Skip to content

Bump ejs and @quasar/app in /front#24

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/front/multi-e723ac0e33
Open

Bump ejs and @quasar/app in /front#24
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/front/multi-e723ac0e33

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 17, 2025

Bumps ejs to 3.1.10 and updates ancestor dependency @quasar/app. These dependencies need to be updated together.

Updates ejs from 2.7.4 to 3.1.10

Release notes

Sourced from ejs's releases.

v3.1.10

Version 3.1.10

v3.1.9

Version 3.1.9

v3.1.8

Version 3.1.8

v3.1.7

Version 3.1.7

v3.1.6

Version 3.1.6

v3.1.5

Version 3.1.5

v3.0.2

No release notes provided.

Commits

Updates @quasar/app from 1.4.3 to 2.4.4

Release notes

Sourced from @​quasar/app's releases.

@​quasar/app-vite-v2.4.0

New

  • feat(app-vite): upgrade to Vite 7
  • feat(app-vite): upgrade default electron-builder from v24 to v26

Upgrade warning

  • Vite 7 no longer supports Node.js 18, which reached its EOL. Node.js 20.19+ / 22.12+ is now required, which propagates to our CLI too.
  • Please check the Vite 7 breaking changes, which are very small-impact (99% of users will not be impacted).
  • We decided to upgrade Vite from v6 to v7 in a minor release because of this very small impact. Bumping up the major version of q/app-vite would mean extra work for all AE owners, and the effort and friction is not worth it.

Donations

Quasar Framework is an open-source MIT-licensed project made possible due to the generous contributions by sponsors and backers. If you are interested in supporting this project, please consider the following:

@​quasar/app-vite-v2.3.0

New

  • feat(app-vite): allow manual creation of ssr dev https server (#18050)
  • feat(app-vite&app-webpack): improve custom ssr webserver support and types #18052

Changes

  • fix(app-vite): Electron build fails with pnpm as package manager #18007

Donations

Quasar Framework is an open-source MIT-licensed project made possible due to the generous contributions by sponsors and backers. If you are interested in supporting this project, please consider the following:

@​quasar/app-vite-v2.2.1

Changes

  • fix(app-vite): properly resolve AE script paths #18003

Donations

Quasar Framework is an open-source MIT-licensed project made possible due to the generous contributions by sponsors and backers. If you are interested in supporting this project, please consider the following:

@​quasar/app-vite-v2.2.0

Changes

  • feat(app-vite): spawn Capacitor v7 projects by default

Donations

Quasar Framework is an open-source MIT-licensed project made possible due to the generous contributions by sponsors and backers. If you are interested in supporting this project, please consider the following:

... (truncated)

Commits
  • 4b806dd chore(ui): Bump version
  • 79f7eb9 fix(QScrollArea): for some scenarios, it shows/hides scrollbars in a loop whe...
  • 546749d fix(BottomSheet/api): JSON definition for actions should include any other cu...
  • 95f65c9 Revert "chore(docs): remove unnecessary prop from Bottom Sheet examples #11924"
  • eb7e61a Revert "chore(docs): remove unnecessary prop from Bottom Sheet examples #11924"
  • d8a5566 chore(docs): remove unnecessary prop from Bottom Sheet examples #11924
  • d204a27 chore(docs): remove unnecessary prop from Bottom Sheet examples #11924
  • a599493 feat(QBtn): improve aria for disabled button as link and toggle buttons (#11914)
  • 2ccf50d fix(ui/api): Proper example in the API (#11910)
  • e01821f fix(docs): Proper example in the API (#11910)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [ejs](https://github.com/mde/ejs) to 3.1.10 and updates ancestor dependency [@quasar/app](https://github.com/quasarframework/quasar). These dependencies need to be updated together.


Updates `ejs` from 2.7.4 to 3.1.10
- [Release notes](https://github.com/mde/ejs/releases)
- [Commits](mde/ejs@v2.7.4...v3.1.10)

Updates `@quasar/app` from 1.4.3 to 2.4.4
- [Release notes](https://github.com/quasarframework/quasar/releases)
- [Commits](https://github.com/quasarframework/quasar/compare/@quasar/app-v1.4.3...quasar-v2.4.4)

---
updated-dependencies:
- dependency-name: ejs
  dependency-version: 3.1.10
  dependency-type: indirect
- dependency-name: "@quasar/app"
  dependency-version: 2.4.4
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Dec 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants