Skip to content

Bump the frontend-security group in /frontend with 5 updates - #2689

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/frontend-security-c1087ab78d
Open

Bump the frontend-security group in /frontend with 5 updates#2689
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/frontend-security-c1087ab78d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the frontend-security group in /frontend with 5 updates:

Package From To
@mui/x-data-grid 9.11.0 9.12.0
@mui/x-date-pickers 9.11.0 9.12.0
i18next 26.3.6 26.4.0
nostr-tools 2.24.2 2.25.0
react-i18next 17.0.11 17.0.12

Updates @mui/x-data-grid from 9.11.0 to 9.12.0

Release notes

Sourced from @​mui/x-data-grid's releases.

v9.12.0

We'd like to extend a big thank you to the 12 contributors who made this release possible. Here are some highlights ✨:

  • 🧮 Support Formulas on the Data Grid: cells in opted-in columns can hold spreadsheet-like formulas (=SUM(RANGE(…)), =price * quantity) evaluated by a built-in engine, with a formula editor and Formula Bar, autocomplete, reference highlighting, optional A1 notation, fill-handle reference adjustment, custom functions, and live formula Excel export
  • ♿️ Improve the accessibility of Data Grid cells and picker day cells
  • 🗓️ Enable multi-resource event creation and editing in the Scheduler
  • 🐞 Bugfixes
  • 📚 Documentation improvements

Special thanks go out to these community members for their valuable contributions: @​Anexus5919, @​mustafajw07

The following team members contributed to this release: @​brijeshb42, @​flaviendelangle, @​JCQuintas, @​LukasTy, @​MBilalShafi, @​michelengelen, @​noraleonte, @​rita-codes, @​romgrk, @​silviuaavram

Data Grid

@mui/x-data-grid@9.12.0

@mui/x-data-grid-pro@9.12.0 pro

Same changes as in @mui/x-data-grid@9.12.0, plus:

@mui/x-data-grid-premium@9.12.0 premium

Same changes as in @mui/x-data-grid-pro@9.12.0, plus:

Date and Time Pickers

@mui/x-date-pickers@9.12.0

@mui/x-date-pickers-pro@9.12.0 pro

Same changes as in @mui/x-date-pickers@9.12.0, plus:

... (truncated)

Changelog

Sourced from @​mui/x-data-grid's changelog.

9.12.0

Aug 21, 2026

We'd like to extend a big thank you to the 12 contributors who made this release possible. Here are some highlights ✨:

  • 🧮 Support Formulas on the Data Grid: cells in opted-in columns can hold spreadsheet-like formulas (=SUM(RANGE(…)), =price * quantity) evaluated by a built-in engine, with a formula editor and Formula Bar, autocomplete, reference highlighting, optional A1 notation, fill-handle reference adjustment, custom functions, and live formula Excel export
  • ♿️ Improve the accessibility of Data Grid cells and picker day cells
  • 🗓️ Enable multi-resource event creation and editing in the Scheduler
  • 🐞 Bugfixes
  • 📚 Documentation improvements

Special thanks go out to these community members for their valuable contributions: @​Anexus5919, @​mustafajw07

The following team members contributed to this release: @​brijeshb42, @​flaviendelangle, @​JCQuintas, @​LukasTy, @​MBilalShafi, @​michelengelen, @​noraleonte, @​rita-codes, @​romgrk, @​silviuaavram

Data Grid

@mui/x-data-grid@9.12.0

@mui/x-data-grid-pro@9.12.0 pro

Same changes as in @mui/x-data-grid@9.12.0, plus:

@mui/x-data-grid-premium@9.12.0 premium

Same changes as in @mui/x-data-grid-pro@9.12.0, plus:

Date and Time Pickers

@mui/x-date-pickers@9.12.0

@mui/x-date-pickers-pro@9.12.0 pro

... (truncated)

Commits
  • ce0220b [release] v9.12.0 (#23382)
  • d160993 [DataGridPremium] Formula support (#22807)
  • 20cb519 [DataGrid] Expose apiRef on GridCallbackDetails for selector access in ca...
  • 553d237 [test] Fix act warnings in the data source filter tests (#23360)
  • 6d40a0d [DataGrid] Support the "rowheader" attribute for grid cells (#23340)
  • 62c43fa [DataGrid] Stop sending incomplete filter items to the data source (#23303)
  • 17580d3 [DataGrid] Fix header height not updating when headerFilters or `columnGrou...
  • fef2279 [DataGrid] Fix unhandled rejection when unmounting mid-autosize (#23319)
  • 3edb100 [DataGrid] Label the blank singleSelect filter option (#23294)
  • See full diff in compare view

Updates @mui/x-date-pickers from 9.11.0 to 9.12.0

Release notes

Sourced from @​mui/x-date-pickers's releases.

v9.12.0

We'd like to extend a big thank you to the 12 contributors who made this release possible. Here are some highlights ✨:

  • 🧮 Support Formulas on the Data Grid: cells in opted-in columns can hold spreadsheet-like formulas (=SUM(RANGE(…)), =price * quantity) evaluated by a built-in engine, with a formula editor and Formula Bar, autocomplete, reference highlighting, optional A1 notation, fill-handle reference adjustment, custom functions, and live formula Excel export
  • ♿️ Improve the accessibility of Data Grid cells and picker day cells
  • 🗓️ Enable multi-resource event creation and editing in the Scheduler
  • 🐞 Bugfixes
  • 📚 Documentation improvements

Special thanks go out to these community members for their valuable contributions: @​Anexus5919, @​mustafajw07

The following team members contributed to this release: @​brijeshb42, @​flaviendelangle, @​JCQuintas, @​LukasTy, @​MBilalShafi, @​michelengelen, @​noraleonte, @​rita-codes, @​romgrk, @​silviuaavram

Data Grid

@mui/x-data-grid@9.12.0

@mui/x-data-grid-pro@9.12.0 pro

Same changes as in @mui/x-data-grid@9.12.0, plus:

@mui/x-data-grid-premium@9.12.0 premium

Same changes as in @mui/x-data-grid-pro@9.12.0, plus:

Date and Time Pickers

@mui/x-date-pickers@9.12.0

@mui/x-date-pickers-pro@9.12.0 pro

Same changes as in @mui/x-date-pickers@9.12.0, plus:

... (truncated)

Changelog

Sourced from @​mui/x-date-pickers's changelog.

9.12.0

Aug 21, 2026

We'd like to extend a big thank you to the 12 contributors who made this release possible. Here are some highlights ✨:

  • 🧮 Support Formulas on the Data Grid: cells in opted-in columns can hold spreadsheet-like formulas (=SUM(RANGE(…)), =price * quantity) evaluated by a built-in engine, with a formula editor and Formula Bar, autocomplete, reference highlighting, optional A1 notation, fill-handle reference adjustment, custom functions, and live formula Excel export
  • ♿️ Improve the accessibility of Data Grid cells and picker day cells
  • 🗓️ Enable multi-resource event creation and editing in the Scheduler
  • 🐞 Bugfixes
  • 📚 Documentation improvements

Special thanks go out to these community members for their valuable contributions: @​Anexus5919, @​mustafajw07

The following team members contributed to this release: @​brijeshb42, @​flaviendelangle, @​JCQuintas, @​LukasTy, @​MBilalShafi, @​michelengelen, @​noraleonte, @​rita-codes, @​romgrk, @​silviuaavram

Data Grid

@mui/x-data-grid@9.12.0

@mui/x-data-grid-pro@9.12.0 pro

Same changes as in @mui/x-data-grid@9.12.0, plus:

@mui/x-data-grid-premium@9.12.0 premium

Same changes as in @mui/x-data-grid-pro@9.12.0, plus:

Date and Time Pickers

@mui/x-date-pickers@9.12.0

@mui/x-date-pickers-pro@9.12.0 pro

... (truncated)

Commits
  • ce0220b [release] v9.12.0 (#23382)
  • 7b70c2f [pickers] Associate the day cells with their week day column header (#23339)
  • 7df90fc [pickers] Keep the gridcell role and the column index on filler cells (#23326)
  • 2d8aaf2 [DateRangePicker] Keep the range highlight opaque for disabled days (#23317)
  • 173ca1d [fields] Keep the selected section on blank space clicks (#23318)
  • See full diff in compare view

Updates i18next from 26.3.6 to 26.4.0

Release notes

Sourced from i18next's releases.

v26.4.0

  • perf: cache toResolveHierarchy results per (code, fallbackCode) pair. The hierarchy resolver runs on every t() call and calls Intl.getCanonicalLocales multiple times, which showed up prominently when profiling render-heavy UIs (e.g. virtualized data grids); with the cache the per-call cost drops from ~886 ns to ~41 ns. The cache is invalidated automatically when options.fallbackLng changes (reassignment or in-place array mutation); if you mutate other resolution-relevant options at runtime (load, lowerCaseLng, cleanCode, nonExplicitSupportedLngs), call i18next.services.languageUtils.clearCache() afterwards. Function-valued fallbackLng and per-call array/object fallbackLng options are never cached, so dynamic fallbacks keep working as before. Thanks @​equaterina (#2444).
  • chore: update all devDependencies (Babel stays on 7.x until @rollup/plugin-babel supports 8, eslint on 9.x for neostandard). Removed the unused coveralls package (CI uses the Coveralls GitHub Action) and replaced sinon with nise + vitest.spyOn in the v1 compatibility tests, which resolves all open npm audit findings (0 vulnerabilities) and should close the dependabot alerts on the lockfile.
Changelog

Sourced from i18next's changelog.

26.4.0

  • perf: cache toResolveHierarchy results per (code, fallbackCode) pair. The hierarchy resolver runs on every t() call and calls Intl.getCanonicalLocales multiple times, which showed up prominently when profiling render-heavy UIs (e.g. virtualized data grids); with the cache the per-call cost drops from ~886 ns to ~41 ns. The cache is invalidated automatically when options.fallbackLng changes (reassignment or in-place array mutation); if you mutate other resolution-relevant options at runtime (load, lowerCaseLng, cleanCode, nonExplicitSupportedLngs), call i18next.services.languageUtils.clearCache() afterwards. Function-valued fallbackLng and per-call array/object fallbackLng options are never cached, so dynamic fallbacks keep working as before. Thanks @​equaterina (#2444).
  • chore: update all devDependencies (Babel stays on 7.x until @rollup/plugin-babel supports 8, eslint on 9.x for neostandard). Removed the unused coveralls package (CI uses the Coveralls GitHub Action) and replaced sinon with nise + vitest.spyOn in the v1 compatibility tests, which resolves all open npm audit findings (0 vulnerabilities) and should close the dependabot alerts on the lockfile.
Commits

Updates nostr-tools from 2.24.2 to 2.25.0

Commits

Updates react-i18next from 17.0.11 to 17.0.12

Changelog

Sourced from react-i18next's changelog.

17.0.12

  • fix(IcuTrans): key-less icu.macro nodes (<Trans>Welcome, {name}!</Trans>, <Select>, <Plural> without i18nKey) rendered an empty string since 17.0.0. The macro now emits <IcuTrans defaultTranslation="…"> without a key and IcuTrans passed undefined to t(), which returns ''. Like Trans, IcuTrans now uses defaultTranslation as the key when i18nKey is not provided.
Commits
  • ea721fb 17.0.12
  • 6c2a71e fix(IcuTrans): use defaultTranslation as key when no i18nKey is given
  • 258c96d chore(examples): upgrade all example apps off unmaintained toolchains
  • b8677c8 chore: update dependencies to close dependabot alerts
  • aa9c92b docs: point Trans component links at the current docs (#1929)
  • See full diff in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
i18next [< 22.6, > 22.5.0]
i18next [>= 23.a, < 24]
react-i18next [>= 12.3.a, < 12.4]
@mui/x-data-grid [< 6.11, > 6.10.0]
react-i18next [< 13.1, > 13.0.2]
@mui/x-date-pickers [< 6.11, > 6.10.0]
react-i18next [< 14, > 13.2.2]
@mui/x-data-grid [>= 6.18.a, < 6.19]
@mui/x-date-pickers [>= 6.18.a, < 6.19]
@mui/x-data-grid [< 6.20, > 6.19.2]
@mui/x-date-pickers [< 7, > 6.19.2]
@mui/x-date-pickers [>= 7.3.a, < 7.4]

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the frontend-security group in /frontend with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@mui/x-data-grid](https://github.com/mui/mui-x/tree/HEAD/packages/x-data-grid) | `9.11.0` | `9.12.0` |
| [@mui/x-date-pickers](https://github.com/mui/mui-x/tree/HEAD/packages/x-date-pickers) | `9.11.0` | `9.12.0` |
| [i18next](https://github.com/i18next/i18next) | `26.3.6` | `26.4.0` |
| [nostr-tools](https://github.com/nbd-wtf/nostr-tools) | `2.24.2` | `2.25.0` |
| [react-i18next](https://github.com/i18next/react-i18next) | `17.0.11` | `17.0.12` |


Updates `@mui/x-data-grid` from 9.11.0 to 9.12.0
- [Release notes](https://github.com/mui/mui-x/releases)
- [Changelog](https://github.com/mui/mui-x/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/mui-x/commits/v9.12.0/packages/x-data-grid)

Updates `@mui/x-date-pickers` from 9.11.0 to 9.12.0
- [Release notes](https://github.com/mui/mui-x/releases)
- [Changelog](https://github.com/mui/mui-x/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/mui-x/commits/v9.12.0/packages/x-date-pickers)

Updates `i18next` from 26.3.6 to 26.4.0
- [Release notes](https://github.com/i18next/i18next/releases)
- [Changelog](https://github.com/i18next/i18next/blob/master/CHANGELOG.md)
- [Commits](i18next/i18next@v26.3.6...v26.4.0)

Updates `nostr-tools` from 2.24.2 to 2.25.0
- [Release notes](https://github.com/nbd-wtf/nostr-tools/releases)
- [Commits](https://github.com/nbd-wtf/nostr-tools/commits)

Updates `react-i18next` from 17.0.11 to 17.0.12
- [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md)
- [Commits](i18next/react-i18next@v17.0.11...v17.0.12)

---
updated-dependencies:
- dependency-name: "@mui/x-data-grid"
  dependency-version: 9.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-security
- dependency-name: "@mui/x-date-pickers"
  dependency-version: 9.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-security
- dependency-name: i18next
  dependency-version: 26.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-security
- dependency-name: nostr-tools
  dependency-version: 2.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-security
- dependency-name: react-i18next
  dependency-version: 17.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 29, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 29, 2026 07:03
@dependabot @github

dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: frontend. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants