Skip to content

chore(deps): Bump the minor-and-patch group across 1 directory with 9 updates - #680

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/astro-site/minor-and-patch-00cd075355
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/astro-site/minor-and-patch-00cd075355

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 9 updates in the /astro-site directory:

Package From To
astro 7.3.4 7.3.5
sanitize-html 2.17.7 2.18.0
@types/sanitize-html 2.16.1 2.16.2
satori 0.33.4 0.35.0
@types/sanitize-html 2.16.1 2.16.2
@typescript-eslint/parser 8.70.1 8.71.0
eslint 10.11.0 10.12.0
globals 17.12.0 17.13.0
shiki 4.4.3 4.5.0
typescript-eslint 8.70.1 8.71.0

Updates astro from 7.3.4 to 7.3.5

Release notes

Sourced from astro's releases.

astro@7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

Changelog

Sourced from astro's changelog.

7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

Commits

Updates sanitize-html from 2.17.7 to 2.18.0

Changelog

Sourced from sanitize-html's changelog.

2.18.0 (2026-09-30)

Adds

  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.

Fixes

  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for the fix.

Security

  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).

    Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.

Commits

Updates @types/sanitize-html from 2.16.1 to 2.16.2

Commits

Updates satori from 0.33.4 to 0.35.0

Release notes

Sourced from satori's releases.

0.35.0

0.35.0 (2026-10-02)

Features

0.34.1

0.34.1 (2026-10-02)

Bug Fixes

  • Keep more precision in transform matrices (#829) (553bd11)

0.34.0

0.34.0 (2026-10-02)

Features

0.33.5

0.33.5 (2026-09-22)

Bug Fixes

Commits

Updates @types/sanitize-html from 2.16.1 to 2.16.2

Commits

Updates @typescript-eslint/parser from 8.70.1 to 8.71.0

Release notes

Sourced from @​typescript-eslint/parser's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from @​typescript-eslint/parser's changelog.

8.71.0 (2026-09-28)

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates eslint from 10.11.0 to 10.12.0

Release notes

Sourced from eslint's releases.

v10.12.0

Features

  • 4618052 feat: handle astral letters in new-cap (#21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#21342) (ESLint Bot)
Commits
  • a438ec3 10.12.0
  • 32a73f1 Build: changelog update for 10.12.0
  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332)
  • 152067f chore: update ecosystem plugins (#21362)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376)
  • 67eb586 docs: Update README
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371)
  • Additional commits viewable in compare view

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

Updates shiki from 4.4.3 to 4.5.0

Release notes

Sourced from shiki's releases.

v4.5.0

   🚀 Features

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Commits

Updates typescript-eslint from 8.70.1 to 8.71.0

Release notes

Sourced from typescript-eslint's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from typescript-eslint's changelog.

8.71.0 (2026-09-28)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the minor-and-patch group with 9 updates in the /astro-site directory:

| Package | From | To |
| --- | --- | --- |
| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.3.4` | `7.3.5` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.7` | `2.18.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html) | `2.16.1` | `2.16.2` |
| [satori](https://github.com/vercel/satori) | `0.33.4` | `0.35.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html) | `2.16.1` | `2.16.2` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.70.1` | `8.71.0` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |
| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.4.3` | `4.5.0` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.1` | `8.71.0` |



Updates `astro` from 7.3.4 to 7.3.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro)

Updates `sanitize-html` from 2.17.7 to 2.18.0
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.18.0/packages/sanitize-html)

Updates `@types/sanitize-html` from 2.16.1 to 2.16.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)

Updates `satori` from 0.33.4 to 0.35.0
- [Release notes](https://github.com/vercel/satori/releases)
- [Commits](vercel/satori@0.33.4...0.35.0)

Updates `@types/sanitize-html` from 2.16.1 to 2.16.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)

Updates `@typescript-eslint/parser` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/parser)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

Updates `shiki` from 4.4.3 to 4.5.0
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.5.0/packages/shiki)

Updates `typescript-eslint` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: astro
  dependency-version: 7.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: sanitize-html
  dependency-version: 2.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/sanitize-html"
  dependency-version: 2.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: satori
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/sanitize-html"
  dependency-version: 2.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: shiki
  dependency-version: 4.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@dependabot
dependabot Bot requested a review from williamzujkowski as a code owner October 6, 2026 17:47
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@socket-security

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants