Skip to content

fix(deps): update external fixes - #946

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate-external-fixes
Sep 2, 2026
Merged

fix(deps): update external fixes#946
renovate[bot] merged 1 commit into
mainfrom
renovate-external-fixes

Conversation

@renovate

@renovate renovate Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@aws-sdk/client-apigatewayv2 (source) 3.1101.03.1113.0 age confidence
@aws-sdk/client-iam (source) 3.1101.03.1113.0 age confidence
@aws-sdk/client-lambda (source) 3.1101.03.1113.0 age confidence
@aws-sdk/client-s3 (source) 3.1101.03.1113.0 age confidence
@aws-sdk/client-secrets-manager (source) 3.1101.03.1113.0 age confidence
@aws-sdk/client-ssm (source) 3.1101.03.1113.0 age confidence
@aws-sdk/client-sts (source) 3.1101.03.1113.0 age confidence
esbuild 0.28.10.28.2 age confidence
isomorphic-git (source) 1.40.01.41.5 age confidence

Release Notes

aws/aws-sdk-js-v3 (@​aws-sdk/client-apigatewayv2)

v3.1113.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1109.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1105.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1103.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-apigatewayv2

aws/aws-sdk-js-v3 (@​aws-sdk/client-iam)

v3.1113.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1109.0

Compare Source

Features
  • client-iam: Introduced role manager, an IAM capability that automatically sets up the IAM roles your AWS services need. When you set up a supported service in the console, role manager creates a role for you or reuses an existing one from an AWS-managed template. (1f81145)

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1105.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

v3.1103.0

Compare Source

Features
  • client-iam: Updating endpoint generation logic (4f3cb1d)

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-iam

aws/aws-sdk-js-v3 (@​aws-sdk/client-lambda)

v3.1113.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1109.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1105.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1103.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-lambda

aws/aws-sdk-js-v3 (@​aws-sdk/client-s3)

v3.1113.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1109.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1105.0

Compare Source

Features
  • client-s3: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore. (faf6560)

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1103.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

aws/aws-sdk-js-v3 (@​aws-sdk/client-secrets-manager)

v3.1113.0

Compare Source

3.1113.0(2026-08-18)
Chores
  • scripts: prune stale lib-dynamodb files on copy during codegen (#​8269) (0278e94b)
Documentation Changes
  • client-ec2: Doc release for CreateImage support for instances with local snapshots in Outpost (59ed88c0)
  • client-batch: Update AWS Batch documentation with newer Fargate Supported configurations, notes, and fix broken Docker link re-directs. (c2ba4d77)
New Features
  • client-entityresolution: Added ResourceNotFoundException to DeleteSchemaMapping, DeleteMatchingWorkflow, DeleteIdMappingWorkflow, and DeleteIdNamespace. These operations now return a 404 ResourceNotFoundException (previously a 200 Success) when the target resource does not exist. (860ccc20)
  • client-outposts: AWS Outposts now supports VPC Endpoint configuration in CreatePrivateConnectivityConfig, enabling scoped private connectivity with provisioning role creation for secure outpost installations (74c9d458)
  • client-workspaces: Amazon WorkSpaces now supports nested virtualization, allowing you to run hypervisors and virtualization-based workloads within your WorkSpaces. You can enable or disable nested virtualization when creating a WorkSpace or by modifying an existing WorkSpace's properties. (b15dc812)
  • client-marketplace-catalog: Introducing two new APIs, DescribeAssessment and ListAssessments. These APIs expose validation issues on Marketplace resources. The validation issues are exposed via a newly created resource called Assessment. (a2a6ab2f)
  • client-medialive: AWS Elemental MediaLive now supports SCTE-35 marker passthrough without IDR frame insertion for CMAF Ingest, MediaPackage V2, and transport stream outputs. (b93c2f34)
Bug Fixes
  • token-providers: update SSO refresh throttle per session (#​8268) (ac44fb04)

For list of updated packages, view updated-packages.md in assets-3.1113.0.zip

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1109.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1105.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1103.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-secrets-manager

aws/aws-sdk-js-v3 (@​aws-sdk/client-ssm)

v3.1113.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1109.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1105.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1103.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

aws/aws-sdk-js-v3 (@​aws-sdk/client-sts)

v3.1113.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1112.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1111.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1110.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1109.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1108.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1107.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1106.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1105.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1104.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1103.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

v3.1102.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-sts

evanw/esbuild (esbuild)

v0.28.2

Compare Source

  • Fix tree shaking bug due to TypeScript import alias (#​4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#​4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#​4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#​4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#​4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})
    }
    
    // Old output (with --minify-syntax --target=es6)
    function foo() {
      bar(void 0 || (x = {}));
    }
    
    // New output (with --minify-syntax --target=es6)
    function foo() {
      let x;
      bar(x || (x = {}));
    }
  • Fix a potential deadlock when the JavaScript API is used incorrectly (#​4503, #​4506)

    The JavaScript API runs the native esbuild executable as a long-lived child process and communicates with it over stdin/stdout/stderr. Each API request is asynchronous and the executable stays open as long as it has work to do, which is as long as either stdin is still open (meaning there may be more API requests) or there are currently requests being processed.

    Previously esbuild's tracking of outstanding API requests missed decrementing a reference count in an edge case where esbuild's JavaScript API was used incorrectly and the API request returned an error. This could in some cases cause esbuild's native executable to exit with an error message about a deadlock. This release fixes the reference counting bug.

    This fix was submitted by @​ZuBB.

  • Handle target collisions (#​4509)

    It's possible to specify the same target engine multiple times, such as with --target=chrome1,chrome99. This edge case wasn't anticipated and previously took the last version for the duplicated target engine instead of the minimum version (so chrome99 in this case instead of chrome1). With this release, esbuild will now pick the minimum version between all duplicated target engines.

  • Force .mp3 files to use the audio/mpeg MIME type (#​4485)

    MIME type detection for esbuild's data URLs uses Go's built-in MIME type detection, which is based on the MIME sniffing standard. This works correctly for MP3 files that start with the byte sequence ID3, which is commonly the case. However, it's possible to construct valid MP3 files that do not start with ID3, and that perhaps Go's built-in MIME type detection doesn't implement the "Signature for MP3 without ID3" part of the algorithm. This results in some .mp3 files incorrectly using the application/octet-stream MIME type instead of audio/mpeg. With this release, esbuild will now always use the audio/mpeg MIME type for files ending in .mp3.

  • Add a new TypeScript syntax warning

    TypeScript 7 turned some previously-valid TypeScript syntax into a syntax error because it was confusing. TypeScript 6 accepts 1 + 2 as number * 3 as valid syntax but confusingly converts it to (1 + 2) * 3 instead of the more intuitive conversion to 1 + (2 * 3). This syntax is now an error in TypeScript 7+. With this release, esbuild will now warn about the use of this syntax:

     [WARNING] Operator "*" should not directly follow a TypeScript type cast after the "+" operator [confusing-typescript-cast]
    
        example.ts:1:28:
          1  console.log(1 + 2 as number * 3)
                                         ^
    
      This is a syntax error in newer versions of TypeScript because the type cast has unintuitive
      precedence in this case. Surround the inner expression in parentheses to silence this warning:
    
        example.ts:1:12:
          1  console.log(1 + 2 as number * 3)
                         ~~~~~~~~~~~~~~~
                         (             )

    See microsoft/TypeScript#63527 for more information.

  • Add support for formatting errors for Visual Studio (#​4460)

    Visual Studio has a specific style that it expects log messages to be in for them to show up in the UI when esbuild is run as a custom build step. The current log style that esbuild uses doesn't conform to this specific style.

    With this release, esbuild has a new log style for Visual Studio (and other tools in the MSBuild ecosystem) that can be enabled with --log-style=visualstudio. Here is an example log message in this style:

    $ esbuild example.ts --log-style=visualstudio
    /Users/evan/dev/esbuild/example.ts(1,29): warning ES0010: Operator "*" should not directly follow a TypeScript type cast after the "+" operator
    

    This log style is also available via the JS and Go APIs, and can now be used with the existing formatMessages API.

  • Fix a bug with CSS gamut mapping (#​4488)

    Due to a typo, the fallback colors generated for CSS colors outside of the sRGB gamut weren't correct. This release fixes the generated colors to use the intended algorithm.

    This fix was submitted by @​chatman-media.

isomorphic-git/isomorphic-git (isomorphic-git)

v1.41.5

Compare Source

Bug Fixes

v1.41.4

Compare Source

Bug Fixes

v1.41.3

Compare Source

Bug Fixes
  • don't split a CRLF that straddles two chunks in splitLines (#​2397) (aa6812c)

v1.41.2

Compare Source

Bug Fixes

v1.41.1

Compare Source

Bug Fixes

v1.41.0

Compare Source

Features

v1.40.8

Compare Source

Bug Fixes

v1.40.7

Compare Source

Bug Fixes
  • recognize the scp-like syntax with a user other than git (#​2400) (332c66d)

v1.40.6

Compare Source

Bug Fixes

v1.40.5

Compare Source

Bug Fixes
  • don't crash on a peeled tag whose tag the prefix filtered out (#​2398) (7276b1c)

v1.40.4

Compare Source

Bug Fixes

v1.40.3

Compare Source

Bug Fixes

v1.40.2

Compare Source

Bug Fixes

v1.40.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (in timezone Europe/Zurich)

  • Branch creation
    • "after 2pm on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate-external-fixes branch from 729e05c to 82a785d Compare August 31, 2026 20:54
@github-actions

Copy link
Copy Markdown

This PR will trigger a patch release when merged.

@renovate
renovate Bot force-pushed the renovate-external-fixes branch 2 times, most recently from 813830f to 662aa99 Compare September 1, 2026 14:11
@renovate
renovate Bot force-pushed the renovate-external-fixes branch from 662aa99 to 5b504d5 Compare September 1, 2026 21:57
@renovate
renovate Bot merged commit fa9c6f8 into main Sep 2, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate-external-fixes branch September 2, 2026 04:47
@tripodsan

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 14.4.5 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant