Skip to content

chore(deps): bump the hyperframes group across 1 directory with 46 updates - #524

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vendor/hyperframes/hyperframes-7468bce774
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vendor/hyperframes/hyperframes-7468bce774

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the hyperframes group with 46 updates in the /vendor/hyperframes directory:

Package From To
@types/node 22.19.7 26.6.4
knip 6.29.0 6.40.0
oxfmt 0.63.0 0.72.0
tsx 4.23.5 4.23.15
yaml 2.9.0 2.9.1
@hono/node-server 1.19.11 2.1.3
esbuild 0.25.9 0.28.2
hono 4.12.12 4.13.13
onnxruntime-node 1.21.1 1.30.0
open 11.0.0 11.0.4
postcss 8.4.31 8.5.29
prettier 3.8.3 3.9.9
sharp 0.34.5 0.35.5
ignore 5.3.2 7.0.12
vitest 4.1.11 5.0.3
@google/genai 1.52.0 2.27.0
@chenglou/pretext 0.0.5 0.0.9
@types/jsdom 28.0.3 30.0.0
@vitest/coverage-v8 4.1.11 5.0.3
jsdom 29.1.1 30.1.2
@webgpu/types 0.1.69 0.1.74
htmlparser2 8.0.2 12.0.0
acorn 8.16.0 8.19.0
postcss-selector-parser 7.1.1 7.1.6
@babel/parser 7.27.0 8.0.6
magic-string 0.30.21 1.4.3
recast 0.23.11 0.24.0
@codemirror/autocomplete 6.20.0 6.20.3
@codemirror/commands 6.10.2 6.11.1
@codemirror/lang-html 6.4.11 6.4.12
@codemirror/lang-javascript 6.2.4 6.2.5
@codemirror/lang-markdown 6.5.1 6.5.2
@codemirror/language 6.12.1 6.12.4
@codemirror/state 6.5.4 6.7.6
@codemirror/view 6.40.0 6.43.13
dompurify 3.4.13 3.4.16
lucide-react 0.577.0 1.52.0
marked 17.0.6 18.1.0
@base-ui/react 1.7.0 1.8.0
@lezer/highlight 1.2.3 1.2.5
cn 0.2.4 0.4.0
dockview-react 8.3.1 8.4.1
@vitejs/plugin-react 4.7.0 6.1.2
vite 6.4.3 8.3.3
zustand 5.0.12 5.0.15
chokidar 4.0.3 5.0.0

Updates @types/node from 22.19.7 to 26.6.4

Commits

Updates knip from 6.29.0 to 6.40.0

Release notes

Sourced from knip's releases.

Release 6.40.0

  • Resolve local and scope-only extends in commitlint plugin (#2079) (e667552d4e7122094565d3ad9ae407acfc0ac684) - thanks @​giaBaoJS!
  • Clarify worktree guides and plugin review preparation (dd02baf020d23af1d47c44c1a726a61014b270bd)
  • Document stale cache results and workarounds (#2078) (3573749a5d5bbee6305f207cc7d1b72c200c8c9b)
  • Exclude test files from package entries in production mode (resolve #2082) (b86f45f9d38d4b83baad98e43983e08910e00c78) - thanks @​jonathanong!
  • Resolve Serverless file variables in plugins and functions (resolve #2074) (99cac789694ea8d76cd38184d2d7c95f34315224) - thanks @​SwastikTripathi!
  • Preserve locally referenced namespace members (resolve #2070) (f0f36df766cd74ad7ae03fbf8940bdeb792439be) - thanks @​MFA-G!
  • fix: add the commitlint-plugin prefix to Commitlint plugin names (#2096) (3decd35ff0a4220c7cd2c9142dc69c89794b3927) - thanks @​devYRPauli!
  • fix: match .mjs config files in the simple-git-hooks plugin (#2097) (79a87d92396c2444ae4ef3c780c0d2e18cd73e4c) - thanks @​devYRPauli!
  • fix: match capacitor.config.js in the Capacitor plugin (#2098) (4a5ec96d818117a7f2eafa027e3b707bc97573a8) - thanks @​devYRPauli!
  • fix(typescript): ArrayExpression (#2099) (#2100) (87fea9f201c2fd864eafa31bdad68910a8a177ba) - thanks @​DreamLongYT!
  • Preserve development entry pattern groups (7c229f4e1918075d801ed3b046fa022b1d3bcc41)
  • Resolve null package exports to the files they hide (resolve #2084, close #2085) (5bd46260feb60b957c2631bc72375ef192e441e0)
  • Pin InvokeAI ecosystem test (4e0a3432eb35e3f628f6d3b7fcd14b942de343d0)
  • fix(utils): add jsx extension to source mapping (#2087) (eaa353b5fc30c2f12cdf2c29e6dd68e0d0950062) - thanks @​DreamLongYT!
  • fix(serverless-framework): handle explicit extensions in handler paths (#2091) (e9393965be7563640921e3f20c946fcb9132e1cb) - thanks @​DreamLongYT!
  • Annotate published manifest return type (d95a8310a0d0dca8f23d8dd3f83e7b0a1909d038)
  • Add Jasmine plugin (#2105) (9ed14911d5c5752aef36878ab3d515c35d1ac6bc) - thanks @​SulimanAbdulrazzaq!
  • fix: resolve workspace exports with fallback arrays (#2088) (49c2aaeaba4544f25cc02c19d5da5152a8ef68c3) - thanks @​DreamLongYT!
  • fix(postcss): ignore disabled plugins in object configs (#2092) (b84fdf8a8ee676ee45f4313009ebfe969d034a88) - thanks @​DreamLongYT!
  • Resolve webServer commands in Playwright plugin (#2110) (1af96bce36b0d0d07791de100c7f2ea5672a478c) - thanks @​everton-dgn!
  • Cache config file inputs per plugin (#2109) (01cb43267ca5dc03a2cbcba0a19fd891d4ed1f37) - thanks @​everton-dgn!
  • fix: include custom compiler extensions in source path mapping (#2090) (dc3a47e2d810808314454b8f5c23070f136d15d3) - thanks @​DreamLongYT!
  • Don't let a self-closing swallow the next (#2113) (989fdadde0a068d1d1c52e26a8327b99c5de0668) - thanks @​maniflopi!
  • fix(oxlint): resolve lint from loaded Vite config (#2108) (6d44e532ed6320cdf4f4c3253b26e155c4d26ba7) - thanks @​everton-dgn!
  • fix: resolve Jest module names without the jest-* prefix (#2095) (a5f4cfbff7f263a0ea8d5461a3f9216cbef38602) - thanks @​devYRPauli!
  • Resolve Vitest paths from the top-level root (resolve #2114) (#2119) (8a495d424cf60cab502c5c5ea476a3c761a9da6d) - thanks @​SwastikTripathi!
  • fix(rsbuild): detect config from tools.rspack inside rsbuild config (#2077) (c4ed619d5352b1d7b9ffaacc8c75d247eef39517) - thanks @​TkDodo!
  • Add osls plugin (#2104) (a8bf4bfaeba2ee0aaf756b343789de9fff75a1fa) - thanks @​bytedoe!
  • Explain why types in signatures of used exports are not reported (61f5cc02e6b4e895dbd8507ab845ae30f073211b)
  • Update sponsors page (7ea33fa2c116c29e2c131bda900aaf7b9073a3ff)
  • Edit docs (b459d7c3ad6d5535fd7646d93022a2974641ccd9)

Release 6.39.0

  • Add Railway plugin (#2026) (6da55767eb419701dd32f93789a00e8bdc915276) - thanks @​jonahsnider!
  • Update query snapshot (8877d3cf35943e17a617e1197fa46c5a43342479)
  • Fix excluded tags on entry re-exports (#2062) (b22e27543cb8dd4ba7ec97c70ccfd06bc8f16614) - thanks @​devYRPauli!
  • Update rolldown snapshot (3a45c806e1c1b7ceb078903652c8631566400096)
  • Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067) (d912d807e41f140bbc79bafce6882b3c05dec6ff) - thanks @​bytedoe!
  • fix(angular): keep other projects' inputs when one has no architect (#2064) (af3f42e9772e9937fd71b7557d3b54aee1db339a) - thanks @​Cayan!
  • fix(vite): resolve nested HTML entry points in multi-page apps (#1988) (4648aefe56e7bac521bb6f17189473b46f8ff00f) - thanks @​DreamLongYT!
  • Improve Rstest plugin support (#2068) (add87992e9dfe2f3c22e4c6ba7fa257d7f0151cf) - thanks @​fi3ework!
  • Handle profiles, formatters and require paths in Cucumber plugin (#2065) (2ad39fcf02e067b4bdfc06a658bf4bf5abeea764) - thanks @​giaBaoJS!
  • fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076) (7060bb968339680d694275413aba2833e4521ed9) - thanks @​alokn!
  • fix: read entry export tags under the re-exported names (#2069) (1698683df95a96b3515795eb664aacf030042d7b) - thanks @​devYRPauli!

Release 6.38.0

  • Include co-authors in docs contributor list (0c334100df59d89a512ad598ec50e7f62f6da0c3)
  • Filter bots and agents from docs contributors (617f70d8179c6b8668ca41fe5df77ced5e2b37c0)
  • Update Eve plugin conventions (#2049) (260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks @​matchai!

... (truncated)

Commits
  • dd6d422 Release knip@6.40.0
  • a8bf4bf Add osls plugin (#2104)
  • c4ed619 fix(rsbuild): detect config from tools.rspack inside rsbuild config (#2077)
  • 8a495d4 Resolve Vitest paths from the top-level root (resolve #2114) (#2119)
  • a5f4cfb fix: resolve Jest module names without the jest-* prefix (#2095)
  • 6d44e53 fix(oxlint): resolve lint from loaded Vite config (#2108)
  • 989fdad Don't let a self-closing <script /> swallow the next <script> (#2113)
  • dc3a47e fix: include custom compiler extensions in source path mapping (#2090)
  • 01cb432 Cache config file inputs per plugin (#2109)
  • 1af96bc Resolve webServer commands in Playwright plugin (#2110)
  • Additional commits viewable in compare view

Updates oxfmt from 0.63.0 to 0.72.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.72.0

💥 BREAKING CHANGES

  • e2c68b1 oxfmt: [BREAKING] Format parser:markdown files by oxc_formatter_markdown (#27256) (leaysgur)

🚀 Features

  • b538e3c formatter_css: Parse embedded CSS as a block's contents (#27284) (leaysgur)

🐛 Bug Fixes

  • 71e400b formatter_markdown: Fixed remaining issues found by fuzz (#27334) (leaysgur)
  • 7d0e54d formatter_markdown: Preserve line breaks around Chinese/Japanese characters in all proseWrap (#27331) (leaysgur)
  • e9ae2d8 formatter_css: Fix layouts found in mdn-content repo (css-in-md) (#27326) (leaysgur)
  • df85b4c oxfmt: Keep blank lines after a line break in Prettier Doc to IR (#27325) (leaysgur)
  • 7f65b75 formatter: Format assignment target property as assignment-like (#27289) (leaysgur)
  • 6c08f2a formatter_css: Apply the url() import exception to a lone comma group (#27288) (leaysgur)
  • 1967302 formatter_css: Hug a spaced ident ( only at the at-rule prelude head (#27283) (leaysgur)
  • 2445064 formatter_markdown: Keep a preserved line break before a delimiter row that opens no table (#27278) (leaysgur)
  • dd72fbf formatter_markdown: Keep container columns as spaces under useTabs (#27277) (leaysgur)
  • 1686018 oxfmt: Make one state conditionalGroup fit up to first hardline (#27275) (leaysgur)
  • fd4ddce formatter_json: Flatten block comment only array|object (#27274) (leaysgur)
  • 267557c formatter,oxfmt: Embed only original JSDoc plugin supported languages (#27241) (leaysgur)
  • 2606c60 oxfmt: Do not re-include a file below an excluded directory with a negated pattern (#27237) (Nicolas Le Cam)
  • c2de02b formatter: Decide embedded template layout from AST, not source shape (#27218) (leaysgur)
  • c9e1224 formatter: Handle quoteProps: consistent for patterns and computed keys (#27216) (leaysgur)
  • 36e14df formatter: Keep comments between callee and its opener on the callee side (#27172) (leaysgur)
  • 6da7657 oxfmt: Render diagnostics with source in Stdin mode (#27130) (leaysgur)
  • e9b2ec5 oxfmt/lsp: Reload .prettierignore on watched file change (#27129) (leaysgur)
  • 30eb463 oxfmt: Check global ignores before resolving nested config in Stdin mode (#27128) (leaysgur)

⚡ Performance

  • 72f42a3 formatter_markdown: Pre-allocate the IR buffer (#27333) (leaysgur)
  • cea47e3 formatter_core: Avoid exponential will_break check on nested interned (#27211) (leaysgur)
  • 0aba566 oxfmt: Do not resolve root js config from nested context (#27147) (leaysgur)

📚 Documentation

  • 51506c6 formatter_css: Record divergences found in mdn-content (css-in-md) (#27327) (leaysgur)
  • 656b81c formatter_markdown: Record unclosed fences closing at a directive's closer (#27279) (leaysgur)
  • 66545bf formatter_markdown: Record setext heading wrap divergence (#27221) (leaysgur)
  • af4b269 oxfmt: Document why format() API does not take cwd (#27131) (leaysgur)

oxfmt v0.71.0

🚀 Features

  • e0b1f9f oxfmt: Bump bundled Prettier version to 3.9.9 (#27002) (leaysgur)
  • 342527d oxfmt: Bump bundled Prettier version to 3.9.8 (#26999) (leaysgur)

... (truncated)

Commits

Updates tsx from 4.23.5 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

v4.23.13

4.23.13 (2026-08-30)

Bug Fixes

  • cache: bound shared transform cache memory (#835) (28e1f12)

This release is also available on:

v4.23.12

4.23.12 (2026-08-10)

Bug Fixes

  • shim import.meta when tokens are split by comments or newlines (#829) (ed9d330), closes #828

This release is also available on:

... (truncated)

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • 28e1f12 fix(cache): bound shared transform cache memory (#835)
  • Additional commits viewable in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates @hono/node-server from 1.19.11 to 2.1.3

Release notes

Sourced from @​hono/node-server's releases.

v2.1.3

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

v2.1.1

What's Changed

Full Changelog: honojs/node-server@v2.1.0...v2.1.1

v2.1.0

What's Changed

New Contributors

Full Changelog: honojs/node-server@v2.0.12...v2.1.0

v2.0.12

What's Changed

Full Changelog: honojs/node-server@v2.0.11...v2.0.12

v2.0.11

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​hono/node-server since your current version.


Updates esbuild from 0.25.9 to 0.28.2

Release notes

Sourced from esbuild's releases.

v0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})

... (truncated)

Changelog

Sourced from esbuild's changelog.

Changelog: 2025

This changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).

0.27.2

  • Allow import path specifiers starting with #/ (#4361)

    Previously the specification for package.json disallowed import path specifiers starting with #/, but this restriction has recently been relaxed and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping #/* to ./src/* (previously you had to use another character such as #_* instead, which was more confusing). There is some more context in nodejs/node#49182.

    This change was contributed by @​hybrist.

  • Automatically add the -webkit-mask prefix (#4357, #4358)

    This release automatically adds the -webkit- vendor prefix for the mask CSS shorthand property:

    /* Original code */
    main {
      mask: url(x.png) center/5rem no-repeat
    }
    /* Old output (with --target=chrome110) */
    main {
    mask: url(x.png) center/5rem no-repeat;
    }
    /* New output (with --target=chrome110) */
    main {
    -webkit-mask: url(x.png) center/5rem no-repeat;
    mask: url(x.png) center/5rem no-repeat;
    }

    This change was contributed by @​BPJEnnova.

  • Additional minification of switch statements (#4176, #4359)

    This release contains additional minification patterns for reducing switch statements. Here is an example:

    // Original code
    switch (x) {
      case 0:
        foo()
        break
      case 1:
      default:
        bar()
    }

... (truncated)

Commits
  • 609683d publish 0.28.2 to npm
  • 11b1fe4 add to release notes
  • ab50d91 css: fix green/blue channel swap in oklch gamut mapping (#4488)
  • 04627b6 fix #4498: async TLA checks need a worklist
  • 5c15177 disable gopls in the go folder
  • fc2ee9b css: adjust parser to allow --foo: {...}
  • 209db54 release notes for css nesting bugfix
  • c625d31 fix #4497: preserve nested ampersands during minification (#4500)
  • 34474e2 better isolation of current part in js parser
  • 07f6e8c fix #4507: import assignment tree-shaking bug
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for esbuild since your current version.


Updates hono from 4.12.12 to 4.13.13

Release notes

Sourced from hono's releases.

v4.13.13

Mount Middleware

app.mount() is now available as the Mount Middleware, hono/mount. It is just a handler, so you register it with app.all():

import { Router as IttyRouter } from 'itty-router'
import { Hono } from 'hono'
import { mount } from 'hono/mount'
const ittyRouter = IttyRouter()
ittyRouter.get('/hello', () => new Response('Hello from itty-router'))
const app = new Hono()
app.all('/itty-router/*', mount(ittyRouter.handle))

app.mount() still works in v4 but is deprecated and will be removed in v5. Migrating is a one-line change:

- app.mount('/itty-router', ittyRouter.handle)
+ app.all('/itty-router/*', mount(ittyRouter.handle))

What's Changed

  • test(client): simulate network error for undefined route in parseResponse test in honojs/hono#5439
  • docs(request): fix jsdoc comments for some getters in honojs/hono#5445
  • fix(jsx): allow JSXNode function component results in honojs/hono#5476
  • feat(mount): introduce Mount Middleware and deprecate app.mount in honojs/hono#5221

Full Changelog: honojs/hono@v4.13.12...v4.13.13

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

... (truncated)

Commits
  • 08a023c 4.13.13
  • ae595de feat(mount): introduce Mount Middleware and deprecate app.mount (#5221)
  • f23b146 fix(jsx): allow JSXNode function component results (#5476)
  • 6d73a74 docs(request): fix jsdoc comments for some getters (#5445)
  • deff529 test(client): simulate network error for undefined route in parseResponse tes...
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for hono since your current version.


Updates onnxruntime-node from 1.21.1 to 1.30.0

Release notes

Sourced from onnxruntime-node's releases.

ONNX Runtime v1.30.0

ONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.

Highlights

  • Expanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (#32168, #32340, #32515).
  • Improved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (#31727, #32277, #32284, #32420).
  • Added fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (#31674, #31973, #32178, #32356).
  • Added Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (#29615, #32268).

Announcements & Compatibility

  • FP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with -Donnxruntime_USE_FP4_QMOE=OFF (#32096, #32163).
  • CUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and block_size=32. Set -Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (#32324).
  • CPU FP16 Gemm and MatMul execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (#32301, #32197).
  • WebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (#32287, #31960, #31970).

Security & Reliability

Model Loading, Memory, and Input Validation

  • Limited nested model-graph depth and canonicalized external-data locations to harden model loading (#32344, #32135).
  • Added checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (#32010, #32040).
  • Strengthened shape, rank, and parameter validation for Split, Scan, GatherND, ScatterND, SpaceToDepth/DepthToSpace, Crop, Conv, Normalizer, and pooling (#29461, #31668, #32034, #32039, #32076, #32157, #32160, #32161, #32345, #32349).
  • Hardened generation and attention input handling, including attention-attribute narrowing, BifurcationDetector inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (#31648, #31701, #32009, #32078, #32144).
  • Validated TreeEnsemble node references and bounded subtree comparison, rejected non-finite CPU RoiAlign coordinates, and required ImageScaler bias to match the channel count (#32031, #32043, #32011, #32002).
  • Added an allowlist of safe LoRA adapter parameter data types, validated MatMulFpQ4 shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (#31682, #32032, #32007).

GPU Bounds and Resource Lifetimes

  • Hardened CUDA indexing and buffer-size arithmetic in MatMulNBits, RemovePadding, RotaryEmbedding, SparseAttention, Whisper beam search, NMS, QDQ, and GatherElements (#31643, #31994, #31995, #31996, #31998, #32014, #32029, #32030).
  • Fixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (#32137, #32330, #31997).
  • Fixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept CudaAsyncBuffer staging storage alive across CUDA graph replay (#31968, #32121).
  • Fixed WebGPU out-of-bound...

    Description has been truncated

…dates

Bumps the hyperframes group with 46 updates in the /vendor/hyperframes directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.19.7` | `26.6.4` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.29.0` | `6.40.0` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.63.0` | `0.72.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.5` | `4.23.15` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [@hono/node-server](https://github.com/honojs/node-server) | `1.19.11` | `2.1.3` |
| [esbuild](https://github.com/evanw/esbuild) | `0.25.9` | `0.28.2` |
| [hono](https://github.com/honojs/hono) | `4.12.12` | `4.13.13` |
| [onnxruntime-node](https://github.com/Microsoft/onnxruntime) | `1.21.1` | `1.30.0` |
| [open](https://github.com/sindresorhus/open) | `11.0.0` | `11.0.4` |
| [postcss](https://github.com/postcss/postcss) | `8.4.31` | `8.5.29` |
| [prettier](https://github.com/prettier/prettier) | `3.8.3` | `3.9.9` |
| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.5` |
| [ignore](https://github.com/kaelzhang/node-ignore) | `5.3.2` | `7.0.12` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.3` |
| [@google/genai](https://github.com/googleapis/js-genai) | `1.52.0` | `2.27.0` |
| [@chenglou/pretext](https://github.com/chenglou/pretext) | `0.0.5` | `0.0.9` |
| [@types/jsdom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/jsdom) | `28.0.3` | `30.0.0` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.11` | `5.0.3` |
| [jsdom](https://github.com/jsdom/jsdom) | `29.1.1` | `30.1.2` |
| [@webgpu/types](https://github.com/gpuweb/types) | `0.1.69` | `0.1.74` |
| [htmlparser2](https://github.com/fb55/htmlparser2) | `8.0.2` | `12.0.0` |
| [acorn](https://github.com/acornjs/acorn) | `8.16.0` | `8.19.0` |
| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `7.1.1` | `7.1.6` |
| [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser) | `7.27.0` | `8.0.6` |
| [magic-string](https://github.com/Rich-Harris/magic-string) | `0.30.21` | `1.4.3` |
| [recast](https://github.com/benjamn/recast) | `0.23.11` | `0.24.0` |
| [@codemirror/autocomplete](https://github.com/codemirror/autocomplete) | `6.20.0` | `6.20.3` |
| [@codemirror/commands](https://github.com/codemirror/commands) | `6.10.2` | `6.11.1` |
| [@codemirror/lang-html](https://github.com/codemirror/lang-html) | `6.4.11` | `6.4.12` |
| [@codemirror/lang-javascript](https://github.com/codemirror/lang-javascript) | `6.2.4` | `6.2.5` |
| [@codemirror/lang-markdown](https://github.com/codemirror/lang-markdown) | `6.5.1` | `6.5.2` |
| [@codemirror/language](https://github.com/codemirror/language) | `6.12.1` | `6.12.4` |
| [@codemirror/state](https://github.com/codemirror/state) | `6.5.4` | `6.7.6` |
| [@codemirror/view](https://github.com/codemirror/view) | `6.40.0` | `6.43.13` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.13` | `3.4.16` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.577.0` | `1.52.0` |
| [marked](https://github.com/markedjs/marked) | `17.0.6` | `18.1.0` |
| [@base-ui/react](https://github.com/mui/base-ui/tree/HEAD/packages/react) | `1.7.0` | `1.8.0` |
| [@lezer/highlight](https://github.com/lezer-parser/highlight) | `1.2.3` | `1.2.5` |
| [cn](https://github.com/shadcn-ui/cn/tree/HEAD/packages/cn) | `0.2.4` | `0.4.0` |
| [dockview-react](https://github.com/dockview/dockview/tree/HEAD/packages/dockview-react) | `8.3.1` | `8.4.1` |
| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `4.7.0` | `6.1.2` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.4.3` | `8.3.3` |
| [zustand](https://github.com/pmndrs/zustand) | `5.0.12` | `5.0.15` |
| [chokidar](https://github.com/paulmillr/chokidar) | `4.0.3` | `5.0.0` |



Updates `@types/node` from 22.19.7 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `knip` from 6.29.0 to 6.40.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.40.0/packages/knip)

Updates `oxfmt` from 0.63.0 to 0.72.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.72.0/npm/oxfmt)

Updates `tsx` from 4.23.5 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.5...v4.23.15)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `@hono/node-server` from 1.19.11 to 2.1.3
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.11...v2.1.3)

Updates `esbuild` from 0.25.9 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)
- [Commits](evanw/esbuild@v0.25.9...v0.28.2)

Updates `hono` from 4.12.12 to 4.13.13
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.12...v4.13.13)

Updates `onnxruntime-node` from 1.21.1 to 1.30.0
- [Release notes](https://github.com/Microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](microsoft/onnxruntime@v1.21.1...v1.30.0)

Updates `open` from 11.0.0 to 11.0.4
- [Release notes](https://github.com/sindresorhus/open/releases)
- [Commits](sindresorhus/open@v11.0.0...v11.0.4)

Updates `postcss` from 8.4.31 to 8.5.29
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.4.31...8.5.29)

Updates `prettier` from 3.8.3 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.3...3.9.9)

Updates `sharp` from 0.34.5 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.5)

Updates `ignore` from 5.3.2 to 7.0.12
- [Release notes](https://github.com/kaelzhang/node-ignore/releases)
- [Commits](kaelzhang/node-ignore@5.3.2...7.0.12)

Updates `vitest` from 4.1.11 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `@google/genai` from 1.52.0 to 2.27.0
- [Release notes](https://github.com/googleapis/js-genai/releases)
- [Changelog](https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md)
- [Commits](googleapis/js-genai@v1.52.0...v2.27.0)

Updates `@chenglou/pretext` from 0.0.5 to 0.0.9
- [Changelog](https://github.com/chenglou/pretext/blob/main/CHANGELOG.md)
- [Commits](chenglou/pretext@v0.0.5...v0.0.9)

Updates `@types/jsdom` from 28.0.3 to 30.0.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/jsdom)

Updates `@vitest/coverage-v8` from 4.1.11 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `jsdom` from 29.1.1 to 30.1.2
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v29.1.1...v30.1.2)

Updates `@webgpu/types` from 0.1.69 to 0.1.74
- [Commits](gpuweb/types@v0.1.69...v0.1.74)

Updates `htmlparser2` from 8.0.2 to 12.0.0
- [Release notes](https://github.com/fb55/htmlparser2/releases)
- [Commits](fb55/htmlparser2@v8.0.2...v12.0.0)

Updates `acorn` from 8.16.0 to 8.19.0
- [Commits](acornjs/acorn@8.16.0...8.19.0)

Updates `postcss-selector-parser` from 7.1.1 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.6)

Updates `@babel/parser` from 7.27.0 to 8.0.6
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v8.0.6/packages/babel-parser)

Updates `magic-string` from 0.30.21 to 1.4.3
- [Release notes](https://github.com/Rich-Harris/magic-string/releases)
- [Changelog](https://github.com/Rich-Harris/magic-string/blob/master/CHANGELOG.md)
- [Commits](Rich-Harris/magic-string@v0.30.21...v1.4.3)

Updates `recast` from 0.23.11 to 0.24.0
- [Release notes](https://github.com/benjamn/recast/releases)
- [Commits](benjamn/recast@v0.23.11...v0.24.0)

Updates `@codemirror/autocomplete` from 6.20.0 to 6.20.3
- [Changelog](https://github.com/codemirror/autocomplete/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/autocomplete/commits)

Updates `@codemirror/commands` from 6.10.2 to 6.11.1
- [Changelog](https://github.com/codemirror/commands/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/commands/commits)

Updates `@codemirror/lang-html` from 6.4.11 to 6.4.12
- [Changelog](https://github.com/codemirror/lang-html/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/lang-html/commits)

Updates `@codemirror/lang-javascript` from 6.2.4 to 6.2.5
- [Changelog](https://github.com/codemirror/lang-javascript/blob/main/CHANGELOG.md)
- [Commits](codemirror/lang-javascript@6.2.4...6.2.5)

Updates `@codemirror/lang-markdown` from 6.5.1 to 6.5.2
- [Changelog](https://github.com/codemirror/lang-markdown/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/lang-markdown/commits)

Updates `@codemirror/language` from 6.12.1 to 6.12.4
- [Changelog](https://github.com/codemirror/language/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/language/commits)

Updates `@codemirror/state` from 6.5.4 to 6.7.6
- [Changelog](https://github.com/codemirror/state/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/state/commits)

Updates `@codemirror/view` from 6.40.0 to 6.43.13
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)

Updates `dompurify` from 3.4.13 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.13...3.4.16)

Updates `lucide-react` from 0.577.0 to 1.52.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.52.0/packages/lucide-react)

Updates `marked` from 17.0.6 to 18.1.0
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v17.0.6...v18.1.0)

Updates `@base-ui/react` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/mui/base-ui/releases)
- [Changelog](https://github.com/mui/base-ui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/base-ui/commits/v1.8.0/packages/react)

Updates `@lezer/highlight` from 1.2.3 to 1.2.5
- [Changelog](https://github.com/lezer-parser/highlight/blob/main/CHANGELOG.md)
- [Commits](https://github.com/lezer-parser/highlight/commits)

Updates `cn` from 0.2.4 to 0.4.0
- [Release notes](https://github.com/shadcn-ui/cn/releases)
- [Changelog](https://github.com/shadcn-ui/cn/blob/main/packages/cn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/cn/commits/cn@0.4.0/packages/cn)

Updates `dockview-react` from 8.3.1 to 8.4.1
- [Release notes](https://github.com/dockview/dockview/releases)
- [Commits](https://github.com/dockview/dockview/commits/v8.4.1/packages/dockview-react)

Updates `@vitejs/plugin-react` from 4.7.0 to 6.1.2
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.2/packages/plugin-react)

Updates `vite` from 6.4.3 to 8.3.3
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.3/packages/vite)

Updates `zustand` from 5.0.12 to 5.0.15
- [Release notes](https://github.com/pmndrs/zustand/releases)
- [Commits](pmndrs/zustand@v5.0.12...v5.0.15)

Updates `chokidar` from 4.0.3 to 5.0.0
- [Release notes](https://github.com/paulmillr/chokidar/releases)
- [Changelog](https://github.com/paulmillr/chokidar/blob/main/CHANGELOG.md)
- [Commits](paulmillr/chokidar@4.0.3...5.0.0)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: knip
  dependency-version: 6.40.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: oxfmt
  dependency-version: 0.72.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: hono
  dependency-version: 4.13.13
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: onnxruntime-node
  dependency-version: 1.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: open
  dependency-version: 11.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: postcss
  dependency-version: 8.5.29
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: ignore
  dependency-version: 7.0.12
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: "@google/genai"
  dependency-version: 2.27.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: "@chenglou/pretext"
  dependency-version: 0.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@types/jsdom"
  dependency-version: 30.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: jsdom
  dependency-version: 30.1.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: "@webgpu/types"
  dependency-version: 0.1.74
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: htmlparser2
  dependency-version: 12.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: acorn
  dependency-version: 8.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@babel/parser"
  dependency-version: 8.0.6
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: magic-string
  dependency-version: 1.4.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: recast
  dependency-version: 0.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: "@codemirror/autocomplete"
  dependency-version: 6.20.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@codemirror/commands"
  dependency-version: 6.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: "@codemirror/lang-html"
  dependency-version: 6.4.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@codemirror/lang-javascript"
  dependency-version: 6.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@codemirror/lang-markdown"
  dependency-version: 6.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@codemirror/language"
  dependency-version: 6.12.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: "@codemirror/state"
  dependency-version: 6.7.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: "@codemirror/view"
  dependency-version: 6.43.13
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: lucide-react
  dependency-version: 1.52.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: marked
  dependency-version: 18.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: "@base-ui/react"
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: "@lezer/highlight"
  dependency-version: 1.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: cn
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: dockview-react
  dependency-version: 8.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: hyperframes
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.1.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: vite
  dependency-version: 8.3.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
- dependency-name: zustand
  dependency-version: 5.0.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: hyperframes
- dependency-name: chokidar
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: hyperframes
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants