Skip to content

Build(deps): bump the other group across 1 directory with 34 updates - #2529

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/other-4222e74d46
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/other-4222e74d46

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the other group with 34 updates in the / directory:

Package From To
@okta/okta-signin-widget 7.43.1 7.49.1
@tiptap/core 3.31.2 3.31.3
@tiptap/extension-character-count 3.31.2 3.31.3
@tiptap/extension-document 3.31.2 3.31.3
@tiptap/extension-mention 3.31.2 3.31.3
@tiptap/extension-paragraph 3.31.2 3.31.3
@tiptap/extension-text 3.31.2 3.31.3
@tiptap/extension-text-style 3.31.2 3.31.3
@tiptap/pm 3.31.2 3.31.3
@tiptap/react 3.31.2 3.31.3
@tiptap/starter-kit 3.31.2 3.31.3
@tiptap/suggestion 3.31.2 3.31.3
@types/luxon 3.7.4 3.7.5
@uswds/uswds 3.13.0 3.14.0
i18next 26.3.3 26.4.2
launchdarkly-react-client-sdk 3.9.0 3.9.4
react 19.2.4 19.3.0
@types/react 19.2.18 19.3.0
react-dom 19.2.4 19.3.0
@types/react-dom 19.2.4 19.3.0
react-hook-form 7.72.0 7.88.0
react-redux 9.2.0 9.3.0
react-router-dom 7.13.1 7.18.4
react-toastify 11.0.5 11.1.0
recharts 3.8.0 3.10.1
redux-saga 1.4.2 1.5.1
sass 1.98.0 1.104.1
@testing-library/react 16.3.2 16.3.3
@testing-library/user-event 14.6.1 14.6.7
autoprefixer 10.4.27 10.6.1
eslint-import-resolver-typescript 4.4.4 4.4.5
eslint-plugin-prettier 5.5.5 5.5.6
prettier 3.8.1 3.9.8
webpack 5.105.4 5.111.0

Updates @okta/okta-signin-widget from 7.43.1 to 7.49.1

Release notes

Sourced from @​okta/okta-signin-widget's releases.

7.49.1

🐞 Bug fixes

  • fix (gen3): always use "Set up" label on select-authenticator-enroll (#4138) a7382912e

7.49.0

🐞 Bug fixes

  • fix(gen2/gen3): check LNA permission after probing (#4128)
  • fix(gen2): NFC PIN reset header (#4126)
  • fix: Google Authenticator setup UI improvements (#4092)
  • fix: NFC error callout titles (#4108)
  • fix: update rimraf to compliant version (#4109)
  • fix (Gen1): replace deprecated Q with native Promise (#4119)
  • fix(a11y): Text content contrast ratio (#4107)

7.48.2

🐞 Bug fixes

  • Fix NFC sign in button icons (#4110)
  • Fix ReminderPrompt interrupting screen readers in gen 3 (#4115)

7.48.1

🚀 Features

  • feat(gen2/gen3): passkey promotion nudge (#4091) 5d7333f1d

7.48.0

🚀 Features

  • feat: Adds full NFC PIN authenticator support to the SIW(Gen2 and Gen3). (#4081) 6c3373d3c

🐞 Bug fixes

  • fix(gen3): Add aria labels for show password buttons (#4099) ec7d58e4d
  • fix: a11y - per-platform accessible label on OV download badges (#4097) 42d53ffb8
  • fix(gen3): Prevent gen3 input labels from clipping over footer (#4053) 0533c8c8d

... (truncated)

Commits
  • fa508fb chore: version bump 7.49.1
  • a738291 fix (gen3): always use "Set up" label on select-authenticator-enroll (#4138)
  • 37d11cf chore: version bump 7.49.0
  • e77d629 fix(gen2/gen3): check LNA permission after probing (#4128)
  • 7f50214 backport 7.48 to master
  • 84d3921 fix: update rimraf to compliant version (#4109)
  • b0a3e00 fix: OKTA-1259375 NFC PIN reset header - Gen2 (#4126)
  • e127f9f Translations for okta-signin-widget:enduser (#4125)
  • 5225c54 fix (Gen1): replace deprecated Q with native Promise (#4119)
  • 0fec2f2 chore: adds translation string for n of m feature (#4123)
  • Additional commits viewable in compare view

Updates @tiptap/core from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/core's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/core's changelog.

3.31.3

Patch Changes

  • @​tiptap/pm@​3.31.3
Commits

Updates @tiptap/extension-character-count from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/extension-character-count's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/extension-character-count's changelog.

3.31.3

Patch Changes

  • @​tiptap/extensions@​3.31.3
Commits

Updates @tiptap/extension-document from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/extension-document's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/extension-document's changelog.

3.31.3

Patch Changes

  • @​tiptap/core@​3.31.3
Commits

Updates @tiptap/extension-mention from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/extension-mention's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/extension-mention's changelog.

3.31.3

Patch Changes

  • @​tiptap/core@​3.31.3
  • @​tiptap/pm@​3.31.3
  • @​tiptap/suggestion@​3.31.3
Commits

Updates @tiptap/extension-paragraph from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/extension-paragraph's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/extension-paragraph's changelog.

3.31.3

Patch Changes

  • @​tiptap/core@​3.31.3
Commits

Updates @tiptap/extension-text from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/extension-text's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/extension-text's changelog.

3.31.3

Patch Changes

  • @​tiptap/core@​3.31.3
Commits

Updates @tiptap/extension-text-style from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/extension-text-style's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/extension-text-style's changelog.

3.31.3

Patch Changes

  • @​tiptap/core@​3.31.3
Commits

Updates @tiptap/pm from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/pm's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/pm's changelog.

3.31.3

Commits

Updates @tiptap/react from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/react's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/react's changelog.

3.31.3

Patch Changes

  • 99af46d: Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
    • @​tiptap/core@​3.31.3
    • @​tiptap/pm@​3.31.3
Commits

Updates @tiptap/starter-kit from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/starter-kit's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/starter-kit's changelog.

3.31.3

Patch Changes

  • @​tiptap/extension-dropcursor@​3.31.3
  • @​tiptap/extension-gapcursor@​3.31.3
  • @​tiptap/extension-list-item@​3.31.3
  • @​tiptap/extension-list-keymap@​3.31.3
  • @​tiptap/core@​3.31.3
  • @​tiptap/extension-blockquote@​3.31.3
  • @​tiptap/extension-bold@​3.31.3
  • @​tiptap/extension-bullet-list@​3.31.3
  • @​tiptap/extension-code@​3.31.3
  • @​tiptap/extension-code-block@​3.31.3
  • @​tiptap/extension-document@​3.31.3
  • @​tiptap/extension-hard-break@​3.31.3
  • @​tiptap/extension-heading@​3.31.3
  • @​tiptap/extension-horizontal-rule@​3.31.3
  • @​tiptap/extension-italic@​3.31.3
  • @​tiptap/extension-link@​3.31.3
  • @​tiptap/extension-list@​3.31.3
  • @​tiptap/extension-ordered-list@​3.31.3
  • @​tiptap/extension-paragraph@​3.31.3
  • @​tiptap/extension-strike@​3.31.3
  • @​tiptap/extension-text@​3.31.3
  • @​tiptap/extension-underline@​3.31.3
  • @​tiptap/extensions@​3.31.3
  • @​tiptap/pm@​3.31.3
Commits

Updates @tiptap/suggestion from 3.31.2 to 3.31.3

Release notes

Sourced from @​tiptap/suggestion's releases.

v3.31.3

@​tiptap/extension-collaboration-caret

Patch Changes

  • Fixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.

@​tiptap/react

Patch Changes

  • Fix a TypeScript error (TS2694) in the shipped type declarations when skipLibCheck is turned off.
Changelog

Sourced from @​tiptap/suggestion's changelog.

3.31.3

Patch Changes

  • @​tiptap/core@​3.31.3
  • @​tiptap/pm@​3.31.3
Commits

Updates @types/luxon from 3.7.4 to 3.7.5

Commits

Updates @uswds/uswds from 3.13.0 to 3.14.0

Release notes

Sourced from @​uswds/uswds's releases.

USWDS 3.14.0

What's new in USWDS 3.14.0

Features

Package A11y Breaking Markup change Description
usa-accordion, uswds-core Yes Yes Yes Added a left-aligned expand/collapse icon option. A new $theme-accordion-icon-position setting (default: "start") lets teams set icon placement globally. The .usa-accordion--icon-start and .usa-accordion--icon-end modifier classes support per-instance placement. This improves discoverability for users viewing content at high magnification or zoom levels. Thanks @​HopeTurnerUSCIS, @​rosamundtgov, and @​jeana-adhoc! (#6789)✏️ Teams should verify layout at common zoom levels for the new default accordion behavior.
usa-breadcrumb Yes Yes - Breadcrumbs now wrap by default. The previous truncation behavior is now opt-in via the new usa-breadcrumb--truncate modifier class. Thanks @​AKnassa! (#6722) ✏️ Teams should confirm breadcrumbs display as expected and add usa-breadcrumb--truncate if they want the old truncation behavior.
usa-range Yes - Yes Added a visible hint to the range slider. A new usa-hint element with the text "Move the slider to change the value" is added above the slider so sighted users receive the same guidance that screen reader users already had. Thanks @​ravitejapioneerblaze-code! (#6673, #6811) ✏️ Teams should pull in the updated markup.
usa-range Yes - - Improved range slider border visibility. The border is now 2px and uses the base-darker theme token. A focus ring is also added to the slider input. Thanks @​manichandra! (#6659)
usa-date-picker Yes - Yes Added aria-current="date" to today's date button. Assistive technologies can now programmatically identify the current date in the calendar widget. Thanks @​daresTheDevil! (#6593)
usa-file-input - - - Error border now uses the error-dark token. The file input error state previously used secondary-dark, which could show the wrong color in projects with distinct secondary and error palettes. Thanks @​manichandra! (#6669)

Bug fixes

Package A11y Breaking Markup change Description
usa-modal Yes - - Closing a modal now always restores screen reader access to the page. If the element that opened the modal had left the document by the time the modal closed, page content kept aria-hidden="true" and stayed invisible to assistive technology until reload. Thanks @​vssinghh! (#6786)
usa-modal, uswds-core Yes - Yes Fixed modal content being read twice by screen readers. The default focus target has changed — on open, focus now moves to the first enabled button in the modal footer, or the first enabled button in the modal if no footer button is present. FocusTrap no longer uses autoFocus. (#6703)✏️ Teams should verify modal focus lands where expected after this update.
usa-memorable-date Yes - Yes Added per-field hints to the memorable date component. The component previously used a single shared hint referenced by all three fields via aria-describedby, causing screen readers to repeat the full instruction block on every field focus. Each field now has its own targeted hint. The visible group hint remains for sighted users with aria-hidden="true". (#6725)✏️ Teams should update to the new per-field hint markup. Teams supporting other languages should update their hint strings.
usa-file-input Yes Yes Yes Removed the drag instruction on mobile and coarse-pointer devices. The file input previously showed "Drag file here or choose from folder" on all devices, including mobile where drag-and-drop isn't a practical interaction. Coarse-pointer devices now show and announce "Choose from folder" only. Thanks @​manichandra! (#6660)✏️ Teams should check for layout changes and update any accessibility tests that assert the old exact instruction text.
usa-character-count Yes - - Deferred aria-live to prevent iOS VoiceOver from announcing character count on page load. Live updates continue to fire normally during typing. Thanks @​daresTheDevil! (#6595)
usa-character-count - - - Fixed the label selector so it correctly finds the associated label. Thanks @​ealexhaywood! (#6385)
usa-footer - Yes - Restricted data-tag to heading elements. The footer's big link list was vulnerable to XSS through unsanitized data-tag values. Non-heading elements now gracefully fall back to h4. Thanks @​IHIutch! (#6674)✏️ Teams should review any footer data-tag values that aren't heading elements.
usa-banner, uswds-core - - - Fixed toggle so it resolves aria-controls from the component's root node. This allows banner toggles to work correctly when used inside a shadow root. Thanks @​arpitjain099! (#6714)
uswds-core - - - Fixed the language selector Escape key handler. Thanks @​arpitjain099! (#6713)
uswds-core - - - Guarded the keymap against non-keyboard events from datalist selections. This prevents a console error when a user selects an option from a datalist. Thanks @​vijaygovindaraja! (#6594)
usa-table - - - Restored the row header border in borderless tables. Row-scoped body header cells now keep their top border so row headers don't appear visually disconnected. Thanks @​manichandra! (#6661)
usa-table - - - Fixed .usa-sr-only table caption causing heading-row border collapse. Thanks @​IHIutch! (#6633)
usa-time-picker - - - Added missing combobox style dependency to the time picker package. Thanks @​IHIutch! (#6634)
usa-input, usa-textarea, usa-range, usa-combo-box, usa-input-prefix-suffix, usa-select - - - Set box-sizing: border-box on the %block-input-styles mixin to prevent overflow. Components in host environments that reset global box sizing no longer overflow their containers. Thanks @​VenkateshAddala! (#6736)✏️ Teams should verify these elements display correctly in projects with custom global box-sizing resets (e.g. those who set $theme-global-border-box-sizing: false).
usa-in-page-navigation - - - Standardized the component's enhancement guard to use data-enhanced in line with other USWDS components. (#6688)
uswds-core - - - Fixed ink assignment referencing the wrong variable. Custom ink colors in a project's theme were referencing the wrong system token. Thanks @​nektro! (#6651)✏️ Teams should verify that custom ink colors in their theme render as expected.

Guidance changes

Alert

The alert component page now recommends that alert headings start with the alert type to improve clarity and urgency of the message, both for accessibility and general usability, as well as adding extended guidance to help teams use the correct alert type. Thanks @​jeana-adhoc and @​rosamundtgov! (uswds/uswds#3288)

Markup changes

Memorable date

The memorable date component's three fields now each have their own aria-describedby hint instead of sharing a single group hint. Teams who've copied the memorable date markup should update to the per-field pattern:

 <fieldset class="usa-fieldset">
</tr></table> 

... (truncated)

Commits
  • 92391c3 Merge pull request #6822 from uswds/release-3.14.0
  • fb8177f version bump and add hash file
  • bad6161 Merge pull request #6821 from uswds/task/update-notifications
  • 9cd57f3 update wording
  • dfe087f update notifications to capture extent of changes
  • dc23998 Merge pull request #6767 from uswds/bug/5852-audible-cue-character-count-exce...
  • 26ff46d Merge branch 'develop' into bug/5852-audible-cue-character-count-exceeded
  • 622369b Merge pull request #6817 from uswds/feature/6812-prerelease-verification
  • d7863e7 Merge branch 'develop' into feature/6812-prerelease-verification
  • 797e3e9 Merge pull request #6820 from uswds/task/fix-viewbox-setting-deprecation
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​uswds/uswds since your current version.


Updates i18next from 26.3.3 to 26.4.2

Release notes

Sourced from i18next's releases.

v26.4.2

  • fix: $&, $`, $' and $$ inside a nested value ($t(key)) now stay literal. nest() handed the resolved value straight to String.replace as the replacement argument, so those sequences were read as replacement patterns: $& re-inserted the $t(...) match, $` / $' inserted the text before / after it, and $$ collapsed to $. Through t() the $& case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted $t(...) was matched again on every pass and t() never returned — also under the default escapeValue: true when the value arrives via a variable forwarded through nesting options ($t(key, { "name": "{{name}}" }) with a name containing $&). The value is now $-escaped at the String.replace call, the same guard interpolate() already has, and a non-string value returned by a formatter in the nesting chain ($t(key, myFormat)) is stringified before that. Nested values are still not HTML-escaped (#854). Thanks @​mahirhir (#2447).

v26.4.1

  • fix(types): the selector-form keyPrefix overload of getFixedT() is now available under enableSelector: 'strict'. Its constraint was gated on true | 'optimize' only, so under 'strict' it collapsed to never, the overload dropped out, and the returned t silently lost its keyPrefix scope (t(($) => $.deep) failed with Property 'deep' does not exist on type '{}'). The same call already typechecked under true and 'optimize'. Thanks @​hovelopin (#2446).

v26.4.0

  • perf: cache toResolveHierarchy results per (code, fallbackCode) pair. The hierarchy resolver runs on every t() call and calls Intl.getCanonicalLocales multiple times, which showed up prominently when profiling render-heavy UIs (e.g. virtualized data grids); with the cache the per-call cost drops from ~886 ns to ~41 ns. The cache is invalidated automatically when options.fallbackLng changes (reassignment or in-place array mutation); if you mutate other resolution-relevant options at runtime (load, lowerCaseLng, cleanCode, nonExplicitSupportedLngs), call i18next.services.languageUtils.clearCache() afterwards. Function-valued fallbackLng and per-call array/object fallbackLng options are never cached, so dynamic fallbacks keep working as before. Thanks @​equaterina (#2444).
  • chore: update all devDependencies (Babel stays on 7.x until @rollup/plugin-babel supports 8, eslint on 9.x for neostandard). Removed the unused coveralls package (CI uses the Coveralls GitHub Action) and replaced sinon with nise + vitest.spyOn in the v1 compatibility tests, which resolves all open npm audit findings (0 vulnerabilities) and should close the dependabot alerts on the lockfile.

v26.3.6

  • fix: allow TypeScript 7 in the optional typescript peer dependency range (^5 || ^6 || ^7). With typescript@7.0.2 in a project, npm install failed with an ERESOLVE peer conflict. The published types are TS7-compatible as-is: every test/typescript suite produces identical results under 6.0 and 7.0.2. Reported in react-i18next#1927, thanks @​andikapradanaarif.

v26.3.5

  • fix: $t() nesting options blocks that span multiple lines are now parsed. nest() decided where the nested key ends by testing match[1] with /{.*}/, whose dot does not cross line breaks — so a $t(key, { ... }) options object containing a newline was treated as having no options, mis-split as formatters, and the nested lookup ran without its options (placeholders stayed unresolved). The nesting regexp itself already matches newlines inside $t(...); adding the s (dotAll) flag makes multiline options behave like the single-line form. Thanks @​spokodev (#2440).
  • fix: getUsedParamsDetails (the returnDetails: true path) no longer mutates the passed replace object. It wrote count straight onto options.replace so the returned usedParams would include it — a caller reusing one replace object across t() calls then carried a stale count into later interpolations (e.g. a previous call's count: 5 rendered instead of the current call's value). The details are now built from a copy; usedParams still includes count. Thanks @​spokodev (#2441).
  • fix: with the default skipOnVariables: true + escapeValue: true, a {{placeholder}} carried inside an interpolated value now stays literal even when the value contains escapable characters. The skip logic advanced the regex lastIndex by the raw value length, but the escaped text written into the string is longer, so lastIndex landed inside the inserted value and a trailing {{placeholder}} in it got interpolated — leaking another in-scope variable that should have stayed literal (values without escapable characters were already skipped correctly). The advance now uses the escaped length that is actually written, and the regex-safe $-doubling is applied only at the String.replace call so it can't distort the length arithmetic. Thanks @​spokodev (#2442).

v26.3.4

  • fix(security): deepExtend (used by addResourceBundle(..., deep, overwrite)) no longer recurses into inherited properties. It checked key existence with the in operator, which walks the prototype chain, so a source key matching an inherited built-in (e.g. hasOwnProperty, toString) caused recursion into the shared Object.prototype function and, with overwrite: true, could overwrite e.g. Object.prototype.hasOwnProperty.call with a non-callable value — corrupting a shared built-in process-wide (DoS). Existence is now checked with Object.prototype.hasOwnProperty.call, so such keys are copied as plain own data instead. This complements the existing __proto__/constructor guard and is also strictly more correct for an own-property merge. Only affects applications that pass attacker-controlled data with deep: true and overwrite: true; no standard backend/integration does this. Distinct from CVE-2026-48713 / CVE-2026-48714 (different packages, setPath mechanism). Thanks to zx (Jace) for the responsible disclosure.
Changelog

Sourced from i18next's changelog.

26.4.2

  • fix: $&, $`, $' and $$ inside a nested value ($t(key)) now stay literal. nest() handed the resolved value straight to String.replace as the replacement argument, so those sequences were read as replacement patterns: $& re-inserted the $t(...) match, $` / $' inserted the text before / after it, and $$ collapsed to $. Through t() the $& case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted $t(...) was matched again on every pass and t() never returned — also under the default escapeValue: true when the value arrives via a variable forwarded through nesting options ($t(key, { "name": "{{name}}" }) with a name containing $&). The value is now $-escaped at the String.replace call, the same guard interpolate() already has, and a non-string value returned by a formatter in the nesting chain ($t(key, myFormat)) is stringified before that. Nested values are still not HTML-escaped (#854). Thanks @​mahirhir (#2447).

26.4.1

  • fix(types): the selector-form keyPrefix overload of getFixedT() is now available under enableSelector: 'strict'. Its constraint was gated on true | 'optimize' only, so under 'strict' it collapsed to never, the overload dropped out, and the returned t silently lost its keyPrefix scope (t(($) => $.deep) failed with Property 'deep' does not exist on type '{}'). The same call already typechecked under true and 'optimize'. Thanks @​hovelopin (#2446).

26.4.0

  • perf: cache toResolveHierarchy results per (code, fallbackCode) pair. The hierarchy resolver runs on every t() call and calls Intl.getCanonicalLocales multiple times, which showed up prominently when profiling render-heavy UIs (e.g. virtualized data grids); with the cache the per-call cost drops from ~886 ns to ~41 ns. The cache is invalidated automatically when options.fallbackLng changes (reassignment or in-place array mutation); if you mutate other resolution-relevant options at runtime (load, lowerCaseLng, cleanCode, nonExplicitSupportedLngs), call i18next.services.languageUtils.clearCache() afterwards. Function-valued fallbackLng and per-call array/object fallbackLng options are never cached, so dynamic fallbacks keep working as before. Thanks @​equaterina (#2444).
  • chore: update all devDependencies (Babel stays on 7.x until @rollup/plugin-babel supports 8, eslint on 9.x for neostandard). Removed the unused coveralls package (CI uses the Coveralls GitHub Action) and replaced sinon with nise + vitest.spyOn in the v1 compatibility tests, which resolves all open npm audit findings (0 vulnerabilities) and should close the dependabot alerts on the lockfile.

26.3.6

  • fix: allow TypeScript 7 in the optional typescript peer dependency range (^5 || ^6 || ^7). With typescript@7.0.2 in a project, npm install failed with an ERESOLVE peer conflict. The published types are TS7-compatible as-is: every test/typescript suite produces identical results under 6.0 and 7.0.2. Reported in react-i18next#1927, thanks @​andikapradanaarif.

26.3.5

  • fix: $t() nesting options blocks that span multiple lines are now parsed. nest() decided where the nested key ends by testing match[1] with /{.*}/, whose dot does not cross line breaks — so a $t(key, { ... }) options object containing a newline was treated as having no options, mis-split as formatters, and the nested lookup ran without its options (placeholders stayed unresolved). The nesting regexp itself already matches newlines inside $t(...); adding the s (dotAll) flag makes multiline options behave like the single-line form. Thanks @​spokodev (#2440).
  • fix: getUsedParamsDetails (the returnDetails: true path) no longer mutates the passed replace object. It wrote count straight onto options.replace so the returned usedParams would include it — a caller reusing one replace object across t() calls then carried a stale count into later interpolations (e.g. a previous call's count: 5 rendered instead of the current call's value). The details are now built from a copy; usedParams still includes count. Thanks @​spokodev (#2441).
  • fix: with the default skipOnVariables: true + escapeValue: true, a {{placeholder}} carried inside an interpolated value now stays literal even when the value contains escapable characters. The skip logic advanced the regex lastIndex by the raw value length, but the escaped text written into the string is longer, so lastIndex landed inside the inserted value and a trailing {{placeholder}} in it got interpolated — leaking another in-scope variable that should have stayed literal (values without escapable characters were already skipped correctly). The advance now uses the escaped length that is actually written, and the regex-safe $-doubling is applied only at the String.replace call so it can't distort the length arithmetic. Thanks @​spokodev (#2442).

26.3.4

  • fix(security): deepExtend (used by addResourceBundle(..., deep, overwrite)) no longer recurses into inherited properties. It checked key existence with the in operator, which walks the prototype chain, so a source key matching an inherited built-in (e.g. hasOwnProperty, toString) caused recursion into the shared Object.prototype function and, with overwrite: true, could overwrite e.g. Object.prototype.hasOwnProperty.call with a non-callable value — corrupting a shared built-in process-wide (DoS). Existence is now checked with Object.prototype.hasOwnProperty.call, so such keys are copied as plain own data instead. This complements the existing __proto__/constructor guard and is also strictly more correct for an own-property merge. Only affects applications that pass attacker-controlled data with deep: true and overwrite: true; no standard backend/integration does this. Distinct from CVE-2026-48713 / CVE-2026-48714 (different packages, setPath mechanism). See advisory GHSA-6jcc-5g8w-32mx, CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H). Thanks to zx (Jace) @​manus-use for the responsible disclosure.
Commits
  • 4dba50f 26.4.2
  • e436b62 build
  • d955fb0 fix: stringify formatter results in nested values, changelog v26.4.2
  • dfafa3c fix: keep replacement patterns literal in nested values (#2447)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 14, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 14, 2026 01:36
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@dependabot
dependabot Bot requested review from garyjzhao and removed request for a team September 14, 2026 01:36
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Sep 14, 2026
Bumps the other group with 34 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@okta/okta-signin-widget](https://github.com/okta/okta-signin-widget) | `7.43.1` | `7.49.1` |
| [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) | `3.31.2` | `3.31.3` |
| [@tiptap/extension-character-count](https://github.com/ueberdosis/tiptap/tree/HEAD/packages-deprecated/extension-character-count) | `3.31.2` | `3.31.3` |
| [@tiptap/extension-document](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-document) | `3.31.2` | `3.31.3` |
| [@tiptap/extension-mention](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-mention) | `3.31.2` | `3.31.3` |
| [@tiptap/extension-paragraph](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-paragraph) | `3.31.2` | `3.31.3` |
| [@tiptap/extension-text](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-text) | `3.31.2` | `3.31.3` |
| [@tiptap/extension-text-style](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-text-style) | `3.31.2` | `3.31.3` |
| [@tiptap/pm](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/pm) | `3.31.2` | `3.31.3` |
| [@tiptap/react](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/react) | `3.31.2` | `3.31.3` |
| [@tiptap/starter-kit](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/starter-kit) | `3.31.2` | `3.31.3` |
| [@tiptap/suggestion](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/suggestion) | `3.31.2` | `3.31.3` |
| [@types/luxon](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/luxon) | `3.7.4` | `3.7.5` |
| [@uswds/uswds](https://github.com/uswds/uswds) | `3.13.0` | `3.14.0` |
| [i18next](https://github.com/i18next/i18next) | `26.3.3` | `26.4.2` |
| [launchdarkly-react-client-sdk](https://github.com/launchdarkly/react-client-sdk) | `3.9.0` | `3.9.4` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.4` | `19.3.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.18` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.3.0` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.4` | `19.3.0` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.72.0` | `7.88.0` |
| [react-redux](https://github.com/reduxjs/react-redux) | `9.2.0` | `9.3.0` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.13.1` | `7.18.4` |
| [react-toastify](https://github.com/fkhadra/react-toastify) | `11.0.5` | `11.1.0` |
| [recharts](https://github.com/recharts/recharts) | `3.8.0` | `3.10.1` |
| [redux-saga](https://github.com/redux-saga/redux-saga) | `1.4.2` | `1.5.1` |
| [sass](https://github.com/sass/dart-sass) | `1.98.0` | `1.104.1` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |
| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.1` | `14.6.7` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.4.27` | `10.6.1` |
| [eslint-import-resolver-typescript](https://github.com/import-js/eslint-import-resolver-typescript) | `4.4.4` | `4.4.5` |
| [eslint-plugin-prettier](https://github.com/prettier/eslint-plugin-prettier) | `5.5.5` | `5.5.6` |
| [prettier](https://github.com/prettier/prettier) | `3.8.1` | `3.9.8` |
| [webpack](https://github.com/webpack/webpack) | `5.105.4` | `5.111.0` |



Updates `@okta/okta-signin-widget` from 7.43.1 to 7.49.1
- [Release notes](https://github.com/okta/okta-signin-widget/releases)
- [Commits](okta/okta-signin-widget@okta-signin-widget-7.43.1...okta-signin-widget-7.49.1)

Updates `@tiptap/core` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/core/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/core)

Updates `@tiptap/extension-character-count` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages-deprecated/extension-character-count/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages-deprecated/extension-character-count)

Updates `@tiptap/extension-document` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/extension-document/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/extension-document)

Updates `@tiptap/extension-mention` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/extension-mention/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/extension-mention)

Updates `@tiptap/extension-paragraph` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/extension-paragraph/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/extension-paragraph)

Updates `@tiptap/extension-text` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/extension-text/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/extension-text)

Updates `@tiptap/extension-text-style` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/extension-text-style/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/extension-text-style)

Updates `@tiptap/pm` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/pm/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/pm)

Updates `@tiptap/react` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/react/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/react)

Updates `@tiptap/starter-kit` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/starter-kit/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/starter-kit)

Updates `@tiptap/suggestion` from 3.31.2 to 3.31.3
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/suggestion/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/suggestion)

Updates `@types/luxon` from 3.7.4 to 3.7.5
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/luxon)

Updates `@uswds/uswds` from 3.13.0 to 3.14.0
- [Release notes](https://github.com/uswds/uswds/releases)
- [Commits](uswds/uswds@v3.13.0...v3.14.0)

Updates `i18next` from 26.3.3 to 26.4.2
- [Release notes](https://github.com/i18next/i18next/releases)
- [Changelog](https://github.com/i18next/i18next/blob/master/CHANGELOG.md)
- [Commits](i18next/i18next@v26.3.3...v26.4.2)

Updates `launchdarkly-react-client-sdk` from 3.9.0 to 3.9.4
- [Release notes](https://github.com/launchdarkly/react-client-sdk/releases)
- [Changelog](https://github.com/launchdarkly/react-client-sdk/blob/main/CHANGELOG.md)
- [Commits](launchdarkly/react-client-sdk@launchdarkly-react-client-sdk-v3.9.0...launchdarkly-react-client-sdk-v3.9.4)

Updates `react` from 19.2.4 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `@types/react` from 19.2.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-dom` from 19.2.4 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@types/react-dom` from 19.2.4 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `react-hook-form` from 7.72.0 to 7.88.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.72.0...v7.88.0)

Updates `react-redux` from 9.2.0 to 9.3.0
- [Release notes](https://github.com/reduxjs/react-redux/releases)
- [Changelog](https://github.com/reduxjs/react-redux/blob/master/CHANGELOG.md)
- [Commits](reduxjs/react-redux@v9.2.0...v9.3.0)

Updates `react-router-dom` from 7.13.1 to 7.18.4
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom)

Updates `react-toastify` from 11.0.5 to 11.1.0
- [Release notes](https://github.com/fkhadra/react-toastify/releases)
- [Commits](fkhadra/react-toastify@v11.0.5...v11.1.0)

Updates `recharts` from 3.8.0 to 3.10.1
- [Release notes](https://github.com/recharts/recharts/releases)
- [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md)
- [Commits](recharts/recharts@v3.8.0...v3.10.1)

Updates `redux-saga` from 1.4.2 to 1.5.1
- [Release notes](https://github.com/redux-saga/redux-saga/releases)
- [Changelog](https://github.com/redux-saga/redux-saga/blob/main/CHANGELOG.md)
- [Commits](https://github.com/redux-saga/redux-saga/compare/redux-saga@1.4.2...redux-saga@1.5.1)

Updates `sass` from 1.98.0 to 1.104.1
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](sass/dart-sass@1.98.0...1.104.1)

Updates `@testing-library/react` from 16.3.2 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/react-testing-library@v16.3.2...v16.3.3)

Updates `@testing-library/user-event` from 14.6.1 to 14.6.7
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](testing-library/user-event@v14.6.1...v14.6.7)

Updates `autoprefixer` from 10.4.27 to 10.6.1
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.4.27...10.6.1)

Updates `eslint-import-resolver-typescript` from 4.4.4 to 4.4.5
- [Release notes](https://github.com/import-js/eslint-import-resolver-typescript/releases)
- [Changelog](https://github.com/import-js/eslint-import-resolver-typescript/blob/master/CHANGELOG.md)
- [Commits](import-js/eslint-import-resolver-typescript@v4.4.4...v4.4.5)

Updates `eslint-plugin-prettier` from 5.5.5 to 5.5.6
- [Release notes](https://github.com/prettier/eslint-plugin-prettier/releases)
- [Changelog](https://github.com/prettier/eslint-plugin-prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/eslint-plugin-prettier@v5.5.5...v5.5.6)

Updates `prettier` from 3.8.1 to 3.9.8
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.1...3.9.8)

Updates `webpack` from 5.105.4 to 5.111.0
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.105.4...v5.111.0)

---
updated-dependencies:
- dependency-name: "@okta/okta-signin-widget"
  dependency-version: 7.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: "@testing-library/react"
  dependency-version: 16.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@testing-library/user-event"
  dependency-version: 14.6.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/core"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/extension-character-count"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/extension-document"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/extension-mention"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/extension-paragraph"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/extension-text"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/extension-text-style"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/pm"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/react"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/starter-kit"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@tiptap/suggestion"
  dependency-version: 3.31.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@types/luxon"
  dependency-version: 3.7.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: "@uswds/uswds"
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: autoprefixer
  dependency-version: 10.5.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: eslint-import-resolver-typescript
  dependency-version: 4.4.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: eslint-plugin-prettier
  dependency-version: 5.5.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: i18next
  dependency-version: 26.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: launchdarkly-react-client-sdk
  dependency-version: 3.9.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other
- dependency-name: prettier
  dependency-version: 3.9.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: react-hook-form
  dependency-version: 7.87.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: react-redux
  dependency-version: 9.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: react-router-dom
  dependency-version: 7.18.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: react-toastify
  dependency-version: 11.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: recharts
  dependency-version: 3.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: redux-saga
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: sass
  dependency-version: 1.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other
- dependency-name: webpack
  dependency-version: 5.110.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: other
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/other-4222e74d46 branch from 374c2ed to 2a98616 Compare September 21, 2026 01:36
@dependabot @github

dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 22, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/other-4222e74d46 branch September 22, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants