Skip to content

chore(deps): bump the minor-and-patch group across 1 directory with 5 updates - #67

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/minor-and-patch-90403e9cde
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/minor-and-patch-90403e9cde

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 5 updates in the /frontend directory:

Package From To
@tanstack/react-query 5.102.8 5.103.2
next 16.3.4 16.3.6
tailwind-merge 3.6.0 3.7.0
eslint-config-next 16.3.4 16.3.6
orval 8.34.0 8.37.0

Updates @tanstack/react-query from 5.102.8 to 5.103.2

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.103.2
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query-next-experimental@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query-persist-client@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.103.2
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query@​5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2
Changelog

Sourced from @​tanstack/react-query's changelog.

5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2

5.103.1

Patch Changes

5.103.0

Patch Changes

Commits
  • e0f6c55 ci: Version Packages (#11525)
  • c08f576 ci: Version Packages (#11511)
  • 19ccf27 ci: Version Packages (#11339)
  • 2da46cd chore(*): use eslint description syntax for grandfathered 'no-restricted-synt...
  • 58ad3e2 fix: isolate TypeScript test output (#11503)
  • d63afc7 Simplifed query methods/internal tests new lint (#11347)
  • 23fbdc3 test({react,preact,solid,angular}-query): remove 'fromGenericOptionsQueryFn' ...
  • 50680b9 test({react,preact,solid,svelte}-query,angular-query-experimental): rename 'm...
  • 0b326b6 test({react,preact}-query/useMutation): add tests for 'MutationFunctionContex...
  • a1119e5 ref(hydration): remove outdated dehydratedAt fallback (#11436)
  • Additional commits viewable in compare view

Updates next from 16.3.4 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)
Commits
  • a758ffc v16.3.6
  • 868fad3 [active-lts] Harden next/og SVG serialization
  • 8c81cbb [lts-active] test: remove unsupported deployment ID builder cases (#98821)
  • ca2c75e v16.3.5
  • 14fb290 [backport] Fix use cache prerender signal retention (#98448)
  • 2b1f28d [16.3.x] Add CSP nonce to script tags of loading and template files (#98403)
  • 4b56cee [16.3.x] Backport docs fixes (#98317)
  • 5568a02 [backport] docs: local development: Rewrite docker section, add Windows Dev D...
  • 93249ab [16.3.X] Emit whole-app server NFTs when output: 'standalone' is used with ...
  • 6549fd7 [16.3.x] next/image: reject empty image on read/write to disk cache (#98186)
  • Additional commits viewable in compare view

Updates tailwind-merge from 3.6.0 to 3.7.0

Release notes

Sourced from tailwind-merge's releases.

tailwind-merge@3.7.0

New Features

  • Prepare some upcoming changes by @​dcastil in dcastil/tailwind-merge#713
    • Theme getters returned by fromTheme now expose the theme key they read as a themeKey property, so tooling can identify the referenced theme scale without calling the getter.
    • Release tags now include the package name, starting with tailwind-merge@3.7.0.

Bug Fixes

Documentation

Other

Full Changelog: v3.6.0...v3.7.0

Thanks to @​brandonmcconnell, @​manavm1990, @​langy, @​roboflow, @​syntaxfm, @​getsentry, @​codecov, a private sponsor, @​openclaw, @​sourcegraph, @​cesarvcanal, @​CasperKristiansson, @​jbisasky, @​frontendmasters and more via @​thnxdev for sponsoring tailwind-merge! ❤️

Commits
  • 511d68a tailwind-merge@3.7.0
  • 2461127 Release tooling: Pass the namespaced tag prefix and commit message to pnpm's ...
  • 9d41508 add changelog for tailwind-merge@3.7.0
  • c78a80f Configurator: Reuse runtime lookups during pruning
  • 49c317d Monorepo: Fix contributing link and include package coverage
  • 7b565ca Configurator: prune a generated config to a project's used classes (core step)
  • d83e013 Releases: auto-re-pin tag-pinned links on every version bump
  • b71fd41 Docs: pin every in-repo file link to a release tag instead of main
  • ee29441 Docs: point the ThemeObject JSDoc link at the packaged docs location
  • 9521b10 Releases: per-package pipeline with namespaced tags
  • Additional commits viewable in compare view

Updates eslint-config-next from 16.3.4 to 16.3.6

Release notes

Sourced from eslint-config-next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)
Commits

Updates orval from 8.34.0 to 8.37.0

Release notes

Sourced from orval's releases.

Release v8.37.0

What's Changed

New Contributors

Full Changelog: orval-labs/orval@v8.36.0...v8.37.0

Release v8.36.0

What's Changed

Full Changelog: orval-labs/orval@v8.35.0...v8.36.0

Release v8.35.0

What's Changed

... (truncated)

Commits
  • a9c8fc2 chore(release): bump version to v8.37.0 (#4196)
  • 8490ed4 fix(swr): apply urlEncodeParameters to the axios request function (#4195)
  • db17934 build(deps): bump voidzero-dev/setup-vp from 1.20.0 to 1.21.0 (#4193)
  • c761b14 refactor: replace fs-extra with node:fs (#4192)
  • f2d50c5 fix(core): serialize factory enum members from their value (GHSA-w4x4-mpp4-48...
  • 2559097 chore: bump vite+ 0.3.1 -> 0.3.3 (#4190)
  • 6951c4f feat(angular): parse JSON request bodies under runtimeValidation.requestBodie...
  • 5dd8f70 refactor(core): simplify snake/kebab case machinery and drop unused upper (#4...
  • dfd3a2a feat(mock): add override.mock.exactOptional for exactOptionalPropertyTypes (#...
  • 1e727f2 fix(core): type multipart file parts in shared request body schemas (#4183)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the minor-and-patch group with 5 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.102.8` | `5.103.2` |
| [next](https://github.com/vercel/next.js) | `16.3.4` | `16.3.6` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.4` | `16.3.6` |
| [orval](https://github.com/orval-labs/orval) | `8.34.0` | `8.37.0` |



Updates `@tanstack/react-query` from 5.102.8 to 5.103.2
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.103.2/packages/react-query)

Updates `next` from 16.3.4 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.4...v16.3.6)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `eslint-config-next` from 16.3.4 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `orval` from 8.34.0 to 8.37.0
- [Release notes](https://github.com/orval-labs/orval/releases)
- [Commits](orval-labs/orval@v8.34.0...v8.37.0)

---
updated-dependencies:
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.103.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: orval
  dependency-version: 8.37.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@timothybrown

Copy link
Copy Markdown
Owner

Superseded by #68, which applies these same five bumps re-resolved locally with the pnpm.overrides block intact (this PR failed --frozen-lockfile with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH), and also clears the 12 open undici alerts.

@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/minor-and-patch-90403e9cde branch October 3, 2026 12:17
timothybrown added a commit that referenced this pull request Oct 3, 2026
Supersedes #67, which CI rejected with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH:
Dependabot regenerated pnpm-lock.yaml without the `pnpm.overrides`
block. Re-resolved locally instead, keeping overrides intact.

Security alerts cleared (12 -> 0, all undici, fixed in 7.29.1):
- 11 of the 12 were reopened by #63. Its orval 8.34 bump pulled in
  @scalar/json-magic 0.13.5/0.14.0, which declare an exact
  `undici: 7.24.4` dependency, so a vulnerable copy landed beside the
  patched 7.29.1. #108 (TLS cert validation bypass) is new today.
- Added an `undici: ^7.29.1` override floor. Bumping orval/scalar would
  not hold: json-magic 0.15.4 still pins undici exactly (7.29.1), so
  the next advisory would reopen this. The floor stays within 7.x,
  which is what json-magic's own newer releases already use.

Also raised two existing floors for advisories published 2026-09-29
that GitHub has not alerted on yet: fast-uri ^3.1.8 and
brace-expansion ^5.0.12. pnpm audit: 27 -> 1. The remaining one is
braces 3.0.3 (GHSA-vfj7-8cjw-p6xm), which has no patched release; it is
reached only through eslint-config-next's lint toolchain.

minor-and-patch group (#67), at #67's exact targets:
@tanstack/react-query 5.103.2, next/eslint-config-next 16.3.6,
tailwind-merge 3.7.0, orval 8.37.0. pnpm's resolver picked
react-query 5.104.1 and orval 8.39.0 (1-2 days old); held them back to
respect the 7-day cooldown. Every newly added package version in the
lockfile is at least 9 days old.

Overrides use caret floors, not exact pins.

Verified locally: pnpm install --frozen-lockfile succeeds; generate
(byte-identical output under orval 8.37), tsc, lint and build clean;
601 tests pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant