Skip to content

chore(deps): bump the security group across 14 directories with 6 updates - #36

Merged
hostingerbot[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/templates/movement-library/security-9ba8c9bdba
Oct 6, 2026
Merged

hostingerbot[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/templates/movement-library/security-9ba8c9bdba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the security group with 2 updates in the /templates/movement-library directory: brace-expansion and source-map-js.
Bumps the security group with 1 update in the /templates/model directory: brace-expansion.
Bumps the security group with 5 updates in the /templates/manual directory:

Package From To
brace-expansion 5.0.9 5.0.12
devalue 5.9.2 5.9.4
source-map-js 1.2.1 1.2.2
http-cache-semantics 4.2.0 4.3.0
smol-toml 1.8.0 1.9.0

Bumps the security group with 1 update in the /templates/launch directory: brace-expansion.
Bumps the security group with 5 updates in the /templates/journal directory:

Package From To
brace-expansion 5.0.9 5.0.12
devalue 5.9.2 5.9.4
source-map-js 1.2.1 1.2.2
http-cache-semantics 4.2.0 4.3.0
smol-toml 1.8.0 1.9.0

Bumps the security group with 5 updates in the /templates/integrations directory:

Package From To
brace-expansion 5.0.9 5.0.12
devalue 5.9.2 5.9.4
source-map-js 1.2.1 1.2.2
http-cache-semantics 4.2.0 4.3.0
smol-toml 1.8.0 1.9.0

Bumps the security group with 5 updates in the /templates/groom-room directory:

Package From To
brace-expansion 5.0.9 5.0.12
devalue 5.9.2 5.9.4
source-map-js 1.2.1 1.2.2
http-cache-semantics 4.2.0 4.3.0
smol-toml 1.8.0 1.9.0

Bumps the security group with 2 updates in the /templates/flash-sheet directory: brace-expansion and source-map-js.
Bumps the security group with 4 updates in the /templates/first-chapter directory: brace-expansion, devalue, postcss-selector-parser and source-map-js.
Bumps the security group with 2 updates in the /templates/engineering-blog directory: brace-expansion and source-map-js.
Bumps the security group with 2 updates in the /templates/drop directory: brace-expansion and source-map-js.
Bumps the security group with 4 updates in the /templates/devfolio directory: brace-expansion, devalue, postcss-selector-parser and source-map-js.
Bumps the security group with 3 updates in the /templates/design-system directory: brace-expansion, postcss-selector-parser and source-map-js.
Bumps the security group with 4 updates in the /templates/couch-to-5k directory: brace-expansion, devalue, postcss-selector-parser and source-map-js.

Updates brace-expansion from 5.0.9 to 5.0.12

Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Updates brace-expansion from 1.1.18 to 1.1.21

Commits

Updates brace-expansion from 5.0.9 to 5.0.12

Commits

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Updates http-cache-semantics from 4.2.0 to 4.3.0

Commits

Updates smol-toml from 1.8.0 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates brace-expansion from 1.1.18 to 1.1.21

Commits

Updates brace-expansion from 5.0.9 to 5.0.12

Commits

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Updates http-cache-semantics from 4.2.0 to 4.3.0

Commits

Updates smol-toml from 1.8.0 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates brace-expansion from 5.0.9 to 5.0.12

Commits

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Updates http-cache-semantics from 4.2.0 to 4.3.0

Commits

Updates smol-toml from 1.8.0 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates brace-expansion from 5.0.9 to 5.0.12

Commits

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation poo...

    Description has been truncated

…ates

Bumps the security group with 2 updates in the /templates/movement-library directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 1 update in the /templates/model directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).
Bumps the security group with 5 updates in the /templates/manual directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `5.0.9` | `5.0.12` |
| [devalue](https://github.com/sveltejs/devalue) | `5.9.2` | `5.9.4` |
| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |
| [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.2.0` | `4.3.0` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.8.0` | `1.9.0` |

Bumps the security group with 1 update in the /templates/launch directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).
Bumps the security group with 5 updates in the /templates/journal directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `5.0.9` | `5.0.12` |
| [devalue](https://github.com/sveltejs/devalue) | `5.9.2` | `5.9.4` |
| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |
| [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.2.0` | `4.3.0` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.8.0` | `1.9.0` |

Bumps the security group with 5 updates in the /templates/integrations directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `5.0.9` | `5.0.12` |
| [devalue](https://github.com/sveltejs/devalue) | `5.9.2` | `5.9.4` |
| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |
| [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.2.0` | `4.3.0` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.8.0` | `1.9.0` |

Bumps the security group with 5 updates in the /templates/groom-room directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `5.0.9` | `5.0.12` |
| [devalue](https://github.com/sveltejs/devalue) | `5.9.2` | `5.9.4` |
| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |
| [http-cache-semantics](https://github.com/kornelski/http-cache-semantics) | `4.2.0` | `4.3.0` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.8.0` | `1.9.0` |

Bumps the security group with 2 updates in the /templates/flash-sheet directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 4 updates in the /templates/first-chapter directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [devalue](https://github.com/sveltejs/devalue), [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 2 updates in the /templates/engineering-blog directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 2 updates in the /templates/drop directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 4 updates in the /templates/devfolio directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [devalue](https://github.com/sveltejs/devalue), [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 3 updates in the /templates/design-system directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the security group with 4 updates in the /templates/couch-to-5k directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [devalue](https://github.com/sveltejs/devalue), [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) and [source-map-js](https://github.com/7rulnik/source-map-js).


Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `http-cache-semantics` from 4.2.0 to 4.3.0
- [Commits](https://github.com/kornelski/http-cache-semantics/commits)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `http-cache-semantics` from 4.2.0 to 4.3.0
- [Commits](https://github.com/kornelski/http-cache-semantics/commits)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `http-cache-semantics` from 4.2.0 to 4.3.0
- [Commits](https://github.com/kornelski/http-cache-semantics/commits)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `http-cache-semantics` from 4.2.0 to 4.3.0
- [Commits](https://github.com/kornelski/http-cache-semantics/commits)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `postcss-selector-parser` from 7.1.5 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@7.1.5...7.1.6)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `postcss-selector-parser` from 7.1.5 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@7.1.5...7.1.6)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `postcss-selector-parser` from 7.1.5 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@7.1.5...7.1.6)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `brace-expansion` from 5.0.9 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `postcss-selector-parser` from 7.1.5 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@7.1.5...7.1.6)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: http-cache-semantics
  dependency-version: 4.3.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: http-cache-semantics
  dependency-version: 4.3.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: http-cache-semantics
  dependency-version: 4.3.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: http-cache-semantics
  dependency-version: 4.3.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
  dependency-group: security
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: security
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: indirect
  dependency-group: security
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Template preview

Built each changed template, opened npm run preview, requested /, then compared Playwright screenshots to the committed catalog images (preview/<id>-thumbnail.png at 1440×900 and preview/<id>-homepage.png full page).

Template Install Lint Build Audit Health Thumbnail diff Homepage diff
couch-to-5k ✅ ✅ ✅ ✅ ✅ 1.0% ✅ 1.7% ✅
design-system ✅ ✅ ✅ ✅ 1 resolved ✅ 1.5% ✅ 1.5% ✅
devfolio ✅ ✅ ✅ ✅ ✅ 1.9% ✅ 2.2% ✅
drop ✅ ✅ ✅ ✅ ✅ 9.4% ✅ 9.4% ✅
engineering-blog ✅ ✅ ✅ ✅ ✅ 2.0% ✅ 2.5% ✅
first-chapter ✅ ✅ ✅ ✅ ✅ 0.9% ✅ 1.4% ✅
flash-sheet ✅ ✅ ✅ ✅ ✅ 0.4% ✅ 1.2% ✅
groom-room ✅ ✅ ✅ ✅ 5 resolved ✅ 0.9% ✅ 0.6% ✅
integrations ✅ ✅ ✅ ✅ 5 resolved ✅ 0.8% ✅ 1.2% ✅
journal ✅ ✅ ✅ ✅ 5 resolved ✅ 1.0% ✅ 0.9% ✅
launch ✅ ✅ ✅ ✅ ✅ 0.2% ✅ 0.2% ✅
manual ✅ ✅ ✅ ✅ 5 resolved ✅ 2.4% ✅ 3.4% ✅
model ✅ ✅ ✅ ✅ ✅ 8.6% ✅ 15.2% ✅
movement-library ✅ ✅ ✅ ✅ ✅ 1.3% ✅ 1.4% ✅

couch-to-5k

Expected thumbnail Actual Diff
expected actual diff

design-system

Expected thumbnail Actual Diff
expected actual diff

devfolio

Expected thumbnail Actual Diff
expected actual diff

drop

Expected thumbnail Actual Diff
expected actual diff

engineering-blog

Expected thumbnail Actual Diff
expected actual diff

first-chapter

Expected thumbnail Actual Diff
expected actual diff

flash-sheet

Expected thumbnail Actual Diff
expected actual diff

groom-room

Expected thumbnail Actual Diff
expected actual diff

integrations

Expected thumbnail Actual Diff
expected actual diff

journal

Expected thumbnail Actual Diff
expected actual diff

launch

Expected thumbnail Actual Diff
expected actual diff

manual

Expected thumbnail Actual Diff
expected actual diff

model

Expected thumbnail Actual Diff
expected actual diff

movement-library

Expected thumbnail Actual Diff
expected actual diff

Download screenshots and diffs from this run’s visual-<template> artifacts.

This check fails if install, lint, build, / health, or screenshot diff over the limit fails, or if the PR introduces a high/critical advisory in production dependencies that the base commit did not have (npm audit --omit=dev, head vs base). Pre-existing advisories are listed for information and belong to dependency-update PRs. Limits default to 25% (thumbnail) and 30% (homepage) to absorb Mac-vs-Linux font rasterization.

@hostingerbot
hostingerbot Bot merged commit a889e61 into main Oct 6, 2026
18 checks passed
@hostingerbot
hostingerbot Bot deleted the dependabot/npm_and_yarn/templates/movement-library/security-9ba8c9bdba branch October 6, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants