chore(deps): bump the npm_and_yarn group across 3 directories with 14 updates - #635
chore(deps): bump the npm_and_yarn group across 3 directories with 14 updates#635dependabot[bot] wants to merge 2 commits into
Conversation
… updates Bumps the npm_and_yarn group with 3 updates in the / directory: [happy-dom](https://github.com/capricorn86/happy-dom), [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) and [undici](https://github.com/nodejs/undici). Bumps the npm_and_yarn group with 1 update in the /demo directory: [joi](https://github.com/hapijs/joi). Bumps the npm_and_yarn group with 3 updates in the /website directory: [postcss](https://github.com/postcss/postcss), [rollup](https://github.com/rollup/rollup) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). Updates `happy-dom` from 20.6.1 to 20.10.2 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v20.6.1...v20.10.2) Updates `vitest` from 4.0.18 to 4.1.0 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest) Updates `picomatch` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@4.0.3...4.0.4) Updates `postcss` from 8.5.6 to 8.5.15 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.6...8.5.15) Updates `undici` from 7.22.0 to 7.27.2 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.22.0...v7.27.2) Updates `vite` from 7.3.1 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) Updates `joi` from 17.13.3 to 18.2.1 - [Commits](hapijs/joi@v17.13.3...v18.2.1) Updates `postcss` from 8.5.6 to 8.5.15 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.6...8.5.15) Updates `rollup` from 4.57.1 to 4.61.1 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md) - [Commits](rollup/rollup@v4.57.1...v4.61.1) Updates `astro` from 5.17.1 to 6.4.6 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@6.4.6/packages/astro) Updates `defu` from 6.1.4 to 6.1.7 - [Release notes](https://github.com/unjs/defu/releases) - [Changelog](https://github.com/unjs/defu/blob/main/CHANGELOG.md) - [Commits](unjs/defu@v6.1.4...v6.1.7) Updates `devalue` from 5.6.2 to 5.8.1 - [Release notes](https://github.com/sveltejs/devalue/releases) - [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md) - [Commits](sveltejs/devalue@v5.6.2...v5.8.1) Updates `h3` from 1.15.5 to 1.15.11 - [Release notes](https://github.com/h3js/h3/releases) - [Changelog](https://github.com/h3js/h3/blob/v1.15.11/CHANGELOG.md) - [Commits](h3js/h3@v1.15.5...v1.15.11) Updates `smol-toml` from 1.6.0 to 1.6.1 - [Release notes](https://github.com/squirrelchat/smol-toml/releases) - [Commits](squirrelchat/smol-toml@v1.6.0...v1.6.1) Updates `svgo` from 4.0.0 to 4.0.1 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v4.0.0...v4.0.1) --- updated-dependencies: - dependency-name: happy-dom dependency-version: 20.10.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: vitest dependency-version: 4.1.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: picomatch dependency-version: 4.0.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: postcss dependency-version: 8.5.15 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 7.27.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 8.0.16 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: joi dependency-version: 18.2.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: postcss dependency-version: 8.5.15 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: rollup dependency-version: 4.61.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: astro dependency-version: 6.4.6 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: defu dependency-version: 6.1.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: devalue dependency-version: 5.8.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: h3 dependency-version: 1.15.11 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: smol-toml dependency-version: 1.6.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: svgo dependency-version: 4.0.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit e51d96c. Configure here.
| }, | ||
| "devDependencies": { | ||
| "@testing-library/dom": "^10.4.1", | ||
| "@vitest/coverage-v8": "^4.0.18", |
There was a problem hiding this comment.
Coverage package dropped from lockfile
High Severity
This PR removes @vitest/coverage-v8 from the root lockfile while dashboard/vitest.config.ts still uses coverage.provider: "v8" and CI still runs vitest … --coverage after npm ci. Vitest does not ship that provider; without the package, the dashboard coverage job fails on install/run.
Reviewed by Cursor Bugbot for commit e51d96c. Configure here.
…ardware sw-hygiene-test timed out on macos-latest while passing on ubuntu-latest, so the Test workflow was red on every push. The cause was algorithmic, not the runner: detect_dead_code ran one recursive grep over the whole scripts/ tree per function definition — ~4,200 definitions x 368 files, plus ~4 subprocess spawns each (~21,000 forks). That cost ~190s on an M-series Mac and overran the 300s per-suite budget on macOS, where fork() and BSD grep are both slower than on Linux. Linux passed only because it was faster, not because it was correct. Replaced with two linear passes over a single awk token index: O(symbols + tree). The scan drops 190s -> 1.5s and the suite 300s+ (TIMEOUT) -> 22s. Usage is now counted per identifier token rather than per substring, so a helper named `run` is no longer "used" by a line containing "running" — the unused rule is unchanged (a definition mentions its own name once, so <=1 is unused). Bash 3.2 has no associative arrays, so the index lives entirely in awk. Also in this change: - claude-code-review.yml: skip dependabot and fork PRs. Those runs get a read-only token and no access to repo secrets, so claude_code_oauth_token interpolated to an empty string and the action died at the installation-token step ~12s in. That is the whole reason this check was permanently red on #583/#635/#636. A missing credential is now a skip, not a failure, matching the integration-claude pattern already in test.yml. - test.yml: pin shellcheck to v0.11.0 rather than taking the runner's apt build, whose SC2120 findings differ from what developers run locally; add bubblewrap + socat, the Claude CLI sandbox deps whose absence was the integration-claude failure. - sw-test-all.sh: echo the tail of each failing suite's log. The per-suite logs live in a temp dir the EXIT trap removes, so CI showed which suite failed but never why. - mutation-executor.sh: the sed_i fallback branch called sed_i, which is only reached when sed_i is undefined — guaranteed failure. Use `-i.bak`, the one in-place form BSD and GNU sed both accept. - sw-code-review.sh, and the code-review/pipeline tests: same `sed -i ''` portability fix; the empty-suffix form is BSD-only and makes GNU sed read '' as the script. Full suite: 162 passed, 0 failed, 0 timed out (713s). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot recreate |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |


Bumps the npm_and_yarn group with 3 updates in the / directory: happy-dom, vitest and undici.
Bumps the npm_and_yarn group with 1 update in the /demo directory: joi.
Bumps the npm_and_yarn group with 3 updates in the /website directory: postcss, rollup and astro.
Updates
happy-domfrom 20.6.1 to 20.10.2Release notes
Sourced from happy-dom's releases.
... (truncated)
Commits
b334a12fix: #2163 Updates external dependencies (#2188)20f89aafix: #2180 Try to fix publish workflow (#2181)f08c3fachore: #2177 Update happy-conventional-commit (#2179)df504c0chore: #2177 Update happy-conventional-commit (#2178)c3db9e2chore: #2174 Fix NPM cache issue (#2175)5a50f8achore: #2171 Fix canvas adapter peer dependency to happy-dom (#2173)090183achore: #2171 Fix canvas adapter peer dependency to happy-dom (#2172)e5b81b1feat: #241 Adds canvas adapter package (#2069)cd6f87ffix: #0 Fix github release workflow (#2141)4090adefix: #0 Fix github release workflow (#2140)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for happy-dom since your current version.
Updates
vitestfrom 4.0.18 to 4.1.0Release notes
Sourced from vitest's releases.
... (truncated)
Commits
4150b91chore: release v4.1.01de0aa2fix: correctly identify concurrent test during static analysis (#9846)c3cac1cfix: use isAgent check, not just TTY, for watch mode (#9841)eab68bachore(deps): update all non-major dependencies (#9824)031f02afix: allow catch/finally for async assertion (#9827)3e9e096feat(reporters): addagentreporter to reduce ai agent token usage (#9779)0c2c013chore: release v4.1.0-beta.68181e06fix:hideSkippedTestsshould not hidetest.todo(fix #9562) (#9781)a8216b0fix: manual and redirect mock shouldn'tloadortransformoriginal module...689a22afix(browser): types ofgetCDPSessionandcdp()(#9716)Updates
picomatchfrom 4.0.3 to 4.0.4Release notes
Sourced from picomatch's releases.
Commits
e5474fcPublish 4.0.44516eb5Merge commit from fork5eceecdMerge commit from fork0db7dd7Run benchmark again against latest minimatch version (#161)9500377docs: clarify what brace expansion syntax is and isn't supported (#134)2661f23fix typo in globstars.js test name (#138)1798b07docs: fixmakeReexample (#143)9d76bc5chore: undocument removed options (#146)e4d718bRemove unused time-require (#160)38dffebchore(deps): pin dependencies (#158)Updates
postcssfrom 8.5.6 to 8.5.15Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
eae46dbRelease 8.5.15 version79508ffUpdate CI actionsb128e21Speed up declaration parsing by avoiding creating new array on each token9825dcaFix code format55789c8Update dependencies84fbbe9Install older pnpm action for old Node.js9f860bdRevert pnpm action for old Node.js0877198Update CI actionsb2d1a33Fix linter warnings0700dacMerge pull request #2088 from rootvector2/add-oss-fuzz-harnessUpdates
undicifrom 7.22.0 to 7.27.2Release notes
Sourced from undici's releases.
... (truncated)
Commits
b0ba52dBumped v7.27.2 (#5369)c03ed25fix: use legacy global dispatcher in v7 (#5368)4527877Bumped v7.27.1 (#5354)3e17d92fix: preserve raw headers in dispatch handler bridge (#5345)d7aeee3Bumped v7.27.0 (#5340)2054b13[7.x] fix: support Node 26 and legacy global dispatcher (#5319)acf8008Bumped v7.26.0 (#5322)2b3cd22fix: validate EOF for chunked h1 responses (#5273) (#5307)301f347test: avoid Promise.withResolvers in tls session reuse test0f6c792fix: preserve allowH2 when wrapping custom connectUpdates
vitefrom 7.3.1 to 8.0.16Release notes
Sourced from vite's releases.
... (truncated)
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
f94df87release: v8.0.16dc245c7fix: reject windows alternate paths (#22572)50b9512fix(deps): reject UNC paths for launch-editor-middleware (#22571)8d1b019release: v8.0.152686d7dfix(deps): update all non-major dependencies (#22511)3052a67chore(deps): update rolldown-related dependencies (#22566)e3cfb9dfix(optimizer): close the rolldown bundle when write() rejects (#22528)6978a9crefactor: correct logic incollectAllModulesfunction (#22562)646dbedfeat: update rolldown to 1.0.3 (#22538)85a0efffix: capitalize error messages and remove spurious space in parse error (#22488)Updates
joifrom 17.13.3 to 18.2.1Commits
048fe0518.2.12392713Merge pull request #3113 from hapijs/fix/link-max-call-stackfc146a6fix: protect link recursion from max call stackf4e97e018.2.0626893dMerge pull request #3111 from hapijs/feat/link-maxRecursion9c7a443feat: add maxRecursion limit to links7d43b1218.1.2d98c802Merge pull request #3107 from mahmoodhamdi/fix/json-schema-number-rules7edc591fix: improve JSON Schema conversion for number.port() and number.sign()06afeb518.1.1Updates
postcssfrom 8.5.6 to 8.5.15Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
eae46dbRelease 8.5.15 version79508ffUpdate CI actionsb128e21Speed up declaration parsing by avoiding creating new array on each token9825dcaFix code format55789c8Update dependencies84fbbe9Install older pnpm action for old Node.js9f860bdRevert pnpm action for old Node.js0877198Update CI actionsb2d1a33Fix linter warnings0700dacMerge pull request #2088 from rootvector2/add-oss-fuzz-harnessUpdates
rollupfrom 4.57.1 to 4.61.1Release notes
Sourced from rollup's releases.