Skip to content

chore(deps): update all non-major dependencies - #136

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

chore(deps): update all non-major dependencies#136
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@​nuxt/icon 2.5.02.5.1 age confidence dependencies patch
@nuxt/scripts (source) 1.3.31.3.8 age confidence dependencies patch
@nuxtjs/seo (source) 5.3.125.3.14 age confidence dependencies patch
@regle/nuxt (source) 1.29.01.29.1 age confidence devDependencies patch
@tanstack/query-persist-client-core (source) 5.101.45.102.8 age confidence dependencies minor
@tanstack/vue-query (source) 5.101.45.102.8 age confidence dependencies minor
@tanstack/vue-virtual (source) 3.13.353.13.36 age confidence dependencies patch
@tiptap/core (source) 3.30.03.30.5 age confidence pnpm-workspace.overrides patch 3.30.6
@tiptap/extension-blockquote (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-bold (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-code (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-emoji (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-heading (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-italic (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-mention (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-placeholder (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-strike (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/extension-underline (source) 3.30.03.30.5 age confidence dependencies patch 3.30.6
@tiptap/pm (source) 3.30.03.30.5 age confidence pnpm-workspace.overrides patch 3.30.6
@tiptap/starter-kit (source) 3.30.03.30.5 age confidence pnpm-workspace.overrides patch 3.30.6
@tiptap/suggestion (source) 3.30.03.30.5 age confidence pnpm-workspace.overrides patch 3.30.6
@tiptap/vue-3 (source) 3.30.03.30.5 age confidence pnpm-workspace.overrides patch 3.30.6
@unocss/nuxt (source) ^66.7.5^66.8.1 age confidence devDependencies minor
@vue/test-utils ^2.4.11^2.5.0 age confidence devDependencies minor
dompurify 3.4.73.4.14 age confidence dependencies patch
es-toolkit (source) 1.50.01.52.0 age confidence dependencies minor
marked (source) 18.0.918.0.11 age confidence dependencies patch
motion-v 2.3.02.4.0 age confidence dependencies minor
oxfmt (source) ^0.54.0^0.65.0 age confidence devDependencies minor
prosemirror-view 1.42.21.42.3 age confidence pnpm-workspace.overrides patch
reka-ui 2.10.32.10.4 age confidence pnpm-workspace.overrides patch
reka-ui 2.10.32.10.4 age confidence dependencies patch
toshimaru/auto-author-assign v3.0.2v3.1.0 age confidence action minor
typescript 6.0.3-bridge.12.tsgo.7.0.26.0.3-bridge.15.tsgo.7.0.2 age confidence pnpm-workspace.overrides patch
unocss (source) ^66.7.5^66.8.1 age confidence devDependencies minor
virtua ^0.49.3^0.50.0 age confidence dependencies minor 0.51.0
vue-router (source) 5.2.05.3.0 age confidence dependencies minor
workbox-build (source) 7.4.07.4.1 age confidence pnpm-workspace.overrides patch

Release Notes

nuxt/scripts (@​nuxt/scripts)

v1.3.8

Compare Source

   🐞 Bug Fixes
  • registry: Don't declare the global Window via extends (1.x backport)  -  by @​harlan-zw, Togetic and Claude Opus 5 (1M context) in #​880 (be0ce)
    View changes on GitHub

v1.3.7

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.6

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.5

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
harlan-zw/nuxt-seo (@​nuxtjs/seo)

v5.3.14

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v5.3.13

Compare Source

   🚀 Features
   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub
victorgarciaesgi/regle (@​regle/nuxt)

v1.29.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
TanStack/query (@​tanstack/query-persist-client-core)

v5.102.8

Compare Source

Patch Changes

v5.102.7

Compare Source

Patch Changes

v5.102.6

Compare Source

Patch Changes

v5.102.5

Compare Source

Patch Changes

v5.102.4

Compare Source

Patch Changes

v5.102.3

Compare Source

Patch Changes

v5.102.2

Compare Source

Patch Changes

v5.102.1

Compare Source

Patch Changes

v5.102.0

Compare Source

Patch Changes
TanStack/query (@​tanstack/vue-query)

v5.102.8

Compare Source

Patch Changes

v5.102.7

Compare Source

Patch Changes

v5.102.6

Compare Source

Patch Changes

v5.102.5

Compare Source

Patch Changes

v5.102.4

Compare Source

Patch Changes

v5.102.3

Compare Source

Patch Changes

v5.102.2

Compare Source

Patch Changes

v5.102.1

Compare Source

Patch Changes

v5.102.0

Compare Source

Minor Changes
Patch Changes
TanStack/virtual (@​tanstack/vue-virtual)

v3.13.36

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/core)

v3.30.5

Compare Source

@​tiptap/core
Patch Changes
  • Fix a denial-of-service risk where crafted block or inline Markdown attributes could consume excessive CPU and block the browser or server event loop.

v3.30.4

Compare Source

@​tiptap/core
Patch Changes
  • Prevent untrusted HTML attributes from changing an object's prototype when merged with mergeAttributes.

v3.30.3

Compare Source

Patch Changes
  • 965a880: Fix JSX runtime to properly render nested sibling elements by spreading children arrays into DOMOutputSpec

v3.30.2

Compare Source

Patch Changes
  • 3dffed5: Keep mixed JSX children as separate siblings in DOM output.
  • 214a140: Fixed a bug where editor.chain and editor.can can not be accessed on editor initialization

v3.30.1

Compare Source

Patch Changes
  • abc8828: Added new ProseMirror helpers that check whether a value is a specific ProseMirror type.
unocss/unocss (@​unocss/nuxt)

v66.8.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v66.8.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub
vuejs/test-utils (@​vue/test-utils)

v2.5.0

Compare Source

cure53/DOMPurify (dompurify)

v3.4.14: DOMPurify 3.4.14

Compare Source

  • Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @​AlirezaRouhbakhsh
  • Fixed a couple of edge cases with mixed document contexts, thanks @​fishjojo1
  • Added the SVG pointer-events and vector-effect presentation attributes to the allow-list, thanks @​Jaybhade
  • Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation
  • Updated the documentation in several spots, README, wiki, etc., thanks @​Akokonunes
  • Updated several development dependencies and CI workflow actions

v3.4.13: DOMPurify 3.4.13

Compare Source

  • Fixed an issue with hook removal during IN_PLACE sanitization, thanks @​koyokr
  • Fixed an issue with hooks potentially bypassing the clone guard, thanks @​AkshayjainG
  • Fixed an issue with DOM clobbering via ownerDocument during IN_PLACE, thanks @​AkshayjainG
  • Bumped several dependencies where possible

v3.4.12: DOMPurify 3.4.12

Compare Source

  • Fixed an issue where a hook would not get called for custom elements, thanks @​Rikuxx0
  • Hardened the handling of hooks removing elements, @​mkrause-bee360
  • Added support for a few new SVG attributes, thanks @​cbn-falias & @​Develop-KIM
  • Hardened the handling of declarative partial updates
  • Updated the documentation is several spots, README, wiki, etc.
  • Bumped several dependencies where possible

v3.4.11: DOMPurify 3.4.11

Compare Source

  • Fixed an issue with a leaky config for hooks via setConfig, thanks @​trace37labs
  • Bumped vulnerable development dependencies to arrive at plain 0 with npm audit
  • Updated the osv-scanner suppression list as no vulnerable dependencies are left for now
  • Updated up the linting tool-chain and removed now-redundant lint directives
  • Updated the documentation is several spots, README, wiki, etc.
  • Bumped several dependencies where possible

v3.4.10: DOMPurify 3.4.10

Compare Source

  • Refactored codebase for clarity: extracted the public type declarations into types.ts
  • Decomposed the three largest sanitizer functions into focused helpers
  • Removed duplicated defaults and dead branches, consolidated SAFE_FOR_TEMPLATES scrubbing into single shared path
  • Improved per-node performance by hoisting the mXSS probe regexes and testing textContent before innerHTML
  • Added a deterministic micro-benchmark harness (npm run bench) with a --compare mode
  • Reduced CI cost by running the full three-engine browser suite once per PR
  • Refreshed the demos/ folder so every demo runs again, and added a SVG-via-<img> demo
  • Documented the bench and test:happydom scripts in the README
  • Completed the Attack Classes & Bypass History wiki page
  • Bumped several dependencies where possible

v3.4.9: DOMPurify 3.4.9

Compare Source

  • Further improved the handling of Trusted Types config options, thanks @​offset
  • Further improved the handling of IN_PLACE sanitization, thanks @​mozfreddyb
  • Added more test coverage for IN_PLACE and Trusted Types related usage
  • Bumped several dependencies where possible
  • Updated README and wiki with more accurate documentation & attack samples

v3.4.8: DOMPurify 3.4.8

Compare Source

  • Cleaned up the repository root, renamed some and removed unneeded files
  • Fixed an issue with handling of Trusted Types policies, thanks @​fulstadev
  • Fixed the node iterator for better template scrubbing, thanks @​IamLeandrooooo
  • Included formerly missing LICENSE-MPL in published npm package, thanks @​asamuzaK
  • Bumped several dependencies where possible
toss/es-toolkit (es-toolkit)

v1.52.0

Compare Source

Released on August 28th, 2026.

  • Added the es-toolkit/iterator entrypoint, a lazy iterator module with chunk,
    count, dropWhile, head, iterate, partition, range, scan,
    takeWhile, uniqBy, and zip ([#​1815]), plus cartesianProduct ([#​2031]).
    The same functions are also available from es-toolkit/fp/iterator.

  • Added defer and deferAsync to es-toolkit/util. ([#​2032])

  • Added flowAsync to es-toolkit/fp, a promise-aware left-to-right composition. ([#​2033])

  • Added the EmptyObject, IsEqual, JSONValue, Primitive, SetOptional,
    SetRequired, and UnknownRecord types. ([#​2044])

  • Fixed merge to infer the deep merged return type, and exported the Merge type. ([#​1959])

  • Fixed omitBy and pickBy to type numeric callback keys as strings, and
    exported the ObjectKeys type. ([#​2037])

  • Fixed attempt and attemptAsync to default their error type parameter to unknown. ([#​2052])

The following bring es-toolkit/compat closer to Lodash. Behavior for the affected
edge cases now matches Lodash, so results may differ if you relied on the previous output.

  • Fixed compat/debounce to skip the maxWait invocation when both leading and
    trailing are false. ([#​1678])

  • Fixed compat/toString to convert objects with a custom valueOf. ([#​2034])

  • Fixed compat/mergeWith to assign null values in array sources. ([#​1929])

  • Fixed compat/has and compat/hasIn to normalize the -0 path key. ([#​2035])

  • Fixed compat/differenceWith and compat/without to normalize -0 to 0. ([#​2049])

  • Fixed compat/findLastIndex to convert fromIndex to an integer. ([#​2047])

  • Fixed compat/xorWith to match Lodash when no comparator is given. ([#​2057])

  • Covered the new iterator entrypoints in the dist and browser compatibility
    checks. ([#​2030])

  • Made the agent skills portable when installed on their own. ([#​2054])

  • Fixed documentation typos and the Deno install commands. ([#​2062])

v1.51.0

Compare Source

Released on August 17th, 2026.

  • Added the es-toolkit/bigint entrypoint: bigint counterparts of the math
    functions (sum, sumBy, max, min, maxBy, minBy, clamp, inRange,
    median, medianBy, percentile, range, rangeRight), kept separate so
    the number implementations stay unchanged. ([#​1966])

  • Added dedent, which removes common leading whitespace from template strings. ([#​1679])

  • Added deepFreeze for recursively freezing objects. ([#​1680])

  • Added mapValuesAsync and mapKeysAsync. ([#​1544])

  • Added toPascalCaseKeys, toKebabCaseKeys, and toConstantCaseKeys,
    completing the object key casing family. ([#​1984])

  • Exported the ToCamelCaseKeys, ToPascalCaseKeys, ToSnakeCaseKeys,
    ToKebabCaseKeys, and ToConstantCaseKeys types. ([#​1651])

  • Added a preserveArrays option to flattenObject. ([#​974])

  • Fixed retry to pass the last error to the delay callback ([#​1759]) and to
    throw the last attempt's error without applying a final delay ([#​1901]).

  • Fixed mergeWith and toMerged to handle mixed array/object types
    co

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
✓ Lockfile passes supply-chain policies (verified 50s ago)
Progress: resolved 1, reused 0, downloaded 0, added 0
Progress: resolved 88, reused 0, downloaded 0, added 0
Progress: resolved 347, reused 0, downloaded 0, added 0
Progress: resolved 527, reused 0, downloaded 0, added 0
Progress: resolved 878, reused 0, downloaded 0, added 0
Progress: resolved 945, reused 0, downloaded 0, added 0
Progress: resolved 1520, reused 0, downloaded 0, added 0
[ERR_PNPM_TRUST_DOWNGRADE] High-risk trust downgrade for "@trickfilm400/rollup-plugin-off-main-thread@3.0.0-pre1" (possible package takeover)

This error happened while installing the dependencies of workbox-build@7.4.1

Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Earlier versions had provenance attestation, but this version has no trust evidence. A trust downgrade may indicate a supply chain incident.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 20, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
magi 4981e65 Aug 31 2026, 08:24 PM

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 20 times, most recently from 92b382b to 75f899d Compare July 27, 2026 18:10
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 73073f0 to 068b1c5 Compare July 30, 2026 19:00
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from 5fd842e to a27d0dc Compare August 13, 2026 18:44
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 14 times, most recently from e1f4c06 to 52f8068 Compare August 21, 2026 17:41
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 52f8068 to 0644079 Compare August 22, 2026 03:26
@jvxz

jvxz commented Aug 27, 2026

Copy link
Copy Markdown
Owner

@greptileai review

@greptile-apps

greptile-apps Bot commented Aug 27, 2026

Copy link
Copy Markdown

Greptile Summary

This PR updates non-major application, build-tool, editor, UI, and GitHub Action dependencies. The dependency manifests were changed without the corresponding lockfile regeneration required by frozen CI installs.

  • Updates Nuxt, TanStack Query, DOMPurify, Virtua, UnoCSS, oxfmt, and related dependencies.
  • Aligns Tiptap, ProseMirror, Reka UI, TypeScript bridge, and Workbox workspace overrides.
  • Updates the automatic author-assignment action from v3.0.2 to v3.1.0.

Confidence Score: 4/5

This PR should not be merged until the pnpm lockfile is regenerated, because current CI and autofix installations will fail before their checks run.

The changed dependency declarations and workspace overrides no longer match the tracked lockfile, while both relevant workflows enforce frozen-lockfile installation.

Files Needing Attention: package.json, pnpm-workspace.yaml, pnpm-lock.yaml

Important Files Changed

Filename Overview
package.json Updates application and development dependencies, but leaves their tracked lockfile specifiers stale and breaks frozen installs.
pnpm-workspace.yaml Updates several workspace overrides without updating the lockfile’s override snapshot.
.github/workflows/auto-author-assign.yml Updates the author-assignment action’s version tag with no changed workflow behavior identified.

Fix all with Greploop Fix All in Claude Code

Reviews (1): Last reviewed commit: "chore(deps): update all non-major depend..." | Re-trigger Greptile

Comment thread package.json
"dependencies": {
"@nuxt/fonts": "0.14.0",
"@nuxt/icon": "2.5.0",
"@nuxt/icon": "2.5.1",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Stale lockfile blocks CI

When CI or autofix runs, the changed dependency manifests no longer match pnpm-lock.yaml, so pnpm install --frozen-lockfile exits before type checking, linting, formatting, or tests can run. Regenerate and commit the lockfile with these dependency updates.

Fix in Claude Code

@greptile-apps

greptile-apps Bot commented Aug 27, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant