Skip to content

- Update all non-major dependencies with digest and pinDigest - #181

Open
blumilk-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pindigest
Open

blumilk-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pindigest

Conversation

@blumilk-renovate

@blumilk-renovate blumilk-renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
Infisical/secrets-action action patch v1.0.16 -> v1.0.18 age confidence
alpinejs (source) dependencies minor ^3.15.12 -> ^3.17.4 age confidence
autoprefixer dependencies patch ^10.5.4 -> ^10.5.6 age confidence
axios (source) dependencies minor ^1.13.6 -> ^1.20.0 age confidence
axllent/mailpit (source) minor v1.30.7 -> v1.31.3 v1.31.4 age confidence
composer stage minor 2.9.8 -> 2.10.3 age confidence
docker/build-push-action action minor v7.3.0 -> v7.4.0 age confidence
docker/setup-buildx-action action minor v4.2.0 -> v4.4.1 age confidence
filament/filament (source) require patch ^3.3.50 -> ^3.3.55 age confidence
filament/spatie-laravel-media-library-plugin (source) require patch ^3.3.54 -> ^3.3.55 age confidence
laravel/telescope require-dev minor ^5.22.1 -> ^5.25.0 age confidence
livewire/livewire require patch ^3.8.3 -> ^3.8.10 age confidence
mockery/mockery require-dev patch ^1.6.12 -> ^1.6.15 age confidence
nginx/nginx patch 1.31.3 -> 1.31.6 age confidence
node stage minor 24.19.0-bookworm-slim -> 24.21.0-bookworm-slim age confidence
php final patch 8.3.33-fpm-bookworm -> 8.3.35-fpm-bookworm age confidence
postcss (source) dependencies patch ^8.5.26 -> ^8.5.28 8.5.29 age confidence
postgres final minor 17.10 -> 17.11 age confidence

Release Notes

Infisical/secrets-action (Infisical/secrets-action)

v1.0.18

Compare Source

What's Changed
  • Add project-id input as an alternative to project-slug in #​40

Full Changelog: Infisical/secrets-action@v1.0.17...v1.0.18

v1.0.17

Compare Source

What's Changed
  • feat: add optional secret-name input to fetch a single secret by @​claude[bot] in #​39
New Contributors

Full Changelog: Infisical/secrets-action@v1.0.16...v1.0.17

alpinejs/alpine (alpinejs)

v3.17.4

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.17.3...v3.17.4

v3.17.3

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.17.2...v3.17.3

v3.17.2

Compare Source

What's Changed

Full Changelog: alpinejs/alpine@v3.17.1...v3.17.2

v3.17.1

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.17.0...v3.17.1

v3.17.0

Compare Source

What's Changed

New Contributors

Full Changelog: alpinejs/alpine@v3.16.3...v3.17.0

v3.16.3

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.16.2...v3.16.3

v3.16.2

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.16.1...v3.16.2

postcss/autoprefixer (autoprefixer)

v10.5.6

Compare Source

v10.5.5

Compare Source

axios/axios (axios)

v1.20.0

Compare Source

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#​11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#​11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#​11087, #​11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#​11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#​11094, #​11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#​11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#​11096)

🔧 Maintenance & Chores

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

axllent/mailpit (axllent/mailpit)

v1.31.3

Compare Source

Chore
  • Limit maximum MIME parts parsed per message to 500
  • Refactor regex usage for string cleaning and normalization
  • Optimize envelope parsing by using a shared parser instance
  • Optimize message summary construction by eliminating JSON round-trip
  • Replace bytes.ToLower with containsFold for case-insensitive tag matching
  • Replace inline regex for leading whitespace with a package-level variable
  • Symlink sendmail to Mailpit in Docker image (#​736)
  • Update Go dependencies
  • Update node dependencies
  • Update GitHub Actions dependencies

v1.31.2

Compare Source

Security
Feature
  • Add major version tag for Docker images in workflow (#​734)
Chore
  • Improve message rendering performance with envelope caching
  • Update Go dependencies
  • Update node dependencies
  • Update caniemail test database
Fix
  • Re-quote local-parts in API JSON responses (#​732)

v1.31.1

Compare Source

Security
  • Add --allowed-hosts flag to mitigate DNS rebinding against the API
Chore
  • Update Go dependencies
  • Update node dependencies
  • Update Github Actions
Fix
  • Block Azure WireServer, IPv4-translated prefix and additional reserved ranges in SSRF deny-list
  • Pass line-boundary state to drainData to prevent SMTP desync
  • Allow SP inside quoted local-parts per RFC 5321 (#​731)
  • Bound header-rewrite scanner to header block and fail closed on missing header
  • Prevent quadratic CPU in proxy CSS rewriter via O(1) asset dedup

v1.31.0

Compare Source

Feature
  • Add deep dark theme (#​728)
  • Add debounced search refresh for filtered views on new messages
Chore
  • Make read/unread message state clearly distinguishable (WCAG AA)
  • Add accessible names to icon-only buttons and fix sender tag mismatch
  • Update Go dependencies
  • Update node dependencies
  • Update caniemail test database
  • Update GitHub Actions
Fix
  • Include all IANA special-use IPv4 ranges in IsInternalIP check
  • Prevent SMTP command injection via drainData fragment-boundary bypass
  • Validate Send API custom header keys per RFC 5322
docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.4.1

Compare Source

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

filamentphp/panels (filament/filament)

v3.3.55

Compare Source

filamentphp/spatie-laravel-media-library-plugin (filament/spatie-laravel-media-library-plugin)

v3.3.55

Compare Source

laravel/telescope (laravel/telescope)

v5.25.0

Compare Source

v5.24.0

Compare Source

v5.23.0

Compare Source

livewire/livewire (livewire/livewire)

v3.8.10

Compare Source

What's Changed

Full Changelog: livewire/livewire@v3.8.9...v3.8.10

v3.8.9

Compare Source

What's Changed

Full Changelog: livewire/livewire@v3.8.8...v3.8.9

v3.8.8

Compare Source

What's Changed

Full Changelog: livewire/livewire@v3.8.7...v3.8.8

v3.8.7

Compare Source

What's Changed

Full Changelog: livewire/livewire@v3.8.6...v3.8.7

v3.8.6

Compare Source

What's Changed

New Contributors

Full Changelog: livewire/livewire@v3.8.5...v3.8.6

v3.8.5

Compare Source

What's Changed

New Contributors

Full Changelog: livewire/livewire@v3.8.4...v3.8.5

mockery/mockery (mockery/mockery)

v1.6.15

Compare Source

Fixed

v1.6.14

Compare Source

Changed
Fixed

v1.6.13

Compare Source

Added
Changed
Fixed
nginx/nginx (nginx/nginx)

v1.31.6

Compare Source

nginx-1.31.6 mainline version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module (CVE-2026-90439).

See official CHANGES on nginx.org.

Below is a release summary generated by GitHub.

What's Changed

Full Changelog: nginx/nginx@release-1.31.5...release-1.31.6

v1.31.5

Compare Source

nginx-1.31.5 mainline version has been released, featuring control API, predicate locations, client_body_early_read directive and the ngx_http_json_module.

See official CHANGES on nginx.org.

Below is a release summary generated by GitHub.

What's Changed

New Contributors

Full Changelog: nginx/nginx@release-1.31.4...release-1.31.5

v1.31.4

Compare Source

nginx-1.31.4 mainline version has been released.

See official CHANGES on nginx.org.

Below is a release summary generated by GitHub.

What's Changed

New Contributors

Full Changelog: nginx/nginx@release-1.31.3...release-1.31.4

nodejs/node (node)

v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #​65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #​63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #​65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #​65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #​65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #​64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #​65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #​64965
Commits
  • [84d706cb9b] - assert: improve documentation wording (Kamal Rawal) #​64953
  • [90d127db33] - (SEMVER-MINOR) benchmark: add --analyze mode to compare.js (James M Snell) [#&#820

Configuration

📅 Schedule: Branch creation - On day 1 of the month, every 3 months ( * * 1 */3 * ) in timezone Europe/Warsaw, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@blumilk-renovate
blumilk-renovate Bot requested a review from a team as a code owner October 1, 2026 10:49
@blumilk-renovate
blumilk-renovate Bot requested a review from Blusia October 1, 2026 10:49
@blumilk-renovate

blumilk-renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm warn Unknown env config "store". This will error in a future major version of npm. See `npm help npmrc` for supported config options.
npm error code EALLOWREMOTE
npm error Fetching packages of type "remote" have been disabled
npm error Refusing to fetch "https://registry.npmjs.org/@tailwindcss/oxide-wasm32-wasi/-/oxide-wasm32-wasi-4.3.3.tgz"
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2026-10-05T10_41_19_879Z-debug-0.log

@blumilk-renovate
blumilk-renovate Bot force-pushed the renovate/all-minor-patch-digest-pindigest branch 3 times, most recently from 902d48f to 8d09a10 Compare October 4, 2026 10:41
@blumilk-renovate
blumilk-renovate Bot force-pushed the renovate/all-minor-patch-digest-pindigest branch from 8d09a10 to 078a6c8 Compare October 5, 2026 10:41

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants