build(deps): bump the npm_and_yarn group across 1 directory with 24 updates - #56
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump the npm_and_yarn group across 1 directory with 24 updates#56dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
This was referenced Jul 9, 2026
…pdates --- updated-dependencies: - dependency-name: "@angular/common" dependency-version: 22.0.6 dependency-type: direct:production - dependency-name: "@angular/compiler" dependency-version: 21.2.17 dependency-type: direct:production - dependency-name: "@angular/core" dependency-version: 21.2.17 dependency-type: direct:production - dependency-name: "@hono/node-server" dependency-version: 1.19.14 dependency-type: indirect - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.26.0 dependency-type: indirect - dependency-name: "@sigstore/core" dependency-version: 3.2.1 dependency-type: indirect - dependency-name: "@sigstore/verify" dependency-version: 3.1.1 dependency-type: indirect - dependency-name: fast-uri dependency-version: 3.1.3 dependency-type: indirect - dependency-name: flatted dependency-version: 3.4.2 dependency-type: indirect - dependency-name: follow-redirects dependency-version: 1.16.0 dependency-type: indirect - dependency-name: hono dependency-version: 4.12.28 dependency-type: indirect - dependency-name: immutable dependency-version: 5.1.9 dependency-type: indirect - dependency-name: ip-address dependency-version: 10.2.0 dependency-type: indirect - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect - dependency-name: piscina dependency-version: 5.2.0 dependency-type: indirect - dependency-name: postcss dependency-version: 8.5.16 dependency-type: direct:development - dependency-name: qs dependency-version: 6.15.3 dependency-type: indirect - dependency-name: rollup dependency-version: 4.60.2 dependency-type: indirect - dependency-name: sigstore dependency-version: 4.1.1 dependency-type: indirect - dependency-name: tar dependency-version: 7.5.19 dependency-type: indirect - dependency-name: tmp dependency-version: 0.2.7 dependency-type: indirect - dependency-name: undici dependency-version: 6.27.0 dependency-type: indirect - dependency-name: vite dependency-version: 7.3.5 dependency-type: indirect - dependency-name: yaml dependency-version: 2.9.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/npm_and_yarn-b88b48ada5
branch
from
July 13, 2026 03:03
2a3c329 to
0428750
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 13 updates in the / directory:
21.1.222.0.621.1.221.2.1721.1.221.2.178.5.68.5.161.19.91.19.141.25.21.26.03.0.33.1.33.3.23.4.21.15.91.16.00.2.30.2.74.17.234.18.16.14.16.15.32.7.02.9.0Updates
@angular/commonfrom 21.1.2 to 22.0.6Release notes
Sourced from @angular/common's releases.
... (truncated)
Changelog
Sourced from @angular/common's changelog.
... (truncated)
Commits
748faa4docs(docs-infra): Add build-time validation for API and guide links using rou...8e6d7f7fix(router): use safe hasOwnProperty when parsing query paramseb8fb9ffix(common): use Object.hasOwn in I18nSelectPipe to handle null-prototype and...cd8f472docs: add documentation for HttpClient response body size limit and related e...8cdc202fix(http): prevent caching of responses with Set-Cookie headers6867f77fix(http): distinguish repeated transfer cache params6c1f3e9fix(common): skip transfer cache for uncacheable HTTP traffic (#69316)7ef1399fix(http): skip transfer cache for fetch credentialed requests (#69316)94ea403fix(common): escape anchor fragment in shadow DOM name selector2dd65d2fix(http): pass down thereportUploadProgressandreportDownloadProgress...Updates
@angular/compilerfrom 21.1.2 to 21.2.17Release notes
Sourced from @angular/compiler's releases.
... (truncated)
Changelog
Sourced from @angular/compiler's changelog.
... (truncated)
Commits
dc9c996fix(compiler): sanitize two-way propertiesae1c8a1fix(compiler): move projection attributes into constantseb1cbbffix(compiler): prevent namespaced SVG <style> elements from being stripped29ceeffdocs: fix typos in source code comments782e015fix(compiler): strip namespaced SVG script elements during template compilati...ff12fe5fix(core): normalize tag names in runtime i18n attribute security context loo...0b07f47fix(compiler): normalize tag names with custom namespaces in DomElementSchema...cc1378dfix(compiler): sanitize dynamic href and xlink:href bindings on SVG a element...daaf329fix(core): support prefix-insensitive DOM schema lookups and compile-time i18...68282dffix(compiler): strip namespaced SVG script elements during template compilationUpdates
@angular/corefrom 21.1.2 to 21.2.17Release notes
Sourced from @angular/core's releases.
... (truncated)
Changelog
Sourced from @angular/core's changelog.
... (truncated)
Commits
88832c8fix(core): validate lowercase SVG animation attribute names (#69269)3551074fix(platform-server): harden platform location origin validation during SSRbc55749fix(common): use cryptographically secure SHA-256 for transfer cache key gene...d846326fix(common): skip transfer cache for uncacheable HTTP traffice245d40fix(http): skip transfer cache for fetch credentialed requests1523061fix(core): harden TransferState restoration against DOM clobbering736c4abrefactor(core): fix broken unit test.3fd6897fix(core): harden inherit definition feature against polluted prototypes7e38336fix(core): use Object.create(null) for LOCALE_DATA as a hardening measure29ceeffdocs: fix typos in source code commentsUpdates
postcssfrom 8.5.6 to 8.5.16Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
92ccc93Release 8.5.16 version818bdd6Update formatting46e4510FixInput#origin()returning incorrect position (#2036)34942ceFix testsd4feed6Don't clone root-less child nodes in container constructor (#2097)da323fcRevert version update to fix old Node.js on CI8863369Update dependencies3828982Preserve node raws when rehydrating a JSON AST (#2100)d1e80b8Fix Node#rangeBy() ignoring index 0 (#2091)b91e4a6Fix Node.js 26 testsMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.
Updates
@hono/node-serverfrom 1.19.9 to 1.19.14Release notes
Sourced from @hono/node-server's releases.
Commits
b5e63a31.19.14c02d777fix: add custom inspect to lightweight Request/Response to prevent TypeError ...fd64e651.19.13025c30fMerge commit from fork6cdb5a71.19.1270250f7fix: request draining for early 413 responses (#329)cfc08b3chore: ignore claude setting (#314)ecd4d6b1.19.11c944899fix: do not overwrite Content-Length in the fast path pattern if Content-Leng...2f8ca361.19.10Updates
@modelcontextprotocol/sdkfrom 1.25.2 to 1.26.0Release notes
Sourced from @modelcontextprotocol/sdk's releases.
Commits
fe9c07bchore: bump version to 1.26.0 (#1479)4f01e7efix: add non-null assertions for optional setupServer fields in stateful testa05be17Merge commit from fork50d9fa3Fix #1430: Client Credentials providers scopes support (backported) (#1442)aa81a66fix(deps): resolve npm audit vulnerabilities and bump dependencies (v1.x back...6aba065chore: bump v1.25.3 for backport fixes (#1412)6e8f7e1fix: prevent Hono from overriding global Response object (v1.x) (#1411)12ae856[v1.x backport] Use correct schema for client sampling validation when tools ...Updates
@sigstore/corefrom 3.1.0 to 3.2.1Release notes
Sourced from @sigstore/core's releases.
Commits
c1dc7d4Version Packages (#1607)f074710reject integratedTime w/o inclusionPromise (#1659)7845532OID certificate extension verification (#1658)b5aa4f1proper utf-8 encoding in DSSE PAE (#1657)c7a34e0clarify cert ID matching (#1656)9858bd7Upgrade TypeScript to 6.x (#1655)8cef20dbump qs from 6.15.1 to 6.15.2 (#1654)aca341bbump@sigstore/mockdeps (#1653)0855acaPin all@swc/coreplatform binaries as optionalDependencies (#1652)44a374dPin all@swc/coreplatform binaries as optionalDependencies (#1650)Updates
@sigstore/verifyfrom 3.1.0 to 3.1.1Release notes
Sourced from @sigstore/verify's releases.
Commits
c1dc7d4Version Packages (#1607)f074710reject integratedTime w/o inclusionPromise (#1659)7845532OID certificate extension verification (#1658)b5aa4f1proper utf-8 encoding in DSSE PAE (#1657)c7a34e0clarify cert ID matching (#1656)9858bd7Upgrade TypeScript to 6.x (#1655)8cef20dbump qs from 6.15.1 to 6.15.2 (#1654)aca341bbump@sigstore/mockdeps (#1653)0855acaPin all@swc/coreplatform binaries as optionalDependencies (#1652)44a374dPin all@swc/coreplatform binaries as optionalDependencies (#1650)Updates
fast-urifrom 3.0.3 to 3.1.3Release notes
Sourced from fast-uri's releases.