Skip to content

chore(deps): bump the minor-and-patch group across 1 directory with 14 updates - #1237

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/services/shared-app-api/minor-and-patch-8e93fe149c
Open

chore(deps): bump the minor-and-patch group across 1 directory with 14 updates#1237
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/services/shared-app-api/minor-and-patch-8e93fe149c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 14 updates in the /services/shared-app-api directory:

Package From To
countries-list 3.3.0 3.4.1
libphonenumber-js 1.12.41 1.13.12
linkify-html 4.3.2 4.3.3
linkifyjs 4.3.2 4.3.3
sanitize-html 2.17.5 2.17.7
zod 4.3.6 4.5.4
@eslint/markdown 8.0.1 8.0.3
@fast-csv/parse 5.0.5 5.0.7
@jest/globals 30.3.0 30.5.1
eslint 10.2.0 10.9.1
jest 30.3.0 30.5.1
prettier 3.8.1 3.9.6
ts-jest 29.4.9 29.4.12
typescript-eslint 8.58.0 8.69.0

Updates countries-list from 3.3.0 to 3.4.1

Release notes

Sourced from countries-list's releases.

v3.4.1

✨ Alternative & former country names (#178, #179)

getCountryCode() now resolves a curated set of alternative names — fixing name→code lookups that broke when countries adopted new ISO short names:

  • Former ISO namesCzech Republic→CZ, Cape Verde→CV, Turkey→TR, Swaziland→SZ, Macedonia→MK, Burma→MM
  • Common short formsUK/Britain→GB, US/USA/America→US, UAE→AE, Holland→NL
  • Historical / colonial namesPersia→IR, Ceylon→LK, Siam→TH, Rhodesia→ZW, Abyssinia→ET, Formosa→TW, Zaire→CD, and more
  • Spelling variantsByelorussia→BY, Rumania→RO, Bahrein→BH, plus diacritic-free Cote d'Ivoire, Turkiye

New optional alias?: string[] on ICountry (also surfaced via getCountryData). A build-time guard test ensures no name, native, or alias is ever ambiguous. Adds ~1.2 KB to countries.min.json — fully non-breaking.

Myanmar (Burma) is now cleanly Myanmar, with Burma / Myanmar (Burma) kept resolvable as aliases.

🛠 Tooling (#176, #180)

  • Adopt TypeScript 7; extend check-types to all workspace packages.
  • Align packageManager to bun@1.3.14; sync workspace versions.
  • Version-bump script now runs Biome format automatically (keeps releases lint-clean).

Full changelog: annexare/Countries@v3.4.0...v3.4.1

v3.4.0

What's Changed

ISO 4217 currency support (#166, #167, #169, #171)

  • New countries-list/currencies subpath export: currencies data plus getCurrency() and getCurrencyByNumeric() helpers
  • Each currency includes: name, native name, symbol (narrow, Unicode CLDR), symbolNative, numeric (three-digit ISO code), decimals (minor unit), and withdrawn flag for codes no longer in the current ISO list
  • New JSON artifacts: currencies.min.json, currencies.all.min.json, minimal/currencies.numeric.min.json, minimal/currencies.symbol.min.json
  • Country currency data actualized to the current ISO 4217 list (#167), ZWG (Zimbabwe Gold) added (#169)

ISO 3166 short names (#170)

  • Czech Republic → Czechia (native: Česká republika → Česko)
  • Cape Verde → Cabo Verde
  • ⚠️ getCountryCode() lookups by the previous long-form names no longer resolve — use the ISO short names

Tooling & tests

  • TypeScript 6, Biome 2.5, Turborepo dropped in favor of Bun workspace scripts (#168)
  • Published bundles are now tested under the real Node.js runtime (CJS + ESM, main and currencies entry points) in CI (#173)

Full Changelog: annexare/Countries@v3.3.0...v3.4.0

Commits
  • 1c39332 chore(release): v3.4.1 (#180)
  • 66d92dd feat(aliases): colonial-era, spelling & ASCII country name aliases (#179)
  • ae60f8f build(deps): bump actions/checkout in the github-actions group (#175)
  • 1c0f419 feat: resolve alternative and former country names in getCountryCode (#178)
  • 3e19734 chore: adopt TypeScript 7, extend type-check coverage, align versions (#176)
  • 6d3ffc5 chore(release): v3.4.0
  • d05cb1f chore(deps): bump Biome to 2.5.3, lefthook to 2.1.10
  • eda6123 test(node): restore test-node as a real Node-runtime suite (#173)
  • cbe3513 fix(data): adopt ISO short names — Czechia, Cabo Verde (#170)
  • 7ea551c test(currencies): cover built dist subpath bundle (#171)
  • Additional commits viewable in compare view

Updates libphonenumber-js from 1.12.41 to 1.13.12

Changelog

Sourced from libphonenumber-js's changelog.

1.13.12 / 27.8.2026

  • Updated metadata to version 9.0.38:
    • Updated phone metadata for region code(s): GM, HK, IN, JO, PG, SN, TZ, ZW
    • Updated geocoding data for country calling code(s): 55 (en), 61 (en), 91 (en), 220 (en), 221 (en), 263 (en)
    • Updated carrier data for country calling code(s): 221 (en), 254 (en), 255 (en), 373 (en), 675 (en), 852 (en, zh), 962 (en)

1.13.11 / 14.8.2026

  • Updated metadata to version 9.0.37:
    • Updated alternate formatting data for country calling code(s): 34, 90
    • Updated phone metadata for region code(s): AR, BD, CL, ES, FJ, GM, GY, IL, MZ, NO, PE, SJ, SY, TG, TR, UG
    • Updated short number metadata for region code(s): ES
    • Updated geocoding data for country calling code(s): 220 (en), 963 (en)
    • Updated carrier data for country calling code(s): 47 (en), 56 (en), 90 (en), 220 (en), 228 (en), 234 (en), 254 (en), 256 (en), 592 (en), 963 (en), 972 (en)
    • Updated / refreshed time zone meta data.

1.13.10 / 30.7.2026

  • Updated metadata to version 9.0.36:
    • Updated alternate formatting data for country calling code(s): 995
    • Updated phone metadata for region code(s): BD, EH, FO, GE, IL, LI, MA, ML, NO, SJ
    • Updated short number metadata for region code(s): FO, IT
    • Updated carrier data for country calling code(s): 47 (en), 61 (en), 212 (en), 256 (en), 298 (en), 423 (en), 972 (en), 995 (en)

1.13.9 / 17.7.2026

  • Updated metadata to version 9.0.35:
    • Updated alternate formatting data for country calling code(s): 995
    • Updated phone metadata for region code(s): AC, CN, FO, GE, IR, KE, SE, UG, ZW
    • Updated short number metadata for region code(s): FR
    • Updated geocoding data for country calling code(s): 86 (en, zh)
    • Updated carrier data for country calling code(s): 61 (en), 86 (en, zh), 93 (en, fa), 247 (en), 250 (en), 254 (en), 256 (en), 263 (en), 298 (en), 420 (en), 976 (en), 995 (en)

1.13.8 / 3.7.2026

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitLab CI/CD, a new releaser for libphonenumber-js since your current version.


Updates linkify-html from 4.3.2 to 4.3.3

Release notes

Sourced from linkify-html's releases.

v4.3.3

What's Changed

  • Fix parsing bugs with some special encoded URLs
  • Parsed emails should not include port numbers
  • Exact version requirement for interfaces and plugins to avoid incompatibility issues with older versions of linkify core
  • Support for jQuery 4

Full Changelog: nfrasser/linkifyjs@v4.3.2...v4.3.3

Changelog

Sourced from linkify-html's changelog.

v4.3.3

  • Fix parsing bugs with some special encoded URLs
  • Parsed emails should not include port numbers
  • Exact version requirement for interfaces and plugins to avoid incompatibility issues with older versions of linkify core
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for linkify-html since your current version.


Updates linkifyjs from 4.3.2 to 4.3.3

Release notes

Sourced from linkifyjs's releases.

v4.3.3

What's Changed

  • Fix parsing bugs with some special encoded URLs
  • Parsed emails should not include port numbers
  • Exact version requirement for interfaces and plugins to avoid incompatibility issues with older versions of linkify core
  • Support for jQuery 4

Full Changelog: nfrasser/linkifyjs@v4.3.2...v4.3.3

Changelog

Sourced from linkifyjs's changelog.

v4.3.3

  • Fix parsing bugs with some special encoded URLs
  • Parsed emails should not include port numbers
  • Exact version requirement for interfaces and plugins to avoid incompatibility issues with older versions of linkify core
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for linkifyjs since your current version.


Updates sanitize-html from 2.17.5 to 2.17.7

Changelog

Sourced from sanitize-html's changelog.

2.17.7 (2026-08-13)

Security

  • Fixed an XSS / URL scheme policy bypass affecting configurations that allow the SVG animation elements (animate, animateColor, animateMotion, animateTransform or set) together with attributeName and one of the animation value attributes. The default configuration was not affected, as these elements are not in the default allowedTags. apostrophecms was not affected. Thanks to koyokr for responsibly disclosing the vulnerability (GHSA-g8qq-57p8-ggw5).

2.17.6 (2026-07-10)

Fixes

  • Allow transformTags to emit text when textFilter is set, even if the tag is initially empty. This is consistent with the documentation. Thanks to spokodev for the fix.

Security

  • Fixed an XSS/allowlist bypass in which the contents of a raw-text element (textarea or xmp) nested inside an svg or math root were re-emitted without HTML-escaping. sanitize-html treated that content as inert raw text because htmlparser2 10.x classified raw-text elements by tag name and ignored the namespace, but a real HTML5 parser treats textarea/xmp as ordinary foreign elements inside SVG/MathML and re-parses their contents as live markup. As a result, markup and event-handler attributes that the allowlist never permitted (for example <svg><textarea><img src=x onerror=alert(1)>) could survive sanitization and execute in the browser. This is now fixed on two fronts: htmlparser2 was upgraded to 12.x, which is namespace-aware and parses textarea/xmp inside SVG/MathML as ordinary elements, so their non-allowlisted children (such as the injected img) are dropped by the allowlist instead of being preserved as raw text; and any raw-text content sanitize-html still emits for these tags (at HTML integration points such as foreignObject/mtext, or outside foreign content) is always HTML-escaped. The default configuration is not affected; the precondition is an allowedTags that includes svg or math together with textarea or xmp. Thanks to khoadb175 for responsibly disclosing the vulnerability.
  • Fixed a mutation-XSS / allowedTags bypass affecting configurations that allow the textarea or xmp raw-text tags. htmlparser2 10.x did not recognize an end tag with a trailing solidus (e.g. </textarea/>) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats </textarea/> as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as <textarea></textarea/><img src=x onerror=...> could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: htmlparser2 was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no < can reopen a tag when the output is re-parsed (textarea, an RCDATA element whose entities htmlparser2 decodes, is escaped like normal text, while xmp, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because htmlparser2 is ESM-only from version 11 onward, sanitize-html now requires Node.js >=22.12.0 (the first 22.x release in which require() of an ES module is available unflagged). Thanks to bibu123456 for reporting the vulnerability and Kayiz-PT for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).
Commits

Updates zod from 4.3.6 to 4.5.4

Release notes

Sourced from zod's releases.

v4.5.4

Commits:

  • 84e416fbf4740527bbc8f319634f4e1b065bb42c fix(v4): stop the cycle walk from firing a default factory (#6500)
  • e8e206fa33ac5fe7ce20a2beb12d57b1cb3df653 4.5.4

v4.5.3

Commits:

  • e6b6ab347675cd2bd54b1bdbed16f98c59be82a9 docs(blog): widen the z.compile example to a 20-property schema
  • 87d6464418582bb96fc665a01f852ca6da324ad0 fix(docs): drop the OG description when the title wraps past two lines
  • 99fce394a026823e602b9c30d8d5d9f5f1932ce7 bench(v4): z.compile() against zod-compiler (#6499)
  • e3a695b6bf3f0d591ea682816e3cdaea04b0f967 docs(v4): record the email regex and container output-shape findings under Open
  • 7e24a24288183ce02554f1ded7775d0650a7b7e6 docs(blog): drop the reading time and put a GitHub link in the navbar
  • eab51ff3592b2d11d863f4ee4d5452f31a3de1b6 fix(v4): emit record numeric keys as strings in toJSONSchema (#6497)

v4.5.2

Commits:

  • a354314ac04fdd5484aa62dd5c3a4b553211a0e4 fix(docs): keep blog posts out of the docs collection (#6484)
  • d378c42aff6869f0929058a7923cd775880f5c4c ci: drop canary publishing from the release workflow (#6487)
  • 212b941791e7faae078e17645eb612824fd8f79a fix(v4): let a prototype method getter answer a bare call so vi.spyOn works (#6488)
  • e7576f542a7bc7ef3cc5eeec237714fd0e6b6e98 docs(blog): let the page show through the navbar in dark mode (#6489)
  • fedb06fafe33a66ce0b5c236ad2557e0a5a170fe fix(docs): match the blog TOC hover bar to the 2px active indicator
  • 6c932fcb2eea6eb671710ea058ca9fdc382ada89 chore: bump devcontainer image to Node 24 (#6470)
  • 6635d9dd367a664109de83c021995821f48efa29 docs(blog): soften the "method memoization" attribution
  • 019ae299cc75daa132bf1acf59086a520abf6b85 fix(docs): drop ISR on the docs route so the home page hydrates
  • 652bb438aa4c626c1cd7948c6849c4691239fca7 chore(docs): drop the scroll log from the route-change scroller
  • 571c8e8a3d73b4305f4abfdd6977773cc12f2bf5 fix(docs): render blog tabs with the stock fumadocs tab card
  • 9a193aa24b4efa3b315b91d4c56c8bc385b8513f 4.5.2

v4.5.1

Commits:

  • 2e862dbf89da2835e5206a8fd3d3be61afe3cf7f ci: gate the GitHub release and JSR publish on the version being live on npm
  • 8e03380510db36fa6fda979fc78a375fdea8021c 4.5.1

v4.5.0

Zod 4.5 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • e8e206f 4.5.4
  • 84e416f fix(v4): stop the cycle walk from firing a default factory (#6500)
  • 1a16102 4.5.3
  • eab51ff fix(v4): emit record numeric keys as strings in toJSONSchema (#6497)
  • 7e24a24 docs(blog): drop the reading time and put a GitHub link in the navbar
  • e3a695b docs(v4): record the email regex and container output-shape findings under Open
  • 99fce39 bench(v4): z.compile() against zod-compiler (#6499)
  • 87d6464 fix(docs): drop the OG description when the title wraps past two lines
  • e6b6ab3 docs(blog): widen the z.compile example to a 20-property schema
  • 9a193aa 4.5.2
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for zod since your current version.


Updates @eslint/markdown from 8.0.1 to 8.0.3

Release notes

Sourced from @​eslint/markdown's releases.

v8.0.3

8.0.3 (2026-07-01)

Bug Fixes

  • type compatibility issue between Markdown v8 and ESLint v9.39.x (#648) (3986839)
  • update dependency @​eslint/plugin-kit to ^0.7.2 (#665) (645b0c3)

v8.0.2

8.0.2 (2026-05-19)

Bug Fixes

Changelog

Sourced from @​eslint/markdown's changelog.

8.0.3 (2026-07-01)

Bug Fixes

  • type compatibility issue between Markdown v8 and ESLint v9.39.x (#648) (3986839)
  • update dependency @​eslint/plugin-kit to ^0.7.2 (#665) (645b0c3)

8.0.2 (2026-05-19)

Bug Fixes

Commits
  • e93e014 chore: release 8.0.3 🚀 (#666)
  • 5c16c41 docs: Update README sponsors
  • f5b6548 docs: Update README sponsors
  • c627dca docs: Update README sponsors
  • 54d3323 chore: update non-major dev-dependencies to v3.8.4 (#670)
  • d006b8a docs: Update README sponsors
  • 3986839 fix: type compatibility issue between Markdown v8 and ESLint v9.39.x (#648)
  • 133ddaa docs: Update README sponsors
  • c154e51 docs: Update README sponsors
  • 15e6148 chore: update dependency @​eslint/json to v2 (#668)
  • Additional commits viewable in compare view

Updates @fast-csv/parse from 5.0.5 to 5.0.7

Release notes

Sourced from @​fast-csv/parse's releases.

v5.0.7

5.0.7 (2026-05-06)

Bug Fixes

  • deps: update dependency @​types/yargs to v17.0.33 (#1146) (bfa5b0c)
  • deps: update dependency @​types/yargs to v17.0.35 (#1165) (d91a6e8)
  • deps: update dependency typescript to v5.9.2 (#1130) (88e40c5)
  • deps: update dependency typescript to v5.9.2 (#1137) (132e7e0)
  • deps: update dependency typescript to v5.9.3 (#1163) (f344b83)
  • deps: update docusaurus monorepo to v3.6.2 (#1051) (b41a649)
  • deps: update jest monorepo to v30 (#1133) (5a5540e)
  • deps: update jest monorepo to v30.2.0 (#1149) (c9233f5)

Reverts

Changelog

Sourced from @​fast-csv/parse's changelog.

5.0.7 (2026-05-06)

Note: Version bump only for package @​fast-csv/parse

Commits

Updates @jest/globals from 30.3.0 to 30.5.1

Release notes

Sourced from @​jest/globals's releases.

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

v30.5.0

On a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴


This is a big release. It touches jest-runtime, jest-resolve and jest-haste-map in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please open an issue.

Highlights

whenCalledWith

Mock functions can now configure return values per argument list, contributed by @​timkindberg (#16053):

const fn = jest.fn();
fn.whenCalledWith('apple').mockReturnValue('red');
fn.whenCalledWith('banana').mockReturnValue('yellow');
fn.whenCalledWith(expect.any(Number)).mockReturnValue('numeric');
fn('apple'); // 'red'
fn('banana'); // 'yellow'
fn(42); // 'numeric'
fn('grape'); // undefined

The returned object is a real Mock, so mockReturnValueOnce, mockResolvedValue, mockImplementation etc. all chain here too. Argument slots accept literals or any asymmetric matcher, with the same equality semantics as toHaveBeenCalledWith(). Calls that match nothing fall through to the base mock. See the Mock Functions docs for matching and precedence details.

Describe-level retries

jest.retryTimes() can now retry a whole describe block instead of a single test, contributed by @​soltonigiri (#16322). Each attempt reruns the block's beforeAll/afterAll hooks, child tests and nested describes, which helps when tests in a block depend on shared state:

</tr></table> 

... (truncated)

Changelog

Sourced from @​jest/globals's changelog.

30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

30.5.0

Features

  • [@jest/expect-utils, jest-mock] Add mockFn.whenCalledWith(...args) for configuring return values per argument list, with first-class asymmetric-matcher support (#16053)
  • [@jest/expect-utils] Export AsymmetricMatcher and FunctionParameters types (previously private to expect) (#16053)
  • [jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types] --collectTests now expands test.each/describe.each cases and reports per-status counts (skipped/todo via the new wouldRun flag for selected tests) plus a summary line that match a real run, including under --testNamePattern and .only/fdescribe focus on both the circus and jasmine2 runners (#16259)
  • [jest-circus, jest-environment, jest-runtime, jest-types] Add describe-level retries via jest.retryTimes(..., {entireDescribe: true}) (#16322)
  • [jest-circus, jest-message-util, jest-reporters, jest-types] Add retryMessages to AssertionResult and export formatErrorStack, so the retry log renders nested cause and AggregateError sections with code frames instead of serialized [cause]:/[errors]: markers (#16316)
  • [jest-circus, jest-types] Add unhandledErrorsDetailed to Circus.RunResult, so an unhandled rejection reports its cause chain and AggregateError entries with code frames instead of a pre-serialized stack (#16316)
  • [jest-haste-map] Replace NodeWatcher and FSEventsWatcher with @parcel/watcher for the non-watchman watch path (#16188)
  • [jest-resolve] Bump unrs-resolver to 1.12.1, remove jest-pnp-resolver and unnecessary checks (#15721)
  • [jest-resolve] Honor Node's --preserve-symlinks / NODE_PRESERVE_SYMLINKS in the default reso...

    Description has been truncated

…4 updates

Bumps the minor-and-patch group with 14 updates in the /services/shared-app-api directory:

| Package | From | To |
| --- | --- | --- |
| [countries-list](https://github.com/annexare/Countries) | `3.3.0` | `3.4.1` |
| [libphonenumber-js](https://gitlab.com/catamphetamine/libphonenumber-js) | `1.12.41` | `1.13.12` |
| [linkify-html](https://github.com/nfrasser/linkifyjs/tree/HEAD/packages/linkify-html) | `4.3.2` | `4.3.3` |
| [linkifyjs](https://github.com/nfrasser/linkifyjs/tree/HEAD/packages/linkifyjs) | `4.3.2` | `4.3.3` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.5` | `2.17.7` |
| [zod](https://github.com/colinhacks/zod) | `4.3.6` | `4.5.4` |
| [@eslint/markdown](https://github.com/eslint/markdown) | `8.0.1` | `8.0.3` |
| [@fast-csv/parse](https://github.com/C2FO/fast-csv/tree/HEAD/packages/parse) | `5.0.5` | `5.0.7` |
| [@jest/globals](https://github.com/jestjs/jest/tree/HEAD/packages/jest-globals) | `30.3.0` | `30.5.1` |
| [eslint](https://github.com/eslint/eslint) | `10.2.0` | `10.9.1` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.3.0` | `30.5.1` |
| [prettier](https://github.com/prettier/prettier) | `3.8.1` | `3.9.6` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.9` | `29.4.12` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.58.0` | `8.69.0` |



Updates `countries-list` from 3.3.0 to 3.4.1
- [Release notes](https://github.com/annexare/Countries/releases)
- [Commits](annexare/Countries@v3.3.0...v3.4.1)

Updates `libphonenumber-js` from 1.12.41 to 1.13.12
- [Changelog](https://gitlab.com/catamphetamine/libphonenumber-js/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/catamphetamine/libphonenumber-js/compare/v1.12.41...v1.13.12)

Updates `linkify-html` from 4.3.2 to 4.3.3
- [Release notes](https://github.com/nfrasser/linkifyjs/releases)
- [Changelog](https://github.com/nfrasser/linkifyjs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/nfrasser/linkifyjs/commits/v4.3.3/packages/linkify-html)

Updates `linkifyjs` from 4.3.2 to 4.3.3
- [Release notes](https://github.com/nfrasser/linkifyjs/releases)
- [Changelog](https://github.com/nfrasser/linkifyjs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/nfrasser/linkifyjs/commits/v4.3.3/packages/linkifyjs)

Updates `sanitize-html` from 2.17.5 to 2.17.7
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.7/packages/sanitize-html)

Updates `zod` from 4.3.6 to 4.5.4
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.3.6...v4.5.4)

Updates `@eslint/markdown` from 8.0.1 to 8.0.3
- [Release notes](https://github.com/eslint/markdown/releases)
- [Changelog](https://github.com/eslint/markdown/blob/main/CHANGELOG.md)
- [Commits](eslint/markdown@v8.0.1...v8.0.3)

Updates `@fast-csv/parse` from 5.0.5 to 5.0.7
- [Release notes](https://github.com/C2FO/fast-csv/releases)
- [Changelog](https://github.com/C2FO/fast-csv/blob/main/packages/parse/CHANGELOG.md)
- [Commits](https://github.com/C2FO/fast-csv/commits/v5.0.7/packages/parse)

Updates `@jest/globals` from 30.3.0 to 30.5.1
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest-globals)

Updates `eslint` from 10.2.0 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.2.0...v10.9.1)

Updates `jest` from 30.3.0 to 30.5.1
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest)

Updates `prettier` from 3.8.1 to 3.9.6
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.1...3.9.6)

Updates `ts-jest` from 29.4.9 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.9...v29.4.12)

Updates `typescript-eslint` from 8.58.0 to 8.69.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: countries-list
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: libphonenumber-js
  dependency-version: 1.13.12
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: linkify-html
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: linkifyjs
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: sanitize-html
  dependency-version: 2.17.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: zod
  dependency-version: 4.5.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@eslint/markdown"
  dependency-version: 8.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@fast-csv/parse"
  dependency-version: 5.0.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@jest/globals"
  dependency-version: 30.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: jest
  dependency-version: 30.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: prettier
  dependency-version: 3.9.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: typescript-eslint
  dependency-version: 8.69.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
@netlify

netlify Bot commented Sep 7, 2026

Copy link
Copy Markdown

Deploy Preview for agoracitizen canceled.

Name Link
🔨 Latest commit ace3537
🔍 Latest deploy log https://app.netlify.com/projects/agoracitizen/deploys/6a9e40b347d24e0008cfebdb

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant