Skip to content

build(deps): bump nanoid from 5.1.16 to 6.0.0 - #1193

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/nanoid-5.1.16
Open

build(deps): bump nanoid from 5.1.16 to 6.0.0#1193
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/nanoid-5.1.16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 8, 2026

Copy link
Copy Markdown
Contributor

Bumps nanoid from 5.1.16 to 6.0.0.

Release notes

Sourced from nanoid's releases.

6.0.0

  • Made nanoid() and customAlphabet() 4 times faster (by @​orhanayd).
  • Removed Node.js 18 and 20 support.
Changelog

Sourced from nanoid's changelog.

6.0.0

  • Made nanoid() and customAlphabet() 4 times faster (by @​orhanayd).
  • Removed Node.js 18 and 20 support.
Commits

@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Aug 8, 2026
@github-actions github-actions Bot added the chore label Aug 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/nanoid-5.1.16 branch 2 times, most recently from 5e163d3 to a03cb3a Compare August 9, 2026 08:58
@dependabot dependabot Bot changed the title chore(deps): bump nanoid from 5.1.6 to 5.1.16 chore(deps): bump nanoid from 5.1.16 to 6.0.0 Aug 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/nanoid-5.1.16 branch 2 times, most recently from 5a16ae5 to e3008f2 Compare August 9, 2026 13:06
h4yfans added a commit that referenced this pull request Aug 12, 2026
…1356)

Bundles five stale bot PRs into a single change against current main so
one coherent lockfile lands instead of nine conflicting stale ones.

- prettier ^3.8.3 -> ^3.9.6 (#1197)
- ip-address override >=10.1.1 -> >=10.3.1, resolves 10.5.0 (#1190, security)
- hono override >=4.12.27 -> >=4.12.34, resolves 4.13.1 (#1189, security)
- nanoid@>=4.0.0 <5.0.9 override 5.0.9 -> 5.1.16 (#1194)
- framer-motion -> motion ^12.24.7 in landing (#1196)

The renovate PR for the motion swap replaced the package but left all 49
`from 'framer-motion'` imports untouched, which does not resolve once
framer-motion is off the manifest. Repointed them at `motion/react` and
updated the vite manualChunks entry that named the old package.

Left out deliberately: #1193 (nanoid 6.0.0 major) and #1195 (forces a 3.x
transitive to v5) — both advisories are already closed by the existing
pins, so they add breakage risk without security value.
@dependabot dependabot Bot changed the title chore(deps): bump nanoid from 5.1.16 to 6.0.0 build(deps): bump nanoid from 5.1.16 to 6.0.0 Aug 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/nanoid-5.1.16 branch from e3008f2 to 04a39b5 Compare August 12, 2026 17:51
Bumps [nanoid](https://github.com/ai/nanoid) from 5.1.16 to 6.0.0.
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@5.1.16...6.0.0)

---
updated-dependencies:
- dependency-name: nanoid
  dependency-version: 5.1.16
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/nanoid-5.1.16 branch from 04a39b5 to 4ea3c01 Compare August 12, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants