Repository navigation
chore(deps): bump the npm_and_yarn group across 1 directory with 7 updates - #826
dependabot[bot] wants to merge 1 commit into
Conversation
…dates Bumps the npm_and_yarn group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [hono](https://github.com/honojs/hono) | `4.13.2` | `4.13.7` | | [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` | | [@graphql-tools/executor-legacy-ws](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/executors/legacy-ws) | `1.1.27` | `1.1.37` | | [compression](https://github.com/expressjs/compression) | `1.8.1` | `1.8.2` | | [fast-copy](https://github.com/planttheidea/fast-copy) | `3.0.2` | `3.1.0` | | [proxy-addr](https://github.com/jshttp/proxy-addr) | `2.0.7` | `2.0.8` | | [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` | Updates `hono` from 4.13.2 to 4.13.7 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.13.2...v4.13.7) Updates `axios` from 1.19.0 to 1.20.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.19.0...v1.20.0) Updates `@graphql-tools/executor-legacy-ws` from 1.1.27 to 1.1.37 - [Release notes](https://github.com/ardatan/graphql-tools/releases) - [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/executors/legacy-ws/CHANGELOG.md) - [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/executor-legacy-ws@1.1.37/packages/executors/legacy-ws) Updates `compression` from 1.8.1 to 1.8.2 - [Release notes](https://github.com/expressjs/compression/releases) - [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md) - [Commits](expressjs/compression@v1.8.1...v1.8.2) Updates `fast-copy` from 3.0.2 to 3.1.0 - [Release notes](https://github.com/planttheidea/fast-copy/releases) - [Changelog](https://github.com/planttheidea/fast-copy/blob/v3.1.0/CHANGELOG.md) - [Commits](planttheidea/fast-copy@v3.0.2...v3.1.0) Updates `proxy-addr` from 2.0.7 to 2.0.8 - [Release notes](https://github.com/jshttp/proxy-addr/releases) - [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md) - [Commits](jshttp/proxy-addr@v2.0.7...v2.0.8) Updates `source-map-js` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/7rulnik/source-map-js/releases) - [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md) - [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2) --- updated-dependencies: - dependency-name: hono dependency-version: 4.13.7 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 1.20.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@graphql-tools/executor-legacy-ws" dependency-version: 1.1.37 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: compression dependency-version: 1.8.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fast-copy dependency-version: 3.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: proxy-addr dependency-version: 2.0.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: source-map-js dependency-version: 1.2.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2a57b37. Configure here.
| "license": "Apache-2.0", | ||
| "peerDependencies": { | ||
| "next": "^15.5.15", | ||
| "next": "^16.4.0", |
There was a problem hiding this comment.
Next peer range drops Next 15
High Severity
@highlight-run/next narrowed its next peer and runtime dependency from ^15.5.15 to ^16.4.0. Next 15 apps that install this published SDK will fail peer resolution, and the package no longer advertises the Next 15 support it had before this security bump.
Additional Locations (1)
Triggered by learned rule: observability-next: pin next in devDependencies only, not peers
Reviewed by Cursor Bugbot for commit 2a57b37. Configure here.


Bumps the npm_and_yarn group with 7 updates in the / directory:
4.13.24.13.71.19.01.20.01.1.271.1.371.8.11.8.23.0.23.1.02.0.72.0.81.2.11.2.2Updates
honofrom 4.13.2 to 4.13.7Release notes
Sourced from hono's releases.
... (truncated)
Commits
eebdf7b4.13.72b8ed40Merge commit from forkcac0c4d4.13.6dac5d57refactor(on-handler): use forEach for consistent handler iteration (#5326)ec648d6chore: bumpeditorconfig-checker(#5336)e2740d5fix(types): allow symbol keys in Context<any> get and set fallbacks (#5300)499c35efix(client): normalize root WebSocket URLs (#5291)50b8788fix(client): keep a param value of "index" in $url() and $path() (#5297)06880c44.13.5531e9c5Merge commit from forkUpdates
axiosfrom 1.19.0 to 1.20.0Release notes
Sourced from axios's releases.
Changelog
Sourced from axios's changelog.
Commits
84a9f3bchore(release): prepare release 1.20.0 (#11152)e6824eefix: core methodList, HTTP adapter errors, and add tests (#11096)d8a919ffix(xhr): flush final progress during the live loadend dispatch (#11121)2d2a21afix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)d19040bfix: harden runtime option handling (#11141)e0a02ddchore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...d10cb3achore(deps-dev): bump the development_dependencies group with 4 updates (#11143)2c94646chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)76c12bcchore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)ba98559docs: add ScrapingBee sponsor (#11137)Updates
@graphql-tools/executor-legacy-wsfrom 1.1.27 to 1.1.37Changelog
Sourced from @graphql-tools/executor-legacy-ws's changelog.
... (truncated)
Commits
944121eUpcoming Release Changes (#8483)3a43b4bUpcoming Release Changes (#8460)c2f226efix(executor-legacy-ws): isolate per-request auth and subscription results (#...01167f3chore(release): update monorepo packages versions (#8427)3831a06fix(executor-legacy-ws): enable TLS cert validation by default (GHSA-6fw5-9hq...8b9b7dfchore(release): update monorepo packages versions (#8365)0f00a44chore: use HTTPS git URLs for package repository metadata (#8376)9feabd9chore(release): update monorepo packages versions (#8327)07cd760build(deps): bump the actions-deps group across 1 directory with 7 updates (#...755d699build(deps): bump the actions-deps group with 4 updates (#8353)Updates
compressionfrom 1.8.1 to 1.8.2Release notes
Sourced from compression's releases.
Changelog
Sourced from compression's changelog.
Commits
0f970741.8.2 (#287)151f63efix: destroy compression stream on response close0a76495fix: match Cache-Control no-transform directive case-insensitively (#286)c17b6e5docs: update outdated Brotli note and fix npm install docs URL (#276)112911achore(ci): npm-publish via reusable workflows (#269)1bf5eb0build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#267)d8fe64dbuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#266)b218ff5build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (#265)8a1cf8ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#268)4a19855build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#257)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for compression since your current version.
Updates
fast-copyfrom 3.0.2 to 3.1.0Release notes
Sourced from fast-copy's releases.
Changelog
Sourced from fast-copy's changelog.
Commits
e75b1e3Release 3.1.0359c008[Security] Apply port of #137 to v3 (#138)0078ed5[Maintenance] Upgrade to Yarn 4 (#101)f1cc924update CHANGELOGUpdates
proxy-addrfrom 2.0.7 to 2.0.8Release notes
Sourced from proxy-addr's releases.
Changelog
Sourced from proxy-addr's changelog.
Commits
a11ad822.0.8 (#70)780911dfix: reject IPv4 trust via mapped IPv6 subnets with a short prefix92e103efix(ci): use publised as release trigger event (#71)3e5ac75ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (#69)4b9db81chore(ci): npm-publish via workflows (#54)655e895build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#39)50ce4d0build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#45)0fd347fbuild(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#63)6a517fabuild(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (#64)0d45e2aFix "arugment" typo in README (#61)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for proxy-addr since your current version.
Updates
source-map-jsfrom 1.2.1 to 1.2.2Release notes
Sourced from source-map-js's releases.
Changelog
Sourced from source-map-js's changelog.
Commits
0a1d3341.2.24c6fa26Update changelogcf76580Fix denial of service from malicious indexed source maps (CVE-2026-93749) (#79)7899a86Fix crash when executing browser with CSP script-src that don't permit unsafe...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Overview
Bumps Next.js to
16.4.0across the monorepo: e2e apps (nextjs-ldpatch,nextjsfrom 15.x → 16.x),@highlight-run/nextpeer/dependency (15 → 16), and@launchdarkly/observability-nextdevDependency.yarn.lockis refreshed for Next 16.4.0 platform SWC packages and drops the resolved Next 15.5.x tree where it was replaced.The lockfile also pulls in several transitive patch/minor updates, many with security fixes:
hono,axios,@graphql-tools/executor-legacy-ws,compression,fast-copy,proxy-addr, andsource-map-js, plus minor GraphQL tooling deps (@graphql-tools/utils@12,@whatwg-node/promise-helpers@2).Note:
e2e/nextjsstill pinseslint-config-nextat ^15.5.10 while runtime Next is 16—worth confirming lint/CI still matches the new major.Reviewed by Cursor Bugbot for commit 2a57b37. Bugbot is set up for automated code reviews on this repo. Configure here.