chore(deps): bump the npm_and_yarn group across 1 directory with 10 updates - #1
Merged
selmant merged 2 commits intoJul 25, 2026
Merged
Conversation
|
The i18n check failed because translation messages are out of sync. This usually happens when you've added or modified translation strings in your code but haven't updated the translation file. Please run |
Owner
|
@dependabot rebase |
…pdates Bumps the npm_and_yarn group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [axios](https://github.com/axios/axios) | `1.15.0` | `1.18.0` | | [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.0` | | [next](https://github.com/vercel/next.js) | `16.2.6` | `16.2.11` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `8.0.5` | `9.0.1` | | [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.0` | | [typeorm](https://github.com/typeorm/typeorm) | `0.3.29` | `0.3.31` | | [ua-parser-js](https://github.com/faisalman/ua-parser-js) | `2.0.9` | `2.0.10` | | [undici](https://github.com/nodejs/undici) | `8.1.0` | `8.5.0` | | [postcss](https://github.com/postcss/postcss) | `8.5.12` | `8.5.18` | Updates `axios` from 1.15.0 to 1.18.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.15.0...v1.18.0) Updates `js-yaml` from 4.1.1 to 4.3.0 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@4.1.1...4.3.0) Updates `next` from 16.2.6 to 16.2.11 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.2.6...v16.2.11) Updates `nodemailer` from 8.0.5 to 9.0.1 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v8.0.5...v9.0.1) Updates `sharp` from 0.34.5 to 0.35.0 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.34.5...v0.35.0) Updates `typeorm` from 0.3.29 to 0.3.31 - [Release notes](https://github.com/typeorm/typeorm/releases) - [Changelog](https://github.com/typeorm/typeorm/blob/0.3.31/CHANGELOG.md) - [Commits](typeorm/typeorm@0.3.29...0.3.31) Updates `ua-parser-js` from 2.0.9 to 2.0.10 - [Release notes](https://github.com/faisalman/ua-parser-js/releases) - [Changelog](https://github.com/faisalman/ua-parser-js/blob/master/CHANGELOG.md) - [Commits](faisalman/ua-parser-js@2.0.9...2.0.10) Updates `undici` from 8.1.0 to 8.5.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v8.1.0...v8.5.0) Updates `postcss` from 8.5.12 to 8.5.18 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.12...8.5.18) Updates `form-data` from 4.0.5 to 4.0.6 - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v4.0.5...v4.0.6) --- updated-dependencies: - dependency-name: axios dependency-version: 1.18.0 dependency-type: direct:production - dependency-name: form-data dependency-version: 4.0.6 dependency-type: indirect - dependency-name: js-yaml dependency-version: 4.3.0 dependency-type: direct:production - dependency-name: next dependency-version: 16.2.11 dependency-type: direct:production - dependency-name: nodemailer dependency-version: 9.0.1 dependency-type: direct:production - dependency-name: postcss dependency-version: 8.5.18 dependency-type: direct:development - dependency-name: sharp dependency-version: 0.35.0 dependency-type: direct:production - dependency-name: typeorm dependency-version: 0.3.31 dependency-type: direct:production - dependency-name: ua-parser-js dependency-version: 2.0.10 dependency-type: direct:production - dependency-name: undici dependency-version: 8.5.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/npm_and_yarn-6ec97834b1
branch
from
July 25, 2026 17:33
8fd5776 to
c9c0c33
Compare
Axios 1.18 widened response header value types, which broke ImageProxy cache-control/content-type parsing under tsc. Co-authored-by: Cursor <cursoragent@cursor.com>
dependabot
Bot
deleted the
dependabot/npm_and_yarn/npm_and_yarn-6ec97834b1
branch
July 25, 2026 18:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 9 updates in the / directory:
1.15.01.18.04.1.14.3.016.2.616.2.118.0.59.0.10.34.50.35.00.3.290.3.312.0.92.0.108.1.08.5.08.5.128.5.18Updates
axiosfrom 1.15.0 to 1.18.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
2d06f96chore(release): prepare release 1.18.0 (#11003)32fc489fix: malformed http urls (#11000)b40ce49chore(deps-dev): bump the development_dependencies group with 10 updates (#10...fe964f9docs: mark proxy config as Node.js only (#10995)5f229d2chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...fae9d4edocs: clarify package update PR policy (#10992)28ab2cechore(deps-dev): bump the development_dependencies group with 2 updates (#10989)a8e4f13fix(core): keep default validateStatus when request passes undefined (#10899)614f455docs: publish v1.17.0 release notes (#10988)6bb12c1fix: custom auth headers not stripped on cross-origin redirects (#10892)Updates
js-yamlfrom 4.1.1 to 4.3.0Changelog
Sourced from js-yaml's changelog.
... (truncated)
Commits
33d05b54.3.0 released663bfabDrop demo publish, to not override new v5 one.1cb8c7bAdd v4-legacy tag for publish02f27afRestore umd builds back to es58be84edFix es5 compatibility59423c6ReplacemaxMergeSeqLengthoption withmaxTotalMergeKeys(more robust). Ba...6842ef6doc polish590dbab4.2.0 releasedf944dc5Add package.json funding fieldf692719Changelog updateUpdates
nextfrom 16.2.6 to 16.2.11Release notes
Sourced from next's releases.
Commits
9beca08v16.2.113c48c7a[16.x] Fix Turbopack middleware matcher with i18n single localeac1eff3[16.x] Improve performance of checking valid MPA form submissions9a4651e[16.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimeb512063[16.x] Set correct origin for internal redirects in custom serverd303326[16.x] Ensure exotic rewrite param values are properly encoded73b9487[16.x] fix(fetch-cache): key fetch(Request, init) by the effective requestbf9d17f[16.x] fix(incremental-cache): byte-exact fetch cache key for binary bodiesfe28768[16.x] fix(next/image): improve performance of detectContentType()d8afb8d[16.x] Performance improvements when decoding React Server function payloadsUpdates
nodemailerfrom 8.0.5 to 9.0.1Release notes
Sourced from nodemailer's releases.
... (truncated)
Changelog
Sourced from nodemailer's changelog.
... (truncated)
Commits
69cf625chore(master): release 9.0.1 (#1828)a82e060fix: enforce disableFileAccess/disableUrlAccess for raw message option4e58450chore: update dev dependencies541f5fdchore(master): release 9.0.0 (#1827)0c080fbfix: replace deprecated url.parse with a WHATWG URL wrapper6a947acfix!: validate TLS certificates by default when fetching remote contente3b1bdachore(master): release 8.0.11 (#1826)4358cafrefactor: remove dead checks flagged by Code Quality analysiscf5195cchore: harden workflow token permissions and update GitHub Actions067aebefix: parse Ethereal response props without polynomial regex backtrackingUpdates
sharpfrom 0.34.5 to 0.35.0Release notes
Sourced from sharp's releases.
... (truncated)
Commits
2ed5af4Release v0.35.04475cf1Tests: update locator hash for sharp-libvips v1.3.0deb22ddUpgrade to sharp-libvips v1.3.007f1be9Prerelease v0.35.0-rc.8df1109bPrerelease v0.35.0-rc.7aca49b3Upgrade to libvips v8.18.3e9e86f5Type-check density option before range validation (#4536)2f0bcf0Docs: update supported image formats98e03b8Revert "Guard heif bitdepth property for prebuilt binaries"e4ea2f3CI: Ignore package minimum age in smoke testsUpdates
typeormfrom 0.3.29 to 0.3.31Release notes
Sourced from typeorm's releases.
Changelog
Sourced from typeorm's changelog.
Commits
7973203ci: publish to npm fromv0using thelegacytag92e9276ci: usenpm@11099c23echore: prepare release 0.3.31 (#12676)b175f9bMerge commit from forka69a8c6fix(entity-manager): validate where criteria in increment/decrement (#12692)dfd972bfix(query-builder): reject empty where criteria on update and delete operatio...a2d4363chore: update deps (#12661)e1f93dafix(tree-entity): tree entity schema propagation in internal TreeRepository m...a309182fix: normalization of FindOptionsWhere for arrays and Buffers (#12577)d8e9127fix(persistence): preserve select false columns on the in-memory entity after...Updates
ua-parser-jsfrom 2.0.9 to 2.0.10Release notes
Sourced from ua-parser-js's releases.
Changelog
Sourced from ua-parser-js's changelog.
Commits
4121c59Build: Bump version2.0.1090354d3Fix: Prevent ReDoS vulnerability by limiting Client Hints input length (GHSA-...3baa3bcTest: Increase nyc timeout to fix timeout error18d39b5CI: Add GitHub Actions workflow to publish to Docker Hub58b5a0cBuild: Add Dockerfile for container image build965c20dCI: Update fuzz testad97feaBuild: Set sideEffects=false in package.json for tree shaking (#781)312598fCI: Add AI and spam detection to pull request workflow8f9e4dcTest: Fix relative path and update done() callback in CLI test speceb809ecChore(license): Add THIRD_PARTY_NOTICES.md for third-party assetsUpdates
undicifrom 8.1.0 to 8.5.0Release notes
Sourced from undici's releases.