Skip to content

chore(deps): Bump the minor-and-patch group with 3 updates - #30

Merged
j9t merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-47910b4364
Aug 1, 2026
Merged

j9t merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-47910b4364

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 3 updates: html-minifier-next, html-validate and eslint.

Updates html-minifier-next from 7.2.0 to 7.5.0

Changelog

Sourced from html-minifier-next's changelog.

[7.5.0] - 2026-07-19

Fixed

  • Fixed a regular expression denial-of-service (ReDoS) in the parser: A long unterminated end tag (e.g., </aaaa… with no closing >) could have caused quadratic (O(n²)) backtracking in the end-tag pattern on the default minify() path; the parser now skips that pattern when no > lies ahead, restoring linear-time parsing

Changed

  • Improved performance by moving special-case handling off the minifier’s hot paths:
    • Processed options are now memoized per options object, sparing batch runs the repeated regex parsing, closure creation, and option-signature stringification on every minify() call; pathological options objects (e.g., cyclic ones) safely skip memoization, with a one-time warning
    • The minifyURLs cache now persists across minify() calls (per site configuration), matching the process-lifetime behavior of the CSS/JS/SVG caches
    • The parser lowercases each tag name once instead of once per element-set lookup, and the whitespace/comment handlers no longer allocate closures per text node
    • SVG/MathML foreign-content handling is skipped entirely for documents without <svg>/<math> elements
    • mergeScripts merges consecutive scripts in a single pass instead of rescanning the document after every merge, and maxLineLength output assembly is no longer quadratic in the number of segments
  • Updated security-relevant warning about unlimited quantifiers in ignoreCustomFragments to reach console once per process, even without a log hook, and only firing for explicitly passed fragments

[7.4.0] - 2026-07-18

Added

  • Added automatic config file discovery: If an html-minifier-next.config.json file (or, for compatibility, htmlminifier.config.json) is present in the working directory, it’s loaded without needing --config-file—an explicit --config-file still takes precedence, a note on STDERR reports which file was picked up, and the standalone --zero mode remains config-free

Changed

  • Raised the declared Node.js minimum from ≥22 to ≥22.13, reflecting the effective floor of current dependencies

[7.3.0] - 2026-07-17

Added

  • Added cache hit/miss statistics for the CSS, JavaScript, and SVG minification caches: the getCacheStats() function exposes per-cache gets, hits, size, and limit; the CLI’s --verbose and --dry modes print a one-line-per-cache summary to STDERR at the end of a run, omitting caches that were never touched (e.g., when the corresponding minifier is disabled)
  • Added a fixed 1 MB entry size cap to the caches—oversized blocks are still minified normally but are no longer stored, bounding worst-case cache memory without affecting realistically sized inline content
Commits

Updates html-validate from 11.5.5 to 11.5.6

Release notes

Sourced from html-validate's releases.

v11.5.6

11.5.6 (2026-07-12)

Bug Fixes

  • deps: update dependency ignore to v7.0.6 (c91bdb5)
  • rules: allow ul and ol elements to have naming attributes (a9a6267)
Changelog

Sourced from html-validate's changelog.

11.5.6 (2026-07-12)

Bug Fixes

  • deps: update dependency ignore to v7.0.6 (c91bdb5)
  • rules: allow ul and ol elements to have naming attributes (a9a6267)
Commits
  • 385f2fd chore(release): 11.5.6
  • 38d317d chore(deps): update dependency @​html-validate/eslint-config to v9.11.6
  • 73810eb chore(deps): update dependency @​html-validate/eslint-config-vitest to v9.11.5
  • 6a3893b chore(deps): update dependency npm-pkg-lint to v5.1.11
  • 4ad6eb1 chore(deps): update dependency @​html-validate/eslint-config to v9.11.4
  • b89e5ac Merge branch 'fix-aria-label-lists' into 'master'
  • a9a6267 fix(rules): allow ul and ol elements to have naming attributes
  • c91bdb5 fix(deps): update dependency ignore to v7.0.6
  • 29e1f5d chore(deps): update dependency @​html-validate/prettier-config to v4.1.6
  • b017484 chore(deps): update dependency prettier to v3.9.5
  • Additional commits viewable in compare view

Updates eslint from 10.6.0 to 10.8.0

Release notes

Sourced from eslint's releases.

v10.8.0

Features

  • 2fee9bb feat: export ConfigObject from eslint/config (#21082) (sethamus)

Bug Fixes

  • 6b8d2f7 fix: escape reserved characters in rule id in html formatter (#21129) (Francesco Trotta)
  • 9091071 fix: prevent no-unreachable-loop crash when all loop types are ignored (#21116) (Pixel)
  • e23fafe fix: prefer-object-spread add semicolon when adding parenthesis (#21081) (synthex-byte)
  • 20b5ad0 fix: quadratic-time regex in prefer-template (#21096) (Milos Djermanovic)
  • 8b6f6c0 fix: apply ignore configs to computed methods in class-methods-use-this (#21094) (Pixel)
  • b2c608c fix: NewExpression with parenthesized callee in preserve-caught-error (#21083) (Francesco Trotta)

Documentation

  • 6ddf858 docs: fix broken Specify Parser Options anchor link (#21106) (Minsu)
  • 784dfbe docs: Clarify no-eq-null description (#21120) (Park Harin)
  • 7ec733a docs: Fix typos and grammar in glossary (#21095) (Marry (Subin Yang))
  • 92bb13f docs: replace quake link (#21108) (Jung Hyeon Jun)
  • 68eb4a5 docs: fix broken Specify Globals anchor links in rule pages (#21103) (Minsu)
  • d28f697 docs: replace Code Climate CLI links with Qlty CLI links (#21099) (Jung Hyeon Jun)
  • eccc68d docs: correct --suppressions-location option description (#21093) (Ga eun Lee)
  • c5963f7 docs: Update README (GitHub Actions Bot)

Chores

  • 4fbf46d test: pin webpack version to 5.108.4 (#21137) (Francesco Trotta)
  • 2d063e2 chore: update HTTP URLs to HTTPS in JSDoc and comments (#21101) (Bo Hyun Kim)
  • eccbe7b test: add error locations to no-class-assign (#21123) (devoil)
  • e7d1e43 ci: bump actions/setup-go from 6 to 7 (#21118) (dependabot[bot])
  • e9d66d0 ci: bump actions/setup-node from 6 to 7 (#21119) (dependabot[bot])
  • ee225b6 test: Add error location details to no-eq-null rule (#21117) (Park Harin)
  • 044a627 chore: update minimatch to ^10.2.5 (#21107) (김채영)
  • fb09aa8 chore: update ecosystem plugins (#21115) (ESLint Bot)
  • 5abd878 test: add error locations to no-proto (#21114) (Gihyeon Jeong / 정기현)
  • 9715887 test: Add error location details to no-div-regex (#21110) (Park Harin)
  • a746ec6 test: add error locations to no-new-wrappers (#21109) (Gihyeon Jeong / 정기현)
  • 8dde645 test: add error locations to no-ex-assign (#21102) (devoil)
  • 13ab0ec test: add error locations to no-label-var (#21098) (Gihyeon Jeong / 정기현)
  • a99906f test: Add error location details to no-delete-var rule (#21105) (Park Harin)
  • c47e8dc chore: add missing backticks to languages/js/index.js (#21104) (beeen)
  • 0174428 chore: add missing backticks to translate-cli-options.js (#21097) (dongkyu lee)
  • 3d36589 chore: add missing backticks to serialization.js (#21091) (이규환)
  • dcc9312 test: add error locations to eqeqeq (#21090) (Ga eun Lee)
  • 2710b18 ci: Add explicit permissions to rebuild-docs-sites workflow (#21089) (Marry (Subin Yang))
  • 5d2f866 chore: update dependency prettier to v3.9.5 (#21086) (renovate[bot])
  • d584e31 chore: fix failing ecosystem test for eslint-plugin-unicorn (#21084) (Francesco Trotta)
  • bf3eda0 chore: update ecosystem plugins (#21079) (ESLint Bot)

v10.7.0

Features

  • cf2a9bf feat: add errorClassNames option to preserve-caught-error rule (#21032) (sethamus)
  • f8b873a feat: max-nested-callbacks option for constructor callbacks (#21063) (fnx)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 3 updates: [html-minifier-next](https://github.com/j9t/html-minifier-next), [html-validate](https://gitlab.com/html-validate/html-validate) and [eslint](https://github.com/eslint/eslint).


Updates `html-minifier-next` from 7.2.0 to 7.5.0
- [Changelog](https://github.com/j9t/html-minifier-next/blob/main/CHANGELOG.md)
- [Commits](https://github.com/j9t/html-minifier-next/commits)

Updates `html-validate` from 11.5.5 to 11.5.6
- [Release notes](https://gitlab.com/html-validate/html-validate/tags)
- [Changelog](https://gitlab.com/html-validate/html-validate/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/html-validate/html-validate/compare/v11.5.5...v11.5.6)

Updates `eslint` from 10.6.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.6.0...v10.8.0)

---
updated-dependencies:
- dependency-name: html-minifier-next
  dependency-version: 7.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: html-validate
  dependency-version: 11.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 1, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedeslint@​10.6.0 ⏵ 10.8.09710010095 -1100
Updatedhtml-validate@​11.5.5 ⏵ 11.5.6100 +110010096100
Updatedhtml-minifier-next@​7.2.0 ⏵ 7.5.09610010096 +1100

View full report

@j9t
j9t merged commit 8c7d38b into main Aug 1, 2026
7 checks passed
@j9t
j9t deleted the dependabot/npm_and_yarn/minor-and-patch-47910b4364 branch August 1, 2026 07:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant