Skip to content

fix(deps): update all non-major dependencies#491

Merged
ghiscoding merged 1 commit intoghiscoding:mainfrom
renovate-bot:renovate/all-minor-patch
Apr 25, 2026
Merged

fix(deps): update all non-major dependencies#491
ghiscoding merged 1 commit intoghiscoding:mainfrom
renovate-bot:renovate/all-minor-patch

Conversation

@renovate-bot
Copy link
Copy Markdown
Contributor

@renovate-bot renovate-bot commented Apr 19, 2026

This PR contains the following updates:

Package Change Age Confidence
@lerna-lite/cli (source) ^5.0.0^5.1.0 age confidence
@lerna-lite/publish (source) ^5.0.0^5.1.0 age confidence
@lerna-lite/watch (source) ^5.0.0^5.1.0 age confidence
cssnano ^7.1.5^7.1.7 age confidence
dompurify ^3.4.0^3.4.1 age confidence
typescript (source) ^6.0.2^6.0.3 age confidence
vite (source) ^8.0.8^8.0.10 age confidence

Release Notes

lerna-lite/lerna-lite (@​lerna-lite/cli)

v5.1.0

Compare Source

Features
lerna-lite/lerna-lite (@​lerna-lite/publish)

v5.1.0

Compare Source

Note: Version bump only for package @​lerna-lite/publish

lerna-lite/lerna-lite (@​lerna-lite/watch)

v5.1.0

Compare Source

Features
Bug Fixes
cssnano/cssnano (cssnano)

v7.1.7: v.7.1.7

Compare Source

This release is idnetical to the previous one, but is being published to ensure that the latest versions of postcss-normalize-repeat-style and postcss-normalize-positions are uploaded to the npm registry.

v7.1.6: v7.1.6

Compare Source

New feature

Bug fixes

  • fix: update colordx and autoprefixer
  • fix: update postcss peer dependency by @​ludofischer in #​1779 Solves possible security issue

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@7.1.5...cssnano@7.1.6

cure53/DOMPurify (dompurify)

v3.4.1: DOMPurify 3.4.1

Compare Source

  • Fixed an issue with on-handler stripping for HTML-spec-reserved custom element names (font-face, color-profile, missing-glyph, font-face-src, font-face-uri, font-face-format, font-face-name) under permissive CUSTOM_ELEMENT_HANDLING
  • Fixed a case-sensitivity gap in the annotation-xml check that allowed mixed-case variants to bypass the basic-custom-element exclusion in XHTML mode
  • Fixed SANITIZE_NAMED_PROPS repeatedly prefixing already-prefixed id and name values on subsequent sanitization
  • Fixed the IN_PLACE root-node check to explicitly guard against non-string nodeName (DOM-clobbering robustness)
  • Removed a duplicate slot entry from the default HTML attribute allow-list
  • Strengthened the fast-check fuzz harness with explicit XSS invariants, an expanded seed-payload corpus, an additional idempotence property for SANITIZE_NAMED_PROPS, and a negative-control assertion ensuring the invariants actually fire
  • Added regression and pinning tests covering the above fixes and two accepted-behavior contracts (SAFE_FOR_TEMPLATES greedy scrub, hook-added attribute handling)
  • Extended CodeQL analysis to run on 3.x and 2.x maintenance branches
microsoft/TypeScript (typescript)

v6.0.3

Compare Source

vitejs/vite (vite)

v8.0.10

Compare Source

Features
Bug Fixes
  • hmrClient.logger.debug and hmrClient.logger.error looked different from other HMR logs (#​22147) (a4d828f)
  • css: show filename in CSS minification warnings for .css?inline (#​22292) (83f0a78)
  • optimizer: allow user transform.target to override default in optimizeDeps (#​22273) (5c7cec6)
  • remove format sniffing module resolution from JS resolver (#​22297) (b8a21cc)
Code Refactoring

v8.0.9

Compare Source

Features
Bug Fixes
Documentation
Miscellaneous Chores

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every 3 months"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 19, 2026

Playwright E2E Test Results

92 tests  ±0   92 ✅ ±0   2m 13s ⏱️ -6s
75 suites ±0    0 💤 ±0 
 1 files   ±0    0 ❌ ±0 

Results for commit 85c7b38. ± Comparison against base commit 1ae01e2.

♻️ This comment has been updated with latest results.

@renovate-bot renovate-bot changed the title chore(deps): update dependency typescript to ^6.0.3 chore(deps): update all non-major dependencies Apr 22, 2026
@renovate-bot renovate-bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 26b8391 to e93bce7 Compare April 23, 2026 18:35
@renovate-bot renovate-bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies Apr 23, 2026
@renovate-bot renovate-bot force-pushed the renovate/all-minor-patch branch from e93bce7 to 85c7b38 Compare April 25, 2026 06:01
@ghiscoding ghiscoding merged commit a7b83ac into ghiscoding:main Apr 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants