-
Notifications
You must be signed in to change notification settings - Fork 0
deps: bump the dependencies-minor group across 1 directory with 13 updates #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
deps: bump the dependencies-minor group across 1 directory with 13 updates #3
Conversation
…dates Bumps the dependencies-minor group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@fontsource-variable/figtree](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/figtree) | `5.2.8` | `5.2.10` | | [@fontsource/ibm-plex-mono](https://github.com/fontsource/font-files/tree/HEAD/fonts/google/ibm-plex-mono) | `5.2.6` | `5.2.7` | | [@hookform/resolvers](https://github.com/react-hook-form/resolvers) | `5.1.1` | `5.2.2` | | [@oddbird/css-anchor-positioning](https://github.com/oddbird/css-anchor-positioning) | `0.6.1` | `0.7.0` | | [next](https://github.com/vercel/next.js) | `15.5.2` | `15.5.4` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.1.0` | `19.2.0` | | [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.1.8` | `19.2.2` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.1.0` | `19.2.0` | | [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.1.6` | `19.2.1` | | [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.60.0` | `7.64.0` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.54.1` | `1.56.0` | | [sass](https://github.com/sass/dart-sass) | `1.89.2` | `1.93.2` | | [typescript](https://github.com/microsoft/TypeScript) | `5.8.3` | `5.9.3` | Updates `@fontsource-variable/figtree` from 5.2.8 to 5.2.10 - [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md) - [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/figtree) Updates `@fontsource/ibm-plex-mono` from 5.2.6 to 5.2.7 - [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md) - [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/google/ibm-plex-mono) Updates `@hookform/resolvers` from 5.1.1 to 5.2.2 - [Release notes](https://github.com/react-hook-form/resolvers/releases) - [Commits](react-hook-form/resolvers@v5.1.1...v5.2.2) Updates `@oddbird/css-anchor-positioning` from 0.6.1 to 0.7.0 - [Release notes](https://github.com/oddbird/css-anchor-positioning/releases) - [Changelog](https://github.com/oddbird/css-anchor-positioning/blob/main/CHANGELOG.md) - [Commits](oddbird/css-anchor-positioning@v0.6.1...v0.7.0) Updates `next` from 15.5.2 to 15.5.4 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v15.5.2...v15.5.4) Updates `react` from 19.1.0 to 19.2.0 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.0/packages/react) Updates `@types/react` from 19.1.8 to 19.2.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `react-dom` from 19.1.0 to 19.2.0 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.0/packages/react-dom) Updates `@types/react-dom` from 19.1.6 to 19.2.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `react-hook-form` from 7.60.0 to 7.64.0 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](react-hook-form/react-hook-form@v7.60.0...v7.64.0) Updates `@playwright/test` from 1.54.1 to 1.56.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.54.1...v1.56.0) Updates `@types/react` from 19.1.8 to 19.2.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `@types/react-dom` from 19.1.6 to 19.2.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `sass` from 1.89.2 to 1.93.2 - [Release notes](https://github.com/sass/dart-sass/releases) - [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md) - [Commits](sass/dart-sass@1.89.2...1.93.2) Updates `typescript` from 5.8.3 to 5.9.3 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml) - [Commits](microsoft/TypeScript@v5.8.3...v5.9.3) --- updated-dependencies: - dependency-name: "@fontsource-variable/figtree" dependency-version: 5.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: "@fontsource/ibm-plex-mono" dependency-version: 5.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: "@hookform/resolvers" dependency-version: 5.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@oddbird/css-anchor-positioning" dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: next dependency-version: 15.5.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: react dependency-version: 19.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react" dependency-version: 19.2.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: react-dom dependency-version: 19.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react-dom" dependency-version: 19.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: react-hook-form dependency-version: 7.64.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@playwright/test" dependency-version: 1.56.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react" dependency-version: 19.2.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react-dom" dependency-version: 19.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: sass dependency-version: 1.93.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: typescript dependency-version: 5.9.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor ... Signed-off-by: dependabot[bot] <support@github.com>
✓ Safe to upgradeI recommend merging this upgrade because the codebase does not use any of the deprecated APIs or breaking change patterns identified in the release notes. The application uses modern React patterns (no ReactDOM.render or deprecated lifecycle methods), standard CSS instead of Sass (avoiding @import and type() function issues), and does not access Next.js params/searchParams properties that would be affected by async API changes. The security vulnerability CVE-2025-29927 affects Next.js middleware using x-middleware-subrequest headers, which this application does not use—the middleware only implements security headers via @nosecone/next. The application meets all Node.js version requirements (requires Node 20, all upgraded packages support Node 18+). While 44 new features and 50 bug fixes are included, no code changes are required to adopt this upgrade. What we checked
Dependency UsageThis Next.js application serves as a demo/example site with form validation and modern UI features, powered by a focused set of dependencies. The core functionality centers on three demonstration forms (EmailForm, RLForm, SuppportForm) that use React Hook Form with Zod schema validation integrated via @hookform/resolvers to provide robust client-side form validation and error handling. The visual foundation relies on @fontsource packages (Figtree Variable and IBM Plex Mono) for typography, Sass for stylesheet compilation, and @oddbird/css-anchor-positioning to polyfill modern CSS anchor positioning for the hamburger navigation popover on mobile devices. Next.js handles the application framework including routing, metadata, and server/client components, while React and React DOM provide the underlying component model and rendering, with Playwright configured for end-to-end testing of the application.
View 42 more usages
Other Usages (44)These usages were analyzed but no breaking changes were detected: @hookform/resolvers
next
react
react-hook-form
@playwright/test
ChangesCritical Breaking Changes Require Immediate ActionReact ecosystem now requires Node.js 18+ and switched to flat ESLint config as default (legacy moved to Key Stability ImprovementsReact fixed multiple critical bugs including infinite Notable New CapabilitiesReact introduced the
View 200 more changes
References (6)[1]: Project requires Node.js >=20, which exceeds the Node.js 18+ requirement introduced by React 19.2.0 and other upgraded packages example-nextjs-1e0f2/package.json Line 18 in 18f8de8
[2]: Middleware uses @nosecone/next for security headers only, does not handle x-middleware-subrequest headers mentioned in CVE-2025-29927 example-nextjs-1e0f2/middleware.ts Line 1 in 18f8de8
[3]: React Hook Form usage follows current patterns with resolver and formState, not affected by the removed field ids reference or shouldUnregister changes
[4]: Application uses plain CSS, not Sass/SCSS files, avoiding breaking changes related to @import deprecation, type() function, and mixed-decls
[5]: Playwright configuration uses standard device presets, not affected by Chromium manifest v2 deprecation or viewport/text selector breaking changes example-nextjs-1e0f2/playwright.config.ts Line 28 in 18f8de8
[6]: Next.js 15 breaking changes documented but not applicable: no async params/searchParams usage found in codebase, no dynamic API calls in page components (source link) fossabot analyzed this PR using static analysis and dependency research. |
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
✅ Deploy Preview for gilded-rugelach-722bc0 ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Bumps the dependencies-minor group with 13 updates in the / directory:
5.2.8
5.2.10
5.2.6
5.2.7
5.1.1
5.2.2
0.6.1
0.7.0
15.5.2
15.5.4
19.1.0
19.2.0
19.1.8
19.2.2
19.1.0
19.2.0
19.1.6
19.2.1
7.60.0
7.64.0
1.54.1
1.56.0
1.89.2
1.93.2
5.8.3
5.9.3
Updates
@fontsource-variable/figtree
from 5.2.8 to 5.2.10Commits
Updates
@fontsource/ibm-plex-mono
from 5.2.6 to 5.2.7Commits
Updates
@hookform/resolvers
from 5.1.1 to 5.2.2Release notes
Sourced from
@hookform/resolvers
's releases.Commits
e95721d
fix(zod): fix output type for Zod 4 resolver (#803)49a0d7b
fix: discriminated union for zod v4 mini (#784)bc09647
fix(zod): fix output type for Zod 4 resolver (#801)2d28e6a
fix: zod v4 peer deps (#798)f040039
feat(ajv): add ajv-formats for ajvResolver (#797)Updates
@oddbird/css-anchor-positioning
from 0.6.1 to 0.7.0Release notes
Sourced from
@oddbird/css-anchor-positioning
's releases.Commits
40f3a89
v0.7.0db16313
Work with anchor and target inside same shadow root (#353)b18b8ed
Merge pull request #352 from oddbird/dependabot/npm_and_yarn/dev-9d451710aaea505c5
Merge pull request #351 from oddbird/dependabot/npm_and_yarn/prod-8404f4c51fd4bbb67
chore(deps-dev): Bump the dev group with 13 updatesae3512f
chore(deps): Bump the prod group with 2 updates2f9b4c5
Merge pull request #348 from oddbird/dependabot/npm_and_yarn/npm_and_yarn-f5c...98ccee3
chore(deps-dev): Bump vite in the npm_and_yarn group across 1 directory15ebcc0
Merge pull request #346 from oddbird/dependabot/github_actions/actions/setup-...2cc99a6
Merge pull request #347 from oddbird/dependabot/github_actions/actions/setup-...Updates
next
from 15.5.2 to 15.5.4Release notes
Sourced from next's releases.
Commits
40f1d78
v15.5.4cb30f0a
[backport] docs: september improvements and fixes (#83997)b6a32bb
[backport] [CNA] use linter preference (#83194) (#84087)26d61f1
[backport] Turbopack: flush Node.js worker IPC on error (#84079)e11e87a
[backport] fix: error overlay not closing when backdrop clicked (#83981) (#83...0a29888
[backport] fix: devtools initial position should be from next config (#83571)...7a53950
[backport] Turbopack: don't treat metadata routes as RSC (#83804)050bdf1
[backport] Turbopack: throw large static metadata error earlier (#83816)1f6ea09
[backport] Turbopack: Improve handling of symlink resolution errors (#83805)c7d1855
[backport] CI: use KV for test timing data (#83860)Updates
react
from 19.1.0 to 19.2.0Release notes
Sourced from react's releases.
... (truncated)
Changelog
Sourced from react's changelog.
... (truncated)
Commits
5667a41
Bump next prerelease version numbers (#34639)8bb7241
Bump useEffectEvent to Canary (#34610)e3c9656
Ensure Performance Track are Clamped and Don't overlap (#34509)68f00c9
Release Activity in Canary (#34374)0e10ee9
[Reconciler] Set ProfileMode for Host Root Fiber by default in dev (#34432)3bf8ab4
Add missing Activity export to development mode (#34439)1549bda
[Flight] Only assign_store
in dev mode when creating lazy types (#34354)bb6f0c8
[Flight] Fix wrong missing key warning when static child is blocked (#34350)05addfc
Update Flow to 0.266 (#34271)ec5dd0a
Update Flow to 0.257 (#34253)Updates
@types/react
from 19.1.8 to 19.2.2Commits
Updates
react-dom
from 19.1.0 to 19.2.0Release notes
Sourced from react-dom's releases.
... (truncated)
Changelog
Sourced from react-dom's changelog.
... (truncated)
Commits
8618113
Bump scheduler version (#34671)1bd1f01
Ship partial-prerendering APIs to Canary (#34633)2f0649a
[Fizz] Removenonce
option from resume-and-prerender APIs (#34664)5667a41
Bump next prerelease version numbers (#34639)e08f53b
Matchreact-dom/static
test entrypoints and published entrypoints (#34599)8bb7241
Bump useEffectEvent to Canary (#34610)83c88ad
Handle fabric root level fragment with compareDocumentPosition (#34533)68f00c9
Release Activity in Canary (#34374)3168e08
[flags] enable opt-in for enableDefaultTransitionIndicator (#34373)3434ff4
Add scrollIntoView to fragment instances (#32814)Updates
@types/react-dom
from 19.1.6 to 19.2.1Commits
Updates
react-hook-form
from 7.60.0 to 7.64.0Release notes
Sourced from react-hook-form's releases.
... (truncated)
Commits
87d8b77
7.64.06c3b8f7
🥃 chore: upgrade dev deps (#13076)23c699a
✂ chore: remove unused field ids ref in useFieldArray (#13066)37f51ac
🐞 fix: preserve Controller's defaultValue with shouldUnregister prop (#13063)8d61561
🚏 Support optional array fields in PathValueImpl type (#13057)b5b7329
7.63.086a7fb3
🐞 fix: only excuse trigger function when deps has a valid array (#13056)4bfd420
🏔️ chore: major dev deps upgrade (#13053)66b7daf
🔩 chore: lib dev deps upgrade (#13051)62b26d8
🐿️ chore: remove duplicated function isMessage (#13050)Updates
@playwright/test
from 1.54.1 to 1.56.0Release notes
Sourced from
@playwright/test
's releases.... (truncated)
Commits
b6af258
cherry-pick(#37727): devops: fix NPM release step (#37728)d2ef7bb
chore: mark v1.56.0 (#37722)1621d0b
cherry-pick(#37715): chore: disable RenderDocument feature (#37718)ffbf82b
cherry-pick(#37687): docs: v1.56 release notes (#37687) (#37720)2c5e33d
cherry-pick(#37703): docs: pageErrors should return strings in Java and C#0a91ecf
cherry-pick(#37694): chore: move best practices into the journala5c4437
cherry-pick(#37693): docs: use VS Code images for test agents6d13fbe
cherry-pick(#37690): Revert "fix(trace): survive sw restart"d2c267c
cherry-pick(#37689): Revert "fix(trace): should survive ping as the first com...d1fdd81
fix(snapshot): draw a minimum size browser window for small snapshots (#37640)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for
@playwright/test
since your current version.Updates
@types/react
from 19.1.8 to 19.2.2Commits
Updates
@types/react-dom
from 19.1.6 to 19.2.1Commits
Updates
sass
from 1.89.2 to 1.93.2Release notes
Sourced from sass's releases.