chore(deps): update all non-major dependencies#49
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
da6b8c8 to
b27a9f0
Compare
b27a9f0 to
90e6b96
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.21.4→^0.21.5^0.5.2→^0.5.32.0.3→2.0.40.9.10→0.10.2^24.12.3→^24.12.4^4.12.18→^4.12.22^3.2.0→^3.2.111.1.2→11.2.2Release Notes
web-infra-dev/rslib (@rslib/core)
v0.21.5Compare Source
What's Changed
New Features 🎉
Bug Fixes 🐞
Other Changes
4949c44by @renovate[bot] in #1637New Contributors
Full Changelog: web-infra-dev/rslib@v0.21.4...v0.21.5
web-infra-dev/rslint (@rslint/core)
v0.5.3Compare Source
What's Changed
New Features 🎉
prefer-to-berule by @eryue0220 in #870no-identical-titlerule by @eryue0220 in #875no-commented-out-testsrule by @eryue0220 in #931Bug Fixes 🐞
Refactor 🔨
Documentation 📖
experimentalExcludeRoutePathsAPI by @elecmonkey in #879Other Changes
dcc16d9by @fansenze in #873092b34fby @fansenze in #901adb2ab4by @fansenze in #910New Contributors
Full Changelog: web-infra-dev/rslint@v0.5.2...v0.5.3
web-infra-dev/rspack (@rspack/core)
v2.0.4Compare Source
Highlights 💡
Inline const with module declarations (#14032): Previously, Rspack only inlined constant exports from leaf modules in the module graph. Now constant exports from any module can be inlined, even when that module also imports or re-exports other modules. In rare circular-reference cases this can make a TDZ error disappear, but we do not expect real projects to rely on TDZ errors, so Rspack prioritizes the optimization.
Tree shake namespace default reexport (#13980): Previously, the
import * as a from './a'; export default a;pattern did not tree-shakeathrough the default export. Now Rspack further analyzes the default-exported namespace object and can remove unused exports from the original namespace module.CSS global module type (#13988):
css/globalis useful when most selectors in a stylesheet should stay global, but you still want CSS Modules features for selected local selectors. This makes it easier to migrate existing global CSS gradually without turning every class name into a local scoped name..buttonstays global, while.titleis renamed as a local class.CSS Modules local ident options (#14009): CSS Modules now support local ident hash options such as hash function, digest, digest length, and salt. These options make generated class names more configurable and better aligned with webpack-compatible CSS Modules setups.
What's Changed
New Features 🎉
Performance 🚀
Bug Fixes 🐞
Document 📖
Other Changes
Full Changelog: web-infra-dev/rspack@v2.0.3...v2.0.4
web-infra-dev/rstest (@rstest/core)
v0.10.2Compare Source
Highlights
Auto-restore mocks with
using(#1293)Mock instances now implement
Symbol.dispose, so spies are automatically restored when ausingblock exits — no more manualmockRestore()inafterEach.What's Changed
New Features 🎉
Performance 🚀
Bug Fixes 🐞
Document 📖
Other Changes
New Contributors
Full Changelog: web-infra-dev/rstest@v0.10.1...v0.10.2
v0.10.1Compare Source
What's Changed
New Features 🎉
Performance 🚀
Bug Fixes 🐞
Refactor 🔨
Document 📖
Other Changes
ca8d345by @fi3ework in #1283New Contributors
Full Changelog: web-infra-dev/rstest@v0.10.0...v0.10.1
v0.10.0Compare Source
What's Changed
New Features 🎉
Bug Fixes 🐞
toNotFakeoption in useFakeTimers properly by @felixmosh in #1219mergeRslibConfiginstead ofmergeRsbuildConfigby @9aoy in #1238Document 📖
Other Changes
4949c44by @renovate[bot] in #122848b55a0by @renovate[bot] in #1229New Contributors
Full Changelog: web-infra-dev/rstest@v0.9.10...v0.10.0
honojs/hono (hono)
v4.12.22Compare Source
What's Changed
New Contributors
Full Changelog: honojs/hono@v4.12.21...v4.12.22
v4.12.21Compare Source
Security fixes
This release includes fixes for the following security issues:
app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
Affects:
app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3IP Restriction bypasses static deny rules for non-canonical IPv6
Affects:
hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Affects:
hono/cookie. Fixes missing validation ofsameSiteandpriorityoptions against injection characters (;,\r,\n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5xJWT middleware accepts any Authorization scheme, not only Bearer
Affects:
hono/jwt,hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474Users who use
app.mount(),hono/ip-restriction,hono/cookie, orhono/jwt/hono/jwkare encouraged to upgrade to this version.v4.12.20Compare Source
What's Changed
New Contributors
Full Changelog: honojs/hono@v4.12.19...v4.12.20
v4.12.19Compare Source
What's Changed
Configuration
📅 Schedule: (in timezone Asia/Shanghai)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.