Skip to content

Bump the npm-minor-and-patch-updates group across 2 directories with 17 updates - #281

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-updates-5a83dd1627
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-updates-5a83dd1627

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-and-patch-updates group with 17 updates in the / directory:

Package From To
hmrc-frontend 7.35.0 7.38.0
marked 18.0.13 18.0.14
mongoose 9.10.1 9.10.3
sanitize-html 2.17.7 2.18.0
@types/sanitize-html 2.16.1 2.16.2
tsx 4.23.13 4.23.15
@cspell/eslint-plugin 10.3.2 10.3.6
@types/sanitize-html 2.16.1 2.16.2
cspell 10.3.2 10.3.6
eslint 10.10.0 10.11.0
eslint-plugin-perfectionist 5.11.1 5.12.1
jest 30.5.1 30.5.2
mongodb-memory-server 11.2.0 11.3.0
prettier 3.9.6 3.9.9
supertest 7.2.2 7.3.0
ts-jest 29.4.12 29.4.14
typescript-eslint 8.70.0 8.71.0
undici 8.10.2 8.11.2

Bumps the npm-minor-and-patch-updates group with 3 updates in the /data/zip-download directory: hmrc-frontend, marked and tsx.

Updates hmrc-frontend from 7.35.0 to 7.38.0

Release notes

Sourced from hmrc-frontend's releases.

7.38.0

Release : hmrc-frontend 7.38.0

Last commit sha : e1c0ec80d29d7c1cd2baece5f338451a9a6bea99 Last commit author : Jo Pinto Paul Last commit time : 2026-09-23T12:23:25Z

PLATUI-4401: Fixing alignment of language toggle in service navigation on small screens (#567)

Co-authored-by: Tim Bryan timsb@users.noreply.github.com

7.37.0

Release : hmrc-frontend 7.37.0

Last commit sha : 08c42e9316de3a5fb4e6d288bddf7e703723e3e2 Last commit author : Jo Pinto Paul Last commit time : 2026-09-22T12:02:36Z

NOJIRA: npm dependency updates based on audit (#569)

7.36.0

Release : hmrc-frontend 7.36.0

Last commit sha : a0b606d8c63ed9d49f1318523fe7018a82b33bab Last commit author : Patryk Rudnicki Last commit time : 2026-09-21T08:21:16Z

Merge pull request #568 from hmrc/NOJIRA_npm-vulns-exemptions-update

NOJIRA - npm vulnerabilities exemption list updated

Changelog

Sourced from hmrc-frontend's changelog.

[7.38.0] - 2026-09-22

  • Fixed bug where service-navigation-language-select could overflow container when there is a long service name

[7.37.0] - 2026-09-22

  • Dependencies upgrade

[7.36.0] - 2026-09-21

  • Updated npm audit exclusions
Commits
  • e1c0ec8 PLATUI-4401: Fixing alignment of language toggle in service navigation on sma...
  • 08c42e9 NOJIRA: npm dependency updates based on audit (#569)
  • a0b606d Merge pull request #568 from hmrc/NOJIRA_npm-vulns-exemptions-update
  • 7ab7293 NOJIRA - npm vulnerabilities exemption list updated
  • See full diff in compare view

Updates marked from 18.0.13 to 18.0.14

Release notes

Sourced from marked's releases.

v18.0.14

18.0.14 (2026-09-22)

Bug Fixes

Commits

Updates mongoose from 9.10.1 to 9.10.3

Release notes

Sourced from mongoose's releases.

9.10.3 / 2026-09-29

  • fix(model): preserve unsaved documents after ordered bulkSave errors #16533 #16532 IbrahimHafez1
  • fix(model): don't mutate the caller's update object in bulkWrite updateMany #16526 fadiroot
  • fix(schema): run setters declared on the union path itself #16528 giaBaoJS
  • fix(collection): open collection if connection was already opened #16527 #16525 #16524
  • fix(query+model): replace {MODEL} in cast error messages from update and bulkWrite casting #16529 #16502 #16480

9.10.2 / 2026-09-22

Changelog

Sourced from mongoose's changelog.

9.10.3 / 2026-09-29

  • fix(model): preserve unsaved documents after ordered bulkSave errors #16533 #16532 IbrahimHafez1
  • fix(model): don't mutate the caller's update object in bulkWrite updateMany #16526 fadiroot
  • fix(schema): run setters declared on the union path itself #16528 giaBaoJS
  • fix(collection): open collection if connection was already opened #16527 #16525 #16524
  • fix(query+model): replace {MODEL} in cast error messages from update and bulkWrite casting #16529 #16502 #16480

9.10.2 / 2026-09-22

Commits
  • d5841fe chore: release 9.10.3
  • 6779047 Merge pull request #16537 from Automattic/vkarpov15/gh-16529
  • 5ed18f4 Merge pull request #16533 from IbrahimHafez1/fix/ordered-bulk-save-state
  • 780de3f refactor(model): track bulkSave document indexes
  • 04a985a refactor(model): separate ordered and unordered bulkSave results
  • 519f399 fix(query+model): replace {MODEL} in cast error messages from update and bulk...
  • 4093445 Merge pull request #16528 from giaBaoJS/fix/union-path-setters
  • dd91af4 Merge pull request #16527 from Automattic/vkarpov15/gh-16524
  • 3d905bb fix(model): preserve unsaved documents after ordered bulkSave errors
  • 5d3bafd fix(schema): run setters declared on the union path itself
  • Additional commits viewable in compare view

Updates sanitize-html from 2.17.7 to 2.18.0

Changelog

Sourced from sanitize-html's changelog.

2.18.0 (2026-09-30)

Adds

  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.

Fixes

  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for the fix.

Security

  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).

    Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.

Commits

Updates @types/sanitize-html from 2.16.1 to 2.16.2

Commits

Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Updates @cspell/eslint-plugin from 10.3.2 to 10.3.6

Release notes

Sourced from @​cspell/eslint-plugin's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from @​cspell/eslint-plugin's changelog.

v10.3.6 (2026-09-29)

Fixes

  • fix: Report unknown CSpell directives again (#9319)

  • fix(cspell-io): Keep redirected requests under the private root (#9329)

  • fix: Don't reuse cached results made with different command-line options (#9318)

  • fix(cspell-lib): Don't scan the text of documents that won't be checked (#9311)

  • fix: --show-perf-summary shows where all of the run's time goes (#9307)

v10.3.5 (2026-09-27)

Fixes

  • fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)

  • fix: --force-check checks the listed files even when ignorePaths or files would skip them (#9300)

  • fix: files globs starting with ** no longer skip --file and --file-list files in a project under a dot folder (#9299)

  • fix: Thai text and substitutions are checked and reported correctly (#9289)

v10.3.4 (2026-09-24)

Fixes

  • fix: Report errors (#9267)

  • fix: ParsedTag can only be boolean values for now. (#9268)

  • fix: Fix Sponsor cards on npmjs (#9260)

Dictionary Updates

... (truncated)

Commits

Updates @types/sanitize-html from 2.16.1 to 2.16.2

Commits

Updates cspell from 10.3.2 to 10.3.6

Release notes

Sourced from cspell's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.6 (2026-09-29)

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Commits
  • 8559198 v10.3.6
  • 72e1be3 chore: Prepare Release v10.3.6 (auto-deploy) (#9305)
  • e230ca0 test: Give time-limited RPC and worker tests room on slow runners (#9330)
  • 8eae6b6 fix: Report unknown CSpell directives again (#9319)
  • a5f5111 fix: Don't reuse cached results made with different command-line options (#9318)
  • 2f897be fix: --show-perf-summary shows where all of the run's time goes (#9307)
  • fe37b7b chore: Label per package, and bugs links to its open issues (#9309)
  • f37a244 v10.3.5
  • b36374c chore: Prepare Release v10.3.5 (auto-deploy) (#9277)
  • 93e55c0 fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)
  • Additional commits viewable in compare view

Updates eslint from 10.10.0 to 10.11.0

Release notes

Sourced from eslint's releases.

v10.11.0

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#20395) (Nitin Kumar)
Commits
  • 3c0b7c6 10.11.0
  • 321f0a7 Build: changelog update for 10.11.0
  • 520dd77 perf: Implement fast paths in critical areas (#21210)
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331)
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311)
  • 24310e3 chore: update ecosystem plugins (#21324)
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21...
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)
  • Additional commits viewable in compare view

Updates eslint-plugin-perfectionist from 5.11.1 to 5.12.1

Release notes

Sourced from eslint-plugin-perfectionist's releases.

v5.12.1

   🐞 Bug Fixes

    View changes on GitHub

v5.12.0

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Changelog

Sourced from eslint-plugin-perfectionist's changelog.

v5.12.1

compare changes

🐞 Bug Fixes

  • Make eslint an optional peer dependency (41b088e)

❤️ Contributors

v5.12.0

compare changes

🚀 Features

  • Support oxlint without an eslint installation (5488d84)

🐞 Bug Fixes

  • Honor eslint-disable directives with a description (e3d11cc)

❤️ Contributors

Commits
  • 43c3464 build: publish v5.12.1
  • 41b088e fix: make eslint an optional peer dependency
  • e28e3a0 build: publish v5.12.0
  • 521314f chore: update dependencies
  • 5488d84 feat: support oxlint without an eslint installation
  • 38eb692 refactor: share context option matching and comparators
  • e3d11cc fix: honor eslint-disable directives with a description
  • f7eae67 chore: update github actions
  • See full diff in compare view

Updates jest from 30.5.1 to 30.5.2

Release notes

Sourced from jest's releases.

v30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)

New Contributors

Full Changelog: jestjs/jest@v30.5.1...v30.5.2

Changelog

Sourced from jest's changelog.

30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)
Commits

Updates mongodb-memory-server from 11.2.0 to 11.3.0

Release notes

Sourced from mongodb-memory-server's releases.

v11.3.0

11.3.0 (2026-09-21)

Features

Fixes

  • MongoBinaryDownload::attemptDownload: add log when response recieves a error (143588b)
  • MongoBinaryDownload::attemptDownload: change "console.error" to a debug "log" (833bcc7)
  • MongoBinaryDownload: replace zip implementation with new promise API (3fb04f4), closes #990
  • MongoInstance::stop: change to always unset the "mongodProcess" (9e32ef2), closes #1032
  • MongoMemoryReplSet: increase "electionTimeoutMillis" timeout to 5000ms (76d727a), closes #995

Style

  • utils::killProcess: fix typo "An" -> "A" (c2a18ac)

Refactor

  • MongoBinaryDownload: have the 2 extract function be more similar (940b352)

Dependencies

…17 updates

Bumps the npm-minor-and-patch-updates group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [hmrc-frontend](https://github.com/hmrc/hmrc-frontend) | `7.35.0` | `7.38.0` |
| [marked](https://github.com/markedjs/marked) | `18.0.13` | `18.0.14` |
| [mongoose](https://github.com/Automattic/mongoose) | `9.10.1` | `9.10.3` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.7` | `2.18.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html) | `2.16.1` | `2.16.2` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [@cspell/eslint-plugin](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell-eslint-plugin) | `10.3.2` | `10.3.6` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html) | `2.16.1` | `2.16.2` |
| [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) | `10.3.2` | `10.3.6` |
| [eslint](https://github.com/eslint/eslint) | `10.10.0` | `10.11.0` |
| [eslint-plugin-perfectionist](https://github.com/azat-io/eslint-plugin-perfectionist) | `5.11.1` | `5.12.1` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.5.1` | `30.5.2` |
| [mongodb-memory-server](https://github.com/typegoose/mongodb-memory-server/tree/HEAD/packages/mongodb-memory-server) | `11.2.0` | `11.3.0` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.12` | `29.4.14` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.0` | `8.71.0` |
| [undici](https://github.com/nodejs/undici) | `8.10.2` | `8.11.2` |

Bumps the npm-minor-and-patch-updates group with 3 updates in the /data/zip-download directory: [hmrc-frontend](https://github.com/hmrc/hmrc-frontend), [marked](https://github.com/markedjs/marked) and [tsx](https://github.com/privatenumber/tsx).


Updates `hmrc-frontend` from 7.35.0 to 7.38.0
- [Release notes](https://github.com/hmrc/hmrc-frontend/releases)
- [Changelog](https://github.com/hmrc/hmrc-frontend/blob/main/CHANGELOG.md)
- [Commits](hmrc/hmrc-frontend@v7.35.0...v7.38.0)

Updates `marked` from 18.0.13 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.13...v18.0.14)

Updates `mongoose` from 9.10.1 to 9.10.3
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@9.10.1...9.10.3)

Updates `sanitize-html` from 2.17.7 to 2.18.0
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.18.0/packages/sanitize-html)

Updates `@types/sanitize-html` from 2.16.1 to 2.16.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `@cspell/eslint-plugin` from 10.3.2 to 10.3.6
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell-eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell-eslint-plugin)

Updates `@types/sanitize-html` from 2.16.1 to 2.16.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)

Updates `cspell` from 10.3.2 to 10.3.6
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell)

Updates `eslint` from 10.10.0 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.10.0...v10.11.0)

Updates `eslint-plugin-perfectionist` from 5.11.1 to 5.12.1
- [Release notes](https://github.com/azat-io/eslint-plugin-perfectionist/releases)
- [Changelog](https://github.com/azat-io/eslint-plugin-perfectionist/blob/main/changelog.md)
- [Commits](azat-io/eslint-plugin-perfectionist@v5.11.1...v5.12.1)

Updates `jest` from 30.5.1 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `mongodb-memory-server` from 11.2.0 to 11.3.0
- [Release notes](https://github.com/typegoose/mongodb-memory-server/releases)
- [Changelog](https://github.com/typegoose/mongodb-memory-server/blob/master/CHANGELOG.md)
- [Commits](https://github.com/typegoose/mongodb-memory-server/commits/v11.3.0/packages/mongodb-memory-server)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

Updates `ts-jest` from 29.4.12 to 29.4.14
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.14)

Updates `typescript-eslint` from 8.70.0 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

Updates `undici` from 8.10.2 to 8.11.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.10.2...v8.11.2)

Updates `hmrc-frontend` from 7.35.0 to 7.38.0
- [Release notes](https://github.com/hmrc/hmrc-frontend/releases)
- [Changelog](https://github.com/hmrc/hmrc-frontend/blob/main/CHANGELOG.md)
- [Commits](hmrc/hmrc-frontend@v7.35.0...v7.38.0)

Updates `marked` from 18.0.13 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.13...v18.0.14)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

---
updated-dependencies:
- dependency-name: hmrc-frontend
  dependency-version: 7.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: mongoose
  dependency-version: 9.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: sanitize-html
  dependency-version: 2.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@types/sanitize-html"
  dependency-version: 2.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@cspell/eslint-plugin"
  dependency-version: 10.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@types/sanitize-html"
  dependency-version: 2.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: cspell
  dependency-version: 10.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: eslint-plugin-perfectionist
  dependency-version: 5.12.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: mongodb-memory-server
  dependency-version: 11.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: ts-jest
  dependency-version: 29.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: undici
  dependency-version: 8.11.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: hmrc-frontend
  dependency-version: 7.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from cmenon12 as a code owner October 5, 2026 02:08
@dependabot dependabot Bot added the dependencies Updates to dependencies label Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Updates to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant