Skip to content

build(deps): bump the npm group with 13 updates - #20

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-76cd295d21
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-76cd295d21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown

Bumps the npm group with 13 updates:

Package From To
@nuxt/content 3.15.2 3.16.1
shiki 4.4.2 4.5.0
vue 3.5.41 3.5.43
vue-router 5.2.0 5.3.1
@nuxt/test-utils 4.1.0 4.3.2
@vitejs/plugin-vue 6.0.8 6.0.9
@vue/test-utils 2.4.11 2.5.1
happy-dom 20.11.2 20.14.5
playwright-core 1.62.1 1.63.0
sanitize-html 2.17.6 2.18.0
@types/sanitize-html 2.16.1 2.16.2
vitest 4.1.10 5.0.3
yaml 2.9.0 2.9.1

Updates @nuxt/content from 3.15.2 to 3.16.1

Changelog

Sourced from @​nuxt/content's changelog.

3.16.1 (2026-09-21)

Features

  • add content.llms option to disable the nuxt-llms integration (#3843) (656a5ce)

Bug Fixes

  • security: avoid ReDoS in assertSafeQuery (#3851) (f8be485)

3.16.0 (2026-08-27)

Bug Fixes

  • avoid install prompt in non-interactive environments (#3833) (2d0e84b)
  • ContentRenderer: keep async component identity stable across re-resolves (#3835) (dcf86e6)
  • improve generated git cache key (#3839) (d1e353e)
  • module: keep content templates when building with _prepare (#3837) (e390c3b)
  • nuxthub: handle object form of hub.db (#3822) (8841abc)
  • query: tolerate trailing slashes in path-based lookups (#3838) (220d392)
  • runtime: use dynamic import for #content/adapter to prevent prerender failure (#3830) (400390a)
  • use UTC getters in formatDate/formatDateTime to prevent timezone drift (#3782) (9f1f89a)
Commits
  • f0a2e2c chore(release): v3.16.1
  • c2f3e70 chore: update test utils version
  • 0402758 chore: upgrade deps & lockfile (#3857)
  • f8be485 fix(security): avoid ReDoS in assertSafeQuery (#3851)
  • 656a5ce feat: add content.llms option to disable the nuxt-llms integration (#3843)
  • 850e3f0 chore(release): v3.16.0
  • be97f81 chore: upgrade @nuxtjs/mdc
  • ae50a2a chore: upgrade deps
  • 9f1f89a fix: use UTC getters in formatDate/formatDateTime to prevent timezone drift (...
  • d6dad02 chore: disable stale schedule
  • Additional commits viewable in compare view

Updates shiki from 4.4.2 to 4.5.0

Release notes

Sourced from shiki's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.4.3

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates vue from 3.5.41 to 3.5.43

Release notes

Sourced from vue's releases.

v3.5.43

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

v3.5.42

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Changelog

Sourced from vue's changelog.

3.5.43 (2026-09-17)

Bug Fixes

  • compiler-sfc: ignore comment delimiters inside strings and url() when parsing css vars (#15548) (2fde323)
  • compiler-sfc: prepend semicolon for await in switch case (#15498) (9a1df69), closes #15495
  • compiler-sfc: restore await scope when leaving nested blocks (5409708), closes #15465
  • compiler-sfc: reuse parsed parent configs across tsconfig walks (fix #15478) (#15480) (d6febaa)
  • hydration: run leave hooks for hydration placeholders (#15431) (5dda192)
  • reactivity: preserve readonly wrappers in array copy methods (#15469) (599f35b)
  • runtime-core: unmount v-once children after parent rerenders (#15435) (d720338)
  • shared: handle circular references in looseEqual (#15499) (718f782), closes #15496
  • shared: preserve comment-like text in style values (#15471) (b9456cb)
  • suspense: don't drop nested suspense patches during hydration (#15429) (76d42dc)
  • suspense: keep the boundary pending while its branch is patched (#15411) (bfcfe9e), closes #7506
  • suspense: patch a hydrating boundary's pending branch in place (#15432) (2cde6f7)
  • suspense: unmount the DOM an interrupted async component claimed (#15430) (fb9b45c)
  • types: keep optional props when a runtime prop uses a generic PropType (#15523) (243aabc), closes #9546

3.5.42 (2026-08-27)

Bug Fixes

  • hydration: handle async component unmount before lazy hydration (#15252) (6e1814a)
  • hydration: handle moving unresolved async fragment (#15263) (a72036f)
  • runtime-core: avoid caching unmounted suspense children (#15291) (b535917), closes #15288
  • runtime-core: keep .trim result when combined with .number v-model modifier (#15346) (f8d42e1)
  • runtime-core: resolve $el for dev root comment fragment (#15313) (8654f35), closes #12680
  • runtime-dom: support !important on CSS custom properties in style binding (#15348) (31da934)
  • server-renderer: reject CR in attribute names (#15266) (a2b40db)
  • shared: correctly compare Map and Set values (#15328) (ef82a26), closes #15320
  • suspense: don't treat the leaving branch as the fallback while its mount is pending (#15333) (cd19745), closes #15332
  • v-model: re-sync select when model is overridden in change handler (#15298) (6eaecc1), closes #10505
Commits
  • 5be58b4 release: v3.5.43
  • a0b61aa chore: remove and ignore generated git hooks
  • 2fde323 fix(compiler-sfc): ignore comment delimiters inside strings and url() when pa...
  • 599f35b fix(reactivity): preserve readonly wrappers in array copy methods (#15469)
  • 55a2b45 chore(deps): update pnpm to v12 (#15439)
  • 243aabc fix(types): keep optional props when a runtime prop uses a generic PropType (...
  • 718f782 fix(shared): handle circular references in looseEqual (#15499)
  • 9a1df69 fix(compiler-sfc): prepend semicolon for await in switch case (#15498)
  • d6febaa fix(compiler-sfc): reuse parsed parent configs across tsconfig walks (fix #15...
  • b9456cb fix(shared): preserve comment-like text in style values (#15471)
  • Additional commits viewable in compare view

Updates vue-router from 5.2.0 to 5.3.1

Release notes

Sourced from vue-router's releases.

v5.3.1

   🐞 Bug Fixes

  • experimental: Handle non-string params for isActive  -  by @​posva (92cfd)
    View changes on GitHub

v5.3.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits
  • 9a66989 release: vue-router@5.3.1
  • 4fa1401 ci: bump pnpm/action-setup from 6.0.9 to 6.0.10 in the actions group (#2795)
  • 92cfd6f fix(experimental): handle non-string params for isActive
  • 0e91ac8 release: vue-router@5.3.0
  • b19cce2 chore: dark mode e2e
  • 2315047 fix(router): skip scroll saving for unknown pop direction (fix #1431) (#2780)
  • d2b87d5 feat: prevent race condition dev-only error (#2789)
  • b75d5a8 docs: scroll off
  • 033f1c7 feat(scroll): skip scroll computation based on history.scrollRestoration
  • 67babd4 fix(unplugin): generate param types from override paths and stop inheritance ...
  • Additional commits viewable in compare view

Updates @nuxt/test-utils from 4.1.0 to 4.3.2

Release notes

Sourced from @​nuxt/test-utils's releases.

v4.3.2

v4.3.2 is the next patch release.

👉 Changelog

compare changes

🩹 Fixes

  • vitest-environment: keep vitest/environments import opaque to rolldown (6d1195d38)

❤️ Contributors

v4.3.1

v4.3.1 is the next patch release.

👉 Changelog

compare changes

🩹 Fixes

  • deps: allow vitest ^5 as peer dependency (#1809)

🏡 Chore

🎉 New Contributors

❤️ Contributors

v4.3.0

v4.3.0 is the next minor release.

👉 Changelog

compare changes

🚀 Enhancements

  • runtime-utils: add unmockNuxtImport helper (#1795)
  • config: support vitest 5 (#1802)

... (truncated)

Commits

Updates @vitejs/plugin-vue from 6.0.8 to 6.0.9

Release notes

Sourced from @​vitejs/plugin-vue's releases.

plugin-vue@6.0.9

Please refer to CHANGELOG.md for details.

Changelog

Sourced from @​vitejs/plugin-vue's changelog.

6.0.9 (2026-09-14)

Bug Fixes

  • deps: update all non-major dependencies (#812) (b2b559d)
  • plugin-vue: initialize compiler correctly (#475) (127b03f)
  • plugin-vue: transpile TS in templates with empty script block (#838) (189148e)

Miscellaneous Chores

Commits
  • 822c69d release: plugin-vue@6.0.9
  • 127b03f fix(plugin-vue): initialize compiler correctly (#475)
  • 3180192 chore(deps): update dependency obug to v3 (#846)
  • 189148e fix(plugin-vue): transpile TS in templates with empty script block (#838)
  • b2b559d fix(deps): update all non-major dependencies (#812)
  • See full diff in compare view

Updates @vue/test-utils from 2.4.11 to 2.5.1

Release notes

Sourced from @​vue/test-utils's releases.

v2.5.1

What's Changed

New Contributors

Full Changelog: vuejs/test-utils@v2.5.0...v2.5.1

v2.5.0

⚠️ Breaking change: Vue Test Utils no longer supports class components. See #2904.

What's Changed

New Contributors

Full Changelog: vuejs/test-utils@v2.4.11...v2.5.0

Commits

Updates happy-dom from 20.11.2 to 20.14.5

Release notes

Sourced from happy-dom's releases.

v20.14.5

👷‍♂️ Patch fixes

v20.14.4

👷‍♂️ Patch fixes

  • End comments at the first comment end tag when it overlaps a comment start tag - By @​hampustagerud in task #2407

v20.14.3

👷‍♂️ Patch fixes

v20.14.2

👷‍♂️ Patch fixes

  • Fixes regression where not all CSS variables where resolved in getComputedStyle() - By @​klaesra in task #2344

v20.14.1

👷‍♂️ Patch fixes

v20.14.0

🎨 Features

v20.13.2

👷‍♂️ Patch fixes

  • Fix problem with getComputedStyle with :host and :host-context selectors - By @​capricorn86 in task #2349

v20.13.1

👷‍♂️ Patch fixes

  • GetComputedStyle should return inherited value when it is set to inherit - By @​capricorn86 in task #2347

v20.13.0

🎨 Features

v20.12.2

👷‍♂️ Patch fixes

v20.12.1

🎨 Features

  • Adds support for kebab-case properties on CSSStyleDeclaration - By @​capricorn86 in task #2256
  • Adds support for all Chromium CSS properties to CSSStyleDeclaration - By @​capricorn86 in task #2256
    • Downloads a list from the Chromium project when compiling

👷‍♂️ Patch fixes

v20.12.0

... (truncated)

Commits
  • 0d4cdbe fix: #2409 Preserve character references in comment data (#2410)
  • 9c920a4 fix: #2407 End comments at the first comment end tag when it overlaps a com...
  • 5fb1df3 fix: #2363 Avoids cloning all properties in CSSPropertyManager.toString() (...
  • de0a1e9 fix: #2344 Resolve every var() in a value, not only the first one (#2395)
  • 64b8b94 fix: #2366 Invalidate the computed style cache for the whole subtree (#2367)
  • eac5a38 feat: #2357 Improves computed style cache (#2358)
  • 5b3559b fix: #2349 Fix problem with getComputedStyle with :host and :host-context s...
  • f33da73 fix: #2347 getComputedStyle should return inherited value when it is set to...
  • 68b9806 feat: #2345 Adds support for :host psuedo query selector (#2346)
  • 9300a9f fix: #2342 Custom elements should be upgraded when connected to DOM (#2343)
  • Additional commits viewable in compare view

Updates playwright-core from 1.62.1 to 1.63.0

Release notes

Sourced from playwright-core's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates sanitize-html from 2.17.6 to 2.18.0

Changelog

Sourced from sanitize-html's changelog.

2.18.0 (2026-09-30)

Adds

  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.

Fixes

  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for the fix.

Security

  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drop...

    Description has been truncated

Bumps the npm group with 13 updates:

| Package | From | To |
| --- | --- | --- |
| [@nuxt/content](https://github.com/nuxt/content) | `3.15.2` | `3.16.1` |
| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.4.2` | `4.5.0` |
| [vue](https://github.com/vuejs/core) | `3.5.41` | `3.5.43` |
| [vue-router](https://github.com/vuejs/router) | `5.2.0` | `5.3.1` |
| [@nuxt/test-utils](https://github.com/nuxt/test-utils) | `4.1.0` | `4.3.2` |
| [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) | `6.0.8` | `6.0.9` |
| [@vue/test-utils](https://github.com/vuejs/test-utils) | `2.4.11` | `2.5.1` |
| [happy-dom](https://github.com/capricorn86/happy-dom) | `20.11.2` | `20.14.5` |
| [playwright-core](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.6` | `2.18.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html) | `2.16.1` | `2.16.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `5.0.3` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |


Updates `@nuxt/content` from 3.15.2 to 3.16.1
- [Release notes](https://github.com/nuxt/content/releases)
- [Changelog](https://github.com/nuxt/content/blob/main/CHANGELOG.md)
- [Commits](nuxt/content@v3.15.2...v3.16.1)

Updates `shiki` from 4.4.2 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/shiki)

Updates `vue` from 3.5.41 to 3.5.43
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.5.41...v3.5.43)

Updates `vue-router` from 5.2.0 to 5.3.1
- [Release notes](https://github.com/vuejs/router/releases)
- [Commits](vuejs/router@v5.2.0...v5.3.1)

Updates `@nuxt/test-utils` from 4.1.0 to 4.3.2
- [Release notes](https://github.com/nuxt/test-utils/releases)
- [Commits](nuxt/test-utils@v4.1.0...v4.3.2)

Updates `@vitejs/plugin-vue` from 6.0.8 to 6.0.9
- [Release notes](https://github.com/vitejs/vite-plugin-vue/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-vue/commits/plugin-vue@6.0.9/packages/plugin-vue)

Updates `@vue/test-utils` from 2.4.11 to 2.5.1
- [Release notes](https://github.com/vuejs/test-utils/releases)
- [Commits](vuejs/test-utils@v2.4.11...v2.5.1)

Updates `happy-dom` from 20.11.2 to 20.14.5
- [Release notes](https://github.com/capricorn86/happy-dom/releases)
- [Commits](capricorn86/happy-dom@v20.11.2...v20.14.5)

Updates `playwright-core` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `sanitize-html` from 2.17.6 to 2.18.0
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.18.0/packages/sanitize-html)

Updates `@types/sanitize-html` from 2.16.1 to 2.16.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)

Updates `vitest` from 4.1.10 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

---
updated-dependencies:
- dependency-name: "@nuxt/content"
  dependency-version: 3.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: shiki
  dependency-version: 4.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: vue
  dependency-version: 3.5.43
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: vue-router
  dependency-version: 5.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@nuxt/test-utils"
  dependency-version: 4.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@vitejs/plugin-vue"
  dependency-version: 6.0.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vue/test-utils"
  dependency-version: 2.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: happy-dom
  dependency-version: 20.14.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: playwright-core
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: sanitize-html
  dependency-version: 2.18.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/sanitize-html"
  dependency-version: 2.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants