Skip to content

chore(deps): update all non-major dependencies with stable versions (minor)#3165

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-stable
Open

chore(deps): update all non-major dependencies with stable versions (minor)#3165
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-stable

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 15, 2026

This PR contains the following updates:

Package Change Age Confidence
@stylistic/stylelint-plugin ^5.0.1^5.1.0 age confidence
autoprefixer ^10.4.27^10.5.0 age confidence
brace-expansion@>=2.0.0 <=2.0.1 [>=2.0.3>=2.1.0](https://renovatebot.com/diffs/npm/brace-expansion@>=2.0.0 <=2.0.1/2.0.3/2.1.0) age confidence
devalue@<5.6.4 >=5.6.4>=5.7.1 age confidence
devalue@<=5.6.2 >=5.6.4>=5.7.1 age confidence
devalue@>=5.1.0 <5.6.2 [>=5.6.4>=5.7.1](https://renovatebot.com/diffs/npm/devalue@>=5.1.0 <5.6.2/5.6.4/5.7.1) age confidence
devalue@>=5.3.0 <=5.6.1 [>=5.6.4>=5.7.1](https://renovatebot.com/diffs/npm/devalue@>=5.3.0 <=5.6.1/5.6.4/5.7.1) age confidence
sass ^1.98.0^1.99.0 age confidence
undici@<7.24.0 (source) >=7.24.0>=7.25.0 age confidence

Release Notes

stylelint-stylistic/stylelint-stylistic (@​stylistic/stylelint-plugin)

v5.1.0

Compare Source

Added
  • The no-multiple-whitespaces rule, which disallows multiple whitespaces between property values and function arguments.
Fixed
  • The dependencies have now been updated to versions that include security fixes.
postcss/autoprefixer (autoprefixer)

v10.5.0

Compare Source

  • Added mask-position-x and mask-position-y support (by @​toporek).
juliangruber/brace-expansion (brace-expansion@>=2.0.0 <=2.0.1)

v2.1.0

Compare Source

sveltejs/devalue (devalue@<5.6.4)

v5.7.1

Compare Source

Patch Changes
  • 8becc7c: fix: handle regexes consistently in uneval's value and reference formats

v5.7.0

Compare Source

Minor Changes
  • df2e284: feat: use native alternatives to encode/decode base64
  • 498656e: feat: add DataView support
  • a210130: feat: whitelist Float16Array
  • df2e284: feat: simplify TypedArray slices
Patch Changes
  • 5590634: fix: get uneval type handling up to parity with stringify
  • 57f73fc: fix: correctly support boxed bigints and sentinel values
sass/dart-sass (sass)

v1.99.0

Compare Source

  • Add support for parent selectors (&) at the root of the document. These are
    emitted as-is in the CSS output, where they're interpreted as the scoping
    root
    .

  • User-defined functions named calc or clamp are no longer forbidden. If
    such a function exists without a namespace in the current module, it will be
    used instead of the built-in calc() or clamp() function.

  • User-defined functions whose names begin with - and end with -expression,
    -url, -and, -or, or -not are no longer forbidden. These were
    originally intended to match vendor prefixes, but in practice no vendor
    prefixes for these functions ever existed in real browsers.

  • User-defined functions named EXPRESSION, URL, and ELEMENT, those that
    begin with - and end with -ELEMENT, as well as the same names with some
    lowercase letters are now deprecated, These are names conflict with plain CSS
    functions that have special syntax.

    See the Sass website for details.

  • In a future release, calls to functions whose names begin with - and end
    with -expression and -url will no longer have special parsing. For now,
    these calls are deprecated if their behavior will change in the future.

    See the Sass website for details.

  • Calls to functions whose names begin with - and end with -progid:... are
    deprecated.

    See the Sass website for details.

nodejs/undici (undici@<7.24.0)

v7.25.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v7.24.8...v7.25.0

v7.24.8

Compare Source

What's Changed

Full Changelog: nodejs/undici@v7.24.7...v7.24.8

v7.24.7

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.6...v7.24.7

v7.24.6

Compare Source

What's Changed
New Contributors

Full Changelog: nodejs/undici@v7.24.5...v7.24.6

v7.24.5

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.4...v7.24.5

v7.24.4

Compare Source

What's Changed

Full Changelog: nodejs/undici@v7.24.3...v7.24.4

v7.24.3

Compare Source

What's Changed

  • fix(h2): TypeError: Cannot read properties of null (reading 'push') i… by @​hxinhan in #​4881

Full Changelog: nodejs/undici@v7.24.2...v7.24.3

v7.24.2

Compare Source

What's Changed

Full Changelog: nodejs/undici@v7.24.1...v7.24.2

v7.24.1

Compare Source


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • Monday through Friday (* * * * 1-5)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate-bot labels Apr 15, 2026
@renovate renovate Bot enabled auto-merge (squash) April 15, 2026 06:05
@renovate renovate Bot requested review from a team, Justineo, jillztom and kaiarrowood as code owners April 15, 2026 06:05
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Apr 15, 2026

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
Progress: resolved 1, reused 0, downloaded 0, added 0
Progress: resolved 67, reused 0, downloaded 0, added 0
Progress: resolved 70, reused 0, downloaded 0, added 0
 ERR_PNPM_TRUST_DOWNGRADE  High-risk trust downgrade for "vite@6.4.1" (possible package takeover)

This error happened while installing a direct dependency of /tmp/renovate/repos/github/Kong/kongponents

Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Earlier versions had trusted publisher, but this version has provenance attestation. A trust downgrade may indicate a supply chain incident.

@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 15, 2026

Deploy Preview for kongponents-sandbox failed.

Name Link
🔨 Latest commit 0aaf522
🔍 Latest deploy log https://app.netlify.com/projects/kongponents-sandbox/deploys/69ec691362ebca00082f96b0

@renovate renovate Bot force-pushed the renovate/all-stable branch 2 times, most recently from 4fe930e to 930a5c9 Compare April 23, 2026 02:30
@renovate renovate Bot force-pushed the renovate/all-stable branch from 930a5c9 to 9c88404 Compare April 24, 2026 07:41
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/all-stable branch from 9c88404 to 0aaf522 Compare April 25, 2026 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate-bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants