Skip to content

- Update all non-major dependencies with digest and pinDigest - #609

Open
blumilk-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pindigest
Open

blumilk-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pindigest

Conversation

@blumilk-renovate

@blumilk-renovate blumilk-renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
@inertiajs/vue3 (source) ^2.3.27 -> ^2.3.28 age confidence dependencies patch
@vitejs/plugin-vue (source) ^6.0.8 -> ^6.0.9 age confidence dependencies patch
@vue/compiler-sfc (source) ^3.5.40 -> ^3.5.43 age confidence dependencies patch
actions/checkout v6.0.3 -> v6.1.0 age confidence action minor
alpine 3.22.5 -> 3.22.6 age confidence stage patch
axios (source) ^1.13.6 -> ^1.20.0 age confidence dependencies minor
azuyalabs/yasumi (source) ^2.11.0 -> ^2.12.0 age confidence require minor
barryvdh/laravel-debugbar ^4.0.10 -> ^4.4.4 age confidence require-dev patch
composer 2.9.8 -> 2.10.3 age confidence stage minor
composer/composer 2.9.8-bin -> 2.10.3-bin age confidence stage minor
docker/build-push-action v7.3.0 -> v7.4.0 age confidence action minor
docker/login-action v4.4.0 -> v4.6.0 age confidence action minor
docker/setup-buildx-action v4.2.0 -> v4.4.1 age confidence action minor
dompdf/dompdf ^3.1.5 -> ^3.1.6 age confidence require patch
floating-vue (source) ^5.2.2 -> ^5.4.0 age confidence dependencies minor
guzzlehttp/guzzle (source) ^7.10.0 -> ^7.10.6 age confidence require patch
inertiajs/inertia-laravel ^2.0.24 -> ^2.0.28 age confidence require patch
laravel/dusk (source) ^8.6.0 -> ^8.7.0 age confidence require-dev minor
laravel/socialite (source) ^5.29.0 -> ^5.31.0 age confidence require minor
laravel/telescope ^5.21.0 -> ^5.25.0 age confidence require minor
mockery/mockery ^1.6.12 -> ^1.6.15 age confidence require-dev patch
node 22.22.3 -> 22.23.3 age confidence uses-with minor
node 22.22.3-bookworm-slim -> 22.23.3-bookworm-slim age confidence stage minor
php 8.4.23 -> 8.4.26 age confidence patch
php 8.4.23-cli-bookworm -> 8.4.26-cli-bookworm age confidence final patch
php 8.4.23-cli-bookworm -> 8.4.26-cli-bookworm age confidence stage patch
phpunit/phpunit (source) ^12.0.10 -> ^12.5.37 age confidence require-dev patch
postcss (source) ^8.5.22 -> ^8.5.28 age confidence dependencies patch
postgres 74e110c -> 724292d service digest
postgres 74e110c -> 724292d digest
selenium/standalone-chrome 9569014 -> 7efe71e digest
sentry/sentry-laravel (source) ^4.27.0 -> ^4.28.0 age confidence require minor
vue (source) ^3.5.40 -> ^3.5.43 age confidence dependencies patch
vue-echarts ^8.0.1 -> ^8.3.1 age confidence dependencies minor

Release Notes

inertiajs/inertia (@​inertiajs/vue3)

v2.3.28

Compare Source

What's Changed

Full Changelog: inertiajs/inertia@v2.3.27...v2.3.28

vitejs/vite-plugin-vue (@​vitejs/plugin-vue)

v6.0.9

Bug Fixes
Miscellaneous Chores
vuejs/core (@​vue/compiler-sfc)

v3.5.43

Compare Source

Bug Fixes

v3.5.42

Compare Source

Bug Fixes

v3.5.41

Compare Source

Bug Fixes
actions/checkout (actions/checkout)

v6.1.0

Compare Source

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

axios/axios (axios)

v1.20.0

Compare Source

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#​11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#​11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#​11087, #​11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#​11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#​11094, #​11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#​11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#​11096)

🔧 Maintenance & Chores

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

v1.19.0

Compare Source

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

azuyalabs/yasumi (azuyalabs/yasumi)

v2.12.0

Compare Source

Features
  • Add Kenya holiday provider (#​418)
  • (Colombia) Add Day of Our Lady of the Rosary of Chiquinquirá holiday
  • Add Colombia holiday provider (#​403)
  • (Italy) Add San Francesco of Assisi public holiday
  • (Australia) Refresh holiday rules and rename Queen's Birthday to Monarch's Birthday (#​410)
Fixes
  • (South Korea) Add missing namespace to LabourDayTest
  • (Various typos) Correct spelling errors
  • (Canada) Add Boxing Day as explicit holiday and fix tests
  • Replace outdated PHP timezone names (#​425)
  • (Canada) Add Victoria Day and correct historical year bounds
  • (SouthKorea) Correct buddhasBirthday translation year bound and update source URL
  • (Argentina) Align code style with codebase conventions
  • Throw HolidayNotFoundException for unknown holiday keys (#​421)
  • (Japan) Correct year bounds and holiday name accuracy
  • (Belgium) Easter and Pentecost are not official holidays
  • (Belgium) Correct nationalDay translations and rename PentecostMondayTest
Refactor
  • (Provider) Modernize PHP syntax for readability and conciseness
  • Clean up property initialization and modernize test mocks
  • (Test) Remove redundant test constructors
  • (South Korea) Use readonly properties and constructor promotion
  • (South Korea) Add Labor Day and reinstate Constitution Day (#​413)
  • (Netherlands) Standardize test file naming
  • (Japan) Code consistency improvements
  • Clean up SubstituteHoliday and fix Japan iterator null check
Documentation
  • Add release policy documenting bi-annual release cycle
  • Update CODE_OF_CONDUCT to Contributor Covenant v3.0
  • Updates to reflect recent PHPstan level bump
  • Clarify holiday type classification
  • Update list of supported versions
Testing
  • (Canada) Bound random year range in Boxing Day tests to >= 1879
  • (Lithuania) Add allSoulsDay to official holidays test and implement ProviderTestCase
  • (Japan) Skip 2020/2021 in MarineDay random year test instead of early return
  • (SouthKorea) Correct test year range for pre-1949 assertion
  • (Japan) Exclude 2019 from emperorsBirthday random year range
Other
  • Bump composer package versions to latest installed versions
  • (Deps) Bump actions/stale from 10.4.0 to 11.0.0 (#​422)
  • (Deps) Add rector dev dependency and configure tool
  • (Colombia) Fix file permissions on test files
  • Update .editorconfig settings
  • (Deps) Bump actions/stale from 10.3.0 to 10.4.0 (#​419)
  • Increase PHPStan analysis level to 9
  • Upgrade rector configuration
  • (Deps) Bump phpstan from 2.1 to 2.2
  • (Deps) Bump actions/cache from 5 to 6 (#​417)
  • (Deps) Bump actions/checkout from 6 to 7 (#​416)
  • (Deps) Bump actions/stale from 10.2.0 to 10.3.0 (#​411)
fruitcake/laravel-debugbar (barryvdh/laravel-debugbar)

v4.4.4

Compare Source

What's Changed
New Contributors

v4.4.3

Compare Source

What's Changed

Full Changelog: fruitcake/laravel-debugbar@v4.4.2...v4.4.3

v4.4.2

Compare Source

New

php artisan debugbar:install-skill command to install skills when not using Laravel Boost

What's Changed
New Contributors

Full Changelog: fruitcake/laravel-debugbar@v4.4.1...v4.4.2

v4.4.1

Compare Source

What's Changed
New Contributors

Full Changelog: fruitcake/laravel-debugbar@v4.4.0...v4.4.1

docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

docker/login-action (docker/login-action)

v4.6.0

Compare Source

Full Changelog: docker/login-action@v4.5.2...v4.6.0

v4.5.2

Compare Source

Full Changelog: docker/login-action@v4.5.1...v4.5.2

v4.5.1

Compare Source

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Compare Source

Full Changelog: docker/login-action@v4.4.0...v4.5.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.4.1

Compare Source

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

Akryum/floating-vue (floating-vue)

v5.4.0

Compare Source

   🐞 Bug Fixes
   🏎 Performance
    [View changes on GitHub](https://redirect.github.com/Akryum/floating-vue/compare/v5.3.0..

Configuration

📅 Schedule: Branch creation - On day 1 of the month, every 3 months ( * * 1 */3 * ) in timezone Europe/Warsaw, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@blumilk-renovate
blumilk-renovate Bot requested a review from a team as a code owner October 1, 2026 10:25
@blumilk-renovate blumilk-renovate Bot added dependencies Pull requests that update a dependency file docker Pull requests that update Docker code github-actions javascript Pull requests that update Javascript code php Pull requests that update Php code renovate labels Oct 1, 2026
@blumilk-renovate
blumilk-renovate Bot requested a review from Blusia October 1, 2026 10:26
@blumilk-renovate

blumilk-renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: composer.lock
Command failed: composer update azuyalabs/yasumi:2.12.0 barryvdh/laravel-debugbar:4.4.4 dompdf/dompdf:3.1.6 guzzlehttp/guzzle:7.10.6 inertiajs/inertia-laravel:2.0.28 laravel/dusk:8.7.0 laravel/socialite:5.31.0 laravel/telescope:5.25.0 mockery/mockery:1.6.15 phpunit/phpunit:12.5.37 sentry/sentry-laravel:4.28.0 --with-dependencies --ignore-platform-req='ext-*' --ignore-platform-req='lib-*' --no-ansi --no-interaction --no-scripts --no-autoloader --no-plugins --minimal-changes
Loading composer repositories with package information
Dependency laravel/framework is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Updating dependencies
Your requirements could not be resolved to an installable set of packages.

  Problem 1
    - Root composer.json requires guzzlehttp/guzzle ^7.10.6, found guzzlehttp/guzzle[7.10.6, ..., 7.15.5] but these were not loaded, because they are affected by security advisories ("PKSA-gcrk-3vtt-1r14", "PKSA-cnw1-2ytm-cgr8", "PKSA-fy2t-3c5f-827y", "PKSA-qxvb-2bpp-dnk6", "PKSA-bbs6-q5q9-f3t4", "PKSA-bcdd-5xc7-gwfb", "PKSA-pwsk-hy21-4gby", "PKSA-93qv-9n9h-6k6p", "PKSA-k22t-f949-t9g6"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
  Problem 2
    - laravel/framework is locked to version v12.64.0 and an update of this package was not requested.
    - laravel/framework v12.64.0 requires guzzlehttp/guzzle ^7.8.2 -> found guzzlehttp/guzzle[7.8.2, ..., 7.15.5] but these were not loaded, because they are affected by security advisories ("PKSA-gcrk-3vtt-1r14", "PKSA-cnw1-2ytm-cgr8", "PKSA-fy2t-3c5f-827y", "PKSA-qxvb-2bpp-dnk6", "PKSA-bbs6-q5q9-f3t4", "PKSA-bcdd-5xc7-gwfb", "PKSA-pwsk-hy21-4gby", "PKSA-93qv-9n9h-6k6p", "PKSA-k22t-f949-t9g6"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
  Problem 3
    - Root composer.json requires laravel/socialite ^5.31.0 -> satisfiable by laravel/socialite[v5.31.0].
    - laravel/socialite v5.31.0 requires guzzlehttp/guzzle ^6.0|^7.0|^8.0 -> found guzzlehttp/guzzle[6.0.0, ..., 6.5.8, 7.0.0, ..., 7.15.5, 8.0.0, ..., 8.2.0] but these were not loaded, because they are affected by security advisories ("PKSA-gcrk-3vtt-1r14", "PKSA-cnw1-2ytm-cgr8", "PKSA-fy2t-3c5f-827y", "PKSA-qxvb-2bpp-dnk6", "PKSA-bbs6-q5q9-f3t4", "PKSA-bcdd-5xc7-gwfb", "PKSA-pwsk-hy21-4gby", "PKSA-93qv-9n9h-6k6p", "PKSA-k22t-f949-t9g6", "PKSA-yfw5-9gnj-n2c7", "PKSA-k1b4-kshy-xgbh", "PKSA-2z36-j4q9-rsfy", "PKSA-fvw5-9t6n-nwvr", "PKSA-6d8m-6kgw-18zr", "PKSA-stmn-hvzq-wph6"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
  Problem 4
    - spatie/laravel-slack-slash-command is locked to version 1.13.0 and an update of this package was not requested.
    - spatie/laravel-slack-slash-command 1.13.0 requires guzzlehttp/guzzle ^7.0 -> found guzzlehttp/guzzle[7.0.0, ..., 7.15.5] but these were not loaded, because they are affected by security advisories ("PKSA-gcrk-3vtt-1r14", "PKSA-cnw1-2ytm-cgr8", "PKSA-fy2t-3c5f-827y", "PKSA-qxvb-2bpp-dnk6", "PKSA-bbs6-q5q9-f3t4", "PKSA-bcdd-5xc7-gwfb", "PKSA-pwsk-hy21-4gby", "PKSA-93qv-9n9h-6k6p", "PKSA-k22t-f949-t9g6", "PKSA-yfw5-9gnj-n2c7", "PKSA-k1b4-kshy-xgbh", "PKSA-2z36-j4q9-rsfy", "PKSA-fvw5-9t6n-nwvr", "PKSA-6d8m-6kgw-18zr"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
  Problem 5
    - Root composer.json requires laravel/dusk ^8.7.0 -> satisfiable by laravel/dusk[v8.7.0].
    - laravel/dusk v8.7.0 requires guzzlehttp/guzzle ^7.5|^8.0 -> found guzzlehttp/guzzle[7.5.0, ..., 7.15.5, 8.0.0, ..., 8.2.0] but these were not loaded, because they are affected by security advisories ("PKSA-gcrk-3vtt-1r14", "PKSA-cnw1-2ytm-cgr8", "PKSA-fy2t-3c5f-827y", "PKSA-qxvb-2bpp-dnk6", "PKSA-bbs6-q5q9-f3t4", "PKSA-bcdd-5xc7-gwfb", "PKSA-pwsk-hy21-4gby", "PKSA-93qv-9n9h-6k6p", "PKSA-k22t-f949-t9g6"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
  Problem 6
    - spatie/laravel-ignition is locked to version 2.12.0 and an update of this package was not requested.
    - laravel/framework v12.64.0 requires guzzlehttp/guzzle ^7.8.2 -> found guzzlehttp/guzzle[7.8.2, ..., 7.15.5] but these were not loaded, because they are affected by security advisories ("PKSA-gcrk-3vtt-1r14", "PKSA-cnw1-2ytm-cgr8", "PKSA-fy2t-3c5f-827y", "PKSA-qxvb-2bpp-dnk6", "PKSA-bbs6-q5q9-f3t4", "PKSA-bcdd-5xc7-gwfb", "PKSA-pwsk-hy21-4gby", "PKSA-93qv-9n9h-6k6p", "PKSA-k22t-f949-t9g6"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
    - spatie/laravel-ignition 2.12.0 requires illuminate/support ^11.0|^12.0|^13.0 -> satisfiable by laravel/framework[v12.64.0].

Use the option --with-all-dependencies (-W) to allow upgrades, downgrades and removals for packages currently locked to specific versions.

File name: package-lock.json
npm warn Unknown env config "store". This will error in a future major version of npm. See `npm help npmrc` for supported config options.
npm error code EALLOWREMOTE
npm error Fetching packages of type "remote" have been disabled
npm error Refusing to fetch "https://registry.npmjs.org/@tailwindcss/oxide-wasm32-wasi/-/oxide-wasm32-wasi-4.3.3.tgz"
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2026-10-04T10_17_45_128Z-debug-0.log

@blumilk-renovate
blumilk-renovate Bot force-pushed the renovate/all-minor-patch-digest-pindigest branch from 3dc2457 to 877a195 Compare October 3, 2026 10:18
@blumilk-renovate
blumilk-renovate Bot force-pushed the renovate/all-minor-patch-digest-pindigest branch from 877a195 to 06c98a8 Compare October 4, 2026 10:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker code github-actions javascript Pull requests that update Javascript code php Pull requests that update Php code renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants