Skip to content

build(deps-dev): bump the npm-dependencies group across 1 directory with 2 updates - #98

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-b0408f2f5a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-b0408f2f5a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-dependencies group with 2 updates in the / directory: axe-core and wrangler.

Updates axe-core from 4.13.0 to 4.14.0

Release notes

Sourced from axe-core's releases.

Release 4.14.0

This release enables a new rule, and introduces new violations in some existing rules. These can cause the issue totals to go up from a previous version. Similarly we've included various bug fixes to false positives which may see the issue count go down as well. This release focused on various performance improvements which should speed runs up 20% - 40% on most pages. On especially large pages we've measured a 15x performance improvement.

Features

Bug Fixes

Changelog

Sourced from axe-core's changelog.

4.14.0 (2026-10-05)

Features

Bug Fixes

Commits
  • e797173 chore(release): v4.14.0 (#5438)
  • 6976881 chore(release): 4.14.0
  • d53cb0a fix(label-content-name-mismatch): add support for cjk word splitting (#5437)
  • 35a38d8 fix(aria-required-children): explain presentational children that cannot be i...
  • 2ba0812 fix(target-size): ignore overlapping links with the same destination (#5428)
  • 1e33c6c fix(aria-allowed-attr): report case-sensitive aria attributes with non-lowerc...
  • f59642e chore: bump mocha from 11.8.0 to 12.0.2 (#5426)
  • 6efcb6e chore: bump emoji-regex from 10.6.0 to 11.0.0 (#5427)
  • 2da49a3 chore: bump the npm-low-risk group across 1 directory with 7 updates (#5425)
  • aa4a0a1 fix(aria-hidden-focus): suggest removing aria-hidden in the fail messages (#5...
  • Additional commits viewable in compare view

Updates wrangler from 4.147.0 to 4.148.0

Release notes

Sourced from wrangler's releases.

wrangler@4.148.0

Minor Changes

  • #16051 b4e1299 Thanks @​devteamaegis! - Add --source-namespace and --source-repo-name to wrangler queues subscription create for the artifacts.repo source

    The Event Subscriptions API requires source.namespace and source.repo_name for artifacts.repo subscriptions, but Wrangler had no way to pass them, so --source artifacts.repo always failed with a validation error. Both flags are now required for this source, and wrangler queues subscription get shows the subscription's resource as <namespace>/<repo-name>.

  • #15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

  • #16005 4d308f6 Thanks @​oOPa! - Add a --experimental-mode instant option to wrangler kv namespace create

    This lets entitled accounts create Workers KV Instant namespaces while the feature is in private beta.

  • #16030 aa2f9b7 Thanks @​edmundhung! - Add email-protected Quick Tunnels to wrangler dev

    Pass one or more --tunnel-allowed-mail flags to require email authentication when exposing a local development server through a Quick Tunnel. Each value can be an exact email address or a domain pattern.

  • #15283 2dde890 Thanks @​shubhxho! - Support deleting secrets with wrangler versions secret bulk

    Set a secret's value to null in JSON input to remove it from the new Worker version. Bulk output now distinguishes between created and deleted secrets, so retrying wrangler secret bulk with wrangler versions secret bulk preserves requested deletions. Deploy the new version with wrangler versions deploy to apply the changes to production traffic.

Patch Changes

  • #15534 2b1a0ca Thanks @​vahidshaik1901! - Improve guidance for conflicting Wrangler configuration files

    When user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.

  • #16014 c492d63 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261001.1 ^5.20261005.1
    workerd 1.20261001.1 1.20261005.1

... (truncated)

Commits
  • 540f084 Version Packages (#16034)
  • 42c7219 [wrangler] Fix r2 object put and r2 bulk put storing a different key in local...
  • 2dde890 [wrangler] Clarify secret version errors and support versions bulk deletions ...
  • b4e1299 [wrangler] Add --source-namespace and --source-repo-name for artifacts.repo q...
  • 2c23c83 [wrangler] Retry K2 E2E produce requests through workers.dev propagation (#16...
  • 14f0339 [wrangler] Include default module rules in generated types (#15573)
  • 26e03e2 [wrangler] Print temporary account notices to stderr (#16068)
  • aa2f9b7 [wrangler][vite-plugin] Support protected Quick Tunnels (#16030)
  • 4d308f6 [wrangler] Add Workers KV Instant mode to namespace create command (#16005)
  • f8cdcb9 [miniflare] Manage Flagship flags in Local Explorer (#15330)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: wpmoo-org/ui/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 49d3df0f-9f34-4f26-96c0-d773dea51a1d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-dependencies-b0408f2f5a branch 2 times, most recently from 17b23f3 to 2a30809 Compare October 11, 2026 08:13
…ith 2 updates

Bumps the npm-dependencies group with 2 updates in the / directory: [axe-core](https://github.com/dequelabs/axe-core) and [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler).


Updates `axe-core` from 4.13.0 to 4.14.0
- [Release notes](https://github.com/dequelabs/axe-core/releases)
- [Changelog](https://github.com/dequelabs/axe-core/blob/develop/CHANGELOG.md)
- [Commits](dequelabs/axe-core@v4.13.0...v4.14.0)

Updates `wrangler` from 4.147.0 to 4.148.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.148.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: axe-core
  dependency-version: 4.14.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: wrangler
  dependency-version: 4.147.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-dependencies-b0408f2f5a branch from 2a30809 to 1a2ff09 Compare October 11, 2026 17:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants