Skip to content

deps: bump the dependencies-minor group across 1 directory with 12 updates#5

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/dependencies-minor-5461d0767a
Open

deps: bump the dependencies-minor group across 1 directory with 12 updates#5
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/dependencies-minor-5461d0767a

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Oct 22, 2025

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the dependencies-minor group with 12 updates in the / directory:

Package From To
@fontsource-variable/figtree 5.2.8 5.2.10
@fontsource/ibm-plex-mono 5.2.6 5.2.7
@hookform/resolvers 5.1.1 5.2.2
@oddbird/css-anchor-positioning 0.6.1 0.7.0
react 19.1.0 19.2.0
@types/react 19.1.8 19.2.2
react-dom 19.1.0 19.2.0
@types/react-dom 19.1.6 19.2.2
react-hook-form 7.60.0 7.65.0
@playwright/test 1.54.1 1.56.1
sass 1.89.2 1.93.2
typescript 5.8.3 5.9.3

Updates @fontsource-variable/figtree from 5.2.8 to 5.2.10

Commits

Updates @fontsource/ibm-plex-mono from 5.2.6 to 5.2.7

Commits

Updates @hookform/resolvers from 5.1.1 to 5.2.2

Release notes

Sourced from @​hookform/resolvers's releases.

v5.2.2

5.2.2 (2025-09-14)

Bug Fixes

  • zod: fix output type for Zod 4 resolver (#803) (e95721d)

v5.2.1

5.2.1 (2025-07-29)

Bug Fixes

v5.2.0

5.2.0 (2025-07-25)

Features

  • ajv: add ajv-formats for ajvResolver (#797) (f040039)
Commits

Updates @oddbird/css-anchor-positioning from 0.6.1 to 0.7.0

Release notes

Sourced from @​oddbird/css-anchor-positioning's releases.

v0.7.0

What's Changed

New Contributors

Full Changelog: oddbird/css-anchor-positioning@v0.6.1...v0.7.0

Commits
  • 40f3a89 v0.7.0
  • db16313 Work with anchor and target inside same shadow root (#353)
  • b18b8ed Merge pull request #352 from oddbird/dependabot/npm_and_yarn/dev-9d451710aa
  • ea505c5 Merge pull request #351 from oddbird/dependabot/npm_and_yarn/prod-8404f4c51f
  • d4bbb67 chore(deps-dev): Bump the dev group with 13 updates
  • ae3512f chore(deps): Bump the prod group with 2 updates
  • 2f9b4c5 Merge pull request #348 from oddbird/dependabot/npm_and_yarn/npm_and_yarn-f5c...
  • 98ccee3 chore(deps-dev): Bump vite in the npm_and_yarn group across 1 directory
  • 15ebcc0 Merge pull request #346 from oddbird/dependabot/github_actions/actions/setup-...
  • 2cc99a6 Merge pull request #347 from oddbird/dependabot/github_actions/actions/setup-...
  • Additional commits viewable in compare view

Updates react from 19.1.0 to 19.2.0

Release notes

Sourced from react's releases.

19.2.0 (Oct 1, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

  • <Activity>: A new API to hide and restore the UI and internal state of its children.
  • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
  • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
  • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

New React DOM Features

  • Added resume APIs for partial pre-rendering with Web Streams:
  • Added resume APIs for partial pre-rendering with Node Streams:
  • Updated prerender APIs to return a postponed state that can be passed to the resume APIs.

Notable changes

  • React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming <ViewTransition> Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
  • Add Node Web Streams (prerender, renderToReadableStream) to server-side-rendering APIs for Node.js
  • Use underscore instead of : IDs generated by useId

All Changes

React

React DOM

... (truncated)

Changelog

Sourced from react's changelog.

19.2.0 (October 1st, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

  • <Activity>: A new API to hide and restore the UI and internal state of its children.
  • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
  • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
  • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

New React DOM Features

  • Added resume APIs for partial pre-rendering with Web Streams:
  • Added resume APIs for partial pre-rendering with Node Streams:
  • Updated prerender APIs to return a postponed state that can be passed to the resume APIs.

Notable changes

  • React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming <ViewTransition> Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
  • Add Node Web Streams (prerender, renderToReadableStream) to server-side-rendering APIs for Node.js
  • Use underscore instead of : IDs generated by useId

All Changes

React

React DOM

... (truncated)

Commits

Updates @types/react from 19.1.8 to 19.2.2

Commits

Updates react-dom from 19.1.0 to 19.2.0

Release notes

Sourced from react-dom's releases.

19.2.0 (Oct 1, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

  • <Activity>: A new API to hide and restore the UI and internal state of its children.
  • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
  • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
  • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

New React DOM Features

  • Added resume APIs for partial pre-rendering with Web Streams:
  • Added resume APIs for partial pre-rendering with Node Streams:
  • Updated prerender APIs to return a postponed state that can be passed to the resume APIs.

Notable changes

  • React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming <ViewTransition> Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
  • Add Node Web Streams (prerender, renderToReadableStream) to server-side-rendering APIs for Node.js
  • Use underscore instead of : IDs generated by useId

All Changes

React

React DOM

... (truncated)

Changelog

Sourced from react-dom's changelog.

19.2.0 (October 1st, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

  • <Activity>: A new API to hide and restore the UI and internal state of its children.
  • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
  • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
  • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

New React DOM Features

  • Added resume APIs for partial pre-rendering with Web Streams:
  • Added resume APIs for partial pre-rendering with Node Streams:
  • Updated prerender APIs to return a postponed state that can be passed to the resume APIs.

Notable changes

  • React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming <ViewTransition> Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
  • Add Node Web Streams (prerender, renderToReadableStream) to server-side-rendering APIs for Node.js
  • Use underscore instead of : IDs generated by useId

All Changes

React

React DOM

... (truncated)

Commits

Updates @types/react-dom from 19.1.6 to 19.2.2

Commits

Updates react-hook-form from 7.60.0 to 7.65.0

Release notes

Sourced from react-hook-form's releases.

Version 7.65.0

🧿 feat: <Watch /> component (#12986)

import { useForm, Watch } from 'react-hook-form';
const App = () => {
const { register, control } = useForm();
return (
<div>
<form>
<input {...register('foo')} />
<input {...register('bar')} />
</form>
{/* re-render only when value of foo changes */}
<Watch
control={control}
names={['foo']}
render={([foo]) => <span>{foo}</span>}
/>
</div>
);
};

🐞 fix: respect parent-provided useFieldArray rules (#13082) (#13083 🐞 fix: getDirtyFields submit fields with null values when using useForm (#13079)

thanks to @​tesseractjh, @​Han5991 & @​jonathanarnault

Version 7.64.0

🚏 Support optional array fields in PathValueImpl type (#13057) 🐞 fix: preserve Controller's defaultValue with shouldUnregister prop (#13063) ✂ chore: remove unused field ids ref in useFieldArray (#13066)

thanks to @​MPrieur-chaps, @​gynekolog & @​uk960214

Version 7.63.0

🥢 feat: extract form values by form state (#12936)

getValues(undefined, { dirtyFields: true }); // return only dirty fields 
getValues(undefined, { touchedFields: true });  // return only touched fields 

🦍 feat: improve get dirty fields logic (#13049) 🐿️ chore: remove duplicated function isMessage (#13050) 🐞 fix: use field name to update isValidating fields (#13000) 🐞 fix: unregister previous field when switching conditional Controllers (#13041)

... (truncated)

Commits

Updates @playwright/test from 1.54.1 to 1.56.1

Release notes

Sourced from @​playwright/test's releases.

v1.56.1

Highlights

#37871 chore: allow local-network-access permission in chromium #37891 fix(agents): remove workspaceFolder ref from vscode mcp #37759 chore: rename agents to test agents #37757 chore(mcp): fallback to cwd when resolving test config

Browser Versions

  • Chromium 141.0.7390.37
  • Mozilla Firefox 142.0.1
  • WebKit 26.0

v1.56.0

Playwright Agents

Introducing Playwright Agents, three custom agent definitions designed to guide LLMs through the core process of building a Playwright test:

  • 🎭 planner explores the app and produces a Markdown test plan
  • 🎭 generator transforms the Markdown plan into the Playwright Test files
  • 🎭 healer executes the test suite and automatically repairs failing tests

Run npx playwright init-agents with your client of choice to generate the latest agent definitions:

# Generate agent files for each agentic loop
# Visual Studio Code
npx playwright init-agents --loop=vscode
# Claude Code
npx playwright init-agents --loop=claude
# opencode
npx playwright init-agents --loop=opencode

[!NOTE] VS Code v1.105 (currently on the VS Code Insiders channel) is needed for the agentic experience in VS Code. It will become stable shortly, we are a bit ahead of times with this functionality!

Learn more about Playwright Agents

New APIs

UI Mode and HTML Reporter

  • Added option to 'html' reporter to disable the "Copy prompt" button
  • Added option to 'html' reporter and UI Mode to merge files, collapsing test and describe blocks into a single unified list
  • Added option to UI Mode mirroring the --update-snapshots options
  • Added option to UI Mode to run only a single worker at a time

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​playwright/test since your current version.


Updates @types/react from 19.1.8 to 19.2.2

Commits

Updates @types/react-dom from 19.1.6 to 19.2.2

Commits

Updates sass from 1.89.2 to 1.93.2

Release notes

Sourced from sass's releases.

Dart Sass 1.93.2

To install Sass 1.93.2, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.

Changes

  • No user-visible changes.

JavaScript API

  • Fix another error in the release process for @sass/types.

See the full changelog for changes in earlier releases.

Dart Sass 1.93.1

To install Sass 1.93.1, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.

Changes

  • No user-visible changes.

JavaScript API

  • Fix an error in the release process for @sass/types.

See the full changelog for changes in earlier releases.

Dart Sass 1.93.0

To install Sass 1.93.0, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.

Changes

  • Fix a crash when a style rule contains a nested @import, and the loaded file @uses a user-defined module as well as @includes a top-level mixin which emits top-level declarations.

JavaScript API

  • Release a @sass/types package which contains the type annotations used by both the sass and sass-embedded package without any additional code or dependencies.

See the full changelog for changes in earlier releases.

Dart Sass 1.92.1

To install Sass 1.92.1, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.

... (truncated)

Changelog

Sourced from sass's changelog.

1.93.2

  • No user-visible changes.

JavaScript API

  • Fix another error in the release process for @sass/types.

1.93.1

  • No user-visible changes.

JavaScript API

  • Fix an error in the release process for @sass/types.

1.93.0

  • Fix a crash when a style rule contains a nested @import, and the loaded file @uses a user-defined module as well as @includes a top-level mixin which emits top-level declarations.

JavaScript API

  • Release a @sass/types package which contains the type annotations used by both the sass and sass-embedded package without any additional code or dependencies.

1.92.1

  • Fix a bug where variable definitions from one imported, forwarded module would not be passed as implicit configuration to a later imported, forwarded module.

1.92.0

  • Breaking change: Emit declarations, childless at-rules, and comments in the order they appear in the source even when they're interleaved with nested rules. This obsoletes the mixed-decls deprecation.

  • Breaking change: The function name type() is now fully reserved for the plain CSS function. This means that @function definitions with the name type will produce errors, while function calls will be parsed as special function strings.

  • Configuring private variables using @use ... with, @forward ... with, and meta.load-css(..., $with: ...) is now deprecated. Private variables were always intended to be fully encapsulated within the module that defines them, and this helps enforce that encapsulation.

... (truncated)

Commits

Updates typescript from 5.8.3 to 5.9.3

Release notes

Sourced from typescript's releases.

TypeScript 5.9.3

Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.

For release notes, check out the release announcement

Downloads are available on:

TypeScript 5.9

Note: this tag was recreated to point at the correct commit. The npm ...

Description has been truncated

…dates

Bumps the dependencies-minor group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@fontsource-variable/figtree](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/figtree) | `5.2.8` | `5.2.10` |
| [@fontsource/ibm-plex-mono](https://github.com/fontsource/font-files/tree/HEAD/fonts/google/ibm-plex-mono) | `5.2.6` | `5.2.7` |
| [@hookform/resolvers](https://github.com/react-hook-form/resolvers) | `5.1.1` | `5.2.2` |
| [@oddbird/css-anchor-positioning](https://github.com/oddbird/css-anchor-positioning) | `0.6.1` | `0.7.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.1.0` | `19.2.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.1.8` | `19.2.2` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.1.0` | `19.2.0` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.1.6` | `19.2.2` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.60.0` | `7.65.0` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.54.1` | `1.56.1` |
| [sass](https://github.com/sass/dart-sass) | `1.89.2` | `1.93.2` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.8.3` | `5.9.3` |



Updates `@fontsource-variable/figtree` from 5.2.8 to 5.2.10
- [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md)
- [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/figtree)

Updates `@fontsource/ibm-plex-mono` from 5.2.6 to 5.2.7
- [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md)
- [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/google/ibm-plex-mono)

Updates `@hookform/resolvers` from 5.1.1 to 5.2.2
- [Release notes](https://github.com/react-hook-form/resolvers/releases)
- [Commits](react-hook-form/resolvers@v5.1.1...v5.2.2)

Updates `@oddbird/css-anchor-positioning` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/oddbird/css-anchor-positioning/releases)
- [Changelog](https://github.com/oddbird/css-anchor-positioning/blob/main/CHANGELOG.md)
- [Commits](oddbird/css-anchor-positioning@v0.6.1...v0.7.0)

Updates `react` from 19.1.0 to 19.2.0
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.0/packages/react)

Updates `@types/react` from 19.1.8 to 19.2.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-dom` from 19.1.0 to 19.2.0
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.0/packages/react-dom)

Updates `@types/react-dom` from 19.1.6 to 19.2.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `react-hook-form` from 7.60.0 to 7.65.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.60.0...v7.65.0)

Updates `@playwright/test` from 1.54.1 to 1.56.1
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.54.1...v1.56.1)

Updates `@types/react` from 19.1.8 to 19.2.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@types/react-dom` from 19.1.6 to 19.2.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `sass` from 1.89.2 to 1.93.2
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](sass/dart-sass@1.89.2...1.93.2)

Updates `typescript` from 5.8.3 to 5.9.3
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml)
- [Commits](microsoft/TypeScript@v5.8.3...v5.9.3)

---
updated-dependencies:
- dependency-name: "@fontsource-variable/figtree"
  dependency-version: 5.2.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies-minor
- dependency-name: "@fontsource/ibm-plex-mono"
  dependency-version: 5.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies-minor
- dependency-name: "@hookform/resolvers"
  dependency-version: 5.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: "@oddbird/css-anchor-positioning"
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: react
  dependency-version: 19.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: "@types/react"
  dependency-version: 19.2.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: react-dom
  dependency-version: 19.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: react-hook-form
  dependency-version: 7.65.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: "@playwright/test"
  dependency-version: 1.56.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: "@types/react"
  dependency-version: 19.2.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: sass
  dependency-version: 1.93.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
- dependency-name: typescript
  dependency-version: 5.9.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 22, 2025
@fossabot
Copy link
Copy Markdown

fossabot bot commented Oct 22, 2025

fossabot Analysis Failed
You have no credits left. Reach out to autoupdates@fossa.com and we'll top you up.

Credits are consumed when dependency updates are reviewed or proposed.

Re-run with @fossabot analyze.

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Nov 18, 2025

Dependabot couldn't access the repository. Because of this, Dependabot cannot update this pull request.

@fossabot
Copy link
Copy Markdown

fossabot bot commented Mar 24, 2026

fossabot Analysis Paused

App impact analysis skipped — out of credits

Breaking change detection completed but more credits are needed to enable usage detection, impact analysis, fix suggestions, and get your final upgrade determination.

@fontsource-variable/figtree 5.2.85.2.10

View more changes for @fontsource-variable/figtree
  • Updated bundled Figtree variable font from v8 to v9 (v5.2.9, package source)
  • Updated metadata last modification date from 2025-05-13 to 2025-09-11 (v5.2.9, package source)
  • Updated license attribution from 'Google Inc.' to 'Copyright 2022 The Figtree Project Authors' to accurately reflect the font's actual authors (v5.2.10, package source)
  • Updated OFL license URL from http://scripts.sil.org/OFL to https://openfontlicense.org in LICENSE file, README.md, and metadata.json (v5.2.10, package source)
  • Updated README.md licensing section with correct copyright attribution for Figtree font authors (v5.2.10, package source)
  • Updated metadata.json with corrected license attribution and URL (v5.2.10, package source)

@fontsource/ibm-plex-mono 5.2.65.2.7

View more changes for @fontsource/ibm-plex-mono
  • Corrected license attribution metadata from 'Google Inc.' to 'Copyright 2017 IBM Corp. All rights reserved.' with full copyright details for all font variants (v5.2.7, package source)
  • Updated license URL from 'http://scripts.sil.org/OFL' to 'https://openfontlicense.org' for better accessibility and HTTPS security (v5.2.7, package source)
  • Updated IBM Plex Mono font files from version v19 to v20 - includes binary updates to all font variants (cyrillic, latin, vietnamese) in both woff and woff2 formats (v5.2.7, package source)
  • Updated package metadata lastModified date from '2025-05-30' to '2025-09-16' to reflect font source updates (v5.2.7, package source)

@hookform/resolvers 5.1.15.2.2

We found 1 breaking change.

  • Fixed Zod v4 resolver type signature - changed return type from Resolver<z4.input, Context, z4.output> to Resolver<z4.input, Context, z4.input>. The third generic parameter now correctly reflects the actual return type (validated input) instead of the Zod output type.... (v5.2.2, package source)
View more changes for @hookform/resolvers
  • ajv: add ajv-formats for ajvResolver (#797) (f040039) (v5.1.1-5.2.0, release notes)
  • discriminated union for zod v4 mini (#784) (49a0d7b) (v5.2.0-5.2.1, release notes)
  • zod v4 peer deps (#798) (2d28e6a) (v5.2.0-5.2.1, release notes)
  • zod: fix output type for Zod 4 resolver (#801) (bc09647) (v5.2.0-5.2.1, release notes)
  • zod: fix output type for Zod 4 resolver (#803) (e95721d) (v5.2.1-5.2.2, release notes)
  • Add ajv-formats support to ajvResolver (v5.1.1-5.2.0, commit)
  • Fix discriminated union support for Zod v4 (v5.2.0-5.2.1, commit)
  • Fix output type for Zod v4 resolver (v5.2.0-5.2.1, commit)
  • Fix Zod v4 peer dependencies (v5.2.0-5.2.1, commit)
  • Fix output type for Zod 4 resolver (v5.2.1-5.2.2, commit)

...and 8 more in the full analysis

@oddbird/css-anchor-positioning 0.6.10.7.0

View more changes for @oddbird/css-anchor-positioning
  • 🚀 Work with anchor and target inside same shadow root by @​wkillerud in https://redirect.github.com/oddbird/css-anchor-positioning/pull/353 (v0.6.1-0.7.0, release notes)
  • 🏠 INTERNAL: Upgrade dependencies (v0.6.1-0.7.0, release notes)
  • @​wkillerud made their first contribution in https://redirect.github.com/oddbird/css-anchor-positioning/pull/353 (v0.6.1-0.7.0, release notes)
  • Fixed polyfill to support querying anchors and targets across shadow DOM roots, enabling shadow root support as documented in Anchors and targets in shadow dom oddbird/css-anchor-positioning#191 (v0.7.0, package source)
  • Added new roots option to AnchorPositioningPolyfillOptions to support shadow DOM roots - allows configuring one or more shadow roots where the polyfill should apply (defaults to [document]) (v0.7.0, package source)
  • Exported new AnchorPositioningRoot type definition (Document | HTMLElement) for type-safe configuration of root elements (v0.7.0, package source)
  • Exported new querySelectorAllRoots() utility function for querying elements across multiple root elements (v0.7.0, package source)
  • Updated documentation to clarify that anchors and targets in separate shadow roots are now supported via the new roots option (v0.7.0, package source)
  • Updated production dependencies: @​floating-ui/dom (^1.7.1 → ^1.7.4), @​types/css-tree (^2.3.10 → ^2.3.11), nanoid (^5.1.5 → ^5.1.6) (v0.7.0, package source)
  • Updated development dependencies including @​eslint/js, @​vitest/*, typescript, vite, vitest, and other build tools to latest versions (v0.7.0, package source)

...and 1 more in the full analysis

react 19.1.019.2.0

We found 5 breaking changes and 1 deprecation.

View more changes for react
  • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @​hoxyq) (v19.1.1, changelog)
  • Bring React Server Component fixes to Server Actions (@​sebmarkbage #35277) (v19.1.1-19.1.2, changelog)
  • Fix infinite useDeferredValue loop in popstate event (@​acdlite #32821) (v19.2.0, changelog)
  • Fix a bug when an initial value was passed to useDeferredValue (@​acdlite #34376) (v19.2.0, changelog)
  • Fix a crash when submitting forms with Client Actions (@​sebmarkbage #33055) (v19.2.0, changelog)
  • Fix a bug with React.use inside React.lazy-ed Component (@​hi-ogawa #33941) (v19.2.0, changelog)
  • Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@​gnoff #33467) (v19.2.0, changelog)
  • Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@​sebmarkbage #34084, @​denk0403 #33761) (v19.2.0, changelog)
  • Fix a wrong missing key warning (@​unstubbable #34350) (v19.2.0, changelog)
  • Make console log resolve in predictable order (@​sebmarkbage #33665) (v19.2.0, changelog)

...and 308 more in the full analysis

@types/react 19.1.819.2.2

We found 8 breaking changes.

  • Removed unstable_Activity component from experimental.d.ts - previously available as unstable API (v19.1.13, package source)
  • Removed experimental_useEffectEvent from experimental module - this API has been moved to the canary module as useEffectEvent (v19.1.14, package source)
  • Removed ts5.0/v18 directory containing React v18 backward compatibility type definitions - projects relying on these legacy type paths will need to update their type imports or use @​types/react@​18 (v19.1.15, package source)
View more changes for @types/react
  • Improved type safety for SVG dominantBaseline attribute by replacing generic number | string with specific string literals: 'auto', 'use-script', 'no-change', 'reset-size', 'ideographic', 'alphabetic', 'hanging', 'mathematical', 'central', 'middle', 'text-after-edge', 'text-before-edge', 'inherit' (v19.1.11, package source)
  • Improved type safety for SVG textAnchor attribute by replacing generic string with specific string literals: 'start', 'middle', 'end', 'inherit' (v19.1.11, package source)
  • Added CacheSignal interface for React's experimental caching API (v19.1.9, package source)
  • Added cacheSignal() function that returns null or CacheSignal for cache invalidation control (v19.1.9, package source)
  • Added optional 'name' property to Activity boundary component for instrumentation purposes. The name helps identify the boundary in React DevTools. (v19.1.10, package source)
  • Added fetchPriority attribute to script elements with values 'high', 'low', or 'auto' for resource loading prioritization (v19.1.11, package source)
  • Added stable Activity component to canary.d.ts with ActivityProps interface for managing component visibility boundaries (v19.1.13, package source)
  • Activity component supports 'mode' prop with 'hidden' or 'visible' values (defaults to 'visible') for controlling visibility state (v19.1.13, package source)
  • Activity component supports optional 'name' prop for instrumentation and React DevTools identification (v19.1.13, package source)
  • Added useEffectEvent hook to canary module with signature useEffectEvent(callback: T): T for creating stable event callbacks that don't trigger effect re-runs (v19.1.14, package source)

...and 28 more in the full analysis

react-dom 19.1.019.2.0

We found 5 breaking changes and 1 deprecation.

  • Breaking: Require Node.js 18 or newer. (@​michaelfaith in #32458) (v19.1.5-19.2.0, release notes)
  • Breaking: Flat config is now the default recommended preset. Legacy config moved to recommended-legacy. (@​michaelfaith in #32457) (v19.1.5-19.2.0, release notes)
  • Only check if previously removed IO if its removal failed in DevTools (v19.1.5-19.2.0, commit)
View more changes for react-dom
  • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @​hoxyq) (v19.1.0-19.1.1, changelog)
  • Bring React Server Component fixes to Server Actions (@​sebmarkbage #35277) (v19.1.1-19.1.2, changelog)
  • Fix infinite useDeferredValue loop in popstate event (@​acdlite #32821) (v19.1.5-19.2.0, changelog)
  • Fix a bug when an initial value was passed to useDeferredValue (@​acdlite #34376) (v19.1.5-19.2.0, changelog)
  • Fix a crash when submitting forms with Client Actions (@​sebmarkbage #33055) (v19.1.5-19.2.0, changelog)
  • Fix a bug with React.use inside React.lazy-ed Component (@​hi-ogawa #33941) (v19.1.5-19.2.0, changelog)
  • Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@​gnoff #33467) (v19.1.5-19.2.0, changelog)
  • Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@​sebmarkbage #34084, @​denk0403 #33761) (v19.1.5-19.2.0, changelog)
  • Fix a wrong missing key warning (@​unstubbable #34350) (v19.1.5-19.2.0, changelog)
  • Make console log resolve in predictable order (@​sebmarkbage #33665) (v19.1.5-19.2.0, changelog)

...and 325 more in the full analysis

@types/react-dom 19.1.619.2.2

We found 4 breaking changes.

  • Updated peer dependency requirement from @​types/react ^19.0.0 to ^19.2.0 (v19.2.0, package source)
  • Removed ViewTransitionPseudoElement and ViewTransitionInstance interfaces from experimental.d.ts module declaration - these have been moved to canary.d.ts (v19.2.1, package source)
  • Removed FragmentInstance interface from experimental.d.ts module declaration - this has been moved to canary.d.ts (v19.2.1, package source)
View more changes for @types/react-dom
  • Renamed ImportMap type to ReactImportMap in PrerenderOptions.importMap property (v19.2.0, package source)
  • Added CacheSignal interface extending AbortSignal in React module declarations for improved cache control typing (v19.1.7, package source)
  • Added formState optional parameter to renderToPipeableStream options - allows passing ReactFormState for server-side form handling (v19.1.8, package source)
  • Added formState optional parameter to renderToReadableStream options - enables form state management in streaming SSR (v19.1.8, package source)
  • Imported ReactFormState type from client module in server.d.ts - provides type definitions for form state management (v19.1.8, package source)
  • Added experimental_scrollIntoView(alignToTop?: boolean) method to RefAttributes interface for experimental React DOM features (v19.1.9, package source)
  • Added PostponedState interface in react-dom/static module - an opaque, JSON-serializable type for storing postponed rendering state (v19.1.10, package source)
  • Added ResumeOptions interface with nonce, signal, and onError properties for configuring resume operations (v19.1.10, package source)
  • Added PrerenderResult interface with postponed property to return prerender results (v19.1.10, package source)
  • Added resumeAndPrerender() function in react-dom/static for resuming and prerendering React nodes with postponed state (v19.1.10, package source)

...and 41 more in the full analysis

react-hook-form 7.60.07.65.0

We found 1 breaking change.

  • Chore: major dev dependencies upgrade (v7.62.0-7.63.0, commit)
View more changes for react-hook-form
  • Fix watch return type based on defaultValue (v7.60.0-7.61.0, release notes)
  • Fix subscribe with latest defaultValues (v7.60.0-7.61.0, release notes)
  • Remove React wildcard import to resolve ESM build issues (v7.60.0-7.61.0, release notes)
  • Reverted fix for watch return type based on defaultValue (PR #12896) (v7.61.0-7.61.1, release notes)
  • Fix sync of two defaultValues after reset with new defaultValues (#12990) (v7.61.1-7.62.0, release notes)
  • Fix: do not override prototype of data in cloneObject (#12985) (v7.61.1-7.62.0, release notes)
  • Fix field name type conflict in nested FieldErrors (#12972) (v7.61.1-7.62.0, release notes)
  • Fix: preserve Controller's defaultValue with shouldUnregister prop (#13063) (v7.63.0-7.64.0, release notes)
  • fix: respect parent-provided useFieldArray rules (#13082, #13083) (v7.64.0-7.65.0, release notes)
  • fix: getDirtyFields submit fields with null values when using useForm (#13079) (v7.64.0-7.65.0, release notes)

...and 101 more in the full analysis

@playwright/test 1.54.11.56.1

We found 6 breaking changes and 2 deprecations.

  • ⚠️ Dropped support for Chromium extension manifest v2. (v1.54.2-1.55.0, release notes)
  • Undo non-breaking spaces in markdown report (v1.54.2-1.55.0, commit)
  • Removed custom dark mode scrollbar theming from UI (v1.55.1-1.56.0, commit)
View more changes for @playwright/test
  • Fixed regression: Codegen unable to launch in Administrator Terminal on Windows (ProtocolError) (v1.54.1-1.54.2, release notes)
  • Fixed regression: Starting Codegen with target language not working (v1.54.1-1.54.2, release notes)
  • Fix regression: "step id not found" internal error (v1.55.0-1.55.1, release notes)
  • Fix regression: HTML reporter displays broken chip link when there are no projects (v1.55.0-1.55.1, release notes)
  • Revert "fix(a11y): track inert elements as hidden" (v1.55.0-1.55.1, release notes)
  • Event browserContext.on('backgroundpage') has been deprecated and will not be emitted. Method [browserContext.backgroundPages()](https://playwright.... (v1.55.1-1.56.0, release notes)
  • New Property testStepInfo.titlePath Returns the full title path starting from the test file, including test and step titles. (v1.54.2-1.55.0, release notes)
  • Automatic toBeVisible() assertions: Codegen can now generate automatic toBeVisible() assertions for common UI interactions. This feature can be enabled in the Codegen settings UI. (v1.54.2-1.55.0, release notes)
  • Added support for Debian 13 "Trixie". (v1.54.2-1.55.0, release notes)
  • New methods page.consoleMessages() and page.pageErrors() for retrieving the most recent console messages from the page (v1.55.1-1.56.0, release notes)

...and 468 more in the full analysis

sass 1.89.21.93.2

We found 3 breaking changes and 6 deprecations.

  • Breaking change: Emit declarations, childless at-rules, and comments in the order they appear in the source even when they're interleaved with nested rules. This obsoletes the mixed-decls deprecation. (v1.91.0-1.92.0, release notes)
  • Breaking change: The function name type() is now fully reserved for the plain CSS function. This means that @​function definitions with the name type will produce errors, while function calls will be parsed as special function strings. (v1.91.0-1.92.0, release notes)
  • Potentially breaking change: meta.inspect() (as well as other systems that use it such as @​debug and certain error messages) now emits numbers with as high precision as is available instead of rounding to the nearest 1e⁻¹⁰ as we do when serializing to CSS.... (v1.90.0-1.91.0, changelog)
View more changes for sass
  • Fix a performance regression that was introduced in 1.92.0. (v1.91.0-1.92.0, changelog)
  • Fix a bug where variable definitions from one imported, forwarded module would not be passed as implicit configuration to a later imported, forwarded module. (v1.92.0-1.92.1, changelog)
  • Fix a crash when a style rule contains a nested @​import, and the loaded file @​uses a user-defined module as well as @​includes a top-level mixin which emits top-level declarations. (v1.92.1-1.93.0, changelog)
  • Fix an error in the release process for @​sass/types. (v1.93.0-1.93.1, changelog)
  • Fix another error in the release process for @​sass/types. (v1.93.1-1.93.2, changelog)
  • Passing a rest argument ($arg...) before a positional or named argument when calling a function or mixin is now deprecated. This was always outside the specified syntax, but it was historically treated the same as passing the rest argument at the end of the argument list whether or not that... (v1.90.0-1.91.0, changelog)
  • Release a @​sass/types package which contains the type annotations used by both the sass and sass-embedded package without any additional code or dependencies. (v1.92.1-1.93.0, changelog)
  • Allow a @​forwarded module to be loaded with a configuration when that module has already been loaded with a different configuration and the module doesn't define any variables that would have been configured anyway. (v1.89.2-1.90.0, changelog)
  • No user-visible changes. (v1.93.0-1.93.1, changelog)
  • No user-visible changes. (v1.93.1-1.93.2, changelog)

...and 56 more in the full analysis

typescript 5.8.35.9.3

We found 2 breaking changes.

  • Update dependencies, including major versions (v5.9.2, commit)
  • chalk removed (no longer a dependency) (v5.9.2, package source)
View more changes for typescript

...and 134 more in the full analysis


You have no credits left. Reach out to autoupdates@fossa.com and we'll top you up.

Credits are consumed when dependency updates are reviewed or proposed.

Re-run with @fossabot analyze.

Mute out-of-credit notifications until next month (expires 2026-04-01T00:00:00.000Z)

2 similar comments
@fossabot
Copy link
Copy Markdown

fossabot bot commented Mar 25, 2026

fossabot Analysis Paused

App impact analysis skipped — out of credits

Breaking change detection completed but more credits are needed to enable usage detection, impact analysis, fix suggestions, and get your final upgrade determination.

@fontsource-variable/figtree 5.2.85.2.10

View more changes for @fontsource-variable/figtree
  • Updated bundled Figtree variable font from v8 to v9 (v5.2.9, package source)
  • Updated metadata last modification date from 2025-05-13 to 2025-09-11 (v5.2.9, package source)
  • Updated license attribution from 'Google Inc.' to 'Copyright 2022 The Figtree Project Authors' to accurately reflect the font's actual authors (v5.2.10, package source)
  • Updated OFL license URL from http://scripts.sil.org/OFL to https://openfontlicense.org in LICENSE file, README.md, and metadata.json (v5.2.10, package source)
  • Updated README.md licensing section with correct copyright attribution for Figtree font authors (v5.2.10, package source)
  • Updated metadata.json with corrected license attribution and URL (v5.2.10, package source)

@fontsource/ibm-plex-mono 5.2.65.2.7

View more changes for @fontsource/ibm-plex-mono
  • Corrected license attribution metadata from 'Google Inc.' to 'Copyright 2017 IBM Corp. All rights reserved.' with full copyright details for all font variants (v5.2.7, package source)
  • Updated license URL from 'http://scripts.sil.org/OFL' to 'https://openfontlicense.org' for better accessibility and HTTPS security (v5.2.7, package source)
  • Updated IBM Plex Mono font files from version v19 to v20 - includes binary updates to all font variants (cyrillic, latin, vietnamese) in both woff and woff2 formats (v5.2.7, package source)
  • Updated package metadata lastModified date from '2025-05-30' to '2025-09-16' to reflect font source updates (v5.2.7, package source)

@hookform/resolvers 5.1.15.2.2

We found 1 breaking change.

  • Fixed Zod v4 resolver type signature - changed return type from Resolver<z4.input, Context, z4.output> to Resolver<z4.input, Context, z4.input>. The third generic parameter now correctly reflects the actual return type (validated input) instead of the Zod output type.... (v5.2.2, package source)
View more changes for @hookform/resolvers
  • ajv: add ajv-formats for ajvResolver (#797) (f040039) (v5.1.1-5.2.0, release notes)
  • discriminated union for zod v4 mini (#784) (49a0d7b) (v5.2.0-5.2.1, release notes)
  • zod v4 peer deps (#798) (2d28e6a) (v5.2.0-5.2.1, release notes)
  • zod: fix output type for Zod 4 resolver (#801) (bc09647) (v5.2.0-5.2.1, release notes)
  • zod: fix output type for Zod 4 resolver (#803) (e95721d) (v5.2.1-5.2.2, release notes)
  • Add ajv-formats support to ajvResolver (v5.1.1-5.2.0, commit)
  • Fix discriminated union support for Zod v4 (v5.2.0-5.2.1, commit)
  • Fix output type for Zod v4 resolver (v5.2.0-5.2.1, commit)
  • Fix Zod v4 peer dependencies (v5.2.0-5.2.1, commit)
  • Fix output type for Zod 4 resolver (v5.2.1-5.2.2, commit)

...and 8 more in the full analysis

@oddbird/css-anchor-positioning 0.6.10.7.0

View more changes for @oddbird/css-anchor-positioning
  • 🚀 Work with anchor and target inside same shadow root by @​wkillerud in https://redirect.github.com/oddbird/css-anchor-positioning/pull/353 (v0.6.1-0.7.0, release notes)
  • 🏠 INTERNAL: Upgrade dependencies (v0.6.1-0.7.0, release notes)
  • @​wkillerud made their first contribution in https://redirect.github.com/oddbird/css-anchor-positioning/pull/353 (v0.6.1-0.7.0, release notes)
  • Fixed polyfill to support querying anchors and targets across shadow DOM roots, enabling shadow root support as documented in Anchors and targets in shadow dom oddbird/css-anchor-positioning#191 (v0.7.0, package source)
  • Added new roots option to AnchorPositioningPolyfillOptions to support shadow DOM roots - allows configuring one or more shadow roots where the polyfill should apply (defaults to [document]) (v0.7.0, package source)
  • Exported new AnchorPositioningRoot type definition (Document | HTMLElement) for type-safe configuration of root elements (v0.7.0, package source)
  • Exported new querySelectorAllRoots() utility function for querying elements across multiple root elements (v0.7.0, package source)
  • Updated documentation to clarify that anchors and targets in separate shadow roots are now supported via the new roots option (v0.7.0, package source)
  • Updated production dependencies: @​floating-ui/dom (^1.7.1 → ^1.7.4), @​types/css-tree (^2.3.10 → ^2.3.11), nanoid (^5.1.5 → ^5.1.6) (v0.7.0, package source)
  • Updated development dependencies including @​eslint/js, @​vitest/*, typescript, vite, vitest, and other build tools to latest versions (v0.7.0, package source)

...and 1 more in the full analysis

react 19.1.019.2.0

We found 5 breaking changes and 1 deprecation.

View more changes for react
  • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @​hoxyq) (v19.1.1, changelog)
  • Bring React Server Component fixes to Server Actions (@​sebmarkbage #35277) (v19.1.1-19.1.2, changelog)
  • Fix infinite useDeferredValue loop in popstate event (@​acdlite #32821) (v19.2.0, changelog)
  • Fix a bug when an initial value was passed to useDeferredValue (@​acdlite #34376) (v19.2.0, changelog)
  • Fix a crash when submitting forms with Client Actions (@​sebmarkbage #33055) (v19.2.0, changelog)
  • Fix a bug with React.use inside React.lazy-ed Component (@​hi-ogawa #33941) (v19.2.0, changelog)
  • Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@​gnoff #33467) (v19.2.0, changelog)
  • Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@​sebmarkbage #34084, @​denk0403 #33761) (v19.2.0, changelog)
  • Fix a wrong missing key warning (@​unstubbable #34350) (v19.2.0, changelog)
  • Make console log resolve in predictable order (@​sebmarkbage #33665) (v19.2.0, changelog)

...and 308 more in the full analysis

@types/react 19.1.819.2.2

We found 8 breaking changes.

  • Removed unstable_Activity component from experimental.d.ts - previously available as unstable API (v19.1.13, package source)
  • Removed experimental_useEffectEvent from experimental module - this API has been moved to the canary module as useEffectEvent (v19.1.14, package source)
  • Removed ts5.0/v18 directory containing React v18 backward compatibility type definitions - projects relying on these legacy type paths will need to update their type imports or use @​types/react@​18 (v19.1.15, package source)
View more changes for @types/react
  • Improved type safety for SVG dominantBaseline attribute by replacing generic number | string with specific string literals: 'auto', 'use-script', 'no-change', 'reset-size', 'ideographic', 'alphabetic', 'hanging', 'mathematical', 'central', 'middle', 'text-after-edge', 'text-before-edge', 'inherit' (v19.1.11, package source)
  • Improved type safety for SVG textAnchor attribute by replacing generic string with specific string literals: 'start', 'middle', 'end', 'inherit' (v19.1.11, package source)
  • Added CacheSignal interface for React's experimental caching API (v19.1.9, package source)
  • Added cacheSignal() function that returns null or CacheSignal for cache invalidation control (v19.1.9, package source)
  • Added optional 'name' property to Activity boundary component for instrumentation purposes. The name helps identify the boundary in React DevTools. (v19.1.10, package source)
  • Added fetchPriority attribute to script elements with values 'high', 'low', or 'auto' for resource loading prioritization (v19.1.11, package source)
  • Added stable Activity component to canary.d.ts with ActivityProps interface for managing component visibility boundaries (v19.1.13, package source)
  • Activity component supports 'mode' prop with 'hidden' or 'visible' values (defaults to 'visible') for controlling visibility state (v19.1.13, package source)
  • Activity component supports optional 'name' prop for instrumentation and React DevTools identification (v19.1.13, package source)
  • Added useEffectEvent hook to canary module with signature useEffectEvent(callback: T): T for creating stable event callbacks that don't trigger effect re-runs (v19.1.14, package source)

...and 28 more in the full analysis

react-dom 19.1.019.2.0

We found 5 breaking changes and 1 deprecation.

  • Breaking: Require Node.js 18 or newer. (@​michaelfaith in #32458) (v19.1.5-19.2.0, release notes)
  • Breaking: Flat config is now the default recommended preset. Legacy config moved to recommended-legacy. (@​michaelfaith in #32457) (v19.1.5-19.2.0, release notes)
  • Only check if previously removed IO if its removal failed in DevTools (v19.1.5-19.2.0, commit)
View more changes for react-dom
  • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @​hoxyq) (v19.1.0-19.1.1, changelog)
  • Bring React Server Component fixes to Server Actions (@​sebmarkbage #35277) (v19.1.1-19.1.2, changelog)
  • Fix infinite useDeferredValue loop in popstate event (@​acdlite #32821) (v19.1.5-19.2.0, changelog)
  • Fix a bug when an initial value was passed to useDeferredValue (@​acdlite #34376) (v19.1.5-19.2.0, changelog)
  • Fix a crash when submitting forms with Client Actions (@​sebmarkbage #33055) (v19.1.5-19.2.0, changelog)
  • Fix a bug with React.use inside React.lazy-ed Component (@​hi-ogawa #33941) (v19.1.5-19.2.0, changelog)
  • Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@​gnoff #33467) (v19.1.5-19.2.0, changelog)
  • Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@​sebmarkbage #34084, @​denk0403 #33761) (v19.1.5-19.2.0, changelog)
  • Fix a wrong missing key warning (@​unstubbable #34350) (v19.1.5-19.2.0, changelog)
  • Make console log resolve in predictable order (@​sebmarkbage #33665) (v19.1.5-19.2.0, changelog)

...and 325 more in the full analysis

@types/react-dom 19.1.619.2.2

We found 4 breaking changes.

  • Updated peer dependency requirement from @​types/react ^19.0.0 to ^19.2.0 (v19.2.0, package source)
  • Removed ViewTransitionPseudoElement and ViewTransitionInstance interfaces from experimental.d.ts module declaration - these have been moved to canary.d.ts (v19.2.1, package source)
  • Removed FragmentInstance interface from experimental.d.ts module declaration - this has been moved to canary.d.ts (v19.2.1, package source)
View more changes for @types/react-dom
  • Renamed ImportMap type to ReactImportMap in PrerenderOptions.importMap property (v19.2.0, package source)
  • Added CacheSignal interface extending AbortSignal in React module declarations for improved cache control typing (v19.1.7, package source)
  • Added formState optional parameter to renderToPipeableStream options - allows passing ReactFormState for server-side form handling (v19.1.8, package source)
  • Added formState optional parameter to renderToReadableStream options - enables form state management in streaming SSR (v19.1.8, package source)
  • Imported ReactFormState type from client module in server.d.ts - provides type definitions for form state management (v19.1.8, package source)
  • Added experimental_scrollIntoView(alignToTop?: boolean) method to RefAttributes interface for experimental React DOM features (v19.1.9, package source)
  • Added PostponedState interface in react-dom/static module - an opaque, JSON-serializable type for storing postponed rendering state (v19.1.10, package source)
  • Added ResumeOptions interface with nonce, signal, and onError properties for configuring resume operations (v19.1.10, package source)
  • Added PrerenderResult interface with postponed property to return prerender results (v19.1.10, package source)
  • Added resumeAndPrerender() function in react-dom/static for resuming and prerendering React nodes with postponed state (v19.1.10, package source)

...and 41 more in the full analysis

react-hook-form 7.60.07.65.0

We found 1 breaking change.

  • Chore: major dev dependencies upgrade (v7.62.0-7.63.0, commit)
View more changes for react-hook-form
  • Fix watch return type based on defaultValue (v7.60.0-7.61.0, release notes)
  • Fix subscribe with latest defaultValues (v7.60.0-7.61.0, release notes)
  • Remove React wildcard import to resolve ESM build issues (v7.60.0-7.61.0, release notes)
  • Reverted fix for watch return type based on defaultValue (PR #12896) (v7.61.0-7.61.1, release notes)
  • Fix sync of two defaultValues after reset with new defaultValues (#12990) (v7.61.1-7.62.0, release notes)
  • Fix: do not override prototype of data in cloneObject (#12985) (v7.61.1-7.62.0, release notes)
  • Fix field name type conflict in nested FieldErrors (#12972) (v7.61.1-7.62.0, release notes)
  • Fix: preserve Controller's defaultValue with shouldUnregister prop (#13063) (v7.63.0-7.64.0, release notes)
  • fix: respect parent-provided useFieldArray rules (#13082, #13083) (v7.64.0-7.65.0, release notes)
  • fix: getDirtyFields submit fields with null values when using useForm (#13079) (v7.64.0-7.65.0, release notes)

...and 101 more in the full analysis

@playwright/test 1.54.11.56.1

We found 6 breaking changes and 2 deprecations.

  • ⚠️ Dropped support for Chromium extension manifest v2. (v1.54.2-1.55.0, release notes)
  • Undo non-breaking spaces in markdown report (v1.54.2-1.55.0, commit)
  • Removed custom dark mode scrollbar theming from UI (v1.55.1-1.56.0, commit)
View more changes for @playwright/test
  • Fixed regression: Codegen unable to launch in Administrator Terminal on Windows (ProtocolError) (v1.54.1-1.54.2, release notes)
  • Fixed regression: Starting Codegen with target language not working (v1.54.1-1.54.2, release notes)
  • Fix regression: "step id not found" internal error (v1.55.0-1.55.1, release notes)
  • Fix regression: HTML reporter displays broken chip link when there are no projects (v1.55.0-1.55.1, release notes)
  • Revert "fix(a11y): track inert elements as hidden" (v1.55.0-1.55.1, release notes)
  • Event browserContext.on('backgroundpage') has been deprecated and will not be emitted. Method [browserContext.backgroundPages()](https://playwright.... (v1.55.1-1.56.0, release notes)
  • New Property testStepInfo.titlePath Returns the full title path starting from the test file, including test and step titles. (v1.54.2-1.55.0, release notes)
  • Automatic toBeVisible() assertions: Codegen can now generate automatic toBeVisible() assertions for common UI interactions. This feature can be enabled in the Codegen settings UI. (v1.54.2-1.55.0, release notes)
  • Added support for Debian 13 "Trixie". (v1.54.2-1.55.0, release notes)
  • New methods page.consoleMessages() and page.pageErrors() for retrieving the most recent console messages from the page (v1.55.1-1.56.0, release notes)

...and 468 more in the full analysis

sass 1.89.21.93.2

We found 3 breaking changes and 6 deprecations.

  • Breaking change: Emit declarations, childless at-rules, and comments in the order they appear in the source even when they're interleaved with nested rules. This obsoletes the mixed-decls deprecation. (v1.91.0-1.92.0, release notes)
  • Breaking change: The function name type() is now fully reserved for the plain CSS function. This means that @​function definitions with the name type will produce errors, while function calls will be parsed as special function strings. (v1.91.0-1.92.0, release notes)
  • Potentially breaking change: meta.inspect() (as well as other systems that use it such as @​debug and certain error messages) now emits numbers with as high precision as is available instead of rounding to the nearest 1e⁻¹⁰ as we do when serializing to CSS.... (v1.90.0-1.91.0, changelog)
View more changes for sass
  • Fix a performance regression that was introduced in 1.92.0. (v1.91.0-1.92.0, changelog)
  • Fix a bug where variable definitions from one imported, forwarded module would not be passed as implicit configuration to a later imported, forwarded module. (v1.92.0-1.92.1, changelog)
  • Fix a crash when a style rule contains a nested @​import, and the loaded file @​uses a user-defined module as well as @​includes a top-level mixin which emits top-level declarations. (v1.92.1-1.93.0, changelog)
  • Fix an error in the release process for @​sass/types. (v1.93.0-1.93.1, changelog)
  • Fix another error in the release process for @​sass/types. (v1.93.1-1.93.2, changelog)
  • Passing a rest argument ($arg...) before a positional or named argument when calling a function or mixin is now deprecated. This was always outside the specified syntax, but it was historically treated the same as passing the rest argument at the end of the argument list whether or not that... (v1.90.0-1.91.0, changelog)
  • Release a @​sass/types package which contains the type annotations used by both the sass and sass-embedded package without any additional code or dependencies. (v1.92.1-1.93.0, changelog)
  • Allow a @​forwarded module to be loaded with a configuration when that module has already been loaded with a different configuration and the module doesn't define any variables that would have been configured anyway. (v1.89.2-1.90.0, changelog)
  • No user-visible changes. (v1.93.0-1.93.1, changelog)
  • No user-visible changes. (v1.93.1-1.93.2, changelog)

...and 56 more in the full analysis

typescript 5.8.35.9.3

We found 2 breaking changes.

  • Update dependencies, including major versions (v5.9.2, commit)
  • chalk removed (no longer a dependency) (v5.9.2, package source)
View more changes for typescript

...and 134 more in the full analysis


You have no credits left. Reach out to autoupdates@fossa.com and we'll top you up.

Credits are consumed when dependency updates are reviewed or proposed.

Re-run with @fossabot analyze.

Mute out-of-credit notifications until next month (expires 2026-04-01T00:00:00.000Z)

@fossabot
Copy link
Copy Markdown

fossabot bot commented Mar 26, 2026

fossabot Analysis Paused

App impact analysis skipped — out of credits

Breaking change detection completed but more credits are needed to enable usage detection, impact analysis, fix suggestions, and get your final upgrade determination.

@fontsource-variable/figtree 5.2.85.2.10

View more changes for @fontsource-variable/figtree
  • Updated bundled Figtree variable font from v8 to v9 (v5.2.9, package source)
  • Updated metadata last modification date from 2025-05-13 to 2025-09-11 (v5.2.9, package source)
  • Updated license attribution from 'Google Inc.' to 'Copyright 2022 The Figtree Project Authors' to accurately reflect the font's actual authors (v5.2.10, package source)
  • Updated OFL license URL from http://scripts.sil.org/OFL to https://openfontlicense.org in LICENSE file, README.md, and metadata.json (v5.2.10, package source)
  • Updated README.md licensing section with correct copyright attribution for Figtree font authors (v5.2.10, package source)
  • Updated metadata.json with corrected license attribution and URL (v5.2.10, package source)

@fontsource/ibm-plex-mono 5.2.65.2.7

View more changes for @fontsource/ibm-plex-mono
  • Corrected license attribution metadata from 'Google Inc.' to 'Copyright 2017 IBM Corp. All rights reserved.' with full copyright details for all font variants (v5.2.7, package source)
  • Updated license URL from 'http://scripts.sil.org/OFL' to 'https://openfontlicense.org' for better accessibility and HTTPS security (v5.2.7, package source)
  • Updated IBM Plex Mono font files from version v19 to v20 - includes binary updates to all font variants (cyrillic, latin, vietnamese) in both woff and woff2 formats (v5.2.7, package source)
  • Updated package metadata lastModified date from '2025-05-30' to '2025-09-16' to reflect font source updates (v5.2.7, package source)

@hookform/resolvers 5.1.15.2.2

We found 1 breaking change.

  • Fixed Zod v4 resolver type signature - changed return type from Resolver<z4.input, Context, z4.output> to Resolver<z4.input, Context, z4.input>. The third generic parameter now correctly reflects the actual return type (validated input) instead of the Zod output type.... (v5.2.2, package source)
View more changes for @hookform/resolvers
  • ajv: add ajv-formats for ajvResolver (#797) (f040039) (v5.1.1-5.2.0, release notes)
  • discriminated union for zod v4 mini (#784) (49a0d7b) (v5.2.0-5.2.1, release notes)
  • zod v4 peer deps (#798) (2d28e6a) (v5.2.0-5.2.1, release notes)
  • zod: fix output type for Zod 4 resolver (#801) (bc09647) (v5.2.0-5.2.1, release notes)
  • zod: fix output type for Zod 4 resolver (#803) (e95721d) (v5.2.1-5.2.2, release notes)
  • Add ajv-formats support to ajvResolver (v5.1.1-5.2.0, commit)
  • Fix discriminated union support for Zod v4 (v5.2.0-5.2.1, commit)
  • Fix output type for Zod v4 resolver (v5.2.0-5.2.1, commit)
  • Fix Zod v4 peer dependencies (v5.2.0-5.2.1, commit)
  • Fix output type for Zod 4 resolver (v5.2.1-5.2.2, commit)

...and 8 more in the full analysis

@oddbird/css-anchor-positioning 0.6.10.7.0

View more changes for @oddbird/css-anchor-positioning
  • 🚀 Work with anchor and target inside same shadow root by @​wkillerud in https://redirect.github.com/oddbird/css-anchor-positioning/pull/353 (v0.6.1-0.7.0, release notes)
  • 🏠 INTERNAL: Upgrade dependencies (v0.6.1-0.7.0, release notes)
  • @​wkillerud made their first contribution in https://redirect.github.com/oddbird/css-anchor-positioning/pull/353 (v0.6.1-0.7.0, release notes)
  • Fixed polyfill to support querying anchors and targets across shadow DOM roots, enabling shadow root support as documented in Anchors and targets in shadow dom oddbird/css-anchor-positioning#191 (v0.7.0, package source)
  • Added new roots option to AnchorPositioningPolyfillOptions to support shadow DOM roots - allows configuring one or more shadow roots where the polyfill should apply (defaults to [document]) (v0.7.0, package source)
  • Exported new AnchorPositioningRoot type definition (Document | HTMLElement) for type-safe configuration of root elements (v0.7.0, package source)
  • Exported new querySelectorAllRoots() utility function for querying elements across multiple root elements (v0.7.0, package source)
  • Updated documentation to clarify that anchors and targets in separate shadow roots are now supported via the new roots option (v0.7.0, package source)
  • Updated production dependencies: @​floating-ui/dom (^1.7.1 → ^1.7.4), @​types/css-tree (^2.3.10 → ^2.3.11), nanoid (^5.1.5 → ^5.1.6) (v0.7.0, package source)
  • Updated development dependencies including @​eslint/js, @​vitest/*, typescript, vite, vitest, and other build tools to latest versions (v0.7.0, package source)

...and 1 more in the full analysis

react 19.1.019.2.0

We found 5 breaking changes and 1 deprecation.

View more changes for react
  • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @​hoxyq) (v19.1.1, changelog)
  • Bring React Server Component fixes to Server Actions (@​sebmarkbage #35277) (v19.1.1-19.1.2, changelog)
  • Fix infinite useDeferredValue loop in popstate event (@​acdlite #32821) (v19.2.0, changelog)
  • Fix a bug when an initial value was passed to useDeferredValue (@​acdlite #34376) (v19.2.0, changelog)
  • Fix a crash when submitting forms with Client Actions (@​sebmarkbage #33055) (v19.2.0, changelog)
  • Fix a bug with React.use inside React.lazy-ed Component (@​hi-ogawa #33941) (v19.2.0, changelog)
  • Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@​gnoff #33467) (v19.2.0, changelog)
  • Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@​sebmarkbage #34084, @​denk0403 #33761) (v19.2.0, changelog)
  • Fix a wrong missing key warning (@​unstubbable #34350) (v19.2.0, changelog)
  • Make console log resolve in predictable order (@​sebmarkbage #33665) (v19.2.0, changelog)

...and 308 more in the full analysis

@types/react 19.1.819.2.2

We found 8 breaking changes.

  • Removed unstable_Activity component from experimental.d.ts - previously available as unstable API (v19.1.13, package source)
  • Removed experimental_useEffectEvent from experimental module - this API has been moved to the canary module as useEffectEvent (v19.1.14, package source)
  • Removed ts5.0/v18 directory containing React v18 backward compatibility type definitions - projects relying on these legacy type paths will need to update their type imports or use @​types/react@​18 (v19.1.15, package source)
View more changes for @types/react
  • Improved type safety for SVG dominantBaseline attribute by replacing generic number | string with specific string literals: 'auto', 'use-script', 'no-change', 'reset-size', 'ideographic', 'alphabetic', 'hanging', 'mathematical', 'central', 'middle', 'text-after-edge', 'text-before-edge', 'inherit' (v19.1.11, package source)
  • Improved type safety for SVG textAnchor attribute by replacing generic string with specific string literals: 'start', 'middle', 'end', 'inherit' (v19.1.11, package source)
  • Added CacheSignal interface for React's experimental caching API (v19.1.9, package source)
  • Added cacheSignal() function that returns null or CacheSignal for cache invalidation control (v19.1.9, package source)
  • Added optional 'name' property to Activity boundary component for instrumentation purposes. The name helps identify the boundary in React DevTools. (v19.1.10, package source)
  • Added fetchPriority attribute to script elements with values 'high', 'low', or 'auto' for resource loading prioritization (v19.1.11, package source)
  • Added stable Activity component to canary.d.ts with ActivityProps interface for managing component visibility boundaries (v19.1.13, package source)
  • Activity component supports 'mode' prop with 'hidden' or 'visible' values (defaults to 'visible') for controlling visibility state (v19.1.13, package source)
  • Activity component supports optional 'name' prop for instrumentation and React DevTools identification (v19.1.13, package source)
  • Added useEffectEvent hook to canary module with signature useEffectEvent(callback: T): T for creating stable event callbacks that don't trigger effect re-runs (v19.1.14, package source)

...and 28 more in the full analysis

react-dom 19.1.019.2.0

We found 5 breaking changes and 1 deprecation.

  • Breaking: Require Node.js 18 or newer. (@​michaelfaith in #32458) (v19.1.5-19.2.0, release notes)
  • Breaking: Flat config is now the default recommended preset. Legacy config moved to recommended-legacy. (@​michaelfaith in #32457) (v19.1.5-19.2.0, release notes)
  • Only check if previously removed IO if its removal failed in DevTools (v19.1.5-19.2.0, commit)
View more changes for react-dom
  • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @​hoxyq) (v19.1.0-19.1.1, changelog)
  • Bring React Server Component fixes to Server Actions (@​sebmarkbage #35277) (v19.1.1-19.1.2, changelog)
  • Fix infinite useDeferredValue loop in popstate event (@​acdlite #32821) (v19.1.5-19.2.0, changelog)
  • Fix a bug when an initial value was passed to useDeferredValue (@​acdlite #34376) (v19.1.5-19.2.0, changelog)
  • Fix a crash when submitting forms with Client Actions (@​sebmarkbage #33055) (v19.1.5-19.2.0, changelog)
  • Fix a bug with React.use inside React.lazy-ed Component (@​hi-ogawa #33941) (v19.1.5-19.2.0, changelog)
  • Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@​gnoff #33467) (v19.1.5-19.2.0, changelog)
  • Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@​sebmarkbage #34084, @​denk0403 #33761) (v19.1.5-19.2.0, changelog)
  • Fix a wrong missing key warning (@​unstubbable #34350) (v19.1.5-19.2.0, changelog)
  • Make console log resolve in predictable order (@​sebmarkbage #33665) (v19.1.5-19.2.0, changelog)

...and 325 more in the full analysis

@types/react-dom 19.1.619.2.2

We found 4 breaking changes.

  • Updated peer dependency requirement from @​types/react ^19.0.0 to ^19.2.0 (v19.2.0, package source)
  • Removed ViewTransitionPseudoElement and ViewTransitionInstance interfaces from experimental.d.ts module declaration - these have been moved to canary.d.ts (v19.2.1, package source)
  • Removed FragmentInstance interface from experimental.d.ts module declaration - this has been moved to canary.d.ts (v19.2.1, package source)
View more changes for @types/react-dom
  • Renamed ImportMap type to ReactImportMap in PrerenderOptions.importMap property (v19.2.0, package source)
  • Added CacheSignal interface extending AbortSignal in React module declarations for improved cache control typing (v19.1.7, package source)
  • Added formState optional parameter to renderToPipeableStream options - allows passing ReactFormState for server-side form handling (v19.1.8, package source)
  • Added formState optional parameter to renderToReadableStream options - enables form state management in streaming SSR (v19.1.8, package source)
  • Imported ReactFormState type from client module in server.d.ts - provides type definitions for form state management (v19.1.8, package source)
  • Added experimental_scrollIntoView(alignToTop?: boolean) method to RefAttributes interface for experimental React DOM features (v19.1.9, package source)
  • Added PostponedState interface in react-dom/static module - an opaque, JSON-serializable type for storing postponed rendering state (v19.1.10, package source)
  • Added ResumeOptions interface with nonce, signal, and onError properties for configuring resume operations (v19.1.10, package source)
  • Added PrerenderResult interface with postponed property to return prerender results (v19.1.10, package source)
  • Added resumeAndPrerender() function in react-dom/static for resuming and prerendering React nodes with postponed state (v19.1.10, package source)

...and 41 more in the full analysis

react-hook-form 7.60.07.65.0

We found 1 breaking change.

  • Chore: major dev dependencies upgrade (v7.62.0-7.63.0, commit)
View more changes for react-hook-form
  • Fix watch return type based on defaultValue (v7.60.0-7.61.0, release notes)
  • Fix subscribe with latest defaultValues (v7.60.0-7.61.0, release notes)
  • Remove React wildcard import to resolve ESM build issues (v7.60.0-7.61.0, release notes)
  • Reverted fix for watch return type based on defaultValue (PR #12896) (v7.61.0-7.61.1, release notes)
  • Fix sync of two defaultValues after reset with new defaultValues (#12990) (v7.61.1-7.62.0, release notes)
  • Fix: do not override prototype of data in cloneObject (#12985) (v7.61.1-7.62.0, release notes)
  • Fix field name type conflict in nested FieldErrors (#12972) (v7.61.1-7.62.0, release notes)
  • Fix: preserve Controller's defaultValue with shouldUnregister prop (#13063) (v7.63.0-7.64.0, release notes)
  • fix: respect parent-provided useFieldArray rules (#13082, #13083) (v7.64.0-7.65.0, release notes)
  • fix: getDirtyFields submit fields with null values when using useForm (#13079) (v7.64.0-7.65.0, release notes)

...and 101 more in the full analysis

@playwright/test 1.54.11.56.1

We found 6 breaking changes and 2 deprecations.

  • ⚠️ Dropped support for Chromium extension manifest v2. (v1.54.2-1.55.0, release notes)
  • Undo non-breaking spaces in markdown report (v1.54.2-1.55.0, commit)
  • Removed custom dark mode scrollbar theming from UI (v1.55.1-1.56.0, commit)
View more changes for @playwright/test
  • Fixed regression: Codegen unable to launch in Administrator Terminal on Windows (ProtocolError) (v1.54.1-1.54.2, release notes)
  • Fixed regression: Starting Codegen with target language not working (v1.54.1-1.54.2, release notes)
  • Fix regression: "step id not found" internal error (v1.55.0-1.55.1, release notes)
  • Fix regression: HTML reporter displays broken chip link when there are no projects (v1.55.0-1.55.1, release notes)
  • Revert "fix(a11y): track inert elements as hidden" (v1.55.0-1.55.1, release notes)
  • Event browserContext.on('backgroundpage') has been deprecated and will not be emitted. Method [browserContext.backgroundPages()](https://playwright.... (v1.55.1-1.56.0, release notes)
  • New Property testStepInfo.titlePath Returns the full title path starting from the test file, including test and step titles. (v1.54.2-1.55.0, release notes)
  • Automatic toBeVisible() assertions: Codegen can now generate automatic toBeVisible() assertions for common UI interactions. This feature can be enabled in the Codegen settings UI. (v1.54.2-1.55.0, release notes)
  • Added support for Debian 13 "Trixie". (v1.54.2-1.55.0, release notes)
  • New methods page.consoleMessages() and page.pageErrors() for retrieving the most recent console messages from the page (v1.55.1-1.56.0, release notes)

...and 468 more in the full analysis

sass 1.89.21.93.2

We found 3 breaking changes and 6 deprecations.

  • Breaking change: Emit declarations, childless at-rules, and comments in the order they appear in the source even when they're interleaved with nested rules. This obsoletes the mixed-decls deprecation. (v1.91.0-1.92.0, release notes)
  • Breaking change: The function name type() is now fully reserved for the plain CSS function. This means that @​function definitions with the name type will produce errors, while function calls will be parsed as special function strings. (v1.91.0-1.92.0, release notes)
  • Potentially breaking change: meta.inspect() (as well as other systems that use it such as @​debug and certain error messages) now emits numbers with as high precision as is available instead of rounding to the nearest 1e⁻¹⁰ as we do when serializing to CSS.... (v1.90.0-1.91.0, changelog)
View more changes for sass
  • Fix a performance regression that was introduced in 1.92.0. (v1.91.0-1.92.0, changelog)
  • Fix a bug where variable definitions from one imported, forwarded module would not be passed as implicit configuration to a later imported, forwarded module. (v1.92.0-1.92.1, changelog)
  • Fix a crash when a style rule contains a nested @​import, and the loaded file @​uses a user-defined module as well as @​includes a top-level mixin which emits top-level declarations. (v1.92.1-1.93.0, changelog)
  • Fix an error in the release process for @​sass/types. (v1.93.0-1.93.1, changelog)
  • Fix another error in the release process for @​sass/types. (v1.93.1-1.93.2, changelog)
  • Passing a rest argument ($arg...) before a positional or named argument when calling a function or mixin is now deprecated. This was always outside the specified syntax, but it was historically treated the same as passing the rest argument at the end of the argument list whether or not that... (v1.90.0-1.91.0, changelog)
  • Release a @​sass/types package which contains the type annotations used by both the sass and sass-embedded package without any additional code or dependencies. (v1.92.1-1.93.0, changelog)
  • Allow a @​forwarded module to be loaded with a configuration when that module has already been loaded with a different configuration and the module doesn't define any variables that would have been configured anyway. (v1.89.2-1.90.0, changelog)
  • No user-visible changes. (v1.93.0-1.93.1, changelog)
  • No user-visible changes. (v1.93.1-1.93.2, changelog)

...and 56 more in the full analysis

typescript 5.8.35.9.3

We found 2 breaking changes.

  • Update dependencies, including major versions (v5.9.2, commit)
  • chalk removed (no longer a dependency) (v5.9.2, package source)
View more changes for typescript

...and 134 more in the full analysis


You have no credits left. Reach out to autoupdates@fossa.com and we'll top you up.

Credits are consumed when dependency updates are reviewed or proposed.

Re-run with @fossabot analyze.

Mute out-of-credit notifications until next month (expires 2026-04-01T00:00:00.000Z)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants