Skip to content

chore(deps): update all non-major dependencies - #961

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pin
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch-digest-pin

Conversation

@renovate

@renovate renovate Bot commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@axe-core/playwright 4.11.3 → 4.13.0 age confidence devDependencies minor
@double-great/stylelint-a11y 3.4.15 → 3.5.4 age confidence devDependencies minor
@playwright/test (source) 1.61.0 → 1.63.0 age confidence devDependencies minor
@types/node (source) 25.9.3 → 25.9.9 age confidence devDependencies patch
actions/cache v5.0.5 → v5.1.0 age confidence action minor
actions/checkout v6.0.3 → v6.1.0 age confidence action minor
actions/setup-node v6.4.0 → v6.5.0 age confidence action minor
actions/upload-artifact v7.0.1 → v7.0.2 age confidence action patch
axe-core (source) 4.12.1 → 4.14.0 age confidence devDependencies minor
docker/build-push-action v7.2.0 → v7.4.0 age confidence action minor
docker/login-action v4.2.0 → v4.6.0 age confidence action minor
docker/metadata-action v6.1.0 → v6.2.0 age confidence action minor
elm-test 0.19.2-0 → 0.19.2-1 age confidence devDependencies patch
fholzer/nginx-brotli v1.31.1 → v1.31.3 age confidence final patch
github/codeql-action v4.36.2 → v4.38.2 age confidence action minor
node (source) 24.16.0 → 24.21.0 age confidence minor
postcss (source) 8.5.23 → 8.5.29 age confidence devDependencies patch
prettier (source) 3.8.4 → 3.9.9 age confidence devDependencies minor
stylelint (source) 17.13.0 → 17.16.0 age confidence devDependencies minor
stylelint-declaration-strict-value 1.11.1 → 1.12.1 age confidence devDependencies minor
stylelint-scss 7.2.0 → 7.3.0 age confidence devDependencies minor

Release Notes

dequelabs/axe-core-npm (@​axe-core/playwright)

v4.13.0

Compare Source

Features

v4.12.1

Compare Source

Features

4.11.3 (2026-04-29)

Bug Fixes

4.11.2 (2026-04-14)

Bug Fixes

4.11.1 (2026-01-09)

Bug Fixes
double-great/stylelint-a11y (@​double-great/stylelint-a11y)

v3.5.4

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.3...v3.5.4

v3.5.3

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.2...v3.5.3

v3.5.2

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.1...v3.5.2

v3.5.1

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.5.0...v3.5.1

v3.5.0

Compare Source

What's Changed

Full Changelog: double-great/stylelint-a11y@v3.4.15...v3.5.0

microsoft/playwright (@​playwright/test)

v1.63.0

Compare Source

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock.
Tests that share a lock name never run concurrently, across files, workers and projects, while
everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group.
Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the
subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it
matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended
replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments,
and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API
steps, the subtitle is the locator or the navigation url — for example, Click with subtitle getByRole('button').
Both are rendered next to the step title in the trace viewer and the HTML report.

🖼️ Aria and screen snapshots in traces

The snapshots option of tracing.start() and the testOptions.trace fixture option now accept an
object selecting what to capture on every action:

// playwright.config.ts
export default defineConfig({
  use: {
    trace: {
      mode: 'on',
      snapshots: { dom: true, aria: true, screen: true }
    },
  },
});

With aria and screen snapshots recorded, the new Display Aria mode in the trace viewer shows the action screenshot
side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.

New APIs

Browser and Context
Locators
const response = await request.get<User>('/api/users/42');
const user = await response.json(); // typed as User
Test runner
  • New standalone testOptions.reducedMotion, testOptions.forcedColors and testOptions.contrast options.
  • New --add-reporter command line option appends a reporter on top of the ones configured in playwright.config, instead of replacing them like --reporter does.
  • New omitTags option for the list, line, dot, github and junit reporters suppresses the tags that are automatically appended to test titles.
Command line
  • npx playwright install --no-remove keeps the browsers of other Playwright installations instead of removing them.
  • npx playwright codegen --http-credentials records against pages behind HTTP authentication.
Miscellaneous
  • New built-in perfetto reporter writes a Trace Event Format file for the Perfetto UI or chrome://tracing, rendering the test run as a timeline with a lane per worker.
  • The HTML report renders a duration waterfall next to test steps.

Announcements

  • ⚠️ The experimental @playwright/experimental-ct-react, @playwright/experimental-ct-react17 and @playwright/experimental-ct-vue packages will no longer be updated. Follow the migration guide to move to the stories model introduced in 1.62. Story ids passed to fixtures.mount() can now be typed through the generated Stories registry.
  • ⚠️ Ubuntu 20.04 is not supported anymore.
  • 🐧 On Linux arm64, Playwright now downloads the Chrome for Testing build of Chromium, the same build used on all other platforms.

Browser Versions

  • Chromium 153.0.8010.12
  • Mozilla Firefox 155.0
  • WebKit 26.6

This version was also tested against the following stable channels:

  • Google Chrome 153
  • Microsoft Edge 153

v1.62.1

Compare Source

Bug Fixes
  • #​41989 [Regression]: tsconfig "extends" bare specifier isn't resolved via node_modules walk-up like tsc (fatal since 1.62)
  • #​41998 [Regression]: directory-form tsconfig project references ("path": "../pkg") fail to resolve (fatal since 1.62)
  • #​41985 Accessibility snapshot drops button name when text is nested inside spans with aria-hidden SVG
  • #​42000 [Regression]: page.evaluate() arg of a branded primitive type (string & { brand }) no longer type-checks since 1.62
  • #​42013 [BUG]Image-type actionable elements are not presented in the snapshot.

v1.62.0

Compare Source

🧱 New component testing model

Component testing moves to a stories and galleries model.
A story wraps your component in one specific scenario — hard-coded props, mock data, providers — and a gallery page that you serve renders stories on demand.
The new fixtures.mount() fixture navigates to the gallery, mounts a story by id, and returns a Locator scoped to the story's root element:

test('click should expand', async ({ mount }) => {
  const component = await mount('components/Expandable/Stateful');
  await component.getByRole('button').click();
  await expect(component.getByTestId('expanded')).toHaveValue('true');
});

Pass a story type as a template argument to type-check its props, and use update(props) / unmount() on the returned locator to re-render or tear down within a test.

🛑 Cancel operations with AbortSignal

Most operations and web-first assertions now accept a signal option that takes an AbortSignal, letting you cancel long-running actions, navigations, waits, and assertions:

const controller = new AbortController();
setTimeout(() => controller.abort(), 1000);

await page.getByRole('button', { name: 'Submit' }).click({ signal: controller.signal });
await expect(page.getByText('Done')).toBeVisible({ signal: controller.signal });

Providing a signal does not disable the default timeout; pass timeout: 0 to disable it.

🖼️ WebP screenshots

expect(page).toHaveScreenshot() and expect(locator).toHaveScreenshot() can now store snapshots in the WebP format — just give the snapshot a .webp name:

// Visual comparisons store the golden snapshot as lossless WebP.
await expect(page).toHaveScreenshot('homepage.webp');

// Standalone screenshots can trade quality for size with lossy WebP.
await page.screenshot({ path: 'homepage.webp', quality: 50 });

page.screenshot() and [locator.screenshot() (https://playwright.dev/docs/api/class-locator#locator-screenshot) also accept webp as a type, where quality 100 (the default) is lossless and lower values use lossy compression.

🧩 Custom test filtering with Reporter.preprocess()

New reporter.preprocess() hook runs after the configuration is resolved and before reporter.onBegin(), letting a reporter mark individual tests as skipped, excluded, fixed, or failing through a TestRun object:

class MyReporter {
  async preprocess({ config, suite, testRun }) {
    for (const test of suite.allTests()) {
      if (shouldSkip(test))
        testRun.skip(test);
    }
  }
}

🔁 Isolated retries

New testConfig.retryStrategy controls when failed tests are retried.
The default 'immediate' retries as soon as a worker is free; 'isolated' runs all retries at the end, one by one in a single worker, to minimize interference with the rest of the suite:

// playwright.config.ts
export default defineConfig({
  retries: 2,
  retryStrategy: 'isolated',
});

New APIs

Browser and Context
  • New option credentials includes the context's virtual WebAuthn Credentials (passkeys) in the storage state, so they can be persisted and re-seeded into later contexts.
Actions
  • New scroll option ("auto" | "none") on actions to opt out of Playwright's automatic scroll-into-view.
Network
Evaluation
Command line & MCP
Reporters
  • The HTML report's Merge files grouping — previously only a UI toggle — can now be enabled from the config with the new mergeFiles reporter option:
// playwright.config.ts
export default defineConfig({
  reporter: [['html', { mergeFiles: true }]],
});

Announcements

  • ⚠️ Debian 11 is not supported anymore.

Browser Versions

  • Chromium 151.0.7922.34
  • Mozilla Firefox 153.0
  • WebKit 26.5

This version was also tested against the following stable channels:

  • Google Chrome 151
  • Microsoft Edge 151

v1.61.1

Compare Source

Bug Fixes
  • #​41365 [Bug]: Expect.Extend matcher with same name as default matcher in same expect instance overrides default matchers implementation to custom matcher
  • #​41351 [Bug]: Playwright UI mode: apiRequestContext._wrapApiCall reports unexpected number of bytes (same test passes in headed mode)
  • #​41360 [Bug]: Trace viewer: message times in websockets are downscaled by 1000
  • #​41311 [Bug]: [Regression]: Sync loader throws "context.conditions?.includes is not a function" on Node 22.15
  • #​41371 [Regression]: Sync ESM loader (registerHooks) fails to resolve extensionless .ts subpath imports across pnpm workspace symlinks
actions/cache (actions/cache)

v5.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

actions/checkout (actions/checkout)

v6.1.0

Compare Source

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

actions/setup-node (actions/setup-node)

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

actions/upload-artifact (actions/upload-artifact)

v7.0.2

Compare Source

What's Changed

  • Improves artifact download retries when the service returns HTTP 429 (rate limiting), including honoring valid Retry-After headers.
  • Updates @​actions/artifact to v6.3.1.

New Contributors

Full Changelog: actions/upload-artifact@v7.0.1...v7.0.2

dequelabs/axe-core (axe-core)

v4.14.0

Compare Source

Features
Bug Fixes

v4.13.0

Compare Source

Features
Bug Fixes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner June 16, 2026 17:43
@renovate renovate Bot added the dependencies Indicates a change to dependencies label Jun 16, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch from de129db to c7a5c43 Compare June 16, 2026 19:40
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies to v8.5.15 chore(deps): update all non-major dependencies Jun 18, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from 57aefad to 3a3880a Compare June 25, 2026 16:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 10 times, most recently from 5490ef5 to 513d222 Compare July 2, 2026 10:48
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from fb44c72 to 69cddc7 Compare July 9, 2026 19:38
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 7984cbb to 10fabd6 Compare July 12, 2026 13:17
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 8 times, most recently from e902edf to a4f922b Compare August 4, 2026 17:54
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 4 times, most recently from c63428b to 9090f25 Compare August 11, 2026 22:04
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from 2da452c to 45d550c Compare August 19, 2026 01:05
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 5 times, most recently from f82ac1e to f6eaf72 Compare August 26, 2026 18:49
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 7 times, most recently from 5bddced to 4aeedec Compare September 5, 2026 13:47
@renovate
renovate Bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 21cdbd6 to 3910ada Compare September 9, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Indicates a change to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants