Skip to content

chore(deps): (deps): bump the production group with 6 updates#927

Merged
cb1kenobi merged 1 commit intomainfrom
dependabot/npm_and_yarn/production-1f0683ecdf
Apr 8, 2026
Merged

chore(deps): (deps): bump the production group with 6 updates#927
cb1kenobi merged 1 commit intomainfrom
dependabot/npm_and_yarn/production-1f0683ecdf

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 8, 2026

Bumps the production group with 6 updates:

Package From To
undici 7.24.6 8.0.2
baseline-browser-mapping 2.10.13 2.10.16
caniuse-lite 1.0.30001782 1.0.30001786
electron-to-chromium 1.5.330 1.5.332
node-releases 2.0.36 2.0.37
postcss 8.5.8 8.5.9

Updates undici from 7.24.6 to 8.0.2

Release notes

Sourced from undici's releases.

v8.0.2

What's Changed

Full Changelog: nodejs/undici@v8.0.1...v8.0.2

v8.0.1

What's Changed

New Contributors

Full Changelog: nodejs/undici@v7.24.7...v8.0.1

v8.0.0

What's Changed

Full Changelog: nodejs/undici@v7.24.7...v8.0.0

v7.24.7

What's Changed

... (truncated)

Commits
  • 9c24204 Bumped v8.0.2
  • 45bd838 Revert "Reapply "fix: assume http/https scheme for scheme-less proxy env vars...
  • d7b4feb ci: reenable shared builtin CI tests
  • 48c7cf3 fix: release ref (#4965)
  • 58ef10d fix(websocket): fallback to HTTP/1.1 when H2 CONNECT is unavailable (#4966)
  • 490cbc6 Bumped v8.0.1 (#4964)
  • 49ded6d fix(websocket/stream): only enqueue parsed messages in WebSocketStream (#4959)
  • ced6b01 fix: mirror the legacy global dispatcher for built-in fetch (#4962)
  • dc4351a doc: remove duplicate listItem of RetryHandler.md & RetryHandler.md (#4948)
  • 1548c18 build(deps): bump hendrikmuhs/ccache-action from 1.2.19 to 1.2.22 (#4954)
  • Additional commits viewable in compare view

Updates baseline-browser-mapping from 2.10.13 to 2.10.16

Release notes

Sourced from baseline-browser-mapping's releases.

v2.9.3 - remove process.loadEnvFile()

What's Changed

Full Changelog: web-platform-dx/baseline-browser-mapping@v2.9.2...v2.9.3

Commits
  • c8ba05d Patch to 2.10.16 because browser or feature data changed
  • 3887938 Browser or feature data changed
  • 3b7f694 Updating static site
  • 9168fd0 Patch to 2.10.15 because browser or feature data changed
  • 8560cd2 Browser or feature data changed
  • 7c07035 Updating static site
  • 7058e24 Patch to 2.10.14 because browser or feature data changed
  • 406bd81 Browser or feature data changed
  • 34613b9 Bump serialize-javascript from 7.0.4 to 7.0.5 (#130)
  • fdb0665 Bump picomatch (#129)
  • Additional commits viewable in compare view

Updates caniuse-lite from 1.0.30001782 to 1.0.30001786

Commits

Updates electron-to-chromium from 1.5.330 to 1.5.332

Commits

Updates node-releases from 2.0.36 to 2.0.37

Commits

Updates postcss from 8.5.8 to 8.5.9

Release notes

Sourced from postcss's releases.

8.5.9

  • Speed up source map encoding paring in case of the error.
Changelog

Sourced from postcss's changelog.

8.5.9

  • Speed up source map encoding paring in case of the error.
Commits
  • fe88ac2 Release 8.5.9 version
  • c551632 Avoid RegExp when we can use simple JS
  • 89a6b74 Move SECURITY.txt for docs folder to keep GitHub page cleaner
  • 6ceb8a4 Create SECURITY.md
  • 02ccae6 Another way to fix CI with .ts ext in tests on old Node.js
  • 2c36658 Another way to fix CI with TS on old Node.js
  • b906003 Another way to fix CI with old Node.js
  • 04d32cd Fix another issue with Node.js 10 on CI
  • df86cdf Try to fix Node.js 10 on CI
  • 82bec0d Move to oxfmt
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [undici](https://github.com/nodejs/undici) | `7.24.6` | `8.0.2` |
| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.13` | `2.10.16` |
| [caniuse-lite](https://github.com/browserslist/caniuse-lite) | `1.0.30001782` | `1.0.30001786` |
| [electron-to-chromium](https://github.com/Kilian/electron-to-chromium) | `1.5.330` | `1.5.332` |
| [node-releases](https://github.com/chicoxyzzy/node-releases) | `2.0.36` | `2.0.37` |
| [postcss](https://github.com/postcss/postcss) | `8.5.8` | `8.5.9` |


Updates `undici` from 7.24.6 to 8.0.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.24.6...v8.0.2)

Updates `baseline-browser-mapping` from 2.10.13 to 2.10.16
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.10.13...v2.10.16)

Updates `caniuse-lite` from 1.0.30001782 to 1.0.30001786
- [Commits](browserslist/caniuse-lite@1.0.30001782...1.0.30001786)

Updates `electron-to-chromium` from 1.5.330 to 1.5.332
- [Changelog](https://github.com/Kilian/electron-to-chromium/blob/main/CHANGELOG.md)
- [Commits](Kilian/electron-to-chromium@v1.5.330...v1.5.332)

Updates `node-releases` from 2.0.36 to 2.0.37
- [Commits](https://github.com/chicoxyzzy/node-releases/commits/v2.0.37)

Updates `postcss` from 8.5.8 to 8.5.9
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.8...8.5.9)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production
- dependency-name: baseline-browser-mapping
  dependency-version: 2.10.16
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: caniuse-lite
  dependency-version: 1.0.30001786
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: electron-to-chromium
  dependency-version: 1.5.332
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: node-releases
  dependency-version: 2.0.37
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: postcss
  dependency-version: 8.5.9
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Apr 8, 2026
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedundici@​7.24.6 ⏵ 8.0.272 +1100100 +198100

View full report

@cb1kenobi cb1kenobi merged commit c1056aa into main Apr 8, 2026
12 checks passed
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/production-1f0683ecdf branch April 8, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant