Skip to content

Bump unhead and @unhead/vue#815

Open
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/npm_and_yarn/multi-a94bc5c72c
Open

Bump unhead and @unhead/vue#815
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/npm_and_yarn/multi-a94bc5c72c

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 12, 2026

Bumps unhead to 2.1.12 and updates ancestor dependency @unhead/vue. These dependencies need to be updated together.

Updates unhead from 2.0.19 to 2.1.12

Release notes

Sourced from unhead's releases.

v2.1.12

   🐞 Bug Fixes

    View changes on GitHub

v2.1.11

    ⚠️ Security

  • Fixed XSS bypass in useHeadSafe via attribute name injection (GHSA-g5xx-pwrp-g3fv). Users handling untrusted input with useHeadSafe should upgrade immediately.

   🐞 Bug Fixes

    View changes on GitHub

v2.1.10

   🐞 Bug Fixes

    View changes on GitHub

v2.1.9

   🐞 Bug Fixes

    View changes on GitHub

v2.1.8

   🐞 Bug Fixes

    View changes on GitHub

v2.1.7

   🐞 Bug Fixes

    View changes on GitHub

v2.1.6

   🐞 Bug Fixes

... (truncated)

Commits

Updates @unhead/vue from 2.0.19 to 2.1.12

Release notes

Sourced from @​unhead/vue's releases.

v2.1.12

   🐞 Bug Fixes

    View changes on GitHub

v2.1.11

    ⚠️ Security

  • Fixed XSS bypass in useHeadSafe via attribute name injection (GHSA-g5xx-pwrp-g3fv). Users handling untrusted input with useHeadSafe should upgrade immediately.

   🐞 Bug Fixes

    View changes on GitHub

v2.1.10

   🐞 Bug Fixes

    View changes on GitHub

v2.1.9

   🐞 Bug Fixes

    View changes on GitHub

v2.1.8

   🐞 Bug Fixes

    View changes on GitHub

v2.1.7

   🐞 Bug Fixes

    View changes on GitHub

v2.1.6

   🐞 Bug Fixes

... (truncated)

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 12, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/multi-a94bc5c72c branch 3 times, most recently from 8f165c1 to ff72bf8 Compare March 19, 2026 08:34
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/multi-a94bc5c72c branch from ff72bf8 to 1750432 Compare March 25, 2026 06:41
Bumps [unhead](https://github.com/unjs/unhead/tree/HEAD/packages/unhead) to 2.1.12 and updates ancestor dependency [@unhead/vue](https://github.com/unjs/unhead/tree/HEAD/packages/vue). These dependencies need to be updated together.


Updates `unhead` from 2.0.19 to 2.1.12
- [Release notes](https://github.com/unjs/unhead/releases)
- [Commits](https://github.com/unjs/unhead/commits/v2.1.12/packages/unhead)

Updates `@unhead/vue` from 2.0.19 to 2.1.12
- [Release notes](https://github.com/unjs/unhead/releases)
- [Commits](https://github.com/unjs/unhead/commits/v2.1.12/packages/vue)

---
updated-dependencies:
- dependency-name: unhead
  dependency-version: 2.1.12
  dependency-type: indirect
- dependency-name: "@unhead/vue"
  dependency-version: 2.1.12
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/multi-a94bc5c72c branch from 1750432 to fe81527 Compare March 30, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants