Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 19 updates - #166

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-1f8f5c2a22
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-1f8f5c2a22

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 19 updates in the / directory:

Package From To
@astrojs/starlight 0.41.7 0.42.2
@types/node 25.9.5 26.4.0
astro 7.2.4 7.3.3
backlog-js 0.19.1 0.20.1
commander 14.0.3 15.0.0
lefthook 2.1.10 2.1.14
marked 18.0.10 18.0.13
open 11.0.1 11.0.4
oxfmt 0.64.0 0.68.0
oxlint-tsgolint 7.0.2001 7.0.2002
oxlint 1.79.0 1.83.0
rc9 3.0.1 3.1.0
sharp 0.35.3 0.35.4
starlight-links-validator 0.25.3 0.26.0
tsx 4.23.12 4.23.15
turbo 2.10.11 2.11.2
typescript 6.0.3 7.0.2
undici 7.29.0 8.10.0
valibot 1.4.2 1.5.0

Updates @astrojs/starlight from 0.41.7 to 0.42.2

Release notes

Sourced from @​astrojs/starlight's releases.

@​astrojs/starlight@​0.42.2

Patch Changes

@​astrojs/starlight@​0.42.1

Patch Changes

  • #4198 96a44d4 Thanks @​mayank99! - Removes the popover attribute from the sidebar pane on desktop viewports. This ensures the desktop sidebar doesn't stay in a "hidden" popover visibility state.

@​astrojs/starlight@​0.42.0

Minor Changes

  • #3572 292fb17 Thanks @​HiDeoo! - Distributes package as JavaScript files with dedicated type declaration files instead of TypeScript source files.

  • #4121 2623ae6 Thanks @​delucis! - Simplifies markup for Starlight’s mobile menu toggle

    ⚠️ Potentially breaking change: If you use a theme plugin, custom styles, or component overrides targeting the MobileMenuToggle button or PageFrame components, you may need to adjust these for the new markup. The button is no longer wrapped in a <starlight-menu-button> custom element and no longer uses the aria-expanded attribute. Instead, you can use the .sl-menu-button class name to target the button and the :popover-open pseudo-class to style the menu open state specifically.

    In the following example, custom styles for the menu button are updated for the new approach:

    - starlight-menu-button button {
    + .sl-menu-button {
      color: var(--sl-color-text);
    }
    
    starlight-menu-button[aria-expanded='true'] button {
    
    
    .sl-menu-button:has(~ :popover-open) {
    color: var(--sl-color-text-accent-high);
    }

See MobileMenuToggle.astro and PageFrame.astro on GitHub for the full source code of the updated components.

  • #3572 292fb17 Thanks @​HiDeoo! - Removes the tagline configuration option, which was never used.

    If your configuration included a tagline option, you can safely remove it without any replacement.

  • #4134 6135f01 Thanks @​HiDeoo! - Updates internal @astrojs/mdx, @astrojs/markdown-satteri, and satteri dependencies.

    ⚠️ BREAKING CHANGE: The following minimum versions are now required:

    • astro v7.2.10 or later
    • @astrojs/markdown-satteri 0.4.0 or later (if you use it)
    • @astrojs/markdown-remark 7.3.0 or later (if you use it)

    Please update Starlight and Astro together:

  • ... (truncated)

    Changelog

    Sourced from @​astrojs/starlight's changelog.

    0.42.2

    Patch Changes

    0.42.1

    Patch Changes

    • #4198 96a44d4 Thanks @​mayank99! - Removes the popover attribute from the sidebar pane on desktop viewports. This ensures the desktop sidebar doesn't stay in a "hidden" popover visibility state.

    0.42.0

    Minor Changes

    • #3572 292fb17 Thanks @​HiDeoo! - Distributes package as JavaScript files with dedicated type declaration files instead of TypeScript source files.

    • #4121 2623ae6 Thanks @​delucis! - Simplifies markup for Starlight’s mobile menu toggle

      ⚠️ Potentially breaking change: If you use a theme plugin, custom styles, or component overrides targeting the MobileMenuToggle button or PageFrame components, you may need to adjust these for the new markup. The button is no longer wrapped in a <starlight-menu-button> custom element and no longer uses the aria-expanded attribute. Instead, you can use the .sl-menu-button class name to target the button and the :popover-open pseudo-class to style the menu open state specifically.

      In the following example, custom styles for the menu button are updated for the new approach:

      - starlight-menu-button button {
      + .sl-menu-button {
        color: var(--sl-color-text);
      }
      
      starlight-menu-button[aria-expanded='true'] button {
      
      
      .sl-menu-button:has(~ :popover-open) {
      color: var(--sl-color-text-accent-high);
      }

    See MobileMenuToggle.astro and PageFrame.astro on GitHub for the full source code of the updated components.

  • #3572 292fb17 Thanks @​HiDeoo! - Removes the tagline configuration option, which was never used.

    If your configuration included a tagline option, you can safely remove it without any replacement.

  • #4134 6135f01 Thanks @​HiDeoo! - Updates internal @astrojs/mdx, @astrojs/markdown-satteri, and satteri dependencies.

    ⚠️ BREAKING CHANGE: The following minimum versions are now required:

    • astro v7.2.10 or later
    • @astrojs/markdown-satteri 0.4.0 or later (if you use it)
    • @astrojs/markdown-remark 7.3.0 or later (if you use it)
  • ... (truncated)

    Commits

    Updates @types/node from 25.9.5 to 26.4.0

    Commits

    Updates astro from 7.2.4 to 7.3.3

    Release notes

    Sourced from astro's releases.

    astro@7.3.3

    Patch Changes

    • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

    • #17942 0bc5715 Thanks @​matthewp! - Returns appropriate 400 and 404 responses from the image endpoint for invalid and missing local image paths

    • #17700 b2222fc Thanks @​winklemad! - Fixes Astro.preferredLocaleList returning an empty list when a locale is configured with the object form ({ path, codes }) and the browser sends the code with different casing or an underscore, such as en-US matching a configured en-us

    • #17941 394ff79 Thanks @​matthewp! - Fixes astro preview --ignore-lock (and astro dev --ignore-lock) being refused when run from an AI agent environment. The flag now starts the server in the foreground instead of erroring, since agent detection only inferred background mode and was never explicitly requested. An explicit --background combined with --ignore-lock still errors.

    • #17928 3277927 Thanks @​ArmandPhilippot! - Fixes TypeScript autocompletion for getImage() to suggest all available predefined options.

    • #17928 3277927 Thanks @​ArmandPhilippot! - Fixes a type error in getImage() options that allowed passing both widths and densities at the same time.

    • #17857 2637ed1 Thanks @​Princesseuh! - Improves rendering performance

    • #17943 2fc7ce9 Thanks @​matthewp! - Fixes a WebAssembly error when importing astro:actions in tests that run under @cloudflare/vitest-pool-workers

    • #18018 1b5a234 Thanks @​astro-factory! - Fixes trailing-slash redirect response body pointing to the incoming URL instead of the redirect target. The location header was correct, but the HTML body (<meta http-equiv="refresh">, <title>, and <a> tag) contained the original request path without the trailing-slash correction or query string.

    • #17905 eaf70fa Thanks @​SudoDevStudio! - Fixes custom dev toolbar apps losing their UI after client-side navigation with <ClientRouter />.

    • #18011 558b301 Thanks @​astro-factory! - Fixes prerendered Cloudflare pages rendering as [object Object] when nodejs_compat is enabled in wrangler.toml

    • #17944 ba08e35 Thanks @​matthewp! - Fixes a regression in astro dev where writes outside the module graph (for example, @astrojs/cloudflare's .wrangler/state files) invalidated the middleware on every request, causing repeated SSR reloads. Such writes no longer invalidate the middleware.

    • #17531 ae837db Thanks @​danilloestrela! - Updates svgo to 4.0.2 to resolve a security advisory

    • #17953 dbbf10e Thanks @​astro-factory! - Fixes a one-time page reload shortly after the first load on cold dev-server starts when a project has framework components imported from MDX content entries. MDX files are now included in the dev dependency pre-bundling scan, so their framework dependencies are bundled up front instead of being discovered (and reloaded for) at runtime.

    • #17955 4e8ad9a Thanks @​matthewp! - Improves dev server startup time. The content config and dev server app module graphs now begin compiling during server creation without blocking the server from listening. Request handling waits for the shared setup result when needed, cutting astro dev ready time by roughly a third on projects with a content config.

    • #17960 9838049 Thanks @​Chy-Zaber-Bin-Zahid! - Improves the diagnostics of some Astro errors.

    • #17998 0e5478d Thanks @​astro-factory! - Fixes SVG <style> elements nested inside <defs> or other container elements not being hashed for CSP

    • #17994 80f9f1d Thanks @​astro-factory! - Fixes experimental.incrementalBuild restoring pages with stale CSS after a preprocessor partial changes or missing original images referenced by restored pages

    • #17889 8ae6b46 Thanks @​ajfAfg! - Fixes a bug where the dev server stripped the configured base from URLs that only share a prefix with it. With base: '/s', requests to /src/... were rewritten to /rc/... and failed, breaking those pages during development.

    • #17980 cfccafa Thanks @​gameroman! - Improves JSDoc for fonts api

    • #17953 dbbf10e Thanks @​astro-factory! - Fixes CSS HMR for framework components rendered through content entries after ClientRouter navigation

    • #17970 0b4dc3a Thanks @​matthewp! - Improves serialization of transition animation values in generated CSS

    • #17999 30ef3cb Thanks @​astro-factory! - Fixes content collection HMR not updating prerendered pages when an adapter enables a separate prerender environment (e.g. @astrojs/cloudflare with prerenderEnvironment: 'node')

    • #18002 312ab49 Thanks @​shoutoutuoadi325! - Fixes redirect targets being corrupted when a dynamic route parameter value contains $ replacement patterns like $&

    ... (truncated)

    Changelog

    Sourced from astro's changelog.

    7.3.3

    Patch Changes

    • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

    • #17942 0bc5715 Thanks @​matthewp! - Returns appropriate 400 and 404 responses from the image endpoint for invalid and missing local image paths

    • #17700 b2222fc Thanks @​winklemad! - Fixes Astro.preferredLocaleList returning an empty list when a locale is configured with the object form ({ path, codes }) and the browser sends the code with different casing or an underscore, such as en-US matching a configured en-us

    • #17941 394ff79 Thanks @​matthewp! - Fixes astro preview --ignore-lock (and astro dev --ignore-lock) being refused when run from an AI agent environment. The flag now starts the server in the foreground instead of erroring, since agent detection only inferred background mode and was never explicitly requested. An explicit --background combined with --ignore-lock still errors.

    • #17928 3277927 Thanks @​ArmandPhilippot! - Fixes TypeScript autocompletion for getImage() to suggest all available predefined options.

    • #17928 3277927 Thanks @​ArmandPhilippot! - Fixes a type error in getImage() options that allowed passing both widths and densities at the same time.

    • #17857 2637ed1 Thanks @​Princesseuh! - Improves rendering performance

    • #17943 2fc7ce9 Thanks @​matthewp! - Fixes a WebAssembly error when importing astro:actions in tests that run under @cloudflare/vitest-pool-workers

    • #18018 1b5a234 Thanks @​astro-factory! - Fixes trailing-slash redirect response body pointing to the incoming URL instead of the redirect target. The location header was correct, but the HTML body (<meta http-equiv="refresh">, <title>, and <a> tag) contained the original request path without the trailing-slash correction or query string.

    • #17905 eaf70fa Thanks @​SudoDevStudio! - Fixes custom dev toolbar apps losing their UI after client-side navigation with <ClientRouter />.

    • #18011 558b301 Thanks @​astro-factory! - Fixes prerendered Cloudflare pages rendering as [object Object] when nodejs_compat is enabled in wrangler.toml

    • #17944 ba08e35 Thanks @​matthewp! - Fixes a regression in astro dev where writes outside the module graph (for example, @astrojs/cloudflare's .wrangler/state files) invalidated the middleware on every request, causing repeated SSR reloads. Such writes no longer invalidate the middleware.

    • #17531 ae837db Thanks @​danilloestrela! - Updates svgo to 4.0.2 to resolve a security advisory

    • #17953 dbbf10e Thanks @​astro-factory! - Fixes a one-time page reload shortly after the first load on cold dev-server starts when a project has framework components imported from MDX content entries. MDX files are now included in the dev dependency pre-bundling scan, so their framework dependencies are bundled up front instead of being discovered (and reloaded for) at runtime.

    • #17955 4e8ad9a Thanks @​matthewp! - Improves dev server startup time. The content config and dev server app module graphs now begin compiling during server creation without blocking the server from listening. Request handling waits for the shared setup result when needed, cutting astro dev ready time by roughly a third on projects with a content config.

    • #17960 9838049 Thanks @​Chy-Zaber-Bin-Zahid! - Improves the diagnostics of some Astro errors.

    • #17998 0e5478d Thanks @​astro-factory! - Fixes SVG <style> elements nested inside <defs> or other container elements not being hashed for CSP

    • #17994 80f9f1d Thanks @​astro-factory! - Fixes experimental.incrementalBuild restoring pages with stale CSS after a preprocessor partial changes or missing original images referenced by restored pages

    • #17889 8ae6b46 Thanks @​ajfAfg! - Fixes a bug where the dev server stripped the configured base from URLs that only share a prefix with it. With base: '/s', requests to /src/... were rewritten to /rc/... and failed, breaking those pages during development.

    • #17980 cfccafa Thanks @​gameroman! - Improves JSDoc for fonts api

    • #17953 dbbf10e Thanks @​astro-factory! - Fixes CSS HMR for framework components rendered through content entries after ClientRouter navigation

    • #17970 0b4dc3a Thanks @​matthewp! - Improves serialization of transition animation values in generated CSS

    • #17999 30ef3cb Thanks @​astro-factory! - Fixes content collection HMR not updating prerendered pages when an adapter enables a separate prerender environment (e.g. @astrojs/cloudflare with prerenderEnvironment: 'node')

    ... (truncated)

    Commits
    • 8a3106e [ci] release (#17939)
    • 5efea1b Add a version field to the astro-client-only fixture
    • 80f9f1d Hash compiled CSS output in incremental build to detect Sass partial changes ...
    • bc6572f Revert "Forward user class to Picture's outer element" (#18004) (#18030)
    • 0e5478d Normalize CRLF line endings before computing CSP hashes (#17998)
    • 30ef3cb fix: invalidate prerender environment in invalidateDataStore (#17991) (#17999)
    • 312ab49 Fix redirect targets when a param value contains a $ replacement pattern (#...
    • 1b5a234 Fix trailing-slash redirect body to match the Location header target (#18018)
    • 558b301 Fix prerendered Cloudflare pages rendering as [object Object] with nodejs_com...
    • 4464b3a fix(assets): forward class to picture element in Picture component (#18003) (...
    • Additional commits viewable in compare view

    Updates backlog-js from 0.19.1 to 0.20.1

    Release notes

    Sourced from backlog-js's releases.

    v0.20.1

    What's Changed

    Full Changelog: nulab/backlog-js@v0.20.0...v0.20.1

    v0.20.0

    What's Changed

    New Contributors

    Full Changelog: nulab/backlog-js@v0.19.1...v0.20.0

    Commits
    • 39fed62 chore: bump version to v0.20.1
    • 7f11c3a Merge pull request #198 from nulab/feat/file-data-content-type
    • 291852f docs: say what the Content-Type is, not what it used to be
    • 02569b1 Merge pull request #196 from nulab/fix/content-disposition-filename
    • 136c7ed feat: expose the response's Content-Type on FileData
    • 0514ecf docs: cut the comments back to what a later reader needs
    • 9278917 test: cover the headers Backlog actually sends
    • 5556fb3 fix: unquote a quoted ext-value, and say what the decoded name can contain
    • 00348f3 fix: parse Content-Disposition instead of slicing it at the first ''
    • 19a2b38 chore: bump version to v0.20.0
    • Additional commits viewable in compare view

    Updates commander from 14.0.3 to 15.0.0

    Release notes

    Sourced from commander's releases.

    v15.0.0

    Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

    The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

    Added

    • show excess command-arguments in error message (#2384)

    Fixed

    • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
    • update example to use compatible character for MINGW64 (#2475)

    Changed

    • Breaking: migrated Commander implementation from CommonJS to ESM (#2464)
    • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
    • dev: switch tests from Jest to node:test test runner (#2463)

    Deleted

    • Breaking: removed deprecated export of commander/esm.mjs (#2464)

    Migration Tips

    Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.

    If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

    v15.0.0-0

    Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

    The release of Commander 15 in May 2026 will move Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

    Added

    • show excess command-arguments in error message (#2384)

    Fixed

    • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
    • update example to use compatible character for MINGW64 (#2475)

    ... (truncated)

    Changelog

    Sourced from commander's changelog.

    [15.0.0] (2026-05-29)

    Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

    The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

    Added

    • show excess command-arguments in error message (#2384)

    Fixed

    • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
    • update example to use compatible character for MINGW64 (#2475)

    Changed

    • Breaking: migrated Commander implementation from CommonJS to ESM (#2464)
    • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
    • dev: switch tests from Jest to node:test test runner (#2463)

    Deleted

    • Breaking: removed deprecated export of commander/esm.mjs (#2464)

    Migration Tips

    Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.

    If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

    [15.0.0-0] (2026-02-22)

    (Released as 15.0.0)

    Commits

    Updates lefthook from 2.1.10 to 2.1.14

    Release notes

    Sourced from lefthook's releases.

    v2.1.14

    Changelog

    v2.1.12

    Changelog

    • b8350fde604197b2422adfc4ae0af080725822b9 ci: fix npm publishing by bumping Node to 24 (#1508)
    • 9fb290d786a0e122fe113b1b49a45bbd0ffa7d28 fix: LEFTHOOK_OUTPUT precedence (#1506)
    • 2f0a9f37cef73e10d95043ba3754329a21850d57 fix: fail the hook when staging fixed files errors (#1484)

    v2.1.11

    Changelog

    • e5b10ac3a2645784ee2e4260620c49c31b44992a deps: bump Go to 1.26.6 (#1495)
    • d4a259f460b7c1d8c512dd75eedc7068310ee961 fix: inherit terminal size for PTY commands (#1498)
    Changelog

    Sourced from lefthook's changelog.

    2.1.13/2.1.14 (2026-09-14)

    2.1.12 (2026-08-28)

    2.1.11 (2026-08-21)

    Commits
    • 1e23553 2.1.14: small fixes and spinner improvements
    • a2c9d37 2.1.13: small fixes and spinner improvements
    • c7b4983 fix(run): error when --job/--command matches nothing (#1512)
    • e4ca4a1 fix: disable tty things when stdout is not TTY (#1545)
    • aa3fa89 docs: document files inheritance for grouped jobs (#1536)
    • 250f028 fix: force colors when colors are explicitly enabled (#1538)
    • 62f4d5e fix: resolve file_types paths from the repo root (#1537)
    • ef092eb fix(npm) don't force past core.hooksPath guard in npm postinstall (#1475)
    • 3667aeb fix: don't force-install hooks from the npm postinstall (#1510)
    • 354df23 docs: quote template run examples (#1472)
    • Additional commits viewable in compare view

    Updates marked from 18.0.10 to 18.0.13

    Release notes

    Sourced from marked's releases.

    v18.0.13

    18.0.13 (2026-09-12)

    Bug Fixes

    • allow tabs in the thematic break that ends a list item (#4087) (afbb27c)
    • avoid O(n^2) scanning in reflinkSearch (#4090) (c6a25bb)
    • case fold reference link labels (#4077) (aed9336)
    • drop the leading whitespace after a hard line break (#4075) (123ce04)
    • match html block start conditions when ending a list item (#4072) (c2facac)
    • respect raw tokens when closing link labels (#4066) (ef394f7)
    • strip a tab that follows spaces in an indented code block (#4080) (dbb393d)

    v18.0.12

    18.0.12 (2026-09-07)

    Bug Fixes

    • allow a tab before the closing sequence of an ATX heading (#4084) (4417582)
    • allow one more level of nested brackets in a link label (#4064) (37b28d8)
    • do not add a newline to an empty code block (#4073) (23b1706)
    • escape character references in autolink destinations (#4053) (8f432f0)
    • reject GFM email autolink when the domain ends in _ or - (#4063) (df57534)
    • reject invalid characters in HTML tag names (#4083) (300bb1d)
    • remove up to the fence indentation from each content line ...

      Description has been truncated

    …y with 19 updates
    
    Bumps the production-dependencies group with 19 updates in the / directory:
    
    | Package | From | To |
    | --- | --- | --- |
    | [@astrojs/starlight](https://github.com/withastro/starlight/tree/HEAD/packages/starlight) | `0.41.7` | `0.42.2` |
    | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.9.5` | `26.4.0` |
    | [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.2.4` | `7.3.3` |
    | [backlog-js](https://github.com/nulab/backlog-js) | `0.19.1` | `0.20.1` |
    | [commander](https://github.com/tj/commander.js) | `14.0.3` | `15.0.0` |
    | [lefthook](https://github.com/evilmartians/lefthook) | `2.1.10` | `2.1.14` |
    | [marked](https://github.com/markedjs/marked) | `18.0.10` | `18.0.13` |
    | [open](https://github.com/sindresorhus/open) | `11.0.1` | `11.0.4` |
    | [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.64.0` | `0.68.0` |
    | [oxlint-tsgolint](https://github.com/oxc-project/tsgolint) | `7.0.2001` | `7.0.2002` |
    | [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.79.0` | `1.83.0` |
    | [rc9](https://github.com/unjs/rc9) | `3.0.1` | `3.1.0` |
    | [sharp](https://github.com/lovell/sharp) | `0.35.3` | `0.35.4` |
    | [starlight-links-validator](https://github.com/HiDeoo/starlight-links-validator/tree/HEAD/packages/starlight-links-validator) | `0.25.3` | `0.26.0` |
    | [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.15` |
    | [turbo](https://github.com/vercel/turborepo) | `2.10.11` | `2.11.2` |
    | [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
    | [undici](https://github.com/nodejs/undici) | `7.29.0` | `8.10.0` |
    | [valibot](https://github.com/open-circle/valibot) | `1.4.2` | `1.5.0` |
    
    
    
    Updates `@astrojs/starlight` from 0.41.7 to 0.42.2
    - [Release notes](https://github.com/withastro/starlight/releases)
    - [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md)
    - [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.42.2/packages/starlight)
    
    Updates `@types/node` from 25.9.5 to 26.4.0
    - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
    - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)
    
    Updates `astro` from 7.2.4 to 7.3.3
    - [Release notes](https://github.com/withastro/astro/releases)
    - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
    - [Commits](https://github.com/withastro/astro/commits/astro@7.3.3/packages/astro)
    
    Updates `backlog-js` from 0.19.1 to 0.20.1
    - [Release notes](https://github.com/nulab/backlog-js/releases)
    - [Commits](nulab/backlog-js@v0.19.1...v0.20.1)
    
    Updates `commander` from 14.0.3 to 15.0.0
    - [Release notes](https://github.com/tj/commander.js/releases)
    - [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
    - [Commits](tj/commander.js@v14.0.3...v15.0.0)
    
    Updates `lefthook` from 2.1.10 to 2.1.14
    - [Release notes](https://github.com/evilmartians/lefthook/releases)
    - [Changelog](https://github.com/evilmartians/lefthook/blob/master/CHANGELOG.md)
    - [Commits](evilmartians/lefthook@v2.1.10...v2.1.14)
    
    Updates `marked` from 18.0.10 to 18.0.13
    - [Release notes](https://github.com/markedjs/marked/releases)
    - [Commits](markedjs/marked@v18.0.10...v18.0.13)
    
    Updates `open` from 11.0.1 to 11.0.4
    - [Release notes](https://github.com/sindresorhus/open/releases)
    - [Commits](sindresorhus/open@v11.0.1...v11.0.4)
    
    Updates `oxfmt` from 0.64.0 to 0.68.0
    - [Release notes](https://github.com/oxc-project/oxc/releases)
    - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
    - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.68.0/npm/oxfmt)
    
    Updates `oxlint-tsgolint` from 7.0.2001 to 7.0.2002
    - [Release notes](https://github.com/oxc-project/tsgolint/releases)
    - [Commits](oxc-project/tsgolint@v7.0.2001...v7.0.2002)
    
    Updates `oxlint` from 1.79.0 to 1.83.0
    - [Release notes](https://github.com/oxc-project/oxc/releases)
    - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
    - [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.83.0/npm/oxlint)
    
    Updates `rc9` from 3.0.1 to 3.1.0
    - [Release notes](https://github.com/unjs/rc9/releases)
    - [Changelog](https://github.com/unjs/rc9/blob/main/CHANGELOG.md)
    - [Commits](unjs/rc9@v3.0.1...v3.1.0)
    
    Updates `sharp` from 0.35.3 to 0.35.4
    - [Release notes](https://github.com/lovell/sharp/releases)
    - [Commits](lovell/sharp@v0.35.3...v0.35.4)
    
    Updates `starlight-links-validator` from 0.25.3 to 0.26.0
    - [Release notes](https://github.com/HiDeoo/starlight-links-validator/releases)
    - [Changelog](https://github.com/HiDeoo/starlight-links-validator/blob/main/packages/starlight-links-validator/CHANGELOG.md)
    - [Commits](https://github.com/HiDeoo/starlight-links-validator/commits/starlight-links-validator@0.26.0/packages/starlight-links-validator)
    
    Updates `tsx` from 4.23.12 to 4.23.15
    - [Release notes](https://github.com/privatenumber/tsx/releases)
    - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
    - [Commits](privatenumber/tsx@v4.23.12...v4.23.15)
    
    Updates `turbo` from 2.10.11 to 2.11.2
    - [Release notes](https://github.com/vercel/turborepo/releases)
    - [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
    - [Commits](vercel/turborepo@v2.10.11...v2.11.2)
    
    Updates `typescript` from 6.0.3 to 7.0.2
    - [Release notes](https://github.com/microsoft/TypeScript/releases)
    - [Commits](microsoft/TypeScript@v6.0.3...v7.0.2)
    
    Updates `undici` from 7.29.0 to 8.10.0
    - [Release notes](https://github.com/nodejs/undici/releases)
    - [Commits](nodejs/undici@v7.29.0...v8.10.0)
    
    Updates `valibot` from 1.4.2 to 1.5.0
    - [Release notes](https://github.com/open-circle/valibot/releases)
    - [Commits](open-circle/valibot@v1.4.2...v1.5.0)
    
    ---
    updated-dependencies:
    - dependency-name: "@astrojs/starlight"
      dependency-version: 0.42.2
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: "@types/node"
      dependency-version: 26.4.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: production-dependencies
    - dependency-name: astro
      dependency-version: 7.3.3
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: backlog-js
      dependency-version: 0.20.1
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: commander
      dependency-version: 15.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: production-dependencies
    - dependency-name: lefthook
      dependency-version: 2.1.14
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: production-dependencies
    - dependency-name: marked
      dependency-version: 18.0.13
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: production-dependencies
    - dependency-name: open
      dependency-version: 11.0.4
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: production-dependencies
    - dependency-name: oxfmt
      dependency-version: 0.68.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: oxlint-tsgolint
      dependency-version: 7.0.2002
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: production-dependencies
    - dependency-name: oxlint
      dependency-version: 1.83.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: rc9
      dependency-version: 3.1.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: sharp
      dependency-version: 0.35.4
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: production-dependencies
    - dependency-name: starlight-links-validator
      dependency-version: 0.26.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: tsx
      dependency-version: 4.23.15
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: production-dependencies
    - dependency-name: turbo
      dependency-version: 2.11.2
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    - dependency-name: typescript
      dependency-version: 7.0.2
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: production-dependencies
    - dependency-name: undici
      dependency-version: 8.10.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: production-dependencies
    - dependency-name: valibot
      dependency-version: 1.5.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: production-dependencies
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    @dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
    @dependabot
    dependabot Bot requested a review from lollipop-onl as a code owner September 27, 2026 13:56
    @dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
    @github-actions

    Copy link
    Copy Markdown

    Coverage Report

    Status Category Percentage Covered / Total
    🔵 Lines 92.75% 1947 / 2099
    🔵 Statements 92.96% 2036 / 2190
    🔵 Functions 92.87% 456 / 491
    🔵 Branches 80.57% 842 / 1045
    File CoverageNo changed files found.
    Generated in workflow #530 for commit 264ec00 by the Vitest Coverage Report Action

    @dependabot @github

    dependabot Bot commented on behalf of github Sep 28, 2026

    Copy link
    Copy Markdown
    Contributor Author

    Looks like these dependencies are no longer updatable, so this is no longer needed.

    @dependabot dependabot Bot closed this Sep 28, 2026
    @dependabot
    dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-1f8f5c2a22 branch September 28, 2026 16:26
    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    0 participants