Skip to content

fix(deps): update all non-major dependencies - #15

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

fix(deps): update all non-major dependencies#15
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented May 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/a-h/templ v0.3.1001v0.3.1020 age confidence require patch
github.com/evanw/esbuild v0.28.0v0.28.2 age confidence require patch
github.com/tdewolff/parse/v2 v2.8.12v2.8.16 age confidence require patch
golang.org/x/mod v0.35.0v0.39.0 age confidence require minor
golang.org/x/text v0.36.0v0.41.0 age confidence require minor
golangci/golangci-lint v2.12.1v2.12.2 age confidence uses-with patch

Release Notes

a-h/templ (github.com/a-h/templ)

v0.3.1020

Compare Source

Changelog

evanw/esbuild (github.com/evanw/esbuild)

v0.28.2

Compare Source

  • Fix tree shaking bug due to TypeScript import alias (#​4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#​4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#​4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#​4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#​4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})
    }
    
    // Old output (with --minify-syntax --target=es6)
    function foo() {
      bar(void 0 || (x = {}));
    }
    
    // New output (with --minify-syntax --target=es6)
    function foo() {
      let x;
      bar(x || (x = {}));
    }
  • Fix a potential deadlock when the JavaScript API is used incorrectly (#​4503, #​4506)

    The JavaScript API runs the native esbuild executable as a long-lived child process and communicates with it over stdin/stdout/stderr. Each API request is asynchronous and the executable stays open as long as it has work to do, which is as long as either stdin is still open (meaning there may be more API requests) or there are currently requests being processed.

    Previously esbuild's tracking of outstanding API requests missed decrementing a reference count in an edge case where esbuild's JavaScript API was used incorrectly and the API request returned an error. This could in some cases cause esbuild's native executable to exit with an error message about a deadlock. This release fixes the reference counting bug.

    This fix was submitted by @​ZuBB.

  • Handle target collisions (#​4509)

    It's possible to specify the same target engine multiple times, such as with --target=chrome1,chrome99. This edge case wasn't anticipated and previously took the last version for the duplicated target engine instead of the minimum version (so chrome99 in this case instead of chrome1). With this release, esbuild will now pick the minimum version between all duplicated target engines.

  • Force .mp3 files to use the audio/mpeg MIME type (#​4485)

    MIME type detection for esbuild's data URLs uses Go's built-in MIME type detection, which is based on the MIME sniffing standard. This works correctly for MP3 files that start with the byte sequence ID3, which is commonly the case. However, it's possible to construct valid MP3 files that do not start with ID3, and that perhaps Go's built-in MIME type detection doesn't implement the "Signature for MP3 without ID3" part of the algorithm. This results in some .mp3 files incorrectly using the application/octet-stream MIME type instead of audio/mpeg. With this release, esbuild will now always use the audio/mpeg MIME type for files ending in .mp3.

  • Add a new TypeScript syntax warning

    TypeScript 7 turned some previously-valid TypeScript syntax into a syntax error because it was confusing. TypeScript 6 accepts 1 + 2 as number * 3 as valid syntax but confusingly converts it to (1 + 2) * 3 instead of the more intuitive conversion to 1 + (2 * 3). This syntax is now an error in TypeScript 7+. With this release, esbuild will now warn about the use of this syntax:

    ▲ [WARNING] Operator "*" should not directly follow a TypeScript type cast after the "+" operator [confusing-typescript-cast]
    
        example.ts:1:28:
          1 │ console.log(1 + 2 as number * 3)
            ╵                             ^
    
      This is a syntax error in newer versions of TypeScript because the type cast has unintuitive
      precedence in this case. Surround the inner expression in parentheses to silence this warning:
    
        example.ts:1:12:
          1 │ console.log(1 + 2 as number * 3)
            │             ~~~~~~~~~~~~~~~
            ╵             (             )
    

    See microsoft/TypeScript#63527 for more information.

  • Add support for formatting errors for Visual Studio (#​4460)

    Visual Studio has a specific style that it expects log messages to be in for them to show up in the UI when esbuild is run as a custom build step. The current log style that esbuild uses doesn't conform to this specific style.

    With this release, esbuild has a new log style for Visual Studio (and other tools in the MSBuild ecosystem) that can be enabled with --log-style=visualstudio. Here is an example log message in this style:

    $ esbuild example.ts --log-style=visualstudio
    /Users/evan/dev/esbuild/example.ts(1,29): warning ES0010: Operator "*" should not directly follow a TypeScript type cast after the "+" operator
    

    This log style is also available via the JS and Go APIs, and can now be used with the existing formatMessages API.

  • Fix a bug with CSS gamut mapping (#​4488)

    Due to a typo, the fallback colors generated for CSS colors outside of the sRGB gamut weren't correct. This release fixes the generated colors to use the intended algorithm.

    This fix was submitted by @​chatman-media.

v0.28.1

Compare Source

  • Disallow \ in local development server HTTP requests (GHSA-g7r4-m6w7-qqqr)

    This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \ backslash character. It happened due to the use of Go's path.Clean() function, which only handles Unix-style / characters. HTTP requests with paths containing \ are no longer allowed.

    Thanks to @​dellalibera for reporting this issue.

  • Add integrity checks to the Deno API (GHSA-gv7w-rqvm-qjhr)

    The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.

    Note that esbuild's Deno API installs from registry.npmjs.org by default, but allows the NPM_CONFIG_REGISTRY environment variable to override this with a custom package registry. This change means that the esbuild executable served by NPM_CONFIG_REGISTRY must now match the expected content.

    Thanks to @​sondt99 for reporting this issue.

  • Avoid inlining using and await using declarations (#​4482)

    Previously esbuild's minifier sometimes incorrectly inlined using and await using declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for let and const declarations by avoiding doing it for var declarations, which no longer worked when more declaration types were added. Here's an example:

    // Original code
    {
      using x = new Resource()
      x.activate()
    }
    
    // Old output (with --minify)
    new Resource().activate();
    
    // New output (with --minify)
    {using e=new Resource;e.activate()}
  • Fix module evaluation when an error is thrown (#​4461, #​4467)

    If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if import() or require() is used to import a module multiple times. The thrown error is supposed to be thrown by every call to import() or require(), not just the first. With this release, esbuild will now throw the same error every time you call import() or require() on a module that throws during its evaluation.

  • Fix some edge cases around the new operator (#​4477)

    Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a new expression (specifically an optional chain and/or a tagged template literal). The generated code for the new target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the new target in parentheses. Here is an example of some affected code:

    // Original code
    new (foo()`bar`)()
    new (foo()?.bar)()
    
    // Old output
    new foo()`bar`();
    new (foo())?.bar();
    
    // New output
    new (foo())`bar`();
    new (foo()?.bar)();
  • Fix renaming of nested var declarations (#​4471)

    This release fixes a bug where var declarations in nested scopes that are hoisted up to module scope were not correctly being renamed during bundling. That could previously lead to name collisions when minification was disabled, which could potentially cause a behavior change. The bug has been fixed so that these hoisted declarations are now considered to be module-level symbols during the name collision avoidance pass.

  • Emit var instead of const for certain TypeScript-only constructs for ES5 (#​4448)

    While esbuild doesn't generally support converting const to var for ES5 due to nested scoping rules (which is currently a build-time error), esbuild previously incorrectly converted TypeScript-only import assignment constructs into a const declaration even when targeting ES5. With this release, esbuild will now use var for this case instead:

    // Original code
    import x = require('y')
    
    // Old output (with --target=es5)
    const x = require("y");
    
    // New output (with --target=es5)
    var x = require("y");
tdewolff/parse (github.com/tdewolff/parse/v2)

v2.8.16

Compare Source

v2.8.15

Compare Source

v2.8.14

Compare Source

v2.8.13

Compare Source

golangci/golangci-lint (golangci/golangci-lint)

v2.12.2

Compare Source

Released on 2026-05-06

  1. Linters bug fixes
    • gomodguard_v2: fix blocked configuration
    • gomodguard_v2: from 2.1.0 to 2.1.3
    • iface: from 1.4.1 to 1.4.2

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency golangci/golangci-lint to v2.12.2 fix(deps): update all non-major dependencies May 8, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from e7c8efc to 81a9fe6 Compare May 10, 2026 12:56
@renovate

renovate Bot commented May 10, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: e2e/testdata/catchallapp/go.sum
Command failed: go get -t ./...
go: downloading github.com/a-h/templ v0.3.1020
go: downloading github.com/nicksnyder/go-i18n/v2 v2.6.1
go: downloading golang.org/x/text v0.36.0
go: example.com/no-js-e2e/catchallapp/cmd/server imports
	example.com/no-js-e2e/catchallapp/web/generated: cannot find module providing package example.com/no-js-e2e/catchallapp/web/generated

File name: e2e/testdata/clientassetsapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/clientassetsapp/cmd/server imports
	example.com/no-js-e2e/clientassetsapp/web/generated: cannot find module providing package example.com/no-js-e2e/clientassetsapp/web/generated

File name: e2e/testdata/clientassetsslotgroupapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/clientassetsslotgroupapp/cmd/server imports
	example.com/no-js-e2e/clientassetsslotgroupapp/web/generated: cannot find module providing package example.com/no-js-e2e/clientassetsslotgroupapp/web/generated

File name: e2e/testdata/customruntimeapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/customruntimeapp/cmd/server imports
	example.com/no-js-e2e/customruntimeapp/web/generated: cannot find module providing package example.com/no-js-e2e/customruntimeapp/web/generated

File name: e2e/testdata/docsfeatureapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/docsfeatureapp/cmd/server imports
	example.com/no-js-e2e/docsfeatureapp/web/generated: cannot find module providing package example.com/no-js-e2e/docsfeatureapp/web/generated
go: example.com/no-js-e2e/docsfeatureapp/web/resolvers imports
	example.com/no-js-e2e/docsfeatureapp/web/generated/i18n: cannot find module providing package example.com/no-js-e2e/docsfeatureapp/web/generated/i18n
go: example.com/no-js-e2e/docsfeatureapp/web/view imports
	example.com/no-js-e2e/docsfeatureapp/web/components/profile: cannot find module providing package example.com/no-js-e2e/docsfeatureapp/web/components/profile
go: example.com/no-js-e2e/docsfeatureapp/web/view imports
	example.com/no-js-e2e/docsfeatureapp/web/generated/i18n/messages: cannot find module providing package example.com/no-js-e2e/docsfeatureapp/web/generated/i18n/messages

File name: e2e/testdata/groupednamespaceapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/groupednamespaceapp/cmd/server imports
	example.com/no-js-e2e/groupednamespaceapp/web/generated: cannot find module providing package example.com/no-js-e2e/groupednamespaceapp/web/generated
go: example.com/no-js-e2e/groupednamespaceapp/web/view imports
	example.com/no-js-e2e/groupednamespaceapp/web/components/discovercard: cannot find module providing package example.com/no-js-e2e/groupednamespaceapp/web/components/discovercard

File name: e2e/testdata/i18nprefixalwaysapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/i18nprefixalwaysapp/cmd/server imports
	example.com/no-js-e2e/i18nprefixalwaysapp/web/generated: cannot find module providing package example.com/no-js-e2e/i18nprefixalwaysapp/web/generated
go: example.com/no-js-e2e/i18nprefixalwaysapp/web/resolvers imports
	example.com/no-js-e2e/i18nprefixalwaysapp/web/generated/i18n: cannot find module providing package example.com/no-js-e2e/i18nprefixalwaysapp/web/generated/i18n
go: example.com/no-js-e2e/i18nprefixalwaysapp/web/view imports
	example.com/no-js-e2e/i18nprefixalwaysapp/web/generated/i18n/messages: cannot find module providing package example.com/no-js-e2e/i18nprefixalwaysapp/web/generated/i18n/messages

File name: e2e/testdata/methodmatrixapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/methodmatrixapp/cmd/server imports
	example.com/no-js-e2e/methodmatrixapp/web/generated: cannot find module providing package example.com/no-js-e2e/methodmatrixapp/web/generated

File name: e2e/testdata/namespacedtemplcssapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/namespacedtemplcssapp/cmd/server imports
	example.com/no-js-e2e/namespacedtemplcssapp/web/generated: cannot find module providing package example.com/no-js-e2e/namespacedtemplcssapp/web/generated
go: example.com/no-js-e2e/namespacedtemplcssapp/web/view imports
	example.com/no-js-e2e/namespacedtemplcssapp/web/components/statchip: cannot find module providing package example.com/no-js-e2e/namespacedtemplcssapp/web/components/statchip

File name: e2e/testdata/notfoundmetadataapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/notfoundmetadataapp/cmd/server imports
	example.com/no-js-e2e/notfoundmetadataapp/web/generated: cannot find module providing package example.com/no-js-e2e/notfoundmetadataapp/web/generated

File name: e2e/testdata/optionalcatchallapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/optionalcatchallapp/cmd/server imports
	example.com/no-js-e2e/optionalcatchallapp/web/generated: cannot find module providing package example.com/no-js-e2e/optionalcatchallapp/web/generated

File name: e2e/testdata/routepagecssapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/routepagecssapp/cmd/server imports
	example.com/no-js-e2e/routepagecssapp/web/generated: cannot find module providing package example.com/no-js-e2e/routepagecssapp/web/generated

File name: e2e/testdata/templcssapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/templcssapp/cmd/server imports
	example.com/no-js-e2e/templcssapp/web/generated: cannot find module providing package example.com/no-js-e2e/templcssapp/web/generated
go: example.com/no-js-e2e/templcssapp/web/view imports
	example.com/no-js-e2e/templcssapp/web/components/hero: cannot find module providing package example.com/no-js-e2e/templcssapp/web/components/hero

File name: e2e/testdata/templrulesapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/templrulesapp/cmd/server imports
	example.com/no-js-e2e/templrulesapp/web/generated: cannot find module providing package example.com/no-js-e2e/templrulesapp/web/generated
go: example.com/no-js-e2e/templrulesapp/web/view imports
	example.com/no-js-e2e/templrulesapp/web/components/progress: cannot find module providing package example.com/no-js-e2e/templrulesapp/web/components/progress

File name: e2e/testdata/typedmodelsapp/go.sum
Command failed: go get -t ./...
go: example.com/no-js-e2e/typedmodelsapp/cmd/server imports
	example.com/no-js-e2e/typedmodelsapp/web/generated: cannot find module providing package example.com/no-js-e2e/typedmodelsapp/web/generated

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 81a9fe6 to e157a5b Compare May 27, 2026 17:15
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 47a0677 to c6c557f Compare June 15, 2026 07:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 091bcdf to 9e23bd3 Compare July 12, 2026 10:04
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 12a0148 to 879a475 Compare July 31, 2026 11:47
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 5d65bb2 to a608d36 Compare August 8, 2026 21:17
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from a608d36 to ed55276 Compare August 10, 2026 23:06
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from ed55276 to b5f74e5 Compare August 11, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants