Repository navigation
chore(deps): update npm dependencies updates - #219
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
6 times, most recently
from
October 9, 2026 19:43
f492149 to
1bd1266
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
October 10, 2026 08:44
1bd1266 to
5644d6c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.10.1→3.10.218.0.5→18.0.710.11.0→10.12.017.12.0→17.13.05.4.0→5.4.18.5.28→8.5.293.9.9→3.9.102.34.0→2.35.021.1.0→21.1.15.3.1→5.4.0Release Notes
quasarframework/quasar (@quasar/app-vite)
v3.10.2Compare Source
Changes
[RESOLVE_ERROR] Could not resolve '#q-app/bex/background'(Matched alias not found). The same project already built fine on Linux/macOS; Rolldown on Windows needed the#q-app/bex/*aliases registered ahead of the generic#q-appone (#18564)Donations
Quasar Framework is an open-source MIT-licensed project made possible due to the generous contributions by sponsors and backers. If Quasar is useful in your workflow and you want to support ongoing maintenance, please consider the following:
motdotla/dotenv (dotenv)
v18.0.7Compare Source
Changed
quiet: trueas null rather than falsey (#1070)DOTENV_QUIETsetting in.envfile (#1071)v18.0.6Compare Source
Changed
parseBooleannot Boolean() to fix override (#1069)eslint/eslint (eslint)
v10.12.0Compare Source
Features
4618052feat: handle astral letters innew-cap(#21357) (sary)4ec5168feat: allowSourceCode#getText()to accept tokens and comments (#21340) (electrohyun)Bug Fixes
bc51eeefix:prefer-arrow-callbackfalse positive in conditional test (#21373) (Daniel Pinto)bbff86cfix: skip lines with multiple comments inmax-lines-per-function(#21332) (xbinaryx)efc4d6bfix: astral letters inconsistent-return,no-eval,no-invalid-this(#21360) (lumir)93de066fix: prefer-exponentiation-operator autofix for async function base (#21322) (Vladimir Babin)02e34fffix: add missing space afterelseincurlyautofix (#21355) (Pixel)b14b8bcfix: correctid-lengthmessage for long private names (#21348) (Pixel)69aac01fix: supportTSFunctionTypeingetFunctionHeadLoc(#21335) (xbinaryx)686630efix:no-loss-of-precisionfalse positive with0.e5(#21337) (sethamus)Documentation
67eb586docs: Update README (GitHub Actions Bot)5370d7edocs: clarifyone-varseparateRequiresmatches anyrequire()call (#21192) (sethamus)8816c1ddocs: Update README (GitHub Actions Bot)3d2e7cedocs: fix typo in no-unused-expressions documentation (#21346) (bytedoe)Chores
152067fchore: update ecosystem plugins (#21362) (ESLint Bot)b56d58echore: update github/codeql-action action to v4.38.2 (#21376) (renovate[bot])bfaea12perf: cache normalized config globals per languageOptions (#21364) (James Ross)322209eci: avoid Nx cache in ecosystem tests and disable failing test (#21369) (Francesco Trotta)d166567chore: update dependency prettier to v3.9.9 (#21371) (renovate[bot])29585cechore: update dependency eslint-plugin-expect-type to ^0.7.0 (#21359) (renovate[bot])39d79bachore: update github/codeql-action action to v4.38.1 (#21354) (renovate[bot])182a6e9chore: update dependency prettier to v3.9.8 (#21352) (renovate[bot])f995127chore: remove CLAUDE.md in favor of AGENTS.md (#21339) (Jarren)b95fb6cchore: update dependency prettier to v3.9.7 (#21347) (renovate[bot])3782dd4chore: update ecosystem plugins (#21342) (ESLint Bot)sindresorhus/globals (globals)
v17.13.0Compare Source
b007369kucherenko/jscpd (jscpd)
v5.4.1Compare Source
New Features
--similaritycompares the structure of functions in 15 languages. jscpd parses every function and method and normalizes its syntax tree: the names of the functions it calls and its operators stay, local names, field names and literals become markers, and comments and the parentheses around one expression drop out. Every subtree of that tree is a fingerprint, and two functions score the Jaccard index of their two fingerprint sets, so a renamed copy scores 1 and an edited statement lowers the score.mod testsare left out. Code betweenjscpd:ignore-startandjscpd:ignore-end, or matched by--ignore-pattern, adds nothing to a function (#1144).--similarityalone compares at 0.8.--min-nodes(config keyminNodes, 20 by default) sets the smallest normalized tree that takes part,--min-linesapplies as before and--min-tokensdoes not. The JSON report gives the node count of both functions asnodes.fixtures/similarity-demohas a runnable example in every language. (#1129, #1132, #1134, #1136, #1139, #1147, #1148, #1149, #1150, #1152, #1155, #1138, #1141, #1142, #1143, #1145, #1146, #1156)An
ednreporter.-r ednwritesjscpd-report.ednwith{:candidates [...] :clones [...]}. The candidates are every pair--similarityfound, most similar first, with their score, language, both locations and node counts, also the pairs a token clone already reports. The clones are the ones the other passes found, with their kind, method and score. (#1151, #1153, #1156)--changedreports the clones of the files you are working on. The changed files are the onesgit statuslists: staged, unstaged and untracked files, and a renamed file under its new name. jscpd still scans every file and reports a clone when one of its fragments is in a changed file, so a new file that copies an unchanged one shows up..jscpd-baseline.jsonat the repository root, or to the--baselinefile, with the commit and a hash of the scan paths and options. Later runs read it and mark the clones HEAD did not have as[NEW], so--fail-on-new-clonesworks with it. jscpd builds the file again after a commit or for other paths or options. A baseline file without a commit, such as one--update-baselinewrote, is used as it is.--changed-onlyscans the changed files alone, and they match only one another.fixtures/changed-demowalks through five steps. (#1154, #1172)--report-namesets the base name of the report files. Linter aggregators such as MegaLinter run several tools into one reports folder, and two jscpd runs there overwrote each other'sjscpd-report.json.--report-name megalinter-jscpd(config keyreportName) names thejson,xml,csv,html,markdown,sarifandednreports, and the GitHub Action takes it as thereport-nameinput. The badge, OpenMetrics and CodeClimate files keep their names. The name must be a plain file name: a path, an extension or an empty name is an error. Contributed by @MannXo. (#1015, #1058)The MCP server finds every type of clone and compares folders. Every tool takes
kinds:exact,renamed,similarandsemantic, ortype1totype4. Without it, a tool reports whatjscpdreports with the server's options.compare_folders(left, right)returns the JSON report of--comparefor two folders. The server speaks the MCP revision 2026-07-28, and clients of the older revisions keep working.check_duplicationnow finds every copy of a snippet, where it used to match one of two, and--mcpno longer ignores--semantic. (#1135, #1137)Changes
--similarityscores differ from 5.4.0. The method is new, so a pair that scored 0.85 before can score lower now. Refresh a--thresholdor a baseline that was set on the old results.--similarity 1now reports functions with the same structure; up to 5.4.0 a ratio of 1 turned the search off, and jscpd prints a warning that says so. The options that the method replaced never reached a release. (#1156)Bug Fixes
--semanticand--comparefound functions namedifin C, C++ and C# code. Around#ifand#ifdef, the grammars readelse if (…) { }as a function namedif, orwhileorawait, and everyif (in the scan counted as a call to it, so in--compareone such branch could collect thousands of callers. jscpd now drops a function whose type is the keywordelse. A word such asif,whileorcatchbefore a parenthesis counts as a call only as a member, as inpromise.catch(f). Reported by @MysterionRise, fixed by @mvanhorn. (#1163, #1188)Three
--comparefixes found on Apache Lucene and Lucene.NET, all by @MysterionRise:assertEqualsin Lucene's benchmark code took all 6,127 calls to the name, 6,126 of them from tests. (#1165)Testssits in its dotted name, as inLucene.Net.Tests.Analysis.Common. Before, 6,736 functions in 771 files of such projects counted as code. (#1167)The
--comparereports disagreed. The console and the HTML map now round a share the same way, so 60 of 147 functions read 41% in both. A Tests block appears only when a side has a test that counts, and a declaration without a body no longer counts as a function. (#1130)--dead-codereported an import used only in a TSDoc link as unused.{@link X},{@linkcode X}and{@linkplain X}now count as uses ofX, as TypeScript counts them, and in JavaScript files the JSDoc types of@param,@returns,@typeand the like count too. A name in the docs credits the import only, so a function that only a link names is still reported. (#1170, #1171)--ignore-patterndropped the wrong tokens in code blocks. jscpd computed the ranges on the host file but tokenized Markdown fences, component scripts and Razor blocks from the block's own offsets. The ranges now move to the block. (#1144)git commands run from a hook acted on the hook's repository. jscpd's git subprocesses now drop the variables git exports to hooks, such as
GIT_DIRandGIT_INDEX_FILE; before,--baseline-from-refin a pre-commit hook wrote the base tree into the commit's index. A--historyrange or a--baseline-from-refref that starts with-is refused, so a scanned repository's config can no longer pass git an option such as--output=<file>. The worktree cleanup no longer prunes the user's other worktrees, and an API key that an embeddings API echoes in an error is redacted. (#1169)The Nix flake warned about
stdenv.isDarwin. It usesstdenv.hostPlatform.isDarwinnow. Contributed by @mlavrinenko. (#1133)Other
cargo publishwhile the crates.io index catches up (#1123), and thecompare-codebasesskill keeps vendored and build folders out of a comparison (#1124).Dependencies
nilas a node of its own, and--similaritytreats it as a literal.Thank You ❤️
--similarity, theednreporter and--changed: #1129, #1131, #1132, #1134, #1136, #1139, #1147, #1148, #1149, #1150, #1151, #1152, #1153, #1154--report-name(#1058)--comparefixes (#1165, #1166, #1167) and the report of phantom functions (#1163)Published Packages
basta@0.3.1on crates.iocpd-core@0.1.21on crates.iocpd-finder@0.1.21on crates.iocpd-reporter@0.1.22on crates.iocpd-semantic@0.1.2on crates.iocpd-similarity@0.1.0on crates.iocpd-tokenizer@0.1.20on crates.iojscpd@5.4.1on crates.iocpd@5.4.1on npmjscpd@5.4.1on npmjscpd-darwin-arm64@5.4.1on npmjscpd-darwin-x64@5.4.1on npmjscpd-linux-x64-gnu@5.4.1on npmjscpd-linux-arm64-gnu@5.4.1on npmjscpd-linux-x64-musl@5.4.1on npmjscpd-linux-arm64-musl@5.4.1on npmjscpd-windows-x64-msvc@5.4.1on npmjscpd-windows-arm64-msvc@5.4.1on npmjscpd==5.4.1on PyPIVerify
Archives are signed with Sigstore (keyless,
<asset>.sigstore.json)and carry SLSA build provenance. Replace
jscpd-linux-x64-gnu.tar.gzwith your asset:cosign verify-blob \ --bundle jscpd-linux-x64-gnu.tar.gz.sigstore.json \ --certificate-identity-regexp '^https://github\.com/kucherenko/jscpd/' \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ jscpd-linux-x64-gnu.tar.gz gh attestation verify jscpd-linux-x64-gnu.tar.gz --repo kucherenko/jscpd sha256sum --check --ignore-missing checksums.txtpostcss/postcss (postcss)
v8.5.29Compare Source
</style>escaping (by @choudhryfrompak).list.comma()andlist.space()(by @00200200).prettier/prettier (prettier)
v3.9.10Compare Source
diff
Markdown: Update
micromark-extension-gfm-tableto fix the table parse issue on performance (#20266 by @fisker)See micromark/micromark-extension-gfm-table@
4f43eadfor details.release-it/release-it (release-it)
v21.1.1Compare Source
bf2a3d8) - thanks @adamhl8!37898f1)7bd73af)5336543)vuejs/router (vue-router)
v5.4.0Compare Source
🚨 Breaking Changes
🚀 Features
createRouter- by @danielroe in #2804 (9de96)🐞 Bug Fixes
🏎 Performance
View changes on GitHub
Configuration
📅 Schedule: (in timezone Europe/Paris)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.