chore(deps): update npm dependencies updates - #204
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
November 20, 2025 00:55
39f0fd9 to
f5b15bb
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
December 3, 2025 01:04
f5b15bb to
a629a7e
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
December 17, 2025 02:34
8c289ab to
e7a71c7
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
3 times, most recently
from
December 24, 2025 10:02
31851de to
0ee70e4
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
December 31, 2025 14:39
4329ddc to
e1c7eee
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
4 times, most recently
from
January 11, 2026 09:46
7009660 to
b78b7a9
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
3 times, most recently
from
January 20, 2026 21:34
4a442f0 to
1aa61e9
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
4 times, most recently
from
February 5, 2026 22:55
acf96ce to
7af3e6e
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
3 times, most recently
from
February 17, 2026 21:34
b8c1dab to
aceca48
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
February 25, 2026 23:15
aceca48 to
180ca7e
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
March 5, 2026 20:07
180ca7e to
09cc0b8
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
March 13, 2026 22:52
ce89faa to
b9d8e4d
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
March 24, 2026 21:33
b9d8e4d to
fed8293
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
April 1, 2026 22:14
fed8293 to
7ede099
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
4 times, most recently
from
May 17, 2026 13:15
8d6d59e to
031f13c
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
3 times, most recently
from
May 28, 2026 18:33
db3a84b to
ce6f593
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
June 7, 2026 17:54
06a0b58 to
03567a3
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
June 9, 2026 19:45
03567a3 to
78651ec
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
from
June 23, 2026 21:34
78651ec to
2aef404
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
July 12, 2026 15:45
8d2090b to
2c234e9
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
3 times, most recently
from
July 21, 2026 17:57
ff846c4 to
3072937
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
July 30, 2026 16:37
2eef2e9 to
3298f3d
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
August 10, 2026 17:58
001d384 to
f523855
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
August 18, 2026 23:05
3252dc6 to
a41f731
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
August 26, 2026 19:41
c36e350 to
54b586e
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
3 times, most recently
from
September 9, 2026 16:57
8edf6b1 to
56b127a
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-updates
branch
2 times, most recently
from
September 16, 2026 09:50
5e5b91b to
7cc5473
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
17.2.*→17.4.*5.2.0→5.2.1Release Notes
motdotla/dotenv (dotenv)
v17.4.2Compare Source
Changed
v17.4.1Compare Source
Changed
injectingtoinjected(#1005)v17.4.0Compare Source
Added
skills/folder with focused agent skills:skills/dotenv/SKILL.md(core usage) andskills/dotenvx/SKILL.md(encryption, multiple environments, variable expansion) for AI coding agent discovery via the skills.sh ecosystem (npx skills add motdotla/dotenv)Changed
◇ injecting env (14) from .env(#1003)v17.3.1Compare Source
Changed
v17.3.0Compare Source
Added
Changed
v17.2.4Compare Source
Changed
DotenvPopulateInputacceptNodeJS.ProcessEnvtype (#915)kucherenko/jscpd (jscpd)
v5.2.1Compare Source
New Features
--history: duplication trend over git history —jscpd src --history v5.0.0..HEADscans every commit in the range in a detached worktree and prints a bar chart, a per-commit table with the change between points, the overall trend and how far--thresholdcould be tightened without failing the build.--history-since,--history-every Nand--history-limit Nnarrow the range; the JSON reporter carries the points under ahistorykey and the GitHub Action takes ahistoryinput. (#1002, #1050, #1052)--fail-on-empty— an unknown--format, a scan path that does not exist and a reporter that cannot write its file now print an error and exit 1 instead of passing with an empty report.--fail-on-empty(config keyfailOnEmpty, action inputfail-on-empty) turns "analyzed no files" into a failure, so a mistyped path or an over-broad ignore cannot look like a clean run. (#1047, #1049)pip install jscpd— the release now publishes eight platform wheels built from the same prebuilt binaries as the npm and GitHub Release artifacts, sopip install jscpdanduvx jscpdget the Rust engine with no Python code and no Node.js runtime involved. The repository-hosted pre-commit hook installs from PyPI instead of npm, which removes Node.js from the pre-commit path. (#1037, #1039)Bug Fixes
fixtures/haxereportedfile1.hx [1:1 - 62:76]againstfile2.hx [1:1 - 62:2]). The match now asks first whether the clone's own anchor continues, and starts a new clone when it does not, so N-way copies no longer lose pairs. (#1033, #1034)xmllintrefused the file withPCDATA invalid Char value 27;]]>inside a fragment closed the CDATA section early, and attribute values were escaped twice. Such characters are now replaced with U+FFFD,]]>is split across two CDATA sections, and paths are escaped once. (#375, #1055)--follow-symlinksrenamed and double-counted linked files — a file reached through a symlink was reported by its resolved real path, which could be an absolute path outside the scan root, so the report and--ignoredisagreed about its name; a file reachable through two paths counted as two sources, and a file symlink next to its target was reported as a clone of itself. Files now keep the path they were found at, and each real file is scanned once. (#1059, #1060)Other
--noSymlinkswas set; v5 needs--follow-symlinks(config keyfollowSymlinks, and a v4noSymlinks: falsestill maps to following). This was true in every 5.x release but undocumented, and it silently drops a corpus mounted through a symlink. Now in the README and the migration table. (#1059)CITATION.cffand a Citation section — GitHub's "Cite this repository" button and a BibTeX entry for the papers that use jscpd as their detector. The version and release date are kept in step bysync-version.mjs. (#1051)jscpdanddry-refactoringskills (npx skills add kucherenko/jscpd) document--summary, the Type-2 and Type-3 flags with their kind suffixes, and warn that normalized passes surface look-alike code, with conservative defaults and a triage step before refactoring. (#1056, #1057)console-fullprints the--historyblock likeconsoledoes, and the test scaffolding behind the CLI, MCP, reporter and finder suites was deduplicated. (#1053)Dependencies
askamafrom 0.16.0 to 0.16.1 in/rust(#1045)taiki-e/install-actionfrom 2.87.3 to 2.87.8 in/.github/workflows(#1046)Thank You ❤️
--ignore-patternhas no short flag and a barenode_modulesdoes not match, since globs are matched against the whole path (#1038)Published Packages
cpd-core@0.1.13on crates.iocpd-finder@0.1.16on crates.iocpd-reporter@0.1.14on crates.iocpd-tokenizer@0.1.15on crates.iojscpd@5.2.1on crates.iocpd@5.2.1on npmjscpd@5.2.1on npmjscpd-darwin-arm64@5.2.1on npmjscpd-darwin-x64@5.2.1on npmjscpd-linux-x64-gnu@5.2.1on npmjscpd-linux-arm64-gnu@5.2.1on npmjscpd-linux-x64-musl@5.2.1on npmjscpd-linux-arm64-musl@5.2.1on npmjscpd-windows-x64-msvc@5.2.1on npmjscpd-windows-arm64-msvc@5.2.1on npmjscpd==5.2.1on PyPIVerify
Archives are signed with Sigstore (keyless,
<asset>.sigstore.json)and carry SLSA build provenance. Replace
jscpd-linux-x64-gnu.tar.gzwith your asset:cosign verify-blob \ --bundle jscpd-linux-x64-gnu.tar.gz.sigstore.json \ --certificate-identity-regexp '^https://github\.com/kucherenko/jscpd/' \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ jscpd-linux-x64-gnu.tar.gz gh attestation verify jscpd-linux-x64-gnu.tar.gz --repo kucherenko/jscpd sha256sum --check --ignore-missing checksums.txtConfiguration
📅 Schedule: (in timezone Europe/Paris)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.