build: update all non-major dependencies #31089
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.12.1->1.26.0^0.7.0->^0.9.018.3.5->18.12.05.1.7->5.1.822.14.0->22.15.213.0.19->3.0.260.8.15->0.8.16v4.3.1->v4.6.2v4.3.6->v4.6.2^0.29.5->^0.30.0^0.17.5->^0.25.05.6.0->5.7.15.6.0->5.7.1~5.6.0->~5.7.0~3.10.0->~3.99.0~6.3.0->~6.4.0~3.1.0->~3.2.0~2.0.3->~2.2.0~2.1.0->~2.2.0^0.3.8->^0.4.0~11.0.0->~11.7.0~1.2.0->~1.4.0^0.1.13->^0.2.00.5.0->0.5.2~7.4.0->~7.8.01.86.3->1.89.0^0.17.2->^0.19.0^0.8.5->^0.10.0^0.8.4->^0.10.047b1876->f234e850.2.2->0.2.80.39.1->0.46.3Release Notes
bazelbuild/bazelisk (@bazel/bazelisk)
v1.26.0Compare Source
Bazelisk v1.26.0 comes with several improvements:
New Features (Go)
Bug Fixes & Improvements (Go)
go_depsextension (https://github.com/bazelbuild/bazelisk/pull/649).--migratemode (https://github.com/bazelbuild/bazelisk/pull/678).We’d like to thank our amazing contributors @albertocavalcante, @bduffany, @fmeum and @tats-u!
v1.25.0Compare Source
Bazelisk v1.25.0 comes with several improvements:
New Features (Python)
.bazeliskrcfiles (https://github.com/bazelbuild/bazelisk/pull/494).Bug Fixes & Improvements (Go)
bazelisk versionnow also prints the Bazelisk version even if startup flags are set (https://github.com/bazelbuild/bazelisk/pull/646).We’d like to thank our amazing contributors @hauserx, @jwnimmer-tri and @shs96c!
v1.24.1Compare Source
Bazelisk v1.24.1 is a patch release with some minor fixes:
Bug Fixes & Improvements
bisectnow accepts Bazel release branch names (https://github.com/bazelbuild/bazelisk/pull/633).We’d like to thank our amazing users & contributors!
v1.24.0Compare Source
Bazelisk v1.24.0 comes with a new feature:
New Features (Go)
7.*that refers to the latest release or candidate from the given LTS track. Please note that this is different from the existing7.xidentifier which only matches releases, but not candidates (https://github.com/bazelbuild/bazelisk/pull/636).We’d like to thank our amazing users & contributors!
Known issue: https://github.com/bazelbuild/bazelisk/issues/640
v1.23.0Compare Source
Bazelisk v1.23.0 comes with several improvements related to downloads:
Bug Fixes & Improvements
INTERNAL_ERRORproblems caused by improper handling of HTTP responses during retries (https://github.com/bazelbuild/bazelisk/pull/627)We’d like to thank our amazing contributors @jjmaestro and @jwnimmer-tri!
v1.22.1Compare Source
Bazelisk v1.22.1 is a patch release with the following changes:
Bug Fixes & Improvements
We’d like to thank our amazing contributor @sushain97!
v1.22.0Compare Source
Bazelisk v1.22.0 comes with several significant changes:
New Features (Go)
BAZELISKenv variable so that scripts can detect whether they're running under Bazelisk (https://github.com/bazelbuild/bazelisk/pull/612)--bisectnow supports finding the first fixing commit by prefixing the range with~(https://github.com/bazelbuild/bazelisk/pull/613)Removed Features (Go)
last_downstream_greensince the downstream pipeline stopped producing green commits some time ago.Bug Fixes & Improvements
last_greensupport (https://github.com/bazelbuild/bazelisk/pull/614)We’d like to thank our amazing contributors @fmeum and @jwnimmer-tri!
v1.21.0Compare Source
Bazelisk v1.21.0 comes with several significant changes:
New Features (Go)
BAZELISK_HOME_WINDOWS(https://github.com/bazelbuild/bazelisk/pull/474)BAZELISK_WRAPPER_DIRECTORYallows users to specify paths other than the defaulttools/bazellocation (https://github.com/bazelbuild/bazelisk/pull/567)BAZELISK_HOME: Environment variables as well as the tilde sign are now properly expanded (https://github.com/bazelbuild/bazelisk/pull/587)Bug Fixes & Improvements
.bazelversionfiles (https://github.com/bazelbuild/bazelisk/pull/576)We’d like to thank our amazing contributors @albertocavalcante, @API92, @jwnimmer-tri, @keith and @mzapotoczny!
v1.19.0Compare Source
Bazelisk v1.19.0 comes with two significant changes:
MODULE.bazelandREPO.bazelfiles are now obeyed (https://github.com/bazelbuild/bazelisk/pull/503)We’d like to thank our amazing contributors @crncnnr and @katre!
v1.18.0Compare Source
Bazelisk v1.18.0 contains some bug fixes and internal cleanups. Most notably, it uses consistent Bazel paths to avoid spurious rebuilds when downloading the same Bazel binary from a different mirror (https://github.com/bazelbuild/bazelisk/pull/465).
We’d like to thank our amazing contributors @alexeagle, @fmeum, @illicitonion, @sluongng and @wisechengyi!
firebase/firebase-js-sdk (@firebase/app-types)
v0.9.3Compare Source
Patch Changes
b80711925#8604 - Upgrade to TypeScript 5.5.4v0.9.2Compare Source
Patch Changes
ab883d016#8237 - Bump all packages so staging works.v0.9.1Compare Source
Patch Changes
0c5150106#8079 - Updaterepository.urlfield in allpackage.jsonfiles to NPM's preferred format.v0.9.0Compare Source
Minor Changes
1625f7a95#6799 - Update TypeScript version to 4.7.4.v0.8.1Compare Source
Patch Changes
4af28c1a4#6682 - Upgrade TypeScript to 4.7.4.v0.8.0Compare Source
Minor Changes
fdd4ab464#6526 - Add functionality to auto-initialize project config and emulator settings from global defaults provided by framework tooling.octokit/rest.js (@octokit/rest)
v18.12.0Compare Source
Features
.actions.downloadWorkflowRunAttemptLogs(),.actions.getWorkflowRunAttempt(),.repos.generateReleaseNotes(),.checks.rerequestRun(). Graduatenebula,zzzax,switcheroo,baptistepreviews. Removes defunkt/repos/{owner}/{repo}/actions/runs/{run_id}/retryendpoint. Renames methods to have consistentAuthenticatedUser()suffix, deprecates previous method names (#125) (4daa9f3)v18.11.4Compare Source
Bug Fixes
GET /repos/{owner}/{repo}/community/code_of_conduct,DELETE /reactions/{reaction_id}.encrypted_valueandkey_idparameters are required for.rest.actions.{createOrUpdateEnvironmentSecret,setSelectedReposForOrgSecret}().access_tokenparameter is required for.rest.apps.deleteAuthorization(). Previews graduated:ant-man,flash,scarlet-witch,squirrel-girl(#122) (9c02e7d)v18.11.3Compare Source
Bug Fixes
@octokit/plugin-paginate-resttov2.16.4to prevent typescript compile errors (#120) (fca1907)v18.11.2Compare Source
Bug Fixes
luke-cagepreview graduated (#119) (38a823f)v18.11.1Compare Source
Bug Fixes
dorian,inertia,london,lydian,wyandotte(#116) (f1e2416)v18.11.0Compare Source
Features
octokit.rest.repos.{enable,disable}LfsForRepo(),octokit.rest.repos.mergeUpstream({ owner, repo, branch })(916a8bb)v18.10.0Compare Source
Features
.packages.deletePackageForUser(),.packages.deletePackageVersionForUser(),.packages.restorePackageForUser(),.packages.restorePackageVersionForUser(),.secretScanning.listAlertsForOrg()(#105) (40aeaff)Bug Fixes
labelsparameter in.issues.{add,set}Labels()(#105) (40aeaff)v18.9.1Compare Source
Bug Fixes
v18.9.0Compare Source
Features
allow_auto_mergeparameter when creating / updating a repository. Search:ownerin repository items may no longer benull(#95) (c26c4fe)v18.8.0Compare Source
Features
.rest.repos.createAutolink(),.rest.repos.listAutolinks(),.rest.repos.getAutolink(),.rest.repos.deleteAutolink()(#94) (13df9e7)v18.7.2Compare Source
Bug Fixes
.rest.repos.getRelease()response data now includesmentions_count(#92) (01ba88f)v18.7.1Compare Source
Bug Fixes
.rest.repos.uploadReleaseAsset()requiresnameparameter..head.repoproperty is optional in pull request response type (#90) (515ed87)v18.7.0Compare Source
Features
createdparameter tooctokit.actions.listWorkflowRuns()andoctokit.actions.listWorkflowRunsForRepo()(#89) (bd3b6a9)v18.6.8Compare Source
Bug Fixes
@octokit/openapi-typesv9 via @octokit/plugin-rest-endpoint-methods to v5.4.2 (#88) (17399bf)v18.6.7Compare Source
Bug Fixes
octokit.rest.codeScanning.updateAlert()andoctokit.rest.codeScanning.getAlert()response types no longer includes.rule.security_severity_level- reverts v18.6.6 (#80) (91ffcf2)v18.6.6Compare Source
Bug Fixes
octokit.rest.codeScanning.updateAlert()andoctokit.rest.codeScanning.getAlert()response types now include.rule.security_severity_level(#79) (f69f2b2)v18.6.5Compare Source
Bug Fixes
v18.6.4Compare Source
Bug Fixes
.security_and_analysis.secret_scanningproperty in repository responses (#77) (36373fe)v18.6.3Compare Source
Bug Fixes
v18.6.2Compare Source
Bug Fixes
.search.topics()and.search.labels()via @octokit/plugin-rest-endpoint-methods v5.3.3 (#72) (acc61e3)v18.6.1Compare Source
Bug Fixes
@octokit/plugin-rest-endpoint-methodsv5.3.2 (#71) (127e0a8)v18.6.0Compare Source
Features
error.response(#64) (59cf96f)v18.5.6Compare Source
Bug Fixes
v18.5.5Compare Source
Bug Fixes
v18.5.4Compare Source
(that should have been a feature release, sorry)
Features
octokit.rest.repos.getPagesHealthCheck()codeScanning.listAlertInstances(),actions.approveWorkflowRun()apps.createContentAttachmentForRepo(),reactions.createForRelease(),repos.compareCommitsWithBasehead()Deprecations
codeScanning.listAlertsInstances()Bug Fixes
POST /repos/{owner}/{repo}/deployments(repos/create-deployment) does not accept acreated_atparameterv18.5.3Compare Source
Bug Fixes
organdorganizationparameters fromoctokit.repos.createFork()again (#46) (8263ce9)v18.5.2Compare Source
Bug Fixes
v18.5.1Compare Source
Bug Fixes
v18.5.0Compare Source
Features
octokit.rest.*. The methods are also set onoctokit.*for foreseeable time, but no longer documented, and will be deprecated at some point in future (#2054) (40ee966)v18.4.0Compare Source
Features
octokit.repos.getReadmeInDirectory()octokit.packages.getAllPackageVersionsForPackageOwnedByAuthenticatedUser()(deprecatesoctokit.packages.getAllPackageVersionsForAPackageOwnedByTheAuthenticatedUser())octokit.packages.getAllPackageVersionsForPackageOwnedByOrg()(deprecatesoctokit.packages.getAllPackageVersionsForAPackageOwnedByAnOrg)(#2053) (5350388)
actions/upload-artifact (actions/upload-artifact)
v4.6.2Compare Source
What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v4...v4.6.2
v4.6.1Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4...v4.6.1
v4.6.0Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4...v4.6.0
v4.5.0Compare Source
What's Changed
Node.jsversion in action by @hamirmahal in https://github.com/actions/upload-artifact/pull/578artifact-digestoutput by @bdehamer in https://github.com/actions/upload-artifact/pull/656New Contributors
Full Changelog: actions/upload-artifact@v4.4.3...v4.5.0
v4.4.3Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4.4.2...v4.4.3
v4.4.2Compare Source
What's Changed
@actions/artifactto 2.1.11 by @robherley in https://github.com/actions/upload-artifact/pull/627Full Changelog: actions/upload-artifact@v4.4.1...v4.4.2
v4.4.1Compare Source
What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v4.4.0...v4.4.1
v4.4.0Compare Source
Notice: Breaking Changes⚠️
We will no longer include hidden files and folders by default in the
upload-artifactaction of this version. This reduces the risk that credentials are accidentally uploaded into artifacts. Customers who need to continue to upload these files can use a new option,include-hidden-files, to continue to do so.See "Notice of upcoming deprecations and breaking changes in GitHub Actions runners" changelog and this issue for more details.
What's Changed
Full Changelog: actions/upload-artifact@v4.3.6...v4.4.0
v4.3.6Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4...v4.3.6
v4.3.5Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4.3.4...v4.3.5
v4.3.4Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4.3.3...v4.3.4
v4.3.3Compare Source
What's Changed
@actions/artifactdependency to v2.1.6 by @eggyhead in https://github.com/actions/upload-artifact/pull/565Full Changelog: actions/upload-artifact@v4.3.2...v4.3.3
v4.3.2Compare Source
What's Changed
@actions/artifactdependency to v2.1.5 and@actions/coreto v1.0.1 by @eggyhead in https://github.com/actions/upload-artifact/pull/562New Contributors
Full Changelog: actions/upload-artifact@v4.3.1...v4.3.2
angular/dgeni-packages (dgeni-packages)
v0.30.0Compare Source
Features
evanw/esbuild (esbuild)
v0.25.4Compare Source
Add simple support for CORS to esbuild's development server (#4125)
Starting with version 0.25.0, esbuild's development server is no longer configured to serve cross-origin requests. This was a deliberate change to prevent any website you visit from accessing your running esbuild development server. However, this change prevented (by design) certain use cases such as "debugging in production" by having your production website load code from
localhostwhere the esbuild development server is running.To enable this use case, esbuild is adding a feature to allow Cross-Origin Resource Sharing (a.k.a. CORS) for simple requests. Specifically, passing your origin to the new
corsoption will now set theAccess-Control-Allow-Originresponse header when the request has a matchingOriginheader. Note that this currently only works for requests that don't send a preflightOPTIONSrequest, as esbuild's development server doesn't currently supportOPTIONSrequests.Some examples:
CLI:
JS:
Go:
The special origin
*can be used to allow any origin to access esbuild's development server. Note that this means any website you visit will be able to read everything served by esbuild.Pass through invalid URLs in source maps unmodified (#4169)
This fixes a regression in version 0.25.0 where
sourcesin source maps that form invalid URLs were not being passed through to the output. Version 0.25.0 changed the interpretation ofsourcesfrom file paths to URLs, which means that URL parsing can now fail. Previously URLs that couldn't be parsed were replaced with the empty string. With this release, invalid URLs insourcesshould now be passed through unmodified.Handle exports named
__proto__in ES modules (#4162, #4163)In JavaScript, the special property name
__proto__sets the prototype when used inside an object literal. Previously esbuild's ESM-to-CommonJS conversion didn't special-case the property name of exports named__proto__so the exported getter accidentally became the prototype of the object literal. It's unclear what this affects, if anything, but it's better practice to avoid this by using a computed property name in this case.This fix was contributed by @magic-akari.
v0.25.3Compare Source
Fix lowered
asyncarrow functions beforesuper()(#4141, #4142)This change makes it possible to call an
asyncarrow function in a constructor before callingsuper()when targeting environments withoutasyncsupport, as long as the function body doesn't referencethis. Here's an example (notice the change fromthistonull):Some background: Arrow functions with the
asynckeyword are transformed into generator functions for older language targets such as--target=es2016. Since arrow functions capturethis, the generated code forwardsthisinto the body of the generator function. However, JavaScript class syntax forbids usingthisin a constructor before callingsuper(), and this forwarding was problematic since previously happened even when the function body doesn't usethis. Starting with this release, esbuild will now only forwardthisif it's used within the function body.This fix was contributed by @magic-akari.
Fix memory leak with
--watch=true(#4131, #4132)This release fixes a memory leak with esbuild when
--watch=trueis used instead of--watch. Previously using--watch=truecaused esbuild to continue to use more and more memory for every rebuild, but--watch=trueshould now behave like--watchand not leak memory.This bug happened because esbuild disables the garbage collector when it's not run as a long-lived process for extra speed, but esbuild's checks for which arguments cause esbuild to be a long-lived process weren't updated for the new
--watch=truestyle of boolean command-line flags. This has been an issue since this boolean flag syntax was added in version 0.14.24 in 2022. These checks are unfortunately separate from the regular argument parser because of how esbuild's internals are organized (the command-line interface is exposed as a separate Go API so you can build your own custom esbuild CLI).This fix was contributed by @mxschmitt.
More concise output for repeated legal comments (#4139)
Some libraries have many files and also use the same legal comment text in all files. Previously esbuild would copy each legal comment to the output file. Starting with this release, legal comments duplicated across separate files will now be grouped in the output file by unique comment content.
Allow a custom host with the development server (#4110)
With this release, you can now use a custom non-IP
hostwith esbuild's local development server (either with--serve=for the CLI or with theserve()call for the API). This was previously possible, but was intentionally broken in version 0.25.0 to fix a security issue. This change adds the functionality back except that it's now opt-in and only for a single domain name that you provide.For example, if you add a mapping in your
/etc/hostsfile fromlocal.example.comto127.0.0.1and then useesbuild --serve=local.example.com:8000, you will now be able to visit http://local.example.com:8000/ in your browser and successfully connect to esbuild's development server (doing that would previously have been blocked by the browser). This should also work with HTTPS if it's enabled (see esbuild's documentation for how to do that).Add a limit to CSS nesting expansion (#4114)
With this release, esbuild will now fail with an error if there is too much CSS nesting expansion. This can happen when nested CSS is converted to CSS without nesting for older browsers as expanding CSS nesting is inherently exponential due to the resulting combinatorial explosion. The expansion limit is currently hard-coded and cannot be changed, but is extremely unlikely to trigger for real code. It exists to prevent esbuild from using too much time and/or memory. Here's an example:
Previously, transforming this file with
--target=safari1took 5 seconds and generated 40mb of CSS. Trying to do that will now generate the following error instead:Fix path resolution edge case (#4144)
This fixes an edge case where esbuild's path resolution algorithm could deviate from node's path resolution algorithm. It involves a confusing situation where a directory shares the same file name as a file (but without the file extension). See the linked issue for specific details. This appears to be a case where esbuild is correctly following node's published resolution algorithm but where node itself is doing something different. Specifically the step
LOAD_AS_FILEappears to be skipped when the input ends with... This release changes esbuild's behavior for this edge case to match node's behavior.Update Go from 1.23.7 to 1.23.8 (#4133, #4134)
This should have no effect on existing code as this version change does not change Go's operating system support. It may remove certain reports from vulnerability scanners that detect which version of the Go compiler esbuild uses, such as for CVE-2025-22871.
As a reminder, esbuild's development server is intended for development, not for production, so I do not consider most networking-related vulnerabilities in Go to be vulnerabilities in esbuild. Please do not use esbuild's development server in production.
v0.25.2Compare Source
Configuration
📅 Schedule: Branch creation - "after 10:00pm every weekday,before 5:00am every weekday,every weekend" in timezone America/Tijuana, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.