Skip to content

deps(deps): bump the minor-and-patch group with 22 updates - #238

Merged
ralyodio merged 1 commit into
masterfrom
dependabot/npm_and_yarn/minor-and-patch-de61f7f5ea
Sep 28, 2026
Merged

ralyodio merged 1 commit into
masterfrom
dependabot/npm_and_yarn/minor-and-patch-de61f7f5ea

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 22 updates:

Package From To
@alpacahq/alpaca-trade-api 4.0.2 4.0.4
@profullstack/notifications 0.1.0 0.1.4
@profullstack/player 0.12.0 0.13.2
@profullstack/throttle 0.2.2 0.2.3
@supabase/supabase-js 2.116.0 2.117.2
framer-motion 13.4.0 13.4.4
imapflow 2.0.5 2.0.7
isomorphic-dompurify 4.2.0 4.3.0
lucide-react 1.47.0 1.48.0
next 16.3.5 16.3.6
openai 7.18.0 7.23.0
posthog-js 1.434.0 1.434.14
puppeteer 25.11.0 25.12.0
resend 6.28.1 6.29.0
undici 8.10.2 8.11.2
@types/node 26.6.1 26.6.2
@vitest/coverage-v8 5.0.1 5.0.2
dotenv 18.0.0 18.0.4
eslint-config-next 16.3.5 16.3.6
jsdom 30.1.0 30.1.1
tsx 4.23.13 4.23.15
vitest 5.0.1 5.0.2

Updates @alpacahq/alpaca-trade-api from 4.0.2 to 4.0.4

Release notes

Sourced from @​alpacahq/alpaca-trade-api's releases.

v4.0.4

Patch Changes

  • #336 8c7b809 Thanks @​Azein! - Normalize unexpected null market-data response maps to empty objects.

v4.0.3

Patch Changes

  • #330 42ce6ac Thanks @​Azein! - Detailed workflows and the curated API reference now live on the documentation site while README focuses on Node.js setup and compatibility. The package now includes comprehensive LLMS.md guidance for coding agents, with an equivalent installable Agent Skill. The v3-to-v4 codemod now correctly migrates getOrderByClientId, and package verification checks links in every shipped Markdown document.
Changelog

Sourced from @​alpacahq/alpaca-trade-api's changelog.

4.0.4

Patch Changes

  • #336 8c7b809 Thanks @​Azein! - Normalize unexpected null market-data response maps to empty objects.

4.0.3

Patch Changes

  • #330 42ce6ac Thanks @​Azein! - Detailed workflows and the curated API reference now live on the documentation site while README focuses on Node.js setup and compatibility. The package now includes comprehensive LLMS.md guidance for coding agents, with an equivalent installable Agent Skill. The v3-to-v4 codemod now correctly migrates getOrderByClientId, and package verification checks links in every shipped Markdown document.
Commits

Updates @profullstack/notifications from 0.1.0 to 0.1.4

Release notes

Sourced from @​profullstack/notifications's releases.

v0.1.4

  • subscribe({ timeoutMs }): gives up with reason timeout instead of hanging on Chrome's quiet prompt or Brave.
  • A save answered by a redirect (lost session sent to sign-in) now throws save-failed.
  • unsubscribe({ removeMethod: 'POST' }) for POST /unsubscribe routes (default DELETE).
  • @profullstack/notifications/sw-classic: service-worker handlers for plain-script workers via importScripts.

v0.1.3

subscribe() now names Chromium's AbortError instead of echoing "Registration failed - push service error": PushError reason 'no-push-service' (ungoogled Chromium and other builds without a push service) or 'brave-push-off' (with the brave://settings/privacy fix), and Chromium's AbortError permission-denied maps to 'denied'. (#1)

v0.1.2

vapidKeysFromEnv also reads VAPID_PUBLIC / VAPID_PRIVATE. The ttl option is documented: 24h default, where web-push used 4 weeks.

v0.1.1

sendPush errors now include the push service's response text (trimmed to 300 chars), e.g. push service answered 403: invalid JWT provided.

Commits
  • 07f3207 feat: timeoutMs, redirected-save check, removeMethod, classic service worker ...
  • 12b9f3d fix(client): name Chromium's AbortError (no push service, Brave, permission) ...
  • c5fb100 feat: read VAPID_PUBLIC/VAPID_PRIVATE too; document the 24h ttl default
  • 6331d4f feat: include the push service's response text in sendPush errors
  • See full diff in compare view

Updates @profullstack/player from 0.12.0 to 0.13.2

Commits

Updates @profullstack/throttle from 0.2.2 to 0.2.3

Commits

Updates @supabase/supabase-js from 2.116.0 to 2.117.2

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

2.117.0 (2026-09-22)

🚀 Features

  • auth: enable passkey API by default and deprecate experimental passkey opt-in (#2695)

❤️ Thank You

  • fadymak
Commits
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • 739b351 fix(auth): return stored session when a refresh loses to another tab (#2698)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • cc45ccf feat(auth): enable passkey API by default and deprecate experimental passkey ...
  • c511286 docs(realtime): document relationship of accessToken() and heartbeat (#2680)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • See full diff in compare view

Updates framer-motion from 13.4.0 to 13.4.4

Changelog

Sourced from framer-motion's changelog.

[13.4.4] 2026-09-25

Changed

  • scroll: 44% smaller.
  • useScroll: 33% smaller.
  • Scroll callbacks: 50% faster.
  • Removed ScrollTimeline support for JS callbacks as benchmarked no improvement over scrollInfo.

Fixed

  • useDragControls: Fixed snapToCursor origin drift on repeated calls.
  • drag: Improved pointerend timing.
  • spring: Check invalid spring values before applying.
  • AnimatePresence: Ensure children don't stick during reentry.

[13.4.3] 2026-09-24

Fixed

  • <motion>: Ensure animations replay when Suspense reveals memoized content.

[13.4.2] 2026-09-23

Fixed

  • Reorder: Don't scale position of elements at origin 0 when dragConstraints changes.
  • Unrecognised easing names no longer throw.

[13.4.1] 2026-09-22

Fixed

  • animate: CSS variable writes on SVGs apply to style attribute.
Commits
  • 33f6e72 v13.4.4
  • e50ec7b Updating changelog
  • 6e98fce Fix spelling mistakes in code comments
  • a47d6f2 Fix AnimatePresence child stuck at initial after re-entering during exit (#3834)
  • 164be2b v13.4.3
  • d2747a2 Updating changelog
  • 720530a Merge pull request #3833 from motiondivision/cursor/bc-824bfd3c-7a94-4eee-be1...
  • 7eb469a Fix #3832: Replay animations when Suspense reveals memoized motion content
  • be8a4b3 Add failing Cypress test for Suspense reveal of memoized content (#3832)
  • ef59724 Add failing tests for animations after Suspense reveals memoized content (#3832)
  • Additional commits viewable in compare view

Updates imapflow from 2.0.5 to 2.0.7

Changelog

Sourced from imapflow's changelog.

2.0.7 (2026-09-25)

Bug Fixes

  • fetch: keep body sections a server sends as quoted strings (a4f2f18), closes #403

2.0.6 (2026-09-22)

Bug Fixes

  • parser: split flags a server writes without the separating space (96b2022)
Commits
  • cc1c796 Merge pull request #404 from postalsys/release-please--branches--master--comp...
  • e58e682 chore(master): release 2.0.7 [skip-ci]
  • a4f2f18 fix(fetch): keep body sections a server sends as quoted strings
  • 9a2f573 Merge pull request #402 from postalsys/release-please--branches--master--comp...
  • d760ab0 chore(master): release 2.0.6 [skip-ci]
  • 96b2022 fix(parser): split flags a server writes without the separating space
  • ee97145 chore(deps): update dev dependencies [skip ci]
  • See full diff in compare view

Updates isomorphic-dompurify from 4.2.0 to 4.3.0

Release notes

Sourced from isomorphic-dompurify's releases.

4.3.0: Updated dependencies

  • jsdom 30.0.1 -> 30.1.0
  • vitest 5.0.0 -> 5.0.1 (dev)
  • @​biomejs/biome 2.5.12 -> 2.5.14 (dev)
  • lefthook 2.1.12 -> 2.1.14 (dev)
  • pnpm 12.3.4 -> 12.4.2 (tooling)

Note: jsdom 30.1.0 improves resource consumption - clearWindow() now returns the heap fully to baseline (previously ~1.7 MB residual per clear cycle).

Commits
  • fa4709c chore: release 4.3.0
  • a09f7ff chore(deps): bump pnpm to 12.4.2 and biome schema to 2.5.14
  • 4b955a0 chore(deps): bump jsdom from 30.0.1 to 30.1.0
  • a72fc36 chore(deps-dev): bump @​biomejs/biome from 2.5.13 to 2.5.14
  • 139c593 chore(deps-dev): bump vitest from 5.0.0 to 5.0.1
  • 6b2d4fb chore(deps-dev): bump @​biomejs/biome from 2.5.12 to 2.5.13
  • 45eed24 chore(deps-dev): bump lefthook from 2.1.12 to 2.1.14
  • See full diff in compare view

Updates lucide-react from 1.47.0 to 1.48.0

Release notes

Sourced from lucide-react's releases.

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Commits

Updates next from 16.3.5 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates openai from 7.18.0 to 7.23.0

Release notes

Sourced from openai's releases.

v7.23.0

7.23.0 (2026-09-23)

Features

Chores

  • api: document exact Chat Completions seed bounds (#2796) (13b844f)

v7.22.0

7.22.0 (2026-09-22)

Features

  • api: add GPT-6 Sol and Luna model identifiers (#2790) (cff2135)

v7.21.0

7.21.0 (2026-09-22)

Features

  • api: add session environment reset events (#2777) (5de2360)

Bug Fixes

  • api: preserve model choices and improve request handling (#2787) (a4a4396)

Chores

  • api: document response management resources (#2775) (0472fb3)

v7.20.0

7.20.0 (2026-09-19)

Features

  • api: add environment-variable vault credentials (#2768) (fbccf12)
  • api: add external storage configuration management (#2773) (7e89b62)
  • api: add safety case retrieval (#2774) (d357e64)
  • api: add safety warning and deactivation webhook events (#2772) (91c7fb5)

... (truncated)

Changelog

Sourced from openai's changelog.

7.23.0 (2026-09-23)

Features

Chores

  • api: document exact Chat Completions seed bounds (#2796) (13b844f)

7.22.0 (2026-09-22)

Features

  • api: add GPT-6 Sol and Luna model identifiers (#2790) (cff2135)

7.21.0 (2026-09-22)

Features

  • api: add session environment reset events (#2777) (5de2360)

Bug Fixes

  • api: preserve model choices and improve request handling (#2787) (a4a4396)

Chores

  • api: document response management resources (#2775) (0472fb3)

7.20.0 (2026-09-19)

Features

  • api: add environment-variable vault credentials (#2768) (fbccf12)
  • api: add external storage configuration management (#2773) (7e89b62)
  • api: add safety case retrieval (#2774) (d357e64)
  • api: add safety warning and deactivation webhook events (#2772) (91c7fb5)
  • api: add SIP media security to incoming call events (#2770) (db9a57b)

Bug Fixes

... (truncated)

Commits

Updates posthog-js from 1.434.0 to 1.434.14

Release notes

Sourced from posthog-js's releases.

posthog-js@1.434.14

1.434.14

Patch Changes

  • #5097 ae954ab Thanks @​turnipdabeets! - Fix useThumbSurvey from @posthog/react/surveys and posthog-js/react/surveys ignoring the client passed to PostHogProvider, which left it capturing no survey events. (2026-09-25)

posthog-js@1.434.13

1.434.13

Patch Changes

  • #5098 a7250f0 Thanks @​Piccirello! - Replay loads a recorded font under the replay iframe's content security policy, not the embedding page's. (2026-09-24)

posthog-js@1.434.12

1.434.12

Patch Changes

  • #5073 60bd968 Thanks @​ksvat! - The replayer no longer freezes the tab on a mutation that adds tens of thousands of nodes at once. It now applies a batch of 1,000 or more adds against a detached subtree, so the document updates style and layout once instead of per insert. A recorded batch of 25,746 style elements went from 92 seconds of blocked main thread to 1.5 seconds. (2026-09-23)

posthog-js@1.434.11

1.434.11

Patch Changes

posthog-js@1.434.10

1.434.10

Patch Changes

  • #5060 a9c40ec Thanks @​marandaneto! - Fix SDK initialization when a script loader pre-creates window.posthog as a placeholder object. (2026-09-23)

posthog-js@1.434.9

1.434.9

Patch Changes

  • #4970 708a5f7 Thanks @​Christian2702! - Session replay no longer defers its input setter hooks on zone.js's patched setTimeout. In Angular apps each of those timers ended a zone task and triggered another change detection, so any component writing an input property on every cycle drove the tab into an endless loop at 100% CPU. (2026-09-22)

posthog-js@1.434.8

1.434.8

... (truncated)

Commits
  • 2fa67a0 chore: update versions and lockfile [version bump]
  • ae954ab fix(react): share context across entrypoints so useThumbSurvey sees the provi...
  • 518ae78 chore: update versions and lockfile [version bump]
  • e3955f8 feat: expose feature flag reasons in the Node OpenFeature provider (#5099)
  • 8333188 chore: update versions and lockfile [version bump]
  • 4e0f232 fix(rollup): keep the release snippet exact through Vite 8 minification (#5095)
  • b89f249 chore: update versions and lockfile [version bump]
  • de59de0 fix(react-native): submit shuffled survey choices from display order (#5108)
  • 72157d4 chore: update versions and lockfile [version bump]
  • 17fb79b chore(react-native-plugin): raise posthog-ios and posthog-android floors (#5100)
  • Additional commits viewable in compare view

Updates puppeteer from 25.11.0 to 25.12.0

Release notes

Sourced from puppeteer's releases.

puppeteer-core: v25.12.0

25.12.0 (2026-09-23)

🎉 Features

🛠️ Fixes

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​puppeteer/browsers bumped from 3.2.2 to 3.2.3

puppeteer: v25.12.0

25.12.0 (2026-09-23)

🎉 Features

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​puppeteer/browsers bumped from 3.2.2 to 3.2.3
      • puppeteer-core bumped from 25.11.0 to 25.12.0
Commits

Updates resend from 6.28.1 to 6.29.0

Release notes

Sourced from resend's releases.

v6.29.0

What's Changed

Full Changelog: resend/resend-node@v6.28.1...v6.29.0

Commits

Updates undici from 8.10.2 to 8.11.2

Release notes

Sourced from undici's releases.

v8.11.2

What's Changed

New Contributors

Full Changelog: nodejs/undici@v8.11.1...v8.11.2

v8.11.1

What's Changed

Full Changelog: nodejs/undici@v8.11.0...v8.11.1

v8.11.0

What's Changed

... (truncated)

Commits
  • 7e016ad Bumped v8.11.2 (#5886)
  • fcdd5a6 fix: skip reconnecting f...

    Description has been truncated

Bumps the minor-and-patch group with 22 updates:

| Package | From | To |
| --- | --- | --- |
| [@alpacahq/alpaca-trade-api](https://github.com/alpacahq/alpaca-trade-api-js) | `4.0.2` | `4.0.4` |
| [@profullstack/notifications](https://github.com/profullstack/notifications) | `0.1.0` | `0.1.4` |
| [@profullstack/player](https://github.com/profullstack/player) | `0.12.0` | `0.13.2` |
| [@profullstack/throttle](https://github.com/profullstack/throttle) | `0.2.2` | `0.2.3` |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.116.0` | `2.117.2` |
| [framer-motion](https://github.com/motiondivision/motion) | `13.4.0` | `13.4.4` |
| [imapflow](https://github.com/postalsys/imapflow) | `2.0.5` | `2.0.7` |
| [isomorphic-dompurify](https://github.com/kkomelin/isomorphic-dompurify) | `4.2.0` | `4.3.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.47.0` | `1.48.0` |
| [next](https://github.com/vercel/next.js) | `16.3.5` | `16.3.6` |
| [openai](https://github.com/openai/openai-node) | `7.18.0` | `7.23.0` |
| [posthog-js](https://github.com/PostHog/posthog-js) | `1.434.0` | `1.434.14` |
| [puppeteer](https://github.com/puppeteer/puppeteer) | `25.11.0` | `25.12.0` |
| [resend](https://github.com/resend/resend-node) | `6.28.1` | `6.29.0` |
| [undici](https://github.com/nodejs/undici) | `8.10.2` | `8.11.2` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.1` | `26.6.2` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.1` | `5.0.2` |
| [dotenv](https://github.com/motdotla/dotenv) | `18.0.0` | `18.0.4` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.5` | `16.3.6` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.0` | `30.1.1` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.2` |


Updates `@alpacahq/alpaca-trade-api` from 4.0.2 to 4.0.4
- [Release notes](https://github.com/alpacahq/alpaca-trade-api-js/releases)
- [Changelog](https://github.com/alpacahq/alpaca-trade-api-js/blob/master/CHANGELOG.md)
- [Commits](alpacahq/alpaca-trade-api-js@v4.0.2...v4.0.4)

Updates `@profullstack/notifications` from 0.1.0 to 0.1.4
- [Release notes](https://github.com/profullstack/notifications/releases)
- [Commits](profullstack/notifications@v0.1.0...v0.1.4)

Updates `@profullstack/player` from 0.12.0 to 0.13.2
- [Release notes](https://github.com/profullstack/player/releases)
- [Commits](https://github.com/profullstack/player/commits/v0.13.2)

Updates `@profullstack/throttle` from 0.2.2 to 0.2.3
- [Commits](https://github.com/profullstack/throttle/commits/v0.2.3)

Updates `@supabase/supabase-js` from 2.116.0 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js)

Updates `framer-motion` from 13.4.0 to 13.4.4
- [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md)
- [Commits](motiondivision/motion@v13.4.0...v13.4.4)

Updates `imapflow` from 2.0.5 to 2.0.7
- [Release notes](https://github.com/postalsys/imapflow/releases)
- [Changelog](https://github.com/postalsys/imapflow/blob/master/CHANGELOG.md)
- [Commits](postalsys/imapflow@v2.0.5...v2.0.7)

Updates `isomorphic-dompurify` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/kkomelin/isomorphic-dompurify/releases)
- [Commits](kkomelin/isomorphic-dompurify@4.2.0...4.3.0)

Updates `lucide-react` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

Updates `openai` from 7.18.0 to 7.23.0
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/main/CHANGELOG.md)
- [Commits](openai/openai-node@v7.18.0...v7.23.0)

Updates `posthog-js` from 1.434.0 to 1.434.14
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/compare/posthog-js@1.434.0...posthog-js@1.434.14)

Updates `puppeteer` from 25.11.0 to 25.12.0
- [Release notes](https://github.com/puppeteer/puppeteer/releases)
- [Changelog](https://github.com/puppeteer/puppeteer/blob/main/CHANGELOG.md)
- [Commits](puppeteer/puppeteer@puppeteer-v25.11.0...puppeteer-v25.12.0)

Updates `resend` from 6.28.1 to 6.29.0
- [Release notes](https://github.com/resend/resend-node/releases)
- [Changelog](https://github.com/resend/resend-node/blob/canary/CHANGELOG.md)
- [Commits](resend/resend-node@v6.28.1...v6.29.0)

Updates `undici` from 8.10.2 to 8.11.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.10.2...v8.11.2)

Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/coverage-v8)

Updates `dotenv` from 18.0.0 to 18.0.4
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v18.0.0...v18.0.4)

Updates `eslint-config-next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `jsdom` from 30.1.0 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.0...v30.1.1)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `vitest` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: "@alpacahq/alpaca-trade-api"
  dependency-version: 4.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@profullstack/notifications"
  dependency-version: 0.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@profullstack/player"
  dependency-version: 0.13.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@profullstack/throttle"
  dependency-version: 0.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.117.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: framer-motion
  dependency-version: 13.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: imapflow
  dependency-version: 2.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: isomorphic-dompurify
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: openai
  dependency-version: 7.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: posthog-js
  dependency-version: 1.434.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: puppeteer
  dependency-version: 25.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: resend
  dependency-version: 6.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: undici
  dependency-version: 8.11.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dotenv
  dependency-version: 18.0.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm rollup under unrecognized license

License: unrecognized license - This license was not allowed or given any lesser classification by the applicable policy (package/LICENSE.md)

From: pnpm-lock.yaml → npm/@vitejs/plugin-react@5.2.0 → npm/vitest@5.0.2 → npm/rollup@4.63.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/rollup@4.63.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm @profullstack/throttle

Location: Package overview

From: package.json → npm/@profullstack/throttle@0.2.3

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@profullstack/throttle@0.2.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ralyodio
ralyodio merged commit 18e91c1 into master Sep 28, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/minor-and-patch-de61f7f5ea branch September 28, 2026 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant