Skip to content

deps(deps): bump the major group across 1 directory with 3 updates - #214

Merged
ralyodio merged 1 commit into
masterfrom
dependabot/npm_and_yarn/major-dcc2d24488
Sep 8, 2026
Merged

deps(deps): bump the major group across 1 directory with 3 updates#214
ralyodio merged 1 commit into
masterfrom
dependabot/npm_and_yarn/major-dcc2d24488

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the major group with 3 updates in the / directory: isomorphic-dompurify, @vitest/coverage-v8 and vitest.

Updates isomorphic-dompurify from 3.23.0 to 4.1.0

Release notes

Sourced from isomorphic-dompurify's releases.

4.1.0: Align Requirements table with the 4.x Node.js floor

  • README Requirements table: the raised Node.js floor is now listed under >=4.0.0 (was >=3.20.0)
  • lefthook 2.1.10 -> 2.1.12 (dev)

4.0.0: Semver correction for the Node.js floor bump

This is a major version bump with no functional code changes relative to 3.23.0.

v3.20.0 raised the minimum Node.js version (inherited from jsdom 30) - a breaking change that should have been a major release. 4.0.0 corrects that: the same code as 3.23.0, now on a proper major so ^3.x consumers are not silently upgraded onto a build that dropped their Node.js version.

  • Node.js requirement: ^22.22.2 || ^24.15.0 || >=26.0.0 (Node 20 no longer supported)
  • Versions 3.20.0-3.23.0 are deprecated on npm - use 4.x, or pin 3.19.0 for Node < 22.22.2 (also available via the node20 dist-tag)
  • @​biomejs/biome 2.5.10 -> 2.5.11 (dev)
Commits
  • e7b5f69 chore: release 4.1.0 (align README Requirements table with the 4.x Node.js fl...
  • c67da50 chore(deps-dev): bump lefthook from 2.1.10 to 2.1.12
  • 285264e chore: release 4.0.0 (correct semver for the Node.js floor bump)
  • 438d244 chore(deps-dev): bump @​biomejs/biome from 2.5.10 to 2.5.11
  • See full diff in compare view

Updates @vitest/coverage-v8 from 4.1.11 to 5.0.0

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits

Updates vitest from 4.1.11 to 5.0.0

Release notes

Sourced from vitest's releases.

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits
  • f441c6f chore: release v5.0.0 (#11130)
  • d46a747 fix: treat test.describe as a suite during static collection (#11128)
  • 584cf30 fix: add a warning if inline project has duplicate plugins due to unexpected ...
  • f08ce4b fix: apply queued mocks from doMock() in queue order (fixes #10706) (#11127)
  • 897f51f chore: release v5.0.0-rc.4 (#11107)
  • 1339b06 chore(deps): update all non-major dependencies (#11104)
  • 51e9494 feat!: parse files statically in vitest list by default (#11088)
  • 2122ffd fix: propagate --maxWorkers to projects (#11102)
  • dc10f5f fix(browser): report the action error when a task times out (#11101)
  • d4fe198 feat: promote clearCache out of experimental (#11086)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

socket-security Bot commented Sep 7, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​vitest/​coverage-v8@​4.1.11 ⏵ 5.0.09910079 +199 +1100
Updatedvitest@​4.1.11 ⏵ 5.0.098 +110079 +199 +1100
Updatedisomorphic-dompurify@​3.23.0 ⏵ 4.1.010010010096 +2100

View full report

@socket-security

socket-security Bot commented Sep 7, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Low adoption: npm @vitest/istanbul-lib-coverage

Location: Package overview

From: pnpm-lock.yamlnpm/@vitest/coverage-v8@5.0.0npm/@vitest/istanbul-lib-coverage@1.0.1

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitest/istanbul-lib-coverage@1.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm @vitest/istanbul-lib-report

Location: Package overview

From: pnpm-lock.yamlnpm/@vitest/coverage-v8@5.0.0npm/@vitest/istanbul-lib-report@1.0.1

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitest/istanbul-lib-report@1.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Bumps the major group with 3 updates in the / directory: [isomorphic-dompurify](https://github.com/kkomelin/isomorphic-dompurify), [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `isomorphic-dompurify` from 3.23.0 to 4.1.0
- [Release notes](https://github.com/kkomelin/isomorphic-dompurify/releases)
- [Commits](kkomelin/isomorphic-dompurify@3.23.0...4.1.0)

Updates `@vitest/coverage-v8` from 4.1.11 to 5.0.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/coverage-v8)

Updates `vitest` from 4.1.11 to 5.0.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major
- dependency-name: isomorphic-dompurify
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps(deps): bump the major group with 3 updates deps(deps): bump the major group across 1 directory with 3 updates Sep 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/major-dcc2d24488 branch from b4f3792 to 2285466 Compare September 8, 2026 01:04
@ralyodio
ralyodio merged commit b4fc54c into master Sep 8, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/major-dcc2d24488 branch September 8, 2026 01:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant