An open index of dependabot pull requests across open source projects.

chore(deps): bump the npm_and_yarn group across 14 directories with 28 updates

Closed
Number: #1
Type: Pull Request
State: Closed
Author: dependabot[bot] dependabot[bot]
Association: None
Comments: 2
Created: May 15, 2025 at 02:49 PM UTC
(4 months ago)
Updated: June 04, 2025 at 04:24 AM UTC
(3 months ago)
Closed: June 04, 2025 at 04:24 AM UTC
(3 months ago)
Time to Close: 20 days
Labels:
dependencies javascript
Description:

Bumps the npm_and_yarn group with 22 updates in the / directory:

Package From To
vitest 1.6.0 1.6.1
astro 3.5.0 4.16.18
webpack 5.95.0 5.96.0
@nestjs/common 10.4.6 10.4.16
@nestjs/core 10.4.6 11.1.1
next 13.2.0 14.2.26
nuxt 3.13.2 3.16.0
node-fetch 2.7.0 3.3.2
solid-js 1.8.17 1.9.4
svelte 3.49.0 4.2.19
@sveltejs/kit 2.0.2 2.20.6
axios 1.7.7 1.8.2
esbuild 0.20.0 0.25.0
mongoose 5.13.22 6.13.6
@xmldom/xmldom 0.8.3 0.8.10
ejs 3.1.8 3.1.10
http-proxy-middleware 2.0.7 2.0.9
prismjs 1.29.0 1.30.0
serialize-javascript 6.0.0 6.0.2
tmpl 1.0.4 1.0.5
tough-cookie 4.0.0 4.1.4
undici 5.28.3 5.29.0

Bumps the npm_and_yarn group with 1 update in the /dev-packages/e2e-tests/test-applications/nextjs-turbo directory: next.
Bumps the npm_and_yarn group with 3 updates in the /packages/astro directory: astro, vite and @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/aws-serverless directory: @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/bun directory: @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/google-cloud-serverless directory: @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/nestjs directory: @sentry/node.
Bumps the npm_and_yarn group with 2 updates in the /packages/nextjs directory: next and @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/nuxt directory: @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/profiling-node directory: @sentry/node.
Bumps the npm_and_yarn group with 3 updates in the /packages/remix directory: vitest, vite and @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/solidstart directory: @sentry/node.
Bumps the npm_and_yarn group with 1 update in the /packages/svelte directory: svelte.
Bumps the npm_and_yarn group with 3 updates in the /packages/sveltekit directory: vite, svelte and @sentry/node.

Updates vitest from 1.6.0 to 1.6.1

Release notes

Sourced from vitest's releases.

v1.6.1

This release includes security patches for:

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates astro from 3.5.0 to 4.16.18

Changelog

Sourced from astro's changelog.

4.16.18

Patch Changes

4.16.17

Patch Changes

  • #12632 e7d14c3 Thanks @​ematipico! - Fixes an issue where the checkOrigin feature wasn't correctly checking the content-type header

4.16.16

Patch Changes

4.16.15

Patch Changes

4.16.14

Patch Changes

4.16.13

Patch Changes

... (truncated)

Commits

Updates vite from 5.4.10 to 5.4.19

Release notes

Sourced from vite's releases.

v6.3.5

Please refer to CHANGELOG.md for details.

v6.3.4

Please refer to CHANGELOG.md for details.

v6.3.3

Please refer to CHANGELOG.md for details.

v6.3.2

Please refer to CHANGELOG.md for details.

create-vite@6.3.1

Please refer to CHANGELOG.md for details.

v6.3.1

Please refer to CHANGELOG.md for details.

create-vite@6.3.0

Please refer to CHANGELOG.md for details.

v6.3.0

Please refer to CHANGELOG.md for details.

v6.3.0-beta.2

Please refer to CHANGELOG.md for details.

v6.3.0-beta.1

Please refer to CHANGELOG.md for details.

v6.3.0-beta.0

Please refer to CHANGELOG.md for details.

v6.2.7

Please refer to CHANGELOG.md for details.

v6.2.6

Please refer to CHANGELOG.md for details.

v6.2.5

Please refer to CHANGELOG.md for details.

v6.2.4

Please refer to CHANGELOG.md for details.

v6.2.3

Please refer to CHANGELOG.md for details.

v6.2.2

Please refer to CHANGELOG.md for details.

... (truncated)

Changelog

Sourced from vite's changelog.

6.3.5 (2025-05-05)

6.3.4 (2025-04-30)

  • fix: check static serve file inside sirv (#19965) (c22c43d), closes #19965
  • fix(optimizer): return plain object when using require to import externals in optimized dependenci (efc5eab), closes #19940
  • refactor: remove duplicate plugin context type (#19935) (d6d01c2), closes #19935

6.3.3 (2025-04-24)

  • fix: ignore malformed uris in tranform middleware (#19853) (e4d5201), closes #19853
  • fix(assets): ensure ?no-inline is not included in the asset url in the production environment (#1949 (16a73c0), closes #19496
  • fix(css): resolve relative imports in sass properly on Windows (#19920) (ffab442), closes #19920
  • fix(deps): update all non-major dependencies (#19899) (a4b500e), closes #19899
  • fix(ssr): fix execution order of re-export (#19841) (ed29dee), closes #19841
  • fix(ssr): fix live binding of default export declaration and hoist exports getter (#19842) (80a91ff), closes #19842
  • perf: skip sourcemap generation for renderChunk hook of import-analysis-build plugin (#19921) (55cfd04), closes #19921
  • test(ssr): test ssrTransform re-export deps and test stacktrace with first line (#19629) (9399cda), closes #19629

6.3.2 (2025-04-18)

6.3.1 (2025-04-17)

6.3.0 (2025-04-16)

... (truncated)

Commits
  • 84e4647 release: v6.3.5
  • fd38d07 fix(ssr): handle uninitialized export access as undefined (#19959)
  • b040d54 release: v6.3.4
  • c22c43d fix: check static serve file inside sirv (#19965)
  • efc5eab fix(optimizer): return plain object when using require to import externals ...
  • d6d01c2 refactor: remove duplicate plugin context type (#19935)
  • db9eb97 release: v6.3.3
  • e4d5201 fix: ignore malformed uris in tranform middleware (#19853)
  • 55cfd04 perf: skip sourcemap generation for renderChunk hook of import-analysis-build...
  • ffab442 fix(css): resolve relative imports in sass properly on Windows (#19920)
  • Additional commits viewable in compare view

Updates webpack from 5.95.0 to 5.96.0

Release notes

Sourced from webpack's releases.

v5.96.0

Bug Fixes

  • Fixed Module Federation should track all referenced chunks
  • Handle Data URI without base64 word
  • HotUpdateChunk have correct runtime when modified with new runtime
  • Order of chunks ids in generated chunk code
  • No extra Javascript chunks when using asset module as an entrypoint
  • Use optimistically logic for output.environment.dynamicImport to determine chunk format when no browserslist or target
  • Collision with global variables for optimization.avoidEntryIife
  • Avoid through variables in inlined module
  • Allow chunk template strings in output.devtoolNamespace
  • No extra runtime for get javascript/css chunk filename
  • No extra runtime for prefetch and preload in JS runtime when it was unsed in CSS
  • Avoid cache invalidation using ProgressPlugin
  • Increase parallelism when using importModule on the execution stage
  • Correctly parsing string in export and import
  • Typescript types
  • [CSS] css/auto considers a module depending on its filename as css (pure CSS) or css/local, before it was css/global and css/local
  • [CSS] Always interpolate classes even if they are not involved in export
  • [CSS] No extra runtime in Javascript runtime chunks for asset modules used in CSS
  • [CSS] No extra runtime in Javascript runtime chunks for external asset modules used in CSS
  • [CSS] No extra runtime for the node target
  • [CSS] Fixed url()s and @import parsing
  • [CSS] Fixed - emit a warning on broken :local and :global

New Features

  • Export CSS and ESM runtime modules
  • Single Runtime Chunk and Federation eager module hoisting
  • [CSS] Support /* webpackIgnore: true */ for CSS files
  • [CSS] Support src() support
  • [CSS] CSS nesting in CSS modules
Commits
  • aff0c3e chore(release): 5.96.0
  • 6f11ec1 refactor: module source types code
  • b07142f refactor: module source types code
  • 7d98b3c fix: Module Federation should track all referenced chunks
  • 6d09769 chore: linting
  • cb3cf61 chore: add test
  • 69dd27e fix: Module Federation should track all referenced chunks
  • 6a6f14f refactor: udate acorn
  • db32353 refactor: code
  • 79b8f00 refactor: update acorn
  • Additional commits viewable in compare view

Updates @nestjs/common from 10.4.6 to 10.4.16

Release notes

Sourced from @​nestjs/common's releases.

v10.4.16

What's Changed

Full Changelog: https://github.com/nestjs/nest/compare/v10.4.15...v10.4.16

v10.4.15 (2024-12-09)

Dependencies

v10.4.13 (2024-12-03)

Bug fixes

  • common
    • #14256 chore(common): Add type declaration for RawBody decorator with pipes (@​sapenlei)

Dependencies

Committers: 3

v10.4.12 (2024-11-29)

Bug fixes

Dependencies

... (truncated)

Commits
  • 6c8aec6 chore(@​nestjs) publish v10.4.16 release
  • 2b9e132 chore: update outdated tests, make file-type optional
  • cb0d650 chore: remove duplicate packages
  • 6196ab2 Merge branch 'Chathula-fix-nestjs-common-mime-validator'
  • 0ac7959 chore: minor tweaks
  • 312a54a Update packages/common/pipes/file/file-type.validator.ts
  • a28fc03 refactor(common): move back file type validator options type
  • 07b4b38 refactor(common): move file-type package to peer dependencies
  • 0b7af8a refactor(common): refactor code to use simple eval
  • 6953b7a fix(common): used eval import
  • Additional commits viewable in compare view

Updates @nestjs/core from 10.4.6 to 11.1.1

Release notes

Sourced from @​nestjs/core's releases.

v11.1.1 (2025-05-14)

Bug fixes

Enhancements

Dependencies

Committers: 7

v11.1.0 (2025-04-23)

Enhancements

Committers: 1

v11.0.21 (2025-04-23)

Enhancements

  • common

... (truncated)

Commits

Updates next from 13.2.0 to 14.2.26

Release notes

Sourced from next's releases.

v14.2.26

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • Match subrequest handling for edge and node (#77476)

v13.5.11

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • Lock swc binaries version

v13.5.10

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • Match subrequest handling for edge and node

v13.5.9

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary. This release contains a security patch for CVE-2025-29927.

Core Changes

  • [backport] middleware subrequest patch (#77418)
Commits

Updates nuxt from 3.13.2 to 3.16.0

Release notes

Sourced from nuxt's releases.

v3.16.0

👀 Highlights

There's a lot in this one!

⚡️ A New New Nuxt

Say hello to create-nuxt, a new tool for starting Nuxt projects (big thanks to @​devgar for donating the package name)!

It's a streamlined version of nuxi init - just a sixth of the size and bundled as a single file with all dependencies inlined, to get you going as fast as possible.

Starting a new project is as simple as:

npm create nuxt

screenshot of create nuxt app

Special thanks to @​cmang for the beautiful ASCII-art. ❤️

Want to learn more about where we're headed with the Nuxt CLI? Check out our roadmap here, including our plans for an interactive modules selector.

🚀 Unhead v2

We've upgraded to unhead v2, the engine behind Nuxt's <head> management. This major version removes deprecations and improves how context works:

  • For Nuxt 3 users, we're shipping a legacy compatibility build so nothing breaks
  • The context implementation is now more direct via Nuxt itself
// Nuxt now re-exports composables while properly resolving the context
export function useHead(input, options = {}) {
  const unhead = injectHead(options.nuxt)
  return head(input, { head: unhead, ...options })
}

If you're using Unhead directly in your app, keep in mind:

  1. Import from Nuxt's auto-imports or #app/composables/head instead of @unhead/vue
  2. Importing directly from @unhead/vue might lose async context

Don't worry though - we've maintained backward compatibility in Nuxt 3, so most users won't need to change anything!

If you've opted into compatibilityVersion: 4, check out our upgrade guide for additional changes.

🔧 Devtools v2 Upgrade

Nuxt Devtools has leveled up to v2 (#30889)!

... (truncated)

Commits
  • 7a37a98 v3.16.0
  • 0d13fe9 chore(deps): update all non-major dependencies (3.x) (#31264)
  • 2476cab fix(nuxt): strip query in x-nitro-prerender header
  • 2c68c92 chore(deps): update all non-major dependencies (3.x) (#31240)
  • bf454cb fix(nuxt): pass useFetch function name on server for warning (#31213)
  • b29c0e8 chore: ignore nitro/renderer templates
  • 7c427df fix(nuxt): fall back to wasm if oxc native bindings are missing (#31190)
  • 0ebaa51 fix(nuxt): apply ignore rules to nitro devStorage (#31233)
  • 2f833f4 fix(nuxt): preserve query/hash when calling navigateTo with replace (#31244)
  • 3cd4384 fix(nuxt): ensure head components are reactive (#31248)
  • Additional commits viewable in compare view

Updates node-fetch from 2.7.0 to 3.3.2

Release notes

Sourced from node-fetch's releases.

v3.3.2

3.3.2 (2023-07-25)

Bug Fixes

v3.3.1

3.3.1 (2023-03-11)

Bug Fixes

  • release "Allow URL class object as an argument for fetch()" #1696 (#1716) (7b86e94)

v3.3.0

3.3.0 (2022-11-10)

Features

v3.2.10

3.2.10 (2022-07-31)

Bug Fixes

v3.2.9

3.2.9 (2022-07-18)

Bug Fixes

  • Headers: don't forward secure headers on protocol change (#1599) (e87b093)

v3.2.8

3.2.8 (2022-07-12)

Bug Fixes

... (truncated)

Commits

Updates solid-js from 1.8.17 to 1.9.4

Release notes

Sourced from solid-js's releases.

v1.9.0 - LGTM!

This release like the last is focusing on small quality of life improvements and adjustments that will help us move towards 2.0. So while not the most exciting release to everyone it provides some really important features and fixes to some developers.

And unlike many previous releases the vast majority of the work and features came from PRs from the community. So really all I can say is Looks Good to Me!

Better JSX Validation

While still incomplete across templates we've added JSDOM to the compiler to better detect invalid HTML at build time by comparing what we expect the template to be with what a browser would output. This now includes things that are nested we didn't detect before like putting <a> inside other <a> tags which will lead to the browser "correcting" it in less than intuitive ways.

Improved Exports

While each environment in solid-js/web has its own methods to be used in the compiler. We are now exporting the client methods from the server to prevent weird import errors. Now these methods will throw if used in this environment but shouldn't break your build.

Additionally we have seen some issues in bundlers that incorrectly feed our ESM exports back through the browser field. While this is a known issue they all pointed issues at each other and with no intention of fixing it. We have removed the browser field in this release, meaning some legacy packages may have issues resolving browser if they don't support export conditions.

This is regretful but this blocked deployments on several platforms and since this was the only fix at our disposal after two years of attempting to push this issue to the bundlers to no avail, we've moved forward with it.

Custom Element improvements

We have a few improvements to our custom element support in this release. First off we now detect elements with the is attribute as custom elements which means all the special behavior is afforded to them.

We've also improved our event handler delegating retargetting to better handle shadow DOM events. There were cases where we skipped over part of the tree.

Finally we've added the bool: attribute namespace to handle explicitly setting certain attributes according to boolean attribute rules. While this isn't necessary for built-in booleans currently we handle most attributes as properties and we lacked a specific override. But now we have it:

<my-element bool:enable={isEnabled()}></my-element>

Support for handleEvent Syntax in Non-Delegated Events

A little known thing is that events actually also support objects instead of functions (See: https://developer.mozilla.org/en-US/docs/Web/API/EventTarget/addEventListener)

We(thanks @​titoBouzout) realized we can use this mechanism as a way to set advanced rules like passive or capture on this object as way to handle all current and future event attributes that browsers might add. This way we don't need specific mechanisms like oncapture: (which is now deprecated).

Instead using on: you can set the event properties you wish.

<>
  <div on:click={{
    handleEvent(e) {
      console.log("clicked", e)
    },
    once:true
  }/>
  <div on:wheel={{
    handleEvent(e) {
      e.preventDefault() // only works on not passive events
      e.stopPropagation()  
</tr>&l...

Description has been truncated

Summary by Sourcery

Update npm and yarn dependencies across multiple packages to apply security patches, bug fixes, and minor enhancements.

Chores:

  • Bump 22 core dependencies in the root to latest minor or patch versions for astro, next, nuxt, webpack, vitest, vite, node-fetch, mongoose, svelte, solid-js, axios, esbuild, and related libraries.
  • Align @sentry/node to v8.49.0 across all integration packages (astro, remix, sveltekit, nextjs, aws-serverless, bun, google-cloud-serverless, nestjs, nuxt, profiling-node, solidstart).
  • Upgrade build tooling: Vite to v6.3.5, Vitest to v3.1.3, and Esbuild to v0.25.0.
  • Standardize Next.js versions to 14.2.26 in main packages and to 15.2.4 in the e2e test application.
  • Upgrade NestJS common to v10.4.16 and core to v11.1.1 and bump mongoose to v6.13.6 in node-integration-tests.
Pull Request Statistics
Commits:
1
Files Changed:
19
Additions:
+5204
Deletions:
-4715
Package Dependencies
Package:
vitest
Ecosystem:
npm
Version Change:
1.6.0 → 1.6.1
Update Type:
Patch
Package:
astro
Ecosystem:
npm
Version Change:
3.5.0 → 4.16.18
Update Type:
Major
Package:
axios
Ecosystem:
npm
Version Change:
1.7.7 → 1.8.2
Update Type:
Minor
Ecosystem:
npm
Version Change:
4.0.0 → 4.1.4
Update Type:
Minor
Package:
next
Ecosystem:
npm
Version Change:
13.2.0 → 14.2.26
Update Type:
Major
Package:
undici
Ecosystem:
npm
Version Change:
5.28.3 → 5.29.0
Update Type:
Minor
Ecosystem:
npm
Version Change:
2.0.7 → 2.0.9
Update Type:
Patch
Package:
webpack
Ecosystem:
npm
Version Change:
5.95.0 → 5.96.0
Update Type:
Minor
Ecosystem:
npm
Version Change:
6.0.0 → 6.0.2
Update Type:
Patch
Package:
esbuild
Ecosystem:
npm
Version Change:
0.20.0 → 0.25.0
Update Type:
Minor
Package:
prismjs
Ecosystem:
npm
Version Change:
1.29.0 → 1.30.0
Update Type:
Minor
Package:
mongoose
Ecosystem:
npm
Version Change:
5.13.22 → 6.13.6
Update Type:
Major
Ecosystem:
npm
Version Change:
10.4.6 → 10.4.16
Update Type:
Patch
Package:
ejs
Ecosystem:
npm
Version Change:
3.1.8 → 3.1.10
Update Type:
Patch
Package:
nuxt
Ecosystem:
npm
Version Change:
3.13.2 → 3.16.0
Update Type:
Minor
Package:
solid-js
Ecosystem:
npm
Version Change:
1.8.17 → 1.9.4
Update Type:
Minor
Ecosystem:
npm
Version Change:
2.0.2 → 2.20.6
Update Type:
Minor
Package:
svelte
Ecosystem:
npm
Version Change:
3.49.0 → 4.2.19
Update Type:
Major
Package:
node-fetch
Ecosystem:
npm
Version Change:
2.7.0 → 3.3.2
Update Type:
Major
Ecosystem:
npm
Version Change:
10.4.6 → 11.1.1
Update Type:
Major
Package:
tmpl
Ecosystem:
npm
Version Change:
1.0.4 → 1.0.5
Update Type:
Patch
Ecosystem:
npm
Version Change:
0.8.3 → 0.8.10
Update Type:
Patch
Technical Details
ID: 308688
UUID: 2522357229
Node ID: PR_kwDONiTHuM6WWB3t
Host: GitHub
Repository: lkeff/sentry-javascript
Merge State: Unknown