Skip to content

ci(deps): update all non-major dependencies#2010

Open
renovate[bot] wants to merge 1 commit into
developfrom
renovate/all-minor-patch
Open

ci(deps): update all non-major dependencies#2010
renovate[bot] wants to merge 1 commit into
developfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Oct 8, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@commitlint/cli (source) 20.5.020.5.3 age confidence devDependencies patch
@commitlint/config-conventional (source) 20.5.020.5.3 age confidence devDependencies patch
@eslint/js (source) 9.39.39.39.4 age confidence devDependencies patch
@formatjs/intl (source) 4.1.74.1.11 age confidence dependencies patch 4.1.12
@formatjs/intl-locale 5.3.25.3.8 age confidence dependencies patch
@types/express-session (source) 1.18.21.19.0 age confidence pnpm.overrides minor
@types/express-session (source) 1.18.21.19.0 age confidence devDependencies minor
@types/node (source) 22.19.022.19.19 age confidence devDependencies patch
@types/react (source) 19.2.1419.2.15 age confidence pnpm.overrides patch
@types/react (source) 19.2.1419.2.15 age confidence devDependencies patch
ace-builds 1.43.61.44.0 age confidence dependencies minor
axios (source) 1.15.01.16.1 age confidence dependencies minor
baseline-browser-mapping 2.10.232.10.31 age confidence devDependencies patch 2.10.32
copy-to-clipboard 4.0.04.0.2 age confidence dependencies patch
country-flag-icons 1.6.161.6.17 age confidence dependencies patch
cypress (source) 15.13.115.15.0 age confidence devDependencies minor 15.16.0
eslint (source) 9.39.39.39.4 age confidence devDependencies patch
eslint-plugin-formatjs 6.4.56.4.10 age confidence devDependencies patch 6.4.12 (+1)
express-rate-limit 8.3.28.5.2 age confidence dependencies minor
globals 17.5.017.6.0 age confidence devDependencies minor
gravatar-url 4.0.14.0.2 age confidence dependencies patch
jiti 2.6.12.7.0 age confidence devDependencies minor
node 22.22.2-alpine3.2322.22.3-alpine3.23 age confidence container patch
node-gyp 12.2.012.3.0 age confidence dependencies minor
nodemailer (source) 8.0.58.0.7 age confidence dependencies patch 8.0.9 (+1)
pnpm (source) 10.24.010.33.4 age confidence packageManager minor 10.34.0
postcss (source) 8.5.128.5.15 age confidence devDependencies patch
prettier (source) 3.8.23.8.3 age confidence devDependencies patch
prettier-plugin-tailwindcss 0.7.20.8.0 age confidence devDependencies minor
react-animate-height 3.2.33.2.4 age confidence dependencies patch
react-aria 3.47.03.48.0 age confidence dependencies minor
semver 7.7.47.8.0 age confidence dependencies minor 7.8.1
tsc-alias (source) 1.8.161.8.17 age confidence devDependencies patch
typescript (source) 5.4.55.9.3 age confidence devDependencies minor
undici (source) 8.1.08.3.0 age confidence dependencies minor
zod (source) 4.3.64.4.3 age confidence dependencies minor

Release Notes

conventional-changelog/commitlint (@​commitlint/cli)

v20.5.3

Compare Source

Note: Version bump only for package @​commitlint/cli

v20.5.2

Compare Source

Note: Version bump only for package @​commitlint/cli

conventional-changelog/commitlint (@​commitlint/config-conventional)

v20.5.3

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

eslint/eslint (@​eslint/js)

v9.39.4

Compare Source

formatjs/formatjs (@​formatjs/intl)

v4.1.11

Compare Source

v4.1.10

Compare Source

v4.1.9

Compare Source

v4.1.8

Compare Source

ajaxorg/ace-builds (ace-builds)

v1.44.0

Compare Source

Features
Bug Fixes
  • mode type to accept both SyntaxMode and string across definitions and implementations (#​5925) (a6b1cb1)
  • row calculation for fractional coords in virtual_renderer (#​5914) (a6724b7)
1.43.6 (2026-01-23)
Bug Fixes
1.43.5 (2025-12-02)
1.43.4 (2025-10-17)
Bug Fixes
1.43.3 (2025-09-02)
Bug Fixes
1.43.2 (2025-07-15)
Features
1.43.1 (2025-07-02)
Bug Fixes
1.42.1 (2025-06-20)
Features
axios/axios (axios)

v1.16.1

Compare Source

v1.16.0

Compare Source

v1.16.0 — May 2, 2026

This release adds support for the QUERY HTTP method and a new ECONNREFUSED error constant, lands a substantial wave of HTTP, fetch, and XHR adapter bug fixes around redirects, aborts, headers, and timeouts, and welcomes 23 new contributors.

⚠️ Notable Changes

A handful of fixes in this release are either security-adjacent or change observable behaviour. Please review before upgrading:

  • Fetch adapter now enforces maxBodyLength and maxContentLength. These limits were silently ignored on the fetch adapter prior to 1.16.0 — anyone relying on them as a safety net (DoS protection, accidental large uploads) had no protection. (#​10795)
  • Proxy requests now preserve user-supplied Host headers. Previously, the proxy path could overwrite a custom Host. Virtual-host-style routing through a proxy will now behave correctly. (#​10822)
  • Basic auth credentials embedded in URLs are now URL-decoded. If you have percent-encoded credentials in a URL (e.g. https://user:p%40ss@host), the decoded value is what now goes on the wire. (#​10825)
  • parseProtocol now strictly requires a colon in the protocol separator. Strings that loosely parsed as protocols before may no longer match. (#​10729)
  • Deprecated unescape() replaced with modern UTF-8 encoding. Non-ASCII URL handling is now spec-correct; consumers depending on legacy unescape() quirks may see different output bytes. (#​7378)
  • transformRequest input typing change was reverted. The typing change introduced in #​10745 was reverted in #​10810 after follow-up review — net behavior is unchanged from 1.15.2. (#​10745, #​10810)

🚀 New Features

  • QUERY HTTP Method: Added support for the QUERY HTTP method across adapters and type definitions. (#​10802)
  • ECONNREFUSED Error Constant: Exposed ECONNREFUSED as a constant on AxiosError so callers can match connection-refused failures without comparing string literals (closes #​6485). (#​10680)
  • Encode Helper Export: Exported the internal encode helper from buildURL so userland param serializers can reuse the same encoding logic that axios uses internally. (#​6897)

🐛 Bug Fixes

  • HTTP Adapter — Redirects & Headers: Cleared stale headers when a redirect targets a no-proxy host, fixed the redirect listener chain so listeners no longer stack across hops, restored the missing requestDetails argument on beforeRedirect, preserved user-supplied Host headers when forwarding through a proxy, and properly URL-decoded basic auth credentials. (#​10794, #​10800, #​6241, #​10822, #​10825)
  • HTTP Adapter — Streams & Timeouts: Preserved the partial response object on AxiosError when a stream is aborted after headers arrive, honoured the timeout option during the connect phase when redirects are disabled, and resolved an unsettled-promise hang when an aborted request was combined with compression and maxRedirects: 0. (#​10708, #​10819, #​7149)
  • Fetch Adapter: Enforced maxBodyLength / maxContentLength in the fetch adapter, set the User-Agent header to match the HTTP adapter, preserved the original abort reason instead of replacing it with a generic error, and deferred global access so importing the module no longer throws a TypeError in restricted environments. (#​10795, #​10772, #​10806, #​7260)
  • XHR Adapter: Unsubscribed the cancelToken and AbortSignal listeners on the error, timeout, and abort code paths to prevent leaked subscriptions. (#​10787)
  • Error Handling: Attached the parsed response to AxiosError when JSON.parse fails inside dispatchRequest, prevented settle from emitting undefined error codes, and tightened the parseProtocol regex to require a colon in the protocol separator. (#​10724, #​7276, #​10729)
  • Types & Exports: Aligned the CommonJS CancelToken typings with the ESM build, fixed a compiler error caused by RawAxiosHeaders, and re-exported create from the package index. (#​7414, #​6389, #​6460)
  • UTF-8 Encoding: Replaced the deprecated unescape() call with a modern UTF-8 encoding implementation. (#​7378)
  • Misc Cleanup: Resolved a batch of small inconsistencies and gadget-level issues across the codebase. (#​10833)

🔧 Maintenance & Chores

  • Refactor — ES6 Modernisation: Modernised the utils module and XHR adapter to use ES6 features, and tidied the multipart boundary error message. (#​10588, #​7419)
  • Tests: Hardened the HTTP test server lifecycle to fix flaky FormData EPIPE failures, fixed Win32 platform support for the pipe tests, and corrected an incorrect test assumption. (#​10820, #​10791, #​10796)
  • Docs: Documented paramsSerializer.encode for strict RFC 3986 query encoding, updated the parseReviver TypeScript definitions and configuration docs for ES2023, added timeout guidance to the README's first async example, and expanded notes around the recent type changes. (#​10821, #​10782, #​10759, #​10804)
  • Reverted: Reverted the transformRequest input typing change from #​10745 after follow-up review. (#​10745, #​10810)
  • Dependencies: Bumped actions/setup-node, the github-actions group, and postcss (in /docs) to their latest versions. (#​10785, #​10813, #​10814)
  • Release: Updated changelog and packages, and prepared the 1.16.0 release. (#​10790, #​10834)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog

v1.15.2

Compare Source

This release delivers prototype-pollution hardening for the Node HTTP adapter, adds an opt-in allowedSocketPaths allowlist to mitigate SSRF via Unix domain sockets, fixes a keep-alive socket memory leak, and ships supply-chain hardening across CI and security docs.

🔒 Security Fixes

  • Prototype Pollution Hardening (HTTP Adapter): Hardened the Node HTTP adapter and resolveConfig/mergeConfig/validator paths to read only own properties and use null-prototype config objects, preventing polluted auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser from influencing requests. (#​10779)
  • SSRF via socketPath: Rejects non-string socketPath values and adds an opt-in allowedSocketPaths config option to restrict permitted Unix domain socket paths, returning AxiosError ERR_BAD_OPTION_VALUE on mismatch. (#​10777)
  • Supply-chain Hardening: Added .npmrc with ignore-scripts=true, lockfile lint CI, non-blocking reproducible build diff, scoped CODEOWNERS, expanded SECURITY.md/THREATMODEL.md with provenance verification (npm audit signatures), 60-day resolution policy, and maintainer incident-response runbook. (#​10776)

🚀 New Features

  • allowedSocketPaths Config Option: New request config option (and TypeScript types) to allowlist Unix domain socket paths used by the Node http adapter; backwards compatible when unset. (#​10777)

🐛 Bug Fixes

  • Keep-alive Socket Memory Leak: Installs a single per-socket error listener tracking the active request via kAxiosSocketListener/kAxiosCurrentReq, eliminating per-request listener accumulation, MaxListenersExceededWarning, and linear heap growth under concurrent or long-running keep-alive workloads (fixes #​10780). (#​10788)

🔧 Maintenance & Chores

  • Changelog: Updated CHANGELOG.md with v1.15.1 release notes. (#​10781)

Full Changelog

v1.15.1

Compare Source

web-platform-dx/baseline-browser-mapping (baseline-browser-mapping)

v2.10.31

Compare Source

v2.10.30

Compare Source

v2.10.29

Compare Source

v2.10.28

Compare Source

v2.10.27

Compare Source

v2.10.25

Compare Source

v2.10.24

Compare Source

sudodoki/copy-to-clipboard (copy-to-clipboard)

v4.0.2

Compare Source

compare changes

🩹 Fixes
  • Make sure execCommand works in fullscreen (#​158)
🏡 Chore
  • Bump axios from 1.14.0 to 1.15.2 (#​155)
  • Bump follow-redirects from 1.15.11 to 1.16.0 (#​157)
  • Bump basic-ftp from 5.2.0 to 5.3.0 (#​156)
❤️ Contributors

v4.0.1

Compare Source

compare changes

🏡 Chore
  • Fix copy in modal for execCommand fallback (#​151)
  • Add changelog (#​153)
✅ Tests
  • Add e2e scenario for modal tests (#​152)
❤️ Contributors
catamphetamine/country-flag-icons (country-flag-icons)

v1.6.17

Compare Source

cypress-io/cypress (cypress)

v15.15.0

Compare Source

Changelog: https://docs.cypress.io/app/references/changelog#15-15-0

v15.14.2

Compare Source

Changelog: https://docs.cypress.io/app/references/changelog#15-14-2

v15.14.1

Compare Source

Changelog: https://docs.cypress.io/app/references/changelog#15-14-1

v15.14.0

Compare Source

Changelog: https://docs.cypress.io/app/references/changelog#15-14-0

eslint/eslint (eslint)

v9.39.4

Compare Source

Bug Fixes

Documentation

Chores

express-rate-limit/express-rate-limit (express-rate-limit)

v8.5.2

Compare Source

You can view the changelog here.

v8.5.1

Compare Source

You can view the changelog here.

v8.5.0

Compare Source

You can view the changelog here.

v8.4.1

Compare Source

You can view the changelog here.

v8.4.0

Compare Source

sindresorhus/globals (globals)

v17.6.0

Compare Source

sindresorhus/gravatar-url (gravatar-url)

v4.0.2

Compare Source

  • Fix support for undefined Gravatar URL options d244597
  • Fix type for default option (#​11) 23859ff

unjs/jiti (jiti)

v2.7.0

Compare Source

compare changes

🚀 Enhancements
  • Add explicit resource management (using/await using) support (#​422)
  • Support opt-in tsconfigPaths (#​427)
  • Support virtual modules option (#​428)
  • Add jiti/static export (#​430)
🔥 Performance
  • interopDefault: Add caching to reduce proxy overhead by ~2x (#​421)
🩹 Fixes
  • require: Passthrough resolve options (#​412)
  • ci: Skip --coverage flag for node 18 (fe264b4)
  • require: Fallback to transpilation when tryNative fails (#​413)
  • Fallback for ENAMETOOLONG when evaluating esm (#​429)
📦 Build
🏡 Chore
✅ Tests
🤖 CI
  • Update node test matrix (0abda72)
❤️ Contributors
nodejs/node (node)

v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @​marco-ippolito

Compare Source

Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner October 8, 2025 03:13
@renovate renovate Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2025
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 5204b95 to dbe1cf5 Compare October 16, 2025 18:43
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from db2c4d0 to 577ea25 Compare October 19, 2025 20:37
@github-actions github-actions Bot added the merge conflict Cannot merge due to merge conflicts label Oct 19, 2025
@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 577ea25 to 60b9a87 Compare October 19, 2025 20:45
@github-actions github-actions Bot removed the merge conflict Cannot merge due to merge conflicts label Oct 19, 2025
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 042eeba to 7e64349 Compare October 28, 2025 14:32
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from f693b7b to 72ca8ec Compare November 4, 2025 20:10
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from e42333a to e4e01ca Compare November 11, 2025 23:16
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from dd32450 to 2c61a49 Compare December 22, 2025 14:07
@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

4 similar comments
@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@cypress
Copy link
Copy Markdown

cypress Bot commented Jan 27, 2026

seerr    Run #3409

Run Properties:  status check passed Passed #3409  •  git commit 598505f149: chore(deps): update all non-major dependencies
Project seerr
Branch Review renovate/all-minor-patch
Run status status check passed Passed #3409
Run duration 02m 12s
Commit git commit 598505f149: chore(deps): update all non-major dependencies
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 32
View all changes introduced in this branch ↗︎

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

20 similar comments
@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Feb 9, 2026

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 5, 2026

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 8, 2026

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

@github-actions
Copy link
Copy Markdown

This pull request has merge conflicts. Please resolve the conflicts so the PR can be successfully reviewed and merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants