Skip to content

chore(deps): roll up 11 Dependabot patch and minor updates - #36470

Open
Hotell wants to merge 24 commits into
microsoft:masterfrom
Hotell:dependabot-rollup/20260731-145324
Open

chore(deps): roll up 11 Dependabot patch and minor updates#36470
Hotell wants to merge 24 commits into
microsoft:masterfrom
Hotell:dependabot-rollup/20260731-145324

Conversation

@Hotell

@Hotell Hotell commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Summary

Rollup of 11 open Dependabot patch/minor updates into a single PR, created with /dependabot-rollup.

Each source PR head was merged with --no-ff onto master; all merged without conflicts. yarn dedupe was then run and committed.

Merged updates

PR Update Kind
#36434 node-forge 1.3.3 → 1.4.0 minor
#36451 launch-editor 2.6.1 → 2.14.1 minor
#36445 postcss 8.5.10 → 8.5.18 patch
#36448 http-proxy-middleware 2.0.9 → 2.0.10 patch
#36449 undici 7.25.0 → 7.29.0 minor
#36450 websocket-driver 0.7.4 → 0.7.5 patch
#36444 @babel/core 7.29.0 → 7.29.6 patch
#36446 systeminformation 5.30.7 → 5.33.1 minor
#36458 flatted 3.3.3 → 3.4.3 minor
#36460 koa 2.16.1 → 2.16.4 patch
#36447 tar 7.5.20 → 7.5.22 patch

Skipped: none.

Excluded from this rollup

Semver-major GitHub Actions bumps are intentionally kept separate for focused review:

PR Reason
#36427 actions/setup-node 6 → 7, semver-major
#36428 actions/upload-pages-artifact 4 → 5, semver-major
#36429 actions/labeler 6 → 7, semver-major
#36430 actions/checkout 6 → 7, semver-major
#36431 actions/download-artifact 7 → 8, semver-major

Validation

yarn install --immutable   # passed, lockfile consistent after merges
yarn dedupe                # deduped nanoid + postcss ranges, committed
yarn dedupe --check        # "No packages can be deduped using the highest strategy"

Full build/test/lint validation is delegated to CI on this PR — the lockfile change marks all 255 Nx projects as affected.

Notes

  • No source Dependabot PR was closed or modified. Close them once this rollup merges.
  • No beachball change file: only yarn.lock and workspace package.json dev dependency ranges changed, no published package source.

dependabot Bot and others added 24 commits July 22, 2026 10:30
Bumps [node-forge](https://github.com/digitalbazaar/forge) from 1.3.3 to 1.4.0.
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md)
- [Commits](digitalbazaar/forge@v1.3.3...v1.4.0)

---
updated-dependencies:
- dependency-name: node-forge
  dependency-version: 1.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.29.0 to 7.29.6.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core)

---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-version: 7.29.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.18.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.10...8.5.18)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.18
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [http-proxy-middleware](https://github.com/chimurai/http-proxy-middleware) from 2.0.9 to 2.0.10.
- [Release notes](https://github.com/chimurai/http-proxy-middleware/releases)
- [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v2.0.10/CHANGELOG.md)
- [Commits](chimurai/http-proxy-middleware@v2.0.9...v2.0.10)

---
updated-dependencies:
- dependency-name: http-proxy-middleware
  dependency-version: 2.0.10
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [systeminformation](https://github.com/sebhildebrandt/systeminformation) from 5.30.7 to 5.33.1.
- [Release notes](https://github.com/sebhildebrandt/systeminformation/releases)
- [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md)
- [Commits](sebhildebrandt/systeminformation@v5.30.7...v5.33.1)

---
updated-dependencies:
- dependency-name: systeminformation
  dependency-version: 5.33.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.25.0 to 7.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.25.0...v7.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.
- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-driver-node@0.7.4...0.7.5)

---
updated-dependencies:
- dependency-name: websocket-driver
  dependency-version: 0.7.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.6.1 to 2.14.1.
- [Commits](vitejs/launch-editor@v2.6.1...v2.14.1)

---
updated-dependencies:
- dependency-name: launch-editor
  dependency-version: 2.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.3.
- [Commits](WebReflection/flatted@v3.3.3...v3.4.3)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [koa](https://github.com/koajs/koa) from 2.16.1 to 2.16.4.
- [Release notes](https://github.com/koajs/koa/releases)
- [Changelog](https://github.com/koajs/koa/blob/master/History.md)
- [Commits](koajs/koa@v2.16.1...v2.16.4)

---
updated-dependencies:
- dependency-name: koa
  dependency-version: 2.16.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.20 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.20...v7.5.22)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@github-actions

Copy link
Copy Markdown

📊 Bundle size report

✅ No changes found

@github-actions

Copy link
Copy Markdown

Pull request demo site: URL

Comment thread package.json
@Hotell
Hotell marked this pull request as ready for review July 31, 2026 16:13
@Hotell
Hotell requested a review from a team as a code owner July 31, 2026 16:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant