Skip to content

Bump the minor-and-patch group across 1 directory with 9 updates - #106

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-c56eb5c8c5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-c56eb5c8c5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown

Bumps the minor-and-patch group with 9 updates in the / directory:

Package From To
@shikijs/langs 4.2.0 4.5.0
@shikijs/themes 4.2.0 4.5.0
lucide-react 1.47.0 1.50.0
shiki 4.2.0 4.5.0
electron 44.4.2 44.5.1
esbuild 0.25.12 0.28.2
@types/vscode 1.134.0 1.140.0
lucide-static 1.45.0 1.50.0
tsx 4.23.13 4.23.15

Updates @shikijs/langs from 4.2.0 to 4.5.0

Release notes

Sourced from @​shikijs/langs's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.4.3

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v4.4.2

   🐞 Bug Fixes

   🏎 Performance

... (truncated)

Commits

Updates @shikijs/themes from 4.2.0 to 4.5.0

Release notes

Sourced from @​shikijs/themes's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.4.3

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v4.4.2

   🐞 Bug Fixes

   🏎 Performance

... (truncated)

Commits

Updates lucide-react from 1.47.0 to 1.50.0

Release notes

Sourced from lucide-react's releases.

Version 1.50.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.49.0...1.50.0

Version 1.49.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.48.0...1.49.0

Version 1.48.0

What's Changed

... (truncated)

Commits
  • e042fec fix(packages): declare @types/react as an optional peer dependency (#4892)
  • f06ac67 chore(typchecking): More typecheck jobs for all packages (#4885)
  • See full diff in compare view

Updates shiki from 4.2.0 to 4.5.0

Release notes

Sourced from shiki's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.4.3

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v4.4.2

   🐞 Bug Fixes

   🏎 Performance

... (truncated)

Commits

Updates electron from 44.4.2 to 44.5.1

Release notes

Sourced from electron's releases.

electron v44.5.1

Release Notes for v44.5.1

Other Changes

  • Backported fixes from upstream ANGLE, Chromium, Dawn and V8. #54564

electron v44.5.0

Release Notes for v44.5.0

Features

  • Added launch-failure reporting with systemErrorCode to the app child-process-gone event. #54231 (Also in 45)

Fixes

  • Changed the default trash implementation on KDE Plasma 6 to kioclient. #54361 (Also in 45)
  • DevTools zoom in/out now uses the same zoom steps as Chromium. #54387 (Also in 45)
  • Fixed --xdg-portal-required-version having no effect and a spurious portal warning being logged for file dialogs on Linux. #54303 (Also in 43, 45)
  • Fixed a child WebContentsView losing focus when its window is reactivated. #54455 (Also in 43, 45)
  • Fixed a crash when a WebAuthn request used a security key that required its PIN. #54403 (Also in 45)
  • Fixed a crash when creating a framed window on Wayland in environments where GTK could not initialize. #54420 (Also in 45)
  • Fixed a crash when sending a DevTools protocol command with a non-string value for an optional string parameter via webContents.debugger. #54445 (Also in 43, 45)
  • Fixed a GPU process crash on startup when another instance of the app is using the same session data directory. #54469
  • Fixed a grey border around frameless windows on Linux WMs without compositing. #54391 (Also in 43, 45)
  • Fixed a main process crash when a native API method was called with a this value of a different native type; it now throws a TypeError. #54315 (Also in 43)
  • Fixed a possible crash during process exit when vm.Script or vm contexts created in the main process had been garbage collected shortly before quitting. #54266 (Also in 43, 45)
  • Fixed a possible crash on Windows on ARM when powerMonitor is torn down. #54408 (Also in 45)
  • Fixed a renderer crash calling image.toPNG() from a sandboxed preload script. #54502 (Also in 43, 45)
  • Fixed a renderer crash when a ResizeObserver loop-limit error handler modified layout. #54290 (Also in 45)
  • Fixed accent-color-changed on Windows reporting a colour that differed from systemPreferences.getAccentColor(). #54409 (Also in 45)
  • Fixed an issue where crashReporter.setUploadToServer() had no effect after crashReporter.start() was called. #54518 (Also in 45)
  • Fixed app.getRecentDocuments() omitting documents with non-ASCII paths on Windows. #54407 (Also in 45)
  • Fixed clipboard.read(), readText() and has() resolving seconds late on Linux while the app was idle. #54308 (Also in 42, 43, 45)
  • Fixed desktopCapturer.getSources() leaving non-resizable windows resizable on macOS. #54397 (Also in 43, 45)
  • Fixed fs.rmSync failing to remove read-only files on Windows. #54255 (Also in 42, 43, 45)
  • Fixed GDK_BACKEND leaking into processes spawned by Electron apps on Linux. #54425 (Also in 43, 45)
  • Fixed hidden windows continuing to render at full frame rate after setBackgroundThrottling(false) followed by setBackgroundThrottling(true). #54341 (Also in 45)
  • Fixed pointerLock permission requests from some iframes reporting the parent frame. #54464 (Also in 42, 43, 45)
  • Fixed setContentProtection(true) having no effect in Windows remote sessions. #54500 (Also in 45)
  • Fixed setIgnoreMouseEvents() taking effect late on X11. #54497 (Also in 43, 45)
  • Fixed setIgnoreMouseEvents(true) being undone by the next resize on X11. #54393 (Also in 43, 45)
    • Added setIgnoreMouseEvents support on Wayland.
  • Fixed shell.showItemInFolder() on Linux for paths containing #, ? or % when the file manager is reached over D-Bus. #54406 (Also in 45)
  • Fixed the default action label on Linux notifications not being localized. #54401 (Also in 43, 45)
  • Fixed the GPU process crash-looping on Windows when the sandbox cannot read the install folder; the folder is now reported instead. #54484 (Also in 43, 45)
  • Fixed the zoom level resetting on file: and other host-less pages after a location.hash change. #54442 (Also in 43, 45)
  • Fixed typing not working after closing an alert() or confirm() on Windows. #54461 (Also in 43, 45)
  • Fixed utilityProcess dropping stdout/stderr output that the child wrote immediately before exiting. #54278 (Also in 42, 43, 45)
  • Fixed visual zoom limits resetting on navigation and not applying to webviews. #54449 (Also in 43, 45)

... (truncated)

Commits
  • 19c6011 chore: cherry-pick 27 changes from angle, chromium, dawn and v8 (#54564)
  • 435b189 test: parse all custom page size PDFs in one pdf.js process (#54544)
  • a2db7a8 test: wait for child output before asserting on it (#54541)
  • fa180db fix: crashReporter.setUploadToServer() having no effect after start (#54518)
  • 60f40fe test: wait for focus before requesting pointer lock in spec (#54533)
  • f0a852d test: wait for earlier Electron workers to exit before serial specs (#54512)
  • 42ed175 fix: apply the X11 input shape before setIgnoreMouseEvents() returns (#54497)
  • 71490d8 fix: apply setContentProtection() in Windows remote sessions again (#54500)
  • d4bd178 fix: throw instead of crashing when nativeImage cannot create a Buffer (#54502)
  • 614efcd fix: report install folders that the sandbox cannot read on Windows instead o...
  • Additional commits viewable in compare view

Updates esbuild from 0.25.12 to 0.28.2

Release notes

Sourced from esbuild's releases.

v0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})

... (truncated)

Changelog

Sourced from esbuild's changelog.

Changelog: 2025

This changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).

0.27.2

  • Allow import path specifiers starting with #/ (#4361)

    Previously the specification for package.json disallowed import path specifiers starting with #/, but this restriction has recently been relaxed and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping #/* to ./src/* (previously you had to use another character such as #_* instead, which was more confusing). There is some more context in nodejs/node#49182.

    This change was contributed by @​hybrist.

  • Automatically add the -webkit-mask prefix (#4357, #4358)

    This release automatically adds the -webkit- vendor prefix for the mask CSS shorthand property:

    /* Original code */
    main {
      mask: url(x.png) center/5rem no-repeat
    }
    /* Old output (with --target=chrome110) */
    main {
    mask: url(x.png) center/5rem no-repeat;
    }
    /* New output (with --target=chrome110) */
    main {
    -webkit-mask: url(x.png) center/5rem no-repeat;
    mask: url(x.png) center/5rem no-repeat;
    }

    This change was contributed by @​BPJEnnova.

  • Additional minification of switch statements (#4176, #4359)

    This release contains additional minification patterns for reducing switch statements. Here is an example:

    // Original code
    switch (x) {
      case 0:
        foo()
        break
      case 1:
      default:
        bar()
    }

... (truncated)

Commits
  • 609683d publish 0.28.2 to npm
  • 11b1fe4 add to release notes
  • ab50d91 css: fix green/blue channel swap in oklch gamut mapping (#4488)
  • 04627b6 fix #4498: async TLA checks need a worklist
  • 5c15177 disable gopls in the go folder
  • fc2ee9b css: adjust parser to allow --foo: {...}
  • 209db54 release notes for css nesting bugfix
  • c625d31 fix #4497: preserve nested ampersands during minification (#4500)
  • 34474e2 better isolation of current part in js parser
  • 07f6e8c fix #4507: import assignment tree-shaking bug
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for esbuild since your current version.


Updates @types/vscode from 1.134.0 to 1.140.0

Commits

Updates lucide-static from 1.45.0 to 1.50.0

Release notes

Sourced from lucide-static's releases.

Version 1.50.0

What's Changed

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
@dependabot
dependabot Bot requested a review from Dkm0315 as a code owner September 29, 2026 03:33
@dependabot dependabot Bot changed the title Bump the minor-and-patch group with 9 updates Bump the minor-and-patch group across 1 directory with 9 updates Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/minor-and-patch-c56eb5c8c5 branch 12 times, most recently from a5688ea to eb74bb1 Compare October 5, 2026 13:23
Bumps the minor-and-patch group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@shikijs/langs](https://github.com/shikijs/shiki/tree/HEAD/packages/langs) | `4.2.0` | `4.5.0` |
| [@shikijs/themes](https://github.com/shikijs/shiki/tree/HEAD/packages/themes) | `4.2.0` | `4.5.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.47.0` | `1.50.0` |
| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.2.0` | `4.5.0` |
| [electron](https://github.com/electron/electron) | `44.4.2` | `44.5.1` |
| [esbuild](https://github.com/evanw/esbuild) | `0.25.12` | `0.28.2` |
| [@types/vscode](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/vscode) | `1.134.0` | `1.140.0` |
| [lucide-static](https://github.com/lucide-icons/lucide) | `1.45.0` | `1.50.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |



Updates `@shikijs/langs` from 4.2.0 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/langs)

Updates `@shikijs/themes` from 4.2.0 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/themes)

Updates `lucide-react` from 1.47.0 to 1.50.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.50.0/packages/lucide-react)

Updates `shiki` from 4.2.0 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/shiki)

Updates `electron` from 44.4.2 to 44.5.1
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v44.4.2...v44.5.1)

Updates `esbuild` from 0.25.12 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)
- [Commits](evanw/esbuild@v0.25.12...v0.28.2)

Updates `@types/vscode` from 1.134.0 to 1.140.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/vscode)

Updates `lucide-static` from 1.45.0 to 1.50.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](lucide-icons/lucide@1.45.0...1.50.0)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

---
updated-dependencies:
- dependency-name: "@shikijs/langs"
  dependency-version: 4.4.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@shikijs/themes"
  dependency-version: 4.4.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/vscode"
  dependency-version: 1.138.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: electron
  dependency-version: 44.4.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: lucide-static
  dependency-version: 1.48.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: shiki
  dependency-version: 4.4.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/minor-and-patch-c56eb5c8c5 branch from eb74bb1 to d9abfb3 Compare October 5, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants