Skip to content

Bump the dependencies group across 1 directory with 25 updates - #337

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-0cdecfa463
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-0cdecfa463

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 25 updates in the / directory:

Package From To
@fortawesome/fontawesome-svg-core 7.3.0 7.3.1
@fortawesome/react-fontawesome 3.3.1 3.5.0
@mui/x-date-pickers 8.29.0 8.29.3
@reduxjs/toolkit 2.12.0 2.13.0
axios 1.18.1 1.20.0
express 4.22.2 4.22.3
ip-range-check 0.2.0 0.2.1
morgan 1.11.0 1.12.1
postcss 8.5.16 8.5.28
react-colorful 5.7.0 5.8.1
react-hook-form 7.80.0 7.89.0
react-router-dom 6.30.4 6.30.6
recharts 3.9.1 3.10.1
socket.io 4.8.3 4.8.4
socket.io-client 4.8.3 4.8.4
systeminformation 5.31.11 5.33.15
tar 7.5.19 7.5.22
uuid 14.0.1 14.0.2
@testing-library/react 16.3.2 16.3.3
@testing-library/user-event 14.6.1 14.6.7
jest 30.4.2 30.5.2
jest-environment-jsdom 30.4.1 30.5.2
prettier 3.9.4 3.9.9
supertest 7.2.2 7.3.1
vitest 3.2.6 3.2.7

Updates @fortawesome/fontawesome-svg-core from 7.3.0 to 7.3.1

Release notes

Sourced from @​fortawesome/fontawesome-svg-core's releases.

Release 7.3.1

Change log available at https://fontawesome.com/docs/changelog/

Commits
Maintainer changes

This version was pushed to npm by fortawesome-admin, a new releaser for @​fortawesome/fontawesome-svg-core since your current version.


Updates @fortawesome/react-fontawesome from 3.3.1 to 3.5.0

Release notes

Sourced from @​fortawesome/react-fontawesome's releases.

v3.5.0

3.5.0 (2026-07-20)

Features

Chores

  • deps: roll back commitlint to fix release notes generation (d5f3376)
  • fix missing changelog for 3.4.0 (e33cff5)

v3.4.0

3.4.0 (2026-07-08)

Features

  • Support for new animations introduced in FontAwesome v7.3.0 (#651)

Chores

Full Changelog: FortAwesome/react-fontawesome@v3.3.1...v3.4.0

Changelog

Sourced from @​fortawesome/react-fontawesome's changelog.

3.5.0 (2026-07-20)

Features

Chores

  • deps: roll back commitlint to fix release notes generation (d5f3376)
  • fix missing changelog for 3.4.0 (e33cff5)

3.4.0 (2026-07-08)

Features

  • Support for new animations introduced in FontAwesome v7.3.0 (#651)

Chores

  • deps: bump fast-uri from 3.1.0 to 3.1.2 (a193c11)
  • deps-dev: bump dev dependencies to use FA 7.3.0 (cc540d8)
Commits
  • 162b1cd chore(release): 3.5.0 [skip ci]
  • d5f3376 chore(deps): roll back commitlint to fix release notes generation
  • 94a3d3e Merge pull request #652 from FortAwesome/new-7-3-canvas-options
  • c5333b9 feat: add new canvas options
  • e33cff5 chore: fix missing changelog for 3.4.0
  • 814990b chore(release): 3.4.0 [skip ci]
  • cc540d8 chore(deps): bump dev to FA 7.3.0
  • 949c7a1 Merge pull request #651 from FortAwesome/new-7-3-animations
  • 3dfea93 fix: more accurate links to animations
  • 4415c9e feat: new animations to support 7.3.0
  • Additional commits viewable in compare view

Updates @mui/x-date-pickers from 8.29.0 to 8.29.3

Release notes

Sourced from @​mui/x-date-pickers's releases.

v8.29.3

We'd like to extend a big thank you to the 2 contributors who made this release possible. Here are some highlights ✨:

  • 🐞 Bugfixes

The following team members contributed to this release: @​LukasTy, @​MBilalShafi

Data Grid

@mui/x-data-grid@8.29.3

  • [DataGrid] Fix toolbar button stealing focus when a sibling's disabled state changes (#23265) @​MBilalShafi

@mui/x-data-grid-pro@8.29.3 pro

Same changes as in @mui/x-data-grid@8.29.3.

@mui/x-data-grid-premium@8.29.3 premium

Same changes as in @mui/x-data-grid-pro@8.29.3.

Date and Time Pickers

@mui/x-date-pickers@8.29.3

@mui/x-date-pickers-pro@8.29.3 pro

Same changes as in @mui/x-date-pickers@8.29.3, plus:

  • [DateRangePicker] Fix broken active range position underline in single input range fields (#23201) @​LukasTy

Charts

@mui/x-charts@8.29.3

Internal changes.

@mui/x-charts-pro@8.29.3 pro

Same changes as in @mui/x-charts@8.29.3.

@mui/x-charts-premium@8.29.3 premium

Same changes as in @mui/x-charts-pro@8.29.3.

Tree View

... (truncated)

Changelog

Sourced from @​mui/x-date-pickers's changelog.

8.29.3

Aug 21, 2026

We'd like to extend a big thank you to the 2 contributors who made this release possible. Here are some highlights ✨:

  • 🐞 Bugfixes

The following team members contributed to this release: @​LukasTy, @​MBilalShafi

Data Grid

@mui/x-data-grid@8.29.3

  • [DataGrid] Fix toolbar button stealing focus when a sibling's disabled state changes (#23265) @​MBilalShafi

@mui/x-data-grid-pro@8.29.3 pro

Same changes as in @mui/x-data-grid@8.29.3.

@mui/x-data-grid-premium@8.29.3 premium

Same changes as in @mui/x-data-grid-pro@8.29.3.

Date and Time Pickers

@mui/x-date-pickers@8.29.3

@mui/x-date-pickers-pro@8.29.3 pro

Same changes as in @mui/x-date-pickers@8.29.3, plus:

  • [DateRangePicker] Fix broken active range position underline in single input range fields (#23201) @​LukasTy

Charts

@mui/x-charts@8.29.3

Internal changes.

@mui/x-charts-pro@8.29.3 pro

Same changes as in @mui/x-charts@8.29.3.

@mui/x-charts-premium@8.29.3 premium

... (truncated)

Commits

Updates @reduxjs/toolkit from 2.12.0 to 2.13.0

Release notes

Sourced from @​reduxjs/toolkit's releases.

v2.13.0

This feature release updates our build tooling to TSDown and PNPM, adds official TypeScript 7 support, and includes a long list of bugfixes across RTK Query, createAsyncThunk, createEntityAdapter, and combineSlices.

Changelog

Build Tooling Updates

We've fully modernizing modernized our build tooling across all of the Redux repos. That included switching from Yarn to PNPM, ESLint to Oxlint, Prettier to Oxfmt, and TSUp to TSDown.

The part that matters for users is that we now build the package with TSDown instead of tsup. The package layout, exports definitions, and exported APIs are all unchanged from 2.12. We've checked the new build with attw, and verified that CJS and ESM entry points load in both dev and prod builds, and that the legacy-esm artifacts still target ES2017. The contents of the bundles do look a bit different (smaller CJS artifacts, slightly different helper output in the legacy-esm files). If you see any behavior differences that look build-related, please file an issue!

This is also our first release published via the updated PNPM-based workflow, still using NPM Trusted Publishing. We've also added pkg.pr.new previews for every commit, so you can try out a PR build before it's released.

Docs Updates

We've shipped a new combined Redux libraries docs site! The core docs site at https://redux.js.org now contains the docs for all of our libraries: Redux core and usage guides, Redux Toolkit, React Redux, and Reselect. The prior standalone docs sites for RTK, R-R, and Reselect now redirect to their respective sections of the combined docs. We've also done a major cleanup pass on the docs, deduplicating pages that had similarities (like the Next.js or RTK2 migration pages that lived in both the core and RTK docs), and updating outdated content (modernizing example code snippets, deleting dead links, and making RTK and hooks the default patterns shown). The RTK content now lives at https://redux.js.org/toolkit/ .

TypeScript 7 Support

TS 7.0 (the native Go port) is now out! We fixed the remaining type errors in RTK when checked by TS 7.0 and 7.1, and TS 7.0 is now part of our CI test matrix.

Per our TS support policy of matching DefinitelyTyped's support window, we've also updated our support matrix to TS 5.6+. As always, RTK may still work with earlier versions, but we no longer test against them.

RTK Query Fixes

useQueryState (and thus useQuery) was passing a new inline selector to useSelector on every render, and also reading the store directly during render. The selector is now memoized, and the direct store read is gone. This also fixes a bug where isSuccess could flip from false to true on an unrelated re-render while a query was refetching after an error. isSuccess now correctly stays false in that case.

data now reflects cache updates made via updateQueryData while a refetch is in flight, instead of showing the previous result.

Polling now reads the current cache state when each poll fires, rather than the state at the time the poll was scheduled. This means skipPollingIfUnfocused respects focus loss that happens after scheduling, and polls stop if their cache entry was removed.

We fixed a race where a duplicate query request rejected by the thunk condition could cause queued tag invalidations to run too early and be lost, leaving stale data in the cache.

Tags with falsy ids like 0 now invalidate and clean up correctly.

Lazy query hooks now re-subscribe correctly when effects restart while the hook state is preserved, such as with Fast Refresh or <Activity>.

Infinite queries no longer trigger onQueryStarted when fetching past the end of the list, and the infinite query hook result type now includes the page error flags.

fetchBaseQuery only treats a URL as absolute if it starts with a scheme.

We also fixed an error when rehydrating state for an endpoint name that has no definition.

Other Fixes

createAsyncThunk no longer swallows aborts that happen before the pending action is dispatched, and now correctly sets rejectedWithValue when rejectWithValue is called with a falsy payload.

createEntityAdapter's setAll now keeps the last item when given duplicate IDs, matching setMany. The sorted adapter's updateMany now merges multiple updates for the same ID before applying them.

combineSlices now keeps its internal state proxy cache per instance, so multiple combined reducers no longer interfere with each other.

... (truncated)

Commits
  • 370f7eb Release 2.13.0
  • 8c40241 Fix release-it commands for PNPM
  • 483f0fb Fix unstable selector reference inside of useQueryState and isSuccess dur...
  • 62103f5 Fix TS7 errors and update TS matrix (#5455)
  • 71db2d4 Fetch the other libraries' docs from master in previews (#5454)
  • 0eeae5c Convert Redux Toolkit docs to the combined site format (#5451)
  • c9dac93 docs: clarify browser ESM import map usage (#5375)
  • 00b133f fix(toolkit): handle circular references in immutable state middleware (#5433)
  • ded675e docs site: fix pagefind search by preloading window.pagefind (#5447)
  • 322c01a Reinstate lazy queries after preserved effects restart (#5424)
  • Additional commits viewable in compare view

Updates axios from 1.18.1 to 1.20.0

Release notes

Sourced from axios's releases.

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)

🔧 Maintenance & Chores

  • Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
  • Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
  • Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
  • CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

v1.19.0 - July 22, 2026

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

🔒 Security Fixes

  • Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (GHSA-hmw2-7cc7-3qxx). (#11028)

... (truncated)

Changelog

Sourced from axios's changelog.

Changelog

v1.19.0 — July 22, 2026

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

🔒 Security Fixes

  • Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (GHSA-hmw2-7cc7-3qxx). (#11028)

🚀 New Features

  • Configuration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors, adapters, and serializers. (#11043, #11081)
  • Header Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (#11051)
  • HTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (#11067)

🐛 Bug Fixes

  • Form Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (#11006, #11018)

  • Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (#11029, #11053)

  • Cancellation: Propagated already-aborted input signals immediately when composing abort signals. (#11035)

  • Header Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (#11036, #11037)

  • URL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (#11008, #11038)

  • Progress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (#11039, #11040)

  • Error and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (#11044, #11059)

  • Content-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (#11061)

  • Synchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (#11071)

🔧 Maintenance & Chores

  • Dependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (#11031, #11055, #11056, #11058, #11079, #11080, #11088, #11089, #11090)
  • Build Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (#11054)
  • Form Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (#11062)
  • Developer Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (#11032, #11073)
  • Documentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (#11041, #11068, #11076, #11078)
  • Publishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (#11083, #11095)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve Axios:

... (truncated)

Commits
  • 84a9f3b chore(release): prepare release 1.20.0 (#11152)
  • e6824ee fix: core methodList, HTTP adapter errors, and add tests (#11096)
  • d8a919f fix(xhr): flush final progress during the live loadend dispatch (#11121)
  • 2d2a21a fix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)
  • d19040b fix: harden runtime option handling (#11141)
  • e0a02dd chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...
  • d10cb3a chore(deps-dev): bump the development_dependencies group with 4 updates (#11143)
  • 2c94646 chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)
  • 76c12bc chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)
  • ba98559 docs: add ScrapingBee sponsor (#11137)
  • Additional commits viewable in compare view

Updates express from 4.22.2 to 4.22.3

Changelog

Sourced from express's changelog.

4.22.3

  • Allow conditional revalidation for QUERY requests
    • req.fresh now includes QUERY in the freshness check, so QUERY responses can return 304 when a validator matches
  • deps: qs@~6.16.0
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for express since your current version.


Updates ip-range-check from 0.2.0 to 0.2.1

Changelog

Sourced from ip-range-check's changelog.

0.2.1

Security fix: SSRF filter bypass via abbreviated IPv4 notation

GHSA-87xc-4hwr-pxf6

ipRangeCheck previously treated any unparseable address as "not in range" (false). Abbreviated IPv4 forms such as "127.1", "0177.1", and "127.0x1" failed to parse under ipaddr.js 1.x, so a denylist check like ipRangeCheck(host, ["127.0.0.0/8", ...]) returned false for them — even though Node, browsers, curl, and most OS resolvers connect these forms to 127.0.0.1. An application using this library to block requests to private IP ranges (a common SSRF defense) could be bypassed by an attacker supplying one of these forms as the target host. See the security advisory for full details, including which usage patterns are and aren't affected.

Behavior change: short/hex/octal IPv4 notations are now accepted

Upgrading ipaddr.js from 1.x to 2.x changed how non-standard IPv4 notations are handled. Previously they failed to parse, so ipRangeCheck returned false for any check involving them. They now parse using the classic inet_aton rules — the same rules the OS, browsers, and curl apply when connecting:

  • Shorthand: "127.1" → 127.0.0.1 (the final part fills the remaining bytes), so ipRangeCheck("127.1", "127.0.0.0/8") is now true (was false).
  • Hexadecimal octets: "0x7f.1" → 127.0.0.1.
  • Octal octets: a leading zero means octal, so "010.1" → 8.0.0.1, not 10.0.0.1.

This matches what those inputs actually resolve to on a real network stack, which is generally what you want when checking whether an address falls in a range (e.g. blocking 127.0.0.0/8 now correctly catches "127.1"). However, if you were relying on these notations failing validation, you must now validate input format separately (e.g. with ipaddr.IPv4.isValidFourPartDecimal() from ipaddr.js).

Dependencies

  • Upgraded ipaddr.js 1.9.1 → 2.5.0.
  • Removed mocha in favour of Node's built-in test runner (node --test). The package now has zero dev dependencies and a single runtime dependency, and npm audit reports zero vulnerabilities.
  • Committed package-lock.json.

Running the tests now requires Node.js 22 or newer. This does not affect consumers of the library — the shipped code is unchanged and its supported Node versions are unaffected.

... (truncated)

Commits
  • 77e5e80 Release 0.2.1: fix SSRF filter bypass via abbreviated IPv4 notation
  • c13d325 Drop end-of-life Node 20 from CI matrix
  • 4ebfdd7 Test on Node 26 in CI
  • 83cd85c Replace mocha with Node's built-in test runner
  • 64ea943 Bump checkout and setup-node actions to v7
  • e09491b Revert version bump; hold 1.0.0 changelog as unreleased
  • f0ced78 Add inet_aton notation tests, changelog, and bump to 1.0.0
  • 673e4b6 Upgrade ipaddr.js to 2.5.0 and mocha to 11.8.0
  • a7aca1c Use npm ci with caching in CI
  • 9b88851 Commit package-lock.json
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by danielcompton, a new releaser for ip-range-check since your current version.


Updates morgan from 1.11.0 to 1.12.1

Release notes

Sourced from morgan's releases.

1.12.1

Important

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.12.0...1.12.1

1.12.0

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.11.0...1.12.0

Changelog

Sourced from morgan's changelog.

1.12.1

1.12.0

  • Security fix for CVE-2026-15603(GHSA-jxfw-x594-9x9m)
  • Allow format functions to return objects for streams in objectMode
  • Respect the NO_COLOR environment variable in the dev format
Commits
  • b1272e7 1.12.1 (#386)
  • 4b695ed fix: escape double quotes in log fields
  • 0f74eca build(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)
  • e399e3c build(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)
  • 1e86b34 build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)
  • 87c0afd build(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)
  • 286b000 test: run CI on Windows and macOS (#379)
  • 5a5902a docs: fix typos across documentation (#378)
  • 063f084 1.12.0 (#376)
  • fbf9383 fix: escape all token values in log output
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for morgan since your current version.


Updates postcss from 8.5.16 to 8.5.28

Release notes

Sourced from postcss's releases.

8.5.28

  • Fixes types regression.

8.5.27

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).
Changelog

Sourced from postcss's changelog.

8.5.28

  • Fixes types regression.

8.5.27

  • Fixed removing any comments starting with /*# (by @​dylanpulver).
  • Fixed * hack before a comment in Custom Properties (by @​Jaybhade).
  • Fixed empty values in the middle of list.comma() (by @​MahinAnowar).
  • Fixed whitespace-only values in list.space() (by @​MahinAnowar).
  • Fixed rule’s end position on space before semicolon (by

Bumps the dependencies group with 25 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@fortawesome/fontawesome-svg-core](https://github.com/FortAwesome/Font-Awesome) | `7.3.0` | `7.3.1` |
| [@fortawesome/react-fontawesome](https://github.com/FortAwesome/react-fontawesome) | `3.3.1` | `3.5.0` |
| [@mui/x-date-pickers](https://github.com/mui/mui-x/tree/HEAD/packages/x-date-pickers) | `8.29.0` | `8.29.3` |
| [@reduxjs/toolkit](https://github.com/reduxjs/redux-toolkit) | `2.12.0` | `2.13.0` |
| [axios](https://github.com/axios/axios) | `1.18.1` | `1.20.0` |
| [express](https://github.com/expressjs/express) | `4.22.2` | `4.22.3` |
| [ip-range-check](https://github.com/danielcompton/ip-range-check) | `0.2.0` | `0.2.1` |
| [morgan](https://github.com/expressjs/morgan) | `1.11.0` | `1.12.1` |
| [postcss](https://github.com/postcss/postcss) | `8.5.16` | `8.5.28` |
| [react-colorful](https://github.com/omgovich/react-colorful) | `5.7.0` | `5.8.1` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.80.0` | `7.89.0` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `6.30.4` | `6.30.6` |
| [recharts](https://github.com/recharts/recharts) | `3.9.1` | `3.10.1` |
| [socket.io](https://github.com/socketio/socket.io) | `4.8.3` | `4.8.4` |
| [socket.io-client](https://github.com/socketio/socket.io) | `4.8.3` | `4.8.4` |
| [systeminformation](https://github.com/sebhildebrandt/systeminformation) | `5.31.11` | `5.33.15` |
| [tar](https://github.com/isaacs/node-tar) | `7.5.19` | `7.5.22` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |
| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.1` | `14.6.7` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.2` |
| [jest-environment-jsdom](https://github.com/jestjs/jest/tree/HEAD/packages/jest-environment-jsdom) | `30.4.1` | `30.5.2` |
| [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.9` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `3.2.6` | `3.2.7` |



Updates `@fortawesome/fontawesome-svg-core` from 7.3.0 to 7.3.1
- [Release notes](https://github.com/FortAwesome/Font-Awesome/releases)
- [Changelog](https://github.com/FortAwesome/Font-Awesome/blob/7.x/CHANGELOG.md)
- [Commits](FortAwesome/Font-Awesome@7.3.0...7.3.1)

Updates `@fortawesome/react-fontawesome` from 3.3.1 to 3.5.0
- [Release notes](https://github.com/FortAwesome/react-fontawesome/releases)
- [Changelog](https://github.com/FortAwesome/react-fontawesome/blob/main/CHANGELOG.md)
- [Commits](FortAwesome/react-fontawesome@v3.3.1...v3.5.0)

Updates `@mui/x-date-pickers` from 8.29.0 to 8.29.3
- [Release notes](https://github.com/mui/mui-x/releases)
- [Changelog](https://github.com/mui/mui-x/blob/v8.29.3/CHANGELOG.md)
- [Commits](https://github.com/mui/mui-x/commits/v8.29.3/packages/x-date-pickers)

Updates `@reduxjs/toolkit` from 2.12.0 to 2.13.0
- [Release notes](https://github.com/reduxjs/redux-toolkit/releases)
- [Commits](reduxjs/redux-toolkit@v2.12.0...v2.13.0)

Updates `axios` from 1.18.1 to 1.20.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.18.1...v1.20.0)

Updates `express` from 4.22.2 to 4.22.3
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.3/History.md)
- [Commits](expressjs/express@v4.22.2...v4.22.3)

Updates `ip-range-check` from 0.2.0 to 0.2.1
- [Changelog](https://github.com/danielcompton/ip-range-check/blob/master/CHANGELOG.md)
- [Commits](danielcompton/ip-range-check@v0.2.0...v0.2.1)

Updates `morgan` from 1.11.0 to 1.12.1
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.11.0...1.12.1)

Updates `postcss` from 8.5.16 to 8.5.28
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.16...8.5.28)

Updates `react-colorful` from 5.7.0 to 5.8.1
- [Release notes](https://github.com/omgovich/react-colorful/releases)
- [Changelog](https://github.com/omgovich/react-colorful/blob/master/CHANGELOG.md)
- [Commits](https://github.com/omgovich/react-colorful/commits)

Updates `react-hook-form` from 7.80.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.80.0...v7.89.0)

Updates `react-router-dom` from 6.30.4 to 6.30.6
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@6.30.6/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@6.30.6/packages/react-router-dom)

Updates `recharts` from 3.9.1 to 3.10.1
- [Release notes](https://github.com/recharts/recharts/releases)
- [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md)
- [Commits](recharts/recharts@v3.9.1...v3.10.1)

Updates `socket.io` from 4.8.3 to 4.8.4
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io@4.8.3...socket.io@4.8.4)

Updates `socket.io-client` from 4.8.3 to 4.8.4
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-client@4.8.3...socket.io-client@4.8.4)

Updates `systeminformation` from 5.31.11 to 5.33.15
- [Release notes](https://github.com/sebhildebrandt/systeminformation/releases)
- [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md)
- [Commits](sebhildebrandt/systeminformation@v5.31.11...v5.33.15)

Updates `tar` from 7.5.19 to 7.5.22
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.19...v7.5.22)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.1...v14.0.2)

Updates `@testing-library/react` from 16.3.2 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/react-testing-library@v16.3.2...v16.3.3)

Updates `@testing-library/user-event` from 14.6.1 to 14.6.7
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](testing-library/user-event@v14.6.1...v14.6.7)

Updates `jest` from 30.4.2 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `jest-environment-jsdom` from 30.4.1 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest-environment-jsdom)

Updates `prettier` from 3.9.4 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.4...3.9.9)

Updates `supertest` from 7.2.2 to 7.3.1
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.1)

Updates `vitest` from 3.2.6 to 3.2.7
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v3.2.7/packages/vitest)

---
updated-dependencies:
- dependency-name: "@fortawesome/fontawesome-svg-core"
  dependency-version: 7.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@fortawesome/react-fontawesome"
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@mui/x-date-pickers"
  dependency-version: 8.29.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@reduxjs/toolkit"
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: express
  dependency-version: 4.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: ip-range-check
  dependency-version: 0.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: morgan
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: react-colorful
  dependency-version: 5.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: react-router-dom
  dependency-version: 6.30.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: recharts
  dependency-version: 3.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: socket.io
  dependency-version: 4.8.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: socket.io-client
  dependency-version: 4.8.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: systeminformation
  dependency-version: 5.33.15
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: tar
  dependency-version: 7.5.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@testing-library/react"
  dependency-version: 16.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@testing-library/user-event"
  dependency-version: 14.6.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: jest-environment-jsdom
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: supertest
  dependency-version: 7.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: vitest
  dependency-version: 3.2.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved because this is a Dependabot semver minor/patch update.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants