Skip to content

build(deps-dev): bump the npm-development group across 1 directory with 5 updates - #60

Merged
zoeyrose merged 3 commits into
mainfrom
dependabot/npm_and_yarn/npm-development-4d14cbc31f
Oct 3, 2026
Merged

zoeyrose merged 3 commits into
mainfrom
dependabot/npm_and_yarn/npm-development-4d14cbc31f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-development group with 5 updates in the / directory:

Package From To
@semantic-release/github 12.0.9 12.0.10
astro 7.3.2 7.3.5
conventional-changelog-conventionalcommits 10.2.1 10.4.0
prettier 3.9.6 3.9.9
prettier-plugin-astro 0.14.1 1.1.0

Updates @semantic-release/github from 12.0.9 to 12.0.10

Release notes

Sourced from @​semantic-release/github's releases.

v12.0.10

12.0.10 (2026-09-21)

Bug Fixes

  • deps: update dependency @​octokit/plugin-paginate-rest to v15 (#1284) (a63f458)
Commits
  • a63f458 fix(deps): update dependency @​octokit/plugin-paginate-rest to v15 (#1284)
  • f5f6d0e build(deps): bump brace-expansion (#1300)
  • eaffbba build(deps): bump undici from 6.27.0 to 6.28.1 (#1301)
  • 07686dc chore(deps): update dependency undici to v7.29.0 [security] (#1283)
  • 9f010ee build(deps-dev): bump baseline-browser-mapping from 2.10.42 to 2.11.25 (#1295)
  • 81eeeca build(deps-dev): bump js-yaml from 3.15.0 to 3.15.2 (#1294)
  • 43c2210 build(deps-dev): bump fast-uri from 3.1.4 to 3.1.8 (#1290)
  • e703272 build(deps-dev): bump browserslist from 4.28.4 to 4.29.0 (#1291)
  • e7f4b4b chore(deps): update dependency prettier to v3.9.8 (#1298)
  • 2e9e42b chore(deps): update dependency prettier to v3.9.7 (#1296)
  • Additional commits viewable in compare view

Updates astro from 7.3.2 to 7.3.5

Release notes

Sourced from astro's releases.

astro@7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

astro@7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2

astro@7.3.3

Patch Changes

  • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

  • #17942 0bc5715 Thanks @​matthewp! - Returns appropriate 400 and 404 responses from the image endpoint for invalid and missing local image paths

  • #17700 b2222fc Thanks @​winklemad! - Fixes Astro.preferredLocaleList returning an empty list when a locale is configured with the object form ({ path, codes }) and the browser sends the code with different casing or an underscore, such as en-US matching a configured en-us

  • #17941 394ff79 Thanks @​matthewp! - Fixes astro preview --ignore-lock (and astro dev --ignore-lock) being refused when run from an AI agent environment. The flag now starts the server in the foreground instead of erroring, since agent detection only inferred background mode and was never explicitly requested. An explicit --background combined with --ignore-lock still errors.

  • #17928 3277927 Thanks @​ArmandPhilippot! - Fixes TypeScript autocompletion for getImage() to suggest all available predefined options.

... (truncated)

Changelog

Sourced from astro's changelog.

7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2

7.3.3

Patch Changes

  • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

  • #17942 0bc5715 Thanks @​matthewp! - Returns appropriate 400 and 404 responses from the image endpoint for invalid and missing local image paths

  • #17700 b2222fc Thanks @​winklemad! - Fixes Astro.preferredLocaleList returning an empty list when a locale is configured with the object form ({ path, codes }) and the browser sends the code with different casing or an underscore, such as en-US matching a configured en-us

  • #17941 394ff79 Thanks @​matthewp! - Fixes astro preview --ignore-lock (and astro dev --ignore-lock) being refused when run from an AI agent environment. The flag now starts the server in the foreground instead of erroring, since agent detection only inferred background mode and was never explicitly requested. An explicit --background combined with --ignore-lock still errors.

... (truncated)

Commits

Updates conventional-changelog-conventionalcommits from 10.2.1 to 10.4.0

Release notes

Sourced from conventional-changelog-conventionalcommits's releases.

conventional-changelog-conventionalcommits: v10.4.0

Features

  • fail loudly when a preset is rendered by an old writer (#1539) (341e3f0), closes #1495

conventional-changelog-conventionalcommits: v10.3.0

Features

Bug Fixes

Changelog

Sourced from conventional-changelog-conventionalcommits's changelog.

10.4.0 (2026-08-18)

Features

  • fail loudly when a preset is rendered by an old writer (#1539) (341e3f0), closes #1495

10.3.0 (2026-08-10)

Features

Bug Fixes

Commits
  • 340ad83 chore(release): monorepo release (#1540)
  • 341e3f0 feat(conventional-changelog-angular,conventional-changelog-conventionalcommit...
  • cbd52fb chore(release): monorepo release (#1530)
  • 612d368 fix(conventional-changelog,conventional-changelog-writer,conventional-changel...
  • 7be33d4 feat(conventional-changelog-angular,conventional-changelog-conventionalcommit...
  • a8ef1ed feat(conventional-changelog-angular,conventional-changelog-conventionalcommit...
  • 18332e8 test: remove duplicate repository fields from fixtures (#1527)
  • See full diff in compare view

Updates prettier from 3.9.6 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
</tr></table> 

... (truncated)

Commits

Updates prettier-plugin-astro from 0.14.1 to 1.1.0

Release notes

Sourced from prettier-plugin-astro's releases.

v1.1.0

Minor Changes

  • bfbb6c5: Adds support for three astroAllowShorthand formatting modes:

    • When unset / undefined, the attributes stay as written, i.e <Comp value={value} /> and <Comp {value} /> can co-exist in the same file.
    • When set to true, attributes that can be written in the shorthand form will automatically be transformed. <Comp value={value} /> will become <Comp {value} />
    • When set to false, attributes will always be expanded to their full form.

Patch Changes

  • 4b3547e: Fix non-idempotent indentation of multiline comments nested inside CSS rules.
  • edfb35f: Fixes raw elements being forcefully paired up when self-closed.

v1.0.1

Patch Changes

  • 5b5a735: Publish TypeScript declarations for Astro plugin options.
  • 6154471: Fixes an error when a JavaScript comment appears before a raw or custom-printed element, such as a <script> in the alternate branch of a conditional expression.
  • fabb28f: Fix non-idempotent CSS <style> block formatting with astroCompressHTML set to 'html' or 'none'.

v1.0.0

Major Changes

  • a8bf1a3: Raises the minimum supported Node version to 22.12.0.

  • 595d47f: The plugin has been fully rewritten on top of Astro 7's new Rust compiler. This rewrite fixes many long-standing issues, such as certain elements not being handled properly inside expressions.

    Whitespace formatting now matches Astro’s whitespace handling, and a new astroCompressHTML option has been added to match Astro's compressHTML setting. If you set compressHTML in your Astro config, also set astroCompressHTML in your Prettier config to match.

    In addition, this rewrite has allowed us to more closely match Prettier's built-in JSX and HTML formatting, leading to less cosmetic differences between the different files in your repo.

v1.0.0-beta.2

Patch Changes

  • cc30d24: Fixes various formatting issues when using astroCompressHTML: 'html' or 'none':

    • Fixes a stray > being added after an empty or ignored element that is followed by a sibling.
    • Fixes closing tags being split from trailing void elements like <img>.
    • Fixes whitespace being added inside tables, lists, and captions under htmlWhitespaceSensitivity: 'strict'.
    • Fixes line breaks around inline elements being replaced by spaces.
    • Allows inline elements to wrap at the print width without adding rendered whitespace.
    • Keeps inline elements written on one line on that line.
    • Fixes components with dotted names like <Astro.self> losing their closing tags or failing to format.
    • Fixes whitespace around inline-block elements and reflowing markup written on one line.
    • Fixes quotes in style attribute values being written unescaped, corrupting the attribute and breaking the next format.
    • Fixes children hugging the closing bracket when an element's attributes span multiple lines.
    • Fixes whitespace being added around a lone <slot />, which stopped :empty from matching the container.
    • Fixes srcset values being mangled when a URL contains a comma, such as a data: URI or query string.
    • Lays out block-level elements like HTML.
    • Fixes whitespace being removed around a lone <slot />, which allowed :empty to start matching the container.

... (truncated)

Changelog

Sourced from prettier-plugin-astro's changelog.

1.1.0

Minor Changes

  • bfbb6c5: Adds support for three astroAllowShorthand formatting modes:

    • When unset / undefined, the attributes stay as written, i.e <Comp value={value} /> and <Comp {value} /> can co-exist in the same file.
    • When set to true, attributes that can be written in the shorthand form will automatically be transformed. <Comp value={value} /> will become <Comp {value} />
    • When set to false, attributes will always be expanded to their full form.

Patch Changes

  • 4b3547e: Fix non-idempotent indentation of multiline comments nested inside CSS rules.
  • edfb35f: Fixes raw elements being forcefully paired up when self-closed.

1.0.1

Patch Changes

  • 5b5a735: Publish TypeScript declarations for Astro plugin options.
  • 6154471: Fixes an error when a JavaScript comment appears before a raw or custom-printed element, such as a <script> in the alternate branch of a conditional expression.
  • fabb28f: Fix non-idempotent CSS <style> block formatting with astroCompressHTML set to 'html' or 'none'.

1.0.0

Major Changes

  • a8bf1a3: Raises the minimum supported Node version to 22.12.0.

  • 595d47f: The plugin has been fully rewritten on top of Astro 7's new Rust compiler. This rewrite fixes many long-standing issues, such as certain elements not being handled properly inside expressions.

    Whitespace formatting now matches Astro’s whitespace handling, and a new astroCompressHTML option has been added to match Astro's compressHTML setting. If you set compressHTML in your Astro config, also set astroCompressHTML in your Prettier config to match.

    In addition, this rewrite has allowed us to more closely match Prettier's built-in JSX and HTML formatting, leading to less cosmetic differences between the different files in your repo.

1.0.0-beta.2

Patch Changes

  • cc30d24: Fixes various formatting issues when using astroCompressHTML: 'html' or 'none':

    • Fixes a stray > being added after an empty or ignored element that is followed by a sibling.
    • Fixes closing tags being split from trailing void elements like <img>.
    • Fixes whitespace being added inside tables, lists, and captions under htmlWhitespaceSensitivity: 'strict'.
    • Fixes line breaks around inline elements being replaced by spaces.
    • Allows inline elements to wrap at the print width without adding rendered whitespace.
    • Keeps inline elements written on one line on that line.
    • Fixes components with dotted names like <Astro.self> losing their closing tags or failing to format.
    • Fixes whitespace around inline-block elements and reflowing markup written on one line.
    • Fixes quotes in style attribute values being written unescaped, corrupting the attribute and breaking the next format.
    • Fixes children hugging the closing bracket when an element's attributes span multiple lines.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for prettier-plugin-astro since your current version.


Maintainer refresh

Reformatted Astro source for the updated formatter, preserving rendered content. Installation, 34 tests and deployment dry run passed; independent source review passed. Audit remains blocked by unpatched GHSA-vfj7-8cjw-p6xm and GHSA-ch52-4w7c-c8xp; no audit bypass was applied.

Verified current main: 6415184e0e85db0d9deb275f16d5e0335200f5c9; refreshed head: 99d8bbadc57de2965129efe0bc50c2a7d09bac82. Standard lockfiles, immutable CI references and production identities remain. No merge or deployment was performed.

Audit gate refresh

Merged the current main commit to inherit the reviewed changeset-based dependency audit and resolve any branch conflicts. Standard lockfiles and normal dependency ranges remain; no custom locks, accepted-version lists or advisory exceptions were added. TypeScript remains on version 6. Independent source review approved this refreshed revision. Local acceptance is recorded separately; Linux validation, Windows checks/build, Conventional PR title, CodeQL and the Pages preview now all pass for this exact head.

Verified main: d2aab153e5e1ea41b49ecc900bdee952e089dd5a; refreshed head: 129bb3e04ed0d92f4a8e217e955aef92d48029b1.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 26, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Deploying atrinik-website with  Cloudflare Pages  Cloudflare Pages

Latest commit: 129bb3e
Status: ✅  Deploy successful!
Preview URL: https://0d12c319.atrinik-website.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-npm.atrinik-website.pages.dev

View logs

@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Sep 26, 2026
@zoeyrose zoeyrose moved this to Review in Atrinik work Sep 26, 2026
…th 5 updates

Bumps the npm-development group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@semantic-release/github](https://github.com/semantic-release/github) | `12.0.9` | `12.0.10` |
| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.3.2` | `7.3.5` |
| [conventional-changelog-conventionalcommits](https://github.com/conventional-changelog/conventional-changelog/tree/HEAD/packages/conventional-changelog-conventionalcommits) | `10.2.1` | `10.4.0` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [prettier-plugin-astro](https://github.com/withastro/prettier-plugin-astro) | `0.14.1` | `1.1.0` |



Updates `@semantic-release/github` from 12.0.9 to 12.0.10
- [Release notes](https://github.com/semantic-release/github/releases)
- [Commits](semantic-release/github@v12.0.9...v12.0.10)

Updates `astro` from 7.3.2 to 7.3.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro)

Updates `conventional-changelog-conventionalcommits` from 10.2.1 to 10.4.0
- [Release notes](https://github.com/conventional-changelog/conventional-changelog/releases)
- [Changelog](https://github.com/conventional-changelog/conventional-changelog/blob/master/packages/conventional-changelog-conventionalcommits/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/conventional-changelog/commits/conventional-changelog-conventionalcommits-v10.4.0/packages/conventional-changelog-conventionalcommits)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `prettier-plugin-astro` from 0.14.1 to 1.1.0
- [Release notes](https://github.com/withastro/prettier-plugin-astro/releases)
- [Changelog](https://github.com/withastro/prettier-plugin-astro/blob/main/CHANGELOG.md)
- [Commits](withastro/prettier-plugin-astro@v0.14.1...v1.1.0)

---
updated-dependencies:
- dependency-name: "@semantic-release/github"
  dependency-version: 12.0.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: astro
  dependency-version: 7.3.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: conventional-changelog-conventionalcommits
  dependency-version: 10.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-development
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-development
- dependency-name: prettier-plugin-astro
  dependency-version: 1.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-development-4d14cbc31f branch from 91287b6 to 6ac92eb Compare October 3, 2026 19:04
@zoeyrose
zoeyrose merged commit e0d7338 into main Oct 3, 2026
9 checks passed
@zoeyrose
zoeyrose deleted the dependabot/npm_and_yarn/npm-development-4d14cbc31f branch October 3, 2026 23:45
@github-project-automation github-project-automation Bot moved this from Review to Done in Atrinik work Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant