Skip to content

chore(deps): bump the windows-frontend group across 1 directory with 20 updates - #1403

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/windows/app/windows-frontend-3ec4ab553c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/windows/app/windows-frontend-3ec4ab553c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the windows-frontend group with 20 updates in the /apps/windows/app directory:

Package From To
@tauri-apps/plugin-clipboard-manager 2.3.3 2.4.1
@tauri-apps/plugin-dialog 2.7.3 2.8.1
@tauri-apps/plugin-fs 2.5.2 2.6.0
@tauri-apps/plugin-http 2.6.1 2.8.0
@tauri-apps/plugin-shell 2.3.6 2.4.0
@tauri-apps/plugin-updater 2.11.0 2.13.1
react-hook-form 7.88.0 7.89.0
@biomejs/biome 2.5.14 2.5.15
@eslint-react/eslint-plugin 5.20.8 5.23.5
@tauri-apps/cli 2.11.5 2.12.1
@types/node 26.6.2 26.6.4
eslint 10.11.0 10.12.0
eslint-plugin-sukka 10.2.0 10.4.0
globals 17.12.0 17.13.0
knip 6.38.0 6.39.0
lint-staged 17.5.1 17.6.0
sass 1.105.0 1.105.1
typescript-eslint 8.70.1 8.71.0
vite 8.3.1 8.3.2
vitest 5.0.1 5.0.3

Updates @tauri-apps/plugin-clipboard-manager from 2.3.3 to 2.4.1

Release notes

Sourced from @​tauri-apps/plugin-clipboard-manager's releases.

biometric-js v2.4.1

[2.4.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-biometric@2.4.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.1kB README.md
npm notice 2.2kB dist-js/index.cjs
npm notice 3.4kB dist-js/index.d.ts
npm notice 2.1kB dist-js/index.js
npm notice 685B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-biometric
npm notice version: 2.4.1
npm notice filename: tauri-apps-plugin-biometric-2.4.1.tgz
npm notice package size: 3.6 kB
npm notice unpacked size: 12.4 kB
npm notice shasum: 08fb2149f8812d8f264bedf5119d656cea23a580
npm notice integrity: sha512-dH/IPC+NTiB28[...]qdY33uaVNIxvw==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3028114630
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-biometric@2.4.1

biometric v2.4.1

[2.4.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.

... (truncated)

Commits
  • d66aa6f publish new versions (#2822)
  • 6f34587 fix(single-instance): disable dbus name replacement (#2860)
  • 708fa4e chore(deps): update dependency eslint-config-prettier to v10.1.8 (#2858)
  • b729203 fix(upload): fix download() locks main thread on Android (#2838)
  • 2f9c71a chore(deps): update dependency rollup to v4.45.1 (#2850)
  • 80d4d8e chore(deps): update eslint monorepo to v9.31.0 (v2) (#2839)
  • e7a98b0 chore(deps): update dependency typescript-eslint to v8.37.0 (#2848)
  • 44a1f65 fix(fs): writeFile create file by default (#2846)
  • 6210cd3 chore(deps): update dependency rollup to v4.45.0 (#2841)
  • 467f07b chore(deps): update dependency vite to v7 (v2) (#2800)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-dialog from 2.7.3 to 2.8.1

Release notes

Sourced from @​tauri-apps/plugin-dialog's releases.

dialog-js v2.8.1

[2.8.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-dialog@2.8.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.5kB README.md
npm notice 7.1kB dist-js/index.cjs
npm notice 15.1kB dist-js/index.d.ts
npm notice 7.0kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 657B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-dialog
npm notice version: 2.8.1
npm notice filename: tauri-apps-plugin-dialog-2.8.1.tgz
npm notice package size: 6.8 kB
npm notice unpacked size: 34.3 kB
npm notice shasum: f29f3c28862a1ed767b6fd241f34abf26129f88f
npm notice integrity: sha512-/DtE3B62JgpYu[...]phsKnb+738Dmw==
npm notice total files: 7
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3028120915
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-dialog@2.8.1

dialog v2.8.1

[2.8.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.

... (truncated)

Commits
  • d4835d0 publish new versions (#3660)
  • 569ee82 fix: mobile docs.rs builds
  • 25f3874 chore(deps): update dependency eslint-plugin-security to v4.1.0 (#3661)
  • 2fd4bed chore(autostart): update auto-launch to 0.6 (#3546)
  • e511284 publish new versions (#3647)
  • ce59e96 docs(log): remove unrelated single-instance comment from log readme
  • 29130c2 ci: run clippy on all platforms (#3650)
  • 4353819 chore: add changefile to re-release plugin-http npm package as 2.8.0 (#3656)
  • ec14142 chore(deps): update dependency @​types/node to v24 (#3649)
  • 90b9869 chore(deps): update rust crate dirs to v7 (#3573)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-fs from 2.5.2 to 2.6.0

Release notes

Sourced from @​tauri-apps/plugin-fs's releases.

deep-link-js v2.6.0

[2.6.0]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-deep-link@2.6.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 6.2kB README.md
npm notice 4.7kB dist-js/index.cjs
npm notice 4.0kB dist-js/index.d.ts
npm notice 4.5kB dist-js/index.js
npm notice 801B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-deep-link
npm notice version: 2.6.0
npm notice filename: tauri-apps-plugin-deep-link-2.6.0.tgz
npm notice package size: 4.8 kB
npm notice unpacked size: 21.1 kB
npm notice shasum: 42f4e74e87aea6ace90871ad293f4fface5910cc
npm notice integrity: sha512-41rOuYUZjxcEz[...]TsoJQ2R9U5MCA==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005261605
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-deep-link@2.6.0

deep-link v2.6.0

[2.6.0]

... (truncated)

Commits

Updates @tauri-apps/plugin-http from 2.6.1 to 2.8.0

Release notes

Sourced from @​tauri-apps/plugin-http's releases.

http-js v2.8.0

[2.8.0]

npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-http@2.8.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 2.6kB README.md
npm notice 7.7kB dist-js/index.cjs
npm notice 3.4kB dist-js/index.d.ts
npm notice 7.7kB dist-js/index.js
npm notice 655B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-http
npm notice version: 2.8.0
npm notice filename: tauri-apps-plugin-http-2.8.0.tgz
npm notice package size: 5.5 kB
npm notice unpacked size: 23.0 kB
npm notice shasum: 1cf059a5c97cadea0e5f6a07c22931a118c60ffc
npm notice integrity: sha512-cPvZvfUSaBkqG[...]jyXRPNo6Cky6g==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005263804
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-http@2.8.0

opener-js v2.7.0

[2.7.0]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61

... (truncated)

Commits
  • 6e2e7e4 publish new versions (#3070)
  • 9a2c98f temp: remove updater changefiles
  • 4a2ecb6 chore(deps): update rkyv, closes #3196
  • 31415ef docs(shell): update example to include Encoding usage in Command::spawn (#3...
  • 04b33ea chore(deps): update dependency typescript-eslint to v8.50.1 (#3181)
  • 54e21f1 chore(deps): update dependency rollup to v4.54.0 (#3179)
  • d528c88 chore(deps): update dependency rollup to v4.53.5 (#3172)
  • 69146fa chore(deps): update dependency rollup to v4.53.4 (#3167)
  • 9f68f2d chore(deps): update dependency typescript-eslint to v8.50.0 (#3170)
  • 3d0d2e0 fix(opener): ignore inAppBrowser on desktop (#3163)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-shell from 2.3.6 to 2.4.0

Release notes

Sourced from @​tauri-apps/plugin-shell's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits

Updates @tauri-apps/plugin-updater from 2.11.0 to 2.13.1

Release notes

Sourced from @​tauri-apps/plugin-updater's releases.

updater-js v2.13.1

[2.13.1]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
  • 90b9869e (#3573 by @​renovate) Updated dirs to v7

  • 22e286f3 (#3501 by @​renovate) Updated dependency infer to 0.22

npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-updater@2.13.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.2kB README.md
npm notice 6.7kB dist-js/index.cjs
npm notice 7.1kB dist-js/index.d.ts
npm notice 6.6kB dist-js/index.js
npm notice 659B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-updater
npm notice version: 2.13.1
npm notice filename: tauri-apps-plugin-updater-2.13.1.tgz
npm notice package size: 4.8 kB
npm notice unpacked size: 25.1 kB
npm notice shasum: 2ad227ba05293fe34c5c59c0ff8a1cd690c8e9a8
npm notice integrity: sha512-+STDzJ0sdQLIm[...]/AJz0jxysytiw==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005269671
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-updater@2.13.1

updater v2.13.1

... (truncated)

Commits
  • e511284 publish new versions (#3647)
  • ce59e96 docs(log): remove unrelated single-instance comment from log readme
  • 29130c2 ci: run clippy on all platforms (#3650)
  • 4353819 chore: add changefile to re-release plugin-http npm package as 2.8.0 (#3656)
  • ec14142 chore(deps): update dependency @​types/node to v24 (#3649)
  • 90b9869 chore(deps): update rust crate dirs to v7 (#3573)
  • 22e286f chore(deps): update rust crate infer to 0.22 (#3501)
  • ecd3273 chore(deps): update windows-rs and webview2 crates (#3480)
  • aa2cc64 fix(android): Migrate Gradle scripts to compilerOptions DSL (#3478)
  • a2364a5 fix: integration test
  • Additional commits viewable in compare view

Updates react-hook-form from 7.88.0 to 7.89.0

Release notes

Sourced from react-hook-form's releases.

Version 7.89.0

🐞 Fixes

  • Fix form state select option (#13784)
  • Remove duplicate default value field (#13783)
  • Fix validateField skipping refs without setCustomValidity under native validation (#13782)
  • Fix form-level validation using a stale validate function (#13777)
  • Fix useFieldArray touched fields handling (#13776)
  • Fix pending delayError timers for nested paths (#13775)
  • Fix getValues extracting unmarked field array entries (#13773)
  • Fix field array touched state not being re-indexed when unsubscribed (#13772)
  • Fix nested delayError timers remaining when a parent validates clean (#13771)
  • Fix nested delayError timers remaining after resetField() resets a parent (#13769)
  • Fix stale field array root errors after an operation satisfies the validation rule (#13767)
  • Fix setValue() not revalidating dependencies when shouldValidate is enabled (#13765)
  • Fix stale built-in validation results after reset() during handleSubmit() (#13761)
  • Fix stale form-level validation results after reset() (#13762)
  • Fix validation rules removed from register options at runtime remaining active (#13758)
  • Fix useController required validation not using the controlled value (#13756)
  • Fix stale form-level errors remaining after successful re-validation (#13755)
  • Fix useFieldArray marking the form dirty when the array default value is null (#13750)
  • Fix isValid not being recomputed when the errors prop is emptied (#13748)
  • Fix form-level validation running more than once per traversal (#13747)
  • Fix stale built-in validation results after reset() during onChange (#13745)
  • Fix stale resolver results after reset() during onChange (#13744)
  • Fix setValue() not triggering field array root validation when shouldValidate is enabled (#13743)
  • Fix getFieldState(name, formState) updates after reset() (#13741)
  • Fix dirty state remaining for rows removed from a field array (#13739)

🧹 Refactors

  • Replace rimraf cleanup with fs.rmSync (#13770)
  • Reduce bundle size (#13759)

📦 Dependencies

  • Add optional @types/react peer dependency (#13781)

❤️ Thank You

Changelog

Sourced from react-hook-form's changelog.

[7.89.0] - 2026-09-26

Changed

  • Add optional @types/react peer dependency

Fixed

  • validateField calling setCustomValidity on refs that don't implement it under native validation
  • Form-level validate running a stale function instead of the latest one
  • Form-level validation leaving stale errors after a successful re-validation
  • Form-level validation running more than once per traversal
  • Stale validation results (resolver, built-in, form-level validate) being applied after reset in onChange and handleSubmit
  • Pending delayError timers for nested paths not being cancelled when a parent validates clean or is reset via resetField
  • getValues(names, { dirtyFields }) returning every row of a field array instead of only the marked entries
  • Field array touched state not being re-indexed when touchedFields is not subscribed
  • useFieldArray emitting touchedFields in form state updates when unnecessary
  • Stale field array root error not clearing once an array operation satisfies the rule
  • useFieldArray marking the form dirty when the array default is null
  • Dirty state lingering for rows removed from a field array
  • setValue with shouldValidate not revalidating deps
  • setValue with shouldValidate not triggering validation for a field array root
  • Validation rules removed from register options at runtime still being applied
  • useController validating required against the input value instead of the controlled value
  • isValid not recomputing when the errors prop is emptied
  • getFieldState(name, formState) with a resolver after reset()
Commits
  • 4722d22 7.89.0
  • 72a4c98 👟 chore: correct form state select option (#13784)
  • 14c7bec 🕵🏻‍♂️ chore: remove duplicate default value field (#13783)
  • d9cab62 🤖 chore: add optional @​types/react peer dependency (#13781)
  • c12546c 🐞 fix(validateField): skip refs without setCustomValidity under native valida...
  • 5fd9ef6 🐞 fix(validate): run the latest form level validate function (#13777)
  • 7893230 🐞 fix(useFieldArray): improve touched fields handling and add tests (#13776)
  • ad8abf6 🐴 cancel pending delayError timers for nested paths (#13775)
  • eb159da 🐞 fix(getValues): extract only the marked entries of a field array (#13773)
  • 4647014 🐞 fix: re-index field array touched state when it is not subscribed (#13772)
  • Additional commits viewable in compare view

Updates @biomejs/biome from 2.5.14 to 2.5.15

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.15

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #11723 3b429d1 Thanks @​m1handr! - Fixed #11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

... (truncated)

Commits

Updates @eslint-react/eslint-plugin from 5.20.8 to 5.23.5

Release notes

Sourced from @​eslint-react/eslint-plugin's releases.

v5.23.5 (2026-10-03)

What's Changed

🐞 Fixes

  • react-x/set-state-in-effect: the ref-derived value exemption now also covers setState calls reached indirectly through functions or hook callbacks invoked from the effect setup, not only setState written directly in the setup body. (#1982)
  • react-x/set-state-in-effect: more ref read shapes are recognized as ref-derived values — <ref-named>.current anywhere in a member chain, locals derived from other ref-derived locals, and reads through a ref/xxxRef parameter. (#1982)
  • react-web-api/no-leaked-event-listener: removeEventListener inside a function called from the effect cleanup now pairs with its addEventListener, fixing false positives for listeners removed on unmount; cleanup calls resolve to the actual functions, so same-named shadowed functions no longer pair by coincidence. (#1982)

🏗️ Internal

  • Bumped effect to 4.0.0 and migrated the repo scripts to the v4 APIs. (#1981)

Full Changelog: Rel1cx/eslint-react@v5.23.4...v5.23.5

Attestation

https://github.com/Rel1cx/eslint-react/attestations/52275386

v5.23.4 (2026-10-03)

What's Changed

🐞 Fixes

  • Added the missing react-x/static-components rule to the disable-experimental preset. (#1980)
  • Fixed type imports in react-x/exhaustive-deps and react-x/rules-of-hooks (RuleFeature is now imported from @eslint-react/eslint instead of @eslint-react/shared).

📝 Documentation

  • react-jsx/no-useless-fragment: clarified the scope of the allowExpressions option and unified experimental-rule callout wording across rule docs.
  • react-x: unified cross-rule references in rule docs to full rule names.
  • Removed low-relevance entries from the further reading sections of rule docs, and removed a redundant note about eslint being an optional peer dependency.
  • Fixed inaccuracies in internal documentation. (#1980)

🏗️ Internal

  • Adopted ts-pattern for type checks in @eslint-react/core, @eslint-react/jsx, and the react-dom plugin, and declared the missing ts-pattern dependencies.
  • Added behavior boundary tests for react-jsx/no-useless-fragment.
  • Bumped fumadocs-core, fumadocs-ui, and lucide-react in the website.

Full Changelog: Rel1cx/eslint-react@v5.23.3...v5.23.4

Attestation

https://github.com/Rel1cx/eslint-react/attestations/52237942

... (truncated)

Changelog

Sourced from @​eslint-react/eslint-plugin's changelog.

v5.23.5 (2026-10-03)

🐞 Fixes

  • react-x/set-state-in-effect: the ref-derived value exemption now also covers setState calls reached indirectly through functions or hook callbacks invoked from the effect setup, not only setState written directly in the setup body. (Description has been truncated

@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: windows. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 6, 2026
…20 updates

Bumps the windows-frontend group with 20 updates in the /apps/windows/app directory:

| Package | From | To |
| --- | --- | --- |
| [@tauri-apps/plugin-clipboard-manager](https://github.com/tauri-apps/plugins-workspace) | `2.3.3` | `2.4.1` |
| [@tauri-apps/plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.7.3` | `2.8.1` |
| [@tauri-apps/plugin-fs](https://github.com/tauri-apps/plugins-workspace) | `2.5.2` | `2.6.0` |
| [@tauri-apps/plugin-http](https://github.com/tauri-apps/plugins-workspace) | `2.6.1` | `2.8.0` |
| [@tauri-apps/plugin-shell](https://github.com/tauri-apps/plugins-workspace) | `2.3.6` | `2.4.0` |
| [@tauri-apps/plugin-updater](https://github.com/tauri-apps/plugins-workspace) | `2.11.0` | `2.13.1` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.88.0` | `7.89.0` |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.14` | `2.5.15` |
| [@eslint-react/eslint-plugin](https://github.com/Rel1cx/eslint-react/tree/HEAD/plugins/eslint-plugin) | `5.20.8` | `5.23.5` |
| [@tauri-apps/cli](https://github.com/tauri-apps/tauri) | `2.11.5` | `2.12.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.2` | `26.6.4` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [eslint-plugin-sukka](https://github.com/SukkaW/eslint-plugin-sukka) | `10.2.0` | `10.4.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.38.0` | `6.39.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `17.5.1` | `17.6.0` |
| [sass](https://github.com/sass/dart-sass) | `1.105.0` | `1.105.1` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.1` | `8.71.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.3` |



Updates `@tauri-apps/plugin-clipboard-manager` from 2.3.3 to 2.4.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@nfc-v2.3.3...fs-v2.4.1)

Updates `@tauri-apps/plugin-dialog` from 2.7.3 to 2.8.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@dialog-v2.7.3...dialog-v2.8.1)

Updates `@tauri-apps/plugin-fs` from 2.5.2 to 2.6.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.5.2...fs-v2.6.0)

Updates `@tauri-apps/plugin-http` from 2.6.1 to 2.8.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@http-v2.6.1...log-v2.8.0)

Updates `@tauri-apps/plugin-shell` from 2.3.6 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@nfc-v2.3.6...os-v2.4.0)

Updates `@tauri-apps/plugin-updater` from 2.11.0 to 2.13.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@updater-v2.11.0...updater-v2.13.1)

Updates `react-hook-form` from 7.88.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.88.0...v7.89.0)

Updates `@biomejs/biome` from 2.5.14 to 2.5.15
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.15/packages/@biomejs/biome)

Updates `@eslint-react/eslint-plugin` from 5.20.8 to 5.23.5
- [Release notes](https://github.com/Rel1cx/eslint-react/releases)
- [Changelog](https://github.com/Rel1cx/eslint-react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Rel1cx/eslint-react/commits/v5.23.5/plugins/eslint-plugin)

Updates `@tauri-apps/cli` from 2.11.5 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.11.5...@tauri-apps/cli-v2.12.1)

Updates `@types/node` from 26.6.2 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `eslint-plugin-sukka` from 10.2.0 to 10.4.0
- [Commits](SukkaW/eslint-plugin-sukka@10.2.0...10.4.0)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

Updates `knip` from 6.38.0 to 6.39.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.39.0/packages/knip)

Updates `lint-staged` from 17.5.1 to 17.6.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.5.1...v17.6.0)

Updates `sass` from 1.105.0 to 1.105.1
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](sass/dart-sass@1.105.0...1.105.1)

Updates `typescript-eslint` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

Updates `vite` from 8.3.1 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: windows-frontend
- dependency-name: "@eslint-react/eslint-plugin"
  dependency-version: 5.23.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/cli"
  dependency-version: 2.12.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/plugin-clipboard-manager"
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/plugin-dialog"
  dependency-version: 2.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/plugin-fs"
  dependency-version: 2.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/plugin-http"
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/plugin-shell"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@tauri-apps/plugin-updater"
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: windows-frontend
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: eslint-plugin-sukka
  dependency-version: 10.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: knip
  dependency-version: 6.39.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: lint-staged
  dependency-version: 17.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: sass
  dependency-version: 1.105.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: windows-frontend
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: windows-frontend
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: windows-frontend
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: windows-frontend
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): Bump the windows-frontend group across 1 directory with 20 updates chore(deps): bump the windows-frontend group across 1 directory with 20 updates Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/apps/windows/app/windows-frontend-3ec4ab553c branch from 64dc21d to 64efde8 Compare October 6, 2026 19:20
@raydocs

raydocs commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Superseded by #1421 (main aaa0c1d), which carries these updates with a regenerated lockfile. Held: typescript stays on 6.0.3 because typescript-eslint 8.71.1 declares peer typescript <6.1.0 and throws on TS 7. Record: docs/changelog.d/2026-10-06-deps-windows.md.

@raydocs raydocs closed this Oct 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/apps/windows/app/windows-frontend-3ec4ab553c branch October 6, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant