Skip to content

build(deps-dev): bump the npm-development group across 1 directory with 13 updates#898

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-development-6be76b5bd6
Open

build(deps-dev): bump the npm-development group across 1 directory with 13 updates#898
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-development-6be76b5bd6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-development group with 13 updates in the / directory:

Package From To
@bahmutov/cypress-esbuild-preprocessor 2.2.0 2.2.8
@percy/cli 1.24.0 1.31.13
@percy/cypress 3.1.2 3.1.8
@storybook/test-runner 0.22.1 0.24.4
allure-commandline 2.40.0 2.41.0
browserstack-cypress-cli 1.36.5 1.36.7
cypress-tags 1.1.2 1.2.2
esbuild 0.17.10 0.28.0
@web/dev-server-esbuild 1.0.1 1.0.5
@web/test-runner 0.18.0 0.20.2
@web/test-runner-browserstack 0.7.0 0.8.0
@web/test-runner-playwright 0.11.0 0.11.1
esmock 2.6.0 2.7.5

Updates @bahmutov/cypress-esbuild-preprocessor from 2.2.0 to 2.2.8

Release notes

Sourced from @​bahmutov/cypress-esbuild-preprocessor's releases.

v2.2.8

2.2.8 (2025-12-02)

Bug Fixes

  • Await resolving on 1st run until bundle has made it to fs (#515) (9729b37)

v2.2.7

2.2.7 (2025-10-24)

Bug Fixes

v2.2.6

2.2.6 (2025-09-14)

Bug Fixes

  • deps: update dependency debug to v4.4.3 (#503) (4595c7d)

v2.2.5

2.2.5 (2025-05-15)

Bug Fixes

  • deps: update dependency debug to v4.4.1 (#477) (b77c1e1)

v2.2.4

2.2.4 (2024-12-07)

Bug Fixes

  • deps: update dependency debug to v4.4.0 (#448) (bfaec6f)

v2.2.3

2.2.3 (2024-09-06)

Bug Fixes

  • deps: update dependency debug to v4.3.7 (6b34d4e)

v2.2.2

2.2.2 (2024-07-27)

... (truncated)

Commits
  • 9729b37 fix: Await resolving on 1st run until bundle has made it to fs (#515)
  • 2b02197 chore(deps): update dependency prettier to v3.7.3 (#524)
  • 75a0c9c chore(deps): update dependency prettier to v3.7.2 (#523)
  • c94564b chore(deps): update dependency prettier to v3.7.1 (#522)
  • 0ba856b chore(deps): update actions/checkout action to v6 (#521)
  • 46b871f Updated badges
  • 333beef chore(deps): update dependency cypress to v15.7.0 (#520)
  • e7a5e3e Updated badges
  • 5f4e5ae chore(deps): update dependency esbuild to v0.27.0 (#519)
  • b7a3803 chore(deps): update dependency esbuild to v0.26.0 (#518)
  • Additional commits viewable in compare view

Updates @percy/cli from 1.24.0 to 1.31.13

Release notes

Sourced from @​percy/cli's releases.

v1.31.13

What's Changed

✨ Enhancements

Full Changelog: percy/cli@v1.31.12...v1.31.13

v1.31.13-beta.0

What's Changed

✨ Enhancements

Full Changelog: percy/cli@v1.31.12...v1.31.13-beta.0

v1.31.12

New Contributors

Full Changelog: percy/cli@v1.31.11...v1.31.12

v1.31.12-beta.0

No release notes provided.

v1.31.11

What's Changed

🐛 Bug Fixes

🏗 Maintenance

⬆️⬇️ Dependency Updates

New Contributors

... (truncated)

Commits

Updates @percy/cypress from 3.1.2 to 3.1.8

Release notes

Sourced from @​percy/cypress's releases.

Release 2.1.8

What's Changed

New Contributors

Full Changelog: percy/percy-cypress@v3.1.7...v3.1.8

v3.1.8-beta.2

What's Changed

New Contributors

Full Changelog: percy/percy-cypress@v3.1.8-beta.1...v3.1.8-beta.2

v3.1.8-beta.1

What's Changed

New Contributors

Full Changelog: percy/percy-cypress@v3.1.8-beta.0...v3.1.8-beta.1

v3.1.8-beta.0

What's Changed

Full Changelog: percy/percy-cypress@v3.1.7-beta.0...v3.1.8-beta.0

v3.1.7

v3.1.7-beta.0

What's Changed

... (truncated)

Commits

Updates @storybook/test-runner from 0.22.1 to 0.24.4

Release notes

Sourced from @​storybook/test-runner's releases.

v0.24.4

🐛 Bug Fix

Authors: 1

v0.24.3

🐛 Bug Fix

Authors: 1

v0.24.3-next.0

🐛 Bug Fix

Authors: 1

v0.24.2

🐛 Bug Fix

Authors: 1

v0.24.2-next.0

🐛 Bug Fix

Authors: 1

v0.24.1

🐛 Bug Fix

... (truncated)

Changelog

Sourced from @​storybook/test-runner's changelog.

v0.24.4 (Thu May 14 2026)

🐛 Bug Fix

Authors: 1


v0.24.3 (Wed Mar 18 2026)

🐛 Bug Fix

Authors: 1


v0.24.2 (Thu Nov 27 2025)

🐛 Bug Fix

Authors: 1


v0.24.1 (Wed Oct 29 2025)

🐛 Bug Fix

Authors: 3

... (truncated)

Commits
  • 824d43b Bump version to: 0.24.4 [skip ci]
  • 51f6097 Update CHANGELOG.md [skip ci]
  • 55a7a25 Merge pull request #603 from storybookjs/chore/peerdeps
  • 34dc7fd chore: update storybook peerdependencies to prerelease
  • 72de1cb Bump version to: 0.24.3 [skip ci]
  • 11c305f Update CHANGELOG.md [skip ci]
  • b4e46a5 Merge pull request #596 from storybookjs/release/v0.24.3
  • 222f5a4 Merge branch 'main' into release/v0.24.3
  • 2d76468 Merge pull request #595 from storybookjs/yann/storybook-10-4-support
  • d7c0719 set up provenance
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​storybook/test-runner since your current version.


Updates allure-commandline from 2.40.0 to 2.41.0

Release notes

Sourced from allure-commandline's releases.

2.41.0

Full Changelog: allure-framework/allure-npm@2.40.0...2.41.0

Commits

Updates browserstack-cypress-cli from 1.36.5 to 1.36.7

Release notes

Sourced from browserstack-cypress-cli's releases.

Public Beta v1.36.7

Highlighted Changes 拾

🐛 Fix serialize-javascript browserstack/browserstack-cypress-cli#1103 browserstack/browserstack-cypress-cli@v1.36.6...v1.36.7

Public Beta v1.36.6

Highlighted Changes 🥳 🐛 [TRA] Fix cy logs not appearing in dashboard for failing test #1094

browserstack/browserstack-cypress-cli@v1.36.5...v1.36.6

Commits
  • 9bbf468 Merge pull request #1105 from browserstack/deploy-1.36.6
  • 6740e0d 1.36.6
  • a9a153b Merge pull request #1103 from browserstack/security/fix-serialize-javascript-...
  • 461435b fix(security): pin serialize-javascript via overrides + lockfile v1 [APS-18800]
  • 40517f3 Merge pull request #1101 from browserstack/revert-1096-security/fix-serialize...
  • 59b1bcb Revert "[APS-18800] fix(security): upgrade serialize-javascript to 7.0.3 to f...
  • 8884dc3 Merge pull request #1080 from browserstack/fix/APS-18613-command-injection-cy...
  • e9f1fbc Merge branch 'master' into fix/APS-18613-command-injection-cypress-config
  • 6d2ac1a Merge pull request #1094 from browserstack/sdk-5709
  • 56e11ea Merge branch 'master' into sdk-5709
  • Additional commits viewable in compare view

Updates cypress-tags from 1.1.2 to 1.2.2

Changelog

Sourced from cypress-tags's changelog.

[1.2.2] - 2024-05-14

Changed

  • Remove dist folder from gitignore as we need to publish it in github. Closes 262.

[1.2.1] - 2024-05-14

Changed

  • add check version to pull_request. Closes 262.

[1.2.0] - 2024-05-14

Changed

  • Upgrade dependencies to latest. Closes 262.
Commits
Maintainer changes

This version was pushed to npm by infosum_sre, a new releaser for cypress-tags since your current version.


Updates esbuild from 0.17.10 to 0.28.0

Release notes

Sourced from esbuild's releases.

v0.28.0

  • Add support for with { type: 'text' } imports (#4435)

    The import text proposal has reached stage 3 in the TC39 process, which means that it's recommended for implementation. It has also already been implemented by Deno and Bun. So with this release, esbuild also adds support for it. This behaves exactly the same as esbuild's existing text loader. Here's an example:

    import string from './example.txt' with { type: 'text' }
    console.log(string)
  • Add integrity checks to fallback download path (#4343)

    Installing esbuild via npm is somewhat complicated with several different edge cases (see esbuild's documentation for details). If the regular installation of esbuild's platform-specific package fails, esbuild's install script attempts to download the platform-specific package itself (first with the npm command, and then with a HTTP request to registry.npmjs.org as a last resort).

    This last resort path previously didn't have any integrity checks. With this release, esbuild will now verify that the hash of the downloaded binary matches the expected hash for the current release. This means the hashes for all of esbuild's platform-specific binary packages will now be embedded in the top-level esbuild package. Hopefully this should work without any problems. But just in case, this change is being done as a breaking change release.

  • Update the Go compiler from 1.25.7 to 1.26.1

    This upgrade should not affect anything. However, there have been some significant internal changes to the Go compiler, so esbuild could potentially behave differently in certain edge cases:

    • It now uses the new garbage collector that comes with Go 1.26.
    • The Go compiler is now more aggressive with allocating memory on the stack.
    • The executable format that the Go linker uses has undergone several changes.
    • The WebAssembly build now unconditionally makes use of the sign extension and non-trapping floating-point to integer conversion instructions.

    You can read the Go 1.26 release notes for more information.

v0.27.7

  • Fix lowering of define semantics for TypeScript parameter properties (#4421)

    The previous release incorrectly generated class fields for TypeScript parameter properties even when the configured target environment does not support class fields. With this release, the generated class fields will now be correctly lowered in this case:

    // Original code
    class Foo {
      constructor(public x = 1) {}
      y = 2
    }
    // Old output (with --loader=ts --target=es2021)
    class Foo {
    constructor(x = 1) {
    this.x = x;
    __publicField(this, "y", 2);
    }
    x;
    }
    // New output (with --loader=ts --target=es2021)
    class Foo {

... (truncated)

Changelog

Sourced from esbuild's changelog.

Changelog: 2023

This changelog documents all esbuild versions published in the year 2023 (versions 0.16.13 through 0.19.11).

0.19.11

  • Fix TypeScript-specific class transform edge case (#3559)

    The previous release introduced an optimization that avoided transforming super() in the class constructor for TypeScript code compiled with useDefineForClassFields set to false if all class instance fields have no initializers. The rationale was that in this case, all class instance fields are omitted in the output so no changes to the constructor are needed. However, if all of this is the case and there are #private instance fields with initializers, those private instance field initializers were still being moved into the constructor. This was problematic because they were being inserted before the call to super() (since super() is now no longer transformed in that case). This release introduces an additional optimization that avoids moving the private instance field initializers into the constructor in this edge case, which generates smaller code, matches the TypeScript compiler's output more closely, and avoids this bug:

    // Original code
    class Foo extends Bar {
      #private = 1;
      public: any;
      constructor() {
        super();
      }
    }
    // Old output (with esbuild v0.19.9)
    class Foo extends Bar {
    constructor() {
    super();
    this.#private = 1;
    }
    #private;
    }
    // Old output (with esbuild v0.19.10)
    class Foo extends Bar {
    constructor() {
    this.#private = 1;
    super();
    }
    #private;
    }
    // New output
    class Foo extends Bar {
    #private = 1;
    constructor() {
    super();
    }
    }

  • Minifier: allow reording a primitive past a side-effect (#3568)

    The minifier previously allowed reordering a side-effect past a primitive, but didn't handle the case of reordering a primitive past a side-effect. This additional case is now handled:

... (truncated)

Commits
  • 6a794df publish 0.28.0 to npm
  • 64ee0ea fix #4435: support with { type: text } imports
  • ef65aee fix sort order in snapshots_packagejson.txt
  • 1a26a8e try to fix test-old-ts, also shuffle CI tasks
  • 556ce6c use '' instead of null to omit build hashes
  • 8e675a8 ci: allow missing binary hashes for tests
  • 7067763 Reapply "update go 1.25.7 => 1.26.1"
  • 39473a9 fix #4343: integrity check for binary download
  • 2025c9f publish 0.27.7 to npm
  • c6b586e fix typo in Makefile for @esbuild/win32-x64
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for esbuild since your current version.


Updates @web/dev-server-esbuild from 1.0.1 to 1.0.5

Release notes

Sourced from @​web/dev-server-esbuild's releases.

@​web/dev-server-esbuild@​1.0.4

Patch Changes

  • d826727: upgrade esbuild to 0.25.x

@​web/dev-server-esbuild@​1.0.3

Patch Changes

  • f506af31: Upgrade esbuild to 0.24.x
  • Updated dependencies [fb33d75c]
    • @​web/dev-server-core@​0.7.4
Changelog

Sourced from @​web/dev-server-esbuild's changelog.

1.0.5

Patch Changes

  • d304459: Bump esbuild version to 0.27.0

1.0.4

Patch Changes

  • d826727: upgrade esbuild to 0.25.x

1.0.3

Patch Changes

  • f506af31: Upgrade esbuild to 0.24.x
  • Updated dependencies [fb33d75c]
    • @​web/dev-server-core@​0.7.4

1.0.2

Patch Changes

  • fix: update @​web/dev-server-core
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​web/dev-server-esbuild since your current version.


Updates @web/test-runner from 0.18.0 to 0.20.2

Release notes

Sourced from @​web/test-runner's releases.

@​web/test-runner@​0.20.2

Patch Changes

  • 7aedbaa: Summary Reporter - re-enabled error reporting and made option to disable browser logs and error reporting in this reporter

@​web/test-runner-chrome@​0.18.1

Patch Changes

  • 79b0ba4: This changeset removes the Puppeteer/Chrome focus browser patches that shouldn't be needed anymore, and can cause instability.

    The patches were added quite a while ago, and the upstream issues should be resolved in Chromium. See: https://issues.chromium.org/issues/40272146.

    Also see: puppeteer/puppeteer#10350.

    The patches are currently also resulting some instability of web test runner. That is because the patch calls an exposed function from inside the browser, while navigation later on during stopSession can happen; breaking the handle for retrieving function call arguments passed to the exposed function.

    Puppeteer team found this issue and also landed a fix to improve the failure mode here. See: puppeteer/puppeteer#13759

@​web/test-runner@​0.20.1

Patch Changes

  • 24e3290: Improve debug message for test runner uncaught exceptions

    This should make debugging easier. It wasn't very easy to figure out where the errors originated from (because of how the actual uncaught exception only happened with many concurrent builds inside a sandbox environment that is hard to debug).

  • Updated dependencies [79b0ba4]

    • @​web/test-runner-chrome@​0.18.1
Changelog

Sourced from @​web/test-runner's changelog.

0.20.2

Patch Changes

  • 7aedbaa: Summary Reporter - re-enabled error reporting and made option to disable browser logs and error reporting in this reporter

0.20.1

Patch Changes

  • 24e3290: Improve debug message for test runner uncaught exceptions

    This should make debugging easier. It wasn't very easy to figure out where the errors originated from (because of how the actual uncaught exception only happened with many concurrent builds inside a sandbox environment that is hard to debug).

  • Updated dependencies [79b0ba4]

    • @​web/test-runner-chrome@​0.18.1

0.20.0

Minor Changes

  • 86eaa21: Upgrade puppeteer version to v24

Patch Changes

  • Updated dependencies [86eaa21]
    • @​web/test-runner-chrome@​0.18.0

0.19.0

Minor Changes

  • b546e8b5: Upgrade puppeteer-core and puppeteer to v23

Patch Changes

  • Updated dependencies [b546e8b5]
    • @​web/test-runner-chrome@​0.17.0

0.18.3

Patch Changes

  • 6914f3b6: Show suites names for summaryReporter when flatten option is true

0.18.2

... (truncated)

Commits
  • 9645344 Version Packages
  • 61260d5 Turned error reporting back on by default to match old behviour before it was...
  • 4fa7523 add back broken error reporting and make log reporting optional
  • db00ed5 Version Packages
  • 24e3290 refactor: improve debug message for test runner uncaught exceptions
  • f00a581 Version Packages
  • fcb71cd Version Packages
  • 8834ad8 Version Packages
  • d5ae228 Version Packages (#2803)
  • 9a88d83 Version Packages (#2774)
  • Additional commits viewable in compare view

Updates @web/test-runner-browserstack from 0.7.0 to 0.8.0

Release notes

Sourced from @​web/test-runner-browserstack's releases.

@​web/test-runner-browserstack@​0.8.0

Minor Changes

  • e755f6b: Upgrade WebdriverIO to v9, drop JWP capabilities

Patch Changes

  • Updated dependencies [e755f6b]
    • @​web/test-runner-webdriver@​0.9.0

@​web/test-runner-browserstack@​0.7.2

Patch Changes

Changelog

Sourced from @​web/test-runner-browserstack's changelog.

0.8.0

Minor Changes

  • e755f6b: Upgrade WebdriverIO to v9, drop JWP capabilities

Patch Changes

  • Updated dependencies [e755f6b]
    • @​web/test-runner-webdriver@​0.9.0

0.7.2

Patch Changes

0.7.1

Patch Changes

Commits

Updates @web/test-runner-playwright from 0.11.0 to 0.11.1

Release notes

Sourced from @​web/test-runner-playwright's releases.

@​web/test-runner-playwright@​0.11.1

Patch Changes

  • dbd6f47: bump playwright
Changelog

Sourced from @​web/test-runner-playwright's changelog.

0.11.1

Patch Changes

  • dbd6f47: bump playwright
Commits
  • 6462890 Version Packages
  • 0260bc7 chore: bump playwright version to latest which works in GitHub Actions Ubuntu...
  • 54d65a4 ci: align reporters across all packages
  • 90e4472 ci: use workspaces to run node tests
  • 5792e9c Add file extensions to file imports
  • See full diff in compare view

Updates esmock from 2.6.0 to 2.7.5

Release notes

Sourced from esmock's releases.

clerical changes; linting+coverage

src files are unchanged; only clerical changes for linting and coverage tools,

support typescript-modules

restore support for ava and other test runners,

match exact export paths

increment resolvewithplus, match exact export paths, thanks @​matz3

add node v24 to test matrix

a "version bump" release with no new features adding node v24 to the test matrix

resolve openai mocking

resolve issue that prevented openai package mock

support node v23

Add node 23 ro the test matrix and update to support node 23,

add pnpm test

fixes an issue that prevented esmock from being used with pnpm,

add swc tests

add swc tests and remove swc caution from README thanks @​Brooooooklyn

migrate eslint 9 add tsx tests,

add node v22 to test matrix

... (truncated)

Changelog

Sourced from esmock's changelog.

changelog

…th 13 updates

Bumps the npm-development group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@bahmutov/cypress-esbuild-preprocessor](https://github.com/bahmutov/cypress-esbuild-preprocessor) | `2.2.0` | `2.2.8` |
| [@percy/cli](https://github.com/percy/cli/tree/HEAD/packages/cli) | `1.24.0` | `1.31.13` |
| [@percy/cypress](https://github.com/percy/percy-cypress) | `3.1.2` | `3.1.8` |
| [@storybook/test-runner](https://github.com/storybookjs/test-runner) | `0.22.1` | `0.24.4` |
| [allure-commandline](https://github.com/allure-framework/allure-npm) | `2.40.0` | `2.41.0` |
| [browserstack-cypress-cli](https://github.com/browserstack/browserstack-cypress-cli) | `1.36.5` | `1.36.7` |
| [cypress-tags](https://github.com/infosum/cypress-tags) | `1.1.2` | `1.2.2` |
| [esbuild](https://github.com/evanw/esbuild) | `0.17.10` | `0.28.0` |
| [@web/dev-server-esbuild](https://github.com/modernweb-dev/web/tree/HEAD/packages/dev-server-esbuild) | `1.0.1` | `1.0.5` |
| [@web/test-runner](https://github.com/modernweb-dev/web/tree/HEAD/packages/test-runner) | `0.18.0` | `0.20.2` |
| [@web/test-runner-browserstack](https://github.com/modernweb-dev/web/tree/HEAD/packages/test-runner-browserstack) | `0.7.0` | `0.8.0` |
| [@web/test-runner-playwright](https://github.com/modernweb-dev/web/tree/HEAD/packages/test-runner-playwright) | `0.11.0` | `0.11.1` |
| [esmock](https://github.com/iambumblehead/esmock) | `2.6.0` | `2.7.5` |



Updates `@bahmutov/cypress-esbuild-preprocessor` from 2.2.0 to 2.2.8
- [Release notes](https://github.com/bahmutov/cypress-esbuild-preprocessor/releases)
- [Commits](bahmutov/cypress-esbuild-preprocessor@v2.2.0...v2.2.8)

Updates `@percy/cli` from 1.24.0 to 1.31.13
- [Release notes](https://github.com/percy/cli/releases)
- [Commits](https://github.com/percy/cli/commits/v1.31.13/packages/cli)

Updates `@percy/cypress` from 3.1.2 to 3.1.8
- [Release notes](https://github.com/percy/percy-cypress/releases)
- [Commits](percy/percy-cypress@v3.1.2...v3.1.8)

Updates `@storybook/test-runner` from 0.22.1 to 0.24.4
- [Release notes](https://github.com/storybookjs/test-runner/releases)
- [Changelog](https://github.com/storybookjs/test-runner/blob/v0.24.4/CHANGELOG.md)
- [Commits](storybookjs/test-runner@v0.22.1...v0.24.4)

Updates `allure-commandline` from 2.40.0 to 2.41.0
- [Release notes](https://github.com/allure-framework/allure-npm/releases)
- [Commits](allure-framework/allure-npm@2.40.0...2.41.0)

Updates `browserstack-cypress-cli` from 1.36.5 to 1.36.7
- [Release notes](https://github.com/browserstack/browserstack-cypress-cli/releases)
- [Commits](browserstack/browserstack-cypress-cli@v1.36.5...v1.36.7)

Updates `cypress-tags` from 1.1.2 to 1.2.2
- [Changelog](https://github.com/infosum/cypress-tags/blob/master/CHANGELOG.md)
- [Commits](https://github.com/infosum/cypress-tags/commits)

Updates `esbuild` from 0.17.10 to 0.28.0
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2023.md)
- [Commits](evanw/esbuild@v0.17.10...v0.28.0)

Updates `@web/dev-server-esbuild` from 1.0.1 to 1.0.5
- [Release notes](https://github.com/modernweb-dev/web/releases)
- [Changelog](https://github.com/modernweb-dev/web/blob/master/packages/dev-server-esbuild/CHANGELOG.md)
- [Commits](https://github.com/modernweb-dev/web/commits/@web/dev-server-polyfill@1.0.5/packages/dev-server-esbuild)

Updates `@web/test-runner` from 0.18.0 to 0.20.2
- [Release notes](https://github.com/modernweb-dev/web/releases)
- [Changelog](https://github.com/modernweb-dev/web/blob/master/packages/test-runner/CHANGELOG.md)
- [Commits](https://github.com/modernweb-dev/web/commits/@web/test-runner@0.20.2/packages/test-runner)

Updates `@web/test-runner-browserstack` from 0.7.0 to 0.8.0
- [Release notes](https://github.com/modernweb-dev/web/releases)
- [Changelog](https://github.com/modernweb-dev/web/blob/master/packages/test-runner-browserstack/CHANGELOG.md)
- [Commits](https://github.com/modernweb-dev/web/commits/@web/test-runner-browserstack@0.8.0/packages/test-runner-browserstack)

Updates `@web/test-runner-playwright` from 0.11.0 to 0.11.1
- [Release notes](https://github.com/modernweb-dev/web/releases)
- [Changelog](https://github.com/modernweb-dev/web/blob/master/packages/test-runner-playwright/CHANGELOG.md)
- [Commits](https://github.com/modernweb-dev/web/commits/@web/test-runner-playwright@0.11.1/packages/test-runner-playwright)

Updates `esmock` from 2.6.0 to 2.7.5
- [Release notes](https://github.com/iambumblehead/esmock/releases)
- [Changelog](https://github.com/iambumblehead/esmock/blob/main/CHANGELOG.md)
- [Commits](iambumblehead/esmock@v2.6.0...v2.7.5)

---
updated-dependencies:
- dependency-name: "@bahmutov/cypress-esbuild-preprocessor"
  dependency-version: 2.2.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@percy/cli"
  dependency-version: 1.31.13
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: "@percy/cypress"
  dependency-version: 3.1.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@storybook/test-runner"
  dependency-version: 0.24.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: allure-commandline
  dependency-version: 2.41.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: browserstack-cypress-cli
  dependency-version: 1.36.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: cypress-tags
  dependency-version: 1.2.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: esbuild
  dependency-version: 0.28.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: "@web/dev-server-esbuild"
  dependency-version: 1.0.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@web/test-runner"
  dependency-version: 0.20.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: "@web/test-runner-browserstack"
  dependency-version: 0.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: "@web/test-runner-playwright"
  dependency-version: 0.11.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: esmock
  dependency-version: 2.7.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Jun 16, 2026
@socket-security

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm cheerio is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/cheerio@1.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/cheerio@1.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm edgedriver is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/edgedriver@6.3.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/edgedriver@6.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm htmlparser2 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/htmlparser2@10.1.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/htmlparser2@10.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm puppeteer-core is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/puppeteer-core@24.43.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/puppeteer-core@24.43.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webdriverio is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/webdriverio@9.28.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webdriverio@9.28.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants