Skip to content

Bump smol-toml and nx - #408

Merged
BaseMax merged 2 commits into
mainfrom
dependabot/npm_and_yarn/multi-eaeb213a91
Oct 8, 2026
Merged

BaseMax merged 2 commits into
mainfrom
dependabot/npm_and_yarn/multi-eaeb213a91

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps smol-toml and nx. These dependencies needed to be updated together.
Updates smol-toml from 1.6.1 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

v1.8.0

What's Changed

Full Changelog: squirrelchat/smol-toml@v1.7.2...v1.8.0

v1.7.2

What's Changed

... (truncated)

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates nx from 23.1.1 to 23.3.0

Release notes

Sourced from nx's releases.

23.3.0 (2026-10-07)

🚀 Features

  • angular: support ngrx v22 (#36950)
  • angular-rspack: scaffold and run SSR apps on the @​angular/ssr application engine (#36298)
  • core: emit a runbook and per-step instructions for orchestrated migrate runs (#36766)
  • core: report the cache location alongside usage (#36959)
  • core: share one workspace walk across processes through the files archive (#36980)
  • core: hash a continuous dependency's inputs into the task it serves (#37017)
  • core: guarantee terminal output files and add an agent-friendly summary output style (#36703)
  • core: add includeIgnored filesets and let the workspace context own the daemon's watch (#37025)
  • core: cache plugin capabilities so reading them costs at most one load (#36999)
  • core: spawn one agent session for orchestrated migrate runs and land its installs and commits (#36918)
  • core: add sandbox target configuration for observed-IO opt-out (#36853)
  • core: hash tasks from Nx Cloud I/O snapshots (#37036)
  • core: replace the sandbox target property with ultracache (#37165)
  • core: opt in to selecting affected tasks instead of projects (#36825)
  • core: record unresolved migrations and cap retries in orchestrated migrate runs (#36986)
  • core: report an active orchestrated migrate run instead of resuming it (#36988)
  • core: report abandoned, revisited and resumed orchestrated migrate runs and their dispense ordinals (#36989)
  • core: turn ultracache on with NX_CLOUD_USE_ULTRACACHE (#37242)
  • core: explain why each task is affected with --explain (#36885)
  • core: run a final agent validation pass at the end of an orchestrated migrate run (#37069)
  • js: cache TypeScript reference expansion during createNodes (#37003, #37002)
  • linter: add a batched @​nx/oxlint:lint executor (#36827)
  • nx-cloud: add nx cloud demo link to cloud prompts (#36956)
  • nx-cloud: remove the never option from the nx cloud prompt (#37079)
  • repo: add a .NET example for @​nx/dotnet (#36701)
  • testing: support cypress v16 (#36953)
  • vitest: support vitest 5 (#37142)

🩹 Fixes

  • angular: correct declaration maps and exports of buildable libraries (#36373, #36357)
  • angular-rspack: keep incremental rebuild state warm when skipTypeChecking is enabled (#36972, #36970)
  • angular-rspack: keep class field closures per instance in minified builds (#37066, #37050)
  • angular-rspack: update piscina to address critical vulnerability (#37252)
  • bundling: write the esbuild bundle to an overridden outputPath (#37101, #37091)
  • bundling: clear typescript update timer when a rollup build closes its watch program (#37196)
  • core: separate daemon runtime env from graph identity (#36565, #36564)
  • core: validate the migrations path before extracting package migrations (#36887)
  • core: release per-run process listeners and task history results (#36866)
  • core: read the pnpm 12 min-release-age policy instead of deferring to an install (#36915, #36914)
  • core: carry minimumReleaseAge into pruned pnpm deploy output (#36900, #36899)
  • core: report how a plugin worker was lost instead of always calling it an exit (#36894)
  • core: keep the cache in the workspace on CI (#36922)
  • core: restore the wasm walker imports dropped by a stray cfg attribute (#36924)
  • core: avoid mutating target options when resolving configurations (#36934)
  • core: carry pnpm's package-manager document into the pruned lockfile (#36947)

... (truncated)

Commits
  • 2b305ee fix(core): accept --final-validation with a migrate CLI pinned below 23.2.0 (...
  • d133deb fix(core): size the default cache bound from its own filesystem (#37269)
  • cd1ea02 fix(core): reuse the stored ultracache configurations without an age limit (#...
  • e09f772 fix(core): stop merging declared negations into ultracache file groups (#37304)
  • a0dc568 chore(core): update smol-toml to 1.9.0 for GHSA-r4xh-jqrq-34v2 (#37293)
  • a26644b fix(core): answer daemon output tracking from the workspace context (#37217)
  • 3ec060f fix(core): keep ultracache exclusions with the globs they trim (#37285)
  • af0b4fb feat(core): run a final agent validation pass at the end of an orchestrated m...
  • ead0427 fix(core): skip batch cache lookups for deferred tasks until their deps run (...
  • da9d339 feat(core): explain why each task is affected with --explain (#36885)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [smol-toml](https://github.com/squirrelchat/smol-toml) and [nx](https://github.com/nrwl/nx/tree/HEAD/packages/nx). These dependencies needed to be updated together.

Updates `smol-toml` from 1.6.1 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.6.1...v1.9.0)

Updates `nx` from 23.1.1 to 23.3.0
- [Release notes](https://github.com/nrwl/nx/releases)
- [Commits](https://github.com/nrwl/nx/commits/23.3.0/packages/nx)

---
updated-dependencies:
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: indirect
- dependency-name: nx
  dependency-version: 23.3.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from BaseMax as a code owner October 8, 2026 09:39
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2026
@dependabot
dependabot Bot requested a review from jbampton as a code owner October 8, 2026 09:39
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2026
@BaseMax
BaseMax merged commit 536c1e2 into main Oct 8, 2026
5 checks passed
@BaseMax
BaseMax deleted the dependabot/npm_and_yarn/multi-eaeb213a91 branch October 8, 2026 09:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant