build: update all non-major dependencies (main)#33631
Merged
dgp1130 merged 1 commit intoJul 25, 2026
Merged
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates various dependencies across multiple package.json files in the workspace, including @typescript-eslint/eslint-plugin, undici, oxc-parser, piscina, sass, @oxc-project/types, less, postcss, and source-map. The review highlights that updating oxc-parser and @oxc-project/types to 0.141.0 introduces breaking changes (splitting MetaProperty into ImportMeta and NewTarget) which could break AST traversal or manipulation logic relying on MetaProperty.
angular-robot
force-pushed
the
ng-renovate/main-all-non-major-dependencies
branch
from
July 23, 2026 09:13
6f73469 to
f7f0941
Compare
alan-agius4
approved these changes
Jul 23, 2026
angular-robot
force-pushed
the
ng-renovate/main-all-non-major-dependencies
branch
10 times, most recently
from
July 24, 2026 19:51
83dda27 to
098242e
Compare
See associated pull request for more information.
angular-robot
force-pushed
the
ng-renovate/main-all-non-major-dependencies
branch
from
July 24, 2026 22:16
098242e to
0848b68
Compare
Collaborator
|
This PR was merged into the repository. The changes were merged into the following branches:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.2.4→4.2.50.140.0→0.141.08.64.0→8.65.08.64.0→8.65.04.6.7→4.8.01.0.0→1.1.00.140.0→0.141.05.2.0→5.3.08.5.19→8.5.221.101.0→1.101.70.7.6→0.8.08.7.0→8.8.05.108.4→5.109.08.0.3→8.0.4Release Notes
listr2/listr2 (@listr2/prompt-adapter-inquirer)
v4.2.5Compare Source
@listr2/prompt-adapter-inquirer 4.2.5 (2026-07-21)
Bug Fixes
Dependencies
oxc-project/oxc (@oxc-project/types)
v0.141.0💥 BREAKING CHANGES
54cc121ast: [BREAKING] SplitMetaPropertyintoImportMetaandNewTarget(#24557) (camc314)typescript-eslint/typescript-eslint (@typescript-eslint/eslint-plugin)
v8.65.0Compare Source
🚀 Features
🩹 Fixes
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
typescript-eslint/typescript-eslint (@typescript-eslint/parser)
v8.65.0Compare Source
🚀 Features
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
less/less.js (less)
v4.8.0Compare Source
Changes
Deprecation Warnings
@charsetinterpolation for removal in Less 5.x. Less 4 preserves the existing output while warning; migrate names to valid identifiers and use a static quoted@charsetdeclaration. (@matthew-dean)v4.7.0Compare Source
Changes
Rich-Harris/magic-string (magic-string)
v1.1.0Compare Source
Bug Fixes
Performance Improvements
Mapfor tracking chunks (#313) (25d7461)oxc-project/oxc (oxc-parser)
v0.141.0💥 BREAKING CHANGES
54cc121ast: [BREAKING] SplitMetaPropertyintoImportMetaandNewTarget(#24557) (camc314)🚀 Features
7b045cdminfier: Drop last break from last switch case (#24673) (Armano)3d22307parser: AddParseOptions::enable_ident_hashes(#24491) (Boshen)piscinajs/piscina (piscina)
v5.3.0Compare Source
What's Changed
Full Changelog: piscinajs/piscina@v5.2.0...v5.3.0
postcss/postcss (postcss)
v8.5.22Compare Source
v8.5.21Compare Source
v8.5.20Compare Source
AtRule#paramsis set after (by @sarathfrancis90).sass/dart-sass (sass)
v1.101.7Compare Source
v1.101.6Compare Source
v1.101.5Compare Source
v1.101.4Compare Source
Avoid emitting
rgb()orrgba()functions with non-percent decimalchannels. Older browsers only support integer values or (potentially decimal)
percentages for these functions, so in order to preserve
backwards-compatibility while retaining full precision for modern browsers,
legacy colors that contain at least one non-integer channel will now use
percentages for their channels (for example,
rgb(0%, 100%, 50%)rather thanrgb(0, 255, 127.5)).Fix a bug where the values of plain-CSS
if()expressions were emitted usingtheir
meta.inspect()format rather than their CSS serialization format.v1.101.3Compare Source
mozilla/source-map (source-map)
v0.8.0Compare Source
Adding security policy
Use Object.create for sourceContents
Fixes types for SourceMapConsumer.initialize
nodejs/undici (undici)
v8.8.0Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v8.7.0...v8.8.0
webpack/webpack (webpack)
v5.109.0Compare Source
Minor Changes
Default
experiments.typescriptto"auto", enabling built-in TypeScript support on Node.js >= 22.6 when no TypeScript loader is registered. (by @alexander-akait in #21477)Default
experiments.css,experiments.htmlandexperiments.asyncWebAssemblyto"auto", enabling built-in support unless a loader is registered for those files; modules with inline or hook-injected loaders (e.g. html-webpack-plugin templates) keep being parsed as JavaScript. (by @alexander-akait in #21477)Add
output.resourceHintsto emit resource hints (preload/prefetch/modulepreload/preconnect), on by default for ESM output, plusmodule.parser.<type>.urlHints,css.fontPreloadandjavascript.dynamicImportCssPreload. (by @alexander-akait in #21477)Add built-in build progress via
infrastructureLogging.progress, plusestimatedTime,phaseTimings, progress barwidthandprogressBar: "auto"onProgressPlugin. (by @alexander-akait in #21477)Concatenate CommonJS modules with statically analyzable exports; opt out via
optimization.concatenateModules: { commonjs: false }. (by @alexander-akait in #21477)Wrap "weird" CommonJS modules into module concatenation instead of bailing out. (by @alexander-akait in #21477)
Add
output.html.inline(true | "script" | "style") and thewebpackInlinemagic comment to inline chunk content into HTML. (by @alexander-akait in #21477)Add
output.html.injectto control where chunk tags are injected. (by @alexander-akait in #21477)Add
output.html.title,output.html.metaandoutput.html.baseoptions for head generation. (by @alexander-akait in #21477)Support per-icon link attributes (
sizes,media,color,type,crossorigin) and arrays inoutput.html.favicon. (by @alexander-akait in #21487)Add
output.html.manifestto generate and link a web app manifest with hashed icons. (by @alexander-akait in #21487)Add
output.html.cspto inject a Content-Security-Policy meta with inline-content hashes and an optional nonce. (by @alexander-akait in #21487)Add the
output.htmlinjectTagscompilation hook to inject tags (script/link/meta/…) withinjectToplacement. (by @alexander-akait in #21487)Add the
output.htmltransformTagscompilation hook to mutate, remove, or move (between<head>and<body>) a page's existing<script>/<link>/<style>/<meta>tags. (by @alexander-akait in #21487)Extend the HTML pipeline with
htmllink sources (bundled as their own emitted page) andrel="preload"/"prefetch"links bundled as chunks. (by @alexander-akait in #21477)Recognize more asset-bearing HTML sources: the
twitter:player:streammeta, legacy SVG references, and Web App Manifesticons/screenshots/shortcutsURLs. (by @alexander-akait in #21477)Add
module.parser.html.asto parse HTML as a document or an element fragment. (by @alexander-akait in #21477)Allow disabling a built-in HTML parser source via
type: falseinsources. (by @alexander-akait in #21477)Export
webpack.html.HtmlModulesPluginwithtransformHtml/htmlEmittedcompilation hooks. (by @alexander-akait in #21477)Resolve
@custom-media(including media-type values) and@custom-selectorin native CSS. (by @alexander-akait in #21477)Scope
view-transition-name/-group/-classnames and::view-transition-*()pseudo references in CSS modules undercustomIdents. (by @alexander-akait in #21486)Add
import.meta.globsupport, with acaseSensitiveoption and consistent hidden/node_modulesmatching. (by @alexander-akait in #21477)Resolve
import.meta.resolve("./asset")to the emitted asset URL via theimportMeta.resolveparser option. (by @alexander-akait in #21477)Add
import.meta.envdefaults:MODE,DEV,PROD,SSRandBASE_URL. (by @alexander-akait in #21477)Add fine-grained
import.metaparser options. (by @alexander-akait in #21477)Deprecate the
importMetaContextparser option in favor ofimportMeta.webpackContext. (by @alexander-akait in #21477)Emit analyzable
new URL(…, import.meta.url), worker/worklet URL andimport()references with literal specifiers for ESM module output. (by @alexander-akait in #21477)Compile async modules to generators for targets without async/await. (by @alexander-akait in #21477)
Evaluate and validate the second argument of dynamic
import(specifier, options). (by @alexander-akait in #21477)Add
module.parser.javascript.workletto bundle WorkletaddModule()entries. (by @alexander-akait in #21477)Add
?raw,?url,?inlineand?no-inlineasset query suffixes underexperiments.futureDefaults. (by @alexander-akait in #21477)Add an
interop("default" | "esModule") hint for object externals to control default-export interop. (by @alexander-akait in #21477)Add an
amd-asyncexternals type that loads AMD externals without an AMD library wrapper. (by @alexander-akait in #21477)Support
cache.compression: "zstd"for the filesystem cache. (by @alexander-akait in #21477)Warn on strict-mode-only syntax and semantic hazards in ES module output, configurable via the
strictModeViolationsparser option. (by @alexander-akait in #21477)Support parsers without location APIs: locations derive from node offsets and AST nodes no longer carry
loc. (by @alexander-akait in #21477)Attach the original DOM event to
ChunkLoadErrorandScriptExternalLoadErroraserror.event. (by @alexander-akait in #21477)Add
output.wasmStreamingFallbackfor wasm fallback on a wrong MIME type. (by @alexander-akait in #21477)Show why a module was marked as not cacheable in stats output. (by @alexander-akait in #21477)
Expose the active
MultiWatchingonMultiCompiler.watching. (by @alexander-akait in #21477)Resolve git merge conflicts when parsing the build-http lockfile. (by @alexander-akait in #21477)
Patch Changes
Fix broken HMR with
output.moduleand non-importchunk loading by emitting a plain-JSON hot-update manifest. (by @alexander-akait in #21477)Fix unused CSS module exports leaking into the JS wrapper. (by @alexander-akait in #21477)
Fix deferred import evaluation: re-throw cached errors, guard forcing a still-evaluating module, keep re-exported deferred namespaces identical, and evaluate initial-chunk deferred context imports lazily. (by @alexander-akait in #21477)
Keep ESM live bindings for a module library's entry exports, including when the runtime is emitted as a separate chunk. (by @alexander-akait in #21477)
Fix SplitChunks merging undersized modules into the wrong result group. (by @alexander-akait in #21477)
Fix named id assignment reusing an already-used numbered suffix, which could produce duplicate module/chunk ids. (by @alexander-akait in #21477)
Fix inlined non-binary asset modules with
encoding: falseemitting "undefined" instead of their content. (by @alexander-akait in #21477)Decode non-base64 data URIs as UTF-8 so multi-byte characters are preserved. (by @alexander-akait in #21477)
Keep required JSON data intact when a prototype method (e.g.
arr.includes()) is called on it. (by @alexander-akait in #21477)Recognize modern RegExp flags (
d,s,u,v) when statically evaluatingnew RegExp(...). (by @alexander-akait in #21477)Merge object-form and dotted DefinePlugin definitions so
import.meta.env/process.envare consistent across direct, whole-object and destructured access. (by @alexander-akait in #21477)Emit an error when an object external has no entry for the used externals type. (by @alexander-akait in #21477)
Fix a persistent cache restore crash when a content section starts exactly on a content-buffer boundary. (by @alexander-akait in #21477)
Restore missing
internalSerializablesentries (webpack/lib/Module and cold filesystem cache). (by @alexander-akait in #21477)Fix watch rebuild crash when context symlink targets lack
timestampHash. (by @alexander-akait in #21477)Fix lazy compilation backend leaking idle module entries and hanging on exit. (by @alexander-akait in #21477)
Stop logging benign ECONNRESET client errors from the lazy compilation server. (by @alexander-akait in #21477)
Accept compilations from another webpack copy in
getCompilationHooksagain. (by @alexander-akait in #21477)Fix
output.htmlinjection edge cases: escaping, head detection, duplicate meta tags, resource-hint/entry-tag retention withinject: false, and stylesheet placement. (by @alexander-akait in #21477)Ignore a
<base>inside an inert<template>when resolving HTML URLs. (by @alexander-akait in #21477)Bust an HTML page's
[contenthash]when its inlined chunk content changes. (by @alexander-akait in #21477)Fix a dangling stylesheet
<link>for a JS-only chunk in an HTML entry. (by @alexander-akait in #21477)Fix a malformed HTML magic comment leaking a pending
webpackInlinedirective onto the next element. (by @alexander-akait in #21477)Fix off-by-one dropping the last character of an unterminated
url(...)at end-of-input. (by @alexander-akait in #21477)Consume the trailing whitespace of a CSS hex escape when unescaping identifiers. (by @alexander-akait in #21477)
Fix
[fullhash]inoutput.webassemblyModuleFilenameby dropping a stray brace and requesting thegetFullHashruntime module. (by @alexander-akait in #21477)Fix duplicated errors/warnings in stats output when detail-less entries exceed
errorsSpace/warningsSpace. (by @alexander-akait in #21477)Improve module parse errors with a babel-style code frame and the module type. (by @alexander-akait in #21485)
Fix
formatSizerendering sizes of 1 TiB or larger as "undefined". (by @alexander-akait in #21477)Skip the anonymous default export
.namefix-up whennameis non-configurable, instead of throwing on pre-ES2015 engines. (by @alexander-akait in #21477)Escape
?and#in context module regexp identifiers so source map names are not truncated. (by @alexander-akait in #21477)Resolve directory requests to their index module in scoped
DllReferencePlugin. (by @alexander-akait in #21477)Skip the
hasSymbolcheck in the async module runtime whenenvironment.symbolis set. (by @alexander-akait in #21477)Use a shared
__webpack_require__.cjshelper for wrapped CommonJS modules. (by @alexander-akait in #21477)Derive ASI positions from source text instead of acorn's
onInsertedSemicolon, so custom parsers need not collect semicolons. (by @alexander-akait in #21477)Avoid a second full parse for
autosource type by downgrading module to script in place on a top-level return. (by @alexander-akait in #21477)Fix exponential-time side-effects analysis on cyclic module graphs by memoizing cycle-free results via Tarjan lowlink. (by @alexander-akait in #21477)
Speed up JavaScript parsing and AST walking and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up CSS and HTML parsing and code generation and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up snapshot creation and reduce its memory usage. (by @alexander-akait in #21477)
Reduce allocations in JS codegen, concatenation, queues and parser setup. (by @alexander-akait in #21477)
Speed up stats generation on large builds by reusing the item context across array items. (by @alexander-akait in #21477)
Memoize loader resolution per compilation to avoid re-resolving the same loader for every matching module. (by @alexander-akait in #21477)
Reuse and harden webpack's shared resource parser in the loader runner. (by @alexander-akait in #21477)
Update webpack-sources to 3.5.1 and enhanced-resolve to 5.24.2 to cut peak memory. (by @alexander-akait in #21477)
Inline the loader-runner package into core. (by @alexander-akait in #21477)
Fix context hash crash on unsupported directory entries like FIFOs and sockets. (by @hai-x in #21484)
Verify internalSerializables in lint:special and regenerate it in fix:special. (by @alexander-akait in #21476)
webpack/webpack-dev-middleware (webpack-dev-middleware)
v8.0.4Compare Source
Patch Changes
on-finisheddependency with Node.js built-instream.finished. (by @bjohansebas in #2346)