Skip to content

chore(deps): update all non-major dependencies - #165

Merged
renovate[bot] merged 1 commit into
devfrom
renovate/all-minor-patch
Feb 2, 2026
Merged

renovate[bot] merged 1 commit into
devfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Feb 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@babel/core (source) ^7.28.6 → ^7.29.0 age confidence
@eslint/compat (source) ^2.0.1 → ^2.0.2 age confidence
@mantine/core (source) ^8.3.13 → ^8.3.14 age confidence
@mantine/dates (source) ^8.3.13 → ^8.3.14 age confidence
@mantine/hooks (source) ^8.3.13 → ^8.3.14 age confidence
@microsoft/api-extractor (source) ^7.55.2 → ^7.56.0 age confidence
@rsbuild/plugin-babel (source) ^1.0.7 → ^1.1.0 age confidence
@rsbuild/plugin-react (source) ^1.4.3 → ^1.4.5 age confidence
@rslib/core (source) ^0.19.3 → ^0.19.4 age confidence
@storybook/addon-docs (source) ^10.2.0 → ^10.2.3 age confidence
@storybook/addon-themes (source) ^10.2.0 → ^10.2.3 age confidence
@storybook/react (source) ^10.2.0 → ^10.2.3 age confidence
@types/react (source) ^19.2.9 → ^19.2.10 age confidence
eslint-plugin-react-refresh ^0.4.26 → ^0.5.0 age confidence
eslint-plugin-storybook (source) ^10.2.0 → ^10.2.3 age confidence
globals ^17.1.0 → ^17.3.0 age confidence
pnpm (source) 10.28.1 → 10.28.2 age confidence
storybook (source) ^10.2.0 → ^10.2.3 age confidence
typescript-eslint (source) ^8.53.1 → ^8.54.0 age confidence

Release Notes

mantinedev/mantine (@​mantine/core)

v8.3.14

Compare Source

What's Changed

  • [@mantine/core] Switch: Fix checkbox not being recognized by Playwright (#​8370, #​8645)
  • [@mantine/core] MultiSelect: Fix click on chevron not opening dropdown when clearable is enabled (#​8641)
  • [@mantine/modals] Fix types of context modals inferred incorrectly (#​8625)
  • [@mantine/core] MultiSelect: Fix clear button overlapping with pills (#​8634)

New Contributors

Full Changelog: mantinedev/mantine@8.3.13...8.3.14

web-infra-dev/rsbuild (@​rsbuild/plugin-react)

v1.4.5

Compare Source

What's Changed

New Features 🎉
Bug Fixes 🐞
Document 📖
Other Changes

New Contributors

Full Changelog: web-infra-dev/rsbuild@v1.4.4...v1.4.5

ArnaudBarre/eslint-plugin-react-refresh (eslint-plugin-react-refresh)

v0.5.0

Compare Source

Breaking changes
  • The package now ships as ESM and requires ESLint 9 + node 20. Because legacy config doesn't support ESM, this requires to use flat config
  • A new reactRefresh export is available and prefered over the default export. It's an object with two properties:
    • plugin: The plugin object with the rules
    • configs: An object containing configuration presets, each exposed as a function. These functions accept your custom options, merge them with sensible defaults for that config, and return the final config object.
  • customHOCs option was renamed to extraHOCs
  • Validation of HOCs calls is now more strict, you may need to add some HOCs to the extraHOCs option

Config example:

import { defineConfig } from "eslint/config";
import { reactRefresh } from "eslint-plugin-react-refresh";

export default defineConfig(
  /* Main config */
  reactRefresh.configs.vite({ extraHOCs: ["someLibHOC"] }),
);

Config example without config:

import { defineConfig } from "eslint/config";
import { reactRefresh } from "eslint-plugin-react-refresh";

export default defineConfig({
  files: ["**/*.ts", "**/*.tsx"],
  plugins: {
    // other plugins
    "react-refresh": reactRefresh.plugin,
  },
  rules: {
    // other rules
    "react-refresh/only-export-components": [
      "warn",
      { extraHOCs: ["someLibHOC"] },
    ],
  },
});
Why

This version follows a revamp of the internal logic to better make the difference between random call expressions like export const Enum = Object.keys(Record) and actual React HOC calls like export const MemoComponent = memo(Component). (fixes #​93)

The rule now handles ternaries and patterns like export default customHOC(props)(Component) which makes it able to correctly support files like this one given this config:

{
  "react-refresh/only-export-components": [
    "warn",
    { "extraHOCs": ["createRootRouteWithContext"] }
  ]
}

[!NOTE]
Actually createRoute functions from TanStack Router are not React HOCs, they return route objects that fake to be a memoized component but are not. When only doing createRootRoute({ component: Foo }), HMR will work fine, but as soon as you add a prop to the options that is not a React component, HMR will not work. I would recommend to avoid adding any TanStack function to extraHOCs it you want to preserve good HMR in the long term. Bluesky thread.

Because I'm not 100% sure this new logic doesn't introduce any false positive, this is done in a major-like version. This also give me the occasion to remove the hardcoded connect from the rule. If you are using connect from react-redux, you should now add it to extraHOCs like this:

{
  "react-refresh/only-export-components": ["warn", { "extraHOCs": ["connect"] }]
}
sindresorhus/globals (globals)

v17.3.0

Compare Source


pnpm/pnpm (pnpm)

v10.28.2: pnpm 10.28.2

Compare Source

Patch Changes

  • Security fix: prevent path traversal in directories.bin field.

  • When pnpm installs a file: or git: dependency, it now validates that symlinks point within the package directory. Symlinks to paths outside the package root are skipped to prevent local data from being leaked into node_modules.

    This fixes a security issue where a malicious package could create symlinks to sensitive files (e.g., /etc/passwd, ~/.ssh/id_rsa) and have their contents copied when the package is installed.

    Note: This only affects file: and git: dependencies. Registry packages (npm) have symlinks stripped during publish and are not affected.

  • Fixed optional dependencies to request full metadata from the registry to get the libc field, which is required for proper platform compatibility checks #​9950.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Feb 2, 2026
@vercel

vercel Bot commented Feb 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
mantine-resource-timeline Ready Ready Preview, Comment Feb 2, 2026 5:46am

@pkg-pr-new

pkg-pr-new Bot commented Feb 2, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/jvllmr/mantine-resource-timeline@165

commit: 1168cba

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 017135b to 1168cba Compare February 2, 2026 05:46
@renovate
renovate Bot merged commit 58b0124 into dev Feb 2, 2026
8 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch February 2, 2026 08:38

This branch was successfully deployed

1 active deployment
Preview — 1168cbab Deployed Feb 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants