Update non-major dependencies #32

Merged
renovate merged 1 commit from renovate/non-major-dependencies into main 2026-07-18 02:14:39 +02:00
Owner

This PR contains the following updates:

Package Change Age Confidence
@expressive-code/plugin-line-numbers (source) ^0.43.0^0.44.0 age confidence
@types/hast (source) 3.0.43.0.5 age confidence
astro-expressive-code (source) ^0.43.0^0.44.0 age confidence
markdown-it 14.2.014.3.0 age confidence
prettier (source) 3.8.43.9.5 age confidence
sanitize-html (source) 2.17.52.17.6 age confidence
satori ^0.26.0^0.28.0 age confidence

Release Notes

expressive-code/expressive-code (@​expressive-code/plugin-line-numbers)

v0.44.0

Compare Source

Patch Changes
expressive-code/expressive-code (astro-expressive-code)

v0.44.0

Compare Source

Minor Changes
  • 9169010: Adds support for Astro v7 and Sätteri v0.9
Patch Changes
  • rehype-expressive-code@​0.44.0
markdown-it/markdown-it (markdown-it)

v14.3.0

Compare Source

Changed
  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.
Fixed
  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #​1185.
prettier/prettier (prettier)

v3.9.5

Compare Source

diff

Markdown: Cap ordered list mark at 999,999,999 (#​19351 by @​tats-u)

CommonMark parsers only support ordered list item numbers up to 999,999,999.

With this change, Prettier now caps the ordered list item number at 999,999,999 to ensure that the output is correctly parsed as an ordered list by CommonMark parsers. Numbers larger than 999,999,999 are not parsed as list item numbers and are left unchanged in the output:

<!-- Input -->
999999998. text
999999998. text
999999998. text
999999998. text

1234567890123456789012) text

<!-- Prettier 3.9.4 -->
999999998. text
999999999. text
1000000000. text
1000000001. text

1234567890123456789012) text

<!-- Prettier 3.9.5 -->
999999998. text
999999999. text
999999999. text
999999999. text

1234567890123456789012) text

Do not remove <> from an inline link or image with an empty URL and a title, as this removal would change its interpretation.

<!-- Input -->
[link](<> "title")

<!-- Prettier 3.9.4 -->
[link]( "title")

<!-- Prettier 3.9.5 -->
[link](<> "title")
Less: Remove extra spaces after [ in map lookups (#​19503 by @​kovsu)
// Input
.foo {
  color: #theme[ primary];
  color: #theme[@&#8203;name];
  color: #theme[@&#8203;@&#8203;name];
}

// Prettier 3.9.4
.foo {
  color: #theme[ primary];
  color: #theme[ @&#8203;name];
  color: #theme[ @&#8203;@&#8203;name];
}

// Prettier 3.9.5
.foo {
  color: #theme[primary];
  color: #theme[@&#8203;name];
  color: #theme[@&#8203;@&#8203;name];
}
CSS: Prevent addition space in type() with + (#​19516 by @​bigandy)

This fixes the addition space before + in CSS type() declaration. For example type(<number>+) was being converted into type(<number> +) which is invalid CSS and does not work.

/* Input */
div {
  border-radius: attr(br type(<length>+));
}

/* Prettier 3.9.4 */
div {
  border-radius: attr(br type(<length> +));
}

/* Prettier 3.9.5 */
div {
  border-radius: attr(br type(<length>+));
}
Less: Remove spaces between merge markers and colons (#​19517 by @​kovsu)
// Input
a {
  box-shadow  +  : 0 0 1px #&#8203;000;
}

// Prettier 3.9.4
a {
  box-shadow+  : 0 0 1px #&#8203;000;
}

// Prettier 3.9.5
a {
  box-shadow+: 0 0 1px #&#8203;000;
}
<!-- Input -->
[[Foo:Bar]]

<!-- Prettier 3.9.4 -->
[[Foo]]

<!-- Prettier 3.9.5 -->
[[Foo:Bar]]
TypeScript: Fix comments being dropped on shorthand type import/export specifiers (#​19565 by @​kirkwaiblinger)
// Input
export { type /* comment */ T } from "foo";
import { type /* comment */ T } from "foo";

// Prettier 3.9.4
Error: Comment "comment" was not printed. Please report this error!

// Prettier 3.9.5
export { type /* comment */ T } from "foo";
import { type /* comment */ T } from "foo";
Miscellaneous: Preserving comments' placement property (#​19567 by @​Janther)

Prettier@​3.9.0 deleted an undocumented property on comments, which was already used by plugins, comment.placement is now available again after comment attach.

Flow: Stop enforcing empty module declaration to break (#​19568 by @​fisker)
// Input
declare module "foo" {}

// Prettier 3.9.4
declare module "foo" {
}

// Prettier 3.9.5
declare module "foo" {}
Angular: Support expression for exhaustive typechecking (#​19571 by @​fisker)
<!-- Input -->
@&#8203;switch (state.mode) {
  @&#8203;default never(state);
}

<!-- Prettier 3.9.4 -->
@&#8203;switch (state.mode) {
  @&#8203;default never;
}

<!-- Prettier 3.9.5 -->
@&#8203;switch (state.mode) {
  @&#8203;default never(state);
}
TypeScript: Ignore comments inside mapped type when checking type parameter comments (#​19572 by @​fisker)
// Input
foo<{
  // comment
  [key in keyof Foo]: number
}>();

// Prettier 3.9.4
foo<
  {
    // comment
    [key in keyof Foo]: number;
  }
>();

// Prettier 3.9.5
foo<{
  // comment
  [key in keyof Foo]: number;
}>();
Less: Fix adjacent block comments being corrupted (#​19574 by @​kovsu)
// Input
/* a *//* b */
/* a */* {
  color: red;
}

// Prettier 3.9.4
/* a */
/* b */
/* a * {
  color: red;
}

// Prettier 3.9.5
/* a */ /* b */
/* a */
* {
  color: red;
}
JavaScript: Handle dangling comments in SwitchStatement (#​19581 by @​fisker)
// Input
switch (foo) {
 // comment
}

// Prettier 3.9.4
switch (
  foo
  // comment
) {
}

// Prettier 3.9.5
switch (foo) {
  // comment
}
TypeScript: Remove space in comment-only object type (#​19583 by @​fisker)
// Input
var foo = {
  /* comment */
};
type Foo = {
  /* comment */
};

// Prettier 3.9.4
var foo = {/* comment */};
type Foo = { /* comment */ };

// Prettier 3.9.5
var foo = {/* comment */};
type Foo = {/* comment */};

v3.9.4

Compare Source

diff

Angular: Format @content(name) -> @content (name) to align with other block syntax (#​19499 by @​fisker)
<!-- Input -->
<FancyButton [label]="title">
  @&#8203;content (icon) {
    <span>Icon!</span>
  }
  @&#8203;content (description) {
    <span>Description text</span>
  }
  <span>Other children</span>
</FancyButton>

<!-- Prettier 3.9.3 -->
<FancyButton [label]="title">
  @&#8203;content(icon) {
    <span>Icon!</span>
  }
  @&#8203;content(description) {
    <span>Description text</span>
  }
  <span>Other children</span>
</FancyButton>

<!-- Prettier 3.9.4 -->
<FancyButton [label]="title">
  @&#8203;content (icon) {
    <span>Icon!</span>
  }
  @&#8203;content (description) {
    <span>Description text</span>
  }
  <span>Other children</span>
</FancyButton>

v3.9.3

Compare Source

diff

Markdown: Fix unexpected removal of characters in liquid syntax (#​19489 by @​seiyab)
// Input
<!-- Input -->
{{ page.title
}} text

<!-- Prettier 3.9.1 -->
{{ page.title
 text

<!-- Prettier 3.9.3 -->
{{ page.title
}} text
TypeScript: Allow decorators to be used with declare on class fields (#​19492 by @​evoactivity)

Extensively used within the Ember ecosystem, decorators with declare on class fields will ignore the babel parser error and allow Prettier to format the code without breaking it.

// Input
export default class ProjectStatusComponent extends Component<ProjectStatusSig> {
  @&#8203;service declare server: ServerService;
}

// Prettier 3.9.1
// SyntaxError: Decorators can't be used with a declare field. (2:3)
//  1 | export default class ProjectStatusComponent extends Component<ProjectStatusSig> {
//> 2 |   @&#8203;service declare server: ServerService;
//    |   ^
//  3 | }

// Prettier 3.9.3
export default class ProjectStatusComponent extends Component<ProjectStatusSig> {
  @&#8203;service declare server: ServerService;
}

v3.9.2

Compare Source

v3.9.1

Compare Source

diff

CLI: Fix ignored file has been cached incorrectly (#​19483 by @​kovsu)

Bug details #​18016

v3.9.0

Compare Source

diff

🔗 Release Notes

v3.8.5

Compare Source

diff

Flow: Support readonly as a variance annotation (#​19022 by @​marcoww6)

Flow now accepts readonly as a property variance annotation, equivalent to + (covariant/read-only).

// Input
type T = {
  readonly foo: string,
};

// Prettier 3.8.4
SyntaxError

// Prettier 3.8.5
type T = {
  readonly foo: string,
};
apostrophecms/apostrophe (sanitize-html)

v2.17.6

Fixes
  • Allow transformTags to emit text when textFilter is set, even if the tag is initially empty. This is consistent with the documentation. Thanks to spokodev for the fix.
Security
  • Fixed an XSS/allowlist bypass in which the contents of a raw-text element (textarea or xmp) nested inside an svg or math root were re-emitted without HTML-escaping. sanitize-html treated that content as inert raw text because htmlparser2 10.x classified raw-text elements by tag name and ignored the namespace, but a real HTML5 parser treats textarea/xmp as ordinary foreign elements inside SVG/MathML and re-parses their contents as live markup. As a result, markup and event-handler attributes that the allowlist never permitted (for example <svg><textarea><img src=x onerror=alert(1)>) could survive sanitization and execute in the browser. This is now fixed on two fronts: htmlparser2 was upgraded to 12.x, which is namespace-aware and parses textarea/xmp inside SVG/MathML as ordinary elements, so their non-allowlisted children (such as the injected img) are dropped by the allowlist instead of being preserved as raw text; and any raw-text content sanitize-html still emits for these tags (at HTML integration points such as foreignObject/mtext, or outside foreign content) is always HTML-escaped. The default configuration is not affected; the precondition is an allowedTags that includes svg or math together with textarea or xmp. Thanks to khoadb175 for responsibly disclosing the vulnerability.
  • Fixed a mutation-XSS / allowedTags bypass affecting configurations that allow the textarea or xmp raw-text tags. htmlparser2 10.x did not recognize an end tag with a trailing solidus (e.g. </textarea/>) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats </textarea/> as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as <textarea></textarea/><img src=x onerror=...> could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: htmlparser2 was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no < can reopen a tag when the output is re-parsed (textarea, an RCDATA element whose entities htmlparser2 decodes, is escaped like normal text, while xmp, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because htmlparser2 is ESM-only from version 11 onward, sanitize-html now requires Node.js >=22.12.0 (the first 22.x release in which require() of an ES module is available unflagged). Thanks to bibu123456 for reporting the vulnerability and Kayiz-PT for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).
vercel/satori (satori)

v0.28.0

Compare Source

Features

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@expressive-code/plugin-line-numbers](https://github.com/expressive-code/expressive-code) ([source](https://github.com/expressive-code/expressive-code/tree/HEAD/packages/@expressive-code/plugin-line-numbers)) | [`^0.43.0` → `^0.44.0`](https://renovatebot.com/diffs/npm/@expressive-code%2fplugin-line-numbers/0.43.1/0.44.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@expressive-code%2fplugin-line-numbers/0.44.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@expressive-code%2fplugin-line-numbers/0.43.1/0.44.0?slim=true) | | [@types/hast](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/hast) ([source](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/hast)) | [`3.0.4` → `3.0.5`](https://renovatebot.com/diffs/npm/@types%2fhast/3.0.4/3.0.5) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@types%2fhast/3.0.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@types%2fhast/3.0.4/3.0.5?slim=true) | | [astro-expressive-code](https://github.com/expressive-code/expressive-code) ([source](https://github.com/expressive-code/expressive-code/tree/HEAD/packages/astro-expressive-code)) | [`^0.43.0` → `^0.44.0`](https://renovatebot.com/diffs/npm/astro-expressive-code/0.43.1/0.44.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/astro-expressive-code/0.44.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/astro-expressive-code/0.43.1/0.44.0?slim=true) | | [markdown-it](https://github.com/markdown-it/markdown-it) | [`14.2.0` → `14.3.0`](https://renovatebot.com/diffs/npm/markdown-it/14.2.0/14.3.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/markdown-it/14.3.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/markdown-it/14.2.0/14.3.0?slim=true) | | [prettier](https://prettier.io) ([source](https://github.com/prettier/prettier)) | [`3.8.4` → `3.9.5`](https://renovatebot.com/diffs/npm/prettier/3.8.4/3.9.5) | ![age](https://developer.mend.io/api/mc/badges/age/npm/prettier/3.9.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/prettier/3.8.4/3.9.5?slim=true) | | [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/main/packages/sanitize-html#readme) ([source](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html)) | [`2.17.5` → `2.17.6`](https://renovatebot.com/diffs/npm/sanitize-html/2.17.5/2.17.6) | ![age](https://developer.mend.io/api/mc/badges/age/npm/sanitize-html/2.17.6?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/sanitize-html/2.17.5/2.17.6?slim=true) | | [satori](https://github.com/vercel/satori) | [`^0.26.0` → `^0.28.0`](https://renovatebot.com/diffs/npm/satori/0.26.0/0.28.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/satori/0.28.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/satori/0.26.0/0.28.0?slim=true) | --- ### Release Notes <details> <summary>expressive-code/expressive-code (@&#8203;expressive-code/plugin-line-numbers)</summary> ### [`v0.44.0`](https://github.com/expressive-code/expressive-code/blob/HEAD/packages/@&#8203;expressive-code/plugin-line-numbers/CHANGELOG.md#0440) [Compare Source](https://github.com/expressive-code/expressive-code/compare/@expressive-code/plugin-line-numbers@0.43.1...@expressive-code/plugin-line-numbers@0.44.0) ##### Patch Changes - [@&#8203;expressive-code/core](https://github.com/expressive-code/core)@&#8203;0.44.0 </details> <details> <summary>expressive-code/expressive-code (astro-expressive-code)</summary> ### [`v0.44.0`](https://github.com/expressive-code/expressive-code/blob/HEAD/packages/astro-expressive-code/CHANGELOG.md#0440) [Compare Source](https://github.com/expressive-code/expressive-code/compare/astro-expressive-code@0.43.1...astro-expressive-code@0.44.0) ##### Minor Changes - [`9169010`](https://github.com/expressive-code/expressive-code/commit/9169010): Adds support for Astro v7 and Sätteri v0.9 ##### Patch Changes - rehype-expressive-code\@&#8203;0.44.0 </details> <details> <summary>markdown-it/markdown-it (markdown-it)</summary> ### [`v14.3.0`](https://github.com/markdown-it/markdown-it/blob/HEAD/CHANGELOG.md#1430---2026-07-02) [Compare Source](https://github.com/markdown-it/markdown-it/compare/14.2.0...14.3.0) ##### Changed - Reworked build pipeline & tools. - Added source maps. - Bumped `linkify-it` to 5.0.2. ##### Fixed - Preserve backslash-space hard line breaks, matching CommonMark 6.7, [#&#8203;1185](https://github.com/markdown-it/markdown-it/issues/1185). </details> <details> <summary>prettier/prettier (prettier)</summary> ### [`v3.9.5`](https://github.com/prettier/prettier/blob/HEAD/CHANGELOG.md#395) [Compare Source](https://github.com/prettier/prettier/compare/3.9.4...3.9.5) [diff](https://github.com/prettier/prettier/compare/3.9.4...3.9.5) ##### Markdown: Cap ordered list mark at 999,999,999 ([#&#8203;19351](https://github.com/prettier/prettier/pull/19351) by [@&#8203;tats-u](https://github.com/tats-u)) CommonMark parsers only support ordered list item numbers up to 999,999,999. With this change, Prettier now caps the ordered list item number at 999,999,999 to ensure that the output is correctly parsed as an ordered list by CommonMark parsers. Numbers larger than 999,999,999 are not parsed as list item numbers and are left unchanged in the output: <!-- prettier-ignore --> ```markdown <!-- Input --> 999999998. text 999999998. text 999999998. text 999999998. text 1234567890123456789012) text <!-- Prettier 3.9.4 --> 999999998. text 999999999. text 1000000000. text 1000000001. text 1234567890123456789012) text <!-- Prettier 3.9.5 --> 999999998. text 999999999. text 999999999. text 999999999. text 1234567890123456789012) text ``` ##### Markdown: Avoid corrupting empty link with title ([#&#8203;19487](https://github.com/prettier/prettier/pull/19487) by [@&#8203;andersk](https://github.com/andersk)) Do not remove `<>` from an inline link or image with an empty URL and a title, as this removal would change its interpretation. <!-- prettier-ignore --> ```md <!-- Input --> [link](<> "title") <!-- Prettier 3.9.4 --> [link]( "title") <!-- Prettier 3.9.5 --> [link](<> "title") ``` ##### Less: Remove extra spaces after `[` in map lookups ([#&#8203;19503](https://github.com/prettier/prettier/pull/19503) by [@&#8203;kovsu](https://github.com/kovsu)) <!-- prettier-ignore --> ```less // Input .foo { color: #theme[ primary]; color: #theme[@&#8203;name]; color: #theme[@&#8203;@&#8203;name]; } // Prettier 3.9.4 .foo { color: #theme[ primary]; color: #theme[ @&#8203;name]; color: #theme[ @&#8203;@&#8203;name]; } // Prettier 3.9.5 .foo { color: #theme[primary]; color: #theme[@&#8203;name]; color: #theme[@&#8203;@&#8203;name]; } ``` ##### CSS: Prevent addition space in `type()` with `+` ([#&#8203;19516](https://github.com/prettier/prettier/pull/19516) by [@&#8203;bigandy](https://github.com/bigandy)) This fixes the addition space before `+` in CSS `type()` declaration. For example `type(<number>+)` was being converted into `type(<number> +)` which is invalid CSS and does not work. <!-- prettier-ignore --> ```css /* Input */ div { border-radius: attr(br type(<length>+)); } /* Prettier 3.9.4 */ div { border-radius: attr(br type(<length> +)); } /* Prettier 3.9.5 */ div { border-radius: attr(br type(<length>+)); } ``` ##### Less: Remove spaces between merge markers and colons ([#&#8203;19517](https://github.com/prettier/prettier/pull/19517) by [@&#8203;kovsu](https://github.com/kovsu)) <!-- prettier-ignore --> ```less // Input a { box-shadow + : 0 0 1px #&#8203;000; } // Prettier 3.9.4 a { box-shadow+ : 0 0 1px #&#8203;000; } // Prettier 3.9.5 a { box-shadow+: 0 0 1px #&#8203;000; } ``` ##### Markdown: Preserve wiki links with aliases ([#&#8203;19527](https://github.com/prettier/prettier/pull/19527) by [@&#8203;kovsu](https://github.com/kovsu)) <!-- prettier-ignore --> ```markdown <!-- Input --> [[Foo:Bar]] <!-- Prettier 3.9.4 --> [[Foo]] <!-- Prettier 3.9.5 --> [[Foo:Bar]] ``` ##### TypeScript: Fix comments being dropped on shorthand `type` import/export specifiers ([#&#8203;19565](https://github.com/prettier/prettier/pull/19565) by [@&#8203;kirkwaiblinger](https://github.com/kirkwaiblinger)) <!-- prettier-ignore --> ```tsx // Input export { type /* comment */ T } from "foo"; import { type /* comment */ T } from "foo"; // Prettier 3.9.4 Error: Comment "comment" was not printed. Please report this error! // Prettier 3.9.5 export { type /* comment */ T } from "foo"; import { type /* comment */ T } from "foo"; ``` ##### Miscellaneous: Preserving comments' `placement` property ([#&#8203;19567](https://github.com/prettier/prettier/pull/19567) by [@&#8203;Janther](https://github.com/Janther)) Prettier\@&#8203;3.9.0 deleted an undocumented property on comments, which was already used by plugins, `comment.placement` is now available again after comment attach. ##### Flow: Stop enforcing empty module declaration to break ([#&#8203;19568](https://github.com/prettier/prettier/pull/19568) by [@&#8203;fisker](https://github.com/fisker)) <!-- prettier-ignore --> ```flow // Input declare module "foo" {} // Prettier 3.9.4 declare module "foo" { } // Prettier 3.9.5 declare module "foo" {} ``` ##### Angular: Support expression for exhaustive typechecking ([#&#8203;19571](https://github.com/prettier/prettier/pull/19571) by [@&#8203;fisker](https://github.com/fisker)) <!-- prettier-ignore --> ```html <!-- Input --> @&#8203;switch (state.mode) { @&#8203;default never(state); } <!-- Prettier 3.9.4 --> @&#8203;switch (state.mode) { @&#8203;default never; } <!-- Prettier 3.9.5 --> @&#8203;switch (state.mode) { @&#8203;default never(state); } ``` ##### TypeScript: Ignore comments inside mapped type when checking type parameter comments ([#&#8203;19572](https://github.com/prettier/prettier/pull/19572) by [@&#8203;fisker](https://github.com/fisker)) <!-- prettier-ignore --> ```tsx // Input foo<{ // comment [key in keyof Foo]: number }>(); // Prettier 3.9.4 foo< { // comment [key in keyof Foo]: number; } >(); // Prettier 3.9.5 foo<{ // comment [key in keyof Foo]: number; }>(); ``` ##### Less: Fix adjacent block comments being corrupted ([#&#8203;19574](https://github.com/prettier/prettier/pull/19574) by [@&#8203;kovsu](https://github.com/kovsu)) <!-- prettier-ignore --> ```less // Input /* a *//* b */ /* a */* { color: red; } // Prettier 3.9.4 /* a */ /* b */ /* a * { color: red; } // Prettier 3.9.5 /* a */ /* b */ /* a */ * { color: red; } ``` ##### JavaScript: Handle dangling comments in `SwitchStatement` ([#&#8203;19581](https://github.com/prettier/prettier/pull/19581) by [@&#8203;fisker](https://github.com/fisker)) <!-- prettier-ignore --> ```jsx // Input switch (foo) { // comment } // Prettier 3.9.4 switch ( foo // comment ) { } // Prettier 3.9.5 switch (foo) { // comment } ``` ##### TypeScript: Remove space in comment-only object type ([#&#8203;19583](https://github.com/prettier/prettier/pull/19583) by [@&#8203;fisker](https://github.com/fisker)) <!-- prettier-ignore --> ```tsx // Input var foo = { /* comment */ }; type Foo = { /* comment */ }; // Prettier 3.9.4 var foo = {/* comment */}; type Foo = { /* comment */ }; // Prettier 3.9.5 var foo = {/* comment */}; type Foo = {/* comment */}; ``` ### [`v3.9.4`](https://github.com/prettier/prettier/blob/HEAD/CHANGELOG.md#394) [Compare Source](https://github.com/prettier/prettier/compare/3.9.3...3.9.4) [diff](https://github.com/prettier/prettier/compare/3.9.3...3.9.4) ##### Angular: Format `@content(name)` -> `@content (name)` to align with other block syntax ([#&#8203;19499](https://github.com/prettier/prettier/pull/19499) by [@&#8203;fisker](https://github.com/fisker)) <!-- prettier-ignore --> ```html <!-- Input --> <FancyButton [label]="title"> @&#8203;content (icon) { <span>Icon!</span> } @&#8203;content (description) { <span>Description text</span> } <span>Other children</span> </FancyButton> <!-- Prettier 3.9.3 --> <FancyButton [label]="title"> @&#8203;content(icon) { <span>Icon!</span> } @&#8203;content(description) { <span>Description text</span> } <span>Other children</span> </FancyButton> <!-- Prettier 3.9.4 --> <FancyButton [label]="title"> @&#8203;content (icon) { <span>Icon!</span> } @&#8203;content (description) { <span>Description text</span> } <span>Other children</span> </FancyButton> ``` ### [`v3.9.3`](https://github.com/prettier/prettier/blob/HEAD/CHANGELOG.md#393) [Compare Source](https://github.com/prettier/prettier/compare/3.9.2...3.9.3) [diff](https://github.com/prettier/prettier/compare/3.9.1...3.9.3) ##### Markdown: Fix unexpected removal of characters in liquid syntax ([#&#8203;19489](https://github.com/prettier/prettier/pull/19489) by [@&#8203;seiyab](https://github.com/seiyab)) <!-- prettier-ignore --> ```md // Input <!-- Input --> {{ page.title }} text <!-- Prettier 3.9.1 --> {{ page.title text <!-- Prettier 3.9.3 --> {{ page.title }} text ``` ##### TypeScript: Allow decorators to be used with declare on class fields ([#&#8203;19492](https://github.com/prettier/prettier/pull/19492) by [@&#8203;evoactivity](https://github.com/evoactivity)) Extensively used within the Ember ecosystem, decorators with `declare` on class fields will ignore the babel parser error and allow Prettier to format the code without breaking it. <!-- prettier-ignore --> ```ts // Input export default class ProjectStatusComponent extends Component<ProjectStatusSig> { @&#8203;service declare server: ServerService; } // Prettier 3.9.1 // SyntaxError: Decorators can't be used with a declare field. (2:3) // 1 | export default class ProjectStatusComponent extends Component<ProjectStatusSig> { //> 2 | @&#8203;service declare server: ServerService; // | ^ // 3 | } // Prettier 3.9.3 export default class ProjectStatusComponent extends Component<ProjectStatusSig> { @&#8203;service declare server: ServerService; } ``` ### [`v3.9.2`](https://github.com/prettier/prettier/compare/3.9.1...3.9.2) [Compare Source](https://github.com/prettier/prettier/compare/3.9.1...3.9.2) ### [`v3.9.1`](https://github.com/prettier/prettier/blob/HEAD/CHANGELOG.md#391) [Compare Source](https://github.com/prettier/prettier/compare/3.9.0...3.9.1) [diff](https://github.com/prettier/prettier/compare/3.9.0...3.9.1) ##### CLI: Fix ignored file has been cached incorrectly ([#&#8203;19483](https://github.com/prettier/prettier/pull/19483) by [@&#8203;kovsu](https://github.com/kovsu)) Bug details [#&#8203;18016](https://github.com/prettier/prettier/issues/18016) ### [`v3.9.0`](https://github.com/prettier/prettier/blob/HEAD/CHANGELOG.md#390) [Compare Source](https://github.com/prettier/prettier/compare/3.8.5...3.9.0) [diff](https://github.com/prettier/prettier/compare/3.8.5...3.9.0) 🔗 [Release Notes](https://prettier.io/blog/2026/06/27/3.9.0) ### [`v3.8.5`](https://github.com/prettier/prettier/blob/HEAD/CHANGELOG.md#385) [Compare Source](https://github.com/prettier/prettier/compare/3.8.4...3.8.5) [diff](https://github.com/prettier/prettier/compare/3.8.4...3.8.5) ##### Flow: Support `readonly` as a variance annotation ([#&#8203;19022](https://github.com/prettier/prettier/pull/19022) by [@&#8203;marcoww6](https://github.com/marcoww6)) Flow now accepts `readonly` as a property variance annotation, equivalent to `+` (covariant/read-only). <!-- prettier-ignore --> ```jsx // Input type T = { readonly foo: string, }; // Prettier 3.8.4 SyntaxError // Prettier 3.8.5 type T = { readonly foo: string, }; ``` </details> <details> <summary>apostrophecms/apostrophe (sanitize-html)</summary> ### [`v2.17.6`](https://github.com/apostrophecms/apostrophe/blob/HEAD/packages/sanitize-html/CHANGELOG.md#2176-2026-07-10) ##### Fixes - Allow transformTags to emit text when textFilter is set, even if the tag is initially empty. This is consistent with the documentation. Thanks to [spokodev](https://github.com/spokodev) for the fix. ##### Security - Fixed an XSS/allowlist bypass in which the contents of a raw-text element (`textarea` or `xmp`) nested inside an `svg` or `math` root were re-emitted without HTML-escaping. `sanitize-html` treated that content as inert raw text because `htmlparser2` 10.x classified raw-text elements by tag name and ignored the namespace, but a real HTML5 parser treats `textarea`/`xmp` as ordinary foreign elements inside SVG/MathML and re-parses their contents as live markup. As a result, markup and event-handler attributes that the allowlist never permitted (for example `<svg><textarea><img src=x onerror=alert(1)>`) could survive sanitization and execute in the browser. This is now fixed on two fronts: `htmlparser2` was upgraded to 12.x, which is namespace-aware and parses `textarea`/`xmp` inside SVG/MathML as ordinary elements, so their non-allowlisted children (such as the injected `img`) are dropped by the allowlist instead of being preserved as raw text; and any raw-text content `sanitize-html` still emits for these tags (at HTML integration points such as `foreignObject`/`mtext`, or outside foreign content) is always HTML-escaped. The default configuration is not affected; the precondition is an `allowedTags` that includes `svg` or `math` together with `textarea` or `xmp`. Thanks to [khoadb175](https://github.com/khoadb175) for responsibly disclosing the vulnerability. - Fixed a mutation-XSS / `allowedTags` bypass affecting configurations that allow the `textarea` or `xmp` raw-text tags. `htmlparser2` 10.x did not recognize an end tag with a trailing solidus (e.g. `</textarea/>`) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats `</textarea/>` as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as `<textarea></textarea/><img src=x onerror=...>` could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: `htmlparser2` was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no `<` can reopen a tag when the output is re-parsed (`textarea`, an RCDATA element whose entities `htmlparser2` decodes, is escaped like normal text, while `xmp`, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because `htmlparser2` is ESM-only from version 11 onward, `sanitize-html` now requires Node.js `>=22.12.0` (the first 22.x release in which `require()` of an ES module is available unflagged). Thanks to [bibu123456](https://github.com/bibu123456) for reporting the vulnerability and [Kayiz-PT](https://github.com/Kayiz-PT) for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw). </details> <details> <summary>vercel/satori (satori)</summary> ### [`v0.28.0`](https://github.com/vercel/satori/releases/tag/0.28.0) [Compare Source](https://github.com/vercel/satori/compare/0.26.0...0.28.0) ##### Features - trigger npm publish after OIDC fix ([#&#8203;771](https://github.com/vercel/satori/issues/771)) ([b5c1f64](https://github.com/vercel/satori/commit/b5c1f64543e5c3b313097795317c618cfeeac8ae)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIyMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
renovate scheduled this pull request to auto merge when all checks succeed 2026-07-15 02:14:27 +02:00
renovate force-pushed renovate/non-major-dependencies from 6979248459 to 6396e64490 2026-07-18 02:14:36 +02:00 Compare
renovate deleted branch renovate/non-major-dependencies 2026-07-18 02:14:39 +02:00
Sign in to join this conversation.
No description provided.