Skip to content

chore(deps-dev): bump valibot from 1.3.1 to 1.5.0 - #154

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bun/valibot-1.5.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bun/valibot-1.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown

Bumps valibot from 1.3.1 to 1.5.0.

Release notes

Sourced from valibot's releases.

v1.5.0

Many thanks to @​tats-u, @​idleberg, @​yslpn, @​francisjohnjohnston-web, @​MaxFreedomPollard, @​mahirhir, @​ItzXynx, @​LeSingh1, @​maxtaran2010, @​ysknsid25, @​cyyynthia, @​spokodev and @​sanjibani for contributing to this release.

  • Add codePoints, maxCodePoints, minCodePoints and notCodePoints validation actions to validate the number of Unicode code points (pull request #888)
  • Add ksuid validation action to validate KSUIDs (pull request #1370)
  • Change Standard Schema properties to use eager initialization for faster schema construction and replace internal _getStandardProps utility with _standardSchema (pull request #1534)
  • Change url action to use URL.canParse when available to avoid constructing URL objects (pull request #1608)
  • Fix stringifyJson action to preserve the dataset value when JSON.stringify returns undefined (pull request #1476)
  • Fix literal schema and value, values, notValue and notValues actions to treat NaN as equal to itself (pull request #1573)
  • Fix intersect schema to merge matching NaN values and invalid dates (pull request #1573)
  • Fix cache and cacheAsync methods to clone the issues of a cached dataset, preventing parent schemas from adding their path item to the same issue on every cache hit (pull request #1620)
  • Fix strictObject, looseObject, objectWithRest and their async variants to correctly handle unknown input keys that collide with Object.prototype members (pull request #1523)
  • Fix intersect and intersectAsync schemas to ignore inherited properties when merging objects and preserve own properties without invoking inherited setters or changing the output prototype (pull request #1621)
  • Fix ulid action to reject ULIDs that exceed the maximum 128-bit value (pull request #1498)
  • Fix email action to reject non-ASCII characters accepted by Unicode case folding (pull request #1075)

v1.5.0 (to-json-schema)

  • Add support for JSON Schema draft-2020-12 and OpenAPI 3.0 Schema Object format
  • Add propertyNames support to record schemas for key validation constraints
  • Add support for toBigint, toBoolean, toDate, toNumber and toString actions for typeMode: 'input'
  • Add new toStandardJsonSchema function to convert Valibot schemas to Standard JSON Schema format
  • Change return type from JSONSchema7 to a custom JsonSchema type

v1.4.2

Many thanks to @​Faze-up and @​chatman-media for contributing to this release.

  • Fix word count actions to cache the Intl.Segmenter for non-primitive locales, preventing it from being recreated on every words, minWords, maxWords and notWords validation (pull request #1521)
  • Fix flatten method to handle issue path keys that collide with Object.prototype members like toString instead of throwing a TypeError (pull request #1522)
  • Fix intersect schema to merge object keys that collide with Object.prototype members like toString instead of failing to merge them (pull request #1522)

v1.4.1

  • Fix intersect schema to infer correct input and output types for non-tuple array options instead of never (pull request #1478)

v1.4.0

Many thanks to @​ksaurav24, @​heiwen, @​compulim, @​ysknsid25, @​alaycock-stripe, @​IlyaSemenov, @​wszgrcy, @​LMGO, @​yslpn, @​EltonLobo07 and @​Eronmmer for contributing to this release.

Read the release notes on our website for a quick overview of the most exciting new features in this release.

  • Add isoDateTimeSecond validation action to validate ISO date times with seconds (pull request #1418)
  • Add toCamelCase, toKebabCase, toPascalCase and toSnakeCase transformation actions to convert strings between common naming conventions (pull request #1457)
  • Change internal ReadonlyOutputKeys and OutputWithReadonly types of object schemas and WithReadonly type of record schemas to improve TypeScript type performance (pull request #1442)
  • Change hot paths to reduce object allocations and improve runtime performance (pull request #1437)
  • Change build target to ES2020 so distributed output stays compatible with environments that lack support for newer syntax (pull request #1455)
  • Change internal _LruCache to use a TypeScript private method instead of a #private class field to avoid runtime helpers in the transpiled output (pull request #1455)
  • Change internal _isValidObjectKey to use Object.prototype.hasOwnProperty.call instead of Object.hasOwn so the distributed output stays compatible with runtimes that lack the ES2022 Object.hasOwn builtin (pull request #1421)
  • Change flatten method to accept readonly issue arrays (pull request #1269)
  • Fix potential RangeError caused by spreading large issue arrays (pull request #1437)
  • Fix creditCard validation action to reject Mastercard numbers with invalid lengths (pull request #1462)
  • Fix intersect schema to no longer mutate input values, allowing frozen objects and arrays to be merged (pull request #1463)

... (truncated)

Commits
  • 5016198 chore: prepare Valibot v1.5.0 release (#1627)
  • 1ffb038 fix(intersect): skip inherited prototype props in _merge (#1621)
  • 1c4983f fix(ulid): restrict first character to 0-7 per ULID spec (#1498)
  • 5e449cd perf(url): use URL.canParse for validation (#1608)
  • 4acda1b Make sure that email validators don't match unintentional non-ASCII local par...
  • 95943ab fix: handle object keys that collide with Object.prototype in object schemas ...
  • d65438c fix(cache): clone cached issues to stop issue paths from accumulating (#1620)
  • 3ed804a dependabot: bump the github-actions group across 1 directory with 2 updates (...
  • 0681f43 fix: use SameValueZero equality for special numeric values (#1573)
  • 98ef8b4 Improve perf by changing ~standard implementation (#1534)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from beeeku as a code owner September 25, 2026 14:17
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 8f65877b-429f-4830-935c-a9803a4d74a5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Bundle Size Report

Package Base PR Delta
@workkit/agent 80KiB 80KiB no change
@workkit/ai 94KiB 94KiB no change
@workkit/ai-gateway 260KiB 260KiB no change
@workkit/api 119KiB 119KiB no change
@workkit/approval 106KiB 106KiB no change
@workkit/astro 18KiB 18KiB no change
@workkit/auth 48KiB 48KiB no change
@workkit/browser 32KiB 32KiB no change
@workkit/cache 39KiB 39KiB no change
@workkit/chat 47KiB 47KiB no change
@workkit/chat-react 20KiB 20KiB no change
@workkit/cli 312KiB 312KiB no change
@workkit/cron 68KiB 68KiB no change
@workkit/crypto 40KiB 40KiB no change
@workkit/d1 90KiB 90KiB no change
@workkit/do 58KiB 58KiB no change
@workkit/env 43KiB 43KiB no change
@workkit/errors 40KiB 40KiB no change
@workkit/features 23KiB 23KiB no change
@workkit/health 19KiB 19KiB no change
@workkit/hono 36KiB 36KiB no change
@workkit/kv 52KiB 52KiB no change
@workkit/logger 24KiB 24KiB no change
@workkit/mail 54KiB 54KiB no change
@workkit/mcp 127KiB 127KiB no change
@workkit/memory 41KiB 41KiB no change
@workkit/notify 290KiB 290KiB no change
@workkit/pdf 36KiB 36KiB no change
@workkit/queue 54KiB 54KiB no change
@workkit/r2 57KiB 57KiB no change
@workkit/ratelimit 51KiB 51KiB no change
@workkit/realtime 44KiB 44KiB no change
@workkit/remix 34KiB 34KiB no change
@workkit/testing 114KiB 114KiB no change
@workkit/turnstile 14KiB 14KiB no change
@workkit/types 21KiB 21KiB no change
@workkit/workflow 46KiB 46KiB no change

Bumps [valibot](https://github.com/open-circle/valibot) from 1.3.1 to 1.5.0.
- [Release notes](https://github.com/open-circle/valibot/releases)
- [Commits](open-circle/valibot@v1.3.1...v1.5.0)

---
updated-dependencies:
- dependency-name: valibot
  dependency-version: 1.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@beeeku

beeeku commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Superseded by #160, which folds this bump into a workspace-wide in-range refresh (and, for #148, pairs react with react-dom so the docs build stays consistent).

@beeeku beeeku closed this Sep 29, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/bun/valibot-1.5.0 branch September 29, 2026 11:12
beeeku added a commit that referenced this pull request Sep 29, 2026
…#115)

Clears every error-level trivy finding in bun.lock (25 -> 0) so
`maina verify` passes without suppression.

Workspace refresh (`bun update -r`, no majors for shipped code):
- Runtime floors move only in approval/mcp (hono ^4.13.11, past the
  4.12.x advisories) and mail (mimetext ^3.0.28, postal-mime ^2.7.6);
  patch changeset included. Peer ranges unchanged.
- Folds in #153 (`@cloudflare/puppeteer` 1.4.0, dev-only) and #154
  (`valibot` 1.5.0). Pairs react + react-dom 19.3, superseding #148.
- Root override `@puppeteer/browsers` ^3.2.3 drops `extract-zip` 2.0.1
  (symlink file-write CVEs, no upstream fix). Dev-only; browser/pdf
  tests pass 35/35 and 51/51.

apps/docs (private, not published) — Astro 5 -> 7:
- astro ^7.2.10, @astrojs/starlight ^0.42.4, @astrojs/react ^7,
  @astrojs/starlight-tailwind ^5, tailwindcss ^4 via @tailwindcss/vite;
  drops @astrojs/tailwind and tailwind.config.ts (CSS-first config).
- Starlight 0.39+ sidebar: autogenerate moves into `items`.
- `bg-gradient-to-r` -> `bg-linear-to-r` (Tailwind 4 rename).
- Fixes the critical AVIF RCE plus SSRF/XSS advisories on astro.
- Same 33 pages built; `astro check` 0 errors; landing + guide pages
  screenshot-compared against the Astro 5 build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant