Skip to content

chore(deps): update all non-major dependencies#2136

Open
chrisbbreuer wants to merge 1 commit into
mainfrom
buddy-bot/update-non-major-updates
Open

chore(deps): update all non-major dependencies#2136
chrisbbreuer wants to merge 1 commit into
mainfrom
buddy-bot/update-non-major-updates

Conversation

@chrisbbreuer
Copy link
Copy Markdown
Member

@chrisbbreuer chrisbbreuer commented May 5, 2026

This PR contains the following updates:

Package Updates Summary

Type Count
📦 NPM Packages 5
Total 5

📦 npm Dependencies

npm

5 packages will be updated

Package Change Age Adoption Passing Confidence
lodash (source) 4.17.23 -> 4.18.1 age adoption passing confidence
@stacksjs/bunpress (source) 0.1.4 -> 0.1.6 age adoption passing confidence
@stacksjs/clapp (source) 0.2.8 -> 0.2.10 age adoption passing confidence
bunfig (source) 0.15.11 -> 0.15.13 age adoption passing confidence
vue (source) 3.5.0 -> 3.5.34 age adoption passing confidence

Release Notes

lodash/lodash (lodash)

4.17.23 -> 4.18.1

4.18.1

Compare Source

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See lodash/lodash#6167#issuecomment-4165269769

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

[View full release notes]

Released by jonchurch on 4/1/2026

4.18.0

Compare Source

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, [879aaa9](lodash/lodash@879aaa931...

[View full release notes]

Released by jonchurch on 3/31/2026

stacksjs/bunpress (@stacksjs/bunpress)

0.1.4 -> 0.1.6

v0.1.6

Compare Source

Released by github-actions[bot] on 5/24/2026

v0.1.5

Compare Source

Released by github-actions[bot] on 5/10/2026

stacksjs/clapp (@stacksjs/clapp)

0.2.8 -> 0.2.10

v0.2.10

Compare Source

Released by github-actions[bot] on 5/14/2026

v0.2.9

Compare Source

Released by github-actions[bot] on 5/11/2026

stacksjs/bunfig (bunfig)

0.15.11 -> 0.15.13

v0.15.13

Compare Source

Released by github-actions[bot] on 5/8/2026

v0.15.12

Compare Source

Released by github-actions[bot] on 5/8/2026

v0.15.9

Compare Source

Released by github-actions[bot] on 4/29/2026

vuejs/core (vue)

3.5.0 -> 3.5.34

v3.6.0-beta.12

Compare Source

For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the minor branch.

Released by github-actions[bot] on 5/15/2026

v3.6.0-beta.11

Compare Source

For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the minor branch.

Released by github-actions[bot] on 5/7/2026

v3.5.34

Compare Source

For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the minor branch.

Released by github-actions[bot] on 5/6/2026


📊 Package Statistics

  • lodash: 155,057,075 weekly downloads
  • @stacksjs/bunpress: 62,721 weekly downloads
  • @stacksjs/clapp: 79,607 weekly downloads
  • bunfig: 72,213 weekly downloads
  • vue: 13,386,057 weekly downloads

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Buddy 🤖

@netlify
Copy link
Copy Markdown

netlify Bot commented May 5, 2026

Deploy Preview for ts-quick-reaction failed. Why did it fail? →

Name Link
🔨 Latest commit 2ea2fdb
🔍 Latest deploy log https://app.netlify.com/projects/ts-quick-reaction/deploys/6a13799f28fc97000821d7ee

@chrisbbreuer chrisbbreuer force-pushed the buddy-bot/update-non-major-updates branch 7 times, most recently from 10912e8 to 8cacb78 Compare May 12, 2026 00:34
@chrisbbreuer chrisbbreuer force-pushed the buddy-bot/update-non-major-updates branch 3 times, most recently from 2066d8d to 0728c6b Compare May 19, 2026 13:06
@chrisbbreuer chrisbbreuer force-pushed the buddy-bot/update-non-major-updates branch from 0728c6b to 2ea2fdb Compare May 24, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant