Skip to content

npm: bump the npm-development group across 1 directory with 27 updates - #386

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/main/npm-development-fbb50d7420
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/main/npm-development-fbb50d7420

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-development group with 27 updates in the / directory:

Package From To
@wordpress/scripts 34.1.0 34.2.0
@eslint/eslintrc 3.3.6 3.3.7
brace-expansion 1.1.18 1.1.21
@jridgewell/sourcemap-codec 1.5.5 1.6.0
@peculiar/asn1-cms 2.9.3 2.9.4
@peculiar/asn1-csr 2.9.3 2.9.4
@peculiar/asn1-ecc 2.9.3 2.9.4
@peculiar/asn1-pfx 2.9.3 2.9.4
@peculiar/asn1-pkcs9 2.9.3 2.9.4
body-parser 1.20.6 1.20.8
colord 2.9.3 2.10.0
compression 1.8.1 1.8.2
enhanced-resolve 5.24.5 5.25.1
express 4.22.2 4.22.3
fast-uri 3.1.5 3.1.8
fastq 1.20.1 1.20.3
glob-to-regex.js 1.2.0 1.3.1
jest-environment-jsdom 30.4.1 30.5.1
memfs 4.68.1 4.78.1
minimizer-webpack-plugin 5.6.1 5.10.1
nanoid 3.3.18 3.3.19
postcss 8.5.26 8.5.28
sass 1.102.0 1.104.1
svg-parser 2.0.4 2.1.0
svgo 3.3.4 3.3.5
webpack 5.109.2 5.111.0
webpack-dev-middleware 7.4.5 7.4.6

Updates @wordpress/scripts from 34.1.0 to 34.2.0

Changelog

Sourced from @​wordpress/scripts's changelog.

34.2.0 (2026-08-26)

Commits

Updates @eslint/eslintrc from 3.3.6 to 3.3.7

Release notes

Sourced from @​eslint/eslintrc's releases.

eslintrc: v3.3.7

3.3.7 (2026-09-01)

Bug Fixes

  • Bump js-yaml to 4.3.1 (#239) (f27e7c9)
  • update js-yaml to 4.3.2 to address security vulnerability (#243) (bb0d97a)
Changelog

Sourced from @​eslint/eslintrc's changelog.

3.3.7 (2026-09-01)

Bug Fixes

  • Bump js-yaml to 4.3.1 (#239) (f27e7c9)
  • update js-yaml to 4.3.2 to address security vulnerability (#243) (bb0d97a)
Commits

Updates brace-expansion from 1.1.18 to 1.1.21

Commits

Updates @jridgewell/sourcemap-codec from 1.5.5 to 1.6.0

Changelog

Sourced from @​jridgewell/sourcemap-codec's changelog.

[1.6.0] - 2026-08-27

  • Add Range Mapping support: #45
    • includes new decodeRangeMappings and encodeRangeMappings APIs

Full Changelog: jridgewell/sourcemaps@sourcemap-codec/1.5.5...sourcemap-codec/1.6.0

Commits
  • b760015 sourcemap-codec/1.6.0
  • 8aec729 Ignore map files during ripgrepping
  • 6566f0c Range mappings: update encoding to latest
  • e5d58e6 Improve mocha setup
  • f34bc27 Changelogs
  • 01a4f69 Small clenaup
  • 6cbfce2 Add test:watch commands
  • f3cb43e Separate signing from encoding/decoding integers
  • b319fc0 Range mappings: add initial decoding/encoding support
  • 59f4045 Add unsigned VLQ encode/decode options
  • See full diff in compare view

Updates @peculiar/asn1-cms from 2.9.3 to 2.9.4

Release notes

Sourced from @​peculiar/asn1-cms's releases.

v2.9.4

npm publish status

All intended npm packages were published successfully.

What's Changed

Full Changelog: PeculiarVentures/asn1-schema@v2.9.3...v2.9.4

Commits
  • a0608da chore(release): v2.9.4
  • e87a267 chore(packages): add node engine requirement to all packages
  • See full diff in compare view

Updates @peculiar/asn1-csr from 2.9.3 to 2.9.4

Release notes

Sourced from @​peculiar/asn1-csr's releases.

v2.9.4

npm publish status

All intended npm packages were published successfully.

What's Changed

Full Changelog: PeculiarVentures/asn1-schema@v2.9.3...v2.9.4

Commits
  • a0608da chore(release): v2.9.4
  • e87a267 chore(packages): add node engine requirement to all packages
  • See full diff in compare view

Updates @peculiar/asn1-ecc from 2.9.3 to 2.9.4

Release notes

Sourced from @​peculiar/asn1-ecc's releases.

v2.9.4

npm publish status

All intended npm packages were published successfully.

What's Changed

Full Changelog: PeculiarVentures/asn1-schema@v2.9.3...v2.9.4

Commits
  • a0608da chore(release): v2.9.4
  • e87a267 chore(packages): add node engine requirement to all packages
  • See full diff in compare view

Updates @peculiar/asn1-pfx from 2.9.3 to 2.9.4

Release notes

Sourced from @​peculiar/asn1-pfx's releases.

v2.9.4

npm publish status

All intended npm packages were published successfully.

What's Changed

Full Changelog: PeculiarVentures/asn1-schema@v2.9.3...v2.9.4

Commits
  • a0608da chore(release): v2.9.4
  • e87a267 chore(packages): add node engine requirement to all packages
  • See full diff in compare view

Updates @peculiar/asn1-pkcs9 from 2.9.3 to 2.9.4

Release notes

Sourced from @​peculiar/asn1-pkcs9's releases.

v2.9.4

npm publish status

All intended npm packages were published successfully.

What's Changed

Full Changelog: PeculiarVentures/asn1-schema@v2.9.3...v2.9.4

Commits
  • a0608da chore(release): v2.9.4
  • e87a267 chore(packages): add node engine requirement to all packages
  • See full diff in compare view

Updates body-parser from 1.20.6 to 1.20.8

Release notes

Sourced from body-parser's releases.

1.20.8

Important

Same code base as 1.20.7. This was created to test the new release process.

What's Changed

Full Changelog: expressjs/body-parser@1.20.7...1.20.8

1.20.7

What's Changed

Full Changelog: expressjs/body-parser@1.20.6...1.20.7

Changelog

Sourced from body-parser's changelog.

1.20.8

  • Same code base as 1.20.7. This was created to test the new release process.

1.20.7

  • deps: qs@~6.16.0
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for body-parser since your current version.


Updates colord from 2.9.3 to 2.10.0

Release notes

Sourced from colord's releases.

v2.10 (RGB color mixing)

  • mix, tints, shades and tones (mix plugin) now accept an optional interpolation color space. LAB stays the default; pass "rgb" to interpolate RGB channels instead — the way browsers and design tools (such as Figma) composite translucent layers.
import { colord, extend } from "colord";
import mixPlugin from "colord/plugins/mix";
extend([mixPlugin]);
colord("#ff0000").mix("#ffffff", 0.5, "rgb").toHex(); // "#ff8080"
colord("#f0f3f1").mix("#007d40", 0.14, "rgb").toHex(); // "#cee2d8" — same as compositing rgba(0, 125, 64, 0.14) over #f0f3f1
colord("#ff0000").tints(3, "rgb").map((c) => c.toHex()); // ["#ff0000", "#ff8080", "#ffffff"]

Changelog

Sourced from colord's changelog.

2.10.0

  • Improve mix plugin by adding an optional "rgb" interpolation mode to mix, tints, tones and shades

2.9.7

  • Make HEX parsing and serialization more than 2x faster

2.9.6

  • Fix: Rotate the unrounded hue so rotate and harmonies preserve the original color
  • Fix: Normalize HWB whiteness + blackness over 100% to gray ❤️ @​spokodev

2.9.5

Both fixes change returned numbers for a small set of colors; toHex() output is unchanged. Snapshots holding h: 360, "hsl(360, …)" or a delta() value may need updating.

2.9.4

  • Fix: Reject malformed color strings in linear time ❤️ @​GAP-dev
Commits

Updates compression from 1.8.1 to 1.8.2

Release notes

Sourced from compression's releases.

v1.8.2

Important

What's Changed

New Contributors

Full Changelog: expressjs/compression@v1.8.1...v1.8.2

Changelog

Sourced from compression's changelog.

1.8.2

Commits
  • 0f97074 1.8.2 (#287)
  • 151f63e fix: destroy compression stream on response close
  • 0a76495 fix: match Cache-Control no-transform directive case-insensitively (#286)
  • c17b6e5 docs: update outdated Brotli note and fix npm install docs URL (#276)
  • 112911a chore(ci): npm-publish via reusable workflows (#269)
  • 1bf5eb0 build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#267)
  • d8fe64d build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#266)
  • b218ff5 build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (#265)
  • 8a1cf8e build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#268)
  • 4a19855 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#257)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for compression since your current version.


Updates enhanced-resolve from 5.24.5 to 5.25.1

Release notes

Sourced from enhanced-resolve's releases.

v5.25.1

Patch Changes

v5.25.0

Minor Changes

Changelog

Sourced from enhanced-resolve's changelog.

5.25.1

Patch Changes

5.25.0

Minor Changes

Commits
  • e913bc5 chore(release): new release (#671)
  • a00ff09 fix: treat only a whole file: URL as one when parsing a request (#670)
  • 835c4fe chore(release): new release (#669)
  • 90e5106 feat: accept file: URL strings where a path is expected (#668)
  • b51c806 ci: fix the flaky "database is locked" failure in the Deno job (#666)
  • c3eee53 chore(deps): update dependencies and migrate to changesets v3 (#665)
  • 70f60e7 chore(deps): bump js-yaml (#664)
  • 1aa1fc3 chore(deps-dev): bump smol-toml from 1.6.1 to 1.8.0 (#663)
  • 3ad59cb chore(deps): bump the dependencies group across 1 directory with 2 updates (#...
  • 7070c25 chore(deps-dev): bump browserslist from 4.28.2 to 4.28.8 (#662)
  • Additional commits viewable in compare view

Updates express from 4.22.2 to 4.22.3

Changelog

Sourced from express's changelog.

4.22.3

  • Allow conditional revalidation for QUERY requests
    • req.fresh now includes QUERY in the freshness check, so QUERY responses can return 304 when a validator matches
  • deps: qs@~6.16.0
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for express since your current version.


Updates fast-uri from 3.1.5 to 3.1.8

Release notes

Sourced from fast-uri's releases.

v3.1.8

⚠️ Security Warning

This security release fixes the following medium-severity security advisory:

Users of the v3.x release line should upgrade to v3.1.8.

Full Changelog: fastify/fast-uri@v3.1.7...v3.1.8

v3.1.7

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.7.

Full Changelog: fastify/fast-uri@v3.1.6...v3.1.7

v3.1.6

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.6.

Full Changelog: fastify/fast-uri@v3.1.5...v3.1.6

Commits
  • ead3ab7 Bumped v3.1.8
  • c88b59e fix: normalize decoded reg-name case
  • 412e40a Bumped v3.1.7
  • 9f4c943 fix: backport port and IP-literal validation to v3.x (#216)
  • 1eb3ce4 fix: treat unterminated bracket hosts as reg-names again (#214)
  • 6f970b2 Bumped v3.1.6
  • d941579 fix: never run IDN canonicalization on bracketed IP literals
  • c0f0279 test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)
  • 37f3417 Merge commit from fork
  • 607bfbe Merge commit from fork
  • Additional commits viewable in compare view

Updates fastq from 1.20.1 to 1.20.3

Release notes

Sourced from fastq's releases.

v1.20.3

Full Changelog: mcollina/fastq@v1.20.2...v1.20.3

v1.20.2

What's Changed

Full Changelog: mcollina/fastq@v1.20.1...v1.20.2

Commits

Updates glob-to-regex.js from 1.2.0 to 1.3.1

Release notes

Sourced from glob-to-regex.js's releases.

v1.3.1

1.3.1 (2026-09-13)

Bug Fixes

  • 🐛 improve magic character matches (3585905)

v1.3.0

1.3.0 (2026-09-13)

Features

  • 🎸 add negation, improve POSIX class support, introduce nodot option (9d304c1)
Commits
  • 2b429f9 Merge pull request #11 from streamich/fix-magic-star
  • 3585905 fix: 🐛 improve magic character matches
  • 3136141 Merge pull request #10 from streamich/better-alignment-with-node
  • 9d304c1 feat: 🎸 add negation, improve POSIX class support, introduce nodot option
  • 1db39ce chore: Revise SECURITY.md for clarity on support and reporting
  • See full diff in compare view

Updates jest-environment-jsdom from 30.4.1 to 30.5.1

Release notes

Sourced from jest-environment-jsdom's releases.

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

v30.5.0

On a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴


This is a big release. It touches jest-runtime, jest-resolve and jest-haste-map in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please open an issue.

Highlights

whenCalledWith

Mock functions can now configure return values per argument list, contributed by @​timkindberg (#16053):

const fn = jest.fn();
fn.whenCalledWith('apple').mockReturnValue('red');
fn.whenCalledWith('banana').mockReturnValue('yellow');
fn.whenCalledWith(expect.any(Number)).mockReturnValue('numeric');
fn('apple'); // 'red'
fn('banana'); // 'yellow'
fn(42); // 'numeric'
fn('grape'); // undefined

The returned object is a real Mock, so mockReturnValueOnce, mockResolvedValue, mockImplementation etc. all chain here too. Argument slots accept literals or any asymmetric matcher, with the same equality semantics as toHaveBeenCalledWith(). Calls that match nothing fall through to the base mock. See the Mock Functions docs for matching and precedence details.

Describe-level retries

jest.retryTimes() can now retry a whole describe block instead of a single test, contributed by @​soltonigiri (#16322). Each attempt reruns the block's beforeAll/afterAll hooks, child tests and nested describes, which helps when tests in a block depend on shared state:

</tr></table> 

... (truncated)

Changelog

Sourced from jest-environment-jsdom's changelog.

30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

30.5.0

Features

  • [@jest/expect-utils, jest-mock] Add mockFn.whenCalledWith(...args) for configuring return values per argument list, with first-class asymmetric-matcher support (#16053)
  • [@jest/expect-utils] Export AsymmetricMatcher and FunctionParameters types (previously private to expect) (#16053)
  • [jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types] --collectTests now expands test.each/describe.each cases and reports per-status counts (skipped/todo via the new wouldRun flag for selected tests) plus a summary line that match a real run, including under --testNamePattern and .only/fdescribe focus on both the circus and jasmine2 runners (#16259)
  • [jest-circus, jest-environment, jest-runtime, jest-types] Add describe-level retries via jest.retryTimes(..., {entireDescribe: true}) (#16322)
  • [jest-circus, jest-message-util, jest-reporters, jest-types] Add retryMessages to AssertionResult and export formatErrorStack, so the retry log renders nested cause and AggregateError sections with code frames instead of serialized [cause]:/[errors]: markers (#16316)
  • [jest-circus, jest-types] Add unhandledErrorsDetailed to Circus.RunResult, so an unhandled rejection reports its cause chain and AggregateError entries with code frames instead of a pre-serialized stack (#16316)
  • [jest-haste-map] Replace NodeWatcher and FSEventsWatcher with @parcel/watcher for the non-watchman watch path (#16188)
  • [jest-resolve] Bump unrs-resolver to 1.12.1, remove jest-pnp-resolver and unnecessary checks (#15721)
  • [jest-resolve] Honor Node's --preserve-symlinks / NODE_PRESERVE_SYMLINKS in the default resolver by passing symlinks: false to unrs-resolver (#16260)
  • [jest-runtime] Apply automocking and manual __mocks__ files to synchronously evaluable ESM graphs on Node 24.9+ - static imports, dynamic import() and require() of an ESM file now generate an automock from the real module's namespace instead of failing with "Attempting to import a mock without a factory". Graphs that need async evaluation (top-level await) or an async-only resolver or transformer still throw (#16391)
  • [jest-runtime] Route process.getBuiltinModule through the sandbox, so it returns the sandbox process and the hooked node:module instead of the host's (#16391)
  • [jest-runtime] Throw an actionable error from module.register() and module.registerHooks() inside a test - the hooks attached to the loader running Jest itself, never saw the sandboxed requires they were meant for, and stayed registered for every later test file in the worker (#16391)
  • [jest-runtime] Surface resolution and import-attribute errors in an ESM graph before executing any of its CJS dependencies on Node 24.9+, matching Node's run-nothing-on-a-broken-graph behavior; the legacy loader on older versions keeps its linking-time execution order (#16391)
  • [jest-runtime] Throw ERR_SOURCE_PHASE_NOT_DEFINED with an actionable message for import source and import.source(), instead of failing at instantiation with V8's bare "Source phase import object is not defined" (#16391)
  • [jest-runtime] Emit the JSON-without-import-attribute deprecation warning once per test file instead of once per worker, so it is no longer silently swallowed for every file after the first (#16391)
  • [jest-runtime] Set import.meta.main to true in the test file and false in every module it loads, matching Node 24+ (

Bumps the npm-development group with 27 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts) | `34.1.0` | `34.2.0` |
| [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.6` | `3.3.7` |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.18` | `1.1.21` |
| [@jridgewell/sourcemap-codec](https://github.com/jridgewell/sourcemaps/tree/HEAD/packages/sourcemap-codec) | `1.5.5` | `1.6.0` |
| [@peculiar/asn1-cms](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/cms) | `2.9.3` | `2.9.4` |
| [@peculiar/asn1-csr](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/csr) | `2.9.3` | `2.9.4` |
| [@peculiar/asn1-ecc](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/ecc) | `2.9.3` | `2.9.4` |
| [@peculiar/asn1-pfx](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pfx) | `2.9.3` | `2.9.4` |
| [@peculiar/asn1-pkcs9](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pkcs9) | `2.9.3` | `2.9.4` |
| [body-parser](https://github.com/expressjs/body-parser) | `1.20.6` | `1.20.8` |
| [colord](https://github.com/omgovich/colord) | `2.9.3` | `2.10.0` |
| [compression](https://github.com/expressjs/compression) | `1.8.1` | `1.8.2` |
| [enhanced-resolve](https://github.com/webpack/enhanced-resolve) | `5.24.5` | `5.25.1` |
| [express](https://github.com/expressjs/express) | `4.22.2` | `4.22.3` |
| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.5` | `3.1.8` |
| [fastq](https://github.com/mcollina/fastq) | `1.20.1` | `1.20.3` |
| [glob-to-regex.js](https://github.com/streamich/glob-to-regex) | `1.2.0` | `1.3.1` |
| [jest-environment-jsdom](https://github.com/jestjs/jest/tree/HEAD/packages/jest-environment-jsdom) | `30.4.1` | `30.5.1` |
| [memfs](https://github.com/streamich/memfs) | `4.68.1` | `4.78.1` |
| [minimizer-webpack-plugin](https://github.com/webpack/minimizer-webpack-plugin) | `5.6.1` | `5.10.1` |
| [nanoid](https://github.com/ai/nanoid) | `3.3.18` | `3.3.19` |
| [postcss](https://github.com/postcss/postcss) | `8.5.26` | `8.5.28` |
| [sass](https://github.com/sass/dart-sass) | `1.102.0` | `1.104.1` |
| [svg-parser](https://github.com/Rich-Harris/svg-parser) | `2.0.4` | `2.1.0` |
| [svgo](https://github.com/svg/svgo) | `3.3.4` | `3.3.5` |
| [webpack](https://github.com/webpack/webpack) | `5.109.2` | `5.111.0` |
| [webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware) | `7.4.5` | `7.4.6` |



Updates `@wordpress/scripts` from 34.1.0 to 34.2.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@34.2.0/packages/scripts)

Updates `@eslint/eslintrc` from 3.3.6 to 3.3.7
- [Release notes](https://github.com/eslint/eslintrc/releases)
- [Changelog](https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md)
- [Commits](eslint/eslintrc@eslintrc-v3.3.6...eslintrc-v3.3.7)

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

Updates `@jridgewell/sourcemap-codec` from 1.5.5 to 1.6.0
- [Changelog](https://github.com/jridgewell/sourcemaps/blob/main/packages/sourcemap-codec/CHANGELOG.md)
- [Commits](https://github.com/jridgewell/sourcemaps/commits/sourcemap-codec/1.6.0/packages/sourcemap-codec)

Updates `@peculiar/asn1-cms` from 2.9.3 to 2.9.4
- [Release notes](https://github.com/PeculiarVentures/asn1-schema/releases)
- [Commits](https://github.com/PeculiarVentures/asn1-schema/commits/v2.9.4/packages/cms)

Updates `@peculiar/asn1-csr` from 2.9.3 to 2.9.4
- [Release notes](https://github.com/PeculiarVentures/asn1-schema/releases)
- [Commits](https://github.com/PeculiarVentures/asn1-schema/commits/v2.9.4/packages/csr)

Updates `@peculiar/asn1-ecc` from 2.9.3 to 2.9.4
- [Release notes](https://github.com/PeculiarVentures/asn1-schema/releases)
- [Commits](https://github.com/PeculiarVentures/asn1-schema/commits/v2.9.4/packages/ecc)

Updates `@peculiar/asn1-pfx` from 2.9.3 to 2.9.4
- [Release notes](https://github.com/PeculiarVentures/asn1-schema/releases)
- [Commits](https://github.com/PeculiarVentures/asn1-schema/commits/v2.9.4/packages/pfx)

Updates `@peculiar/asn1-pkcs9` from 2.9.3 to 2.9.4
- [Release notes](https://github.com/PeculiarVentures/asn1-schema/releases)
- [Commits](https://github.com/PeculiarVentures/asn1-schema/commits/v2.9.4/packages/pkcs9)

Updates `body-parser` from 1.20.6 to 1.20.8
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.6...1.20.8)

Updates `colord` from 2.9.3 to 2.10.0
- [Release notes](https://github.com/omgovich/colord/releases)
- [Changelog](https://github.com/omgovich/colord/blob/master/CHANGELOG.md)
- [Commits](https://github.com/omgovich/colord/commits/v2.10)

Updates `compression` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](expressjs/compression@v1.8.1...v1.8.2)

Updates `enhanced-resolve` from 5.24.5 to 5.25.1
- [Release notes](https://github.com/webpack/enhanced-resolve/releases)
- [Changelog](https://github.com/webpack/enhanced-resolve/blob/main/CHANGELOG.md)
- [Commits](webpack/enhanced-resolve@v5.24.5...v5.25.1)

Updates `express` from 4.22.2 to 4.22.3
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.3/History.md)
- [Commits](expressjs/express@v4.22.2...v4.22.3)

Updates `fast-uri` from 3.1.5 to 3.1.8
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.8)

Updates `fastq` from 1.20.1 to 1.20.3
- [Release notes](https://github.com/mcollina/fastq/releases)
- [Commits](mcollina/fastq@v1.20.1...v1.20.3)

Updates `glob-to-regex.js` from 1.2.0 to 1.3.1
- [Release notes](https://github.com/streamich/glob-to-regex/releases)
- [Commits](streamich/glob-to-regex@v1.2.0...v1.3.1)

Updates `jest-environment-jsdom` from 30.4.1 to 30.5.1
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest-environment-jsdom)

Updates `memfs` from 4.68.1 to 4.78.1
- [Release notes](https://github.com/streamich/memfs/releases)
- [Changelog](https://github.com/streamich/memfs/blob/master/CHANGELOG.md)
- [Commits](streamich/memfs@v4.68.1...v4.78.1)

Updates `minimizer-webpack-plugin` from 5.6.1 to 5.10.1
- [Release notes](https://github.com/webpack/minimizer-webpack-plugin/releases)
- [Changelog](https://github.com/webpack/minimizer-webpack-plugin/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webpack/minimizer-webpack-plugin/commits)

Updates `nanoid` from 3.3.18 to 3.3.19
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@3.3.18...3.3.19)

Updates `postcss` from 8.5.26 to 8.5.28
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.26...8.5.28)

Updates `sass` from 1.102.0 to 1.104.1
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](sass/dart-sass@1.102.0...1.104.1)

Updates `svg-parser` from 2.0.4 to 2.1.0
- [Release notes](https://github.com/Rich-Harris/svg-parser/releases)
- [Changelog](https://github.com/Rich-Harris/svg-parser/blob/master/CHANGELOG.md)
- [Commits](Rich-Harris/svg-parser@v2.0.4...v2.1.0)

Updates `svgo` from 3.3.4 to 3.3.5
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

Updates `webpack` from 5.109.2 to 5.111.0
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.109.2...v5.111.0)

Updates `webpack-dev-middleware` from 7.4.5 to 7.4.6
- [Release notes](https://github.com/webpack/webpack-dev-middleware/releases)
- [Changelog](https://github.com/webpack/webpack-dev-middleware/blob/v7.4.6/CHANGELOG.md)
- [Commits](webpack/webpack-dev-middleware@v7.4.5...v7.4.6)

---
updated-dependencies:
- dependency-name: "@wordpress/scripts"
  dependency-version: 34.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: "@eslint/eslintrc"
  dependency-version: 3.3.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@jridgewell/sourcemap-codec"
  dependency-version: 1.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: "@peculiar/asn1-cms"
  dependency-version: 2.9.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@peculiar/asn1-csr"
  dependency-version: 2.9.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@peculiar/asn1-ecc"
  dependency-version: 2.9.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@peculiar/asn1-pfx"
  dependency-version: 2.9.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: "@peculiar/asn1-pkcs9"
  dependency-version: 2.9.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: body-parser
  dependency-version: 1.20.8
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: colord
  dependency-version: 2.10.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: compression
  dependency-version: 1.8.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: enhanced-resolve
  dependency-version: 5.25.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: express
  dependency-version: 4.22.3
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: fastq
  dependency-version: 1.20.3
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: glob-to-regex.js
  dependency-version: 1.3.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: jest-environment-jsdom
  dependency-version: 30.5.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: memfs
  dependency-version: 4.78.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: minimizer-webpack-plugin
  dependency-version: 5.10.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: nanoid
  dependency-version: 3.3.19
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: sass
  dependency-version: 1.104.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: svg-parser
  dependency-version: 2.1.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: svgo
  dependency-version: 3.3.5
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: webpack
  dependency-version: 5.111.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: webpack-dev-middleware
  dependency-version: 7.4.6
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm-development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 23, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/main/npm-development-fbb50d7420 branch September 23, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants