Skip to content

chore(deps): bump posthog-js from 1.396.3 to 1.406.2 in /frontend - #381

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/posthog-js-1.406.2
Open

chore(deps): bump posthog-js from 1.396.3 to 1.406.2 in /frontend#381
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/posthog-js-1.406.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown

Bumps posthog-js from 1.396.3 to 1.406.2.

Release notes

Sourced from posthog-js's releases.

posthog-js@1.406.2

1.406.2

Patch Changes

  • #4206 a3112d9 Thanks @​posthog! - fix(surveys): stop recurring surveys re-showing off a stale internal targeting flag

    Recurring surveys could re-display and record a duplicate response when the eligibility check ran against a cached internal targeting flag before fresh flags had loaded. The display loop now waits for feature flags to actually load before trusting the internal targeting flag, and forces a flag reload after a survey is completed so the flag recomputes promptly. (2026-07-21)

posthog-js@1.406.1

1.406.1

Patch Changes

  • #4127 220fa2c Thanks @​sarmah-rup! - Don't let save_referrer overwrite a $referrer / $referring_domain that was explicitly set via posthog.register(), so registered attribution values survive pageviews in SPA and iframe contexts (2026-07-21)

posthog-js@1.406.0

1.406.0

Minor Changes

  • #4194 d39b903 Thanks @​dustinbyrne! - Move shared browser utility implementations into @posthog/browser-common and consume them directly from posthog-js. (2026-07-21)

Patch Changes

  • #4204 ba977d0 Thanks @​turnipdabeets! - Keep autocapture off when a remote config response omits autocapture_opt_out. The SDK now retains the last known server value for the missing-field case, the same as when the config fetch fails, instead of enabling autocapture. Values persisted by earlier SDK versions are still trusted; a browser holding a stale value corrects itself on the first config response that includes the field. (2026-07-21)
  • Updated dependencies [d39b903]:
    • @​posthog/browser-common@​0.2.0

posthog-js@1.405.3

1.405.3

Patch Changes

  • #4200 91505ba Thanks @​pauldambra! - fix: apply the active full snapshot interval as soon as a recording trigger matches (2026-07-21)

posthog-js@1.405.2

1.405.2

Patch Changes

... (truncated)

Commits
  • 4f49b55 chore: update versions and lockfile [version bump]
  • a3112d9 fix(surveys): stop recurring surveys re-showing off a stale internal targetin...
  • 975bd48 chore: update versions and lockfile [version bump]
  • 220fa2c fix: don't overwrite registered $referrer with document.referrer (#4127)
  • 9df5cc0 docs(browser): use customizations entrypoint in playgrounds (#4212)
  • 32fb42b chore: update versions and lockfile [version bump]
  • ba977d0 fix: ignore missing autocapture_opt_out in remote config instead of enabling ...
  • d39b903 refactor(browser): move shared utilities to browser-common (#4194)
  • 9c76008 chore: update versions and lockfile [version bump]
  • 91505ba fix: reschedule replay snapshots after trigger activation (#4200)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [posthog-js](https://github.com/PostHog/posthog-js) from 1.396.3 to 1.406.2.
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/compare/posthog-js@1.396.3...posthog-js@1.406.2)

---
updated-dependencies:
- dependency-name: posthog-js
  dependency-version: 1.406.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, frontend. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel

vercel Bot commented Jul 22, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
math-path-platform Ready Ready Preview, Comment Jul 22, 2026 9:02am

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants