Skip to content

build(deps-dev): bump all - #1910

Merged
renovate[bot] merged 1 commit into
livefrom
renovate/all
Sep 28, 2026
Merged

renovate[bot] merged 1 commit into
livefrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update Pending
@biomejs/biome (source) 2.5.13 → 2.5.14 age adoption passing confidence devDependencies patch
@types/node (source) 24.13.4 → 24.13.6 age adoption passing confidence devDependencies patch 24.19.0
autoprefixer 10.6.0 → 10.6.1 age adoption passing confidence devDependencies patch
cssnano 9.0.4 → 9.0.5 age adoption passing confidence devDependencies patch 9.1.0
github/codeql-action v4.38.0 → v4.38.1 age adoption passing confidence action patch v4.38.2
markdownlint-cli2 0.23.2 → 0.23.3 age adoption passing confidence devDependencies patch
pnpm (source) 12.4.1 → 12.5.1 age adoption passing confidence packageManager minor 12.6.0
pnpm (source) 12.4.1 → 12.5.1 age adoption passing confidence engines minor 12.6.0
prettier (source) 3.9.6 → 3.9.8 age adoption passing confidence devDependencies patch 3.9.9
vnu-jar 26.9.7 → 26.9.16 age adoption passing confidence devDependencies patch 26.9.27

Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.14

Compare Source

Patch Changes
  • #​9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #​11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #​11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #​11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #​11461 22e9966 Thanks @​FoundDream! - Fixed #​11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #​11766 c2542c6 Thanks @​dyc3! - Fixed #​11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #​11790 17d0ff0 Thanks @​ematipico! - Fixed #​10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

  • #​11777 7ee3a6c Thanks @​ematipico! - Fixed #​7573: added the requireExplicitCase option to useExhaustiveSwitchCases. When set to true, the rule reports missing cases even when the switch has a default clause, so you can keep a runtime fallback while checking that every value in the union has its own case. The option defaults to false.

  • #​11751 d37f24b Thanks @​ematipico! - Fixed #​8347: the fix from useConsistentArrowReturn now parenthesizes returned expressions that begin with object literals before removing the arrow function body braces, preventing invalid output for expressions such as object property access.

  • #​11784 46e8912 Thanks @​dyc3! - Fixed #​11782: noUndeclaredCustomProperties could hang while checking stylesheets imported by JavaScript modules with many shared dependencies.

  • #​11731 1534885 Thanks @​ematipico! - Fixed #​7984: The fix from useSimplifiedLogicExpression now preserves line breaks in multiline conditions with line comments, preventing the right-hand side condition from being commented out.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​7304: the HTML formatter now preserves authored segment breaks between CJK characters, and next to CJK punctuation, instead of replacing them with spaces.

     <div lang="zh-Hant-TW">
    -  這個段落是那麼長, 在一行寫不行。
    +  這個段落是那麼長,
    +  在一行寫不行。
     </div>
  • #​11749 ff992a1 Thanks @​ematipico! - Fixed #​11747: formatting and checking large parenthesized object expressions no longer exhibit quadratic slowdowns.

  • #​11736 1dd1fc4 Thanks @​dyc3! - Fixed #​8177: code actions no longer modify the wrong part of Vue, Svelte, or Astro files when experimental full HTML support is disabled.

  • #​11743 3835945 Thanks @​santichausis! - Fixed #​10247: biome check --write/biome lint --write now correctly writes fixes for code inside an HTML attribute expression (for example a Svelte onclick={...} handler, or a mustache expression like {count}), instead of silently reporting the diagnostic as fixable and applying nothing.

    For example, running biome lint --write --unsafe for useBlockStatements (an unsafe fix) on this Svelte component used to leave the file unchanged:

    <button onclick={() => { if (open) close(); }}>Close</button>
  • #​11740 8ea8b4a Thanks @​dyc3! - Fixed #​11453: useConsistentTestIt now updates imports alongside calls, preserving the original export through an alias. The rule ignores locally declared functions and withholds fixes when the preferred name would conflict with another binding or global reference.

  • #​11355 27177ca Thanks @​dyc3! - Fixed the HTML formatter incorrectly applying native HTML element formatting to PascalCase component names such as <Ul> and <Body> in Vue, Svelte, and Astro files.

    -<Body>
    -  <div>content</div>
    -</Body>
    +<Body><div>content</div></Body>
  • #​11355 27177ca Thanks @​dyc3! - Fixed the HTML formatter incorrectly applying SVG block formatting to unknown elements whose names matched SVG element names.

    -<foreignobject>
    -  <div>content</div>
    -</foreignobject>
    +<foreignobject><div>content</div></foreignobject>
  • #​11741 fc69047 Thanks @​dyc3! - Fixed #​8893: useImportExtensions no longer suggests adding .ts to .jsx imports when a colocated .d.ts file provides type declarations.

  • #​11642 c87341c Thanks @​dyc3! - Added the nursery rule useConsistentFunctionStyle, which requires a consistent style for defining functions.

    By default, the rule reports the following declaration because it requires a function expression assigned to a variable:

    function greet() {
        return "Hello";
    }
  • #​11770 ddfd622 Thanks @​dyc3! - Fixed #​8980: suppression comments targeting the entire assist category are now respected, including biome-ignore-all assist when running check.

  • #​11792 7a4b895 Thanks @​dyc3! - Fixed dashed utility base names in the Tailwind parser, including border-bs, font-features, and scrollbar-thumb. Classes such as min-inline-[12rem] now preserve the complete base name and parse the arbitrary value separately.

  • #​11739 1fc17e3 Thanks @​Netail! - The rule useIncludes now also reports lastIndexOf() comparisons and some() calls with a strict-equality callback.

    arr.lastIndexOf(x) !== -1
    
    arr.some(item => item === x)
  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​6888. GritQL plugins can now use contains on import-clause metavariables such as $clause in import $clause from "module" patterns.

  • #​11790 17d0ff0 Thanks @​ematipico! - Fixed #​11786: useAnchorContent now reports anchors without accessible content in HTML, Astro, Vue, and Svelte even when they have an aria-label, aria-labelledby, or title attribute, matching JSX behavior.

  • #​11651 a9c4aa0 Thanks @​saberoueslati! - Added the new nursery rule noVueUndeclaredDirectives, which reports custom Vue directives that are not declared by a <script setup> binding, the component's directives option, or the rule's globals option. Closes #​11478.

    <template>
      <!-- v-highlight is not declared anywhere -->
      <div v-highlight></div>
    </template>

    Aliased named imports in single-file components are now tracked under their local name, so noUndeclaredVariables recognizes vHighlight in import { highlight as vHighlight } from "./directives".

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7795. The noJsxLiterals rule now ignores surrounding whitespace when matching literals against allowedStrings.

  • #​11780 99c7049 Thanks @​ematipico! - Fixed false positives in useExhaustiveSwitchCases when numeric cases use different spellings of the same value. For example, case 0x1 now covers the numeric literal type 1.

  • #​11720 c7c4e2b Thanks @​ematipico! - Fixed #​7880: noUselessStringConcat no longer reports literal concatenations split across multiple lines when a numeric literal ends the chain.

  • #​11355 27177ca Thanks @​dyc3! - Improved performance of the HTML formatter for documents that contain many HTML-native or SVG-native tags.

  • #​11720 c7c4e2b Thanks @​ematipico! - Fixed #​7949: useReadonlyClassProperties now reports static class properties that are never reassigned.

  • #​11751 d37f24b Thanks @​ematipico! - Fixed #​7644: useImportExtensions now resolves path aliases declared by referenced TypeScript project configurations.

  • #​11791 f88793c Thanks @​dyc3! - Fixed a false positive in useTailwindShorthandClasses for strings in conditional tests, such as cn(m === "w-2 h-2" ? "bg-red-800" : "bg-red-400").

  • #​11720 c7c4e2b Thanks @​ematipico! - Fixed #​7783: noNoninteractiveElementInteractions no longer reports event handlers on native <dialog> elements.

  • #​11733 7030068 Thanks @​dyc3! - Fixed #​11730: useExhaustiveSwitchCases reports missing cases when iterating over a class property with for...of.

  • #​11717 2107dae Thanks @​ternaus! - Fixed #​11716: the noUnknownAttribute rule now accepts fullscreen event handlers, the credentialless iframe property, and the SVG maskType property when the React dependency range allows React 19.3 or later. The credentialless and maskType properties are restricted to <iframe> and <mask> elements, respectively.

  • #​11737 b7e3559 Thanks @​dyc3! - Fixed #​11692: noFloatingPromises now detects unhandled promises returned through generic method signatures, including Playwright fixtures.

  • #​11780 99c7049 Thanks @​ematipico! - Fixed #​7747: useExhaustiveSwitchCases now reports missing cases for literal unions derived from const tuples with (typeof values)[number] and objects with keyof typeof object.

    Other type-aware rules, including noFloatingPromises and noUselessTypeConversion, also recognize supported indexed-access results.

  • #​11724 a9a5e9a Thanks @​dyc3! - Fixed redundant parentheses around binary and logical unary operands with leading line comments.

     !(
       // leading
    -  (a || b)
    +  a || b
     );
  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7722: noUnusedImports no longer reports type-only imports used in computed names of declared class properties.

  • #​11731 1534885 Thanks @​ematipico! - Fixed #​6390: Biome now offers suppression actions for noDynamicNamespaceImportAccess in editors.

  • #​11751 d37f24b Thanks @​ematipico! - Fixed #​7533: noDescendingSpecificity no longer compares selector specificity across separate cascade layer blocks.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​6206: useUniqueElementIds no longer reports static IDs on elements in SVG contexts.

    <svg>
        <defs>
            <pattern id="dots" width="10" height="10" />
        </defs>
        <rect fill="url(#dots)" width="100%" height="100%" />
    </svg>
  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​5447, so the GitHub reporter now associates annotations with the correct files when Biome runs from a nested directory.

  • #​11720 c7c4e2b Thanks @​ematipico! - Fixed #​7816: useHookAtTopLevel no longer reports methods named like hooks when called on another function's result, such as Reactotron.configure(...).useReactNative(...).

  • #​11355 27177ca Thanks @​dyc3! - Removed special HTML formatter handling for the obsolete <listing> element.

  • #​11731 1534885 Thanks @​ematipico! - Fixed an issue where Grit plugin code fixes weren't available as editor code actions.

  • #​11726 dea163f Thanks @​dyc3! - Fixed #​11722: the JavaScript formatter inserts a newline before the closing angle bracket when a leading comment forces type arguments onto multiple lines.

     type Foo = Record<
       // comment
       string,
    -  number>;
    +  number
    +>;
  • #​9758 02ea438 Thanks @​Netail! - Added the nursery rule noJsonUnsafeValues, which disallows JSON values that are unsafe to use between different tools or languages.

    Invalid:

    [
      2e308, // Number evaluating to Infinity
      -2e308, // Number evaluating to -Infinity
      "\ud83d", // String with lone surrogate
      1e-400, // Unsafe zero (too small, will evaluate to 0)
      9007199254740992, // Unsafe integer (outside safe integer range)
      2.2250738585072009e-308, // Subnormal number
    ]
  • #​11790 17d0ff0 Thanks @​ematipico! - Fixed #​8574: the JavaScript formatter sometimes added extra parentheses and moved comments when formatting multiline expressions after operators such as !. Comments now stay beside the values they describe, without an extra pair of parentheses.

     !(
    -  (
    -    cond1 || // force this to be multi line
    -    cond3
    -  ) // comment
    +  cond1 || // force this to be multi line
    +  cond3 // comment
     );
  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7711: biome lint --suppress no longer fails with conflicting rule fixes when multiple diagnostics target a declaration preceded by a multiline comment.

  • #​11700 0e9fe53 Thanks @​dyc3! - Added the nursery rule noObsoleteTags, which reports obsolete HTML elements in HTML and JSX, such as <font color="red">Text</font>.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​7363: Biome GritQL plugins now match TypeScript interface snippets such as interface $name { $body }.

  • #​11729 f047985 Thanks @​m1handr! - Added support for suite() as an alias of describe() across test analysis rules and formatter. Rules now recognize suite, fsuite, xsuite, and test.suite blocks. The formatter recognises them as test declarations.

  • #​11778 4b7aa1f Thanks @​ematipico! - Fixed #​7727: GritQL snippets such as import $what from $where now match namespace imports, including type-only imports. Explicit import type $what from $where patterns also match type-only named and namespace imports.

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7603: useSingleJsDocAsterisk no longer reports asterisks that are part of JSDoc comment content, such as italic text, as extra line markers.

  • #​11706 e19512a Thanks @​dyc3! - Fixed #​11704: files re-included by negation patterns in a nested .gitignore are processed when vcs.useIgnoreFile is enabled, even when the ignore file contains *.

  • #​11718 76a302a Thanks @​dyc3! - Fixed #​8573: own-line comments before binary operators stay above the operator when javascript.formatter.operatorLinebreak is "before".

     foo
    -  || // comment
    -  bar;
    +  // comment
    +  || bar;
  • #​9797 64fd314 Thanks @​Netail! - Added the nursery rule useConsistentObjectKeys, which requires JSON object keys to follow a consistent Unicode representation.

postcss/autoprefixer (autoprefixer)

v10.6.1

Compare Source

  • Fixed grid gap set with the row-gap and column-gap longhands (by dualfroz).
cssnano/cssnano (cssnano)

v9.0.5: v9.0.5

Compare Source

What's Changed

Bug Fixes
  • fix(postcss-svgo): decode SVG following WHATWG specification in #​1975
Other changes
  • Update dependencies

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@9.0.4...cssnano@9.0.5

github/codeql-action (github/codeql-action)

v4.38.1

Compare Source

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #​4146
DavidAnson/markdownlint-cli2 (markdownlint-cli2)

v0.23.3

Compare Source

  • Update dependencies
pnpm/pnpm (pnpm)

v12.5.1: pnpm 12.5.1

Compare Source

Patch Changes

  • pnpm now reports an unknown task setting in pnpm-workspace.yaml and carries on. It used to refuse to start, so a project could not use a task setting that only the pnpm version its packageManager pins reads. The setting is still an error when the running pnpm is that pinned version.

  • Python interpreter installation now retries historical release metadata requests. It caches the release list for up to 24 hours and refreshes it once after a lookup miss. When a release omits the current platform, the search samples at most eight other releases before reporting that the lookup is inconclusive.

  • Python registries entries now route packages by exact names or trailing-prefix patterns in packages. Registry declaration order no longer affects resolution. A matched package resolves exclusively from its assigned registry, including transitive and build dependencies. Use packages: ["*"] to declare the default index.

  • pnpm install no longer fails with "Too many levels of symbolic links" when a Cargo configuration file above the workspace is a symlink, such as a ~/.cargo/config.toml linked from a dotfiles repository.

  • pnpm install now returns "Already up to date" in a workspace where dedupeDirectDeps left a project without a node_modules directory of its own. Such a project forced a full install on every run.

  • pnpm install no longer refuses the repeat-install fast path just because a changed pnpm-lock.yaml is 16 MiB or larger. Such a lockfile forced a full install on the run after every change.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.5.0: pnpm 12.5

Compare Source

pnpm 12.5.0 makes Python a first-class ecosystem, accepts Package URLs in pnpm add, names whole platforms in supportedArchitectures, and gives tasks machine-wide concurrency limits. It also fixes an install that could reuse one package's downloaded tarball for another.

Minor Changes

Installing packages
  • pnpm add accepts a Package URL in place of a package name. pnpm add pkg:npm/express@4.18.2 saves express to package.json. pnpm add pkg:cargo/serde@1.0.188 saves serde to Cargo.toml. pnpm add pkg:pypi/requests@2.31.0 saves requests to pyproject.toml. pkg is now a reserved specifier prefix, whatever case it is written in, so a named registry can no longer be called pkg.

  • A registries entry can now name the ecosystem it serves.

    registries:
      https://internal.example/simple/:
        ecosystem: pypi
      https://pypi.org/simple/:
        ecosystem: pypi
      https://index.crates.io/:
        ecosystem: cargo

    ecosystem accepts npm, cargo and pypi. An entry that does not name one serves npm, as every entry did before.

    An ecosystem with several indexes searches them in the order they are declared. The first index that has a package supplies it, so the one declared last answers what none before it had.

    A registries entry may not carry credentials. pnpm reads them from .npmrc, matched by origin, for a PyPI index as for every other package source.

Configuring pnpm
  • supportedArchitectures now accepts a list of platforms, in place of the os, cpu and libc axes.

    supportedArchitectures:
      - linux-x64
      - darwin-arm64
      - win32-x64

    An install prepares for the platforms the list names, and for those only. A platform reads as <os>-<cpu>, with a C library on Linux, as in linux-x64-musl or linux-x64-manylinux_2_28. The Rust target triple of the same machine is accepted too, so x86_64-unknown-linux-gnu names the platform linux-x64 names. A Linux platform that names no C library is the glibc platform. current is the platform the install runs on.

    The os, cpu and libc mapping keeps working and keeps its meaning.

  • Added concurrency groups for tasks. A task in pnpm-workspace.yaml can name a concurrencyGroup. The new concurrencyGroups setting gives each group a limit. At most that many tasks of the group run at once on the machine, counted across every pnpm process, pnpm pipeline included. A task past the limit waits for a running one to finish. A script that calls pnpm run for a task of the same group runs under the slot its parent holds.

    tasks:
      test:rust:
        concurrencyGroup: cargo
    concurrencyGroups:
      cargo: 2
  • tools names the programs pnpm downloads, and mirror says where each one comes from.

    tools:
      node:
        mirror: https://mirror.example.com/node/download
        channels:
          nightly: https://nightly.example.com/
      bun:
        mirror: https://mirror.example.com/bun
      python:
        mirror: https://mirror.example.com/python-build-standalone/releases

    node, bun and python can be named. Any other tool is refused.

    mirror is the base a tool's own layout hangs off.

    channels sends one release channel elsewhere. A channel neither it nor node-mirror:<channel> names is left to mirror. Only node publishes channels, so naming them for another tool is refused.

    Set it in the global config.yaml or in PNPM_CONFIG_TOOLS. A pnpm-workspace.yaml that names a tool mirror is ignored.

    pnpm pack-app downloads the Node.js it embeds through tools.node. node-mirror:<channel> keeps working and names the same thing as an entry under channels.

Python interpreters and environments
  • pnpm install now chooses a Python interpreter for each project instead of installing every project with one interpreter #​14945. A project is installed with the first interpreter on the machine that its requires-python accepts, so a workspace can hold projects that support different Python versions. pnpm reads .python-version too, and prefers the version it asks for. Set python.executable in pnpm-workspace.yaml to name one interpreter for every project.

  • pnpm install now installs a Python interpreter when no interpreter on the machine fits the project #​14945. The builds are python-build-standalone's, which uv and rye install too. One interpreter is shared by every project on the machine, and a later install uses it without downloading anything. runtimeOnFail decides what an install with no interpreter that fits does, the way it does for a Node.js runtime. error reports the project instead of installing one. warn and ignore install with an interpreter the machine has that the project's requires-python rejects. tools.python.mirror names a mirror.

  • Python environments now live in the store. Each project keeps only its .venv link, which points at the project's current environment generation under python-envs in the store. A repository with many Python projects no longer holds a .pnpm/python-envs directory in each of them. The next install relinks a .venv that an earlier release published. The old .pnpm/python-envs directory is left in place, since a running program may still use it, and can be deleted once none does. With frozenStore set, pnpm writes nothing to the store, so environments stay in the project's .pnpm/python-envs #​15014.

  • Python environments now use packageImportMethod to import wheel files from the store. Use clone-or-copy for copy-on-write clones with a copy fallback, or copy for independent files. Hardlinked files share writes with the store and other environments.

    Isolated Python build environments keep backend writes private with copy-on-write clones or copies.

Python projects and workspaces
  • pnpm install now installs a Python project's own package, so the project can be imported and the commands in [project.scripts] run right after an install #​14945. The installed package points at the source tree, so an edit to a module takes effect without another install. pnpm installs the package of a project that declares a [build-system]. tool.uv.package overrides that either way.

  • pnpm install now installs a Python project in the workspace from its own source. Declare it under [tool.uv.sources], as shared = { workspace = true } or shared = { path = "../shared", editable = true }. pnpm builds the project with the backend it declares. It installs the build editable, so an edit to the project takes effect without another install.

    Approve the build backend under allowBuilds in pnpm-workspace.yaml as a Package URL, as pkg:pypi/hatchling: true. An install that has not approved a backend does not build the projects that need it. The message names the key to add.

    pnpm install now refuses a requirement that names a project in the workspace when nothing declares where it comes from. It used to take that name from the index.

  • The members of a uv workspace can now share one Python environment. Set shared-environment = true under [tool.pnpm.python] in the pyproject.toml that declares [tool.uv.workspace]. pnpm install then resolves every member as one graph into one pylock.toml and one .venv at the workspace root. Two members that require versions of a distribution no release satisfies at once are refused with an error naming both. Each project still gets an environment of its own by default #​15015.

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot added 🏗️ Category: Build Issues and PRs related to the build directory 📦 Type: Developer Dependencies PRs that modify packages only req'd for local development and testing labels Sep 28, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 28, 2026 00:28
@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for gh-pages-openinf ready!

Name Link
🔨 Latest commit 56649ce
🔍 Latest deploy log https://app.netlify.com/projects/gh-pages-openinf/deploys/6ab9b4992a4a140008703d07
😎 Deploy Preview https://deploy-preview-1910--gh-pages-openinf.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 38d7e924-2c6e-4346-8a48-5f7abf302e28

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcssnano@​9.0.4 ⏵ 9.0.5991006998 -1100
Updated@​types/​node@​24.13.4 ⏵ 24.13.61001008196 +1100
Updatedvnu-jar@​26.9.7 ⏵ 26.9.16911008298100
Updatedautoprefixer@​10.6.0 ⏵ 10.6.11001008993 -1100
Updatedmarkdownlint-cli2@​0.23.2 ⏵ 0.23.399 +1100100 +191 +4100
Updatedprettier@​3.9.6 ⏵ 3.9.89810097 +199100
Updated@​biomejs/​biome@​2.5.13 ⏵ 2.5.14100 +1100100 +199100

View full report

@renovate
renovate Bot merged commit 8e75553 into live Sep 28, 2026
16 of 18 checks passed
@renovate
renovate Bot deleted the renovate/all branch September 28, 2026 00:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🏗️ Category: Build Issues and PRs related to the build directory 📦 Type: Developer Dependencies PRs that modify packages only req'd for local development and testing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants