fix(deps): update dependencies (non-major)#283
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
4c74146 to
7e2ddbc
Compare
69cff77 to
00345d9
Compare
2d0ea52 to
13875e2
Compare
c361900 to
9720510
Compare
daed1e3 to
8760338
Compare
cf0b0a8 to
f17d33c
Compare
db420a5 to
19b5fb3
Compare
19b5fb3 to
9f7f48d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.3.0→3.3.15.5.0→5.6.03.14.0→3.20.017.4.1→17.4.26.8.2→6.8.419.2.4→19.2.719.2.4→19.2.77.14.0→7.18.02.8.3→2.9.0Release Notes
FortAwesome/react-fontawesome (@fortawesome/react-fontawesome)
v3.3.1Compare Source
Chores
harrisiirak/cron-parser (cron-parser)
v5.6.0Compare Source
What's Changed
90e1c68862c0cdNew Contributors
Full Changelog: harrisiirak/cron-parser@v5.5.0...v5.6.0
bradymholt/cRonstrue (cronstrue)
v3.20.0Compare Source
Full Changelog: bradymholt/cRonstrue@v3.19.0...v3.20.0
v3.19.0Compare Source
What's Changed
issues: writepermission for PR comments by @bradymholt with @Copilot in #395Full Changelog: bradymholt/cRonstrue@v3.18.0...v3.19.0
v3.18.0Compare Source
What's Changed
Full Changelog: bradymholt/cRonstrue@v3.16.0...v3.18.0
motdotla/dotenv (dotenv)
v17.4.2Compare Source
Changed
panva/openid-client (openid-client)
v6.8.4Compare Source
Fixes
v6.8.3Compare Source
Documentation
Fixes
facebook/react (react)
v19.2.7: 19.2.7 (June 1st, 2026)Compare Source
React Server Components
FormDataentries in Server Actions which regressed in 19.2.6(#36566 by @unstubbable)
v19.2.6: 19.2.6 (May 6th, 2026)Compare Source
React Server Components
(by @eps1lon and @unstubbable)
v19.2.5: 19.2.5 (April 8th, 2026)Compare Source
React Server Components
remix-run/react-router (react-router-dom)
v7.18.0Compare Source
Patch Changes
react-router@7.18.0v7.17.0Compare Source
Patch Changes
react-router@7.17.0v7.16.0Compare Source
Patch Changes
unpkgfield frompackage.json. This was removed from other packages with the release of v7 but missed in thereact-router-domre-export package (#15075)react-router@7.16.0v7.15.1Compare Source
Patch Changes
react-router@7.15.1v7.15.0Compare Source
Patch Changes
react-router@7.15.0v7.14.2Compare Source
Patch Changes
react-router@7.14.2v7.14.1Compare Source
Patch Changes
react-router@7.14.1eemeli/yaml (yaml)
v2.9.0Compare Source
The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of
parseDocument()andparseAllDocuments(): I've removed the claim that they'll "never throw".It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which
yamlCVEs have been issued so far.Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.
Array.prototype.push.apply()with large source arrayv2.8.4Compare Source
maxAliasCount:0(#677)e1a1a77)minFractionDigitsonly to decimal strings (#676)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.