Repository navigation
Update All NPM Dependencies - #17
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
5 times, most recently
from
July 9, 2026 17:45
7f3a8f4 to
223e73b
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
12 times, most recently
from
July 16, 2026 17:37
4f3dd5a to
1aac3e0
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
5 times, most recently
from
July 24, 2026 22:01
2677903 to
97d9913
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
3 times, most recently
from
August 3, 2026 01:46
5426bb1 to
c340b37
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
5 times, most recently
from
August 10, 2026 17:55
baf48d1 to
fb37b54
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
5 times, most recently
from
August 31, 2026 21:51
bc38c7b to
865ab83
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
5 times, most recently
from
September 9, 2026 18:30
8a1c0aa to
8d55ada
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
6 times, most recently
from
September 16, 2026 00:48
4796d1f to
b3389e3
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
6 times, most recently
from
September 25, 2026 00:48
2312afe to
89f1999
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
6 times, most recently
from
October 5, 2026 20:41
feb535b to
22597a1
Compare
renovate
Bot
force-pushed
the
renovate/all-npm-dependencies
branch
from
October 7, 2026 08:26
22597a1 to
9e04fc0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.4.0→2.7.19.39.4→9.39.50.13.11→0.13.147.0.1→7.1.00.1.42→0.3.035.3.0→35.3.19.39.4→9.39.50.14.5→0.18.017.6.0→17.12.02.1.8→2.1.143.8.3→3.9.95.1.0→5.4.01.9.13→1.9.1517.12.0→17.15.08.60.0→8.70.17.3.3→7.3.62.11.12→2.11.14Release Notes
crxjs/chrome-extension-tools (@crxjs/vite-plugin)
v2.7.1Patch Changes
efa9c63: Update direct dependency ranges forconvert-source-map,debug,and
fs-extra.6efde9d: Filter Vite 8/Rolldown-only options before the dev file writer callsRollup, removing
Unknown input options: platformwarnings.v2.7.0Minor Changes
9f00943: Add dev HMR support for manifest-declared MAIN world content scripts.Patch Changes
a9cc89a: Remove unused vite-plugin dependencies and update selected dependencyversions.
v2.6.1Patch Changes
2b88621: Coalesce file writer readiness waits so large dev-server graphupdates do not repeatedly recompute the same dependency traversal. This also
fixes late HMR readiness waits that could miss the shared ready event and
delay content script updates.
v2.6.0Minor Changes
4f5d2ec: feat: add IIFE content script bundlingContent scripts named with
.iife.tsextension are automatically bundled asself-contained IIFE files with all dependencies inlined. This is useful for
MAIN world content scripts used with
chrome.scripting.executeScriptorchrome.scripting.registerContentScripts.Patch Changes
5316e9c: Allowchrome-extension://andmoz-extension://origins in Vitedev-server CORS automatically. This keeps extension pages able to fetch
dev-server files on Vite releases with the stricter localhost-only CORS
default, including Vite
4.5.6,5.4.12, and6.0.9+, without requiringprojects to configure
server.cors.originmanually.1aee9ad: fix: dynamic content scripts failing in build --watch mode2f8bab5: Fix the dev-mode loading page so it waits for the requested extensionHTML file, preserves the page URL query string, allows extension-origin
readiness polling, and throttles automatic reloads to avoid rapid flicker.
1681511: Expand vite-plugin CI to run e2e tests against supported Viteversions and fix compatibility issues exposed by the matrix.
0593d58: fix: publish ESM declarations for the Vite plugin entrypointv2.5.0Minor Changes
4756baf: feat: add HMR support for CSS declared in manifest content_scripts4756baf: add: browser_specific_settings.gecko properties4756baf: Fix "TypeError: plugins is not iterable" error when usingrolldown-vite (Vite 7).
In rolldown-vite, the buildStart hook doesn't receive options.plugins. This
fix uses the configResolved hook to get plugins from the resolved config, with
buildStart kept as a fallback for older Vite versions.
4756baf: Fixed#852, the plugin
now emits a correct URL in
service-worker-loader.jswhen the Vite optionserver.httpsis enabled.4756baf: fix: resolve TypeScript types correctly for ESM and CJS consumers4756baf: feat: add Vite 8 beta supportPatch Changes
4756baf: ci: migrate release workflow to npm trusted publishers570312a: fix: sanitize colons from output filenames on Windows4756baf: fix: copy CSS files declared in manifest content_scripts to output4756baf: Replace cheerio with node-html-parser to fix npm deprecation warningfor whatwg-encoding.
Also adds explicit vite peerDependency declaration (^3.0.0 through ^7.0.0) to
enable proper version resolution when used with different vite versions.
4756baf: ci: run compat tests against stable Vite 8, make the vite8 availableas a peer dependency
4756baf: fix: UnoCSS/TailwindCSS HMR issues with virtual CSS modules8a99b4f: made data_collection_permissions optional4756baf: fix: respect user's build.manifest setting in Vite 4+When users set
build.manifest: falsein their Vite config, the Vite manifestfile (
.vite/manifest.jsonin Vite 5+, ormanifest.jsonin older versions)is now properly removed from the output bundle.
CRXJS internally requires the Vite manifest to derive content script resources
during build, so it forces
build.manifest: true. Previously, this meant theVite manifest was always included in the output even if the user explicitly
disabled it. Now, CRXJS removes the manifest from the bundle after processing
if the user didn't want it.
Closes #1077
d364bd8: chore: upgrade chokidar to 5.0.04756baf: feat(client): Update the style and content of the development modeloading page
eslint/eslint (@eslint/js)
v9.39.5Compare Source
Bug Fixes
253be16fix: handle unavailable require cache (backport of #20812 to v9.x) (#21065) (Eric)Documentation
74930eddocs: switch build to Node.js 24 (#20894) (Milos Djermanovic)eaec8bbdocs: Add ESLint v9.x EOL notice (#20828) (Milos Djermanovic)Chores
458205fchore: update@eslint/eslintrcand@eslint/jsfor v9.39.5 (#21077) (Francesco Trotta)202117bchore: package.json update for @eslint/js release (Jenkins)d9eb6edtest: disable warning forvm.constants.USE_MAIN_CONTEXT_DEFAULT_LOADER(#21074) (Francesco Trotta)7b431a7chore: overridere2dependency for@metascraper/helpers(#21068) (Milos Djermanovic)daf7791chore: pin fflate@0.8.2 (#20895) (Milos Djermanovic)daee8baci: use pnpm ineslint-flat-config-utilstype integration test (#20829) (Milos Djermanovic)116d4beci: unpin Node.js 25.x in CI (#20619) (Copilot)kobaltedev/kobalte (@kobalte/core)
v0.13.14Compare Source
Patch Changes
3d32663: ## v0.13.14 (September 7, 2026)Bug fixes
v0.13.13Patch Changes
cb89022: ## v0.13.13 (August 10, 2026)New features
Bug fixes
release-it/keep-a-changelog (@release-it/keep-a-changelog)
v7.1.0Compare Source
07d9ce2) - thanks @kou029w!183a58f)bcd086a)ag-grid/ag-grid (ag-grid-community)
v35.3.1Compare Source
solidjs-community/eslint-plugin-solid (eslint-plugin-solid)
v0.18.0Compare Source
Four new correctness rules (from #219, thanks @brenelz), a revived community rule (#145, thanks @SarguelUnda), extensions to existing rules, and a batch of reactivity false-positive fixes. Verified against the official Solid 2.0 templates (zero findings).
New rules (enabled in
v2/v2-strict)solid/no-write-in-pure-computation(error) — setter calls increateMemocallbacks, the compute half ofcreateEffect(compute, effect), and component bodies, all pure owned scopes that throw on writes in Solid 2.0 dev. HonorsownedWrite: true;onSettled/createTrackedEffect/handlers/effect halves exempt by function boundary. Closes #79.solid/no-store-mutation-outside-setter(error) — mutating a store's read proxy is silently ignored by core (no error, no update); lint is the only guardrail today.solid/no-unused-signal(warn) — never-written or never-readcreateSignal/createStore/createOptimistictuples, which unused-variable rules can't see.solid/no-boolean-enumerated-attribute(error) — booleans on enumerated attributes (draggable,spellcheck,contenteditable,translate, tristatearia-*) produce a different state than the string tokens; literals autofix. Closes #144/#145.Reactivity false-positive fixes
untrack(async () => ...)no longer reports an async tracked scope (#188)this.state = stateis a reference escape, not a snapshot (#184)makePersisted(createSignal(...))-style wrappers analyze as pass-through (#190)New setting
settings.solid.moduleSourcesregisters custom renderers/re-export wrappers as Solid primitive sources (#183)Full details in the changelog.
v0.17.1Compare Source
Bug fixes only. Thanks to @jynxio and @brenelz for the reports and PRs.
Fixes
solid/reactivityregression from 0.16.1 (#223). ThestaleCapturecheck flagged captures read inside synchronous array-method callbacks (items.filter((item) => item.includes(q))) withincreateMemo/createEffectbodies. A function passed as a call argument doesn't escape through areturnbelow it — only the call's result does — so these callbacks run during the computation, where the capture is fresh. IIFEs are exempt for the same reason.solid/importstype mappings for Solid 2.0 (#220, #221, #222). TheJSXnamespace only exists in@solidjs/webin 2.0; the rule was autofixing correct imports into a module that doesn't export it.ValidComponent/ComponentPropsare now accepted from bothsolid-js(DOM-independent) and@solidjs/web(DOM-aware) since the two packages export genuinely different types. The fixer also no longer produces a duplicatetypemodifier (import type { type JSX }) when moving inline type specifiers.renderToStringAsyncis a removed API, not a misplaced one. It no longer exists in Solid 2.0 (renderToStringawaits async content). Dropped from the v2 imports map — which was autofixing imports into a dead end — and added tosolid/removed-apiwith migration guidance.solid/removed-apinow also scans@solidjs/webimports, so a mechanically source-rewritten import of a removed API is still reported.Also verified fixed and closed: #193 (signals passed as
create*arguments stopped warning with the 0.16.1 accessor-passing work).v0.17.0Compare Source
Server functions are core in Solid 2.0, so the plugin now lints them. Four new rules cover the
"use server"directive's silent failure modes — all enabled as errors in thev2andv2-strictconfigs, and verified against the official Solid 2.0 templates (zero findings) and under Oxlint.New Rules
solid/valid-use-server. The compiler only honors"use server"in specific positions and silently ignores it everywhere else — often shipping database access or secrets to the client without any error. Flags directives that aren't in the directive prologue (after other statements, inside plain blocks), template-literal "directives", and directives in positions the compiler never extracts (object methods, getters/setters, class methods). For module-level directive files, also flags non-function exports (which fail at server boot) and calls to client declaration wrappers (GET,live,withMetafrom@solidjs/web;query,action,liveQueryfrom@solidjs/router), whose client-side behavior is silently compiled out in such files. AclientWrappersoption adds project-specific wrapper names, with*wildcard and/regex/support.solid/require-async-server-function. On the client every server function call resolves a Promise, but during SSR the function is called in-process and returns synchronously — so a non-async server function observes two different return types, and TypeScript only sees one of them. Covers function-level directives and all exports of module-level directive files (includingexport { name }specifiers). Autofixes by insertingasync.solid/no-invalid-server-capture. An editor-time mirror of the compiler's closure-capture validation: server functions cannot capture variables from intermediate scopes (component state, enclosing function parameters), because the extracted function is hoisted to module level on the server and becomes a network proxy on the client. The compiler already rejects this at build time; the rule reports the same captures as you type. Module top-level bindings, imports, globals, own params/locals, named-function-expression self-references, and TS type-only references are all allowed.solid/no-browser-globals-in-server-function. Flags unambiguous browser-only globals (window,document,localStorage, etc.) inside server functions, which only run on the server. The list is deliberately conservative — server runtimes providefetch,crypto,URL, and evennavigator, so those never warn — and shadowing bindings andtypeof windowguards are ignored. In module-level directive files, the whole module is checked.Internal
customReactiveFunctions-style pattern matching (exact names,*wildcards,/regex/strings) was extracted into a sharedcreateNameMatcherutility, now used by bothsolid/reactivityandsolid/valid-use-server.Full Changelog: solidjs-community/eslint-plugin-solid@v0.16.1...v0.17.0
v0.16.1Compare Source
A precision pass over
solid/reactivity, driven by the longest-standing false-positive reports in the tracker. Every fix landed with a regression test reproducing the original issue, and the Solid 2.0 templates still lint clean.Fixes
valuegets a real explanation (#209). Passing a reactive expression to a provider'svalueprop previously produced the generic "should be used within JSX" message — nonsense for something that is in JSX. It now reports a dedicated message explaining that providers readvalueonce, untracked, when created (true in both Solid 1.x and 2.0), and to pass the signal, memo, or store itself. Detection also now covers the Solid 2.0 form, where the context object is used directly as the provider (<MyContext value={...}>), by resolving JSX names tocreateContext()calls.createResourceargument shapes (#199, #195).createResource(fetcher, options)no longer treats the fetcher as a tracked scope (so async fetchers with an options object stop reportingnoAsyncTrackedScope), and increateResource(source, fetcher)the fetcher is now correctly treated as an untracked called function that may be async and read current values. The source remains a synchronous tracked scope.const { item } = propsinsidecreateMemo/createEffectre-runs on updates and no longer warns. Destructuring at component setup level still does.window.setTimeoutand friends (#194). Timer and scheduling callbacks prefixed withwindow.,globalThis., orself.now get the same called-function treatment as the bare globals.mergeProps/mergefunction arguments are tracked scopes (#179). Both wrap function sources increateMemo, so reactive reads inside them no longer warn.createMemoaccessor to acreate*/use*/custom reactive function no longer warns, matching the existing allowance for signals.create*calls (#52).return createMemo(...)(or as an arrow body) no longer reportsshouldAssign— the result is handed to the caller, like a custom primitive.doSomething(() => props.toggle)) no longer warns, matching the existing behavior for named functions: synchronous calls still run tracked, and later calls poll current values.Features
customReactiveFunctions(#176). Entries now support*wildcards ("watch*") and regexes written as"/pattern/"strings, in addition to exact names.v0.16.0Compare Source
The complete Solid 2.0 lint surface: version-aware rules, new
v2/v2-strictconfigs, and afull set of 2.0-specific rules, all vetted against the official Solid 2.0 templates (which lint
clean with zero errors and zero warnings under the
v2config).Features
settings.solid.version. Rules can now read the targeted Solid major version from ESLintsettings (
settings: { solid: { version: 2 } }). Unset means the permissive dual-versionbehavior from 0.15. The new configs preset it; any custom config can opt in with one line.
v2config (eslint-plugin-solid/configs/v2, alsosolid.configs.v2): what theofficial Solid 2.0 templates ship. Sets the version setting, switches existing rules to strict
2.0 semantics, and enables the new 2.0 rules — errors are reserved for near-certain bugs,
heuristics stay warnings.
v2-strictconfig (eslint-plugin-solid/configs/v2-strict): everything inv2plusthe plugin's strongest opinions (see below).
solid/removed-api(error inv2): flags removed/renamed 1.x APIs withautofixes where mechanical (
onMount→onSettled,batch→flush,mergeProps→merge,unwrap→snapshot,equalFn→isEqual,getListener→getObserver,classList={{...}}→class={{...}},"solid-js/web"→"@solidjs/web","solid-js/store"→"solid-js") and prescriptive migration messages otherwise(
createResource,on,Suspense→Loading,Index→<For keyed={false}>,produce, etc.).Lists verified against the Solid 2.0 RC source.
solid/no-single-arg-create-effect(error inv2): Solid 2.0 requires the splitcreateEffect(compute, effect)form. The single-argument 1.x form produces no TS compile erroron a bare statement call and only throws at runtime in dev mode; this rule is the build-time
hard stop for the most commonly reproduced AI mistake.
solid/no-accessor-as-prop(error inv2):<div title={count} />silentlyrenders a stringified function. Fires on any expression that statically resolves to a function
in a value-typed DOM attribute, with a message that states the fix (
count→count()).Event handlers,
ref,children, namespaced attributes, components, and custom elements areexempt.
solid/prefer-structured-class(warning inv2, error inv2-strict): nudgesmanually-built class strings (concatenation with conditionals, conditional template literals,
.join(" ")) toward the structured array/objectClassValueforms that Solid 2.0 acceptsnatively. Static strings and plain interpolation are untouched.
solid/no-module-scope-reactive-primitive(error inv2-strictonly): reactivestate at module scope is shared across SSR requests.
createRoot-wrapped module state is thedeliberate escape hatch and is not flagged.
solid/prefer-onSettled-for-side-effects(warning inv2-strictonly): flagsside-effectful setup (timers, global listeners, observers) in component bodies, where it also
runs during SSR; suggests
onSettled. Never flagsonCleanupitself.solid/no-restated-default-options(error inv2-strictonly, autofixable):removes restated defaults like
<For keyed={true}>and<Show keyed={false}>.settings.solid.versionis 2):solid/no-unknown-namespacesinverts its premise: namespaces are no longer reserved in 2.0,so any colon-name is a legal literal attribute — but the formerly-special prefixes
use:,attr:,bool:,on:, andoncapture:are flagged as near-certain 1.x migration bugs withper-prefix guidance.
prop:remains the only special namespace.solid/event-handlersgraduates from style to correctness: only camelCaseonClickis anevent handler in 2.0; a lowercase
onclickwith a function value is a listener that willnever fire (autofixed to camelCase for known DOM events). Lowercase names with static string
values are legitimate literal attributes and are no longer flagged.
onDoubleClick(whichlowercases to a nonexistent DOM event) is autofixed to
onDblClick.solid/importsrequires the 2.0 export locations: store exports from core"solid-js", webexports from
"@solidjs/web". The legacysolid-js/store/solid-js/websubpaths aresolid/removed-api's territory, avoiding double reports.solid/jsx-no-undefauto-imports the 2.0 control-flow components (For,Repeat,Show,Switch,Match,Errored,Loading,Reveal);Indexis no longer suggested.solid/reactivitydelegates its uncalled-signal-in-DOM-attribute case tosolid/no-accessor-as-propso a node never gets two reports.solid/no-react-depsself-gates off (a dependency array in the second argument is already atype and runtime error in 2.0).
v2config over sources copied from the officialSolid 2.0 templates in CI, and
test/lint-templates.mjssweeps a localsolidjs/templatescheckout. All eleven
solid-v2/*templates lint clean.v0.15.0Compare Source
The revival release: Solid 2.0 support and a modernized toolchain.
Breaking Changes
eslintpeer dependency range is now^9.0.0 || ^10.0.0. Support for ESLint v6–v8 has been dropped.plugin:solid/recommendedandplugin:solid/typescriptconfigs have been removed, matching ESLint v10's removal of the eslintrc system. Useeslint-plugin-solid/configs/recommended/eslint-plugin-solid/configs/typescript, or the configs on the root export (solid.configs.recommended/solid.configs.typescript). Theconfigs["flat/recommended"]andconfigs["flat/typescript"]names from 0.14.x still work as aliases.engines.nodefield is now>=22.0.0(Node 20 reached end-of-life in April 2026).Features
solid/reactivity. The rule now recognizes, alongside the 1.x APIs:createProjection,createOptimistic,createOptimisticStore,merge,omit,isPending,latest,resolve,deep,repeat,flush,action,onSettled,createTrackedEffect,createErrorBoundary,createLoadingBoundary,createRevealOrder, function-formcreateSignal(fn)/createStore(fn), split effects (createEffect(compute, effect)), async computations (e.g.createMemo(async () => ...)), and<For>'skeyedprop callback shapes. Imports from@solidjs/signalsare recognized as Solid imports. Callsites whose meaning differs between 1.x and 2.0 are resolved permissively so that neither interpretation warns.readAfterAwaitwarning insolid/reactivity. In async computations (asynccreateMemo, function-form derived primitives), reactive reads placed after the firstawaitoryieldare not tracked—in 1.x they behave like reads in an event handler, and in 2.0 they can observe unpredictable mid-transition state. The rule now reports these reads specifically and suggests reading the value before the computation suspends.solid/importsunderstands Solid 2.0 export locations.createStore,reconcile, and store types imported from coresolid-js(their 2.0 home) are no longer flagged.jsPluginswithout modification; see the README for setup.Internal
Full Changelog: solidjs-community/eslint-plugin-solid@v0.14.5...v0.15.0
sindresorhus/globals (globals)
v17.12.0Compare Source
50a2119__webpack_layer__global (#351)779a11av17.11.0Compare Source
react-nativeglobals (#337)61eafbfv17.10.0Compare Source
GM_cookieto Greasemonkey globals (#349)f468407v17.9.0Compare Source
5a958edv17.8.0Compare Source
7394811v17.7.0Compare Source
33b75f9evilmartians/lefthook (lefthook)
v2.1.14Compare Source
v2.1.12Compare Source
v2.1.10Compare Source
NO_COLORis set (#1449) by @viralpraxisv2.1.9Compare Source
prettier/prettier (prettier)
v3.9.9Compare Source
diff
Markdown: Fix text with
$been incorrectly parsed as math syntax (#20140 by @fisker)v3.9.8Compare Source
diff
Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @seiyab)
v3.9.7Compare Source
diff
Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @Austin1serb, @giaBaoJS)
JavaScript: Fix embedded template literal idempotency (#19725 by @fisker)
Markdown: Preserve Liquid blocks after Markdown tables (#19730 by @wanxiankai, @seiyab)
Markdown: Preserve single tildes in Markdown (#19739 by @lazerg)
Since 3.9.0, single-tilde spans like
H~2~Owere rewritten to double tildes, turning subscript syntax into strike-through. Only double tildes are treated that way now, matching GitHub.Markdown: Fix Markdown blockquote containing
>characters (#19802 by @seiyab)Markdown: Strip blockquote markers from a setext heading's continuation lines (#19878 by @Kjubikstronk)
A setext heading spanning multiple lines inside a blockquote kept the
>marker of its continuation lines as literal text.