Skip to content

chore: update non-major dependencies - #4369

Merged
takecchi merged 2 commits into
mainfrom
renovate/non-major-dependencies
Oct 10, 2026
Merged

takecchi merged 2 commits into
mainfrom
renovate/non-major-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@modelcontextprotocol/sdk (source) 1.31.0 → 1.32.1 age confidence
@openai/codex (source) 0.160.0 → 0.160.1 age confidence
@scalar/hono-api-reference (source) 0.12.8 → 0.12.10 age confidence
@types/node (source) 22.20.4 → 22.20.5 age confidence
eslint (source) 10.11.0 → 10.12.0 age confidence
jsdom 30.1.1 → 30.1.2 age confidence
lucide-react (source) 1.49.0 → 1.52.0 age confidence
marked (source) 18.0.14 → 18.1.0 age confidence
mdast-util-from-markdown 2.0.3 → 2.1.0 age confidence
pg (source) 8.23.0 → 8.23.1 age confidence
radix-ui (source) 1.6.7 → 1.7.0 age confidence
shadcn (source) 4.21.0 → 4.21.3 age confidence
typescript-eslint (source) 8.71.0 → 8.71.1 age confidence
virtua ^0.52.0 → ^0.53.0 age confidence
vite (source) 8.3.1 → 8.3.3 age confidence
vitest (source) 5.0.2 → 5.0.3 age confidence

Release Notes

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk)

v1.32.1

Compare Source

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.32.0...1.32.1

v1.32.0

Compare Source

Upgrade notes

  • Redirects: the HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on StreamableHTTPClientTransport or SSEClientTransport. In browsers, a redirected request fails unless that option is set.
  • New options, both off unless you set them: maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth accepts only tokens issued for this server (the token's audience).

What's Changed

  • [v1.x] fix(client): follow redirects only within the endpoint's origin by @​claude[bot] in #​2902
  • docs: point SECURITY.md at GitHub Security Advisories (v1.x) by @​claude[bot] in #​2910
  • [v1.x] examples: close idle sessions and cap the session map by @​maxisbey in #​2914
  • [v1.x] fix(tasks): keep tasks of the in-memory task store within the session that created them by @​claude[bot] in #​2925
  • [v1.x] feat(server): add maxToolInputElements option to limit the number of elements in tool-call arguments by @​claude[bot] in #​2927
  • [v1.x] fix(server): accept tools/call and prompts/get requests that omit arguments by @​raashish1601 in #​2045
  • [v1.x] feat(auth): add expectedResource to requireBearerAuth by @​claude[bot] in #​2930
  • [v1.x] test(e2e): cover tools/call and prompts/get without arguments by @​claude[bot] in #​2931
  • chore: bump version to 1.32.0 by @​claude[bot] in #​2935

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.31.0...1.32.0

scalar/scalar (@​scalar/hono-api-reference)

v0.12.10

v0.12.9

eslint/eslint (eslint)

v10.12.0

Compare Source

Features

  • 4618052 feat: handle astral letters in new-cap (#​21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#​21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#​21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#​21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#​21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#​21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#​21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#​21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#​21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#​21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#​21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#​21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#​21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#​21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#​21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#​21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#​21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#​21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#​21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#​21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#​21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#​21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#​21342) (ESLint Bot)
jsdom/jsdom (jsdom)

v30.1.2

Compare Source

  • Updated URLs to support Unicode v18.0.0 in internationalized domain names.
  • Reduced package size and memory use for CSS property definitions. (@​scttcper)
  • Fixed severe slowdowns when building large DOM trees, including SVG charts with D3, which regressed in v30.1.0. (@​cmdcolin)
  • Fixed exponentially slow reads of empty inherited CSS custom properties in deeply nested documents, and custom properties incorrectly inheriting past an initial reset. (@​scttcper)
  • Fixed getComputedStyle() returning stale results after editing stylesheet declarations, selectors, or media queries, including in imported stylesheets.
  • Fixed selector matching and computed styles after changes to form control checkedness, indeterminacy, selection, values, and validity, including during form resets and canceled clicks.
  • Fixed computed styles for :focus, :focus-visible, :focus-within, and selectors containing them after focus changes, including inside focus and blur listeners. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing elements hidden by 'display', including through shadow hosts and slots, and elements excluded by shadow DOM slot assignment. (@​asamuzaK)
  • Fixed getComputedStyle() throwing for elements without inline-style support, including XML and MathML elements.
  • Fixed a memory leak where stylesheet parsing retained the last parsed stylesheet's window after window.close().
  • Fixed memory growth from long-lived MutationObserver instances retaining bookkeeping for garbage-collected nodes. (@​scttcper)
  • Fixed retained select.selectedOptions collections becoming stale after selection changes and form resets.
  • Fixed rejection of negative CSS sizing values, including for 'min-width', 'min-height', 'max-width', and 'max-height', which regressed in v30.1.0.
  • Fixed handling of deeply nested color-mix() expressions, including exceptions during color resolution. (@​asamuzaK)
lucide-icons/lucide (lucide-react)

v1.52.0: Version 1.52.0

Compare Source

What's Changed

Full Changelog: lucide-icons/lucide@1.51.0...1.52.0

v1.51.0: Version 1.51.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.50.0...1.51.0

v1.50.0: Version 1.50.0

Compare Source

What's Changed
New Contributors

Full Changelog: lucide-icons/lucide@1.49.0...1.50.0

markedjs/marked (marked)

v18.1.0

Compare Source

Bug Fixes
Features
  • add linkParenPossible to lexer state to fail fast for link token generation (#​4070) (4ee44f7)
syntax-tree/mdast-util-from-markdown (mdast-util-from-markdown)

v2.1.0

Compare Source

Features
  • 2ff38d8 Add support for afterExit, beforeEnter listeners
Performance

Full Changelog: syntax-tree/mdast-util-from-markdown@2.0.3...2.1.0

brianc/node-postgres (pg)

v8.23.1

Compare Source

radix-ui/primitives (radix-ui)

v1.7.0

Dialog
  • Fixed nested, portalled layers being unusable inside a modal layer. A non-modal popover rendered inside a modal Dialog previously broke some user interactions because the modal layer's trapped FocusScope reclaimed focus, and its RemoveScroll only allowed scrolling within the modal content.
Navigation Menu
  • Added a disableToggle prop to NavigationMenu.Sub.
    • true: Clicking the trigger of an already-open submenu item keeps it open. This is the default and matches existing behavior.
    • false: Clicking the trigger of a submenu item toggles it open or closed.
  • Added an activationMode prop to NavigationMenu.Root and NavigationMenu.Sub.
    • "automatic": Hovering or focusing a trigger opens its item, and moving away from the trigger closes it after a short delay. This is the default and matches existing behavior.
    • "manual": Pointer entry and focus never open an item. The item opens when its trigger is clicked.
    • When activationMode is omitted on NavigationMenu.Sub, it inherits the value from the parent NavigationMenu.Root, so setting "manual" on the root also applies to submenus unless a submenu opts back in to "automatic".
  • Fixed a bug where a submenu's defaultValue was reset when an external element was focused before the menu opened.
  • Fixed a bug where NavigationMenu.Viewport discarded its children and rendered the active content in their place. The active content is now rendered inside the consumer's element alongside any children it already had.
Popover
  • Added Popover.Title and Popover.Description parts that provide accessible names and descriptions for popover content.
Scroll Area
  • Added a ScrollArea.Content part so consumers can own the wrapper element implicitly rendered by ScrollArea.Viewport. Pass disableImplicitContentElement to the viewport and render ScrollArea.Content as its child.

    <ScrollArea.Root>
      <ScrollArea.Viewport disableImplicitContentElement>
        <ScrollArea.Content>{children}</ScrollArea.Content>
      </ScrollArea.Viewport>
      <ScrollArea.Scrollbar>
        <ScrollArea.Thumb />
      </ScrollArea.Scrollbar>
    </ScrollArea.Root>

    In the next major release, the viewport will no longer render this element implicitly. We recommend migrating to this API now for a smoother upgrade.

  • Fixed a bug where asChild on ScrollArea.Viewport merged props onto the implicit content element instead of the consumer's element.

Slider
  • Added a preserveThumbOrder prop to Slider that prevents thumbs from crossing over one another. When enabled, each thumb is constrained to the values of its neighbors instead of swapping positions when dragged past them.
Other updates
  • Added support for multiple aria-describedby attributes, so id strings from a component and its child are merged, normalized, and deduplicated instead of one replacing the other.
  • Fixed a bug where internal event handlers were still called on disabled Select.Item elements.
  • Fixed a bug where a paused Toast would not auto-close after its duration changed while the timer was paused.
  • Fixed a bug where a focused element inside Tabs.Content did not fire a blur event before the tab switched. Tabs.Trigger now moves focus before the tab's state change.
  • Fixed compatibility issues with React Server Components.
shadcn-ui/ui (shadcn)

v4.21.3

Compare Source

Patch Changes

v4.21.2

Compare Source

Patch Changes

v4.21.1

Compare Source

Patch Changes
typescript-eslint/typescript-eslint (typescript-eslint)

v8.71.1

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

inokawa/virtua (virtua)

v0.53.3

Compare Source

What's Changed

Full Changelog: inokawa/virtua@0.53.2...0.53.3

v0.53.2

Compare Source

What's Changed

Full Changelog: inokawa/virtua@0.53.1...0.53.2

v0.53.1

Compare Source

What's Changed

Full Changelog: inokawa/virtua@0.53.0...0.53.1

v0.53.0

Compare Source

masonry.mov

What's Changed

Full Changelog: inokawa/virtua@0.52.10...0.53.0

vitejs/vite (vite)

v8.3.3

Compare Source

Bug Fixes

v8.3.2

Compare Source

Bug Fixes
Performance Improvements
Documentation
  • fix dead og-image PNG links in vite6/vite7 changelog entries (#​23594) (1929b4c)
Miscellaneous Chores
Code Refactoring
Tests
  • bundled-dev: accept a rolldown dev runtime with no helper imports (#​23606) (634745d)
vitest-dev/vitest (vitest)

v5.0.3

Compare Source

   🐞 Bug Fixes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • "before 6am on saturday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

renovate Bot and others added 2 commits October 9, 2026 16:26
Renovate が catalog の @openai/codex だけを 0.160.1 へ上げ、scripts/codex-version-sync.test.ts と codex-protocol.test.ts が落ちていた。生成スキーマは 0.160.0 と中身が同一(置き場の版の名前だけが変わる)。
@renovate

renovate Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@takecchi
takecchi merged commit 938fbdd into main Oct 10, 2026
6 checks passed
@takecchi
takecchi deleted the renovate/non-major-dependencies branch October 10, 2026 01:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant