Skip to content

Merging main into v3 for release - #274

Merged
abdulahmad307 merged 36 commits into
v3from
main
Oct 6, 2026
Merged

abdulahmad307 merged 36 commits into
v3from
main

Conversation

@abdulahmad307

@abdulahmad307 abdulahmad307 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

For release after the merge of this PR: #273 - will run tests again against v3 branch once merged

dependabot Bot and others added 27 commits August 5, 2026 23:45
Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nodejs/undici/releases">undici's
releases</a>.</em></p>
<blockquote>
<h2>v6.28.0</h2>
<h2>⚠️ Security fixes</h2>
<ul>
<li><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5">GHSA-m8rv-5g2x-5cg5</a>:
a malicious <code>type</code> property on a duck-typed blob-like
HTTP/1.1 request body could inject CRLF sequences into the generated
<code>content-type</code> header. Undici now coerces and validates the
value before adding it to the request. Fixed by <a
href="https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400">740a0b7c</a>.</li>
<li><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524">GHSA-8xcm-r25x-g524</a>:
the retry interceptor could expose a stale <code>Content-Length</code>
after resuming a partial response, potentially causing downstream
response desynchronization, hangs, or corruption. Undici now rejects
partial responses whose <code>Content-Length</code> is inconsistent with
<code>Content-Range</code>. Fixed by <a
href="https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e">cba3a52a</a>,
with corrected fixtures in <a
href="https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420">4fd5a0c6</a>.</li>
<li><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm">GHSA-v3r7-h72x-cjcm</a>:
unsanitized <code>domain</code> and <code>unparsed</code> values passed
to <code>setCookie()</code> could inject cookie attributes. Undici now
validates cookie domains, paths, and unparsed attributes more strictly.
Fixed by <a
href="https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235">af748404</a>.</li>
</ul>
<p><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272">GHSA-4cwx-7wf7-3272</a>
and <a
href="https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54">GHSA-jr45-8vmc-qm54</a>
affect the cache interceptor in Undici v7 and v8; Undici v6 is not in
their affected version ranges.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0">https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a"><code>01a912e</code></a>
Bumped v6.28.0 (<a
href="https://redirect.github.com/nodejs/undici/issues/5591">#5591</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e"><code>481ecfc</code></a>
Use Node 22 and npm 11 to release</li>
<li><a
href="https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400"><code>740a0b7</code></a>
fix: validate blob body content type</li>
<li><a
href="https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0"><code>2698e49</code></a>
fix: validate coerced header values for CRLF (<a
href="https://redirect.github.com/nodejs/undici/issues/5579">#5579</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420"><code>4fd5a0c</code></a>
test(retry): correct broken content-range fixtures in
retry-handler.js</li>
<li><a
href="https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e"><code>cba3a52</code></a>
fix(retry): reject partial content length mismatch</li>
<li><a
href="https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235"><code>af74840</code></a>
fix: harden cookie domain, path, and unparsed attribute validation</li>
<li>See full diff in <a
href="https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici&package-manager=npm_and_yarn&previous-version=6.27.0&new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>
Bumps [@octokit/types](https://github.com/octokit/types.ts) from 16.0.0 to 17.0.0.
- [Release notes](https://github.com/octokit/types.ts/releases)
- [Commits](octokit/types.ts@v16.0.0...v17.0.0)

---
updated-dependencies:
- dependency-name: "@octokit/types"
  dependency-version: 17.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@octokit/types](https://github.com/octokit/types.ts) from 16.0.0
to 17.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/octokit/types.ts/releases">@​octokit/types's
releases</a>.</em></p>
<blockquote>
<h2>v17.0.0</h2>
<h1><a
href="https://github.com/octokit/types.ts/compare/v16.0.0...v17.0.0">17.0.0</a>
(2026-08-01)</h1>
<h3>Features</h3>
<ul>
<li>drop projects-classic endpoints, add GitHub API endpoints: cache
limits (retention &amp; storage) for repos/orgs/enterprises, billing
budgets &amp; usage, artifacts deployment metadata, and projectsV2
drafts &amp; fields (<a
href="https://redirect.github.com/octokit/types.ts/issues/713">#713</a>)
(<a
href="https://github.com/octokit/types.ts/commit/0296144cacd4d01d5f051de05e519a764b26f447">0296144</a>)</li>
</ul>
<h3>BREAKING CHANGES</h3>
<ul>
<li>Removed <code>/orgs/{org}/projects</code></li>
<li>Removed <code>/orgs/{org}/settings/billing/actions</code></li>
<li>Removed <code>/orgs/{org}/settings/billing/packages</code></li>
<li>Removed
<code>/orgs/{org}/settings/billing/shared-storage</code></li>
<li>Removed <code>/orgs/{org}/teams/{team_slug}/projects</code></li>
<li>Removed
<code>/orgs/{org}/teams/{team_slug}/projects/{project_id}</code></li>
<li>Removed <code>/projects/columns/{column_id}</code></li>
<li>Removed <code>/projects/columns/{column_id}/moves</code></li>
<li>Removed <code>/projects/{project_id}</code></li>
<li>Removed <code>/projects/{project_id}/collaborators</code></li>
<li>Removed
<code>/projects/{project_id}/collaborators/{username}</code></li>
<li>Removed
<code>/projects/{project_id}/collaborators/{username}/permission</code></li>
<li>Removed <code>/repos/{owner}/{repo}/projects</code></li>
<li>Removed <code>/teams/{team_id}/projects</code></li>
<li>Removed <code>/teams/{team_id}/projects/{project_id}</code></li>
<li>Removed <code>/user/projects</code></li>
<li>Removed <code>/users/{username}/projects</code></li>
<li>Removed <code>/users/{username}/settings/billing/actions</code></li>
<li>Removed
<code>/users/{username}/settings/billing/packages</code></li>
<li>Removed
<code>/users/{username}/settings/billing/shared-storage</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/octokit/types.ts/commit/0296144cacd4d01d5f051de05e519a764b26f447"><code>0296144</code></a>
feat: drop projects-classic endpoints, add GitHub API endpoints: cache
limits...</li>
<li><a
href="https://github.com/octokit/types.ts/commit/f672eb565d8f0ce35e5559a32a7d3cd0e850e0e3"><code>f672eb5</code></a>
ci(action): update actions/create-github-app-token action to v3 (<a
href="https://redirect.github.com/octokit/types.ts/issues/702">#702</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/5a8840f1ecb12b1e0ccaed9740ac94e39d6fc598"><code>5a8840f</code></a>
chore(deps): update dependency npm-run-all2 to v9 (<a
href="https://redirect.github.com/octokit/types.ts/issues/707">#707</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/13d28d782c1a6e34bd43ae3afbc7981d91fb7224"><code>13d28d7</code></a>
ci(action): update actions/add-to-project action to v2 (<a
href="https://redirect.github.com/octokit/types.ts/issues/705">#705</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/8303723ee4919b44ee06808e3f155f6ea0390215"><code>8303723</code></a>
ci(action): update actions/checkout action to v7 (<a
href="https://redirect.github.com/octokit/types.ts/issues/709">#709</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/de769019bbe5e835c34c47100aa72141c84d31fe"><code>de76901</code></a>
ci(action): update actions/setup-node action to v7 (<a
href="https://redirect.github.com/octokit/types.ts/issues/711">#711</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/b61f4adda1f88aa2eea6b7f94a1db772a219e49d"><code>b61f4ad</code></a>
chore(deps): update dependency handlebars to v4.7.9 [security] (<a
href="https://redirect.github.com/octokit/types.ts/issues/706">#706</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/52c1c756ef10e10bf5518f7a567075cf5efbd3bf"><code>52c1c75</code></a>
ci(action): update actions/checkout action to v6 (<a
href="https://redirect.github.com/octokit/types.ts/issues/697">#697</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/9eebb161e4f5c4cc878546a06b7da81a24728b52"><code>9eebb16</code></a>
build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (<a
href="https://redirect.github.com/octokit/types.ts/issues/695">#695</a>)</li>
<li>See full diff in <a
href="https://github.com/octokit/types.ts/compare/v16.0.0...v17.0.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for <code>@​octokit/types</code> since your current
version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@octokit/types&package-manager=npm_and_yarn&previous-version=16.0.0&new-version=17.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>
Bumps the bundler-minor-and-patch group in /sites/site-with-errors with 1 update: [rack](https://github.com/rack/rack).


Updates `rack` from 3.2.6 to 3.2.7
- [Release notes](https://github.com/rack/rack/releases)
- [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md)
- [Commits](rack/rack@v3.2.6...v3.2.7)

---
updated-dependencies:
- dependency-name: rack
  dependency-version: 3.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
… in the bundler-minor-and-patch group (#258)

Bumps the bundler-minor-and-patch group in /sites/site-with-errors with
1 update: [rack](https://github.com/rack/rack).

Updates `rack` from 3.2.6 to 3.2.7
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/rack/rack/blob/main/CHANGELOG.md">rack's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<p>All notable changes to this project will be documented in this file.
For info on how to format all future additions to this file please
reference <a href="https://keepachangelog.com/en/1.0.0/">Keep A
Changelog</a>.</p>
<h2>Unreleased</h2>
<h3>SPEC Changes</h3>
<ul>
<li>Define <code>rack.response_finished</code> callback arguments more
strictly. (<a
href="https://redirect.github.com/rack/rack/pull/2365">#2365</a>, <a
href="https://github.com/skipkayhil"><code>@​skipkayhil</code></a>)</li>
</ul>
<h3>Added</h3>
<ul>
<li>Add <code>Rack::Files#assign_headers</code> to allow overriding how
the configured file headers are set. (<a
href="https://redirect.github.com/rack/rack/pull/2377">#2377</a>, <a
href="https://github.com/codergeek121"><code>@​codergeek121</code></a>)</li>
<li>Add support for <code>rack.response_finished</code> to
<code>Rack::TempfileReaper</code>. (<a
href="https://redirect.github.com/rack/rack/pull/2363">#2363</a>, <a
href="https://github.com/skipkayhil"><code>@​skipkayhil</code></a>)</li>
<li>Add support for streaming bodies when using
<code>Rack::Events</code>. (<a
href="https://redirect.github.com/rack/rack/blob/main/redirect.github.com/rack/rack/pull/2375">#2375</a>,
<a href="https://github.com/unflxw"><code>@​unflxw</code></a>)</li>
<li>Add <code>deflaters</code> option to <code>Rack::Deflater</code> to
enable custom compression algorithms like zstd. (<a
href="https://redirect.github.com/rack/rack/issues/2168">#2168</a>, <a
href="https://github.com/alexanderadam"><code>@​alexanderadam</code></a>)</li>
<li>Add <code>Rack::Request#prefetch?</code> for identifying requests
with <code>Sec-Purpose: prefetch</code> header set. (<a
href="https://redirect.github.com/rack/rack/pull/2405">#2405</a>, <a
href="https://github.com/glaszig"><code>@​glaszig</code></a>)</li>
<li>Add <code>rack.request.config</code> environment key to configure
Rack::Request behavior.</li>
<li>Add <code>Rack::Request#headers</code> for simpler access to request
headers by header name. (<a
href="https://redirect.github.com/rack/rack/pull/1881">#1881</a>, <a
href="https://github.com/jeremyevans"><code>@​jeremyevans</code></a>)</li>
<li>Allow disabling the <code>Rack::QueryParser</code> bytesize and
params limits by passing <code>nil</code> for the
<code>bytesize_limit</code>/<code>params_limit</code> keyword arguments,
or a negative value for
<code>RACK_QUERY_PARSER_BYTESIZE_LIMIT</code>/<code>RACK_QUERY_PARSER_PARAMS_LIMIT</code>.
(<a href="https://redirect.github.com/rack/rack/pull/2492">#2492</a>, <a
href="https://github.com/alpaca-tc"><code>@​alpaca-tc</code></a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Require Ruby 2.7.3 or newer and replace <code>ruby2_keywords</code>
with argument forwarding.</li>
<li>Raise before exceeding a part limit, not after. (<a
href="https://redirect.github.com/rack/rack/pull/2362">#2362</a>, <a
href="https://github.com/matthew-puku"><code>@​matthew-puku</code></a>)</li>
<li>Rack::Deflater now uses a fixed GZip mtime value. (<a
href="https://redirect.github.com/rack/rack/pull/2372">#2372</a>, <a
href="https://github.com/bensheldon"><code>@​bensheldon</code></a>)</li>
<li>Multipart parser drops support for RFC 2231 <code>filename*</code>
parameter (prohibited by RFC 7578) and now properly handles UTF-8
encoded filenames via percent-encoding and direct UTF-8 bytes. (<a
href="https://redirect.github.com/rack/rack/pull/2398">#2398</a>, <a
href="https://github.com/wtn"><code>@​wtn</code></a>)</li>
<li>The query parser now raises
<code>Rack::QueryParser::IncompatibleEncodingError</code> if we try to
parse params that are not ASCII compatible. (<a
href="https://redirect.github.com/rack/rack/pull/2416">#2416</a>, <a
href="https://github.com/bquorning"><code>@​bquorning</code></a>)</li>
<li>The mime type for <code>.pem</code> files has been changed from
<code>application/x-x509-ca-cert</code> to
<code>application/x-pem-file</code>. (<a
href="https://redirect.github.com/rack/rack/pull/2435">#2435</a>, <a
href="https://github.com/jeremyevans"><code>@​jeremyevans</code></a>)</li>
<li>Freeze <code>Rack::Auth::AbstractRequest::AUTHORIZATION_KEYS</code>,
<code>Rack::Utils::STATUS_WITH_NO_ENTITY_BODY</code>,
<code>Rack::Multipart::Parser::EMPTY</code>,
<code>Rack::Utils.default_query_parser</code>, and internal constants in
<code>Rack::Lint</code>. (<a
href="https://redirect.github.com/rack/rack/pull/2428">#2428</a>, <a
href="https://github.com/jhawthorn"><code>@​jhawthorn</code></a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li><code>Rack::Multipart::UploadedFile</code> now delegates keyword
arguments to the wrapped tempfile. Calls such as
<code>uploaded_file.readlines(chomp: true)</code> raised
<code>TypeError</code> on Ruby 3.0+. (<a
href="https://redirect.github.com/rack/rack/issues/2481">#2481</a>, <a
href="https://redirect.github.com/rack/rack/pull/2499">#2499</a>, <a
href="https://github.com/SeanLF"><code>@​SeanLF</code></a>)</li>
<li>Multipart parser: limit MIME header size check to the unread buffer
region to avoid false <code>multipart mime part header too large</code>
errors when previously read data accumulates in the scan buffer. (<a
href="https://redirect.github.com/rack/rack/pull/2392">#2392</a>, <a
href="https://github.com/alpaca-tc"><code>@​alpaca-tc</code></a>, <a
href="https://github.com/willnet"><code>@​willnet</code></a>, <a
href="https://github.com/krororo"><code>@​krororo</code></a>)</li>
<li>Multipart parser: add nil guards to prevent
<code>NoMethodError</code> crashes when handling
<code>Content-Disposition</code> without parameters and
<code>Content-Type</code> parameters without '='. (<a
href="https://github.com/haruki0409"><code>@​haruki0409</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/rack/rack/commit/70d2e1046789a70e240e01b9ac0b3ffc9b26d33f"><code>70d2e10</code></a>
Bump patch version.</li>
<li><a
href="https://github.com/rack/rack/commit/9b31adf2a8a1fa443cda4825f35b1fff76b2eedd"><code>9b31adf</code></a>
Fix specs on Ruby 2.4</li>
<li><a
href="https://github.com/rack/rack/commit/7c0ababcbad4e4b3fe0cc45c3a8d8b4e2a8cfcef"><code>7c0abab</code></a>
Do not ignore Ruby 2.4/2.5 errors in CI</li>
<li><a
href="https://github.com/rack/rack/commit/ef52d4e87ba4346ba381361712c8f714ae9dbe11"><code>ef52d4e</code></a>
Fix <code>FORWARDED</code> typo.</li>
<li><a
href="https://github.com/rack/rack/commit/108405ea9fec02dc14c8317e25619d1001ffe4a9"><code>108405e</code></a>
Restore Ruby 2.4/2.5 compatibility</li>
<li><a
href="https://github.com/rack/rack/commit/c3fe39348bc688f6c02096c04fa6fbc668300c1a"><code>c3fe393</code></a>
Update changelog.</li>
<li>See full diff in <a
href="https://github.com/rack/rack/compare/v3.2.6...v3.2.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rack&package-manager=bundler&previous-version=3.2.6&new-version=3.2.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
- new issue template for allowlisting third-party issues from NPM
- plugin documentation reorganized and rewritten to organize information
  about all plugins vs. NPM plugins only vs. local plugins only
- new issue template for allowlisting third-party issues from NPM
- plugin documentation reorganized and rewritten to organize information
about all plugins vs. NPM plugins only vs. local plugins only
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Updated demo video link for the a11y scanner.
Updated demo video link for the a11y scanner.
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.28.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.15...8.5.28)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to
8.5.28.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.28</h2>
<ul>
<li>Fixes types regression.</li>
</ul>
<h2>8.5.27</h2>
<ul>
<li>Fixed removing any comments starting with <code>/*#</code> (by <a
href="https://github.com/dylanpulver"><code>@​dylanpulver</code></a>).</li>
<li>Fixed <code>*</code> hack before a comment in Custom Properties (by
<a href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
<li>Fixed empty values in the middle of <code>list.comma()</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
<li>Fixed whitespace-only values in <code>list.space()</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
<li>Fixed rule’s end position on space before semicolon (by <a
href="https://github.com/maximilliangrand"><code>@​maximilliangrand</code></a>).</li>
<li>Fixed types (by <a
href="https://github.com/romainmenke"><code>@​romainmenke</code></a>).</li>
<li>Fixed Chinese text in deprecation warning (by <a
href="https://github.com/Jesse205"><code>@​Jesse205</code></a>).</li>
</ul>
<h2>8.5.26</h2>
<ul>
<li>Fixed <code>list.split()</code> regression (by <a
href="https://github.com/lazerg"><code>@​lazerg</code></a>).</li>
<li>Track symlinks in path protection in source map loading (by <a
href="https://github.com/drengir1"><code>@​drengir1</code></a>).</li>
</ul>
<h2>8.5.25</h2>
<ul>
<li>Fixed 8.5.17 visitor regression.</li>
<li>Fixed <code>list.split()</code> for non-string values (by <a
href="https://github.com/amir-rezaei"><code>@​amir-rezaei</code></a>).</li>
</ul>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
<h2>8.5.22</h2>
<ul>
<li>Fixed custom property losing semicolon before a comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
</ul>
<h2>8.5.21</h2>
<ul>
<li>Fixed childless at-rule losing semicolon before comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed docs (by <a
href="https://github.com/isker"><code>@​isker</code></a>).</li>
</ul>
<h2>8.5.20</h2>
<ul>
<li>Fixed missing space if <code>AtRule#params</code> is set after (by
<a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed mixing AST error on warnings (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.19</h2>
<ul>
<li>Fixed cleaning <code>before</code> for new nodes inserted to
<code>Root</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.18</h2>
<ul>
<li>Restricted loading previous source maps file to the
<code>opts.from</code> folder for security reasons (use <code>unsafeMap:
true</code> to disable the check).</li>
</ul>
<h2>8.5.17</h2>
<ul>
<li>Fixed <code>Maximum call stack size exceeded</code> error.</li>
<li>Fixed Prototype hijacking for <code>postcss.fromJSON()</code>.</li>
<li>Fixed <code>Input#origin()</code> for unmapped end position (by <a
href="https://github.com/chatman-media"><code>@​chatman-media</code></a>).</li>
</ul>
<h2>8.5.16</h2>
<ul>
<li>Fixed <code>Input#origin()</code> position (by <a
href="https://github.com/mizdra"><code>@​mizdra</code></a>).</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.28</h2>
<ul>
<li>Fixes types regression.</li>
</ul>
<h2>8.5.27</h2>
<ul>
<li>Fixed removing any comments starting with <code>/*#</code> (by <a
href="https://github.com/dylanpulver"><code>@​dylanpulver</code></a>).</li>
<li>Fixed <code>*</code> hack before a comment in Custom Properties (by
<a href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
<li>Fixed empty values in the middle of <code>list.comma()</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
<li>Fixed whitespace-only values in <code>list.space()</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
<li>Fixed rule’s end position on space before semicolon (by <a
href="https://github.com/maximilliangrand"><code>@​maximilliangrand</code></a>).</li>
<li>Fixed types (by <a
href="https://github.com/romainmenke"><code>@​romainmenke</code></a>).</li>
<li>Fixed Chinese text in deprecation warning (by <a
href="https://github.com/Jesse205"><code>@​Jesse205</code></a>).</li>
</ul>
<h2>8.5.26</h2>
<ul>
<li>Fixed <code>list.split()</code> regression (by <a
href="https://github.com/lazerg"><code>@​lazerg</code></a>).</li>
<li>Track symlinks in path protection in source map loading (by <a
href="https://github.com/drengir1"><code>@​drengir1</code></a>).</li>
</ul>
<h2>8.5.25</h2>
<ul>
<li>Fixed 8.5.17 visitor regression.</li>
<li>Fixed <code>list.split()</code> for non-string values (by <a
href="https://github.com/amir-rezaei"><code>@​amir-rezaei</code></a>).</li>
</ul>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
<h2>8.5.22</h2>
<ul>
<li>Fixed custom property losing semicolon before a comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
</ul>
<h2>8.5.21</h2>
<ul>
<li>Fixed childless at-rule losing semicolon before comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed docs (by <a
href="https://github.com/isker"><code>@​isker</code></a>).</li>
</ul>
<h2>8.5.20</h2>
<ul>
<li>Fixed missing space if <code>AtRule#params</code> is set after (by
<a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed mixing AST error on warnings (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.19</h2>
<ul>
<li>Fixed cleaning <code>before</code> for new nodes inserted to
<code>Root</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a"><code>e544bff</code></a>
Release 8.5.28 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a"><code>f8fc252</code></a>
Typo</li>
<li><a
href="https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce"><code>5039fd7</code></a>
Add missed release notes</li>
<li><a
href="https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af"><code>ae40ca4</code></a>
Release 8.5.27 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba"><code>62b1626</code></a>
Fix linter</li>
<li><a
href="https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4"><code>1dba938</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881"><code>3e82edc</code></a>
Keep non-annotation comments when the processor has no plugins (<a
href="https://redirect.github.com/postcss/postcss/issues/2150">#2150</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e"><code>6d23bc3</code></a>
Fix link</li>
<li><a
href="https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a"><code>508e997</code></a>
Add GitHub Sponsors link</li>
<li><a
href="https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b"><code>e993739</code></a>
Add CodeRabbit sponsor (<a
href="https://redirect.github.com/postcss/postcss/issues/2145">#2145</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/postcss/compare/8.5.15...8.5.28">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for postcss since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=postcss&package-manager=npm_and_yarn&previous-version=8.5.15&new-version=8.5.28)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>
Bumps [undici](https://github.com/nodejs/undici) from 6.28.0 to 6.28.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nodejs/undici/releases">undici's
releases</a>.</em></p>
<blockquote>
<h2>v6.28.1</h2>
<h2>⚠️ Security fixes</h2>
<h3>High severity</h3>
<ul>
<li><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5">GHSA-rfgv-xxqx-mfg5</a>:
a WebSocket server could select a subprotocol when none was requested,
causing an uncaught <code>TypeError</code> that could terminate the
process. Undici now rejects the handshake with protocol error 1002.
Fixed by <a
href="https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5">2af0faf8</a>.</li>
</ul>
<h3>Medium severity</h3>
<ul>
<li><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v">GHSA-3wwx-pv8p-q78v</a>:
a malformed permessage-deflate payload exceeding the configured
decompression limit could emit an unhandled zlib error and terminate the
process. Undici now destroys the inflater after reaching the limit.
Fixed by <a
href="https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c">07c60d9c</a>.</li>
</ul>
<h3>Low severity</h3>
<ul>
<li><a
href="https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r">GHSA-r53p-7pc4-xj5r</a>:
the retry interceptor could concatenate a resumed response with
inconsistent framing into downstream output, enabling response splitting
or corruption. Undici now validates <code>Content-Range</code> against
the original response framing before resuming. Fixed by <a
href="https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548">ce31bc82</a>.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>perf: reduce EventSourceStream parser allocations (<a
href="https://redirect.github.com/nodejs/undici/issues/5032">#5032</a>)
by <a href="https://github.com/mcollina"><code>@​mcollina</code></a> in
<a
href="https://redirect.github.com/nodejs/undici/pull/5647">nodejs/undici#5647</a></li>
<li>[v6.x] perf(h1): drop idle-socket timer floor with a ref'd
setImmediate (<a
href="https://redirect.github.com/nodejs/undici/issues/5707">#5707</a>)
by <a href="https://github.com/mcollina"><code>@​mcollina</code></a> in
<a
href="https://redirect.github.com/nodejs/undici/pull/5770">nodejs/undici#5770</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1">https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodejs/undici/commit/ffc8aa0fdd4c54024f384e57784d5047c8b4085a"><code>ffc8aa0</code></a>
Bumped v6.28.1 (<a
href="https://redirect.github.com/nodejs/undici/issues/5773">#5773</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/3866a3bc4ebaea2c6400db9193c2366072080dc4"><code>3866a3b</code></a>
perf(h1): drop idle-socket timer floor with a ref'd setImmediate (<a
href="https://redirect.github.com/nodejs/undici/issues/5707">#5707</a>)
(<a
href="https://redirect.github.com/nodejs/undici/issues/5770">#5770</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548"><code>ce31bc8</code></a>
fix(retry): validate resumed response framing</li>
<li><a
href="https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5"><code>2af0faf</code></a>
fix(websocket): reject unrequested subprotocols</li>
<li><a
href="https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c"><code>07c60d9</code></a>
fix(websocket): destroy inflater after decompression limit</li>
<li><a
href="https://github.com/nodejs/undici/commit/bd90fff2a6e1350ba87e9b70811c5337502d2e39"><code>bd90fff</code></a>
perf: reduce EventSourceStream parser allocations (<a
href="https://redirect.github.com/nodejs/undici/issues/5032">#5032</a>)
(<a
href="https://redirect.github.com/nodejs/undici/issues/5647">#5647</a>)</li>
<li>See full diff in <a
href="https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici&package-manager=npm_and_yarn&previous-version=6.28.0&new-version=6.28.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@octokit/types](https://github.com/octokit/types.ts) from 17.0.0
to 18.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/octokit/types.ts/releases">@​octokit/types's
releases</a>.</em></p>
<blockquote>
<h2>v18.0.0</h2>
<h1><a
href="https://github.com/octokit/types.ts/compare/v17.0.0...v18.0.0">18.0.0</a>
(2026-08-29)</h1>
<h3>Features</h3>
<ul>
<li>update endpoints with major additions as of 2026-08-24 (<a
href="https://redirect.github.com/octokit/types.ts/issues/723">#723</a>)
(<a
href="https://github.com/octokit/types.ts/commit/c4b93f2fed6515aa00e8dccf290d4ade41c3b4af">c4b93f2</a>)</li>
</ul>
<h3>BREAKING CHANGES</h3>
<ul>
<li>remove deprecated endpoints</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/octokit/types.ts/commit/c4b93f2fed6515aa00e8dccf290d4ade41c3b4af"><code>c4b93f2</code></a>
feat: update endpoints with major additions as of 2026-08-24 (<a
href="https://redirect.github.com/octokit/types.ts/issues/723">#723</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/4d46114afb91cea4590b7b40ea451fb937de08b1"><code>4d46114</code></a>
chore(deps): Temporarily disable docs generation/publish in release
workflow...</li>
<li><a
href="https://github.com/octokit/types.ts/commit/dd020c12a0752953ec91eadc498ea0727298bc53"><code>dd020c1</code></a>
build(deps-dev): remove semantic-release, bump prettier (<a
href="https://redirect.github.com/octokit/types.ts/issues/719">#719</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/8b92916979a122a248bb9807bffdeff4c8e33ea7"><code>8b92916</code></a>
build(deps-dev): bump markdown-it from 14.1.0 to 14.3.0 (<a
href="https://redirect.github.com/octokit/types.ts/issues/717">#717</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/f88ca90fc7f50d349b20b20bd65afc270c5ffc25"><code>f88ca90</code></a>
build(deps-dev): bump lodash-es from 4.17.23 to 4.18.1 (<a
href="https://redirect.github.com/octokit/types.ts/issues/718">#718</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/66f2dd6b844976c03dd868950d5d6340fecf931f"><code>66f2dd6</code></a>
build(deps-dev): bump brace-expansion from 2.0.1 to 2.0.2 (<a
href="https://redirect.github.com/octokit/types.ts/issues/715">#715</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/ce4890d5caa266668e1e4ee089e9cbe3e2f0d029"><code>ce4890d</code></a>
build(deps-dev): bump linkify-it from 5.0.0 to 5.0.2 (<a
href="https://redirect.github.com/octokit/types.ts/issues/716">#716</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/afd965b8f6bf5bdae67fc90a4f4376b5869f7a27"><code>afd965b</code></a>
build(deps-dev): bump npm from 11.6.2 to 11.19.0 (<a
href="https://redirect.github.com/octokit/types.ts/issues/714">#714</a>)</li>
<li><a
href="https://github.com/octokit/types.ts/commit/e9121d4f1b71c55cf78e74a1bd7289b6a73df41d"><code>e9121d4</code></a>
build(deps-dev): bump lodash-es from 4.17.21 to 4.17.23 (<a
href="https://redirect.github.com/octokit/types.ts/issues/700">#700</a>)</li>
<li>See full diff in <a
href="https://github.com/octokit/types.ts/compare/v17.0.0...v18.0.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@octokit/types&package-manager=npm_and_yarn&previous-version=17.0.0&new-version=18.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)
from 4.1.6 to 5.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-dev/vitest/releases">vitest's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.0</h2>
<p>Vitest 5 is officially out! This release focuses on performance and
brings a lot of new features while fixing long-standing bugs. See our <a
href="https://vitest.dev/blog/vitest-5.html">blog post</a> for the
official announcement.</p>
<h3>   🚨 Breaking Changes</h3>
<ul>
<li>Replace <code>loupe.inspect</code> with pretty-format  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Claude Opus 5 (1M context)</strong> and <strong>OpenAI
Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9609">vitest-dev/vitest#9609</a>
<a href="https://github.com/vitest-dev/vitest/commit/3f802da4b"><!-- raw
HTML omitted -->(3f802)<!-- raw HTML omitted --></a></li>
<li>Remove quotes from string values in <code>test.for/each</code> title
<code>$</code> variable (take 2)  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10170">vitest-dev/vitest#10170</a>
<a href="https://github.com/vitest-dev/vitest/commit/04d37e9d7"><!-- raw
HTML omitted -->(04d37)<!-- raw HTML omitted --></a></li>
<li>Default <code>attachmentsDir</code> from
<code>.vitest-attachements/</code> to <code>.vitest/attachments/</code>
 -  by <a
href="https://github.com/MdSadiqMd"><code>@​MdSadiqMd</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10186">vitest-dev/vitest#10186</a>
<a href="https://github.com/vitest-dev/vitest/commit/1ba7338c3"><!-- raw
HTML omitted -->(1ba73)<!-- raw HTML omitted --></a></li>
<li>Remove <code>sequential</code> test/suite options in favor of
<code>concurrent</code>  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a> and
<strong>OpenAI Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10198">vitest-dev/vitest#10198</a>
<a href="https://github.com/vitest-dev/vitest/commit/9229f2edc"><!-- raw
HTML omitted -->(9229f)<!-- raw HTML omitted --></a></li>
<li>Represent locator as an object instead of a string  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10212">vitest-dev/vitest#10212</a>
<a href="https://github.com/vitest-dev/vitest/commit/80f07edf6"><!-- raw
HTML omitted -->(80f07)<!-- raw HTML omitted --></a></li>
<li>Inline <code>expect</code> package  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10221">vitest-dev/vitest#10221</a>
<a href="https://github.com/vitest-dev/vitest/commit/ad16223e7"><!-- raw
HTML omitted -->(ad162)<!-- raw HTML omitted --></a></li>
<li>Remove deprecated entry points  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10222">vitest-dev/vitest#10222</a>
<a href="https://github.com/vitest-dev/vitest/commit/994c6ddb9"><!-- raw
HTML omitted -->(994c6)<!-- raw HTML omitted --></a></li>
<li>Require Node.js 22 and Vite 6.4  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10178">vitest-dev/vitest#10178</a>
<a href="https://github.com/vitest-dev/vitest/commit/3876283e8"><!-- raw
HTML omitted -->(38762)<!-- raw HTML omitted --></a></li>
<li>Fail <code>expect.poll</code> when function didn't resolve in time
 -  by <a href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>
and <strong>OpenAI Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10233">vitest-dev/vitest#10233</a>
<a href="https://github.com/vitest-dev/vitest/commit/4df048c11"><!-- raw
HTML omitted -->(4df04)<!-- raw HTML omitted --></a></li>
<li>Throw an error if hoistable methods are outside the top level scope
 -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10460">vitest-dev/vitest#10460</a>
<a href="https://github.com/vitest-dev/vitest/commit/d0b4fddcb"><!-- raw
HTML omitted -->(d0b4f)<!-- raw HTML omitted --></a></li>
<li><code>toHaveTextContent</code> is strict, add
<code>toMatchTextContent</code> as alternative  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10473">vitest-dev/vitest#10473</a>
<a href="https://github.com/vitest-dev/vitest/commit/18f303079"><!-- raw
HTML omitted -->(18f30)<!-- raw HTML omitted --></a></li>
<li>Don't lookup config file from ancestor directories  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>OpenAI Codex</strong> and <strong>Hiroshi Ogawa</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10428">vitest-dev/vitest#10428</a>
<a href="https://github.com/vitest-dev/vitest/commit/945d9090e"><!-- raw
HTML omitted -->(945d9)<!-- raw HTML omitted --></a></li>
<li>Inline <code>@vitest/runner</code> package, do not publish it
anymore  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10511">vitest-dev/vitest#10511</a>
<a href="https://github.com/vitest-dev/vitest/commit/6d6e46b1e"><!-- raw
HTML omitted -->(6d6e4)<!-- raw HTML omitted --></a></li>
<li>Allow mutating happy-dom/jsdom window object  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenAI Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10373">vitest-dev/vitest#10373</a>
<a href="https://github.com/vitest-dev/vitest/commit/206e8cff8"><!-- raw
HTML omitted -->(206e8)<!-- raw HTML omitted --></a></li>
<li>Expose <code>concurrencyId</code>/<code>workerId</code> on
TestModule's diagnostics, make id 1-based  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10516">vitest-dev/vitest#10516</a>
<a href="https://github.com/vitest-dev/vitest/commit/bdd985433"><!-- raw
HTML omitted -->(bdd98)<!-- raw HTML omitted --></a></li>
<li>Add <code>screenshotDirectory</code> config to
<code>browser.expect.toMatchScreenshot</code>  -  by <a
href="https://github.com/macarie"><code>@​macarie</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10592">vitest-dev/vitest#10592</a>
<a href="https://github.com/vitest-dev/vitest/commit/a60ded0fb"><!-- raw
HTML omitted -->(a60de)<!-- raw HTML omitted --></a></li>
<li>Update <code>@sinonjs/fake-timers</code> and support mocking
<code>Temporal</code>  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenCode
(gpt-5.6-sol)</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10654">vitest-dev/vitest#10654</a>
<a href="https://github.com/vitest-dev/vitest/commit/f8b1532fe"><!-- raw
HTML omitted -->(f8b15)<!-- raw HTML omitted --></a></li>
<li>Remove webdriverio package  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10675">vitest-dev/vitest#10675</a>
<a href="https://github.com/vitest-dev/vitest/commit/5fed68f72"><!-- raw
HTML omitted -->(5fed6)<!-- raw HTML omitted --></a></li>
<li>Clear mocks by default before each test  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10613">vitest-dev/vitest#10613</a>
<a href="https://github.com/vitest-dev/vitest/commit/0f6463bf2"><!-- raw
HTML omitted -->(0f646)<!-- raw HTML omitted --></a></li>
<li>Don't emit localStorage warnings on Node 26, fail gracefully when
worker fails to start  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10293">vitest-dev/vitest#10293</a>
<a href="https://github.com/vitest-dev/vitest/commit/334edef92"><!-- raw
HTML omitted -->(334ed)<!-- raw HTML omitted --></a></li>
<li>Separate config resolution from the server creation  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10554">vitest-dev/vitest#10554</a>
<a href="https://github.com/vitest-dev/vitest/commit/1c0ec3444"><!-- raw
HTML omitted -->(1c0ec)<!-- raw HTML omitted --></a></li>
<li>Inline projects extend the root config by default  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10750">vitest-dev/vitest#10750</a>
<a href="https://github.com/vitest-dev/vitest/commit/fec001ad3"><!-- raw
HTML omitted -->(fec00)<!-- raw HTML omitted --></a></li>
<li>Enable mocking Temporal without fake timers  -  by <a
href="https://github.com/fabon-f"><code>@​fabon-f</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenCode
(gpt-5.6-sol)</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10757">vitest-dev/vitest#10757</a>
<a href="https://github.com/vitest-dev/vitest/commit/ac2d46b42"><!-- raw
HTML omitted -->(ac2d4)<!-- raw HTML omitted --></a></li>
<li>Support nested projects  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10846">vitest-dev/vitest#10846</a>
<a href="https://github.com/vitest-dev/vitest/commit/ec367cf2a"><!-- raw
HTML omitted -->(ec367)<!-- raw HTML omitted --></a></li>
<li>Use <code>&gt;</code> as separator in <code>-t</code>, calculate
<code>only</code> once  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10686">vitest-dev/vitest#10686</a>
<a href="https://github.com/vitest-dev/vitest/commit/a0b20bc86"><!-- raw
HTML omitted -->(a0b20)<!-- raw HTML omitted --></a></li>
<li>Fail the test when an asynchronous assertion is not awaited  -  by
<a href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10868">vitest-dev/vitest#10868</a>
<a href="https://github.com/vitest-dev/vitest/commit/86d4a9da9"><!-- raw
HTML omitted -->(86d4a)<!-- raw HTML omitted --></a></li>
<li>Share the Vite server between inline projects  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10848">vitest-dev/vitest#10848</a>
<a href="https://github.com/vitest-dev/vitest/commit/d87c96ee4"><!-- raw
HTML omitted -->(d87c9)<!-- raw HTML omitted --></a></li>
<li>Parse files statically in vitest list by default  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11088">vitest-dev/vitest#11088</a>
<a href="https://github.com/vitest-dev/vitest/commit/51e949416"><!-- raw
HTML omitted -->(51e94)<!-- raw HTML omitted --></a></li>
<li><strong>benchmark</strong>:
<ul>
<li>Rewrite the public API  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10113">vitest-dev/vitest#10113</a>
<a href="https://github.com/vitest-dev/vitest/commit/19f6e8947"><!-- raw
HTML omitted -->(19f6e)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>browser</strong>:
<ul>
<li>Iframe scale  -  by <a
href="https://github.com/macarie"><code>@​macarie</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9745">vitest-dev/vitest#9745</a>
<a href="https://github.com/vitest-dev/vitest/commit/b639852cc"><!-- raw
HTML omitted -->(b6398)<!-- raw HTML omitted --></a></li>
<li>Enable <code>locators.exact</code> by default  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10430">vitest-dev/vitest#10430</a>
<a href="https://github.com/vitest-dev/vitest/commit/e203202f9"><!-- raw
HTML omitted -->(e2032)<!-- raw HTML omitted --></a></li>
<li>Require <code>sessionId</code> for orchestrator html request  -  by
<a href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenAI Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10522">vitest-dev/vitest#10522</a>
<a href="https://github.com/vitest-dev/vitest/commit/79b7d8fcc"><!-- raw
HTML omitted -->(79b7d)<!-- raw HTML omitted --></a></li>
<li>Save failure screenshots in <code>attachmentsDir</code>  -  by <a
href="https://github.com/macarie"><code>@​macarie</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10917">vitest-dev/vitest#10917</a>
<a href="https://github.com/vitest-dev/vitest/commit/3b5bbd8b4"><!-- raw
HTML omitted -->(3b5bb)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>coverage</strong>:
<ul>
<li><code>include/exclude</code> globs too eager  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9818">vitest-dev/vitest#9818</a>
<a href="https://github.com/vitest-dev/vitest/commit/edacb0fd4"><!-- raw
HTML omitted -->(edacb)<!-- raw HTML omitted --></a></li>
<li>Allow <code>thresholds.perFile</code> to accept an object  -  by <a
href="https://github.com/vladlenskiy"><code>@​vladlenskiy</code></a> and
<a href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10190">vitest-dev/vitest#10190</a>
<a href="https://github.com/vitest-dev/vitest/commit/13b78d98b"><!-- raw
HTML omitted -->(13b78)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>expect</strong>:
<ul>
<li>Fix <code>toThrow(&quot;&quot;)</code> behavior by reverting <a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/6710">#6710</a>
 -  by <a href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9643">vitest-dev/vitest#9643</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/6710">vitest-dev/vitest#6710</a>
<a href="https://github.com/vitest-dev/vitest/commit/6c3e4bdbf"><!-- raw
HTML omitted -->(6c3e4)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>mocker</strong>:
<ul>
<li>Deserialize automock as automock  -  by <a
href="https://github.com/nami8824"><code>@​nami8824</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10192">vitest-dev/vitest#10192</a>
<a href="https://github.com/vitest-dev/vitest/commit/2f892712d"><!-- raw
HTML omitted -->(2f892)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>reporters</strong>:
<ul>
<li><code>blob</code> reporter and <code>--merge-reports</code> default
to <code>.vitest/blob/</code>  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10232">vitest-dev/vitest#10232</a>
<a href="https://github.com/vitest-dev/vitest/commit/d22b029ae"><!-- raw
HTML omitted -->(d22b0)<!-- raw HTML omitted --></a></li>
<li>Write json and junit reporter output files to <code>.vitest</code>
by default  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong>, <strong>OpenCode (gpt-5.6-sol)</strong>
and <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10621">vitest-dev/vitest#10621</a>
<a href="https://github.com/vitest-dev/vitest/commit/58577290a"><!-- raw
HTML omitted -->(58577)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitest-dev/vitest/commit/f441c6fab25e579c5b7dd3dd50538416f415fbae"><code>f441c6f</code></a>
chore: release v5.0.0 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11130">#11130</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/d46a7472266d5bb43595ea51dcdd64ab0f560f12"><code>d46a747</code></a>
fix: treat test.describe as a suite during static collection (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11128">#11128</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/584cf308437069385b0fb905fa3ff7d7b7f65a90"><code>584cf30</code></a>
fix: add a warning if inline project has duplicate plugins due to
unexpected ...</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/f08ce4b7144542af128dcb884150c42074223653"><code>f08ce4b</code></a>
fix: apply queued mocks from doMock() in queue order (fixes <a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10706">#10706</a>)
(<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11127">#11127</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/897f51fd2493046c52ec9539b7d02fe3763bd63e"><code>897f51f</code></a>
chore: release v5.0.0-rc.4 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11107">#11107</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/1339b0655dc4679aeb8f905bacee83b6f76f6b23"><code>1339b06</code></a>
chore(deps): update all non-major dependencies (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11104">#11104</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/51e9494166d8d0108a621fce80c41b6dba760bae"><code>51e9494</code></a>
feat!: parse files statically in vitest list by default (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11088">#11088</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/2122ffdfb42d86c9a2f1238100d6a031312cae32"><code>2122ffd</code></a>
fix: propagate --maxWorkers to projects (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11102">#11102</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/dc10f5f8fb69b026afcf56f8a7a9dd36bd964d73"><code>dc10f5f</code></a>
fix(browser): report the action error when a task times out (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11101">#11101</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/d4fe1986fe334d22940039e815ccdbcc907baa6a"><code>d4fe198</code></a>
feat: promote clearCache out of experimental (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11086">#11086</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=vitest&package-manager=npm_and_yarn&previous-version=4.1.6&new-version=5.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Pins GitHub Actions `uses:` references in `github/accessibility-scanner`
to immutable commit SHAs.

## Summary

| Metric | Count |
| --- | ---: |
| Files changed | 3 |
| Files scanned | 2 |
| Refs found | 3 |
| Refs pinned | 3 |
| Skipped refs | 0 |
| Warnings | 0 |
| Errors | 0 |

## Why

Pinning actions to full commit SHAs prevents future tag or branch
retargeting from changing workflow behavior without review.

## Reviewer notes

- Original refs are preserved in inline comments when possible.
- Pin comments use the Dependabot-compatible original-ref style.
- Branch refs were allowed and pinned to their current HEAD; review
mutable-branch pins carefully.
- No minimum action age was enforced for this run.

## Pinned refs

| Location | Before | After | Resolved as |
| --- | --- | --- | --- |
| `.github/workflows/lint.yml:26` | `actions/checkout@v7` |
`actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` |
| `.github/workflows/lint.yml:29` | `actions/setup-node@v7` |
`actions/setup-node@820762786026740c76f36085b0efc47a31fe5020` | `tag` |
| `.github/workflows/test.yml:34` | `actions/checkout@v7` |
`actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` |

## Dependabot

- Added a 7-day cooldown (`cooldown: default-days: 7`) to the existing
`github-actions` Dependabot configuration.
- The cooldown delays applying a newly published action release for 7
days, reducing exposure to a compromised or broken release while keeping
you SHA-pinned.

---

Generated by pinner 0.1.0.
Bumps the github-actions group with 1 update in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby).


Updates `ruby/setup-ruby` from 1.321.0 to 1.324.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](ruby/setup-ruby@95ef2b0...a0102e0)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.324.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
…ub-actions group across 1 directory (#271)

Bumps the github-actions group with 1 update in the / directory:
[ruby/setup-ruby](https://github.com/ruby/setup-ruby).

Updates `ruby/setup-ruby` from 1.321.0 to 1.324.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ruby/setup-ruby/releases">ruby/setup-ruby's
releases</a>.</em></p>
<blockquote>
<h2>v1.324.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add truffleruby-40.0.0,truffleruby+graalvm-40.0.0 by <a
href="https://github.com/ruby-builder-bot"><code>@​ruby-builder-bot</code></a>
in <a
href="https://redirect.github.com/ruby/setup-ruby/pull/938">ruby/setup-ruby#938</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ruby/setup-ruby/compare/v1.323.0...v1.324.0">https://github.com/ruby/setup-ruby/compare/v1.323.0...v1.324.0</a></p>
<h2>v1.323.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update CRuby releases on Windows by <a
href="https://github.com/ruby-builder-bot"><code>@​ruby-builder-bot</code></a>
in <a
href="https://redirect.github.com/ruby/setup-ruby/pull/937">ruby/setup-ruby#937</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ruby/setup-ruby/compare/v1.322.0...v1.323.0">https://github.com/ruby/setup-ruby/compare/v1.322.0...v1.323.0</a></p>
<h2>v1.322.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add ruby-4.0.7 by <a
href="https://github.com/ruby-builder-bot"><code>@​ruby-builder-bot</code></a>
in <a
href="https://redirect.github.com/ruby/setup-ruby/pull/936">ruby/setup-ruby#936</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ruby/setup-ruby/compare/v1.321.0...v1.322.0">https://github.com/ruby/setup-ruby/compare/v1.321.0...v1.322.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ruby/setup-ruby/commit/a0102e0972be65f351c307e2d64b9314a57c8073"><code>a0102e0</code></a>
Add truffleruby-40.0.0,truffleruby+graalvm-40.0.0</li>
<li><a
href="https://github.com/ruby/setup-ruby/commit/984c0c890880bbf811283d6f09c4607c62d210a4"><code>984c0c8</code></a>
Update CRuby releases on Windows</li>
<li><a
href="https://github.com/ruby/setup-ruby/commit/bec3f19a76460dbe12f60def7d1a77585f07516c"><code>bec3f19</code></a>
Add ruby-4.0.7</li>
<li>See full diff in <a
href="https://github.com/ruby/setup-ruby/compare/95ef2b042f9d7a56d8268cba8559e2842e2ad01b...a0102e0972be65f351c307e2d64b9314a57c8073">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ruby/setup-ruby&package-manager=github_actions&previous-version=1.321.0&new-version=1.324.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
Bumps the github-actions group with 1 update in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby).


Updates `ruby/setup-ruby` from 1.324.0 to 1.327.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](ruby/setup-ruby@a0102e0...1459426)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.327.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: abdulahmad307 <204748719+abdulahmad307@users.noreply.github.com>
Co-authored-by: abdulahmad307 <204748719+abdulahmad307@users.noreply.github.com>
This is clone of [@mvanhorns](https://github.com/mvanhorn)'s PR
#223 - opened with
copilot. We need the PR opened in this repo directly so the appropriate
tests and validations can run before we merge.

Scans can start before a page’s client-rendered content is ready. This
change lets each URL specify elements that must be visible before
scanning begins.

- **Configuration:** Add optional `waitForSelectors` to `url_configs`;
validate that it’s an array of strings.
- **Scanning:** Wait up to 30 seconds for each selector after navigation
and before collecting findings.
- **Example:**
  ```json

[{"url":"https://example.com","waitForSelectors":["#app","[data-ready]"]}]
  ```

Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 19:27
@abdulahmad307
abdulahmad307 requested a review from a team as a code owner October 5, 2026 19:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Copilot was unable to run its full agentic suite in this review.

Copilot review overview

Review effort: Lite
Findings: 1 Medium severity · 5 Low severity

Open (6)
What changed in this PR

Updates the accessibility scanner to support waiting for page readiness via waitForSelectors in url_configs, along with dependency bumps, GitHub Action hardening, and expanded documentation/tests.

Changes:

  • Add waitForSelectors support end-to-end (types, input validation, runtime waiting, and tests).
  • Improve plugin documentation (including NPM-hosted plugin allowlisting guidance) and add an issue form.
  • Bump dependencies and pin GitHub Action workflow dependencies to SHAs.
File Description
sites/​site-with-errors/​Gemfile.lock Updates rack version in the example site lockfile.
package.json Bumps JS deps (notably @octokit/types and vitest).
action.yml Documents waitForSelectors for the published action input.
README.md Updates demo link and documents waitForSelectors usage in examples/table.
PLUGINS.md Expands plugin docs (local + NPM-hosted, allowlisting flow).
.github/​workflows/​test.yml Pins actions/checkout and updates ruby/setup-ruby ref.
.github/​workflows/​lint.yml Pins actions/checkout and actions/setup-node to SHAs.
.github/​dependabot.yml Adds a Dependabot cooldown configuration block.
.github/​actions/​find/​tests/​index.test.ts Adds tests for url_configs.waitForSelectors pass-through + validation.
.github/​actions/​find/​tests/​findForUrl.test.ts Adds page-load/cleanup behavior tests around selector waiting.
.github/​actions/​find/​src/​types.d.ts Extends UrlConfig type with waitForSelectors.
.github/​actions/​find/​src/​index.ts Validates waitForSelectors input shape in url_configs.
.github/​actions/​find/​src/​findForUrl.ts Implements selector waiting and strengthens resource cleanup logic.
.github/​actions/​find/​action.yml Documents waitForSelectors for the internal find action.
.github/​actions/​find/​README.md Documents url_configs.waitForSelectors behavior and timeout.
.github/​ISSUE_TEMPLATE/​allowlist-npm-plugin-request.yml Adds an issue form for NPM plugin allowlisting requests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread PLUGINS.md
Comment thread .github/ISSUE_TEMPLATE/allowlist-npm-plugin-request.yml
Comment thread .github/ISSUE_TEMPLATE/allowlist-npm-plugin-request.yml
Comment thread .github/ISSUE_TEMPLATE/allowlist-npm-plugin-request.yml
Comment thread .github/workflows/test.yml Outdated
Comment thread PLUGINS.md
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@abdulahmad307

abdulahmad307 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

passing workflows:

all copilot comments are minor things like code-comments, hyphenation usage, etc...

@github github deleted a comment from Copilot AI Oct 6, 2026
abdulahmad307 and others added 9 commits October 6, 2026 12:25
…ub-actions group across 1 directory (#272)

Bumps the github-actions group with 1 update in the / directory:
[ruby/setup-ruby](https://github.com/ruby/setup-ruby).

Updates `ruby/setup-ruby` from 1.324.0 to 1.327.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ruby/setup-ruby/releases">ruby/setup-ruby's
releases</a>.</em></p>
<blockquote>
<h2>v1.327.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update CRuby releases on Windows by <a
href="https://github.com/ruby-builder-bot"><code>@​ruby-builder-bot</code></a>
in <a
href="https://redirect.github.com/ruby/setup-ruby/pull/942">ruby/setup-ruby#942</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ruby/setup-ruby/compare/v1.326.0...v1.327.0">https://github.com/ruby/setup-ruby/compare/v1.326.0...v1.327.0</a></p>
<h2>v1.326.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add ruby-3.4.11 by <a
href="https://github.com/ruby-builder-bot"><code>@​ruby-builder-bot</code></a>
in <a
href="https://redirect.github.com/ruby/setup-ruby/pull/940">ruby/setup-ruby#940</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ruby/setup-ruby/compare/v1.325.0...v1.326.0">https://github.com/ruby/setup-ruby/compare/v1.325.0...v1.326.0</a></p>
<h2>v1.325.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add jruby-10.0.7.0,jruby-10.1.2.0 by <a
href="https://github.com/ruby-builder-bot"><code>@​ruby-builder-bot</code></a>
in <a
href="https://redirect.github.com/ruby/setup-ruby/pull/939">ruby/setup-ruby#939</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/ruby/setup-ruby/compare/v1.324.0...v1.325.0">https://github.com/ruby/setup-ruby/compare/v1.324.0...v1.325.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ruby/setup-ruby/commit/14594264cd68ce8a2345dd349bc3d138a4ef85c8"><code>1459426</code></a>
Update CRuby releases on Windows</li>
<li><a
href="https://github.com/ruby/setup-ruby/commit/762794c140bbeda0f1224786aa33b4b46783a6c1"><code>762794c</code></a>
Add ruby-3.4.11</li>
<li><a
href="https://github.com/ruby/setup-ruby/commit/e8944e80fb94b20106697132f8c20c665fab29e9"><code>e8944e8</code></a>
Add jruby-10.0.7.0,jruby-10.1.2.0</li>
<li>See full diff in <a
href="https://github.com/ruby/setup-ruby/compare/a0102e0972be65f351c307e2d64b9314a57c8073...14594264cd68ce8a2345dd349bc3d138a4ef85c8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ruby/setup-ruby&package-manager=github_actions&previous-version=1.324.0&new-version=1.327.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.4.
- [Commits](WebReflection/flatted@v3.3.3...v3.4.4)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.7 to 5.0.12.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.7...v5.0.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.28.1 to 6.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.28.1...v6.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion)
from 5.0.7 to 5.0.12.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/f3410159d768f56c9d9f4511d3e1b46425fc1099"><code>f341015</code></a>
5.0.12</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96"><code>33a5ef1</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/82479277b90f2f86263e946f9ff89689b3734568"><code>8247927</code></a>
5.0.11</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c"><code>935d78f</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/df7682f386cdf2d7fef6067bc78ed70d824e1f3f"><code>df7682f</code></a>
5.0.10</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/1ade9de71f3a8719c82c61a7977121067bb55b02"><code>1ade9de</code></a>
npm run format</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"><code>6735c94</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/4e7046543469d31e2b324b1bf14d8606d74f7f18"><code>4e70465</code></a>
chore: ensure prettier formatting (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/154">#154</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/fd7a5e34cfcd9a9df6e0ee17817807104392ecff"><code>fd7a5e3</code></a>
Bump ip-address from 10.2.0 to 10.4.0 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/152">#152</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/1790143e9aa05279b087b94104c03d3cb775e2e4"><code>1790143</code></a>
Bump uuid and <code>@​tapjs/processinfo</code> (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/120">#120</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/juliangruber/brace-expansion/compare/v5.0.7...v5.0.12">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=brace-expansion&package-manager=npm_and_yarn&previous-version=5.0.7&new-version=5.0.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from
1.2.1 to 1.2.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/7rulnik/source-map-js/releases">source-map-js's
releases</a>.</em></p>
<blockquote>
<h2>v1.2.2</h2>
<ul>
<li>
<p>Fix crash when executing in browser with CSP script-src that don't
permit unsafe-eval (<a
href="https://redirect.github.com/7rulnik/source-map-js/pull/29">#29</a>)
<a href="https://github.com/xfournet"><code>@​xfournet</code></a></p>
</li>
<li>
<p>Fix denial of service from malicious indexed source maps
(CVE-2026-93749) (<a
href="https://redirect.github.com/7rulnik/source-map-js/pull/79">#79</a>)</p>
<p>Reported by <a
href="https://github.com/waydeshi"><code>@​waydeshi</code></a> in <a
href="https://redirect.github.com/7rulnik/source-map-js/issues/76">#76</a>.
A fix was also proposed by <a
href="https://github.com/aniebiet"><code>@​aniebiet</code></a> in <a
href="https://redirect.github.com/7rulnik/source-map-js/pull/78">#78</a>.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md">source-map-js's
changelog</a>.</em></p>
<blockquote>
<h2>1.2.2</h2>
<ul>
<li>
<p>Fix crash when executing in browser with CSP script-src that don't
permit unsafe-eval (<a
href="https://redirect.github.com/7rulnik/source-map-js/pull/29">#29</a>)
<a href="https://github.com/xfournet"><code>@​xfournet</code></a></p>
</li>
<li>
<p>Fix denial of service from malicious indexed source maps
(CVE-2026-93749) (<a
href="https://redirect.github.com/7rulnik/source-map-js/pull/79">#79</a>)</p>
<p>Reported by <a
href="https://github.com/waydeshi"><code>@​waydeshi</code></a> in <a
href="https://redirect.github.com/7rulnik/source-map-js/issues/76">#76</a>.
A fix was also proposed by <a
href="https://github.com/aniebiet"><code>@​aniebiet</code></a> in <a
href="https://redirect.github.com/7rulnik/source-map-js/pull/78">#78</a>.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/7rulnik/source-map-js/commit/0a1d334fd1e55a47df97fcd60a7915d46df3b08a"><code>0a1d334</code></a>
1.2.2</li>
<li><a
href="https://github.com/7rulnik/source-map-js/commit/4c6fa26d77419bd8e48ec92844866cce7d9ae739"><code>4c6fa26</code></a>
Update changelog</li>
<li><a
href="https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016"><code>cf76580</code></a>
Fix denial of service from malicious indexed source maps
(CVE-2026-93749) (<a
href="https://redirect.github.com/7rulnik/source-map-js/issues/79">#79</a>)</li>
<li><a
href="https://github.com/7rulnik/source-map-js/commit/7899a86615c630f4fc220273ff9fe2e8e49a56df"><code>7899a86</code></a>
Fix crash when executing browser with CSP script-src that don't permit
unsafe...</li>
<li>See full diff in <a
href="https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=source-map-js&package-manager=npm_and_yarn&previous-version=1.2.1&new-version=1.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to
3.4.4.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/WebReflection/flatted/commit/e6f5ca700c4ca8104a6a83472c8219e267bd5e84"><code>e6f5ca7</code></a>
3.4.4</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/47f14fac0b1a41989f216b0cda4c50596ca339f6"><code>47f14fa</code></a>
removed E_STRICT from PHP</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/40505688464c49fe6374e7bc4cdd9bd2e9e6f330"><code>4050568</code></a>
fixced go-lang issues in CI</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/4303f4db38ba0ba8d5e2ed6e9689cefc74c46b63"><code>4303f4d</code></a>
Merge pull request <a
href="https://redirect.github.com/WebReflection/flatted/issues/101">#101</a>
from mfinelli/gocriticfixes</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/106735b609c15df51539a0d7c0a270182efd904c"><code>106735b</code></a>
updated package-lock.json</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/670a1bdf9dcfba02111c3034294366f10696fb53"><code>670a1bd</code></a>
3.4.3</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/50a61a90ea5ca64c114f0aa040ad127e3a97feff"><code>50a61a9</code></a>
Fix <a
href="https://redirect.github.com/WebReflection/flatted/issues/104">#104</a>
- allow <code>null</code> as replacer value</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/8aa64f460cf0c4dac9cc214c831aade28f8f2c6e"><code>8aa64f4</code></a>
solved crytical errors over dependencies</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/b85577f39ff85959d02e8862cc0dde8114b43762"><code>b85577f</code></a>
Fix go-critic errors</li>
<li><a
href="https://github.com/WebReflection/flatted/commit/bb8c63cea5befd4315519cb4458c6fc07bb9cf7b"><code>bb8c63c</code></a>
Merge pull request <a
href="https://redirect.github.com/WebReflection/flatted/issues/100">#100</a>
from WebReflection/WebReflection-patch-1</li>
<li>Additional commits viewable in <a
href="https://github.com/WebReflection/flatted/compare/v3.3.3...v3.4.4">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=flatted&package-manager=npm_and_yarn&previous-version=3.3.3&new-version=3.4.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>
Bumps [undici](https://github.com/nodejs/undici) from 6.28.1 to 6.29.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nodejs/undici/releases">undici's
releases</a>.</em></p>
<blockquote>
<h2>v6.29.0</h2>
<h2>What's Changed</h2>
<ul>
<li>[v6.x] fix(retry): settle exposed body on terminal failure by <a
href="https://github.com/mcollina"><code>@​mcollina</code></a> in <a
href="https://redirect.github.com/nodejs/undici/pull/5778">nodejs/undici#5778</a></li>
<li>Backport upgrade diagnostics lifecycle fixes to v6.x by <a
href="https://github.com/BridgeAR"><code>@​BridgeAR</code></a> in <a
href="https://redirect.github.com/nodejs/undici/pull/5833">nodejs/undici#5833</a></li>
<li>test: synchronize the issue-3356 body timeout by <a
href="https://github.com/BridgeAR"><code>@​BridgeAR</code></a> in <a
href="https://redirect.github.com/nodejs/undici/pull/5834">nodejs/undici#5834</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/nodejs/undici/compare/v6.28.1...v6.29.0">https://github.com/nodejs/undici/compare/v6.28.1...v6.29.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodejs/undici/commit/e1d0501f8705253c32a8b40bdb3fc0474167c92d"><code>e1d0501</code></a>
Bumped v6.29.0 (<a
href="https://redirect.github.com/nodejs/undici/issues/5888">#5888</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/57ac4dea0d38a0bf068eaf7eda0b8cb9e86f6a99"><code>57ac4de</code></a>
test: synchronize the issue-3356 body timeout (<a
href="https://redirect.github.com/nodejs/undici/issues/5834">#5834</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/6d441740cf5dad3455a7a7881451e802f10b0b2a"><code>6d44174</code></a>
Backport upgrade diagnostics lifecycle fixes to v6.x (<a
href="https://redirect.github.com/nodejs/undici/issues/5833">#5833</a>)</li>
<li><a
href="https://github.com/nodejs/undici/commit/2a91fc828ecc51865fe7d77376e5f676d030769b"><code>2a91fc8</code></a>
fix(retry): settle exposed body on terminal failure (<a
href="https://redirect.github.com/nodejs/undici/issues/5778">#5778</a>)</li>
<li>See full diff in <a
href="https://github.com/nodejs/undici/compare/v6.28.1...v6.29.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici&package-manager=npm_and_yarn&previous-version=6.28.1&new-version=6.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github/accessibility-scanner/network/alerts).

</details>
@abdulahmad307
abdulahmad307 merged commit 5317f29 into v3 Oct 6, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants