Skip to content

Bump the npm-minor-patch group with 14 updates - #44

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-80db58e6b5
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-80db58e6b5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the npm-minor-patch group with 14 updates:

Package From To
@googlemaps/js-api-loader 2.1.1 2.1.3
dompurify 3.4.15 3.4.16
marked 18.0.13 18.0.14
mermaid 12.0.0 12.1.0
vue-i18n 11.4.12 11.4.13
vuetify 4.2.1 4.2.3
@types/google.maps 3.66.3 3.66.5
@types/node 26.6.2 26.6.4
eslint 10.11.0 10.12.0
eslint-plugin-vue 10.11.0 10.11.1
jsdom 30.1.0 30.1.1
vite 8.3.0 8.3.2
vitest 5.0.1 5.0.3
vue-tsc 3.3.11 3.3.12

Updates @googlemaps/js-api-loader from 2.1.1 to 2.1.3

Release notes

Sourced from @​googlemaps/js-api-loader's releases.

v2.1.3

2.1.3 (2026-09-22)

Bug Fixes

v2.1.2

2.1.2 (2026-09-14)

Bug Fixes

  • update dependencies and refactor library typing to use google.maps.ImportLibraryMap (#1247) (412f177)
Changelog

Sourced from @​googlemaps/js-api-loader's changelog.

2.1.3 (2026-09-22)

Bug Fixes

2.1.2 (2026-09-14)

Bug Fixes

  • update dependencies and refactor library typing to use google.maps.ImportLibraryMap (#1247) (412f177)
Commits
  • a2ea171 chore(main): release 2.1.3 (#1303)
  • 0c794c8 fix: add allowScripts block to package.json (#1302)
  • cf89cb7 build(deps-dev): bump eslint from 10.9.1 to 10.10.0 (#1299)
  • adb4400 build(deps-dev): bump @​babel/runtime-corejs3 from 8.0.0 to 8.0.6 (#1300)
  • 3445060 build(deps-dev): bump rollup-plugin-dts from 6.4.1 to 6.5.1 (#1301)
  • 27b4ecd chore(main): release 2.1.2 (#1268)
  • ff440c2 build(deps-dev): bump typescript-eslint from 8.69.0 to 8.70.0 (#1298)
  • e46c00c build(deps-dev): bump @​typescript-eslint/parser from 8.69.0 to 8.70.0 (#1297)
  • 6b2f534 build(deps-dev): bump jest from 30.4.2 to 30.5.1 (#1295)
  • 939512e build(deps-dev): bump jest-environment-jsdom from 30.4.1 to 30.5.1 (#1294)
  • Additional commits viewable in compare view

Updates dompurify from 3.4.15 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible
Commits

Updates marked from 18.0.13 to 18.0.14

Release notes

Sourced from marked's releases.

v18.0.14

18.0.14 (2026-09-22)

Bug Fixes

Commits

Updates mermaid from 12.0.0 to 12.1.0

Release notes

Sourced from mermaid's releases.

mermaid@12.1.0

Minor Changes

  • #8303 9140716 Thanks @​filipsajdak! - feat: add the elk.orientFeedbackEdges option, enabled by default. With the ELK layout, an edge from a node that a subgraph feeds back into that subgraph is now routed downstream instead of around the subgraph. This changes the layout of existing ELK diagrams that contain such edges; set elk.orientFeedbackEdges: false to keep the previous routing.

  • #8250 fd4f5f2 Thanks @​kartben! - feat: add a bitOrder option to packet diagrams. It defaults to ascending, which is the current behaviour, and descending mirrors every row so it reads from that row's highest bit down to its lowest. Fields are still declared lowest bit first and keep their width, so switching a diagram between the two conventions only means changing bitOrder.

Patch Changes

  • #8330 50c9e55 Thanks @​ashishjain0512! - fix: upgrade chevrotain to 13 so mermaid no longer pulls in vulnerable lodash-es@4.17.23

  • #8259 4c90f5c Thanks @​afonsojanu! - fix(sequence): allow whitespace between an actor name and its @{ ... } config object

    participant Bob@{ "type" : "database" } parsed fine, but adding a single space before the config object (participant Bob @{ "type" : "database" }) failed with a confusing parse error, even though the plain form without a config object tolerates trailing whitespace just fine.

  • #8339 c7fa1a5 Thanks @​ashishjain0512! - fix: keep ELK class-diagram cardinalities off namespace frames

  • #8334 d67331d Thanks @​ashishjain0512! - fix(class): place cardinality labels beside their relation ends on dagre's sides with ELK, centre dagre's end labels, and stop clipping their text

  • #8344 99a050b Thanks @​pbrolin47! - fix: with the ELK layout, an edge label could sit up to 16px beside its edge instead of centred on it, when the edge's terminal jog was straightened after the label's position was computed. The label is now re-projected onto the straightened route

  • #8276 3101c7d Thanks @​mir-ashiq! - fix(error): show the actual error message in the error diagram

    When a diagram fails to parse, the error diagram now draws the real error message below the "Syntax error in text" headline, wrapped to at most four lines. Hosts that only show the SVG (GitHub, GitLab, Obsidian, exported images) no longer hide what actually went wrong, e.g. that the flowchart edge limit was exceeded and maxEdges needs raising via mermaid.initialize.

  • #8296 aa29345 Thanks @​pentaoa! - fix: preserve explicit source relations on event modeling reset frames

  • #8297 967bbde Thanks @​pentaoa! - fix: reject duplicate event modeling frame IDs before rendering

  • #8337 147f343 Thanks @​knsv-bot! - fix: a flowchart that declares the same subgraph id more than once now renders as one merged subgraph with the ELK layout instead of producing NaN geometry. Classes and view: collapsed set on a repeated subgraph now apply to it, whichever declaration they follow.

  • #8203 40ef7b4 Thanks @​MFA-G! - perf(frontmatter): replace the quadratic front matter regex on hot paths

    frontMatterRegex backtracks polynomially on whitespace-heavy input, so a diagram well inside the default maxTextSize could stall parsing for over a second. detectType and extractFrontMatter now use a linear scanner that matches the regex result exactly, leaving no document stripped differently.

  • #8254 351d7d2 Thanks @​galshir! - fix: warn when a gantt task references an unknown after/until task id, or when its end value is neither a valid date nor a valid duration

  • #8249 b657a2c Thanks @​mir-ashiq! - fix(sequence): allow hyphenated actor and participant names when a config object is attached

... (truncated)

Commits
  • 21f72f0 Merge pull request #8360 from mermaid-js/changeset-release/master
  • 3f89f7b Version Packages
  • 4ef0218 Merge pull request #8358 from mermaid-js/release/12.0.1
  • f45c691 Fix error from build docs
  • d9cb282 Fix label overlap bug
  • 47fffa0 Merge pull request #8297 from pentaoa/fix/eventmodeling-duplicate-frame-ids
  • 12c280e Merge develop and preserve eventmodeling regression tests
  • c0f7052 Merge pull request #8296 from pentaoa/fix/eventmodeling-reset-explicit-relations
  • 4f6ac96 Merge pull request #8345 from mermaid-js/bug/8283_xychart-legend-clip-title-h...
  • 679093a Merge pull request #8344 from mermaid-js/pebr/issue-8292-elk-label
  • Additional commits viewable in compare view

Updates vue-i18n from 11.4.12 to 11.4.13

Release notes

Sourced from vue-i18n's releases.

v11.4.13

What's Changed

⚡ Improvement Features

Full Changelog: intlify/vue-i18n@v11.4.12...v11.4.13

Changelog

Sourced from vue-i18n's changelog.

v11.4.13 (2026-10-02T11:01:59.781Z)

This changelog is generated by GitHub Releases

What's Changed

⚡ Improvement Features

Full Changelog: intlify/vue-i18n@v11.4.12...v11.4.13

Commits

Updates vuetify from 4.2.1 to 4.2.3

Release notes

Sourced from vuetify's releases.

v4.2.3

🔧 Bug Fixes

  • VDataTable/VDataIterator: emit update:options once when searching (2933523)
  • VExpansionPanels: don't apply rounded-0 when rounded is not set (17c9f8d)
  • VIcon/VBadge/VBottomNavigation: respect theme prop (3d26868), closes #23211
  • VOtpInput: keep caret and active slot in sync during composition (61719f9), closes #23221
  • VProgressLinear: split buffer bar when value is at 0 (af79966)
  • VTimeline: isolate styles from nested timelines (#23228) (4b1919e), closes #21426

v4.2.2

🔧 Bug Fixes

  • VAutocomplete/VCombobox: prevent menu icon from toggling twice (#23200) (c8b9d6a), closes #23197
  • VPullToRefresh: wrap styles in the components cascade layer (#23207) (9453f06), closes #23206
  • VSelect/VAutocomplete: match autofill against item values (#23063) (b6c9f5c), closes #20560
  • VSelect/VAutocomplete/VCombobox: apply menu-elevation to the content div (#23193) (8d1d985), closes #23192
  • VSwitch: rotate icon for vertical direction (6b090a0)
  • VTab: restore overflow for correct slider animation (1c5545c)
  • VTabs: apply inset-radius to tab for ripple and focus ring (bf6abfc)

🧪 Labs

  • VCommandPalette: render the list.prepend slot (#23204) (7cd8c57), closes #23202
  • VHighlight: correct foreground color in forced-colors mode (c00064f)
  • VMonthPicker: !important not needed in trumps layer (fdc76e5)
  • VVideo: !important for thumb label no longer needed (b3d8bb1)
Commits
  • f5800f7 chore(release): publish v4.2.3
  • af79966 fix(VProgressLinear): split buffer bar when value is at 0
  • 4b1919e fix(VTimeline): isolate styles from nested timelines (#23228)
  • 17c9f8d fix(VExpansionPanels): don't apply rounded-0 when rounded is not set
  • 61719f9 fix(VOtpInput): keep caret and active slot in sync during composition
  • 9103f25 chore(VDatePicker): one more test to improve coverage
  • 8afa2cd chore(VCombobox): one more test to improve coverage
  • 1f9428a chore: cleanup dead code and leftover v2 specs
  • 2933523 fix(VDataTable/VDataIterator): emit update:options once when searching
  • fc31f50 chore: re-enable skipped tests
  • Additional commits viewable in compare view

Updates @types/google.maps from 3.66.3 to 3.66.5

Commits

Updates @types/node from 26.6.2 to 26.6.4

Commits

Updates eslint from 10.11.0 to 10.12.0

Release notes

Sourced from eslint's releases.

v10.12.0

Features

  • 4618052 feat: handle astral letters in new-cap (#21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#21342) (ESLint Bot)
Commits
  • a438ec3 10.12.0
  • 32a73f1 Build: changelog update for 10.12.0
  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332)
  • 152067f chore: update ecosystem plugins (#21362)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376)
  • 67eb586 docs: Update README
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371)
  • Additional commits viewable in compare view

Updates eslint-plugin-vue from 10.11.0 to 10.11.1

Release notes

Sourced from eslint-plugin-vue's releases.

v10.11.1

Patch Changes

Changelog

Sourced from eslint-plugin-vue's changelog.

10.11.1

Patch Changes

Commits

Updates jsdom from 30.1.0 to 30.1.1

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)
Commits
  • 0a117f4 30.1.1
  • 103f67d Remove unnecessary window cleanup from API tests
  • cdda00a Test HTTP/2 document and subresource loading
  • 7ab92ce Update @​asamuzakjp/dom-selector to v9.2.1
  • d940c20 Share jsdom settings across descendant windows
  • 6ba40cb Fix and simplify option propagation
  • 3b3be70 Preserve CSS priorities across declaration updates
  • 97b2758 Align focusing and unfocusing with HTML
  • b7b460b Update w3c-xmlserializer to v6
  • 71d562f Update html-encoding-sniffer to v7
  • Additional commits viewable in compare view

Updates vite from 8.3.0 to 8.3.2

Release notes

Sourced from vite's releases.

v8.3.2

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)

... (truncated)

Changelog

Sourced from vite's changelog.

8.3.2 (2026-10-01)

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (

Bumps the npm-minor-patch group with 14 updates:

| Package | From | To |
| --- | --- | --- |
| [@googlemaps/js-api-loader](https://github.com/googlemaps/js-api-loader) | `2.1.1` | `2.1.3` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.15` | `3.4.16` |
| [marked](https://github.com/markedjs/marked) | `18.0.13` | `18.0.14` |
| [mermaid](https://github.com/mermaid-js/mermaid) | `12.0.0` | `12.1.0` |
| [vue-i18n](https://github.com/intlify/vue-i18n/tree/HEAD/packages/vue-i18n) | `11.4.12` | `11.4.13` |
| [vuetify](https://github.com/vuetifyjs/vuetify/tree/HEAD/packages/vuetify) | `4.2.1` | `4.2.3` |
| [@types/google.maps](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/google.maps) | `3.66.3` | `3.66.5` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.2` | `26.6.4` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [eslint-plugin-vue](https://github.com/vuejs/eslint-plugin-vue) | `10.11.0` | `10.11.1` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.0` | `30.1.1` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.3` |
| [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `3.3.11` | `3.3.12` |


Updates `@googlemaps/js-api-loader` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/googlemaps/js-api-loader/releases)
- [Changelog](https://github.com/googlemaps/js-api-loader/blob/main/CHANGELOG.md)
- [Commits](googlemaps/js-api-loader@v2.1.1...v2.1.3)

Updates `dompurify` from 3.4.15 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.15...3.4.16)

Updates `marked` from 18.0.13 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.13...v18.0.14)

Updates `mermaid` from 12.0.0 to 12.1.0
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@12.0.0...mermaid@12.1.0)

Updates `vue-i18n` from 11.4.12 to 11.4.13
- [Release notes](https://github.com/intlify/vue-i18n/releases)
- [Changelog](https://github.com/intlify/vue-i18n/blob/v11.4.13/CHANGELOG.md)
- [Commits](https://github.com/intlify/vue-i18n/commits/v11.4.13/packages/vue-i18n)

Updates `vuetify` from 4.2.1 to 4.2.3
- [Release notes](https://github.com/vuetifyjs/vuetify/releases)
- [Commits](https://github.com/vuetifyjs/vuetify/commits/v4.2.3/packages/vuetify)

Updates `@types/google.maps` from 3.66.3 to 3.66.5
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/google.maps)

Updates `@types/node` from 26.6.2 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `eslint-plugin-vue` from 10.11.0 to 10.11.1
- [Release notes](https://github.com/vuejs/eslint-plugin-vue/releases)
- [Changelog](https://github.com/vuejs/eslint-plugin-vue/blob/master/CHANGELOG.md)
- [Commits](vuejs/eslint-plugin-vue@v10.11.0...v10.11.1)

Updates `jsdom` from 30.1.0 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.0...v30.1.1)

Updates `vite` from 8.3.0 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `vue-tsc` from 3.3.11 to 3.3.12
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.12/packages/tsc)

---
updated-dependencies:
- dependency-name: "@googlemaps/js-api-loader"
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: mermaid
  dependency-version: 12.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: vue-i18n
  dependency-version: 11.4.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vuetify
  dependency-version: 4.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@types/google.maps"
  dependency-version: 3.66.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: eslint-plugin-vue
  dependency-version: 10.11.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vue-tsc
  dependency-version: 3.3.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
mt3hr added a commit that referenced this pull request Oct 7, 2026
…eql-action)を取り込み、vue-tsc だけ 3.3.11 に据え置く

Dependabot が出していた PR 6本(#39〜#44)と、未対応のアラート2件
(GHSA-p98j-92pf-mc4p dompurify / GHSA-gfhx-hw2g-v5hg serialize-javascript、どちらも low)を
1コミットで取り込む。PR はマージせずに閉じる。

## npm

まとめ PR(npm-minor-patch の14本)から vue-tsc を除いた13本と、
serialize-javascript 7.1.1 → 7.1.2(workbox-build 経由の推移依存なので lock だけ)。
主なもの: Vuetify 4.2.1 → 4.2.3、Vite 8.3.0 → 8.3.2、mermaid 12.0.0 → 12.1.0、
vitest 5.0.1 → 5.0.3、ESLint 10.11.0 → 10.12.0、vue-i18n 11.4.12 → 11.4.13、dompurify 3.4.15 → 3.4.16。

**vue-tsc は 3.3.11 に据え置く。** 3.3.12 には、テンプレート内のアロー関数で import した値を
参照すると誤って `.value` を付ける退行があり(vuejs/language-tools#6237。修正 PR は未リリース)、
`:rules="[(v: string) => !!v || i18n.global.t(...)]"` を持つ追加画面 8本と kftl-page の
`router.replace` で型検査が落ちる(まとめ PR の CI はこれで赤だった)。
コードを回避形へ書き換えず、修正版を待つ。

dompurify の脆弱性は IN_PLACE とフックの組み合わせに限られ、gkill 自身は文字列を渡す
sanitize だけなので直接は当たらない。mermaid が内部で DOMPurify を使うので上げておく。

## Go

modernc.org/sqlite 1.59.0 → 1.60.1(modernc.org/libc 1.77.0 → 1.77.1 を揃える)と
go-git/go-billy 5.9.1 → 5.9.2(golang.org/x/net・x/text のセキュリティ更新を含む)を、
src/server と src/plugins/ の7モジュールへ。`go mod tidy` は examples/gkill_example を含む
9モジュールで打ち、go.mod / go.sum の差分は PR と一致した。

## GitHub Actions

codeql-action の init と analyze を 4.38.1 → 4.38.2 へ同時に上げる。Dependabot は2本を
別々の PR で出していたため、どちらも analyze が「Loaded a configuration file for version
4.38.2, but running version 4.38.1」で必ず落ちていた。

## Dependabot 設定

- Actions を1本の PR にまとめる(groups: actions-all)。codeql-action の init / analyze が
  別 PR で来て両方赤くなるのを防ぐ
- npm に vue-tsc 3.3.12 の ignore を足す。まとめ PR に混ざると PR 全体の型検査が落ちるため。
  3.3.13 以降は通常どおり来る

検証: 型検査(vue-tsc --build --force。増分情報が依存の更新を拾わず検査を省いたので全量で)、
Vite ビルド、ESLint(--max-warnings 0)、test_client_unit 2519 件全件成功(テスト件数)、
test_tools 99 件全件成功(テスト件数)、vet_plugins / test_plugins、test_server、npm run verify_docs OK
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer being updated by Dependabot, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-minor-patch-80db58e6b5 branch October 7, 2026 13:51
@mt3hr

mt3hr commented Oct 7, 2026

Copy link
Copy Markdown
Owner

main へ直接取り込んだので閉じます(f0b53d5f)。vue-tsc 3.3.12 はテンプレートの型検査を壊す退行(vuejs/language-tools#6237)があるため 3.3.11 に据え置き、残りの13本はこの PR と同じ版で取り込みました。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant