Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 44 updates - #281

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-d92dbac6c0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-d92dbac6c0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 44 updates in the / directory:

Package From To
typescript 6.0.3 7.0.2
@astrojs/cloudflare 14.1.4 14.3.3
@hugeicons/core-free-icons 4.2.3 4.3.5
@sentry/browser 10.67.0 11.0.0
@tabler/icons 3.45.0 3.48.0
@tanstack/virtual-core 3.17.5 3.17.11
astro 7.1.3 7.3.5
posthog-js 1.405.3 1.434.13
tailwind-variants 3.2.2 3.3.1
@astrojs/react 6.0.1 7.0.0
@base-ui/react 1.6.0 1.8.0
@tanstack/react-virtual 3.14.7 3.14.13
lucide-react 1.25.0 1.48.0
react 19.2.7 19.3.0
react-dom 19.2.7 19.3.0
shadcn 4.13.1 4.21.0
sonner 2.0.7 2.0.8
tailwind-merge 3.6.0 3.7.0
@astrojs/starlight 0.41.3 0.42.4
sharp 0.35.3 0.35.4
three 0.185.1 0.186.1
@modelcontextprotocol/sdk 1.29.0 1.30.1
pg 8.22.0 8.23.0
@apidevtools/swagger-parser 12.1.0 13.1.0
@aws-sdk/client-s3 3.1091.0 3.1140.0
@babel/parser 8.0.4 8.0.6
@exodus/bytes 1.15.1 1.16.0
@fastify/busboy 3.2.0 3.2.2
@hono/mcp 0.3.1 0.3.2
@hono/node-server 2.0.11 2.1.1
@hono/zod-openapi 1.5.1 1.6.3
@libsql/client 0.17.4 0.18.0
@sentry/bun 10.67.0 11.0.0
@sentry/node 10.67.0 11.0.0
@ungap/structured-clone 1.3.3 1.4.0
add-mcp 1.13.0 2.4.0
drizzle-orm 0.45.2 0.45.3
hono 4.12.31 4.13.9
posthog-node 5.46.0 5.53.0
whatwg-url 17.1.0 17.1.2
ws 8.21.1 8.21.3
yaml 2.9.0 2.9.1
zod 4.4.3 4.6.5
@astrojs/language-server 2.16.12 2.17.1

Updates typescript from 6.0.3 to 7.0.2

Release notes

Sourced from typescript's releases.

TypeScript 7.0.2

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2

Commits
  • 1e4744d Merge branch 'main' into ts7-release
  • a5a219cmicrosoft/typescript-go#4558
  • ecfe30d Update status localization
  • 5de25b5 Hide executable name in TypeScript status
  • d7ce74a Show bundled TypeScript version for packaged servers
  • 29be66a Correct TS 7 release version to 7.0.2
  • ed2bd1b Merge branch 'main' into ts7-release
  • 8873075 Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...
  • 9427131 Set up stable / nightly extension split, other prep (microsoft/typescript-go#...
  • d4eaca5microsoft/typescript-go#4549
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Updates @astrojs/cloudflare from 14.1.4 to 14.3.3

Release notes

Sourced from @​astrojs/cloudflare's releases.

@​astrojs/cloudflare@​14.3.3

Patch Changes

  • #18059 30cb32e Thanks @​Princesseuh! - Fixes image transforms without a specified quality outputting an higher quality than expected on certain formats

  • #18091 28d59a9 Thanks @​astro-factory! - Fixes optimizeDeps.include glob astro/runtime/** matching .d.ts files, which caused 83 unnecessary optimizer entries and empty output chunks per environment during dev

  • #18032 f7dbc6a Thanks @​adamchal! - Fixes image requests when using imageService: 'compile' with passthroughImageService().

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

@​astrojs/cloudflare@​14.3.2

Patch Changes

  • #17958 b95c574 Thanks @​astro-factory! - Fixes a build failure when the wrangler config uses the exports field to declare Durable Object classes

  • #18022 24946f7 Thanks @​matthewp! - Fixes cold astro dev crashes when using the passthrough image service

  • #17842 d68db73 Thanks @​adamchal! - Fixes broken images on static sites by transforming prerendered images at build time with the default Cloudflare Images binding

  • #17945 750b4db Thanks @​matthewp! - Pre-bundles renderer server entrypoints and the default console logger during dev so they are included in the initial optimization pass, preventing a mid-request re-optimization that could crash the dev server on Cloudflare (workerd).

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

@​astrojs/cloudflare@​14.3.1

Patch Changes

  • #17914 a400504 Thanks @​astro-factory! - Fixes a build crash when a custom worker entrypoint exports Durable Object classes alongside prerendered pages. The prerender worker no longer inherits durable_objects, migrations, or workflows from the entry worker config.

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

@​astrojs/cloudflare@​14.3.0

Minor Changes

  • #17795 15e2deb Thanks @​matthewp! - Adds concurrent rendering support for experimental.incrementalBuild, including when using @astrojs/cloudflare

    Incremental builds no longer disable caching when build.concurrency is greater than 1. Projects that set build.concurrency: 1 to keep the cache enabled can remove that workaround. Cloudflare builds also reduce serialization overhead for large prerendered pages.

  • #17887 35aa62e Thanks @​matthewp! - Adds a Cloudflare finalize() response handler for custom request handlers

    Call finalize() to apply cookies and Cloudflare CDN cache defaults to the response from an astro/fetch pipeline:

    import { astro, FetchState } from 'astro/fetch';
    import { cf, finalize } from '@astrojs/cloudflare/fetch';
    export default {
    async fetch(request: Request, env: Env, context: ExecutionContext) {
    const state = new FetchState(request);

... (truncated)

Changelog

Sourced from @​astrojs/cloudflare's changelog.

14.3.3

Patch Changes

  • #18059 30cb32e Thanks @​Princesseuh! - Fixes image transforms without a specified quality outputting an higher quality than expected on certain formats

  • #18091 28d59a9 Thanks @​astro-factory! - Fixes optimizeDeps.include glob astro/runtime/** matching .d.ts files, which caused 83 unnecessary optimizer entries and empty output chunks per environment during dev

  • #18032 f7dbc6a Thanks @​adamchal! - Fixes image requests when using imageService: 'compile' with passthroughImageService().

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

14.3.2

Patch Changes

  • #17958 b95c574 Thanks @​astro-factory! - Fixes a build failure when the wrangler config uses the exports field to declare Durable Object classes

  • #18022 24946f7 Thanks @​matthewp! - Fixes cold astro dev crashes when using the passthrough image service

  • #17842 d68db73 Thanks @​adamchal! - Fixes broken images on static sites by transforming prerendered images at build time with the default Cloudflare Images binding

  • #17945 750b4db Thanks @​matthewp! - Pre-bundles renderer server entrypoints and the default console logger during dev so they are included in the initial optimization pass, preventing a mid-request re-optimization that could crash the dev server on Cloudflare (workerd).

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

14.3.1

Patch Changes

  • #17914 a400504 Thanks @​astro-factory! - Fixes a build crash when a custom worker entrypoint exports Durable Object classes alongside prerendered pages. The prerender worker no longer inherits durable_objects, migrations, or workflows from the entry worker config.

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

14.3.0

Minor Changes

  • #17795 15e2deb Thanks @​matthewp! - Adds concurrent rendering support for experimental.incrementalBuild, including when using @astrojs/cloudflare

    Incremental builds no longer disable caching when build.concurrency is greater than 1. Projects that set build.concurrency: 1 to keep the cache enabled can remove that workaround. Cloudflare builds also reduce serialization overhead for large prerendered pages.

  • #17887 35aa62e Thanks @​matthewp! - Adds a Cloudflare finalize() response handler for custom request handlers

    Call finalize() to apply cookies and Cloudflare CDN cache defaults to the response from an astro/fetch pipeline:

    import { astro, FetchState } from 'astro/fetch';
    import { cf, finalize } from '@astrojs/cloudflare/fetch';

... (truncated)

Commits
  • 790c6f7 [ci] release (#18035)
  • 00393ff Update dependency vitest [SECURITY] (#18026)
  • 28d59a9 fix(cloudflare): restrict optimizeDeps glob to .js files to exclude .d.ts (#1...
  • 40378cc [ci] format
  • 30cb32e fix(cloudflare): set default image transformation quality (#18059)
  • 1e66b14 Update dependency svelte to v5.55.7 [SECURITY] (#18021)
  • 24f63d3 Update dependency hono to v4.13.5 [SECURITY] (#18020)
  • 2245837 fix(astro): stop the head-metadata plugin invalidating its own virtual module...
  • f7dbc6a fix(cloudflare): respect passthrough image service in compile mode (#18032)
  • 8a3106e [ci] release (#17939)
  • Additional commits viewable in compare view

Updates @hugeicons/core-free-icons from 4.2.3 to 4.3.5

Commits

Updates @sentry/browser from 10.67.0 to 11.0.0

Release notes

Sourced from @​sentry/browser's releases.

11.0.0

Version 11.0.0 marks a major release of the Sentry JavaScript SDKs containing breaking changes. The goal of this release is to be better compatible with OpenTelemetry, make our integrations work across Node.js, Cloudflare, Bun and Deno through run-time and build-time instrumentation, and make span streaming and more permissive data collection the default.

How To Upgrade

Please carefully read through the migration guide in the Sentry docs on how to upgrade from version 10 to version 11. Make sure to select your specific platform/framework in the top left corner: https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found within the Sentry JavaScript SDK Repository: https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

Breaking Changes

All SDKs

  • feat: Remove support for initialising via --require (#22513)
  • feat!: Rename deprecated http.* span attributes (#23574)
  • feat!: Rename deprecated net. span attributes (#23301)
  • feat!: Replace skipOpenTelemetrySetup with enableOpenTelemetrySetup (#23199)
  • feat!: Replace the deprecated http.target span attribute (#23575)
  • feat!: Require Node >=20.19.0 as minimum supported version (#22558)
  • feat!: Use handler span op for terminal request handlers (#22871)
  • feat!: Use middleware span op for web-server middleware (#22852)
  • feat(frameworks)!: Use function op for framework functions (#23047)
  • feat(node/cloudflare)!: Remove deprecated honoIntegration (#22480)
  • feat(v11): Drop TypeScript 3.8 support (#18604)

AI integrations

  • feat(langchain): Emit gen_ai.pipeline.name instead of langchain.chain.name (#23740)
  • ref(anthropic)!: Move Anthropic AI integration to @sentry/server-utils (#22954)
  • ref(google-genai)!: Move Google GenAI integration to @sentry/server-utils (#22959)
  • ref(langchain)!: Move LangChain and LangGraph integrations to @sentry/server-utils (#22962)
  • ref(langgraph)!: Drop gen_ai.create_agent spans (#22840)
  • ref(openai)!: Move OpenAI AI integration to @sentry/server-utils (#22953)
  • ref(vercel-ai)!: Move Vercel AI integration to @sentry/server-utils (#22964)
  • ref(workers-ai)!: Move Workers AI integration to @sentry/server-utils (#22960)

@​sentry/angular

  • feat(angular,ember,sveltekit)!: Use router span op for frontend routers (#23086)
  • feat(angular)!: Use ui.mount and function span ops for tracing decorators (#22667)

@​sentry/astro

  • feat(astro)!: Drop support for Astro 3 (#22683)
  • feat(astro)!: Enable orchestrion instrumentation on Cloudflare Workers (#23003)
  • feat(astro)!: Remove deprecated sourceMapsUploadOptions build option (#23630)
  • feat(astro)!: Remove unstable_sentryVitePluginOptions (#23370)
  • ref(astro)!: Migrate import hook to makeOrchestrionLoader (#22861)
  • ref(astro)!: Remove deprecated release/debug conflict workaround from BuildTimeOptionsBase (#23270)

... (truncated)

Changelog

Sourced from @​sentry/browser's changelog.

11.0.0

Version 11.0.0 marks a major release of the Sentry JavaScript SDKs containing breaking changes. The goal of this release is to be better compatible with OpenTelemetry, make our integrations work across Node.js, Cloudflare, Bun and Deno through run-time and build-time instrumentation, and make span streaming and more permissive data collection the default.

How To Upgrade

Please carefully read through the migration guide in the Sentry docs on how to upgrade from version 10 to version 11. Make sure to select your specific platform/framework in the top left corner: https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found within the Sentry JavaScript SDK Repository: https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

Breaking Changes

All SDKs

  • feat: Remove support for initialising via --require (#22513)
  • feat!: Rename deprecated http.* span attributes (#23574)
  • feat!: Rename deprecated net. span attributes (#23301)
  • feat!: Replace skipOpenTelemetrySetup with enableOpenTelemetrySetup (#23199)
  • feat!: Replace the deprecated http.target span attribute (#23575)
  • feat!: Require Node >=20.19.0 as minimum supported version (#22558)
  • feat!: Use handler span op for terminal request handlers (#22871)
  • feat!: Use middleware span op for web-server middleware (#22852)
  • feat(frameworks)!: Use function op for framework functions (#23047)
  • feat(node/cloudflare)!: Remove deprecated honoIntegration (#22480)
  • feat(v11): Drop TypeScript 3.8 support (#18604)

AI integrations

  • feat(langchain): Emit gen_ai.pipeline.name instead of langchain.chain.name (#23740)
  • ref(anthropic)!: Move Anthropic AI integration to @sentry/server-utils (#22954)
  • ref(google-genai)!: Move Google GenAI integration to @sentry/server-utils (#22959)
  • ref(langchain)!: Move LangChain and LangGraph integrations to @sentry/server-utils (#22962)
  • ref(langgraph)!: Drop gen_ai.create_agent spans (#22840)
  • ref(openai)!: Move OpenAI AI integration to @sentry/server-utils (#22953)
  • ref(vercel-ai)!: Move Vercel AI integration to @sentry/server-utils (#22964)
  • ref(workers-ai)!: Move Workers AI integration to @sentry/server-utils (#22960)

@​sentry/angular

  • feat(angular,ember,sveltekit)!: Use router span op for frontend routers (#23086)
  • feat(angular)!: Use ui.mount and function span ops for tracing decorators (#22667)

@​sentry/astro

  • feat(astro)!: Drop support for Astro 3 (#22683)
  • feat(astro)!: Enable orchestrion instrumentation on Cloudflare Workers (#23003)
  • feat(astro)!: Remove deprecated sourceMapsUploadOptions build option (#23630)
  • feat(astro)!: Remove unstable_sentryVitePluginOptions (#23370)
  • ref(astro)!: Migrate import hook to makeOrchestrionLoader (#22861)

... (truncated)

Commits
  • 3e02c87 release: 11.0.0
  • fe07bdf Merge pull request #24620 from getsentry/prepare-release/11.0.0
  • ed38fe7 meta(changelog): Update changelog for 11.0.0
  • ea27349 docs: Fix Solid, SolidStart, and NestJS README snippets (#24571)
  • 84027a1 fix(tanstackstart-react): Reject non-POST requests to the managed tunnel rout...
  • 6a99951 feat(tanstackstart-react): Emit low-cardinality names for function spans (#...
  • 3fdf506 chore: Add external contributor to CHANGELOG.md (#24616)
  • bf7b9b2 fix(cloudflare): Bind pass-through Queue producer methods to the binding (#24...
  • 1960dad fix(server-utils): Stop the orchestrion Vite plugin from adding an empty ssr ...
  • e281d82 chore: Remove CLAUDE.md symlink (#24524)
  • Additional commits viewable in compare view

Updates @tabler/icons from 3.45.0 to 3.48.0

Release notes

Sourced from @​tabler/icons's releases.

Release 3.48.0

18 new icons:

  • outline/duplicate
  • outline/folder-ai
  • outline/folder-sparkle
  • outline/git-branch-check
  • outline/git-branch-x
  • outline/git-merge-queue
  • outline/git-pull-request-locked
  • outline/git-pull-request-unlisted
  • outline/message-2-ai
  • outline/message-2-sparkle
  • outline/message-ai
  • outline/message-sparkle
  • outline/model-ai
  • outline/pencil-ai
  • outline/stack-check
  • outline/stack-minus
  • outline/stack-plus
  • outline/stack-x

Release 3.47.0

18 new icons:

  • outline/airpods-l
  • outline/airpods-r
  • outline/cash-coin
  • outline/edit-bulk
  • outline/folder-stats
  • outline/folder-user
  • outline/gpu-2
  • outline/gpu
  • outline/map-pinned
  • outline/orbit-vertical
  • outline/orbit
  • outline/orbits
  • outline/reduce-motion
  • outline/reference-image
  • outline/secret-phrases
  • outline/sticker-smile
  • outline/voice-2
  • outline/voice

Fixed icon: outline/align-right-2

... (truncated)

Commits
  • 0239805 Release 3.48.0
  • c892ab3 Add duplicate, folder-ai, folder-sparkle, git-branch-*, `git-merge-qu...
  • f27ec33 Update dependencies to fix Dependabot alerts (#1612)
  • 1c54c36 Add security policy (#1611)
  • 87e7c39 Release 3.47.0
  • 9a16e46 Add voice and voice-2 icons (#1610)
  • 3cff1b7 Add airpods-l, airpods-r, folder-stats, folder-user, map-pinned, `r...
  • 4538638 Add cash-coin, edit-bulk and sticker-smile icons (#1607)
  • 2ef62ef Add gpu and gpu-2 icons (#1606)
  • e2087c1 Bump @​angular/compiler from 21.2.5 to 21.2.20 (#1594)
  • Additional commits viewable in compare view

Updates @tanstack/virtual-core from 3.17.5 to 3.17.11

Release notes

Sourced from @​tanstack/virtual-core's releases.

@​tanstack/virtual-core@​3.17.11

Patch Changes

  • #1284 06d1b6b - Read the current scroll offset when the debounced scroll-end fallback fires so measurement adjustments made since the last browser scroll event are not overwritten by stale state.

  • #1248 2c0a0ea - Keep a travelling smooth scrollToIndex alive when content is prepended. With anchorTo: 'end', the prepend anchor sync wrote scrollTop instantly, which cancelled the browser's smooth animation and left the scroll stranded partway; Chromium drops a smooth request re-issued right after such a cancel, so it could not be resumed. The sync is now skipped while a smooth programmatic scroll is still in flight, and the animation continues to its recomputed target. A smooth scroll that has already landed still receives the anchor sync.

@​tanstack/virtual-core@​3.17.10

Patch Changes

  • #1272 ab3278c - Keep an end-pinned virtualizer following appended items when older items are trimmed in the same update and the item count does not increase. Recognize ordered, overlapping windows while preserving reading anchors for users who have scrolled away from the end.

    Preserve item keys in the lazy measurement cache so a stable getItemKey callback reading mutable data cannot change the identity of previously measured rows.

@​tanstack/virtual-core@​3.17.9

Patch Changes

  • #1260 4a0adf3 - Recover the bottom pin when the browser clamps an end-anchored scroll compensation write. resizeItem compensates a size change by writing scrollTop before the consumer has committed the new total size, so when the grown item does not itself extend the scroll range the browser clamps the write to the old maximum and the viewport is left short of the end with no scroll event to correct it. Two cases hit this: paddingEnd > 0 with a growing last item, where the overflowing item only extends scrollHeight to its own end and the clamp lands exactly paddingEnd short (#1258); and a row above the last one growing while the last row keeps its size, under directDomUpdates (#1266). A compensation write whose target exceeds the scroll maximum at write time is now recorded as clamped and re-issued once the sizer has grown — right after notify for consumers that size the container synchronously in onChange, and from _willUpdate for consumers that size it during a render. The clamped read-back keeps the retry pending; any other scroll event cancels it, so a user reading history is never yanked.

@​tanstack/virtual-core@​3.17.8

Patch Changes

  • #1256 a0a411e - Cancel the pending isScrolling reset when a scroll observer is torn down, and reset isScrolling and scrollDirection in cleanup() so they don't stay stuck after the scroll element changes or is removed.

  • #1246 d2cf98b - Ignore connected measurement nodes whose indexes are outside the current item count.

@​tanstack/virtual-core@​3.17.7

Patch Changes

  • #1239 a5417b4 - Fix a one-frame viewport jump when above-viewport rows resize while scrolling up (#1227). resizeItem writes scrollTop synchronously inside the ResizeObserver callback to compensate for the size change, but then notified asynchronously — so the browser could paint a frame with the new scrollTop and the old item transforms, making the content jerk by the resize delta and snap back. When a compensation actually moves the scroll position, resizeItem now notifies synchronously so the transform commit lands in the same paint as the scroll write. Resizes that don't move the scroll position (below-fold measurements, iOS-deferred adjustments) keep the cheaper async notify.

@​tanstack/virtual-core@​3.17.6

Patch Changes

  • #1236 7ae32b5 - Stop the default scroll-adjustment heuristic from drifting the viewport when a viewport-spanning item grows. Previously any item whose top sat above the fold (itemStart < scrollOffset) had its size delta compensated on every re-measure — including a streaming chat message that spans the fold and grows at its bottom, dragging scrollTop downward token by token (#1218). Re-measurements now only compensate items that are entirely above the fold (itemStart + itemSize <= scrollOffset); growth below the anchor point leaves the scroll position untouched. First measurements (estimate→actual) still compensate any above-fold item, and a custom shouldAdjustScrollPositionOnItemSizeChange still overrides the default.
Changelog

Sourced from @​tanstack/virtual-core's changelog.

3.17.11

Patch Changes

  • #1284 06d1b6b - Read the current scroll offset when the debounced scroll-end fallback fires so measurement adjustments made since the last browser scroll event are not overwritten by stale state.

  • #1248 2c0a0ea - Keep a travelling smooth scrollToIndex alive when content is prepended. With anchorTo: 'end', the prepend anchor sync wrote scrollTop instantly, which cancelled the browser's smooth animation and left the scroll stranded partway; Chromium drops a smooth request re-issued right after such a cancel, so it could not be resumed. The sync is now skipped while a smooth programmatic scroll is still in flight, and the animation continues to its recomputed target. A smooth scroll that has already landed still receives the anchor sync.

3.17.10

Patch Changes

  • #1272 ab3278c - Keep an end-pinned virtualizer following appended items when older items are trimmed in the same update and the item count does not increase. Recognize ordered, overlapping windows while preserving reading anchors for users who have scrolled away from the end.

    Preserve item keys in the lazy measurement cache so a stable getItemKey callback reading mutable data cannot change the identity of previously measured rows.

3.17.9

Patch Changes

  • #1260 4a0adf3 - Recover the bottom pin when the browser clamps an end-anchored scroll compensation write. resizeItem compensates a size change by writing scrollTop before the consumer has committed the new total size, so when the grown item does not itself extend the scroll range the browser clamps the write to the old maximum and the viewport is left short of the end with no scroll event to correct it. Two cases hit this: paddingEnd > 0 with a growing last item, where the overflowing item only extends scrollHeight to its own end and the clamp lands exactly paddingEnd short (#1258); and a row above the last one growing while the last row keeps its size, under directDomUpdates (#1266). A compensation write whose target exceeds the scroll maximum at write time is now recorded as clamped and re-issued once the sizer has grown — right after notify for consumers that size the container synchronously in onChange, and from _willUpdate for consumers that size it during a render. The clamped read-back keeps the retry pending; any other scroll event cancels it, so a user reading history is never yanked.

3.17.8

Patch Changes

  • #1256 a0a411e - Cancel the pending isScrolling reset when a scroll observer is torn down, and reset isScrolling and scrollDirection in cleanup() so they don't stay stuck after the scroll element changes or is removed.

  • #1246 d2cf98b - Ignore connected measurement nodes whose indexes are outside the current item count.

3.17.7

Patch Changes

  • #1239 a5417b4 - Fix a one-frame viewport jump when above-viewport rows resize while scrolling up (#1227). resizeItem writes scrollTop synchronously inside the ResizeObserver callback to compensate for the size change, but then notified asynchronously — so the browser could paint a frame with the new scrollTop and the old item transforms, making the content jerk by the resize delta and snap back. When a compensation actually moves the scroll position, resizeItem now notifies synchronously so the transform commit lands in the same paint as the scroll write. Resizes that don't move the scroll position (below-fold measurements, iOS-deferred adjustments) keep the cheaper async notify.

3.17.6

Patch Changes

  • #1236 7ae32b5 - Stop the default scroll-adjustment heuristic from drifting the viewport when a viewport-spanning item grows. Previously any item whose top sat above the fold (itemStart < scrollOffset) had its size delta compensated on every re-measure — including a streaming chat message that spans the fold and grows at its bottom, dragging scrollTop downward token by token (#1218). Re-measurements now only compensate items that are entirely above the fold (itemStart + itemSize <= scrollOffset); growth below the anchor point leaves the scroll position untouched. First measurements (estimate→actual) still compensate any above-fold item, and a custom shouldAdjustScrollPositionOnItemSizeChange still overrides the default.
Commits
  • 78371e8 ci: Version Packages (#1279)
  • 06d1b6b fix(virtual-core): refresh offset in scroll-end fallback (#1284)
  • 2c0a0ea fix(virtual-core): keep a travelling smooth scroll alive through a prepend (#...
  • df47889 ci: Version Packages (#1277)
  • ab3278c fix(virtual-core): preserve measurement keys and follow sliding windows (#1272)
  • 171029d ci: Version Packages (#1269)
  • 4a0adf3 fix(virtual-core): re-issue clamped end-anchor compensation once the sizer gr...
  • e9874f0 ci: Version Packages (#1247)
  • a0a411e fix(virtual-core): cancel the isScrolling debounce on scroll-observer cleanup...
  • d2cf98b fix(virtual-core): ignore stale connected measurements (#1246)
  • Additional commits viewable in compare view

Updates astro from 7.1.3 to 7.3.5

Release notes

Sourced from astro's releases.

astro@7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

astro@7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&#x26;) and named (&amp;) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2

astro@7.3.3

Patch Changes

  • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

…y with 44 updates

Bumps the production-dependencies group with 44 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [@astrojs/cloudflare](https://github.com/withastro/astro/tree/HEAD/packages/integrations/cloudflare) | `14.1.4` | `14.3.3` |
| [@hugeicons/core-free-icons](https://github.com/hugeicons/hugeicons/tree/HEAD/packages/core-free-icons) | `4.2.3` | `4.3.5` |
| [@sentry/browser](https://github.com/getsentry/sentry-javascript) | `10.67.0` | `11.0.0` |
| [@tabler/icons](https://github.com/tabler/tabler-icons) | `3.45.0` | `3.48.0` |
| [@tanstack/virtual-core](https://github.com/TanStack/virtual/tree/HEAD/packages/virtual-core) | `3.17.5` | `3.17.11` |
| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.1.3` | `7.3.5` |
| [posthog-js](https://github.com/PostHog/posthog-js) | `1.405.3` | `1.434.13` |
| [tailwind-variants](https://github.com/heroui-inc/tailwind-variants) | `3.2.2` | `3.3.1` |
| [@astrojs/react](https://github.com/withastro/astro/tree/HEAD/packages/integrations/react) | `6.0.1` | `7.0.0` |
| [@base-ui/react](https://github.com/mui/base-ui/tree/HEAD/packages/react) | `1.6.0` | `1.8.0` |
| [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) | `3.14.7` | `3.14.13` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.25.0` | `1.48.0` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.7` | `19.3.0` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn) | `4.13.1` | `4.21.0` |
| [sonner](https://github.com/emilkowalski/sonner) | `2.0.7` | `2.0.8` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [@astrojs/starlight](https://github.com/withastro/starlight/tree/HEAD/packages/starlight) | `0.41.3` | `0.42.4` |
| [sharp](https://github.com/lovell/sharp) | `0.35.3` | `0.35.4` |
| [three](https://github.com/mrdoob/three.js) | `0.185.1` | `0.186.1` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.1` |
| [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.22.0` | `8.23.0` |
| [@apidevtools/swagger-parser](https://github.com/APIDevTools/swagger-parser) | `12.1.0` | `13.1.0` |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1091.0` | `3.1140.0` |
| [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser) | `8.0.4` | `8.0.6` |
| [@exodus/bytes](https://github.com/ExodusOSS/bytes) | `1.15.1` | `1.16.0` |
| [@fastify/busboy](https://github.com/fastify/busboy) | `3.2.0` | `3.2.2` |
| [@hono/mcp](https://github.com/honojs/middleware/tree/HEAD/packages/mcp) | `0.3.1` | `0.3.2` |
| [@hono/node-server](https://github.com/honojs/node-server) | `2.0.11` | `2.1.1` |
| [@hono/zod-openapi](https://github.com/honojs/middleware/tree/HEAD/packages/zod-openapi) | `1.5.1` | `1.6.3` |
| [@libsql/client](https://github.com/tursodatabase/libsql-client-ts/tree/HEAD/packages/libsql-client) | `0.17.4` | `0.18.0` |
| [@sentry/bun](https://github.com/getsentry/sentry-javascript) | `10.67.0` | `11.0.0` |
| [@sentry/node](https://github.com/getsentry/sentry-javascript) | `10.67.0` | `11.0.0` |
| [@ungap/structured-clone](https://github.com/ungap/structured-clone) | `1.3.3` | `1.4.0` |
| [add-mcp](https://github.com/neon-solutions/add-mcp) | `1.13.0` | `2.4.0` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [hono](https://github.com/honojs/hono) | `4.12.31` | `4.13.9` |
| [posthog-node](https://github.com/PostHog/posthog-js/tree/HEAD/packages/node) | `5.46.0` | `5.53.0` |
| [whatwg-url](https://github.com/jsdom/whatwg-url) | `17.1.0` | `17.1.2` |
| [ws](https://github.com/websockets/ws) | `8.21.1` | `8.21.3` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |
| [@astrojs/language-server](https://github.com/withastro/astro/tree/HEAD/packages/language-tools/language-server) | `2.16.12` | `2.17.1` |



Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v6.0.3...v7.0.2)

Updates `@astrojs/cloudflare` from 14.1.4 to 14.3.3
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/cloudflare/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/cloudflare@14.3.3/packages/integrations/cloudflare)

Updates `@hugeicons/core-free-icons` from 4.2.3 to 4.3.5
- [Commits](https://github.com/hugeicons/hugeicons/commits/HEAD/packages/core-free-icons)

Updates `@sentry/browser` from 10.67.0 to 11.0.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.67.0...11.0.0)

Updates `@tabler/icons` from 3.45.0 to 3.48.0
- [Release notes](https://github.com/tabler/tabler-icons/releases)
- [Commits](tabler/tabler-icons@v3.45.0...v3.48.0)

Updates `@tanstack/virtual-core` from 3.17.5 to 3.17.11
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/virtual-core/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/virtual-core@3.17.11/packages/virtual-core)

Updates `astro` from 7.1.3 to 7.3.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro)

Updates `posthog-js` from 1.405.3 to 1.434.13
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/compare/posthog-js@1.405.3...posthog-js@1.434.13)

Updates `tailwind-variants` from 3.2.2 to 3.3.1
- [Release notes](https://github.com/heroui-inc/tailwind-variants/releases)
- [Changelog](https://github.com/heroui-inc/tailwind-variants/blob/main/CHANGELOG.md)
- [Commits](heroui-inc/tailwind-variants@v3.2.2...v3.3.1)

Updates `@astrojs/react` from 6.0.1 to 7.0.0
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/react/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/react@7.0.0/packages/integrations/react)

Updates `@base-ui/react` from 1.6.0 to 1.8.0
- [Release notes](https://github.com/mui/base-ui/releases)
- [Changelog](https://github.com/mui/base-ui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/base-ui/commits/v1.8.0/packages/react)

Updates `@tanstack/react-virtual` from 3.14.7 to 3.14.13
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/react-virtual/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/react-virtual@3.14.13/packages/react-virtual)

Updates `lucide-react` from 1.25.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `react` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `shadcn` from 4.13.1 to 4.21.0
- [Release notes](https://github.com/shadcn-ui/ui/releases)
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.21.0/packages/shadcn)

Updates `sonner` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/emilkowalski/sonner/releases)
- [Commits](emilkowalski/sonner@v2.0.7...v2.0.8)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `@astrojs/starlight` from 0.41.3 to 0.42.4
- [Release notes](https://github.com/withastro/starlight/releases)
- [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md)
- [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.42.4/packages/starlight)

Updates `sharp` from 0.35.3 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.3...v0.35.4)

Updates `three` from 0.185.1 to 0.186.1
- [Release notes](https://github.com/mrdoob/three.js/releases)
- [Commits](https://github.com/mrdoob/three.js/commits)

Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.30.1)

Updates `pg` from 8.22.0 to 8.23.0
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.0/packages/pg)

Updates `@apidevtools/swagger-parser` from 12.1.0 to 13.1.0
- [Release notes](https://github.com/APIDevTools/swagger-parser/releases)
- [Changelog](https://github.com/APIDevTools/swagger-parser/blob/main/CHANGELOG.md)
- [Commits](APIDevTools/swagger-parser@v12.1.0...v13.1.0)

Updates `@aws-sdk/client-s3` from 3.1091.0 to 3.1140.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/clients/client-s3)

Updates `@babel/parser` from 8.0.4 to 8.0.6
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v8.0.6/packages/babel-parser)

Updates `@exodus/bytes` from 1.15.1 to 1.16.0
- [Release notes](https://github.com/ExodusOSS/bytes/releases)
- [Commits](ExodusOSS/bytes@v1.15.1...v1.16.0)

Updates `@fastify/busboy` from 3.2.0 to 3.2.2
- [Release notes](https://github.com/fastify/busboy/releases)
- [Commits](fastify/busboy@v3.2.0...v3.2.2)

Updates `@hono/mcp` from 0.3.1 to 0.3.2
- [Release notes](https://github.com/honojs/middleware/releases)
- [Changelog](https://github.com/honojs/middleware/blob/main/packages/mcp/CHANGELOG.md)
- [Commits](https://github.com/honojs/middleware/commits/@hono/mcp@0.3.2/packages/mcp)

Updates `@hono/node-server` from 2.0.11 to 2.1.1
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v2.0.11...v2.1.1)

Updates `@hono/zod-openapi` from 1.5.1 to 1.6.3
- [Release notes](https://github.com/honojs/middleware/releases)
- [Changelog](https://github.com/honojs/middleware/blob/main/packages/zod-openapi/CHANGELOG.md)
- [Commits](https://github.com/honojs/middleware/commits/@hono/zod-openapi@1.6.3/packages/zod-openapi)

Updates `@libsql/client` from 0.17.4 to 0.18.0
- [Release notes](https://github.com/tursodatabase/libsql-client-ts/releases)
- [Changelog](https://github.com/tursodatabase/libsql-client-ts/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tursodatabase/libsql-client-ts/commits/v0.18.0/packages/libsql-client)

Updates `@sentry/bun` from 10.67.0 to 11.0.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.67.0...11.0.0)

Updates `@sentry/node` from 10.67.0 to 11.0.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.67.0...11.0.0)

Updates `@ungap/structured-clone` from 1.3.3 to 1.4.0
- [Commits](ungap/structured-clone@v1.3.3...v1.4.0)

Updates `add-mcp` from 1.13.0 to 2.4.0
- [Release notes](https://github.com/neon-solutions/add-mcp/releases)
- [Changelog](https://github.com/neon-solutions/add-mcp/blob/main/CHANGELOG.md)
- [Commits](neon-solutions/add-mcp@v1.13.0...v2.4.0)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `hono` from 4.12.31 to 4.13.9
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.31...v4.13.9)

Updates `posthog-node` from 5.46.0 to 5.53.0
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/commits/posthog-node@5.53.0/packages/node)

Updates `whatwg-url` from 17.1.0 to 17.1.2
- [Release notes](https://github.com/jsdom/whatwg-url/releases)
- [Commits](jsdom/whatwg-url@v17.1.0...v17.1.2)

Updates `ws` from 8.21.1 to 8.21.3
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.1...8.21.3)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

Updates `@astrojs/language-server` from 2.16.12 to 2.17.1
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/language-tools/language-server/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/language-server@2.17.1/packages/language-tools/language-server)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@astrojs/cloudflare"
  dependency-version: 14.3.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@hugeicons/core-free-icons"
  dependency-version: 4.3.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@sentry/browser"
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@tabler/icons"
  dependency-version: 3.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@tanstack/virtual-core"
  dependency-version: 3.17.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: astro
  dependency-version: 7.3.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: posthog-js
  dependency-version: 1.434.13
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: tailwind-variants
  dependency-version: 3.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@astrojs/react"
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@base-ui/react"
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@tanstack/react-virtual"
  dependency-version: 3.14.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: shadcn
  dependency-version: 4.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: sonner
  dependency-version: 2.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@astrojs/starlight"
  dependency-version: 0.42.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: three
  dependency-version: 0.186.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: pg
  dependency-version: 8.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@apidevtools/swagger-parser"
  dependency-version: 13.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@babel/parser"
  dependency-version: 8.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@exodus/bytes"
  dependency-version: 1.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@fastify/busboy"
  dependency-version: 3.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@hono/mcp"
  dependency-version: 0.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@hono/zod-openapi"
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@libsql/client"
  dependency-version: 0.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@sentry/bun"
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@sentry/node"
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: "@ungap/structured-clone"
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: add-mcp
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: hono
  dependency-version: 4.13.9
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: posthog-node
  dependency-version: 5.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: whatwg-url
  dependency-version: 17.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: ws
  dependency-version: 8.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@astrojs/language-server"
  dependency-version: 2.17.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: spiritledsoftware/caplets/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 179e491d-654f-4c17-9796-f004974698b2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​tanstack/​react-virtual@​3.14.7 ⏵ 3.14.13100 +110069 +196 -1100
Updated@​base-ui/​react@​1.6.0 ⏵ 1.8.07210089 +194100
Updated@​tanstack/​virtual-core@​3.17.5 ⏵ 3.17.1199 +110073 +196100
Updated@​types/​pg@​8.20.0 ⏵ 8.23.1100 +110073 +190100
Updated@​types/​react-dom@​19.2.3 ⏵ 19.3.0100 +110075 +192100
Updated@​sentry/​node@​10.67.0 ⏵ 11.0.076 -22100100 +596 +1100
Updated@​types/​react@​19.2.17 ⏵ 19.3.0100 +110079 +193100
Updatedposthog-node@​5.46.0 ⏵ 5.53.092 +2010079 +1100100
Updated@​babel/​parser@​8.0.4 ⏵ 8.0.61001008097 +2100
Updated@​astrojs/​language-server@​2.16.12 ⏵ 2.17.19810080 +196 +2100
Updatedlucide-react@​1.25.0 ⏵ 1.48.010010098 +196 +180
Updatedposthog-js@​1.405.3 ⏵ 1.434.139810083 +2100100
Updatedsonner@​2.0.7 ⏵ 2.0.810010083 +183100
Updatedreact@​19.2.7 ⏵ 19.3.0100 +110084 +197100
Updated@​astrojs/​cloudflare@​14.1.4 ⏵ 14.3.310010084 +197100
Updated@​astrojs/​starlight@​0.41.3 ⏵ 0.42.499 +110085 +197 +2100
Updatedtailwind-merge@​3.6.0 ⏵ 3.7.0100 +110086 +195100
Updated@​ungap/​structured-clone@​1.3.3 ⏵ 1.4.0100 +110099 +186100
Updatedtailwind-variants@​3.2.2 ⏵ 3.3.1100 +1100100 +186 +2100
Updatedpg@​8.22.0 ⏵ 8.23.099 +1100100 +187100
Updated@​hono/​mcp@​0.3.1 ⏵ 0.3.29810095 +187 -4100
Updated@​libsql/​client@​0.17.4 ⏵ 0.18.0100 +1100100 +188100
Updatedastro@​7.1.3 ⏵ 7.3.598 +1100 +7588 +197100
Addeddrizzle-orm@​0.45.3981008898100
Updated@​sentry/​bun@​10.67.0 ⏵ 11.0.0981009096 +1100
Addedyaml@​2.9.110010010090100
Updated@​hono/​node-server@​2.0.11 ⏵ 2.1.1100 +110010090 -1100
Updated@​sentry/​browser@​10.67.0 ⏵ 11.0.099 +211009196 +1100
Updated@​fastify/​busboy@​3.2.0 ⏵ 3.2.2100 +110010091100
Updatedshadcn@​4.13.1 ⏵ 4.21.09810091 +196 -1100
Updated@​apidevtools/​swagger-parser@​12.1.0 ⏵ 13.1.09910010092 +3100
See 13 more rows in the dashboard

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm sentry under LicenseRef-FSL-1.1-ALv2

License: LicenseRef-FSL-1.1-ALv2 - The applicable license policy does not permit this license (5) (package/LICENSE.md)

From: pnpm-lock.yaml → npm/@sentry/node@11.0.0 → npm/sentry@0.44.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/sentry@0.44.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants