chore(deps): bump the production group across 1 directory with 12 updates - #26
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump the production group across 1 directory with 12 updates#26dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…ates Bumps the production group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@grpc/proto-loader](https://github.com/grpc/grpc-node) | `0.7.15` | `0.8.1` | | [@graphql-tools/schema](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/schema) | `10.0.32` | `10.1.0` | | [@openfga/sdk](https://github.com/openfga/js-sdk) | `0.9.1` | `0.9.7` | | [helmet](https://github.com/helmetjs/helmet) | `8.1.0` | `8.3.0` | | [ws](https://github.com/websockets/ws) | `8.21.0` | `8.21.3` | | [@opentelemetry/api](https://github.com/open-telemetry/opentelemetry-js) | `1.9.0` | `1.9.1` | | [@opentelemetry/exporter-trace-otlp-http](https://github.com/open-telemetry/opentelemetry-js) | `0.219.0` | `0.221.0` | | [@opentelemetry/sdk-metrics](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.10.0` | | [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.219.0` | `0.221.0` | | [@opentelemetry/sdk-trace-base](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.10.0` | | [jose](https://github.com/panva/jose) | `6.1.3` | `6.2.9` | | [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.18.0` | `8.23.0` | Updates `@grpc/proto-loader` from 0.7.15 to 0.8.1 - [Release notes](https://github.com/grpc/grpc-node/releases) - [Commits](https://github.com/grpc/grpc-node/compare/@grpc/proto-loader@0.7.15...@grpc/proto-loader@0.8.1) Updates `@graphql-tools/schema` from 10.0.32 to 10.1.0 - [Release notes](https://github.com/ardatan/graphql-tools/releases) - [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/schema/CHANGELOG.md) - [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/schema@10.1.0/packages/schema) Updates `@openfga/sdk` from 0.9.1 to 0.9.7 - [Release notes](https://github.com/openfga/js-sdk/releases) - [Changelog](https://github.com/openfga/js-sdk/blob/main/CHANGELOG.md) - [Commits](openfga/js-sdk@v0.9.1...v0.9.7) Updates `helmet` from 8.1.0 to 8.3.0 - [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md) - [Commits](helmetjs/helmet@v8.1.0...v8.3.0) Updates `ws` from 8.21.0 to 8.21.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.21.0...8.21.3) Updates `@opentelemetry/api` from 1.9.0 to 1.9.1 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@v1.9.0...v1.9.1) Updates `@opentelemetry/exporter-trace-otlp-http` from 0.219.0 to 0.221.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@experimental/v0.219.0...experimental/v0.221.0) Updates `@opentelemetry/sdk-metrics` from 2.8.0 to 2.10.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@v2.8.0...v2.10.0) Updates `@opentelemetry/sdk-node` from 0.219.0 to 0.221.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@experimental/v0.219.0...experimental/v0.221.0) Updates `@opentelemetry/sdk-trace-base` from 2.8.0 to 2.10.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@v2.8.0...v2.10.0) Updates `jose` from 6.1.3 to 6.2.9 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](panva/jose@v6.1.3...v6.2.9) Updates `pg` from 8.18.0 to 8.23.0 - [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md) - [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.0/packages/pg) --- updated-dependencies: - dependency-name: "@grpc/proto-loader" dependency-version: 0.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: "@graphql-tools/schema" dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: "@openfga/sdk" dependency-version: 0.9.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production - dependency-name: helmet dependency-version: 8.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: ws dependency-version: 8.21.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production - dependency-name: "@opentelemetry/api" dependency-version: 1.9.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production - dependency-name: "@opentelemetry/exporter-trace-otlp-http" dependency-version: 0.221.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: "@opentelemetry/sdk-metrics" dependency-version: 2.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: "@opentelemetry/sdk-node" dependency-version: 0.221.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: "@opentelemetry/sdk-trace-base" dependency-version: 2.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: jose dependency-version: 6.2.9 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: pg dependency-version: 8.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production ... Signed-off-by: dependabot[bot] <support@github.com>
syzygyhack
added a commit
that referenced
this pull request
Aug 23, 2026
The corrected Dependabot grouping produced reviewable PRs this time (#25, #26), so these are applied as one batch alongside cel-go. Go: github.com/google/cel-go 0.27.0 -> 0.29.0. npm (production): @grpc/proto-loader 0.7.15 -> 0.8.1, @graphql-tools/schema 10.0.32 -> 10.1.0, @openfga/sdk 0.9.1 -> 0.9.7, helmet 8.1.0 -> 8.3.0, ws 8.21.0 -> 8.21.3, jose 6.1.3 -> 6.2.9, pg 8.18.0 -> 8.23.0, and the OpenTelemetry packages (api 1.9.1, sdk-metrics/sdk-trace-base 2.10.0, sdk-node/exporter-trace-otlp-http 0.221.0). npm (dev): @opentelemetry/context-async-hooks and tsx. One wrinkle worth recording: bumping ws in the manifests left the lockfile out of step with the `ws` pnpm override, which is a CVE floor rather than a pin. The floor still admits 8.21.3, so it stays as is; the lockfile was resynced and `--frozen-lockfile` passes. Verified: go build and go test pass with cel-go 0.29; frozen lockfile install, build 15/15, typecheck 29/29, unit tests 32/32 tasks.
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/production-ce9740c31c
branch
August 23, 2026 14:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production group with 12 updates in the / directory:
0.7.150.8.110.0.3210.1.00.9.10.9.78.1.08.3.08.21.08.21.31.9.01.9.10.219.00.221.02.8.02.10.00.219.00.221.02.8.02.10.06.1.36.2.98.18.08.23.0Updates
@grpc/proto-loaderfrom 0.7.15 to 0.8.1Release notes
Sourced from @grpc/proto-loader's releases.
Commits
a558430Merge pull request #3049 from murgatroid99/proto-loader_v0.8.1753fbc1proto-loader: Bump to version 0.8.11589ddaMerge pull request #3048 from tawni-dev/fix/protobufjs-7.5.5-security-bump736a45cfix: bump protobufjs to ^7.5.5 to address GHSA-xq3m-2v4x-88gg2670b37Merge pull request #3046 from zarinn3pal/feat/health_check_example37af6c0Merge pull request #3045 from hfhchan-plb/patch-1fd67ca6feat: Added health check exampled7dac60unroll loop and remove unnecessary check99028d3Fix lipo extract command for M1 macs0af3c67Merge pull request #3044 from zarinn3pal/fix/psm-interop-nodeUpdates
@graphql-tools/schemafrom 10.0.32 to 10.1.0Changelog
Sourced from @graphql-tools/schema's changelog.
... (truncated)
Commits
9feabd9chore(release): update monorepo packages versions (#8327)2273c21GraphQL 17 Compatibility (#8346)11f0a21chore(release): update monorepo packages versions (#8303)3c27f9achore(release): update monorepo packages versions (#8284)76b54dachore(release): update monorepo packages versions (#8264)062d229chore(release): update monorepo packages versions (#8261)c7f20acchore(release): update monorepo packages versions (#8157)4aa9156chore(release): update monorepo packages versions (#8145)Updates
@openfga/sdkfrom 0.9.1 to 0.9.7Release notes
Sourced from @openfga/sdk's releases.
... (truncated)
Changelog
Sourced from @openfga/sdk's changelog.
... (truncated)
Commits
ff0a9f5release: v0.9.7 (#470)2978621chore(deps-dev): bump the dependencies group with 4 updates (#469)39be98achore: replace Jest with Node test runner (#466)8ea3346docs: update stated node version support (#468)ad7a03dchore(deps): bump the dependencies group across 1 directory with 9 updates (#...36497d6fix(ci): resolve npm audit vulnerabilities (#464)8d4cfddchore(deps): bump the dependencies group with 5 updates (#463)a301a25chore(deps): bump the dependencies group across 1 directory with 3 updates (#...acd4913chore: sync generated code with sdk-generator (#454)0d20683refactor: rework how nock is setup and used to harden tests (#395)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@openfga/sdksince your current version.Updates
helmetfrom 8.1.0 to 8.3.0Changelog
Sourced from helmet's changelog.
Commits
75f1a988.3.0f03f70dUpdate changelog for 8.3.0 releasea307fceFix capitalization in CSP package changelog5347b43Format default CSP in README for readability9afc570CSP: fix middleware-specific README missing link266c95cMinor speedups to project setups test7a4196cCSP: update package-specific changelog02716b4CSP: improve performance when there are no dynamic directives3f511edCSP: move utility functions to separate file80338afCSP: disabling defaults with no directives is now an errorUpdates
wsfrom 8.21.0 to 8.21.3Release notes
Sourced from ws's releases.
Commits
c791e70[dist] 8.21.3e97a20e[fix] Reject offers withclient_max_window_bitsbelow config787ebf2[dist] 8.21.2b4d62ebRevert "[ci] Trust Coveralls Homebrew tap"e4bb883[security] Use GitHub PVR as main reporting channel2eb3be0[test] Skip test on Node.js versions where it does not applyae1de54[dist] 8.21.18e9511b[ci] Trust Coveralls Homebrew tapf197ac6[fix] Lower default values ofmaxBufferedChunksandmaxFragments8df8265[ci] Update actions/checkout action to v7Updates
@opentelemetry/apifrom 1.9.0 to 1.9.1Release notes
Sourced from @opentelemetry/api's releases.
Changelog
Sourced from @opentelemetry/api's changelog.
Commits
279458eRelease 1.9.1 / 0.35.1 (#3573)4978743fix(http): remove outgoing headers normalization (#3557)d1f9594chore(deps): update dependency rimraf to v4 (#3532)e0abcc0fix: remove JSON syntax error and regenerate tsconfig files (#3566)a90c558fix(sdk-node): register instrumentations early (#3502)5b070b8fix: include TraceState in trace exports (#3569)dcb09b7chore(deps): update dependency gh-pages to v5 (#3571)3bc93a9feat: exponential histogram - part 1 - mapping functions (#3504)3670071fix: avoid grpc types dependency (#3551)b5ef0e4chore: fix proto generation (#3567)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@opentelemetry/apisince your current version.Updates
@opentelemetry/exporter-trace-otlp-httpfrom 0.219.0 to 0.221.0Release notes
Sourced from @opentelemetry/exporter-trace-otlp-http's releases.
... (truncated)
Commits
76fa6b5chore: prepare next release (#6942)3787896chore(deps): update dependency webpack-cli to v7.2.1 (#6934)be5f757fix(deps): update dependency body-parser to v2.3.0 [security] (#6941)f6d8fbechore(deps): lock file maintenance (#6559)9612732chore: remove examples/dice from workspaces (#6937)7107906chore: start using min-release-age in .npmrc, disable minimumReleaseAge for r...a7e5d11chore(deps): update dependency webpack to v5.108.4 (#6933)af7a82dchore(deps): update dependency msw to v2.15.0 (#6831)b9f57c6chore(deps): update dependency@types/webpack-envto v1.18.8 (#6877)cbb4abfchore(deps): update ubuntu docker tag to v26 (#6635)Updates
@opentelemetry/sdk-metricsfrom 2.8.0 to 2.10.0Release notes
Sourced from @opentelemetry/sdk-metrics's releases.
Changelog
Sourced from @opentelemetry/sdk-metrics's changelog.
Commits
76fa6b5chore: prepare next release (#6942)3787896chore(deps): update dependency webpack-cli to v7.2.1 (#6934)be5f757fix(deps): update dependency body-parser to v2.3.0 [security] (#6941)f6d8fbechore(deps): lock file maintenance (#6559)9612732chore: remove examples/dice from workspaces (#6937)7107906chore: start using min-release-age in .npmrc, disable minimumReleaseAge for r...a7e5d11chore(deps): update dependency webpack to v5.108.4 (