chore(deps): bump the npm-production group across 1 directory with 15 updates - #737
Merged
brendanjryan merged 1 commit intoAug 1, 2026
Merged
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
commit: |
… updates Bumps the npm-production group with 15 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@stripe/stripe-js](https://github.com/stripe/stripe-js) | `9.9.0` | `9.12.0` | | [incur](https://github.com/wevm/incur) | `0.4.10` | `0.4.19` | | [ox](https://github.com/wevm/ox) | `0.14.33` | `1.0.5` | | [@hono/node-server](https://github.com/honojs/node-server) | `2.0.10` | `2.0.11` | | [@typescript/native-preview](https://github.com/microsoft/typescript-go) | `7.0.0-dev.20260323.1` | `7.0.0-dev.20260707.2` | | [hono](https://github.com/honojs/hono) | `4.12.27` | `4.12.32` | | [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.1` | | [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.3` | `8.1.5` | | [ws](https://github.com/websockets/ws) | `8.21.0` | `8.21.1` | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.101.2` | `5.101.4` | | [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.2.8` | | [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.7` | `19.2.8` | | [wagmi](https://github.com/wevm/wagmi/tree/HEAD/packages/react) | `3.6.21` | `3.7.4` | | [accounts](https://github.com/tempoxyz/accounts) | `0.14.11` | `0.15.5` | Updates `@stripe/stripe-js` from 9.9.0 to 9.12.0 - [Release notes](https://github.com/stripe/stripe-js/releases) - [Commits](stripe/stripe-js@v9.9.0...v9.12.0) Updates `incur` from 0.4.10 to 0.4.19 - [Release notes](https://github.com/wevm/incur/releases) - [Changelog](https://github.com/wevm/incur/blob/main/CHANGELOG.md) - [Commits](https://github.com/wevm/incur/compare/incur@0.4.10...incur@0.4.19) Updates `ox` from 0.14.33 to 1.0.5 - [Release notes](https://github.com/wevm/ox/releases) - [Changelog](https://github.com/wevm/ox/blob/main/CHANGELOG.md) - [Commits](https://github.com/wevm/ox/compare/ox@0.14.33...ox@1.0.5) Updates `@hono/node-server` from 2.0.10 to 2.0.11 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v2.0.10...v2.0.11) Updates `@typescript/native-preview` from 7.0.0-dev.20260323.1 to 7.0.0-dev.20260707.2 - [Release notes](https://github.com/microsoft/typescript-go/releases) - [Changelog](https://github.com/microsoft/typescript-go/blob/main/CHANGES.md) - [Commits](https://github.com/microsoft/typescript-go/commits) Updates `hono` from 4.12.27 to 4.12.32 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.27...v4.12.32) Updates `tsx` from 4.22.4 to 4.23.1 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.22.4...v4.23.1) Updates `typescript` from 5.9.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) Updates `vite` from 8.1.3 to 8.1.5 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.5/packages/vite) Updates `ws` from 8.21.0 to 8.21.1 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.21.0...8.21.1) Updates `@tanstack/react-query` from 5.101.2 to 5.101.4 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.4/packages/react-query) Updates `react` from 19.2.7 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react) Updates `react-dom` from 19.2.7 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom) Updates `wagmi` from 3.6.21 to 3.7.4 - [Release notes](https://github.com/wevm/wagmi/releases) - [Changelog](https://github.com/wevm/wagmi/blob/main/packages/react/CHANGELOG.md) - [Commits](https://github.com/wevm/wagmi/commits/wagmi@3.7.4/packages/react) Updates `accounts` from 0.14.11 to 0.15.5 - [Release notes](https://github.com/tempoxyz/accounts/releases) - [Changelog](https://github.com/tempoxyz/accounts/blob/main/CHANGELOG.md) - [Commits](https://github.com/tempoxyz/accounts/compare/accounts@0.14.11...accounts@0.15.5) --- updated-dependencies: - dependency-name: "@stripe/stripe-js" dependency-version: 9.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-production - dependency-name: incur dependency-version: 0.4.19 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: ox dependency-version: 1.0.5 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-production - dependency-name: "@hono/node-server" dependency-version: 2.0.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: "@typescript/native-preview" dependency-version: 7.0.0-dev.20260707.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: hono dependency-version: 4.12.32 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: tsx dependency-version: 4.23.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-production - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-production - dependency-name: vite dependency-version: 8.1.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: ws dependency-version: 8.21.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: "@tanstack/react-query" dependency-version: 5.101.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: react dependency-version: 19.2.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: react-dom dependency-version: 19.2.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-production - dependency-name: wagmi dependency-version: 3.7.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-production - dependency-name: accounts dependency-version: 0.15.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-production ... Signed-off-by: dependabot[bot] <support@github.com>
brendanjryan
force-pushed
the
dependabot/npm_and_yarn/npm-production-10c68d8852
branch
from
August 1, 2026 17:27
bc6e100 to
a4c02af
Compare
brendanjryan
deleted the
dependabot/npm_and_yarn/npm-production-10c68d8852
branch
August 1, 2026 17:39
2 tasks
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
… deps Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Revert package.json to match the workspace overrides and add dependabot ignore rules for all packages pinned via pnpm-workspace.yaml overrides, since dependabot cannot read those overrides and the bumps have no effect. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
…check Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Fix: revert package.json to match the workspace overrides and add a CI check (scripts/check-override-drift.js) that fails when package.json versions conflict with workspace overrides. This prevents future drift without maintaining a brittle manual ignore list -- the check reads pnpm-workspace.yaml at CI time and catches any dependabot PR that bumps an overridden package. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
…check Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Fix: revert package.json to match the workspace overrides and add a CI check (scripts/check-override-drift.ts) that fails when package.json versions conflict with workspace overrides. This prevents future drift without maintaining a brittle manual ignore list -- the check reads pnpm-workspace.yaml at CI time and catches any dependabot PR that bumps an overridden package. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
…check Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Fix: revert package.json to match the workspace overrides and add a CI check (scripts/check-override-drift.ts) that fails when package.json versions conflict with workspace overrides. This prevents future drift without maintaining a brittle manual ignore list -- the check reads pnpm-workspace.yaml at CI time and catches any dependabot PR that bumps an overridden package. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
…check Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Fix: revert package.json to match the workspace overrides and add a CI check (scripts/check-override-drift.ts) that fails when package.json versions conflict with workspace overrides. This prevents future drift without maintaining a brittle manual ignore list -- the check reads pnpm-workspace.yaml at CI time and catches any dependabot PR that bumps an overridden package. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
…check Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Fix: revert package.json to match the workspace overrides and add a CI check (scripts/check-override-drift.ts) that fails when package.json versions conflict with workspace overrides. This prevents future drift without maintaining a brittle manual ignore list -- the check reads pnpm-workspace.yaml at CI time and catches any dependabot PR that bumps an overridden package. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
bensandler-stripe
added a commit
to bensandler-stripe/mppx
that referenced
this pull request
Aug 3, 2026
…check Dependabot PR wevm#737 bumped ox, typescript, and file-type in package.json but the pnpm-workspace.yaml overrides continued pinning the old versions. This caused a silent mismatch where the declared deps differed from what was actually installed: - ox: declared 1.0.5, installed 0.14.33 (pinned for viem@2.55.10 compat) - typescript: declared ~7.0.2, installed ~5.9.3 - file-type: declared 22.0.1, installed 21.3.2 Fix: revert package.json to match the workspace overrides and add a CI check (scripts/check-override-drift.ts) that fails when package.json versions conflict with workspace overrides. This prevents future drift without maintaining a brittle manual ignore list -- the check reads pnpm-workspace.yaml at CI time and catches any dependabot PR that bumps an overridden package. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Committed-By-Agent: claude
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-production group with 15 updates in the / directory:
9.9.09.12.00.4.100.4.190.14.331.0.52.0.102.0.117.0.0-dev.20260323.17.0.0-dev.20260707.24.12.274.12.324.22.44.23.15.9.37.0.28.1.38.1.58.21.08.21.15.101.25.101.419.2.719.2.819.2.719.2.83.6.213.7.40.14.110.15.5Updates
@stripe/stripe-jsfrom 9.9.0 to 9.12.0Release notes
Sourced from @stripe/stripe-js's releases.
Commits
0d7ed54v9.12.0d45ffdeBump js-yaml from 3.14.2 to 3.15.0 (#950)9675093Bump ws from 5.2.3 to 5.2.7 (#951)ec1315eAdd optional line item types to Checkout SDK (#949)31973ebv9.10.052b1156Terms element types (#948)5168bdcUpdate Checkout Form change event types (#946)255eac0Add fields.name types to AE (#947)8007285Add validateElements type to StripeCheckoutLoadActionsSuccess (#945)Updates
incurfrom 0.4.10 to 0.4.19Release notes
Sourced from incur's releases.
... (truncated)
Changelog
Sourced from incur's changelog.
... (truncated)
Commits
bb2e5e0chore: version packages (#204)6c6bc6cfeat(mcp): add server identity (#203)76e26c6chore: version packages (#201)9f11871fix: isolate stateless MCP requests (#202)1cc5c95fix: release MCP response streams (#200)34ede46chore: version packages (#198)63da696Update variadic-positional-args.mdeacc238feat(parser): support variadic positional args via final array key (#199)5b9647afeat(mcp): render cta suggestions in tool result and error text (#197)241c680chore: version packages (#196)Updates
oxfrom 0.14.33 to 1.0.5Release notes
Sourced from ox's releases.
... (truncated)
Changelog
Sourced from ox's changelog.
... (truncated)
Commits
cde4f8achore: version packages (#316)b179677fix(tempo): correct zone chain IDs (#314)4d502d8chore: version packages (#313)d7721a1feat(tempo): addEarnSharesutilities (#312)025873dchore: version packages (#307)7355d1dfeat(tempo): update native multisig (#305)5df5dd3chore: version packages (#304)34b28bechore: bump abitype to 1.3.0 (#303)438d16echore: version packages (#302)1815469fix(abi): preserve leading NUL bytes in strings (#301)Attestation changes
This version has no provenance attestation, while the previous version (0.14.33) was attested. Review the package versions before updating.
Updates
@hono/node-serverfrom 2.0.10 to 2.0.11Release notes
Sourced from @hono/node-server's releases.
Commits
834e54f2.0.11ba72bcdperf(request): fast-path PATCH method (#380)962baa4perf(request): fast-path QUERY methods (#376)62284d6test: use a custom helper for path traversal tests (#377)Updates
@typescript/native-previewfrom 7.0.0-dev.20260323.1 to 7.0.0-dev.20260707.2Commits
Maintainer changes
This version was pushed to npm by microsoft1es, a new releaser for
@typescript/native-previewsince your current version.Updates
honofrom 4.12.27 to 4.12.32Release notes
Sourced from hono's releases.
... (truncated)
Commits
26d8e424.12.32402eb3afix(secure-headers): keep CSP callbacks scoped to their header (#5147)c85aeadfix: useObject.create(null)when parsing query, headers, and params (#5161)a88c89dtest(cloudflare-workers): add coverage for onClose, onError, send, and close ...44f8843fix(sse): emit empty id field to reset Last-Event-ID (#5138)e36f57dfix(aws-lambda): add jwt and lambda authorizer types for API Gateway v2 (#5142)bf8608cci: enable reports for type & bundle size check (#5148)cadff884.12.3164c613atest(validator): fix misspelled identifier in transform type test (#5136)aeba9ecfix(sse): emit retry feild when retry is0(#5135)Updates
tsxfrom 4.22.4 to 4.23.1Release notes
Sourced from tsx's releases.
Commits
79fdddefix(watch): treat script and dependency paths literallye818ad6perf: index transform cache lazilycdcc623perf: map Node TypeScript formats directlyd067938perf: load esbuild lazily in CLI95d0672fix(watch): avoid clearing piped output6fd4607docs: add per-page metadataf4176d8docs: generate sitemap8d4ffc2fix: support tsImport after global preloadf0e89b2docs: document Node's public type-stripping API vs internal loader pathf8992f1perf: use sync module hooks on Node v22.22.3+Updates
typescriptfrom 5.9.3 to 7.0.2Release notes
Sourced from typescript's releases.
Commits
Maintainer changes
This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.
Updates
vitefrom 8.1.3 to 8.1.5Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
5e7fe12release: v8.1.56c08c39fix(optimizer): respect importer module format for dynamic import interop wit...5a72b87fix(client): overlay error message format align rolldown (#22869)f8b38e3fix(module-runner): don't crash stack-trace source mapping when globalThis.Bu...8100320fix(bundled-dev): avoid duplicatedbuildEnd(#22931)c88c236docs(build): fix incorrect@defaultfor build.cssMinify (#22948)b59a73ffix(ssr): scope switch-case declarations to the switch, not the function (#22...fef682dfix(deps): update all non-major dependencies (#22921)3c345e4fix(deps): update rolldown-related dependencies (#22922)369ed60docs(build): fix incorrect@defaultfor build.lib.formats (#22911)Updates
wsfrom 8.21.0 to 8.21.1Release notes
Sourced from ws's releases.
Commits
ae1de54[dist] 8.21.18e9511b[ci] Trust Coveralls Homebrew tapf197ac6[fix] Lower default values ofmaxBufferedChunksandmaxFragments8df8265[ci] Update actions/checkout action to v7a2f4e7c[fix] Count empty fragments toward the limit (#2329)e79f912[pkg] Approve install scripts for bufferutil and utf-8-validate4ea355d[doc] Document 32-bit signed integer coercion for option values2120f4c[example] Remove uuid dependency4c534a6[security] Add latest vulnerability to SECURITY.mdUpdates
@tanstack/react-queryfrom 5.101.2 to 5.101.4Release notes
Sourced from @tanstack/react-query's releases.
... (truncated)
Changelog
Sourced from @tanstack/react-query's changelog.
Commits
86bb8a6ci: Version Packages (#11094)181ea82ci: Version Packages (#11089)6d55b07test({react,preact}-query): use the '.then()' convention consistently (#11085)44f38dftest({react,preact,solid}-query/useInfiniteQuery): inline the shared 'fetchIt...d1558c1test({react,preact}-query/usePrefetchQuery): inline the 'generateQueryFn' fac...99690d1test({react,preact}-query/usePrefetchInfiniteQuery): inline single-use helper...10770f0test({react,preact}-query/usePrefetchInfiniteQuery): inline the shared 'Suspe...dbd5a86test({react,preact}-query/usePrefetchQuery): inline the shared 'Suspended' co...b955f60test({react,preact}-query/useSuspenseQuery): assert the 'loading' fallback is...b9c657etest({react,preact}-query/usePrefetchQuery): assert the 'Loading...' fallback...Updates
reactfrom 19.2.7 to 19.2.8Release notes
Sourced from react's releases.
Commits
1dd4ecb[FlightReply] Performance improvements when decoding (#37087)b0d2fdb[19.2.x] Update required references to GitHub repo (#36753)Updates
react-domfrom 19.2.7 to 19.2.8Release notes
Sourced from react-dom's releases.
Commits
1dd4ecb[FlightReply] Performance improvements when decoding (#37087)b0d2fdb[19.2.x] Update required references to GitHub repo (#36753)Updates
wagmifrom 3.6.21 to 3.7.4Release notes
Sourced from wagmi's releases.