Skip to content

chore(deps): update all non-major dependencies - #961

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pin
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pin

Conversation

@renovate

@renovate renovate Bot commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@axe-core/playwright 4.11.3 → 4.13.0 age confidence devDependencies minor
@double-great/stylelint-a11y 3.4.15 → 3.5.4 age confidence devDependencies minor
@playwright/test (source) 1.61.0 → 1.63.0 age confidence devDependencies minor
@types/node (source) 25.9.3 → 25.9.9 age confidence devDependencies patch
actions/cache v5.0.5 → v5.1.0 age confidence action minor
actions/checkout v6.0.3 → v6.1.0 age confidence action minor
actions/setup-node v6.4.0 → v6.5.0 age confidence action minor
axe-core (source) 4.12.1 → 4.13.0 age confidence devDependencies minor
docker/build-push-action v7.2.0 → v7.4.0 age confidence action minor
docker/login-action v4.2.0 → v4.6.0 age confidence action minor
docker/metadata-action v6.1.0 → v6.2.0 age confidence action minor
elm-test 0.19.2-0 → 0.19.2-1 age confidence devDependencies patch
fholzer/nginx-brotli v1.31.1 → v1.31.3 age confidence final patch
github/codeql-action v4.36.2 → v4.38.2 age confidence action minor
node (source) 24.16.0 → 24.21.0 age confidence minor
postcss (source) 8.5.23 → 8.5.28 age confidence devDependencies patch
prettier (source) 3.8.4 → 3.9.9 age confidence devDependencies minor
stylelint (source) 17.13.0 → 17.16.0 age confidence devDependencies minor
stylelint-declaration-strict-value 1.11.1 → 1.12.1 age confidence devDependencies minor
stylelint-scss 7.2.0 → 7.3.0 age confidence devDependencies minor

Release Notes

dequelabs/axe-core-npm (@​axe-core/playwright)

v4.13.0

Compare Source

v4.12.1

Compare Source

double-great/stylelint-a11y (@​double-great/stylelint-a11y)

v3.5.4

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.3...v3.5.4

v3.5.3

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.2...v3.5.3

v3.5.2

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.1...v3.5.2

v3.5.1

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.0...v3.5.1

v3.5.0

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.4.15...v3.5.0

microsoft/playwright (@​playwright/test)

v1.63.0

Compare Source

v1.62.1

Compare Source

v1.62.0

Compare Source

🧱 New component testing model

Component testing moves to a stories and galleries model.
A story wraps your component in one specific scenario — hard-coded props, mock data, providers — and a

gallery page that you serve renders stories on demand. The new fixtures.mount() fixture navigates
to the gallery, mounts a story by id, and returns a Locator scoped to the story's root element:

test('click should expand', async ({ mount }) => {
  const component = await mount('components/Expandable/Stateful');
  await component.getByRole('button').click();
  await expect(component.getByTestId('expanded')).toHaveValue('true');
});

Pass a story type as a template argument to type-check its props, and use update(props) /
unmount() on the returned locator to re-render or tear down within a test.

🛑 Cancel operations with AbortSignal

Most operations and web-first assertions now accept a signal option that takes an
AbortSignal, letting you
cancel long-running actions, navigations, waits, and assertions:

const controller = new AbortController();
setTimeout(() => controller.abort(), 1000);

await page.getByRole('button', { name: 'Submit' }).click({ signal: controller.signal });
await expect(page.getByText('Done')).toBeVisible({ signal: controller.signal });

Providing a signal does not disable the default timeout; pass timeout: 0 to disable it.

🖼️ WebP screenshots

expect(page).toHaveScreenshot() and expect(locator).toHaveScreenshot()
can now store snapshots in the WebP format — just give the snapshot a .webp name:

// Visual comparisons store the golden snapshot as lossless WebP.
await expect(page).toHaveScreenshot('homepage.webp');

// Standalone screenshots can trade quality for size with lossy WebP.
await page.screenshot({ path: 'homepage.webp', quality: 50 });

page.screenshot() and locator.screenshot() also accept webp as a type,
where quality 100 (the default) is lossless and lower values use lossy compression.

🧩 Custom test filtering with Reporter.preprocess()

New reporter.preprocess() hook runs after the configuration is resolved and before
reporter.onBegin(), letting a reporter mark individual tests as skipped, excluded,
fixed, or failing through a TestRun object:

class MyReporter {
  async preprocess({ config, suite, testRun }) {
    for (const test of suite.allTests()) {
      if (shouldSkip(test))
        testRun.skip(test);
    }
  }
}
🔁 Isolated retries

New testConfig.retryStrategy controls when failed tests are retried. The default
'immediate' retries as soon as a worker is free; 'isolated' runs all retries at the end,
one by one in a single worker, to minimize interference with the rest of the suite:

// playwright.config.ts
export default defineConfig({
  retries: 2,
  retryStrategy: 'isolated',
});
New APIs
Browser and Context
  • New option credentials includes the context's virtual WebAuthn Credentials (passkeys) in the storage state, so they can be persisted and re-seeded into later contexts.
Actions
  • New scroll option ("auto" | "none") on actions to opt out of Playwright's automatic scroll-into-view.
Network
Evaluation
Command line & MCP
Reporters
  • The HTML report's Merge files grouping — previously only a UI toggle — can now be enabled from the config with the new mergeFiles reporter option:
// playwright.config.ts
export default defineConfig({
  reporter: [['html', { mergeFiles: true }]],
});
Announcements
  • ⚠️ Debian 11 is not supported anymore.
Browser Versions
  • Chromium 151.0.7922.34
  • Mozilla Firefox 153.0
  • WebKit 26.5

This version was also tested against the following stable channels:

  • Google Chrome 151
  • Microsoft Edge 151

v1.61.1

Compare Source

actions/cache (actions/cache)

v5.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

actions/checkout (actions/checkout)

v6.1.0

Compare Source

actions/setup-node (actions/setup-node)

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

dequelabs/axe-core (axe-core)

v4.13.0

Compare Source

Features
Bug Fixes
4.12.1 (2026-06-09)
Bug Fixes
  • axe.d.ts: make enabled property of RuleMetadata optional (#​5129) (7eb3d2d)
docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

v7.3.0

Compare Source

docker/login-action (docker/login-action)

v4.6.0

Compare Source

v4.5.2

Compare Source

v4.5.1

Compare Source

v4.5.0

Compare Source

v4.4.0

Compare Source

v4.3.0

Compare Source

Full Changelog: docker/login-action@v4.2.0...v4.3.0

docker/metadata-action (docker/metadata-action)

v6.2.0

Compare Source

rtfeldman/node-test-runner (elm-test)

v0.19.2-1

Compare Source

This release adds a few CLI options, reduces the dependency footprint, and fixes a bug.

Added

This release adds a few CLI options that elm-test-rs already has:

  • --workers for choosing how many workers elm-test should use to run tests in parallel. Use --workers 1 to run tests single-threaded.
  • --dependencies oldest for Elm package developers.
  • --offline for making sure elm-test makes no HTTP requests.
github/codeql-action (github/codeql-action)

v4.38.2

Compare Source

v4.38.1

Compare Source

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #​4146

v4.38.0

Compare Source

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #​4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #​4072
  • Update default CodeQL bundle version to 2.27.0. #​4129

v4.37.9

Compare Source

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070

v4.37.5

Compare Source

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #​4061

v4.37.4

Compare Source

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.

nodejs/node (node)

v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #​65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #​63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #​65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #​65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #​65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #​64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #​65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #​64965
Commits

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner June 16, 2026 17:43
@renovate renovate Bot added the dependencies Indicates a change to dependencies label Jun 16, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch from de129db to c7a5c43 Compare June 16, 2026 19:40
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies to v8.5.15 chore(deps): update all non-major dependencies Jun 18, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from 57aefad to 3a3880a Compare June 25, 2026 16:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 10 times, most recently from 5490ef5 to 513d222 Compare July 2, 2026 10:48
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from fb44c72 to 69cddc7 Compare July 9, 2026 19:38
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 7984cbb to 10fabd6 Compare July 12, 2026 13:17
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 8 times, most recently from e902edf to a4f922b Compare August 4, 2026 17:54
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from c63428b to 9090f25 Compare August 11, 2026 22:04
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from 2da452c to 45d550c Compare August 19, 2026 01:05
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 5 times, most recently from f82ac1e to f6eaf72 Compare August 26, 2026 18:49
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from 5bddced to 4aeedec Compare September 5, 2026 13:47
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 21cdbd6 to 3910ada Compare September 9, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Indicates a change to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants