Skip to content

chore(deps): update npm packages#410

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/npm-packages
Jul 20, 2026
Merged

chore(deps): update npm packages#410
renovate[bot] merged 1 commit into
mainfrom
renovate/npm-packages

Conversation

@renovate

@renovate renovate Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@angular/animations (source) 22.0.622.0.7 age adoption passing confidence
@angular/build 22.0.622.0.7 age adoption passing confidence
@angular/cdk 22.0.422.0.5 age adoption passing confidence
@angular/common (source) 22.0.622.0.7 age adoption passing confidence
@angular/compiler (source) 22.0.622.0.7 age adoption passing confidence
@angular/compiler-cli (source) 22.0.622.0.7 age adoption passing confidence
@angular/core (source) 22.0.622.0.7 age adoption passing confidence
@angular/forms (source) 22.0.622.0.7 age adoption passing confidence
@angular/material 22.0.422.0.5 age adoption passing confidence
@angular/platform-browser (source) 22.0.622.0.7 age adoption passing confidence
@angular/platform-browser-dynamic (source) 22.0.622.0.7 age adoption passing confidence
@angular/router (source) 22.0.622.0.7 age adoption passing confidence
@sanity/types (source) 6.4.06.5.0 age adoption passing confidence
@tailwindcss/vite (source) 4.3.24.3.3 age adoption passing confidence
autoprefixer 10.5.210.5.4 age adoption passing confidence
obug 2.1.32.1.4 age adoption passing confidence
pkg-pr-new (source) 0.0.750.0.78 age adoption passing confidence
postcss (source) 8.5.178.5.19 age adoption passing confidence
posthog-js (source) 1.399.11.403.0 age adoption passing confidence
tailwindcss (source) 4.3.24.3.3 age adoption passing confidence
tsx (source) 4.23.04.23.1 age adoption passing confidence
vite (source) 8.1.48.1.5 age adoption passing confidence

Release Notes

angular/angular (@​angular/animations)

v22.0.7

Compare Source

common
Commit Type Description
91e33aa1de fix avoid prototype lookups in date format caches
compiler
Commit Type Description
5b516e3a58 fix parsing of an empty template literal interpolation
compiler-cli
Commit Type Description
c88ddde1c9 fix re-tag SourceFiles after TsCreateProgramDriver.updateFiles()
core
Commit Type Description
94d9591b51 fix allow static attributes for explicit input transforms
c89f71a74c fix ignore processing instruction syntax in templates
70500e4067 fix preserve explicit input transform write type
forms
Commit Type Description
1b9964675f fix allow multiple async validators
64d6d47a0c fix preserve intermediate number values in signal forms
6cf7446afa fix prevent stale CVA writeback during debounce
http
Commit Type Description
20b7dc3023 fix prevent interceptor signal reads from leaking into calling reactive contexts
localize
Commit Type Description
22d5a091d1 fix build runtime translations map with a null prototype
8ce1fcf7fa fix use Object.hasOwn for placeholder lookup in translate
platform-browser
Commit Type Description
b34bf0dce8 fix prevent ReDoS in SOURCEMAP_URL_REGEXP
angular/angular-cli (@​angular/build)

v22.0.7

Compare Source

@​angular/cli
Commit Type Description
e85c10ccb fix copy packageManager field and yarn config for temp installs
b87cafec0 fix support resolving subproject dependencies in pnpm workspaces
angular/components (@​angular/cdk)

v22.0.5

Compare Source

aria
Commit Type Description
e74c69be33 fix combobox: closing immediately when opening programmatically with zone.js (#​33518)
cdk
Commit Type Description
1059f80cef fix overlay: guard against null document.body before popover support check (#​33403)
adbf93559e fix private: guard createPolicy against DOM clobbering (#​33410)
material
Commit Type Description
d26e892021 fix button: match focus indicator shape to FAB (#​33527)
ea89b9c37f fix datepicker: use rounded shape for calendar focus indicators (#​33524)
092b55aa67 fix sort: double focus indicators when strong focus is enabled (#​33520)
e93bc9e5d6 fix stepper: add border radius to header hover state in m2 (#​33529)
multiple
Commit Type Description
b2620abaa2 fix pass form field to error state tracker (#​33509)
sanity-io/sanity (@​sanity/types)

v6.5.0

Compare Source

Sanity Studio v6.5.0

This release includes various improvements and bug fixes.

For the complete changelog with all details, please visit:
www.sanity.io/changelog/studio-Ni40LjA

Install or upgrade Sanity Studio

To upgrade to this version, run:

npm install sanity@latest

To initiate a new Sanity Studio project or learn more about upgrading, please refer to our comprehensive guide on Installing and Upgrading Sanity Studio.

📓 Full changelog

Author Message Commit
squiggler-app[bot] chore(tests): generate dts tests 🤖 ✨ (#​13514) df9d16f
@​stipsan fix(release-notes): produce schema-valid suggested content (#​13515) 1acd626
@​stipsan fix(form): keep empty reference array items when clicking custom item UI (#​13508) 73aeb3b
@​pedrobonamin fix(core): defer onDeleteComplete until after dialog cleanup (#​13512) 7837303
@​pedrobonamin fix(core): clear scheduled draft perspective after deleting scheduled draft (#​13509) 1d3ea79
@​bjoerge chore(dev): perf bench followups (#​13507) f6bd1e6
@​snorrees fix(structure): allow all document actions when a Canvas-linked document is editable (#​13506) 02c71ff
@​bjoerge chore(dev): add perf bench (#​13442) 376f1dd
squiggler-app[bot] fix(deps): update dependency @​sanity/cli to ^7.8.0 (#​13501) d5384dc
squiggler-app[bot] chore(tests): generate dts tests 🤖 ✨ (#​13492) c9a1a58
@​bjoerge fix: only show document sync state toast on actual commit failures (#​13487) 0c7bf65
@​bjoerge fix: keep editState + document versions warm across subscription churn (#​13490) f7a0425
@​pedrobonamin feat(variants): allow creating variant documents in releases (#​13488) bef5e19
@​stipsan chore(lint): turn off no-unnecessary-type-assertion (#​13486) b7d3c8d
squiggler-app[bot] chore(deps): update dependency i18next to ^26.3.6 (#​13418) e7270c1
@​juice49 chore: revert "chore(lint): make no-unnecessary-type-assertion an error with grandfathered suppressions (#​13375)" (#​13484) ebae0ce
squiggler-app[bot] chore(deps): dedupe pnpm-lock.yaml (#​13483) 5fe5c6f
squiggler-app[bot] chore(tests): generate dts tests 🤖 ✨ (#​13471) da58c4f
squiggler-app[bot] chore(deps): update dependency vite to ^8.1.4 (#​13369) b74d8ce
squiggler-app[bot] chore(deps): dedupe pnpm-lock.yaml (#​13444) 8d0f761
@​juice49 chore(sanity): lint getVariantsDocumentCounts (#​13479) 4b4bb83
Copilot fix(variants): pass variant id to useSetVariant from pin button (#​13478) 5fc9d92
@​jordanl17 feat(telemetry): track workspace feature flags in workspace features observed (#​13386) bb9fccb
@​pedrobonamin feat(variants): add pin button to variants tool (#​13468) 20dc63d
@​juice49 refactor(sanity): reduce data needed by setVariant to simply the variant id (#​13473) 529eb0e
@​christianhg feat(comments): anchor text comments on the block's data path (#​13116) dc5f601
@​christianhg test(test-studio): toggle inline containers on the Container Table field (#​13116) 93e1bb7
@​christianhg fix(comments): match CommentsField threads by path prefix (#​13116) 51859f8
@​pedrobonamin feat(variants): prevent variant deletion when it has documents (#​13467) 241ba91
@​binoy14 feat(schema): add descriptor upload client (#​13284) 4b4bf8a
@​bjoerge chore: migrate more internal cli's to optique (#​13470) 7b4f70e
@​bjoerge fix(core): delegate useProject request errors to the studio error channel (#​13459) 6e197c4
@​pedrobonamin feat(variants): show live document counts in variants overview (#​13460) 4650c5b
@​bjoerge refactor(internal): migrate internal clis from yargs to optique (#​13466) 00f41e9
@​bjoerge fix(sanity): base reload prompt on served package version, drop range heuristic (#​13462) 210efaf
@​bjoerge fix: treat session not found as an invalid session (#​13458) 0a2698e
@​juice49 chore(sanity): expose variants preview state to document group inventory machine (#​13463) e4496c0
@​juice49 chore(sanity): expose variants to document group inventory machine (#​13463) 211bb21
@​bjoerge fix(structure): delegate intent resolution request failures to studio error handler (#​13464) e19ca5c
@​pedrobonamin feat(perspective): support setting variant and perspective atomically (#​13461) a2242c9
@​bjoerge fix: only offer reload-to-update for versions auto-update will serve (#​13451) 11edcfa
squiggler-app[bot] fix(deps): update dependency @​sanity/cli to ^7.7.1 (#​13453) bcebe7c
@​pedrobonamin refactor(releases): split bundle document type into shared, release and variant types (#​13446) dc3438c
squiggler-app[bot] chore(tests): generate dts tests 🤖 ✨ (#​13456) 5535b98
@​pedrobonamin fix(core): variants details not rendering the documents (#​13455) 4ab4b17
@​pedrobonamin chore: disable automatic issue triage (#​13452) d51f56c
@​pedrobonamin fix(vision): make saved queries side panel scrollable (#​13449) 4e796ad
@​pedrobonamin chore(core): updates to variant detail page (#​13230) d38f654
squiggler-app[bot] fix(deps): update dependency @​sanity/preview-url-secret to ^4.0.8 (#​13420) e81a160
tailwindlabs/tailwindcss (@​tailwindcss/vite)

v4.3.3

Compare Source

Fixed
  • Support --watch --poll[=ms] in @tailwindcss/cli when filesystem events are unreliable or unavailable (#​20297)
  • Canonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. bg-[#fff] and bg-[#FFF]bg-white) (#​20298)
  • Prevent Preflight from overriding Firefox's native iframe:focus-visible outline styles (#​20292)
  • Ensure theme('colors.foo') in JS plugins resolves correctly when both --color-foo and --color-foo-bar exist (#​20299)
  • Ensure fractional opacity modifiers work with named shadow sizes like shadow-sm/12.5, text-shadow-sm/12.5, drop-shadow-sm/12.5, and inset-shadow-sm/12.5 (#​20302)
  • Parse selectors like [data-foo]div as two selectors instead of one (#​20303)
  • Ensure @tailwindcss/postcss rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#​20310)
  • Ensure CSS nesting is handled even when Lightning CSS isn't run, such as in @tailwindcss/browser and Tailwind Play (#​20124)
  • Prevent achromatic theme colors from shifting hue when mixed in polar color spaces like oklch (#​20314)
  • Ensure --spacing(0) is optimized to 0px instead of 0 so it remains a <length> when used in calc(…) (#​20319)
  • Load @parcel/watcher only when needed in @tailwindcss/cli --watch mode, so one-off builds and --watch --poll work when @parcel/watcher can't be loaded (#​20325)
  • Use explicit platform fonts instead of system-ui and ui-sans-serif so CJK text respects the page's lang attribute on Windows (#​20318)
  • Prevent @tailwindcss/upgrade from rewriting ignored files when run from a subdirectory (#​20329)
  • Ensure earlier @source rules pointing to nested files are scanned when later @source rules point to files in parent folders (#​20335)
  • Prevent @tailwindcss/vite from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#​20336)
postcss/autoprefixer (autoprefixer)

v10.5.4

Compare Source

v10.5.3

Compare Source

sxzz/obug (obug)

v2.1.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
stackblitz-labs/pkg.pr.new (pkg-pr-new)

v0.0.78

Compare Source

postcss/postcss (postcss)

v8.5.19

Compare Source

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

v8.5.18

Compare Source

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).
PostHog/posthog-js (posthog-js)

v1.403.0

Compare Source

1.403.0

Minor Changes
  • #​4159 fad6d9a Thanks @​haacked! - add $feature_flag_has_experiment to $feature_flag_called events

    $feature_flag_called events now carry a $feature_flag_has_experiment boolean sourced from the server's has_experiment flag metadata (the /flags?v=2 response for remote evaluation, the /api/feature_flag/local_evaluation definitions for posthog-node local evaluation). The property is only sent when the server explicitly reports has_experiment; it is omitted entirely when the value is unknown (older servers, missing metadata, bootstrapped or locally injected flags). (2026-07-16)

Patch Changes

v1.402.3

Compare Source

1.402.3

Patch Changes
  • #​4157 4a2ecf5 Thanks @​posthog! - Session recording no longer emits an uncaught NotAllowedError ("Sharing constructed stylesheets in multiple documents is not allowed") when a page assigns a CSSStyleSheet constructed in a different document to adoptedStyleSheets. That assignment is the host page's own invalid operation, but the recorder's patched setter sat on the call stack, so the exception was attributed to rrweb and churned fingerprints in error tracking. The recorder now contains this specific rejection (matched by its standardized NotAllowedError name, so it works even when the setter throws from an iframe realm) and skips recording those sheets, while still re-throwing any other native-setter error so host-page behaviour is preserved.
    (2026-07-15)

  • #​4158 0dc389e Thanks @​posthog! - fix(replay): session recording no longer throws TypeError: Converting circular structure to JSON when replay event data contains a circular reference. The circular-reference guard now also detects cycles that pass through an array, and affected events are captured with [Circular] markers instead of surfacing an unhandled error and being dropped.
    (2026-07-15)

  • Updated dependencies [fc2cb2e]:

v1.402.2

Compare Source

1.402.2

Patch Changes
  • #​4151 81adbfd Thanks @​posthog! - Session recording no longer emits an uncaught TypeError: Illegal invocation when a programmatic input-value change happens on an object that is not a genuine n

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • "before 10am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) July 19, 2026 18:45
@socket-security

socket-security Bot commented Jul 19, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @angular/build is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: napi/playground/package.jsonnpm/@angular/build@22.0.7

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@angular/build@22.0.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/npm-packages branch from d9b06eb to 88e7158 Compare July 19, 2026 21:39
@renovate
renovate Bot merged commit 1f8baa7 into main Jul 20, 2026
10 checks passed
@renovate
renovate Bot deleted the renovate/npm-packages branch July 20, 2026 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant