Skip to content

build(deps): bump the minor-and-patch group with 8 updates - #191

Merged
uhyo merged 1 commit into
masterfrom
dependabot/npm_and_yarn/minor-and-patch-eaae2e33b3
Oct 4, 2026
Merged

uhyo merged 1 commit into
masterfrom
dependabot/npm_and_yarn/minor-and-patch-eaae2e33b3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 8 updates:

Package From To
oxlint 1.85.0 1.86.0
turbo 2.11.3 2.11.6
@shikijs/rehype 4.4.3 4.5.0
shiki 4.4.3 4.5.0
wrangler 4.137.0 4.145.0
vitest 5.0.1 5.0.3
@types/node 26.6.2 26.6.3
vite 8.3.0 8.3.1

Updates oxlint from 1.85.0 to 1.86.0

Release notes

Sourced from oxlint's releases.

oxlint v1.86.0

🚀 Features

  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)

🐛 Bug Fixes

  • 8306aa4 linter/typescript/no-unnecessary-parameter-property-assignment: Account for parameter property reassignment (#26955) (camc314)
  • 42dfbb5 linter/eslint/one-var: Keep declare when splitting declarations (#27081) (Cheolhee Lee)
  • 2ba7e33 linter/eslint/require-await: Count await using as an await (#27080) (Cheolhee Lee)
  • 611e4ed linter/plugins: Include executing selectors in JS plugin rule timings (#27111) (overlookmotel)
  • 2cac66f react-compiler: Handle recursive function expressions (#26796) (Brennan Butler)
  • e996e6c react-compiler: Treat zero-argument new Date as impure (#26894) (Boshen)
  • 571cfa3 oxlint: Skip type-aware lint rules in type-check-only mode (#27076) (camc314)
  • d0b2462 oxlint: Skip undefined children in CFG walker (#27075) (camc314)
  • 5186328 parser: Handle HTML comment values (#22933) (Boshen)
  • 0b630e8 linter/typescript/unified-signatures: Align rule with upstream (#26956) (camc314)
  • ebb22f1 linter/node/no-exports-assign: Change category from style to suspicious (#26555) (Bartok)
  • cce28a0 linter/import/no-duplicates: Distinguish import attributes (#26936) (camc314)
  • feb733b linter/unicorn/prefer-spread: Stop checking string split calls (#26935) (camc314)
  • 929e154 linter/eslint/no-unused-vars: Honor ignore patterns inside array rest bindings (#26923) (camc314)
  • 5bdb9b8 linter/eslint/no-unused-vars: Recognize consumed update expressions (#26782) (camc314)
  • 5c05bef linter/eslint/prefer-const: Ignore embedded assignments (#26920) (camc314)

⚡ Performance

  • ded4c29 linter/eslint/no-unused-vars: Skip sequence checks when absent (#26921) (camc314)
Changelog

Sourced from oxlint's changelog.

[1.86.0] - 2026-09-28

🚀 Features

  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)

[1.82.0] - 2026-09-07

🚀 Features

  • 6a0e19c linter/eslint/no-unmodified-loop-condition: Support checkConditionalExpressions option (#26249) (camc314)

[1.81.0] - 2026-08-31

📚 Documentation

  • d5be037 linter/typescript/switch-exhaustiveness-check: Clarify default case comment pattern (#26100) (camc314)

[1.79.0] - 2026-08-18

💥 BREAKING CHANGES

  • 8c4552d linter: [BREAKING] Split react/react-compiler into per-category rules (#25500) (Boshen)

🐛 Bug Fixes

  • 228e8e0 linter: Resolve inactive React compiler rules (#25830) (Boshen)
  • aa49d86 linter: Allow spread rule options in config types (#25675) (ch3rry)
  • 36f8451 linter/eslint/no-eval: Align indirect default with ESLint (#25656) (camc314)
  • beb724d linter/eslint/no-unused-vars: Report bare underscore parameters (#25663) (camc314)
  • 4004c10 linter/eslint/no-irregular-whitespace: Check comments by default (#25660) (camc314)
  • 285820e linter/no-large-snapshots: Precompile and document allowed snapshot matchers (#25611) (Mikhail Baev)
  • 4df5835 linter: Allow capitalized built-in calls (#25516) (Boshen)

[1.78.0] - 2026-08-10

🚀 Features

  • ccb8fe8 linter/jsdoc: Implement no-blank-blocks rule (#25207) (Mikhail Baev)
  • d4a897c linter/eslint: Implement one-var rule (#24470) (Cole Ellison)
  • 5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match eslint (#24571) (Cole Ellison)

🐛 Bug Fixes

  • 9573937 linter/typescript: Validate ban-ts-comment description_format (#25320) (Mikhail Baev)

[1.77.0] - 2026-08-03

🐛 Bug Fixes

... (truncated)

Commits
  • 2ae2939 release(apps): oxlint v1.86.0 && oxfmt v0.71.0 (#27132)
  • 9d80eed feat(linter/react/only-export-components): support allowCompoundComponents ...
  • e05b155 feat(linter): add typescript/no-generated-empty-object-type (#26958)
  • 88a0096 chore(oxlint): require tsgolint 7.0.2003 (#27021)
  • See full diff in compare view

Updates turbo from 2.11.3 to 2.11.6

Release notes

Sourced from turbo's releases.

Turborepo v2.11.6

What's Changed

Changelog

New Contributors

Full Changelog: vercel/turborepo@v2.11.5...v2.11.6

Turborepo v2.11.5

What's Changed

Changelog

... (truncated)

Commits
  • fcd1213 publish 2.11.6 to registry
  • 90718d1 fix: Infer single-package mode for query commands (#14351)
  • a409ce5 fix: Complete task query metadata for non-script entrypoints (#14350)
  • bc7c148 feat: Filter tasks by tags in the CLI (#14345)
  • 49d1607 feat: Filter query tasks and packages by tags (#14344)
  • fba5351 feat: Expose task and package tags in query (#14343)
  • b4570e0 test: Deflake untracked scan-scope assertions (#14348)
  • fa107aa docs: Point security.txt to Vercel HackerOne program (#14346)
  • 0deb0e7 fix: Upgrade brace-expansion to latest compatible releases (#14347)
  • d44edbe feat: Add task tags with configuration inheritance (#14342)
  • Additional commits viewable in compare view

Updates @shikijs/rehype from 4.4.3 to 4.5.0

Release notes

Sourced from @​shikijs/rehype's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates shiki from 4.4.3 to 4.5.0

Release notes

Sourced from shiki's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates wrangler from 4.137.0 to 4.145.0

Release notes

Sourced from wrangler's releases.

wrangler@4.145.0

Minor Changes

  • #15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #15943 8468487 Thanks @​sejoker! - Graduate SQL, Catalog, and Pipelines under wrangler basin out of beta to stable

    Basin SQL is now available under wrangler basin sql, Basin Catalog operations are available under wrangler basin catalog, and Pipelines operations are available under wrangler basin pipelines. These commands are now stable, while the previous wrangler r2 sql, wrangler r2 bucket catalog, and wrangler pipelines command paths remain available as hidden compatibility aliases.

    The Basin SQL authentication environment variable is now WRANGLER_BASIN_SQL_AUTH_TOKEN. Update any existing WRANGLER_R2_SQL_AUTH_TOKEN configuration to use the new name. The fallback to CLOUDFLARE_API_TOKEN remains available.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 stream management commands

    Use wrangler k2 streams create order_events, wrangler k2 streams list, wrangler k2 streams get <stream-id>, and wrangler k2 streams delete <stream-id> to manage K2 streams. Creation enables Worker bindings but not HTTP ingestion by default, matching the dashboard. Pass --http-enabled to enable authenticated HTTP ingestion and print its endpoint. Creation prints the stream ID and a binding configuration with a YOUR_BINDING_NAME placeholder for the Worker's variable name, but does not edit the configuration file automatically.

    All four commands support --json. Deletion requires confirmation, or --force/-y to skip it; use --force --json for JSON deletion output. Creation also accepts retention, HTTP authentication, Worker-input, and CORS options; listing supports pagination and a name filter. Default Wrangler logins now request k2.read and k2.write; existing OAuth users should run wrangler login again, or use a custom API token granting K2 Config Write. The account must be enabled for K2.

Patch Changes

  • #15908 ddaa558 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260926.1 ^5.20260930.2
    workerd 1.20260926.1 1.20260930.2
  • Updated dependencies [b9f1cdc, ddaa558, a0712e5]:

... (truncated)

Commits

Updates vitest from 5.0.1 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Updates @types/node from 26.6.2 to 26.6.3

Commits

Updates vite from 8.3.0 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

Bumps the minor-and-patch group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.85.0` | `1.86.0` |
| [turbo](https://github.com/vercel/turborepo) | `2.11.3` | `2.11.6` |
| [@shikijs/rehype](https://github.com/shikijs/shiki/tree/HEAD/packages/rehype) | `4.4.3` | `4.5.0` |
| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.4.3` | `4.5.0` |
| [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `4.137.0` | `4.145.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.2` | `26.6.3` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.1` |


Updates `oxlint` from 1.85.0 to 1.86.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint)

Updates `turbo` from 2.11.3 to 2.11.6
- [Release notes](https://github.com/vercel/turborepo/releases)
- [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
- [Commits](vercel/turborepo@v2.11.3...v2.11.6)

Updates `@shikijs/rehype` from 4.4.3 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/rehype)

Updates `shiki` from 4.4.3 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/shiki)

Updates `wrangler` from 4.137.0 to 4.145.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.145.0/packages/wrangler)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `@types/node` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `vite` from 8.3.0 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

---
updated-dependencies:
- dependency-name: oxlint
  dependency-version: 1.86.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: turbo
  dependency-version: 2.11.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@shikijs/rehype"
  dependency-version: 4.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: shiki
  dependency-version: 4.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: wrangler
  dependency-version: 4.145.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@uhyo
uhyo merged commit 57c84f9 into master Oct 4, 2026
2 checks passed
@uhyo
uhyo deleted the dependabot/npm_and_yarn/minor-and-patch-eaae2e33b3 branch October 4, 2026 08:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant