Repository navigation
fix(deps): update all minor dependencies - #1295
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor
branch
21 times, most recently
from
September 10, 2026 17:44
a9c7ac5 to
2178756
Compare
renovate
Bot
force-pushed
the
renovate/all-minor
branch
from
September 11, 2026 02:45
2178756 to
aa8207d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
10.5.10→10.6.010.5.10→10.6.010.5.10→10.6.010.3.0→10.4.01.33.1→1.35.15.3.0→5.4.15.8.0→5.9.04.4.3→4.5.44.6.2(+2)Release Notes
storybookjs/storybook (@storybook/addon-docs)
v10.6.0Compare Source
Storybook 10.6 contains hundreds of fixes and improvements:
List of all updates
@storybook/angular-vitepeers that nothing else brings in - #36002, thanks @valentinpalkovic!@angular/corethrough the package manager, not the raw specifier - #35999, thanks @valentinpalkovic!stylesthe way the Angular builders do - #35998, thanks @valentinpalkovic!storybook skills/storybook toolsand align the evals - #35957, thanks @kasperpeulen!storybook skillscommand - #35757, thanks @ghengeveld!storybook skillswithstorybook toolsshape - #36121, thanks @ghengeveld!skills get/skills list, addskills --all- #36127, thanks @kasperpeulen!storybook tools --jsonstdout parseable - #36023, thanks @kasperpeulen!Outputblock as the--jsonshape - #36089, thanks @kasperpeulen!storybook skills get setupand remove duplicate sandbox addon - #36024, thanks @kasperpeulen!storybook toolscommand derived at runtime from the OSA toolsets - #35850, thanks @JReinhold!docs show-storyas an alternative to componentId + storyName - #36104, thanks @kasperpeulen!storybook/internal/tools- #35983, thanks @JReinhold!conventional-changelog/conventional-changelog (conventional-changelog-conventionalcommits)
v10.4.0Compare Source
Features
jdx/fnox (fnox)
v1.35.1: : Signed release provenanceCompare Source
A small release with no changes to fnox's runtime behavior. The one user-facing improvement is that release downloads can now be verified against a signed provenance manifest; the rest is documentation and internal tooling.
Changed
packslip.sigstore.jsonbeside the archives, listing each artifact's sha256/sha512, the bundled executable, host shared-library requirements, and build-provenance attestations, all tied to thegithub.com/jdx/fnoxOIDC identity. Installers can verify a download against that identity rather than a signing key the project would have to hold and rotate. Afnox.usage.kdlCLI spec is also published so consumers can generate completions, man pages, and docs without executing fnox locally.Full Changelog: jdx/fnox@v1.35.0...v1.35.1
💚 Sponsor fnox
fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.
v1.35.0: : Selective Profile InheritanceCompare Source
This release introduces selective profile inheritance, letting profiles compose their secrets, providers, and lease backends from other named profiles, alongside a batch of correctness fixes to secret resolution, sync caching, and the background daemon.
Added
Selective profile inheritance (#770) -- @jdx. Named profiles can now declare an ordered
inheritslist so their configuration is layered from ancestor profiles before the profile itself, with later entries winning on conflicts. Inheritance applies to secrets, providers, lease backends, anddefault_provider, and supports nested inheritance. Unknown inherited profiles and inheritance cycles are reported as actionable configuration errors, and inheritedfnox.<profile>.tomlfiles are discovered automatically.fnox -P api-local exec -- ./apiFixed
Sync refreshes from current sources, not stale caches (#774) -- @davdroman.
fnox sync --local-filecould resolve secrets from its previously generated local cache instead of the current source configuration, so changes to a tracked provider or value were ignored on refresh. Cached sync entries are now excluded when resolving refresh sources, stale entries (including inherited profiles and both local override filenames) are removed during full refreshes, and ordinary local overrides, providers, profile inheritance, and--no-defaultsbehavior are preserved.fnox checkbatches Age secret resolution (#779) -- @davdroman.checkpreviously resolved each secret separately, repeatedly unwrapping the same shared key for batch-encrypted Age values backed by a hardware or plugin identity, which could require one authorization per secret. Eligible Age-backed secrets are now resolved in batches per provider, unwrapping each shared batch key once, while preserving per-secret errors for invalid ciphertexts.Background daemon detaches from the client working directory (#795) -- @jdx. Background daemons now start from
/instead of inheriting the client's working directory, so the daemon keeps serving requests even after the directory that auto-started it is deleted. Per-request resolution is unchanged, since clients still send theircwdon each request.Intentional default fallbacks stay quiet (#771) -- @jdx. When a secret uses
if_missing: ignoreand falls back from a failed provider to a default (including interpolated defaults), the fallback message is now logged at debug instead of warn. Interpolated default resolution also no longer re-runs the already-failed root provider, while still surfacing genuine interpolation cycle errors.Performance
cd(#766) -- @jdx.fnox hook-envno longer forces a full secret reload on every working-directory change. Sessions now refresh only when the effective config hierarchy or relevantFNOX_*environment variables change, so navigating between directories within the samefnox.tomltree preserves the loaded environment.Documentation
FNOX_BW_SESSION, notFNOX_BW_SESSION_TOKEN), FIDO2/YubiKey setup using a positional type instead of a nonexistent--typeflag,http_timeoutdocumented as a duration string, import examples that require--providerand--force, corrected keychain/Linux Secret Service requirements, and README additions for the fido2, yubikey, foks, and keeper-sm providers.Full Changelog: jdx/fnox@v1.34.1...v1.35.0
💚 Sponsor fnox
fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.
v1.34.1: : Safer profiles, exports, and macOS binariesCompare Source
A patch release focused on safety and correctness: unknown profiles now fail loudly instead of silently falling back to defaults, dotenv exports survive Docker Compose interpolation, interactive daemon cache misses regain access to your terminal, and macOS release binaries are now notarized.
Fixed
Unknown profiles are rejected (#741) -- @jdx. An active profile that has neither a
[profiles.<name>]table nor a matchingfnox.<name>.tomloverlay now errors (listing the available profiles) instead of silently falling back to top-level secrets, which could leak defaults on a typo. Shell integration (hook-env) also refuses unknown profiles. Creating new profiles viaset,import, andprovider addstill works.Dotenv export preserves dollar signs (#746) -- @jdx. Secrets containing
$are now emitted in single quotes so Docker Compose no longer interpolates them, falling back to double quotes with\$escaping when needed. Dotenv import was aligned to match: it reassembles multiline single-quoted values, unescapes\', and treats\$in double quotes as a literal dollar sign.Interactive daemon cache misses resolve in the foreground (#743) -- @jdx. When the daemon misses its cache for an interactive client, the missing keys are now resolved in the foreground so PIN, touch, browser, and auth-command prompts reach the invoking terminal; resolved values are then sent back to the daemon for reuse. Non-interactive callers continue to resolve daemon-side and never prompt.
age batch decryption prompts once (#755) -- @jdx.
fnox syncnow wraps a single random key with age per batch and encrypts each secret under it, so age (and hardware-backed plugins) only prompt once per sync instead of once per secret. Existing sync caches remain readable, and re-runningfnox syncmigrates them to the batched format.Security
^[A-Za-z_][A-Za-z0-9_]*$), enforced when loading, validating, runningset, andimport, with shell emitters quoting names defensively across Bash, Zsh, Fish, and PowerShell.execand MCPexecnow strip ambientFNOX_AGE_KEYandFNOX_AGE_KEY_FILEbefore spawning child processes while still injecting explicitly configured secrets.Changed
Documentation
<path>render correctly instead of being parsed as Vue elements (#739) -- @jdx.Full Changelog: jdx/fnox@v1.34.0...v1.34.1
💚 Sponsor fnox
fnox is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, hk, and more. Keeping fnox secure, maintained, and free is funded by sponsors.
If fnox is handling secrets or config for you or your team, please consider sponsoring at jdx.dev. Sponsorships are what let fnox stay independent and the project keep moving.
v1.34.0: : Keeper Secrets Manager & sturdier file secretsCompare Source
This release adds a read-only Keeper Secrets Manager provider and delivers a batch of fixes to file-backed secrets, FIDO2 prompting, and shell integration.
Added
Keeper Secrets Manager provider (#720) -- @jdx. A new read-only
keeper-smprovider backed by Keeper's official Rust SDK. Secret values use Keeper notation such asRECORD_UID/field/password. Authentication works from a JSON config file (KSM_CONFIG/FNOX_KEEPER_CONFIG, or the default~/.keeper/ksm-config.json), with optional one-time-token bootstrap viaKSM_TOKEN/FNOX_KEEPER_TOKEN(which must persist to a file-backed config). Batch reads redeem the token once and fetch concurrently, and Keeper environment variables are scrubbed from the proxy's ambient credentials.fnox set --from-file <path>(#730) -- @jdx. Reads a secret value verbatim from a UTF-8 file without trimming, preserving trailing newlines. This fixes SSH private keys and similaras_filesecrets losing their required final newline, which happened becausefnox settrims stdin values and shell command substitution strips trailing newlines. The existingecho "x" | fnox set KEYbehavior is unchanged;--from-filecannot be combined with a positional value.Fixed
as_filesecrets are cleaned up on shell exit (#724) -- @jdx. Decrypted temp files created foras_filesecrets previously lingered because cleanup only ran on a laterhook-envrefresh.fnox deactivatenow removes session-recorded temp files, and a new zshzshexithook cleans them up when you close the terminal. Cleanup is scoped to paths under the session's hook temp dir (survivingTMPDIRchanges), and nested zsh sessions no longer delete files owned by their parent.FIDO2 prompts only once per batch (#732) -- @jdx. Resolving multiple FIDO2-protected secrets no longer triggers repeated and delayed PIN/touch prompts. The provider now acquires the hardware HMAC secret once and decrypts all values with it, and device discovery runs before the PIN prompt so missing or multiple-device errors surface without an unusable prompt. Per-secret results and errors are preserved without negatively caching transient hardware failures.
Auth output kept off
hook-envstdout (#713) -- @halms.fnox hook-envstdout is evaluated as shell code, so an expired session that triggered reauthentication could cause login progress output to be executed as commands. Auth-command stdout is now routed to stderr while remaining live for interactive logins.MCP tool list works with strict clients (#727) -- @jdx.
tools/listnow includes thettlMs: 0andcacheScope: "private"cache hints required by the MCP2026-07-28schema, so strict clients such as Claude Code can fetch fnox tools again. The existing no-cache behavior is preserved.Documentation
${SECRET_NAME}interpolation in default values (#733) -- @arthurfiorette. Explains resolution order across providers, interpolated defaults, literal defaults, and environment variables, plus errors for undefined references and dependency cycles.New Contributors
Full Changelog: jdx/fnox@v1.33.1...v1.34.0
💚 Sponsor fnox
fnox is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, hk, and more. Keeping fnox secure, maintained, and free is funded by sponsors.
If fnox is handling secrets or config for you or your team, please consider sponsoring at jdx.dev. Sponsorships are what let fnox stay independent and the project keep moving.
nodeca/js-yaml (js-yaml)
v5.4.1Compare Source
v5.4.0Compare Source
Added
scalarStyleRulesdumper option to customize string formatting.See Scalar styling for details.
Changed
and collection nodes now use
SCALAR_STYLEandCOLLECTION_STYLEvalues;explicit tags use the separate
taggedproperty. Alias nodes now containonly
kindandanchor. This only affects code that directly constructs oredits AST nodes.
sortKeysoption was rewritten using AST mutation to avoidside effects.
loaded values; in particular, whitespace-only strings are now double-quoted.
Fixed
quoteFlowKeysandflowSkipColonSpace,including alias and property-only keys, #786.
Configuration
📅 Schedule: (in timezone Asia/Tokyo)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.