Skip to content

chore: release v0.17.0 - #2992

Merged
danielroe merged 34 commits into
releasefrom
main
Jul 15, 2026
Merged

chore: release v0.17.0#2992
danielroe merged 34 commits into
releasefrom
main

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Jul 3, 2026

Copy link
Copy Markdown

This PR will deploy the following changes to production (npmx.dev).

Next version: v0.17.0 (current: v0.16.1)

Features

Fixes

Other Changes


Merging this PR will:

  • Deploy to npmx.dev via Vercel
  • Create a v0.17.0 tag and GitHub Release
  • Publish npmx-connector@0.17.0 to npm

@github-actionsgithub-actionsBot added the release Production release PR label Jul 3, 2026
@github-actions
github-actionsBot requested review from a teamJuly 3, 2026 18:29
@github-actionsgithub-actionsBot added the release Production release PR label Jul 3, 2026
@vercel

vercelBot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
npmx-lunariaReadyReadyPreview, CommentJul 15, 2026 9:33am
npmx.devReadyReadyPreview, CommentJul 15, 2026 9:33am
1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
docs.npmx.devIgnoredIgnoredPreviewJul 15, 2026 9:33am

Request Review

Co-authored-by: Willow (GHOST) <git@willow.sh>
@github-actionsgithub-actionsBot changed the title chore: release v0.16.2chore: release v0.17.0Jul 4, 2026
@github-actions

github-actionsBot commented Jul 4, 2026

Copy link
Copy Markdown
Author

e18e dependency analysis

No dependency warnings found.

@github-actions

github-actionsBot commented Jul 4, 2026

Copy link
Copy Markdown
Author

Lunaria Status Overview

🌕 This pull request will trigger status changes.

Learn more

By default, every PR changing files present in the Lunaria configuration's files property will be considered and trigger status changes accordingly.

You can change this by adding one of the keywords present in the ignoreKeywords property in your Lunaria configuration file in the PR's title (ignoring all files) or by including a tracker directive in the merged commit's description.

Tracked Files

FileNote
i18n/locales/ar.jsonLocalization changed, will be marked as complete. 🔄️
i18n/locales/bn-IN.jsonLocalization changed, will be marked as complete. 🔄️
i18n/locales/en.jsonSource changed, localizations will be marked as outdated.
i18n/locales/hi-IN.jsonLocalization changed, will be marked as complete. 🔄️
i18n/locales/ja-JP.jsonLocalization changed, will be marked as complete. 🔄️
i18n/locales/nl.jsonLocalization changed, will be marked as complete. 🔄️
i18n/locales/ru-RU.jsonLocalization changed, will be marked as complete. 🔄️
Warnings reference
IconDescription
🔄️The source for this localization has been updated since the creation of this pull request, make sure all changes in the source have been applied.

Co-authored-by: Your Name <your@email.com>
Co-authored-by: Willow (GHOST) <git@willow.sh>
Co-authored-by: graphieros <alec.lloyd.probert@gmail.com>
Co-authored-by: Alec Lloyd Probert <55991794+graphieros@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Willow (GHOST) <git@willow.sh>
@socket-security

socket-securityBot commented Jul 5, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/@nuxtjs/i18n@10.4.0npm/nuxt@4.4.8npm/storybook@10.4.6npm/docus@5.12.3npm/unocss@66.7.4npm/@nuxt/scripts@1.3.0npm/rolldown@1.1.4npm/knip@6.24.0npm/nuxt-og-image@6.7.2npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm @mswjs/interceptors is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/msw@2.14.6npm/@mswjs/interceptors@0.41.9

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@mswjs/interceptors@0.41.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm better-sqlite3 is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:docs/package.jsonnpm/better-sqlite3@12.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/better-sqlite3@12.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm css-tree is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/@nuxt/fonts@0.14.0npm/nuxt@4.4.8npm/docus@5.12.3npm/unocss@66.7.4npm/nuxt-og-image@6.7.2npm/css-tree@3.2.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/css-tree@3.2.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/vite-plugin-pwa@1.3.0npm/es-abstract@1.24.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-abstract@1.24.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm oxfmt is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/vite-plus@0.2.2npm/oxfmt@0.57.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/oxfmt@0.57.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm oxfmt is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/vite-plus@0.2.2npm/oxfmt@0.57.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/oxfmt@0.57.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/@nuxt/fonts@0.14.0npm/@nuxt/test-utils@4.0.3npm/@nuxtjs/i18n@10.4.0npm/unplugin-vue-markdown@32.0.0npm/vue-router@5.1.0npm/nuxt@4.4.8npm/@storybook/addon-docs@10.4.6npm/@nuxt/ui@4.9.0npm/docus@5.12.3npm/unocss@66.7.4npm/@unocss/nuxt@66.7.4npm/@nuxt/scripts@1.3.0npm/nuxt-og-image@6.7.2npm/webpack@5.108.4

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.108.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:pnpm-lock.yamlnpm/msw@2.14.6npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

…2714)
Signed-off-by: Matt Van Horn <mvanhorn@gmail.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Co-authored-by: Willow (GHOST) <git@willow.sh>
Co-authored-by: Willow (GHOST) <git@willow.sh>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Alec Lloyd Probert <55991794+graphieros@users.noreply.github.com>
Co-authored-by: Willow (GHOST) <git@willow.sh>
Co-authored-by: Felix Schneider <99918022+trueberryless@users.noreply.github.com>
patak-cat
patak-cat previously approved these changes Jul 15, 2026
@danielroedanielroe reopened this Jul 15, 2026
@danielroe
danielroe merged commit 688a1e2 into releaseJul 15, 2026
72 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

releaseProduction release PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@patak-cat@ghostdevv@danielroe@43081j@alexdln@trueberryless@shuuji3@BittuBarnwal7479@graphieros@fengmk2@btea@harlan-zw@AriPerkkio@gittihub-jpg@2u841r@gameroman@dragomano@mvanhorn@juninhokaponne@ayuwidyaagata