Skip to content

chore: bump the npm-all group with 9 updates - #30

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-all-45696e6381
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-all-45696e6381

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-all group with 9 updates:

Package From To
@fastify/static 10.1.3 10.1.5
@sentry/node 10.72.0 11.0.0
dotenv 17.4.2 18.0.4
fastify 5.12.1 5.12.5
fastify-cli 8.0.0 8.0.2
oxfmt 0.65.0 0.70.0
oxlint 1.80.0 1.85.0
vite 8.2.2 8.3.1
vitest 4.1.11 5.0.2

Updates @fastify/static from 10.1.3 to 10.1.5

Release notes

Sourced from @​fastify/static's releases.

v10.1.5

What's Changed

New Contributors

Full Changelog: fastify/fastify-static@v10.1.4...v10.1.5

v10.1.4

This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).

It fixes a route guard and allowedPath bypass on case-insensitive filesystems. Users should upgrade to @fastify/static 10.1.4.

Full Changelog: fastify/fastify-static@v10.1.3...v10.1.4

Commits
  • 2f0953a Bumped v10.1.5
  • 275d87e fix: use registered root for relative downloads (#610)
  • a39a464 Bumped v10.1.4
  • ac46015 Ignore .pi
  • 6288466 test: consume compressed response bodies
  • 04134a4 test: cover rootless path validation on Windows
  • d9a8c0a test: make case-folding fallback portable
  • dbe65e8 Merge commit from fork
  • 48b821f chore: bump content-disposition in the dependencies group (#607)
  • ee3f89d chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#604)
  • See full diff in compare view

Updates @sentry/node from 10.72.0 to 11.0.0

Release notes

Sourced from @​sentry/node's releases.

11.0.0

Version 11.0.0 marks a major release of the Sentry JavaScript SDKs containing breaking changes. The goal of this release is to be better compatible with OpenTelemetry, make our integrations work across Node.js, Cloudflare, Bun and Deno through run-time and build-time instrumentation, and make span streaming and more permissive data collection the default.

How To Upgrade

Please carefully read through the migration guide in the Sentry docs on how to upgrade from version 10 to version 11. Make sure to select your specific platform/framework in the top left corner: https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found within the Sentry JavaScript SDK Repository: https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

Breaking Changes

All SDKs

  • feat: Remove support for initialising via --require (#22513)
  • feat!: Rename deprecated http.* span attributes (#23574)
  • feat!: Rename deprecated net. span attributes (#23301)
  • feat!: Replace skipOpenTelemetrySetup with enableOpenTelemetrySetup (#23199)
  • feat!: Replace the deprecated http.target span attribute (#23575)
  • feat!: Require Node >=20.19.0 as minimum supported version (#22558)
  • feat!: Use handler span op for terminal request handlers (#22871)
  • feat!: Use middleware span op for web-server middleware (#22852)
  • feat(frameworks)!: Use function op for framework functions (#23047)
  • feat(node/cloudflare)!: Remove deprecated honoIntegration (#22480)
  • feat(v11): Drop TypeScript 3.8 support (#18604)

AI integrations

  • feat(langchain): Emit gen_ai.pipeline.name instead of langchain.chain.name (#23740)
  • ref(anthropic)!: Move Anthropic AI integration to @sentry/server-utils (#22954)
  • ref(google-genai)!: Move Google GenAI integration to @sentry/server-utils (#22959)
  • ref(langchain)!: Move LangChain and LangGraph integrations to @sentry/server-utils (#22962)
  • ref(langgraph)!: Drop gen_ai.create_agent spans (#22840)
  • ref(openai)!: Move OpenAI AI integration to @sentry/server-utils (#22953)
  • ref(vercel-ai)!: Move Vercel AI integration to @sentry/server-utils (#22964)
  • ref(workers-ai)!: Move Workers AI integration to @sentry/server-utils (#22960)

@​sentry/angular

  • feat(angular,ember,sveltekit)!: Use router span op for frontend routers (#23086)
  • feat(angular)!: Use ui.mount and function span ops for tracing decorators (#22667)

@​sentry/astro

  • feat(astro)!: Drop support for Astro 3 (#22683)
  • feat(astro)!: Enable orchestrion instrumentation on Cloudflare Workers (#23003)
  • feat(astro)!: Remove deprecated sourceMapsUploadOptions build option (#23630)
  • feat(astro)!: Remove unstable_sentryVitePluginOptions (#23370)
  • ref(astro)!: Migrate import hook to makeOrchestrionLoader (#22861)
  • ref(astro)!: Remove deprecated release/debug conflict workaround from BuildTimeOptionsBase (#23270)

... (truncated)

Changelog

Sourced from @​sentry/node's changelog.

11.0.0

Version 11.0.0 marks a major release of the Sentry JavaScript SDKs containing breaking changes. The goal of this release is to be better compatible with OpenTelemetry, make our integrations work across Node.js, Cloudflare, Bun and Deno through run-time and build-time instrumentation, and make span streaming and more permissive data collection the default.

How To Upgrade

Please carefully read through the migration guide in the Sentry docs on how to upgrade from version 10 to version 11. Make sure to select your specific platform/framework in the top left corner: https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found within the Sentry JavaScript SDK Repository: https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

Breaking Changes

All SDKs

  • feat: Remove support for initialising via --require (#22513)
  • feat!: Rename deprecated http.* span attributes (#23574)
  • feat!: Rename deprecated net. span attributes (#23301)
  • feat!: Replace skipOpenTelemetrySetup with enableOpenTelemetrySetup (#23199)
  • feat!: Replace the deprecated http.target span attribute (#23575)
  • feat!: Require Node >=20.19.0 as minimum supported version (#22558)
  • feat!: Use handler span op for terminal request handlers (#22871)
  • feat!: Use middleware span op for web-server middleware (#22852)
  • feat(frameworks)!: Use function op for framework functions (#23047)
  • feat(node/cloudflare)!: Remove deprecated honoIntegration (#22480)
  • feat(v11): Drop TypeScript 3.8 support (#18604)

AI integrations

  • feat(langchain): Emit gen_ai.pipeline.name instead of langchain.chain.name (#23740)
  • ref(anthropic)!: Move Anthropic AI integration to @sentry/server-utils (#22954)
  • ref(google-genai)!: Move Google GenAI integration to @sentry/server-utils (#22959)
  • ref(langchain)!: Move LangChain and LangGraph integrations to @sentry/server-utils (#22962)
  • ref(langgraph)!: Drop gen_ai.create_agent spans (#22840)
  • ref(openai)!: Move OpenAI AI integration to @sentry/server-utils (#22953)
  • ref(vercel-ai)!: Move Vercel AI integration to @sentry/server-utils (#22964)
  • ref(workers-ai)!: Move Workers AI integration to @sentry/server-utils (#22960)

@​sentry/angular

  • feat(angular,ember,sveltekit)!: Use router span op for frontend routers (#23086)
  • feat(angular)!: Use ui.mount and function span ops for tracing decorators (#22667)

@​sentry/astro

  • feat(astro)!: Drop support for Astro 3 (#22683)
  • feat(astro)!: Enable orchestrion instrumentation on Cloudflare Workers (#23003)
  • feat(astro)!: Remove deprecated sourceMapsUploadOptions build option (#23630)
  • feat(astro)!: Remove unstable_sentryVitePluginOptions (#23370)
  • ref(astro)!: Migrate import hook to makeOrchestrionLoader (#22861)

... (truncated)

Commits
  • 3e02c87 release: 11.0.0
  • fe07bdf Merge pull request #24620 from getsentry/prepare-release/11.0.0
  • ed38fe7 meta(changelog): Update changelog for 11.0.0
  • ea27349 docs: Fix Solid, SolidStart, and NestJS README snippets (#24571)
  • 84027a1 fix(tanstackstart-react): Reject non-POST requests to the managed tunnel rout...
  • 6a99951 feat(tanstackstart-react): Emit low-cardinality names for function spans (#...
  • 3fdf506 chore: Add external contributor to CHANGELOG.md (#24616)
  • bf7b9b2 fix(cloudflare): Bind pass-through Queue producer methods to the binding (#24...
  • 1960dad fix(server-utils): Stop the orchestrion Vite plugin from adding an empty ssr ...
  • e281d82 chore: Remove CLAUDE.md symlink (#24524)
  • Additional commits viewable in compare view

Updates dotenv from 17.4.2 to 18.0.4

Changelog

Sourced from dotenv's changelog.

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)

18.0.0 (2026-09-17)

Added

  • NEW: Dotenv now has a CLI. (#1022)
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
  • NEW: Dotenv now has a fast parser thanks to @​homanp of superagent.sh. Pass config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)
$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv

faster than Node native parseEnv!

Changed

  • Injecting message sent to stderr rather than stdout and tips removed (#1037)

... (truncated)

Commits

Updates fastify from 5.12.1 to 5.12.5

Release notes

Sourced from fastify's releases.

v5.12.5

⚠️ Security release

What's Changed

Full Changelog: fastify/fastify@v5.12.4...v5.12.5

v5.12.4

Fixed the fastify.js version mismatch.

Full Changelog: fastify/fastify@v5.12.2...v5.12.4

v5.12.2

⚠️ Security release

What's Changed

Full Changelog: fastify/fastify@v5.12.1...v5.12.2

Commits
  • ba235fd Bumped v5.12.5
  • ad06a4c Merge commit from fork
  • 7af0d77 [Backport 5.x] perf: avoid redundant request-part reads during validation (#7...
  • 990ebef [Backport 5.x] perf: reduce content-type parser overhead (#7019)
  • 1690e35 Bumped v5.12.4
  • 1c991c4 Bumped v5.12.3
  • 942a2be Bumped v5.12.2
  • 853f6e2 test(validation): cover normalization and async branches
  • f02d8d4 fix(validation): do not unwrap async validator results
  • 93c239a fix: reject malformed URLs before custom 404 handlers
  • Additional commits viewable in compare view

Updates fastify-cli from 8.0.0 to 8.0.2

Release notes

Sourced from fastify-cli's releases.

v8.0.2

What's Changed

Full Changelog: fastify/fastify-cli@v8.0.1...v8.0.2

v8.0.1

What's Changed

New Contributors

Full Changelog: fastify/fastify-cli@v8.0.0...v8.0.1

Commits
  • 52e6842 Bumped 8.0.2
  • 83bcdd2 fix: restore test execution and CLI compatibility
  • a81a231 fix: restore yargs-parser compatible argument parsing (#913)
  • a710b45 Bumped v8.0.1
  • 6e2f434 ignore AI files
  • 816a40a Merge commit from fork
  • 1c63433 fix: clean dist/ before build:ts in TypeScript template (#883)
  • 44db164 Fix command-specific --help handling (#892)
  • ea960d3 chore: bump chalk from 4.1.2 to 6.0.0 in the dependencies group (#908)
  • e70186b chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#907)
  • Additional commits viewable in compare view

Updates oxfmt from 0.65.0 to 0.70.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.70.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits

Updates oxlint from 1.80.0 to 1.85.0

Release notes

Sourced from oxlint's releases.

oxlint v1.85.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits
  • 288d8cc release(apps): oxlint v1.85.0 && oxfmt v0.70.0 (#26903)
  • f02a64a release(apps): oxlint v1.84.0 && oxfmt v0.69.0 (#26874)
  • 7bf68f7 release(apps): oxlint v1.83.0 && oxfmt v0.68.0 (#26631)
  • b4da00b release(apps): oxlint v1.82.0 && oxfmt v0.67.0 (#26384)
  • aa38ddf fix(linter/unicorn/numeric-separators-style): correct schema defaults (#26393)
  • 6a0e19c feat(linter/eslint/no-unmodified-loop-condition): support `checkConditionalEx...
  • 0b4e2e6 release(apps): oxlint v1.81.0 && oxfmt v0.66.0 (#26199)
  • d5be037 docs(linter/typescript/switch-exhaustiveness-check): clarify default case com...
  • 63bc313 chore(npm): update funding URL (#26066)
  • See full diff in compare view

Updates vite from 8.2.2 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

create-vite@8.3.0

Please refer to CHANGELOG.md for details.

v8.3.0

Features

  • build: avoid settling seen preload dependencies for performance (#23446) (e6f6b3e)

Bug Fixes

  • handle CRLF line endings in code frame positions (#23219) (9913672)
  • only treat whole node_modules path segments as dependencies (fix #17467) (#23437) (ef0dc17)

Performance Improvements

  • proxy: pre-compile context matchers at server creation (#23263) (8abf700)

v8.3.0-beta.1

Features

Bug Fixes

  • build: keep hash placeholders as-is in resolveFileUrl hook (#23422) (e8d6a4d)

... (truncated)

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

8.3.0 (2026-09-10)

Features

  • build: avoid settling seen preload dependencies for performance (#23446) (e6f6b3e)
  • devtools: enable dev server integration (#23333) (68aeb8a)
  • accept Rolldown watch options in server.watch (#23133) (1b5cfe3)
  • add closeServer and closePreviewServer hooks (#23110) (e17d2d5)
  • add top-level tsconfig option (#23310) (93164c3)
  • add warning for unsupported hooks in plugin returned from applyToEnvironment hook (#23191) (fdef04f)
  • cli: support naming the CPU profile via --profile [name] (#23042) (a500dee)
  • config: warn on named imports from JSON modules (#23378) (472385e)
  • css: minify style tag (#23183) (8156684)
  • searched params attached to workers are now preserved (#22280) (517b97f)
  • support subpath imports in dynamic import statements (#23185) (b78e2f1)
  • use import.meta.ROLLDOWN_FILE_URL_* for assets in JS (#22888) (4366ac4)
  • use import.meta.ROLLDOWN_FILE_URL_* for other plugins (#22894) (e38f29e)
  • worker: remove worker chunk if it's detected that it's not referenced (#22473) (924997a)

Bug Fixes

  • handle CRLF line endings in code frame positions (#23219) (9913672)
  • only treat whole node_modules path segments as dependencies (fix #17467) (#23437) (ef0dc17)
  • build: keep hash placeholders as-is in resolveFileUrl hook (#23422) (e8d6a4d)
  • bundled-dev: mark payload delivered on client report (#23373) (a6d43bc)

... (truncated)

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Updates vitest from 4.1.11 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

Bumps the npm-all group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [@fastify/static](https://github.com/fastify/fastify-static) | `10.1.3` | `10.1.5` |
| [@sentry/node](https://github.com/getsentry/sentry-javascript) | `10.72.0` | `11.0.0` |
| [dotenv](https://github.com/motdotla/dotenv) | `17.4.2` | `18.0.4` |
| [fastify](https://github.com/fastify/fastify) | `5.12.1` | `5.12.5` |
| [fastify-cli](https://github.com/fastify/fastify-cli) | `8.0.0` | `8.0.2` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.65.0` | `0.70.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.80.0` | `1.85.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.2` |


Updates `@fastify/static` from 10.1.3 to 10.1.5
- [Release notes](https://github.com/fastify/fastify-static/releases)
- [Commits](fastify/fastify-static@v10.1.3...v10.1.5)

Updates `@sentry/node` from 10.72.0 to 11.0.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.72.0...11.0.0)

Updates `dotenv` from 17.4.2 to 18.0.4
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.4)

Updates `fastify` from 5.12.1 to 5.12.5
- [Release notes](https://github.com/fastify/fastify/releases)
- [Commits](fastify/fastify@v5.12.1...v5.12.5)

Updates `fastify-cli` from 8.0.0 to 8.0.2
- [Release notes](https://github.com/fastify/fastify-cli/releases)
- [Commits](fastify/fastify-cli@v8.0.0...v8.0.2)

Updates `oxfmt` from 0.65.0 to 0.70.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.70.0/npm/oxfmt)

Updates `oxlint` from 1.80.0 to 1.85.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.85.0/npm/oxlint)

Updates `vite` from 8.2.2 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 4.1.11 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: "@fastify/static"
  dependency-version: 10.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-all
- dependency-name: "@sentry/node"
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm-all
- dependency-name: dotenv
  dependency-version: 18.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm-all
- dependency-name: fastify
  dependency-version: 5.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-all
- dependency-name: fastify-cli
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-all
- dependency-name: oxfmt
  dependency-version: 0.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: oxlint
  dependency-version: 1.85.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants