anolilab/semantic-release-clean-package-json@367

@anolilab/semantic-release-pnpm

npm i https://pkg.pr.new/@anolilab/semantic-release-pnpm@367

@anolilab/semantic-release-preset

npm i https://pkg.pr.new/@anolilab/semantic-release-preset@367

commit: 14062fc

@renovate
renovate Bot force-pushed the renovate/minor-updates branch 5 times, most recently from 9784313 to 80d798b Compare July 27, 2026 09:48
@socket-security

socket-security Bot commented Jul 27, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedyargs@​18.1.09910010092100
Addedlint-staged@​17.3.010010010097100

View full report

@renovate
renovate Bot force-pushed the renovate/minor-updates branch 3 times, most recently from d364689 to 37c260f Compare July 31, 2026 10:05
@renovate
renovate Bot force-pushed the renovate/minor-updates branch 12 times, most recently from c6fcf89 to 3a482ea Compare August 10, 2026 10:28
Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate
renovate Bot force-pushed the renovate/minor-updates branch from 3a482ea to 1392b25 Compare August 10, 2026 10:34
@prisis
prisis merged commit ae5470d into main Aug 10, 2026
17 of 33 checks passed
@prisis
prisis deleted the renovate/minor-updates branch August 10, 2026 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c: dependencies Pull requests that adds/updates a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant