Sitelet https://github.com/theredstring/redstring/pull/10
Skip to content

deps: bump the npm-minor-and-patch group across 1 directory with 23 updates - #10

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-2c2475f05f
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-2c2475f05f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown

Bumps the npm-minor-and-patch group with 23 updates in the / directory:

Package From To
@chenglou/pretext 0.0.5 0.0.9
@modelcontextprotocol/sdk 1.31.0 1.32.0
@octokit/rest 22.0.0 22.0.1
@rdfjs/parser-n3 2.1.0 2.2.0
cors 2.8.5 2.8.6
electron-log 5.4.3 5.4.4
express-rate-limit 8.5.2 8.7.0
heic-to 1.5.2 1.6.5
hono 4.13.11 4.13.12
jsonwebtoken 9.0.2 9.0.3
papaparse 5.5.3 5.7.0
react-virtuoso 4.18.3 4.18.16
sparql-http-client 3.0.1 3.1.0
use-debounce 10.0.5 10.1.1
zustand 5.0.3 5.0.15
@cloudflare/workers-types 5.20260929.1 5.20261004.1
@testing-library/react 16.3.0 16.3.3
@testing-library/user-event 14.6.1 14.6.7
electron 44.5.0 44.5.1
eslint-plugin-react 7.35.0 7.37.5
eslint-plugin-react-refresh 0.4.11 0.5.7
wait-on 9.0.3 9.5.1
wrangler 4.144.0 4.147.0

Updates @chenglou/pretext from 0.0.5 to 0.0.9

Changelog

Sourced from @​chenglou/pretext's changelog.

0.0.9 - 2026-09-07

Fixed

  • Streaming line layouts and line statistics now agree with batch layout when a later break follows a soft hyphen. Streaming also retains later text after consecutive lines containing only invisible break controls (#222).
  • Terminal soft hyphens now stay invisible and preserve terminal letter spacing across the rich line APIs.
  • Rich bidi metadata now resets independently at each paragraph boundary.
  • Rich-inline preparation with long internal whitespace, streaming layout of long hyphenated runs, and long font-size strings now avoid excessive repeated work (#221).
  • Rich-inline cursors now retain original item indices across empty items, zero-width items can occupy a line, and boundary spaces preserve their font and signed letter spacing. Mutating a visited line no longer changes the walker's continuation (#220).
  • Overlong independent symbol runs can now wrap at grapheme boundaries, with browser-specific punctuation attachment (#208).
  • Numeric minus signs no longer introduce a preferred break before their number, and ASCII hyphens after CJK text stay attached to the preceding character (#213, #215).
  • The Markdown chat demo now keeps ordinary text inside its bubbles in Firefox on macOS (#202).

0.0.8 - 2026-06-11

Added

  • The published package now ships declaration maps, so editor go-to-definition and programmatic TypeScript source tracing land in the shipped .ts source instead of the .d.ts files.

Fixed

  • Word-internal keyboard and Unicode symbol runs in long words now stay with surrounding text the way browsers break them, while browser-break symbols stay breakable (#169).
  • Overlong hyphenated runs now prefer browser-like dash breakpoints before falling back to emergency grapheme breaks (#89).

0.0.7 - 2026-05-10

Changed

  • The package now declares itself side-effect-free so bundlers can tree-shake unused entrypoints (#160).
  • layoutNextLine() and layoutNextLineRange() now avoid redundant chunk lookup in chunk-heavy manual layout paths (#140).

Fixed

  • { wordBreak: 'keep-all' } now handles no-space mixed Latin, numeric, and CJK text more like browsers.
  • No-space punctuation chains now stay together for non-ASCII word-like text too, instead of only ASCII words.
  • Opening punctuation such as ¡, ¿, German low quotes, and ⸘ now stays with the following word instead of dangling at line end (#165).
  • Numeric prefix/postfix symbols like $, %, €, +, −, and ° now stay attached to adjacent text the way browser line breaking does (#105).
  • Soft-hyphen breaks now stay at the soft-hyphen insertion point instead of pulling post-hyphen graphemes onto the broken line (#162).
  • Line geometry now preserves browser-style terminal letter spacing, including rich-inline item boundaries and visible soft-hyphen breaks (#171).
  • Rich-inline item boundaries no longer overflow the requested width after a forced-progress break (#132).
  • The markdown chat demo now drops parsed link URLs unless they resolve to HTTP(S) hrefs (#168).

0.0.6 - 2026-04-22

Added

  • Numeric CSS-pixel letterSpacing support on prepare(), prepareWithSegments(), and each existing rich-inline item (#108, #156).

Fixed

... (truncated)

Commits
  • 8460bf9 Release 0.0.9
  • 934141a Simplify preparation and rich line materialization
  • 172eeed Validate browser measurement environments and report ownership
  • f37d482 Merge pull request #222 from chenglou/codex/wrapping-observation-production-2...
  • f85abc3 Link shared line layout fix to PR 222
  • d92ad71 Retain independent native extraction observations
  • d5810ef Preserve reviewed line-walker fixes in wrapping comparisons
  • 2b73992 Unify complex line layout decisions
  • cdc34f1 Merge pull request #221 from chenglou/codex/linear-work-20260905
  • 7a0b4a8 Bound whitespace and streamed breakpoint searches
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/sdk from 1.31.0 to 1.32.0

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.32.0

Upgrade notes

  • Redirects: the HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on StreamableHTTPClientTransport or SSEClientTransport. In browsers, a redirected request fails unless that option is set.
  • New options, both off unless you set them: maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth accepts only tokens issued for this server (the token's audience).

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.31.0...1.32.0

Commits
  • 32549b0 chore: bump version to 1.32.0 (#2935)
  • 588d51d [v1.x] test(e2e): cover tools/call and prompts/get without arguments (#2931)
  • 5a0724d [v1.x] feat(auth): add expectedResource to requireBearerAuth (#2930)
  • 0ca0b62 [v1.x] fix(server): accept tools/call and prompts/get requests that omit argu...
  • fd26801 [v1.x] feat(server): add maxToolInputElements option to limit the number of e...
  • 727075b [v1.x] fix(tasks): keep tasks of the in-memory task store within the session ...
  • 0ff6377 [v1.x] examples: close idle sessions and cap the session map (#2914)
  • c2ce003 docs: point SECURITY.md at GitHub Security Advisories (v1.x) (#2910)
  • 30bfe51 [v1.x] fix(client): follow redirects only within the endpoint's origin (#2902)
  • See full diff in compare view

Updates @octokit/rest from 22.0.0 to 22.0.1

Release notes

Sourced from @​octokit/rest's releases.

v22.0.1

22.0.1 (2025-10-31)

Bug Fixes

  • deps: update octokit monorepo (major) (#538) (ded2f17)
Commits
  • daa3ec9 ci(action): update actions/setup-node action to v6 (#534)
  • 1dec0c7 ci(action): update peter-evans/create-or-update-comment action to v5 (#531)
  • ded2f17 fix(deps): update octokit monorepo (major) (#538)
  • 0e0eaea chore(deps): update dependency @​types/node to v24 (#537)
  • c04acc8 chore(deps): update vitest monorepo to v4 (major) (#536)
  • e6dd306 chore(deps): update dependency undici to v7 (#474)
  • 5f380d0 build(deps-dev): Bump form-data from 4.0.2 to 4.0.4 in /docs (#520)
  • dc6827d build(deps-dev): Bump tar-fs from 2.1.2 to 2.1.3 in /docs (#516)
  • See full diff in compare view

Updates @rdfjs/parser-n3 from 2.1.0 to 2.2.0

Commits
  • 9342f5f 2.2.0
  • 17717a5 Merge pull request #30 from rdfjs-base/n3-update
  • 35df859 Merge pull request #29 from rdfjs-base/ci-update
  • daf713d chore: updated ci dependencies
  • 01b9daf feat: updated n3.js dependency, added support/tests for triple terms
  • 4148a09 Merge pull request #27 from rdfjs-base/dependabot/npm_and_yarn/c8-11.0.0
  • 73ac52b Bump c8 from 10.1.3 to 11.0.0
  • a31aaa2 Merge pull request #24 from rdfjs-base/dependabot/github_actions/actions/chec...
  • dde2259 Bump actions/checkout from 5 to 6
  • 37db73d Merge pull request #23 from rdfjs-base/dependabot/github_actions/actions/setu...
  • Additional commits viewable in compare view

Updates cors from 2.8.5 to 2.8.6

Release notes

Sourced from cors's releases.

v2.8.6

What's Changed

New Contributors

... (truncated)

Changelog

Sourced from cors's changelog.

2.8.6 / 2026-01-22

  • Improve documentation (API, context, examples...)
  • Remove additional markdown files from tarball
Commits
Maintainer changes

This version was pushed to npm by ulisesgascon, a new releaser for cors since your current version.


Updates electron-log from 5.4.3 to 5.4.4

Commits

Updates express-rate-limit from 8.5.2 to 8.7.0

Release notes

Sourced from express-rate-limit's releases.

v8.7.0

You can view the changelog here.

v8.6.2

You can view the changelog here.

v8.6.1

You can view the changelog here.

v8.6.0

You can view the changelog here.

Commits
  • 48db09e 8.7.0
  • dce5871 v8.7.0 changelog
  • 2f08044 Add inspect.software health badge (#673)
  • a29757c feat: add retryAfter option (#661)
  • 146e88b chore: rename license
  • 5cfb8e8 ci: drop top-level id-token: write from the workflow token (#676)
  • 062bbdd fix: re-wrap license.md so GitHub recognizes it as MIT (#675)
  • 514772d chore(deps-dev): bump mintlify in the development-dependencies group (#674)
  • 4f06c8a chore(deps-dev): bump the development-dependencies group with 2 updates (#671)
  • 83356a5 chore(deps): bump ip-address from 10.4.0 to 10.5.0 (#672)
  • Additional commits viewable in compare view

Updates heic-to from 1.5.2 to 1.6.5

Release notes

Sourced from heic-to's releases.

v1.6.5

Full Changelog: hoppergee/heic-to@v1.6.4...v1.6.5

v1.6.4

Full Changelog: hoppergee/heic-to@v1.6.3...v1.6.4

v1.6.3

Full Changelog: hoppergee/heic-to@v1.6.2...v1.6.3

v1.6.2

Full Changelog: hoppergee/heic-to@v1.6.1...v1.6.2

v1.6.1

Full Changelog: hoppergee/heic-to@v1.6.0...v1.6.1

v1.6.0

Full Changelog: hoppergee/heic-to@v1.5.2...v1.6.0

Commits

Updates hono from 4.13.11 to 4.13.12

Release notes

Sourced from hono's releases.

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

Commits
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • c437d75 test(build): type-check the bundled declarations from a consumer project (#5486)
  • be1f749 fix(build): keep internal types private in bundled d.ts and avoid a self-refe...
  • See full diff in compare view

Updates jsonwebtoken from 9.0.2 to 9.0.3

Changelog

Sourced from jsonwebtoken's changelog.

9.0.3 - 2025-12-04

  • updates jws version to 4.0.1.
Commits

Updates papaparse from 5.5.3 to 5.7.0

Release notes

Sourced from papaparse's releases.

5.7.0

We are happy to annunce a new minor release of PapaParse.

This release includes the following change:

Add the `downloadTimeout` option to abort slow remote requests after a configurable duration (https://github.com/mholt/PapaParse/pull/1138)

Thanks @​Kocayilmaz for contributing it

5.6.0

We are happy to annunce a new minor release of PapaParse.

This release includes the following change:

  • Remove jQuery as dependency (#1137)

Thanks @​Kocayilmaz for contributing it

Changelog

Sourced from papaparse's changelog.

5.7.0

Features

  • Add the downloadTimeout option to abort slow remote requests after a configurable duration (#1138, #786)

5.6.1

Bug Fixes

  • Call transformHeader only once per header in streaming mode (#1130)
  • Prevent header de-duplication from running again after resuming parsing (#1135)

5.6.0

Features

  • Remove the optional jQuery plugin integration (#1137)

5.5.5

Bug Fixes

  • Improve automatic delimiter detection by prioritizing row consistency over field count (#1128, #1077)
  • Serialize dates with Date.toISOString(), preserving expanded years and writing invalid dates as empty fields (#1140)

5.5.4

Bug Fixes

  • Strip the byte order mark (BOM) from header column names
  • Correctly quote and escape custom quote characters when unparsing (#1124, #1068)

Maintenance

  • Update supported Node.js versions in CI (#1097)
  • Document Papa.BYTE_ORDER_MARK (#1096)
  • Add regression coverage for renamedHeaders with duplicate headers (#1024, #1102)
  • Use HTTPS for README links (#1104)
Commits
  • 555c1c1 Minor version bump
  • a5cc2dc Patch version bump
  • 29e3a09 Add downloadTimeout option to abort slow remote requests (#1138)
  • 2e20001 Use tabs for identation on comment
  • b98bd0e Simplify comments
  • a869cd9 Fix header de-duplication re-running on every resumed row (#1135)
  • b3b6a64 Remove coment describing old behaviour
  • 8dd3318 call transformHeader once per header in streaming mode (#1130)
  • e6c2b7b Update CHANGELOG
  • bc382b7 Minor version bump
  • Additional commits viewable in compare view

Updates react-virtuoso from 4.18.3 to 4.18.16

Release notes

Sourced from react-virtuoso's releases.

react-virtuoso@4.18.16

Patch Changes

  • #1512 b7238f3 Thanks @​cpruijsen! - Map skipAnimationFrameInResizeObserver through TableVirtuoso's urx optional props so the table resize observer consumes it instead of leaving the leftover prop on the scroller DOM.

react-virtuoso@4.18.15

Patch Changes

  • #1461 364c071 Thanks @​aehmt! - Fixed "Zero-sized element, this should not happen" error when initialItemCount exceeds the available data. The initial list state builder now clamps the item count to the data remaining after initialTopMostItemIndex, and renders no items when data is explicitly empty, preventing phantom items with undefined data from being rendered. initialItemCount also became a reactive input of the list state computation, so changing it after mount recomputes the list instead of leaving stale state until an unrelated update.

react-virtuoso@4.18.14

Patch Changes

  • #1497 ac8a5f4 Thanks @​cpruijsen! - Allow a custom List wrapper to render a ul instead of a div, keeping its forwarded ref typed to the chosen element. Item is unchanged.

react-virtuoso@4.18.13

Patch Changes

  • #1493 d3c437e Thanks @​albertcalasanzs! - Fix the transcript blanking for a frame when an older page is prepended.

    The compensation for a prepend was a deviation that grows the content followed, one requestAnimationFrame later, by the scroll that cancels it. In between there is a painted frame in which the list is displaced by the whole page — and because prepends fire near scrollTop 0, that displacement is the entire viewport.

    The scroll now runs as soon as the renderer acknowledges, from a layout effect, that the deviation has reached the DOM: after the mutation, before paint. Both land in the same paint, and because the content has already grown the scroll can no longer be clamped to the old maximum. If nothing acknowledges by the next frame the previous deferred behaviour still applies, so the worst case is unchanged.

react-virtuoso@4.18.12

Patch Changes

  • #1487 d975e6c Thanks @​petyosi! - Measure window-scrolling lists before they enter the viewport so their estimated height is included in the document layout.

react-virtuoso@4.18.10

Patch Changes

  • fca20fa Thanks @​petyosi! - Fix explicit undefined initial top-most item index values crashing when empty data updates to an object-form initial index.

react-virtuoso@4.18.9

Patch Changes

  • #1444 0c68e81 Thanks @​Luccas-carvalho! - Harden scroll-target and initial-index handling:
    • Clamp the initial top-most item index to the available range, so an out-of-range initialTopMostItemIndex (for example after the data set shrinks) no longer starts the list at a blank or mid-list position.
    • Stop mutating the location object passed to scrollToIndex; normalizeIndexLocation now applies its defaults to a shallow copy.
    • Treat a default-positioned initialTopMostItemIndex of { index: 0 } the same as 0, avoiding a redundant initial scroll and a delayed followOutput.

... (truncated)

Changelog

Sourced from react-virtuoso's changelog.

4.18.16

Patch Changes

  • #1512 b7238f3 Thanks @​cpruijsen! - Map skipAnimationFrameInResizeObserver through TableVirtuoso's urx optional props so the table resize observer consumes it instead of leaving the leftover prop on the scroller DOM.

4.18.15

Patch Changes

  • #1461 364c071 Thanks @​aehmt! - Fixed "Zero-sized element, this should not happen" error when initialItemCount exceeds the available data. The initial list state builder now clamps the item count to the data remaining after initialTopMostItemIndex, and renders no items when data is explicitly empty, preventing phantom items with undefined data from being rendered. initialItemCount also became a reactive input of the list state computation, so changing it after mount recomputes the list instead of leaving stale state until an unrelated update.

4.18.14

Patch Changes

  • #1497 ac8a5f4 Thanks @​cpruijsen! - Allow a custom List wrapper to render a ul instead of a div, keeping its forwarded ref typed to the chosen element. Item is unchanged.

4.18.13

Patch Changes

  • #1493 d3c437e Thanks @​albertcalasanzs! - Fix the transcript blanking for a frame when an older page is prepended.

    The compensation for a prepend was a deviation that grows the content followed, one requestAnimationFrame later, by the scroll that cancels it. In between there is a painted frame in which the list is displaced by the whole page — and because prepends fire near scrollTop 0, that displacement is the entire viewport.

    The scroll now runs as soon as the renderer acknowledges, from a layout effect, that the deviation has reached the DOM: after the mutation, before paint. Both land in the same paint, and because the content has already grown the scroll can no longer be clamped to the old maximum. If nothing acknowledges by the next frame the previous deferred behaviour still applies, so the worst case is unchanged.

4.18.12

Patch Changes

  • #1487 d975e6c Thanks @​petyosi! - Measure window-scrolling lists before they enter the viewport so their estimated height is included in the document layout.

4.18.11

Patch Changes

  • #1458 0d5214a Thanks @​wanxiankai! - Handle horizontal list direction changes between LTR and RTL without remounting the list.

4.18.10

Patch Changes

... (truncated)

Commits
  • 6650ec4 Version Packages (#1515)
  • b7238f3 fix: map skipAnimationFrameInResizeObserver on TableVirtuoso (#1512)
  • efb21c7 Version Packages (#1507)
  • 364c071 fix: clamp initialItemCount to data length when data prop is used (#1461)
  • 2dc4329 Version Packages
  • ac8a5f4 Allow custom list wrappers to use ul elements
  • ebd6b0f Version Packages (#1494)
  • d3c437e fix: apply prepend compensation in th...

    Description has been truncated

@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from theredstring as a code owner October 5, 2026 23:28
…pdates

Bumps the npm-minor-and-patch group with 23 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@chenglou/pretext](https://github.com/chenglou/pretext) | `0.0.5` | `0.0.9` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.31.0` | `1.32.0` |
| [@octokit/rest](https://github.com/octokit/rest.js) | `22.0.0` | `22.0.1` |
| [@rdfjs/parser-n3](https://github.com/rdfjs-base/parser-n3) | `2.1.0` | `2.2.0` |
| [cors](https://github.com/expressjs/cors) | `2.8.5` | `2.8.6` |
| [electron-log](https://github.com/megahertz/electron-log) | `5.4.3` | `5.4.4` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.5.2` | `8.7.0` |
| [heic-to](https://github.com/hoppergee/heic-to) | `1.5.2` | `1.6.5` |
| [hono](https://github.com/honojs/hono) | `4.13.11` | `4.13.12` |
| [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) | `9.0.2` | `9.0.3` |
| [papaparse](https://github.com/mholt/PapaParse) | `5.5.3` | `5.7.0` |
| [react-virtuoso](https://github.com/petyosi/react-virtuoso/tree/HEAD/packages/react-virtuoso) | `4.18.3` | `4.18.16` |
| [sparql-http-client](https://github.com/rdf-ext/sparql-http-client) | `3.0.1` | `3.1.0` |
| [use-debounce](https://github.com/xnimorz/use-debounce) | `10.0.5` | `10.1.1` |
| [zustand](https://github.com/pmndrs/zustand) | `5.0.3` | `5.0.15` |
| [@cloudflare/workers-types](https://github.com/cloudflare/workerd) | `5.20260929.1` | `5.20261004.1` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.0` | `16.3.3` |
| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.1` | `14.6.7` |
| [electron](https://github.com/electron/electron) | `44.5.0` | `44.5.1` |
| [eslint-plugin-react](https://github.com/jsx-eslint/eslint-plugin-react) | `7.35.0` | `7.37.5` |
| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.4.11` | `0.5.7` |
| [wait-on](https://github.com/jeffbski/wait-on) | `9.0.3` | `9.5.1` |
| [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `4.144.0` | `4.147.0` |



Updates `@chenglou/pretext` from 0.0.5 to 0.0.9
- [Changelog](https://github.com/chenglou/pretext/blob/main/CHANGELOG.md)
- [Commits](chenglou/pretext@v0.0.5...v0.0.9)

Updates `@modelcontextprotocol/sdk` from 1.31.0 to 1.32.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.31.0...1.32.0)

Updates `@octokit/rest` from 22.0.0 to 22.0.1
- [Release notes](https://github.com/octokit/rest.js/releases)
- [Commits](octokit/rest.js@v22.0.0...v22.0.1)

Updates `@rdfjs/parser-n3` from 2.1.0 to 2.2.0
- [Commits](rdfjs-base/parser-n3@v2.1.0...v2.2.0)

Updates `cors` from 2.8.5 to 2.8.6
- [Release notes](https://github.com/expressjs/cors/releases)
- [Changelog](https://github.com/expressjs/cors/blob/master/HISTORY.md)
- [Commits](expressjs/cors@v2.8.5...v2.8.6)

Updates `electron-log` from 5.4.3 to 5.4.4
- [Changelog](https://github.com/megahertz/electron-log/blob/master/CHANGELOG.md)
- [Commits](megahertz/electron-log@v5.4.3...v5.4.4)

Updates `express-rate-limit` from 8.5.2 to 8.7.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v8.5.2...v8.7.0)

Updates `heic-to` from 1.5.2 to 1.6.5
- [Release notes](https://github.com/hoppergee/heic-to/releases)
- [Commits](hoppergee/heic-to@v1.5.2...v1.6.5)

Updates `hono` from 4.13.11 to 4.13.12
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.11...v4.13.12)

Updates `jsonwebtoken` from 9.0.2 to 9.0.3
- [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](auth0/node-jsonwebtoken@v9.0.2...v9.0.3)

Updates `papaparse` from 5.5.3 to 5.7.0
- [Release notes](https://github.com/mholt/PapaParse/releases)
- [Changelog](https://github.com/mholt/PapaParse/blob/master/CHANGELOG.md)
- [Commits](mholt/PapaParse@5.5.3...5.7.0)

Updates `react-virtuoso` from 4.18.3 to 4.18.16
- [Release notes](https://github.com/petyosi/react-virtuoso/releases)
- [Changelog](https://github.com/petyosi/react-virtuoso/blob/main/packages/react-virtuoso/CHANGELOG.md)
- [Commits](https://github.com/petyosi/react-virtuoso/commits/react-virtuoso@4.18.16/packages/react-virtuoso)

Updates `sparql-http-client` from 3.0.1 to 3.1.0
- [Changelog](https://github.com/rdf-ext/sparql-http-client/blob/master/CHANGELOG.md)
- [Commits](rdf-ext/sparql-http-client@v3.0.1...v3.1.0)

Updates `use-debounce` from 10.0.5 to 10.1.1
- [Release notes](https://github.com/xnimorz/use-debounce/releases)
- [Changelog](https://github.com/xnimorz/use-debounce/blob/master/CHANGELOG.md)
- [Commits](https://github.com/xnimorz/use-debounce/commits)

Updates `zustand` from 5.0.3 to 5.0.15
- [Release notes](https://github.com/pmndrs/zustand/releases)
- [Commits](pmndrs/zustand@v5.0.3...v5.0.15)

Updates `@cloudflare/workers-types` from 5.20260929.1 to 5.20261004.1
- [Release notes](https://github.com/cloudflare/workerd/releases)
- [Changelog](https://github.com/cloudflare/workerd/blob/main/RELEASE.md)
- [Commits](https://github.com/cloudflare/workerd/commits)

Updates `@testing-library/react` from 16.3.0 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/react-testing-library@v16.3.0...v16.3.3)

Updates `@testing-library/user-event` from 14.6.1 to 14.6.7
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](testing-library/user-event@v14.6.1...v14.6.7)

Updates `electron` from 44.5.0 to 44.5.1
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v44.5.0...v44.5.1)

Updates `eslint-plugin-react` from 7.35.0 to 7.37.5
- [Release notes](https://github.com/jsx-eslint/eslint-plugin-react/releases)
- [Changelog](https://github.com/jsx-eslint/eslint-plugin-react/blob/master/CHANGELOG.md)
- [Commits](jsx-eslint/eslint-plugin-react@v7.35.0...v7.37.5)

Updates `eslint-plugin-react-refresh` from 0.4.11 to 0.5.7
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.4.11...v0.5.7)

Updates `wait-on` from 9.0.3 to 9.5.1
- [Release notes](https://github.com/jeffbski/wait-on/releases)
- [Commits](jeffbski/wait-on@v9.0.3...v9.5.1)

Updates `wrangler` from 4.144.0 to 4.147.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.147.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: "@chenglou/pretext"
  dependency-version: 0.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: "@cloudflare/workers-types"
  dependency-version: 5.20261002.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: "@octokit/rest"
  dependency-version: 22.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: "@rdfjs/parser-n3"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: "@testing-library/react"
  dependency-version: 16.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: "@testing-library/user-event"
  dependency-version: 14.6.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: cors
  dependency-version: 2.8.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: electron
  dependency-version: 44.5.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: electron-log
  dependency-version: 5.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: eslint-plugin-react
  dependency-version: 7.37.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: eslint-plugin-react-refresh
  dependency-version: 0.5.7
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: express-rate-limit
  dependency-version: 8.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: heic-to
  dependency-version: 1.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: hono
  dependency-version: 4.13.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: jsonwebtoken
  dependency-version: 9.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: papaparse
  dependency-version: 5.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: react-virtuoso
  dependency-version: 4.18.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
- dependency-name: sparql-http-client
  dependency-version: 3.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: use-debounce
  dependency-version: 10.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: wait-on
  dependency-version: 9.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: wrangler
  dependency-version: 4.147.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch
- dependency-name: zustand
  dependency-version: 5.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-and-patch-2c2475f05f branch from 04a7f3c to 07c1962 Compare October 7, 2026 03:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants