Skip to content

- Update all non-major dependencies with digest and pinDigest - #449

Open
blumilk-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pindigest
Open

blumilk-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pindigest

Conversation

@blumilk-renovate

@blumilk-renovate blumilk-renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@alpinejs/focus (source) ^3.15.12 -> ^3.17.4 age confidence dependencies minor
@alpinejs/persist (source) ^3.15.12 -> ^3.17.4 age confidence dependencies minor
@types/alpinejs (source) ^3.13.11 -> ^3.17.0 age confidence dependencies minor
@typescript-eslint/eslint-plugin (source) ^8.59.4 -> ^8.71.0 age confidence devDependencies minor
@typescript-eslint/parser (source) ^8.59.4 -> ^8.71.0 age confidence devDependencies minor
alpine 3.22.5 -> 3.22.6 age confidence stage patch
alpinejs (source) ^3.15.12 -> ^3.17.4 age confidence dependencies minor
axllent/mailpit (source) v1.30.7 -> v1.31.3 age confidence minor v1.31.4
composer 2.9.8 -> 2.10.3 age confidence stage minor
composer/composer 2.9.8-bin -> 2.10.3-bin age confidence stage minor
docker/build-push-action v7.3.0 -> v7.4.0 age confidence action minor
docker/setup-buildx-action v4.2.0 -> v4.4.1 age confidence action minor
filament/filament (source) ^3.3.54 -> ^3.3.55 age confidence require patch
filament/spatie-laravel-translatable-plugin (source) ^3.3.54 -> ^3.3.55 age confidence require patch
guzzlehttp/guzzle (source) ^7.10.6 -> ^7.15.5 age confidence require patch
larastan/larastan ^3.10.0 -> ^3.12.2 age confidence require-dev minor
laravel/framework (source) ^12.65.0 -> ^12.69.3 age confidence require minor
mockery/mockery ^1.6.12 -> ^1.6.15 age confidence require-dev patch
nesbot/carbon (source) ^3.13.2 -> ^3.13.3 age confidence require patch
node (source) 22.23.2 -> 22.23.3 age confidence patch
node 22.22.3-bullseye-slim -> 22.23.2-bullseye-slim age confidence stage minor
php 8.4.24 -> 8.4.26 age confidence patch
php 8.4.24-fpm-bookworm -> 8.4.26-fpm-bookworm age confidence final patch
phpunit/phpunit (source) ^12.5.33 -> ^12.5.37 age confidence require-dev patch 12.5.38
postcss (source) ^8.5.26 -> ^8.5.28 age confidence devDependencies patch 8.5.29
sentry/sentry-laravel (source) ^4.25.1 -> ^4.28.0 age confidence require minor

Release Notes

alpinejs/alpine (@​alpinejs/focus)

v3.17.4

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.17.3...v3.17.4

v3.17.3

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.17.2...v3.17.3

v3.17.2

Compare Source

What's Changed

Full Changelog: alpinejs/alpine@v3.17.1...v3.17.2

v3.17.1

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.17.0...v3.17.1

v3.17.0

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.16.3...v3.17.0

v3.16.3

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.16.2...v3.16.3

v3.16.2

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.16.1...v3.16.2

v3.16.1

Compare Source

What's Changed

Full Changelog: alpinejs/alpine@v3.16.0...v3.16.1

v3.16.0

Compare Source

What's Changed
New Contributors

Full Changelog: alpinejs/alpine@v3.15.12...v3.16.0

typescript-eslint/typescript-eslint (@​typescript-eslint/eslint-plugin)

v8.71.0

Compare Source

🚀 Features
  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#​12732)
🩹 Fixes
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#​12912)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#​12832)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#​12885)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.1

Compare Source

🩹 Fixes
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#​12904)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#​12826)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#​12747)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#​12845)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#​12880)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#​12716)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#​12873)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#​12869)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#​12850)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#​12854)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#​12818)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#​12637)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#​12768)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

🚀 Features
  • eslint-plugin: [no-generated-empty-object-type] add rule (#​12730)
🩹 Fixes
  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#​12780)
  • eslint-plugin: [no-unnecessary-condition] no false positive on RHS of a nested logical expression (#​12728)
  • eslint-plugin: [member-ordering] don't report fields that read fields declared before them (#​12729)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

🚀 Features
  • eslint-plugin: [no-misused-promises] add flagUnions option for checkConditionals (#​12603)
🩹 Fixes
  • eslint-plugin: [no-meaningless-void-operator] report void on non-call expressions (#​12727)
  • eslint-plugin: [unified-signatures] compare type parameters by constraint instead of name (#​12741)
  • eslint-plugin: [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (#​12731)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

🚀 Features
  • eslint-plugin: [strict-void-return] add fix suggestions (#​12086)
🩹 Fixes
  • eslint-plugin: [no-empty-object-type] ignore suggestions that result in invalid interfaces and export defaults (#​12739)
  • eslint-plugin: [no-floating-promises] setting ignoreVoid: false results in false negative in ArrowFunctionExpression (#​12646)
  • eslint-plugin: [no-unnecessary-type-assertion] prevent stack overflow in recursive types (#​12711)
  • eslint-plugin: [unified-signatures] report identical signatures (#​12678)
  • eslint-plugin: [return-await] prevent autofix from breaking code in arrow-functions (#​12707)
  • eslint-plugin: [unified-signatures] deduplicate types in report (#​12656)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

typescript-eslint/typescript-eslint (@​typescript-eslint/parser)

v8.71.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.1

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.69.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

axllent/mailpit (axllent/mailpit)

v1.31.3

Compare Source

Chore
  • Limit maximum MIME parts parsed per message to 500
  • Refactor regex usage for string cleaning and normalization
  • Optimize envelope parsing by using a shared parser instance
  • Optimize message summary construction by eliminating JSON round-trip
  • Replace bytes.ToLower with containsFold for case-insensitive tag matching
  • Replace inline regex for leading whitespace with a package-level variable
  • Symlink sendmail to Mailpit in Docker image (#​736)
  • Update Go dependencies
  • Update node dependencies
  • Update GitHub Actions dependencies

v1.31.2

Compare Source

Security
Feature
  • Add major version tag for Docker images in workflow (#​734)
Chore
  • Improve message rendering performance with envelope caching
  • Update Go dependencies
  • Update node dependencies
  • Update caniemail test database
Fix
  • Re-quote local-parts in API JSON responses (#​732)

v1.31.1

Compare Source

Security
  • Add --allowed-hosts flag to mitigate DNS rebinding against the API
Chore
  • Update Go dependencies
  • Update node dependencies
  • Update Github Actions
Fix
  • Block Azure WireServer, IPv4-translated prefix and additional reserved ranges in SSRF deny-list
  • Pass line-boundary state to drainData to prevent SMTP desync
  • Allow SP inside quoted local-parts per RFC 5321 (#​731)
  • Bound header-rewrite scanner to header block and fail closed on missing header
  • Prevent quadratic CPU in proxy CSS rewriter via O(1) asset dedup

v1.31.0

Compare Source

Feature
  • Add deep dark theme (#​728)
  • Add debounced search refresh for filtered views on new messages
Chore
  • Make read/unread message state clearly distinguishable (WCAG AA)
  • Add accessible names to icon-only buttons and fix sender tag mismatch
  • Update Go dependencies
  • Update node dependencies
  • Update caniemail test database
  • Update GitHub Actions
Fix
  • Include all IANA special-use IPv4 ranges in IsInternalIP check
  • Prevent SMTP command injection via drainData fragment-boundary bypass
  • Validate Send API custom header keys per RFC 5322
docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.4.1

Compare Source

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

filamentphp/panels (filament/filament)

v3.3.55

Compare Source

filamentphp/spatie-laravel-translatable-plugin (filament/spatie-laravel-translatable-plugin)

v3.3.55

Compare Source

guzzle/guzzle (guzzlehttp/guzzle)

v7.15.5

Compare Source

Changed
  • Adjusted guzzlehttp/psr7 version constraint to ^2.13.1
  • Adjusted guzzlehttp/promises version constraint to ^2.5.3

v7.15.4

Compare Source

Added
  • Added support for PHP 8.6
Changed
  • Replace the deprecated spl_object_hash() in handler stack debug output for PHP 8.6
larastan/larastan (larastan/larastan)

v3.12.2: 3.12.2

Compare Source

What's Changed

Fixed

  • Improve unused view detection for mail content, Mail::send(), concatenated view names, and slash-separated Blade view names by @​FeBe95 in #​2479
  • Preserve unsigned column types when an integer cast is applied and support them in higher-order collection sum() calls by @​canvural in 6f44183
  • Recognize quiet increment and decrement methods forwarded by models by @​canvural in 0196dee
  • Treat schema dump columns without NOT NULL as nullable by @​canvural in 29c3d08
  • Use Builder<Model> when a relationship path cannot be followed through an unknown model by @​MizouziE in #​2549
  • Detect Octane container injection in arrow functions by @​arpitjain099 in #​2551

Performance

Internal

New Contributors

Full Changelog: v3.12.1...v3.12.2

v3.12.1: 3.12.1

Compare Source

What's Changed

Fixed

  • Preserve custom builder types in relation count queries and BelongsToMany::firstWhere() callbacks by @​canvural in 2e561c8
  • Allow null and object HTTP request body data by @​lazerg in #​2507

Changed

Internal

Full Changelog: v3.12.0...v3.12.1

v3.12.0: 3.12.0

Compare Source

What's Changed

Added


Configuration

📅 Schedule: Branch creation - On day 1 of the month, every 3 months ( * * 1 */3 * ) in timezone Europe/Warsaw, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@blumilk-renovate
blumilk-renovate Bot requested a review from a team as a code owner October 1, 2026 10:02
@blumilk-renovate blumilk-renovate Bot added dependencies Pull requests that update a dependency file docker Pull requests that update Docker code github-actions javascript Pull requests that update Javascript code php Pull requests that update Php code renovate labels Oct 1, 2026
@blumilk-renovate
blumilk-renovate Bot requested a review from Blusia October 1, 2026 10:02
@blumilk-renovate

blumilk-renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm warn Unknown env config "store". This will error in a future major version of npm. See `npm help npmrc` for supported config options.
npm error code EALLOWREMOTE
npm error Fetching packages of type "remote" have been disabled
npm error Refusing to fetch "https://registry.npmjs.org/@tailwindcss/oxide-wasm32-wasi/-/oxide-wasm32-wasi-4.3.3.tgz"
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2026-10-03T10_01_57_808Z-debug-0.log

@blumilk-renovate
blumilk-renovate Bot force-pushed the renovate/all-minor-patch-digest-pindigest branch from 85e5004 to 2ae300e Compare October 2, 2026 10:41
@blumilk-renovate
blumilk-renovate Bot force-pushed the renovate/all-minor-patch-digest-pindigest branch from 2ae300e to 2324eae Compare October 3, 2026 10:02

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker code github-actions javascript Pull requests that update Javascript code php Pull requests that update Php code renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants