Skip to content

deps(deps): bump the minor-and-patch group with 14 updates - #91

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-61dc3bcf1c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-61dc3bcf1c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 14 updates:

Package From To
@amplitude/analytics-browser 2.45.8 2.45.10
agentic-flow 2.1.2 2.1.3
react-router-dom 7.18.3 7.18.4
tailwind-merge 3.6.0 3.7.0
@testing-library/dom 10.4.1 10.4.2
@types/node 26.5.1 26.6.1
@vitest/coverage-v8 5.0.0 5.0.1
autoprefixer 10.5.6 10.6.1
jsdom 30.0.1 30.1.0
ruflo 3.41.2 3.42.4
sass-embedded 1.104.0 1.104.1
vitest 5.0.0 5.0.1
@rollup/rollup-linux-x64-gnu 4.63.1 4.63.3
tsx 4.22.1 4.23.13

Updates @amplitude/analytics-browser from 2.45.8 to 2.45.10

Release notes

Sourced from @​amplitude/analytics-browser's releases.

@​amplitude/analytics-browser@​2.45.10

2.45.10 (2026-09-16)

Bug Fixes

@​amplitude/analytics-browser@​2.45.9

2.45.9 (2026-09-16)

Bug Fixes

Commits
  • 38cb08c chore(release): publish
  • 4cfc431 fix: pin custom enrichment plugin (#1995)
  • 2e3b125 chore(release): publish
  • 6650407 chore: use Nx for publishing (#1993)
  • 62016c3 ci(release): stream lerna version output (#1991)
  • 0b4a09a feat(react-native): apply diagnostics sample rate from remote config (#1983)
  • 20fc2a7 fix(android): skip explicit Kotlin plugin when AGP registers the kotlin exten...
  • f37d648 chore: add manual stress test for shadow DOM (#1989)
  • 5c09973 fix(autocapture): expose zones when the mid-height line is viewed (#1972)
  • 942c8bc fix(browser): normalize empty instance names (#1956)
  • Additional commits viewable in compare view

Updates agentic-flow from 2.1.2 to 2.1.3

Release notes

Sourced from agentic-flow's releases.

v2.1.3 — Windows fix, cleaner local model routing, jujutsu compatibility

agentic-flow v2.1.3 — Windows fix, cleaner local model routing, jujutsu compatibility

What is agentic-flow?

agentic-flow lets you run Claude Code (or the Claude Agent SDK) against cheaper or fully local AI models instead of always paying for the most expensive one, and then take whatever agent you built and deploy it as a real hosted service. It bundles a router that picks the right model for the job, a memory system (AgentDB) so agents remember what they've learned, and a set of provider integrations (OpenRouter, Ollama, local ONNX models, and more) so you're not locked into one vendor.

What's in this release

This is a patch release — a cleanup pass that closed out a backlog of pull requests, fixed one real Windows crash, and shipped a handful of small, well-verified bug fixes. Nothing here changes how you use agentic-flow; everything is either invisible (a bug you'd only hit in specific conditions) or additive (new example code, a security policy document).

🪟 Fixed a Windows-only crash in local model loading

If you were running agentic-flow's local ONNX inference path on Windows, importing certain modules could crash immediately — even in code paths that never actually used ONNX at all — because the native binding was being loaded as a side effect of just importing the file, and that native binding can't load on some Windows setups. It's now loaded lazily, only when you actually try to run a local model. We verified this fix empirically (not just by reading the code): we reproduced the exact crash-on-import behavior, confirmed the fix removes it, and confirmed the model still loads correctly the moment it's actually needed.

🧵 Fixed a startup crash on newer Node.js

agentdb-cli.ts used a variable (__dirname) that isn't available in modern JavaScript modules, causing it to crash at startup in some environments. Fixed to use the standard modern equivalent.

🔧 jj (Jujutsu) version control support brought up to date

If you use agentic-flow's Jujutsu integration, branch operations (create/delete/list) now use the current jj bookmark command instead of the old jj branch command, which newer versions of Jujutsu (0.21+) removed entirely. Also added the missing macOS Apple Silicon (arm64) build of the Jujutsu bindings, so installs on Apple Silicon Macs no longer silently fall back to an unoptimized path.

🔌 Fully local, no-API-key setup is more reliable

If you run agentic-flow entirely offline against a local model (no cloud API key at all), several small threading issues in how the proxy port, the Ollama provider, and local model file paths were passed around are now fixed — this path should now "just work" more consistently.

📚 32 new example applications

Added a large batch of example projects demonstrating agentic-flow in more advanced scenarios (protein-folding consensus, Byzantine fault-tolerant coordination, peer-to-peer game content generation, and more) — useful as starting points if you're building something ambitious.

🔐 Added a SECURITY.md

A starting point for how to report security issues in this project.

Behind the scenes

We also did a broader cleanup of the project's pull request backlog — closing out several PRs whose underlying bugs had already been fixed a different way elsewhere, a couple that turned out to be unrelated content mistakenly opened against this repo, and one that didn't hold up to a live fact-check. The full reasoning for every decision is documented in ADR-078, and one unrelated-but-real finding (a security gap in an in-progress OAuth feature over in the RuVector project) was flagged there for its author to fix before merging.

We also found and filed a real bug in npm itself that currently blocks the standard npm audit fix command from running in this project — tracked for whoever picks it up next.

Upgrading

npm install agentic-flow@latest
# or, if you use npx:
npx agentic-flow@latest --version   # should print 2.1.3

No action needed — every change above is either invisible unless you were hitting the specific bug, or purely additive.


🤖 Generated with RuFlo

Commits

Updates react-router-dom from 7.18.3 to 7.18.4

Changelog

Sourced from react-router-dom's changelog.

v7.18.4

Patch Changes

Commits

Updates tailwind-merge from 3.6.0 to 3.7.0

Release notes

Sourced from tailwind-merge's releases.

tailwind-merge@3.7.0

New Features

  • Prepare some upcoming changes by @​dcastil in dcastil/tailwind-merge#713
    • Theme getters returned by fromTheme now expose the theme key they read as a themeKey property, so tooling can identify the referenced theme scale without calling the getter.
    • Release tags now include the package name, starting with tailwind-merge@3.7.0.

Bug Fixes

Documentation

Other

Full Changelog: v3.6.0...v3.7.0

Thanks to @​brandonmcconnell, @​manavm1990, @​langy, @​roboflow, @​syntaxfm, @​getsentry, @​codecov, a private sponsor, @​openclaw, @​sourcegraph, @​cesarvcanal, @​CasperKristiansson, @​jbisasky, @​frontendmasters and more via @​thnxdev for sponsoring tailwind-merge! ❤️

Commits
  • 511d68a tailwind-merge@3.7.0
  • 2461127 Release tooling: Pass the namespaced tag prefix and commit message to pnpm's ...
  • 9d41508 add changelog for tailwind-merge@3.7.0
  • c78a80f Configurator: Reuse runtime lookups during pruning
  • 49c317d Monorepo: Fix contributing link and include package coverage
  • 7b565ca Configurator: prune a generated config to a project's used classes (core step)
  • d83e013 Releases: auto-re-pin tag-pinned links on every version bump
  • b71fd41 Docs: pin every in-repo file link to a release tag instead of main
  • ee29441 Docs: point the ThemeObject JSDoc link at the packaged docs location
  • 9521b10 Releases: per-package pipeline with namespaced tags
  • Additional commits viewable in compare view

Updates @testing-library/dom from 10.4.1 to 10.4.2

Release notes

Sourced from @​testing-library/dom's releases.

v10.4.2

10.4.2 (2026-09-13)

Bug Fixes

  • deps: pin @​types/node to a TypeScript 4-compatible version (#1386) (6049cc0)
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​testing-library/dom since your current version.


Updates @types/node from 26.5.1 to 26.6.1

Commits

Updates @vitest/coverage-v8 from 5.0.0 to 5.0.1

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates autoprefixer from 10.5.6 to 10.6.1

Release notes

Sourced from autoprefixer's releases.

10.6.1

  • Fixed grid gap set with the row-gap and column-gap longhands (by dualfroz).

10.6.0 “Post tenebras lux”

Changelog

Sourced from autoprefixer's changelog.

10.6.1

  • Fixed grid gap set with the row-gap and column-gap longhands (by dualfroz).

10.6.0 “Post tenebras lux”

Commits

Updates jsdom from 30.0.1 to 30.1.0

Release notes

Sourced from jsdom's releases.

v30.1.0

jsdom is feeling the AGI!

This release is dedicated to @​scttcper, who unleashed @​codex upon jsdom and found tons of performance improvements. Along the way, he found and fixed many correctness issues as well.

We really appreciate his thoughtful PRs, which did a great job following the project's contribution guidelines, and were clearly human-curated, with their PR descriptions edited to be brief and respectful of the maintainers' time.

Thanks to @​scttcper, as well as all the other contributors of this release (most of whom were AI-assisted).

  • Added named access to elements on document, such as document.myForm for <form name="myForm">. (@​vojtisprime11)
  • Added QuotaExceededError, including its use for storage quota errors and oversized crypto.getRandomValues() requests.
  • Added support for the relaxed DOM naming rules when creating elements, attributes, and document types.
  • Improved performance of DOM construction, tree mutations, range operations, and live collection access, especially on large documents. (@​scttcper, @​erezrokah)
  • Improved performance of getComputedStyle(), style changes, and CSS serialization. (@​scttcper, @​jhult)
  • Improved performance of event dispatch, form control and label lookups, and updates to <select> elements and radio button groups. (@​scttcper)
  • Reduced memory use when creating and working with DOM nodes, attributes, event listeners, and mutation observers. (@​scttcper)
  • Changed window.close() to preserve access to the document and its DOM through retained references.
  • Fixed element.querySelectorAll() returning no matches when the first part of the selector matches the element itself, which regressed in v30.0.0. (@​asamuzaK)
  • Fixed case sensitivity in CSS attribute selectors, including selectors matching data-state="", title="", and other case-sensitive values. (@​asamuzaK)
  • Fixed document.querySelector() failing to find a matching element when an earlier element has the same ID but does not match the rest of the selector. (@​vojtisprime11)
  • Fixed :focus matching in shadow trees. (@​asamuzaK)
  • Fixed DOM insertion and replacement, including valid document.replaceChildren() calls, invalid document element and doctype placements, and mutations during element.replaceWith().
  • Fixed the ordering of script execution, custom element callbacks, iframe loading, and mutation observer notifications during DOM insertion, including in shadow trees.
  • Fixed queued events and navigation continuing after window.close() or iframe removal, and prevented new scripts, resource loads, timers, and animation frames from starting in destroyed documents. (@​scttcper)
  • Fixed parent documents waiting indefinitely for loading to finish when a child iframe removes itself during loading.
  • Fixed request cancellation across redirects, during pending requestInterceptor() callbacks, and when reusing an XMLHttpRequest after aborting it.
  • Fixed resource loading and JSDOM.fromURL() potentially hanging when response handling throws and response stream cleanup does not finish.
  • Fixed successful cached resource loads being treated as aborted.
  • Fixed getComputedStyle() and document.styleSheets using the wrong stylesheet order after inserting or updating <style> elements.
  • Fixed getComputedStyle() ignoring nested @import and @media rules in imported stylesheets, and returning stale results after imports finish loading.
  • Fixed style invalidation, stylesheet removal, and frame source updates in shadow trees.
  • Fixed repeated getComputedStyle() calls changing case-sensitive background URLs, and inconsistent resolution of border shorthands containing system colors. (@​scttcper)
  • Fixed computed border widths, including borderless elements incorrectly reporting 16px, which regressed in v30.0.0. (@​Alberto-BaseNet)
  • Fixed getComputedStyle() to resolve 'font-weight' keywords to numeric values. (@​tianrking)
  • Fixed getComputedStyle() to convert lengths to pixels inside CSS math functions containing percentages, and to resolve percentages in 'font-size' math functions. (@​soroushm)
  • Fixed serialization of min() and max() containing nested calc(), which regressed in v30.0.0. (@​asamuzaK)
  • Fixed CSS values mixing lengths or percentages with math functions, such as 'grid-template-columns' values containing both 100px and calc(). (@​rome-xi)
  • Fixed parsing of 'background' and 'border' shorthands with adjacent components, such as url(a.png)no-repeat, including a crash when parsing inline styles. Also fixed handling of invalid shorthand assignments and escaped or unusual characters in CSS declarations. (@​asamuzaK)
  • Fixed parsing of unitless zero values in 'flex' shorthands, such as 35 1 0, and rejection of negative 'flex-basis' lengths and percentages. (@​asamuzaK)
  • Fixed shorthand style assignments producing extra mutation records and custom element callbacks for intermediate values. (@​scttcper)
  • Fixed Range and Selection handling of CDATA sections, including boundary offsets and range cloning, extraction, deletion, insertion, and stringification. (@​scttcper)
  • Fixed text.normalize() incorrectly removing the text node or merging its siblings. (@​scttcper)
  • Fixed cloning and importing CDATA sections and processing instructions whose contents have been modified, and serialization of CDATA sections adopted into HTML documents.
  • Fixed stale named-property collections on window, and incorrect named access from empty or namespaced id="" and name="" values. (@​scttcper)
  • Fixed elements in documents created with DOMParser or document.implementation.createHTMLDocument() appearing as named properties on window and being retained in memory. (@​Iaotle)
  • Fixed memory leaks from mutation observers retaining observed nodes, abort signals retaining removed event listeners, and storage event tracking retaining closed windows. (@​scttcper)
  • Fixed storage events being sent to windows created after the storage change, and ensured surviving recipients still receive events when the source document is destroyed.
  • Fixed attribute lookups after namespace prefix changes, and namespaced attributes incorrectly affecting ID lookups and element behavior. (@​scttcper)
  • Fixed input.list in detached element trees. (@​scttcper)
  • Fixed attr.ownerDocument after setting an attribute node on an element in another document or adopting its element. (@​Kjubikstronk)

... (truncated)

Commits
  • 556b11f 30.1.0
  • 9547fbf Tie queued tasks to document lifetime
  • 3be65d9 Disable unused HTML reports in the WPT runner
  • d555e61 Replace SymbolTree with a DOM-specific tree
  • f28983d Clone CDATA and processing instructions without revalidation
  • 33e4fa7 Invalidate computed styles after CSS imports load
  • ec6fd5b Select storage event recipients at mutation time
  • bcc037a Honor script type and legacy event attributes
  • faa5c4f Preserve currentScript across nested scripts
  • 8d7a37f Avoid quadratic HTML collection iteration
  • Additional commits viewable in compare view

Updates ruflo from 3.41.2 to 3.42.4

Release notes

Sourced from ruflo's releases.

v3.42.4 — smart search score semantics fix

What changed

Fixes Finding B of #3327: memory_search({ smart: true }) was reporting SmartRetrieval's internal RRF fusion score in the similarity field instead of the underlying retrieval relevance score — e.g. a raw retrieval relevance of 0.8 was showing up as 0.03252247488101534.

  • similarity now carries the raw retrieval relevance (matches smart: false behavior)
  • the fused SmartRetrieval ranking score is now exposed separately as rankingScore
  • threshold behavior is unchanged (still applied pre-RRF/MMR/recency)
  • 14 new regression tests across the SmartRetrieval package and MCP handler

Fixed in #3340 (thanks @​takagibit18).

Finding A of #3327 (reasoningBank/vectorBackend reporting enabled:true but routing through bridge-fallback) remains open and unclaimed.

Note on version history

3.42.1–3.42.3 were published to npm without matching version-bump commits on main. Verified their tags (v3.42.0, v3.42.1, v3.42.3) are all ancestors of this release, so 3.42.4 is a strict superset of everything previously shipped.

Co-Authored-By: RuFlo ruv@ruv.net

v3.42.3 — Windows publish + hook-override quoting fixes

Fixes

  • hooks: quote-aware split for RUFLO_HOOK_CLI_OVERRIDE (#3344) — the test-only CLI-override parser in plugins/ruflo-core/scripts/ruflo-hook.cjs did a naive .split(' '), which broke process.execPath into C:\Program plus stray tokens on a standard Windows Node install (C:\Program Files\nodejs\node.exe). Found while verifying #3332's Windows argv fix on a real Windows machine rather than windows-latest CI (whose hosted Node path has no space). No production impact — RUFLO_HOOK_CLI_OVERRIDE is never set outside the test harness.
  • release: spawn npm.cmd with shell:true on Windows (#3346, #3348) — scripts/stage-internal-runtime-bundles.mjs and scripts/prepare-root-publish.mjs both spawned npm.cmd directly without shell:true, which throws EINVAL on any current Node/Windows combo (CreateProcess can't launch a .cmd, and Node has refused to shell out to one implicitly since CVE-2024-27980). This blocked every Windows publish of @claude-flow/cli and the claude-flow umbrella package. Found live while publishing this release from a Windows machine.

Verification

  • plugins/ruflo-core/scripts/test-hooks.mjs: 32/32 (was 29/32 before #3344)
  • v3/@claude-flow/cli/__tests__/ruflo-hook-windows-argv.test.ts, escape-cmd-arg.test.cjs, mcp-launch.test.cjs, scripts/smoke-ruflo-hook-cjs.mjs, cross-platform/env-var audits: all clean
  • Full Windows publish pipeline (@claude-flow/cli → claude-flow → ruflo) exercised end-to-end on a real Windows machine after the fixes landed
  • latest / alpha / v3alpha dist-tags verified aligned at 3.42.3 across all three packages

🤖 Generated with RuFlo

v3.42.1 — SONA env-default, review batch, and reliability fixes

A patch release: one small feature (opt-in, fully backward-compatible) plus a batch of independently-reviewed bug fixes, a performance fix, and a dependency bump — all reviewed, tested, and merged in this pass.

What's new for you

SONA learning mode can now default from the environment

RUFLO_INTELLIGENCE_MODE sets a fleet-wide default learning mode (real-time, balanced, research, edge, batch) without threading mode/sonaMode through every call site — useful for a managed deployment that wants every session to learn in a specific profile. An explicit per-call mode always wins; an unset or unrecognised value falls through to balanced, so a typo can never silently pick a profile. (Originally landed with a bug where one of the two places reading this variable only checked it once per process instead of per session — fixed before release, with new regression tests in both places.)

Diagnostics and memory fixes

  • ruflo doctor no longer guesses your memory driver from a raw table count (a heuristic that never actually correlated with which driver you're using) — it now reports only what it verifies directly.
  • ruflo doctor now resolves the installed MetaHarness version correctly instead of reporting stale/incorrect data.
  • memory_stats now answers from the live store instead of a snapshot that couldn't see in-flight writes — a working memory store no longer reports itself as uninitialized. Also fixes a namespace named __proto__ silently vanishing from the breakdown, and a hardcoded row cap that was truncating large stores without saying so.
  • A database handle used during memory initialization now closes on every code path, including the failure path that used to leak it.
  • Opening the graph database now verifies the handle is actually persistent before using it — a bad argument shape used to silently produce an in-memory-only graph that vanished on exit, with no error.

... (truncated)

Commits
  • e558f0c chore(release): 3.42.0 -> 3.42.4 — smart search score semantics fix (#3327/#3...
  • 2602b64 chore(release): 3.42.0 — dream-cycle backlog batch (14 PRs)
  • See full diff in compare view

Updates sass-embedded from 1.104.0 to 1.104.1

Changelog

Sourced from sass-embedded's changelog.

1.104.1

  • Fix a bug where loud comments before @use rules could be emitted multiple times under certain circumstances.

  • Fix a bug in which an invalid selector at the end of an indented syntax stylesheet would cause the parser to crash instead of emitting a useful error message.

Command Line Interface

  • Many-to-many compilations no longer compile any files that appear in the output directory if the output directory is also within the source directory. This fixes a bug where --watch mode could enter an infinite loop recompiling the same CSS file over and over.

  • Sass now sets the modification time of output files to the time compilation started rather than the time it ended. This ensures that, if a source file is modified during compilation, --watch and --update mode will recompile the outputs to include the new source file contents.

Commits

Updates vitest from 5.0.0 to 5.0.1

Release notes

Sourced from vitest's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • 03630a5 chore: release v5.0.1 (#11275)
  • a47d790 fix(fakeTimers): force queueMicrotask and nextTick in toNotFake (#11261)
  • 2ce29d5 fix: warn when deprecated deps.optimizer.web is used (#11214)
  • ccd6d05 docs: fix typecheck exclude default in documentation (#11223)
  • 91ab158 fix(doctor): measure vm pools for custom environments (#11212)
  • 23dda73 fix: share the server on self-referencing extends (#11034)
  • 498fbe9 fix: resolve ResolvedConfig exactOptionalPropertyTypes errors (#11175)
  • 115c3f6 fix: correct typos in error message and comments (#11187)
  • 7361465 fix: keep metadata file when clearing the cache (#11199)

Bumps the minor-and-patch group with 14 updates:

| Package | From | To |
| --- | --- | --- |
| [@amplitude/analytics-browser](https://github.com/amplitude/Amplitude-TypeScript) | `2.45.8` | `2.45.10` |
| [agentic-flow](https://github.com/ruvnet/agentic-flow) | `2.1.2` | `2.1.3` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.18.3` | `7.18.4` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [@testing-library/dom](https://github.com/testing-library/dom-testing-library) | `10.4.1` | `10.4.2` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.5.1` | `26.6.1` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.0` | `5.0.1` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.5.6` | `10.6.1` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.0.1` | `30.1.0` |
| [ruflo](https://github.com/ruvnet/claude-flow/tree/HEAD/ruflo) | `3.41.2` | `3.42.4` |
| [sass-embedded](https://github.com/sass/embedded-host-node) | `1.104.0` | `1.104.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.0` | `5.0.1` |
| [@rollup/rollup-linux-x64-gnu](https://github.com/rollup/rollup) | `4.63.1` | `4.63.3` |
| [tsx](https://github.com/privatenumber/tsx) | `4.22.1` | `4.23.13` |


Updates `@amplitude/analytics-browser` from 2.45.8 to 2.45.10
- [Release notes](https://github.com/amplitude/Amplitude-TypeScript/releases)
- [Commits](https://github.com/amplitude/Amplitude-TypeScript/compare/@amplitude/analytics-browser@2.45.8...@amplitude/analytics-browser@2.45.10)

Updates `agentic-flow` from 2.1.2 to 2.1.3
- [Release notes](https://github.com/ruvnet/agentic-flow/releases)
- [Changelog](https://github.com/ruvnet/agentic-flow/blob/main/docs/CHANGELOG.md)
- [Commits](https://github.com/ruvnet/agentic-flow/commits/v2.1.3)

Updates `react-router-dom` from 7.18.3 to 7.18.4
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `@testing-library/dom` from 10.4.1 to 10.4.2
- [Release notes](https://github.com/testing-library/dom-testing-library/releases)
- [Changelog](https://github.com/testing-library/dom-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/dom-testing-library@v10.4.1...v10.4.2)

Updates `@types/node` from 26.5.1 to 26.6.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/coverage-v8)

Updates `autoprefixer` from 10.5.6 to 10.6.1
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.6...10.6.1)

Updates `jsdom` from 30.0.1 to 30.1.0
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.0.1...v30.1.0)

Updates `ruflo` from 3.41.2 to 3.42.4
- [Release notes](https://github.com/ruvnet/claude-flow/releases)
- [Changelog](https://github.com/ruvnet/ruflo/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ruvnet/claude-flow/commits/v3.42.4/ruflo)

Updates `sass-embedded` from 1.104.0 to 1.104.1
- [Changelog](https://github.com/sass/embedded-host-node/blob/main/CHANGELOG.md)
- [Commits](sass/embedded-host-node@1.104.0...1.104.1)

Updates `vitest` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

Updates `@rollup/rollup-linux-x64-gnu` from 4.63.1 to 4.63.3
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.63.1...v4.63.3)

Updates `tsx` from 4.22.1 to 4.23.13
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.22.1...v4.23.13)

---
updated-dependencies:
- dependency-name: "@amplitude/analytics-browser"
  dependency-version: 2.45.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: agentic-flow
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: react-router-dom
  dependency-version: 7.18.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@testing-library/dom"
  dependency-version: 10.4.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: autoprefixer
  dependency-version: 10.6.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: jsdom
  dependency-version: 30.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ruflo
  dependency-version: 3.42.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: sass-embedded
  dependency-version: 1.104.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@rollup/rollup-linux-x64-gnu"
  dependency-version: 4.63.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.13
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/minor-and-patch-61dc3bcf1c branch September 28, 2026 05:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants