Skip to content

chore: bump the npm-all group with 6 updates - #12

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-all-50691feeaf
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-all-50691feeaf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-all group with 6 updates:

Package From To
morgan 1.12.0 1.12.1
oxfmt 0.65.0 0.70.0
oxlint 1.80.0 1.85.0
supertest 7.2.2 7.3.0
vite 8.2.2 8.3.1
vitest 4.1.11 5.0.2

Updates morgan from 1.12.0 to 1.12.1

Release notes

Sourced from morgan's releases.

1.12.1

Important

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.12.0...1.12.1

Changelog

Sourced from morgan's changelog.

1.12.1

Commits
  • b1272e7 1.12.1 (#386)
  • 4b695ed fix: escape double quotes in log fields
  • 0f74eca build(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)
  • e399e3c build(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)
  • 1e86b34 build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)
  • 87c0afd build(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)
  • 286b000 test: run CI on Windows and macOS (#379)
  • 5a5902a docs: fix typos across documentation (#378)
  • See full diff in compare view

Updates oxfmt from 0.65.0 to 0.70.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.70.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits

Updates oxlint from 1.80.0 to 1.85.0

Release notes

Sourced from oxlint's releases.

oxlint v1.85.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits
  • 288d8cc release(apps): oxlint v1.85.0 && oxfmt v0.70.0 (#26903)
  • f02a64a release(apps): oxlint v1.84.0 && oxfmt v0.69.0 (#26874)
  • 7bf68f7 release(apps): oxlint v1.83.0 && oxfmt v0.68.0 (#26631)
  • b4da00b release(apps): oxlint v1.82.0 && oxfmt v0.67.0 (#26384)
  • aa38ddf fix(linter/unicorn/numeric-separators-style): correct schema defaults (#26393)
  • 6a0e19c feat(linter/eslint/no-unmodified-loop-condition): support `checkConditionalEx...
  • 0b4e2e6 release(apps): oxlint v1.81.0 && oxfmt v0.66.0 (#26199)
  • d5be037 docs(linter/typescript/switch-exhaustiveness-check): clarify default case com...
  • 63bc313 chore(npm): update funding URL (#26066)
  • See full diff in compare view

Updates supertest from 7.2.2 to 7.3.0

Release notes

Sourced from supertest's releases.

v7.3.0

  • fix: stabilize ephemeral server requests and assertions 71dc5fb
  • Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd8535d99 3b5ba5c
  • Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2.3.2 c3419b2
  • Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1 7e409db
  • Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expansion-1.1.21 b55a7f9
  • Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslist-4.29.0 7a5deaa
  • Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8 a75f6ee
  • Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2 c2cb33e
  • Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind 7fb34e7
  • chore(deps-dev): bump js-yaml from 3.14.2 to 3.15.2 c357584
  • chore(deps-dev): bump browserslist from 4.25.1 to 4.29.0 2a01b57
  • chore(deps-dev): bump fast-uri from 3.0.6 to 3.1.8 343394d
  • chore(deps-dev): bump brace-expansion from 1.1.12 to 1.1.21 6b203e9
  • Merge pull request #881 from forwardemail/dependabot/npm_and_yarn/qs-6.14.2 d40ca7e
  • fix: match ephemeral server address family b6f5995
  • chore(deps-dev): bump lodash from 4.17.21 to 4.18.1 81766ca
  • chore(deps-dev): bump picomatch from 2.3.1 to 2.3.2 985ac7c
  • chore(deps): bump minimatch 58baa5f
  • chore(deps): bump qs from 6.14.1 to 6.14.2 c406e82

forwardemail/supertest@v7.2.2...v7.3.0

Commits
  • a3f5cb8 7.3.0
  • 71dc5fb fix: stabilize ephemeral server requests and assertions
  • 3b5ba5c Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd85...
  • c3419b2 Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2...
  • 7e409db Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1
  • b55a7f9 Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expan...
  • 7a5deaa Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslis...
  • a75f6ee Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8
  • c2cb33e Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2
  • 7fb34e7 Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind
  • Additional commits viewable in compare view

Updates vite from 8.2.2 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

create-vite@8.3.0

Please refer to CHANGELOG.md for details.

v8.3.0

Features

  • build: avoid settling seen preload dependencies for performance (#23446) (e6f6b3e)

Bug Fixes

  • handle CRLF line endings in code frame positions (#23219) (9913672)
  • only treat whole node_modules path segments as dependencies (fix #17467) (#23437) (ef0dc17)

Performance Improvements

  • proxy: pre-compile context matchers at server creation (#23263) (8abf700)

v8.3.0-beta.1

Features

Bug Fixes

  • build: keep hash placeholders as-is in resolveFileUrl hook (#23422) (e8d6a4d)

... (truncated)

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

8.3.0 (2026-09-10)

Features

  • build: avoid settling seen preload dependencies for performance (#23446) (e6f6b3e)
  • devtools: enable dev server integration (#23333) (68aeb8a)
  • accept Rolldown watch options in server.watch (#23133) (1b5cfe3)
  • add closeServer and closePreviewServer hooks (#23110) (e17d2d5)
  • add top-level tsconfig option (#23310) (93164c3)
  • add warning for unsupported hooks in plugin returned from applyToEnvironment hook (#23191) (fdef04f)
  • cli: support naming the CPU profile via --profile [name] (#23042) (a500dee)
  • config: warn on named imports from JSON modules (#23378) (472385e)
  • css: minify style tag (#23183) (8156684)
  • searched params attached to workers are now preserved (#22280) (517b97f)
  • support subpath imports in dynamic import statements (#23185) (b78e2f1)
  • use import.meta.ROLLDOWN_FILE_URL_* for assets in JS (#22888) (4366ac4)
  • use import.meta.ROLLDOWN_FILE_URL_* for other plugins (#22894) (e38f29e)
  • worker: remove worker chunk if it's detected that it's not referenced (#22473) (924997a)

Bug Fixes

  • handle CRLF line endings in code frame positions (#23219) (9913672)
  • only treat whole node_modules path segments as dependencies (fix #17467) (#23437) (ef0dc17)
  • build: keep hash placeholders as-is in resolveFileUrl hook (#23422) (e8d6a4d)
  • bundled-dev: mark payload delivered on client report (#23373) (a6d43bc)

... (truncated)

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Updates vitest from 4.1.11 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub

v5.0.1

   🚀 Features

   🐞 Bug Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-all group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [morgan](https://github.com/expressjs/morgan) | `1.12.0` | `1.12.1` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.65.0` | `0.70.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.80.0` | `1.85.0` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.2` |


Updates `morgan` from 1.12.0 to 1.12.1
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.12.0...1.12.1)

Updates `oxfmt` from 0.65.0 to 0.70.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.70.0/npm/oxfmt)

Updates `oxlint` from 1.80.0 to 1.85.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.85.0/npm/oxlint)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

Updates `vite` from 8.2.2 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 4.1.11 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: morgan
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-all
- dependency-name: oxfmt
  dependency-version: 0.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: oxlint
  dependency-version: 1.85.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants