Skip to content

chore: bump the npm-patch-minor group with 7 updates - #76

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-patch-minor-ee0fc010ea
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-patch-minor-ee0fc010ea

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-patch-minor group with 7 updates:

Package From To
@axe-core/playwright 4.12.1 4.13.0
@playwright/test 1.62.1 1.63.0
@types/node 26.1.2 26.6.4
html-validate 11.6.0 11.16.2
oxfmt 0.70.0 0.71.0
style-dictionary 5.5.0 5.6.0
yaml 2.9.0 2.9.1

Updates @axe-core/playwright from 4.12.1 to 4.13.0

Release notes

Sourced from @​axe-core/playwright's releases.

Release 4.13.0

What's Changed

Full Changelog: dequelabs/axe-core-npm@v4.11.3...v4.13.0

Changelog

Sourced from @​axe-core/playwright's changelog.

4.13.0 (2026-08-10)

Features

Commits

Updates @playwright/test from 1.62.1 to 1.63.0

Release notes

Sourced from @​playwright/test's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates @types/node from 26.1.2 to 26.6.4

Commits

Updates html-validate from 11.6.0 to 11.16.2

Release notes

Sourced from html-validate's releases.

v11.16.2

11.16.2 (2026-10-04)

Bug Fixes

  • cli: handle writing formatter output directly to file descriptors (8014966)
  • deps: update dependency ignore to v7.0.11 (c227d47)
  • deps: update dependency ignore to v7.0.12 (b1f84d7)

v11.16.1

11.16.1 (2026-09-27)

Bug Fixes

  • deps: update dependency ignore to v7.0.10 (b3540ce)
  • fix serialization error when jest or vitest worker got an autofixable result (69b9728), closes #372

v11.16.0

11.16.0 (2026-09-15)

Features

  • api: unified HtmlValidate.autofix() and deprecate all other variants (40c67f0)
  • rules: add minSectioningRootInitialRank option to heading-level (7b9629f)

Bug Fixes

  • deps: update dependency ignore to v7.0.9 (0337345)

v11.15.0

11.15.0 (2026-09-07)

Features

  • api: add new insertTextBefore() and insertTextAfter() methods to ErrorFixer` (ac6ca62)

v11.14.0

11.14.0 (2026-09-05)

Features

  • api: add fixableErrorCount and fixableWarningCount to Report object (5bad2dd)
  • api: add fixableErrorCount and fixableWarningCount to Result object (edc169f)
  • cli: stylish and codeframe formatters output number of fixable errors and warnings (6f230fc)
  • deps: support vitest v5 (9bc1709)

v11.13.0

11.13.0 (2026-09-03)

Features

... (truncated)

Changelog

Sourced from html-validate's changelog.

11.16.2 (2026-10-04)

Bug Fixes

  • cli: handle writing formatter output directly to file descriptors (8014966)
  • deps: update dependency ignore to v7.0.11 (c227d47)
  • deps: update dependency ignore to v7.0.12 (b1f84d7)

11.16.1 (2026-09-27)

Bug Fixes

  • deps: update dependency ignore to v7.0.10 (b3540ce)
  • fix serialization error when jest or vitest worker got an autofixable result (69b9728), closes #372

11.16.0 (2026-09-15)

Features

  • api: unified HtmlValidate.autofix() and deprecate all other variants (40c67f0)
  • rules: add minSectioningRootInitialRank option to heading-level (7b9629f)

Bug Fixes

  • deps: update dependency ignore to v7.0.9 (0337345)

11.15.0 (2026-09-07)

Features

  • api: add new insertTextBefore() and insertTextAfter() methods to ErrorFixer` (ac6ca62)

11.14.0 (2026-09-05)

Features

  • api: add fixableErrorCount and fixableWarningCount to Report object (5bad2dd)
  • api: add fixableErrorCount and fixableWarningCount to Result object (edc169f)
  • cli: stylish and codeframe formatters output number of fixable errors and warnings (6f230fc)
  • deps: support vitest v5 (9bc1709)

11.13.0 (2026-09-03)

Features

  • api: expose autofixCollectEdits for integrations to support autofix (b7de9fa)

11.12.0 (2026-09-01)

Features

... (truncated)

Commits
  • 712042c chore(release): 11.16.2
  • 658d4c3 Merge branch 'feature/format-fd' into 'master'
  • 8014966 fix(cli): handle writing formatter output directly to file descriptors
  • beac346 chore(deps): update dependency npm-pkg-lint to v5.4.0
  • 60f50a5 chore(deps): update dependency rollup to v4.64.0
  • 559d12d Merge branch 'perf/test-speed' into 'master'
  • 6adf858 refactor(meta): replace hash-based schema caching with strings
  • 38093c5 chore(deps): update dependency cssnano to v9.2.0
  • b1f84d7 fix(deps): update dependency ignore to v7.0.12
  • 76bb1e1 chore(deps): update dependency npm-pkg-lint to v5.3.2
  • Additional commits viewable in compare view

Updates oxfmt from 0.70.0 to 0.71.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.71.0

🚀 Features

  • e0b1f9f oxfmt: Bump bundled Prettier version to 3.9.9 (#27002) (leaysgur)
  • 342527d oxfmt: Bump bundled Prettier version to 3.9.8 (#26999) (leaysgur)

🐛 Bug Fixes

  • eeba1db formatter: Skip test-call layout when arguments have comments (#27119) (leaysgur)
  • 1f7b8ad oxfmt: Allow repeated CLI calls in the same process (#27051) (Liang)
  • 7bcb807 formatter_markdown: Keep blank line between HTML and nested list (#27112) (leaysgur)
  • 10b10c5 formatter: Keep comments around = on their side and line (#27041) (leaysgur)
  • 9aad365 formatter: Keep comments deferred before an assignment operator (#26997) (waltu)
  • 8fbddb1 formatter/jsdoc: More alignment with original plugin (#27039) (leaysgur)
  • 50be18e formatter: Keep trailing spaces on normal block comments (#27037) (leaysgur)
  • 56d1880 formatter: Nestle adjacent block comments (#27036) (leaysgur)
  • 3be5d94 formatter: Treat /*** comments as JSDoc (#27035) (leaysgur)
  • cd45f71 formatter: Keep trailing double spaces on JSDoc lines (#26861) (John Costa)
  • fd695f4 formatter_markdown: Fix more mismatches found in ecosystem-ci repos (#27003) (leaysgur)
  • 4e77d59 formatter_markdown: Keep a math span after a kept line break from opening a block (#27001) (leaysgur)
  • 584b8b0 formatter_markdown: Keep a shape line after a multi-line inline node or link title (#27000) (leaysgur)
  • b939645 formatter_markdown: Keep a line break before an inline liquid tag under preserve (#26998) (leaysgur)
Commits

Updates style-dictionary from 5.5.0 to 5.6.0

Release notes

Sourced from style-dictionary's releases.

v5.6.0

Minor Changes

  • 2f28731: Add "sassdoc" comment style (a triple-slash short comment)

Patch Changes

  • 76074dc: Fix outputReferences leaking a raw {group.$root} placeholder into formatted output instead of resolving it, when a reference path segment (e.g. a DTCG $root token) contains a RegExp special character.

v5.5.5

Patch Changes

  • bc51123: Fix prototype pollution GHSA-cr3w-v879-f973 for nested objects created by the convertTokenData utility in "object" output mode.

v5.5.4

Patch Changes

  • 0170a9a: Patch @​bundled-es-modules/glob which fixes a transitive dependency vulnerability (glob->url->qs).

v5.5.3

Patch Changes

  • 863685d: Limit nested composite token expansion to the configured type filters.
  • 2aced93: Preserve alpha precision in the color/css transform.

v5.5.2

Patch Changes

  • b65ea0b: Disallow output literal "undefined" for tokens with descriptions when commentStyle is set to none.

v5.5.1

Patch Changes

Changelog

Sourced from style-dictionary's changelog.

5.6.0

Minor Changes

  • 2f28731: Add "sassdoc" comment style (a triple-slash short comment)

Patch Changes

  • 76074dc: Fix outputReferences leaking a raw {group.$root} placeholder into formatted output instead of resolving it, when a reference path segment (e.g. a DTCG $root token) contains a RegExp special character.

5.5.5

Patch Changes

5.5.4

Patch Changes

  • 0170a9a: Patch @​bundled-es-modules/glob which fixes a transitive dependency vulnerability (glob->url->qs).

5.5.3

Patch Changes

  • 863685d: Limit nested composite token expansion to the configured type filters.
  • 2aced93: Preserve alpha precision in the color/css transform.

5.5.2

Patch Changes

  • b65ea0b: Disallow output literal "undefined" for tokens with descriptions when commentStyle is set to none.

5.5.1

Patch Changes

Commits
  • 8710de9 chore: release (#1759)
  • 9f94e71 chore(deps-dev): bump brace-expansion from 1.1.18 to 1.1.21 (#1761)
  • aa58ad4 chore(deps-dev): bump dompurify from 3.4.13 to 3.4.16 (#1762)
  • f092a44 chore(deps): bump devalue from 5.9.2 to 5.9.4 (#1760)
  • a5b1a8a docs: update basic example documentation to reflect new file structure (#1742)
  • 2f28731 feat: add “sassdoc” comment style (a triple-slash short comment) (#1753)
  • 76074dc fix: escape regex special chars when matching reference names in outputRefere...
  • 951cc61 chore: update changelog with other GH advisory link, for tracking (#1752)
  • 489abdf chore: release (#1751)
  • bc51123 fix: nested obj proto pollution vulnerability in convertTokenData() (#1750)
  • Additional commits viewable in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-patch-minor group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [@axe-core/playwright](https://github.com/dequelabs/axe-core-npm) | `4.12.1` | `4.13.0` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.6.4` |
| [html-validate](https://gitlab.com/html-validate/html-validate) | `11.6.0` | `11.16.2` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.70.0` | `0.71.0` |
| [style-dictionary](https://github.com/style-dictionary/style-dictionary) | `5.5.0` | `5.6.0` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |


Updates `@axe-core/playwright` from 4.12.1 to 4.13.0
- [Release notes](https://github.com/dequelabs/axe-core-npm/releases)
- [Changelog](https://github.com/dequelabs/axe-core-npm/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/dequelabs/axe-core-npm/commits/v4.13.0)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@types/node` from 26.1.2 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `html-validate` from 11.6.0 to 11.16.2
- [Release notes](https://gitlab.com/html-validate/html-validate/tags)
- [Changelog](https://gitlab.com/html-validate/html-validate/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/html-validate/html-validate/compare/v11.6.0...v11.16.2)

Updates `oxfmt` from 0.70.0 to 0.71.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.71.0/npm/oxfmt)

Updates `style-dictionary` from 5.5.0 to 5.6.0
- [Release notes](https://github.com/style-dictionary/style-dictionary/releases)
- [Changelog](https://github.com/style-dictionary/style-dictionary/blob/main/CHANGELOG.md)
- [Commits](style-dictionary/style-dictionary@v5.5.0...v5.6.0)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

---
updated-dependencies:
- dependency-name: "@axe-core/playwright"
  dependency-version: 4.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: html-validate
  dependency-version: 11.16.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: oxfmt
  dependency-version: 0.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: style-dictionary
  dependency-version: 5.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@altaywtf

Copy link
Copy Markdown
Member

Superseded by Renovate.

@altaywtf altaywtf closed this Oct 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@altaywtf
altaywtf deleted the dependabot/npm_and_yarn/npm-patch-minor-ee0fc010ea branch October 10, 2026 07:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant