fix(deps): update prod minor+patch - #103
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/prod-minor+patch
branch
15 times, most recently
from
September 6, 2026 14:05
a00b8a4 to
58153ad
Compare
renovate
Bot
force-pushed
the
renovate/prod-minor+patch
branch
from
September 7, 2026 14:28
58153ad to
db046cf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.17.4→0.18.0^2.3.0→^2.4.0^2.3.0→^2.4.0^13.3.2→^13.3.3^5.102.4→^5.102.8^3.30.3→^3.31.3^3.30.3→^3.31.3^3.30.3→^3.31.3^3.30.3→^3.31.3^3.30.3→^3.31.3^3.30.3→^3.31.3^11.0.22→^11.0.23^1.34.0→^1.41.0^3.22.0→^3.23.1^5.8.0→^5.8.1^4.4.3→^4.5.4Release Notes
tursodatabase/libsql-client-ts (@libsql/client)
v0.18.0Compare Source
MasterKale/SimpleWebAuthn (@simplewebauthn/server)
v13.3.3Compare Source
Changes:
(#788)
MetadataServiceto know about the new FIDO MDS blob trust anchorcertificate (#789)
ueberdosis/tiptap (@tiptap/core)
v3.31.3Compare Source
@tiptap/extension-collaboration-caret
Patch Changes
@tiptap/react
Patch Changes
skipLibCheckis turned off.v3.31.2Compare Source
@tiptap/pm
Patch Changes
prosemirror-viewto^1.42.3, which fixes an XSS vulnerability where pasting crafted HTML could run arbitrary JavaScript (GHSA-c8x8-7fp4-3x9w).v3.31.1Compare Source
@tiptap/core
Patch Changes
v3.31.0Compare Source
@tiptap/react
Minor Changes
e7bf804: Alignselectedwith ProseMirror node selections by default, expose text selections throughselectionInside, and keepselectedOnTextSelectioncompatible.v3.30.6Compare Source
@tiptap/core
Patch Changes
@tiptap/extension-list
Patch Changes
@tiptap/extension-youtube
Patch Changes
srcattribute no longer crashes the editor. The embed is kept without a source.@tiptap/markdown
Patch Changes
@tiptap/react
Patch Changes
avoidwork/filesize.js (filesize)
v11.0.23Compare Source
#331#335#334#333#332#330#329#328#326#325#324#323#322#321#320#319#318#317#316#315lucide-icons/lucide (lucide-react)
v1.41.0: Version 1.41.0Compare Source
What's Changed
germandgerm-offby @rrod497 in #4056door-stairwellicon & updateddoor-*icons by @jguddas in #3554credit-card-readericon by @jguddas in #4616germ&germ-offby @karsa-mistmere in #4789virus/virus-officon by @karsa-mistmere in #4765can-sodaicon by @jaynewey in #4718square-alertIcon by @viralcodex in #3687lab/bottle-toothbrush-combicon by @karsa-mistmere in #4756@lucide/labby @ericfennis in #4792trashicon in favour oftrash-2by @jguddas in #3141leaficon by @karsa-mistmere in #4801New Contributors
Full Changelog: lucide-icons/lucide@1.40.0...1.41.0
v1.40.0: Version 1.40.0Compare Source
What's Changed
canicon by @l0uisgrange in #4767bridgeicon by @Nykoula in #3949shrimp-officon by @jguddas in #3613shopping-cart-plus&shopping-cart-minusicons by @Ajay199210 in #4248lighthouseicon by @Xougui in #4507New Contributors
Full Changelog: lucide-icons/lucide@1.39.0...1.40.0
v1.39.0: Version 1.39.0Compare Source
What's Changed
whistleicon by @timmy471 in #3006mail-penicon by @jennieboops in #4399Full Changelog: lucide-icons/lucide@1.38.0...1.39.0
v1.38.0: Version 1.38.0Compare Source
What's Changed
Full Changelog: lucide-icons/lucide@1.36.0...1.38.0
v1.37.0: Version 1.37.0Compare Source
What's Changed
face-angryeven more angry by @karsa-mistmere in #4708swordsicon by @jguddas in #4707shopping-carticon by @jguddas in #2909playing-card,playing-cards, andplaying-cards-fanby @Barakudum in #4258beeficon by @jguddas in #3457circle-dotby @jguddas in #3909pandaicon by @jguddas in #3187blendicon by @jguddas in #3105keyicon by @jguddas in #3111square-split-verticalicon by @jguddas in #3939asteriskicon by @jguddas in #3906message-circle-dashed-checkicon by @aliyasirnac in #3678pianoicon by @karsa-mistmere in #4766credit-card-x&credit-card-checkicon by @karsa-mistmere in #4763credit-card-minusicon by @ameniti-mx in #4440credit-card-plusicon by @ameniti-mx in #4441New Contributors
Full Changelog: lucide-icons/lucide@1.35.0...1.37.0
v1.36.0: Version 1.36.0Compare Source
What's Changed
face-angryeven more angry by @karsa-mistmere in #4708swordsicon by @jguddas in #4707shopping-carticon by @jguddas in #2909playing-card,playing-cards, andplaying-cards-fanby @Barakudum in #4258beeficon by @jguddas in #3457circle-dotby @jguddas in #3909pandaicon by @jguddas in #3187blendicon by @jguddas in #3105keyicon by @jguddas in #3111square-split-verticalicon by @jguddas in #3939asteriskicon by @jguddas in #3906message-circle-dashed-checkicon by @aliyasirnac in #3678pianoicon by @karsa-mistmere in #4766credit-card-x&credit-card-checkicon by @karsa-mistmere in #4763credit-card-minusicon by @ameniti-mx in #4440credit-card-plusicon by @ameniti-mx in #4441New Contributors
Full Changelog: lucide-icons/lucide@1.35.0...1.36.0
What's Changed
face-angryeven more angry by @karsa-mistmere in #4708swordsicon by @jguddas in #4707shopping-carticon by @jguddas in #2909playing-card,playing-cards, andplaying-cards-fanby @Barakudum in #4258beeficon by @jguddas in #3457circle-dotby @jguddas in #3909pandaicon by @jguddas in #3187blendicon by @jguddas in #3105keyicon by @jguddas in #3111square-split-verticalicon by @jguddas in #3939asteriskicon by @jguddas in #3906message-circle-dashed-checkicon by @aliyasirnac in #3678pianoicon by @karsa-mistmere in #4766credit-card-x&credit-card-checkicon by @karsa-mistmere in #4763credit-card-minusicon by @ameniti-mx in #4440credit-card-plusicon by @ameniti-mx in #4441New Contributors
Full Changelog: lucide-icons/lucide@1.35.0...1.36.0
v1.35.0: Version 1.35.0Compare Source
What's Changed
ship-cargoicon by @l0uisgrange in #4706trailericon by @MadsMadsDk in #4405galaxyicon by @karsa-mistmere in #4715baticon to lab by @RajnishKMehta in #3914ghosticon by @jguddas in #3533robot-armicon by @zoharma in #4447New Contributors
Full Changelog: lucide-icons/lucide@1.34.0...1.35.0
omgovich/react-colorful (react-colorful)
v5.8.1Compare Source
{ r: 200, g: 120, b: 35 }no longer becomes{ r: 199, g: 119, b: 34 }after moving the alpha slider. Thanks to @t-hamano for the investigation (via #234, fixes #163)colinhacks/zod (zod)
v4.5.4Compare Source
Commits:
84e416ffix(v4): stop the cycle walk from firing a default factory (#6500)e8e206f4.5.4v4.5.3Compare Source
v4.5.2Compare Source
Commits:
a354314fix(docs): keep blog posts out of the docs collection (#6484)d378c42ci: drop canary publishing from the release workflow (#6487)212b941fix(v4): let a prototype method getter answer a bare call so vi.spyOn works (#6488)e7576f5docs(blog): let the page show through the navbar in dark mode (#6489)fedb06ffix(docs): match the blog TOC hover bar to the 2px active indicator6c932fcchore: bump devcontainer image to Node 24 (#6470)6635d9ddocs(blog): soften the "method memoization" attribution019ae29fix(docs): drop ISR on the docs route so the home page hydrates652bb43chore(docs): drop the scroll log from the route-change scroller571c8e8fix(docs): render blog tabs with the stock fumadocs tab card9a193aa4.5.2v4.5.1Compare Source
Commits:
2e862dbci: gate the GitHub release and JSR publish on the version being live on npm8e033804.5.1v4.5.0Compare Source
Zod 4.5 is now available.
At a glance:
z.compile()— the flagship feature of Zod 4.5z.creditCard()— 12–19 digits plus Luhn checksumz.properties()— the multi-property counterpart toz.property()z.deepPartial()/.exactPartial()z.validate(): boolean— a fast-path to verify input validity without a full parse (up to 16x faster on invalid data)bn), Central Kurdish (ckb), Hindi (hi), Kannada (kn), Norwegian Nynorsk (nn), Brazilian Portuguese (pt-BR), Slovak (sk), Turkmen (tk)z.compile()You can now pre-compile any Zod schema using
z.compile(schema). This dramatically speeds up parsing performance.A compiled schema can be used exactly like an uncompiled one. There are no special rules around compiled schemas. They're just faster.
On objects, arrays, and unions, this speeds up parsing by a factor of ~3–7. More complex schemas stand to benefit more than simpler ones.
Time per parse by schema type, standard parser vs compiled — lower is better (benchmark)
Below are the Moltar benchmark results comparing Zod (compiled and uncompiled) against the Moltar ParseSafe bench.
Throughput on the moltar benchmark fixture (parseSafe: returns a new object with unknown keys stripped) — higher is better (benchmark)
And the equivalent results for the Moltar AssertLoose bench. Tested against the new
z.validate(schema, input)function (detailed later in the post).Throughput on the moltar benchmark fixture (assertLoose: returns a boolean, unknown keys allowed) — higher is better (benchmark)
Zod's entire test suite runs twice—once normally and again with auto-compilation enabled globally—to ensure perfect fidelity.
How it works
Under the hood,
z.compile()walks the entire schema once and produces a hyperoptimized snippet of flat, loop-free JavaScript that can validate inputs far faster than a standard runtime validator. This snippet can be executed vianew Function()(effectively a more powerfuleval) to serve as a fast-path validator. Schemas use this to "fast check" validity, falling back to the regular runtime logic on validation failure to provide granular error information.Take this simple
Pointschema:Here is the generated snippet for it:
For the large majority of inputs, the generated function validates the data with the fastest logic JavaScript can express: straight-line
typeofchecks and property reads, with no interpreter in between. When it can't handle an input, Zod falls back to the standard parser.This is the function Zod generates for the
Playerschema above:Armed with the power of
new Function(), this happens in-process at runtime. There is no need to integrate with your build system.import "zod/compile"To compile every schema in an application, import
zod/compileonce at the top of your entry point. Every schema constructed after that import is automatically compiled the first time it's used to parse data.It also works as a Node.js CLI flag, which guarantees it runs before any module defines a schema:
Or set
preloadinbunfig.tomlornub.jsonc.{ "preload": ["zod/compile"] }All schemas benefit to varying degrees, though complex object/tuple/array schemas benefit more than simple scalar validators.
z.creditCard()A new string format: 12–19 digits, optionally separated by single spaces or hyphens, with a valid Luhn checksum. (#5931)
z.properties()The multi-property counterpart to
z.property(). (#5912)z.deepPartial()Back in functional form after being removed as a method in Zod 4. (#5928)
The result is still a
ZodObject, so.shapeand.extend()keep working..exactPartial()Like
.partial(), but wraps each field inz.exactOptional()instead ofz.optional(): keys may be omitted, but an explicitundefinedis rejected. This matches TypeScript'sPartial<>underexactOptionalPropertyTypes. (#6065)In Zod Mini it's a top-level function:
z.exactPartial(Recipe).z.validate()Standalone boolean validation, in Zod, Zod Mini, and Zod Core. It answers "is this input valid?" without constructing a
ZodError, which makes rejection cheap: on invalid input it is up to 16x faster than.safeParse().success. The return type is a guard on the schema's input type, andz.validateAsync()covers schemas with async refinements. (#6471)z.input()/z.output()Project a schema onto its input or output side. Useful for validating the two halves of a codec independently. (#5928)
This is a no-op on schemas not containing codecs/pipes.
z.toZod<T>()A utility to define a Zod schema that agrees exactly with a static type, often one that is handwritten or externally defined. (#5913)
z.getDiscriminatedOption()Extract a discriminated union member by discriminator value. (#5947)
Cyclical inputs
Zod recursive schemas now support cyclical data. For bundle size reasons, Zod Mini requires you to register a memoizer explicitly. (#6387, #6482)
Zod
Zod Mini
9x reduction in schema memory footprint
In Zod 4.4 a bare
z.string()retained 7.5kb of heap. In Zod 4.5 it retains 784 bytes.Retained heap per schema instance, Zod 4.4.3 vs 4.5 (benchmark)
In Zod 4.4 and earlier, all schema methods were automatically bound to the instance itself. This allowed users to pluck methods from schemas without causing issues due to
this-binding.A consequence of this is that each bound method allocates space on the heap; method implementations are not shared across all instances via
prototype, as you'd expect. Zod 4.5 implements a method memoization pattern that avoids allocating bound methods until they are actually accessed.Faster failures
Zod
.parse()/.safeParse()instantiates a JavaScriptError, which captures a stack trace. In the case of validation failures, this is often much slower than the parsing logic itself. When using.safeParse(), Zod no longer captures this stack trace, speeding up failure-path parses by a factor of ~7.5x. (#6316, #6450)Player schema (benchmark)
Symbol keys in
z.object()A shape can now declare a symbol key. TypeScript tracks it: a
constsymbol infers asunique symbol, soz.infermakes the key required and checks its value type. Undeclared symbol keys are still ignored. (#6448)Bug fixes
All of these fix soundness issues, so a schema that relied on the old behavior may now reject input it used to accept.
z.iso.datetime()requires secondsRFC 3339 mandates seconds.
z.iso.datetime()andz.iso.datetime({ offset: true })no longer accept minute-precision input like2020-01-01T06:15Z.local: truestill admits2020-01-01T06:15, since an unqualified datetime is outside RFC 3339 either way. ([Configuration
📅 Schedule: (in timezone Europe/Lisbon)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.