Skip to content

Bump the patch-dependencies group with 6 updates - #625

Merged
github-actions[bot] merged 1 commit into
masterfrom
dependabot/npm_and_yarn/patch-dependencies-4cdb22217e
Oct 1, 2026
Merged

github-actions[bot] merged 1 commit into
masterfrom
dependabot/npm_and_yarn/patch-dependencies-4cdb22217e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-dependencies group with 6 updates:

Package From To
@napi-rs/canvas 1.0.8 1.0.9
kysely 0.29.5 0.29.6
youtube-dl-exec 3.1.13 3.1.15
expect 30.5.0 30.5.2
lefthook 2.1.12 2.1.14
oxlint-tsgolint 7.0.2001 7.0.2003

Updates @napi-rs/canvas from 1.0.8 to 1.0.9

Release notes

Sourced from @​napi-rs/canvas's releases.

v1.0.9

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.8...v1.0.9

Changelog

Sourced from @​napi-rs/canvas's changelog.

1.0.9 (2026-09-09)

Bug Fixes

  • deps: update cssparser to 0.38 and cssparser-color to 0.6 (#1335) (caec867)
  • invalidate FontCollection typeface cache on font registration (#1334) (9e4fbec)

Features

Commits
  • b2723ff 1.0.9
  • 70f3022 docs(skill): fold the m154 run experience into upgrade-skia
  • 1b3e054 docs(skill): record the m154 failure classes in upgrade-skia
  • 7257dc9 chore: add repo-level upgrade-skia skill
  • c68eea9 feat: chrome/m154 (#1337)
  • 22eb20d chore: commit Cargo.lock, build with --locked, fix the cargo cache key (#1336)
  • caec867 fix(deps): update cssparser to 0.38 and cssparser-color to 0.6 (#1335)
  • 9e4fbec fix: invalidate FontCollection typeface cache on font registration (#1334)
  • fe11ee0 ci: repair armv7 apt sources and musl builder image (#1331)
  • c7e9ac0 chore(deps): update dependency electron to v44 (#1326)
  • Additional commits viewable in compare view

Updates kysely from 0.29.5 to 0.29.6

Release notes

Sourced from kysely's releases.

0.29.6

Hey 👋

A small batch of bug fixes. Please report any issues. 🤞😰🤞

🚀 Features

🐞 Bugfixes

PostgreSQL 🐘 / SQLite 📘

📖 Documentation

📦 CICD & Tooling

⚠️ Breaking Changes

🐤 New Contributors

What's Changed

Full Changelog: kysely-org/kysely@v0.29.5...v0.29.6

Commits
  • 2fefd4c 0.29.6
  • 2feb1f3 chore: bumps dependencies. (#2045)
  • b596221 fix: allow immutable columns in doUpdateSet's where. (#2043)
  • b9674df chore(CONTRIBUTING): llm contribution farming accounts.
  • 90fe25c chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...
  • 6582fb6 chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#1984)
  • b497657 chore(deps-dev): bump shiki from 4.4.2 to 4.4.3 (#1982)
  • 44c4782 chore(deps): bump step-security/harden-runner from 2.20.1 to 2.21.0 (#1987)
  • 20e5d15 chore(deps-dev): bump mysql2 from 3.23.2 to 3.23.3 (#1983)
  • 93cb9ad Update link to Migrator API docs (#1991)
  • Additional commits viewable in compare view

Updates youtube-dl-exec from 3.1.13 to 3.1.15

Release notes

Sourced from youtube-dl-exec's releases.

v3.1.15

What's Changed

Full Changelog: microlinkhq/youtube-dl-exec@v3.1.14...v3.1.15

v3.1.14

What's Changed

Full Changelog: microlinkhq/youtube-dl-exec@v3.1.13...v3.1.14

Changelog

Sourced from youtube-dl-exec's changelog.

3.1.15 (2026-09-05)

Bug Fixes

3.1.14 (2026-09-02)

Bug Fixes

Commits

Updates expect from 30.5.0 to 30.5.2

Release notes

Sourced from expect's releases.

v30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)

New Contributors

Full Changelog: jestjs/jest@v30.5.1...v30.5.2

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

Changelog

Sourced from expect's changelog.

30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)

30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)
Commits

Updates lefthook from 2.1.12 to 2.1.14

Release notes

Sourced from lefthook's releases.

v2.1.14

Changelog

Changelog

Sourced from lefthook's changelog.

2.1.13/2.1.14 (2026-09-14)

Commits
  • 1e23553 2.1.14: small fixes and spinner improvements
  • a2c9d37 2.1.13: small fixes and spinner improvements
  • c7b4983 fix(run): error when --job/--command matches nothing (#1512)
  • e4ca4a1 fix: disable tty things when stdout is not TTY (#1545)
  • aa3fa89 docs: document files inheritance for grouped jobs (#1536)
  • 250f028 fix: force colors when colors are explicitly enabled (#1538)
  • 62f4d5e fix: resolve file_types paths from the repo root (#1537)
  • ef092eb fix(npm) don't force past core.hooksPath guard in npm postinstall (#1475)
  • 3667aeb fix: don't force-install hooks from the npm postinstall (#1510)
  • 354df23 docs: quote template run examples (#1472)
  • See full diff in compare view

Updates oxlint-tsgolint from 7.0.2001 to 7.0.2003

Release notes

Sourced from oxlint-tsgolint's releases.

v7.0.2003

What's Changed

New Contributors

Full Changelog: oxc-project/tsgolint@v7.0.2002...v7.0.2003

v7.0.2002

What's Changed

... (truncated)

Commits
  • eb93391 perf: add experimental checker scheduling modes (#1240)
  • e3a79a5 refactor: extract checker workload scheduling (#1241)
  • 1fdaa0d perf(no-unnecessary-type-assertion): reject incompatible types first (#1181)
  • 364b239 perf: speed up headless file-to-program assignment (#1239)
  • 52500be perf: avoid singleton union type allocations in hot rules (#1237)
  • 22b148a fix(no-unnecessary-condition): check nested logical expressions in truthiness...
  • 356609f fix(no-deprecated): detect deprecated aliases in object shorthand (#1235)
  • cbf3909 fix(no-useless-default-assignment): handle tuples with rest elements (#1223)
  • 7bd5c11 fix: match package specifiers on whole path components (#1225)
  • 6f25883 fix: preserve expression syntax when removing await (#1233)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the patch-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@napi-rs/canvas](https://github.com/Brooooooklyn/canvas) | `1.0.8` | `1.0.9` |
| [kysely](https://github.com/kysely-org/kysely) | `0.29.5` | `0.29.6` |
| [youtube-dl-exec](https://github.com/microlinkhq/youtube-dl-exec) | `3.1.13` | `3.1.15` |
| [expect](https://github.com/jestjs/jest/tree/HEAD/packages/expect) | `30.5.0` | `30.5.2` |
| [lefthook](https://github.com/evilmartians/lefthook) | `2.1.12` | `2.1.14` |
| [oxlint-tsgolint](https://github.com/oxc-project/tsgolint) | `7.0.2001` | `7.0.2003` |


Updates `@napi-rs/canvas` from 1.0.8 to 1.0.9
- [Release notes](https://github.com/Brooooooklyn/canvas/releases)
- [Changelog](https://github.com/Brooooooklyn/canvas/blob/main/CHANGELOG.md)
- [Commits](Brooooooklyn/canvas@v1.0.8...v1.0.9)

Updates `kysely` from 0.29.5 to 0.29.6
- [Release notes](https://github.com/kysely-org/kysely/releases)
- [Commits](kysely-org/kysely@v0.29.5...v0.29.6)

Updates `youtube-dl-exec` from 3.1.13 to 3.1.15
- [Release notes](https://github.com/microlinkhq/youtube-dl-exec/releases)
- [Changelog](https://github.com/microlinkhq/youtube-dl-exec/blob/master/CHANGELOG.md)
- [Commits](microlinkhq/youtube-dl-exec@v3.1.13...v3.1.15)

Updates `expect` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/expect)

Updates `lefthook` from 2.1.12 to 2.1.14
- [Release notes](https://github.com/evilmartians/lefthook/releases)
- [Changelog](https://github.com/evilmartians/lefthook/blob/master/CHANGELOG.md)
- [Commits](evilmartians/lefthook@v2.1.12...v2.1.14)

Updates `oxlint-tsgolint` from 7.0.2001 to 7.0.2003
- [Release notes](https://github.com/oxc-project/tsgolint/releases)
- [Commits](oxc-project/tsgolint@v7.0.2001...v7.0.2003)

---
updated-dependencies:
- dependency-name: "@napi-rs/canvas"
  dependency-version: 1.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-dependencies
- dependency-name: kysely
  dependency-version: 0.29.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-dependencies
- dependency-name: youtube-dl-exec
  dependency-version: 3.1.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-dependencies
- dependency-name: expect
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-dependencies
- dependency-name: lefthook
  dependency-version: 2.1.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-dependencies
- dependency-name: oxlint-tsgolint
  dependency-version: 7.0.2003
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@github-actions
github-actions Bot merged commit 31177c1 into master Oct 1, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/patch-dependencies-4cdb22217e branch October 1, 2026 05:20

This branch had an error being deployed

1 failed deployment
e2e — bb796472 Deployed Oct 1, 2026 by dependabot[bot] via Deploy e2e #282
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants