[Snyk] Upgrade @hotwired/turbo from 8.0.13 to 8.0.21#388
Open
HeapReaper wants to merge 1 commit intomainfrom
Open
[Snyk] Upgrade @hotwired/turbo from 8.0.13 to 8.0.21#388HeapReaper wants to merge 1 commit intomainfrom
HeapReaper wants to merge 1 commit intomainfrom
Conversation
Snyk has created this PR to upgrade @hotwired/turbo from 8.0.13 to 8.0.21. See this package in npm: @hotwired/turbo See this project in Snyk: https://app.snyk.io/org/kelvincodesstuff/project/7e5a08b3-4c92-4b98-968e-963d61efed79?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade @hotwired/turbo from 8.0.13 to 8.0.21.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 6 versions ahead of your current version.
The recommended version was released a month ago.
Issues fixed by the recommended upgrade:
SNYK-JS-HOTWIREDTURBO-15046444
Release notes
Package name: @hotwired/turbo
-
8.0.21 - 2026-01-16
- Remove
- Remove
- Bump multer from 1.4.2 to 2.0.2 by @ dependabot[bot] in #1451
- Add
- Functional Tests: Replace chai with Playwright Assertions by @ seanpdoyle in #1454
- Fix regression with empty target attribute (#1444) by @ yujiteshima in #1455
- Functional Tests: Rendering - Replace
- Rendering Functional Tests: Replace chai with Playwright by @ seanpdoyle in #1459
- Frame Functional Tests: Replace chai with Playwright by @ seanpdoyle in #1461
- Build: Remove circular dependency by @ seanpdoyle in #1453
- Visit Functional Tests: Replace chai with Playwright by @ seanpdoyle in #1463
- Fix UUID generation to include all hex digits by @ kaisersakhi in #1425
- Fix #577: Send the Turbo-Frame header as referenced by data-turbo-frame attribute on form submission by @ inkstak in #579
- Add support for data-turbo-frame="_parent" in nested frames by @ anthonyfranco in #1446
- Use new format instead of legacy by @ loqimean in #1016
- Remove duplicate siblings when using before/after actions by @ tpaulshippy in #1290
- Update html[dir] attribute during navigation by @ alhajrahmoun in #1418
- Loading Functional Tests: Replace
- Remove deprecated support for
- Remove deprecated
- Playwright Root: use
- Simplify same page anchor visits by @ domchristie in #1285
- Playwright: replace
- Bump js-yaml from 4.1.0 to 4.1.1 by @ dependabot[bot] in #1468
- Remove
- Tests: Flaky
- Prevent slow turbo frame requests from resetting cookies by @ domchristie in #1399
- Fix noscript style evaluation during navigation (#1464) by @ yujiteshima in #1475
- Mention the correct element "data-turbo-suppress-warning" is expected on by @ redross in #1424
- @ yujiteshima made their first contribution in #1455
- @ kaisersakhi made their first contribution in #1425
- @ inkstak made their first contribution in #579
- @ anthonyfranco made their first contribution in #1446
- @ loqimean made their first contribution in #1016
- @ tpaulshippy made their first contribution in #1290
- @ alhajrahmoun made their first contribution in #1418
- @ redross made their first contribution in #1424
-
8.0.20 - 2025-10-28
- Fix: preserve removed turbo-frames with refresh=morph on page refreshes by @ jorgemanrubia in #1452
-
8.0.19 - 2025-10-28
- Better testing timeouts for less painful development by @ botandrose in #1317
- Add 2 second timeouts to infinitely-looping assertions by @ botandrose in #1378
- Reloading a morphing frame should trigger reloads on its child morphing frames recursively by @ botandrose in #1311
- Revert fetch to call window.fetch directly again by @ chrisyuska in #1381
- Bump koa from 2.15.4 to 2.16.1 by @ dependabot[bot] in #1398
- Update playwright by @ silva96 in #1400
- Respect prefers-reduced-motion by @ indykoning in #1409
- Rename meta tag used to enable view transitions to turbo-view-transition by @ Intrepidd in #1380
- Make sure full page reloads use the response URL after a redirect by @ m-vo in #1420
- Improve prefetch/navigation performance by @ m-vo in #1421
- Fix navigating to the turbo-root does not use Turbo Drive by @ m-vo in #1426
- Don't ignore the browser's default for
- Expose morphing functions for consumer use by @ seanpdoyle in #1319
- bump idiomorph version to 0.7.4 by @ htcarr3 in #1441
- @ chrisyuska made their first contribution in #1381
- @ silva96 made their first contribution in #1400
- @ indykoning made their first contribution in #1409
- @ m-vo made their first contribution in #1420
- @ stefanvermaas made their first contribution in #1429
- @ htcarr3 made their first contribution in #1441
-
8.0.18 - 2025-09-26
- Better testing timeouts for less painful development by @ botandrose in #1317
- Add 2 second timeouts to infinitely-looping assertions by @ botandrose in #1378
- Reloading a morphing frame should trigger reloads on its child morphing frames recursively by @ botandrose in #1311
- Revert fetch to call window.fetch directly again by @ chrisyuska in #1381
- Bump koa from 2.15.4 to 2.16.1 by @ dependabot[bot] in #1398
- Update playwright by @ silva96 in #1400
- Respect prefers-reduced-motion by @ indykoning in #1409
- Rename meta tag used to enable view transitions to turbo-view-transition by @ Intrepidd in #1380
- Make sure full page reloads use the response URL after a redirect by @ m-vo in #1420
- Improve prefetch/navigation performance by @ m-vo in #1421
- Fix navigating to the turbo-root does not use Turbo Drive by @ m-vo in #1426
- Don't ignore the browser's default for
- Expose morphing functions for consumer use by @ seanpdoyle in #1319
- @ chrisyuska made their first contribution in #1381
- @ silva96 made their first contribution in #1400
- @ indykoning made their first contribution in #1409
- @ m-vo made their first contribution in #1420
- @ stefanvermaas made their first contribution in #1429
-
8.0.17 - 2025-09-26
-
8.0.14 - 2025-09-26
-
8.0.13 - 2025-03-02
from @hotwired/turbo GitHub release notesWhat's Changed
SubmitEventpolyfill by @ seanpdoyle in #909requestSubmitpolyfill by @ seanpdoyle in #908[method]and[scroll]attributes for Refresh Stream by @ seanpdoyle in #1208chaiwith Playwright by @ seanpdoyle in #1458assertwithexpectby @ seanpdoyle in #1466[data-turbo-cache="false"]by @ seanpdoyle in #1470Turbo.clearCache()function by @ seanpdoyle in #1471expectinstead ofassertby @ seanpdoyle in #1467PrefetchCache: extract and re-useLRUCachefromSnapshotCacheby @ seanpdoyle in #1469assertwithexpectby @ seanpdoyle in #1465chai: Replace all calls with Playwright'sexpectby @ seanpdoyle in #1473[autofocus]assertions by @ seanpdoyle in #1474New Contributors
Full Changelog: v8.0.20...v8.0.21
What's Changed
Full Changelog: v8.0.19...v8.0.20
What's Changed
a[href]links by @ stefanvermaas in #1429New Contributors
Full Changelog: 8.0.13...v8.0.19
What's Changed
a[href]links by @ stefanvermaas in #1429New Contributors
Full Changelog: 8.0.13...v8.0.18
v8.0.17
v8.0.14
Bump version
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: