Skip to content

chore(deps): weekly safe npm updates · 4 packages - #36

Open
mendral-app[bot] wants to merge 2 commits into
mainfrom
mendral/deps/weekly-safe-npm-20260713
Open

chore(deps): weekly safe npm updates · 4 packages#36
mendral-app[bot] wants to merge 2 commits into
mainfrom
mendral/deps/weekly-safe-npm-20260713

Conversation

@mendral-app

@mendral-app mendral-app Bot commented Jul 13, 2026

Copy link
Copy Markdown

Packages bumped

Package Old New Published
@nuxt/content 3.12.0 3.15.0 2026-07-02
@nuxtjs/robots 5.7.0 5.7.1 2026-03-02
better-sqlite3 12.6.2 12.11.1 2026-06-15
remark-mdc 3.10.0 3.11.1 2026-07-02
Per-package detail

@nuxt/content 3.12.0 → 3.15.0

  • v3.13.0: Security fix — unauthenticated SQL injection vulnerability patched. MDC config sourcing via hook.
  • v3.14.0: New useSearchCollection composable with FTS5 full-text search, custom properties on ContentConfig.
  • v3.15.0: Explicit Bun SQLite connector, type inference for extraFields in search, Vercel tmp directory fix.
  • Impact: The landing site uses @nuxt/content for the blog. The SQL injection fix in v3.13.0 is security-relevant. Features are additive, no breaking changes.

@nuxtjs/robots 5.7.0 → 5.7.1

  • Nuxt 4 compatibility fix (>=4.0), devtools indexable status bug fix.
  • Impact: We use Nuxt 4 — this directly fixes compatibility. Minor patch, no risk.

better-sqlite3 12.6.2 → 12.11.1

  • SQLite upgraded to v3.53.1 (from ~v3.50.x).
  • Added Node.js v26 prebuilds, percentile functions enabled.
  • Various Electron compatibility fixes (not relevant to us — server-side only).
  • Impact: Used as the content database for @nuxt/content. SQLite engine upgrade brings performance and correctness fixes. No API changes.

remark-mdc 3.10.0 → 3.11.1

  • v3.11.0: Fixed fenced code block indentation handling.
  • v3.11.1: Fixed chunk link reset between slots to preserve list structure.
  • Impact: Used for Markdown Component (MDC) parsing in blog posts. Bug fixes improve rendering correctness. No breaking changes.

Files modified

  • landing/package.json
  • landing/pnpm-lock.yaml
  • .github/workflows/ci.yml (pin actions to SHAs — required by new org policy)
Skipped this ecosystem
Package Current Latest eligible Reason
nuxt 4.3.1 4.4.8 Open PR #32
vue 3.5.28 3.5.39 Open PR #32
@tailwindcss/typography 0.5.19 0.5.20 Open PR #32
parse5 8.0.0 8.0.1 Open PR #30
@nuxtjs/sitemap 7.6.0 7.6.0 Already latest
@nuxtjs/tailwindcss 6.13.2 6.13.2 Already latest
debug 4.4.3 4.4.3 Already latest
rehype-raw 7.0.0 7.0.0 Already latest
remark-emoji 5.0.2 5.0.2 Already latest
remark-gfm 4.0.1 4.0.1 Already latest
remark-rehype 11.1.2 11.1.2 Already latest
unified 11.0.5 11.0.5 Already latest
unist-util-visit 5.1.0 5.1.0 Already latest
vue-router 4.6.4 4.6.4 Already latest

Note

Created by Mendral. Tag @mendral-app with feedback or questions.

mendral-app Bot added 2 commits July 13, 2026 02:50
Required by new org policy enforcing SHA-pinned actions.
Bump @nuxt/content (3.12.0 → 3.15.0), @nuxtjs/robots (5.7.0 → 5.7.1),
better-sqlite3 (12.6.2 → 12.11.1), remark-mdc (3.10.0 → 3.11.1).
@mendral-app
mendral-app Bot marked this pull request as ready for review July 13, 2026 09:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants