Skip to content

chore(deps): update all patch dependencies#13765

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-patch
Open

chore(deps): update all patch dependencies#13765
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-patch

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 26, 2026

This PR contains the following updates:

Package Change Age Confidence
@rsbuild/core (source) ^1.7.2^1.7.3 age confidence
@rsbuild/plugin-vue (source) ^1.2.3^1.2.5 age confidence
@rslib/core (source) ^0.19.2^0.19.4 age confidence
@types/node (source) ^24.10.9^24.10.10 age confidence
@vue/runtime-core (source) ^3.5.26^3.5.27 age confidence
@vue/shared (source) ^3.5.26^3.5.27 age confidence
autoprefixer ^10.4.23^10.4.24 age confidence
commander ^14.0.2^14.0.3 age confidence
pnpm (source) 10.28.010.28.2 age confidence
pnpm (source) >= 10.28.0>= 10.28.2 age confidence
transliteration ^2.6.0^2.6.1 age confidence
vue (source) ^3.5.26^3.5.27 age confidence

Release Notes

web-infra-dev/rsbuild (@​rsbuild/core)

v1.7.3

Compare Source

web-infra-dev/rsbuild (@​rsbuild/plugin-vue)

v1.2.5

Compare Source

What's Changed

New Features 🎉
Bug Fixes 🐞
Document 📖
Other Changes

New Contributors

Full Changelog: web-infra-dev/rsbuild@v1.2.4...v1.2.5

v1.2.4

Compare Source

What's Changed

New Features 🎉
Bug Fixes 🐞
Document 📖
Other Changes

New Contributors

Full Changelog: web-infra-dev/rsbuild@v1.2.3...v1.2.4

web-infra-dev/rslib (@​rslib/core)

v0.19.4

Compare Source

What's Changed

New Features 🎉
Bug Fixes 🐞
Document 📖
Other Changes

New Contributors

Full Changelog: web-infra-dev/rslib@v0.19.3...v0.19.4

v0.19.3

Compare Source

What's Changed

Document 📖
Other Changes

Full Changelog: web-infra-dev/rslib@v0.19.2...v0.19.3

vuejs/core (@​vue/runtime-core)

v3.5.27

Compare Source

Bug Fixes
postcss/autoprefixer (autoprefixer)

v10.4.24

Compare Source

  • Made Autoprefixer a little faster (by @​Cherry).
tj/commander.js (commander)

v14.0.3

Compare Source

Added
Changes
  • old major versions now supported for 12 months instead of just previous major version, to give predictable end-of-life date ([#​2462])
  • clarify typing for deprecated callback parameter to .outputHelp() ([#​2427])
  • simple readability improvements to README ([#​2465])
pnpm/pnpm (pnpm)

v10.28.2: pnpm 10.28.2

Compare Source

Patch Changes

  • Security fix: prevent path traversal in directories.bin field.

  • When pnpm installs a file: or git: dependency, it now validates that symlinks point within the package directory. Symlinks to paths outside the package root are skipped to prevent local data from being leaked into node_modules.

    This fixes a security issue where a malicious package could create symlinks to sensitive files (e.g., /etc/passwd, ~/.ssh/id_rsa) and have their contents copied when the package is installed.

    Note: This only affects file: and git: dependencies. Registry packages (npm) have symlinks stripped during publish and are not affected.

  • Fixed optional dependencies to request full metadata from the registry to get the libc field, which is required for proper platform compatibility checks #​9950.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.28.1

Compare Source

yf-hk/transliteration (transliteration)

v2.6.1

Compare Source

  • Fix: Added transliteration/latin entrypoint with proper exports mapping
  • Fix: Preserved access to dist/* and package.json for tooling/CDN usage
  • Fix: Latin-only build now resets to Latin data on setData(..., true)

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/all-patch branch 7 times, most recently from 365493d to b0d6153 Compare February 2, 2026 18:28
@renovate renovate bot force-pushed the renovate/all-patch branch from b0d6153 to 3114edf Compare February 3, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants