Skip to content

build: Bump the backend-minor group across 1 directory with 19 updates - #210

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend-minor-3a4f220b23
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend-minor-3a4f220b23

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the backend-minor group with 19 updates in the / directory:

Package From To
@nestjs/throttler 6.5.0 6.7.1
@opentelemetry/auto-instrumentations-node 0.79.0 0.80.0
@opentelemetry/exporter-trace-otlp-http 0.221.0 0.222.0
@opentelemetry/resources 2.10.0 2.11.0
@opentelemetry/sdk-node 0.221.0 0.222.0
jose 6.2.10 6.2.12
pg 8.23.0 8.23.1
redis 6.2.1 6.3.0
@types/node 26.4.0 26.6.3
@typescript-eslint/eslint-plugin 8.68.0 8.71.0
@typescript-eslint/parser 8.68.0 8.71.0
eslint 10.9.1 10.11.0
eslint-plugin-sonarjs 4.2.0 4.2.2
globals 17.11.0 17.13.0
jest 30.5.0 30.5.2
prettier 3.9.6 3.9.9
supertest 7.2.2 7.3.0
ts-jest 29.4.12 29.4.14
typescript-eslint 8.68.0 8.71.0

Updates @nestjs/throttler from 6.5.0 to 6.7.1

Release notes

Sourced from @​nestjs/throttler's releases.

v6.7.1

Patch Changes

  • e8368b3: Set rate limit headers through res.setHeader() when the response has no res.header() method, so the guard no longer throws res.header is not a function on custom HTTP adapters. The logic lives in a new protected setResponseHeader() method that subclasses can override.
  • a482ef9: Coerce numeric strings for limit, ttl and blockDuration to numbers, as returned for example by ConfigService.get<number>() for environment variables. Previously Date.now() + '60000' concatenated instead of adding, which silently corrupted every expiry and X-RateLimit-Reset. A value that is not numeric now fails with an error naming the option and the throttler.
  • a9a28b9: Respect an explicit 0 for limit, ttl and blockDuration in @Throttle() and the module options instead of falling back to the default. blockDuration: 0 now means "no extra block": the in-memory storage rejects requests while the window is full and lets them through again as soon as the oldest hit expires, without recording the rejected ones.
  • bf81677: Import shared interfaces from the public Nest package entry point for Nest 12 compatibility.
  • caaabc9: Stop the in-memory storage from retaining request contexts. It used to schedule one setTimeout per counted hit, and each timer kept the request's AsyncLocalStorage stores (for example an ORM's per-request entity manager) in memory until the TTL expired. It now records when each hit expires and prunes expired hits on access. The idle-record sweep is also no longer tied to the context of the first request. With blockDuration: 0, Retry-After now reports when the oldest hit expires rather than when the window ends.
  • 7703c10: Log a warning when no throttler is configured. The guard limits nothing in that case and previously said nothing at boot, so ThrottlerModule.forRoot() and ThrottlerModule.forRoot([]) looked like a working setup.

v6.7.0

Minor Changes

  • 7004a97: Normalize IPv6 source addresses in the default tracker, and evict expired records from the in-memory storage.

    The built-in getTracker returned req.ip verbatim, so a client holding an IPv6 allocation could send every request from a different address within its own subnet and never share a counter, defeating the rate limit. Addresses are now masked to a /64 before being used as the tracker; the prefix length is configurable via the new ipv6SubnetPrefix module option. IPv4 addresses, IPv4-mapped addresses, the loopback, and custom getTracker implementations are unaffected.

    ThrottlerStorageService also never removed records, so a stream of requests from distinct trackers grew the internal map for the lifetime of the process. Idle records are now swept out once their window has fully elapsed. Limiting behaviour is unchanged: a record is only dropped after every pending hit has expired and any block has lapsed.

    Note that the tracker string for IPv6 clients changes shape (2001:db8:0:1::/64), so storage keys rotate once on upgrade.

v6.6.0

Minor Changes

  • c342bad: Declare the supported Node versions in engines, matching the range the CI matrix tests
  • c625e98: Update to allow for support for Nest version 12
Changelog

Sourced from @​nestjs/throttler's changelog.

6.7.1

Patch Changes

  • e8368b3: Set rate limit headers through res.setHeader() when the response has no res.header() method, so the guard no longer throws res.header is not a function on custom HTTP adapters. The logic lives in a new protected setResponseHeader() method that subclasses can override.
  • a482ef9: Coerce numeric strings for limit, ttl and blockDuration to numbers, as returned for example by ConfigService.get<number>() for environment variables. Previously Date.now() + '60000' concatenated instead of adding, which silently corrupted every expiry and X-RateLimit-Reset. A value that is not numeric now fails with an error naming the option and the throttler.
  • a9a28b9: Respect an explicit 0 for limit, ttl and blockDuration in @Throttle() and the module options instead of falling back to the default. blockDuration: 0 now means "no extra block": the in-memory storage rejects requests while the window is full and lets them through again as soon as the oldest hit expires, without recording the rejected ones.
  • bf81677: Import shared interfaces from the public Nest package entry point for Nest 12 compatibility.
  • caaabc9: Stop the in-memory storage from retaining request contexts. It used to schedule one setTimeout per counted hit, and each timer kept the request's AsyncLocalStorage stores (for example an ORM's per-request entity manager) in memory until the TTL expired. It now records when each hit expires and prunes expired hits on access. The idle-record sweep is also no longer tied to the context of the first request. With blockDuration: 0, Retry-After now reports when the oldest hit expires rather than when the window ends.
  • 7703c10: Log a warning when no throttler is configured. The guard limits nothing in that case and previously said nothing at boot, so ThrottlerModule.forRoot() and ThrottlerModule.forRoot([]) looked like a working setup.

6.7.0

Minor Changes

  • 7004a97: Normalize IPv6 source addresses in the default tracker, and evict expired records from the in-memory storage.

    The built-in getTracker returned req.ip verbatim, so a client holding an IPv6 allocation could send every request from a different address within its own subnet and never share a counter, defeating the rate limit. Addresses are now masked to a /64 before being used as the tracker; the prefix length is configurable via the new ipv6SubnetPrefix module option. IPv4 addresses, IPv4-mapped addresses, the loopback, and custom getTracker implementations are unaffected.

    ThrottlerStorageService also never removed records, so a stream of requests from distinct trackers grew the internal map for the lifetime of the process. Idle records are now swept out once their window has fully elapsed. Limiting behaviour is unchanged: a record is only dropped after every pending hit has expired and any block has lapsed.

    Note that the tracker string for IPv6 clients changes shape (2001:db8:0:1::/64), so storage keys rotate once on upgrade.

6.6.0

Minor Changes

  • c342bad: Declare the supported Node versions in engines, matching the range the CI matrix tests
  • c625e98: Update to allow for support for Nest version 12

6.4.0

6.5.1

Patch Changes

  • 603cb82: handles edge case where multiple clients making frequent requests interfere with each other
Commits
  • 91f4912 Merge pull request #2706 from nestjs/changeset-release/master
  • c5e8c90 chore: version packages
  • 9ec3aa3 Merge pull request #2668 from nestjs/renovate/major-nest-monorepo
  • 5d3b9ae Merge pull request #2712 from nestjs/fix/coerce-numeric-options
  • 4335230 Merge pull request #2711 from nestjs/fix/timer-free-storage
  • a482ef9 fix(guard): coerce numeric string options
  • e082222 chore(deps): update nest monorepo to v12
  • caaabc9 fix(storage): do not retain request contexts in timers
  • 4ab8c63 Merge pull request #2697 from nestjs/renovate/node-24.x
  • c36f011 Merge pull request #2703 from nestjs/renovate/nest-graphql-monorepo
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​nestjs/throttler since your current version.


Updates @opentelemetry/auto-instrumentations-node from 0.79.0 to 0.80.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.80.0

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.31.0 to ^0.32.0

... (truncated)

Commits

Updates @opentelemetry/exporter-trace-otlp-http from 0.221.0 to 0.222.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-http's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @​trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @​trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @​trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @​trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @​dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @​JacksonWeber

📚 Documentation

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @​david-luna
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/resources from 2.10.0 to 2.11.0

Release notes

Sourced from @​opentelemetry/resources's releases.

v2.11.0

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @​pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @​LarryHu0217

🐛 Bug Fixes

  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @​mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @​mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @​LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @​pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id
Changelog

Sourced from @​opentelemetry/resources's changelog.

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @​pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @​LarryHu0217

🐛 Bug Fixes

  • fix(sdk-trace-base): avoid a Webpack self-reference error in CommonJS output #6981 @​sansynx
  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @​mwear
  • fix(core): cap tracestate list-members when calling TraceState.set() so a 32-member list cannot grow past the W3C limit #6964 @​Zuhef

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @​mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @​LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @​pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-node from 0.221.0 to 0.222.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @​trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @​trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @​trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @​trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @​dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @​JacksonWeber

📚 Documentation

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @​david-luna
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates jose from 6.2.10 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)
Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)
Commits
  • 505a55b chore(release): 6.2.12
  • 7bc9a33 perf: encode single-signature JWS input once
  • 78637bd perf: normalize General JWE shared headers once
  • bf5138b perf: deduplicate pending jwks key imports
  • b23a6f3 perf: use native encoding for larger ASCII strings
  • fd3ae3f perf: normalize jwks selection metadata once
  • 6925d43 perf: avoid copying AES-GCM output
  • be62530 docs: clarify and shorten public API guidance
  • 1b41312 build: preserve README when generation fails
  • 0b51829 build: check tree-shaking for every public binding
  • Additional commits viewable in compare view

Updates pg from 8.23.0 to 8.23.1

Changelog

Sourced from pg's changelog.

All major and minor releases are briefly explained below.

For richer information consult the commit log on github with referenced pull requests.

We do not include break-fix version release in this file.

Commits
  • 0980cef Publish
  • 2759b2c fix(pg): run a named statement with an empty text more than once (#3781)
  • 7feb7df fix(pg): expose detail and hint on errors from the native client (#3780)
  • 9683053 fix(pg): do not treat Sync as connection ending (#3772)
  • 4589038 fix: validate server certificate against host when connecting to an IP addres...
  • 9808955 cleanup: Fix typo in comment
  • 2b02f64 fix: avoid mutating query config (#3720)
  • 0cef6af Reject portal based queries in pipeline mode instead of misrouting rows (#3737)
  • 2991480 Deprecate serializing invalid Dates (#3731)
  • c940d7c Fail pipelined queries when the connection dies instead of hanging (#3736)
  • Additional commits viewable in compare view

Updates redis from 6.2.1 to 6.3.0

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for redis since your current version.


Updates @types/node from 26.4.0 to 26.6.3

Commits

Updates @typescript-eslint/eslint-plugin from 8.68.0 to 8.71.0

Release notes

Sourced from @​typescript-eslint/eslint-plugin's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)

... (truncated)

Changelog

Sourced from @​typescript-eslint/eslint-plugin's changelog.

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.70.1 (2026-09-21)

🩹 Fixes

  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (<...

    Description has been truncated

Bumps the backend-minor group with 19 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@nestjs/throttler](https://github.com/nestjs/throttler) | `6.5.0` | `6.7.1` |
| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.79.0` | `0.80.0` |
| [@opentelemetry/exporter-trace-otlp-http](https://github.com/open-telemetry/opentelemetry-js) | `0.221.0` | `0.222.0` |
| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `2.10.0` | `2.11.0` |
| [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.221.0` | `0.222.0` |
| [jose](https://github.com/panva/jose) | `6.2.10` | `6.2.12` |
| [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.23.0` | `8.23.1` |
| [redis](https://github.com/redis/node-redis) | `6.2.1` | `6.3.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.0` | `26.6.3` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.68.0` | `8.71.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.68.0` | `8.71.0` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` |
| [eslint-plugin-sonarjs](https://github.com/SonarSource/SonarJS) | `4.2.0` | `4.2.2` |
| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.13.0` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.5.0` | `30.5.2` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.12` | `29.4.14` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.68.0` | `8.71.0` |



Updates `@nestjs/throttler` from 6.5.0 to 6.7.1
- [Release notes](https://github.com/nestjs/throttler/releases)
- [Changelog](https://github.com/nestjs/throttler/blob/master/CHANGELOG.md)
- [Commits](nestjs/throttler@v6.5.0...v6.7.1)

Updates `@opentelemetry/auto-instrumentations-node` from 0.79.0 to 0.80.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.80.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/exporter-trace-otlp-http` from 0.221.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.221.0...experimental/v0.222.0)

Updates `@opentelemetry/resources` from 2.10.0 to 2.11.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.10.0...v2.11.0)

Updates `@opentelemetry/sdk-node` from 0.221.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.221.0...experimental/v0.222.0)

Updates `jose` from 6.2.10 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.10...v6.2.12)

Updates `pg` from 8.23.0 to 8.23.1
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.1/packages/pg)

Updates `redis` from 6.2.1 to 6.3.0
- [Release notes](https://github.com/redis/node-redis/releases)
- [Changelog](https://github.com/redis/node-redis/blob/master/CHANGELOG.md)
- [Commits](https://github.com/redis/node-redis/compare/redis@6.2.1...redis@6.3.0)

Updates `@types/node` from 26.4.0 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.68.0 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.68.0 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/parser)

Updates `eslint` from 10.9.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.11.0)

Updates `eslint-plugin-sonarjs` from 4.2.0 to 4.2.2
- [Release notes](https://github.com/SonarSource/SonarJS/releases)
- [Changelog](https://github.com/SonarSource/SonarJS/blob/master/docs/RELEASE.md)
- [Commits](https://github.com/SonarSource/SonarJS/commits)

Updates `globals` from 17.11.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.11.0...v17.13.0)

Updates `jest` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

Updates `ts-jest` from 29.4.12 to 29.4.14
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.14)

Updates `typescript-eslint` from 8.68.0 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@nestjs/throttler"
  dependency-version: 6.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/exporter-trace-otlp-http"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/resources"
  dependency-version: 2.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: jose
  dependency-version: 6.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: pg
  dependency-version: 8.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: redis
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: eslint-plugin-sonarjs
  dependency-version: 4.2.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: ts-jest
  dependency-version: 29.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from Mikefluff as a code owner October 4, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants