Skip to content

chore(deps): bump the npm group across 1 directory with 5 updates - #20

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-124eafbd4b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-124eafbd4b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown

Bumps the npm group with 5 updates in the / directory:

Package From To
@types/node 22.20.1 26.6.3
esbuild 0.25.12 0.28.2
mediabunny 1.53.1 1.60.0
typescript 5.9.3 7.0.2
@modelcontextprotocol/sdk 1.30.0 1.30.1

Updates @types/node from 22.20.1 to 26.6.3

Commits

Updates esbuild from 0.25.12 to 0.28.2

Release notes

Sourced from esbuild's releases.

v0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})

... (truncated)

Changelog

Sourced from esbuild's changelog.

Changelog: 2025

This changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).

0.27.2

  • Allow import path specifiers starting with #/ (#4361)

    Previously the specification for package.json disallowed import path specifiers starting with #/, but this restriction has recently been relaxed and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping #/* to ./src/* (previously you had to use another character such as #_* instead, which was more confusing). There is some more context in nodejs/node#49182.

    This change was contributed by @​hybrist.

  • Automatically add the -webkit-mask prefix (#4357, #4358)

    This release automatically adds the -webkit- vendor prefix for the mask CSS shorthand property:

    /* Original code */
    main {
      mask: url(x.png) center/5rem no-repeat
    }
    /* Old output (with --target=chrome110) */
    main {
    mask: url(x.png) center/5rem no-repeat;
    }
    /* New output (with --target=chrome110) */
    main {
    -webkit-mask: url(x.png) center/5rem no-repeat;
    mask: url(x.png) center/5rem no-repeat;
    }

    This change was contributed by @​BPJEnnova.

  • Additional minification of switch statements (#4176, #4359)

    This release contains additional minification patterns for reducing switch statements. Here is an example:

    // Original code
    switch (x) {
      case 0:
        foo()
        break
      case 1:
      default:
        bar()
    }

... (truncated)

Commits
  • 609683d publish 0.28.2 to npm
  • 11b1fe4 add to release notes
  • ab50d91 css: fix green/blue channel swap in oklch gamut mapping (#4488)
  • 04627b6 fix #4498: async TLA checks need a worklist
  • 5c15177 disable gopls in the go folder
  • fc2ee9b css: adjust parser to allow --foo: {...}
  • 209db54 release notes for css nesting bugfix
  • c625d31 fix #4497: preserve nested ampersands during minification (#4500)
  • 34474e2 better isolation of current part in js parser
  • 07f6e8c fix #4507: import assignment tree-shaking bug
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for esbuild since your current version.


Updates mediabunny from 1.53.1 to 1.60.0

Release notes

Sourced from mediabunny's releases.

v1.60.0

  • Added VideoTrackMetadata.canBeTransparent to provide transparency hints to the muxer
  • Fixed how Matroska segment duration is interpreted
  • Fixed Opus in HLS not getting the correct codec string (#529)
  • Prevented HLS muxer from emitting BANDWIDTH=0

v1.59.1

  • Fixed conversion API erroring for files that violate the GOP timestamp rule for audio tracks (#526)
  • Fixed extension worker errors not surfacing, causing promises to never resolve (#525)
  • Added support for recursive SeekHeads when reading Matroska (#524)

v1.59.0

  • Added MetadataTags.beatsPerMinute (#514)
  • Fixed audio resampling sometimes flushing output buffers too early (#519)
  • Fixed HLS BANDWIDTH attribute not being inherited to tracks for URI-less media renditions (#520)
  • Made HLS demuxer less strict with playlists that reference non-existing media groups (#520)

v1.58.1

  • Fixed invalid scaling for µ-law and A-law audio (#517)
  • Fixed inverted A-law audio polarity
  • Fixed off-by-one errors when doing PCM audio encode->decode roundtrips or using AudioSample.copyTo()
  • UrlSource now aborts ongoing requests immediately on dispose (#518)

v1.58.0

  • Added ConversionCopyOptions.boundaryTolerance for controlling the maximum permitted additional/removed media to make a copy path possible (#511)
  • Fixed Conversion API erroring in packet copy path when the input file violated the GOP keyframe rule (#511)
  • Ignore Content-Length/Range headers on encoded 206 responses (#513)

v1.57.0

  • Added support for flipped video: flip metadata is exposed via InputVideoTrack.getFlip() (applied after rotation) and supported bidirectionally for ISOBMFF and Matroska, and flipping is now available across the whole API surface: VideoTrackMetadata.flip, VideoSampleInit.flip, VideoSample.flip, VideoSample.setFlip(), flip options for drawing video frames, VideoSampleTransformOptions.flip, VideoTransformOptions.flip, CanvasSinkOptions.flip and ConversionVideoOptions.flip. Custom VideoSample transformers now also receive the flip as a transformation input, and it is a supported operation in @mediabunny/server. Flipping metadata can be automatically passed through in the Conversion API in the packet copy path. (#510)
  • Added InputVideoTrack.getTransformationMatrix(): returns the raw 3x3 affine transformation matrix the track applies to its raw video frames. Rotation and flip are derived from this, but it can contain other transformations as well. This matrix can be written into new files via VideoTrackMetadata.transformationMatrix.
  • Added automatic writing of the btrt (bitrate) box when muxing ISOBMFF files
  • Added BaseTrackMetadata.bitrate and BaseTrackMetadata.averageBitrate for providing bitrate guesstimates as metadata
  • btrt bitrate metadata is now extracted from ISOBMFF files and exposed via InputTrack.getBitrate() and InputTrack.getAverageBitrate()
  • Added a frameRate option to the canEncodeVideo helper functions (#507)
  • Deprecated OutputFormat.supportsVideoRotationMetadata, use OutputFormat.supportsVideoTransformationMetadata instead.
  • Deprecated ConversionVideoOptions.allowRotationMetadata, use ConversionVideoOptions.allowTransformationMetadata instead.
  • Fixed untranslated rotation matrices being written into ISOBMFF header boxes
  • ISOBMFF demuxer now also respects the movie-global transformation matrix
  • Fixed incorrect parsing of AES-128 IV in HLS (#509)
  • Output.finalize() failing now automatically transitions the Output to the canceled state (#506)

v1.56.3

  • Fixed CustomSource not canceling streams when disposing inputs (#499)

v1.56.2

  • Fixed upmixing from stereo to quad or 5:1 resulting in NaN samples (#497)

v1.56.1

  • Repeated metadata keys for Vorbis-style metadata (Ogg, FLAC) are now surfaced as string[] in raw (#490)

... (truncated)

Commits
  • 359e4e4 Bump minor
  • 51cbaa1 Fix lint
  • 84e48de Clean up, add fix for BANDWIDTH=0 in HLS muxer
  • d407b27 Merge pull request #529 from lagudafuadtosin/hls-opus-codec-string
  • 9d26f28 Write Opus as "Opus" in the HLS CODECS attribute
  • 206b1bd Add VideoTrackMetadata.canBeTransparent, write Matroska segment duration the ...
  • 049a893 Bump patch
  • 2fb9518 Add support for recursive SeekHeads in Matroska (closes #524)
  • 0010bed Merge pull request #525 from benhall-7/main
  • 5da21a6 Drop audio packets in copy conversion if they would violate the GOP timestamp...
  • Additional commits viewable in compare view

Updates typescript from 5.9.3 to 7.0.2

Release notes

Sourced from typescript's releases.

TypeScript 7.0.2

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0.1 RC

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0 Beta

For release notes, check out the release announcement.

Downloads are available on:

Commits
  • 1e4744d Merge branch 'main' into ts7-release
  • a5a219cmicrosoft/typescript-go#4558
  • ecfe30d Update status localization
  • 5de25b5 Hide executable name in TypeScript status
  • d7ce74a Show bundled TypeScript version for packaged servers
  • 29be66a Correct TS 7 release version to 7.0.2
  • ed2bd1b Merge branch 'main' into ts7-release
  • 8873075 Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...
  • 9427131 Set up stable / nightly extension split, other prep (microsoft/typescript-go#...
  • d4eaca5microsoft/typescript-go#4549
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Updates @modelcontextprotocol/sdk from 1.30.0 to 1.30.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Bumps the npm group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.20.1` | `26.6.3` |
| [esbuild](https://github.com/evanw/esbuild) | `0.25.12` | `0.28.2` |
| [mediabunny](https://github.com/Vanilagy/mediabunny) | `1.53.1` | `1.60.0` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.30.1` |



Updates `@types/node` from 22.20.1 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `esbuild` from 0.25.12 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)
- [Commits](evanw/esbuild@v0.25.12...v0.28.2)

Updates `mediabunny` from 1.53.1 to 1.60.0
- [Release notes](https://github.com/Vanilagy/mediabunny/releases)
- [Commits](Vanilagy/mediabunny@v1.53.1...v1.60.0)

Updates `typescript` from 5.9.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: mediabunny
  dependency-version: 1.60.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants