Skip to content

build(deps): bump the server-minor-and-patch group across 1 directory with 10 updates - #218

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/server-minor-and-patch-0a5cc9d3d7
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/server-minor-and-patch-0a5cc9d3d7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the server-minor-and-patch group with 10 updates in the /server directory:

Package From To
@aws-sdk/client-ssm 3.1087.0 3.1121.0
@deepgram/sdk 5.5.0 5.9.0
express-rate-limit 8.5.2 8.7.0
groq-sdk 1.3.0 1.6.0
helmet 8.2.0 8.3.0
joi 18.2.3 18.2.5
mediasoup 3.20.9 3.26.0
mongoose 9.7.2 9.9.4
tsx 4.23.1 4.23.13
@types/node 26.1.1 26.4.0

Updates @aws-sdk/client-ssm from 3.1087.0 to 3.1121.0

Release notes

Sourced from @​aws-sdk/client-ssm's releases.

v3.1121.0

3.1121.0(2026-08-28)

New Features
  • client-ecs: Amazon Elastic Container Service - This release adds support for early success criteria on ECS rolling deployments, letting deployment complete once a configurable percentage of tasks are healthy, with configurable BLOCKING (required) or DEFERRED (asynchronous) cleanup of previous service revisions. (ef22d750)
  • client-healthlake: New HealthLake API, RestoreFHIRDatastore, providing the capability to restore active datastores to a point in time within the last 30 days or recover a deleted datastore from the delete snapshot. (62491742)
  • client-bedrock-agentcore: AgentCore Memory now supports direct ingestion into long-term memory via IngestData API (20d652de)
  • client-partnercentral-selling: Releasing PARC, new APN Program that lets sellers add solftware revenue details to aws opportunity summary (2b6350f0)
  • client-cognito-identity-provider: Adds two new operations - GetClientToken which allows M2M auth through the SDK, and DescribeTermsByClient to find which Terms are associated with a user-pool client without knowing the Terms resource id. (86dffd28)
  • client-bedrock-agent: Adds an optional syncSchedule field to CreateDataSource and UpdateDataSource for Managed Knowledge Bases data source connectors, so a data source can sync automatically on a daily, weekly, or monthly schedule. (a8d3714a)

For list of updated packages, view updated-packages.md in assets-3.1121.0.zip

v3.1120.0

3.1120.0(2026-08-27)

Documentation Changes
  • client-opensearch: Updating SDK and CLI documentation for AttachDataSource API. (d696fe76)
New Features
  • client-lambda-microvms: Added InsufficientCapacityException to RunMicrovm for capacity-related failures. Added lifecycle status field (AVAILABLE, DEPRECATED) to ListManagedMicrovmImageVersions. Added ConflictException to CreateMicrovmAuthToken and CreateMicrovmShellAuthToken for unregistered MicroVMs. (72a8ff80)
  • client-codedeploy: Added a deploymentMode parameter to CreateDeployment. Set it to RESTART to restart an EC2 and on-premises fleet, using the last successful revision, honoring Deployment Configuration. (78d4f964)
  • client-cloudwatch-logs: Added resultCount to QueryStatistics in GetQueryResults. This field returns the total number of output rows in the final result set, helping customers programmatically determine whether a query produced results after all operations including post-aggregation filters. (0e4d242b)
  • client-datazone: Add cascadeDelete to DeleteDomain. When specified, DataZone recursively deletes all projects, environments, subscriptions, and their underlying AWS resources before removing the domain. Deletion progress is reported via deleteProgress and resource failures via failureReasons on GetDomain. (3a74dc4b)
  • client-rds: Adding support for the full snapshot size, in bytes, of DB instance snapshots. (ab2f66f5)
  • client-ec2: EC2 allows AMI owners to define compatible instance types on their AMIs, blocking RunInstances calls automatically for launches on non-permitted instance types. (311b3b26)
  • client-cognito-identity-provider: Adds the AdminDeleteSoftwareToken API operation, enabling administrators to remove a user's registered TOTP (software token) MFA configuration from a user pool. (f661bebc)

For list of updated packages, view updated-packages.md in assets-3.1120.0.zip

v3.1119.0

3.1119.0(2026-08-26)

Chores
  • codegen: smithy-aws-typescript-codegen 0.53.0 (#8276) (dffb383b)
New Features
  • client-sagemaker: Amazon SageMaker AI now supports ml.g7 instances for model optimization. You can now run model optimization jobs on ml.g7 instances, in supported AWS Regions. (6d5e1066)
  • client-devops-agent: AWS DevOps Agent now supports trigger filter groups for Release Readiness Review, letting you control when the capability auto-triggers based on webhook events and target branches. (bc3d53d5)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-ssm's changelog.

3.1121.0 (2026-08-28)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1120.0 (2026-08-27)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1119.0 (2026-08-26)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1118.0 (2026-08-25)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1117.0 (2026-08-24)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1116.0 (2026-08-21)

Note: Version bump only for package @​aws-sdk/client-ssm

3.1115.0 (2026-08-20)

... (truncated)

Commits

Updates @deepgram/sdk from 5.5.0 to 5.9.0

Release notes

Sourced from @​deepgram/sdk's releases.

v5.9.0

5.9.0 (2026-08-28)

Listen v2 (Flux) force-end-turn, listen v1 diarization metadata, the Flux TTS GA voice catalog, and a passthrough-auth fix.

Features

  • Listen v2 (Flux) force-end-turn: socket.sendForceEndTurn() sends the new ListenV2ForceEndTurn control message, ending the current turn on demand; Flux flushes buffered audio and emits a standard EndOfTurn. ListenV2TurnInfo gains trigger (model | manual | timeout, open enum) identifying what ended each turn. eot_threshold now accepts up to 1.0 (previously capped at 0.9) to suppress Flux's confidence-based end-of-turn detection and own turn endings yourself — note eot_timeout_ms is an independent mechanism that still ends a turn after a pause, so set both when ForceEndTurn should be the only way a turn ends. Enablement is per deployment server-side (live in Deepgram-hosted US data centers at release). (#537) (03e7062)
  • Listen v1 diarization detail: metadata.diarize_info (model_uuid, arch) identifies which diarizer ran, and words gain per-word speaker_confidence. (#537) (03e7062)
  • Flux TTS GA voice catalog: the agent's Deepgram speak provider grows from 12 to 36 voices, and flux-kit-en is now the default voice when agent.speak is omitted. See Compatibility for flux-renee-en. (#537) (03e7062)
  • Speak v2: dedicated numeric SpeakV2SpeedValue type for the mid-stream Configure.speed field, plus expanded speed / expressivity documentation including the SPEED_NOT_SUPPORTED and EXPRESSIVITY_* warning codes. (#537) (03e7062)
  • REST clients: new per-request additionalBodyParameters option, spread onto the request body; debug logging of passthrough requests now scrubs credentials from URLs. (#537) (03e7062)

Bug Fixes

  • core: client.fetch() now authenticates passthrough requests to all Deepgram hosts — an absolute URL to agent.deepgram.com previously lost the auth header and failed with an unexplained 401. Part of the origin-scoping change described under Compatibility. (#537) (03e7062)
  • websocket: default binaryType to arraybuffer for Bun compatibility (cc4293c), closes #525
  • websocket: default binaryType to arraybuffer for Bun compatibility (#535) (1913abc)

Compatibility

  • Passthrough client.fetch() credentials are now origin-scoped. Previously the SDK attached your Deepgram auth headers to every URL passed to client.fetch(), including third-party hosts — a credential leak. Credentials are now sent only to Deepgram first-party origins (api.deepgram.com, agent.deepgram.com) and your configured baseUrl; requests to any other absolute URL are sent without auth. If you were routing passthrough calls through a proxy or other non-Deepgram host and relying on the key being auto-attached, attach it explicitly via request headers. Self-hosted and custom-baseUrl deployments are unaffected.
  • flux-renee-en was dropped from the GA voice catalog spec. The Deepgram.Model.FluxReneeEn constant remains, marked @deprecated, and the voice still synthesizes (verified 2026-08-19) — the GA cutover was a docs/spec change with no server-side removal.
  • SpeakV2Speed stays numeric. The generator retyped it as a string enum; it is widened back to admit number, so speak.v2.connect({ speed: 1.0 }) keeps compiling. Numbers and their string equivalents serialize identically on the wire.
  • DeepgramTimeoutError still extends Error, not DeepgramError. The generator's re-parenting is deferred to the next major (it would silently change the behavior of ordered instanceof catch chains) and will be documented in the migration guide.
  • No modules were removed and no optional → required field changes on request types — verified by diffing the clean-built .d.ts surface (575 shared declaration files) against 5.8.0.

v5.8.0

5.8.0 (2026-08-12)

Flux TTS streaming controls, Listen v2 redaction, and an agent provider back-compat fix.

Features

  • Speak v2 (Flux TTS streaming, /v2/speak): barge-in via sendInterrupt() (SpeakV2Interrupt, optional playback_offset), answered by SpeakV2SpeechInterrupted with text_spoken / text_remaining; mid-session Configure via sendConfigure() with ConfigureSuccess / ConfigureFailure responses; new speed (0.85–1.15 in 0.05 increments) and expressivity (-2–2; 0 is the voice's nominal delivery) connect params. Inline pause and pronunciation controls are not applied at launch — they are stripped before synthesis, the related warning codes are reserved and not currently emitted, and controls_applied counts are currently 0; support is coming soon. (#532) (e851496)
  • Listen v2: ListenV2Redact (numbers, aggressive_numbers). (#532) (e851496)

Bug Fixes

  • agent: model the AgentV1UpdateListen provider as a merged shape rather than a union, preserving back-compat for existing callers (the regenerated union broke reads of V2-only fields and required version). Compile-compat only; the wire payload is unchanged. (a65d1aa, a6e3c79)

Compatibility

  • No optional → required field changes on request types.

... (truncated)

Changelog

Sourced from @​deepgram/sdk's changelog.

5.9.0 (2026-08-28)

Listen v2 (Flux) force-end-turn, listen v1 diarization metadata, the Flux TTS GA voice catalog, and a passthrough-auth fix.

Features

  • Listen v2 (Flux) force-end-turn: socket.sendForceEndTurn() sends the new ListenV2ForceEndTurn control message, ending the current turn on demand; Flux flushes buffered audio and emits a standard EndOfTurn. ListenV2TurnInfo gains trigger (model | manual | timeout, open enum) identifying what ended each turn. eot_threshold now accepts up to 1.0 (previously capped at 0.9) to suppress Flux's confidence-based end-of-turn detection and own turn endings yourself — note eot_timeout_ms is an independent mechanism that still ends a turn after a pause, so set both when ForceEndTurn should be the only way a turn ends. Enablement is per deployment server-side (live in Deepgram-hosted US data centers at release). (#537) (03e7062)
  • Listen v1 diarization detail: metadata.diarize_info (model_uuid, arch) identifies which diarizer ran, and words gain per-word speaker_confidence. (#537) (03e7062)
  • Flux TTS GA voice catalog: the agent's Deepgram speak provider grows from 12 to 36 voices, and flux-kit-en is now the default voice when agent.speak is omitted. See Compatibility for flux-renee-en. (#537) (03e7062)
  • Speak v2: dedicated numeric SpeakV2SpeedValue type for the mid-stream Configure.speed field, plus expanded speed / expressivity documentation including the SPEED_NOT_SUPPORTED and EXPRESSIVITY_* warning codes. (#537) (03e7062)
  • REST clients: new per-request additionalBodyParameters option, spread onto the request body; debug logging of passthrough requests now scrubs credentials from URLs. (#537) (03e7062)

Bug Fixes

  • core: client.fetch() now authenticates passthrough requests to all Deepgram hosts — an absolute URL to agent.deepgram.com previously lost the auth header and failed with an unexplained 401. Part of the origin-scoping change described under Compatibility. (#537) (03e7062)
  • websocket: default binaryType to arraybuffer for Bun compatibility (cc4293c), closes #525
  • websocket: default binaryType to arraybuffer for Bun compatibility (#535) (1913abc)

Compatibility

  • Passthrough client.fetch() credentials are now origin-scoped. Previously the SDK attached your Deepgram auth headers to every URL passed to client.fetch(), including third-party hosts — a credential leak. Credentials are now sent only to Deepgram first-party origins (api.deepgram.com, agent.deepgram.com) and your configured baseUrl; requests to any other absolute URL are sent without auth. If you were routing passthrough calls through a proxy or other non-Deepgram host and relying on the key being auto-attached, attach it explicitly via request headers. Self-hosted and custom-baseUrl deployments are unaffected.
  • flux-renee-en was dropped from the GA voice catalog spec. The Deepgram.Model.FluxReneeEn constant remains, marked @deprecated, and the voice still synthesizes (verified 2026-08-19) — the GA cutover was a docs/spec change with no server-side removal.
  • SpeakV2Speed stays numeric. The generator retyped it as a string enum; it is widened back to admit number, so speak.v2.connect({ speed: 1.0 }) keeps compiling. Numbers and their string equivalents serialize identically on the wire.
  • DeepgramTimeoutError still extends Error, not DeepgramError. The generator's re-parenting is deferred to the next major (it would silently change the behavior of ordered instanceof catch chains) and will be documented in the migration guide.
  • No modules were removed and no optional → required field changes on request types — verified by diffing the clean-built .d.ts surface (575 shared declaration files) against 5.8.0.

5.8.0 (2026-08-12)

Flux TTS streaming controls, Listen v2 redaction, and an agent provider back-compat fix.

Features

  • Speak v2 (Flux TTS streaming, /v2/speak): barge-in via sendInterrupt() (SpeakV2Interrupt, optional playback_offset), answered by SpeakV2SpeechInterrupted with text_spoken / text_remaining; mid-session Configure via sendConfigure() with ConfigureSuccess / ConfigureFailure responses; new speed (0.85–1.15 in 0.05 increments) and expressivity (-2–2; 0 is the voice's nominal delivery) connect params. Inline pause and pronunciation controls are not applied at launch — they are stripped before synthesis, the related warning codes are reserved and not currently emitted, and controls_applied counts are currently 0; support is coming soon. (#532) (e851496)
  • Listen v2: ListenV2Redact (numbers, aggressive_numbers). (#532) (e851496)

Bug Fixes

  • agent: model the AgentV1UpdateListen provider as a merged shape rather than a union, preserving back-compat for existing callers (the regenerated union broke reads of V2-only fields and required version). Compile-compat only; the wire payload is unchanged. (a65d1aa, a6e3c79)

Compatibility

  • No optional → required field changes on request types.
  • Two existing fields widen on the read path: Deepgram.version ("v1" → string) and Google.version ("v1beta" → open Google.Version). Safe for callers setting the field; a consumer assigning them into a narrowed literal binding must widen the annotation.
  • SpeakV2SpeechMetadata.ControlsApplied / SpeakV2SpeechInterrupted gain a required breaks_applied counter — server-emitted (read-only), so it is safe on the read path.

... (truncated)

Commits
  • d68c38c chore(main): release 5.9.0 (#536)
  • d7ba474 docs(changelog): expand 5.9.0 notes with feature detail and compatibility cal...
  • 850601a chore(main): release 5.9.0
  • 03e7062 feat(regen): listen v2 force-end-turn, listen v1 diarize metadata, and the Fl...
  • 1913abc fix(websocket): default binaryType to arraybuffer for Bun compatibility (#535)
  • 4339fd8 docs(examples): handle WebSocket audio as a Blob in agent examples
  • f4086e0 test(websocket): pin speak.v2 inbound audio as Blob at the wire level
  • 9b8c9d5 test(websocket): pin arraybuffer binaryType default for listen.v2 and speak.v2
  • cc4293c fix(websocket): default binaryType to arraybuffer for Bun compatibility
  • d166c65 chore(main): release 5.8.0 (#533)
  • Additional commits viewable in compare view

Updates express-rate-limit from 8.5.2 to 8.7.0

Release notes

Sourced from express-rate-limit's releases.

v8.7.0

You can view the changelog here.

v8.6.2

You can view the changelog here.

v8.6.1

You can view the changelog here.

v8.6.0

You can view the changelog here.

Commits
  • 48db09e 8.7.0
  • dce5871 v8.7.0 changelog
  • 2f08044 Add inspect.software health badge (#673)
  • a29757c feat: add retryAfter option (#661)
  • 146e88b chore: rename license
  • 5cfb8e8 ci: drop top-level id-token: write from the workflow token (#676)
  • 062bbdd fix: re-wrap license.md so GitHub recognizes it as MIT (#675)
  • 514772d chore(deps-dev): bump mintlify in the development-dependencies group (#674)
  • 4f06c8a chore(deps-dev): bump the development-dependencies group with 2 updates (#671)
  • 83356a5 chore(deps): bump ip-address from 10.4.0 to 10.5.0 (#672)
  • Additional commits viewable in compare view

Updates groq-sdk from 1.3.0 to 1.6.0

Release notes

Sourced from groq-sdk's releases.

v1.6.0

1.6.0 (2026-08-25)

Full Changelog: v1.5.0...v1.6.0

Features

  • chat: add Qwen3.8 reasoning guidance (c2b0264)

Chores

  • GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.yaml [skip ci] (99fc8ef)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (8d224a0)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (2c5b7aa)
  • internal: allow the mock server port to be set with STAINLESS_MOCK_PORT (90cec2d)

Styles

  • chat: format completion params union (91d9de9)

v1.5.0

1.5.0 (2026-07-30)

Full Changelog: v1.4.1...v1.5.0

Features

v1.4.1

1.4.1 (2026-07-29)

Full Changelog: v1.4.0...v1.4.1

Chores

  • internal: codegen related update (873736d)

v1.4.0

1.4.0 (2026-07-24)

Full Changelog: v1.3.0...v1.4.0

Features

  • stlc: configurable CI runner and private-production-repo support in workflow templates (21fa0b8)

... (truncated)

Changelog

Sourced from groq-sdk's changelog.

1.6.0 (2026-08-25)

Full Changelog: v1.5.0...v1.6.0

Features

  • chat: add Qwen3.8 reasoning guidance (c2b0264)

Chores

  • GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.yaml [skip ci] (99fc8ef)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (8d224a0)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (2c5b7aa)
  • internal: allow the mock server port to be set with STAINLESS_MOCK_PORT (90cec2d)

Styles

  • chat: format completion params union (91d9de9)

1.5.0 (2026-07-30)

Full Changelog: v1.4.1...v1.5.0

Features

1.4.1 (2026-07-29)

Full Changelog: v1.4.0...v1.4.1

Chores

  • internal: codegen related update (873736d)

1.4.0 (2026-07-24)

Full Changelog: v1.3.0...v1.4.0

Features

  • stlc: configurable CI runner and private-production-repo support in workflow templates (21fa0b8)

Bug Fixes

  • ci: bump @​arethetypeswrong/cli to ^0.18.0 and run CI workflows on Node 24 (4f98c9b)

... (truncated)

Commits
  • 6de8d02 release: 1.6.0 (#273)
  • 8d224a0 chore: GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci]
  • 2c5b7aa chore: GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci]
  • 99fc8ef chore: GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.y...
  • 9f75436 release: 1.5.0 (#270)
  • a4865c3 release: 1.4.1 (#269)
  • 709b1ab release: 1.4.0 (#266)
  • c6029f3 chore(deps): bump brace-expansion from 2.1.1 to 2.1.2 (#268)
  • 02a599a [codex] chore(deps): bump js-yaml patched versions (#265)
  • 1ddeb6d chore(deps): bump picomatch from 2.3.1 to 2.3.2 (#261)
  • Additional commits viewable in compare view

Updates helmet from 8.2.0 to 8.3.0

Changelog

Sourced from helmet's changelog.

8.3.0 - 2026-07-11

Changed

  • Content-Security-Policy: improved performance by ~7% when there are no dynamic directives
  • Content-Security-Policy: improved error handling for invalid directive names

Fixed

  • Content-Security-Policy: useDefaults: false with no directives is no longer valid, both at runtime and the type level
  • Content-Security-Policy: dynamically-computed directive values would throw, not call next, when invalid
  • Content-Security-Policy: dynamically-computed directive value entries would throw, not call next, when function threw
Commits
  • 75f1a98 8.3.0
  • f03f70d Update changelog for 8.3.0 release
  • a307fce Fix capitalization in CSP package changelog
  • 5347b43 Format default CSP in README for readability
  • 9afc570 CSP: fix middleware-specific README missing link
  • 266c95c Minor speedups to project setups test
  • 7a4196c CSP: update package-specific changelog
  • 02716b4 CSP: improve performance when there are no dynamic directives
  • 3f511ed CSP: move utility functions to separate file
  • 80338af CSP: disabling defaults with no directives is now an error
  • Additional commits viewable in compare view

Updates joi from 18.2.3 to 18.2.5

Commits
  • 58ce83e 18.2.5
  • 120672d Merge pull request #3131 from Hashim1999164/fix/email-allow-underscore
  • 5bd73b8 fix: allow allowUnderscore option on string().email()
  • 2b4f443 Merge pull request #3138 from hapijs/fix/messages-proto-injection
  • 90d0757 fix: prevent messages proto injection
  • 82ff29f Merge pull request #3136 from hapijs/chore/improve-unique-documentation
  • ad308cc chore: improve unique documentation
  • ea3e156 18.2.4
  • 262c4f1 Merge pull request #3134 from hapijs/fix/rename-proto
  • 162f367 fix: prevent proto on renames
  • See full diff in compare view

Updates mediasoup from 3.20.9 to 3.26.0

Release notes

Sourced from mediasoup's releases.

3.26.0

3.25.0

3.24.2

3.24.1

3.24.0

3.23.2

3.23.1

Worker: Fix, use thread_local buffer on MS_ABORT() (PR#1873).

3.23.0

3.22.0

3.21.2

... (truncated)

Changelog

Sourced from mediasoup's changelog.

3.26.0

3.25.0

3.24.2

3.24.1

3.24.0

3.23.2

3.23.1

  • Worker: Fix, use thread_local buffer on MS_ABORT() (PR#1873).

3.23.0

3.22.0

3.21.2

... (truncated)

Commits
  • 8a12e25 release 3.26.0 [no-ci]
  • 2adae20 update npm dev deps
  • d1fa5c6 Simulcast and SVC: Limit temporal layer to the preferred one (#1892)
  • 6f464e1 release rust-0.26.0 [no-ci]
  • b64ab75 mediasoup-sys 0.16.0 [crate-publish] [no-ci]
  • f18816c release 3.25.0 [no-ci]
  • 3c23856 SimulcastProducerStreamManager: Apply new capture time logic and fix 'abs-c...
  • 4e174a7 SCTP: Fix SackChunk::GetValidatedGapAckBlocks() returning a bogus gap-ack-b...
  • 0cc30b0 Fix abs-capture-time extension read failure (#1888)
  • 9e294f1 Generate RTCP Sender Reports based on the capture instant of the media rather...
  • Additional commits viewable in compare view

Updates mongoose from 9.7.2 to 9.9.4

Release notes

Sourced from mongoose's releases.

9.9.4 / 2026-08-25

  • fix(query): set strictQuery and strict on _mongooseOptions consistently #16451 #16447
  • fix(hydration): use the doc model for looking up a ref #16453 rawmind
  • fix(schema): drop the map values subpath when...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 27, 2026
@vercel

vercel Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
a-meet Ready Ready Preview Sep 3, 2026 2:17pm UTC

… with 10 updates

Bumps the server-minor-and-patch group with 10 updates in the /server directory:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm) | `3.1087.0` | `3.1121.0` |
| [@deepgram/sdk](https://github.com/deepgram/deepgram-js-sdk) | `5.5.0` | `5.9.0` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.5.2` | `8.7.0` |
| [groq-sdk](https://github.com/groq/groq-typescript) | `1.3.0` | `1.6.0` |
| [helmet](https://github.com/helmetjs/helmet) | `8.2.0` | `8.3.0` |
| [joi](https://github.com/hapijs/joi) | `18.2.3` | `18.2.5` |
| [mediasoup](https://github.com/versatica/mediasoup) | `3.20.9` | `3.26.0` |
| [mongoose](https://github.com/Automattic/mongoose) | `9.7.2` | `9.9.4` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.13` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.4.0` |



Updates `@aws-sdk/client-ssm` from 3.1087.0 to 3.1121.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1121.0/clients/client-ssm)

Updates `@deepgram/sdk` from 5.5.0 to 5.9.0
- [Release notes](https://github.com/deepgram/deepgram-js-sdk/releases)
- [Changelog](https://github.com/deepgram/deepgram-js-sdk/blob/main/CHANGELOG.md)
- [Commits](deepgram/deepgram-js-sdk@v5.5.0...v5.9.0)

Updates `express-rate-limit` from 8.5.2 to 8.7.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v8.5.2...v8.7.0)

Updates `groq-sdk` from 1.3.0 to 1.6.0
- [Release notes](https://github.com/groq/groq-typescript/releases)
- [Changelog](https://github.com/groq/groq-typescript/blob/main/CHANGELOG.md)
- [Commits](groq/groq-typescript@v1.3.0...v1.6.0)

Updates `helmet` from 8.2.0 to 8.3.0
- [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md)
- [Commits](helmetjs/helmet@v8.2.0...v8.3.0)

Updates `joi` from 18.2.3 to 18.2.5
- [Commits](hapijs/joi@v18.2.3...v18.2.5)

Updates `mediasoup` from 3.20.9 to 3.26.0
- [Release notes](https://github.com/versatica/mediasoup/releases)
- [Changelog](https://github.com/versatica/mediasoup/blob/v3/CHANGELOG.md)
- [Commits](versatica/mediasoup@3.20.9...3.26.0)

Updates `mongoose` from 9.7.2 to 9.9.4
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@9.7.2...9.9.4)

Updates `tsx` from 4.23.1 to 4.23.13
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.1...v4.23.13)

Updates `@types/node` from 26.1.1 to 26.4.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ssm"
  dependency-version: 3.1116.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: "@deepgram/sdk"
  dependency-version: 5.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: express-rate-limit
  dependency-version: 8.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: groq-sdk
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: helmet
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: joi
  dependency-version: 18.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: server-minor-and-patch
- dependency-name: mediasoup
  dependency-version: 3.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: mongoose
  dependency-version: 9.9.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: server-minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: server-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/server/server-minor-and-patch-0a5cc9d3d7 branch from 1fb2ac0 to 748f1b5 Compare September 3, 2026 14:17
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/server/server-minor-and-patch-0a5cc9d3d7 branch October 1, 2026 14:17

This branch was successfully deployed

1 active deployment
Preview — 748f1b5d Deployed Sep 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants