Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 6, 2025

Bumps vue from 3.5.22 to 3.5.23.

Release notes

Sourced from vue's releases.

v3.5.23

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Changelog

Sourced from vue's changelog.

3.5.23 (2025-11-06)

Bug Fixes

  • compiler-core: correctly handle ts type assertions in expressions (#13397) (e6544ac), closes #13395
  • compiler-core: fix v-bind shorthand handling for in-DOM templates (#13933) (b3cca26), closes #13930
  • compiler-sfc: resolve numeric literals and template literals without expressions as static property key (#13998) (75d44c7)
  • compiler-ssr: textarea with v-text directive SSR (#13975) (006a0c1)
  • compiler: using guard instead of non-nullish assertion (#13982) (dcc6f36)
  • custom-element: batch custom element prop patching (#13478) (c13e674), closes #12619
  • custom-element: optimize slot retrieval to avoid duplicates (#13961) (84ca349), closes #13955
  • hydration: avoid mismatch during hydrate text with newlines in interpolation (#9232) (6cbdf78), closes #9229
  • runtime-core: pass props and children to loadingComponent (#13997) (40c4b2a)
  • runtime-dom: ensure iframe sandbox is handled as an attribute to prevent unintended behavior (#13950) (5689884), closes #13946
  • suspense: clear placeholder and fallback el after resolve to enable GC (#13928) (f411c66)
  • transition-group: use offsetLeft and offsetTop instead of getBoundingClientRect to avoid transform scale affect animation (#6108) (dc4dd59), closes #6105
  • v-model: handle number modifier on change (#13959) (8fbe48f), closes #13958
Commits
  • 5cf0097 release: v3.5.23
  • f411c66 fix(suspense): clear placeholder and fallback el after resolve to enable GC (...
  • dc4dd59 fix(TransitionGroup): use offsetLeft and offsetTop instead of getBoundingClie...
  • 40c4b2a fix(runtime-core): pass props and children to loadingComponent (#13997)
  • e6544ac fix(compiler-core): correctly handle ts type assertions in expressions (#13397)
  • 75d44c7 fix(compiler-sfc): resolve numeric literals and template literals without exp...
  • dcc6f36 fix(compiler): using guard instead of non-nullish assertion (#13982)
  • 8fbe48f fix(v-model): handle number modifier on change (#13959)
  • 6cbdf78 fix(hydration): avoid mismatch during hydrate text with newlines in interpola...
  • 006a0c1 fix(compiler-ssr): textarea with v-text directive SSR (#13975)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [vue](https://github.com/vuejs/core) from 3.5.22 to 3.5.23.
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.5.22...v3.5.23)

---
updated-dependencies:
- dependency-name: vue
  dependency-version: 3.5.23
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies This PR involves changes to dependencies label Nov 6, 2025
@safedep
Copy link

safedep bot commented Nov 6, 2025

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

Package Details
Package Malware Vulnerability Risky License Report
icon @babel/helper-validator-identifier @ 7.28.5
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @babel/parser @ 7.28.5
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @babel/types @ 7.28.5
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/compiler-core @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/compiler-dom @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/compiler-sfc @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/compiler-ssr @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/reactivity @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/runtime-core @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/runtime-dom @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/server-renderer @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon @vue/shared @ 3.5.23
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon magic-string @ 0.30.21
pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗
icon vue @ 3.5.23
package.json pnpm-lock.yaml
ok icon
ok icon
ok icon
🔗

This report is generated by SafeDep Github App

@netlify
Copy link

netlify bot commented Nov 6, 2025

Deploy Preview for rsshub-docs-next ready!

Name Link
🔨 Latest commit 25a7bdd
🔍 Latest deploy log https://app.netlify.com/projects/rsshub-docs-next/deploys/690c3c5856835b0009f04ec0
😎 Deploy Preview https://deploy-preview-134--rsshub-docs-next.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions github-actions bot merged commit bd5205c into main Nov 6, 2025
6 of 7 checks passed
@github-actions github-actions bot deleted the dependabot/npm_and_yarn/vue-3.5.23 branch November 6, 2025 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies This PR involves changes to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant