chore(deps): update all non-major dependencies #164
Closed
+75 −194
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.1.84->^0.2.4^0.1.18->^0.2.1^1.2.23->^1.3.3v5.0.0->v5.0.1^0.9.7->^0.9.12^0.2.19->^0.3.1^0.21.12->^0.21.17^0.15.0->^0.15.6^1.3.1->^1.3.32.35.5->2.36.0v1.1.0->v1.2.7^7.1.7->^7.2.6^7.1.7->^7.2.6Release Notes
stacksjs/bumpx (@stacksjs/bumpx)
v0.2.4Compare Source
No significant changes
View changes on GitHub
v0.2.3Compare Source
🚀 Features
View changes on GitHub
v0.2.2Compare Source
No significant changes
View changes on GitHub
v0.2.1Compare Source
No significant changes
View changes on GitHub
v0.2.0Compare Source
No significant changes
View changes on GitHub
v0.1.86Compare Source
No significant changes
View changes on GitHub
v0.1.85Compare Source
🐞 Bug Fixes
View changes on GitHub
stacksjs/logsmith (@stacksjs/logsmith)
v0.2.1Compare Source
No significant changes
View changes on GitHub
v0.2.0Compare Source
No significant changes
View changes on GitHub
actions/checkout (actions/checkout)
v5.0.1Compare Source
What's Changed
Full Changelog: actions/checkout@v5...v5.0.1
stacksjs/buddy-bot (buddy-bot)
v0.9.12Compare Source
v0.9.11Compare Source
Compare changes
🚀 Features
🧹 Chores
📄 Miscellaneous
Contributors
v0.9.9Compare Source
v0.9.8Compare Source
stacksjs/bun-git-hooks (bun-git-hooks)
v0.3.1Compare Source
No significant changes
View changes on GitHub
v0.3.0Compare Source
No significant changes
View changes on GitHub
stacksjs/bunfig (bunfig)
v0.15.6Compare Source
No significant changes
View changes on GitHub
v0.15.5Compare Source
No significant changes
View changes on GitHub
v0.15.4Compare Source
No significant changes
View changes on GitHub
v0.15.3Compare Source
No significant changes
View changes on GitHub
v0.15.2Compare Source
No significant changes
View changes on GitHub
v0.15.1Compare Source
No significant changes
View changes on GitHub
digitalbazaar/forge (node-forge)
v1.3.3Compare Source
Fixed
introduced in 1.3.2.
v1.3.2Compare Source
Security
1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1
structures to desynchronize schema validations, yielding a semantic
divergence that may bypass downstream cryptographic verifications and
security decisions.
1.3.1 and below enables remote, unauthenticated attackers to craft deep
ASN.1 structures that trigger unbounded recursive parsing. This leads to a
Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER
inputs.
and below enables remote, unauthenticated attackers to craft ASN.1
structures containing OIDs with oversized arcs. These arcs may be decoded
as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the
bypass of downstream OID-based security decisions.
Fixed
verification bypass due to missing macData enforcement and improper
asn1.validate routine.
fromDer()max recursion depth check.asn1.maxDepthglobal configurable maximum depth of 256.asn1.fromDer()per-callmaxDepthoption.data. If this assumption is false then this could be a breaking change.
Please file an issue if there are use cases that need a higher maximum.
maxDepthparameter has not been exposed up throughall of the API stack due to the complexities involved. Please file an issue
if there are use cases that require this instead of changing the default
maximum.
2**32 - 1.2**53 - 1.shivammathur/setup-php (shivammathur/setup-php)
v2.36.0Compare Source
Changelog
8.6in thephp-versioninput should now set up a nightly build from the master branch ofphp-src. (#1002)pdo_ibmandibm_db2extensions.blackfireextension on PHP 8.5.gnupgfrom source would install the requiredlibgpgmelibrary automatically. (#1021)symfony-cli. It should now correctly set up the requested version. (#1008)Improved support for
relayextension. Also added support to install the nightly version of the extension. (#1011, #1012)Improved installing PHP on macOS. Also fixed installing PHP on
macos-15-intelGitHub runner. (#1029)Improved support for
deb822format sources files on Linux. It should now set up the sources files indeb822format on Ubuntu 24.04, Debian 13, and newer. It would automatically switch the format as well for the repositories added by the action to the new format when supported. (#1027)Improved support for installing
pdo_oci. (#1028)Fixed installing
gearmanextension for PHP 5.6 and 7.0 on Linux.Fixed an edge case in tools setup to fall back to the latest version. (#1024)
Fixed support to build extensions with uppercase names from PECL. (#1017)
Fixed warning on
redissetup on macOS after formula rename. (shivammathur/homebrew-extensions#5413)Fixed fallback link for
composersetup. (#1025)Updated the link for flex documentation in README. (#1020)
Updated Node.js dependencies.
Thanks @shyim, @tillkruss, and @nicolas-grekas for the contributions 🎉
Thanks @JetBrainsOfficial and @cachewerk for the sponsorship ❤️
For the complete list of changes, please refer to the Full Changelog
Follow for updates
stacksjs/action-releaser (stacksjs/action-releaser)
v1.2.7Compare Source
v1.2.6Compare Source
Compare changes
🐛 Bug Fixes
🧹 Chores
Contributors
v1.2.5Compare Source
Compare changes
🐛 Bug Fixes
🧹 Chores
Contributors
v1.2.4Compare Source
v1.2.3Compare Source
v1.2.2Compare Source
v1.2.1Compare Source
v1.2.0Compare Source
vitejs/vite (vite)
v7.2.6Compare Source
7.2.6 (2025-12-01)
v7.2.4Compare Source
Bug Fixes
v7.2.3Compare Source
Bug Fixes
bindCLIShortcutscalls with shortcut merging (#21103) (5909efd)Performance Improvements
Miscellaneous Chores
v7.2.2Compare Source
Bug Fixes
v7.2.1Compare Source
Bug Fixes
Code Refactoring
indexOfMatchInSlicetofindPreloadMarker(#21054) (f83264f)v7.2.0Compare Source
Bug Fixes
getBuiltinsresponse JSON serializable (#21029) (ad5b3bf)Miscellaneous Chores
v7.1.12Compare Source
Please refer to CHANGELOG.md for details.
v7.1.11Compare Source
Bug Fixes
server.fs.denycheck (#20968) (f479cc5)Miscellaneous Chores
Code Refactoring
Build System
v7.1.10Compare Source
Bug Fixes
//(#20760) (b95fa2a)fileToBuiltUrl(#20898) (73b6d24)Documentation
WebSocketspelling (#20890) (29e98dc)Miscellaneous Chores
v7.1.9Compare Source
Reverts
v7.1.8Compare Source
Bug Fixes
Documentation
Miscellaneous Chores
create-react-applicense (#20865) (166a178)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.