Skip to content

chore(deps): bump the prod group across 1 directory with 9 updates - #74

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/prod-3d792f2af4
Open

chore(deps): bump the prod group across 1 directory with 9 updates#74
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/prod-3d792f2af4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the prod group with 9 updates in the / directory:

Package From To
@codemirror/view 6.43.6 6.43.7
@prisma/adapter-pg 7.9.0 7.9.1
@prisma/client 7.9.0 7.9.1
@supabase/supabase-js 2.110.8 2.111.0
@tanstack/react-virtual 3.14.8 3.14.9
motion 12.42.2 12.43.0
next 16.3.0-preview.9 16.3.0-preview.10
pangu 8.0.0 9.0.0
prisma 7.9.0 7.9.1

Updates @codemirror/view from 6.43.6 to 6.43.7

Commits

Updates @prisma/adapter-pg from 7.9.0 to 7.9.1

Release notes

Sourced from @​prisma/adapter-pg's releases.

7.9.1

Today, we're issuing a patch release to resolve a security advisory in a transitive dependency of Prisma CLI (via @prisma/dev).

This fixes prisma/prisma#29780.

It does not actually affect @prisma/dev or Prisma CLI so no urgent action is required, but it is recommended to upgrade nevertheless to avoid false positives from security scanners.

Commits

Updates @prisma/client from 7.9.0 to 7.9.1

Release notes

Sourced from @​prisma/client's releases.

7.9.1

Today, we're issuing a patch release to resolve a security advisory in a transitive dependency of Prisma CLI (via @prisma/dev).

This fixes prisma/prisma#29780.

It does not actually affect @prisma/dev or Prisma CLI so no urgent action is required, but it is recommended to upgrade nevertheless to avoid false positives from security scanners.

Commits

Updates @supabase/supabase-js from 2.110.8 to 2.111.0

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.111.0

2.111.0 (2026-07-28)

🚀 Features

  • auth: store PKCE verifiers in per-flow slots to survive overlapping flows (#2569)

❤️ Thank You

v2.111.0-canary.0

2.111.0-canary.0 (2026-07-28)

🚀 Features

  • auth: store PKCE verifiers in per-flow slots to survive overlapping flows (#2569)

❤️ Thank You

v2.110.9

2.110.9 (2026-07-27)

🩹 Fixes

  • auth: downgrade stale refresh token console noise (#2559)
  • realtime: preserve presence refs (#2566)
  • repo: override sharp to >=0.35.0 to clear libvips advisory (#2548)
  • repo: populate symbols in sdk-compliance so capabilities are verifiable (#2547)
  • repo: bump postcss, babel, next to clear audit advisories (#2561)

❤️ Thank You

v2.110.9-canary.3

2.110.9-canary.3 (2026-07-27)

🩹 Fixes

  • realtime: preserve presence refs (#2566)

❤️ Thank You

v2.110.9-canary.2

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.111.0 (2026-07-28)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

2.110.9 (2026-07-27)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

Commits
  • 18b5bb2 chore(release): version 2.110.9 changelogs (#2567)
  • fc2e61e chore(repo): bump postcss override and fix playwright 1.62 tsconfig failure (...
  • 22050de chore(release): version 2.110.8 changelogs (#2546)
  • See full diff in compare view

Updates @tanstack/react-virtual from 3.14.8 to 3.14.9

Release notes

Sourced from @​tanstack/react-virtual's releases.

@​tanstack/react-virtual@​3.14.9

Patch Changes

  • Updated dependencies [a5417b4]:
    • @​tanstack/virtual-core@​3.17.7
Changelog

Sourced from @​tanstack/react-virtual's changelog.

3.14.9

Patch Changes

  • Updated dependencies [a5417b4]:
    • @​tanstack/virtual-core@​3.17.7
Commits
  • b4a76ca fix(marko-virtual): consolidate Marko e2e into one in-package app, fix test (...
  • deca524 ci: Version Packages (#1240)
  • See full diff in compare view

Updates motion from 12.42.2 to 12.43.0

Changelog

Sourced from motion's changelog.

[12.43.0] 2026-07-27

Added

  • Hardware acceleration for backgroundColor in supported browsers.
  • Hardware acceleration for SVG elements.

Fixed

  • AnimatePresence: Exiting children no longer interleave with entering children, which could reorder and remount children present in both renders.
  • motion: Throw error when passing a custom motion component an incorrect ref type.
Commits
  • a4ef40a v12.43.0
  • 14f2d28 adding svg acceleration
  • 1f5a27b Fixing merge
  • 79f0353 Updating changelog
  • 57f179b Updating changelog
  • 695cb39 Merge pull request #3755 from motiondivision/fix-issue-2777
  • 33a1820 Drop the production fallback for non-DOM refs
  • ebe35f2 Throw an actionable invariant for non-DOM custom component refs
  • a6ed094 Merge pull request #3754 from motiondivision/fix-3745-popchild-ref-warning
  • 9f251f3 Merge pull request #3763 from motiondivision/advisor/003-color-waapi
  • Additional commits viewable in compare view

Updates next from 16.3.0-preview.9 to 16.3.0-preview.10

Release notes

Sourced from next's releases.

v16.3.0-preview.10

Misc Changes

  • Unify allow-runtime with Partial Prefetching: #96106
  • Attempt static prefetch before resorting to runtime: #96095
  • Block prefetch task until sufficient response is received: #96017
  • Use a safe clock for Request Insights bookkeeping: #96274
  • Count key length in remaining byte-budgeted LRUs: #96231
  • Serve cached misses from the filesystem route cache: #96230
  • Count URL key length in the filesystem route cache LRU: #96229
  • Turbopack: Only extend the watcher's batch window for unfiltered events: #96186
  • Turbopack: Store watcher batch state with bitflags instead of 4 different sets: #96114
  • docs: document query-only href resolution and fix with-vercel-blob : #96280
  • Micro-optimization for string format: #95774
  • Upgrade React from 28cd4bb0-20260723 to 756fdd47-20260727: #96270
  • [test] Unflake more tests: #96081
  • [test] Run the navigation e2e suite under cacheComponents: #95877
  • [test] Run more test suites under cacheComponents flag, again: #96196
  • [test] Unflake a prefetch-related race: #96222
  • docs(ai-agents): restructure as steps and close 16.2/16.3 coverage gaps: #96247
  • Replace vendored http-proxy with httpxy: #96060
  • Update vendored @mswjs/interceptors to 0.41.9: #96059
  • Track whether runtime data is accessed during prefetch: #95964
  • Add Instant Insights request timing: #95958
  • [turbopack] Tree-shake module.exports = {...} (CJS): #95996
  • [turbopack] Fix de-opt in getChunkRelativeUrl(): #96183
  • Add shell offset to static segment prefetches: #95963
  • Turbopack: support import.meta.glob caseSensitive option: #96226
  • fix(sandbox): release one-shot timeout ids after they run: #96161
  • Fix dev overlay symbolication for project paths needing percent-encoding: #96221
  • [internal] Add a skill for benching changes in a sandbox: #95943
  • Run dev validation in process when using Webpack: #96219
  • Read chunk source maps from disk in the dev validation worker: #96218
  • Retry the source map lookup with a plain path: #96215
  • Pass fallback params to the dev validation worker as maps: #96210
  • [sourcemaps] Reuse source map payloads and consumers across stack frames: #96198
  • fix: release compression stream when client disconnects mid-response: #96173
  • Run Cache Components dev validation on a worker thread: #96153
  • Add a benchmark for dev Cache Components validation on a worker thread: #96152
  • [test] Unflake the enabled-features-trace test suite: #96175
  • [refactor] Prepare dev validation for running on a worker thread: #96151
  • Add the experimental.devValidationWorker config flag: #96150
  • [refactor] Model dev validation render outputs as a discriminated union: #96149
  • Forward dev invalid dynamic usage errors from the render, not validation: #96148
  • Optimize implicit cache tag derivation: #96120
  • Avoid quadratic HMR queue shifts: #96137
  • [sourcemaps] Use file: sourcemaps for Turbopack to improve dev performance: #95946
  • Give RouteCacheEntry a single hidden class across its lifecycle: #96164
  • Keep optimistic-route param handling monomorphic: #96169
  • Store RouteTree slots in a Map to keep slot access monomorphic: #96168

... (truncated)

Commits

Updates pangu from 8.0.0 to 9.0.0

Changelog

Sourced from pangu's changelog.

v9.0.0 / 2026-07-28

  • 修正 <wbr> 這類元素把 / 兩邊拆成不同文字節點時,斜線前面會漏加空格的問題
  • 拿掉了 package.jsonmodule 欄位
  • 拿掉了 package.jsonbrowser 欄位
    • 瀏覽器端請改用 import pangu from 'pangu/browser',本來就是文件建議的用法,型別也一直是對的
    • 之前用 bundler 直接 import pangu from 'pangu',執行時會拿到瀏覽器版本,但是 TypeScript 給的型別是 Node.js 版本
    • <script> 載入 UMD 檔案、或是已經在用 pangu/browser 的話都不受影響
  • 支援的 Node.js 版本改成 v20 以上

v8.2.0 / 2026-07-26

  • 修正引號的加空格規則,當引號的內容跨越換行時,不會再把引號外面本來就有的空格吃掉

v8.1.0 / 2026-07-26

  • 修正 - * = < > _ + 這些符號的加空格規則,夾在半形字元中間時會跟兩邊黏成同一個詞,不會再被拆開
  • 修正 + 在字尾的加空格規則
  • 修正 | 的加空格規則,同一行只要有 | 直接貼著中文,整行的 | 都會當成分隔符來加空格,例如 標題|網站名稱 會變成 標題 | 網站名稱
  • 修正 + 直接貼著中文時會當成分隔符來加空格,跟 | 一樣以行為單位來判斷
  • 修正 ! ; , ? 後面直接貼著中文時的加空格規則,現在不管這些符號前面是什麼字元,都會在符號後面加空格
  • 修正純文字中的 <tag> 現在會被當成一個詞來加空格,但是一般網頁中的 HTML 標籤不受影響
  • 修正文字節點的開頭或結尾是 &nbsp;、旁邊又緊接著連結之類的元素時,會多加一個半形空格的問題
  • Chrome extension 的工具列圖示新增了 OFF 狀態,切到手動模式、或是目前網址被黑白名單排除時,圖示會換成頭戴紙袋的圖示
  • Chrome extension 會在所有網頁啟用瀏覽器原生的 text-autospace: normal; 排版
    • 預設啟用,可以在設定裡關掉
    • 需要 Chrome v140 以上版本
  • pangu/browser 改成只提供 ESM,拿掉了 require 條件,require('pangu/browser') 會出現 ERR_PACKAGE_PATH_NOT_EXPORTED
    • 用 bundler 的話 import 照舊,不受影響
    • 在瀏覽器裡直接用 <script> 載入 UMD 檔案的方式也不受影響
Commits
  • fcb713e update changelog
  • af45e4e chore: sync package-lock.json engines.node with package.json
  • 63df5e2 docs: lead with ESM import in README usage examples
  • 9c595f6 fix: write back tail space when junction spacing lands inside current run
  • f1e17a8 refactor: replace cast-and-mutate CJS export object with PanguModule subclass
  • 85ad7e5 refactor: use import = require in node CJS entry
  • 9ff7805 chore: bump version to 9.0.0
  • c764987 Merge pull request #308 from vinta/refactor/build-configs
  • 42199c7 run extension test in browser-test job
  • 91d8921 update changelogs
  • Additional commits viewable in compare view

Updates prisma from 7.9.0 to 7.9.1

Release notes

Sourced from prisma's releases.

7.9.1

Today, we're issuing a patch release to resolve a security advisory in a transitive dependency of Prisma CLI (via @prisma/dev).

This fixes prisma/prisma#29780.

It does not actually affect @prisma/dev or Prisma CLI so no urgent action is required, but it is recommended to upgrade nevertheless to avoid false positives from security scanners.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 29, 2026
@vercel

vercel Bot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
gtmc Error Error Jul 29, 2026 9:30am

Bumps the prod group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@codemirror/view](https://github.com/codemirror/view) | `6.43.6` | `6.43.7` |
| [@prisma/adapter-pg](https://github.com/prisma/prisma/tree/HEAD/packages/adapter-pg) | `7.9.0` | `7.9.1` |
| [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) | `7.9.0` | `7.9.1` |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.110.8` | `2.111.0` |
| [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) | `3.14.8` | `3.14.9` |
| [motion](https://github.com/motiondivision/motion) | `12.42.2` | `12.43.0` |
| [next](https://github.com/vercel/next.js) | `16.3.0-preview.9` | `16.3.0-preview.10` |
| [pangu](https://github.com/vinta/pangu.js) | `8.0.0` | `9.0.0` |
| [prisma](https://github.com/prisma/prisma/tree/HEAD/packages/cli) | `7.9.0` | `7.9.1` |



Updates `@codemirror/view` from 6.43.6 to 6.43.7
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)

Updates `@prisma/adapter-pg` from 7.9.0 to 7.9.1
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.9.1/packages/adapter-pg)

Updates `@prisma/client` from 7.9.0 to 7.9.1
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.9.1/packages/client)

Updates `@supabase/supabase-js` from 2.110.8 to 2.111.0
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.111.0/packages/core/supabase-js)

Updates `@tanstack/react-virtual` from 3.14.8 to 3.14.9
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/react-virtual/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/react-virtual@3.14.9/packages/react-virtual)

Updates `motion` from 12.42.2 to 12.43.0
- [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md)
- [Commits](motiondivision/motion@v12.42.2...v12.43.0)

Updates `next` from 16.3.0-preview.9 to 16.3.0-preview.10
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.0-preview.9...v16.3.0-preview.10)

Updates `pangu` from 8.0.0 to 9.0.0
- [Changelog](https://github.com/vinta/pangu.js/blob/master/HISTORY.md)
- [Commits](vinta/pangu.js@v8.0.0...v9.0.0)

Updates `prisma` from 7.9.0 to 7.9.1
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.9.1/packages/cli)

---
updated-dependencies:
- dependency-name: "@codemirror/view"
  dependency-version: 6.43.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
- dependency-name: "@prisma/adapter-pg"
  dependency-version: 7.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
- dependency-name: "@prisma/client"
  dependency-version: 7.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.111.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod
- dependency-name: "@tanstack/react-virtual"
  dependency-version: 3.14.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
- dependency-name: motion
  dependency-version: 12.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod
- dependency-name: next
  dependency-version: 16.3.0-preview.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
- dependency-name: pangu
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod
- dependency-name: prisma
  dependency-version: 7.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the prod group with 9 updates chore(deps): bump the prod group across 1 directory with 9 updates Jul 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/prod-3d792f2af4 branch from 87e6dd9 to aa8cefa Compare July 29, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants