chore(deps): bump the npm_and_yarn group across 2 directories with 6 updates#342
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump the npm_and_yarn group across 2 directories with 6 updates#342dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the npm_and_yarn group with 3 updates in the /apps/docs directory: [next](https://github.com/vercel/next.js), [estree-util-value-to-estree](https://github.com/remcohaszing/estree-util-value-to-estree) and [image-size](https://github.com/image-size/image-size). Bumps the npm_and_yarn group with 4 updates in the /apps/sim directory: [next](https://github.com/vercel/next.js), [esbuild](https://github.com/evanw/esbuild), [drizzle-kit](https://github.com/drizzle-team/drizzle-orm) and [react-email](https://github.com/resend/react-email/tree/HEAD/packages/react-email). Updates `next` from 15.3.1 to 15.3.2 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v15.3.1...v15.3.2) Updates `estree-util-value-to-estree` from 3.3.2 to 3.4.0 - [Release notes](https://github.com/remcohaszing/estree-util-value-to-estree/releases) - [Commits](remcohaszing/estree-util-value-to-estree@v3.3.2...v3.4.0) Updates `image-size` from 2.0.0 to 2.0.2 - [Release notes](https://github.com/image-size/image-size/releases) - [Commits](image-size/image-size@v2.0.0...v2.0.2) Updates `next` from 15.3.1 to 15.3.2 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v15.3.1...v15.3.2) Updates `esbuild` from 0.18.20 to 0.25.4 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2023.md) - [Commits](evanw/esbuild@v0.18.20...v0.25.4) Updates `drizzle-kit` from 0.30.6 to 0.31.1 - [Release notes](https://github.com/drizzle-team/drizzle-orm/releases) - [Commits](https://github.com/drizzle-team/drizzle-orm/compare/drizzle-kit@0.30.6...drizzle-kit@0.31.1) Updates `react-email` from 3.0.7 to 4.0.13 - [Release notes](https://github.com/resend/react-email/releases) - [Changelog](https://github.com/resend/react-email/blob/canary/packages/react-email/CHANGELOG.md) - [Commits](https://github.com/resend/react-email/commits/react-email@4.0.13/packages/react-email) --- updated-dependencies: - dependency-name: next dependency-version: 15.3.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: estree-util-value-to-estree dependency-version: 3.4.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: image-size dependency-version: 2.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: next dependency-version: 15.3.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: esbuild dependency-version: 0.25.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: drizzle-kit dependency-version: 0.31.1 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: react-email dependency-version: 4.0.13 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
Contributor
There was a problem hiding this comment.
PR Summary
This pull request updates multiple dependencies across the docs and sim directories, focusing on bug fixes and security improvements.
- Updated Next.js to 15.3.2 in both apps/docs and apps/sim with critical fixes for turbopack, sourcemaps and middleware
- Upgraded esbuild to 0.25.4 with CORS support and source map fixes in apps/sim
- Updated drizzle-kit to 0.31.1 with improved enum DDL handling and Gel extensions support
- Fixed potential DoS vulnerability in image-size package by updating to 2.0.2
- Upgraded react-email to 4.0.13 with Node.js compatibility fixes and improved hot reloading
💡 (1/5) You can manually trigger the bot by mentioning @greptileai in a comment!
2 file(s) reviewed, no comment(s)
Edit PR Review Bot Settings | Greptile
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 3 updates in the /apps/docs directory: next, estree-util-value-to-estree and image-size.
Bumps the npm_and_yarn group with 4 updates in the /apps/sim directory: next, esbuild, drizzle-kit and react-email.
Updates
nextfrom 15.3.1 to 15.3.2Release notes
Sourced from next's releases.
Commits
d9ec4a4v15.3.23def5ffbackport: fix(turbopack): Store persistence of wrapped task on RawVc::LocalOu...d0b2f8a@next/mdx: Use stable turbopack config options (#78880)04176defix(react-compiler): Fix detection of interest (#78879)b40778bfix(turbopack): Backport sourcemap bugfix (#78881)20f3120[next-server] preserve rsc query for rsc redirects (#78876)b464d18Update middleware public/static matching (#78875)Updates
estree-util-value-to-estreefrom 3.3.2 to 3.4.0Release notes
Sourced from estree-util-value-to-estree's releases.
Commits
a07715c3.4.0252291cUpdate dev dependencies23b636fDeclare there are no side effects in package.json471b4feAdd support for Float16Arrayf56b0faUpdate to@remcohaszing/eslintcb5305c3.3.31854f86Add remark job as a dependency of release559fce2Run tests against Node.js 22652e019Use singular Object.defineProperty if possibled0c394fFix proto property emitUpdates
image-sizefrom 2.0.0 to 2.0.2Release notes
Sourced from image-size's releases.
Commits
032c3342.0.28994131fix potential Denial of Service via specially crafted payloads (#436)e62c61fdelete the part about partial downloadinga5750c52.0.16c3cb71fix the bin script9cfcb4fAdd a sync usage exampleUpdates
nextfrom 15.3.1 to 15.3.2Release notes
Sourced from next's releases.
Commits
d9ec4a4v15.3.23def5ffbackport: fix(turbopack): Store persistence of wrapped task on RawVc::LocalOu...d0b2f8a@next/mdx: Use stable turbopack config options (#78880)04176defix(react-compiler): Fix detection of interest (#78879)b40778bfix(turbopack): Backport sourcemap bugfix (#78881)20f3120[next-server] preserve rsc query for rsc redirects (#78876)b464d18Update middleware public/static matching (#78875)Updates
esbuildfrom 0.18.20 to 0.25.4Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
218d29epublish 0.25.4 to npme66cd0bdev server: simple support for CORS requests (#4171)8bf3368js api: validate some options as arrays of strings1e7375ajs api: simplify comma-separated array validation5f5964drelease notes for #4163adb5284fix: handle__proto__as a computed property in exports and add tests for s...0aa9f7bfix #4169: keep invalid source map URLs unmodified5959289add additional guards for #4114 when using:is()677910bpublish 0.25.3 to npma41040efix #4110: support custom non-IPhostvaluesUpdates
drizzle-kitfrom 0.30.6 to 0.31.1Release notes
Sourced from drizzle-kit's releases.
... (truncated)
Commits
efb40feAdd fix for Gel Schemas (#4483)ad28dcdFixedpgSchemaenum types (fixes #4421) (#4450)2263c3cv0.43.0 (#4397)9e81defUpdate CI/CD to 22.04df6d5f70.41 (#4416)6ab1bbeAdd Arktype validation (viadrizzle-arktypepackage) (#4314)Updates
react-emailfrom 3.0.7 to 4.0.13Release notes
Sourced from react-email's releases.
... (truncated)
Changelog
Sourced from react-email's changelog.
... (truncated)
Commits
9208f58chore(root): Version packages (#2228)8e4afcefix(react-email): Support for users withNodeNext-style imports (#2227)221ebf7chore(root): Version packages (#2216)aa518a3fix(react-email): No explicit error when running with Node <= 17 (#1923)dcb8164chore(root): Version packages (#2208)e42c267chore(react-email): Remove debugging log45ab698fix(react-email): "createServerParamsForMetadata is not a function" (#2206)1a17219fix(react-email): Import compiled templates withcreateRequire's require (#...6e33167chore(root): Version packages (#2203)a41a943fix(react-email): Tests not importing@babel/traversethe same as raw ESM (#2...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.