Skip to content

build(deps): bump the minor-and-patch group with 9 updates - #149

Merged
GeiserX merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-335830dcf5
Sep 28, 2026
Merged

GeiserX merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-335830dcf5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 9 updates:

Package From To
dotenv 18.0.0 18.0.3
maplibre-gl 6.10.0 6.11.2
next 16.3.5 16.3.6
@types/node 26.6.1 26.6.2
@vitest/coverage-v8 5.0.1 5.0.2
eslint-config-next 16.3.5 16.3.6
jsdom 30.1.0 30.1.1
tsx 4.23.13 4.23.15
vitest 5.0.1 5.0.2

Updates dotenv from 18.0.0 to 18.0.3

Changelog

Sourced from dotenv's changelog.

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)
Commits
  • f6390d1 18.0.3
  • 456da68 changelog
  • 12ea34b Merge pull request #1059 from motdotla/config-quiet
  • a654bc2 patch DOTENV_QUIET
  • a0ae3e0 Merge pull request #1058 from SulimanAbdulrazzaq/fix/fast-parser-lone-export-...
  • d6b3a1d demonstrate DOTENV_QUIET failing
  • d57e0bc fix: keep assignments after a bare export line in the fast parser
  • 5203712 perf: skip quoted text and short-circuit ASCII whitespace checks
  • c69ed11 chore: align package version with 18.0.2 changelog
  • 2db9acf fix: retain closing quote candidates in the fast scanner
  • Additional commits viewable in compare view

Updates maplibre-gl from 6.10.0 to 6.11.2

Release notes

Sourced from maplibre-gl's releases.

v6.11.2

✨ Features and improvements

  • Improve rendering performance by uploading each tile's projection data once per frame instead of before every draw call (#8545) (by @​birkskyum)
  • Support multiple glyph variants in requests, caches, and atlases (#8488) (by @​NEKOYASAN)

🐞 Bug fixes

  • Fix Map#once(type, layerId, listener) unsubscribing on the first event that misses the layer instead of the first event that hits it (#8499) (by @​cherenkov)
  • Remove hillshade gradient toward the poles (#8551) (by @​birkskyum)
  • Fix camera settings being undone during camera movement with terrain or transformCameraUpdate (#8550) (by @​birkskyum)
  • Fix zooming and panning with the pointer above the horizon moving the map in the opposite direction (#8544) (by @​birkskyum)
  • Fix the camera jumping when a drag over terrain ends at a pitch above 84° (#8541) (by @​birkskyum)
  • Ease the center elevation over terrain during easeTo and flyTo instead of holding it and jumping when the animation ends (#8543) (by @​johncarmack1984)
  • Fix fitBounds and cameraForBounds throwing on the globe projection when the padding exceeds the viewport, instead of warning and returning undefined as on mercator (#8538) (by @​drakeo338)
  • Keep raster tiles sharp at a fractional devicePixelRatio, where the canvas covered a different number of device pixels than its backing store held and the compositor rescaled it (#1590) (by @​zdila)

v6.11.1

🐞 Bug fixes

  • Fix missing promoteId when merging queued updateData diffs in geojson source (#8500) (by @​cherenkov)
  • Sanitize attribution with an allow list of tags and attributes rather than a list of known-dangerous ones (#8532) (by @​HarelM)
  • Fix the camera jumping or bobbing around gestures over terrain, and ignoring terrain that loads after easeTo/flyTo (#8471) (by @​johncarmack1984)
  • Stop sending a vector tile to the worker when it was dropped while its request was being transformed or while the worker was still starting up, which left the parsed tile in the worker for the lifetime of the map (#8516) (by @​cherenkov)

v6.11.0

✨ Features and improvements

  • Fire a contextmenu map event on long press for touch devices (#373) (by @​kirthi-b)
  • Transition paint, light and sky properties that read global-state from the value they had when the state changes, where they snapped to the new value while holding idle for the transition duration (#8395) (by @​avosa)
  • Speed up cross-tile symbol matching for sources with promoteId by keying symbols on their feature id as well as their label (#8470, continues #7665) (by @​bradymadden97 and @​johncarmack1984)
  • Add Map#calculateAnchoredCameraOptions to calculate camera options that place a geographic anchor at a screen position without moving the map (#8288) (by @​xavierjs)
  • Skip the loaded-tile scan for constant symbol-height-offset layers when computing tile coverage (#8424) (by @​clement-igonet)
  • Type and document that an addProtocol handler may return an ImageBitmap or HTMLImageElement for an image resource, so decoded pixels are not encoded and decoded again (#8515) (by @​MannXo)

🐞 Bug fixes

  • Fade the globe atmosphere in with the camera's altitude, so the sky keeps the horizon until the atmosphere takes over from space (#8464) (by @​birkskyum)
  • Report worker script failures through the map error event (#8018) (by @​xavierjs)
  • Fix slow panning and zooming in Firefox on macOS since 6.8.0 (#8468) (by @​timsluis and @​birkskyum)
  • Keep source-specific tile LOD settings from changing internal terrain render-to-texture tile selection (#8048) (by @​DoFabien)
  • Fix map.setSky() silently keeping the old sky and firing no error event when the value included a -transition key (#8375) (by @​Yasser-Ameur)
  • Fix markers and popups misplaced after a projection change or by terrain that loads after the map settled. (#8433) (by @​patte)
  • Insert sanitized attribution HTML as DOM nodes instead of re-parsing a serialized string (#8528) (by @​cherenkov)
Changelog

Sourced from maplibre-gl's changelog.

6.11.2

✨ Features and improvements

  • Improve rendering performance by uploading each tile's projection data once per frame instead of before every draw call (#8545) (by @​birkskyum)
  • Support multiple glyph variants in requests, caches, and atlases (#8488) (by @​NEKOYASAN)

🐞 Bug fixes

  • Fix Map#once(type, layerId, listener) unsubscribing on the first event that misses the layer instead of the first event that hits it (#8499) (by @​cherenkov)
  • Remove hillshade gradient toward the poles (#8551) (by @​birkskyum)
  • Fix camera settings being undone during camera movement with terrain or transformCameraUpdate (#8550) (by @​birkskyum)
  • Fix zooming and panning with the pointer above the horizon moving the map in the opposite direction (#8544) (by @​birkskyum)
  • Fix the camera jumping when a drag over terrain ends at a pitch above 84° (#8541) (by @​birkskyum)
  • Ease the center elevation over terrain during easeTo and flyTo instead of holding it and jumping when the animation ends (#8543) (by @​johncarmack1984)
  • Fix fitBounds and cameraForBounds throwing on the globe projection when the padding exceeds the viewport, instead of warning and returning undefined as on mercator (#8538) (by @​drakeo338)
  • Keep raster tiles sharp at a fractional devicePixelRatio, where the canvas covered a different number of device pixels than its backing store held and the compositor rescaled it (#1590) (by @​zdila)

6.11.1

🐞 Bug fixes

  • Fix missing promoteId when merging queued updateData diffs in geojson source (#8500) (by @​cherenkov)
  • Sanitize attribution with an allow list of tags and attributes rather than a list of known-dangerous ones (#8532) (by @​HarelM)
  • Fix the camera jumping or bobbing around gestures over terrain, and ignoring terrain that loads after easeTo/flyTo (#8471) (by @​johncarmack1984)
  • Stop sending a vector tile to the worker when it was dropped while its request was being transformed or while the worker was still starting up, which left the parsed tile in the worker for the lifetime of the map (#8516) (by @​cherenkov)

6.11.0

✨ Features and improvements

  • Fire a contextmenu map event on long press for touch devices (#373) (by @​kirthi-b)
  • Transition paint, light and sky properties that read global-state from the value they had when the state changes, where they snapped to the new value while holding idle for the transition duration (#8395) (by @​avosa)
  • Speed up cross-tile symbol matching for sources with promoteId by keying symbols on their feature id as well as their label (#8470, continues #7665) (by @​bradymadden97 and @​johncarmack1984)
  • Add Map#calculateAnchoredCameraOptions to calculate camera options that place a geographic anchor at a screen position without moving the map (#8288) (by @​xavierjs)
  • Skip the loaded-tile scan for constant symbol-height-offset layers when computing tile coverage (#8424) (by @​clement-igonet)
  • Type and document that an addProtocol handler may return an ImageBitmap or HTMLImageElement for an image resource, so decoded pixels are not encoded and decoded again (#8515) (by @​MannXo)

🐞 Bug fixes

  • Fade the globe atmosphere in with the camera's altitude, so the sky keeps the horizon until the atmosphere takes over from space (#8464) (by @​birkskyum)
  • Report worker script failures through the map error event (#8018) (by @​xavierjs)
  • Fix slow panning and zooming in Firefox on macOS since 6.8.0 (#8468) (by @​timsluis and @​birkskyum)
  • Keep source-specific tile LOD settings from changing internal terrain render-to-texture tile selection (#8048) (by @​DoFabien)
  • Fix map.setSky() silently keeping the old sky and firing no error event when the value included a -transition key (#8375) (by @​Yasser-Ameur)
  • Fix markers and popups misplaced after a projection change or by terrain that loads after the map settled. (#8433) (by @​patte)
  • Insert sanitized attribution HTML as DOM nodes instead of re-parsing a serialized string (#8528) (by @​cherenkov)
Commits
  • acb7b72 Bump js version to 6.11.2 (#8555)
  • d28f844 fix: Map#once with layerId unsubscribes only after a real hit (#8499)
  • 99d0160 Support multiple glyph variants (#8488)
  • 98268d3 Fix globe cameraForBoxAndBearing throwing when padding exceeds the viewport (...
  • f560a83 Size the canvas to whole device pixels (#8513)
  • 7a897d0 Remove hillshade gradient toward the poles (#8551)
  • 0dff33a Fix camera settings being undone during camera movement (#8550)
  • c2031bf GM2.8 Upload projection data once per tile instead of once per draw (#8545)
  • 728a44c Fix zoom and drag above the horizon moving the map the wrong way (#8544)
  • 3dfdce0 refactor: one method builds the mercator animation's end transform (#8546)
  • Additional commits viewable in compare view

Updates next from 16.3.5 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates @types/node from 26.6.1 to 26.6.2

Commits

Updates @vitest/coverage-v8 from 5.0.1 to 5.0.2

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates eslint-config-next from 16.3.5 to 16.3.6

Release notes

Sourced from eslint-config-next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates jsdom from 30.1.0 to 30.1.1

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)
Commits
  • 0a117f4 30.1.1
  • 103f67d Remove unnecessary window cleanup from API tests
  • cdda00a Test HTTP/2 document and subresource loading
  • 7ab92ce Update @​asamuzakjp/dom-selector to v9.2.1
  • d940c20 Share jsdom settings across descendant windows
  • 6ba40cb Fix and simplify option propagation
  • 3b3be70 Preserve CSS priorities across declaration updates
  • 97b2758 Align focusing and unfocusing with HTML
  • b7b460b Update w3c-xmlserializer to v6
  • 71d562f Update html-encoding-sniffer to v7
  • Additional commits viewable in compare view

Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Updates vitest from 5.0.1 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [dotenv](https://github.com/motdotla/dotenv) | `18.0.0` | `18.0.3` |
| [maplibre-gl](https://github.com/maplibre/maplibre-gl-js) | `6.10.0` | `6.11.2` |
| [next](https://github.com/vercel/next.js) | `16.3.5` | `16.3.6` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.1` | `26.6.2` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.1` | `5.0.2` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.5` | `16.3.6` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.0` | `30.1.1` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.2` |


Updates `dotenv` from 18.0.0 to 18.0.3
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v18.0.0...v18.0.3)

Updates `maplibre-gl` from 6.10.0 to 6.11.2
- [Release notes](https://github.com/maplibre/maplibre-gl-js/releases)
- [Changelog](https://github.com/maplibre/maplibre-gl-js/blob/main/CHANGELOG.md)
- [Commits](maplibre/maplibre-gl-js@v6.10.0...v6.11.2)

Updates `next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/coverage-v8)

Updates `eslint-config-next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `jsdom` from 30.1.0 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.0...v30.1.1)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `vitest` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: maplibre-gl
  dependency-version: 6.11.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: GeiserX/Pumperly/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: a99fa324-8ec0-4c04-9626-76f6b81b4fa6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@GeiserX
GeiserX merged commit 458649f into main Sep 28, 2026
8 checks passed
@GeiserX
GeiserX deleted the dependabot/npm_and_yarn/minor-and-patch-335830dcf5 branch September 28, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant