Skip to content

Bump the production-dependencies group across 1 directory with 17 updates - #37

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-5c74c57a9d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-5c74c57a9d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 17 updates in the / directory:

Package From To
@aws-sdk/client-s3 3.1073.0 3.1138.0
@hono/node-server 2.0.5 2.1.1
better-sqlite3 12.11.1 13.0.3
drizzle-orm 0.45.2 0.45.3
hono 4.12.26 4.13.8
jose 6.2.3 6.2.12
pg-boss 10.4.2 12.34.0
redis 4.7.1 6.2.1
zod 4.4.3 4.6.5
@dagrejs/dagre 3.0.0 3.1.1
autoprefixer 10.5.0 10.6.1
lucide-react 0.468.0 1.47.0
postcss 8.5.19 8.5.28
react 18.3.1 19.3.0
react-dom 18.3.1 19.3.0
tailwindcss 3.4.19 4.3.3
zustand 4.5.7 5.0.15

Updates @aws-sdk/client-s3 from 3.1073.0 to 3.1138.0

Release notes

Sourced from @​aws-sdk/client-s3's releases.

v3.1138.0

3.1138.0(2026-09-22)

Chores
  • codegen: sync for MetricsRecorder support and core error/retry fixes (#8312) (9a104768)
  • middleware-sdk-s3: add feature ID 'S3_REGION_REDIRECT' (#8311) (f8b0f8d3)
New Features
  • clients: update client endpoints as of 2026-09-22 (e854d54a)
  • client-glue: Adding two new fields for Glue Materialized Views feature - (1) SubObjectsStatistics and (2) SparkPipelineInfo. (32b7228c)
  • client-cloudwatchomni: Amazon CloudWatch Omni is now generally available, an AI-powered unified observability for AI agents, applications, and infrastructure. As part of it, organization centralization rules now support cross-account context graph centralization. (f4c9a42a)
  • client-observabilityadmin: Amazon CloudWatch Omni is now generally available, an AI-powered unified observability for AI agents, applications, and infrastructure. Centralization now supports context graph for multi-account resource discovery, and dataset integrations makes logs available in CloudWatch datasets. (a24414c0)
  • client-ec2: Amazon EC2 now supports quote-based start date changes for future-dated Capacity Reservations (f1cb11a8)
  • client-quicksight: Adds support for granular custom permissions on 28 action connectors, including Gmail, Google Drive, Google Sheets, Airtable, and Dropbox. Administrators can now allow or deny individual connector operations instead of all action connectors at once. (7f02673f)
  • client-sso-admin: AWS IAM Identity Center now returns PrimaryRegion and Regions in the DescribeInstance response, providing information about replicated instances, and returns IdentityStoreArn in both the ListInstances and DescribeInstance responses. (83be3d86)
  • client-api-gateway: API Gateway now supports two new security policies for REST APIs and custom domain names, SecurityPolicy-TLS13-1-2-Ext2-PQ-2025-09 (TLS 1.3 1.2 with post-quantum cryptography) and SecurityPolicy-TLS13-1-2-Ext2-FIPS-PQ-2025-09 (adds FIPS). Both retain legacy algorithms for backward compatibility. (924dc413)

For list of updated packages, view updated-packages.md in assets-3.1138.0.zip

v3.1137.0

3.1137.0(2026-09-21)

New Features
  • client-sagemaker: Add support for r6i, m8i, c8i, r8i instance types in Training and Processing (cd872ff2)
  • client-bedrock-agentcore-control: Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints (74c149a8)
  • client-billingconductor: Launching Auto Billing Transfer Billing Group Creation Preference feature (16130cc7)
  • client-docdb: Add support for CopyTagsToSnapshot field in CreateDbCluster, ModifyDbCluster, RestoreDbClusterFromSnapshot and RestoreDbClusterToPointInTime for DocumentDB. (c02fad3a)
  • client-bedrock-agentcore: Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints. (d665aa0c)

For list of updated packages, view updated-packages.md in assets-3.1137.0.zip

v3.1136.0

3.1136.0(2026-09-18)

New Features
  • client-datazone: Adds support for specifying Notebook type (dfe90a44)
  • client-sagemaker: Adds support for the hub content resource in SageMaker Search. (5733f294)
  • client-glue: Introducing AWS Glue Data Quality advanced rule recommendations for faster recommendations. This capability uses Amazon Athena to analyze a sample of table data and Amazon Bedrock to recommend DQDL rules. (984a8422)
  • client-ec2: This release adds documentation for the T8i instance family to the EC2 ModifyDefaultCreditSpecification and GetDefaultCreditSpecification APIs. (27cc9e36)
  • client-appintegrations: This release adds support for A2A servers via the ApplicationType and AuthConfig fields, allowing customers to register their agent-to-agent servers with API key authentication. (6be76cb1)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-s3's changelog.

3.1138.0 (2026-09-22)

Note: Version bump only for package @​aws-sdk/client-s3

3.1137.0 (2026-09-21)

Note: Version bump only for package @​aws-sdk/client-s3

3.1136.0 (2026-09-18)

Note: Version bump only for package @​aws-sdk/client-s3

3.1135.0 (2026-09-17)

Note: Version bump only for package @​aws-sdk/client-s3

3.1134.0 (2026-09-16)

Note: Version bump only for package @​aws-sdk/client-s3

3.1133.0 (2026-09-15)

Note: Version bump only for package @​aws-sdk/client-s3

3.1132.0 (2026-09-14)

... (truncated)

Commits
  • c68e50e Publish v3.1138.0
  • 9a10476 chore(codegen): sync for MetricsRecorder support and core error/retry fixes (...
  • 6b43247 Publish v3.1137.0
  • d6b94db Publish v3.1136.0
  • 2d5f18d Publish v3.1135.0
  • 0d6310b Publish v3.1134.0
  • 615a1ca Publish v3.1133.0
  • 99b4bd0 Publish v3.1132.0
  • 33f2cc7 Publish v3.1131.0
  • 996d664 docs(client-s3): Updated S3 Object Lock Default Retention documentation.
  • Additional commits viewable in compare view

Updates @hono/node-server from 2.0.5 to 2.1.1

Release notes

Sourced from @​hono/node-server's releases.

v2.1.1

What's Changed

Full Changelog: honojs/node-server@v2.1.0...v2.1.1

v2.1.0

What's Changed

New Contributors

Full Changelog: honojs/node-server@v2.0.12...v2.1.0

v2.0.12

What's Changed

Full Changelog: honojs/node-server@v2.0.11...v2.0.12

v2.0.11

What's Changed

Full Changelog: honojs/node-server@v2.0.10...v2.0.11

v2.0.10

Security fixes

This release includes a fix for the following security issue:

Unauthenticated memory-leak DoS via aborted WebSocket handshake

Affects: upgradeWebSocket. A WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header leaked the request's IncomingMessage and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. GHSA-9mqv-5hh9-4cgg


Users of upgradeWebSocket are encouraged to upgrade to this version.

v2.0.9

What's Changed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​hono/node-server since your current version.


Updates better-sqlite3 from 12.11.1 to 13.0.3

Release notes

Sourced from better-sqlite3's releases.

v13.0.3

What's Changed

Full Changelog: WiseLibs/better-sqlite3@v13.0.2...v13.0.3

v13.0.2

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v13.0.1...v13.0.2

v13.0.1

Full Changelog: WiseLibs/better-sqlite3@v13.0.0...v13.0.1

Fixed a regression in parameter binding where it would be overly strict and reject plain objects from other realms (e.g., in jest tests).

v13.0.0

Version 13.0.0 marks a major milestone, as it's the first version of better-sqlite3 to run on the N-API. This means prebuilt binaries should theoretically work across different versions of Node.js and Electron, and perhaps even other runtimes like Bun. As a result, we've removed the deprecated prebuild-install dependency, and now prebuilt binaries are published directly with the better-sqlite3 code itself. If your platform/architecture doesn't have a prebuilt binary, it should compile during install as before.

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v12.12.0...v13.0.0

v12.12.0

What's Changed

[!WARNING]

BREAKING: Starting with Electron v43, binary assets will require glibc 2.41 or higher on Linux hosts.

... (truncated)

Commits

Updates drizzle-orm from 0.45.2 to 0.45.3

Release notes

Sourced from drizzle-orm's releases.

0.45.3

New Netlify DB Driver

Note: The Netlify DB driver is developed and maintained by the Netlify team.

Installation:

npm i @netlify/db

Usage example:

import { drizzle } from 'drizzle-orm/netlify-db';
// reads NETLIFY_DB_URL and NETLIFY_DB_DRIVER env vars
const db = drizzle();
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';
const db = drizzle(process.env.DATABASE_URL);
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';

// Explicit client — consumer controls the driver
const db = drizzle({ client: netlifyDbClient });

const result = await db.execute('select 1');
Commits
  • 15454db +
  • 54e436f exclude gel from pull
  • 0fd1cc6 remove gel
  • d028db7 skip gel
  • 93dc01e [All-kit]: Warn when journal timestamps can cause migrations to be skipped (#...
  • b786252 Merge pull request #6049 from drizzle-team/drizzle-kit-announcements
  • f9fc5bf Add drizzle-kit announcement manifest and schema doc
  • 9d64532 Merge pull request #6004 from drizzle-team/pin-npm-11-main
  • 0af2f2e Pin the release npm self-update to major 11: the npm 12.0.0 tarball is missin...
  • 6968638 Merge pull request #6001 from drizzle-team/release-router-dispatch-inputs
  • Additional commits viewable in compare view

Updates hono from 4.12.26 to 4.13.8

Release notes

Sourced from hono's releases.

v4.13.8

What's Changed

Full Changelog: honojs/hono@v4.13.7...v4.13.8

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

v4.13.5

Security fixes

This release includes fixes for the following security issues:

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a ? after a # was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Affects: toSSG() for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in ssgParams values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

... (truncated)

Commits
  • 098e119 4.13.8
  • e8c8c21 perf(jsx/dom): optimize matching-head child lookup during reconciliation (#5329)
  • 8755b17 docs(combine): fix except() JSDoc param and add missing @​returns (#5346)
  • edd138e fix(request): keep the request media type when reusing a cached body (#5366)
  • 9b4e9c2 fix(accept): clamp a negative q to 0, not 1 (#5357)
  • 65cff90 fix(accept): treat the q parameter name as case-insensitive (#5349)
  • f147de5 fix(accepts, language): skip accept entries with quality 0 when matching (#5311)
  • 90e1b94 fix(aws-lambda): respect backpressure when streaming the response body (#5351)
  • 7792f5d perf(jsx/dom): reduce lookup work for large keyed updates (#5340)
  • e7b38ee docs: fix typos in code comments and link third-party middleware section (#5343)
  • Additional commits viewable in compare view

Updates jose from 6.2.3 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

v6.2.10

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)
  • jwt: prevent replacing protected headers (ae07d09)
  • jwt: reject invalid duration inputs (282f9aa)
  • jwt: validate builder claim values (ea03f83)

... (truncated)

Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

6.2.10 (2026-08-21)

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)

... (truncated)

Commits
  • 505a55b chore(release): 6.2.12
  • 7bc9a33 perf: encode single-signature JWS input once
  • 78637bd perf: normalize General JWE shared headers once
  • bf5138b perf: deduplicate pending jwks key imports
  • b23a6f3 perf: use native encoding for larger ASCII strings
  • fd3ae3f perf: normalize jwks selection metadata once
  • 6925d43 perf: avoid copying AES-GCM output
  • be62530 docs: clarify and shorten public API guidance
  • 1b41312 build: preserve README when generation fails
  • 0b51829 build: check tree-shaking for every public binding
  • Additional commits viewable in compare view

Updates pg-boss from 10.4.2 to 12.34.0

Release notes

Sourced from pg-boss's releases.

12.34.0

Schema version: 42, unchanged from 12.33.0

  • redrive() can be filtered by payload, age and id, and previewRedrive() reports what a redrive would do before it does it.
  • redrive() now works on CockroachDB
  • Some test clock fixes

Filtered redrive, and a preview before it runs

redrive() moves jobs out of a dead letter queue and re-creates them on the queue they came from. Until now the only way to narrow it was by source queue, so draining a dead letter queue was all or nothing per source. It now takes three more filters:

  • data: only jobs whose payload contains this object, matched the same way as findJobs()
  • createdBefore: only jobs that arrived in the dead letter queue before this Date
  • ids: only these jobs, by their id in the dead letter queue

createdBefore is also how to drain a fixed set across several calls. Pass one cutoff to every call and jobs dead-lettered while the loop runs are never swept in:

const cutoff = new Date()
let moved
do {
  moved = await boss.redrive('payments-dlq', { data: { tenant: 'acme' }, createdBefore: cutoff, limit: 500 })
} while (moved > 0)

The new previewRedrive() takes the same options (minus limit) and moves nothing. It returns the total, where the jobs would fan out to, and how many a redrive would leave behind because they have no recorded source queue and no destination was given, or their source queue has since been deleted:

const { total, destinations, unroutable } = await boss.previewRedrive('payments-dlq', {
  data: { tenant: 'acme' }
})
// { total: 12431, destinations: [{ name: 'payment-processing', count: 12113 }, { name: 'payment-refunds', count: 310 }], unroutable: 8 }

The preview and the redrive read one shared predicate, so the preview cannot count a job the redrive would skip. What it cannot see is a collision at redrive time: a destination with a singleton or short policy can still drop a job whose key is already taken, exactly as redrive() always has.

Only jobs still waiting in the dead letter queue are candidates, as before. A job the dead letter queue's own workers have failed stays where it is.

redrive() on CockroachDB

redrive() failed on CockroachDB on every call, because it deletes from and inserts into the job table in one statement, which CockroachDB refuses. On CockroachDB the same move now runs as three statements in one transaction, with the same filters, order and limit, so it moves the same jobs.

Fixes

  • A job in a dead letter queue forgot where it came from the first time that queue's own worker failed it. Failing a job deletes and re-inserts it, and the re-insert did not copy sourceName, sourceId, sourceCreatedOn or sourceRetryCount. After that redrive() could not route the job back and left it in place. The re-insert now carries the four fields on PostgreSQL and CockroachDB alike. Jobs that already lost them are not repaired; redrive those with an explicit destination.
  • When two redriven jobs collide on a destination's singleton or short policy, PostgreSQL now keeps the older one. Before, which one survived depended on the physical order of the rows. CockroachDB ignores that ordering when it resolves the conflict, so there either one may be kept.
  • On CockroachDB, update() and updateQueue() failed on every call, because they used jsonb_exists(), which CockroachDB does not have.
  • On CockroachDB, detectSchemaDrift() reported drift on every fresh install, because CockroachDB stores its own rewriting of index definitions and function bodies. On CockroachDB it now reports missing and invalid indexes and functions without comparing their definitions, as it already did for column types, defaults and constraints.
  • On CockroachDB, findJobs() returned integer fields as strings, and no read converted sourceRetryCount. fetch(), getJobById() and findJobs() now all return numbers.
  • TestClock.setTime() moving forward left in-process deadlines, such as handler expiration, behind the database, and the next tick() replayed every skipped interval period, about 43,000 callbacks for a one-day jump. Timers that the jump makes overdue now fire once on the next tick, and intervals keep their period from the new time. A backward jump leaves pending timers alone. setTime() called during a tick now throws instead of losing the jump. Thanks for the PR by @​bhamiltoncx in timgit/pg-boss#922

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for pg-boss since your current version.


Updates redis from 4.7.1 to 6.2.1

Release notes

Sourced from redis's releases.

redis@6.2.1

What's Changed

New Contributors

Full Changelog: https://github.com/redis/node-redis/compare/redis@6.2.0...redis@6.2.1

redis@6.2.0

6.2.0

✨ Highlights

Cluster commands now follow the server's request/response policies. node-redis reads each command's routing policy from the server's COMMAND metadata and routes and aggregates accordingly, so the cluster client behaves much more like a single server. Multi-key commands that span hash slots — MGET, MSET, DEL, EXISTS, TOUCH, UNLINK — are transparently split per slot and their replies reassembled in caller order, so cross-slot calls that previously failed with CROSSSLOT now just work. Fan-out commands such as KEYS, DBSIZE, FLUSHALL, PING, WAIT, SCRIPT EXISTS and CONFIG SET run across every shard (or every node) and their replies are aggregated per the server's policy, SCAN walks the whole cluster behind a per-client virtual cursor, and RANDOMKEY / FT.CURSOR get correct cluster-aware routing. Replica read-scaling was also aligned with the server flags, so read-only keyless commands (DBSIZE, KEYS, SCAN, RANDOMKEY, and the RediSearch / time-series reads) can be served from replicas again.

⚠️ Behavior change for the raw sendCommand path: a table-recognized command sent raw — e.g. cluster.sendCommand(['DBSIZE']) — now follows its policy (fan-out and aggregate) instead of hitting a single node. Callers who relied on raw commands for per-node operations should target a specific node with cluster.nodeClient(node).sendCommand(...).

This release also brings a broad wave of new command coverage across the client and modules. The time-series package gains the most: new TS.NRANGE/TS.NREVRANGE multi-key pivot commands, a TS.READ cursor reader, TS.QUERYLABELS, EXCLUDEEMPTY on MRANGE/MREVRANGE, and multi-aggregator support. RediSearch adds FT.ALIASLIST, a COLLECT reducer for FT.AGGREGATE, HNSW RERANK, timeout warnings on the FT.SEARCH family, and the full set of stemmer languages. The core client adds SUNIONCARD/SDIFFCARD, LMOVEM/BLMOVEM, ZREVRANK WITHSCORE, COMMAND DOCS, and XREAD MAXCOUNT/MAXSIZE. A large batch of correctness fixes lands for zero-valued optional arguments (LIMIT 0, DB 0, SAMPLES 0, ENTRIESREAD 0, IDLETIME/FREQ 0, ENTRIESADDED 0) that were previously dropped from the wire, alongside several cluster and sentinel connection-lifecycle fixes.

The new HIMPORT command family (managed fieldset lifecycle) ships as experimental — see the warning below.

🚀 New Features

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants