Skip to content

chore(deps-dev): bump the npm-development group with 6 updates - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-development-72b87ed150
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-development-72b87ed150

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-development group with 6 updates:

Package From To
@types/node 26.6.3 26.6.4
@vitejs/plugin-react 6.1.1 6.1.2
jsdom 30.1.1 30.1.2
oxlint 1.86.0 1.87.0
shadcn 4.21.0 4.21.4
vite 8.3.1 8.3.3

Updates @types/node from 26.6.3 to 26.6.4

Commits

Updates @vitejs/plugin-react from 6.1.1 to 6.1.2

Release notes

Sourced from @​vitejs/plugin-react's releases.

plugin-react@6.1.2

Fix HMR for compound components (#1484)

Adding or removing a component from a compound component was not handled, creating stale updates. Doing this now triggers hmr invalidate on the file and propagates the invalidation to importers.

Fix compiler.logDiagnostics option not working (#1483)

With oxc-transform-react >= 0.148, the logDiagnostics was not working. This version fixes it and requires oxc-transform-react >= 0.152 as a peer dependency if you are using the compiler option. compiler.logDiagnostics option is now deprecated and should be swapped for the builtin compiler.reportDiagnostics.

Disable refresh for non-jsx with compiler enabled (fix #1478) (#1485)

When the compiler was enabled, TS files could trigger fast refresh which would cause runtime errors. The logic now follows what the builtin oxc plugin in Vite does.

Changelog

Sourced from @​vitejs/plugin-react's changelog.

6.1.2 (2026-10-05)

Fix HMR for compound components (#1484)

Adding or removing a component from a compound component was not handled, creating stale updates. Doing this now triggers hmr invalidate on the file and propagates the invalidation to importers.

Fix compiler.logDiagnostics option not working (#1483)

With oxc-transform-react >= 0.148, the logDiagnostics was not working. This version fixes it and requires oxc-transform-react >= 0.152 as a peer dependency if you are using the compiler option. compiler.logDiagnostics option is now deprecated and should be swapped for the builtin compiler.reportDiagnostics.

Disable refresh for non-jsx with compiler enabled (fix #1478) (#1485)

When the compiler was enabled, TS files could trigger fast refresh which would cause runtime errors. The logic now follows what the builtin oxc plugin in Vite does.

Commits

Updates jsdom from 30.1.1 to 30.1.2

Release notes

Sourced from jsdom's releases.

v30.1.2

  • Updated URLs to support Unicode v18.0.0 in internationalized domain names.
  • Reduced package size and memory use for CSS property definitions. (@​scttcper)
  • Fixed severe slowdowns when building large DOM trees, including SVG charts with D3, which regressed in v30.1.0. (@​cmdcolin)
  • Fixed exponentially slow reads of empty inherited CSS custom properties in deeply nested documents, and custom properties incorrectly inheriting past an initial reset. (@​scttcper)
  • Fixed getComputedStyle() returning stale results after editing stylesheet declarations, selectors, or media queries, including in imported stylesheets.
  • Fixed selector matching and computed styles after changes to form control checkedness, indeterminacy, selection, values, and validity, including during form resets and canceled clicks.
  • Fixed computed styles for :focus, :focus-visible, :focus-within, and selectors containing them after focus changes, including inside focus and blur listeners. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing elements hidden by 'display', including through shadow hosts and slots, and elements excluded by shadow DOM slot assignment. (@​asamuzaK)
  • Fixed getComputedStyle() throwing for elements without inline-style support, including XML and MathML elements.
  • Fixed a memory leak where stylesheet parsing retained the last parsed stylesheet's window after window.close().
  • Fixed memory growth from long-lived MutationObserver instances retaining bookkeeping for garbage-collected nodes. (@​scttcper)
  • Fixed retained select.selectedOptions collections becoming stale after selection changes and form resets.
  • Fixed rejection of negative CSS sizing values, including for 'min-width', 'min-height', 'max-width', and 'max-height', which regressed in v30.1.0.
  • Fixed handling of deeply nested color-mix() expressions, including exceptions during color resolution. (@​asamuzaK)
Commits
  • a23bfb7 30.1.2
  • 64a75d2 Update dependencies and dev dependencies
  • 7bf9653 Invalidate styles after CSSOM and control state changes
  • fe9009c Update focused area handling
  • a8d28b3 Release windows retained by stylesheet parsing
  • 05a2c01 Deduplicate generated CSS property metadata
  • 1efa190 Reduce generated CSS property data
  • a372e12 Avoid Document named-property rebuilds after irrelevant tree mutations
  • b2cd235 Update css-color
  • 0542d2b Release idle MutationObserver bookkeeping
  • Additional commits viewable in compare view

Updates oxlint from 1.86.0 to 1.87.0

Release notes

Sourced from oxlint's releases.

oxlint v1.87.0

🚀 Features

  • 42dcfd2 linter/react/no-unescaped-entities: Implement suggestion (#27292) (Mikhail Baev)
  • cd4510d linter/unicorn/no-useless-switch-case: Implement suggestion (#27245) (Mikhail Baev)
  • 1a7c902 linter/react/jsx-no-target-blank: Implement suggestion (#27181) (Mikhail Baev)

🐛 Bug Fixes

  • 176b4b9 linter/jsx-a11y/label-has-associated-control: Validate label attribute values (#27302) (sama Pyb)
  • 7d381c3 linter/jsx-a11y/mouse-events-have-key-events: Handle nullish event handlers (#27306) (sama Pyb)
  • 4e09837 linter/jsx-a11y/lang: Validate lang expression strings (#27304) (sama Pyb)
  • 7d28a66 linter/unicorn/numeric-separators-style: Report misgrouped BigInt literals (#27207) (breken)
  • e928322 linter/unicorn/no-zero-fractions: Parenthesize separator and large integers in fixer (#27206) (breken)
  • 3d61a59 parser: Validate TypeScript type member separators (#27222) (camc314)
  • f08236b linter/eslint/prefer-exponentiation-operator: Preserve autofix precedence (#27150) (camc314)
  • 7d60ae3 linter/valid-title: Continue checks after allowed words (#27146) (Cameron)
  • ad5dd5d linter/eslint/no-unused-vars: Respect disabled argument checks for used ignore patterns (#26925) (camc314)
Changelog

Sourced from oxlint's changelog.

Changelog

All notable changes to this package will be documented in this file.

The format is based on Keep a Changelog.

Commits

Updates shadcn from 4.21.0 to 4.21.4

Release notes

Sourced from shadcn's releases.

shadcn@4.21.4

Patch Changes

shadcn@4.21.3

Patch Changes

shadcn@4.21.2

Patch Changes

shadcn@4.21.1

Patch Changes

... (truncated)

Changelog

Sourced from shadcn's changelog.

4.21.4

Patch Changes

4.21.3

Patch Changes

4.21.2

Patch Changes

4.21.1

Patch Changes

... (truncated)

Commits
  • 3464245 chore(release): version packages (#12159)
  • 76fd499 fix(registry): drop the ts-morph dependency (#12189)
  • efa1178 fix(registry): rewrite and crawl imports without ts-morph (#12188)
  • e8c3143 fix(registry): edit tailwind.config without ts-morph (#12177)
  • d51870f chore(release): version packages (#12152)
  • dba2716 chore(release): version packages (#12141)
  • 95efb5c fix(registry): read components.json and package.json without cosmiconfig (#12...
  • 3b1ae6e fix(registry): skip npm audit and fund when installing dependencies (#12140)
  • 3502dbc chore(release): version packages (#12063)
  • bf6646b feat(registry): extract @​shadcn/registry from shadcn (#12087)
  • Additional commits viewable in compare view

Updates vite from 8.3.1 to 8.3.3

Release notes

Sourced from vite's releases.

v8.3.3

Bug Fixes

  • deps: update launch-editor to v2.14.2 (#23654) (22fd1d5)
  • html: filename passed to transformIndexHtml should not include queries (#23653) (7dafd8e)
  • server: check fs.serve for ?vite-wasm-instance (#23655) (ba8b7ab)
  • server: store ids to safeModulePaths rather than URLs (#23656) (c3e06f9)

v8.3.2

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Changelog

Sourced from vite's changelog.

8.3.3 (2026-10-06)

Bug Fixes

  • deps: update launch-editor to v2.14.2 (#23654) (22fd1d5)
  • html: filename passed to transformIndexHtml should not include queries (#23653) (7dafd8e)
  • server: check fs.serve for ?vite-wasm-instance (#23655) (ba8b7ab)
  • server: store ids to safeModulePaths rather than URLs (#23656) (c3e06f9)

8.3.2 (2026-10-01)

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Commits
  • fea5b21 release: v8.3.3 (#23657)
  • c3e06f9 fix(server): store ids to safeModulePaths rather than URLs (#23656)
  • ba8b7ab fix(server): check fs.serve for ?vite-wasm-instance (#23655)
  • 22fd1d5 fix(deps): update launch-editor to v2.14.2 (#23654)
  • 7dafd8e fix(html): filename passed to transformIndexHtml should not include queries (...
  • 1003321 release: v8.3.2 (#23623)
  • 24bd331 fix(worker): align worker urls in client and server when using terser (#23614)
  • 94d0080 perf: only register time middleware when debug logging is enabled (#23621)
  • 89574f6 perf: avoid encoding intermediate source maps (#23461)
  • 5a3a010 fix(server): release previous environments after initialization (#23499)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-development group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.1.1` | `6.1.2` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.1` | `30.1.2` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.86.0` | `1.87.0` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn) | `4.21.0` | `4.21.4` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.3` |


Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitejs/plugin-react` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.2/packages/plugin-react)

Updates `jsdom` from 30.1.1 to 30.1.2
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.1...v30.1.2)

Updates `oxlint` from 1.86.0 to 1.87.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.87.0/npm/oxlint)

Updates `shadcn` from 4.21.0 to 4.21.4
- [Release notes](https://github.com/shadcn-ui/ui/releases)
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.21.4/packages/shadcn)

Updates `vite` from 8.3.1 to 8.3.3
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.3/packages/vite)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: jsdom
  dependency-version: 30.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: oxlint
  dependency-version: 1.87.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: shadcn
  dependency-version: 4.21.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: vite
  dependency-version: 8.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from htcom-code as a code owner October 10, 2026 23:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants