Repository navigation
Merging main into v3 for release - #274
Conversation
Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v6.27.0...v6.28.0) --- updated-dependencies: - dependency-name: undici dependency-version: 6.28.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nodejs/undici/releases">undici's releases</a>.</em></p> <blockquote> <h2>v6.28.0</h2> <h2>⚠️ Security fixes</h2> <ul> <li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5">GHSA-m8rv-5g2x-5cg5</a>: a malicious <code>type</code> property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated <code>content-type</code> header. Undici now coerces and validates the value before adding it to the request. Fixed by <a href="https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400">740a0b7c</a>.</li> <li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524">GHSA-8xcm-r25x-g524</a>: the retry interceptor could expose a stale <code>Content-Length</code> after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose <code>Content-Length</code> is inconsistent with <code>Content-Range</code>. Fixed by <a href="https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e">cba3a52a</a>, with corrected fixtures in <a href="https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420">4fd5a0c6</a>.</li> <li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm">GHSA-v3r7-h72x-cjcm</a>: unsanitized <code>domain</code> and <code>unparsed</code> values passed to <code>setCookie()</code> could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by <a href="https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235">af748404</a>.</li> </ul> <p><a href="https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272">GHSA-4cwx-7wf7-3272</a> and <a href="https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54">GHSA-jr45-8vmc-qm54</a> affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0">https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a"><code>01a912e</code></a> Bumped v6.28.0 (<a href="https://redirect.github.com/nodejs/undici/issues/5591">#5591</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e"><code>481ecfc</code></a> Use Node 22 and npm 11 to release</li> <li><a href="https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400"><code>740a0b7</code></a> fix: validate blob body content type</li> <li><a href="https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0"><code>2698e49</code></a> fix: validate coerced header values for CRLF (<a href="https://redirect.github.com/nodejs/undici/issues/5579">#5579</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420"><code>4fd5a0c</code></a> test(retry): correct broken content-range fixtures in retry-handler.js</li> <li><a href="https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e"><code>cba3a52</code></a> fix(retry): reject partial content length mismatch</li> <li><a href="https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235"><code>af74840</code></a> fix: harden cookie domain, path, and unparsed attribute validation</li> <li>See full diff in <a href="https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details>
Bumps [@octokit/types](https://github.com/octokit/types.ts) from 16.0.0 to 17.0.0. - [Release notes](https://github.com/octokit/types.ts/releases) - [Commits](octokit/types.ts@v16.0.0...v17.0.0) --- updated-dependencies: - dependency-name: "@octokit/types" dependency-version: 17.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@octokit/types](https://github.com/octokit/types.ts) from 16.0.0 to 17.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/octokit/types.ts/releases">@octokit/types's releases</a>.</em></p> <blockquote> <h2>v17.0.0</h2> <h1><a href="https://github.com/octokit/types.ts/compare/v16.0.0...v17.0.0">17.0.0</a> (2026-08-01)</h1> <h3>Features</h3> <ul> <li>drop projects-classic endpoints, add GitHub API endpoints: cache limits (retention & storage) for repos/orgs/enterprises, billing budgets & usage, artifacts deployment metadata, and projectsV2 drafts & fields (<a href="https://redirect.github.com/octokit/types.ts/issues/713">#713</a>) (<a href="https://github.com/octokit/types.ts/commit/0296144cacd4d01d5f051de05e519a764b26f447">0296144</a>)</li> </ul> <h3>BREAKING CHANGES</h3> <ul> <li>Removed <code>/orgs/{org}/projects</code></li> <li>Removed <code>/orgs/{org}/settings/billing/actions</code></li> <li>Removed <code>/orgs/{org}/settings/billing/packages</code></li> <li>Removed <code>/orgs/{org}/settings/billing/shared-storage</code></li> <li>Removed <code>/orgs/{org}/teams/{team_slug}/projects</code></li> <li>Removed <code>/orgs/{org}/teams/{team_slug}/projects/{project_id}</code></li> <li>Removed <code>/projects/columns/{column_id}</code></li> <li>Removed <code>/projects/columns/{column_id}/moves</code></li> <li>Removed <code>/projects/{project_id}</code></li> <li>Removed <code>/projects/{project_id}/collaborators</code></li> <li>Removed <code>/projects/{project_id}/collaborators/{username}</code></li> <li>Removed <code>/projects/{project_id}/collaborators/{username}/permission</code></li> <li>Removed <code>/repos/{owner}/{repo}/projects</code></li> <li>Removed <code>/teams/{team_id}/projects</code></li> <li>Removed <code>/teams/{team_id}/projects/{project_id}</code></li> <li>Removed <code>/user/projects</code></li> <li>Removed <code>/users/{username}/projects</code></li> <li>Removed <code>/users/{username}/settings/billing/actions</code></li> <li>Removed <code>/users/{username}/settings/billing/packages</code></li> <li>Removed <code>/users/{username}/settings/billing/shared-storage</code></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/octokit/types.ts/commit/0296144cacd4d01d5f051de05e519a764b26f447"><code>0296144</code></a> feat: drop projects-classic endpoints, add GitHub API endpoints: cache limits...</li> <li><a href="https://github.com/octokit/types.ts/commit/f672eb565d8f0ce35e5559a32a7d3cd0e850e0e3"><code>f672eb5</code></a> ci(action): update actions/create-github-app-token action to v3 (<a href="https://redirect.github.com/octokit/types.ts/issues/702">#702</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/5a8840f1ecb12b1e0ccaed9740ac94e39d6fc598"><code>5a8840f</code></a> chore(deps): update dependency npm-run-all2 to v9 (<a href="https://redirect.github.com/octokit/types.ts/issues/707">#707</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/13d28d782c1a6e34bd43ae3afbc7981d91fb7224"><code>13d28d7</code></a> ci(action): update actions/add-to-project action to v2 (<a href="https://redirect.github.com/octokit/types.ts/issues/705">#705</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/8303723ee4919b44ee06808e3f155f6ea0390215"><code>8303723</code></a> ci(action): update actions/checkout action to v7 (<a href="https://redirect.github.com/octokit/types.ts/issues/709">#709</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/de769019bbe5e835c34c47100aa72141c84d31fe"><code>de76901</code></a> ci(action): update actions/setup-node action to v7 (<a href="https://redirect.github.com/octokit/types.ts/issues/711">#711</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/b61f4adda1f88aa2eea6b7f94a1db772a219e49d"><code>b61f4ad</code></a> chore(deps): update dependency handlebars to v4.7.9 [security] (<a href="https://redirect.github.com/octokit/types.ts/issues/706">#706</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/52c1c756ef10e10bf5518f7a567075cf5efbd3bf"><code>52c1c75</code></a> ci(action): update actions/checkout action to v6 (<a href="https://redirect.github.com/octokit/types.ts/issues/697">#697</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/9eebb161e4f5c4cc878546a06b7da81a24728b52"><code>9eebb16</code></a> build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (<a href="https://redirect.github.com/octokit/types.ts/issues/695">#695</a>)</li> <li>See full diff in <a href="https://github.com/octokit/types.ts/compare/v16.0.0...v17.0.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for <code>@octokit/types</code> since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
Bumps the bundler-minor-and-patch group in /sites/site-with-errors with 1 update: [rack](https://github.com/rack/rack). Updates `rack` from 3.2.6 to 3.2.7 - [Release notes](https://github.com/rack/rack/releases) - [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md) - [Commits](rack/rack@v3.2.6...v3.2.7) --- updated-dependencies: - dependency-name: rack dependency-version: 3.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: bundler-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
… in the bundler-minor-and-patch group (#258) Bumps the bundler-minor-and-patch group in /sites/site-with-errors with 1 update: [rack](https://github.com/rack/rack). Updates `rack` from 3.2.6 to 3.2.7 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/rack/rack/blob/main/CHANGELOG.md">rack's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference <a href="https://keepachangelog.com/en/1.0.0/">Keep A Changelog</a>.</p> <h2>Unreleased</h2> <h3>SPEC Changes</h3> <ul> <li>Define <code>rack.response_finished</code> callback arguments more strictly. (<a href="https://redirect.github.com/rack/rack/pull/2365">#2365</a>, <a href="https://github.com/skipkayhil"><code>@skipkayhil</code></a>)</li> </ul> <h3>Added</h3> <ul> <li>Add <code>Rack::Files#assign_headers</code> to allow overriding how the configured file headers are set. (<a href="https://redirect.github.com/rack/rack/pull/2377">#2377</a>, <a href="https://github.com/codergeek121"><code>@codergeek121</code></a>)</li> <li>Add support for <code>rack.response_finished</code> to <code>Rack::TempfileReaper</code>. (<a href="https://redirect.github.com/rack/rack/pull/2363">#2363</a>, <a href="https://github.com/skipkayhil"><code>@skipkayhil</code></a>)</li> <li>Add support for streaming bodies when using <code>Rack::Events</code>. (<a href="https://redirect.github.com/rack/rack/blob/main/redirect.github.com/rack/rack/pull/2375">#2375</a>, <a href="https://github.com/unflxw"><code>@unflxw</code></a>)</li> <li>Add <code>deflaters</code> option to <code>Rack::Deflater</code> to enable custom compression algorithms like zstd. (<a href="https://redirect.github.com/rack/rack/issues/2168">#2168</a>, <a href="https://github.com/alexanderadam"><code>@alexanderadam</code></a>)</li> <li>Add <code>Rack::Request#prefetch?</code> for identifying requests with <code>Sec-Purpose: prefetch</code> header set. (<a href="https://redirect.github.com/rack/rack/pull/2405">#2405</a>, <a href="https://github.com/glaszig"><code>@glaszig</code></a>)</li> <li>Add <code>rack.request.config</code> environment key to configure Rack::Request behavior.</li> <li>Add <code>Rack::Request#headers</code> for simpler access to request headers by header name. (<a href="https://redirect.github.com/rack/rack/pull/1881">#1881</a>, <a href="https://github.com/jeremyevans"><code>@jeremyevans</code></a>)</li> <li>Allow disabling the <code>Rack::QueryParser</code> bytesize and params limits by passing <code>nil</code> for the <code>bytesize_limit</code>/<code>params_limit</code> keyword arguments, or a negative value for <code>RACK_QUERY_PARSER_BYTESIZE_LIMIT</code>/<code>RACK_QUERY_PARSER_PARAMS_LIMIT</code>. (<a href="https://redirect.github.com/rack/rack/pull/2492">#2492</a>, <a href="https://github.com/alpaca-tc"><code>@alpaca-tc</code></a>)</li> </ul> <h3>Changed</h3> <ul> <li>Require Ruby 2.7.3 or newer and replace <code>ruby2_keywords</code> with argument forwarding.</li> <li>Raise before exceeding a part limit, not after. (<a href="https://redirect.github.com/rack/rack/pull/2362">#2362</a>, <a href="https://github.com/matthew-puku"><code>@matthew-puku</code></a>)</li> <li>Rack::Deflater now uses a fixed GZip mtime value. (<a href="https://redirect.github.com/rack/rack/pull/2372">#2372</a>, <a href="https://github.com/bensheldon"><code>@bensheldon</code></a>)</li> <li>Multipart parser drops support for RFC 2231 <code>filename*</code> parameter (prohibited by RFC 7578) and now properly handles UTF-8 encoded filenames via percent-encoding and direct UTF-8 bytes. (<a href="https://redirect.github.com/rack/rack/pull/2398">#2398</a>, <a href="https://github.com/wtn"><code>@wtn</code></a>)</li> <li>The query parser now raises <code>Rack::QueryParser::IncompatibleEncodingError</code> if we try to parse params that are not ASCII compatible. (<a href="https://redirect.github.com/rack/rack/pull/2416">#2416</a>, <a href="https://github.com/bquorning"><code>@bquorning</code></a>)</li> <li>The mime type for <code>.pem</code> files has been changed from <code>application/x-x509-ca-cert</code> to <code>application/x-pem-file</code>. (<a href="https://redirect.github.com/rack/rack/pull/2435">#2435</a>, <a href="https://github.com/jeremyevans"><code>@jeremyevans</code></a>)</li> <li>Freeze <code>Rack::Auth::AbstractRequest::AUTHORIZATION_KEYS</code>, <code>Rack::Utils::STATUS_WITH_NO_ENTITY_BODY</code>, <code>Rack::Multipart::Parser::EMPTY</code>, <code>Rack::Utils.default_query_parser</code>, and internal constants in <code>Rack::Lint</code>. (<a href="https://redirect.github.com/rack/rack/pull/2428">#2428</a>, <a href="https://github.com/jhawthorn"><code>@jhawthorn</code></a>)</li> </ul> <h3>Fixed</h3> <ul> <li><code>Rack::Multipart::UploadedFile</code> now delegates keyword arguments to the wrapped tempfile. Calls such as <code>uploaded_file.readlines(chomp: true)</code> raised <code>TypeError</code> on Ruby 3.0+. (<a href="https://redirect.github.com/rack/rack/issues/2481">#2481</a>, <a href="https://redirect.github.com/rack/rack/pull/2499">#2499</a>, <a href="https://github.com/SeanLF"><code>@SeanLF</code></a>)</li> <li>Multipart parser: limit MIME header size check to the unread buffer region to avoid false <code>multipart mime part header too large</code> errors when previously read data accumulates in the scan buffer. (<a href="https://redirect.github.com/rack/rack/pull/2392">#2392</a>, <a href="https://github.com/alpaca-tc"><code>@alpaca-tc</code></a>, <a href="https://github.com/willnet"><code>@willnet</code></a>, <a href="https://github.com/krororo"><code>@krororo</code></a>)</li> <li>Multipart parser: add nil guards to prevent <code>NoMethodError</code> crashes when handling <code>Content-Disposition</code> without parameters and <code>Content-Type</code> parameters without '='. (<a href="https://github.com/haruki0409"><code>@haruki0409</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/rack/rack/commit/70d2e1046789a70e240e01b9ac0b3ffc9b26d33f"><code>70d2e10</code></a> Bump patch version.</li> <li><a href="https://github.com/rack/rack/commit/9b31adf2a8a1fa443cda4825f35b1fff76b2eedd"><code>9b31adf</code></a> Fix specs on Ruby 2.4</li> <li><a href="https://github.com/rack/rack/commit/7c0ababcbad4e4b3fe0cc45c3a8d8b4e2a8cfcef"><code>7c0abab</code></a> Do not ignore Ruby 2.4/2.5 errors in CI</li> <li><a href="https://github.com/rack/rack/commit/ef52d4e87ba4346ba381361712c8f714ae9dbe11"><code>ef52d4e</code></a> Fix <code>FORWARDED</code> typo.</li> <li><a href="https://github.com/rack/rack/commit/108405ea9fec02dc14c8317e25619d1001ffe4a9"><code>108405e</code></a> Restore Ruby 2.4/2.5 compatibility</li> <li><a href="https://github.com/rack/rack/commit/c3fe39348bc688f6c02096c04fa6fbc668300c1a"><code>c3fe393</code></a> Update changelog.</li> <li>See full diff in <a href="https://github.com/rack/rack/compare/v3.2.6...v3.2.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details>
- new issue template for allowlisting third-party issues from NPM - plugin documentation reorganized and rewritten to organize information about all plugins vs. NPM plugins only vs. local plugins only
- new issue template for allowlisting third-party issues from NPM - plugin documentation reorganized and rewritten to organize information about all plugins vs. NPM plugins only vs. local plugins only
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Updated demo video link for the a11y scanner.
Updated demo video link for the a11y scanner.
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.28. - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.15...8.5.28) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.28 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.28. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss/releases">postcss's releases</a>.</em></p> <blockquote> <h2>8.5.28</h2> <ul> <li>Fixes types regression.</li> </ul> <h2>8.5.27</h2> <ul> <li>Fixed removing any comments starting with <code>/*#</code> (by <a href="https://github.com/dylanpulver"><code>@dylanpulver</code></a>).</li> <li>Fixed <code>*</code> hack before a comment in Custom Properties (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> <li>Fixed empty values in the middle of <code>list.comma()</code> (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> <li>Fixed whitespace-only values in <code>list.space()</code> (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> <li>Fixed rule’s end position on space before semicolon (by <a href="https://github.com/maximilliangrand"><code>@maximilliangrand</code></a>).</li> <li>Fixed types (by <a href="https://github.com/romainmenke"><code>@romainmenke</code></a>).</li> <li>Fixed Chinese text in deprecation warning (by <a href="https://github.com/Jesse205"><code>@Jesse205</code></a>).</li> </ul> <h2>8.5.26</h2> <ul> <li>Fixed <code>list.split()</code> regression (by <a href="https://github.com/lazerg"><code>@lazerg</code></a>).</li> <li>Track symlinks in path protection in source map loading (by <a href="https://github.com/drengir1"><code>@drengir1</code></a>).</li> </ul> <h2>8.5.25</h2> <ul> <li>Fixed 8.5.17 visitor regression.</li> <li>Fixed <code>list.split()</code> for non-string values (by <a href="https://github.com/amir-rezaei"><code>@amir-rezaei</code></a>).</li> </ul> <h2>8.5.24</h2> <ul> <li>Preserve the BOM after the processing (by <a href="https://github.com/hdimer"><code>@hdimer</code></a>).</li> </ul> <h2>8.5.23</h2> <ul> <li>Do not load source map without <code>opts.from</code> for security reasons.</li> </ul> <h2>8.5.22</h2> <ul> <li>Fixed custom property losing semicolon before a comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> </ul> <h2>8.5.21</h2> <ul> <li>Fixed childless at-rule losing semicolon before comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed docs (by <a href="https://github.com/isker"><code>@isker</code></a>).</li> </ul> <h2>8.5.20</h2> <ul> <li>Fixed missing space if <code>AtRule#params</code> is set after (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed mixing AST error on warnings (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> </ul> <h2>8.5.19</h2> <ul> <li>Fixed cleaning <code>before</code> for new nodes inserted to <code>Root</code> (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> </ul> <h2>8.5.18</h2> <ul> <li>Restricted loading previous source maps file to the <code>opts.from</code> folder for security reasons (use <code>unsafeMap: true</code> to disable the check).</li> </ul> <h2>8.5.17</h2> <ul> <li>Fixed <code>Maximum call stack size exceeded</code> error.</li> <li>Fixed Prototype hijacking for <code>postcss.fromJSON()</code>.</li> <li>Fixed <code>Input#origin()</code> for unmapped end position (by <a href="https://github.com/chatman-media"><code>@chatman-media</code></a>).</li> </ul> <h2>8.5.16</h2> <ul> <li>Fixed <code>Input#origin()</code> position (by <a href="https://github.com/mizdra"><code>@mizdra</code></a>).</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's changelog</a>.</em></p> <blockquote> <h2>8.5.28</h2> <ul> <li>Fixes types regression.</li> </ul> <h2>8.5.27</h2> <ul> <li>Fixed removing any comments starting with <code>/*#</code> (by <a href="https://github.com/dylanpulver"><code>@dylanpulver</code></a>).</li> <li>Fixed <code>*</code> hack before a comment in Custom Properties (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> <li>Fixed empty values in the middle of <code>list.comma()</code> (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> <li>Fixed whitespace-only values in <code>list.space()</code> (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> <li>Fixed rule’s end position on space before semicolon (by <a href="https://github.com/maximilliangrand"><code>@maximilliangrand</code></a>).</li> <li>Fixed types (by <a href="https://github.com/romainmenke"><code>@romainmenke</code></a>).</li> <li>Fixed Chinese text in deprecation warning (by <a href="https://github.com/Jesse205"><code>@Jesse205</code></a>).</li> </ul> <h2>8.5.26</h2> <ul> <li>Fixed <code>list.split()</code> regression (by <a href="https://github.com/lazerg"><code>@lazerg</code></a>).</li> <li>Track symlinks in path protection in source map loading (by <a href="https://github.com/drengir1"><code>@drengir1</code></a>).</li> </ul> <h2>8.5.25</h2> <ul> <li>Fixed 8.5.17 visitor regression.</li> <li>Fixed <code>list.split()</code> for non-string values (by <a href="https://github.com/amir-rezaei"><code>@amir-rezaei</code></a>).</li> </ul> <h2>8.5.24</h2> <ul> <li>Preserve the BOM after the processing (by <a href="https://github.com/hdimer"><code>@hdimer</code></a>).</li> </ul> <h2>8.5.23</h2> <ul> <li>Do not load source map without <code>opts.from</code> for security reasons.</li> </ul> <h2>8.5.22</h2> <ul> <li>Fixed custom property losing semicolon before a comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> </ul> <h2>8.5.21</h2> <ul> <li>Fixed childless at-rule losing semicolon before comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed docs (by <a href="https://github.com/isker"><code>@isker</code></a>).</li> </ul> <h2>8.5.20</h2> <ul> <li>Fixed missing space if <code>AtRule#params</code> is set after (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed mixing AST error on warnings (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> </ul> <h2>8.5.19</h2> <ul> <li>Fixed cleaning <code>before</code> for new nodes inserted to <code>Root</code> (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a"><code>e544bff</code></a> Release 8.5.28 version</li> <li><a href="https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a"><code>f8fc252</code></a> Typo</li> <li><a href="https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce"><code>5039fd7</code></a> Add missed release notes</li> <li><a href="https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af"><code>ae40ca4</code></a> Release 8.5.27 version</li> <li><a href="https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba"><code>62b1626</code></a> Fix linter</li> <li><a href="https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4"><code>1dba938</code></a> Update dependencies</li> <li><a href="https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881"><code>3e82edc</code></a> Keep non-annotation comments when the processor has no plugins (<a href="https://redirect.github.com/postcss/postcss/issues/2150">#2150</a>)</li> <li><a href="https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e"><code>6d23bc3</code></a> Fix link</li> <li><a href="https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a"><code>508e997</code></a> Add GitHub Sponsors link</li> <li><a href="https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b"><code>e993739</code></a> Add CodeRabbit sponsor (<a href="https://redirect.github.com/postcss/postcss/issues/2145">#2145</a>)</li> <li>Additional commits viewable in <a href="https://github.com/postcss/postcss/compare/8.5.15...8.5.28">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for postcss since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details>
Bumps [undici](https://github.com/nodejs/undici) from 6.28.0 to 6.28.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nodejs/undici/releases">undici's releases</a>.</em></p> <blockquote> <h2>v6.28.1</h2> <h2>⚠️ Security fixes</h2> <h3>High severity</h3> <ul> <li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5">GHSA-rfgv-xxqx-mfg5</a>: a WebSocket server could select a subprotocol when none was requested, causing an uncaught <code>TypeError</code> that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by <a href="https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5">2af0faf8</a>.</li> </ul> <h3>Medium severity</h3> <ul> <li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v">GHSA-3wwx-pv8p-q78v</a>: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by <a href="https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c">07c60d9c</a>.</li> </ul> <h3>Low severity</h3> <ul> <li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r">GHSA-r53p-7pc4-xj5r</a>: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates <code>Content-Range</code> against the original response framing before resuming. Fixed by <a href="https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548">ce31bc82</a>.</li> </ul> <h2>What's Changed</h2> <ul> <li>perf: reduce EventSourceStream parser allocations (<a href="https://redirect.github.com/nodejs/undici/issues/5032">#5032</a>) by <a href="https://github.com/mcollina"><code>@mcollina</code></a> in <a href="https://redirect.github.com/nodejs/undici/pull/5647">nodejs/undici#5647</a></li> <li>[v6.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (<a href="https://redirect.github.com/nodejs/undici/issues/5707">#5707</a>) by <a href="https://github.com/mcollina"><code>@mcollina</code></a> in <a href="https://redirect.github.com/nodejs/undici/pull/5770">nodejs/undici#5770</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1">https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodejs/undici/commit/ffc8aa0fdd4c54024f384e57784d5047c8b4085a"><code>ffc8aa0</code></a> Bumped v6.28.1 (<a href="https://redirect.github.com/nodejs/undici/issues/5773">#5773</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/3866a3bc4ebaea2c6400db9193c2366072080dc4"><code>3866a3b</code></a> perf(h1): drop idle-socket timer floor with a ref'd setImmediate (<a href="https://redirect.github.com/nodejs/undici/issues/5707">#5707</a>) (<a href="https://redirect.github.com/nodejs/undici/issues/5770">#5770</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548"><code>ce31bc8</code></a> fix(retry): validate resumed response framing</li> <li><a href="https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5"><code>2af0faf</code></a> fix(websocket): reject unrequested subprotocols</li> <li><a href="https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c"><code>07c60d9</code></a> fix(websocket): destroy inflater after decompression limit</li> <li><a href="https://github.com/nodejs/undici/commit/bd90fff2a6e1350ba87e9b70811c5337502d2e39"><code>bd90fff</code></a> perf: reduce EventSourceStream parser allocations (<a href="https://redirect.github.com/nodejs/undici/issues/5032">#5032</a>) (<a href="https://redirect.github.com/nodejs/undici/issues/5647">#5647</a>)</li> <li>See full diff in <a href="https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@octokit/types](https://github.com/octokit/types.ts) from 17.0.0 to 18.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/octokit/types.ts/releases">@octokit/types's releases</a>.</em></p> <blockquote> <h2>v18.0.0</h2> <h1><a href="https://github.com/octokit/types.ts/compare/v17.0.0...v18.0.0">18.0.0</a> (2026-08-29)</h1> <h3>Features</h3> <ul> <li>update endpoints with major additions as of 2026-08-24 (<a href="https://redirect.github.com/octokit/types.ts/issues/723">#723</a>) (<a href="https://github.com/octokit/types.ts/commit/c4b93f2fed6515aa00e8dccf290d4ade41c3b4af">c4b93f2</a>)</li> </ul> <h3>BREAKING CHANGES</h3> <ul> <li>remove deprecated endpoints</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/octokit/types.ts/commit/c4b93f2fed6515aa00e8dccf290d4ade41c3b4af"><code>c4b93f2</code></a> feat: update endpoints with major additions as of 2026-08-24 (<a href="https://redirect.github.com/octokit/types.ts/issues/723">#723</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/4d46114afb91cea4590b7b40ea451fb937de08b1"><code>4d46114</code></a> chore(deps): Temporarily disable docs generation/publish in release workflow...</li> <li><a href="https://github.com/octokit/types.ts/commit/dd020c12a0752953ec91eadc498ea0727298bc53"><code>dd020c1</code></a> build(deps-dev): remove semantic-release, bump prettier (<a href="https://redirect.github.com/octokit/types.ts/issues/719">#719</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/8b92916979a122a248bb9807bffdeff4c8e33ea7"><code>8b92916</code></a> build(deps-dev): bump markdown-it from 14.1.0 to 14.3.0 (<a href="https://redirect.github.com/octokit/types.ts/issues/717">#717</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/f88ca90fc7f50d349b20b20bd65afc270c5ffc25"><code>f88ca90</code></a> build(deps-dev): bump lodash-es from 4.17.23 to 4.18.1 (<a href="https://redirect.github.com/octokit/types.ts/issues/718">#718</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/66f2dd6b844976c03dd868950d5d6340fecf931f"><code>66f2dd6</code></a> build(deps-dev): bump brace-expansion from 2.0.1 to 2.0.2 (<a href="https://redirect.github.com/octokit/types.ts/issues/715">#715</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/ce4890d5caa266668e1e4ee089e9cbe3e2f0d029"><code>ce4890d</code></a> build(deps-dev): bump linkify-it from 5.0.0 to 5.0.2 (<a href="https://redirect.github.com/octokit/types.ts/issues/716">#716</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/afd965b8f6bf5bdae67fc90a4f4376b5869f7a27"><code>afd965b</code></a> build(deps-dev): bump npm from 11.6.2 to 11.19.0 (<a href="https://redirect.github.com/octokit/types.ts/issues/714">#714</a>)</li> <li><a href="https://github.com/octokit/types.ts/commit/e9121d4f1b71c55cf78e74a1bd7289b6a73df41d"><code>e9121d4</code></a> build(deps-dev): bump lodash-es from 4.17.21 to 4.17.23 (<a href="https://redirect.github.com/octokit/types.ts/issues/700">#700</a>)</li> <li>See full diff in <a href="https://github.com/octokit/types.ts/compare/v17.0.0...v18.0.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.6 to 5.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitest-dev/vitest/releases">vitest's releases</a>.</em></p> <blockquote> <h2>v5.0.0</h2> <p>Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our <a href="https://vitest.dev/blog/vitest-5.html">blog post</a> for the official announcement.</p> <h3> 🚨 Breaking Changes</h3> <ul> <li>Replace <code>loupe.inspect</code> with pretty-format - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>Claude Opus 5 (1M context)</strong> and <strong>OpenAI Codex</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/9609">vitest-dev/vitest#9609</a> <a href="https://github.com/vitest-dev/vitest/commit/3f802da4b"><!-- raw HTML omitted -->(3f802)<!-- raw HTML omitted --></a></li> <li>Remove quotes from string values in <code>test.for/each</code> title <code>$</code> variable (take 2) - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10170">vitest-dev/vitest#10170</a> <a href="https://github.com/vitest-dev/vitest/commit/04d37e9d7"><!-- raw HTML omitted -->(04d37)<!-- raw HTML omitted --></a></li> <li>Default <code>attachmentsDir</code> from <code>.vitest-attachements/</code> to <code>.vitest/attachments/</code> - by <a href="https://github.com/MdSadiqMd"><code>@MdSadiqMd</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10186">vitest-dev/vitest#10186</a> <a href="https://github.com/vitest-dev/vitest/commit/1ba7338c3"><!-- raw HTML omitted -->(1ba73)<!-- raw HTML omitted --></a></li> <li>Remove <code>sequential</code> test/suite options in favor of <code>concurrent</code> - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a> and <strong>OpenAI Codex</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10198">vitest-dev/vitest#10198</a> <a href="https://github.com/vitest-dev/vitest/commit/9229f2edc"><!-- raw HTML omitted -->(9229f)<!-- raw HTML omitted --></a></li> <li>Represent locator as an object instead of a string - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10212">vitest-dev/vitest#10212</a> <a href="https://github.com/vitest-dev/vitest/commit/80f07edf6"><!-- raw HTML omitted -->(80f07)<!-- raw HTML omitted --></a></li> <li>Inline <code>expect</code> package - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10221">vitest-dev/vitest#10221</a> <a href="https://github.com/vitest-dev/vitest/commit/ad16223e7"><!-- raw HTML omitted -->(ad162)<!-- raw HTML omitted --></a></li> <li>Remove deprecated entry points - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10222">vitest-dev/vitest#10222</a> <a href="https://github.com/vitest-dev/vitest/commit/994c6ddb9"><!-- raw HTML omitted -->(994c6)<!-- raw HTML omitted --></a></li> <li>Require Node.js 22 and Vite 6.4 - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10178">vitest-dev/vitest#10178</a> <a href="https://github.com/vitest-dev/vitest/commit/3876283e8"><!-- raw HTML omitted -->(38762)<!-- raw HTML omitted --></a></li> <li>Fail <code>expect.poll</code> when function didn't resolve in time - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a> and <strong>OpenAI Codex</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10233">vitest-dev/vitest#10233</a> <a href="https://github.com/vitest-dev/vitest/commit/4df048c11"><!-- raw HTML omitted -->(4df04)<!-- raw HTML omitted --></a></li> <li>Throw an error if hoistable methods are outside the top level scope - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10460">vitest-dev/vitest#10460</a> <a href="https://github.com/vitest-dev/vitest/commit/d0b4fddcb"><!-- raw HTML omitted -->(d0b4f)<!-- raw HTML omitted --></a></li> <li><code>toHaveTextContent</code> is strict, add <code>toMatchTextContent</code> as alternative - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10473">vitest-dev/vitest#10473</a> <a href="https://github.com/vitest-dev/vitest/commit/18f303079"><!-- raw HTML omitted -->(18f30)<!-- raw HTML omitted --></a></li> <li>Don't lookup config file from ancestor directories - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>OpenAI Codex</strong> and <strong>Hiroshi Ogawa</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10428">vitest-dev/vitest#10428</a> <a href="https://github.com/vitest-dev/vitest/commit/945d9090e"><!-- raw HTML omitted -->(945d9)<!-- raw HTML omitted --></a></li> <li>Inline <code>@vitest/runner</code> package, do not publish it anymore - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10511">vitest-dev/vitest#10511</a> <a href="https://github.com/vitest-dev/vitest/commit/6d6e46b1e"><!-- raw HTML omitted -->(6d6e4)<!-- raw HTML omitted --></a></li> <li>Allow mutating happy-dom/jsdom window object - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>Hiroshi Ogawa</strong> and <strong>OpenAI Codex</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10373">vitest-dev/vitest#10373</a> <a href="https://github.com/vitest-dev/vitest/commit/206e8cff8"><!-- raw HTML omitted -->(206e8)<!-- raw HTML omitted --></a></li> <li>Expose <code>concurrencyId</code>/<code>workerId</code> on TestModule's diagnostics, make id 1-based - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10516">vitest-dev/vitest#10516</a> <a href="https://github.com/vitest-dev/vitest/commit/bdd985433"><!-- raw HTML omitted -->(bdd98)<!-- raw HTML omitted --></a></li> <li>Add <code>screenshotDirectory</code> config to <code>browser.expect.toMatchScreenshot</code> - by <a href="https://github.com/macarie"><code>@macarie</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10592">vitest-dev/vitest#10592</a> <a href="https://github.com/vitest-dev/vitest/commit/a60ded0fb"><!-- raw HTML omitted -->(a60de)<!-- raw HTML omitted --></a></li> <li>Update <code>@sinonjs/fake-timers</code> and support mocking <code>Temporal</code> - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>Hiroshi Ogawa</strong> and <strong>OpenCode (gpt-5.6-sol)</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10654">vitest-dev/vitest#10654</a> <a href="https://github.com/vitest-dev/vitest/commit/f8b1532fe"><!-- raw HTML omitted -->(f8b15)<!-- raw HTML omitted --></a></li> <li>Remove webdriverio package - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10675">vitest-dev/vitest#10675</a> <a href="https://github.com/vitest-dev/vitest/commit/5fed68f72"><!-- raw HTML omitted -->(5fed6)<!-- raw HTML omitted --></a></li> <li>Clear mocks by default before each test - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10613">vitest-dev/vitest#10613</a> <a href="https://github.com/vitest-dev/vitest/commit/0f6463bf2"><!-- raw HTML omitted -->(0f646)<!-- raw HTML omitted --></a></li> <li>Don't emit localStorage warnings on Node 26, fail gracefully when worker fails to start - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10293">vitest-dev/vitest#10293</a> <a href="https://github.com/vitest-dev/vitest/commit/334edef92"><!-- raw HTML omitted -->(334ed)<!-- raw HTML omitted --></a></li> <li>Separate config resolution from the server creation - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10554">vitest-dev/vitest#10554</a> <a href="https://github.com/vitest-dev/vitest/commit/1c0ec3444"><!-- raw HTML omitted -->(1c0ec)<!-- raw HTML omitted --></a></li> <li>Inline projects extend the root config by default - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10750">vitest-dev/vitest#10750</a> <a href="https://github.com/vitest-dev/vitest/commit/fec001ad3"><!-- raw HTML omitted -->(fec00)<!-- raw HTML omitted --></a></li> <li>Enable mocking Temporal without fake timers - by <a href="https://github.com/fabon-f"><code>@fabon-f</code></a>, <strong>Hiroshi Ogawa</strong> and <strong>OpenCode (gpt-5.6-sol)</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10757">vitest-dev/vitest#10757</a> <a href="https://github.com/vitest-dev/vitest/commit/ac2d46b42"><!-- raw HTML omitted -->(ac2d4)<!-- raw HTML omitted --></a></li> <li>Support nested projects - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10846">vitest-dev/vitest#10846</a> <a href="https://github.com/vitest-dev/vitest/commit/ec367cf2a"><!-- raw HTML omitted -->(ec367)<!-- raw HTML omitted --></a></li> <li>Use <code>></code> as separator in <code>-t</code>, calculate <code>only</code> once - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10686">vitest-dev/vitest#10686</a> <a href="https://github.com/vitest-dev/vitest/commit/a0b20bc86"><!-- raw HTML omitted -->(a0b20)<!-- raw HTML omitted --></a></li> <li>Fail the test when an asynchronous assertion is not awaited - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10868">vitest-dev/vitest#10868</a> <a href="https://github.com/vitest-dev/vitest/commit/86d4a9da9"><!-- raw HTML omitted -->(86d4a)<!-- raw HTML omitted --></a></li> <li>Share the Vite server between inline projects - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10848">vitest-dev/vitest#10848</a> <a href="https://github.com/vitest-dev/vitest/commit/d87c96ee4"><!-- raw HTML omitted -->(d87c9)<!-- raw HTML omitted --></a></li> <li>Parse files statically in vitest list by default - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/11088">vitest-dev/vitest#11088</a> <a href="https://github.com/vitest-dev/vitest/commit/51e949416"><!-- raw HTML omitted -->(51e94)<!-- raw HTML omitted --></a></li> <li><strong>benchmark</strong>: <ul> <li>Rewrite the public API - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10113">vitest-dev/vitest#10113</a> <a href="https://github.com/vitest-dev/vitest/commit/19f6e8947"><!-- raw HTML omitted -->(19f6e)<!-- raw HTML omitted --></a></li> </ul> </li> <li><strong>browser</strong>: <ul> <li>Iframe scale - by <a href="https://github.com/macarie"><code>@macarie</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/9745">vitest-dev/vitest#9745</a> <a href="https://github.com/vitest-dev/vitest/commit/b639852cc"><!-- raw HTML omitted -->(b6398)<!-- raw HTML omitted --></a></li> <li>Enable <code>locators.exact</code> by default - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10430">vitest-dev/vitest#10430</a> <a href="https://github.com/vitest-dev/vitest/commit/e203202f9"><!-- raw HTML omitted -->(e2032)<!-- raw HTML omitted --></a></li> <li>Require <code>sessionId</code> for orchestrator html request - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>Hiroshi Ogawa</strong> and <strong>OpenAI Codex</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10522">vitest-dev/vitest#10522</a> <a href="https://github.com/vitest-dev/vitest/commit/79b7d8fcc"><!-- raw HTML omitted -->(79b7d)<!-- raw HTML omitted --></a></li> <li>Save failure screenshots in <code>attachmentsDir</code> - by <a href="https://github.com/macarie"><code>@macarie</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10917">vitest-dev/vitest#10917</a> <a href="https://github.com/vitest-dev/vitest/commit/3b5bbd8b4"><!-- raw HTML omitted -->(3b5bb)<!-- raw HTML omitted --></a></li> </ul> </li> <li><strong>coverage</strong>: <ul> <li><code>include/exclude</code> globs too eager - by <a href="https://github.com/AriPerkkio"><code>@AriPerkkio</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/9818">vitest-dev/vitest#9818</a> <a href="https://github.com/vitest-dev/vitest/commit/edacb0fd4"><!-- raw HTML omitted -->(edacb)<!-- raw HTML omitted --></a></li> <li>Allow <code>thresholds.perFile</code> to accept an object - by <a href="https://github.com/vladlenskiy"><code>@vladlenskiy</code></a> and <a href="https://github.com/AriPerkkio"><code>@AriPerkkio</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10190">vitest-dev/vitest#10190</a> <a href="https://github.com/vitest-dev/vitest/commit/13b78d98b"><!-- raw HTML omitted -->(13b78)<!-- raw HTML omitted --></a></li> </ul> </li> <li><strong>expect</strong>: <ul> <li>Fix <code>toThrow("")</code> behavior by reverting <a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/6710">#6710</a> - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/9643">vitest-dev/vitest#9643</a> and <a href="https://redirect.github.com/vitest-dev/vitest/issues/6710">vitest-dev/vitest#6710</a> <a href="https://github.com/vitest-dev/vitest/commit/6c3e4bdbf"><!-- raw HTML omitted -->(6c3e4)<!-- raw HTML omitted --></a></li> </ul> </li> <li><strong>mocker</strong>: <ul> <li>Deserialize automock as automock - by <a href="https://github.com/nami8824"><code>@nami8824</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10192">vitest-dev/vitest#10192</a> <a href="https://github.com/vitest-dev/vitest/commit/2f892712d"><!-- raw HTML omitted -->(2f892)<!-- raw HTML omitted --></a></li> </ul> </li> <li><strong>reporters</strong>: <ul> <li><code>blob</code> reporter and <code>--merge-reports</code> default to <code>.vitest/blob/</code> - by <a href="https://github.com/AriPerkkio"><code>@AriPerkkio</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10232">vitest-dev/vitest#10232</a> <a href="https://github.com/vitest-dev/vitest/commit/d22b029ae"><!-- raw HTML omitted -->(d22b0)<!-- raw HTML omitted --></a></li> <li>Write json and junit reporter output files to <code>.vitest</code> by default - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>Hiroshi Ogawa</strong>, <strong>OpenCode (gpt-5.6-sol)</strong> and <a href="https://github.com/AriPerkkio"><code>@AriPerkkio</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10621">vitest-dev/vitest#10621</a> <a href="https://github.com/vitest-dev/vitest/commit/58577290a"><!-- raw HTML omitted -->(58577)<!-- raw HTML omitted --></a></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitest-dev/vitest/commit/f441c6fab25e579c5b7dd3dd50538416f415fbae"><code>f441c6f</code></a> chore: release v5.0.0 (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11130">#11130</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/d46a7472266d5bb43595ea51dcdd64ab0f560f12"><code>d46a747</code></a> fix: treat test.describe as a suite during static collection (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11128">#11128</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/584cf308437069385b0fb905fa3ff7d7b7f65a90"><code>584cf30</code></a> fix: add a warning if inline project has duplicate plugins due to unexpected ...</li> <li><a href="https://github.com/vitest-dev/vitest/commit/f08ce4b7144542af128dcb884150c42074223653"><code>f08ce4b</code></a> fix: apply queued mocks from doMock() in queue order (fixes <a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10706">#10706</a>) (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11127">#11127</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/897f51fd2493046c52ec9539b7d02fe3763bd63e"><code>897f51f</code></a> chore: release v5.0.0-rc.4 (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11107">#11107</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/1339b0655dc4679aeb8f905bacee83b6f76f6b23"><code>1339b06</code></a> chore(deps): update all non-major dependencies (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11104">#11104</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/51e9494166d8d0108a621fce80c41b6dba760bae"><code>51e9494</code></a> feat!: parse files statically in vitest list by default (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11088">#11088</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/2122ffdfb42d86c9a2f1238100d6a031312cae32"><code>2122ffd</code></a> fix: propagate --maxWorkers to projects (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11102">#11102</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/dc10f5f8fb69b026afcf56f8a7a9dd36bd964d73"><code>dc10f5f</code></a> fix(browser): report the action error when a task times out (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11101">#11101</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/d4fe1986fe334d22940039e815ccdbcc907baa6a"><code>d4fe198</code></a> feat: promote clearCache out of experimental (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11086">#11086</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Pins GitHub Actions `uses:` references in `github/accessibility-scanner` to immutable commit SHAs. ## Summary | Metric | Count | | --- | ---: | | Files changed | 3 | | Files scanned | 2 | | Refs found | 3 | | Refs pinned | 3 | | Skipped refs | 0 | | Warnings | 0 | | Errors | 0 | ## Why Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review. ## Reviewer notes - Original refs are preserved in inline comments when possible. - Pin comments use the Dependabot-compatible original-ref style. - Branch refs were allowed and pinned to their current HEAD; review mutable-branch pins carefully. - No minimum action age was enforced for this run. ## Pinned refs | Location | Before | After | Resolved as | | --- | --- | --- | --- | | `.github/workflows/lint.yml:26` | `actions/checkout@v7` | `actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` | | `.github/workflows/lint.yml:29` | `actions/setup-node@v7` | `actions/setup-node@820762786026740c76f36085b0efc47a31fe5020` | `tag` | | `.github/workflows/test.yml:34` | `actions/checkout@v7` | `actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` | ## Dependabot - Added a 7-day cooldown (`cooldown: default-days: 7`) to the existing `github-actions` Dependabot configuration. - The cooldown delays applying a newly published action release for 7 days, reducing exposure to a compromised or broken release while keeping you SHA-pinned. --- Generated by pinner 0.1.0.
Bumps the github-actions group with 1 update in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby). Updates `ruby/setup-ruby` from 1.321.0 to 1.324.0 - [Release notes](https://github.com/ruby/setup-ruby/releases) - [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb) - [Commits](ruby/setup-ruby@95ef2b0...a0102e0) --- updated-dependencies: - dependency-name: ruby/setup-ruby dependency-version: 1.324.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
…ub-actions group across 1 directory (#271) Bumps the github-actions group with 1 update in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby). Updates `ruby/setup-ruby` from 1.321.0 to 1.324.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ruby/setup-ruby/releases">ruby/setup-ruby's releases</a>.</em></p> <blockquote> <h2>v1.324.0</h2> <h2>What's Changed</h2> <ul> <li>Add truffleruby-40.0.0,truffleruby+graalvm-40.0.0 by <a href="https://github.com/ruby-builder-bot"><code>@ruby-builder-bot</code></a> in <a href="https://redirect.github.com/ruby/setup-ruby/pull/938">ruby/setup-ruby#938</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/setup-ruby/compare/v1.323.0...v1.324.0">https://github.com/ruby/setup-ruby/compare/v1.323.0...v1.324.0</a></p> <h2>v1.323.0</h2> <h2>What's Changed</h2> <ul> <li>Update CRuby releases on Windows by <a href="https://github.com/ruby-builder-bot"><code>@ruby-builder-bot</code></a> in <a href="https://redirect.github.com/ruby/setup-ruby/pull/937">ruby/setup-ruby#937</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/setup-ruby/compare/v1.322.0...v1.323.0">https://github.com/ruby/setup-ruby/compare/v1.322.0...v1.323.0</a></p> <h2>v1.322.0</h2> <h2>What's Changed</h2> <ul> <li>Add ruby-4.0.7 by <a href="https://github.com/ruby-builder-bot"><code>@ruby-builder-bot</code></a> in <a href="https://redirect.github.com/ruby/setup-ruby/pull/936">ruby/setup-ruby#936</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/setup-ruby/compare/v1.321.0...v1.322.0">https://github.com/ruby/setup-ruby/compare/v1.321.0...v1.322.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ruby/setup-ruby/commit/a0102e0972be65f351c307e2d64b9314a57c8073"><code>a0102e0</code></a> Add truffleruby-40.0.0,truffleruby+graalvm-40.0.0</li> <li><a href="https://github.com/ruby/setup-ruby/commit/984c0c890880bbf811283d6f09c4607c62d210a4"><code>984c0c8</code></a> Update CRuby releases on Windows</li> <li><a href="https://github.com/ruby/setup-ruby/commit/bec3f19a76460dbe12f60def7d1a77585f07516c"><code>bec3f19</code></a> Add ruby-4.0.7</li> <li>See full diff in <a href="https://github.com/ruby/setup-ruby/compare/95ef2b042f9d7a56d8268cba8559e2842e2ad01b...a0102e0972be65f351c307e2d64b9314a57c8073">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details>
Bumps the github-actions group with 1 update in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby). Updates `ruby/setup-ruby` from 1.324.0 to 1.327.0 - [Release notes](https://github.com/ruby/setup-ruby/releases) - [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb) - [Commits](ruby/setup-ruby@a0102e0...1459426) --- updated-dependencies: - dependency-name: ruby/setup-ruby dependency-version: 1.327.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: abdulahmad307 <204748719+abdulahmad307@users.noreply.github.com>
Co-authored-by: abdulahmad307 <204748719+abdulahmad307@users.noreply.github.com>
This is clone of [@mvanhorns](https://github.com/mvanhorn)'s PR #223 - opened with copilot. We need the PR opened in this repo directly so the appropriate tests and validations can run before we merge. Scans can start before a page’s client-rendered content is ready. This change lets each URL specify elements that must be visible before scanning begins. - **Configuration:** Add optional `waitForSelectors` to `url_configs`; validate that it’s an array of strings. - **Scanning:** Wait up to 30 seconds for each selector after navigation and before collecting findings. - **Example:** ```json [{"url":"https://example.com","waitForSelectors":["#app","[data-ready]"]}] ``` Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
There was a problem hiding this comment.
Note
Copilot was unable to run its full agentic suite in this review.
Copilot review overview
Review effort: Lite
Findings: 1
Open (6)
The link target./default-function-apilooks like a file path rather than a section anchor, so it… · New Use consistent hyphenation for 'third-party' (currently appears as 'Third Party' / 'third party'),… · New Use consistent hyphenation for 'third-party' (currently appears as 'Third Party' / 'third party'),… · New Use consistent hyphenation for 'third-party' (currently appears as 'Third Party' / 'third party'),… · New In this workflow,actions/checkoutis pinned with a SHA and an inline version comment (`#… · New This documentation link is pinned to a specific commit hash, which can quickly become stale as the… · New
What changed in this PR
Updates the accessibility scanner to support waiting for page readiness via waitForSelectors in url_configs, along with dependency bumps, GitHub Action hardening, and expanded documentation/tests.
Changes:
- Add
waitForSelectorssupport end-to-end (types, input validation, runtime waiting, and tests). - Improve plugin documentation (including NPM-hosted plugin allowlisting guidance) and add an issue form.
- Bump dependencies and pin GitHub Action workflow dependencies to SHAs.
| File | Description |
|---|---|
sites/site-with-errors/Gemfile.lock |
Updates rack version in the example site lockfile. |
package.json |
Bumps JS deps (notably @octokit/types and vitest). |
action.yml |
Documents waitForSelectors for the published action input. |
README.md |
Updates demo link and documents waitForSelectors usage in examples/table. |
PLUGINS.md |
Expands plugin docs (local + NPM-hosted, allowlisting flow). |
.github/workflows/test.yml |
Pins actions/checkout and updates ruby/setup-ruby ref. |
.github/workflows/lint.yml |
Pins actions/checkout and actions/setup-node to SHAs. |
.github/dependabot.yml |
Adds a Dependabot cooldown configuration block. |
.github/actions/find/tests/index.test.ts |
Adds tests for url_configs.waitForSelectors pass-through + validation. |
.github/actions/find/tests/findForUrl.test.ts |
Adds page-load/cleanup behavior tests around selector waiting. |
.github/actions/find/src/types.d.ts |
Extends UrlConfig type with waitForSelectors. |
.github/actions/find/src/index.ts |
Validates waitForSelectors input shape in url_configs. |
.github/actions/find/src/findForUrl.ts |
Implements selector waiting and strengthens resource cleanup logic. |
.github/actions/find/action.yml |
Documents waitForSelectors for the internal find action. |
.github/actions/find/README.md |
Documents url_configs.waitForSelectors behavior and timeout. |
.github/ISSUE_TEMPLATE/allowlist-npm-plugin-request.yml |
Adds an issue form for NPM plugin allowlisting requests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
passing workflows:
all copilot comments are minor things like code-comments, hyphenation usage, etc... |
…ub-actions group across 1 directory (#272) Bumps the github-actions group with 1 update in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby). Updates `ruby/setup-ruby` from 1.324.0 to 1.327.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ruby/setup-ruby/releases">ruby/setup-ruby's releases</a>.</em></p> <blockquote> <h2>v1.327.0</h2> <h2>What's Changed</h2> <ul> <li>Update CRuby releases on Windows by <a href="https://github.com/ruby-builder-bot"><code>@ruby-builder-bot</code></a> in <a href="https://redirect.github.com/ruby/setup-ruby/pull/942">ruby/setup-ruby#942</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/setup-ruby/compare/v1.326.0...v1.327.0">https://github.com/ruby/setup-ruby/compare/v1.326.0...v1.327.0</a></p> <h2>v1.326.0</h2> <h2>What's Changed</h2> <ul> <li>Add ruby-3.4.11 by <a href="https://github.com/ruby-builder-bot"><code>@ruby-builder-bot</code></a> in <a href="https://redirect.github.com/ruby/setup-ruby/pull/940">ruby/setup-ruby#940</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/setup-ruby/compare/v1.325.0...v1.326.0">https://github.com/ruby/setup-ruby/compare/v1.325.0...v1.326.0</a></p> <h2>v1.325.0</h2> <h2>What's Changed</h2> <ul> <li>Add jruby-10.0.7.0,jruby-10.1.2.0 by <a href="https://github.com/ruby-builder-bot"><code>@ruby-builder-bot</code></a> in <a href="https://redirect.github.com/ruby/setup-ruby/pull/939">ruby/setup-ruby#939</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/setup-ruby/compare/v1.324.0...v1.325.0">https://github.com/ruby/setup-ruby/compare/v1.324.0...v1.325.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ruby/setup-ruby/commit/14594264cd68ce8a2345dd349bc3d138a4ef85c8"><code>1459426</code></a> Update CRuby releases on Windows</li> <li><a href="https://github.com/ruby/setup-ruby/commit/762794c140bbeda0f1224786aa33b4b46783a6c1"><code>762794c</code></a> Add ruby-3.4.11</li> <li><a href="https://github.com/ruby/setup-ruby/commit/e8944e80fb94b20106697132f8c20c665fab29e9"><code>e8944e8</code></a> Add jruby-10.0.7.0,jruby-10.1.2.0</li> <li>See full diff in <a href="https://github.com/ruby/setup-ruby/compare/a0102e0972be65f351c307e2d64b9314a57c8073...14594264cd68ce8a2345dd349bc3d138a4ef85c8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details>
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.4. - [Commits](WebReflection/flatted@v3.3.3...v3.4.4) --- updated-dependencies: - dependency-name: flatted dependency-version: 3.4.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.7 to 5.0.12. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.7...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2. - [Release notes](https://github.com/7rulnik/source-map-js/releases) - [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md) - [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2) --- updated-dependencies: - dependency-name: source-map-js dependency-version: 1.2.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.28.1 to 6.29.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v6.28.1...v6.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 6.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.7 to 5.0.12. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/juliangruber/brace-expansion/commit/f3410159d768f56c9d9f4511d3e1b46425fc1099"><code>f341015</code></a> 5.0.12</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96"><code>33a5ef1</code></a> Merge commit from fork</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/82479277b90f2f86263e946f9ff89689b3734568"><code>8247927</code></a> 5.0.11</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c"><code>935d78f</code></a> Merge commit from fork</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/df7682f386cdf2d7fef6067bc78ed70d824e1f3f"><code>df7682f</code></a> 5.0.10</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/1ade9de71f3a8719c82c61a7977121067bb55b02"><code>1ade9de</code></a> npm run format</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"><code>6735c94</code></a> Merge commit from fork</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/4e7046543469d31e2b324b1bf14d8606d74f7f18"><code>4e70465</code></a> chore: ensure prettier formatting (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/154">#154</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/fd7a5e34cfcd9a9df6e0ee17817807104392ecff"><code>fd7a5e3</code></a> Bump ip-address from 10.2.0 to 10.4.0 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/152">#152</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/1790143e9aa05279b087b94104c03d3cb775e2e4"><code>1790143</code></a> Bump uuid and <code>@tapjs/processinfo</code> (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/120">#120</a>)</li> <li>Additional commits viewable in <a href="https://github.com/juliangruber/brace-expansion/compare/v5.0.7...v5.0.12">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details>
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/7rulnik/source-map-js/releases">source-map-js's releases</a>.</em></p> <blockquote> <h2>v1.2.2</h2> <ul> <li> <p>Fix crash when executing in browser with CSP script-src that don't permit unsafe-eval (<a href="https://redirect.github.com/7rulnik/source-map-js/pull/29">#29</a>) <a href="https://github.com/xfournet"><code>@xfournet</code></a></p> </li> <li> <p>Fix denial of service from malicious indexed source maps (CVE-2026-93749) (<a href="https://redirect.github.com/7rulnik/source-map-js/pull/79">#79</a>)</p> <p>Reported by <a href="https://github.com/waydeshi"><code>@waydeshi</code></a> in <a href="https://redirect.github.com/7rulnik/source-map-js/issues/76">#76</a>. A fix was also proposed by <a href="https://github.com/aniebiet"><code>@aniebiet</code></a> in <a href="https://redirect.github.com/7rulnik/source-map-js/pull/78">#78</a>.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md">source-map-js's changelog</a>.</em></p> <blockquote> <h2>1.2.2</h2> <ul> <li> <p>Fix crash when executing in browser with CSP script-src that don't permit unsafe-eval (<a href="https://redirect.github.com/7rulnik/source-map-js/pull/29">#29</a>) <a href="https://github.com/xfournet"><code>@xfournet</code></a></p> </li> <li> <p>Fix denial of service from malicious indexed source maps (CVE-2026-93749) (<a href="https://redirect.github.com/7rulnik/source-map-js/pull/79">#79</a>)</p> <p>Reported by <a href="https://github.com/waydeshi"><code>@waydeshi</code></a> in <a href="https://redirect.github.com/7rulnik/source-map-js/issues/76">#76</a>. A fix was also proposed by <a href="https://github.com/aniebiet"><code>@aniebiet</code></a> in <a href="https://redirect.github.com/7rulnik/source-map-js/pull/78">#78</a>.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a"><code>0a1d334</code></a> 1.2.2</li> <li><a href="https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739"><code>4c6fa26</code></a> Update changelog</li> <li><a href="https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016"><code>cf76580</code></a> Fix denial of service from malicious indexed source maps (CVE-2026-93749) (<a href="https://redirect.github.com/7rulnik/source-map-js/issues/79">#79</a>)</li> <li><a href="https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df"><code>7899a86</code></a> Fix crash when executing browser with CSP script-src that don't permit unsafe...</li> <li>See full diff in <a href="https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details>
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.4. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/WebReflection/flatted/commit/e6f5ca700c4ca8104a6a83472c8219e267bd5e84"><code>e6f5ca7</code></a> 3.4.4</li> <li><a href="https://github.com/WebReflection/flatted/commit/47f14fac0b1a41989f216b0cda4c50596ca339f6"><code>47f14fa</code></a> removed E_STRICT from PHP</li> <li><a href="https://github.com/WebReflection/flatted/commit/40505688464c49fe6374e7bc4cdd9bd2e9e6f330"><code>4050568</code></a> fixced go-lang issues in CI</li> <li><a href="https://github.com/WebReflection/flatted/commit/4303f4db38ba0ba8d5e2ed6e9689cefc74c46b63"><code>4303f4d</code></a> Merge pull request <a href="https://redirect.github.com/WebReflection/flatted/issues/101">#101</a> from mfinelli/gocriticfixes</li> <li><a href="https://github.com/WebReflection/flatted/commit/106735b609c15df51539a0d7c0a270182efd904c"><code>106735b</code></a> updated package-lock.json</li> <li><a href="https://github.com/WebReflection/flatted/commit/670a1bdf9dcfba02111c3034294366f10696fb53"><code>670a1bd</code></a> 3.4.3</li> <li><a href="https://github.com/WebReflection/flatted/commit/50a61a90ea5ca64c114f0aa040ad127e3a97feff"><code>50a61a9</code></a> Fix <a href="https://redirect.github.com/WebReflection/flatted/issues/104">#104</a> - allow <code>null</code> as replacer value</li> <li><a href="https://github.com/WebReflection/flatted/commit/8aa64f460cf0c4dac9cc214c831aade28f8f2c6e"><code>8aa64f4</code></a> solved crytical errors over dependencies</li> <li><a href="https://github.com/WebReflection/flatted/commit/b85577f39ff85959d02e8862cc0dde8114b43762"><code>b85577f</code></a> Fix go-critic errors</li> <li><a href="https://github.com/WebReflection/flatted/commit/bb8c63cea5befd4315519cb4458c6fc07bb9cf7b"><code>bb8c63c</code></a> Merge pull request <a href="https://redirect.github.com/WebReflection/flatted/issues/100">#100</a> from WebReflection/WebReflection-patch-1</li> <li>Additional commits viewable in <a href="https://github.com/WebReflection/flatted/compare/v3.3.3...v3.4.4">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details>
Bumps [undici](https://github.com/nodejs/undici) from 6.28.1 to 6.29.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nodejs/undici/releases">undici's releases</a>.</em></p> <blockquote> <h2>v6.29.0</h2> <h2>What's Changed</h2> <ul> <li>[v6.x] fix(retry): settle exposed body on terminal failure by <a href="https://github.com/mcollina"><code>@mcollina</code></a> in <a href="https://redirect.github.com/nodejs/undici/pull/5778">nodejs/undici#5778</a></li> <li>Backport upgrade diagnostics lifecycle fixes to v6.x by <a href="https://github.com/BridgeAR"><code>@BridgeAR</code></a> in <a href="https://redirect.github.com/nodejs/undici/pull/5833">nodejs/undici#5833</a></li> <li>test: synchronize the issue-3356 body timeout by <a href="https://github.com/BridgeAR"><code>@BridgeAR</code></a> in <a href="https://redirect.github.com/nodejs/undici/pull/5834">nodejs/undici#5834</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/nodejs/undici/compare/v6.28.1...v6.29.0">https://github.com/nodejs/undici/compare/v6.28.1...v6.29.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodejs/undici/commit/e1d0501f8705253c32a8b40bdb3fc0474167c92d"><code>e1d0501</code></a> Bumped v6.29.0 (<a href="https://redirect.github.com/nodejs/undici/issues/5888">#5888</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/57ac4dea0d38a0bf068eaf7eda0b8cb9e86f6a99"><code>57ac4de</code></a> test: synchronize the issue-3356 body timeout (<a href="https://redirect.github.com/nodejs/undici/issues/5834">#5834</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/6d441740cf5dad3455a7a7881451e802f10b0b2a"><code>6d44174</code></a> Backport upgrade diagnostics lifecycle fixes to v6.x (<a href="https://redirect.github.com/nodejs/undici/issues/5833">#5833</a>)</li> <li><a href="https://github.com/nodejs/undici/commit/2a91fc828ecc51865fe7d77376e5f676d030769b"><code>2a91fc8</code></a> fix(retry): settle exposed body on terminal failure (<a href="https://redirect.github.com/nodejs/undici/issues/5778">#5778</a>)</li> <li>See full diff in <a href="https://github.com/nodejs/undici/compare/v6.28.1...v6.29.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/github/accessibility-scanner/network/alerts). </details>


For release after the merge of this PR: #273 - will run tests again against v3 branch once merged