Skip to content

fix(deps): update all non-major dependencies - #38

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/all-non-major-dependencies
Oct 5, 2026
Merged

renovate[bot] merged 1 commit into
masterfrom
renovate/all-non-major-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@commitlint/cli (source) 21.2.2 → 21.2.3 age confidence
@eslint/eslintrc 3.3.6 → 3.3.7 age confidence
@posthog/nextjs-config (source) 1.9.70 → 1.11.1 age confidence
@testing-library/react 16.3.2 → 16.3.3 age confidence
@types/node (source) 24.19.0 → 24.19.1 age confidence
@types/react (source) 19.2.18 → 19.3.0 age confidence
@types/react-dom (source) 19.2.4 → 19.3.0 age confidence
@typescript-eslint/eslint-plugin (source) 8.67.0 → 8.71.0 age confidence
@typescript-eslint/parser (source) 8.67.0 → 8.71.0 age confidence
eslint-config-next (source) 16.3.1 → 16.3.8 age confidence
happy-dom 20.11.6 → 20.14.5 age confidence
next (source) 16.3.6 → 16.3.8 age confidence
pnpm (source) 10.34.5 → 10.34.6 age confidence
postcss (source) 8.5.26 → 8.5.28 age confidence
posthog-js (source) 1.418.6 → 1.435.6 age confidence
prettier (source) 3.9.6 → 3.9.9 age confidence
react (source) 19.2.8 → 19.3.0 age confidence
react-dom (source) 19.2.8 → 19.3.0 age confidence
react-hook-form (source) 7.85.0 → 7.89.0 age confidence
sass 1.103.1 → 1.105.1 age confidence
tailwind-merge (source) 3.6.0 → 3.7.0 age confidence
typescript-eslint (source) 8.67.0 → 8.71.0 age confidence
zod (source) 4.4.3 → 4.6.5 age confidence

Release Notes

conventional-changelog/commitlint (@​commitlint/cli)

v21.2.3

Compare Source

Bug Fixes
  • lint: trim trailing whitespace off the message handed to ignore matchers (#​4960) (a6f279b)
eslint/eslintrc (@​eslint/eslintrc)

v3.3.7

Compare Source

Bug Fixes
PostHog/posthog-js (@​posthog/nextjs-config)

v1.11.1

Compare Source

Patch Changes
  • #​4768 09c6b93 Thanks @​marandaneto! - Delete webpack server source maps after upload without leaving them in Next.js deployment traces.
    (2026-09-04)

v1.11.0

Compare Source

Minor Changes
  • #​4705 dd5888a Thanks @​ablaszkiewicz! - Change the default sourcemaps.releaseMode to event: set sourcemaps.releaseMode: 'symbol-set', or POSTHOG_RELEASE_MODE=symbol-set, to keep binding uploaded symbol sets to a release. The @posthog/plugin-utils bump is major, so an installed plugin keeps the old default until the plugin itself is upgraded.

    event mode requires a posthog-cli with release resolve and --release-mode, and posthog-js 1.409.0, posthog-node 5.47.0, or @posthog/core 1.46.0 at runtime. An older CLI fails a rollup build and skips the upload on webpack and Next.js. An older SDK reports no release on exceptions. (2026-09-02)

Patch Changes
  • #​4737 c589ab8 Thanks @​cat-ph! - Bump @posthog/cli to ~0.16.2, which fixes a race in sourcemap process: inject and upload used to walk the directory roots separately, so a bundler still writing into the output directory mid-run (e.g. Turbopack's background filesystem-cache flush on Next.js 16.3+) could hand upload a chunk inject never stamped and abort the build with "Chunk ID not found". The CLI now uploads exactly the pairs it injected, and --delete-after cleanup skips files that vanished or changed after upload instead of failing the build.
    (2026-09-02)
  • Updated dependencies [c589ab8, dd5888a]:

v1.10.0

Compare Source

Minor Changes
  • #​4563 530d88b Thanks @​ablaszkiewicz! - Add experimental sourcemaps.releaseMode: 'event' to the webpack plugin and Next.js config. In event mode posthog-cli resolves the release once and injects its id into every chunk on disk, so exceptions report their release directly instead of it being bound to the uploaded symbol sets, and chunk ids are content-derived so a rebuild of unchanged code reuses the symbol set already uploaded. On webpack >= 5.104 the plugin also turns on webpack's own debug ids, which the CLI adopts as chunk ids, so one id identifies a chunk across the whole toolchain. The option defaults to the POSTHOG_RELEASE_MODE environment variable and then to symbol-set, which behaves exactly as before. Event mode needs a posthog-cli with the release resolve command.
    (2026-08-24)
Patch Changes
  • #​4563 530d88b Thanks @​ablaszkiewicz! - Bump @posthog/cli to ~0.14.1, which makes sourcemap inject --release-mode=event adopt a bundler-emitted ECMA-426 debug id as the chunk id instead of deriving its own, so the ids webpack stamps into each chunk are the ones the CLI uploads against.
    (2026-08-24)
  • Updated dependencies [530d88b, 530d88b]:
testing-library/react-testing-library (@​testing-library/react)

v16.3.3

Compare Source

Bug Fixes
typescript-eslint/typescript-eslint (@​typescript-eslint/eslint-plugin)

v8.71.0

Compare Source

🚀 Features
  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#​12732)
🩹 Fixes
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#​12912)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#​12832)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#​12885)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.1

Compare Source

🩹 Fixes
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#​12904)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#​12826)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#​12747)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#​12845)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#​12880)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#​12716)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#​12873)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#​12869)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#​12850)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#​12854)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#​12818)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#​12637)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#​12768)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

🚀 Features
  • eslint-plugin: [no-generated-empty-object-type] add rule (#​12730)
🩹 Fixes
  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#​12780)
  • eslint-plugin: [no-unnecessary-condition] no false positive on RHS of a nested logical expression (#​12728)
  • eslint-plugin: [member-ordering] don't report fields that read fields declared before them (#​12729)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

🚀 Features
  • eslint-plugin: [no-misused-promises] add flagUnions option for checkConditionals (#​12603)
🩹 Fixes
  • eslint-plugin: [no-meaningless-void-operator] report void on non-call expressions (#​12727)
  • eslint-plugin: [unified-signatures] compare type parameters by constraint instead of name (#​12741)
  • eslint-plugin: [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (#​12731)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

🚀 Features
  • eslint-plugin: [strict-void-return] add fix suggestions (#​12086)
🩹 Fixes
  • eslint-plugin: [no-empty-object-type] ignore suggestions that result in invalid interfaces and export defaults (#​12739)
  • eslint-plugin: [no-floating-promises] setting ignoreVoid: false results in false negative in ArrowFunctionExpression (#​12646)
  • eslint-plugin: [no-unnecessary-type-assertion] prevent stack overflow in recursive types (#​12711)
  • eslint-plugin: [unified-signatures] report identical signatures (#​12678)
  • eslint-plugin: [return-await] prevent autofix from breaking code in arrow-functions (#​12707)
  • eslint-plugin: [unified-signatures] deduplicate types in report (#​12656)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

typescript-eslint/typescript-eslint (@​typescript-eslint/parser)

v8.71.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.1

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

vercel/next.js (eslint-config-next)

v16.3.8

Compare Source

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#​98931)
Credits

Huge thanks to @​lukesandberg for helping!

v16.3.6

Compare Source

v16.3.5

Compare Source

v16.3.4

Compare Source

v16.3.3

Compare Source

v16.3.2

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • [backport] Scope app-entry export validation to files inside the app directory (#​97357)
  • [backport] Fix catch-all index page being served for every other slug (#​97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#​97353) (#​97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#​97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#​97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#​97603)
Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

capricorn86/happy-dom (happy-dom)

v20.14.5

Compare Source

v20.14.4

Compare Source

👷‍♂️ Patch fixes

v20.14.3

Compare Source

👷‍♂️ Patch fixes

v20.14.2

Compare Source

👷‍♂️ Patch fixes

v20.14.1

Compare Source

v20.14.0

Compare Source

🎨 Features

v20.13.2

Compare Source

👷‍♂️ Patch fixes

v20.13.1

Compare Source

v20.13.0

Compare Source

🎨 Features

v20.12.2

Compare Source

v20.12.1

Compare Source

v20.12.0

Compare Source

v20.11.15

Compare Source

👷‍♂️ Patch fixes

v20.11.14

Compare Source

v20.11.13

Compare Source

👷‍♂️ Patch fixes

v20.11.12

Compare Source

👷‍♂️ Patch fixes

v20.11.11

Compare Source

v20.11.10

Compare Source

v20.11.9

Compare Source

v20.11.8

Compare Source

👷‍♂️ Patch fixes
  • Values pushed or assigned to the adoptedStyleSheet array should be validated - By @​capricorn86 in task #​2315

v20.11.7

Compare Source

👷‍♂️ Patch fixes
  • The properties Document.adoptedStyleSheets and ShadowRoot.adoptedStyleSheets should validate it's value - By @​capricorn86 in task #​2313
pnpm/pnpm (pnpm)

v10.34.6

Compare Source

Patch Changes
  • e7888e5: pnpm self-update now resolves and verifies pnpm through registry, authentication, proxy, and TLS settings from trusted non-project configuration. Project configuration and the default project pnpmfile can no longer redirect the pnpm download or disable engine identity verification.

  • 46bc7c9: pnpm no longer tells you to update itself with Corepack or with pnpm add -g:

    • The update notification now suggests pnpm self-update, or the standalone install script when pnpm is running under Corepack. It used to suggest corepack use pnpm@<version>, or pnpm add -g pnpm / pnpm add -g @pnpm/exe when pnpm was not installed by the standalone script — but pnpm add -g refuses to install pnpm and points at pnpm self-update anyway, and @pnpm/exe is not published for pnpm v12 or newer, where the unscoped pnpm package is itself the native executable.
    • pnpm self-update under Corepack now points at the standalone install script too, instead of telling you to update pnpm with Corepack.
  • 46bc7c9: Updated adm-zip to v0.6.0, which fixes a memory-exhaustion vulnerability where a crafted ZIP file could make it allocate 4 GB of memory. adm-zip is used to extract the Node.js, Bun, and Deno archives that pnpm downloads on Windows.

  • Updated the embedded Node.js release keys to the current canonical nodejs/release-keys list.

  • Updated the embedded npm registry signing keys to the set currently advertised by npm.

  • 702ad5f: Update the embedded Node.js release keys with the new key added to nodejs/release-keys (Stewart X Addison, 655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD).

Platinum Sponsors

Bit

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx
postcss/postcss (postcss)

v8.5.28

Compare Source

  • Fixes types regression.

v8.5.27

Compare Source

PostHog/posthog-js (posthog-js)

v1.435.6

Compare Source

1.435.6

Patch Changes

v1.435.5

Compare Source

1.435.5

Patch Changes
  • #​5167 59b93a3 Thanks @​dustinbyrne! - Preserve session attribution and registered properties across initialization and configuration updates when persistence writes are debounced.
    (2026-09-30)

v1.435.4

Compare Source

1.435.4

Patch Changes
  • #​5158 5c92e83 Thanks @​posthog! - Fix a DataCloneError when session replay records network timing inside a cross-origin iframe.
    (2026-09-30)

v1.435.3

Compare Source

1.435.3

Patch Changes
  • #​4976 47db7ce Thanks @​posthog! - Start session recording at DOMContentLoaded, so a page whose load event is late or never fires still records, and report $sdk_debug_rrweb_attached from rrweb's own recording state
    (2026-09-30)

v1.435.2

Compare Source

1.435.2

Patch Changes
  • #​5144 bd66cee Thanks @​marandaneto! - Reduce replay debug properties on captured events while preserving recording status and capture diagnostics. Report cumulative mutation-drop counts and dropped bytes on $snapshot events only when greater than zero.
    (2026-09-30)

v1.435.1

Compare Source

1.435.1

Patch Changes

v1.435.0

Compare Source

1.435.0

Minor Changes
  • #​4794 e89d224 Thanks @​AyobamiH! - Add onActiveMatchingSurveysChanged to subscribe to survey eligibility updates with safe unsubscribe and recoverable load-error reporting.
    (2026-09-29)
Patch Changes

v1.434.18

Compare Source

1.434.18

Patch Changes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Chicago)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot merged commit 1bbaddd into master Oct 5, 2026
3 checks passed
@renovate
renovate Bot deleted the renovate/all-non-major-dependencies branch October 5, 2026 09:51
@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
rdap Ready Ready Preview Oct 5, 2026 9:52am UTC

@codecov-commenter

codecov-commenter commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.58%. Comparing base (77f116d) to head (6727635).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master      #38   +/-   ##
=======================================
  Coverage   95.58%   95.58%           
=======================================
  Files          16       16           
  Lines         657      657           
  Branches      207      207           
=======================================
  Hits          628      628           
  Misses         29       29           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch was successfully deployed

1 active deployment
Preview — 67276354 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant