Skip to content

build(deps): bump the production group across 1 directory with 32 updates#3426

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/production-291df1e79e
Open

build(deps): bump the production group across 1 directory with 32 updates#3426
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/production-291df1e79e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor

Bumps the production group with 28 updates in the /frontend directory:

Package From To
@awesome.me/webawesome 3.1.0 3.8.0
@lit/localize 0.12.1 0.12.2
@lit/task 1.0.0 1.0.3
@novnc/novnc 1.4.0 1.7.0
@shoelace-style/shoelace 2.18.0 2.20.1
@tanstack/lit-virtual 3.13.12 3.13.30
@webrecorder/hickory 0.0.10 0.4.0
clsx 2.1.0 2.1.1
cronstrue 3.2.0 3.14.0
highlight.js 11.8.0 11.11.1
ink-mde 0.33.0 0.34.0
lit 3.2.1 3.3.3
lodash 4.17.21 4.18.1
@types/lodash 4.14.191 4.17.24
micromark 4.0.0 4.0.2
micromark-extension-gfm-strikethrough 2.0.0 2.1.0
nanoid 5.1.5 5.1.11
patch-package 8.0.0 8.0.1
postcss 8.4.21 8.5.15
postcss-lit 1.1.1 1.4.1
replaywebpage 2.4.3 2.4.6
slugify 1.6.6 1.6.9
tabbable 6.2.0 6.4.0
tlds 1.259.0 1.261.0
tsconfig-paths-webpack-plugin 4.1.0 4.2.0
@playwright/test 1.60.0 1.61.0
@types/react 19.1.3 19.2.17
@web/test-runner 0.13.31 0.20.2

Updates @awesome.me/webawesome from 3.1.0 to 3.8.0

Release notes

Sourced from @​awesome.me/webawesome's releases.

v3.8.0

Bug Fixes

Commits

  • 0704951: fix copy button test (konnorrogers)
  • 8312c32: fix copy button test (konnorrogers)
  • 340c281: syncing component badges across views via shared macro (#2391) (Brian Talbot) #2391
  • Standardizing Hover Utilities for Card Links (#2390) #2390 (Brian Talbot)
  • Polish Changelog View (#2395) #2395 (Brian Talbot)
  • 9888c98: Make linkify-components Transformer Site-Wide (#2397) (Brian Talbot) #2397
  • Set wa-breadcrumb-item Render href="" as a Link (#2398) #2398 (Brian Talbot)
  • 3fd7088: fixing wa-breadcrumb-item regression rendering as link when href is absent (#2400) (Brian Talbot) #2400
  • 057ef4d: using new size-based values (#2399) (Brian Talbot) #2399
  • f39a4de: udpated changelog (#2406) (Kelsey Jackson) #2406
  • c699518: Fixed link to themes in Angular documentation (#2408) (Anna Johansson) #2408
  • 86adc26: update changelog (#2410) (Cory LaViska) #2410
  • d2c9062: ignore assets directories (#2417) (Konnor Rogers) #2417
  • 2c91bb2: styling wa-textarea disabled state to match wa-input (#2419) (Brian Talbot) #2419
  • 2194fc5: fix padding bug (#2411) (Cory LaViska) #2411
  • Code Example Polish (#2414) #2414 (Brian Talbot)
  • 50ad382: Syncing Component Durations + WA Transition Tokens (#2423) (Brian Talbot) #2423
  • Improve Lighthouse Score (#2420) #2420 (Brian Talbot)
  • 0c785a0: extending transition token sync to wa-combobox and wa-toast-item (#2427) (Brian Talbot) #2427
  • e75719f: unifying component category labels across the docs (#2431) (Brian Talbot) #2431
  • d5aab1c: fixing build awesome nav link by sourcing from site.json (#2432) (Brian Talbot) #2432
  • 7dac904: don't clip outlines everywhere (#2440) (Cory LaViska) #2440
  • 829abbd: Make drawer lightDismiss default false (#2437) (DanielKanyo) #2437
  • ed1aaf7: add tests + changelog; #2437 (#2446) (Cory LaViska) #2446
  • 0c052ab: Add scroll into view handleDocumentKeyDown (#2430) (Wendelin) #2430
  • 57537db: Wendevlin fix dropdown scroll (#2447) (Cory LaViska) #2447
  • f4e485d: add changelog (#2448) (Cory LaViska) #2448
  • 630fc68: fix link; closes #2445 (#2449) (Cory LaViska) #2449
  • 7e0f421: Reset menu styles in Native Styles (#2450) (Lindsay M) #2450
  • Link to a Component's Category (#2443) #2443 (Brian Talbot)
  • 4fb78fc: Improve placement of content in textarea when exceeding rows (#2424) (trent) #2424
  • c3999db: Add text-transform-Based Text Utilities (#2404) (Brian Talbot) #2404
  • 4012339: Add text-align-Based Text Utilities + Adopt Flat wa-text- Naming (#2403) (Brian Talbot) #2403
  • fff9166: Revise Native Styles (#2459) (Brian Talbot) #2459
  • 117d515: Add Prose Text Utility (#2370) (Brian Talbot) #2370
  • d43e26c: Rewrite theming documentation (#2249) (Lindsay M) #2249
  • 4d00ea0: Add and components (#2434) (Kelsey Jackson) #2434
  • 2fe74a1: submit empty strings for null form values (#2463) (Konnor Rogers) #2463
  • 63e6f13: update zoomable frame to import wa-icon (#2466) (Konnor Rogers) #2466
  • 50bdfbc: Add <wa-time-picker>, <wa-known-date>, and supporting translations, events, etc. for <wa-date-picker> and <wa-calendar> (#2407) (Cory LaViska) #2407
  • eafe6e2: Add forked qr-library with support for images (#2139) (Konnor Rogers) #2139
  • 72c389b: Date picker again (#2468) (Cory LaViska) #2468
  • beacbd1: prettier (Cory LaViska)
  • 49ef47c: fix selector column (#2469) (Cory LaViska) #2469

... (truncated)

Commits

Updates @lit/context from 1.1.3 to 1.1.6

Release notes

Sourced from @​lit/context's releases.

@​lit/context@​1.1.6

Patch Changes

@​lit/context@​1.1.5

Patch Changes

Changelog

Sourced from @​lit/context's changelog.

1.1.6

Patch Changes

1.1.5

Patch Changes

1.1.4

Patch Changes

Commits

Updates @lit/localize from 0.12.1 to 0.12.2

Release notes

Sourced from @​lit/localize's releases.

@​lit/localize@​0.12.2

Patch Changes

Changelog

Sourced from @​lit/localize's changelog.

0.12.2

Patch Changes

Commits

Updates @lit/task from 1.0.0 to 1.0.3

Release notes

Sourced from @​lit/task's releases.

@​lit/task@​1.0.3

Patch Changes

@​lit/task@​1.0.2

Patch Changes

  • #4836 05691ba4 Thanks @​maxpatiiuk! - Improve type inference of tuples returned by the args function being used as task function parameter.

@​lit/task@​1.0.1

Patch Changes

  • #4552 4050cac6 Thanks @​jrencz! - Make status of Task a readonly property

    So far status was writable which allowed for setting status of task form outside. Doing so did cause rendering of expected template but the task was becoming internally incoherent.

    Now attempt to assign status will end up in throwing a TypeError.

Changelog

Sourced from @​lit/task's changelog.

1.0.3

Patch Changes

1.0.2

Patch Changes

  • #4836 05691ba4 Thanks @​maxpatiiuk! - Improve type inference of tuples returned by the args function being used as task function parameter.

1.0.1

Patch Changes

  • #4552 4050cac6 Thanks @​jrencz! - Make status of Task a readonly property

    So far status was writable which allowed for setting status of task form outside. Doing so did cause rendering of expected template but the task was becoming internally incoherent.

    Now attempt to assign status will end up in throwing a TypeError.

Commits

Updates @novnc/novnc from 1.4.0 to 1.7.0

Release notes

Sourced from @​novnc/novnc's releases.

noVNC 1.7.0

A new version of noVNC is now available. Lots of changes have been made since the last release, but the highlights are:

Application:

  • Added Croatian translation.
  • Added Hungarian translation.
  • Fixed a styling bug where some buttons in the GUI would almost disappear.
  • The browser will now warn before the session's tab is closed when view only is not enabled.

Library:

  • The NPM bundle has been converted to ES-module format.
  • The novnc_proxy script now uses the bash-builtin type instead of which when checking if websockify is installed.
  • Received image data is now dropped once rendered, resulting in more efficient memory usage.
  • Detection of H.264 has been improved.
  • The deprecated showDotCursor setting has now been removed.

Regards, The noVNC Developers

noVNC 1.7.0 beta

A new beta version of noVNC is now available. Many changes have been made since the last release, but the highlights are:

Application:

  • Added Croatian translation.
  • Added Hungarian translation.
  • Fixed a styling bug where some buttons in the GUI would almost disappear.
  • The browser will now warn before the session's tab is closed when view only is not enabled.

Library:

  • The NPM bundle has been converted to ES-module format.
  • The novnc_proxy script now uses the bash-builtin type instead of which when checking if websockify is installed.
  • Received image data is now dropped once rendered, resulting in more efficient memory usage.
  • Detection of H.264 has been improved.
  • The deprecated showDotCursor setting has now been removed.

Regards, The noVNC Developers

noVNC 1.6.0

A new version of noVNC is now available. Lots of changes have been made since the last release, but the highlights are:

Application:

  • Updated GUI with a more modern styling.
  • Settings can now be configured via defaults.json and mandatory.json.
  • Support for relative WebSocket URLs.

... (truncated)

Commits
  • 63107bd noVNC 1.7.0
  • 18cabdf Update generated json files
  • 85ae81a noVNC 1.7.0 beta
  • 7a96227 Remove show_dot from docs/EMBEDDING.md
  • 43266f4 Remove showDotCursor from docs/API.md
  • 4ccc3b4 Use Node version 24 when publishing to npmjs
  • 8f3555b Publish with latest npm version
  • 7808f57 Stop using access tokens when publishing to npmjs
  • 603d63f Allow publishing to npmjs.com with OIDC
  • 5ac7bd2 Update Swedish translation
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​novnc/novnc since your current version.


Updates @shoelace-style/localize from 3.2.1 to 3.2.2

Changelog

Sourced from @​shoelace-style/localize's changelog.

3.2.2

  • Fixed a bug where malformed <html lang> values caused Intl.Locale to throw a RangeError. The controller now falls through to the fallback translation instead.
  • Fixed a type error in update() where connected elements were incorrectly annotated as LitElement
Commits

Updates @shoelace-style/shoelace from 2.18.0 to 2.20.1

Release notes

Sourced from @​shoelace-style/shoelace's releases.

v2.20.1

Commits

  • 19537b1: Fix a11y issues for closing components with focused children (Christian Schilling) #2383
  • 61c73cd: Add ticket number to changelog (Christian Schilling) #2383
  • Nested tab groups broken in v2.19.1 (#2367) #2367 (Christian Schilling)
  • d83d620: Remove log statement (Christian Schilling) #2383
  • 0a48bc5: Merge remote-tracking branch 'upstream/next' into fix/a11y-errors-for-blur (Christian Schilling) #2383
  • 91235cb: Fixes dropdown closing on tab key (#2371) (Gabriel Belgamo) #2371
  • 1b9104d: update changelog (Cory LaViska)
  • 5ef3c91: fix contextElement guard (#2399) (Diego Ferreiro Val) #2399
  • ee42086: update changelog (Cory LaViska)
  • e09277e: Fixes closable sl-alert can be closed on whole vertical area without visual indication (#2375) (Susanne Kirchner) #2375
  • eef4c17: update changelog (Cory LaViska)
  • d2ce983: Merge branch 'fix/a11y-errors-for-blur' of https://github.com/schilchSICKAG/shoelace into schilchSICKAG-fix/a11y-errors-for-blur (Cory LaViska) #2383
  • 5be9540: Merge branch 'schilchSICKAG-fix/a11y-errors-for-blur' into next (Cory LaViska)
  • 0cf1984: update docs to fix types (Cory LaViska)
  • bcf08a8: Carousel accessibility (#2364) (Matt McLean) #2364
  • d1f94ab: update changelog (Cory LaViska)
  • 3142d14: update version (Cory LaViska)
  • fb59fda: 2.20.1 (Cory LaViska)

v2.20.0

Commits

  • 7fd18d1: Modify ja.ts (#2329) (jz5) #2329
  • c16c533: update changelog (Cory LaViska)
  • 7f88bb3: Svelte documentation: adding Two-way Binding example in (#2327) (Emanuel Saramago) #2327
  • b5e82d6: update docs (Cory LaViska)
  • 81e94f2: Only trigger defaultslotchange of select after initialization (#2318) (Susanne Kirchner) #2318
  • f0c93d0: update changelog (Cory LaViska)
  • 6761fdc: Merge branch 'next' of https://github.com/shoelace-style/shoelace into next (Cory LaViska)
  • b0399ca: fix tabbable for radios (#2357) (Konnor Rogers) #2357
  • 372ba1f: fix ssr for sl-alert and scrollend-polyfill (#2359) (Christian Schilling) #2359
  • 69cf94b: Explain why dividers don't show if you use TailwindCSS and add a workaround. (#2356) (Marcus) #2356
  • b5f308c: move to section (Cory LaViska)
  • cb6460c: update action (Cory LaViska)
  • d93ee89: add changelog check (Cory LaViska)
  • 0bc6d8c: fix error (Cory LaViska)
  • c3b1fb9: try again (Cory LaViska)
  • fce7f7c: fix comment (Cory LaViska)
  • afc2b06: sigh (Cory LaViska)
  • 03f8464: ahem (Cory LaViska)
  • 471e6cc: somebody save me (Cory LaViska)
  • c858a3a: yaml was a mistake (Cory LaViska)
  • 5e11687: save me tarides (Cory LaViska)
  • 4530ba3: welp (Cory LaViska)
  • d674577: not today i guess (Cory LaViska)
  • ca8a12b: maybe, just maybe (Cory LaViska)
  • 74dafea: somebody save me (Cory LaViska)
  • 39e4557: ok konnor (Cory LaViska)
  • d45e6df: revert (Cory LaViska)

... (truncated)

Commits

Updates @tanstack/lit-virtual from 3.13.12 to 3.13.30

Release notes

Sourced from @​tanstack/lit-virtual's releases.

@​tanstack/lit-virtual@​3.13.30

Patch Changes

  • Updated dependencies [ef69ea3]:
    • @​tanstack/virtual-core@​3.17.1

@​tanstack/lit-virtual@​3.13.29

Patch Changes

@​tanstack/lit-virtual@​3.13.28

Patch Changes

  • Updated dependencies [c746841]:
    • @​tanstack/virtual-core@​3.16.1

@​tanstack/lit-virtual@​3.13.27

Patch Changes

  • Updated dependencies [fc992ab]:
    • @​tanstack/virtual-core@​3.16.0

@​tanstack/lit-virtual@​3.13.26

Patch Changes

@​tanstack/lit-virtual@​3.13.25

Patch Changes

  • Updated dependencies [97a204d]:
    • @​tanstack/virtual-core@​3.14.0

@​tanstack/lit-virtual@​3.13.24

Patch Changes

  • Updated dependencies [7ece2d5]:
    • @​tanstack/virtual-core@​3.13.23

@​tanstack/lit-virtual@​3.13.23

Patch Changes

@​tanstack/lit-virtual@​3.13.22

Patch Changes

... (truncated)

Changelog

Sourced from @​tanstack/lit-virtual's changelog.

3.13.30

Patch Changes

  • Updated dependencies [ef69ea3]:
    • @​tanstack/virtual-core@​3.17.1

3.13.29

Patch Changes

3.13.28

Patch Changes

  • Updated dependencies [c746841]:
    • @​tanstack/virtual-core@​3.16.1

3.13.27

Patch Changes

  • Updated dependencies [fc992ab]:
    • @​tanstack/virtual-core@​3.16.0

3.13.26

Patch Changes

3.13.25

Patch Changes

  • Updated dependencies [97a204d]:
    • @​tanstack/virtual-core@​3.14.0

3.13.24

Patch Changes

  • Updated dependencies [7ece2d5]:
    • @​tanstack/virtual-core@​3.13.23

3.13.23

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tanstack/lit-virtual since your current version.


Updates @tanstack/virtual-core from 3.13.12 to 3.17.1

Release notes

Sourced from @​tanstack/virtual-core's releases.

@​tanstack/virtual-core@​3.17.1

Patch Changes

  • #1199 ef69ea3 - Fix "items jump while scrolling up": the default scroll-adjustment predicate now compensates scrollTop on the first measurement of an above-viewport item even while scrolling backward (the estimate→actual delta must be absorbed), and only skips compensation for re-measurements during backward scroll to avoid the cascading jank

@​tanstack/virtual-core@​3.17.0

Minor Changes

  • #1186 fbf3bdb - Add useCachedMeasurements option to skip DOM measurement when the list is hidden (e.g. display: none). When enabled, the default measureElement returns the cached size or estimateSize fallback instead of reading the DOM, preventing ResizeObserver from resetting measurements to zero.

Patch Changes

  • #1183 c0b84c8 - Skip synchronous DOM read (offsetWidth/offsetHeight) in default measureElement when a cached size already exists, reducing layout reflow on re-renders

@​tanstack/virtual-core@​3.16.1

Patch Changes

  • Eagerly adjust scrollOffset on prepend to prevent one-frame jump with anchorTo: 'end' (#1176)

    When items are prepended with anchorTo: 'end' and dynamic sizes, the virtualizer would compute the wrong visible range for one frame (using stale estimate-based positions) and then correct in the next frame via _willUpdate, producing a visible jump. This fix eagerly adjusts scrollOffset in setOptions during the render pass so calculateRange/getVirtualItems return the correct items immediately.

@​tanstack/virtual-core@​3.16.0

Minor Changes

  • Add end-anchored virtualization support for chat, logs, and reverse feeds. (#1173)

    New anchorTo: 'end' mode keeps the current visible item stable when older items are prepended, while preserving the existing start-anchored behavior by default. It also keeps an end-pinned viewport pinned when the last item grows during streaming output.

    Add followOnAppend so new items scroll into view only when the viewport was already at the end, plus scrollEndThreshold, scrollToEnd(), getDistanceFromEnd(), and isAtEnd() helpers for chat-style integrations.

@​tanstack/virtual-core@​3.15.0

Minor Changes

  • iOS Safari momentum-scroll handling. Writing scrollTop while a finger (#1168) is on the screen, during momentum decay, or while the page is in the elastic-overscroll bounce zone all cancel the in-flight scroll in iOS WebKit. The virtualizer previously had no iOS-specific handling, which manifested as the recurring "scroll abruptly stops when content above resizes" complaints on Safari mobile.

    Adds three layers of protection, default-on, all transparent to consumers:

    • Touch event distinction. A touchstart→touchend window plus a 150 ms grace timer for the early-momentum phase. Scroll-position adjustments triggered during any of these states accumulate into a _iosDeferredAdjustment field instead of writing scrollTop.
    • Subpixel reconciliation. When the browser reports back a rounded scrollTop within 1.5 px of a value we just wrote, the virtualizer prefers the intended value rather than treating the round-trip as a

... (truncated)

Changelog

Sourced from @​tanstack/virtual-core's changelog.

3.17.1

Patch Changes

  • #1199 ef69ea3 - Fix "items jump while scrolling up": the default scroll-adjustment predicate now compensates scrollTop on the first measurement of an above-viewport item even while scrolling backward (the estimate→actual delta must be absorbed), and only skips compensation for re-measurements during backward scroll to avoid the cascading jank

3.17.0

Minor Changes

  • #1186 fbf3bdb - Add useCachedMeasurements option to skip DOM measurement when the list is hidden (e.g. display: none). When enabled, the default measureElement returns the cached size or estimateSize fallback instead of reading the DOM, preventing ResizeObserver from resetting measurements to zero.

Patch Changes

  • #1183 c0b84c8 - Skip synchronous DOM read (offsetWidth/offsetHeight) in default measureElement when a cached size already exists, reducing layout reflow on re-renders

3.16.1

Patch Changes

  • Eagerly adjust scrollOffset on prepend to prevent one-frame jump with anchorTo: 'end' (#1176)

    When items are prepended with anchorTo: 'end' and dynamic sizes, the virtualizer would compute the wrong visible range for one frame (using stale estimate-based positions) and then correct in the next frame via _willUpdate, producing a visible jump. This fix eagerly adjusts scrollOffset in setOptions during the render pass so calculateRange/getVirtualItems return the correct items immediately.

3.16.0

Minor Changes

  • Add end-anchored virtualization support for chat, logs, and reverse feeds. (#1173)

    New anchorTo: 'end' mode keeps the current visible item stable when older items are prepended, while preserving the existing start-anchored behavior by default. It also keeps an end-pinned viewport pinned when the last item grows during streaming output.

    Add followOnAppend so new items scroll into view only when the viewport was already at the end, plus scrollEndThreshold, scrollToEnd(), getDistanceFromEnd(), and isAtEnd() helpers for chat-style integrations.

3.15.0

Minor Changes

  • iOS Safari momentum-scroll handling. Writing scrollTop while a finger (#1168) is on the screen, during momentum decay, or while the page is in the elastic-overscroll bounce zone all cancel the in-flight scroll in iOS WebKit. The virtualizer previously had no iOS-specific handling, which manifested as the recurring "scroll abruptly stops when content above resizes" complaints on Safari mobile.

    Adds three layers of protection, default-on, all transparent to consumers:

    • Touch event distinction. A touchstart→touchend window plus a 150 ms grace timer for the early-momentum phase. Scroll-position adjustments triggered during any of these states accumulate into a
    • ...

      Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 23, 2026
@socket-security

socket-security Bot commented Jun 23, 2026

Copy link
Copy Markdown

@socket-security

socket-security Bot commented Jun 23, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @awesome.me/webawesome is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: frontend/package.jsonnpm/@awesome.me/webawesome@3.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@awesome.me/webawesome@3.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @novnc/novnc is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: frontend/package.jsonnpm/@novnc/novnc@1.7.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@novnc/novnc@1.7.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @shoelace-style/shoelace is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: frontend/package.jsonnpm/@shoelace-style/shoelace@2.20.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@shoelace-style/shoelace@2.20.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm fast-xml-parser is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/replaywebpage@2.4.6npm/fast-xml-parser@4.5.6

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/fast-xml-parser@4.5.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm puppeteer-core is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@web/test-runner@0.20.2npm/puppeteer-core@24.43.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/puppeteer-core@24.43.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/production-291df1e79e branch from 4d21107 to 9654e98 Compare June 23, 2026 19:25
…ates

Bumps the production group with 28 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [@awesome.me/webawesome](https://github.com/shoelace-style/webawesome) | `3.1.0` | `3.8.0` |
| [@lit/localize](https://github.com/Lit/Lit/tree/HEAD/packages/localize) | `0.12.1` | `0.12.2` |
| [@lit/task](https://github.com/lit/lit/tree/HEAD/packages/task) | `1.0.0` | `1.0.3` |
| [@novnc/novnc](https://github.com/novnc/noVNC) | `1.4.0` | `1.7.0` |
| [@shoelace-style/shoelace](https://github.com/shoelace-style/shoelace) | `2.18.0` | `2.20.1` |
| [@tanstack/lit-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/lit-virtual) | `3.13.12` | `3.13.30` |
| [@webrecorder/hickory](https://github.com/webrecorder/hickory) | `0.0.10` | `0.4.0` |
| [clsx](https://github.com/lukeed/clsx) | `2.1.0` | `2.1.1` |
| [cronstrue](https://github.com/bradymholt/cRonstrue) | `3.2.0` | `3.14.0` |
| [highlight.js](https://github.com/highlightjs/highlight.js) | `11.8.0` | `11.11.1` |
| [ink-mde](https://github.com/davidmyersdev/ink-mde) | `0.33.0` | `0.34.0` |
| [lit](https://github.com/lit/lit/tree/HEAD/packages/lit) | `3.2.1` | `3.3.3` |
| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |
| [@types/lodash](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/lodash) | `4.14.191` | `4.17.24` |
| [micromark](https://github.com/micromark/micromark) | `4.0.0` | `4.0.2` |
| [micromark-extension-gfm-strikethrough](https://github.com/micromark/micromark-extension-gfm-strikethrough) | `2.0.0` | `2.1.0` |
| [nanoid](https://github.com/ai/nanoid) | `5.1.5` | `5.1.11` |
| [patch-package](https://github.com/ds300/patch-package) | `8.0.0` | `8.0.1` |
| [postcss](https://github.com/postcss/postcss) | `8.4.21` | `8.5.15` |
| [postcss-lit](https://github.com/43081j/postcss-lit) | `1.1.1` | `1.4.1` |
| [replaywebpage](https://github.com/webrecorder/replayweb.page) | `2.4.3` | `2.4.6` |
| [slugify](https://github.com/simov/slugify) | `1.6.6` | `1.6.9` |
| [tabbable](https://github.com/focus-trap/tabbable) | `6.2.0` | `6.4.0` |
| [tlds](https://github.com/stephenmathieson/node-tlds) | `1.259.0` | `1.261.0` |
| [tsconfig-paths-webpack-plugin](https://github.com/dividab/tsconfig-paths-webpack-plugin) | `4.1.0` | `4.2.0` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.60.0` | `1.61.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.1.3` | `19.2.17` |
| [@web/test-runner](https://github.com/modernweb-dev/web/tree/HEAD/packages/test-runner) | `0.13.31` | `0.20.2` |



Updates `@awesome.me/webawesome` from 3.1.0 to 3.8.0
- [Release notes](https://github.com/shoelace-style/webawesome/releases)
- [Commits](shoelace-style/webawesome@v3.1.0...v3.8.0)

Updates `@lit/context` from 1.1.3 to 1.1.6
- [Release notes](https://github.com/lit/lit/releases)
- [Changelog](https://github.com/lit/lit/blob/main/packages/context/CHANGELOG.md)
- [Commits](https://github.com/lit/lit/commits/@lit/context@1.1.6/packages/context)

Updates `@lit/localize` from 0.12.1 to 0.12.2
- [Release notes](https://github.com/Lit/Lit/releases)
- [Changelog](https://github.com/lit/lit/blob/main/packages/localize/CHANGELOG.md)
- [Commits](https://github.com/Lit/Lit/commits/@lit/localize@0.12.2/packages/localize)

Updates `@lit/task` from 1.0.0 to 1.0.3
- [Release notes](https://github.com/lit/lit/releases)
- [Changelog](https://github.com/lit/lit/blob/main/packages/task/CHANGELOG.md)
- [Commits](https://github.com/lit/lit/commits/@lit/task@1.0.3/packages/task)

Updates `@novnc/novnc` from 1.4.0 to 1.7.0
- [Release notes](https://github.com/novnc/noVNC/releases)
- [Commits](novnc/noVNC@v1.4.0...v1.7.0)

Updates `@shoelace-style/localize` from 3.2.1 to 3.2.2
- [Changelog](https://github.com/shoelace-style/localize/blob/main/CHANGELOG.md)
- [Commits](https://github.com/shoelace-style/localize/commits)

Updates `@shoelace-style/shoelace` from 2.18.0 to 2.20.1
- [Release notes](https://github.com/shoelace-style/shoelace/releases)
- [Commits](shoelace-style/shoelace@v2.18.0...v2.20.1)

Updates `@tanstack/lit-virtual` from 3.13.12 to 3.13.30
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/lit-virtual/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/lit-virtual@3.13.30/packages/lit-virtual)

Updates `@tanstack/virtual-core` from 3.13.12 to 3.17.1
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/virtual-core/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/virtual-core@3.17.1/packages/virtual-core)

Updates `@webrecorder/hickory` from 0.0.10 to 0.4.0
- [Release notes](https://github.com/webrecorder/hickory/releases)
- [Changelog](https://github.com/webrecorder/hickory/blob/main/CHANGELOG.md)
- [Commits](webrecorder/hickory@v0.0.10...v0.4.0)

Updates `clsx` from 2.1.0 to 2.1.1
- [Release notes](https://github.com/lukeed/clsx/releases)
- [Commits](lukeed/clsx@v2.1.0...v2.1.1)

Updates `cronstrue` from 3.2.0 to 3.14.0
- [Release notes](https://github.com/bradymholt/cRonstrue/releases)
- [Changelog](https://github.com/bradymholt/cRonstrue/blob/main/CHANGELOG.md)
- [Commits](bradymholt/cRonstrue@v3.2.0...v3.14.0)

Updates `highlight.js` from 11.8.0 to 11.11.1
- [Release notes](https://github.com/highlightjs/highlight.js/releases)
- [Changelog](https://github.com/highlightjs/highlight.js/blob/main/CHANGES.md)
- [Commits](highlightjs/highlight.js@11.8.0...11.11.1)

Updates `ink-mde` from 0.33.0 to 0.34.0
- [Release notes](https://github.com/davidmyersdev/ink-mde/releases)
- [Commits](davidmyersdev/ink-mde@v0.33.0...v0.34.0)

Updates `lit` from 3.2.1 to 3.3.3
- [Release notes](https://github.com/lit/lit/releases)
- [Changelog](https://github.com/lit/lit/blob/main/packages/lit/CHANGELOG.md)
- [Commits](https://github.com/lit/lit/commits/lit@3.3.3/packages/lit)

Updates `lodash` from 4.17.21 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.18.1)

Updates `@types/lodash` from 4.14.191 to 4.17.24
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/lodash)

Updates `micromark` from 4.0.0 to 4.0.2
- [Release notes](https://github.com/micromark/micromark/releases)
- [Commits](micromark/micromark@4.0.0...4.0.2)

Updates `micromark-extension-gfm-strikethrough` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/micromark/micromark-extension-gfm-strikethrough/releases)
- [Commits](micromark/micromark-extension-gfm-strikethrough@2.0.0...2.1.0)

Updates `nanoid` from 5.1.5 to 5.1.11
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@5.1.5...5.1.11)

Updates `patch-package` from 8.0.0 to 8.0.1
- [Release notes](https://github.com/ds300/patch-package/releases)
- [Changelog](https://github.com/ds300/patch-package/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ds300/patch-package/commits)

Updates `postcss` from 8.4.21 to 8.5.15
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.4.21...8.5.15)

Updates `postcss-lit` from 1.1.1 to 1.4.1
- [Release notes](https://github.com/43081j/postcss-lit/releases)
- [Commits](43081j/postcss-lit@v1.1.1...v1.4.1)

Updates `replaywebpage` from 2.4.3 to 2.4.6
- [Release notes](https://github.com/webrecorder/replayweb.page/releases)
- [Changelog](https://github.com/webrecorder/replayweb.page/blob/main/CHANGES.md)
- [Commits](webrecorder/replayweb.page@v2.4.3...v2.4.6)

Updates `slugify` from 1.6.6 to 1.6.9
- [Changelog](https://github.com/simov/slugify/blob/master/CHANGELOG.md)
- [Commits](https://github.com/simov/slugify/commits)

Updates `tabbable` from 6.2.0 to 6.4.0
- [Release notes](https://github.com/focus-trap/tabbable/releases)
- [Changelog](https://github.com/focus-trap/tabbable/blob/master/CHANGELOG.md)
- [Commits](focus-trap/tabbable@v6.2.0...v6.4.0)

Updates `tlds` from 1.259.0 to 1.261.0
- [Changelog](https://github.com/stephenmathieson/node-tlds/blob/master/CHANGELOG.md)
- [Commits](stephenmathieson/node-tlds@1.259.0...1.261.0)

Updates `tsconfig-paths-webpack-plugin` from 4.1.0 to 4.2.0
- [Changelog](https://github.com/jonaskello/tsconfig-paths-webpack-plugin/blob/master/CHANGELOG.md)
- [Commits](jonaskello/tsconfig-paths-webpack-plugin@v4.1.0...v4.2.0)

Updates `yaml` from 2.2.1 to 2.3.4
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.2.1...v2.3.4)

Updates `@playwright/test` from 1.60.0 to 1.61.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.60.0...v1.61.0)

Updates `@types/react` from 19.1.3 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@web/test-runner` from 0.13.31 to 0.20.2
- [Release notes](https://github.com/modernweb-dev/web/releases)
- [Changelog](https://github.com/modernweb-dev/web/blob/master/packages/test-runner/CHANGELOG.md)
- [Commits](https://github.com/modernweb-dev/web/commits/@web/test-runner@0.20.2/packages/test-runner)

---
updated-dependencies:
- dependency-name: "@awesome.me/webawesome"
  dependency-version: 3.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@lit/context"
  dependency-version: 1.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@lit/localize"
  dependency-version: 0.12.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@lit/task"
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@novnc/novnc"
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@playwright/test"
  dependency-version: 1.61.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@shoelace-style/localize"
  dependency-version: 3.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@shoelace-style/shoelace"
  dependency-version: 2.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@tanstack/lit-virtual"
  dependency-version: 3.13.30
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@tanstack/virtual-core"
  dependency-version: 3.17.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@types/lodash"
  dependency-version: 4.17.24
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@web/test-runner"
  dependency-version: 0.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@webrecorder/hickory"
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: clsx
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: cronstrue
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: highlight.js
  dependency-version: 11.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: ink-mde
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: lit
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: micromark
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: micromark-extension-gfm-strikethrough
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: nanoid
  dependency-version: 5.1.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: patch-package
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: postcss
  dependency-version: 8.5.15
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: postcss-lit
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: replaywebpage
  dependency-version: 2.4.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: slugify
  dependency-version: 1.6.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: tabbable
  dependency-version: 6.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: tlds
  dependency-version: 1.261.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: tsconfig-paths-webpack-plugin
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: yaml
  dependency-version: 2.3.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/production-291df1e79e branch from 9654e98 to eba1bf6 Compare June 23, 2026 23:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants