Skip to content

build: update all non-major dependencies (main) - #33682

Closed
angular-robot wants to merge 1 commit into
angular:mainfrom
angular-robot:ng-renovate/main-all-non-major-dependencies
Closed

build: update all non-major dependencies (main)#33682
angular-robot wants to merge 1 commit into
angular:mainfrom
angular-robot:ng-renovate/main-all-non-major-dependencies

Conversation

@angular-robot

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@modelcontextprotocol/sdk (source) 1.29.01.30.0 age adoption passing confidence
@oxc-project/types (source) 0.141.00.142.0 age adoption passing confidence
@rollup/wasm-node (source) 4.62.24.62.3 age adoption passing confidence
eslint (source) 10.7.010.8.0 age adoption passing confidence
globals 17.7.017.8.0 age adoption passing confidence
jsdom 30.0.030.0.1 age adoption passing confidence
less (source) 4.8.04.8.1 age adoption passing confidence
oxc-parser (source) 0.141.00.142.0 age adoption passing confidence
postcss (source) 8.5.228.5.24 age adoption passing confidence
puppeteer (source) 25.3.025.4.0 age adoption passing confidence
rollup (source) 4.62.24.62.3 age adoption passing confidence
sass 1.101.71.102.0 age adoption passing confidence
undici (source) 8.8.08.9.0 age adoption passing confidence
verdaccio (source) 6.8.06.9.0 age adoption passing confidence
webpack 5.109.05.109.2 age adoption passing confidence
webpack-dev-middleware 8.0.48.1.0 age adoption passing confidence
yargs (source) 18.0.018.1.0 age adoption passing confidence

  • If you want to rebase/retry this PR, check this box

Release Notes

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk)

v1.30.0

Compare Source

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0

rollup/rollup (@​rollup/wasm-node)

v4.62.3

Compare Source

2026-07-26

Bug Fixes
  • Sanitize illegal characters preserved modules input base (#​6439)
Pull Requests
eslint/eslint (eslint)

v10.8.0

Compare Source

Features

Bug Fixes

  • 6b8d2f7 fix: escape reserved characters in rule id in html formatter (#​21129) (Francesco Trotta)
  • 9091071 fix: prevent no-unreachable-loop crash when all loop types are ignored (#​21116) (Pixel)
  • e23fafe fix: prefer-object-spread add semicolon when adding parenthesis (#​21081) (synthex-byte)
  • 20b5ad0 fix: quadratic-time regex in prefer-template (#​21096) (Milos Djermanovic)
  • 8b6f6c0 fix: apply ignore configs to computed methods in class-methods-use-this (#​21094) (Pixel)
  • b2c608c fix: NewExpression with parenthesized callee in preserve-caught-error (#​21083) (Francesco Trotta)

Documentation

  • 6ddf858 docs: fix broken Specify Parser Options anchor link (#​21106) (Minsu)
  • 784dfbe docs: Clarify no-eq-null description (#​21120) (Park Harin)
  • 7ec733a docs: Fix typos and grammar in glossary (#​21095) (Marry (Subin Yang))
  • 92bb13f docs: replace quake link (#​21108) (Jung Hyeon Jun)
  • 68eb4a5 docs: fix broken Specify Globals anchor links in rule pages (#​21103) (Minsu)
  • d28f697 docs: replace Code Climate CLI links with Qlty CLI links (#​21099) (Jung Hyeon Jun)
  • eccc68d docs: correct --suppressions-location option description (#​21093) (Ga eun Lee)
  • c5963f7 docs: Update README (GitHub Actions Bot)

Chores

  • 4fbf46d test: pin webpack version to 5.108.4 (#​21137) (Francesco Trotta)
  • 2d063e2 chore: update HTTP URLs to HTTPS in JSDoc and comments (#​21101) (Bo Hyun Kim)
  • eccbe7b test: add error locations to no-class-assign (#​21123) (devoil)
  • e7d1e43 ci: bump actions/setup-go from 6 to 7 (#​21118) (dependabot[bot])
  • e9d66d0 ci: bump actions/setup-node from 6 to 7 (#​21119) (dependabot[bot])
  • ee225b6 test: Add error location details to no-eq-null rule (#​21117) (Park Harin)
  • 044a627 chore: update minimatch to ^10.2.5 (#​21107) (김채영)
  • fb09aa8 chore: update ecosystem plugins (#​21115) (ESLint Bot)
  • 5abd878 test: add error locations to no-proto (#​21114) (Gihyeon Jeong / 정기현)
  • 9715887 test: Add error location details to no-div-regex (#​21110) (Park Harin)
  • a746ec6 test: add error locations to no-new-wrappers (#​21109) (Gihyeon Jeong / 정기현)
  • 8dde645 test: add error locations to no-ex-assign (#​21102) (devoil)
  • 13ab0ec test: add error locations to no-label-var (#​21098) (Gihyeon Jeong / 정기현)
  • a99906f test: Add error location details to no-delete-var rule (#​21105) (Park Harin)
  • c47e8dc chore: add missing backticks to languages/js/index.js (#​21104) (beeen)
  • 0174428 chore: add missing backticks to translate-cli-options.js (#​21097) (dongkyu lee)
  • 3d36589 chore: add missing backticks to serialization.js (#​21091) (이규환)
  • dcc9312 test: add error locations to eqeqeq (#​21090) (Ga eun Lee)
  • 2710b18 ci: Add explicit permissions to rebuild-docs-sites workflow (#​21089) (Marry (Subin Yang))
  • 5d2f866 chore: update dependency prettier to v3.9.5 (#​21086) (renovate[bot])
  • d584e31 chore: fix failing ecosystem test for eslint-plugin-unicorn (#​21084) (Francesco Trotta)
  • bf3eda0 chore: update ecosystem plugins (#​21079) (ESLint Bot)
sindresorhus/globals (globals)

v17.8.0

Compare Source


jsdom/jsdom (jsdom)

v30.0.1

Compare Source

  • Fixed getComputedStyle() with calc() and other functions throwing an exception, which regressed in v30.0.0. (@​asamuzaK)
  • Sped up up range operations on large documents (@​leonidaz)
less/less.js (less)

v4.8.1

Compare Source

Changes
oxc-project/oxc (oxc-parser)

v0.142.0

🚀 Features
  • 11f5d1f ast_visit: Add Utf8ToUtf16::convert_program_and_comments (#​24859) (overlookmotel)
🐛 Bug Fixes
  • e80574f estree: Handle empty spans serializing ImportMeta and NewTarget (#​24775) (overlookmotel)
postcss/postcss (postcss)

v8.5.24

Compare Source

  • Preserve the BOM after the processing (by @​hdimer).

v8.5.23

Compare Source

  • Do not load source map without opts.from for security reasons.
puppeteer/puppeteer (puppeteer)

v25.4.0

Compare Source

🎉 Features
Dependencies
  • The following workspace dependencies were updated
    • dependencies
      • puppeteer-core bumped from 25.3.0 to 25.4.0
🛠️ Fixes
sass/dart-sass (sass)

v1.102.0

Compare Source

  • Use the 2.4 gamma transfer function for rec2020, as specified by the latest
    draft of CSS Color 4.
nodejs/undici (undici)

v8.9.0

Compare Source

⚠️ Security fixes
High severity
  • GHSA-4cwx-7wf7-3272: malformed qualified private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 4fe5bc5f with regression coverage in 9f09b49a.
Medium severity
  • GHSA-m8rv-5g2x-5cg5: a malicious type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 7d3cf924.
  • GHSA-jr45-8vmc-qm54: optional whitespace around = in qualified no-cache and private directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by c601fff1.
  • GHSA-8xcm-r25x-g524: the retry interceptor could expose a stale Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by e11a68ed, with corrected fixtures in 2b3f7493.
  • GHSA-v3r7-h72x-cjcm: unsanitized domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 10d93fc3.
Additional hardening

Undici now validates non-string header values after coercion, including array elements, preventing crafted toString() or Symbol.toPrimitive implementations from introducing CRLF sequences. This defense-in-depth change was made in 354a151f.

What's Changed
New Contributors

Full Changelog: nodejs/undici@v8.8.0...v8.9.0

verdaccio/verdaccio (verdaccio)

v6.9.0

Compare Source

Minor Changes
  • b67a665: feat: require Node.js 22 as the minimum supported version

    Node.js 22 or higher is now required (previously the CLI still accepted Node.js 18,
    while engines already demanded 20). The CLI refuses to start on older runtimes and
    engines is set to >=22; Node.js 24 is the recommended version. CI, e2e, and smoke
    test matrices now cover Node.js 22, 24, and 26. Registry operators on Node.js 18 or 20
    must upgrade the runtime before taking this release.

  • b67a665: feat: dual CJS + ESM build with exports field, migrate build from babel to vite 8

    Native ESM support. The package now ships both CommonJS (build/**/*.js) and ESM
    (build/**/*.mjs) outputs and declares an exports field, so
    import { runServer } from 'verdaccio' resolves a real ES module instead of the
    CommonJS interop. require('verdaccio') keeps working exactly as before. The
    verdaccio CLI now runs on the ESM build, which means ESM-only dependencies can be
    loaded at runtime on every supported Node.js version.

    Build toolchain. Babel has been replaced by vite 8 (rolldown) for transpilation;
    type declarations are still emitted by TypeScript. This is not observable in the
    registry behavior, but local workflows changed: yarn start and the debug/ bootstrap
    scripts now use tsx instead of babel-node/@babel/register.

Patch Changes
  • b67a665: fix(deps): update @​verdaccio/hooks to 8.1.1

    Restores publish/unpublish webhook notifications when running on the ESM build: hooks
    8.1.0 could not send them (the notify client failed silently on every call). The new
    version replaces the frozen got-cjs fork with got 15 loaded in a way that works
    from both the ESM and CommonJS builds, and reports delivery failures based on the real
    HTTP response status.

  • b67a665: fix(deps): update @​verdaccio/* packages to the 2026-07-25 release batch

    Updates all @verdaccio/* and verdaccio-* dependencies (config 8.1.4, core 8.1.4,
    auth 8.0.6, middleware 8.0.7, htpasswd/audit 13.0.5, among others). Notably
    @verdaccio/config 8.1.4 moves to js-yaml 4.3.0, resolving the high-severity
    advisory GHSA-52cp-r559-cp3m
    (YAML merge-key chains forcing quadratic CPU consumption).

  • 2969ec8: fix: migrate uplink/storage URL parsing to the WHATWG URL API

    Removes the [DEP0169] DeprecationWarning: url.parse() printed at startup on
    Node.js 22+. The proxy and local-storage layers no longer use the legacy url.parse()
    / url.format() helpers; uplink URL validation, distfile filename extraction, and the
    remote-protocol tarball rewrite now go through the standardized URL API. Behavior is
    unchanged for the absolute HTTP(S) URLs used in practice — the default HTTPS port :443
    still normalizes to a match, and invalid uplink URLs are treated as not-valid instead of
    being parsed leniently.

    Because the WHATWG URL constructor throws on malformed input (unlike the lenient legacy
    url.parse()), a misconfigured uplink url now fails fast at startup with a clear,
    credential-redacted error, and a malformed dist.tarball returned by an upstream registry
    is skipped (with a warning) instead of aborting the package update. Uplink URL validation
    also now compares the uplink's own port when deciding whether to ignore the default HTTPS
    port, so an HTTPS uplink on a non-default port no longer matches a default-port tarball.

webpack/webpack (webpack)

v5.109.2

Compare Source

Patch Changes
  • Resolve aliases pointing at a package directory whose name ends with .js again. (by @​alexander-akait in #​21542)

  • Name CSS sources in source maps by their resource path, without the css prefix. (by @​bjohansebas in #​21536)

  • Delete no longer referenced files from the filesystem cache directory after storing the cache, age them by recorded time so restored caches are cleaned too, and collect every fully expired pack in one store instead of one per build. (by @​bjohansebas in #​21528)

  • Report "universal" as the loader context target for the universal target. (by @​alexander-akait in #​21540)

  • Skip require().prop in dead branches gated by inlined imported constants. (by @​hai-x in #​21517)

  • Annotate configuration options and public hooks in the generated types with the @since JSDoc tag. (by @​bjohansebas in #​21473)

v5.109.1

Compare Source

Patch Changes
  • Fix stray semicolon emitted before an imported call following a parenthesized sequence element. (by @​alexander-akait in #​21533)

  • Make require(esm) module.exports re-export analysis independent of module processing order. (by @​alexander-akait in #​21521)

  • Ignore ERR_SERVER_NOT_RUNNING on lazy-compilation backend dispose so compiler.close() succeeds on Bun. (by @​alexander-akait in #​21521)

  • Name the failing key when DefinePlugin fails to evaluate a typeof value. (by @​alexander-akait in #​21503)

  • Improve Deno compatibility: guard setNoDelay and force-close connections on lazy-compilation backend dispose, and return a real ArrayBuffer from the Node async/sync wasm loader so WebAssembly.instantiate accepts it. (by @​alexander-akait in #​21524)

  • Speed up the HTML parser and cut its peak memory: module-scope helpers/state and tokenizer callbacks, plus exact AST column pre-sizing. (by @​alexander-akait in #​21492)

  • Track CommonJS build dependencies by parsing sources when require.cache children are unavailable (e.g. Bun). (by @​alexander-akait in #​21531)

  • Cook common string-literal escapes on the JS parser fast path and own the tokenizer's cold-path readers. (by @​alexander-akait in #​21500)

  • Build the CSS parseA* AST on the SoA store instead of node classes, cutting parse memory and time. (by @​alexander-akait in #​21498)

  • Speed up and cut memory of the experimental CSS and HTML parsers: drop two derivable AST node columns, and scan long string, url, comment, and plaintext token bodies natively. (by @​alexander-akait in #​21504)

  • Speed up non-modules CSS parsing: skip redundant token re-reads, drop selector-prelude tokens without materializing nodes, allocate rule preludes lazily, and fast-path empty list seals. (by @​alexander-akait in #​21511)

  • Speed up stats generation and cut its peak memory: reuse cached sort comparators instead of thrashing the comparator caches on every sort, and drop redundant module-graph lookups and allocations in the extractors. (by @​alexander-akait in #​21506)

  • Speed up CSS parsing: byte-range function-name checks, indexed sibling lookahead. (by @​bjohansebas in #​21520)

  • Reduce allocations and redundant work across the code-generation, module-concatenation, exports/usage-analysis, hashing, and chunk-splitting hot paths. (by @​alexander-akait in #​21516)

  • Enable the Node.js compile cache in the webpack CLI entry point. (by @​bjohansebas in #​21523)

  • Encode the persistent cache with V8's value serializer. (by @​avivkeller in #​21514)

  • Speed up SplitChunksPlugin: reject non-subset chunk sets with 64-bit signatures, cache unnamed entry keys, and drop per-module closures. (by @​avivkeller in #​21529)

  • Initialize NormalModule._ast in the constructor so each instance keeps a single hidden-class shape. (by @​alexander-akait in #​21515)

  • Reduce allocations in the binary serialization hot paths. (by @​alexander-akait in #​21526)

  • Deduplicate and simplify several lib modules and speed up AggressiveMergingPlugin. (by @​alexander-akait in #​21525)

  • Rename nested const/let __webpack_require__ and __webpack_exports__ declarations in bundled webpack output. (by @​hai-x in #​21508)

webpack/webpack-dev-middleware (webpack-dev-middleware)

v8.1.0

Compare Source

Minor Changes
  • Reuse an already active MultiCompiler watching session instead of starting a duplicate one (requires webpack >= 5.109). (by @​bjohansebas in #​2371)
yargs/yargs (yargs)

v18.1.0

Compare Source

Features
  • ignore bun when getting bin name (b77831c)
Bug Fixes

See associated pull request for more information.
@angular-robot angular-robot added action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only] labels Jul 30, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates several third-party dependencies across multiple package.json files in the workspace, including webpack, rollup, sass, postcss, eslint, and jsdom, to newer minor or patch versions. As there are no review comments, I have no feedback to provide.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants