Skip to content

chore(deps): bump the npm-minor-and-patch group with 10 updates - #4428

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-15877b2bed
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-15877b2bed

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-and-patch group with 10 updates:

Package From To
@vitest/coverage-v8 5.0.2 5.0.3
lint-staged 17.5.1 17.6.0
vitest 5.0.2 5.0.3
snowflake-sdk 3.3.0 3.4.0
globals 17.12.0 17.13.0
mocha 12.0.2 12.0.3
typescript-eslint 8.70.1 8.71.0
sass-embedded 1.105.0 1.105.1
vite 8.3.1 8.3.2
vue-tsc 3.3.11 3.3.12

Updates @vitest/coverage-v8 from 5.0.2 to 5.0.3

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates lint-staged from 17.5.1 to 17.6.0

Release notes

Sourced from lint-staged's releases.

v17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Changelog

Sourced from lint-staged's changelog.

17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Commits
  • 48f9f4e Merge pull request #1857 from lint-staged/changeset-release/main
  • 16b2e21 chore(changeset): release
  • 195f156 docs: improve changeset
  • 0ba6261 fix: create hidden directory only when required
  • 66ac2de docs: fixes to changesets
  • 80af8d7 Merge pull request #1863 from lint-staged/fix-issues
  • e433488 fix: handle task editing a symlinked file to a regular file, and --fail-on-ch...
  • e5019b3 fix: handle trailing newlines when detecting changed files
  • 74efec8 ci: run Cygwin and MSYS2 tests on Node.js 26
  • 655b7dc fix: use TypeScript types instead of JSDoc
  • Additional commits viewable in compare view

Updates vitest from 5.0.2 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates snowflake-sdk from 3.3.0 to 3.4.0

Release notes

Sourced from snowflake-sdk's releases.

Release

Changelog

Sourced from snowflake-sdk's changelog.

3.4.0

New features:

  • Added the workloadIdentityHostsnowflakedb/snowflake-connector-nodejs#1479

Changes:

  • Turned OCSP off by default and marked it as @deprecated. OCSP support will be removed in the next major release; use CRL validation (certRevocationCheckModesnowflakedb/snowflake-connector-nodejs#1482snowflakedb/snowflake-connector-nodejs#1485, snowflakedb/snowflake-connector-nodejs#1489)
    • To keep using OCSP, call snowflake.configure({ disableOCSPChecks: false }) or snowflake.configure({ ocspFailOpen: true|false }). disableOCSPChecks: true always turns OCSP off, even when ocspFailOpen is set. CRL still takes precedence when certRevocationCheckMode is enabled
    • Deprecated APIs: OCSP options (disableOCSPChecks, ocspFailOpen, useConnectionConfigProxyForOCSP), connection.setupOcspPrivateLink(), ocspModes, and OCSP error codes

Bugfixes:

  • Fixed failed PUT operations reporting Unknown Error in uploading a filesnowflakedb/snowflake-connector-nodejs#1478
  • Hardened external-browser authentication: the local callback listener now binds to 127.0.0.1, rejects requests whose Originsnowflakedb/snowflake-connector-nodejs#1493

Dependencies:

  • Bumped toml dependency to ^5.0.0snowflakedb/snowflake-connector-nodejs#1477
Commits
  • 099fb93 3.4.0 release (#1492)
  • 93765b5 SNOW-3649847: Accept external-browser callback Origin only from the Snowflake...
  • 9f05690 [SNOW-4108955] Reqs changed: disableocsp should triumph over fail-open settin...
  • df3e57a SNOW-4108955 Code Review Polishing (#1485)
  • 4499225 SNOW-4108955-ocsp by default (#1482)
  • b3d150d SNOW-4017205 - Polish sts endpoint logic (#1484)
  • 6384740 SNOW-4017203 Add tests for min TLS version, fix propagating errors from file ...
  • c528630 SNOW-4017205 Make STS hostname configurable (#1479)
  • 19bfce7 SNOW-4065118 Update toml dependency to 5.x (#1477)
  • See full diff in compare view

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

Updates mocha from 12.0.2 to 12.0.3

Release notes

Sourced from mocha's releases.

v12.0.3

12.0.3 (2026-10-01)

🩹 Fixes

  • keep watching when the last test file is removed (#6355) (921c161)
  • show require() error on unsupported directory import (#6354) (a68344f)
  • support --X one-char aliases (#6391) (1227939)

📚 Documentation

🧹 Chores

Changelog

Sourced from mocha's changelog.

12.0.3 (2026-10-01)

🩹 Fixes

  • keep watching when the last test file is removed (#6355) (921c161)
  • show require() error on unsupported directory import (#6354) (a68344f)
  • support --X one-char aliases (#6391) (1227939)

📚 Documentation

🧹 Chores

Commits

Updates typescript-eslint from 8.70.1 to 8.71.0

Release notes

Sourced from typescript-eslint's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from typescript-eslint's changelog.

8.71.0 (2026-09-28)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates sass-embedded from 1.105.0 to 1.105.1

Changelog

Sourced from sass-embedded's changelog.

1.105.1

  • Improve error messages for @extends across different media queries.
Commits

Updates vite from 8.3.1 to 8.3.2

Release notes

Sourced from vite's releases.

v8.3.2

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Changelog

Sourced from vite's changelog.

8.3.2 (2026-10-01)

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Commits
  • 1003321 release: v8.3.2 (#23623)
  • 24bd331 fix(worker): align worker urls in client and server when using terser (#23614)
  • 94d0080 perf: only register time middleware when debug logging is enabled (#23621)
  • 89574f6 perf: avoid encoding intermediate source maps (#23461)
  • 5a3a010 fix(server): release previous environments after initialization (#23499)
  • 1929b4c docs: fix dead og-image PNG links in vite6/vite7 changelog entries (#23594)
  • 6894f5c fix(server): handle file watcher errors without crashing (#23503)
  • cf5c028 perf(build): avoid quadratic link scan in the preload helper (#23510)
  • bba3bb8 fix: merge build.rolldownOptions.output.minify correctly (#23536)
  • 5e4b9ca fix(optimize-deps): avoid "unsupported" warnings for browser:false mappings (...
  • Additional commits viewable in compare view

Updates vue-tsc from 3.3.11 to 3.3.12

Release notes

Sourced from vue-tsc's releases.

v3.3.12

language-core

  • security: improved handling of untrusted Vue files (cea0698)
  • feat: infer first parameter type of default factory for defineModel (1be73b8)
  • feat: report duplicate CSS module names, including non-identifier names (d41d919) (ffb85e5)
  • fix: keep union props when using withDefaults (084f30f)
  • fix: keep inference-only props string single-line with block comments (55ca36f)
  • fix: support calling template bindings without .value (7ad4a94)
  • fix: avoid type guards missing from the tsc bundle in template binding analysis (e743e80)
  • fix: pad directive hook signatures to check short-arity directive bindings (94052b8)
  • fix: vueCompilerOptions.plugins now overrides the inherited list instead of being deduplicated on resolve (4fa9e97) (c0e5d2e)
  • fix: eliminate synthesized ignore comments across codegen, scoped class aliases and compound event handlers (dbcb7de) (

Bumps the npm-minor-and-patch group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.2` | `5.0.3` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `17.5.1` | `17.6.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.2` | `5.0.3` |
| [snowflake-sdk](https://github.com/snowflakedb/snowflake-connector-nodejs) | `3.3.0` | `3.4.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |
| [mocha](https://github.com/mochajs/mocha) | `12.0.2` | `12.0.3` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.1` | `8.71.0` |
| [sass-embedded](https://github.com/sass/embedded-host-node) | `1.105.0` | `1.105.1` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.2` |
| [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `3.3.11` | `3.3.12` |


Updates `@vitest/coverage-v8` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `lint-staged` from 17.5.1 to 17.6.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.5.1...v17.6.0)

Updates `vitest` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `snowflake-sdk` from 3.3.0 to 3.4.0
- [Release notes](https://github.com/snowflakedb/snowflake-connector-nodejs/releases)
- [Changelog](https://github.com/snowflakedb/snowflake-connector-nodejs/blob/master/CHANGELOG.md)
- [Commits](snowflakedb/snowflake-connector-nodejs@v3.3.0...v3.4.0)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

Updates `mocha` from 12.0.2 to 12.0.3
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md)
- [Commits](mochajs/mocha@v12.0.2...v12.0.3)

Updates `typescript-eslint` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

Updates `sass-embedded` from 1.105.0 to 1.105.1
- [Changelog](https://github.com/sass/embedded-host-node/blob/main/CHANGELOG.md)
- [Commits](sass/embedded-host-node@1.105.0...1.105.1)

Updates `vite` from 8.3.1 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

Updates `vue-tsc` from 3.3.11 to 3.3.12
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.12/packages/tsc)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: lint-staged
  dependency-version: 17.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: snowflake-sdk
  dependency-version: 3.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: mocha
  dependency-version: 12.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: sass-embedded
  dependency-version: 1.105.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: vue-tsc
  dependency-version: 3.3.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 5, 2026
@posit-snyk-bot

posit-snyk-bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant