chore(deps): Update all non-major dependencies - #191
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 05:24
b57575e to
27b07af
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 17:12
27b07af to
647dde0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 23:39
647dde0 to
ae8b41c
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.7.2→^1.7.4^5.18.7→^5.19.01.170.32→1.170.35^1.168.35→^1.168.37^3.3.2→^3.3.4^25.9.5→^25.9.6^19.2.18→^19.3.0^19.2.7→^19.3.0^1.7.2→^1.7.4^17.5.0→^17.5.1^1.41.0→^1.45.0^19.2.8→^19.3.0^19.2.8→^19.3.07.87.0→7.88.0^8.69.0→^8.70.0^1.4.2→^1.5.0^8.2.2→^8.3.0Release Notes
better-auth/better-auth (@better-auth/passkey)
v1.7.4Compare Source
v1.7.3Compare Source
TanStack/router (@tanstack/react-router)
v1.170.35Compare Source
Patch Changes
8c43c71- Upgrade TanStack Store to 0.11 and migrate router subscriptions to useSelector, preserving selector comparisons and Vue subscription cleanup.v1.170.34Compare Source
Patch Changes
#8279
aee42c6- Avoid allocating event-handler arrays and wrapper functions for links without user-supplied event handlers.#8308
9c1871c- Validate navigation and redirect destinations, keep ambiguous relative URLs on the current origin, and constrain prerender requests and output paths. Prevent redirect headers from appearing in serialized server function response bodies.Preserve native form HTTP redirects, route error handling and masks for document redirects, and per-navigation destinations for shared loader redirects. Avoid redundant origin parsing and reduce link styling and server-rendering work. Configured origins must already be normalized.
Keep blocked-link inactive props consistent during React hydration, honor explicit redirect Location headers before checking route options, and refresh Vue link state when destinations become internal. Reuse the protocol-relative URL check while parsing redirect schemes once.
Reduce React link bundle size by sharing pathname comparisons, state-prop selection, and element creation.
Share normalized pathname comparisons in Solid and Vue links to reduce bundle size.
#8311
9aec5a7- React Links resolve state props without temporary class-name arrays or unnecessary style copies.Updated dependencies [
f9836f1,9c1871c,9871c06,0654c0a]:v1.170.33Compare Source
Patch Changes
#8165
2f20c00- Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.#8209
28a5e45- Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components andonCatchcallbacks asunknown. Solid boundary errors remain typed asError; SSR now wraps non-Errorloader errors to match Solid’s native boundary behavior, preserving the original value incause. Router state and loaderonErrorvalues are unchanged.When upgrading React or Vue, narrow boundary errors (for example, with
error instanceof Error) before readingmessageorstack.ErrorComponentProps<TError>remains available for values narrowed to a specific error type. RouteonErrortypes are unchanged.#8161
f0b5eda- Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.#8251
0497cae- Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.#8169
0caf6b9- Fix route-scopeduseMatch,useSearch, anduseParamsAPIs to forward theshouldThrowoption and preserve optional return types whenshouldThrow: false.#8257
cf166d1- Fix repeatedinnerHTMLwrites for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.Updated dependencies [
edf0e16,2f20c00,28a5e45,08eff50,216c0c4,2f91503,f0b5eda,50eafca,0497cae,ee28348,9035abc,c18e690]:TanStack/router (@tanstack/router-plugin)
v1.168.37Compare Source
Patch Changes
#8300
49bcd4d- Refresh compatible build and runtime dependencies.Updated dependencies [
f9836f1,aee42c6,49bcd4d,9c1871c,9aec5a7,9871c06,0654c0a]:v1.168.36Compare Source
Patch Changes
edf0e16,2f20c00,28a5e45,08eff50,216c0c4,2f91503,f0b5eda,50eafca,0497cae,0caf6b9,ee28348,cf166d1,c18e690]:glincker/thesvg (@thesvg/react)
v3.3.4Compare Source
Patch Changes
better-auth/better-auth (better-auth)
v1.7.4Compare Source
Patch Changes
#11205
3f890ebThanks @bytaesu! - Support Vitest 5 in the testing utilities while retaining support for previously supported Vitest versions.#11224
c1756a2Thanks @bytaesu! - Addexperimental.instrumentation.enabledto disable Better Auth OpenTelemetry span creation per auth instance. Instrumentation remains enabled by default and independent of usage reporting.#11217
9b9638eThanks @onmax! - AllowtestUtilsauth helpers to accept additional session fields through thesessionoption, including required fields without defaults and per-session overrides of configured defaults.Updated dependencies [
3ff842a,b905bfe,c1756a2]:v1.7.3Compare Source
Patch Changes
#11060
3660f06Thanks @bytaesu! - Handle malformed custom-scheme callback URLs without excessive processing.#11037
5bd7096Thanks @bytaesu! - Prevent repeated TOTP enrollment from replacing an active authenticator and its backup codes.#11120
7ec7146Thanks @onmax! - PreventgetSessionfrom failing when cookie caching is disabled while clients still have cached session cookies.#9908
76d311fThanks @harshil1712! - Add Cloudflare as a built-in social provider, with support for client-secret authentication and PKCE clients without a secret.#11188
c47b765Thanks @bytaesu! - Normalize Auth0 domains without a potentially slow trailing-slash regular expression.#11084
2d5c63dThanks @bytaesu! - Prevent duplicate session requests and hydration mismatches when using the Vue client with NuxtuseFetch.#11147
a9d8c12Thanks @bytaesu! - AddisPasswordCompromisedfor checking passwords against Have I Been Pwned in custom server-side flows, while ignoring padded response entries with zero occurrences.#10988
9fc7498Thanks @bytaesu! - Run callback hooks after proxied OAuth sign-ins and preserve server state when callback cookies are unavailable. The legacy/oauth-proxy-callbackendpoint is deprecated and will be removed in the next minor release.#11178
be0e007Thanks @bytaesu! - Report missing tables, missing columns, and required columns Better Auth never writes during initialization, with guidance for fixing them. Kysely checks the live database schema. Authentication requests await the same check and are rejected if the schema does not match.Validation is enabled by default, including in production. Set
advanced.database.validateSchema: falseto disable runtime validation.auth migraterefuses to apply changes when required unwritten columns need manual repair.#11069
0bb0dbfThanks @bytaesu! - Improve dynamic organization role permission check performance.#11153
2220ee7Thanks @bytaesu! - Restore sign-in compatibility with 1.6 databases by identifying accounts with(providerId, accountId)and removing theissuerrequirement introduced in 1.7.0. Upgrading from 1.6 no longer requires an account schema migration. Ambiguous account keys are rejected instead of selecting an arbitrary account.If you applied the 1.7.0 through 1.7.2 account schema, remove its issuer unique index before upgrading. For SQL databases, also make
issuernullable or remove the column so sign-ups and account linking can succeed.auth migratedoes not perform this cleanup. Follow the upgrade guide for database-specific steps.#10978
5fe5bc2Thanks @BetterAndBetterII! - Skip a generic OAuth provider when discovery fails instead of taking down the rest of the auth API.#10963
74a7369Thanks @thisismert! - Track email OTP sign-ins in the last login method plugin.#11085
e16b40aThanks @bytaesu! - Provide type-safe NuxtuseFetchintegration for the Vue client'suseSessionhook.#11066
c0444dcThanks @bytaesu! - Upgrade the packaged Zod dependency to 4.5. Generated OpenAPI schemas now mark required request fields consistently with runtime validation, including passkey registration responses.Updated dependencies [
352d012,76d311f,3e9e197,157ec8d,baa08f4,9e36635,be0e007,a2bae0c,1a1b7d5,2220ee7]:lint-staged/lint-staged (lint-staged)
v17.5.1Compare Source
Patch Changes
#1852
bfcca94- Fix TypeScript issueTS1254fromdefineConfig()by changing the signature fromconstto afunction:lucide-icons/lucide (lucide-react)
v1.45.0: Version 1.45.0Compare Source
What's Changed
calendar-chevrons-righticon by @AlexandrePhilibert in #3565building-complex-plusicon by @tylerkade in #4758mouth&mouth-offby @karsa-mistmere in #4787iv-bagicon by @karsa-mistmere in #4821lecternicon by @UsamaKhan in #2925layout-arrow-rightandlayout-arrow-downby @samuelalake in #4541parkicon by @skajosborn in #3177album,book-marked,folder-bookmarkicons by @karsa-mistmere in #3043housesicon by @danielbayley in #3241notebook-doticon by @elenakovelskikh in #3228messages-circleicon by @Mirazstudio-offical in #4754plant-poticon by @vqh2602 in #3122cookieicon by @karsa-mistmere in #4815globe-codeicon by @AleksejDix in #3722New Contributors
Full Changelog: lucide-icons/lucide@1.44.0...1.45.0
v1.44.0: Version 1.44.0Compare Source
What's Changed
door-openby @karsa-mistmere in #4826satellite-dishicon by @karsa-mistmere in #4813toothbrushicon by @karsa-mistmere in #4755New Contributors
Full Changelog: lucide-icons/lucide@1.43.0...1.44.0
v1.43.0: Version 1.43.0Compare Source
What's Changed
tic-tac-toeicon by @karsa-mistmere in #4772id-cardicon by @karsa-mistmere in #4820id-card-lanyardicon by @karsa-mistmere in #4819carton/carton-offfrom lab by @karsa-mistmere in #4818Full Changelog: lucide-icons/lucide@1.42.0...1.43.0
react/react (react)
v19.3.0Compare Source
react/react (react-dom)
v19.3.0Compare Source
react-hook-form/react-hook-form (react-hook-form)
v7.88.0: Version 7.88.0Compare Source
✨ Features
🐞 Fixes
resetField()(#13735)replace()(#13734)reset()duringhandleSubmit()(#13733)trigger()targets their parent (#13732)handleSubmit()(#13731)trigger()targets a field with only nested resolver errors (#13730)useWatchcompute cache not being initialized with the initial output (#13728)FileListbeing lost during flatten/expand and omit undefined values injsonToFormData(#13725)schemaErrorLookupreporting nested containers as exact-name errors (#13727)isValidatingnot being recomputed afterunregister()clears validating fields (#13723)reset()(#13722)iterateFieldsByActiononly breaking out of one loop level (#13718)setError()overwrites (#13716)reset()not clearing validating fields (#13714)remove()leaking deleted values onto surviving field-array items (#13713)validateFieldcallingsetCustomValidityonce per key in validate-object mode (#13707)useFieldArrayfocus behavior for checkboxes and radio buttons in appended rows (#13705)getFieldStatereadingisValidatingfrom the supplied form state (#13704)unregister()stripping kept values from the submit payload (#13703)useFormStatenot re-subscribing when control changes (#13702)reset()keepingdirtyFieldsout of sync withisDirtywhenkeepValuesis enabled (#13701)useFormnot reconciling correctly when an Activity subtree is initially hidden (#13698)delayErrortimer fires (#13697)cloneObjectthrowing when checkingBlobwithinstanceof(#13694)useFieldArrayretaining stale fields after an Activity subtree reconnects (#13688)🧹 Refactors
_isTrackedto the remaining multi-key proxy/subscribe form-state checks (#13699)_isTrackedhelper for proxy/subscribe form-state checks (#13690)abortEarlyparameter fromiterateFieldsByAction(#13689)clearErrors(#13696)📝 Documentation
useWatchcompute example variable names in JSDoc (#13700)📦 Dependencies
joifrom 18.2.1 to 18.2.5 (#13719)❤️ Thank You
open-circle/valibot (valibot)
v1.5.0Compare Source
Many thanks to @tats-u, @idleberg, @yslpn, @francisjohnjohnston-web, @MaxFreedomPollard, @mahirhir, @ItzXynx, @LeSingh1, @maxtaran2010, @ysknsid25, @cyyynthia, @spokodev and @sanjibani for contributing to this release.
codePoints,maxCodePoints,minCodePointsandnotCodePointsvalidation actions to validate the number of Unicode code points (pull request #888)ksuidvalidation action to validate KSUIDs (pull request #1370)_getStandardPropsutility with_standardSchema(pull request #1534)urlaction to useURL.canParsewhen available to avoid constructing URL objects (pull request #1608)stringifyJsonaction to preserve the dataset value whenJSON.stringifyreturnsundefined(pull request #1476)literalschema andvalue,values,notValueandnotValuesactions to treatNaNas equal to itself (pull request #1573)intersectschema to merge matchingNaNvalues and invalid dates (pull request #1573)cacheandcacheAsyncmethods to clone the issues of a cached dataset, preventing parent schemas from adding their path item to the same issue on every cache hit (pull request #1620)strictObject,looseObject,objectWithRestand their async variants to correctly handle unknown input keys that collide withObject.prototypemembers (pull request #1523)intersectandintersectAsyncschemas to ignore inherited properties when merging objects and preserve own properties without invoking inherited setters or changing the output prototype (pull request #1621)ulidaction to reject ULIDs that exceed the maximum 128-bit value (pull request #1498)emailaction to reject non-ASCII characters accepted by Unicode case folding (pull request #1075)vitejs/vite (vite)
v8.3.0Compare Source
Features
Bug Fixes
node_modulespath segments as dependencies (fix #17467) (#23437) (ef0dc17)Performance Improvements
Configuration
📅 Schedule: (in timezone Europe/London)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.