Skip to content

chore(deps): bump the all-dependencies group with 3 updates - #58

Merged
shgysk8zer0 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/all-dependencies-637eeb26f3
Sep 9, 2026
Merged

shgysk8zer0 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/all-dependencies-637eeb26f3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 3 updates: qr, @shgysk8zer0/importmap and eslint.

Updates qr from 0.6.0 to 0.7.0

Release notes

Sourced from qr's releases.

0.7.0

  • Decoder: new architecture, focusing on camera latency. 2x more accurate than previous version on BoofCV
  • Decoder: with new effort / timeLimit knobs and a multi-format _QRScanner
  • Encoder: speed-up 4-45x faster, reduce size by 30%
  • Encoder: add data-url output
  • Hardened for security, improved error messages and type checks

Full Changelog: paulmillr/qr@0.6.0...0.7.0

Changelog

Sourced from qr's changelog.

0.7.0 (2026-08-31)

  • Decoder: new architecture, focusing on camera latency. 2x more accurate than previous version on BoofCV
  • Decoder: with new effort / timeLimit knobs and a multi-format _QRScanner
  • Encoder: speed-up 4-45x faster, reduce size by 30%
  • Encoder: add data-url output
  • Hardened for security, improved error messages and type checks
Commits

Updates @shgysk8zer0/importmap from 1.10.3 to 1.10.4

Release notes

Sourced from @​shgysk8zer0/importmap's releases.

Release v1.10.4

See Changelog

Changelog

Sourced from @​shgysk8zer0/importmap's changelog.

[v1.10.4] - 2026-09-01

Changed

  • Update @aegisjsproject/router and various others

[Unreleased]

Commits
  • 82db11b Merge pull request #397 from shgysk8zer0/patch/update
  • 2513621 Update @aegisjsproject/router and various others
  • 218de3d Merge pull request #396 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • 1e3a55b Bump eslint from 10.8.1 to 10.9.0 in the all-dependencies group
  • b6dd179 Merge pull request #395 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • b56ca75 Bump eslint from 10.8.0 to 10.8.1 in the all-dependencies group
  • 62330ba Merge pull request #394 from shgysk8zer0/dependabot/npm_and_yarn/js-yaml-4.3.1
  • a211dcc Bump js-yaml from 4.2.0 to 4.3.1
  • 2eb055b Merge pull request #393 from shgysk8zer0/dependabot/npm_and_yarn/all-dependen...
  • 4af4b96 Bump eslint from 10.7.0 to 10.8.0 in the all-dependencies group
  • Additional commits viewable in compare view

Updates eslint from 10.9.1 to 10.10.0

Release notes

Sourced from eslint's releases.

v10.10.0

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#21286) (한국)
  • 8724829 docs: update compat table links (#21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)

Chores

  • b3d876b chore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)
  • 1696682 ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))
  • 2c7f5d6 chore: update github/codeql-action action to v4.37.9 (#21296) (renovate[bot])
  • 3c753f1 chore: update eslint (#21289) (renovate[bot])
  • 1c73469 chore: update ecosystem plugins (#21280) (ESLint Bot)
  • 08a02be test: add error locations to no-extra-boolean-cast (#21266) (lumir)
  • 77bb1db chore: update github/codeql-action action to v4.37.8 (#21270) (renovate[bot])
  • 007e81a ci: skip EMFILE test on Node.js 26 (#21265) (lumir)
  • 0430280 chore: improve ecosystem tests compatibility on Windows (#21178) (crimsonjay0)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-dependencies group with 3 updates: [qr](https://github.com/paulmillr/qr), [@shgysk8zer0/importmap](https://github.com/shgysk8zer0/importmap) and [eslint](https://github.com/eslint/eslint).


Updates `qr` from 0.6.0 to 0.7.0
- [Release notes](https://github.com/paulmillr/qr/releases)
- [Changelog](https://github.com/paulmillr/qr/blob/main/CHANGELOG.md)
- [Commits](paulmillr/qr@0.6.0...0.7.0)

Updates `@shgysk8zer0/importmap` from 1.10.3 to 1.10.4
- [Release notes](https://github.com/shgysk8zer0/importmap/releases)
- [Changelog](https://github.com/shgysk8zer0/importmap/blob/master/CHANGELOG.md)
- [Commits](shgysk8zer0/importmap@v1.10.3...v1.10.4)

Updates `eslint` from 10.9.1 to 10.10.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.10.0)

---
updated-dependencies:
- dependency-name: qr
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: "@shgysk8zer0/importmap"
  dependency-version: 1.10.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: eslint
  dependency-version: 10.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​shgysk8zer0/​importmap@​1.10.3 ⏵ 1.10.477 +110010094 -1100
Updatedqr@​0.6.0 ⏵ 0.7.0100100100 +189 +6100
Updatedeslint@​10.9.1 ⏵ 10.10.097 +110010097100

View full report

@shgysk8zer0
shgysk8zer0 merged commit 2c70917 into master Sep 9, 2026
6 checks passed
@shgysk8zer0
shgysk8zer0 deleted the dependabot/npm_and_yarn/all-dependencies-637eeb26f3 branch September 9, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant