Skip to content

Bump the minor-and-patch group across 2 directories with 9 updates - #202

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/canvas/minor-and-patch-0bafa42808
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/canvas/minor-and-patch-0bafa42808

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 8 updates in the /canvas directory:

Package From To
cn 0.3.0 0.4.0
dompurify 3.4.15 3.4.16
marked 18.0.13 18.0.14
@types/node 26.6.1 26.6.2
jsdom 30.1.0 30.1.1
oxlint 1.83.0 1.85.0
vite 8.3.0 8.3.1
vitest 5.0.1 5.0.2

Bumps the minor-and-patch group with 1 update in the /desktop directory: electron.

Updates cn from 0.3.0 to 0.4.0

Release notes

Sourced from cn's releases.

cn@0.4.0

Minor Changes

  • #153 2691a38 Thanks @​shadcn! - cn build and the plugins now register the theme scales declared in your Tailwind CSS.

cn@0.3.3

Patch Changes

  • #152 00daa7e Thanks @​shadcn! - Calls with an interpolated argument, such as cn(base, "translate-x-[" + x + "px]"), no longer thrash the argument cache. 2,213 → 80 ns per call on that shape; stable arguments are unchanged.

  • #150 6f5ccfa Thanks @​shadcn! - cn build -o *.ts output now typechecks under noUncheckedIndexedAccess and the rest of the @tsconfig/strictest flags. The .mjs output is unchanged.

cn@0.3.2

Patch Changes

  • #147 e703bfe Thanks @​shadcn! - Custom animate-* classes are no longer merged, matching tailwind-merge. Only the default theme animations (spin, ping, pulse, bounce), animate-none, and arbitrary values share the animate group, so plugin classes such as animate-in, animate-once, and animate-duration-500 are never dropped.

cn@0.3.1

Patch Changes

  • #144 19a9a66 Thanks @​shadcn! - Axis utilities now override the logical sides they cover, matching tailwind-merge 3.7.0. px-2 replaces ps-* and pe-*, py-2 replaces pbs-* and pbe-*, and the same applies to mx/my, inset-x/inset-y, border-x/border-y widths and colors, and scroll-mx/scroll-my/scroll-px/scroll-py.
Changelog

Sourced from cn's changelog.

0.4.0

Minor Changes

  • #153 2691a38 Thanks @​shadcn! - cn build and the plugins now register the theme scales declared in your Tailwind CSS.

0.3.3

Patch Changes

  • #152 00daa7e Thanks @​shadcn! - Calls with an interpolated argument, such as cn(base, "translate-x-[" + x + "px]"), no longer thrash the argument cache. 2,213 → 80 ns per call on that shape; stable arguments are unchanged.

  • #150 6f5ccfa Thanks @​shadcn! - cn build -o *.ts output now typechecks under noUncheckedIndexedAccess and the rest of the @tsconfig/strictest flags. The .mjs output is unchanged.

0.3.2

Patch Changes

  • #147 e703bfe Thanks @​shadcn! - Custom animate-* classes are no longer merged, matching tailwind-merge. Only the default theme animations (spin, ping, pulse, bounce), animate-none, and arbitrary values share the animate group, so plugin classes such as animate-in, animate-once, and animate-duration-500 are never dropped.

0.3.1

Patch Changes

  • #144 19a9a66 Thanks @​shadcn! - Axis utilities now override the logical sides they cover, matching tailwind-merge 3.7.0. px-2 replaces ps-* and pe-*, py-2 replaces pbs-* and pbe-*, and the same applies to mx/my, inset-x/inset-y, border-x/border-y widths and colors, and scroll-mx/scroll-my/scroll-px/scroll-py.
Commits
  • 84db832 chore(release): version packages (#154)
  • 2691a38 feat(build): register theme scales from the Tailwind CSS entry (#153)
  • acfba70 chore(release): version packages (#151)
  • 00daa7e fix(engine): stop the arg cache thrashing on interpolated arguments (#152)
  • 6f5ccfa fix(build): typecheck .ts output under noUncheckedIndexedAccess (#150)
  • 210353b chore(release): version packages (#148)
  • e703bfe fix(config): stop merging custom animate classes (#147)
  • 8f12110 chore(release): version packages (#145)
  • 19a9a66 fix(config): override logical sides with axis utilities (#144)
  • See full diff in compare view

Updates dompurify from 3.4.15 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible
Commits

Updates marked from 18.0.13 to 18.0.14

Release notes

Sourced from marked's releases.

v18.0.14

18.0.14 (2026-09-22)

Bug Fixes

Commits

Updates @types/node from 26.6.1 to 26.6.2

Commits

Updates jsdom from 30.1.0 to 30.1.1

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)
Commits
  • 0a117f4 30.1.1
  • 103f67d Remove unnecessary window cleanup from API tests
  • cdda00a Test HTTP/2 document and subresource loading
  • 7ab92ce Update @​asamuzakjp/dom-selector to v9.2.1
  • d940c20 Share jsdom settings across descendant windows
  • 6ba40cb Fix and simplify option propagation
  • 3b3be70 Preserve CSS priorities across declaration updates
  • 97b2758 Align focusing and unfocusing with HTML
  • b7b460b Update w3c-xmlserializer to v6
  • 71d562f Update html-encoding-sniffer to v7
  • Additional commits viewable in compare view

Updates oxlint from 1.83.0 to 1.85.0

Release notes

Sourced from oxlint's releases.

oxlint v1.85.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits

Updates vite from 8.3.0 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Updates vitest from 5.0.1 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates electron from 44.4.3 to 44.4.5

Release notes

Sourced from electron's releases.

electron v44.4.5

Release Notes for v44.4.5

Other Changes

  • Backported fixes from upstream ANGLE, Chromium, Dawn, PDFium and V8. #54222

electron v44.4.4

Release Notes for v44.4.4

Fixes

  • Fixed a Cannot read properties of undefined (reading 'startTime') error thrown in pages while the DevTools Performance panel's live metrics were active. #54162
  • Fixed a crash when calling setIgnoreMenuShortcuts() on DevTools. #54116 (Also in 43, 45)
  • Fixed a spurious "sandboxed_renderer.bundle.js script failed to run" console error when DevTools attached to a sandboxed frame before its first navigation. #54155 (Also in 42, 43)
  • Fixed alignment of the text label and popup menu in the macOS save dialog. #54143 (Also in 45)
  • Fixed an "Invalid guestInstanceId" error when removing a loaded <webview> from the DOM. #54099 (Also in 42, 43, 45)
  • Fixed GPU shaders compiled by Skia not being cached between launches. #54161 (Also in 45)
  • Fixed ready-to-show never firing for some hidden windows on Windows and Linux. #54118 (Also in 43, 45)
  • Fixed the tray context menu not working for snap-confined apps because AppArmor blocked the /org/chromium/DbusMenu path. #54103 (Also in 45)
Commits
  • 694f458 chore: cherry-pick 35 changes from angle, chromium, dawn, pdfium and v8 (#54222)
  • b200482 build: remove ts-node and load specs as native ESM (44-x-y) (#54194)
  • ee593ac build: fail the PGO collect attempt on renderer death and relaunch (#54185)
  • 0925610 build: update @​electron/lint-roller to 4.0.0 and check docs code blocks with ...
  • af6e064 fix: skip the sandbox bundle on documents without startup data (#54155)
  • aee8d2d chore: cherry-pick 6a47f93393a7 from devtools-frontend (#54162)
  • 98b15d3 fix: persist GPU shaders compiled by Skia between launches (44-x-y) (#54161)
  • 906e18f fix: keep hidden windows rendering when they navigate (44-x-y) (#54118)
  • 02f814b build: update PGO profiles (#54145)
  • 1996b13 fix: vertically align "format" row of macOS save dialog elements (#54143)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Devin Review

Bumps the minor-and-patch group with 8 updates in the /canvas directory:

| Package | From | To |
| --- | --- | --- |
| [cn](https://github.com/shadcn-ui/cn/tree/HEAD/packages/cn) | `0.3.0` | `0.4.0` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.15` | `3.4.16` |
| [marked](https://github.com/markedjs/marked) | `18.0.13` | `18.0.14` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.1` | `26.6.2` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.0` | `30.1.1` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.83.0` | `1.85.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.2` |

Bumps the minor-and-patch group with 1 update in the /desktop directory: [electron](https://github.com/electron/electron).


Updates `cn` from 0.3.0 to 0.4.0
- [Release notes](https://github.com/shadcn-ui/cn/releases)
- [Changelog](https://github.com/shadcn-ui/cn/blob/main/packages/cn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/cn/commits/cn@0.4.0/packages/cn)

Updates `dompurify` from 3.4.15 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.15...3.4.16)

Updates `marked` from 18.0.13 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.13...v18.0.14)

Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `jsdom` from 30.1.0 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.0...v30.1.1)

Updates `oxlint` from 1.83.0 to 1.85.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.85.0/npm/oxlint)

Updates `vite` from 8.3.0 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

Updates `electron` from 44.4.3 to 44.4.5
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v44.4.3...v44.4.5)

---
updated-dependencies:
- dependency-name: cn
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: oxlint
  dependency-version: 1.85.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: electron
  dependency-version: 44.4.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from Jing-yilin as a code owner September 28, 2026 17:28
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying super-prototyping with  Cloudflare Pages  Cloudflare Pages

Latest commit: 10f2c69
Status:🚫  Build failed.

View logs

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants