Skip to content

build(deps): bump the server-minor-and-patch group across 1 directory with 8 updates - #191

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/server-minor-and-patch-e4f24a0e78
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/server-minor-and-patch-e4f24a0e78

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the server-minor-and-patch group with 6 updates in the /server directory:

Package From To
@aws-sdk/client-ssm 3.1087.0 3.1093.0
@deepgram/sdk 5.5.0 5.7.0
express-rate-limit 8.5.2 8.6.0
helmet 8.2.0 8.3.0
mediasoup 3.20.9 3.22.0
mongoose 9.7.2 9.8.0

Updates @aws-sdk/client-ssm from 3.1087.0 to 3.1093.0

Release notes

Sourced from @​aws-sdk/client-ssm's releases.

v3.1093.0

3.1093.0(2026-07-22)

Documentation Changes
  • client-elastic-load-balancing-v2: This adds CLI examples for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6. (2e38710d)
New Features
  • clients: update client endpoints as of 2026-07-22 (8e084a49)
  • client-arc-region-switch: Adds support for a client token in StartPlanExecution to make plan execution requests idempotent for safe retries. (6cfe2c05)
  • client-pcs: AWS PCS Node Lifecycle Actions provides a structured way to run custom scripts at defined points in a compute node's lifecycle directly through the AWS PCS compute node group API. (c3c4289a)
  • client-partnercentral-account: Adds Qualifications Association APIs that enable partners to associate a subsidiary account's qualifications with a primary account. Once associated, qualifications are shared across all connected accounts and scorecards are consolidated. Partners can start and track association and disassociation. (4b0d8db8)
  • client-sesv2: Launching DEED and MREP in US GOV (29718039)
  • client-observabilityadmin: Enablement for ALB and Bedrock Knowledge Base logs via Observability Admin Telemetry Rule for account and organization level (0bd549cf)
  • client-amp: Add CloudWatch dataset destinations for Amazon Managed Service for Prometheus collectors. (3709a0bd)
  • client-cloudwatch: Adds documented value constraints for CloudWatch Log Alarm scheduled query configuration fields, and makes LogGroupIdentifiers optional for log alarms. (5884c0d4)
  • client-guardduty: Amazon GuardDuty now returns filter lifecycle metadata in GetFilter responses. The response includes createdAt and updatedAt timestamps and a version number that increments on each update, giving you visibility into when a filter was created and last modified. (15117c91)

For list of updated packages, view updated-packages.md in assets-3.1093.0.zip

v3.1092.0

3.1092.0(2026-07-21)

Documentation Changes
  • client-securityhub: Security Hub standard and control multicloud API documentation updates (2e19bf93)
New Features
  • client-redshift: Amazon Redshift - Added support for managing Query Editor V2 IAM Identity Center applications via new CreateQev2IdcApplication, DescribeQev2IdcApplications, ModifyQev2IdcApplication, and DeleteQev2IdcApplication API operations. (17507f23)
  • client-inspector2: GA date - July 21st 2026, remove Tags field from ListCodeSecurityIntegration and ListCodeSecurityScanConfiguration. (33a1778d)
  • client-emr-containers: Added support for the DeleteSecurityConfiguration API, which allows customers to delete security configurations in Amazon EMR on EKS. Also added authenticationConfiguration in securityConfigurationdata structure. (e344cea9)
  • client-redshift-data: update the workgroupArn to include EUSC partition, tests in THF Gamma and Prod no issue (4f372fc5)
  • client-invoicing: Added the SendProcurementPortalValidation and VerifyProcurementPortalValidation APIs. You can use the AWS SDKs to self-service activate your Procurement Portal Preferences created on the Billing Preferences page with a one-time-passcode (OTP) delivered to your portal. (35e023c0)
  • client-entityresolution: Add support for real time matching with AWS Entity Resolution matching workflows with advanced rule sets. (b92fd6c4)
  • client-ssm: Added a WarningMessage field to Automation along with corresponding public documentation. (7af6eb58)
  • client-timestream-influxdb: This release adds support for custom plugins in Amazon Timestream for InfluxDB. InfluxDB 3 Core and Enterprise DB parameter groups now accept a plugin repository URL and optional AWS Secrets Manager secret ARN, so the Processing Engine loads your Python plugins from a public or private repository. (ade4b969)
  • core/protocols: bytebuffer serializer and buffer deserializer for JSON (#8202) (f39955af)

For list of updated packages, view updated-packages.md in assets-3.1092.0.zip

v3.1091.0

3.1091.0(2026-07-20)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-ssm's changelog.

3.1093.0 (2026-07-22)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1092.0 (2026-07-21)

Features

  • client-ssm: Added a WarningMessage field to Automation along with corresponding public documentation. (7af6eb5)

3.1091.0 (2026-07-20)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1090.0 (2026-07-17)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1089.0 (2026-07-16)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1088.0 (2026-07-15)

Note: Version bump only for package @​aws-sdk/client-ssm

Commits

Updates @deepgram/sdk from 5.5.0 to 5.7.0

Release notes

Sourced from @​deepgram/sdk's releases.

v5.7.0

5.7.0 (2026-07-22)

Features

  • regen: listen v2 numerals, multilingual Aura-2 voices, and streaming close() fix (#522) (7f0b9e0)

Bug Fixes

  • agent: re-add deprecated stt_latency to AgentV1LatencyReport (back-compat shim) (007c7e4)
  • socket: make streaming close() idempotent to prevent close-handler recursion (bf3d1df)

What's in this release

SDK regeneration for 2026-07-20 (spec ff8fd2b). No breaking changes.

New API surface (Fern-owned, additive)

  • listen.v2 numerals — new numerals param + ListenV2Numerals type. Connection-time only. Verified end-to-end (serializes onto the connect URL; a TTS'd digits phrase transcribes as 5 5 5 1 2 3 4 … 42 … 3rd with numerals: true vs spelled-out with false).
  • New Aura-2 multilingual TTS voices — ~40 voices (es / de / nl / fr / it / ja) on SpeakV1Model / AudioGenerateRequestModel. Additive only.

Bug fix — streaming close() recursion (bf3d1df)

  • The generated Socket.close() synchronously re-fires the registered close handler via handleClose(); a close handler that calls close() again (idiomatic cleanup) recursed infinitely → RangeError: Maximum call stack size exceeded. All 5 streaming sockets were affected (agent.v1, listen.v1, listen.v2, speak.v1, speak.v2); pre-existing on main.
  • Fixed at the wrapper layer (CustomClient.ts, already frozen) with a shared WeakSet guard — no generated files frozen. Regression test drives the public createConnection path for all 5 services.

Bug fix — stt_latency back-compat shim (007c7e4)

  • The spec removed stt_latency from AgentV1LatencyReport (docs #1006). Since it's a server-emitted (read-only) message, stt_latency?: number is re-added by hand as a deprecated read-side field (frozen in .fernignore): report.stt_latency keeps resolving (to undefined) instead of breaking existing readers at compile time — no request/wire impact. Mirrors the Python SDK's read-side shim (deepgram-python-sdk#746).
  • Both shims work around generator output and can be dropped once corrected upstream.

Validation — all green

make build ✅ · make test ✅ (unit 580/580, wire 139/139) · make typecheck-tests ✅ · biome lint ✅ · biome format ✅ · 27/27 non-management examples run clean against the live API.

v5.6.0

No release notes provided.

Changelog

Sourced from @​deepgram/sdk's changelog.

5.7.0 (2026-07-22)

Features

  • regen: listen v2 numerals, multilingual Aura-2 voices, and streaming close() fix (#522) (7f0b9e0)

Bug Fixes

  • agent: re-add deprecated stt_latency to AgentV1LatencyReport (back-compat shim) (007c7e4)
  • socket: make streaming close() idempotent to prevent close-handler recursion (bf3d1df)

5.6.0 (2026-07-14)

Features

  • Streaming text-to-speech (Flux) via speak.v2 — new WebSocket TTS: client.speak.v2.connect(...) streams Speak/Flush/Close and returns audio frames plus control messages. Also adds agent UpdateListen/ListenUpdated (swap the listen provider mid-session) and Flux end-of-turn tuning (eot_threshold, eager_eot_threshold, eot_timeout_ms). (#515) (7bba2d2)
  • Flux text-to-speech batch (REST) endpoint and agent latency report. (#519) (a27336e)
Commits
  • d330c39 chore(main): release 5.7.0 (#523)
  • 85ff12a chore(main): release 5.7.0
  • 7f0b9e0 feat(regen): listen v2 numerals, multilingual Aura-2 voices, and streaming cl...
  • adbbae1 docs: remove cross-repo references from code comments
  • 007c7e4 fix(agent): re-add deprecated stt_latency to AgentV1LatencyReport (back-compa...
  • bf3d1df fix(socket): make streaming close() idempotent to prevent close-handler recur...
  • 10e404c chore: re-apply manual patches after regen
  • a394677 SDK regeneration
  • 023bbad chore: unfreeze files pending regen
  • e5484e7 chore: initialize SDK regeneration branch
  • Additional commits viewable in compare view

Updates express-rate-limit from 8.5.2 to 8.6.0

Release notes

Sourced from express-rate-limit's releases.

v8.6.0

You can view the changelog here.

Commits
  • fffb3c4 8.6.0
  • f366b2d docs: debugging guide, time constants, & v8.6.0 changelog (#652)
  • 593ddd2 fix: make debug output easier to read (#653)
  • ef8c129 fix: Pin safe version of @​asyncapi/specs dev dep (#659)
  • 7b05e0d feat: add time constants to support more readable values for windowMs (#655)
  • 863e730 chore(deps-dev): bump the development-dependencies group with 3 updates (#657)
  • e0e711e fix: correct wording in usage documentation for express-rate-limit (#656)
  • fcd3aa7 chore(deps-dev): bump the development-dependencies group with 3 updates (#651)
  • 99d4298 feat: use debug for debug logging (#641)
  • 23e4dde feat: Run validations once each (#650)
  • Additional commits viewable in compare view

Updates helmet from 8.2.0 to 8.3.0

Changelog

Sourced from helmet's changelog.

8.3.0 - 2026-07-11

Changed

  • Content-Security-Policy: improved performance by ~7% when there are no dynamic directives
  • Content-Security-Policy: improved error handling for invalid directive names

Fixed

  • Content-Security-Policy: useDefaults: false with no directives is no longer valid, both at runtime and the type level
  • Content-Security-Policy: dynamically-computed directive values would throw, not call next, when invalid
  • Content-Security-Policy: dynamically-computed directive value entries would throw, not call next, when function threw
Commits
  • 75f1a98 8.3.0
  • f03f70d Update changelog for 8.3.0 release
  • a307fce Fix capitalization in CSP package changelog
  • 5347b43 Format default CSP in README for readability
  • 9afc570 CSP: fix middleware-specific README missing link
  • 266c95c Minor speedups to project setups test
  • 7a4196c CSP: update package-specific changelog
  • 02716b4 CSP: improve performance when there are no dynamic directives
  • 3f511ed CSP: move utility functions to separate file
  • 80338af CSP: disabling defaults with no directives is now an error
  • Additional commits viewable in compare view

Updates mediasoup from 3.20.9 to 3.22.0

Release notes

Sourced from mediasoup's releases.

3.22.0

3.21.2

3.21.1

3.21.0

  • Worker: Fix new consumer regressions ([PR #1849](versatica/mediasoup#1849)).
  • Add NotFoundError, thrown when the referenced entity in the Worker doesn't exist ([PR #1852](versatica/mediasoup#1852)).
    • Expose mediasoup Node errors via mediasoup/errors (in EMS).
    • Breaking change: Rename InvalidStateError to WorkerClosedError.

3.20.10

  • Worker: Handle new STUN "NOMINATION" attribute 0x0030 (1846).
Changelog

Sourced from mediasoup's changelog.

3.22.0

3.21.2

3.21.1

3.21.0

  • Worker: Fix new consumer regressions ([PR #1849](versatica/mediasoup#1849)).
  • Add NotFoundError, thrown when the referenced entity in the Worker doesn't exist ([PR #1852](versatica/mediasoup#1852)).
    • Expose mediasoup Node errors via mediasoup/errors (in EMS).
    • Breaking change: Rename InvalidStateError to WorkerClosedError.

3.20.10

Commits
  • eb9475c release 3.22.0 [no-ci]
  • bc0a5e4 npm audit fix
  • 34d34c6 Encode subchannels in SCTP messages (#1859)
  • 90235a7 Node: Remvoe not needed public router.addPipeTransportPair() method
  • febd648 release rust-0.22.12 [no-ci]
  • ffcf1ac mediasoup-sys 0.12.12 [crate-publish] [no-ci]
  • 87d3c9b release 3.21.2 [no-ci]
  • dd64242 update npm dev deps
  • 5a65533 Worker: Fix crash when an SCTP DataConsumer is closed and triggers buffered...
  • 638ce1d improve doc/Rust-crates.md
  • Additional commits viewable in compare view

Updates mongoose from 9.7.2 to 9.8.0

Release notes

Sourced from mongoose's releases.

9.8.0 / 2026-07-20

9.7.4 / 2026-07-06

  • types(create): fix handling of nested objects typed as interfaces #16363 #16362
  • types: correct this parameter handling for methods with versionKey #16344 #16046
  • docs: add FAQ entry for querySrv ECONNREFUSED errors on Windows with mongodb+srv:// connections #16342 ajay naik

9.7.3 / 2026-06-26

  • types(model): correct Model.validate() return type to Promise #16340 #16338
  • types: use @​standard-schema/spec for StandardSchema types rather than inlining #16341 #16339
Changelog

Sourced from mongoose's changelog.

9.8.0 / 2026-07-20

9.7.4 / 2026-07-06

  • types(create): fix handling of nested objects typed as interfaces #16363 #16362
  • types: correct this parameter handling for methods with versionKey #16344 #16046
  • docs: add FAQ entry for querySrv ECONNREFUSED errors on Windows with mongodb+srv:// connections #16342 ajay naik

9.7.3 / 2026-06-26

  • types(model): correct Model.validate() return type to Promise #16340 #16338
  • types: use @​standard-schema/spec for StandardSchema types rather than inlining #16341 #16339
Commits
  • 246c727 chore: release 9.8.0
  • 0755d1b Merge pull request #16392 from Automattic/9.8
  • 7f78844 Merge pull request #16393 from WaleedAshraf/fix-minimize-empty-array-subdocum...
  • a260682 Merge pull request #16386 from AbdelrahmanHafez/fix/bulksave-new-doc-version
  • d68da8b Merge pull request #16366 from Automattic/copilot/fix-github-actions-job-node...
  • b0ac309 Update comment for version key handling on insert
  • 7037f00 Merge pull request #16380 from rajkumar0932/fix/geo-object-cast-legacy-arg
  • 7080cfa Merge pull request #16394 from AbdelrahmanHafez/test/npm-test-nested-suites
  • add8752 test: run nested test directories in the default mocha suites
  • 083cab6 fix(subdocument): don't minimize empty document array elements to null
  • Additional commits viewable in compare view

Updates @vitest/coverage-v8 from 3.2.6 to 4.1.10

Release notes

Sourced from @​vitest/coverage-v8's releases.

v4.1.10

   🐞 Bug Fixes

    View changes on GitHub

v4.1.9

🐞 Bug Fixes

View changes on GitHub

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

... (truncated)

Commits

Updates vitest from 3.2.6 to 4.1.10

Release notes

Sourced from vitest's releases.

v4.1.10

   🐞 Bug Fixes

    View changes on GitHub

v4.1.9

🐞 Bug Fixes

View changes on GitHub

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

... (truncated)

Commits
  • db616d2 chore: release v4.1.10 (#10718)
  • bae52b5 fix(vm): fix external module resolve error with deps optimizer query for enco...
  • a7a61e7 chore: release v4.1.9 (#10598)
  • 934b0f5 fix(pool): prevent test run hang on worker crash (#10543) [backport to v4] (#...
  • 7fb2965 fix(browser): wait for orchestrator readiness before resolving browser sessio...
  • a518019 fix: fix importOriginal with optimizer and query import [backport to v4] (#...
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • a09d472 chore: release v4.1.7
  • a8fd24c chore: release v4.1.6
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific depend...

Description has been truncated

… with 8 updates

Bumps the server-minor-and-patch group with 6 updates in the /server directory:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm) | `3.1087.0` | `3.1093.0` |
| [@deepgram/sdk](https://github.com/deepgram/deepgram-js-sdk) | `5.5.0` | `5.7.0` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.5.2` | `8.6.0` |
| [helmet](https://github.com/helmetjs/helmet) | `8.2.0` | `8.3.0` |
| [mediasoup](https://github.com/versatica/mediasoup) | `3.20.9` | `3.22.0` |
| [mongoose](https://github.com/Automattic/mongoose) | `9.7.2` | `9.8.0` |



Updates `@aws-sdk/client-ssm` from 3.1087.0 to 3.1093.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1093.0/clients/client-ssm)

Updates `@deepgram/sdk` from 5.5.0 to 5.7.0
- [Release notes](https://github.com/deepgram/deepgram-js-sdk/releases)
- [Changelog](https://github.com/deepgram/deepgram-js-sdk/blob/main/CHANGELOG.md)
- [Commits](deepgram/deepgram-js-sdk@v5.5.0...v5.7.0)

Updates `express-rate-limit` from 8.5.2 to 8.6.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v8.5.2...v8.6.0)

Updates `helmet` from 8.2.0 to 8.3.0
- [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md)
- [Commits](helmetjs/helmet@v8.2.0...v8.3.0)

Updates `mediasoup` from 3.20.9 to 3.22.0
- [Release notes](https://github.com/versatica/mediasoup/releases)
- [Changelog](https://github.com/versatica/mediasoup/blob/v3/CHANGELOG.md)
- [Commits](versatica/mediasoup@3.20.9...3.22.0)

Updates `mongoose` from 9.7.2 to 9.8.0
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@9.7.2...9.8.0)

Updates `@vitest/coverage-v8` from 3.2.6 to 4.1.10
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8)

Updates `vitest` from 3.2.6 to 4.1.10
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ssm"
  dependency-version: 3.1093.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: "@deepgram/sdk"
  dependency-version: 5.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: express-rate-limit
  dependency-version: 8.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: helmet
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: mediasoup
  dependency-version: 3.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: mongoose
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: server-minor-and-patch
- dependency-name: vitest
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: server-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 23, 2026
@vercel

vercel Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
a-meet Ready Ready Preview, Comment Jul 23, 2026 2:21pm

@dependabot @github

dependabot Bot commented on behalf of github Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 30, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/server/server-minor-and-patch-e4f24a0e78 branch July 30, 2026 14:15

This branch was successfully deployed

1 active deployment
Preview — 686274a2 Deployed Jul 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants