Skip to content

chore(deps): Update all non-major dependencies - #191

Merged
chertik77 merged 1 commit into
mainfrom
renovate/all-minor-patch
Sep 15, 2026
Merged

chertik77 merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@better-auth/passkey (source) ^1.7.2 → ^1.7.4 age confidence
@eslint-react/eslint-plugin (source) ^5.18.7 → ^5.19.0 age confidence
@tanstack/react-router (source) 1.170.32 → 1.170.35 age confidence
@tanstack/router-plugin (source) ^1.168.35 → ^1.168.37 age confidence
@thesvg/react (source) ^3.3.2 → ^3.3.4 age confidence
@types/node (source) ^25.9.5 → ^25.9.6 age confidence
@types/react (source) ^19.2.18 → ^19.3.0 age confidence
@types/react-dom (source) ^19.2.7 → ^19.3.0 age confidence
better-auth (source) ^1.7.2 → ^1.7.4 age confidence
lint-staged ^17.5.0 → ^17.5.1 age confidence
lucide-react (source) ^1.41.0 → ^1.45.0 age confidence
react (source) ^19.2.8 → ^19.3.0 age confidence
react-dom (source) ^19.2.8 → ^19.3.0 age confidence
react-hook-form (source) 7.87.0 → 7.88.0 age confidence
typescript-eslint (source) ^8.69.0 → ^8.70.0 age confidence
valibot (source) ^1.4.2 → ^1.5.0 age confidence
vite (source) ^8.2.2 → ^8.3.0 age confidence

Release Notes

better-auth/better-auth (@​better-auth/passkey)

v1.7.4

Compare Source

v1.7.3

Compare Source

TanStack/router (@​tanstack/react-router)

v1.170.35

Compare Source

Patch Changes
  • #​7824 8c43c71 - Upgrade TanStack Store to 0.11 and migrate router subscriptions to useSelector, preserving selector comparisons and Vue subscription cleanup.

v1.170.34

Compare Source

Patch Changes
  • #​8279 aee42c6 - Avoid allocating event-handler arrays and wrapper functions for links without user-supplied event handlers.

  • #​8308 9c1871c - Validate navigation and redirect destinations, keep ambiguous relative URLs on the current origin, and constrain prerender requests and output paths. Prevent redirect headers from appearing in serialized server function response bodies.

    Preserve native form HTTP redirects, route error handling and masks for document redirects, and per-navigation destinations for shared loader redirects. Avoid redundant origin parsing and reduce link styling and server-rendering work. Configured origins must already be normalized.

    Keep blocked-link inactive props consistent during React hydration, honor explicit redirect Location headers before checking route options, and refresh Vue link state when destinations become internal. Reuse the protocol-relative URL check while parsing redirect schemes once.

    Reduce React link bundle size by sharing pathname comparisons, state-prop selection, and element creation.

    Share normalized pathname comparisons in Solid and Vue links to reduce bundle size.

  • #​8311 9aec5a7 - React Links resolve state props without temporary class-name arrays or unnecessary style copies.

  • Updated dependencies [f9836f1, 9c1871c, 9871c06, 0654c0a]:

v1.170.33

Compare Source

Patch Changes
  • #​8165 2f20c00 - Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.

  • #​8209 28a5e45 - Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components and onCatch callbacks as unknown. Solid boundary errors remain typed as Error; SSR now wraps non-Error loader errors to match Solid’s native boundary behavior, preserving the original value in cause. Router state and loader onError values are unchanged.

    When upgrading React or Vue, narrow boundary errors (for example, with error instanceof Error) before reading message or stack. ErrorComponentProps<TError> remains available for values narrowed to a specific error type. Route onError types are unchanged.

  • #​8161 f0b5eda - Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.

  • #​8251 0497cae - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.

  • #​8169 0caf6b9 - Fix route-scoped useMatch, useSearch, and useParams APIs to forward the shouldThrow option and preserve optional return types when shouldThrow: false.

  • #​8257 cf166d1 - Fix repeated innerHTML writes for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.

  • Updated dependencies [edf0e16, 2f20c00, 28a5e45, 08eff50, 216c0c4, 2f91503, f0b5eda, 50eafca, 0497cae, ee28348, 9035abc, c18e690]:

TanStack/router (@​tanstack/router-plugin)

v1.168.37

Compare Source

Patch Changes

v1.168.36

Compare Source

Patch Changes
glincker/thesvg (@​thesvg/react)

v3.3.4

Compare Source

Patch Changes
  • feat: add Fennec browser icon (#​993)
better-auth/better-auth (better-auth)

v1.7.4

Compare Source

Patch Changes

v1.7.3

Compare Source

Patch Changes
  • #​11060 3660f06 Thanks @​bytaesu! - Handle malformed custom-scheme callback URLs without excessive processing.

  • #​11037 5bd7096 Thanks @​bytaesu! - Prevent repeated TOTP enrollment from replacing an active authenticator and its backup codes.

  • #​11120 7ec7146 Thanks @​onmax! - Prevent getSession from failing when cookie caching is disabled while clients still have cached session cookies.

  • #​9908 76d311f Thanks @​harshil1712! - Add Cloudflare as a built-in social provider, with support for client-secret authentication and PKCE clients without a secret.

  • #​11188 c47b765 Thanks @​bytaesu! - Normalize Auth0 domains without a potentially slow trailing-slash regular expression.

  • #​11084 2d5c63d Thanks @​bytaesu! - Prevent duplicate session requests and hydration mismatches when using the Vue client with Nuxt useFetch.

  • #​11147 a9d8c12 Thanks @​bytaesu! - Add isPasswordCompromised for checking passwords against Have I Been Pwned in custom server-side flows, while ignoring padded response entries with zero occurrences.

  • #​10988 9fc7498 Thanks @​bytaesu! - Run callback hooks after proxied OAuth sign-ins and preserve server state when callback cookies are unavailable. The legacy /oauth-proxy-callback endpoint is deprecated and will be removed in the next minor release.

  • #​11178 be0e007 Thanks @​bytaesu! - Report missing tables, missing columns, and required columns Better Auth never writes during initialization, with guidance for fixing them. Kysely checks the live database schema. Authentication requests await the same check and are rejected if the schema does not match.

    Validation is enabled by default, including in production. Set advanced.database.validateSchema: false to disable runtime validation. auth migrate refuses to apply changes when required unwritten columns need manual repair.

  • #​11069 0bb0dbf Thanks @​bytaesu! - Improve dynamic organization role permission check performance.

  • #​11153 2220ee7 Thanks @​bytaesu! - Restore sign-in compatibility with 1.6 databases by identifying accounts with (providerId, accountId) and removing the issuer requirement introduced in 1.7.0. Upgrading from 1.6 no longer requires an account schema migration. Ambiguous account keys are rejected instead of selecting an arbitrary account.

    If you applied the 1.7.0 through 1.7.2 account schema, remove its issuer unique index before upgrading. For SQL databases, also make issuer nullable or remove the column so sign-ups and account linking can succeed. auth migrate does not perform this cleanup. Follow the upgrade guide for database-specific steps.

  • #​10978 5fe5bc2 Thanks @​BetterAndBetterII! - Skip a generic OAuth provider when discovery fails instead of taking down the rest of the auth API.

  • #​10963 74a7369 Thanks @​thisismert! - Track email OTP sign-ins in the last login method plugin.

  • #​11085 e16b40a Thanks @​bytaesu! - Provide type-safe Nuxt useFetch integration for the Vue client's useSession hook.

  • #​11066 c0444dc Thanks @​bytaesu! - Upgrade the packaged Zod dependency to 4.5. Generated OpenAPI schemas now mark required request fields consistently with runtime validation, including passkey registration responses.

  • Updated dependencies [352d012, 76d311f, 3e9e197, 157ec8d, baa08f4, 9e36635, be0e007, a2bae0c, 1a1b7d5, 2220ee7]:

lint-staged/lint-staged (lint-staged)

v17.5.1

Compare Source

Patch Changes
  • #​1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

lucide-icons/lucide (lucide-react)

v1.45.0: Version 1.45.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.44.0...1.45.0

v1.44.0: Version 1.44.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.43.0...1.44.0

v1.43.0: Version 1.43.0

Compare Source

What's Changed

Full Changelog: lucide-icons/lucide@1.42.0...1.43.0

react/react (react)

v19.3.0

Compare Source

react/react (react-dom)

v19.3.0

Compare Source

react-hook-form/react-hook-form (react-hook-form)

v7.88.0: Version 7.88.0

Compare Source

✨ Features

  • Add Error Message component (#​13472)
  • Add the Error Message component for displaying validation errors from React Hook Form.

🐞 Fixes

  • Fix stale validating state after resetField() (#​13735)
  • Fix errors and touched state remaining for rows removed by replace() (#​13734)
  • Fix stale resolver results updating form state after reset() during handleSubmit() (#​13733)
  • Fix nested registered errors being removed when trigger() targets their parent (#​13732)
  • Fix resolver-reported root errors being dropped during handleSubmit() (#​13731)
  • Fix parent errors being incorrectly set when trigger() targets a field with only nested resolver errors (#​13730)
  • Fix useWatch compute cache not being initialized with the initial output (#​13728)
  • Fix FileList being lost during flatten/expand and omit undefined values in jsonToFormData (#​13725)
  • Fix schemaErrorLookup reporting nested containers as exact-name errors (#​13727)
  • Fix isValidating not being recomputed after unregister() clears validating fields (#​13723)
  • Fix stale resolver state updates after reset() (#​13722)
  • Fix iterateFieldsByAction only breaking out of one loop level (#​13718)
  • Fix stale validation types surviving setError() overwrites (#​13716)
  • Fix reset() not clearing validating fields (#​13714)
  • Fix remove() leaking deleted values onto surviving field-array items (#​13713)
  • Fix the React Server build being unpublished (#​13709)
  • Fix validateField calling setCustomValidity once per key in validate-object mode (#​13707)
  • Fix useFieldArray focus behavior for checkboxes and radio buttons in appended rows (#​13705)
  • Fix getFieldState reading isValidating from the supplied form state (#​13704)
  • Fix unregister() stripping kept values from the submit payload (#​13703)
  • Fix useFormState not re-subscribing when control changes (#​13702)
  • Fix reset() keeping dirtyFields out of sync with isDirty when keepValues is enabled (#​13701)
  • Fix useForm not reconciling correctly when an Activity subtree is initially hidden (#​13698)
  • Fix cleared errors returning after the delayError timer fires (#​13697)
  • Fix cloneObject throwing when checking Blob with instanceof (#​13694)
  • Fix useFieldArray retaining stale fields after an Activity subtree reconnects (#​13688)

🧹 Refactors

  • Extend _isTracked to the remaining multi-key proxy/subscribe form-state checks (#​13699)
  • Extract _isTracked helper for proxy/subscribe form-state checks (#​13690)
  • Remove the unused abortEarly parameter from iterateFieldsByAction (#​13689)
  • Remove redundant optional chaining from clearErrors (#​13696)

📝 Documentation

  • Fix useWatch compute example variable names in JSDoc (#​13700)

📦 Dependencies

❤️ Thank You

open-circle/valibot (valibot)

v1.5.0

Compare Source

Many thanks to @​tats-u, @​idleberg, @​yslpn, @​francisjohnjohnston-web, @​MaxFreedomPollard, @​mahirhir, @​ItzXynx, @​LeSingh1, @​maxtaran2010, @​ysknsid25, @​cyyynthia, @​spokodev and @​sanjibani for contributing to this release.

  • Add codePoints, maxCodePoints, minCodePoints and notCodePoints validation actions to validate the number of Unicode code points (pull request #​888)
  • Add ksuid validation action to validate KSUIDs (pull request #​1370)
  • Change Standard Schema properties to use eager initialization for faster schema construction and replace internal _getStandardProps utility with _standardSchema (pull request #​1534)
  • Change url action to use URL.canParse when available to avoid constructing URL objects (pull request #​1608)
  • Fix stringifyJson action to preserve the dataset value when JSON.stringify returns undefined (pull request #​1476)
  • Fix literal schema and value, values, notValue and notValues actions to treat NaN as equal to itself (pull request #​1573)
  • Fix intersect schema to merge matching NaN values and invalid dates (pull request #​1573)
  • Fix cache and cacheAsync methods to clone the issues of a cached dataset, preventing parent schemas from adding their path item to the same issue on every cache hit (pull request #​1620)
  • Fix strictObject, looseObject, objectWithRest and their async variants to correctly handle unknown input keys that collide with Object.prototype members (pull request #​1523)
  • Fix intersect and intersectAsync schemas to ignore inherited properties when merging objects and preserve own properties without invoking inherited setters or changing the output prototype (pull request #​1621)
  • Fix ulid action to reject ULIDs that exceed the maximum 128-bit value (pull request #​1498)
  • Fix email action to reject non-ASCII characters accepted by Unicode case folding (pull request #​1075)
vitejs/vite (vite)

v8.3.0

Compare Source

Features
  • build: avoid settling seen preload dependencies for performance (#​23446) (e6f6b3e)
Bug Fixes
Performance Improvements

Configuration

📅 Schedule: (in timezone Europe/London)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@vercel

vercel Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
task-pro Ready Ready Preview Sep 14, 2026 11:41pm UTC

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 647dde0 to ae8b41c Compare September 14, 2026 23:39
@chertik77
chertik77 merged commit 7145022 into main Sep 15, 2026
4 checks passed
@chertik77
chertik77 deleted the renovate/all-minor-patch branch September 15, 2026 05:31

This branch was successfully deployed

1 active deployment
Preview — ae8b41cd Deployed Sep 14, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant