Skip to content

fix(deps): update prod minor+patch - #106

Merged
h8d13 merged 1 commit into
masterfrom
renovate/prod-minor+patch
Oct 8, 2026
Merged

h8d13 merged 1 commit into
masterfrom
renovate/prod-minor+patch

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@reduxjs/toolkit (source) ^2.12.0 → ^2.13.0 age confidence
@tanstack/react-query (source) ^5.103.2 → ^5.104.1 age confidence
@tiptap/core (source) ^3.31.3 → ^3.31.4 age confidence
@tiptap/extension-emoji (source) ^3.31.3 → ^3.31.4 age confidence
@tiptap/pm (source) ^3.31.3 → ^3.31.4 age confidence
@tiptap/react (source) ^3.31.3 → ^3.31.4 age confidence
@tiptap/starter-kit (source) ^3.31.3 → ^3.31.4 age confidence
@tiptap/suggestion (source) ^3.31.3 → ^3.31.4 age confidence
filesize (source) ^11.0.24 → ^11.0.25 age confidence
marked (source) ^18.0.13 → ^18.0.14 age confidence
mediasoup-client (source) ^3.23.2 → ^3.24.4 age confidence
prosemirror-view ^1.42.5 → ^1.42.6 age confidence
react-day-picker (source) ^10.0.1 → ^10.0.2 age confidence
react-virtuoso (source) ^4.18.14 → ^4.18.16 age confidence
sanitize-html (source) ^2.17.7 → ^2.18.0 age confidence
ws ^8.21.3 → ^8.22.0 age confidence

Release Notes

reduxjs/redux-toolkit (@​reduxjs/toolkit)

v2.13.0

Compare Source

This feature release updates our build tooling to TSDown and PNPM, adds official TypeScript 7 support, and includes a long list of bugfixes across RTK Query, createAsyncThunk, createEntityAdapter, and combineSlices.

Changelog

Build Tooling Updates

We've fully modernizing modernized our build tooling across all of the Redux repos. That included switching from Yarn to PNPM, ESLint to Oxlint, Prettier to Oxfmt, and TSUp to TSDown.

The part that matters for users is that we now build the package with TSDown instead of tsup. The package layout, exports definitions, and exported APIs are all unchanged from 2.12. We've checked the new build with attw, and verified that CJS and ESM entry points load in both dev and prod builds, and that the legacy-esm artifacts still target ES2017. The contents of the bundles do look a bit different (smaller CJS artifacts, slightly different helper output in the legacy-esm files). If you see any behavior differences that look build-related, please file an issue!

This is also our first release published via the updated PNPM-based workflow, still using NPM Trusted Publishing. We've also added pkg.pr.new previews for every commit, so you can try out a PR build before it's released.

Docs Updates

We've shipped a new combined Redux libraries docs site! The core docs site at https://redux.js.org now contains the docs for all of our libraries: Redux core and usage guides, Redux Toolkit, React Redux, and Reselect. The prior standalone docs sites for RTK, R-R, and Reselect now redirect to their respective sections of the combined docs. We've also done a major cleanup pass on the docs, deduplicating pages that had similarities (like the Next.js or RTK2 migration pages that lived in both the core and RTK docs), and updating outdated content (modernizing example code snippets, deleting dead links, and making RTK and hooks the default patterns shown). The RTK content now lives at https://redux.js.org/toolkit/ .

TypeScript 7 Support

TS 7.0 (the native Go port) is now out! We fixed the remaining type errors in RTK when checked by TS 7.0 and 7.1, and TS 7.0 is now part of our CI test matrix.

Per our TS support policy of matching DefinitelyTyped's support window, we've also updated our support matrix to TS 5.6+. As always, RTK may still work with earlier versions, but we no longer test against them.

RTK Query Fixes

useQueryState (and thus useQuery) was passing a new inline selector to useSelector on every render, and also reading the store directly during render. The selector is now memoized, and the direct store read is gone. This also fixes a bug where isSuccess could flip from false to true on an unrelated re-render while a query was refetching after an error. isSuccess now correctly stays false in that case.

data now reflects cache updates made via updateQueryData while a refetch is in flight, instead of showing the previous result.

Polling now reads the current cache state when each poll fires, rather than the state at the time the poll was scheduled. This means skipPollingIfUnfocused respects focus loss that happens after scheduling, and polls stop if their cache entry was removed.

We fixed a race where a duplicate query request rejected by the thunk condition could cause queued tag invalidations to run too early and be lost, leaving stale data in the cache.

Tags with falsy ids like 0 now invalidate and clean up correctly.

Lazy query hooks now re-subscribe correctly when effects restart while the hook state is preserved, such as with Fast Refresh or <Activity>.

Infinite queries no longer trigger onQueryStarted when fetching past the end of the list, and the infinite query hook result type now includes the page error flags.

fetchBaseQuery only treats a URL as absolute if it starts with a scheme.

We also fixed an error when rehydrating state for an endpoint name that has no definition.

Other Fixes

createAsyncThunk no longer swallows aborts that happen before the pending action is dispatched, and now correctly sets rejectedWithValue when rejectWithValue is called with a falsy payload.

createEntityAdapter's setAll now keeps the last item when given duplicate IDs, matching setMany. The sorted adapter's updateMany now merges multiple updates for the same ID before applying them.

combineSlices now keeps its internal state proxy cache per instance, so multiple combined reducers no longer interfere with each other.

The immutability check middleware now handles circular references in state.

The dynamic middleware now caches its composed middleware chains when the list of middleware hasn't changed.

What's Changed

Full Changelog: reduxjs/redux-toolkit@v2.12.0...v2.13.0

TanStack/query (@​tanstack/react-query)

v5.104.1

Compare Source

Patch Changes

v5.104.0

Compare Source

Minor Changes
Patch Changes

v5.103.3

Compare Source

Patch Changes
ueberdosis/tiptap (@​tiptap/core)

v3.31.4

Compare Source

@​tiptap/extension-mathematics
Patch Changes
  • The mathematics extension no longer crashes the editor in older WebKit browsers and WKWebView.
@​tiptap/core
Patch Changes
  • Fix a TypeError thrown when the source editor is destroyed right after dragging content into another editor.
  • splitBlock no longer throws TransformError: Inserted content deeper than insertion position when the selection spans block boundaries (for example from the start of one paragraph into another block, or across an isolating node). The command now returns false when the split is not possible.
  • Prevent extra CSS declarations from being rendered from editor content.
  • Atom block directives (:::name {…} :::) indented by up to 3 spaces are now tokenized, matching CommonMark indentation rules for block constructs.
  • Numeric HTML entities (&#&#8203;39;, &#x27;) are now decoded when parsing markdown, instead of showing up as literal text in the editor.
  • The editor element keeps role="textbox" after setOptions() when editorProps.attributes is set. Before, a re-render in React replaced the default role with the user attributes. Attributes passed as a function now get the default role as well.
  • Undoing an input rule restores the Markdown characters that triggered it when using Collaboration.
  • Bind parseMarkdown and renderMarkdown to the configured extension so hooks can read this.options and this.name without an Editor.
  • Pressing Enter before the text of a checked task item now leaves the new empty item unchecked and the item with the text checked. Attributes declared with keepOnSplit: false now reset on the new item, not on the one that keeps the text.
  • Stop joinItemForward and joinItemBackward from joining across isolating nodes.
  • Node views without a contentDOM no longer ignore selection mutations, so ProseMirror moves the caret back to a valid position when the browser places it inside the node view.
@​tiptap/markdown
Patch Changes
  • Fix Markdown serialization of inline code containing backticks
  • Bind parseMarkdown and renderMarkdown to the configured extension so hooks can read this.options and this.name without an Editor.
@​tiptap/extension-code
Patch Changes
  • Fix Markdown serialization of inline code containing backticks
@​tiptap/extension-table
Patch Changes
  • Table cells exported to Markdown now escape literal pipe characters, so the cell content survives when the output is read back.
  • Multi-block table cells no longer leak a U+001F control character into Markdown.
  • Right-clicking a cell inside a multi-cell table selection no longer collapses that selection.
  • Prevent extra CSS declarations from being rendered from editor content.
  • Table cells and headers no longer render the default colspan="1" and rowspan="1" attributes. Cells that actually span still render them, matching how prosemirror-tables serializes spans.
@​tiptap/extension-list
Patch Changes
  • Parsing large Markdown documents that contain ordered lists is much faster. A 578KB document went from about 19s to about 160ms.
@​tiptap/extension-collaboration-caret
Patch Changes
  • Prevent extra CSS declarations from being rendered from editor content.
@​tiptap/extension-highlight
Patch Changes
  • Prevent extra CSS declarations from being rendered from editor content.
@​tiptap/extension-text-align
Patch Changes
  • Prevent extra CSS declarations from being rendered from editor content.
@​tiptap/extension-text-style
Patch Changes
  • Prevent extra CSS declarations from being rendered from editor content.
@​tiptap/extension-link
Patch Changes
  • Typing spaces after a link no longer extends the link, including multiple spaces inserted in one transaction. Formatting changes and undo/redo preserve existing linked whitespace.
@​tiptap/react
Patch Changes
  • Fix Enter and Shift-Enter inside React node views on iOS and Android.
  • React and Vue now use matching menu extension versions when installed from a specific release.
@​tiptap/static-renderer
Patch Changes
  • Render <audio> and <video> with a closing tag instead of self-closing them, so browsers no longer nest the following content inside the first audio element.
  • Rendering a node whose renderHTML returns several nested child elements no longer adds stray commas between them in the HTML string output.
@​tiptap/extension-collaboration
Patch Changes
  • Undoing an input rule restores the Markdown characters that triggered it when using Collaboration.
@​tiptap/vue-2
Patch Changes
  • React and Vue now use matching menu extension versions when installed from a specific release.
@​tiptap/vue-3
Patch Changes
  • React and Vue now use matching menu extension versions when installed from a specific release.
avoidwork/filesize.js (filesize)

v11.0.25

Compare Source

  • fix: preserve BigInt precision above Number.MAX_SAFE_INTEGER #355
  • docs: fix README accuracy errors #353
  • chore(deps-dev): bump oxfmt from 0.68.0 to 0.70.0 #352
  • chore(deps-dev): bump oxlint from 1.83.0 to 1.85.0 #351
  • chore(deps-dev): bump rollup from 4.63.3 to 4.63.4 #350
  • chore(deps-dev): bump rollup from 4.63.2 to 4.63.3 #349
  • chore(deps-dev): bump oxfmt from 0.67.0 to 0.68.0 #348
  • chore(deps-dev): bump oxlint from 1.82.0 to 1.83.0 #347
  • chore(deps-dev): bump rollup from 4.63.1 to 4.63.2 #346
  • fix: preserve BigInt precision above Number.MAX_SAFE_INTEGER (#​355) #354
versatica/mediasoup-client (mediasoup-client)

v3.24.4

Compare Source

What's Changed

  • Safari12: Use RID based simulcast as Chrome111 does by @​ibc in #​391

Full Changelog: versatica/mediasoup-client@3.24.3...3.24.4

v3.24.3

Compare Source

What's Changed

New Contributors

Full Changelog: versatica/mediasoup-client@3.24.1...3.24.3

v3.24.1

Compare Source

Full Changelog: versatica/mediasoup-client@3.24.0...3.24.1

v3.24.0

Compare Source

Full Changelog: versatica/mediasoup-client@3.23.2...3.24.0

gpbl/react-day-picker (react-day-picker)

v10.0.2

Compare Source

Patch Changes

DayPicker follows Semantic Versioning. See the Releases page on Github for the complete list of changes, diffs and contributors, or the list of versions published on npm.

petyosi/react-virtuoso (react-virtuoso)

v4.18.16

Compare Source

Patch Changes
  • #​1512 b7238f3 Thanks @​cpruijsen! - Map skipAnimationFrameInResizeObserver through TableVirtuoso's urx optional props so the table resize observer consumes it instead of leaving the leftover prop on the scroller DOM.
apostrophecms/apostrophe (sanitize-html)

v2.18.0

Compare Source

Adds
  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.
Fixes
  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to
    spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change
    in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also
    fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
    the fix.
Security
  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).

    Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.

websockets/ws (ws)

v8.22.0

Compare Source

Features

  • Introduced the protocols option (8b918b0).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the
    state to WebSocket.CLOSING (#​2337).

Configuration

📅 Schedule: (in timezone Europe/Lisbon)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/prod-minor+patch branch 16 times, most recently from 93269e0 to 165013b Compare October 5, 2026 13:32
@renovate
renovate Bot force-pushed the renovate/prod-minor+patch branch 4 times, most recently from ece5410 to a78b117 Compare October 7, 2026 16:10
@renovate
renovate Bot force-pushed the renovate/prod-minor+patch branch from a78b117 to 24a08db Compare October 8, 2026 11:41
@h8d13
h8d13 merged commit 361f825 into master Oct 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant