Skip to content

chore(deps): update all non-major dependencies - #320

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@better-auth/passkey (source) ^1.7.6 → ^1.7.7 age confidence
@cloudflare/vitest-plugin (source) 1.3.0 → 1.3.7 age confidence
@iconify-json/lucide ^1.2.137 → ^1.2.140 age confidence
@iconify-json/simple-icons ^1.2.97 → ^1.2.99 age confidence
@nuxt/scripts (source) 1.3.9 → 1.3.12 age confidence
@nuxt/test-utils ^4.3.2 → ^4.3.3 age confidence
@nuxt/ui (source) ^4.11.2 → ^4.11.3 age confidence
@unhead/vue (source) ^3.4.1 → ^3.4.2 age confidence
better-auth (source) ^1.7.6 → ^1.7.7 age confidence
eslint (source) ^10.11.0 → ^10.12.0 age confidence
nodemailer (source) ^10.0.11 → ^10.0.15 age confidence
pnpm (source) 12.6.0 → 12.10.1 age confidence
vue-tsc (source) ^3.3.11 → ^3.3.12 age confidence
wrangler (source) 4.142.0 → 4.148.0 age confidence

Release Notes

better-auth/better-auth (@​better-auth/passkey)

v1.7.7

Compare Source

cloudflare/workers-sdk (@​cloudflare/vitest-plugin)

v1.3.7

Compare Source

Patch Changes

v1.3.6

Compare Source

Patch Changes

v1.3.5

Compare Source

Patch Changes

v1.3.4

Compare Source

Patch Changes

v1.3.3

Compare Source

Patch Changes

v1.3.2

Compare Source

Patch Changes

v1.3.1

Compare Source

Patch Changes
  • Updated dependencies [7f0734c]:
    • wrangler@​4.143.0
nuxt/scripts (@​nuxt/scripts)

v1.3.12

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.11

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.10

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
nuxt/test-utils (@​nuxt/test-utils)

v4.3.3

Compare Source

v4.3.3 is the next patch release.

👉 Changelog

compare changes

🔥 Performance
  • use h3's toWebHandler instead of node-mock-http (abe8ad944)
  • resolve h3 from the project (b5d802f03)
  • replace estree-walker with oxc-walker (8e8ca5e8b)
  • replace local-pkg with exsolve (38938a879)
  • replace c12 with native dotenv parsing (26c72afa0)
  • inline destr and scule usage (e4bfd2ebe)
  • drop node-fetch-native polyfill (6b654de5c)
  • replace nypm with package-manager-detector (#​1828)
🩹 Fixes
  • runtime-utils: type registerEndpoint against the project h3 (#​1831)
  • e2e: restore console after use nuxt kit (#​1817)
  • config: exclude aliased mock packages from optimizeDeps in browser mode (#​1816)
  • runtime: setup nuxt once per worker in no-isolate (#​1821)
  • browser: correct render helper options type (#​1822)
🏡 Chore
  • move vue to peer dependencies (e70592ffa)
  • declare supported nuxt versions as peer dependency (b473892c9)
🤖 CI
❤️ Contributors
nuxt/ui (@​nuxt/ui)

v4.11.3

Compare Source

Bug Fixes
  • App: apply the dir prop to the provided locale (#​6767) (93c40df)
  • ChatPrompt: add method="post" to prevent input leaking via GET before hydration (#​7078) (57f7699)
  • CheckboxGroup/RadioGroup: lift a hovered table item above its neighbors (#​7073) (926097a)
  • ContentSearch/DashboardSearch: use translated search label as dialog title (#​7062) (3c55cf2)
  • DashboardSidebar/Header: use translated toggle label as menu dialog title (#​7082) (51e98da)
  • EditorToolbar: use tooltip text as aria-label on icon-only buttons (#​7009) (7f0250e)
  • Form: include nested forms in parent dirty state (#​6545) (8977394)
  • Form: keep dirty state and validation in sync with input (#​7033) (56b1156)
  • Form: merge unnamed nested forms into a parent without schema (#​7034) (384fdc1)
  • module: detect kebab-case components in Pug templates (#​7045) (42ba532)
  • module: generate classes prefixed by usePrefix (#​7074) (77c92de)
  • module: use @custom-variant for light and dark variants (#​7023) (584016b)
  • ProseA: only round corners on focus (3da141c)
  • Select/SelectMenu: keep focus moved on selection (#​7083) (6138bf0)
  • Table: keep footer separator above pinned columns (#​7047) (e8756fd)
  • theme: drop double quotes from class strings (#​7039) (5a04c6c)
  • useFilter: keep labels and separators in place while sorting (#​6995) (032a152)
  • useOverlay: resolve every pending promise when reopened (#​7057) (2f50c2e)
  • utils: prevent prototype pollution in set and setAtPath (#​7077) (4bfd115)
unjs/unhead (@​unhead/vue)

v3.4.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
better-auth/better-auth (better-auth)

v1.7.7

Compare Source

Patch Changes
  • #​11476 4186e36 Thanks @​bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.

  • #​11469 8620aa9 Thanks @​aryan1306! - Return rate limit errors with a JSON Content-Type header.

  • #​11491 55cb92e Thanks @​bytaesu! - Respect social provider disableSignUp when signing in with an ID token.

  • #​11375 69defbc Thanks @​bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.

  • #​11494 ac54bfd Thanks @​gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. The oAuthProxy options and supported configuration remain unchanged.

    Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.

  • #​11494 ac54bfd Thanks @​gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. Magic
    Link records and database-backed OAuth or SAML state use separate verification
    identifier prefixes. Links and database-backed sign-ins started before the
    upgrade cannot complete; request new Magic Links and restart those sign-ins.
    Upgrade servers sharing verification storage together, and update
    verification.storeIdentifier.overrides rules for these flows to match the new
    magic-link: and auth-state: prefixes. The link token, callback state,
    endpoints, and public option types are unchanged.

    Upgrade installed Better Auth adapters, plugins, and integrations released
    with better-auth alongside it so participating packages use the same release
    version.

  • Updated dependencies [35d7cd3, 07bdf7e]:

eslint/eslint (eslint)

v10.12.0

Compare Source

Features

  • 4618052 feat: handle astral letters in new-cap (#​21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#​21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#​21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#​21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#​21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#​21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#​21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#​21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#​21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#​21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#​21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#​21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#​21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#​21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#​21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#​21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#​21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#​21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#​21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#​21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#​21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#​21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#​21342) (ESLint Bot)
nodemailer/nodemailer (nodemailer)

v10.0.15

Compare Source

Bug Fixes

v10.0.14

Compare Source

Bug Fixes
  • addressparser: keep a quoted display name that holds no "@​" out of the address (3570d26)
  • addressparser: keep the group recursion depth out of the options object (a680254)
  • addressparser: stop a "[" from hiding the operators after it (5619784)
  • dkim: trim a header field name in linear time (c6f7a55)
  • mime-funcs: read and write header parameters per rfc2045 and rfc2231 (b8ccad7)
  • search only the new bytes for the end of the proxy CONNECT response (81efd7b)

v10.0.13

Compare Source

Bug Fixes
  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

v10.0.12

Compare Source

Bug Fixes
  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)
pnpm/pnpm (pnpm)

v12.10.1: pnpm 12.10.1

Compare Source

This release fixes pnpm install failures after an overrides change and on a filtered frozen install with catalogPrune. It also fixes several bugs in the experimental nodeLinker.type: loaded, which now keeps its generated files in node_modules.

Patch Changes
  • With nodeLinker.type: loaded, pnpm now writes its generated files to node_modules, which projects already ignore in git. The store manifest and loader are node_modules/.pnpm/.store-manifest.json and node_modules/.pnpm/.store-loader.mjs. Bin shims are in node_modules/.bin.

    Earlier versions wrote .pnpm-store.json and .pnpm-store-loader.mjs to the project root, and a .pnpm directory to the root and to each workspace package. Delete them after reinstalling.

  • With nodeLinker.type: loaded, packages that ship their own node_modules directory, such as npm with its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.

  • With nodeLinker.type: loaded, scripts can now run a Node.js runtime installed through devEngines.runtime. Before, every script that called node re-ran its own shim until it failed with "Argument list too long".

  • With nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.

  • pnpm install no longer fails with ERR_PNPM_NO_MATCHING_VERSION after a change to overrides when the lockfile resolves an optional peer dependency to an npm alias of another package #​16654.

  • A frozen install with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records. Before, pnpm install --frozen-lockfile --filter failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH when some workspace projects were missing from disk #​16638.

  • pnpm install --fix-lockfile no longer removes the deprecated and hasBin fields from lockfile entries #​6600.

  • With enableGlobalVirtualStore, an install that updates node_modules now repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project's node_modules already recorded it #​16642.

  • pnpm install now skips the Cargo and Python projects inside a nested directory that has its own pnpm-workspace.yaml or .git directory, such as a git worktree of the same workspace or a separate clone.

  • The Request took warning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.10.0: pnpm 12.10.0

Compare Source

This release adds an experimental loaded node linker, lets pnpm-lock.yaml record resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.

Minor Changes
  • Added experimental nodeLinker: { type: loaded } installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader. nodeLinker.excluded selects packages and their dependency trees to install in the global virtual store.

  • lockfile.includeResolutionSettings: true makes pnpm-lock.yaml record autoDedupe, dedupeInjectedDeps, dedupePeerDependents and linkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that records autoDedupe is reused by later installs on any machine, so pnpm run after pnpm install --frozen-lockfile no longer starts another install #​16583.

Patch Changes
Security
  • pnpm install now prevents dependency versions with path traversal from writing files outside the global virtual store.

  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm install and pnpm publish now reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • The warning about an ignored project .npmrc registry setting no longer prints the username and password of a URL-scoped key such as //user:password@registry.example.com/${PATH}/:_authToken.

Installing and resolving dependencies
  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. On Windows, such a specifier failed with os error 123. On other platforms, pnpm linked it to a directory that does not exist. Reading a package.json that fails now names the file #​16590.

  • pnpm install now fails with ERR_PNPM_PACKAGE_MANIFEST_INVALID_ATTRIBUTE when a project declares a dependency whose specifier is not a string, such as "is-positive": 42. Before, the dependency was silently left out of the lockfile. A readPackage hook can still correct the specifier.

  • Fixed pnpm install failing with ERR_PNPM_CMD_SHIM_RESOLVE_PATH when an executable's parent directory contains a dangling symlink.

  • pnpm install --frozen-lockfile no longer fails with ERR_PNPM_RESOLUTION_SHAPE_MISMATCH when a name@version lockfile entry has a resolution served by a custom fetcher pnpm/tasks#108.

  • pnpm install --fix-lockfile repairs a lockfile whose importer references a package that has no snapshot entry, as left by a badly merged lockfile. It failed with ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY since 12.8.0 #​16618.

  • When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before, pnpm install and pnpm dedupe kept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies of vue pnpm/tasks#61.

  • pnpm dedupe now reads registry metadata for a dependency pinned to an exact version, as pnpm install does. If the registry metadata disagreed with the package's package.json, the lockfile it wrote depended on whether minimumReleaseAge was set #​16615.

Speed and size
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set. pnpm cache prune also removes the metadata cache that older pnpm versions wrote under <cache-dir>/v11/ #​13512.

  • Package metadata requests no longer wait behind queued tarball downloads when maxSockets or a proxy limits the connections to a registry. Large installs resolve faster and print fewer Request took warnings.

  • Sped up installs in large workspaces on macOS when the dependency links already exist. pnpm now keeps a link that already points at the right package without trying to create it first. Relinking the direct dependencies of 1,000 workspace projects took 45 ms, down from 116 ms pnpm/tasks#65.

  • Commands in a project that pins a different pnpm version start about 13 ms faster on macOS. pnpm now runs the pinned version's binary directly, without the shell script in front of it pnpm/tasks#66.

  • The pnpm binary is about 0.9 MB smaller, and the arm64 Linux binary is about 1 MB smaller still.

Running scripts and commands
  • pnpm run no longer prints [ELIFECYCLE] Command failed ... after Ctrl+C ends the script. pnpm still exits the way the script's shell did: on Windows with the shell's exit code (cmd reports -1073741510, PowerShell 1), on Unix by re-raising SIGINT #​16579.

  • pnpm run "/<regex>/" now accepts JavaScript regular expression syntax such as lookahead and lookbehind. A selector like "/^hello:(?!b).*$/" failed with ERR_PNPM_NO_SCRIPT #​16604.

  • pnpm run and pnpm exec now forward --config.* command-line flags to the install started by verifyDepsBeforeRun pnpm/tasks#60.

  • On Windows, a process started by pnpm run or pnpm exec can again start a child with CREATE_BREAKAWAY_FROM_JOB. That child keeps running after pnpm exits, even if the command fails #​16628.

  • Empty nodeOptions values from command-line flags and environment variables now override lower-priority settings. Scripts retain NODE_OPTIONS from the parent environment or extraEnv when nodeOptions is empty.

  • pnpm now reads the failIfNoMatch setting from pnpm-workspace.yaml, so a filter that matches no workspace project exits with code 1 when the setting is true. The new --no-fail-if-no-match flag turns the setting off for one command #​16577.

Configuration, setup, and pnpm versions
  • pnpm config get --global and pnpm config list --global now show only the global configuration, also when run inside a project. Settings from the project's pnpm-workspace.yaml and .npmrc were included before. The same applies to --location=global #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the packageManager field pins it. Since 12.9.0 they failed with SyntaxError: Invalid or unexpected token #​16594.

  • On Windows, pnpm self-update no longer runs the update a second time when it replaces a pnpm.cmd linked by pnpm 12.8 or older. cmd.exe read on in the replaced pnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #​16573.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config [#​16635](htt

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Dependency updates and dependency maintenance automation label Oct 5, 2026
@renovate
renovate Bot deployed to preview October 5, 2026 00:34 Active
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: niklhut/libroo/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: bb7fb126-408d-418f-b3bd-1c51fa31b98c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Cloudflare preview

✅ Preview deployed: https://libroo-pr-320.00doggies-revers.workers.dev

Worker: libroo-pr-320
D1 / R2: libroo-preview-pr-320
Access: libroo-preview-pr-320

View workflow run

This branch was successfully deployed

1 active deployment
preview — 60cdae8d Deployed Oct 7, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates and dependency maintenance automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants