chore(deps): update all non-major dependencies#179
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughRoutine dependency and tooling version bumps across the monorepo: GitHub Actions pins for CodSpeed and zizmor are updated, pnpm is upgraded to 11.8.0, vitest to 4.1.9, and several package dependencies ( ChangesDependency and Tooling Version Bumps
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related issues
Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
0bdbc1d to
e1820a8
Compare
|
View your CI Pipeline Execution ↗ for commit d0da768
☁️ Nx Cloud last updated this comment at |
commit: |
d0da768 to
9377778
Compare
|
c069dc8 to
955e375
Compare
955e375 to
e109fbe
Compare
This PR contains the following updates:
^5.5.0→^5.7.19.0.0-beta.16→9.0.0-beta.21v4.17.5→v4.18.1^6.16.1→^6.21.0^22.7.5→^22.7.6^3.8.4→^3.8.519.2.0→19.2.719.2.0→19.2.7^7.8.4→^7.8.5^1.11.1→^1.12.0^0.22.2→^0.22.38.4.1→8.5.0^6.7.2→^6.7.44.1.8→4.1.9^0.13.1→^0.14.0v0.5.6→v0.5.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
CodSpeedHQ/codspeed-node (@codspeed/vitest-plugin)
v5.7.1Compare Source
What's Changed
Full Changelog: CodSpeedHQ/codspeed-node@v5.7.0...v5.7.1
v5.7.0Compare Source
Highlights
CODSPEED_WALLTIME_PROFILER=samplyenv variable in the codspeed action.What's Changed
Full Changelog: CodSpeedHQ/codspeed-node@v5.6.0...v5.7.0
v5.6.0Compare Source
What's Changed
Full Changelog: CodSpeedHQ/codspeed-node@v5.5.0...v5.6.0
TanStack/table (@tanstack/react-table)
v9.0.0-beta.21Compare Source
Version 9.0.0-beta.21 - 6/26/26, 2:03 PM
Changes
Feat
197fd75) by Kevin Van CottPackages
v9.0.0-beta.20Compare Source
Version 9.0.0-beta.20 - 6/26/26, 1:41 PM
Changes
Feat
0a89a97) by Kevin Van CottChore
2ee9de4) by Kevin Van Cott64b3642) by Kevin Van CottPackages
v9.0.0-beta.19Compare Source
Version 9.0.0-beta.19 - 6/25/26, 4:08 AM
Changes
Fix
f077ae7) by Kevin Van CottDocs
51298bb) by Kevin Van Cotta7aae8b) by Kevin Van Cotta471632) by Kevin Van Cott4e8a35d) by Kevin Van CottExamples
d1c84eb) by Kevin Van CottPackages
v9.0.0-beta.18Compare Source
Version 9.0.0-beta.18 - 6/24/26, 1:07 PM
Changes
Fix
de74706) by Kevin Van CottChore
5c58673) by @SheraffDocs
17b84c3) by Kevin Van CottPackages
v9.0.0-beta.17Compare Source
Version 9.0.0-beta.17 - 6/20/26, 8:27 PM
Changes
Fix
f237e20) by Kevin Van CottChore
dde8248) by Kevin Van CottPackages
CodSpeedHQ/action (CodSpeedHQ/action)
v4.18.1Compare Source
Release Notes
🚀 Features
Install codspeed-runner 4.18.1
Install prebuilt binaries via shell script
Download codspeed-runner 4.18.1
Full Runner Changelog: https://github.com/CodSpeedHQ/codspeed/blob/main/CHANGELOG.md
v4.18.0Compare Source
Release Notes
🚀 Features
🐛 Bug Fixes
Install codspeed-runner 4.18.0
Install prebuilt binaries via shell script
Download codspeed-runner 4.18.0
Full Runner Changelog: https://github.com/CodSpeedHQ/codspeed/blob/main/CHANGELOG.md
v4.17.6Compare Source
Release Notes
🚀 Features
PerfEventto also support samply format by @GuillaumeLagrange🐛 Bug Fixes
💼 Other
🏗️ Refactor
📚 Documentation
⚙️ Internals
Install codspeed-runner 4.17.6
Install prebuilt binaries via shell script
Download codspeed-runner 4.17.6
Full Runner Changelog: https://github.com/CodSpeedHQ/codspeed/blob/main/CHANGELOG.md
Full Changelog: CodSpeedHQ/action@v4.17.5...v4.17.6
webpro-nl/knip (knip)
v6.21.0: Release 6.21.0Compare Source
8754c43)3c8deac) - thanks @gwagjiug!9b8af2b)f89db41)f32c6ea)v6.20.0: Release 6.20.0Compare Source
6f08c68)2bc2f24)v6.19.0: Release 6.19.0Compare Source
3fee8bf) - thanks @fubits1!e30cfe7)71e71a7)v6.18.0: Release 6.18.0Compare Source
7dda4ec)3b71565)64865f8)ec93e20) - thanks @remcohaszing!203c31e)392835a)62d802b)d2caedd) - thanks @gwagjiug!9083c16) - thanks @WooWan!v6.17.2: Release 6.17.2Compare Source
63dbd65)vitest --coverageflag (#1800) (dc11d9f) - thanks @WooWan!8ce1ec8) - thanks @WooWan!27a1cae)630e152)v6.17.1: Release 6.17.1Compare Source
b13d0ca)29f3e46)7b2f345)820c233)v6.17.0: Release 6.17.0Compare Source
e3d93b9) - thanks @sh962214-hub!e6cc533) - thanks @jthrilly!15a329a)fa8eb6d)98aa962)67a0be8)aeabff7)12f266e)bdffeec)3334193)be34178)55e3f3b)67483f0)9bb0512)1c2f398)4ebce9c)8c028e5)nrwl/nx (nx)
v22.7.6Compare Source
22.7.6 (2026-06-23)
🩹 Fixes
❤️ Thank You
prettier/prettier (prettier)
v3.8.5Compare Source
facebook/react (react)
v19.2.7: 19.2.7 (June 1st, 2026)Compare Source
React Server Components
FormDataentries in Server Actions which regressed in 19.2.6(#36566 by @unstubbable)
v19.2.6: 19.2.6 (May 6th, 2026)Compare Source
React Server Components
(by @eps1lon and @unstubbable)
v19.2.5: 19.2.5 (April 8th, 2026)Compare Source
React Server Components
v19.2.4: 19.2.4 (January 26th, 2026)Compare Source
React Server Components
v19.2.3: 19.2.3 (December 11th, 2025)Compare Source
React Server Components
v19.2.2: 19.2.2 (December 11th, 2025)Compare Source
React Server Components
react-server-dom-webpack/*.unbundledto privatereact-server-dom-unbundled(@eps1lon #35290)v19.2.1: 19.2.1 (December 3rd, 2025)Compare Source
React Server Components
npm/node-semver (semver)
v7.8.5Compare Source
Bug Fixes
9c8692a#878 include prereleases in tilde range lower bound with includePrerelease (#878) (@chatman-media)QuiiBz/sherif (sherif)
v1.12.0Compare Source
What's Changed
devEnginesforroot-package-manager-fieldrule by @MasterLambaster in #156New Contributors
Full Changelog: QuiiBz/sherif@v1...v1.12.0
rolldown/tsdown (tsdown)
v0.22.3Compare Source
🚨 Breaking Changes
🐞 Bug Fixes
🏎 Performance
View changes on GitHub
nodejs/undici (undici-types)
v8.5.0Compare Source
This release line addresses 8 security advisories. Most are fixed in
v8.5.0; the SOCKS5 pool-reuse issue was fixed earlier in v8.2.0.
Summary
32dbf0b3b4c287b342d49559a516f870cb105d7c5655ea435655ea436ea54ef8High severity
WebSocket DoS via fragment count bypass — CVE-2026-12151
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix:
32dbf0b3websocket: limit the number of fragments in a message (alsoc5ed7875handle empty fragments and stream limits)A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service.
new WebSocket(...)orWebSocketStreamagainst untrusted endpoints.
WebSocket DoS via cumulative fragment bypass — CVE-2026-9675
GHSA-38rv-x7px-6hhq · CWE-400, CWE-770
Fix:
b4c287b3fix(websocket): enforce max payload size across fragmentsUndici validated the size of individual frames but did not track cumulative size
across a fragmented message. An attacker could send many small fragments that
each pass per-frame validation but collectively exceed the configured limit,
causing memory exhaustion. This is a regression introduced in 8.1.0 (the
6.x and 7.x lines are not affected).
TLS certificate validation bypass in SOCKS5 ProxyAgent — CVE-2026-9697
GHSA-vmh5-mc38-953g · CWE-295
Fix:
42d49559fix: honor requestTls when proxy is SOCKS5The
ProxyAgentsilently discarded therequestTlsoption when configured witha SOCKS5 proxy. TLS connections through the SOCKS5 tunnel ignored user-configured
parameters such as
ca,cert,key,rejectUnauthorized, andservername,falling back to the default Mozilla CA bundle. Applications relying on
certificate pinning to an internal CA were exposed to man-in-the-middle attacks.
ProxyAgent/Socks5ProxyAgentover SOCKS5 that rely onrequestTls.ProxyAgent, whererequestTlsfunctions correctly.Cross-origin request routing via SOCKS5 proxy pool reuse — CVE-2026-6734
GHSA-hm92-r4w5-c3mj · CWE-346 · Fixed in 8.2.0
Fix:
a516f870fix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing (#5041)Socks5ProxyAgentreused a single connection pool across different originswithout verifying the pool's origin matched the requested origin. This could
route credentials and request data to unintended destinations, cause responses
from the wrong origin to be trusted, and enable HTTPS→HTTP downgrade.
Socks5ProxyAgentacross multiple origins(introduced via #4385).
Moderate severity
Cross-user information disclosure via shared cache whitespace bypass — CVE-2026-9678
GHSA-pr7r-676h-xcf6 · CWE-524
Fix:
cb105d7cfix(cache): trim qualified field namesThe cache interceptor mishandled responses with whitespace-padded
Cache-Controldirectives such asprivate=" authorization". In shared-cachemode this could cause authenticated data to be cached and served to other users.
Authorizationupstream and receive non-canonical qualified directives.caching authenticated responses, or add
Vary: Authorizationupstream.HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679
GHSA-p88m-4jfj-68fv · CWE-93
Fix:
5655ea43*fix(cookiesConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.