Skip to content

chore(deps): bump svgo from 2.8.0 to 2.8.2#7309

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/svgo-2.8.2
Open

chore(deps): bump svgo from 2.8.0 to 2.8.2#7309
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/svgo-2.8.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 4, 2026

Bumps svgo from 2.8.0 to 2.8.2.

Release notes

Sourced from svgo's releases.

v2.8.2

This is effectively just a re-release of SVGO v2.8.1, but with *.test.js files omitted. It seems something was wrong with the configuration in the v2.8.0 tag and I hadn't noticed it included a few extra files. 😅

We'll deprecate v2.8.1, and I'll include the change log here.

What's Changed

Dependencies

  • Migrates from our unsupported fork of sax (@​trysound/sax) to the upstream version of sax (sax).

Bug Fixes

  • No longer throws error when encountering comments in DTD.

Metrics

Before and after of the browser bundle of each respective version:

v2.8.0 v2.8.2 Delta
svgo.browser.js 587.2 kB 589.2 kB ⬆️ 2 kB

Support

SVGO v2 is not officially supported, please consider upgrading to SVGO v4 instead. We've backported this fix as there are security implications, but there is no commitment to do this for more complex changes in future.

Consider reading our Migration Guide from v2 to v3 and Migration Guide from v3 to v4 which should ease the process.

v2.8.1

Deprecated

This release left *.test.js files in the package, which have been omitted in v2.8.2. Sorry for the noise!

What's Changed

Dependencies

  • Migrates from our unsupported fork of sax (@​trysound/sax) to the upstream version of sax (sax).

Bug Fixes

  • No longer throws error when encountering comments in DTD.

Metrics

Before and after of the browser bundle of each respective version:

v2.8.0 v2.8.1 Delta

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by sethiii, a new releaser for svgo since your current version.


Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added dependencies javascript Pull requests that update javascript code labels Mar 4, 2026
@greptile-apps
Copy link
Copy Markdown
Contributor

greptile-apps bot commented Mar 4, 2026

PR author is in the excluded authors list.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from cb53218 to a922375 Compare March 4, 2026 23:48
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from a922375 to 58043a1 Compare March 13, 2026 06:16
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 58043a1 to 9482816 Compare March 16, 2026 13:22
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 9482816 to 2712ed1 Compare March 17, 2026 20:13
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 2712ed1 to 1dde488 Compare March 20, 2026 15:57
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 1dde488 to de30434 Compare March 20, 2026 17:52
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from de30434 to 2729c7b Compare March 23, 2026 18:54
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 2729c7b to 30c1fcc Compare March 29, 2026 08:01
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 30c1fcc to d57f28d Compare March 29, 2026 18:09
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from d57f28d to 677dcef Compare March 30, 2026 06:11
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 677dcef to 4e070de Compare March 30, 2026 07:01
Bumps [svgo](https://github.com/svg/svgo) from 2.8.0 to 2.8.2.
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v2.8.0...v2.8.2)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 2.8.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/svgo-2.8.2 branch from 4e070de to b3d93a4 Compare April 2, 2026 14:03
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Apr 2, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants