Skip to content

chore(deps): bump the npm_and_yarn group across 2 directories with 15 updates - #19

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/documentation/npm_and_yarn-21f4e1b432
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/documentation/npm_and_yarn-21f4e1b432

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 11 updates in the /documentation directory:

Package From To
brace-expansion 1.1.11 1.1.21
browserslist 4.24.4 4.29.3
colord 2.9.3 2.10.0
fast-uri 3.0.6 3.1.8
joi 17.13.3 17.13.8
js-yaml 3.14.1 3.15.2
nanoid 3.3.8 3.3.19
postcss-selector-parser 6.1.2 6.1.4
postcss 8.5.1 8.5.28
qs 6.13.0 6.16.0
svgo 3.3.2 3.3.5

Bumps the npm_and_yarn group with 11 updates in the /ui/desktop directory:

Package From To
brace-expansion 1.1.11 1.1.21
browserslist 4.24.4 4.29.3
js-yaml 4.1.0 4.3.2
nanoid 3.3.8 3.3.19
postcss-selector-parser 6.1.2 6.1.4
postcss 8.5.1 8.5.28
qs 6.13.0 6.16.0
electron 33.1.0 41.10.6
@xmldom/xmldom 0.8.10 0.8.15
ip-address 9.0.5 10.7.3
jsondiffpatch 0.6.0 removed

Updates brace-expansion from 1.1.11 to 1.1.21

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

v1.1.12

  • pkg: publish on tag 1.x c460dbd
  • fmt ccb8ac6
  • Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8

juliangruber/brace-expansion@v1.1.11...v1.1.12

Commits

Updates browserslist from 4.24.4 to 4.29.3

Release notes

Sourced from browserslist's releases.

4.29.3

  • Updated Firefox ESR.

4.29.2

  • Fixed ignoring null usage in cover X in Y query (by @​wahidrizka).

4.29.1

4.29.0

  • Added query continuations across lines and array entries (by @​fzlzjerry).

4.28.9

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).

4.28.2

4.28.1

  • Removed Baseline warning since we have it own warning.

4.27.0

  • Added BROWSERSLIST_TRACE_WARNING environment variable.

4.26.3

... (truncated)

Changelog

Sourced from browserslist's changelog.

4.29.3

  • Updated Firefox ESR.

4.29.2

  • Fixed ignoring null usage in cover X in Y query (by @​wahidrizka).

4.29.1

4.29.0

  • Added query continuations across lines and array entries (by @​fzlzjerry).

4.28.9

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).

... (truncated)

Commits
  • b4809dd Release 4.29.3 version
  • 9d844f8 Update Firefox ESR
  • 0033f34 Update dependencies
  • 906d329 Release 4.29.2 version
  • ff8c83f Update dependencies
  • 067f4a1 Merge pull request #952 from wahidrizka/fix-cover-null-usage
  • f760921 Do not add versions without usage data to cover queries
  • 5be63f5 Merge pull request #953 from wahidrizka/docs-android-latest-version
  • 1e5356f Note that Android version queries return only the latest version
  • 5b7e941 Add missed changes to ChangeLog
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for browserslist since your current version.


Updates colord from 2.9.3 to 2.10.0

Release notes

Sourced from colord's releases.

v2.10 (RGB color mixing)

  • mix, tints, shades and tones (mix plugin) now accept an optional interpolation color space. LAB stays the default; pass "rgb" to interpolate RGB channels instead — the way browsers and design tools (such as Figma) composite translucent layers.
import { colord, extend } from "colord";
import mixPlugin from "colord/plugins/mix";
extend([mixPlugin]);
colord("#ff0000").mix("#ffffff", 0.5, "rgb").toHex(); // "#ff8080"
colord("#f0f3f1").mix("#007d40", 0.14, "rgb").toHex(); // "#cee2d8" — same as compositing rgba(0, 125, 64, 0.14) over #f0f3f1
colord("#ff0000").tints(3, "rgb").map((c) => c.toHex()); // ["#ff0000", "#ff8080", "#ffffff"]

Changelog

Sourced from colord's changelog.

2.10.0

  • Improve mix plugin by adding an optional "rgb" interpolation mode to mix, tints, tones and shades

2.9.7

  • Make HEX parsing and serialization more than 2x faster

2.9.6

  • Fix: Rotate the unrounded hue so rotate and harmonies preserve the original color
  • Fix: Normalize HWB whiteness + blackness over 100% to gray ❤️ @​spokodev

2.9.5

Both fixes change returned numbers for a small set of colors; toHex() output is unchanged. Snapshots holding h: 360, "hsl(360, …)" or a delta() value may need updating.

2.9.4

  • Fix: Reject malformed color strings in linear time ❤️ @​GAP-dev
Commits

Updates fast-uri from 3.0.6 to 3.1.8

Release notes

Sourced from fast-uri's releases.

v3.1.8

⚠️ Security Warning

This security release fixes the following medium-severity security advisory:

Users of the v3.x release line should upgrade to v3.1.8.

Full Changelog: fastify/fast-uri@v3.1.7...v3.1.8

v3.1.7

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.7.

Full Changelog: fastify/fast-uri@v3.1.6...v3.1.7

v3.1.6

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.6.

Full Changelog: fastify/fast-uri@v3.1.5...v3.1.6

v3.1.5

⚠️ Security Warning

Fix for GHSA-7p8r-x3mc-p8w7

Full Changelog: fastify/fast-uri@v3.1.4...v3.1.5

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

... (truncated)

Commits
  • ead3ab7 Bumped v3.1.8
  • c88b59e fix: normalize decoded reg-name case
  • 412e40a Bumped v3.1.7
  • 9f4c943 fix: backport port and IP-literal validation to v3.x (#216)
  • 1eb3ce4 fix: treat unterminated bracket hosts as reg-names again (#214)
  • 6f970b2 Bumped v3.1.6
  • d941579 fix: never run IDN canonicalization on bracketed IP literals
  • c0f0279 test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)
  • 37f3417 Merge commit from fork
  • 607bfbe Merge commit from fork
  • Additional commits viewable in compare view

Updates joi from 17.13.3 to 17.13.8

Commits

Updates js-yaml from 3.14.1 to 3.15.2

Changelog

Sourced from js-yaml's changelog.

3.15.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.

3.15.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

3.15.0 - 2026-06-27

Added

  • Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one safeLoad() / safeLoadAll() call.

[3.14.2] - 2025-11-15

Security

  • Fix prototype pollution in merge (<<).
Commits

Updates nanoid from 3.3.8 to 3.3.19

Release notes

Sourced from nanoid's releases.

3.3.19

  • Fixed killing the app by setting huge user ID.

3.3.18

3.3.17

  • Fixed infinite loop on zero size.

3.3.16

3.3.15

  • Fixed npm provenance error.

3.3.14

  • Fixed random pool corruption on big ID sizes.

3.3.13

  • Reduced npm package size.

3.3.12

  • Fixed breaking Nano ID by requesting big ID.

3.3.11

  • Fixed React Native support.

3.3.10

3.3.9

  • Reduced npm package size.
Changelog

Sourced from nanoid's changelog.

3.3.19

3.3.18

3.3.17

  • Fixed infinite loop on zero size.

3.3.16

3.3.15

  • Fixed npm provenance error.

3.3.14

  • Fixed random pool corruption on big ID sizes.

3.3.13

  • Reduced npm package size.

3.3.12

  • Fixed breaking Nano ID by requesting big ID.

3.3.11

  • Fixed React Native support.

3.3.10

3.3.9

  • Reduced npm package size.
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for nanoid since your current version.


Updates postcss-selector-parser from 6.1.2 to 6.1.4

Release notes

Sourced from postcss-selector-parser's releases.

6.1.4

  • fix: tolerate non-node children when serializing selectors

6.1.3

Changelog

Sourced from postcss-selector-parser's changelog.

Changelog of postcss-selector-parser

7.1.6 - 2026-09-03

  • fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)

7.1.5 - 2026-08-07

  • fix: don't treat a non-prefix token before | as a namespace (#324 by @​spokodev)
  • fix: preserve whitespace before a * namespace in attribute selectors (#325 by @​spokodev)
  • fix: TypeError on unclosed [, ( and trailing | (#330 by @​theRizwan)

7.1.4 - 2026-06-11

  • fix: tolerate non-node children when serializing selectors

7.1.3 - 2026-06-11

  • Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)

7.1.2 - 2026-06-09

7.1.1

  • perf: replace startsWith with strict equality (#308)
  • fix(types): add walkUniversal declaration (#311)

7.1.0

  • feat: insert(Before|After) support multiple new node

7.0.0

  • Feat: make insertions during iteration safe (major)
Commits
Maintainer changes

This version was pushed to npm by moox, a new releaser for postcss-selector-parser since your current version.


Updates postcss from 8.5.1 to 8.5.28

Release notes

Sourced from postcss's releases.

8.5.28

  • Fixes types regression.

8.5.27

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

... (truncated)

Changelog

Sourced from postcss's changelog.

8.5.28

  • Fixes types regression.

8.5.27

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.


Updates qs from 6.13.0 to 6.16.0

Changelog

Sourced from qs's changelog.

6.16.0

  • [New] stringify: add a depth option to bound recursion depth (default Infinity)
  • [Fix] stringify: serialize Date values when a filter is provided
  • [Fix] parse: enforce arrayLimit on comma groups under []= when throwOnLimitExceeded is set
  • [Fix] parse: flatten a collection appended to an overflowed array (#571)
  • [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or drop own keys) on an empty array with own properties
  • [Fix] stringify: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (#562)
  • [Docs] threat model: clarify stringify deep-nesting DoS is caller-bounded
  • [Docs] clarify arrayLimit is a representation threshold, not an element-count cap
  • [Tests] parse: remove a test that pinned []= comma groups escaping arrayLimit
  • [Tests] stringify: pin current encodeDotInKeys separator-dot behavior
  • [Dev Deps] update @ljharb/eslint-config, eslint
  • [Dev Deps] update eslint, evalmd

6.15.3

  • [Fix] parse: enforce throwOnLimitExceeded for cumulative array growth via combine/merge
  • [Fix] utils: respect encoding of surrogate pairs across chunks (#559)
  • [Robustness] parse: throw the arrayLimit error before splitting oversized comma values
  • [Robustness] utils.merge / utils.assign: avoid invoking __proto__ setter when copying own properties
  • [Robustness] utils: enforce arrayLimit consistently across merge's array paths
  • [Perf] utils: make compact O(n) via a side-channel visited-set instead of Array.indexOf
  • [Deps] update side-channel
  • [Dev Deps] update eslint, mock-property, tape
  • [Tests] parse: characterize current lenient handling of unbalanced bracket keys (#558)

6.15.2

  • [Fix] stringify: skip null/undefined entries in arrayFormat: 'comma' + encodeValuesOnly instead of crashing in encoder
  • [Fix] stringify: use configured delimiter after charsetSentinel (#555)
  • [Fix] stringify: apply formatter to encoded key under strictNullHandling (#554)
  • [Fix] stringify: skip null/undefined filter-array entries instead of crashing in encoder (#551)
  • [Fix] parse: handle nested bracket groups and add regression tests (#530); changes output for some unbalanced bracket keys (see #558)
  • [readme] fix grammar (#550)
  • [Dev Deps] update @ljharb/eslint-config
  • [Tests] add regression tests for keys containing percent-encoded bracket text

6.15.1

  • [Fix] parse: parameterLimit: Infinity with throwOnLimitExceeded: true silently drops all parameters
  • [Deps] update @ljharb/eslint-config
  • [Dev Deps] update @ljharb/eslint-config, iconv-lite
  • [Tests] increase coverage

6.15.0

  • [New] parse: add strictMerge option to wrap object/primitive conflicts in an array (#425, #122)
  • [Fix] duplicates option should not apply to bracket notation keys (#514)

6.14.2

  • [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)
  • [Fix] arrayLimit means max count, not max index, in combine/merge/parseArrayValue
  • [Fix] parse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)

... (truncated)

Commits
  • bb9379e v6.16.0
  • 62fd254 [Fix] stringify: serialize Date values when a filter is provided
  • 8859c37 [Fix] parse: enforce arrayLimit on comma groups under []= when `throwOn...
  • 8079adc [Tests] parse: remove a test that pinned []= comma groups escaping `array...
  • d56f48c [Fix] parse: flatten a collection appended to an overflowed array
  • e83d321 [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • 7e87a07 [Dev Deps] update @ljharb/eslint-config, eslint
  • 9a76af2 [Dev Deps] update eslint, evalmd
  • 3a890d4 [Dev Deps] update eslint, evalmd
  • b433a9b [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or dro...
  • Additional commits viewable in compare view

Updates svgo from 3.3.2 to 3.3.5

Release notes

Sourced from svgo's releases.

v3.3.5

What's Changed

Security

  • Backport the removeScriptElement hardening from SVGO v4 in #2269:
    • reject executable data: URLs and legacy vbscript: URLs
    • sanitize executable HTML inside <foreignObject> elements
    • handle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines

This addresses GHSA-4vpr-x523-8j87 and GHSA-w27v-7q3p-w38r for the v3 release line.

Support

SVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.

See the migration guide from v3 to v4.

v3.3.4

What's Changed

Security

Support

SVGO v3 is not officially supported, please consider upgrading to SVGO v4 instead. We've backported this fix as there are security implications, but there is no commitment to do this for more complex changes in future.

Consider reading our Migration Guide from v3 to v4 which should ease the process.

v3.3.3

What's Changed

Dependencies

  • Migrates from our unsupported fork of sax (@​trysound/sax) to the upstream version of sax (sax).

Bug Fixes

  • No longer throws error when encountering comments in DTD.

Metrics

Before and after of the browser bundle of each respective version:

v3.3.2 v3.3.3 Delta
svgo.browser.js 910.9 kB 912.9 kB ⬆️ 2 kB

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for svgo since your current version.


Updates brace-expansion from 1.1.11 to 1.1.21

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

v1.1.12

  • pkg: publish on tag 1.x c460dbd
  • fmt ccb8ac6
  • Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8

juliangruber/brace-expansion@v1.1.11...v1.1.12

Commits

Updates browserslist from 4.24.4 to 4.29.3

Release notes

Sourced from browserslist's releases.

4.29.3

  • Updated Firefox ESR.

4.29.2

  • Fixed ignoring null usage in cover X in Y query (by @​wahidrizka).

4.29.1

4.29.0

  • Added query continuations across lines and array entries (by @​fzlzjerry).

4.28.9

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).

4.28.2

4.28.1

  • Removed Baseline warning since we have it own warning.

4.27.0

  • Added BROWSERSLIST_TRACE_WARNING environment variable.

4.26.3

... (truncated)

Changelog

Sourced from browserslist's changelog.

4.29.3

  • Updated Firefox ESR.

4.29.2

  • Fixed ignoring null usage in cover X in Y query (by @​wahidrizka).

4.29.1

4.29.0

  • Added query continuations across lines and array entries (by @​fzlzjerry).

4.28.9

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).

... (truncated)

Commits
  • b4809dd Release 4.29.3 version
  • 9d844f8 Update Firefox ESR
  • 0033f34 Update depe...

    Description has been truncated

    Summary by Bito

    • Updated postcss-selector-parser to version 7.1.6 across multiple dependencies.
    • Upgraded body-parser from 1.20.3 to 1.20.8.
    • Added baseline-browser-mapping dependency.
    • Removed @trysound/sax dependency.

    Summary by cubic

    Updates the documentation and ui/desktop dependency lockfiles to pull in security fixes and maintenance releases across 15 packages, including postcss, browserslist, qs, js-yaml, fast-uri, svgo, and nanoid.

    Also bumps two major dependencies in ui/desktop: electron from 33.1.0 to 41.10.6 and ai from ^3.4.33 to ^7.0.127.

    Migration

    • Verify the desktop app builds and launches correctly with electron 41; this is a major-version jump and may require code changes.
    • Confirm the app still works with ai v7; its API differs significantly from v3.

    Written for commit 77f60e5. Summary will update on new commits.

    Review in cubic

… updates

Bumps the npm_and_yarn group with 11 updates in the /documentation directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.21` |
| [browserslist](https://github.com/browserslist/browserslist) | `4.24.4` | `4.29.3` |
| [colord](https://github.com/omgovich/colord) | `2.9.3` | `2.10.0` |
| [fast-uri](https://github.com/fastify/fast-uri) | `3.0.6` | `3.1.8` |
| [joi](https://github.com/hapijs/joi) | `17.13.3` | `17.13.8` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.1` | `3.15.2` |
| [nanoid](https://github.com/ai/nanoid) | `3.3.8` | `3.3.19` |
| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `6.1.4` |
| [postcss](https://github.com/postcss/postcss) | `8.5.1` | `8.5.28` |
| [qs](https://github.com/ljharb/qs) | `6.13.0` | `6.16.0` |
| [svgo](https://github.com/svg/svgo) | `3.3.2` | `3.3.5` |

Bumps the npm_and_yarn group with 11 updates in the /ui/desktop directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.21` |
| [browserslist](https://github.com/browserslist/browserslist) | `4.24.4` | `4.29.3` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.0` | `4.3.2` |
| [nanoid](https://github.com/ai/nanoid) | `3.3.8` | `3.3.19` |
| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `6.1.4` |
| [postcss](https://github.com/postcss/postcss) | `8.5.1` | `8.5.28` |
| [qs](https://github.com/ljharb/qs) | `6.13.0` | `6.16.0` |
| [electron](https://github.com/electron/electron) | `33.1.0` | `41.10.6` |
| [@xmldom/xmldom](https://github.com/xmldom/xmldom) | `0.8.10` | `0.8.15` |
| [ip-address](https://github.com/beaugunderson/ip-address) | `9.0.5` | `10.7.3` |
| [jsondiffpatch](https://github.com/benjamine/jsondiffpatch) | `0.6.0` | `removed` |



Updates `brace-expansion` from 1.1.11 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.21)

Updates `browserslist` from 4.24.4 to 4.29.3
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](browserslist/browserslist@4.24.4...4.29.3)

Updates `colord` from 2.9.3 to 2.10.0
- [Release notes](https://github.com/omgovich/colord/releases)
- [Changelog](https://github.com/omgovich/colord/blob/master/CHANGELOG.md)
- [Commits](https://github.com/omgovich/colord/commits/v2.10)

Updates `fast-uri` from 3.0.6 to 3.1.8
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.0.6...v3.1.8)

Updates `joi` from 17.13.3 to 17.13.8
- [Commits](hapijs/joi@v17.13.3...v17.13.8)

Updates `js-yaml` from 3.14.1 to 3.15.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.1...3.15.2)

Updates `nanoid` from 3.3.8 to 3.3.19
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@3.3.8...3.3.19)

Updates `postcss-selector-parser` from 6.1.2 to 6.1.4
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v6.1.2...6.1.4)

Updates `postcss` from 8.5.1 to 8.5.28
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.1...8.5.28)

Updates `qs` from 6.13.0 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.16.0)

Updates `svgo` from 3.3.2 to 3.3.5
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.2...v3.3.5)

Updates `brace-expansion` from 1.1.11 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.21)

Updates `browserslist` from 4.24.4 to 4.29.3
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](browserslist/browserslist@4.24.4...4.29.3)

Updates `js-yaml` from 4.1.0 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.1...3.15.2)

Updates `nanoid` from 3.3.8 to 3.3.19
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@3.3.8...3.3.19)

Updates `postcss-selector-parser` from 6.1.2 to 6.1.4
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v6.1.2...6.1.4)

Updates `postcss` from 8.5.1 to 8.5.28
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.1...8.5.28)

Updates `qs` from 6.13.0 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.16.0)

Updates `electron` from 33.1.0 to 41.10.6
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v33.1.0...v41.10.6)

Updates `@xmldom/xmldom` from 0.8.10 to 0.8.15
- [Release notes](https://github.com/xmldom/xmldom/releases)
- [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md)
- [Commits](xmldom/xmldom@0.8.10...0.8.15)

Updates `ip-address` from 9.0.5 to 10.7.3
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v9.0.5...v10.7.3)

Removes `jsondiffpatch`

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: browserslist
  dependency-version: 4.29.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: colord
  dependency-version: 2.10.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: joi
  dependency-version: 17.13.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: js-yaml
  dependency-version: 3.15.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: nanoid
  dependency-version: 3.3.19
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: postcss-selector-parser
  dependency-version: 6.1.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: svgo
  dependency-version: 3.3.5
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: browserslist
  dependency-version: 4.29.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: nanoid
  dependency-version: 3.3.19
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: postcss-selector-parser
  dependency-version: 6.1.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: electron
  dependency-version: 41.10.6
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: "@xmldom/xmldom"
  dependency-version: 0.8.15
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ip-address
  dependency-version: 10.7.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: jsondiffpatch
  dependency-version:
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@safedep

safedep Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

Package Details
Package Malware Vulnerability Risky License Report
@ai-sdk/gateway @ 4.0.103
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@ai-sdk/provider @ 4.0.21
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@ai-sdk/provider-utils @ 5.0.53
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@ampproject/remapping @ 2.3.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@electron-internal/extract-zip @ 1.0.5
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@electron/get @ 5.1.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@standard-schema/spec @ 1.1.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@types/node @ 24.19.1
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@vercel/oidc @ 3.2.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@workflow/serde @ 4.1.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
@xmldom/xmldom @ 0.8.15
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
acorn @ 8.14.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
ai @ 7.0.127
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
baseline-browser-mapping @ 2.11.27
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
body-parser @ 1.20.8
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
brace-expansion @ 2.1.7
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
brace-expansion @ 1.1.21
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
browserslist @ 4.29.3
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
caniuse-lite @ 1.0.30001814
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
colord @ 2.10.0
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
content-disposition @ 0.5.4
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
cookie @ 0.7.2
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
cookie-signature @ 1.0.7
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
electron @ 41.10.6
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
electron-to-chromium @ 1.5.444
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
env-paths @ 3.0.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
eventsource-parser @ 3.1.1
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
express @ 4.22.3
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
fast-uri @ 3.1.8
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
finalhandler @ 1.3.2
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
gray-matter @ 3.15.2
npm documentation/package-lock.json
✔️ ✔️ ✔️ 🔗
http-errors @ 2.0.1
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
ip-address @ 10.7.3
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
joi @ 17.13.8
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
js-yaml @ 4.3.2
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
js-yaml @ 3.15.2
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
mime-db @ 1.52.0
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
mime-types @ 2.1.35
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
nanoid @ 3.3.19
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
node-releases @ 2.0.57
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
object-inspect @ 1.13.4
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
path-to-regexp @ 0.1.13
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
postcss @ 8.5.28
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
postcss-selector-parser @ 7.1.6
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
postcss-selector-parser @ 6.1.4
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
qs @ 6.16.0
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
raw-body @ 2.5.3
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
sax @ 1.6.1
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
send @ 0.19.2
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
serve-static @ 1.16.3
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
side-channel @ 1.1.1
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
side-channel-list @ 1.0.1
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
socks @ 2.8.10
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
statuses @ 2.0.2
npm documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
svgo @ 3.3.5
npm documentation/package-lock.json documentation/yarn.lock
✔️ ✔️ ✔️ 🔗
undici @ 7.30.0
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
undici-types @ 7.24.6
npm ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗
update-browserslist-db @ 1.3.3
npm documentation/package-lock.json documentation/yarn.lock ui/desktop/package-lock.json
✔️ ✔️ ✔️ 🔗

View complete scan results →

This report is generated by SafeDep GitHub App

@ai-document-creator

Copy link
Copy Markdown

ℹ️ No Configured Files to Document

This PR doesn't contain any files that match your documentation configuration.

Files Changed

  • ✏️ documentation/package-lock.json
  • ✏️ documentation/yarn.lock
  • ✏️ ui/desktop/package-lock.json
  • ✏️ ui/desktop/package.json

Why No Documentation?

None of the files configured to be watched in your .github/wai-docbot.yml have changed in this PR.

DocBot processes files based on:

  • Include patterns - Which file types/paths to document
  • Exclude patterns - Which files/folders to skip

Need to document these files?

Check your .github/wai-docbot.yml configuration:

  • Verify your include patterns cover the files you want documented
  • Check if any exclude patterns are blocking these files
  • Ensure file extensions are configured for documentation

View configuration guide →


If changes were expected but not processed, please review your configuration settings.

@ecc-tools

ecc-tools Bot commented Oct 3, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 77f60e54d33b4380829677567760e5575852e4a5

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 4 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 3, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 77f60e54d33b4380829677567760e5575852e4a5

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Install Manifest Integrity, CI/CD Recommendation.

Scanned 4 changed file(s).

Roadmap taxonomy buckets:

Install Manifest Integrity

Install manifests, plugin metadata, and shipped skills should stay synchronized with user-facing setup guidance.

Signals:

  • 3 install or manifest path(s) changed

Paths:

  • documentation/package-lock.json
  • documentation/yarn.lock
  • ui/desktop/package-lock.json

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • User-facing UI changes may ship without browser coverage
  • 3 CI or workflow path(s) changed

Paths:

  • documentation/package-lock.json
  • documentation/yarn.lock
  • ui/desktop/package-lock.json
  • ui/desktop/package.json

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@codeant-ai

codeant-ai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@ecc-tools

ecc-tools Bot commented Oct 3, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 77f60e54d33b4380829677567760e5575852e4a5

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 4 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 3, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 77f60e54d33b4380829677567760e5575852e4a5

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 4 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 75573a9c-5b0d-49c5-8641-32b1b01aab34

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​electron@​33.1.0 ⏵ 41.10.694 +1100 +7510098100
Updatednpm/​ai@​3.4.33 ⏵ 7.0.12799 +1100 +110099100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants