Skip to content

chore(deps): update all non-major dependencies - #301

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@antfu/eslint-config 9.3.0 → 9.5.1 age confidence devDependencies minor
danielroe/uppt v0.6.9 → v0.6.10 age confidence action patch v0.6.11
pg (source) 8.23.0 → 8.23.1 age confidence devDependencies patch
playwright-core (source) 1.62.1 → 1.63.0 age confidence devDependencies minor
tsdown (source) 0.22.14 → 0.23.0 age confidence devDependencies minor
zod (source) 4.5.4 → 4.6.5 age confidence devDependencies minor

Release Notes

antfu/eslint-config (@​antfu/eslint-config)

v9.5.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v9.5.0

Compare Source

   🚀 Features
    View changes on GitHub

v9.4.1

Compare Source

   🚀 Features
  • pnpm: Enforce new-line style for pnpm-workspace.yaml  -  by @​antfu (ab400)
    View changes on GitHub

v9.4.0

Compare Source

   🚀 Features
    View changes on GitHub
danielroe/uppt (danielroe/uppt)

v0.6.10

Compare Source

compare changes

🚀 Enhancements
  • pr: Treat revert commits as release-worthy (#​70)
🩹 Fixes
  • pr,release: Use correct diff link + strip pending timetable line (6959b96)
🏡 Chore
  • Pin README example to v0.6.9 (e01133f)
  • Add back zizmor-ignore comment (83d5a78)
✅ Tests
  • Add some additional tests (d79b75d)
🤖 CI
  • Use pnpm/setup and devEngines (#​64)
  • Replace agentscan action with the github app (511fe92)
❤️ Contributors
brianc/node-postgres (pg)

v8.23.1

Compare Source

microsoft/playwright (playwright-core)

v1.63.0

Compare Source

rolldown/tsdown (tsdown)

v0.23.0

Compare Source

   🧭 Migration Guide

Most users can upgrade directly. Before upgrading, run one final build with tsdown@0.22.14 and resolve all deprecation warnings.

  • config:
    • bundle: false → unbundle: true; bundle: true can be removed
    • outExtension → outExtensions
    • publicDir / --public-dir → copy / --copy
    • removeNodeProtocol: true → nodeProtocol: 'strip'
    • injectStyle → css.inject
  • deps:
    • inlineOnly / deps.onlyAllowBundle → deps.onlyBundle
    • skipNodeModulesBundle: true → deps.neverBundle: true
    • resolveDepSubpath now defaults to false; set it to true to preserve the previous behavior
  • dts:
    • Select a generator with dts.generator, for example { generator: 'oxc' }
    • dts.cjsReexport was removed; dual-format builds now generate CJS declarations in a separate pass
  • attw:
    • The default profile changed from strict to esm-only; set profile: 'strict' to preserve the previous checks
  • programmatic API:
    • build() now returns { bundles, watch }; replace const bundles = await build() with const { bundles } = await build()
  • requirements:
    • Node.js 25 is no longer supported; use ^22.18.0, ^24.11.0, or >=26.0.0
    • The packages no longer publish legacy types and typesVersions fallbacks; use TypeScript’s bundler, node16, or nodenext module resolution
   🚨 Breaking Changes
   🚀 Features
   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub
colinhacks/zod (zod)

v4.6.5

Compare Source

Commits:

  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#​6598)
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#​6600)
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#​6595)"
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#​6595)""
  • 0f3f5ee 4.6.5
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

Compare Source

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#​6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#​6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#​6153)

v4.6.3

Compare Source

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#​6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

Compare Source

Commits:

v4.6.1

Compare Source

A patch on top of 4.6.0.

v4.6.0

Compare Source

Commits:

  • 908c9e1 fix(docs): retry the GitHub stars fetch and log the real status
  • 93186ca docs(wiki): drop the zod-compiler benchmark (#​6505)
  • 8ce9e8d feat(mini): publish Zod Mini as the standalone @​zod/mini package (#​6491)
  • 2956c4c chore(mini): sync @​zod/mini to 4.5.4
  • abd41ad docs(wiki): move plans and comparisons into a gitignored internal/ (#​6506)
  • 8106573 chore(docs): build with Turbopack
  • c7ec94d ci: check zod and @​zod/mini lockstep on npm after every publish (#​6507)
  • c46eeff chore: narrow blanket biome-ignore comments (#​6504)
  • a0898b4 ci: wait hours for npm to serve a publish, not ten minutes (#​6502)
  • 1c0bce0 docs: bring the 4.5 charts and worked examples into the docs pages
  • 70eb2c0 docs: drop the traits section and the compilation feature bullet
  • 43b9bfc docs: drop the bound-methods section from the Zod package page
  • cd4f9a6 perf(v4): report Standard Schema issues without constructing a ZodError (#​6509)
  • f3cb364 docs: surface the blog on the home page and in the sidebar
  • f3e7c72 fix(docs): render the docs 404 page inside the (doc) layout once
  • f412178 ci: publish @​zod/mini to JSR in lockstep with npm (#​6510)
  • 5ff9566 Stop re-exporting the compile internals from zod/v4/core (#​6511)
  • 40b4d0b fix(ci): read zod's latest version with npm view when picking the backfill dist-tag
  • a6b4939 Mark the compile internals @​internal instead of hiding them (#​6518)
  • 3195ed0 docs: label the memory chart like the compile chart
  • 8cd1250 docs: center the memory chart callout labels
  • ff56a55 docs: center the memory chart callout labels and pad them off the number
  • fb2fedf docs: tighten the memory chart callout, pad the canvas, say "less memory"
  • 93f3ab3 docs: replace the blog navbar's GitHub icon with a star-count pill
  • 7ae49d6 docs: drop the circle around the star pill's GitHub mark and center it on the pill's arc
  • b801439 bench: add typebox (compiled and dynamic) to the moltar cross-library harness
  • 1ec6b7c docs: add an RSS feed to the blog at /blog/rss.xml
  • 08ba069 perf(v4): read Luhn digits with charCodeAt instead of string indexing (#​6529)
  • 319f47f Emit a length-aware base64url pattern in toJSONSchema (#​6527)
  • a2a019a Accept enum-typed targets in z.toZod (#​6528)
  • 74f9a6d docs: drop the toZod enum block from basics and pin the page's curation rule in a comment
  • f83ab51 fix(v4): reject component-only strings from z.emoji() (#​6532)
  • 84dd3b0 perf: build literal and enum pattern regexes lazily (#​6531)
  • 0227e53 docs: bump the star pill's GitHub mark to 20px
  • 68a609a Widen literal inputs in property check types (#​6520)
  • 2ec972e refactor: collapse toZod's enum leaf normalizer to a dummy union (#​6533)
  • bc1157e docs: use a Response example for z.properties()
  • 07c43e2 Keep the runtime base64 regexes linear so composed parse paths cannot overflow (#​6534)
  • bec73be perf(v4): build the safeParse error on first read (#​6519)
  • bf99021 perf: move util.cached's accessor to a prototype (#​6537)
  • 69f2a7f Collapse toZod's normalizer and move its docs to the API reference (#​6539)
  • abfb389 feat(v4): make z.properties() a schema, and give z.instanceof() a .properties() method (#​6536)
  • 51caf01 refactor: collapse cachedInternal back into cached (#​6540)
  • 81ded99 perf: answer z.validate from the compiled fast path on invalid input (#​6538)
  • eca9687 fix(v4): enforce the six JSON Schema keywords fromJSONSchema silently dropped (#​6535)
  • 68aca3d docs: cover the 4.5 API surface that never made it into the reference
  • 18e71c7 Rename the JSON Schema process helper so bundler polyfills cannot collide (#​6541)
  • 90269c6 Keep a numeric TS enum's reverse-mapping keys out of .options (#​6542)
  • 4d73088 Release the parsed input once a failing safeParse builds its error (#​6543)
  • cafbee4 fix(v4): parse recursive schemas built by a factory (#​6530)
  • 62e6624 feat(v4): add .validate() and .validateAsync() to Zod Classic (#​6547)
  • 07917f4 test(v4): pin the lazy safeParse error's stack behavior (#​6548)
  • 764ac59 perf(v4): settle z.validate on the first failure in parse order (#​6544)
  • e760471 docs: attribute the compiled failure cost to the fallback, not the double pass
  • 5489a53 test(v4): pin the check-chain case that keeps compiled validate's definite guard (#​6551)
  • 7a00236 fix(v4): don't let format checks overwrite tighter min/max bounds (#​6553)
  • e4d67f3 Migrate development and CI to Nub (#​6562)
  • 6f04836 fix(v4): derive JSON Schema constraints by folding checks in the converter (#​6554)
  • 804e0f5 perf: seal the CommonJS exports so require("zod") stops reading through a getter (#​6564)
  • 741981f perf(compile): for-in record walk, cheaper issue finalization, and a generative compile differential (#​6567)
  • eb1c108 ci: release only on workflow_dispatch behind the npm environment (#​6569)
  • 277613a docs: move the release procedure to the maintainer-local notes
  • dcbcf05 fix(compile): unwind the doc indent when a child generator throws (#​6570)
  • e54716c docs(ecosystem): add @​apical-ts/craft (#​5946)
  • c5b9bcb bench: measure what a runtime island's leaked indent cost the generated source
  • 22bed61 feat(v4): add z.iban() string format with mod-97 checksum (#​6571)
  • 36f1796 fix(v4): stop the memoizer from pinning a finished parse (#​6572)
  • f7fd554 perf(v4): drop the lookaheads from the email regex (#​6573)
  • f9465d4 docs: reconcile the sponsor listings with active sponsorships (#​6576)
  • 213ee75 feat(compile): add z.withParser for externally generated parsers (#​6575)
  • 6de10dc docs: reconcile the sponsor listings against every active sponsorship (#​6579)
  • 661673a docs: make the 9thCO logo visible on the light theme
  • 1c51cbe 4.6.0
  • 3b15499 feat(lang): add Tajik (tg) locale
  • c532d76 test(locales): cover Tajik error branches
  • 574d480 fix(locales): clarify Tajik discriminator value message
  • dd9c36f fix(v4): defer recursive object index inference (#​6580)
  • b12aa52 fix: preserve unique tags with defaulted discriminators (#​6582)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

◈ PR Lens

Note

This drawing shows 7fca7b7, and the branch has new commits since. Tick Redraw to draw the latest one

  • Redraw

🟢 +0 new · 🟠 ~1 changed · 🔴 -0 removed · 0 flows · 1 file · commit 7fca7b7


Architecture

Architecture diagram for danielroe/zero-vue at 7fca7b7

1 component touched across 2 lanes.

Open the interactive canvas


Data flow

No data-flow sequence changed in this PR.


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."

🪧 More tips
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists.
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds.
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through.
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change.
  • Open a diagram on the canvas, then press W or click play to walk through the change one step at a time.
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time.
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs on every push.
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works.
  • Push a commit and the comment redraws for the new head. A slow older run never overwrites a newer one.
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion.

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@socket-security

socket-security Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedplaywright-core@​1.63.0100100799980
Updatedpg@​8.23.0 ⏵ 8.23.199100100 +187 -4100
Updatedtsdown@​0.22.14 ⏵ 0.23.09810088 +196 +1100
Updatedzod@​4.5.4 ⏵ 4.6.510010010095100
Updated@​antfu/​eslint-config@​9.3.0 ⏵ 9.5.19610010096 +4100

View full report

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 736c77f to c219bda Compare September 14, 2026 08:09
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 7fca7b7 to 800de28 Compare September 21, 2026 08:21
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (1)
  • chore(deps)

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 76164d8c-0c59-47ef-9e87-7cda303c70b0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from a72882e to e5fd0ea Compare September 25, 2026 18:28
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from e5fd0ea to 9b63faa Compare October 1, 2026 00:01
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 9b63faa to 5a15c82 Compare October 1, 2026 18:50

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants