Skip to content

build(deps): bump the minor-and-patch group across 1 directory with 27 updates - #15

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-7202bbb1ad
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-7202bbb1ad

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 27 updates in the / directory:

Package From To
@anthropic-ai/sdk 0.117.1 0.128.0
@sentry/nextjs 10.70.0 10.75.3
@supabase/ssr 0.12.4 0.12.7
@supabase/supabase-js 2.112.3 2.117.2
@upstash/redis 1.38.2 1.39.0
dompurify 3.4.13 3.4.16
groq-sdk 1.5.0 1.6.0
next 16.3.1 16.3.6
next-intl 4.13.6 4.14.7
sharp 0.35.3 0.35.4
swagger-ui-react 5.32.13 5.33.0
tailwind-merge 3.6.0 3.7.0
@next/env 16.3.1 16.3.6
@playwright/test 1.62.1 1.63.0
@testing-library/dom 10.4.1 10.4.2
@testing-library/react 16.3.2 16.3.3
@typescript-eslint/eslint-plugin 8.67.0 8.70.1
@typescript-eslint/parser 8.67.0 8.70.1
@vitest/coverage-v8 4.1.10 4.1.11
autoprefixer 10.5.4 10.6.1
eslint-config-next 16.3.1 16.3.6
postcss 8.5.26 8.5.28
ts-jest 29.4.12 29.4.14
vitest 4.1.10 4.1.11
web-tree-sitter 0.26.12 0.27.0
@img/sharp-linux-x64 0.35.3 0.35.4
@swc/core-linux-x64-gnu 1.15.47 1.16.2

Updates @anthropic-ai/sdk from 0.117.1 to 0.128.0

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.128.0

0.128.0 (2026-09-22)

Full Changelog: sdk-v0.127.0...sdk-v0.128.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (eff2748)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (0c1cc0f)
  • tools: addTools() takes effect straight away (#773) (1ccdad0)
  • tools: leave reply-only params off the tool runner's compaction request (#769) (8afc336)

Chores

  • docs: add descriptions to the Dreams API reference (ea4ddd1)
  • docs: add descriptions to the User Profiles API reference (ea4ddd1)
  • docs: add memory store descriptions to the Managed Agents API reference (ea4ddd1)
  • docs: improve descriptions in the Dreams API reference (971c54a)
  • docs: simplify the session thread agent type description (ccf71a2)
  • docs: update diagnostics field descriptions on beta messages (c0b8746)
  • internal: add property-based tests for partial JSON parsing (#776) (3ffac09)

sdk: v0.127.0

0.127.0 (2026-09-18)

Full Changelog: sdk-v0.126.0...sdk-v0.127.0

Features

  • api: add group with display_name to rate limits, deprecate group_type (2575d97)
  • tools: add compactBeforeNextTurn() to the tool runner (#682) (9f75ca6)

Bug Fixes

  • BetaMessageStream: stop coercing a null compaction_delta content into "null" (#655) (dbd6845)
  • client: don't retry requests whose body is a stream or iterator (eebc1b9)
  • client: join multiple anthropic-beta values with a comma and no space (#638) (e0cb1ff)
  • client: make pagination exports on the client namespace type-only (5adea1f)
  • internal: drop jest from tsconfig types (60588af)
  • middleware: echo a streamed compaction summary in the fallback continuation (#657) (2e0f004)
  • tools: keep $defs when transformJSONSchema root is a $ref (#687) (57a9f30)

Performance Improvements

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.128.0 (2026-09-22)

Full Changelog: sdk-v0.127.0...sdk-v0.128.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (eff2748)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (0c1cc0f)
  • tools: addTools() takes effect straight away (#773) (1ccdad0)
  • tools: leave reply-only params off the tool runner's compaction request (#769) (8afc336)

Chores

  • docs: add descriptions to the Dreams API reference (ea4ddd1)
  • docs: add descriptions to the User Profiles API reference (ea4ddd1)
  • docs: add memory store descriptions to the Managed Agents API reference (ea4ddd1)
  • docs: improve descriptions in the Dreams API reference (971c54a)
  • docs: simplify the session thread agent type description (ccf71a2)
  • docs: update diagnostics field descriptions on beta messages (c0b8746)
  • internal: add property-based tests for partial JSON parsing (#776) (3ffac09)

0.127.0 (2026-09-18)

Full Changelog: sdk-v0.126.0...sdk-v0.127.0

Features

  • api: add group with display_name to rate limits, deprecate group_type (2575d97)
  • tools: add compactBeforeNextTurn() to the tool runner (#682) (9f75ca6)

Bug Fixes

  • BetaMessageStream: stop coercing a null compaction_delta content into "null" (#655) (dbd6845)
  • client: don't retry requests whose body is a stream or iterator (eebc1b9)
  • client: join multiple anthropic-beta values with a comma and no space (#638) (e0cb1ff)
  • client: make pagination exports on the client namespace type-only (5adea1f)
  • internal: drop jest from tsconfig types (60588af)
  • middleware: echo a streamed compaction summary in the fallback continuation (#657) (2e0f004)
  • tools: keep $defs when transformJSONSchema root is a $ref (#687) (57a9f30)

Performance Improvements

  • client: skip formatting request details when debug logging is off (2b29ed2)

... (truncated)

Commits
  • 1926adb Merge pull request #1208 from anthropics/release-please--branches--main--chan...
  • 162c8b1 chore: release main
  • 3ffac09 chore(internal): add property-based tests for partial JSON parsing (#776)
  • e40ce27 test(ecosystem): check that unused imports tree-shake to nothing
  • 1ccdad0 fix(tools): addTools() takes effect straight away (#773)
  • 8afc336 fix(tools): leave reply-only params off the tool runner's compaction request ...
  • eff2748 feat(api): add support for claude-opus-5-5, inline tool definitions and MCP t...
  • 06e5f9b codegen metadata
  • 0c1cc0f fix(api): share one evaluated_permission enum across Managed Agents events
  • c0b8746 chore(docs): update diagnostics field descriptions on beta messages
  • Additional commits viewable in compare view

Updates @sentry/nextjs from 10.70.0 to 10.75.3

Release notes

Sourced from @​sentry/nextjs's releases.

10.75.3

  • fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route (#24617)
  • chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • chore(v10/publish): Tag all packages as v10 (#24619)

Bundle size 📦

Path Size
@​sentry/browser 27.56 KB
@​sentry/browser - with treeshaking flags 26.04 KB
@​sentry/browser (incl. Tracing) 46.02 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.77 KB
@​sentry/browser (incl. Tracing, Profiling) 50.67 KB
@​sentry/browser (incl. Tracing, Replay) 84.38 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 74.28 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 89 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 101.33 KB
@​sentry/browser (incl. Feedback) 44.33 KB
@​sentry/browser (incl. sendFeedback) 32.25 KB
@​sentry/browser (incl. FeedbackAsync) 37.27 KB
@​sentry/browser (incl. Metrics) 28.63 KB
@​sentry/browser (incl. Logs) 28.84 KB
@​sentry/browser (incl. Metrics & Logs) 29.52 KB
@​sentry/react 29.32 KB
@​sentry/react (incl. Tracing) 48.28 KB
@​sentry/vue 32.88 KB
@​sentry/vue (incl. Tracing) 47.98 KB
@​sentry/svelte 27.58 KB
CDN Bundle 29.87 KB
CDN Bundle (incl. Tracing) 47.92 KB
CDN Bundle (incl. Logs, Metrics) 31.41 KB
CDN Bundle (incl. Tracing, Logs, Metrics) 49.21 KB
CDN Bundle (incl. Replay, Logs, Metrics) 69.82 KB
CDN Bundle (incl. Tracing, Replay) 84.64 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.87 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 90.31 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 91.55 KB
CDN Bundle - uncompressed 88.83 KB
CDN Bundle (incl. Tracing) - uncompressed 144.49 KB
CDN Bundle (incl. Logs, Metrics) - uncompressed 93.43 KB
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 148.38 KB
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 215.46 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 261.12 KB

... (truncated)

Changelog

Sourced from @​sentry/nextjs's changelog.

10.75.3

  • fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route (#24617)
  • chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • chore(v10/publish): Tag all packages as v10 (#24619)

10.75.2

  • fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)
  • fix(v10/core): Apply dataCollection.urlQueryParams to collected URLs and query strings (#24572)
  • fix(v10/nextjs): Align tunnel request matching in middleware with tunnel rewrite (#24565)
  • fix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams (#24563)

10.75.1

  • fix(v10/cloudflare): Capture telemetry from untraced Durable Object RPC calls (#24512)
  • fix(v10/cloudflare): Instrument namespaces returned by jurisdiction() (#24513)
  • fix(v10/hono): Allow @​cloudflare/workers-types v5 as peer dependency (#24500)
  • fix(v10/nextjs): Resolve Next.js version relative to the SDK when cwd differs (#24475)

10.75.0

Important Changes

  • feat(v10/effect): Capture errors through the Effect v4 ErrorReporter API (#24445)

    On Effect v4, Sentry.effectLayer now registers a Sentry ErrorReporter. Failures that pass through Effect.withErrorReporting, ErrorReporter.report or the built-in HTTP and RPC reporting boundaries are captured automatically, with ErrorReporter.ignore, ErrorReporter.severity and ErrorReporter.attributes annotations respected. Nothing changes on Effect v3.

Other Changes

  • feat(v10/core): Accept a CollectBehavior shorthand for dataCollection.httpHeaders (#24339)
  • fix(v10/browser): Release the XHR virtualError once the request completed (#24307)
  • fix(v10/browser-utils): Skip nullish LCP entries in vendored web-vitals (#24349)
  • fix(v10/bundler-plugins): Stamp debug IDs onto emitted source maps when disable-upload is set (#24332)
  • fix(v10/core): Don't instrument the SDK's own envelope requests (#24276)
  • fix(v10/nextjs): Only include emitted chunk directories in Turbopack sourcemap upload (#24295)
  • fix(v10/nitro): Import from nitro/h3 instead of h3 directly (#24444)
  • fix(v10/node-core): Don't recurse in logAndExitProcess on a broken stdio pipe (#24353)
  • fix(v10/nuxt): Detect Nitro version via the app's Nuxt dependency chain (#24025)
  • fix(v10/replay): Don't rewrite already-emitted nodes when syncing mirror attributes (#23588)

10.74.0

  • feat(v10): Streamline isolation scope handling & reset in isolation scopes (#24152)

... (truncated)

Commits
  • 3b282c1 release: 10.75.3
  • b5ea330 meta(changelog): Update changelog for 10.75.3 (#24649)
  • 533a6fa chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • 4e91ce5 chore(v10/publish): Tag all packages as v10 (#24619)
  • f01ca30 fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel ...
  • 79e6e95 Merge remote-tracking branch 'remotes/origin/release/10.75.2' into v10
  • faeac9a release: 10.75.2
  • 7175b19 meta(changelog): Update changelog for 10.75.2 (#24585)
  • 8f5dc60 fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)
  • 44506df fix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams...
  • Additional commits viewable in compare view

Updates @supabase/ssr from 0.12.4 to 0.12.7

Release notes

Sourced from @​supabase/ssr's releases.

v0.12.7

0.12.7 (2026-09-08)

Bug Fixes

  • apply non-browser defaults when cookies only sets encode (#294) (9d6e2a5)

v0.12.7-rc.162

What's Changed

Full Changelog: supabase/ssr@v0.12.6...v0.12.7-rc.162

v0.12.6

0.12.6 (2026-09-04)

Bug Fixes

  • avoid duplicate cache headers per server client (#283) (af750e2)

v0.12.6-rc.158

What's Changed

New Contributors

Full Changelog: supabase/ssr@v0.12.5...v0.12.6-rc.158

v0.12.5

0.12.5 (2026-08-24)

Bug Fixes

  • warn when auth.storage is ignored by createBrowserClient/createServerClient (#284) (c1700f2), closes #142

v0.12.5-rc.154

What's Changed

... (truncated)

Changelog

Sourced from @​supabase/ssr's changelog.

0.12.7 (2026-09-08)

Bug Fixes

  • apply non-browser defaults when cookies only sets encode (#294) (9d6e2a5)

0.12.6 (2026-09-04)

Bug Fixes

  • avoid duplicate cache headers per server client (#283) (af750e2)

0.12.5 (2026-08-24)

Bug Fixes

  • warn when auth.storage is ignored by createBrowserClient/createServerClient (#284) (c1700f2), closes #142
Commits
  • 9b28f49 chore(main): release 0.12.7 (#295)
  • 9d6e2a5 fix: apply non-browser defaults when cookies only sets encode (#294)
  • 4ed9f65 chore: add workflow for autoclosing stale issues (#292)
  • 71c33a7 chore(main): release 0.12.6 (#291)
  • c7c7e68 docs: fix typos in tsdoc and design doc (#288)
  • af750e2 fix: avoid duplicate cache headers per server client (#283)
  • 905c7c3 build(deps): bump actions/deploy-pages from 5.0.0 to 5.0.1 (#290)
  • 9e2564d chore: update @​supabase/supabase-js to v2.114.0 (#289)
  • c5310fd chore(main): release 0.12.5 (#286)
  • c1700f2 fix: warn when auth.storage is ignored by createBrowserClient/createServerCli...
  • Additional commits viewable in compare view

Updates @supabase/supabase-js from 2.112.3 to 2.117.2

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

2.117.0 (2026-09-22)

🚀 Features

  • auth: enable passkey API by default and deprecate experimental passkey opt-in (#2695)

❤️ Thank You

  • fadymak

2.116.0 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)

🩹 Fixes

  • supabase: warn when schema is passed outside db options (#2663)

❤️ Thank You

2.115.0 (2026-09-03)

🚀 Features

  • postgrest: add getOpenApiSpec() (#2651)

❤️ Thank You

2.114.0 (2026-09-02)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

2.113.0 (2026-09-02)

... (truncated)

Commits
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • 739b351 fix(auth): return stored session when a refresh loses to another tab (#2698)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • cc45ccf feat(auth): enable passkey API by default and deprecate experimental passkey ...
  • c511286 docs(realtime): document relationship of accessToken() and heartbeat (#2680)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • 5aedaab feat(auth): add MFA recovery codes API (#2676)
  • e4f675a fix(supabase): warn when schema is passed outside db options (#2663)
  • dbe7679 chore(release): version 2.115.0 changelogs (#2664)
  • 3eb6193 docs(supabase): clarify db.schema needs the second generic (#2662)
  • Additional commits viewable in compare view

Updates @upstash/redis from 1.38.2 to 1.39.0

Release notes

Sourced from @​upstash/redis's releases.

@​upstash/redis@​1.39.0

Minor Changes

  • 6801501: Add array commands: arset, armset, arget, armget, argetrange, arscan, argrep, ardel, ardelrange, arcount, arlen, arinsert, arring, arlastitems, arnext, arseek, arop and arinfo, available on the client, in pipelines and in transactions.
  • 3f6e286: Support search indexes over Redis streams: redis.search.createIndex({ dataType: "stream", stream: "events", schema }) indexes every entry of the stream as a document keyed by its entry ID. describe() reports dataType: "stream" with the stream key in prefixes.
  • 33658bc: Add vector index support: redis.vector.createIndex() / redis.vector.index() return a VectorIndex with add, get, query, delete, count, info and drop, backed by the new VECTOR.CREATE, VECTOR.ADD, VECTOR.GET, VECTOR.QUERY, VECTOR.DEL, VECTOR.COUNT, VECTOR.INFO and VECTOR.DROP commands.

@​upstash/redis@​1.39.0-canary-20260826110341-795a33599494ef4034259bd4f7d36db70c44f368

Full Changelog: https://github.com/upstash/redis-js/compare/@​upstash/redis@1.38.3...@​upstash/redis@1.39.0-canary-20260826110341-795a33599494ef4034259bd4f7d36db70c44f368

@​upstash/redis@​1.38.4

Patch Changes

  • 7ac8182: Fix read-your-writes sending a stale upstash-sync-token

    A read issued straight after a write travelled with the token from before that write, so the server was under no obligation to serve the write and readYourWrites silently did not hold.

    HttpClient.request() snapshotted the outgoing headers with mergeHeaders(this.headers, ...) and only afterwards wrote the freshest token into this.headers, so the token learned from response N first shipped with request N+2. The assignment now happens before the merge.

    This regressed in 1.34.5. In 1.34.0–1.34.4 the request options held headers: this.headers by reference, so the late write was still picked up before fetch; 1.34.5 introduced per-request header merging, which turned that reference into a copy without moving the assignment.

@​upstash/redis@​1.38.3

Patch Changes

  • f020866: Send an Upstash-Telemetry-Retry header with the retry count on retried requests so retry rates are visible in server-side telemetry
  • 777dc30: Trim telemetry header values before deduplicating so whitespace around existing values does not defeat the dedup check

@​upstash/redis@​1.38.3-canary-20260807072941-777dc30585ae61e5826bb95f5a957e6dea277900

What's Changed

Full Changelog: https://github.com/upstash/redis-js/compare/@​upstash/redis@1.38.2...@​upstash/redis@1.38.3-canary-20260807072941-777dc30585ae61e5826bb95f5a957e6dea277900

Commits
  • 6b27727 chore: version packages (#1456)
  • 33658bc DX-2963: add vector index commands and redis.vector namespace (#1446)
  • 6801501 DX-3009: add array commands (#1451)
  • 3f6e286 DX-3010: support search indexes over redis streams (#1452)
  • 73fbe1a chore: version packages (#1448)
  • 7ac8182 DX-2995: fix read-your-writes sending a stale upstash-sync-token (#1447)
  • 1bec566 ci: poll npm for the ci version instead of a fixed sleep (#1444)
  • 74da1df chore: version packages (#1443)
  • f020866 DX-2960: send Upstash-Telemetry-Retry header with the attempt number (DX-2960...
  • 777dc30 fix: trim telemetry values before dedup and cover distinct-version case (#1442)
  • See full diff in compare view

Updates dompurify from 3.4.13 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible

DOMPurify 3.4.15

  • Added better clobbering hardening when XML content is involved, thanks @​gnyselcuk
  • Added several smaller hardening and edge-case improvements, thanks @​leechristensen
  • Bumped several dependencies where possible

DOMPurify 3.4.14

  • Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @​AlirezaRouhbakhsh
  • Fixed a couple of edge cases with mixed document contexts, thanks @​fishjojo1
  • Added the SVG pointer-events and vector-effect presentation attributes to the allow-list, thanks @​Jaybhade
  • Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation
  • Updated the documentation in several spots, README, wiki, etc., thanks @​Akokonunes
  • Updated several development dependencies and CI workflow actions
Commits

Updates groq-sdk from 1.5.0 to 1.6.0

Release notes

Sourced from groq-sdk's releases.

v1.6.0

1.6.0 (2026-08-25)

Full Changelog: v1.5.0...v1.6.0

Features

  • chat: add Qwen3.8 reasoning guidance (c2b0264)

Chores

  • GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.yaml [skip ci] (99fc8ef)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (8d224a0)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (2c5b7aa)
  • internal: allow the mock server port to be set with STAINLESS_MOCK_PORT (90cec2d)

Styles

  • chat: format completion params union (91d9de9)
Changelog

Sourced from groq-sdk's changelog.

1.6.0 (2026-08-25)

Full Changelog: v1.5.0...v1.6.0

Features

  • chat: add Qwen3.8 reasoning guidance (c2b0264)

Chores

  • GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.yaml [skip ci] (99fc8ef)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (8d224a0)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (2c5b7aa)
  • internal: allow the mock server port to be set with STAINLESS_MOCK_PORT (90cec2d)

Styles

  • chat: format completion params union (91d9de9)
Commits
  • 6de8d02 release: 1.6.0 (#273)
  • 8d224a0 chore: GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci]
  • 2c5b7aa chore: GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci]
  • 99fc8ef chore: GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.y...
  • See full diff in compare view

Updates next from 16.3.1 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

Huge thanks to @​eps1lon, @​mischnic, and @​timneutkens for helping!

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

Commits

…7 updates

Bumps the minor-and-patch group with 27 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.117.1` | `0.128.0` |
| [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) | `10.70.0` | `10.75.3` |
| [@supabase/ssr](https://github.com/supabase/ssr) | `0.12.4` | `0.12.7` |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.112.3` | `2.117.2` |
| [@upstash/redis](https://github.com/upstash/redis-js) | `1.38.2` | `1.39.0` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.13` | `3.4.16` |
| [groq-sdk](https://github.com/groq/groq-typescript) | `1.5.0` | `1.6.0` |
| [next](https://github.com/vercel/next.js) | `16.3.1` | `16.3.6` |
| [next-intl](https://github.com/amannn/next-intl) | `4.13.6` | `4.14.7` |
| [sharp](https://github.com/lovell/sharp) | `0.35.3` | `0.35.4` |
| [swagger-ui-react](https://github.com/swagger-api/swagger-ui) | `5.32.13` | `5.33.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [@next/env](https://github.com/vercel/next.js/tree/HEAD/packages/next-env) | `16.3.1` | `16.3.6` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@testing-library/dom](https://github.com/testing-library/dom-testing-library) | `10.4.1` | `10.4.2` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.67.0` | `8.70.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.67.0` | `8.70.1` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `4.1.11` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.5.4` | `10.6.1` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.1` | `16.3.6` |
| [postcss](https://github.com/postcss/postcss) | `8.5.26` | `8.5.28` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.12` | `29.4.14` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `4.1.11` |
| [web-tree-sitter](https://github.com/tree-sitter/tree-sitter/tree/HEAD/lib/binding_web) | `0.26.12` | `0.27.0` |
| [@img/sharp-linux-x64](https://github.com/lovell/sharp/tree/HEAD/npm/linux-x64) | `0.35.3` | `0.35.4` |
| [@swc/core-linux-x64-gnu](https://github.com/swc-project/swc) | `1.15.47` | `1.16.2` |



Updates `@anthropic-ai/sdk` from 0.117.1 to 0.128.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.117.1...sdk-v0.128.0)

Updates `@sentry/nextjs` from 10.70.0 to 10.75.3
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.70.0...10.75.3)

Updates `@supabase/ssr` from 0.12.4 to 0.12.7
- [Release notes](https://github.com/supabase/ssr/releases)
- [Changelog](https://github.com/supabase/ssr/blob/main/CHANGELOG.md)
- [Commits](supabase/ssr@v0.12.4...v0.12.7)

Updates `@supabase/supabase-js` from 2.112.3 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js)

Updates `@upstash/redis` from 1.38.2 to 1.39.0
- [Release notes](https://github.com/upstash/redis-js/releases)
- [Commits](https://github.com/upstash/redis-js/compare/@upstash/redis@1.38.2...@upstash/redis@1.39.0)

Updates `dompurify` from 3.4.13 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.13...3.4.16)

Updates `groq-sdk` from 1.5.0 to 1.6.0
- [Release notes](https://github.com/groq/groq-typescript/releases)
- [Changelog](https://github.com/groq/groq-typescript/blob/main/CHANGELOG.md)
- [Commits](groq/groq-typescript@v1.5.0...v1.6.0)

Updates `next` from 16.3.1 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.1...v16.3.6)

Updates `next-intl` from 4.13.6 to 4.14.7
- [Release notes](https://github.com/amannn/next-intl/releases)
- [Changelog](https://github.com/amannn/next-intl/blob/main/CHANGELOG.md)
- [Commits](amannn/next-intl@v4.13.6...v4.14.7)

Updates `sharp` from 0.35.3 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.3...v0.35.4)

Updates `swagger-ui-react` from 5.32.13 to 5.33.0
- [Release notes](https://github.com/swagger-api/swagger-ui/releases)
- [Commits](swagger-api/swagger-ui@v5.32.13...v5.33.0)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `@next/env` from 16.3.1 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/next-env)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@testing-library/dom` from 10.4.1 to 10.4.2
- [Release notes](https://github.com/testing-library/dom-testing-library/releases)
- [Changelog](https://github.com/testing-library/dom-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/dom-testing-library@v10.4.1...v10.4.2)

Updates `@testing-library/react` from 16.3.2 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/react-testing-library@v16.3.2...v16.3.3)

Updates `@typescript-eslint/eslint-plugin` from 8.67.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.67.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser)

Updates `@vitest/coverage-v8` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/coverage-v8)

Updates `autoprefixer` from 10.5.4 to 10.6.1
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.4...10.6.1)

Updates `eslint-config-next` from 16.3.1 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `postcss` from 8.5.26 to 8.5.28
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.26...8.5.28)

Updates `ts-jest` from 29.4.12 to 29.4.14
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.14)

Updates `vitest` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

Updates `web-tree-sitter` from 0.26.12 to 0.27.0
- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)
- [Commits](https://github.com/tree-sitter/tree-sitter/commits/v0.27.0/lib/binding_web)

Updates `@img/sharp-linux-x64` from 0.35.3 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](https://github.com/lovell/sharp/commits/v0.35.4/npm/linux-x64)

Updates `@swc/core-linux-x64-gnu` from 1.15.47 to 1.16.2
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](swc-project/swc@v1.15.47...v1.16.2)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.128.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@sentry/nextjs"
  dependency-version: 10.75.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@supabase/ssr"
  dependency-version: 0.12.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.117.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@upstash/redis"
  dependency-version: 1.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: groq-sdk
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: next-intl
  dependency-version: 4.14.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: swagger-ui-react
  dependency-version: 5.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@next/env"
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@testing-library/dom"
  dependency-version: 10.4.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@testing-library/react"
  dependency-version: 16.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: autoprefixer
  dependency-version: 10.6.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ts-jest
  dependency-version: 29.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: web-tree-sitter
  dependency-version: 0.27.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@img/sharp-linux-x64"
  dependency-version: 0.35.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@swc/core-linux-x64-gnu"
  dependency-version: 1.16.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from omen18 as a code owner September 28, 2026 15:30
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: level:beginner. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
code-stride Ready Ready Preview Sep 28, 2026 3:33pm UTC

This branch was successfully deployed

1 active deployment
Preview — 12efa876 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants