Skip to content

chore(deps): update all non-major dependencies - #46

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jun 9, 2025 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@nuxt/eslint (source) 1.4.1 → 1.17.0 age confidence dependencies minor
@nuxt/scripts (source) 1.1.0 → 1.3.12 age confidence dependencies minor
@playwright/test (source) 1.60.0 → 1.64.0 age confidence devDependencies minor
@vue/test-utils 2.4.6 → 2.5.1 age confidence devDependencies minor
danielroe/provenance-action v0.1.0 → v0.2.0 age confidence action minor
nuxt-og-image (source) 5.1.4 → 5.1.13 age confidence dependencies patch
pnpm (source) 12.3.4 → 12.10.1 age confidence devEngines.packageManager minor
simple-git-hooks 2.13.0 → 2.14.0 age confidence devDependencies minor
unplugin-vue-router (source) ^0.12.0 → ^0.19.0 age confidence dependencies minor
vue-sonner 2.0.0 → 2.0.9 age confidence dependencies patch
vue-tsc (source) 3.0.1 → 3.3.12 age confidence devDependencies minor

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

nuxt/eslint (@​nuxt/eslint)

v1.17.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v1.16.0

Compare Source

   🚀 Features
    View changes on GitHub

v1.15.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.15.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.15.0

Compare Source

   🚀 Features
    View changes on GitHub

v1.14.0

Compare Source

   🚀 Features
    View changes on GitHub

v1.13.0

Compare Source

   🚀 Features
  • Upgrade eslint-flat-config-utils eslint-plugin-import-lite and eslint-plugin-jsdoc  -  by @​antfu (10bf9)
    View changes on GitHub

v1.12.1

Compare Source

No significant changes

    View changes on GitHub

v1.11.0

Compare Source

   🚀 Features
    View changes on GitHub

v1.10.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v1.9.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v1.8.0

Compare Source

   🚀 Features
    View changes on GitHub

v1.7.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.7.0

Compare Source

   🚀 Features
    View changes on GitHub

v1.6.0

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.5.2

Compare Source

   🚀 Features
    View changes on GitHub

v1.5.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.5.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub
nuxt/scripts (@​nuxt/scripts)

v1.3.12

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.11

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.10

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.9

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.8

Compare Source

   🐞 Bug Fixes
  • registry: Don't declare the global Window via extends (1.x backport)  -  by @​harlan-zw, Togetic and Claude Opus 5 (1M context) in #​880 (be0ce)
    View changes on GitHub

v1.3.7

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.6

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.5

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.3.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v1.2.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v1.2.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v1.1.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
microsoft/playwright (@​playwright/test)

v1.64.0

Compare Source

🧰 WebMCP

New page.webmcp and frame.webmcp give access to the tools that a page registers through the experimental WebMCP browser API, so you can test them like any other part of your app:

const browser = await chromium.launch({ args: ['--enable-features=WebMCP'] });
const page = await browser.newPage();
await page.goto('https://example.com');

for (const tool of await page.webmcp.tools())
  console.log(tool.name, tool.description);

const result = await page.webmcp.callTool('add', { a: 2, b: 40 });
console.log(result.content[0].text); // "42"

Playwright MCP also supports WebMCP by default, with page-defined tools offered to the agent as webmcp_<tool>. Pass --no-webmcp to opt out.

playwright-cli exposes them as well:

playwright-cli webmcp-list
playwright-cli webmcp-call search_catalog --params '{"query":"cats"}'

🎬 Better videos

Videos can now be recorded at a custom frame rate, and the decorations for actions are styled with plain CSS:

// playwright.config.ts
import { defineConfig } from '@playwright/test';

export default defineConfig({
  use: {
    video: {
      mode: 'on',
      size: { width: 1920, height: 1080 },
      fps: 60,
      show: {
        actions: {
          style: {
            point: 'width: 20px; height: 20px; border-radius: 50%; background: red',
            highlight: 'outline: 2px solid #&#8203;333; background: rgba(0, 128, 255, .15)',
            title: 'font-size: 16px',
          },
        },
      },
    },
  },
});
  • New fps option in testOptions.video, recordVideo and
    screencast.start(). Firefox and WebKit currently capture up to 25 frames per second.
  • New style option takes CSS declarations for the point marker, the target
    highlight and the action title. It replaces the fontSize option, which is now deprecated.
  • The cursor stays visible at the last action point, survives navigations and travels along a natural, eased path.
  • Videos are encoded with VP9 instead of VP8, which takes less CPU and produces smaller files of the same or better
    quality.
  • All video options are also available in Playwright MCP and playwright-cli.

🎯 Test runner

  • New testProject.default option keeps a project in the config without running it by default. You can configure every browser you care about, and let a plain npx playwright test run just your favourite one:

    // playwright.config.ts
    import { defineConfig, devices } from '@playwright/test';
    
    export default defineConfig({
      projects: [
        { name: 'chromium', use: devices['Desktop Chrome'] },
        { name: 'firefox', use: devices['Desktop Firefox'], default: false },
        { name: 'webkit', use: devices['Desktop Safari'], default: false },
      ],
    });
    npx playwright test                     # runs chromium only
    npx playwright test --project=firefox   # runs firefox
    npx playwright test --project="*"       # runs all three, for example on CI
  • New --shuffle command line option schedules tests in a random order, which helps to find tests that accidentally depend on each other.

    npx playwright test --shuffle
    # Running 42 tests using 4 workers, shuffle seed 271828182
    # ...
    
    # Pass the seed to reproduce the same order.
    npx playwright test --shuffle 271828182
  • New lock option in test.describe.configure() adds test locks to all tests in a file or a group:

    test.describe.configure({ lock: 'user-settings' });
  • New type option of toHaveScreenshot in testConfig.expect stores all unnamed screenshots as WebP:

    // playwright.config.ts
    export default defineConfig({
      expect: {
        toHaveScreenshot: { type: 'webp' },
      },
    });

🪆 Locator.within()

New locator.within() combines two locators that you already have, reading in the natural order —
"this button, within that dialog":

const saveButton = page.getByRole('button', { name: 'Save' });
const dialog = page.getByTestId('settings-dialog');

await saveButton.within(dialog).click();

Relative locators such as locator.nth() or locator.first() are resolved inside each parent
separately, which makes column-like queries straightforward:

// The third cell of every row, not the third cell in the table.
const thirdColumn = page.getByRole('cell').nth(2).within(page.getByRole('row'));
await expect(thirdColumn).toHaveText(['Apple', 'Banana', 'Cherry']);

New APIs

Breaking changes ⚠️

  • screen property is now forwarded from the device descriptors. If you use ...devices['Desktop Chrome'] and alike, window.screen and media queries now see the emulated screen size. You can opt-out by explicitly setting screen to undefined:

    // playwright.config.ts
    export default defineConfig({
      use: {
        ...devices['Desktop Chrome'],
        screen: undefined,
      },
    });
  • JSX in your test files now follows your tsconfig.json. Playwright compiles JSX in test files according to the jsx, jsxFactory, jsxFragmentFactory and jsxImportSource tsconfig options, and defaults to the automatic runtime from react/jsx-runtime.

  • --update-snapshots=missing now passes the test run. Tests that only create missing snapshots now pass in the 'missing' mode of testConfig.updateSnapshots, so that CI can generate new snapshots and verify the existing ones in a single run. The mode used when the option is not specified is now called 'default' and behaves as before: missing snapshots are written and the test fails.

  • Elements inside hidden iframes are considered hidden. Elements inside an iframe that is not visible, for example with visibility: hidden, are now considered hidden by actions, locator.isVisible() and expect(locator).toBeVisible().

Browser Versions

  • Chromium 156.0.8078.4
  • Mozilla Firefox 157.0
  • WebKit 27.2

This version was also tested against the following stable channels:

  • Google Chrome 155
  • Microsoft Edge 155

v1.63.0

Compare Source

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock.
Tests that share a lock name never run concurrently, across files, workers and projects, while
everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group.
Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the
subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it
matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended
replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments,
and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API
steps, the subtitle is the locator or the navigation url — for example, Click with subtitle getByRole('button').
Both are rendered next to the step title in the trace viewer and the HTML report.

🖼️ Aria and screen snapshots in traces

The snapshots option of tracing.start() and the testOptions.trace fixture option now accept an
object selecting what to capture on every action:

// playwright.config.ts
export default defineConfig({
  use: {
    trace: {
      mode: 'on',
      snapshots: { dom: true, aria: true, screen: true }
    },
  },
});

With aria and screen snapshots recorded, the new Display Aria mode in the trace viewer shows the action screenshot
side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.

New APIs

Browser and Context
Locators
const response = await request.get<User>('/api/users/42');
const user = await response.json(); // typed as User
Test runner
  • New standalone testOptions.reducedMotion, testOptions.forcedColors and testOptions.contrast options.
  • New --add-reporter command line option appends a reporter on top of the ones configured in playwright.config, instead of replacing them like --reporter does.
  • New omitTags option for the list, line, dot, github and junit reporters suppresses the tags that are automatically appended to test titles.
Command line
  • npx playwright install --no-remove keeps the browsers of other Playwright installations instead of removing them.
  • npx playwright codegen --http-credentials records against pages behind HTTP authentication.
Miscellaneous
  • New built-in perfetto reporter writes a Trace Event Format file for the Perfetto UI or chrome://tracing, rendering the test run as a timeline with a lane per worker.
  • The HTML report renders a duration waterfall next to test steps.

Announcements

  • ⚠️ The experimental @playwright/experimental-ct-react, @playwright/experimental-ct-react17 and @playwright/experimental-ct-vue packages will no longer be updated. Follow the migration guide to move to the stories model introduced in 1.62. Story ids passed to fixtures.mount() can now be typed through the generated Stories registry.
  • ⚠️ Ubuntu 20.04 is not supported anymore.
  • 🐧 On Linux arm64, Playwright now downloads the Chrome for Testing build of Chromium, the same build used on all other platforms.

Browser Versions

  • Chromium 153.0.8010.12
  • Mozilla Firefox 155.0
  • WebKit 26.6

This version was also tested against the following stable channels:

  • Google Chrome 153
  • Microsoft Edge 153

v1.62.1

Compare Source

Bug Fixes
  • #​41989 [Regression]: tsconfig "extends" bare specifier isn't resolved via node_modules walk-up like tsc (fatal since 1.62)
  • #​41998 [Regression]: directory-form tsconfig project references ("path": "../pkg") fail to resolve (fatal since 1.62)
  • #​41985 Accessibility snapshot drops button name when text is nested inside spans with aria-hidden SVG
  • #​42000 [Regression]: page.evaluate() arg of a branded primitive type (string & { brand }) no longer type-checks since 1.62
  • #​42013 [BUG]Image-type actionable elements are not presented in the snapshot.

v1.62.0

Compare Source

🧱 New component testing model

Component testing moves to a stories and galleries model.
A story wraps your component in one specific scenario — hard-coded props, mock data, providers — and a gallery page that you serve renders stories on demand.
The new fixtures.mount() fixture navigates to the gallery, mounts a story by id, and returns a Locator scoped to the story's root element:

test('click should expand', async ({ mount }) => {
  const component = await mount('components/Expandable/Stateful');
  await component.getByRole('button').click();
  await expect(component.getByTestId('expanded')).toHaveValue('true');
});

Pass a story type as a template argument to type-check its props, and use update(props) / unmount() on the returned locator to re-render or tear down within a test.

🛑 Cancel operations with AbortSignal

Most operations and web-first assertions now accept a signal option that takes an AbortSignal, letting you cancel long-running actions, navigations, waits, and assertions:

const controller = new AbortController();
setTimeout(() => controller.abort(), 1000);

await page.getByRole('button', { name: 'Submit' }).click({ signal: controller.signal });
await expect(page.getByText('Done')).toBeVisible({ signal: controller.signal });

Providing a signal does not disable the default timeout; pass timeout: 0 to disable it.

🖼️ WebP screenshots

expect(page).toHaveScreenshot() and expect(locator).toHaveScreenshot() can now store snapshots in the WebP format — just give the snapshot a .webp name:

// Visual comparisons store the golden snapshot as lossless WebP.
await expect(page).toHaveScreenshot('homepage.webp');

// Standalone screenshots can trade quality for size with lossy WebP.
await page.screenshot({ path: 'homepage.webp', quality: 50 });

page.screenshot() and [locator.screenshot() (https://playwright.dev/docs/api/class-locator#locator-screenshot) also accept webp as a type, where quality 100 (the default) is lossless and lower values use lossy compression.

🧩 Custom test filtering with Reporter.preprocess()

New reporter.preprocess() hook runs after the configuration is resolved and before reporter.onBegin(), letting a reporter mark individual tests as skipped, excluded, fixed, or failing through a TestRun object:

class MyReporter {
  async preprocess({ config, suite, testRun }) {
    for (const test of suite.allTests()) {
      if (shouldSkip(test))
        testRun.skip(test);
    }
  }
}

🔁 Isolated retries

New testConfig.retryStrategy controls when failed tests are retried.
The default 'immediate' retries as soon as a worker is free; 'isolated' runs all retries at the end, one by one in a single worker, to minimize interference with the rest of the suite:

// playwright.config.ts
export default defineConfig({
  retries: 2,
  retryStrategy: 'isolated',
});

New APIs

Browser and Context
  • New option credentials includes the context's virtual WebAuthn Credentials (passkeys) in the storage state, so they can be persisted and re-seeded into later contexts.
Actions
  • New scroll option ("auto" | "none") on actions to opt out of Playwright's automatic scroll-into-view.
Network
Evaluation
Command line & MCP
Reporters
  • The HTML report's Merge files grouping — previously only a UI toggle — can now be enabled from the config with the new mergeFiles reporter option:
// playwright.config.ts
export default defineConfig({
  reporter: [['html', { mergeFiles: true }]],
});

Announcements

  • ⚠️ Debian 11 is not supported anymore.

Browser Versions

  • Chromium 151.0.7922.34
  • Mozilla Firefox 153.0
  • WebKit 26.5

This version was also tested against the following stable channels:

  • Google Chrome 151
  • Microsoft Edge 151

v1.61.1

Compare Source

Bug Fixes
  • #​41365 [Bug]: Expect.Extend matcher with same name as default matcher in same expect instance overrides default matchers implementation to custom matcher
  • #​41351 [Bug]: Playwright UI mode: apiRequestContext._wrapApiCall reports unexpected number of bytes (same test passes in headed mode)
  • #​41360 [Bug]: Trace viewer: message times in websockets are downscaled by 1000
  • #​41311 [Bug]: [Regression]: Sync loader throws "context.conditions?.includes is not a function" on Node 22.15
  • #​41371 [Regression]: Sync ESM loader (registerHooks) fails to resolve extensionless .ts subpath imports across pnpm workspace symlinks

v1.61.0

Compare Source

🔑 WebAuthn passkeys

New Credentials virtual authenticator, available via browserContext.credentials, lets tests register passkeys and answer navigator.credentials.create() / navigator.credentials.get() c

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 9, 2025 •

Copy link
Copy Markdown

Deploying dev-mode with  Cloudflare Pages  Cloudflare Pages

Latest commit: a6593b8
Status: ✅  Deploy successful!
Preview URL: https://b4871a9a.dev-mode.pages.dev
Branch Preview URL: https://renovate-all-minor-patch.dev-mode.pages.dev

View logs

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from a0e4601 to 3853611 Compare June 16, 2025 08:36
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 16 times, most recently from 5d5db8c to 1a5208b Compare June 22, 2025 23:38
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 23 times, most recently from bf1a8dd to 708f34a Compare July 7, 2025 09:41
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from fc47a1c to 12a7b8e Compare July 8, 2025 00:37
@socket-security

socket-security Bot commented Nov 5, 2025 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@socket-security

socket-security Bot commented Jun 16, 2026 •

Copy link
Copy Markdown

@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

◈ PR Lens

Note

This drawing shows f1dd2c9, and the branch has new commits since. Tick Redraw to draw the latest one

  • Redraw

🟢 +0 new · 🟠 ~2 changed · 🔴 -0 removed · 0 flows · 5 files · commit f1dd2c9


Architecture

Architecture diagram for danielroe/dev-mode.dev at f1dd2c9

2 components touched across 2 lanes.

Open the interactive canvas


Data flow

No data-flow sequence changed in this PR.


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Push a commit and the comment redraws for the new head. A slow older run never overwrites a newer one.

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists.
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds.
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through.
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change.
  • Open a diagram on the canvas, then press W or click play to walk through the change one step at a time.
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time.
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs on every push.
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works.
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion.

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (1)
  • chore(deps)

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f31071e3-22c0-41cc-8605-39464544aee2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants