Skip to content

chore(deps): bump the dependencies group across 1 directory with 11 updates - #5761

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-2677368f8f
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-2677368f8f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 11 updates in the / directory:

Package From To
@types/ws 8.18.1 8.18.2
@hono/node-server 2.1.1 2.1.3
@types/node 26.6.3 26.6.4
acorn 8.18.0 8.19.0
cspell 10.3.5 10.3.6
eslint-config-webpack 4.14.0 4.15.0
hono 4.13.10 4.13.13
jsdom 30.1.1 30.1.2
marked 18.0.14 18.1.0
memfs 4.79.0 4.80.0
supertest 7.3.0 7.3.1

Updates @types/ws from 8.18.1 to 8.18.2

Commits

Updates @hono/node-server from 2.1.1 to 2.1.3

Release notes

Sourced from @​hono/node-server's releases.

v2.1.3

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

Commits

Updates @types/node from 26.6.3 to 26.6.4

Commits

Updates acorn from 8.18.0 to 8.19.0

Commits
  • 0e0ece7 Mark version 8.19.0
  • c912cf2 Disallow additional subscripts before arrow in async arrow functions
  • f180fd7 Add Unicode v18 support (#1458)
  • ab47d42 Update test case for unexpected identifier character (#1456)
  • f53ee5f Add a contributing.md file
  • 5bd50cd Compare expression end instead of identity in parseSubscripts
  • efd7a21 Delete trailing space
  • e79ec9e Adjust dubious handling of doubleProto tracking in parseMaybeAssign
  • 93e8b90 Upgrade some dependencies with known issues
  • f065b20 Upgrade github actions to get rid of warning
  • Additional commits viewable in compare view

Updates cspell from 10.3.5 to 10.3.6

Release notes

Sourced from cspell's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.6 (2026-09-29)

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Commits
  • 8559198 v10.3.6
  • 72e1be3 chore: Prepare Release v10.3.6 (auto-deploy) (#9305)
  • e230ca0 test: Give time-limited RPC and worker tests room on slow runners (#9330)
  • 8eae6b6 fix: Report unknown CSpell directives again (#9319)
  • a5f5111 fix: Don't reuse cached results made with different command-line options (#9318)
  • 2f897be fix: --show-perf-summary shows where all of the run's time goes (#9307)
  • fe37b7b chore: Label per package, and bugs links to its open issues (#9309)
  • See full diff in compare view

Updates eslint-config-webpack from 4.14.0 to 4.15.0

Release notes

Sourced from eslint-config-webpack's releases.

v4.15.0

Minor Changes

  • Move prettier/prettier out of the recommended configs into the opt-in stylistic/prettier config; run Prettier on its own instead. (by @​alexander-akait in #212)

Patch Changes

  • Turn off jsdoc rules that TypeScript already reports: require-param-type, require-param-name, require-property-name and implements-on-classes. (by @​alexander-akait in #211)

  • Turn off jsdoc/require-next-type, jsdoc/require-throws-type and jsdoc/require-yields-type. (by @​alexander-akait in #210)

  • Check jsdoc/no-restricted-syntax with one combined selector, so it lints faster. (by @​alexander-akait in #208)

Changelog

Sourced from eslint-config-webpack's changelog.

4.15.0

Minor Changes

  • Move prettier/prettier out of the recommended configs into the opt-in stylistic/prettier config; run Prettier on its own instead. (by @​alexander-akait in #212)

Patch Changes

  • Turn off jsdoc rules that TypeScript already reports: require-param-type, require-param-name, require-property-name and implements-on-classes. (by @​alexander-akait in #211)

  • Turn off jsdoc/require-next-type, jsdoc/require-throws-type and jsdoc/require-yields-type. (by @​alexander-akait in #210)

  • Check jsdoc/no-restricted-syntax with one combined selector, so it lints faster. (by @​alexander-akait in #208)

Commits
  • a67ea3a chore(release): new release (#209)
  • 8e7805c feat(stylistic): move prettier/prettier into an opt-in stylistic/prettier con...
  • 8464b5f perf(jsdoc): turn off require-param-type and explain the disabled type rules ...
  • a7db55d fix(jsdoc): turn off require-next-type, require-throws-type and require-yield...
  • dff9d5e perf(jsdoc): check no-restricted-syntax with one combined selector (#208)
  • 16a18a9 chore(deps): bump codecov/codecov-action in the dependencies group (#206)
  • 397f027 chore(deps): bump the dependencies group across 1 directory with 2 updates (#...
  • See full diff in compare view

Updates hono from 4.13.10 to 4.13.13

Release notes

Sourced from hono's releases.

v4.13.13

Mount Middleware

app.mount() is now available as the Mount Middleware, hono/mount. It is just a handler, so you register it with app.all():

import { Router as IttyRouter } from 'itty-router'
import { Hono } from 'hono'
import { mount } from 'hono/mount'
const ittyRouter = IttyRouter()
ittyRouter.get('/hello', () => new Response('Hello from itty-router'))
const app = new Hono()
app.all('/itty-router/*', mount(ittyRouter.handle))

app.mount() still works in v4 but is deprecated and will be removed in v5. Migrating is a one-line change:

- app.mount('/itty-router', ittyRouter.handle)
+ app.all('/itty-router/*', mount(ittyRouter.handle))

What's Changed

  • test(client): simulate network error for undefined route in parseResponse test in honojs/hono#5439
  • docs(request): fix jsdoc comments for some getters in honojs/hono#5445
  • fix(jsx): allow JSXNode function component results in honojs/hono#5476
  • feat(mount): introduce Mount Middleware and deprecate app.mount in honojs/hono#5221

Full Changelog: honojs/hono@v4.13.12...v4.13.13

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

... (truncated)

Commits
  • 08a023c 4.13.13
  • ae595de feat(mount): introduce Mount Middleware and deprecate app.mount (#5221)
  • f23b146 fix(jsx): allow JSXNode function component results (#5476)
  • 6d73a74 docs(request): fix jsdoc comments for some getters (#5445)
  • deff529 test(client): simulate network error for undefined route in parseResponse tes...
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • Additional commits viewable in compare view

Updates jsdom from 30.1.1 to 30.1.2

Release notes

Sourced from jsdom's releases.

v30.1.2

  • Updated URLs to support Unicode v18.0.0 in internationalized domain names.
  • Reduced package size and memory use for CSS property definitions. (@​scttcper)
  • Fixed severe slowdowns when building large DOM trees, including SVG charts with D3, which regressed in v30.1.0. (@​cmdcolin)
  • Fixed exponentially slow reads of empty inherited CSS custom properties in deeply nested documents, and custom properties incorrectly inheriting past an initial reset. (@​scttcper)
  • Fixed getComputedStyle() returning stale results after editing stylesheet declarations, selectors, or media queries, including in imported stylesheets.
  • Fixed selector matching and computed styles after changes to form control checkedness, indeterminacy, selection, values, and validity, including during form resets and canceled clicks.
  • Fixed computed styles for :focus, :focus-visible, :focus-within, and selectors containing them after focus changes, including inside focus and blur listeners. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing elements hidden by 'display', including through shadow hosts and slots, and elements excluded by shadow DOM slot assignment. (@​asamuzaK)
  • Fixed getComputedStyle() throwing for elements without inline-style support, including XML and MathML elements.
  • Fixed a memory leak where stylesheet parsing retained the last parsed stylesheet's window after window.close().
  • Fixed memory growth from long-lived MutationObserver instances retaining bookkeeping for garbage-collected nodes. (@​scttcper)
  • Fixed retained select.selectedOptions collections becoming stale after selection changes and form resets.
  • Fixed rejection of negative CSS sizing values, including for 'min-width', 'min-height', 'max-width', and 'max-height', which regressed in v30.1.0.
  • Fixed handling of deeply nested color-mix() expressions, including exceptions during color resolution. (@​asamuzaK)
Commits
  • a23bfb7 30.1.2
  • 64a75d2 Update dependencies and dev dependencies
  • 7bf9653 Invalidate styles after CSSOM and control state changes
  • fe9009c Update focused area handling
  • a8d28b3 Release windows retained by stylesheet parsing
  • 05a2c01 Deduplicate generated CSS property metadata
  • 1efa190 Reduce generated CSS property data
  • a372e12 Avoid Document named-property rebuilds after irrelevant tree mutations
  • b2cd235 Update css-color
  • 0542d2b Release idle MutationObserver bookkeeping
  • Additional commits viewable in compare view

Updates marked from 18.0.14 to 18.1.0

Release notes

Sourced from marked's releases.

v18.1.0

18.1.0 (2026-10-05)

Bug Fixes

  • avoid cubic backtracking on unicode whitespace in a link destination (#4106) (0d20220)
  • load CLI configs with top-level await (#4100) (c61543e)
  • reject unbalanced parentheses in link destinations (#4107) (3363c99)

Features

  • add linkParenPossible to lexer state to fail fast for link token generation (#4070) (4ee44f7)
Commits
  • e809386 chore(release): 18.1.0 [skip ci]
  • 3363c99 fix: reject unbalanced parentheses in link destinations (#4107)
  • 0d20220 fix: avoid cubic backtracking on unicode whitespace in a link destination (#4...
  • c18a64f chore(deps): bump undici (#4122)
  • 4ee44f7 feat: add linkParenPossible to lexer state to fail fast for link token genera...
  • c61543e fix: load CLI configs with top-level await (#4100)
  • See full diff in compare view

Updates memfs from 4.79.0 to 4.80.0

Release notes

Sourced from memfs's releases.

Release v4.80.0

What's Changed

New Contributors

Full Changelog: streamich/memfs@v4.79.0...v4.80.0

Commits
  • adae41a chore: release v4.80.0
  • d9cfa18 Merge pull request #1298 from Firatakti/codex/fsa-sync-timeout
  • fe75fbc feat: allow configuring the synchronous FSA worker timeout
  • See full diff in compare view

Updates supertest from 7.3.0 to 7.3.1

Release notes

Sourced from supertest's releases.

v7.3.1

  • Merge pull request #907 from JH8459/fix/ephemeral-loopback-bind 884cd26
  • fix: bind ephemeral server to the loopback address it connects to e74a1e0

forwardemail/supertest@v7.3.0...v7.3.1

Commits
  • 3634bdd 7.3.1
  • 884cd26 Merge pull request #907 from JH8459/fix/ephemeral-loopback-bind
  • e74a1e0 fix: bind ephemeral server to the loopback address it connects to
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…pdates

Bumps the dependencies group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/ws](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/ws) | `8.18.1` | `8.18.2` |
| [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [acorn](https://github.com/acornjs/acorn) | `8.18.0` | `8.19.0` |
| [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) | `10.3.5` | `10.3.6` |
| [eslint-config-webpack](https://github.com/webpack/eslint-config-webpack) | `4.14.0` | `4.15.0` |
| [hono](https://github.com/honojs/hono) | `4.13.10` | `4.13.13` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.1` | `30.1.2` |
| [marked](https://github.com/markedjs/marked) | `18.0.14` | `18.1.0` |
| [memfs](https://github.com/streamich/memfs) | `4.79.0` | `4.80.0` |
| [supertest](https://github.com/ladjs/supertest) | `7.3.0` | `7.3.1` |



Updates `@types/ws` from 8.18.1 to 8.18.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/ws)

Updates `@hono/node-server` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v2.1.1...v2.1.3)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `acorn` from 8.18.0 to 8.19.0
- [Commits](acornjs/acorn@8.18.0...8.19.0)

Updates `cspell` from 10.3.5 to 10.3.6
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell)

Updates `eslint-config-webpack` from 4.14.0 to 4.15.0
- [Release notes](https://github.com/webpack/eslint-config-webpack/releases)
- [Changelog](https://github.com/webpack/eslint-config-webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/eslint-config-webpack@v4.14.0...v4.15.0)

Updates `hono` from 4.13.10 to 4.13.13
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.10...v4.13.13)

Updates `jsdom` from 30.1.1 to 30.1.2
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.1...v30.1.2)

Updates `marked` from 18.0.14 to 18.1.0
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.14...v18.1.0)

Updates `memfs` from 4.79.0 to 4.80.0
- [Release notes](https://github.com/streamich/memfs/releases)
- [Changelog](https://github.com/streamich/memfs/blob/master/CHANGELOG.md)
- [Commits](streamich/memfs@v4.79.0...v4.80.0)

Updates `supertest` from 7.3.0 to 7.3.1
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.3.0...v7.3.1)

---
updated-dependencies:
- dependency-name: "@types/ws"
  dependency-version: 8.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: acorn
  dependency-version: 8.19.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: cspell
  dependency-version: 10.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: eslint-config-webpack
  dependency-version: 4.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: hono
  dependency-version: 4.13.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: jsdom
  dependency-version: 30.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: marked
  dependency-version: 18.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: memfs
  dependency-version: 4.80.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: supertest
  dependency-version: 7.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@changeset-bot

changeset-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 827d531

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants