Repository navigation
chore(deps): bump the minor-and-patch group across 1 directory with 5 updates - #67
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
… updates Bumps the minor-and-patch group with 5 updates in the /frontend directory: | Package | From | To | | --- | --- | --- | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.102.8` | `5.103.2` | | [next](https://github.com/vercel/next.js) | `16.3.4` | `16.3.6` | | [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` | | [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.4` | `16.3.6` | | [orval](https://github.com/orval-labs/orval) | `8.34.0` | `8.37.0` | Updates `@tanstack/react-query` from 5.102.8 to 5.103.2 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.103.2/packages/react-query) Updates `next` from 16.3.4 to 16.3.6 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.3.4...v16.3.6) Updates `tailwind-merge` from 3.6.0 to 3.7.0 - [Release notes](https://github.com/dcastil/tailwind-merge/releases) - [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge) Updates `eslint-config-next` from 16.3.4 to 16.3.6 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next) Updates `orval` from 8.34.0 to 8.37.0 - [Release notes](https://github.com/orval-labs/orval/releases) - [Commits](orval-labs/orval@v8.34.0...v8.37.0) --- updated-dependencies: - dependency-name: "@tanstack/react-query" dependency-version: 5.103.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: next dependency-version: 16.3.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: tailwind-merge dependency-version: 3.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: eslint-config-next dependency-version: 16.3.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: orval dependency-version: 8.37.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Owner
|
Superseded by #68, which applies these same five bumps re-resolved locally with the |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/frontend/minor-and-patch-90403e9cde
branch
October 3, 2026 12:17
timothybrown
added a commit
that referenced
this pull request
Oct 3, 2026
Supersedes #67, which CI rejected with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH: Dependabot regenerated pnpm-lock.yaml without the `pnpm.overrides` block. Re-resolved locally instead, keeping overrides intact. Security alerts cleared (12 -> 0, all undici, fixed in 7.29.1): - 11 of the 12 were reopened by #63. Its orval 8.34 bump pulled in @scalar/json-magic 0.13.5/0.14.0, which declare an exact `undici: 7.24.4` dependency, so a vulnerable copy landed beside the patched 7.29.1. #108 (TLS cert validation bypass) is new today. - Added an `undici: ^7.29.1` override floor. Bumping orval/scalar would not hold: json-magic 0.15.4 still pins undici exactly (7.29.1), so the next advisory would reopen this. The floor stays within 7.x, which is what json-magic's own newer releases already use. Also raised two existing floors for advisories published 2026-09-29 that GitHub has not alerted on yet: fast-uri ^3.1.8 and brace-expansion ^5.0.12. pnpm audit: 27 -> 1. The remaining one is braces 3.0.3 (GHSA-vfj7-8cjw-p6xm), which has no patched release; it is reached only through eslint-config-next's lint toolchain. minor-and-patch group (#67), at #67's exact targets: @tanstack/react-query 5.103.2, next/eslint-config-next 16.3.6, tailwind-merge 3.7.0, orval 8.37.0. pnpm's resolver picked react-query 5.104.1 and orval 8.39.0 (1-2 days old); held them back to respect the 7-day cooldown. Every newly added package version in the lockfile is at least 9 days old. Overrides use caret floors, not exact pins. Verified locally: pnpm install --frozen-lockfile succeeds; generate (byte-identical output under orval 8.37), tsc, lint and build clean; 601 tests pass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor-and-patch group with 5 updates in the /frontend directory:
5.102.85.103.216.3.416.3.63.6.03.7.016.3.416.3.68.34.08.37.0Updates
@tanstack/react-queryfrom 5.102.8 to 5.103.2Release notes
Sourced from @tanstack/react-query's releases.
Changelog
Sourced from @tanstack/react-query's changelog.
Commits
e0f6c55ci: Version Packages (#11525)c08f576ci: Version Packages (#11511)19ccf27ci: Version Packages (#11339)2da46cdchore(*): use eslint description syntax for grandfathered 'no-restricted-synt...58ad3e2fix: isolate TypeScript test output (#11503)d63afc7Simplifed query methods/internal tests new lint (#11347)23fbdc3test({react,preact,solid,angular}-query): remove 'fromGenericOptionsQueryFn' ...50680b9test({react,preact,solid,svelte}-query,angular-query-experimental): rename 'm...0b326b6test({react,preact}-query/useMutation): add tests for 'MutationFunctionContex...a1119e5ref(hydration): remove outdated dehydratedAt fallback (#11436)Updates
nextfrom 16.3.4 to 16.3.6Release notes
Sourced from next's releases.
Commits
a758ffcv16.3.6868fad3[active-lts] Harden next/og SVG serialization8c81cbb[lts-active] test: remove unsupported deployment ID builder cases (#98821)ca2c75ev16.3.514fb290[backport] Fix use cache prerender signal retention (#98448)2b1f28d[16.3.x] Add CSP nonce to script tags of loading and template files (#98403)4b56cee[16.3.x] Backport docs fixes (#98317)5568a02[backport] docs: local development: Rewrite docker section, add Windows Dev D...93249ab[16.3.X] Emit whole-app server NFTs whenoutput: 'standalone'is used with ...6549fd7[16.3.x] next/image: reject empty image on read/write to disk cache (#98186)Updates
tailwind-mergefrom 3.6.0 to 3.7.0Release notes
Sourced from tailwind-merge's releases.
Commits
511d68atailwind-merge@3.7.02461127Release tooling: Pass the namespaced tag prefix and commit message to pnpm's ...9d41508add changelog for tailwind-merge@3.7.0c78a80fConfigurator: Reuse runtime lookups during pruning49c317dMonorepo: Fix contributing link and include package coverage7b565caConfigurator: prune a generated config to a project's used classes (core step)d83e013Releases: auto-re-pin tag-pinned links on every version bumpb71fd41Docs: pin every in-repo file link to a release tag instead of mainee29441Docs: point the ThemeObject JSDoc link at the packaged docs location9521b10Releases: per-package pipeline with namespaced tagsUpdates
eslint-config-nextfrom 16.3.4 to 16.3.6Release notes
Sourced from eslint-config-next's releases.
Commits
a758ffcv16.3.6ca2c75ev16.3.5Updates
orvalfrom 8.34.0 to 8.37.0Release notes
Sourced from orval's releases.
... (truncated)
Commits
a9c8fc2chore(release): bump version to v8.37.0 (#4196)8490ed4fix(swr): apply urlEncodeParameters to the axios request function (#4195)db17934build(deps): bump voidzero-dev/setup-vp from 1.20.0 to 1.21.0 (#4193)c761b14refactor: replace fs-extra with node:fs (#4192)f2d50c5fix(core): serialize factory enum members from their value (GHSA-w4x4-mpp4-48...2559097chore: bump vite+ 0.3.1 -> 0.3.3 (#4190)6951c4ffeat(angular): parse JSON request bodies under runtimeValidation.requestBodie...5dd8f70refactor(core): simplify snake/kebab case machinery and drop unused upper (#4...dfd3a2afeat(mock): add override.mock.exactOptional for exactOptionalPropertyTypes (#...1e727f2fix(core): type multipart file parts in shared request body schemas (#4183)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions