Skip to content

fix(deps): update dependencies (non-major)#283

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies-non-major
Open

fix(deps): update dependencies (non-major)#283
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies-non-major

Conversation

@renovate

@renovate renovate Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@fortawesome/react-fontawesome 3.3.03.3.1 age confidence
cron-parser 5.5.05.6.0 age confidence
cronstrue (source) 3.14.03.20.0 age confidence
dotenv 17.4.117.4.2 age confidence
openid-client 6.8.26.8.4 age confidence
react (source) 19.2.419.2.7 age confidence
react-dom (source) 19.2.419.2.7 age confidence
react-router-dom (source) 7.14.07.18.0 age confidence
yaml (source) 2.8.32.9.0 age confidence

Release Notes

FortAwesome/react-fontawesome (@​fortawesome/react-fontawesome)

v3.3.1

Compare Source

Chores
  • deps-dev: bump handlebars from 4.7.8 to 4.7.9 (f1d6d94)
  • deps-dev: bump lodash-es from 4.17.23 to 4.18.1 (212496a)
  • deps-dev: bump picomatch from 2.3.1 to 2.3.2 (557ceaf)
  • deps: bump lodash from 4.17.23 to 4.18.1 (2d06890)
  • deps: node 22.22.2, bump all dev dependencies (99ba500)
harrisiirak/cron-parser (cron-parser)

v5.6.0

Compare Source

What's Changed

New Contributors

Full Changelog: harrisiirak/cron-parser@v5.5.0...v5.6.0

bradymholt/cRonstrue (cronstrue)

v3.20.0

Compare Source

Full Changelog: bradymholt/cRonstrue@v3.19.0...v3.20.0

v3.19.0

Compare Source

What's Changed

Full Changelog: bradymholt/cRonstrue@v3.18.0...v3.19.0

v3.18.0

Compare Source

What's Changed

Full Changelog: bradymholt/cRonstrue@v3.16.0...v3.18.0

motdotla/dotenv (dotenv)

v17.4.2

Compare Source

Changed
  • Improved skill files - tightened up details (#​1009)
panva/openid-client (openid-client)

v6.8.4

Compare Source

Fixes
  • apply optional non-repudiation on generic grant ID Tokens (6202888)
  • filter jwe decryption keys by algorithm (34e2ffd)
  • preserve poll abort signals on requests (96a2d17)
  • retry dpop nonce errors for generic grants (498c4d9)

v6.8.3

Compare Source

Documentation
  • note a workaround for redirect_uri with query string or bare origin (e9689de), closes #​868
Fixes
  • passport: delete one-time state on callback (1e7dd2e)
facebook/react (react)

v19.2.7: 19.2.7 (June 1st, 2026)

Compare Source

React Server Components

v19.2.6: 19.2.6 (May 6th, 2026)

Compare Source

React Server Components

v19.2.5: 19.2.5 (April 8th, 2026)

Compare Source

React Server Components
remix-run/react-router (react-router-dom)

v7.18.0

Compare Source

Patch Changes

v7.17.0

Compare Source

Patch Changes

v7.16.0

Compare Source

Patch Changes
  • Remove stale/invalid unpkg field from package.json. This was removed from other packages with the release of v7 but missed in the react-router-dom re-export package (#​15075)
  • Updated dependencies:

v7.15.1

Compare Source

Patch Changes

v7.15.0

Compare Source

Patch Changes

v7.14.2

Compare Source

Patch Changes

v7.14.1

Compare Source

Patch Changes
eemeli/yaml (yaml)

v2.9.0

Compare Source

The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".

It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.

Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.

  • fix: Avoid calling Array.prototype.push.apply() with large source array
  • fix(lexer): Avoid recursive calls that may exhaust the call stack

v2.8.4

Compare Source

  • Disable alias resolution with maxAliasCount:0 (#​677)
  • Handle invalid unicode escapes (e1a1a77)
  • Apply minFractionDigits only to decimal strings (#​676)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner April 8, 2026 19:31
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 4c74146 to 7e2ddbc Compare April 12, 2026 16:48
@renovate renovate Bot changed the title fix(deps): update dependencies (non-major) to v19.2.5 fix(deps): update dependencies (non-major) Apr 12, 2026
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch 6 times, most recently from 69cff77 to 00345d9 Compare April 20, 2026 05:07
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch 3 times, most recently from 2d0ea52 to 13875e2 Compare April 27, 2026 23:45
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch 4 times, most recently from c361900 to 9720510 Compare May 6, 2026 17:58
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch 2 times, most recently from daed1e3 to 8760338 Compare May 14, 2026 16:31
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch 3 times, most recently from cf0b0a8 to f17d33c Compare June 4, 2026 14:29
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch 2 times, most recently from db420a5 to 19b5fb3 Compare June 18, 2026 19:37
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 19b5fb3 to 9f7f48d Compare June 20, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants