Repository navigation
fix(deps): update prod minor+patch - #106
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/prod-minor+patch
branch
16 times, most recently
from
October 5, 2026 13:32
93269e0 to
165013b
Compare
renovate
Bot
force-pushed
the
renovate/prod-minor+patch
branch
4 times, most recently
from
October 7, 2026 16:10
ece5410 to
a78b117
Compare
renovate
Bot
force-pushed
the
renovate/prod-minor+patch
branch
from
October 8, 2026 11:41
a78b117 to
24a08db
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.12.0→^2.13.0^5.103.2→^5.104.1^3.31.3→^3.31.4^3.31.3→^3.31.4^3.31.3→^3.31.4^3.31.3→^3.31.4^3.31.3→^3.31.4^3.31.3→^3.31.4^11.0.24→^11.0.25^18.0.13→^18.0.14^3.23.2→^3.24.4^1.42.5→^1.42.6^10.0.1→^10.0.2^4.18.14→^4.18.16^2.17.7→^2.18.0^8.21.3→^8.22.0Release Notes
reduxjs/redux-toolkit (@reduxjs/toolkit)
v2.13.0Compare Source
This feature release updates our build tooling to TSDown and PNPM, adds official TypeScript 7 support, and includes a long list of bugfixes across RTK Query,
createAsyncThunk,createEntityAdapter, andcombineSlices.Changelog
Build Tooling Updates
We've fully modernizing modernized our build tooling across all of the Redux repos. That included switching from Yarn to PNPM, ESLint to Oxlint, Prettier to Oxfmt, and TSUp to TSDown.
The part that matters for users is that we now build the package with TSDown instead of
tsup. The package layout,exportsdefinitions, and exported APIs are all unchanged from 2.12. We've checked the new build withattw, and verified that CJS and ESM entry points load in both dev and prod builds, and that thelegacy-esmartifacts still target ES2017. The contents of the bundles do look a bit different (smaller CJS artifacts, slightly different helper output in thelegacy-esmfiles). If you see any behavior differences that look build-related, please file an issue!This is also our first release published via the updated PNPM-based workflow, still using NPM Trusted Publishing. We've also added
pkg.pr.newpreviews for every commit, so you can try out a PR build before it's released.Docs Updates
We've shipped a new combined Redux libraries docs site! The core docs site at https://redux.js.org now contains the docs for all of our libraries: Redux core and usage guides, Redux Toolkit, React Redux, and Reselect. The prior standalone docs sites for RTK, R-R, and Reselect now redirect to their respective sections of the combined docs. We've also done a major cleanup pass on the docs, deduplicating pages that had similarities (like the Next.js or RTK2 migration pages that lived in both the core and RTK docs), and updating outdated content (modernizing example code snippets, deleting dead links, and making RTK and hooks the default patterns shown). The RTK content now lives at https://redux.js.org/toolkit/ .
TypeScript 7 Support
TS 7.0 (the native Go port) is now out! We fixed the remaining type errors in RTK when checked by TS 7.0 and 7.1, and TS 7.0 is now part of our CI test matrix.
Per our TS support policy of matching DefinitelyTyped's support window, we've also updated our support matrix to TS 5.6+. As always, RTK may still work with earlier versions, but we no longer test against them.
RTK Query Fixes
useQueryState(and thususeQuery) was passing a new inline selector touseSelectoron every render, and also reading the store directly during render. The selector is now memoized, and the direct store read is gone. This also fixes a bug whereisSuccesscould flip fromfalsetotrueon an unrelated re-render while a query was refetching after an error.isSuccessnow correctly staysfalsein that case.datanow reflects cache updates made viaupdateQueryDatawhile a refetch is in flight, instead of showing the previous result.Polling now reads the current cache state when each poll fires, rather than the state at the time the poll was scheduled. This means
skipPollingIfUnfocusedrespects focus loss that happens after scheduling, and polls stop if their cache entry was removed.We fixed a race where a duplicate query request rejected by the thunk condition could cause queued tag invalidations to run too early and be lost, leaving stale data in the cache.
Tags with falsy ids like
0now invalidate and clean up correctly.Lazy query hooks now re-subscribe correctly when effects restart while the hook state is preserved, such as with Fast Refresh or
<Activity>.Infinite queries no longer trigger
onQueryStartedwhen fetching past the end of the list, and the infinite query hook result type now includes the page error flags.fetchBaseQueryonly treats a URL as absolute if it starts with a scheme.We also fixed an error when rehydrating state for an endpoint name that has no definition.
Other Fixes
createAsyncThunkno longer swallows aborts that happen before thependingaction is dispatched, and now correctly setsrejectedWithValuewhenrejectWithValueis called with a falsy payload.createEntityAdapter'ssetAllnow keeps the last item when given duplicate IDs, matchingsetMany. The sorted adapter'supdateManynow merges multiple updates for the same ID before applying them.combineSlicesnow keeps its internal state proxy cache per instance, so multiple combined reducers no longer interfere with each other.The immutability check middleware now handles circular references in state.
The dynamic middleware now caches its composed middleware chains when the list of middleware hasn't changed.
What's Changed
pkg.pr.newby @aryaemami59 in #5256entityAdapter):setAllwith duplicate IDs keeps last occurrence (consistent withsetMany) by @JSap0914 in #5321createAsyncThunkaborts that happen before pending by @chatman-media in #5314useRef<T | undefined>(undefined)usages in RTK Query hooks by @DucMinhNe in #5315onQueryStartedfrom triggering at end-of-list by @joseph0926 in #5182remark-typescript-toolsand update to TS7 by @markerikson in #5390rejectedWithValuefor falsyrejectWithValuepayloads by @dfedoryshchev in #5395immutableStateInvariantMiddlewareby @hamed-bavar in #5433useQueryStateandisSuccessduring refetch-after-error by @markerikson in #5456Full Changelog: reduxjs/redux-toolkit@v2.12.0...v2.13.0
TanStack/query (@tanstack/react-query)
v5.104.1Compare Source
Patch Changes
v5.104.0Compare Source
Minor Changes
5279b05- Build projects with Vite 8Patch Changes
5279b05]:v5.103.3Compare Source
Patch Changes
1c9693e- fix(codemods): avoid copying unnecessary files from codemods projectueberdosis/tiptap (@tiptap/core)
v3.31.4Compare Source
@tiptap/extension-mathematics
Patch Changes
@tiptap/core
Patch Changes
TypeErrorthrown when the source editor is destroyed right after dragging content into another editor.splitBlockno longer throwsTransformError: Inserted content deeper than insertion positionwhen the selection spans block boundaries (for example from the start of one paragraph into another block, or across an isolating node). The command now returnsfalsewhen the split is not possible.:::name {…} :::) indented by up to 3 spaces are now tokenized, matching CommonMark indentation rules for block constructs.&#​39;,') are now decoded when parsing markdown, instead of showing up as literal text in the editor.role="textbox"aftersetOptions()wheneditorProps.attributesis set. Before, a re-render in React replaced the default role with the user attributes. Attributes passed as a function now get the default role as well.parseMarkdownandrenderMarkdownto the configured extension so hooks can readthis.optionsandthis.namewithout an Editor.keepOnSplit: falsenow reset on the new item, not on the one that keeps the text.contentDOMno longer ignore selection mutations, so ProseMirror moves the caret back to a valid position when the browser places it inside the node view.@tiptap/markdown
Patch Changes
parseMarkdownandrenderMarkdownto the configured extension so hooks can readthis.optionsandthis.namewithout an Editor.@tiptap/extension-code
Patch Changes
@tiptap/extension-table
Patch Changes
colspan="1"androwspan="1"attributes. Cells that actually span still render them, matching how prosemirror-tables serializes spans.@tiptap/extension-list
Patch Changes
@tiptap/extension-collaboration-caret
Patch Changes
@tiptap/extension-highlight
Patch Changes
@tiptap/extension-text-align
Patch Changes
@tiptap/extension-text-style
Patch Changes
@tiptap/extension-link
Patch Changes
@tiptap/react
Patch Changes
@tiptap/static-renderer
Patch Changes
<audio>and<video>with a closing tag instead of self-closing them, so browsers no longer nest the following content inside the first audio element.renderHTMLreturns several nested child elements no longer adds stray commas between them in the HTML string output.@tiptap/extension-collaboration
Patch Changes
@tiptap/vue-2
Patch Changes
@tiptap/vue-3
Patch Changes
avoidwork/filesize.js (filesize)
v11.0.25Compare Source
#355#353#352#351#350#349#348#347#346#354versatica/mediasoup-client (mediasoup-client)
v3.24.4Compare Source
What's Changed
Full Changelog: versatica/mediasoup-client@3.24.3...3.24.4
v3.24.3Compare Source
What's Changed
transport.produce()ortransport.produceData()fails by @ibc in #390New Contributors
Full Changelog: versatica/mediasoup-client@3.24.1...3.24.3
v3.24.1Compare Source
Full Changelog: versatica/mediasoup-client@3.24.0...3.24.1
v3.24.0Compare Source
Full Changelog: versatica/mediasoup-client@3.23.2...3.24.0
gpbl/react-day-picker (react-day-picker)
v10.0.2Compare Source
Patch Changes
#3010
19033b4Thanks @gpbl! - fix: preserve focus when controlled month changes replace the focused day.#3020
bf1947aThanks @amanokh! - fix: import date-fns functions and DayPicker locales from their subpaths#3007
e07f143Thanks @huuyafwww! - fix: avoid loading all date-fns locales when importing a locale subpath.DayPicker follows Semantic Versioning. See the Releases page on Github for the complete list of changes, diffs and contributors, or the list of versions published on npm.
petyosi/react-virtuoso (react-virtuoso)
v4.18.16Compare Source
Patch Changes
b7238f3Thanks @cpruijsen! - MapskipAnimationFrameInResizeObserverthrough TableVirtuoso's urx optional props so the table resize observer consumes it instead of leaving the leftover prop on the scroller DOM.apostrophecms/apostrophe (sanitize-html)
v2.18.0Compare Source
Adds
loggeroption: pass any console-shaped object, withdebug,info,warnanderrormethods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.Fixes
allowedSchemesByTagis now applied tosrcsetandimagesrcsetURLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the globalallowedSchemesand ignored a tag-specific scheme allowlist. Thanks tospokodev for the fix.
sanitize-htmlbegan escaping any markup preserved inside a disallowed iframe tag, which was a changein behavior due to an upstream change in
htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but alsofully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
the fix.
Security
When
metawas allowed together with itshttp-equivandcontentattributes, the destination URL of a<meta http-equiv="refresh" content="0;url=...">was never checked againstallowedSchemes, because it is embedded incontentrather than being an attribute of its own. Sojavascript:,data:and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case ofurl=, and checked againstallowedSchemes(orallowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, thecontentattribute is removed.contenton othermetaelements is unchanged. The default configuration does not allowmetaand was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).Thanks to adrbogacz for reporting the vulnerability.
When
noscriptis listed innonTextTags, the discarded region could end too early. Browsers with scripting enabled treat<noscript>content as raw text up to the first</noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside<noscript>closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the<noscript>element, while implied closes of othernonTextTagssuch as<option>behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).Thanks to joaquiniglesiaslug for reporting the vulnerability.
The check that drops SVG animation elements (
animate,animateColor,animateMotion,animateTransform,set) when they retarget a URL attribute such ashrefcompared the full tag name, so a namespace-prefixed spelling likesvg:animatewas not recognized when such tags were allowed (for example withallowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to ajavascript:URL after sanitization. The element andattributeNameare now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.
websockets/ws (ws)
v8.22.0Compare Source
Features
protocolsoption (8b918b0).Bug fixes
websocket.close()with invalid arguments no longer transitions thestate to
WebSocket.CLOSING(#2337).Configuration
📅 Schedule: (in timezone Europe/Lisbon)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.