Skip to content

chore(deps): bump the frontend-dependencies group across 1 directory with 6 updates - #78

Merged
evilguy4000 merged 2 commits into
mainfrom
dependabot/npm_and_yarn/frontend/frontend-dependencies-03fcd93374
Oct 6, 2026
Merged

evilguy4000 merged 2 commits into
mainfrom
dependabot/npm_and_yarn/frontend/frontend-dependencies-03fcd93374

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the frontend-dependencies group with 6 updates in the /frontend directory:

Package From To
@sentry/react 10.75.0 11.2.0
react-i18next 17.0.14 17.0.15
jsdom 30.1.0 30.1.1
sharp 0.35.4 0.35.5
vite 8.3.0 8.3.2
vitest 5.0.1 5.0.3

Updates @sentry/react from 10.75.0 to 11.2.0

Release notes

Sourced from @​sentry/react's releases.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)
  • ci: shard Bun integration tests (#24771)

... (truncated)

Changelog

Sourced from @​sentry/react's changelog.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)

... (truncated)

Commits
  • e1a4316 release: 11.2.0
  • 95153b1 Merge pull request #24927 from getsentry/prepare-release/11.2.0
  • b8a90a4 meta(changelog): Update changelog for 11.2.0
  • a0faac6 fix(deps): runtime dependency security fixes (#24911)
  • b45e5b8 feat(deps): bump moment from 2.30.1 to 2.31.0 (#24890)
  • 5c82d5b feat(deps): bump hono from 4.13.5 to 4.13.7 (#24916)
  • 2651a8f test(sveltekit): Add missing prerender e2e test (#24921)
  • 8de2036 feat(deps): bump fastify from 5.12.1 to 5.12.5 (#24917)
  • 29fc37c feat(deps): bump axios from 1.18.0 to 1.20.0 (#24918)
  • 012e9bb fix(server-utils): Preserve raw OpenAI embeddings and conversation responses ...
  • Additional commits viewable in compare view

Updates react-i18next from 17.0.14 to 17.0.15

Changelog

Sourced from react-i18next's changelog.

17.0.15

  • fix(Trans): empty paired component tags now preserve a component's single valid React-element child, whether supplied through a named component map (<wrap></wrap>), a component array (<0></0>), or indexed JSX children (<1></1>). This matches the existing behavior for two or more children and self-closing tags. React represents one JSX child as an element and multiple children as an array; the previous array-only check silently rendered the one-child case empty. Compatibility note: when that sole element contains an interpolation object, the restored raw children can expose an existing React rendering limitation as an error instead of silently rendering empty; the same shape already errors with two children. Fixes #1932.
Commits

Updates jsdom from 30.1.0 to 30.1.1

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)
Commits
  • 0a117f4 30.1.1
  • 103f67d Remove unnecessary window cleanup from API tests
  • cdda00a Test HTTP/2 document and subresource loading
  • 7ab92ce Update @​asamuzakjp/dom-selector to v9.2.1
  • d940c20 Share jsdom settings across descendant windows
  • 6ba40cb Fix and simplify option propagation
  • 3b3be70 Preserve CSS priorities across declaration updates
  • 97b2758 Align focusing and unfocusing with HTML
  • b7b460b Update w3c-xmlserializer to v6
  • 71d562f Update html-encoding-sniffer to v7
  • Additional commits viewable in compare view

Updates sharp from 0.35.4 to 0.35.5

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

Updates vite from 8.3.0 to 8.3.2

Release notes

Sourced from vite's releases.

v8.3.2

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)

... (truncated)

Changelog

Sourced from vite's changelog.

8.3.2 (2026-10-01)

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)

... (truncated)

Commits
  • 1003321 release: v8.3.2 (#23623)
  • 24bd331 fix(worker): align worker urls in client and server when using terser (#23614)
  • 94d0080 perf: only register time middleware when debug logging is enabled (#23621)
  • 89574f6 perf: avoid encoding intermediate source maps (#23461)
  • 5a3a010 fix(server): release previous environments after initialization (#23499)
  • 1929b4c docs: fix dead og-image PNG links in vite6/vite7 changelog entries (#23594)
  • 6894f5c fix(server): handle file watcher errors without crashing (#23503)
  • cf5c028 perf(build): avoid quadratic link scan in the preload helper (#23510)
  • bba3bb8 fix: merge build.rolldownOptions.output.minify correctly (#23536)
  • 5e4b9ca fix(optimize-deps): avoid "unsupported" warnings for browser:false mappings (...
  • Additional commits viewable in compare view

Updates vitest from 5.0.1 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…with 6 updates

Bumps the frontend-dependencies group with 6 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [@sentry/react](https://github.com/getsentry/sentry-javascript) | `10.75.0` | `11.2.0` |
| [react-i18next](https://github.com/i18next/react-i18next) | `17.0.14` | `17.0.15` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.0` | `30.1.1` |
| [sharp](https://github.com/lovell/sharp) | `0.35.4` | `0.35.5` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.3` |



Updates `@sentry/react` from 10.75.0 to 11.2.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.75.0...11.2.0)

Updates `react-i18next` from 17.0.14 to 17.0.15
- [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md)
- [Commits](i18next/react-i18next@v17.0.14...v17.0.15)

Updates `jsdom` from 30.1.0 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.0...v30.1.1)

Updates `sharp` from 0.35.4 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.4...v0.35.5)

Updates `vite` from 8.3.0 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@sentry/react"
  dependency-version: 11.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: frontend-dependencies
- dependency-name: react-i18next
  dependency-version: 17.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-dependencies
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-dependencies
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-dependencies
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-dependencies
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@evilguy4000
evilguy4000 merged commit 8b19664 into main Oct 6, 2026
5 of 6 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/frontend-dependencies-03fcd93374 branch October 6, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant