fix(deps): update all non-major updates - autoclosed#30
Conversation
|
73d9730 to
11d6330
Compare
… weekly update train The grouped non-major PR (#30) has been unmergeable for two weeks because Renovate kept proposing two bumps that can never resolve: - `rand_core` 0.6 → 0.10: the test-only keygen dep must match ed25519-dalek 2.x's rand_core API, and the `getrandom` feature we request no longer exists past 0.6. New rule caps it with `allowedVersions: <0.7.0`. - `sspi` / `smb-rpc` pins in `benchmarks/smb/`: the harness pins these in lockstep with `smb` 0.11's internal `=0.18.7` pin, so independent bumps always dead-end in a `crypto-bigint` conflict. New rule disables Renovate for the whole harness. With these in place, retrying #30 regenerates the group without the poisoned bumps, and automerge can flow again.
11d6330 to
5b54607
Compare
5b54607 to
cd93fb6
Compare
… to tell the truth Renovate PR #30 pooled five unrelated breakages into one 2,300-line PR that broke every app at once and couldn't be bisected. Landing the same work here, verified per app, so #30 can close. **Toolchains.** Rust 1.95.0 → 1.97.1 (not #30's 1.97.0, which was already two releases stale), Go 1.25.12 → 1.26.5, pnpm 11.0.9 → 11.13.1, oxfmt 0.46 → 0.59 (11 files reformatted). Every GitHub Action digest re-verified against upstream tags before bumping rather than copied from the PR body. **Rust.** gix 0.81 → 0.85, rusqlite 0.39 → 0.40 (in lockstep with `index-query`), tower-http 0.6 → 0.7, exacl, sysinfo, mdns-sd, the Tauri plugins, and `mtp-rs` 0.23 → 0.26. `genai` gained a required `ToolResponse.fn_name`. It's filled from the originating tool call, correlated by `call_id` across the transcript, not a placeholder: Gemini's `functionResponse.name` keys on the function name rather than the call ID, so a guessed value would silently degrade tool calling there while looking fine everywhere else. `mtp-rs` 0.26 is a release made specifically for this: `VirtualDeviceConfig` now implements `Default`, so our fixture states only the fields it cares about and the next field addition upstream stops being a compile break here (0.24's `supports_partial_object_64` was one). **Node.** SvelteKit 2.65 → 2.69, Astro, satori, sharp, Playwright, vitest, eslint, stylelint, and the rest. The `cookie` override grew a ceiling (`>=0.7.0 <2`). cookie 2.0 renamed `parse`/`serialize` to `parseCookie`/`stringifyCookie` while SvelteKit's runtime still imports the old names, which is what actually broke the analytics dashboard build. The CVE floor stays; the comment records the condition for lifting the cap. `scheduleBackground` now takes just the `waitUntil` shape it calls. Hono's `Context.executionCtx` and the ambient `@cloudflare/workers-types` `ExecutionContext` disagree about `tracing`, so naming either type breaks on the other's next bump. **specta stays on rc.24, deliberately.** rc.25 types every plain `f32`/`f64` as `number | null`. On return values that's defensible (`serde_json` renders NaN and the infinities as `null`), but it applies the same rule to parameters, where it's wrong: `viewer_get_lines(target_value: f64)` and the four `media_index_*_threshold` commands take non-`Option` floats that serde will reject a `null` for. Adopting it would trade a latent, never-observed hazard for a live one the frontend could trigger, plus ~25 sites of dead null-handling. Renovate disabled on all three crates; the reasoning and the genuine NaN caveat are in `src-tauri/DETAILS.md`. Two of #30's five "breakages" turned out not to exist: the stylelint violations were the stale-transitive false positive our own dependency rule documents, and cleared under `pnpm dedupe`.
…the source
**GitGuardian.** Five open incidents were all one commit's worth of translated UI copy: `fileOperations.archivePassword.*` in the de/nl/es/pt/sv catalogs ("Passwort erforderlich", "Lösenord krävs", "Contraseña necesaria"). No secret, and every new locale would have added five more. `.gitguardian.yaml` now excludes the message catalogs.
`docs/security.md` records the part that isn't obvious: the file only covers ggshield (CI and pre-commit). The GitHub App's realtime scanning reads workspace exclusions from the dashboard instead and ignores this file, so a path has to be added in both places or the incidents keep arriving. The dashboard side is manual — the API doesn't expose exclusions on this plan.
**Renovate.** The one repo-wide non-major group is split per app (desktop including its Rust crates, website, the two Cloudflare apps), with linters and formatters on their own lane since a bump there rewrites or re-flags tracked files across every app and is pure noise mixed into dependency review. This is what made #30 unreviewable.
Also disabled on the CLIP conversion `requirements.txt`. Those pins aren't a dependency set: they record which versions produced the `.mlpackage` artifacts currently pinned by SHA-256 in `media_index/clip/install.rs`, so bumping them without re-running the conversion is drift, and re-running it is a deliberate model release. Worth knowing that `coremltools` declares no torch or transformers bound at all, so a clean resolve proves nothing — `uv pip compile` will hand you transformers 5.x, which `convert.py`'s `from transformers import CLIPModel` predates. The README now describes the real validation: re-run the conversion and check the fidelity cosines against the checked-in reference vectors.
**remark42 v1.15.0 → v1.16.4**, which is a security release: stored XSS via the image proxy, an OAuth open-redirect, path traversal in `/picture/`, and SSRF in the title extractor. Nothing deploys it automatically. Deploy deliberately and re-check Google/GitHub sign-in afterwards, since the open-redirect fix wires `AllowedRedirectHosts`.
|
Auto-closed because the equivalent work landed directly on This PR pooled five unrelated breakages into 2,300 lines that couldn't be reviewed or bisected, so it was redone as scoped work. What actually happened to each failure:
Two versions here were already stale by the time this was picked up: Rust 1.97.0 (1.97.1 shipped 2026-07-16) and pnpm 11.11.0 (11.13.1 clears the 3-day window). Both landed at the newer version. One bump was deliberately not taken: To stop this recurring, |
This PR contains the following updates:
4.11.3→4.12.1^0.0.6→^0.0.84.20260611.1→4.20260702.11.2.103→1.2.1171.2.1182.1.3→2.2.41.60.0→1.61.10.4.0→0.4.17.2.8→7.2.92.65.0→2.69.32.70.07.1.2→7.2.02.11.0→2.11.12.11.2→2.11.45.3.1→5.4.23.0.4→3.0.526.0.1→26.1.14.1.8→4.1.10v5.0.4→v5.1.0de0fac2→df4cb1c3.21→3.247.0.6→7.0.97.1.1(+1)2.13.0→2.13.11.12.0→1.12.1v4.0.1→v4.0.210.4.1→10.7.03.19.0→3.20.00.12→0.13=0.6.0-beta.19→=0.6.50.81→0.8517.6.0→17.7.01.25.12→1.26.5v0.42.0→v0.45.020.10.2→20.10.620.11.04.12.25→4.12.304.12.3111.2.8→11.2.1111.2.121648a78→dad1bfd6.16.1→6.27.0v6.0.0→v6.2.00.16.4→0.16.518.0.5→18.0.60.19→0.200.20.22.8.2→2.8.3==2.1.3→==2.5.1^0.46.0→^0.59.01.69.0→1.74.0==11.0.0→==11.3.011.9.0→11.11.011.15.0(+2)11.0.9→11.11.011.15.0(+2)3.8.4→3.9.51.12.4→1.13.16.12.4→6.17.20.39→0.401.95.0→1.97.01.97.10.26.0→0.28.0==1.5.2→==1.9.00.21.2→0.21.30.21.2→0.21.3^0.34.5→^0.35.0=2.0.0-rc.24→=2.0.0-rc.25=0.0.11→=0.0.1217.13.0→17.14.05.56.3→5.56.55.56.64.6.0→4.7.30.38.4→0.39.073fb865→84b9d35=2.3.1→=2.3.20.11→0.12=2.0.0-rc.24→=2.0.0-rc.25==2.5.1→==2.13.00.6→0.7==4.49.0→==4.57.64.22.4→4.23.18.61.0→8.64.0v1.15.0→v1.16.41.23.4→1.24.08.0.16→8.1.48.1.54.1.8→4.1.104.99.0→4.111.04.112.05.16.0→5.17.05.18.0Release Notes
dequelabs/axe-core-npm (@axe-core/playwright)
v4.12.1Compare Source
chenglou/pretext (@chenglou/pretext)
v0.0.8Compare Source
Added
.tssource instead of the.d.tsfiles.Fixed
v0.0.7Compare Source
Changed
layoutNextLine()andlayoutNextLineRange()now avoid redundant chunk lookup in chunk-heavy manual layout paths (#140).Fixed
{ wordBreak: 'keep-all' }now handles no-space mixed Latin, numeric, and CJK text more like browsers.¡,¿, German low quotes, and⸘now stays with the following word instead of dangling at line end (#165).$,%,€,+,−, and°now stay attached to adjacent text the way browser line breaking does (#105).cloudflare/workerd (@cloudflare/workers-types)
v4.20260702.1Compare Source
v4.20260701.1Compare Source
v4.20260630.1Compare Source
v4.20260629.1Compare Source
v4.20260628.1Compare Source
v4.20260627.1Compare Source
v4.20260626.1Compare Source
v4.20260625.1Compare Source
v4.20260624.1Compare Source
v4.20260623.1Compare Source
v4.20260621.1Compare Source
v4.20260620.1Compare Source
v4.20260619.1Compare Source
v4.20260617.1Compare Source
v4.20260616.1Compare Source
v4.20260615.1Compare Source
v4.20260613.1Compare Source
v4.20260612.1Compare Source
dahlia/logtape (@logtape/logtape)
v2.2.4Compare Source
Released on July 7, 2026.
@logtape/logtape
configure()orconfigureSync()calls couldleave duplicate process exit hooks registered on Node.js and Bun, causing
MaxListenersExceededWarningin long-running test suites or hot-reloadprocesses. LogTape now removes its runtime disposal hook when resetting
configuration. [#192]
v2.2.3Compare Source
Released on July 3, 2026.
@logtape/sentry
errproperty as anexception fallback when the
errorproperty does not contain anErrorinstance, so error-level logs using
{ err }are captured with stacktraces. [[#189]]
v2.2.2Compare Source
Released on July 1, 2026.
@logtape/file
getTimeRotatingFileSink()did not delete old fileswhen both
filenameandmaxAgeMswere configured. Time-rotating filesinks now use file modification times for cleanup when a custom filename
generator is configured. [#183]
v2.2.1Compare Source
Released on June 24, 2026.
@logtape/logtape
withCategoryPrefix()was incorrectly applied tosub-loggers of the meta logger (e.g.,
["logtape", "meta", "sink"]).[#182 by Sebastian Wesley-Smith]
@logtape/sentry
Fixed the Sentry sink to report internal errors to the meta logger
(
["logtape", "meta", "sentry"]) instead ofconsole.debug(),making sink failures observable in tests and production.
[#181 by Sebastian Wesley-Smith]
Fixed a
TypeError: Converting circular structure to JSONraised whilerendering interpolated message values (e.g. logging a
Responseor anyvalue containing a circular reference as
logger.error("…{error}", { error })). The sink now uses the samecross-runtime
inspecthelper as @logtape/logtape and @logtape/pretty(
Deno.inspect()on Deno,util.inspect()on Node.js/Bun) via the#utilimport map, instead of a fallible
globalThis-detection fallback thatsilently degraded to
JSON.stringify()on Node.js. [#180]v2.2.0Compare Source
Released on June 22, 2026.
@logtape/logtape
Improved enabled logging performance by avoiding redundant log record
category copying when no category prefix is active.
Improved enabled string logging performance by using a faster snapshot path
for log records created by LogTape.
Improved simple string logging performance by avoiding implicit context
allocation and lazy record getters when a log call has no properties or
message placeholders.
Improved enabled logging performance by caching effective sink dispatch
plans instead of rebuilding the inherited sink list for every log record.
Improved enabled logging performance for built-in stream sinks by skipping
the pre-sink log record snapshot when the sink consumes the record
synchronously.
Improved default JSON Lines formatter performance by avoiding an
intermediate wrapper object while preserving JSON serialization behavior.
Reduced allocation overhead in enabled logging by avoiding sink array
materialization for the common single-sink path.
@logtape/config
ConfigureOptions.contextLocalStorageoption toconfigureFromObject(), enabling implicit context support when loadingconfiguration from external files. This mirrors the
Config.contextLocalStorageoption available inconfigure()andconfigureSync().@logtape/testing
New package @logtape/testing providing testing utilities for collecting
and asserting LogTape records in memory. [#173, #175]
createLogRecorder(): LogRecorder.LogRecorderinterface withsink,records,clear(),take(),find(),filter(),assertLogged(), andassertNotLogged().LogRecordMatchinterface for matching category, categoryprefix, level, rendered message, raw message, structured properties,
and custom predicates.
Dateproperty values are matched bytimestamp, and regular expression matcher values match string property
values.
PropertyMatchertype for custom property matching.@logtape/elysia, @logtape/express, @logtape/hono, and @logtape/koa
Added opt-in request-scoped context support to
elysiaLogger(),expressLogger(),honoLogger(), andkoaLogger(). Setcontext: trueto read the incomingx-request-idheader, generate arequest ID when the header is missing, write the resolved ID to the
x-request-idresponse header, and addrequestIdto request log recordsand, when implicit context storage is configured, logs emitted while
handling the request. [#172, #174]
context?: boolean | RequestContextOptionstoElysiaLogTapeOptions,ExpressLogTapeOptions,HonoLogTapeOptions,and
KoaLogTapeOptions.RequestContextOptionswithrequestId?: boolean | RequestIdOptions,include?: readonly RequestContextField[], andenrich?: (...) => Record<string, unknown> | Promise<Record<string, unknown>>.RequestIdOptionswithproperty?: string,headerNames?: readonly string[],responseHeader?: string | false,generate?: () => string, andnormalize?: (value: string) => string | null.RequestContextFieldfor selecting request fields in implicitcontext. The Express integration also supports the
httpVersionfield.
Added clearer predefined format names to
elysiaLogger().structured-combinedandstructured-commonare structured request logpresets, while
morgan-combinedandmorgan-commonproduceMorgan-compatible Apache access log text. The existing
combinedandcommonformat names remain supported as deprecated aliases for thecorresponding structured presets. [#178]
Added clearer predefined format names to
expressLogger().structured-combinedandstructured-commonare structured request logpresets, while
morgan-combinedandmorgan-commonproduceMorgan-compatible Apache access log text. The existing
combinedandcommonformat names remain supported as deprecated aliases for thecorresponding structured presets. [#178]
Added clearer predefined format names to
honoLogger().structured-combinedandstructured-commonare structured request logpresets, while
morgan-combinedandmorgan-commonproduceMorgan-compatible Apache access log text. The existing
combinedandcommonformat names remain supported as deprecated aliases for thecorresponding structured presets. [#178]
Added clearer predefined format names to
koaLogger().structured-combinedandstructured-commonare structured request logpresets, while
morgan-combinedandmorgan-commonproduceMorgan-compatible Apache access log text. The existing
combinedandcommonformat names remain supported as deprecated aliases for thecorresponding structured presets. [#178]
@logtape/file
Improved
getStreamFileSink()throughput by writing formatted log recordsdirectly to the underlying file stream instead of routing them through an
extra Node.js stream layer.
Improved file sink throughput by skipping the pre-sink log record snapshot
for built-in file sinks that format records immediately.
Fixed a bug where
getRotatingFileSink()withmaxFiles: 0or a negativemaxFilesstill renamed the current file topath.1during rollover,leaving stale backup files behind even though no backups should be kept.
This adds optional
unlinkSync(path: string): voidmethods to theRotatingFileSinkDriverandAsyncRotatingFileSinkDriverinterfaces;custom base rotating file drivers must provide them when
maxFilesis0or negative.@logtape/lint
New package @logtape/lint providing lint rules for ESLint (v8 and v9),
Oxlint, and Deno Lint that detect common LogTape usage mistakes.
[#170, #171]
no-message-interpolationrule: flags template literals with${}expressions passed as a log method's message argument.prefer-lazy-evaluationrule: flags eagerObjectExpressionproperty values that contain function calls, and provides an auto-fix
that wraps the object in an arrow function callback.
no-unawaited-logrule: flags async arrow or function callbackspassed to log methods without
await; provides a conditional auto-fixwhen the enclosing function is
async.require-meta-sinkrule: warns whenconfigure()orconfigureSync()is called without a logger entry for the metacategory (
"logtape",["logtape"], or["logtape", "meta"]).@logtape/sentry
SentrySinkOptions.sentryoption for passing the Sentry SDKnamespace initialized by the application. This lets the sink use the same
Sentry module instance for captures, active spans, isolation scopes, and
structured logs in apps where @logtape/sentry may otherwise resolve a
different
@sentry/coreversion. [#167]@logtape/drizzle-orm
Added SQLite support to
DrizzleLogger. [#168, #169 by Van-sh]DrizzleDialectstype.DrizzleLoggerOptions.dialect?: DrizzleDialectsoption whichdefaults to
"pg".serialize()andstringLiteral()functions andDrizzleLoggerconstructor take an optionaldialect?: DrizzleDialectparameter.
@logtape/redaction
Added
maxDepthandmaxPropertiesoptions to field-based andpattern-based redaction so very deep or very large log records cannot cause
unbounded recursive traversal. When a limit is exceeded, redaction now
emits a warning through the meta logger and truncates or omits the
unprocessed portion of the record.
PatternRedactionOptionsinterface.RedactionTraversalOptionsinterface.@logtape/adaptor-pino
pinopeer dependency now accepts Pino 10.x in addition to 9.x.The supported range is expanded from
^9.7.0to^9.7.0 || ^10.0.0.[#176]
v2.1.8Compare Source
Released on July 7, 2026.
@logtape/logtape
configure()orconfigureSync()calls couldleave duplicate process exit hooks registered on Node.js and Bun, causing
MaxListenersExceededWarningin long-running test suites or hot-reloadprocesses. LogTape now removes its runtime disposal hook when resetting
configuration. [[#192]]
v2.1.7Compare Source
Released on July 3, 2026.
@logtape/sentry
errproperty as anexception fallback when the
errorproperty does not contain anErrorinstance, so error-level logs using
{ err }are captured with stacktraces. [[#189]]
v2.1.6Compare Source
Released on July 1, 2026.
@logtape/file
getTimeRotatingFileSink()did not delete old fileswhen both
filenameandmaxAgeMswere configured. Time-rotating filesinks now use file modification times for cleanup when a custom filename
generator is configured. [[#183]]
v2.1.5Compare Source
Released on June 16, 2026.
@logtape/syslog
control characters could inject forged syslog frames when
SyslogSinkOptions.includeStructuredDatawas enabled. Structureddata values now replace C0 control characters with printable
#NNNsequences, and structured data parameters with invalid RFC 5424
SD-NAMEkeys are skipped. [CVE-2026-54511]
v2.1.4Compare Source
Released on June 13, 2026.
@logtape/file
getRotatingFileSink()could leave recordsqueued during an active background flush buffered until the next log record
or disposal.
microsoft/playwright (@playwright/test)
v1.61.1Compare Source
v1.61.0Compare Source
🔑 WebAuthn passkeys
New Credentials virtual authenticator, available via browserContext.credentials, lets tests register passkeys and answer
navigator.credentials.create()/navigator.credentials.get()ceremonies in the page — no real hardware key required, works in all browsers:You can also let the app register a passkey once in a setup test, read it back with [credentials.get()](https://playwright.dev/docs/api/class-credentials#creden
Configuration
📅 Schedule: (in timezone Europe/Budapest)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.