Skip to content

chore(deps-dev): bump the npm-dev-dependencies group across 1 directory with 18 updates - #92

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dev-dependencies-0df81b0ad3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dev-dependencies-0df81b0ad3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-dev-dependencies group with 18 updates in the / directory:

Package From To
@playwright/test 1.61.1 1.63.0
@rolldown/plugin-babel 0.2.3 0.2.4
@tanstack/router-plugin 1.168.22 1.168.41
@testing-library/jest-dom 6.9.1 7.0.1
@testing-library/react 16.3.2 16.3.3
@testing-library/user-event 14.6.1 14.6.7
@types/google.maps 3.65.2 3.66.4
@types/node 26.1.1 26.6.3
@vitejs/plugin-react 6.0.3 6.1.1
fallow 3.6.0 3.30.0
jsdom 29.1.1 30.1.1
lefthook 2.1.10 2.1.14
oxfmt 0.59.0 0.70.0
oxlint 1.74.0 1.85.0
tsx 4.23.1 4.23.15
vite 8.1.5 8.3.1
vitest 4.1.10 5.0.2
zod 4.4.3 4.6.5

Updates @playwright/test from 1.61.1 to 1.63.0

Release notes

Sourced from @​playwright/test's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates @rolldown/plugin-babel from 0.2.3 to 0.2.4

Release notes

Sourced from @​rolldown/plugin-babel's releases.

plugin-babel@0.2.4

Please refer to CHANGELOG.md for details.

Changelog

Sourced from @​rolldown/plugin-babel's changelog.

0.2.4 (2026-09-07)

Bug Fixes

Miscellaneous Chores

Commits
  • 49dc455 release: plugin-babel@0.2.4
  • 249a7d2 fix(babel): set inputSourceMap: false to avoid combining source map twice (...
  • c0365e0 chore(deps): update rolldown-related dependencies (#128)
  • 6373896 fix(deps): update all non-major dependencies (#124)
  • 6b89bca chore(deps): update all non-major dependencies (#106)
  • fa5b6df fix(deps): update all non-major dependencies (#99)
  • 59dcaf4 chore(deps): update all non-major dependencies (#92)
  • b73d0dd chore(deps): update all non-major dependencies (#90)
  • 0032957 fix(deps): update all non-major dependencies (#88)
  • d717e25 chore: use pnpm catalog for some packages (#82)
  • Additional commits viewable in compare view

Updates @tanstack/router-plugin from 1.168.22 to 1.168.41

Release notes

Sourced from @​tanstack/router-plugin's releases.

@​tanstack/router-plugin@​1.168.41

Patch Changes

Changelog

Sourced from @​tanstack/router-plugin's changelog.

1.168.41

Patch Changes

1.168.40

Patch Changes

1.168.39

Patch Changes

1.168.38

Patch Changes

1.168.37

Patch Changes

1.168.36

... (truncated)

Commits

Updates @testing-library/jest-dom from 6.9.1 to 7.0.1

Release notes

Sourced from @​testing-library/jest-dom's releases.

v7.0.1

7.0.1 (2026-08-09)

Bug Fixes

  • declare vitest as an optional peer dependency (#733) (3782c78)

v7.0.0

7.0.0 (2026-07-20)

Features

  • add toContainAnyBy* and toContainOneBy* query matchers (1e39089)

BREAKING CHANGES

  • @​testing-library/dom is now a required peer dependency. The minimum supported Node.js version is now 22.

Repaired release for testing-library/jest-dom#731

v6.10.0

6.10.0 (2026-07-20)

Features

  • add toContainAnyBy* and toContainOneBy* query matchers (#731) (cae44df)
Commits
  • 3782c78 fix: declare vitest as an optional peer dependency (#733)
  • 1e39089 feat: add toContainAnyBy* and toContainOneBy* query matchers
  • cae44df feat: add toContainAnyBy* and toContainOneBy* query matchers (#731)
  • 55c07ce ci: switch release to npm trusted publishing (#726)
  • 213256f docs: move toHaveSelection from the deprecated section (#717)
  • See full diff in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​testing-library/jest-dom since your current version.


Updates @testing-library/react from 16.3.2 to 16.3.3

Release notes

Sourced from @​testing-library/react's releases.

v16.3.3

16.3.3 (2026-08-27)

Bug Fixes

  • Avoid act() re-entrant when dispatching events (#1468) (20ce75f)
Commits

Updates @testing-library/user-event from 14.6.1 to 14.6.7

Release notes

Sourced from @​testing-library/user-event's releases.

v14.6.7

14.6.7 (2026-09-02)

Bug Fixes

  • normalize DataTransfer format aliases (#1326) (1e0020b)
  • feature: Add iframe support for user.keyboard typing (#1275) (1e0020b)

v14.6.6

14.6.6 (2026-08-22)

Bug Fixes

  • default pointer event pointerType to empty string instead of the string "undefined" (#1325) (71a5475)

v14.6.5

14.6.5 (2026-08-18)

Bug Fixes

  • tab retargeting if focus moved during keydown (#1296) (43efda7)

v14.6.4

14.6.4 (2026-08-11)

Bug Fixes

v14.6.3

14.6.3 (2026-08-03)

Bug Fixes

v14.6.2

14.6.2 (2026-08-03)

Commits
  • 1e0020b fix: normalize DataTransfer format aliases (#1326)
  • d4b0593 feature: Add iframe support for user.keyboard typing (#1275)
  • 71a5475 fix: default pointer event pointerType to empty string instead of the string ...
  • 43efda7 fix: tab retargeting if focus moved during keydown (#1296)
  • d7e80e3 fix: keyboard event repeat property (#1312)
  • 43d8e6c ci: remove broken npm backfill step (#1322)
  • 1d18b1f fix(release): manually release a patch version (#1321)
  • 232f3e6 docs: add migration note and clean up README badges (#1320)
  • 83e2b22 ci: remove deprecated CodeSandbox CI (#1318)
  • e8da819 ci: publish to npm via OIDC trusted publishing (#1317)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​testing-library/user-event since your current version.


Updates @types/google.maps from 3.65.2 to 3.66.4

Commits

Updates @types/node from 26.1.1 to 26.6.3

Commits

Updates @vitejs/plugin-react from 6.0.3 to 6.1.1

Release notes

Sourced from @​vitejs/plugin-react's releases.

plugin-react@6.1.1

Add compiler.logDiagnostics option

Recoverable React Compiler diagnostics are no longer logged by default. Set compiler.logDiagnostics to true to log them through Vite. Fatal diagnostics are always logged and fail the transform.

Respect environment sourcemap option for React Compiler transform when builder.sharedPlugins is enabled (#1439)

The React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental builder.sharedPlugins was enabled.

plugin-react@6.1.0

Add experimental native React Compiler support (#1419)

Add experimental native React Compiler support.

You can use it by installing oxc-transform-react and enabling it via the compiler option:

npm install -D oxc-transform-react
import { defineConfig } from 'vite'
import react from '@vitejs/plugin-react'
export default defineConfig({
plugins: [
react({ compiler: true })
]
})

plugin-react@6.0.5

Fixed the react compiler preset filter to be linear (#1353)

The improved filter in v6.0.3 was non-linear and caused a performance regression (#1349). The filter was changed to be linear to avoid that.

plugin-react@6.0.4

Fixed $RefreshSig$ is not defined error when running vite dev with NODE_ENV=production

When running vite dev with NODE_ENV=production, the app errored with $RefreshSig$ is not defined. This error is now fixed.

Changelog

Sourced from @​vitejs/plugin-react's changelog.

6.1.1 (2026-08-28)

Add compiler.logDiagnostics option

Recoverable React Compiler diagnostics are no longer logged by default. Set compiler.logDiagnostics to true to log them through Vite. Fatal diagnostics are always logged and fail the transform.

Respect environment sourcemap option for React Compiler transform when builder.sharedPlugins is enabled (#1439)

The React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental builder.sharedPlugins was enabled.

6.1.0 (2026-08-19)

Add experimental native React Compiler support (#1419)

Add experimental native React Compiler support.

You can use it by installing oxc-transform-react and enabling it via the compiler option:

npm install -D oxc-transform-react
import { defineConfig } from 'vite'
import react from '@vitejs/plugin-react'
export default defineConfig({
plugins: [
react({ compiler: true })
]
})

6.0.5 (2026-07-30)

Fixed the react compiler preset filter to be linear (#1353)

The improved filter in v6.0.3 was non-linear and caused a performance regression (#1349). The filter was changed to be linear to avoid that.

6.0.4 (2026-07-22)

Fixed $RefreshSig$ is not defined error when running vite dev with NODE_ENV=production

When running vite dev with NODE_ENV=production, the app errored with $RefreshSig$ is not defined. This error is now fixed.

Commits
  • 04cac50 release: plugin-react@6.1.1 (#1440)
  • 82d35ab fix(react): respect environment sourcemap option when builder.sharedPlugins...
  • 397e847 fix(react): make logging diagnostics an opt-in for React Compiler (#1431)
  • 61006e6 fix(deps): update all non-major dependencies (#1433)
  • e2a649c chore: use deps.neverBundle instead of external in tsdown config (#1430)
  • fb2d6f3 fix(deps): update all non-major dependencies (#1427)
  • 39b3173 release: plugin-react@6.1.0 (#1428)
  • f1340b0 feat(react): add native React Compiler support (#1419)
  • 9ab698e fix(deps): update all non-major dependencies (#1375)
  • 68c0cb8 release: plugin-react@6.0.5 (#1362)
  • Additional commits viewable in compare view

Updates fallow from 3.6.0 to 3.30.0

Release notes

Sourced from fallow's releases.

v3.30.0: flag retirement report, startup import weight, faster language server, Oxc 0.151

Features

  • fallow flags --retirement reports the flags that you can retire. Each row groups every site of one flag and lists the reasons to remove it. The reasons are single-read-site, test-only, literal-constant, identical-branches, empty-branch, guards-dead-code and defined-never-read. The literal-constant reason adds the new kind constant for a flag-prefixed module-level const with a literal value, such as const FEATURE_NEW_UI = true. A guard in the same module must test the flag. These flags are in the retirement report only, not in feature_flags[]. The defined-never-read reason also covers a Vercel flag() definition with an unused export, and an unused member of a flag registry enum. The reasons come from the code only, so they do not show the production state of the flag.
  • The retirement report works in every fallow flags format and gives each flag an age from git. JSON adds a top-level retirement object, and human and markdown output add a "Retirement candidates" section. Compact adds flag-retire: lines, SARIF adds the rule fallow/flag-retirement-candidate at level note, and CodeClimate adds fallow/flag-retirement issues. --flag-age blame (the default), --flag-age pickaxe and --flag-age off set how Fallow measures the age. --reason, --min-age, --sort age|sites|name and --top filter and order the rows. Fallow removes no code. Every action has auto_fixable: false. fallow explain flag-retirement describes the rule.
  • fallow flags --retirement --flag-state <FILE> compares the code with a vendor flag export. The file is a local JSON file with one vendor-neutral schema, and Fallow reads it offline without credentials or network calls. The export adds the reasons fully-rolled-out, archived-in-vendor, missing-in-vendor and vendor-only. The vendor-only rows do not count in summary.distinct_flags. The new flags.vendorKeyPrefix config key removes a prefix from each vendor key before the match. An invalid file, or a file larger than 16 MiB, exits with code 2 and the error code FALLOW_FLAG_STATE_INVALID.
  • fallow flags --retirement can gate CI on flag counts and flag age. --save-regression-baseline <PATH> writes a baseline with a new flags section. --fail-on-regression --regression-baseline <PATH> exits with code 1 when distinct_flags grows more than --tolerance. --max-flag-age <DAYS> exits with code 1 when a flag in scope is older than that limit. Each gate reports a status of pass, exceeded or skipped, and prints the result to stderr in every format. A run with --changed-since or --workspace skips the regression gate and saves no baseline. Without --retirement, the regression options have no effect on fallow flags, and the command prints a warning.
  • The MCP feature_flags tool and the Rust API can return the retirement report. The MCP tool adds the retirement, flag_state and flag_age parameters. FeatureFlagsOptions adds a retirement field. The CLI and the API build the report with the same engine function, so the retirement block is the same on both. The regression gates stay CLI only.
  • fallow flags finds more flag reads. The scan now reports import.meta.env.X reads, and SDK calls with a registry member as the name, such as useFlag(FLAGS.NewCheckout). It also finds flag reads inside a larger if or ternary test, such as if (process.env.FEATURE_X === 'true'). Flags in .js files with JSX now match custom sdkPatterns and envPrefixes. More flag reads now have a guard, so dead_code_overlap can find more unused exports.
  • fallow list --entry-weight reports the startup import weight of each runtime entry point. The report counts the project modules and the source bytes that load before the entry runs. It splits the modules into eager, deferred and out of thread, and lists the packages on the startup path. The unit is source bytes on disk, so the value is not a bundle size. The output is human or JSON (entry_weight in fallow list --format json). The health score does not change.
  • An opt-in regression gate for the startup import weight. fallow list --entry-weight --save-regression-baseline <PATH> writes the eager bytes, modules and packages of each entry into the baseline file. A later run with --regression-baseline <PATH> reports the change of each entry and the new eager packages. Add --fail-on-regression to exit 1 when an entry grows more than --tolerance. A new entry never fails the gate. fallow dead-code --save-regression-baseline <PATH> now keeps the entry weights in the same file.
  • fallow trace --path and fallow viz show dynamic imports. Each hop in the trace JSON has a new dynamic field, and the human output tags such a hop [dynamic]. With --eager-only, the trace follows static value imports only. A new edge flag bit (2) marks a lazy edge. The focus view draws it with a short dash.
  • Built-in Waku plugin. The waku plugin activates from the waku dependency and follows the managed-mode file router. Every module under <srcDir>/pages is an entry, except modules in _components, _hooks and _actions folders. The plugin reads srcDir from waku.config.*, with src as the default. Thanks @​aheissenberger for the contribution (#2921).
  • The language server can parse the project before the first open. Set the initialization option prewarm to true. At initialized, the server then loads the project session and parses the files, but analyzes and publishes nothing. The option is off by default and needs kept project sessions and a workspace root with a package.json.
  • --performance reports exact work counts, the time outside the pipeline and a span tree. The dead-code timings gain a counters object with counts that do not change with the thread count or the machine. A standalone dead-code run adds a process object and a Process section with a WALL row. The new spans array gives the parent of each stage and marks concurrent spans. Health --performance adds git_log_bytes, and the parse cache load gets its own parse_cache_load_ms field.
  • Runtime hot paths show where speed work gives the largest gain. Each entry in runtime_coverage.hot_paths now has an optimization_target block. The block holds cost_score, cost_basis, inner_iterations_per_call, cognitive, cyclomatic and line_count. Compare cost_score only between hot paths with the same cost_basis. The human output, --explain and the MCP get_hot_paths tool show the same fields.

Performance

  • Import resolution, stylesheet scans and coverage remaps do less work. Each specifier in a file now resolves once, not once for each imported binding. A stylesheet is masked for comments one time, and the health --css token scans count lines in one pass. Runtime coverage indexes each source-mapped script one time and finds each offset with a binary search. The findings do not change.
  • The language server keeps its project session between saves. A save now parses only the files that changed, and the other modules come from memory. A change to a config input, such as package.json, a lockfile, a tsconfig file or a rule pack, loads the session again. On a platform without a file change time, such as Windows, each run reads the persisted parse cache as before. The server keeps sessions while their estimated memory is at most 512 MB in total. Set FALLOW_LSP_REUSE_SESSION=0 to load a new session on each run.
  • The language server does less work for each analysis run. It publishes only the diagnostics that changed, and converts diagnostic columns in linear time. It reads an open file only when the buffer can differ from disk. Under autosave, a newer event cancels the run in flight, and the run after a cancelled one always finishes and publishes.
  • Typed MCP tool calls share parsed modules. A later call on the same unchanged files takes the modules from memory. For the sequence analyze, find_dupes, check_health, trace_file, run two times, the parse passes go from 6 to 1. The answers do not change. The store keeps at most 4 file lists and about 512 MiB of parsed modules. It does not keep a project with more than about 40 MiB of source. To stop the reuse, set FALLOW_MCP_WARM_SESSION=0.
  • fallow flags parses each file once with a custom flags config. Before, sdkPatterns, envPrefixes or configObjectHeuristics made the command parse every file a second time. The command also matches guarded flags to unused exports by file and line. The dead_code_overlap output does not change.
  • Fallow starts fewer git processes. A run without --diff-file, --diff-stdin or FALLOW_DIFF_FILE no longer calls git rev-parse for the diff base directories. The Impact project identity reads the git common directory and the toplevel with one call in a work tree.
  • The VS Code extension no longer searches the workspace for manifests at startup. It starts when the workspace root has a package.json or a Fallow config file. It also starts when a JavaScript, TypeScript, Vue, Svelte, Astro or MDX file opens. A monorepo folder with no root package.json now starts the extension when the first source file opens.
  • fallow viz pages load and respond faster. The page parses only the file list, the edges and the summary at start. On the Fallow repository, the data parsed at start drops from 2.49 MB to 64 KB. The HTML file drops from 2.8 MB to 1.9 MB. A hover on the treemap now makes 3 draw calls, not one call per tile. The page shows its frame before the script runs, so the layout does not shift.

Changed

  • fallow flags gives medium confidence to generic SDK names without a flag import. The names isEnabled, getValue and useFeature also occur in libraries that are not flag SDKs. A call to one of these names now has confidence: "medium" when its file imports no flag SDK and no flag module. Other SDK names, such as useFlag and checkGate, keep high confidence.
  • fallow flags reports config.features.x as one read. With flags.configObjectHeuristics on, the scan reported the full access and also the object config.features. Now it reports only the full access.
  • Oxc 0.151. The parser and AST crates move from Oxc 0.126 to 0.151, and oxc_coverage_instrument moves to 0.13. The dead-code, duplication and health output of public projects is the same as with 3.29.0.
  • fallow similar-code inspect and fallow audit use the shared test-code definition. Both now treat files under __test__/, spec/, specs/ and e2e/, and files named *.e2e.* and *.e2e-spec.*, as tests. similar-code inspect also adds *.cy.* files, and no longer lists files under __mocks__/. In fallow audit, a mock or a fixture that imports a changed file does not count as a test.

Bug fixes

  • Health hotspots tag more test files. The [test] tag and the JSON field is_test_path now use the shared test-path definition. A test/, tests/, __tests__/ or __mocks__/ directory at the project root now matches. A .test. or .spec. marker now matches only in the file name.
  • Test-path checks now classify paths relative to the project root. Before, a project inside a test-like directory lost three results. The split line with test files and source files did not show under test, tests or fixtures. The start with <file> hint of the bare fallow command named no file under tests or examples. The CVA checks lost every finding under test or tests. The split line now says M in test files, not M in test directories.
  • .cy. files and spec/ directories need more evidence to be tests. A .cy. file is now a test only in a Cypress context, so a locale file such as src/i18n/strings.cy.ts is production code. A spec or specs directory now holds tests only at a test root.
  • A plain fallow list ignores the --tolerance value. Before, an invalid value exited 2 for a plain listing. Now fallow list parses the value only for --entry-weight.
  • pnpm overrides in a two-document lockfile are no longer reported as unused. pnpm 12 writes pnpm-lock.yaml as two YAML documents when package.json sets packageManager. Fallow now reads each project document of the lockfile. Thanks @​sgaabdu4 for the report (#2909).
  • On Windows, plugin path rules skip the directories they exclude. A plugin can exclude files by a path segment, such as the TanStack Router routeFileIgnorePattern. Before, the check did not split paths on the native Windows separator, so an excluded route file was still an entry point.

Upgrade notes

  • Building fallow from source now needs Rust 1.96 or later (it was 1.92).
  • The parse, extract, graph and duplication caches rebuild once, so the first run after the upgrade parses and resolves the project again.
  • isEnabled, getValue and useFeature calls without a flag import change from high to medium confidence. To keep high confidence for your own function, add its name to flags.sdkPatterns.
  • With flags.configObjectHeuristics on, object entries such as process.features no longer show in the output.

... (truncated)

Commits
    <...

    Description has been truncated

…ry with 18 updates

Bumps the npm-dev-dependencies group with 18 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.63.0` |
| [@rolldown/plugin-babel](https://github.com/rolldown/plugins/tree/HEAD/packages/babel) | `0.2.3` | `0.2.4` |
| [@tanstack/router-plugin](https://github.com/TanStack/router/tree/HEAD/packages/router-plugin) | `1.168.22` | `1.168.41` |
| [@testing-library/jest-dom](https://github.com/testing-library/jest-dom) | `6.9.1` | `7.0.1` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |
| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.1` | `14.6.7` |
| [@types/google.maps](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/google.maps) | `3.65.2` | `3.66.4` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.6.3` |
| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.1.1` |
| [fallow](https://github.com/fallow-rs/fallow) | `3.6.0` | `3.30.0` |
| [jsdom](https://github.com/jsdom/jsdom) | `29.1.1` | `30.1.1` |
| [lefthook](https://github.com/evilmartians/lefthook) | `2.1.10` | `2.1.14` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.59.0` | `0.70.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.74.0` | `1.85.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.15` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.5` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `5.0.2` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |



Updates `@playwright/test` from 1.61.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.61.1...v1.63.0)

Updates `@rolldown/plugin-babel` from 0.2.3 to 0.2.4
- [Release notes](https://github.com/rolldown/plugins/releases)
- [Changelog](https://github.com/rolldown/plugins/blob/main/packages/babel/CHANGELOG.md)
- [Commits](https://github.com/rolldown/plugins/commits/plugin-babel@0.2.4/packages/babel)

Updates `@tanstack/router-plugin` from 1.168.22 to 1.168.41
- [Release notes](https://github.com/TanStack/router/releases)
- [Changelog](https://github.com/TanStack/router/blob/main/packages/router-plugin/CHANGELOG.md)
- [Commits](https://github.com/TanStack/router/commits/@tanstack/router-plugin@1.168.41/packages/router-plugin)

Updates `@testing-library/jest-dom` from 6.9.1 to 7.0.1
- [Release notes](https://github.com/testing-library/jest-dom/releases)
- [Changelog](https://github.com/testing-library/jest-dom/blob/main/CHANGELOG.md)
- [Commits](testing-library/jest-dom@v6.9.1...v7.0.1)

Updates `@testing-library/react` from 16.3.2 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/react-testing-library@v16.3.2...v16.3.3)

Updates `@testing-library/user-event` from 14.6.1 to 14.6.7
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](testing-library/user-event@v14.6.1...v14.6.7)

Updates `@types/google.maps` from 3.65.2 to 3.66.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/google.maps)

Updates `@types/node` from 26.1.1 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitejs/plugin-react` from 6.0.3 to 6.1.1
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react)

Updates `fallow` from 3.6.0 to 3.30.0
- [Release notes](https://github.com/fallow-rs/fallow/releases)
- [Changelog](https://github.com/fallow-rs/fallow/blob/main/release.toml)
- [Commits](fallow-rs/fallow@v3.6.0...v3.30.0)

Updates `jsdom` from 29.1.1 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v29.1.1...v30.1.1)

Updates `lefthook` from 2.1.10 to 2.1.14
- [Release notes](https://github.com/evilmartians/lefthook/releases)
- [Changelog](https://github.com/evilmartians/lefthook/blob/master/CHANGELOG.md)
- [Commits](evilmartians/lefthook@v2.1.10...v2.1.14)

Updates `oxfmt` from 0.59.0 to 0.70.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.70.0/npm/oxfmt)

Updates `oxlint` from 1.74.0 to 1.85.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.85.0/npm/oxlint)

Updates `tsx` from 4.23.1 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.1...v4.23.15)

Updates `vite` from 8.1.5 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 4.1.10 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

---
updated-dependencies:
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: "@rolldown/plugin-babel"
  dependency-version: 0.2.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dev-dependencies
- dependency-name: "@tanstack/router-plugin"
  dependency-version: 1.168.41
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dev-dependencies
- dependency-name: "@testing-library/jest-dom"
  dependency-version: 7.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dev-dependencies
- dependency-name: "@testing-library/react"
  dependency-version: 16.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dev-dependencies
- dependency-name: "@testing-library/user-event"
  dependency-version: 14.6.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dev-dependencies
- dependency-name: "@types/google.maps"
  dependency-version: 3.66.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: fallow
  dependency-version: 3.30.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dev-dependencies
- dependency-name: lefthook
  dependency-version: 2.1.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dev-dependencies
- dependency-name: oxfmt
  dependency-version: 0.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: oxlint
  dependency-version: 1.85.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dev-dependencies
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dev-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: auto-bump, deps. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from krake747 as a code owner October 1, 2026 08:18
@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for magnificent-frangollo-7954c2 ready!

Name Link
🔨 Latest commit 74aeff9
🔍 Latest deploy log https://app.netlify.com/projects/magnificent-frangollo-7954c2/deploys/6abe1762a52c99000806a3cc
😎 Deploy Preview https://deploy-preview-92--magnificent-frangollo-7954c2.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b5e142c6-79a4-45b3-a228-124b384dda7f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant