Skip to content

fix(deps): update all non-major dependencies - #913

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@milkdown/crepe (source) 7.22.1 → 7.22.2 age confidence dependencies patch
@milkdown/kit (source) 7.22.1 → 7.22.2 age confidence dependencies patch
@sveltejs/vite-plugin-svelte (source) 7.1.2 → 7.3.1 age confidence devDependencies minor
@tailwindcss/typography 0.5.19 → 0.5.20 age confidence devDependencies patch
@tauri-apps/plugin-clipboard-manager 2.3.2 → 2.3.3 age confidence dependencies patch
@tauri-apps/plugin-dialog 2.7.1 → 2.7.3 age confidence dependencies patch
@tauri-apps/plugin-log 2.9.0 → 2.9.2 age confidence dependencies patch
@tauri-apps/plugin-shell 2.3.5 → 2.3.6 age confidence dependencies patch
@tauri-apps/plugin-store 2.4.3 → 2.4.5 age confidence dependencies patch
@tauri-apps/plugin-updater 2.10.1 → 2.12.0 age confidence dependencies minor
@types/d3-selection (source) 3.0.11 → 3.0.12 age confidence devDependencies patch
@types/hast (source) 3.0.4 → 3.0.5 age confidence devDependencies patch
@types/node (source) 24.11.0 → 24.13.6 age confidence devDependencies minor 24.19.0
@types/sanitize-html (source) 2.16.0 → 2.16.1 age confidence devDependencies patch
@vitejs/plugin-react (source) 5.1.4 → 5.2.0 age confidence devDependencies minor
actions/checkout v6.0.3 → v6.1.0 age confidence action minor
ajv (source) 8.18.0 → 8.20.0 age confidence overrides minor
anyhow 1.0.102 → 1.0.104 age confidence dependencies patch
async-trait 0.1.89 → 0.1.92 age confidence dependencies patch
base64 0.22 → 0.23 age confidence dependencies minor
bits-ui 2.18.1 → 2.19.3 age confidence devDependencies minor
chrono 0.4.44 → 0.4.45 age confidence dependencies patch
clap 4.6.0 → 4.6.7 age confidence dependencies patch
dialoguer 0.11 → 0.12 age confidence dependencies minor
flate2 1.1.9 → 1.1.10 age confidence dependencies patch
git2 0.20 → 0.21 age confidence dependencies minor
github.com/fsnotify/fsnotify v1.9.0 → v1.10.1 age confidence require minor
github.com/modelcontextprotocol/go-sdk v1.4.1 → v1.8.0 age confidence require minor
github.com/yuin/goldmark v1.8.2 → v1.8.6 age confidence require patch
idb-keyval 6.2.6 → 6.3.0 age confidence dependencies minor
ignore (source) 0.4.25 → 0.4.33 age confidence dependencies patch
jsdom 29.0.2 → 29.1.1 age confidence devDependencies minor
libc 0.2.185 → 0.2.189 age confidence dependencies patch
log 0.4.29 → 0.4.34 age confidence dependencies patch
log 0.4.33 → 0.4.34 age confidence dependencies patch
marked (source) 18.0.5 → 18.0.14 age confidence dependencies patch
marked (source) 17.0.3 → 17.0.6 age confidence dependencies patch
mermaid 11.12.3 → 11.17.2 age confidence dependencies minor
nanoid 0.4 → 0.5 age confidence dependencies minor
nix 0.31.2 → 0.31.3 age confidence dependencies patch
opener 0.8.4 → 0.8.5 age confidence dependencies patch
pnpm (source) 10.33.0 → 10.34.5 age confidence packageManager minor
postcss (source) 8.5.16 → 8.5.28 age confidence devDependencies patch
prettier (source) 3.9.4 → 3.9.9 age confidence devDependencies patch
prettier-plugin-svelte 3.5.0 → 3.5.2 age confidence devDependencies patch
rand (source) 0.9 → 0.10 age confidence dependencies minor
reqwest 0.13.2 → 0.13.5 age confidence dependencies patch
reqwest 0.13.4 → 0.13.5 age confidence dependencies patch
resvg 0.47 → 0.48 age confidence dependencies minor
rusqlite 0.39 → 0.40 age confidence dependencies minor
rusqlite_migration (source) 2.5.0 → 2.6.0 age confidence dependencies minor
rust (source, changelog) 1.96.1 → 1.98.1 age confidence toolchain minor
rustls 0.23.43 → 0.23.45 age confidence dependencies patch
sanitize-html (source) 2.17.5 → 2.17.7 age confidence dependencies patch
serde_json 1.0.149 → 1.0.151 age confidence dependencies patch
shadcn-svelte (source) 1.3.0 → 1.7.0 age confidence devDependencies minor
svelte (source) 5.56.4 → 5.57.1 age confidence devDependencies minor
svelte-check 4.7.1 → 4.7.6 age confidence devDependencies patch
svelte-sonner 1.1.1 → 1.2.1 age confidence devDependencies minor
tailwind-merge (source) 3.6.0 → 3.7.0 age confidence devDependencies minor
tailwind-variants 3.2.2 → 3.3.1 age confidence devDependencies minor
tauri-plugin-clipboard-manager 2.3.2 → 2.3.3 age confidence dependencies patch
tauri-plugin-dialog 2.7.2 → 2.7.3 age confidence dependencies patch
tauri-plugin-log 2.9.0 → 2.9.2 age confidence dependencies patch
tauri-plugin-opener 2.5.4 → 2.5.5 age confidence dependencies patch
tauri-plugin-shell 2.3.5 → 2.3.6 age confidence dependencies patch
tauri-plugin-store 2.4.4 → 2.4.5 age confidence dependencies patch
tauri-plugin-store 2.4.2 → 2.4.5 age confidence dependencies patch
tauri-plugin-updater 2.10.1 → 2.12.0 age confidence dependencies minor
thiserror 2.0.18 → 2.0.21 age confidence dependencies patch
thiserror 2.0.20 → 2.0.21 age confidence dependencies patch
tokio (source) 1.51.1 → 1.53.1 age confidence dependencies minor
tokio (source) 1.51.1 → 1.53.1 age confidence dev-dependencies minor
tokio-rustls 0.26.4 → 0.26.5 age confidence dependencies patch
tokio-util (source) 0.7.18 → 0.7.19 age confidence dependencies patch
tower-http 0.6 → 0.7 age confidence dependencies minor
usvg 0.47 → 0.48 age confidence dependencies minor
uuid 1.23.0 → 1.26.1 age confidence dependencies minor
uuid 1.24.0 → 1.26.1 age confidence dependencies minor
vite (source) 8.1.0 → 8.3.0 age confidence devDependencies minor 8.3.1
vite (source) 7.3.1 → 7.3.6 age confidence devDependencies patch

Release Notes

Milkdown/milkdown (@​milkdown/crepe)

v7.22.2

Compare Source

Patch Changes
  • 0c2f425: Milkdown patch version release.
Milkdown/milkdown (@​milkdown/kit)

v7.22.2

Compare Source

Please refer to CHANGELOG.md for details.

sveltejs/vite-plugin-svelte (@​sveltejs/vite-plugin-svelte)

v7.3.1

Compare Source

Patch Changes
  • fix: inject the inspector into the client under Vite+ on pnpm, where the realpathed client module has no vite/ segment before dist/ (#​1373)

v7.3.0

Compare Source

Minor Changes
  • feat: pass environment to dynamicCompileOptions (#​1386)
Patch Changes
  • fix: don't log inline config when encountering unexpected options (#​1376)

v7.2.0

Compare Source

Minor Changes
  • feat(inspector): add a context menu with current component stack (#​1370)

v7.1.4

Compare Source

Patch Changes
  • fix: enforce ltr styles for inspector (#​1324)

v7.1.3

Compare Source

Patch Changes
  • fix: ensure the inspector is injected into the client correctly for Vite+ projects (#​1355)
tailwindlabs/tailwindcss-typography (@​tailwindcss/typography)

v0.5.20

Compare Source

Fixed
  • Support installing with stable versions of Tailwind CSS v4 (#​424)
tauri-apps/plugins-workspace (@​tauri-apps/plugin-clipboard-manager)

v2.3.3

Compare Source

vitejs/vite-plugin-react (@​vitejs/plugin-react)

v5.2.0

Compare Source

actions/checkout (actions/checkout)

v6.1.0

Compare Source

ajv-validator/ajv (ajv)

v8.20.0

Compare Source

What's Changed

Full Changelog: ajv-validator/ajv@v8.19.0...v8.20.0

dtolnay/anyhow (anyhow)

v1.0.104

Compare Source

  • Update syn dev-dependency to version 3

v1.0.103

Compare Source

  • Fix Stacked Borrows violation (UB) in Error::downcast_mut (#​451, #​452)
dtolnay/async-trait (async-trait)

v0.1.92

Compare Source

  • Resolve double_must_use clippy lint in generated code (#​303)

v0.1.91

Compare Source

v0.1.90

Compare Source

  • Update to syn 3
marshallpierce/rust-base64 (base64)

v0.23.1

Compare Source

  • Make the tests build again on non-SIMD architectures

v0.23.0

Compare Source

  • Added more consts for preconfigured configs and engines
  • Make DecodeError::InvalidLastSymbol more clear by including the decoded value
  • Added SIMD-accelerated engines behind the default-on simd-unsafe feature: Simd picks the best
    instruction set at runtime (AVX2 on x86_64, NEON on aarch64) and falls back to the scalar
    GeneralPurpose engine, while Avx2 and Neon target one instruction set with no runtime
    detection and work in no_std. The engines support the standard and URL-safe alphabets.
  • Update MSRV to 1.71.0
  • Add support for custom padding symbols
huntabyte/bits-ui (bits-ui)

v2.19.3

Compare Source

Patch Changes
  • Prevent delayed focus-scope autofocus from overriding focus already established in the scope or a nested scope. (#​2165)

  • fix(Dialog, AlertDialog): pass preventOverflowTextSelection to the text selection layer explicitly instead of letting it ride the rest props onto the rendered content element as a preventoverflowtextselection attribute. (#​2154)

  • fix(Floating): ignore autoUpdate callbacks that fire after the floating element's effect is destroyed to avoid derived_inert (#​2164)

  • Fix user-select: none being stranded on <body> after clicking inside forceMounted content (Popover, Tooltip, Dialog, AlertDialog, Menu, Select), which left the whole page unselectable until a reload. (#​2161)

  • refactor: the context-menu attribute names and the floating root/anchor state move to leaf modules, so DismissibleLayer no longer imports the menu module for two strings, and FloatingLayer / FloatingLayer.Anchor no longer import the floating content module (and @floating-ui/dom) to register a root and its trigger. No behaviour change. (#​2158)

  • fix(Menu): the trigger's aria-controls links to the content when the menu starts open. The content registers its id by replacing a plain field on the menu state, which a trigger rendered before the content had already read as empty and never re-read; the registration is now reactive. (#​2159)

  • fix(Combobox): open the trigger on a touch tap instead of on touch down, so a finger that lands on it while scrolling no longer opens the list. Takes the Select trigger's touch timing. (#​2156)

  • perf: avoid O(n) work per rendered item on hot paths (#​2110)

    • Select/Combobox: item props now derive from per-item booleans, so moving the highlight or changing the value only rebuilds props (and re-diffs attributes) for the items that actually changed instead of every mounted item
    • Select/Combobox (multiple): selection lookups use a set instead of scanning the value array once per item
    • Calendar/RangeCalendar: data-today resolves the local timezone once per calendar rather than once per cell
    • Menu family: the document-level pointermove listener is only attached while keyboard mode is active
    • ScrollArea, Slider, NavigationMenu: internal resize observation shares a single ResizeObserver across all observed elements
  • fix(TimeField): keep the day period when typing the hour and then editing another segment in 12-hour mode (#​2148)

  • Fix user-select: none being left on <body> when something else on the page calls preventDefault() on a pointerup, which made the whole page unselectable. The text-selection layer's release is internal cleanup and no longer skipped when the event's default action has been cancelled. (#​2163)

  • fix(Collapsible): invalidate deferred measurements when content is replaced or destroyed (#​2149)

  • Fix outside clicks being lost while dismissible content such as DropdownMenu is opening. (#​2143)

v2.19.2

Compare Source

Patch Changes
  • fix: render the id attribute on Popper-based content elements (Tooltip, Popover, Select, Combobox, DropdownMenu, ContextMenu, Menubar, LinkPreview) so aria-describedby on triggers resolves correctly (#​2094)

  • fix: restore body styles on the captured document when delayed scroll-lock cleanup runs after the global document is torn down or replaced (#​2133)

  • fix: respect an explicit Tabs.Content tabindex while preserving the default panel tab stop (#​2132)

v2.19.1

Compare Source

Patch Changes
  • fix(Avatar): detach image handlers on destroy and actually apply the load cleanup - #​2050 (#​2128)

  • fix(Menu): Menu.GroupHeading no longer sets role="group", Menu.Separator now sets role="separator" (#​2091)

  • fix(DismissibleLayer): guard the deferred focus handler against teardown - #​2080 (#​2126)

  • fix(DateField): apply date segments in year/month/day order so a valid day isn't clamped by the placeholder's month in day-first locales (#​2123)

  • fix(Select): keep the user's scroll position when the scroll down button remounts. The button unmounts at the bottom of the list and remounts as soon as the viewport leaves it, and its mount effect realigned the viewport onto the highlighted item, so a small scroll up from the bottom jumped back to the highlighted item. (#​2109)

  • fix(DismissibleLayer): outside clicks shortly after a layer opens no longer fail to dismiss it (#​2111)

    DismissibleLayerState reset its per-interaction state through a 20ms debounce. Because the
    layer's watch runs its cleanup once on every open, each layer scheduled a reset 20ms into its
    own lifetime. An outside pointerdown landing 10-20ms after that cleanup had its
    "responsible layer" flag cleared by the stale reset before the debounced interact-outside
    handler ran, so the handler bailed and the layer stayed open. The reset is now synchronous.

  • fix(ScrollArea): prevent resize work from reading destroyed state after unmount (#​2122)

  • fix(Combobox): highlight the first matching item after custom filtering updates the rendered items. (#​2129)

  • fix(Accordion): cancel deferred content work on destroy to avoid derived_inert (#​2127)

v2.19.0

Compare Source

Minor Changes
  • feat(Checkbox): pass form to the hidden input (#​2089)
Patch Changes
  • fix(DateField): keep focus on the year while correcting its first digit (#​2100)

  • fix(Tooltip): close Tooltip.Trigger on pointerdown for any pointer button so right/middle click dismiss the tooltip and cancel a pending delayed open (#​2101)

  • fix(RadioGroup): don't select item on pointer-driven focus- #​2098 (#​2098)

v2.18.2

Compare Source

Patch Changes
  • fix(DismissibleLayer): cancel pending afterSleep timer on destroy to prevent derived_inert and stale document listeners (#​2080) (#​2087)

  • fix(TextSelectionLayer): don't read the ref box in #pointerdown before the enabled check, which emitted derived_inert on every document pointerdown when a leaked listener outlived its component (#​2107)

  • fix(AlertDialog): pass disabled through to button in AlertDialog.Cancel (#​2068)

chronotope/chrono (chrono)

v0.4.45: 0.4.45

Compare Source

What's Changed

clap-rs/clap (clap)

v4.6.7

Compare Source

v4.6.6

Compare Source

Features
  • Add Command::get_overridden_usage

v4.6.5

Compare Source

v4.6.4

Compare Source

Internal
  • Update to syn v3

v4.6.3

Compare Source

Fixes
  • (derive) Allow "literal".function() as attribute values

v4.6.2

Compare Source

Fixes
  • (help) Say alias when there is only one

v4.6.1

Compare Source

Fixes
  • (derive) Ensure rebuilds happen when an read env variable is changed
console-rs/dialoguer (dialoguer)

v0.12.0: 0.12.0

Compare Source

What's Changed

rust-lang/flate2-rs (flate2)

v1.1.10

Compare Source

What's Changed

New Contributors

Full Changelog: rust-lang/flate2-rs@1.1.9...1.1.10

rust-lang/git2-rs (git2)

v0.21.0

Compare Source

0.20.4...main

Added
  • Added experimental SHA256 repository support behind the new unstable-sha256 Cargo feature,
    along with *_ext API variants that accept an ObjectFormat.
    #​1206
  • Added opts::set_cache_max_size() and opts::get_cached_memory().
    #​1188
  • Added Repository::object_format() and a new ObjectFormat enum.
    #​1204
  • Added Repository::set_config().
    #​1208
  • Added merge_file() along with MergeFileInput.
    #​1210
  • Added Repository::refdb_compress() for packing loose refs.
    #​1221
  • Added public Refdb type, along with Repository::refdb() and Repository::set_refdb(). Repository::refdb_compress() now delegates to Refdb::compress().
    #​1228
  • Adde

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested review from baxen, matt2e and wesbillman as code owners August 10, 2026 01:50

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8c4d39ca7e

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pnpm-lock.yaml Outdated
Comment on lines +26 to +27
specifier: ^17.0.1
version: 17.0.3
version: 18.0.9

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate the pnpm lockfile

This importer now records marked as 18.0.9 even though apps/differ/package.json still declares ^17.0.1, so the lockfile is not consistent with the workspace manifests; there are similar mismatches later, such as apps/staged resolving prettier-plugin-svelte 3.5.2 for ^4.1.1. The workflows run pnpm install --frozen-lockfile (for example .github/workflows/differ-ci.yml:73), and the pnpm install docs state that in CI, installation fails when a present lockfile needs an update and that workspace installs cover all projects (https://pnpm.io/cli/install), so these CI jobs will stop before tests/builds run.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 16 times, most recently from 7213ece to b94370a Compare August 17, 2026 05:14
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from 0825d9f to 16098e6 Compare August 22, 2026 22:55
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from ff3d66b to 9ba89a8 Compare August 30, 2026 23:46
@renovate

renovate Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: apps/penpal/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=48 hours

Details:

Package Change
github.com/google/jsonschema-go v0.4.2 -> v0.4.3
golang.org/x/oauth2 v0.34.0 -> v0.35.0

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 19 times, most recently from 41143ca to bb07d4c Compare September 5, 2026 16:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants