Repository navigation
Update all dependencies [skip netlify] - #1184
Merged
Merged
Conversation
|
View diff of compiled files (may take a few minutes): https://github.com/oddbird/oddleventy-built/compare/main..renovate/all |
renovate
Bot
force-pushed
the
renovate/all
branch
from
October 5, 2026 13:00
65f2319 to
d9d0faa
Compare
jgerigmeyer
approved these changes
Oct 5, 2026
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.0→3.1.00.7.2→0.7.36.0.0→6.0.118.0.3→18.0.517.12.0→17.13.04.63.5→4.63.62.17.7→2.18.01.105.0→1.105.117.15.0→17.16.0Release Notes
11ty/plugin-rss (@11ty/eleventy-plugin-rss)
v3.1.0: Feeds (RSS, Atom, JSON) v3.1.0Compare Source
collection.sortoption to the Virtual Template:"auto"(default, previous behavior),"descending"(newest first by date, regardless of collection order), or"ascending". Use"descending"if your collection is sorted newest-first and your feed was showing your oldest posts. #63getFeedTemplate(options)export, which returns{ content, data }for use witheleventyConfig.addTemplateso you can choose the virtual template path yourself (useful for multiple feeds of the same type).permalink: false) are now skipped by the Virtual Template instead of failing the build. #66 (thank you @robb-j for the assist in #59)feedPlugin,dateToRfc3339,dateToRfc822,getNewestCollectionItemDate,absoluteUrl,convertHtmlToAbsoluteUrls) are available on the default export again (matching CommonJS behavior in v2). Named exports are still the preferred method #91metadata.subtitlefor the feeddescription(matching Atom and RSS) whenmetadata.descriptionisn't set.<icon>instead of<logo>formetadata.logoby @philipmw in #90debugdependency forobug.DEBUG=Eleventy*works the same. #100Milestone: https://github.com/11ty/plugin-rss/milestone/10?closed=1
Full Changelog: 11ty/plugin-rss@v3.0.0...v3.1.0
oddbird/popover-polyfill (@oddbird/popover-polyfill)
v0.7.3Compare Source
#293
chalk/chalk (chalk)
v6.0.1Compare Source
9c93a04motdotla/dotenv (dotenv)
v18.0.5Compare Source
Changed
v18.0.4Compare Source
Changed
import dotenv/configshould default quiet: true (#1063)sindresorhus/globals (globals)
v17.13.0Compare Source
b007369rollup/rollup (rollup)
v4.63.6Compare Source
2026-10-01
Bug Fixes
Pull Requests
apostrophecms/apostrophe (sanitize-html)
v2.18.0Compare Source
Adds
loggeroption: pass any console-shaped object, withdebug,info,warnanderrormethods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.Fixes
allowedSchemesByTagis now applied tosrcsetandimagesrcsetURLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the globalallowedSchemesand ignored a tag-specific scheme allowlist. Thanks tospokodev for the fix.
sanitize-htmlbegan escaping any markup preserved inside a disallowed iframe tag, which was a changein behavior due to an upstream change in
htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but alsofully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
the fix.
Security
When
metawas allowed together with itshttp-equivandcontentattributes, the destination URL of a<meta http-equiv="refresh" content="0;url=...">was never checked againstallowedSchemes, because it is embedded incontentrather than being an attribute of its own. Sojavascript:,data:and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case ofurl=, and checked againstallowedSchemes(orallowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, thecontentattribute is removed.contenton othermetaelements is unchanged. The default configuration does not allowmetaand was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).Thanks to adrbogacz for reporting the vulnerability.
When
noscriptis listed innonTextTags, the discarded region could end too early. Browsers with scripting enabled treat<noscript>content as raw text up to the first</noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside<noscript>closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the<noscript>element, while implied closes of othernonTextTagssuch as<option>behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).Thanks to joaquiniglesiaslug for reporting the vulnerability.
The check that drops SVG animation elements (
animate,animateColor,animateMotion,animateTransform,set) when they retarget a URL attribute such ashrefcompared the full tag name, so a namespace-prefixed spelling likesvg:animatewas not recognized when such tags were allowed (for example withallowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to ajavascript:URL after sanitization. The element andattributeNameare now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.
sass/embedded-host-node (sass-embedded)
v1.105.1Compare Source
@extends across different media queries.stylelint/stylelint (stylelint)
v17.16.0Compare Source
It fixes 2 bugs in the
layout-mappingsrules. This will likely be the last17.xrelease, as we prepare for18.0.0.property-layout-mappingsandunit-layout-mappingsfalse negatives for uppercase property names and units (#9485) (@giaBaoJS).value-keyword-layout-mappingsfalse positives forcaption-side(#9483) (@giaBaoJS).Configuration
📅 Schedule: (in timezone America/New_York)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.