Skip to content

Update all dependencies [skip netlify] - #1184

Merged
jgerigmeyer merged 2 commits into
mainfrom
renovate/all
Oct 5, 2026
Merged

jgerigmeyer merged 2 commits into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@11ty/eleventy-plugin-rss (source) 3.0.0 → 3.1.0 age confidence
@oddbird/popover-polyfill (source) 0.7.2 → 0.7.3 age confidence
chalk 6.0.0 → 6.0.1 age confidence
dotenv 18.0.3 → 18.0.5 age confidence
globals 17.12.0 → 17.13.0 age confidence
rollup (source) 4.63.5 → 4.63.6 age confidence
sanitize-html (source) 2.17.7 → 2.18.0 age confidence
sass-embedded 1.105.0 → 1.105.1 age confidence
stylelint (source) 17.15.0 → 17.16.0 age confidence

Release Notes

11ty/plugin-rss (@​11ty/eleventy-plugin-rss)

v3.1.0: Feeds (RSS, Atom, JSON) v3.1.0

Compare Source

  • Add collection.sort option to the Virtual Template: "auto" (default, previous behavior), "descending" (newest first by date, regardless of collection order), or "ascending". Use "descending" if your collection is sorted newest-first and your feed was showing your oldest posts. #​63
  • Add getFeedTemplate(options) export, which returns { content, data } for use with eleventyConfig.addTemplate so you can choose the virtual template path yourself (useful for multiple feeds of the same type).
    import { rssPlugin, getFeedTemplate } from "@11ty/eleventy-plugin-rss";
    
    export default function($config) {
    	$config.addPlugin(rssPlugin);
    
    	let { content, data } = getFeedTemplate({ type: "atom", outputPath: "/posts.xml", collection: { name: "posts" } });
    	$config.addTemplate("feeds/posts.njk", content, data);
    };
  • Feed entries without a URL (e.g. permalink: false) are now skipped by the Virtual Template instead of failing the build. #​66 (thank you @​robb-j for the assist in #​59)
  • Plugin helpers (feedPlugin, dateToRfc3339, dateToRfc822, getNewestCollectionItemDate, absoluteUrl, convertHtmlToAbsoluteUrls) are available on the default export again (matching CommonJS behavior in v2). Named exports are still the preferred method #​91
  • JSON Virtual Template now falls back to metadata.subtitle for the feed description (matching Atom and RSS) when metadata.description isn't set.
  • Fix Atom Virtual Template using <icon> instead of <logo> for metadata.logo by @​philipmw in #​90
  • Swap debug dependency for obug. DEBUG=Eleventy* works the same. #​100

Milestone: https://github.com/11ty/plugin-rss/milestone/10?closed=1
Full Changelog: 11ty/plugin-rss@v3.0.0...v3.1.0

oddbird/popover-polyfill (@​oddbird/popover-polyfill)

v0.7.3

Compare Source

  • 🐛 BUGFIX: Fix more SSR environment edge cases --
    #​293
  • 🏠 INTERNAL: Upgrade dependencies
chalk/chalk (chalk)

v6.0.1

Compare Source

  • Fix inconsistent coercion of two arguments 9c93a04

motdotla/dotenv (dotenv)

v18.0.5

Compare Source

Changed
  • Fix missing typescript module declaration (#​1068)
  • Improve performance for large .env files (#​1066)

v18.0.4

Compare Source

Changed
  • import dotenv/config should default quiet: true (#​1063)
sindresorhus/globals (globals)

v17.13.0

Compare Source


rollup/rollup (rollup)

v4.63.6

Compare Source

2026-10-01

Bug Fixes
  • Ensure external reexports are always imported when used in a reified dynamic namespace (#​6540)
Pull Requests
apostrophecms/apostrophe (sanitize-html)

v2.18.0

Compare Source

Adds
  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.
Fixes
  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to
    spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change
    in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also
    fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
    the fix.
Security
  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).

    Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.

sass/embedded-host-node (sass-embedded)

v1.105.1

Compare Source

  • Improve error messages for @extends across different media queries.
stylelint/stylelint (stylelint)

v17.16.0

Compare Source

It fixes 2 bugs in the layout-mappings rules. This will likely be the last 17.x release, as we prepare for 18.0.0.

  • Fixed: property-layout-mappings and unit-layout-mappings false negatives for uppercase property names and units (#​9485) (@​giaBaoJS).
  • Fixed: value-keyword-layout-mappings false positives for caption-side (#​9483) (@​giaBaoJS).

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

View diff of compiled files (may take a few minutes): https://github.com/oddbird/oddleventy-built/compare/main..renovate/all

@renovate

renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@jgerigmeyer
jgerigmeyer merged commit 21288d8 into main Oct 5, 2026
10 of 12 checks passed
@jgerigmeyer
jgerigmeyer deleted the renovate/all branch October 5, 2026 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant