Skip to content

fix(deps): update all dependencies - #83

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

fix(deps): update all dependencies#83
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@1stg/app-config (source) ^8.1.0^15.0.0 age confidence devDependencies major
@ant-design/icons (source) ^5.0.1^6.0.0 age confidence dependencies major
@react-enhanced/hooks (source) ^0.4.1^0.5.0 age confidence dependencies minor
@rollup/plugin-replace (source) ^5.0.7^6.0.0 age confidence devDependencies major
@rollup/plugin-strip (source) ^2.1.0^3.0.0 age confidence devDependencies major
@types/express (source) ^4.17.21^5.0.0 age confidence devDependencies major
@types/react (source) ^18.0.33^19.0.0 age confidence devDependencies major
@types/react-dom (source) ^18.0.11^19.0.0 age confidence devDependencies major
@vitejs/plugin-react (source) ^3.1.0^6.0.0 age confidence devDependencies major
@welldone-software/why-did-you-render ^7.0.1^10.0.0 age confidence devDependencies major
antd (source) ^4.24.16^6.0.0 age confidence dependencies major
body-parser ^1.20.3^2.0.0 age confidence devDependencies major
clsx ^1.2.1^2.0.0 age confidence devDependencies major
consola ^2.15.3^3.0.0 age confidence devDependencies major
dotenv ^16.4.7^17.0.0 age confidence devDependencies major
dotenv-expand ^10.0.0^13.0.0 age confidence devDependencies major
express (source) ^4.21.2^5.0.0 age confidence devDependencies major
http-proxy-middleware ^2.0.7^4.0.0 age confidence devDependencies major
node (source) 18.20.724.19.0 age confidence major
nodemon (source) ^2.0.22^3.0.0 age confidence devDependencies major
path-to-regexp ^6.3.0^8.0.0 age confidence devDependencies major
pnpm (source) 8.1.111.20.0 age confidence packageManager major
proxy-agent (source) ^5.0.0^8.0.0 age confidence devDependencies major
react (source) ^18.2.0^19.0.0 age confidence dependencies major
react-dom (source) ^18.2.0^19.0.0 age confidence dependencies major
react-error-boundary (source) ^4.0.13^6.0.0 age confidence dependencies major
react-router-dom (source) ^6.10.0^7.0.0 age confidence dependencies major
rollup (source) ^3.29.5^4.0.0 age confidence devDependencies major
rollup-plugin-visualizer ^5.12.0^7.0.0 age confidence devDependencies major
tsx (source) ^3.14.0^4.0.0 age confidence devDependencies major
type-fest ^3.13.1^5.0.0 age confidence devDependencies major
typescript (source) ^5.5.4^7.0.0 age confidence devDependencies major
vite (source) ^4.2.1^8.0.0 age confidence devDependencies major

Release Notes

1stG/configs (@​1stg/app-config)

v15.0.0

Compare Source

Major Changes
Patch Changes

v14.3.0

Compare Source

Minor Changes
Patch Changes

v14.2.0

Compare Source

Minor Changes
Patch Changes

v14.1.0

Compare Source

Minor Changes
Patch Changes

v14.0.0

Compare Source

Major Changes
Patch Changes

v13.1.0

Compare Source

Minor Changes
Patch Changes

v13.0.1

Compare Source

Patch Changes

v13.0.0

Compare Source

Major Changes
Patch Changes

v12.0.1

Compare Source

Patch Changes

v12.0.0

Compare Source

Major Changes
Patch Changes

v11.1.2

Compare Source

Patch Changes

v11.1.1

Compare Source

Patch Changes

v11.1.0

Compare Source

Minor Changes
Patch Changes

v11.0.3

Compare Source

Patch Changes

v11.0.2

Compare Source

Patch Changes

v11.0.1

Compare Source

Patch Changes

v11.0.0

Compare Source

Major Changes
Patch Changes

v10.0.1

Compare Source

Patch Changes

v10.0.0

Compare Source

Major Changes
Patch Changes

v9.0.1

Compare Source

Patch Changes

v9.0.0

Compare Source

Major Changes
Patch Changes
ant-design/ant-design-icons (@​ant-design/icons)

v6.3.2

Compare Source

v6.3.1

Compare Source

v6.3.0

Compare Source

v6.2.5

Compare Source

v5.4.0

Compare Source

v5.3.7

Compare Source

v5.3.6

Compare Source

v5.3.5

Compare Source

v5.3.4

Compare Source

v5.3.3

Compare Source

v5.3.2

Compare Source

v5.3.1

Compare Source

v5.3.0

Compare Source

v5.2.6

Compare Source

v5.2.5

Compare Source

v5.2.4

Compare Source

v5.2.3

Compare Source

v5.2.2

Compare Source

v5.2.1

Compare Source

v5.2.0

Compare Source

v5.1.4

Compare Source

v5.1.3

Compare Source

v5.1.2

Compare Source

v5.1.1

Compare Source

v5.1.0

Compare Source

rx-ts/react (@​react-enhanced/hooks)

v0.5.0

Compare Source

Minor Changes

v0.4.2

Compare Source

Patch Changes
rollup/plugins (@​rollup/plugin-replace)

v6.0.3

2025-10-29

Bugfixes
  • fix: update delimiters to respect valid js identifier chars (#​1938)

v6.0.2

2024-12-15

Bugfixes
  • fix: add missing types for objectGuards option (#​1818)

v6.0.1

2024-09-23

Bugfixes
  • fix: The preventAssignment option is treated as a value to replace (#​1768)

v6.0.0

2024-09-23

Breaking Changes
  • fix!: objectGuards doesn't take effects (#​1764)
rollup/plugins (@​rollup/plugin-strip)

v3.0.4

Compare Source

2023-10-15

Bugfixes
  • fix: bump magic-string version #​1596

v3.0.3

Compare Source

2023-10-05

Bugfixes
  • fix: ensure rollup 4 compatibility #​1595

v3.0.2

Compare Source

2022-12-17

Bugfixes

v3.0.1

Compare Source

2022-10-21

Updates
  • chore: update rollup dependencies (3038271)

v3.0.0

2022-10-10

Breaking Changes
vitejs/vite-plugin-react (@​vitejs/plugin-react)

v6.0.5

Compare Source

Fixed the react compiler preset filter to be linear (#​1353)

The improved filter in v6.0.3 was non-linear and caused a performance regression (#​1349). The filter was changed to be linear to avoid that.

v6.0.4

Compare Source

Fixed $RefreshSig$ is not defined error when running vite dev with NODE_ENV=production

When running vite dev with NODE_ENV=production, the app errored with $RefreshSig$ is not defined.
This error is now fixed.

v6.0.3

Compare Source

v6.0.2

Compare Source

Allow all options in reactCompilerPreset (#​1189)

This is a type only change. Only compilationMode and target options were available for reactCompilerPreset.

v6.0.1

Compare Source

Expand @rolldown/plugin-babel peer dep range (#​1146)

Expanded @rolldown/plugin-babel peer dep range to include ^0.2.0.

v6.0.0

Compare Source

v5.2.0

Compare Source

v5.1.4

Compare Source

Fix canSkipBabel not accounting for babel.overrides (#​1098)

When configuring babel.overrides without top-level plugins or presets, Babel was incorrectly skipped. The canSkipBabel function now checks for overrides.length to ensure override configurations are processed.

v5.1.3

Compare Source

v5.1.2

Compare Source

v5.1.1

Compare Source

Update code to support newer rolldown-vite (#​976)

rolldown-vite will remove optimizeDeps.rollupOptions in favor of optimizeDeps.rolldownOptions soon. This plugin now uses optimizeDeps.rolldownOptions to support newer rolldown-vite. Please update rolldown-vite to the latest version if you are using an older version.

v5.1.0

Compare Source

Add @vitejs/plugin-react/preamble virtual module for SSR HMR (#​890)

SSR applications can now initialize HMR runtime by importing @vitejs/plugin-react/preamble at the top of their client entry instead of manually calling transformIndexHtml. This simplifies SSR setup for applications that don't use the transformIndexHtml API.

Fix raw Rolldown support for Rolldown 1.0.0-beta.44+ (#​930)

Rolldown 1.0.0-beta.44+ removed the top-level jsx option in favor of transform.jsx. This plugin now uses the transform.jsx option to support Rolldown 1.0.0-beta.44+.

v5.0.4

Compare Source

Perf: use native refresh wrapper plugin in rolldown-vite (#​881)

v5.0.3

Compare Source

HMR did not work for components imported with queries with rolldown-vite (#​872)
Perf: simplify refresh wrapper generation (#​835)

v5.0.2

Compare Source

Skip transform hook completely in rolldown-vite in dev if possible (#​783)

[v5.0.1](https://

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot

changeset-bot Bot commented Mar 1, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: cd3c974

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ellipsis-dev ellipsis-dev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

Looks good to me! 👍

Reviewed everything up to d514768 in 10 seconds. Click for details.
  • Reviewed 110 lines of code in 2 files
  • Skipped 1 files when reviewing.
  • Skipped posting 0 draft comments. View those below.
  • Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.

Workflow ID: wflow_aTY1xPSVqP4PpjO8

You can customize Ellipsis by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.

@renovate
renovate Bot force-pushed the renovate/all branch 5 times, most recently from 2c2684f to 9b39d2a Compare March 10, 2026 01:23
@renovate
renovate Bot force-pushed the renovate/all branch 6 times, most recently from 59f4e0b to c7309ea Compare March 16, 2026 10:09
@renovate
renovate Bot force-pushed the renovate/all branch 6 times, most recently from 2f8b511 to bb7900b Compare March 24, 2026 13:35
@socket-security

socket-security Bot commented Mar 24, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm chrono-node is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@1stg/app-config@15.0.0npm/chrono-node@2.9.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/chrono-node@2.9.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@1stg/app-config@15.0.0npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from f50792b to 89d51d2 Compare March 31, 2026 01:10
@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from a19530b to a9197cc Compare April 23, 2026 15:04
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 9d29f78 to e9893fe Compare April 29, 2026 14:43
@renovate
renovate Bot force-pushed the renovate/all branch 10 times, most recently from 2f4c2b2 to 16edb1b Compare May 11, 2026 10:50
@renovate
renovate Bot force-pushed the renovate/all branch 8 times, most recently from 264c85d to a1481e8 Compare May 18, 2026 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants