build: update all non-major dependencies (main) - #33682
Closed
angular-robot wants to merge 1 commit into
Closed
Conversation
See associated pull request for more information.
There was a problem hiding this comment.
Code Review
This pull request updates several third-party dependencies across multiple package.json files in the workspace, including webpack, rollup, sass, postcss, eslint, and jsdom, to newer minor or patch versions. As there are no review comments, I have no feedback to provide.
alan-agius4
approved these changes
Jul 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.29.0→1.30.00.141.0→0.142.04.62.2→4.62.310.7.0→10.8.017.7.0→17.8.030.0.0→30.0.14.8.0→4.8.10.141.0→0.142.08.5.22→8.5.2425.3.0→25.4.04.62.2→4.62.31.101.7→1.102.08.8.0→8.9.06.8.0→6.9.05.109.0→5.109.28.0.4→8.1.018.0.0→18.1.0Release Notes
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk)
v1.30.0Compare Source
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0
rollup/rollup (@rollup/wasm-node)
v4.62.3Compare Source
2026-07-26
Bug Fixes
Pull Requests
4be7066(@renovate[bot], @lukastaegert)4cda84d(@renovate[bot])eslint/eslint (eslint)
v10.8.0Compare Source
Features
2fee9bbfeat: exportConfigObjectfromeslint/config(#21082) (sethamus)Bug Fixes
6b8d2f7fix: escape reserved characters in rule id inhtmlformatter (#21129) (Francesco Trotta)9091071fix: preventno-unreachable-loopcrash when all loop types are ignored (#21116) (Pixel)e23fafefix: prefer-object-spread add semicolon when adding parenthesis (#21081) (synthex-byte)20b5ad0fix: quadratic-time regex inprefer-template(#21096) (Milos Djermanovic)8b6f6c0fix: apply ignore configs to computed methods in class-methods-use-this (#21094) (Pixel)b2c608cfix: NewExpression with parenthesized callee inpreserve-caught-error(#21083) (Francesco Trotta)Documentation
6ddf858docs: fix broken Specify Parser Options anchor link (#21106) (Minsu)784dfbedocs: Clarifyno-eq-nulldescription (#21120) (Park Harin)7ec733adocs: Fix typos and grammar in glossary (#21095) (Marry (Subin Yang))92bb13fdocs: replace quake link (#21108) (Jung Hyeon Jun)68eb4a5docs: fix broken Specify Globals anchor links in rule pages (#21103) (Minsu)d28f697docs: replace Code Climate CLI links with Qlty CLI links (#21099) (Jung Hyeon Jun)eccc68ddocs: correct --suppressions-location option description (#21093) (Ga eun Lee)c5963f7docs: Update README (GitHub Actions Bot)Chores
4fbf46dtest: pinwebpackversion to 5.108.4 (#21137) (Francesco Trotta)2d063e2chore: update HTTP URLs to HTTPS in JSDoc and comments (#21101) (Bo Hyun Kim)eccbe7btest: add error locations tono-class-assign(#21123) (devoil)e7d1e43ci: bump actions/setup-go from 6 to 7 (#21118) (dependabot[bot])e9d66d0ci: bump actions/setup-node from 6 to 7 (#21119) (dependabot[bot])ee225b6test: Add error location details tono-eq-nullrule (#21117) (Park Harin)044a627chore: update minimatch to ^10.2.5 (#21107) (김채영)fb09aa8chore: update ecosystem plugins (#21115) (ESLint Bot)5abd878test: add error locations tono-proto(#21114) (Gihyeon Jeong / 정기현)9715887test: Add error location details tono-div-regex(#21110) (Park Harin)a746ec6test: add error locations tono-new-wrappers(#21109) (Gihyeon Jeong / 정기현)8dde645test: add error locations tono-ex-assign(#21102) (devoil)13ab0ectest: add error locations tono-label-var(#21098) (Gihyeon Jeong / 정기현)a99906ftest: Add error location details tono-delete-varrule (#21105) (Park Harin)c47e8dcchore: add missing backticks tolanguages/js/index.js(#21104) (beeen)0174428chore: add missing backticks totranslate-cli-options.js(#21097) (dongkyu lee)3d36589chore: add missing backticks toserialization.js(#21091) (이규환)dcc9312test: add error locations toeqeqeq(#21090) (Ga eun Lee)2710b18ci: Add explicit permissions to rebuild-docs-sites workflow (#21089) (Marry (Subin Yang))5d2f866chore: update dependency prettier to v3.9.5 (#21086) (renovate[bot])d584e31chore: fix failing ecosystem test foreslint-plugin-unicorn(#21084) (Francesco Trotta)bf3eda0chore: update ecosystem plugins (#21079) (ESLint Bot)sindresorhus/globals (globals)
v17.8.0Compare Source
7394811jsdom/jsdom (jsdom)
v30.0.1Compare Source
getComputedStyle()withcalc()and other functions throwing an exception, which regressed in v30.0.0. (@asamuzaK)less/less.js (less)
v4.8.1Compare Source
Changes
oxc-project/oxc (oxc-parser)
v0.142.0🚀 Features
11f5d1fast_visit: AddUtf8ToUtf16::convert_program_and_comments(#24859) (overlookmotel)🐛 Bug Fixes
e80574festree: Handle empty spans serializingImportMetaandNewTarget(#24775) (overlookmotel)postcss/postcss (postcss)
v8.5.24Compare Source
v8.5.23Compare Source
opts.fromfor security reasons.puppeteer/puppeteer (puppeteer)
v25.4.0Compare Source
🎉 Features
using) (#15027) (a1ca86b)Dependencies
🛠️ Fixes
sass/dart-sass (sass)
v1.102.0Compare Source
draft of CSS Color 4.
nodejs/undici (undici)
v8.9.0Compare Source
High severity
privateCache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 4fe5bc5f with regression coverage in 9f09b49a.Medium severity
typeproperty on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generatedcontent-typeheader. Undici now coerces and validates the value before adding it to the request. Fixed by 7d3cf924.=in qualifiedno-cacheandprivatedirectives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by c601fff1.Content-Lengthafter resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whoseContent-Lengthis inconsistent withContent-Range. Fixed by e11a68ed, with corrected fixtures in 2b3f7493.domainandunparsedvalues passed tosetCookie()could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 10d93fc3.Additional hardening
Undici now validates non-string header values after coercion, including array elements, preventing crafted
toString()orSymbol.toPrimitiveimplementations from introducing CRLF sequences. This defense-in-depth change was made in 354a151f.What's Changed
New Contributors
Full Changelog: nodejs/undici@v8.8.0...v8.9.0
verdaccio/verdaccio (verdaccio)
v6.9.0Compare Source
Minor Changes
b67a665: feat: require Node.js 22 as the minimum supported versionNode.js 22 or higher is now required (previously the CLI still accepted Node.js 18,
while
enginesalready demanded 20). The CLI refuses to start on older runtimes andenginesis set to>=22; Node.js 24 is the recommended version. CI, e2e, and smoketest matrices now cover Node.js 22, 24, and 26. Registry operators on Node.js 18 or 20
must upgrade the runtime before taking this release.
b67a665: feat: dual CJS + ESM build withexportsfield, migrate build from babel to vite 8Native ESM support. The package now ships both CommonJS (
build/**/*.js) and ESM(
build/**/*.mjs) outputs and declares anexportsfield, soimport { runServer } from 'verdaccio'resolves a real ES module instead of theCommonJS interop.
require('verdaccio')keeps working exactly as before. TheverdaccioCLI now runs on the ESM build, which means ESM-only dependencies can beloaded at runtime on every supported Node.js version.
Build toolchain. Babel has been replaced by vite 8 (rolldown) for transpilation;
type declarations are still emitted by TypeScript. This is not observable in the
registry behavior, but local workflows changed:
yarn startand thedebug/bootstrapscripts now use
tsxinstead ofbabel-node/@babel/register.Patch Changes
b67a665: fix(deps): update @verdaccio/hooks to 8.1.1Restores publish/unpublish webhook notifications when running on the ESM build: hooks
8.1.0 could not send them (the notify client failed silently on every call). The new
version replaces the frozen
got-cjsfork withgot15 loaded in a way that worksfrom both the ESM and CommonJS builds, and reports delivery failures based on the real
HTTP response status.
b67a665: fix(deps): update @verdaccio/* packages to the 2026-07-25 release batchUpdates all
@verdaccio/*andverdaccio-*dependencies (config 8.1.4, core 8.1.4,auth 8.0.6, middleware 8.0.7, htpasswd/audit 13.0.5, among others). Notably
@verdaccio/config8.1.4 moves tojs-yaml4.3.0, resolving the high-severityadvisory GHSA-52cp-r559-cp3m
(YAML merge-key chains forcing quadratic CPU consumption).
2969ec8: fix: migrate uplink/storage URL parsing to the WHATWG URL APIRemoves the
[DEP0169] DeprecationWarning: url.parse()printed at startup onNode.js 22+. The proxy and local-storage layers no longer use the legacy
url.parse()/
url.format()helpers; uplink URL validation, distfile filename extraction, and theremote-protocol tarball rewrite now go through the standardized
URLAPI. Behavior isunchanged for the absolute HTTP(S) URLs used in practice — the default HTTPS port
:443still normalizes to a match, and invalid uplink URLs are treated as not-valid instead of
being parsed leniently.
Because the WHATWG
URLconstructor throws on malformed input (unlike the lenient legacyurl.parse()), a misconfigured uplinkurlnow fails fast at startup with a clear,credential-redacted error, and a malformed
dist.tarballreturned by an upstream registryis skipped (with a warning) instead of aborting the package update. Uplink URL validation
also now compares the uplink's own port when deciding whether to ignore the default HTTPS
port, so an HTTPS uplink on a non-default port no longer matches a default-port tarball.
webpack/webpack (webpack)
v5.109.2Compare Source
Patch Changes
Resolve aliases pointing at a package directory whose name ends with
.jsagain. (by @alexander-akait in #21542)Name CSS sources in source maps by their resource path, without the
cssprefix. (by @bjohansebas in #21536)Delete no longer referenced files from the filesystem cache directory after storing the cache, age them by recorded time so restored caches are cleaned too, and collect every fully expired pack in one store instead of one per build. (by @bjohansebas in #21528)
Report
"universal"as the loader context target for the universal target. (by @alexander-akait in #21540)Skip
require().propin dead branches gated by inlined imported constants. (by @hai-x in #21517)Annotate configuration options and public hooks in the generated types with the
@sinceJSDoc tag. (by @bjohansebas in #21473)v5.109.1Compare Source
Patch Changes
Fix stray semicolon emitted before an imported call following a parenthesized sequence element. (by @alexander-akait in #21533)
Make
require(esm)module.exportsre-export analysis independent of module processing order. (by @alexander-akait in #21521)Ignore ERR_SERVER_NOT_RUNNING on lazy-compilation backend dispose so
compiler.close()succeeds on Bun. (by @alexander-akait in #21521)Name the failing key when DefinePlugin fails to evaluate a
typeofvalue. (by @alexander-akait in #21503)Improve Deno compatibility: guard
setNoDelayand force-close connections on lazy-compilation backend dispose, and return a realArrayBufferfrom the Node async/sync wasm loader soWebAssembly.instantiateaccepts it. (by @alexander-akait in #21524)Speed up the HTML parser and cut its peak memory: module-scope helpers/state and tokenizer callbacks, plus exact AST column pre-sizing. (by @alexander-akait in #21492)
Track CommonJS build dependencies by parsing sources when
require.cachechildren are unavailable (e.g. Bun). (by @alexander-akait in #21531)Cook common string-literal escapes on the JS parser fast path and own the tokenizer's cold-path readers. (by @alexander-akait in #21500)
Build the CSS
parseA*AST on the SoA store instead of node classes, cutting parse memory and time. (by @alexander-akait in #21498)Speed up and cut memory of the experimental CSS and HTML parsers: drop two derivable AST node columns, and scan long string, url, comment, and plaintext token bodies natively. (by @alexander-akait in #21504)
Speed up non-modules CSS parsing: skip redundant token re-reads, drop selector-prelude tokens without materializing nodes, allocate rule preludes lazily, and fast-path empty list seals. (by @alexander-akait in #21511)
Speed up stats generation and cut its peak memory: reuse cached sort comparators instead of thrashing the comparator caches on every sort, and drop redundant module-graph lookups and allocations in the extractors. (by @alexander-akait in #21506)
Speed up CSS parsing: byte-range function-name checks, indexed sibling lookahead. (by @bjohansebas in #21520)
Reduce allocations and redundant work across the code-generation, module-concatenation, exports/usage-analysis, hashing, and chunk-splitting hot paths. (by @alexander-akait in #21516)
Enable the Node.js compile cache in the webpack CLI entry point. (by @bjohansebas in #21523)
Encode the persistent cache with V8's value serializer. (by @avivkeller in #21514)
Speed up SplitChunksPlugin: reject non-subset chunk sets with 64-bit signatures, cache unnamed entry keys, and drop per-module closures. (by @avivkeller in #21529)
Initialize
NormalModule._astin the constructor so each instance keeps a single hidden-class shape. (by @alexander-akait in #21515)Reduce allocations in the binary serialization hot paths. (by @alexander-akait in #21526)
Deduplicate and simplify several lib modules and speed up AggressiveMergingPlugin. (by @alexander-akait in #21525)
Rename nested
const/let __webpack_require__and__webpack_exports__declarations in bundled webpack output. (by @hai-x in #21508)webpack/webpack-dev-middleware (webpack-dev-middleware)
v8.1.0Compare Source
Minor Changes
MultiCompilerwatching session instead of starting a duplicate one (requires webpack >= 5.109). (by @bjohansebas in #2371)yargs/yargs (yargs)
v18.1.0Compare Source
Features
Bug Fixes