Skip to content

chore(deps): bump the npm_and_yarn group across 3 directories with 2 updates#1121

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/npm_and_yarn-6d293111cb
Open

chore(deps): bump the npm_and_yarn group across 3 directories with 2 updates#1121
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/npm_and_yarn-6d293111cb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 2 updates in the / directory: waku and react-router.
Bumps the npm_and_yarn group with 1 update in the /apps/docs.lumeweb.com directory: waku.
Bumps the npm_and_yarn group with 1 update in the /apps/docs.pinner.xyz directory: waku.

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates react-router from 7.5.0 to 8.3.0

Release notes

Sourced from react-router's releases.

v8.3.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v830

v8.2.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v820

v8.1.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v810

v8.0.1

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v801

v8.0.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v800

v7.18.1

See the changelog for release notes: https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7181

v7.18.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180

v7.17.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7170

v7.16.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7160

v7.15.1

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7151

v7.15.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7150

v7.14.2

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7142

v7.14.1

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7141

v7.14.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7140

v7.13.2

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7132

v7.13.1

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7131

v7.13.0

See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7130

... (truncated)

Changelog

Sourced from react-router's changelog.

v8.3.0

Patch Changes

  • Encode path params in href/generatePath per RFC 3986 path-segment rules instead of encodeURIComponent (#15310)
    • Characters that are valid literally in a path segment ($ & + , ; = : @ — RFC 3986 pchar) are no longer percent-encoded, so values like a semver build 1.0.0+1 interpolate unchanged instead of becoming 1.0.0%2B1
    • Structural/unsafe characters (/ ? # %, whitespace, non-ASCII) are still escaped exactly as before
  • Use crypto.randomUUID() for createMemorySessionStorage session ids (#15302)
    • createMemorySessionStorage is only intended for local development and testing - sessions are lost when the server restarts
  • Fix NavLink not applying its pending state when to has a trailing slash (#15300)
  • Preserve RSC route component metadata so routes with a clientLoader can skip unnecessary server requests once their components have rendered while still fetching missing server-rendered elements (#15323)
  • Harden RSC CSRF code paths (#15311)
  • Fix server crash (TypeError: Invalid state: Unable to enqueue) when a request is aborted while the RSC HTML stream has a pending flush (#15286)
    • Handle cancellation of the injectRSCPayload readable side, clear the pending flush, and cancel the underlying RSC payload stream

Unstable Changes

⚠️ Unstable features are not recommended for production use

  • Detect stale RSC clients during lazy route discovery and reload the destination document (#15318)

    Migration

    Apps using the default RSC Framework entry do not need to make any changes. Apps with a custom entry.rsc.tsx should import the generated client version and pass it to unstable_matchRSCServerRequest:

    import clientVersion from "virtual:react-router/unstable_rsc/client-version";
    return unstable_matchRSCServerRequest({
    // ...
    clientVersion,
    });

  • Add CSP nonce support to RSC document rendering (#15320)

    • Add nonce options to unstable_routeRSCServerRequest and unstable_RSCStaticRouter
    • Forward the nonce to the HTML renderer and apply it to injected RSC payload scripts and nonce-aware framework components

    To adopt nonce-based CSP, update your entry.ssr.tsx (run react-router reveal entry.ssr first in RSC Framework Mode) to generate a fresh nonce for each request. Pass it to routeRSCServerRequest, spread the renderHTML options into React's HTML renderer, pass options.nonce to RSCStaticRouter, and use the same nonce in the Content-Security-Policy response header:

    const nonce = crypto.randomUUID();
    const response = await routeRSCServerRequest({
      request,
      serverResponse,
      createFromReadableStream,
      nonce,
      async renderHTML(getPayload, options) {
        const payload = getPayload();
        return renderHTMLToReadableStream(

... (truncated)

Commits
  • 2edaca7 Release v8.3.0 (#15294)
  • 687ab72 Prep release notes
  • d2f1f1b update changes files to use h4 instead of h3 (#15334)
  • 8186207 fix(rsc): preserve component metadata for client loader revalidation (#15323)
  • c26e431 feat(rsc): support CSP nonces in document rendering (#15320)
  • 6286f90 feat(rsc): reload stale clients after new deployments (#15318)
  • 3d83ad4 docs: fix useLinkClickHandler defaultShouldRevalidate default description (#1...
  • f75c89f Update docs links to v8 API reference (#15316)
  • baa9ba6 fix: encode path params per RFC 3986 path-segment rules in href/generatePath ...
  • 69debd1 fix: apply NavLink pending state when the to prop has a trailing slash (#15300)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react-router since your current version.


Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

Updates waku from 1.0.0-beta.0 to 1.0.0-beta.1

Release notes

Sourced from waku's releases.

v1.0.0-beta.1

This release includes security updates, bug fixes, and internal refactors to improve stability and maintainability.

What's Changed

Full Changelog: wakujs/waku@v1.0.0-beta.0...v1.0.0-beta.1

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-6d293111cb branch from f516db5 to ce412fb Compare July 26, 2026 14:21
…updates

Bumps the npm_and_yarn group with 2 updates in the / directory: [waku](https://github.com/wakujs/waku/tree/HEAD/packages/waku) and [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router).
Bumps the npm_and_yarn group with 1 update in the /apps/docs.lumeweb.com directory: [waku](https://github.com/wakujs/waku/tree/HEAD/packages/waku).
Bumps the npm_and_yarn group with 1 update in the /apps/docs.pinner.xyz directory: [waku](https://github.com/wakujs/waku/tree/HEAD/packages/waku).


Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `react-router` from 7.5.0 to 8.3.0
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router@8.3.0/packages/react-router)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

Updates `waku` from 1.0.0-beta.0 to 1.0.0-beta.1
- [Release notes](https://github.com/wakujs/waku/releases)
- [Changelog](https://github.com/wakujs/waku/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wakujs/waku/commits/v1.0.0-beta.1/packages/waku)

---
updated-dependencies:
- dependency-name: react-router
  dependency-version: 8.3.0
  dependency-type: direct:production
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:production
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:production
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:production
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:development
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:development
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:development
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:production
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:production
- dependency-name: waku
  dependency-version: 1.0.0-beta.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-6d293111cb branch from ce412fb to a269ee2 Compare July 26, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants