Skip to content

fix(deps): update all minor dependencies - #1295

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor
Sep 11, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor

Conversation

@renovate

@renovate renovate Bot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@storybook/addon-docs (source) 10.5.10 → 10.6.0 age confidence devDependencies minor
@storybook/addon-links (source) 10.5.10 → 10.6.0 age confidence devDependencies minor
@storybook/react (source) 10.5.10 → 10.6.0 age confidence devDependencies minor
conventional-changelog-conventionalcommits (source) 10.3.0 → 10.4.0 age confidence devDependencies minor
fnox 1.33.1 → 1.35.1 age confidence tools minor
js-yaml 5.3.0 → 5.4.1 age confidence dependencies minor
type-fest 5.8.0 → 5.9.0 age confidence devDependencies minor
zod (source) 4.4.3 → 4.5.4 age confidence dependencies minor 4.6.2 (+2)

Release Notes

storybookjs/storybook (@​storybook/addon-docs)

v10.6.0

Compare Source

New skills architecture for agentic workflows

Storybook 10.6 contains hundreds of fixes and improvements:

  • 💻 CLI bindings for agent tools/skills
  • 🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)
  • 🟢 Vue MCP/skills support and improved docgen/snippets (experimental)
  • 🧩 Tanstack / NextJS-Vite framework bugfixes
  • ⚡ Improved performance and reduced bundle size
List of all updates
conventional-changelog/conventional-changelog (conventional-changelog-conventionalcommits)

v10.4.0

Compare Source

Features
jdx/fnox (fnox)

v1.35.1: : Signed release provenance

Compare Source

A small release with no changes to fnox's runtime behavior. The one user-facing improvement is that release downloads can now be verified against a signed provenance manifest; the rest is documentation and internal tooling.

Changed

  • Signed packslip published with each release (#​807) -- @​jdx. Every release now ships a keyless-signed packslip.sigstore.json beside the archives, listing each artifact's sha256/sha512, the bundled executable, host shared-library requirements, and build-provenance attestations, all tied to the github.com/jdx/fnox OIDC identity. Installers can verify a download against that identity rather than a signing key the project would have to hold and rotate. A fnox.usage.kdl CLI spec is also published so consumers can generate completions, man pages, and docs without executing fnox locally.

Full Changelog: jdx/fnox@v1.35.0...v1.35.1

💚 Sponsor fnox

fnox is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

v1.35.0: : Selective Profile Inheritance

Compare Source

This release introduces selective profile inheritance, letting profiles compose their secrets, providers, and lease backends from other named profiles, alongside a batch of correctness fixes to secret resolution, sync caching, and the background daemon.

Added

  • Selective profile inheritance (#​770) -- @​jdx. Named profiles can now declare an ordered inherits list so their configuration is layered from ancestor profiles before the profile itself, with later entries winning on conflicts. Inheritance applies to secrets, providers, lease backends, and default_provider, and supports nested inheritance. Unknown inherited profiles and inheritance cycles are reported as actionable configuration errors, and inherited fnox.<profile>.toml files are discovered automatically.

    [profiles.openai.secrets]
    OPENAI_API_KEY = { provider = "age", value = "encrypted-key..." }
    
    [profiles.database-local.secrets]
    DATABASE_PASSWORD = { provider = "age", value = "encrypted-password..." }
    
    [profiles.api-local]
    inherits = ["openai", "database-local"]
    fnox -P api-local exec -- ./api

Fixed

  • Sync refreshes from current sources, not stale caches (#​774) -- @​davdroman. fnox sync --local-file could resolve secrets from its previously generated local cache instead of the current source configuration, so changes to a tracked provider or value were ignored on refresh. Cached sync entries are now excluded when resolving refresh sources, stale entries (including inherited profiles and both local override filenames) are removed during full refreshes, and ordinary local overrides, providers, profile inheritance, and --no-defaults behavior are preserved.

  • fnox check batches Age secret resolution (#​779) -- @​davdroman. check previously resolved each secret separately, repeatedly unwrapping the same shared key for batch-encrypted Age values backed by a hardware or plugin identity, which could require one authorization per secret. Eligible Age-backed secrets are now resolved in batches per provider, unwrapping each shared batch key once, while preserving per-secret errors for invalid ciphertexts.

  • Background daemon detaches from the client working directory (#​795) -- @​jdx. Background daemons now start from / instead of inheriting the client's working directory, so the daemon keeps serving requests even after the directory that auto-started it is deleted. Per-request resolution is unchanged, since clients still send their cwd on each request.

  • Intentional default fallbacks stay quiet (#​771) -- @​jdx. When a secret uses if_missing: ignore and falls back from a failed provider to a default (including interpolated defaults), the fallback message is now logged at debug instead of warn. Interpolated default resolution also no longer re-runs the already-failed root provider, while still surfacing genuine interpolation cycle errors.

Performance

  • Skip redundant secret reloads on cd (#​766) -- @​jdx. fnox hook-env no longer forces a full secret reload on every working-directory change. Sessions now refresh only when the effective config hierarchy or relevant FNOX_* environment variables change, so navigating between directories within the same fnox.toml tree preserves the loaded environment.

Documentation

  • Docs and CLI help audited against actual behavior (#​798) -- @​jdx. Every docs page and CLI help string was checked against the code and corrected. Notable fixes include the secret resolution order in how-it-works (provider, then default, then environment), the Bitwarden auth hint (FNOX_BW_SESSION, not FNOX_BW_SESSION_TOKEN), FIDO2/YubiKey setup using a positional type instead of a nonexistent --type flag, http_timeout documented as a duration string, import examples that require --provider and --force, corrected keychain/Linux Secret Service requirements, and README additions for the fido2, yubikey, foks, and keeper-sm providers.

Full Changelog: jdx/fnox@v1.34.1...v1.35.0

💚 Sponsor fnox

fnox is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

v1.34.1: : Safer profiles, exports, and macOS binaries

Compare Source

A patch release focused on safety and correctness: unknown profiles now fail loudly instead of silently falling back to defaults, dotenv exports survive Docker Compose interpolation, interactive daemon cache misses regain access to your terminal, and macOS release binaries are now notarized.

Fixed

  • Unknown profiles are rejected (#​741) -- @​jdx. An active profile that has neither a [profiles.<name>] table nor a matching fnox.<name>.toml overlay now errors (listing the available profiles) instead of silently falling back to top-level secrets, which could leak defaults on a typo. Shell integration (hook-env) also refuses unknown profiles. Creating new profiles via set, import, and provider add still works.

  • Dotenv export preserves dollar signs (#​746) -- @​jdx. Secrets containing $ are now emitted in single quotes so Docker Compose no longer interpolates them, falling back to double quotes with \$ escaping when needed. Dotenv import was aligned to match: it reassembles multiline single-quoted values, unescapes \', and treats \$ in double quotes as a literal dollar sign.

  • Interactive daemon cache misses resolve in the foreground (#​743) -- @​jdx. When the daemon misses its cache for an interactive client, the missing keys are now resolved in the foreground so PIN, touch, browser, and auth-command prompts reach the invoking terminal; resolved values are then sent back to the daemon for reuse. Non-interactive callers continue to resolve daemon-side and never prompt.

  • age batch decryption prompts once (#​755) -- @​jdx. fnox sync now wraps a single random key with age per batch and encrypts each secret under it, so age (and hardware-backed plugins) only prompt once per sync instead of once per secret. Existing sync caches remain readable, and re-running fnox sync migrates them to the batched format.

Security

  • Hardened secret injection boundaries (#​763) -- @​jdx. Secret names must now be valid environment identifiers (^[A-Za-z_][A-Za-z0-9_]*$), enforced when loading, validating, running set, and import, with shell emitters quoting names defensively across Bash, Zsh, Fish, and PowerShell. exec and MCP exec now strip ambient FNOX_AGE_KEY and FNOX_AGE_KEY_FILE before spawning child processes while still injecting explicitly configured secrets.

Changed

  • macOS release binaries are now notarized (#​764) -- @​jdx. The signed macOS binary is submitted to Apple's notary service and built with a hardened runtime, so downloads (which carry the quarantine bit) no longer hit the Gatekeeper "cannot be verified" dialog.

Documentation

  • Generated CLI configuration docs now HTML-encode angle brackets so placeholders like <path> render correctly instead of being parsed as Vue elements (#​739) -- @​jdx.
  • Sync docs now call out the golden path and hardware-backed decryption (#​748) -- @​jdx.

Full Changelog: jdx/fnox@v1.34.0...v1.34.1

💚 Sponsor fnox

fnox is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, hk, and more. Keeping fnox secure, maintained, and free is funded by sponsors.

If fnox is handling secrets or config for you or your team, please consider sponsoring at jdx.dev. Sponsorships are what let fnox stay independent and the project keep moving.

v1.34.0: : Keeper Secrets Manager & sturdier file secrets

Compare Source

This release adds a read-only Keeper Secrets Manager provider and delivers a batch of fixes to file-backed secrets, FIDO2 prompting, and shell integration.

Added

  • Keeper Secrets Manager provider (#​720) -- @​jdx. A new read-only keeper-sm provider backed by Keeper's official Rust SDK. Secret values use Keeper notation such as RECORD_UID/field/password. Authentication works from a JSON config file (KSM_CONFIG / FNOX_KEEPER_CONFIG, or the default ~/.keeper/ksm-config.json), with optional one-time-token bootstrap via KSM_TOKEN / FNOX_KEEPER_TOKEN (which must persist to a file-backed config). Batch reads redeem the token once and fetch concurrently, and Keeper environment variables are scrubbed from the proxy's ambient credentials.

    DB_PASSWORD = { provider = "keeper-sm", value = "RECORD_UID/field/password" }
  • fnox set --from-file <path> (#​730) -- @​jdx. Reads a secret value verbatim from a UTF-8 file without trimming, preserving trailing newlines. This fixes SSH private keys and similar as_file secrets losing their required final newline, which happened because fnox set trims stdin values and shell command substitution strips trailing newlines. The existing echo "x" | fnox set KEY behavior is unchanged; --from-file cannot be combined with a positional value.

    fnox set SSH_KEY --from-file ~/.ssh/id_ed25519

Fixed

  • as_file secrets are cleaned up on shell exit (#​724) -- @​jdx. Decrypted temp files created for as_file secrets previously lingered because cleanup only ran on a later hook-env refresh. fnox deactivate now removes session-recorded temp files, and a new zsh zshexit hook cleans them up when you close the terminal. Cleanup is scoped to paths under the session's hook temp dir (surviving TMPDIR changes), and nested zsh sessions no longer delete files owned by their parent.

  • FIDO2 prompts only once per batch (#​732) -- @​jdx. Resolving multiple FIDO2-protected secrets no longer triggers repeated and delayed PIN/touch prompts. The provider now acquires the hardware HMAC secret once and decrypts all values with it, and device discovery runs before the PIN prompt so missing or multiple-device errors surface without an unusable prompt. Per-secret results and errors are preserved without negatively caching transient hardware failures.

  • Auth output kept off hook-env stdout (#​713) -- @​halms. fnox hook-env stdout is evaluated as shell code, so an expired session that triggered reauthentication could cause login progress output to be executed as commands. Auth-command stdout is now routed to stderr while remaining live for interactive logins.

  • MCP tool list works with strict clients (#​727) -- @​jdx. tools/list now includes the ttlMs: 0 and cacheScope: "private" cache hints required by the MCP 2026-07-28 schema, so strict clients such as Claude Code can fetch fnox tools again. The existing no-cache behavior is preserved.

Documentation

  • Documented ${SECRET_NAME} interpolation in default values (#​733) -- @​arthurfiorette. Explains resolution order across providers, interpolated defaults, literal defaults, and environment variables, plus errors for undefined references and dependency cycles.

New Contributors

Full Changelog: jdx/fnox@v1.33.1...v1.34.0

💚 Sponsor fnox

fnox is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, hk, and more. Keeping fnox secure, maintained, and free is funded by sponsors.

If fnox is handling secrets or config for you or your team, please consider sponsoring at jdx.dev. Sponsorships are what let fnox stay independent and the project keep moving.

nodeca/js-yaml (js-yaml)

v5.4.1

Compare Source

v5.4.0

Compare Source

Added
  • Added the scalarStyleRules dumper option to customize string formatting.
    See Scalar styling for details.
Changed
  • [breaking] Flattened the low-level AST node style representation. Scalar
    and collection nodes now use SCALAR_STYLE and COLLECTION_STYLE values;
    explicit tags use the separate tagged property. Alias nodes now contain
    only kind and anchor. This only affects code that directly constructs or
    edits AST nodes.
  • [breaking] The sortKeys option was rewritten using AST mutation to avoid
    side effects.
  • Reworked scalar style selection. This can change formatting without changing
    loaded values; in particular, whitespace-only strings are now double-quoted.
Fixed
  • Accept a byte order mark at the start of each document in a stream, #​791.
  • Produce valid flow mappings with quoteFlowKeys and flowSkipColonSpace,
    including alias and property-only keys, #​786.
  • Preserve empty scalar items when converting block sequences to flow style.
  • Do not apply the 1024-character simple-key limit to flow mapping keys.
  • Cou

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • "after 5am on Saturday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) September 5, 2026 05:37
@renovate
renovate Bot force-pushed the renovate/all-minor branch 21 times, most recently from a9c7ac5 to 2178756 Compare September 10, 2026 17:44
@renovate
renovate Bot force-pushed the renovate/all-minor branch from 2178756 to aa8207d Compare September 11, 2026 02:45
@renovate
renovate Bot merged commit ba4e052 into main Sep 11, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate/all-minor branch September 11, 2026 02:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants