chore(deps): bump the npm-dependencies group with 13 updates#17
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
chore(deps): bump the npm-dependencies group with 13 updates#17dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the npm-dependencies group with 13 updates: | Package | From | To | | --- | --- | --- | | [@vercel/analytics](https://github.com/vercel/analytics/tree/HEAD/packages/web) | `1.6.0` | `1.6.1` | | [@vercel/speed-insights](https://github.com/vercel/speed-insights/tree/HEAD/packages/web) | `1.3.0` | `1.3.1` | | [next](https://github.com/vercel/next.js) | `16.0.6` | `16.0.10` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.0` | `19.2.3` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.0` | `19.2.3` | | [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) | `4.1.17` | `4.1.18` | | [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `5.1.1` | `5.1.2` | | [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.8.32` | `2.9.7` | | [jsdom](https://github.com/jsdom/jsdom) | `27.2.0` | `27.3.0` | | [lefthook](https://github.com/evilmartians/lefthook) | `2.0.4` | `2.0.11` | | [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) | `0.19.1` | `0.20.0` | | [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.1.17` | `4.1.18` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.14` | `4.0.15` | Updates `@vercel/analytics` from 1.6.0 to 1.6.1 - [Release notes](https://github.com/vercel/analytics/releases) - [Commits](https://github.com/vercel/analytics/commits/1.6.1/packages/web) Updates `@vercel/speed-insights` from 1.3.0 to 1.3.1 - [Release notes](https://github.com/vercel/speed-insights/releases) - [Commits](https://github.com/vercel/speed-insights/commits/1.3.1/packages/web) Updates `next` from 16.0.6 to 16.0.10 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v16.0.6...v16.0.10) Updates `react` from 19.2.0 to 19.2.3 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.3/packages/react) Updates `react-dom` from 19.2.0 to 19.2.3 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.3/packages/react-dom) Updates `@tailwindcss/postcss` from 4.1.17 to 4.1.18 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.1.18/packages/@tailwindcss-postcss) Updates `@vitejs/plugin-react` from 5.1.1 to 5.1.2 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@5.1.2/packages/plugin-react) Updates `baseline-browser-mapping` from 2.8.32 to 2.9.7 - [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases) - [Commits](web-platform-dx/baseline-browser-mapping@v2.8.32...v2.9.7) Updates `jsdom` from 27.2.0 to 27.3.0 - [Release notes](https://github.com/jsdom/jsdom/releases) - [Changelog](https://github.com/jsdom/jsdom/blob/main/Changelog.md) - [Commits](jsdom/jsdom@27.2.0...27.3.0) Updates `lefthook` from 2.0.4 to 2.0.11 - [Release notes](https://github.com/evilmartians/lefthook/releases) - [Changelog](https://github.com/evilmartians/lefthook/blob/master/CHANGELOG.md) - [Commits](evilmartians/lefthook@v2.0.4...v2.0.11) Updates `markdownlint-cli2` from 0.19.1 to 0.20.0 - [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md) - [Commits](DavidAnson/markdownlint-cli2@v0.19.1...v0.20.0) Updates `tailwindcss` from 4.1.17 to 4.1.18 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.1.18/packages/tailwindcss) Updates `vitest` from 4.0.14 to 4.0.15 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.15/packages/vitest) --- updated-dependencies: - dependency-name: "@vercel/analytics" dependency-version: 1.6.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@vercel/speed-insights" dependency-version: 1.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: next dependency-version: 16.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: react dependency-version: 19.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: react-dom dependency-version: 19.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@tailwindcss/postcss" dependency-version: 4.1.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@vitejs/plugin-react" dependency-version: 5.1.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: baseline-browser-mapping dependency-version: 2.9.7 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: jsdom dependency-version: 27.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: lefthook dependency-version: 2.0.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: markdownlint-cli2 dependency-version: 0.20.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: tailwindcss dependency-version: 4.1.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: vitest dependency-version: 4.0.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
michellepace
added a commit
that referenced
this pull request
Dec 19, 2025
Dependencies (security): - next: 16.0.8 → 16.0.10 (CVE-2025-66478) - react/react-dom: 19.2.1 → 19.2.3 (RSC security fixes) Dependencies (dev): - @tailwindcss/postcss: 4 → 4.1.18 - @types/node: 24 → 25 (major) - baseline-browser-mapping: 2.9.6 → 2.9.7 - lefthook: 2.0.9 → 2.0.11 - tailwindcss: 4 → 4.1.18 GitHub Actions: - actions/upload-artifact: v5 → v6 (Node.js 24 support) Consolidates updates from dependabot PRs #16, #17, #18. Includes security patches for Next.js and React Server Components. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Owner
|
Consolidated into PR #15 |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-dependencies group with 13 updates:
1.6.01.6.11.3.01.3.116.0.616.0.1019.2.019.2.319.2.019.2.34.1.174.1.185.1.15.1.22.8.322.9.727.2.027.3.02.0.42.0.110.19.10.20.04.1.174.1.184.0.144.0.15Updates
@vercel/analyticsfrom 1.6.0 to 1.6.1Release notes
Sourced from
@vercel/analytics's releases.Commits
0028584fix(nuxt): remove the module as breaking change (#181)Updates
@vercel/speed-insightsfrom 1.3.0 to 1.3.1Release notes
Sourced from
@vercel/speed-insights's releases.Commits
2452c35fix(nuxt): remove the module as breaking change (#107)Updates
nextfrom 16.0.6 to 16.0.10Release notes
Sourced from next's releases.
Commits
581dee6v16.0.109a0dc9cBackport facebook/react#35351 for 16.0.9 (#87085)3f6a39fv16.0.975e136aUpdate React Versions (#40)4e20596Update React Version (#22)fa85848Backport Next.js changes to v16.0.9 (#20)817ee56v16.0.8b298173Update react version in cna templates (#86950)7492122v16.0.7d21259dupdate version scriptUpdates
reactfrom 19.2.0 to 19.2.3Release notes
Sourced from react's releases.
Changelog
Sourced from react's changelog.
Commits
612e371Version 19.2.3b910fc1Version 19.2.2053df4eVersion 19.2.1Updates
react-domfrom 19.2.0 to 19.2.3Release notes
Sourced from react-dom's releases.
Changelog
Sourced from react-dom's changelog.
Commits
612e371Version 19.2.3b910fc1Version 19.2.2053df4eVersion 19.2.1Updates
@tailwindcss/postcssfrom 4.1.17 to 4.1.18Release notes
Sourced from
@tailwindcss/postcss's releases.Changelog
Sourced from
@tailwindcss/postcss's changelog.Commits
9b32f7cRelease v4.1.18 (#19431)9c8cf8aFix formatting of path in README.md (#19407)Updates
@vitejs/plugin-reactfrom 5.1.1 to 5.1.2Changelog
Sourced from
@vitejs/plugin-react's changelog.Commits
f127a24release: plugin-react@5.1.2db1c665fix(react): newer full bundle mode compat (#1011)1f372b6fix(deps): update all non-major dependencies (#1008)d52455efix(deps): update react 19.2.1 (#998)bcda041fix(deps): update all non-major dependencies (#995)c80546dfix(deps): update all non-major dependencies (#982)Updates
baseline-browser-mappingfrom 2.8.32 to 2.9.7Release notes
Sourced from baseline-browser-mapping's releases.
Commits
30bd7d0Patch to 2.9.7 because browser or feature data changed40a5973Browser or feature data changed13617dfUpdating static site92a0110Patch to 2.9.6 because browser or feature data changed78b2795Browser or feature data changedd3d9879Updating static site9193e75Patch to 2.9.5 because browser or feature data changedb418f5dBrowser or feature data changedbaac99eUpdating static site73c8429Patch to 2.9.4 because browser or feature data changedUpdates
jsdomfrom 27.2.0 to 27.3.0Release notes
Sourced from jsdom's releases.
Changelog
Sourced from jsdom's changelog.
Commits
56b75c2Version 27.3.0decdb95Update dependencies and dev dependencies542b1a6CSSOM improvementsUpdates
lefthookfrom 2.0.4 to 2.0.11Release notes
Sourced from lefthook's releases.
Changelog
Sourced from lefthook's changelog.
Commits
cffbf6c2.0.11: improved remotes fetching, flags completionf7bfafdfeat: refetch and cleanup on ref change (#1210)dcb45c0ci: npm trusted publishing (#1234)fd62bbbfeat: more rudimentary shell completions (#1230)8d74b7c2.0.10: no_auto_install option + fix for empty {files} templateb3791f6feat: add no_auto_install to lefthook.yml (#1231)1f7303dfix: skip if empty files template (#1233)c951a262.0.9: skip pre-commit hook if staged only deleted files07c5ccbfix: skip pre commit hook if no staged files (#1229)97a7399fix: do not try to hash-object directories (#1220)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for lefthook since your current version.
Updates
markdownlint-cli2from 0.19.1 to 0.20.0Changelog
Sourced from markdownlint-cli2's changelog.
Commits
7339935Update to version 0.20.0.b4a4257Add custom rule markdownlint-rule-numbered-headings-unique to Docker containe...dff79ccUpdate documentation and tests for markdownlint version update in previous co...dedb028Bump markdownlint from 0.39.0 to 0.40.0cddf727Add test to ensure all project version numbers match.a1f74abBump execa from 9.6.0 to 9.6.1d2942baUpdate indirect playwright dependencies to 1.57.0.619cca1Bump@playwright/testfrom 1.56.1 to 1.57.0320454aBump eslint-plugin-jsdoc from 61.4.0 to 61.4.1bacb4e3Exclude more invalid JavaScript test files from CodeQL analysis to avoid "Cou...Updates
tailwindcssfrom 4.1.17 to 4.1.18Release notes
Sourced from tailwindcss's releases.
Changelog
Sourced from tailwindcss's changelog.
Commits
9b32f7cRelease v4.1.18 (#19431)820d907ExposecandidatesToAstto the language server (#19405)478e959Don’t emit color-mix fallback rules inside@keyframes(#19419)a5f4644Validate named values in candidate parser (#19397)229121dCanonicalization: combinetext-*andleading-*classes (#19396)243615eHandle backwards compatibility forcontenttheme from JS configs (#19381)7642751Improve compatibility with special default values in JS configs (#19348)af48117remove unnecessary intermediate check9e436f7Try to canonicalize any arbitrary utility to a bare value (#19379)479b725Bump Vitest to v4 (#19216)Updates
vitestfrom 4.0.14 to 4.0.15Release notes
Sourced from vitest's releases.
Commits
eb1abf0chore: release v4.0.15a68f74efeat(cache): add opt-out on a plugin level, fix internal root cache (#9154)122ff32feat(reporters): print import duration breakdown (#9105)0d2e7e3fix(browser): runtoMatchScreenshotonly once when used with `expect.elemen...d57d8bffix(pool): terminate workers onCTRL+cforceful exits (#9140)bb65e15fix(reporters): show project in github reporter (#9138)52b242bchore(deps): update all non-major dependencies (#9133)4c75492fix: fix external behavior withdeps.optimizer(#9125)a5d98fdrefactor(vitest): get current test name from task property (#9120)fd8bd6dfix: useoptimizeDeps.rolldownOptionsto fix depreated warning + fix `ssr.e...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions