Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 12 updates - #40

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/production-dependencies-559fbabedf
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/production-dependencies-559fbabedf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 12 updates in the / directory:

Package From To
@fastify/cookie 11.0.2 11.1.2
@fastify/cors 11.2.0 11.3.0
@fastify/jwt 10.0.0 10.2.2
@fastify/swagger 9.7.0 9.9.1
@fastify/swagger-ui 5.2.5 5.2.6
@prisma/adapter-pg 7.5.0 7.10.0
@prisma/client 7.5.0 7.10.0
@scalar/fastify-api-reference 1.62.0 1.72.4
dayjs 1.11.17 1.11.23
dotenv 17.2.1 17.4.2
tsup 8.5.0 8.5.1
zod 4.3.6 4.6.5

Updates @fastify/cookie from 11.0.2 to 11.1.2

Release notes

Sourced from @​fastify/cookie's releases.

v11.1.2

What's Changed

Full Changelog: fastify/fastify-cookie@v11.1.1...v11.1.2

v11.1.1

What's Changed

New Contributors

Full Changelog: fastify/fastify-cookie@v11.1.0...v11.1.1

v11.1.0

What's Changed

... (truncated)

Commits

Updates @fastify/cors from 11.2.0 to 11.3.0

Release notes

Sourced from @​fastify/cors's releases.

v11.3.0

What's Changed

New Contributors

Full Changelog: fastify/fastify-cors@v11.2.0...v11.3.0

Commits
  • 2c60caa Bumped v11.3.0
  • cf4986e chore: bump @​types/node in the dev-dependencies-typescript group (#411)
  • 816d054 test: remove remaining tap-style assertions from vary tests (#410)
  • 20507ea chore(package.json): fix delvedor's personal url (#409)
  • 6fe85c4 docs(readme): update request origin link (#408)
  • 57bdc65 chore: bump fastify-plugin from 5.1.0 to 6.0.0 in the dependencies group (#407)
  • a8ae57d chore: update depedabot setting
  • 4d34798 chore(.gitattributes): retain binary file eol style (#402)
  • 675ebef refactor(types): migrate from tsd to tstyche (#403)
  • ef25e0b ci: add lock-threads workflow (#401)
  • Additional commits viewable in compare view

Updates @fastify/jwt from 10.0.0 to 10.2.2

Release notes

Sourced from @​fastify/jwt's releases.

v10.2.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fastify-jwt@v10.2.1...v10.2.2

v10.2.1

What's Changed

New Contributors

Full Changelog: fastify/fastify-jwt@v10.2.0...v10.2.1

v10.2.0

What's Changed

New Contributors

Full Changelog: fastify/fastify-jwt@v10.1.0...v10.2.0

v10.1.0

What's Changed

... (truncated)

Commits
  • 0fa8941 Bumped v10.2.2
  • 2bb1a9a Merge commit from fork
  • 36c7b70 chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#429)
  • faf9718 chore: bump fastify/workflows/.github/workflows/plugins-ci.yml
  • 165bbd1 chore(.npmrc): add min-release-age (#426)
  • 6b6caa9 test: update expected error message for clockTimestamp (fast-jwt) (#427)
  • 0cae912 Bumped v10.2.1
  • 66291d8 fix(types): type fastify.jwt as namespace map when namespaces are declared (#...
  • 3279a8c fix: propagate errors from async trusted callback (#405)
  • 986b390 chore: bump c8 from 11.0.0 to 12.0.0 (#425)
  • Additional commits viewable in compare view

Updates @fastify/swagger from 9.7.0 to 9.9.1

Release notes

Sourced from @​fastify/swagger's releases.

v9.9.1

What's Changed

New Contributors

Full Changelog: fastify/fastify-swagger@v9.9.0...v9.9.1

v9.9.0

What's Changed

Full Changelog: fastify/fastify-swagger@v9.8.2...v9.9.0

v9.8.2

What's Changed

Full Changelog: fastify/fastify-swagger@v9.8.1...v9.8.2

v9.8.1

What's Changed

Full Changelog: fastify/fastify-swagger@v9.8.0...v9.8.1

v9.8.0

What's Changed

... (truncated)

Commits
  • f3ecd63 Bumped v9.9.1
  • 697b192 fix(openapi): support untyped oneOf query properties (#945)
  • 50b6f3f fix: convert nullable and keep examples for OpenAPI 3.1+ (#955)
  • 5285637 fix: support $ref to definitions of shared schemas (#952)
  • d31c75e Bumped v9.9.0
  • 74d98db feat: OpenAPI 3.2.0 compatibility (#949)
  • 56b8971 Bumped v9.8.2
  • c1218bc fix(openapi): support null types and type arrays in OpenAPI 3.0 documents
  • 05ce298 docs: document OpenAPI specification extensions in TypeScript (#948)
  • d3206d1 docs: document static paths in dynamic mode
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by tony133, a new releaser for @​fastify/swagger since your current version.


Updates @fastify/swagger-ui from 5.2.5 to 5.2.6

Release notes

Sourced from @​fastify/swagger-ui's releases.

v5.2.6

What's Changed

Full Changelog: fastify/fastify-swagger-ui@v5.2.5...v5.2.6

Commits
  • 56ee372 Bumped v5.2.6
  • b1eff32 fix: correct corrupted PNG favicon signatures (#269)
  • 5b951e6 ci: add lock-threads workflow (#265)
  • 04a6271 chore(deps-dev): bump swagger-ui-dist from 5.32.0 to 5.32.1 (#264)
  • ddf5895 chore(deps): bump fastify/workflows/.github/workflows/plugins-ci-package-mana...
  • c546425 chore(deps): bump fastify/workflows/.github/workflows/plugins-ci.yml (#261)
  • cd4cee7 chore(deps-dev): bump neostandard from 0.12.2 to 0.13.0 (#260)
  • 043d556 chore(deps-dev): bump c8 from 10.1.3 to 11.0.0 (#259)
  • 4ff5aa5 chore(deps-dev): bump swagger-ui-dist from 5.31.0 to 5.32.0 (#258)
  • efde3f0 chore(license): standardise license notice (#256)
  • Additional commits viewable in compare view

Updates @prisma/adapter-pg from 7.5.0 to 7.10.0

Release notes

Sourced from @​prisma/adapter-pg's releases.

7.10.0

Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

Highlights

Run Prisma 7 alongside Prisma 8

This release introduces @prisma/prisma7, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0

Use prisma for the directly installed Prisma 8 CLI and prisma7 for Prisma 7:

npx prisma --version
npx prisma7 --version
npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's prisma.config.* files:

// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'
export default defineConfig({
schema: 'prisma/schema.prisma',
migrations: {
path: 'prisma/migrations',
},
})

Without an explicit --config option, Prisma 7 searches for:

  1. Root-level prisma7.config.* files.
  2. .config/prisma7.* files.
  3. Existing prisma.config.* files as a backwards-compatible fallback.

The supported extensions are .js, .ts, .mjs, .cjs, .mts, and .cts. An explicit config path always takes precedence:

... (truncated)

Commits
  • 3fa65ac fix(p2002): correct modelName in nested create unique constraint errors #2959...
  • a180209 fix(adapter-pg): map PostgreSQL deadlocks to P2034 (#29717)
  • 800f1d1 fix(adapter-pg): preserve constraint name for unique violations (23505) (#29587)
  • 7ef2104 fix(postgres): handle SQLSTATE 23001 for RESTRICT violations (#29554)
  • 35003fd chore(adapter-pg): remove duplicate values parameter (#29650)
  • d6d9fc9 chore: remove parameterization from sqlcommenter-query-insights (#29518)
  • f2ca67e feat: pg statement name generator (#29395)
  • 4131568 fix: set @​types/pg to ^8.16.0 (#29390)
  • 33667c3 fix(adapter-pg): handle both quoted/unquoted column names in ColumnNotFound e...
  • e97b3e0 feat(adapter-pg): accept connection string URL in PrismaPg constructor (#29287)
  • See full diff in compare view

Updates @prisma/client from 7.5.0 to 7.10.0

Release notes

Sourced from @​prisma/client's releases.

7.10.0

Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

Highlights

Run Prisma 7 alongside Prisma 8

This release introduces @prisma/prisma7, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0

Use prisma for the directly installed Prisma 8 CLI and prisma7 for Prisma 7:

npx prisma --version
npx prisma7 --version
npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's prisma.config.* files:

// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'
export default defineConfig({
schema: 'prisma/schema.prisma',
migrations: {
path: 'prisma/migrations',
},
})

Without an explicit --config option, Prisma 7 searches for:

  1. Root-level prisma7.config.* files.
  2. .config/prisma7.* files.
  3. Existing prisma.config.* files as a backwards-compatible fallback.

The supported extensions are .js, .ts, .mjs, .cjs, .mts, and .cts. An explicit config path always takes precedence:

... (truncated)

Commits
  • 05c1b88 Teach Prisma 7 to prefer versioned config files (#30020)
  • cf2bc1f Rename prisma7 package to @​prisma/prisma7 (#30002)
  • ce5a34c Complete downstream actionable Prisma 7 guidance propagation (#29994)
  • 3f13ec6 Complete CLI-owned prisma7 distribution identity (#29969)
  • 179ba0c feat(prisma7): add side-by-side CLI wrapper (#29949)
  • 3fa65ac fix(p2002): correct modelName in nested create unique constraint errors #2959...
  • 6b6d9e9 chore(deps): update engines to 7.10.0-4.0edf323efd1d98336f3f0a68684b56f689b90...
  • b64e33c chore(deps): update engines to 7.10.0-3.9d90ce2c89d5c95a1148aef15e5561ab6c490...
  • 2046f9b feat(client): expose ModelName to compute function in Result extensions (#29782)
  • f2b3abd chore(deps): update engines to 7.10.0-1.6d040c802892de6d56c7e0061b7a10b3e6a0c...
  • Additional commits viewable in compare view

Updates @scalar/fastify-api-reference from 1.62.0 to 1.72.4

Changelog

Sourced from @​scalar/fastify-api-reference's changelog.

1.72.4

1.72.3

1.72.2

1.72.1

1.72.0

1.71.0

1.70.0

1.69.2

1.69.1

1.69.0

1.68.0

1.67.0

Patch Changes

  • #10020: Fix the OpenAPI document endpoints for url sources. When the specification was provided via configuration.url, the plugin still registered ${routePrefix}/openapi.json and ${routePrefix}/openapi.yaml, but they returned a broken response (a 500 for JSON, an empty body for YAML) because the URL string was normalized as if it were the document itself. The reference already loads the URL directly in the browser, so these endpoints are no longer registered for url sources — matching the existing behavior for sources.
  • #10018: Declare support for Fastify v4, v5, and v6 via the plugin's fastify version range, so Fastify validates compatibility at registration and fails fast on an unsupported host. The test suite now runs against Fastify v5, and the plugin was verified against the Fastify v6 pre-release (it behaves identically). The runtime stays compatible with Fastify v4. Also lowers the minimum Node.js version to 20 to match Fastify v5.

1.66.1

Patch Changes

  • #9941: Republish every package through npm trusted publishing. No functional changes.

1.66.0

1.65.1

1.65.0

1.64.1

Patch Changes

  • #9835: Fix the published type declarations so they resolve under moduleResolution: node16/nodenext again. Since 1.62.1 the .d.ts files re-exported relative modules without a file extension (export { default } from './fastifyApiReference'), which ESM resolution rejects with TS2834 — so the plugin's types silently degraded to any for those consumers. The declarations are now emitted as a single self-contained index.d.ts (matching the Next.js integration), which resolves under every module resolution setting.

1.64.0

1.63.0

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​scalar/fastify-api-reference since your current version.


Updates dayjs from 1.11.17 to 1.11.23

Release notes

Sourced from dayjs's releases.

v1.11.23

1.11.23 (2026-08-17)

Bug Fixes

  • plugin: timezone plugin prevent RangeError for invalid Day.js values (#3180) (dad46e6)
  • plugin: timezone plugin prevent RangeError for invalid Day.js values (#3180) (#3181) (2a3785f)

v1.11.22

1.11.22 (2026-08-16)

Bug Fixes

  • plugin: timezone compute instance .tz() offset without host DST (#3174) (e27ee80), closes #3169

v1.11.21

1.11.21 (2026-05-26)

Bug Fixes

v1.11.20

1.11.20 (2026-03-12)

Bug Fixes

  • Update locale km.js to support meridiem (#3017) (9d2b6a1)
  • update updateLocale plugin to merge nested object properties instead of replacing (#3012) (99691c5), closes #1118

v1.11.19

1.11.19 (2025-10-31)

Bug Fixes

  • added usage warnings for diff + updated unit tests (#2948) (269a7a9)
  • dont instantiate regexes within ar locale functions to avoid performance overhead (#2898) (af5e9f0)
  • replace italian locale "un' ora fa" with "un'ora fa", add tests for it (#2930) (9e9f76c)
  • Updated Belarusian locale with relative time (#2656) (1d8746c)

v1.11.18

1.11.18 (2025-08-30)

Bug Fixes

... (truncated)

Changelog

Sourced from dayjs's changelog.

1.11.23 (2026-08-17)

Bug Fixes

  • plugin: timezone plugin prevent RangeError for invalid Day.js values (#3180) (dad46e6)
  • plugin: timezone plugin prevent RangeError for invalid Day.js values (#3180) (#3181) (2a3785f)

1.11.22 (2026-08-16)

Bug Fixes

  • plugin: timezone compute instance .tz() offset without host DST (#3174) (e27ee80), closes #3169

1.11.21 (2026-05-26)

Bug Fixes

1.11.20 (2026-03-12)

Bug Fixes

  • Update locale km.js to support meridiem (#3017) (9d2b6a1)
  • update updateLocale plugin to merge nested object properties instead of replacing (#3012) (99691c5), closes #1118

1.11.19 (2025-10-31)

Bug Fixes

  • added usage warnings for diff + updated unit tests (#2948) (269a7a9)
  • dont instantiate regexes within ar locale functions to avoid performance overhead (#2898) (af5e9f0)
  • replace italian locale "un' ora fa" with "un'ora fa", add tests for it (#2930) (9e9f76c)
  • Updated Belarusian locale with relative time (#2656) (

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 27, 2026
…y with 12 updates

Bumps the production-dependencies group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@fastify/cookie](https://github.com/fastify/fastify-cookie) | `11.0.2` | `11.1.2` |
| [@fastify/cors](https://github.com/fastify/fastify-cors) | `11.2.0` | `11.3.0` |
| [@fastify/jwt](https://github.com/fastify/fastify-jwt) | `10.0.0` | `10.2.2` |
| [@fastify/swagger](https://github.com/fastify/fastify-swagger) | `9.7.0` | `9.9.1` |
| [@fastify/swagger-ui](https://github.com/fastify/fastify-swagger-ui) | `5.2.5` | `5.2.6` |
| [@prisma/adapter-pg](https://github.com/prisma/prisma/tree/HEAD/packages/adapter-pg) | `7.5.0` | `7.10.0` |
| [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) | `7.5.0` | `7.10.0` |
| [@scalar/fastify-api-reference](https://github.com/scalar/scalar/tree/HEAD/integrations/fastify) | `1.62.0` | `1.72.4` |
| [dayjs](https://github.com/iamkun/dayjs) | `1.11.17` | `1.11.23` |
| [dotenv](https://github.com/motdotla/dotenv) | `17.2.1` | `17.4.2` |
| [tsup](https://github.com/egoist/tsup) | `8.5.0` | `8.5.1` |
| [zod](https://github.com/colinhacks/zod) | `4.3.6` | `4.6.5` |



Updates `@fastify/cookie` from 11.0.2 to 11.1.2
- [Release notes](https://github.com/fastify/fastify-cookie/releases)
- [Commits](fastify/fastify-cookie@v11.0.2...v11.1.2)

Updates `@fastify/cors` from 11.2.0 to 11.3.0
- [Release notes](https://github.com/fastify/fastify-cors/releases)
- [Commits](fastify/fastify-cors@v11.2.0...v11.3.0)

Updates `@fastify/jwt` from 10.0.0 to 10.2.2
- [Release notes](https://github.com/fastify/fastify-jwt/releases)
- [Commits](fastify/fastify-jwt@v10.0.0...v10.2.2)

Updates `@fastify/swagger` from 9.7.0 to 9.9.1
- [Release notes](https://github.com/fastify/fastify-swagger/releases)
- [Commits](fastify/fastify-swagger@v9.7.0...v9.9.1)

Updates `@fastify/swagger-ui` from 5.2.5 to 5.2.6
- [Release notes](https://github.com/fastify/fastify-swagger-ui/releases)
- [Commits](fastify/fastify-swagger-ui@v5.2.5...v5.2.6)

Updates `@prisma/adapter-pg` from 7.5.0 to 7.10.0
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.10.0/packages/adapter-pg)

Updates `@prisma/client` from 7.5.0 to 7.10.0
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.10.0/packages/client)

Updates `@scalar/fastify-api-reference` from 1.62.0 to 1.72.4
- [Release notes](https://github.com/scalar/scalar/releases)
- [Changelog](https://github.com/scalar/scalar/blob/main/integrations/fastify/CHANGELOG.md)
- [Commits](https://github.com/scalar/scalar/commits/HEAD/integrations/fastify)

Updates `dayjs` from 1.11.17 to 1.11.23
- [Release notes](https://github.com/iamkun/dayjs/releases)
- [Changelog](https://github.com/iamkun/dayjs/blob/v1.11.23/CHANGELOG.md)
- [Commits](iamkun/dayjs@v1.11.17...v1.11.23)

Updates `dotenv` from 17.2.1 to 17.4.2
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.2.1...v17.4.2)

Updates `tsup` from 8.5.0 to 8.5.1
- [Release notes](https://github.com/egoist/tsup/releases)
- [Commits](egoist/tsup@v8.5.0...v8.5.1)

Updates `zod` from 4.3.6 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.3.6...v4.6.5)

---
updated-dependencies:
- dependency-name: "@fastify/cookie"
  dependency-version: 11.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@fastify/cors"
  dependency-version: 11.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@fastify/jwt"
  dependency-version: 10.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@fastify/swagger"
  dependency-version: 9.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@fastify/swagger-ui"
  dependency-version: 5.2.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@prisma/adapter-pg"
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@prisma/client"
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@scalar/fastify-api-reference"
  dependency-version: 1.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: dayjs
  dependency-version: 1.11.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: dotenv
  dependency-version: 17.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: tsup
  dependency-version: 8.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-559fbabedf branch from 71e90cd to a29cc31 Compare October 5, 2026 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants