Skip to content

chore(deps)(deps): bump the production-minor-patch group across 1 directory with 23 updates - #131

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-minor-patch-15ad412392
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-minor-patch-15ad412392

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-minor-patch group with 23 updates in the / directory:

Package From To
@upstash/redis 1.38.3 1.39.0
@graphql-tools/schema 10.1.0 10.1.1
zod 4.5.0-canary.20260827T054049 4.6.5
@graphql-tools/graphql-file-loader 8.1.19 8.1.20
@graphql-tools/load 8.1.16 8.1.17
@graphql-tools/utils 12.0.0 12.0.1
@upstash/ratelimit 2.0.8 2.2.0
graphql-ws 6.2.1 6.3.0
jose 6.2.10 6.2.12
@apollo/client 4.3.0-rc.0 4.3.1
@nosecone/next 1.11.0 1.13.0
@tanstack/react-virtual 3.14.10 3.14.13
katex 0.18.4 0.18.9
lucide-react 1.34.0 1.48.0
modern-cmdk 1.2.1 1.2.2
motion 13.1.1 13.4.4
next-intl 4.14.0 4.14.7
nosecone 1.11.0 1.13.0
tailwind-merge 3.6.0 3.7.0
three 0.185.1 0.186.1
@hono/zod-validator 0.9.0 0.9.1
hono 4.13.5 4.13.9
modern-pdf-lib 0.40.2 0.40.3

Updates @upstash/redis from 1.38.3 to 1.39.0

Release notes

Sourced from @​upstash/redis's releases.

@​upstash/redis@​1.39.0

Minor Changes

  • 6801501: Add array commands: arset, armset, arget, armget, argetrange, arscan, argrep, ardel, ardelrange, arcount, arlen, arinsert, arring, arlastitems, arnext, arseek, arop and arinfo, available on the client, in pipelines and in transactions.
  • 3f6e286: Support search indexes over Redis streams: redis.search.createIndex({ dataType: "stream", stream: "events", schema }) indexes every entry of the stream as a document keyed by its entry ID. describe() reports dataType: "stream" with the stream key in prefixes.
  • 33658bc: Add vector index support: redis.vector.createIndex() / redis.vector.index() return a VectorIndex with add, get, query, delete, count, info and drop, backed by the new VECTOR.CREATE, VECTOR.ADD, VECTOR.GET, VECTOR.QUERY, VECTOR.DEL, VECTOR.COUNT, VECTOR.INFO and VECTOR.DROP commands.

@​upstash/redis@​1.39.0-canary-20260826110341-795a33599494ef4034259bd4f7d36db70c44f368

Full Changelog: https://github.com/upstash/redis-js/compare/@​upstash/redis@1.38.3...@​upstash/redis@1.39.0-canary-20260826110341-795a33599494ef4034259bd4f7d36db70c44f368

@​upstash/redis@​1.38.4

Patch Changes

  • 7ac8182: Fix read-your-writes sending a stale upstash-sync-token

    A read issued straight after a write travelled with the token from before that write, so the server was under no obligation to serve the write and readYourWrites silently did not hold.

    HttpClient.request() snapshotted the outgoing headers with mergeHeaders(this.headers, ...) and only afterwards wrote the freshest token into this.headers, so the token learned from response N first shipped with request N+2. The assignment now happens before the merge.

    This regressed in 1.34.5. In 1.34.0–1.34.4 the request options held headers: this.headers by reference, so the late write was still picked up before fetch; 1.34.5 introduced per-request header merging, which turned that reference into a copy without moving the assignment.

Commits

Updates @graphql-tools/schema from 10.1.0 to 10.1.1

Changelog

Sourced from @​graphql-tools/schema's changelog.

10.1.1

Patch Changes

Commits
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 23ca392 chore(deps): update dependency graphql-scalars to v2 (#8385)
  • ce2470a build(deps): bump the actions-deps group with 8 updates (#8377)
  • 0f00a44 chore: use HTTPS git URLs for package repository metadata (#8376)
  • See full diff in compare view

Updates zod from 4.5.0-canary.20260827T054049 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits

Updates @graphql-tools/graphql-file-loader from 8.1.19 to 8.1.20

Changelog

Sourced from @​graphql-tools/graphql-file-loader's changelog.

8.1.20

Patch Changes

Commits
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 04e8159 fix(import): union interfaces, require: paths, comments, webpack esModule (#8...
  • 0f00a44 chore: use HTTPS git URLs for package repository metadata (#8376)
  • See full diff in compare view

Updates @graphql-tools/load from 8.1.16 to 8.1.17

Changelog

Sourced from @​graphql-tools/load's changelog.

8.1.17

Patch Changes

Commits
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 12df2f5 fix(load): support ESM custom loaders (#6660)
  • 04e8159 fix(import): union interfaces, require: paths, comments, webpack esModule (#8...
  • 0f00a44 chore: use HTTPS git URLs for package repository metadata (#8376)
  • 1c1c5a0 fix: load errors, observable cleanup, descriptions, and import attributes (#8...
  • See full diff in compare view

Updates @graphql-tools/utils from 12.0.0 to 12.0.1

Changelog

Sourced from @​graphql-tools/utils's changelog.

12.0.1

Patch Changes

  • #8368 60db079 Thanks @​ardatan! - Omit mutation/subscription from printSchemaWithDirectives when those root types are no longer present on the schema (e.g. after pruneSchema).

  • #8366 57e316d Thanks @​ardatan! - Allow % in paths checked by isValidPath (e.g. directories from URL-encoded repo names).

  • #8370 1c1c5a0 Thanks @​ardatan! - Clean up observableToAsyncIterable queues and unsubscribe when the observable completes, so iterators do not retain references after done. Fixes leak detection flakes related to #8057.

  • #8370 1c1c5a0 Thanks @​ardatan! - Prefer runtime description values over stale astNode descriptions in printSchemaWithDirectives / getDescriptionNode. Fixes #5508.

  • #8423 0b9529f Thanks @​enisdenjo! - Fix prototype pollution in mergeDeep

    Source keys named __proto__, constructor or prototype are now skipped at every recursion level, and the check for an existing key uses hasOwnProperty instead of in, so inherited properties are never used as merge targets.

    Previously, merging untrusted data such as JSON.parse('{"constructor":{"__proto__":{"call":"x"}}}') could reach and overwrite properties on Object.prototype or Function.prototype.

Commits
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 0b9529f Fix prototype pollution in mergeDeep (#8423)
  • 23ca392 chore(deps): update dependency graphql-scalars to v2 (#8385)
  • 60db079 fix(utils): omit pruned root operations from printSchemaWithDirectives (#8368)
  • ce2470a build(deps): bump the actions-deps group with 8 updates (#8377)
  • 0f00a44 chore: use HTTPS git URLs for package repository metadata (#8376)
  • 1c1c5a0 fix: load errors, observable cleanup, descriptions, and import attributes (#8...
  • 57e316d fix: optimize descriptions, isValidPath %, and mock resolverValidationOptions...
  • See full diff in compare view

Updates @upstash/ratelimit from 2.0.8 to 2.2.0

Release notes

Sourced from @​upstash/ratelimit's releases.

v2.2.0

What's Changed

New Contributors

Full Changelog: upstash/ratelimit-js@v2.1.0...v2.2.0

v2.1.0

What's Changed

New Contributors

Full Changelog: upstash/ratelimit-js@v2.0.8...v2.1.0

v2.1.0-rc

What's Changed

Full Changelog: upstash/ratelimit-js@v2.0.8...v2.1.0-rc

Commits
  • fccd840 feat: support decimal values and week unit in duration parser (#158)
  • a955a3c Reject token-bucket requests that exceed the remaining tokens (#156)
  • 8f641c6 fix: avoid negative setTimeout delay in blockUntilReady (#159)
  • 75a956e fix: use last token successfully on cachedFixedWindow cache hits (#157)
  • 7e071b9 feat: run lua scripts with allow-key-locking flag (#154)
  • 89c481b DX-2954: poll npm for the ci version instead of a fixed sleep (#155)
  • 91c0bad chore: add npm bugs and homepage metadata, fix repository URL (#152)
  • f2fc2c7 DX-2861: add sdk telemetry (#153)
  • 5b5448a DX-2479: fix package.version
  • 589cc3e Rename skill from 'ratelimit-ts' to 'upstash-ratelimit-ts'
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​upstash/ratelimit since your current version.


Updates graphql-ws from 6.2.1 to 6.3.0

Release notes

Sourced from graphql-ws's releases.

v6.3.0

Minor Changes

  • #691 b5f53cd Thanks @​niukanen1! - Add onPing and onPong server callbacks to ServerOptions, similar to onConnect and onDisconnect. The callbacks receive the connection Context as the first argument and the ping/pong payload as the second, allowing apps to log or react to subprotocol-level pings with access to connection state. The automatic pong reply is preserved when using the server-level onPing callback; the low-level websocket onPing listener still disables the automatic reply for full manual control.

Patch Changes

v6.2.2

Patch Changes

  • #690 1029314 Thanks @​Haasini-kudala! - Support crossws 0.4 by selecting the GraphQL WebSocket subprotocol during the upgrade handshake. Preserve automatic protocol negotiation in the legacy crossws 0.3 Node and uWebSockets adapters.

  • #686 536960e Thanks @​cpruijsen! - Fix the CrossWS adapter ignoring socket closes issued from server.opened

    makeHooks only registered the peer in the clients map after server.opened returned, while send/close no-op'd unless the peer was already in that map. A protocol-mismatch close (and any other close from inside opened) was therefore dropped, the WebSocket stayed open, and no ConnectionAck was ever sent because the message handler was never installed.

Changelog

Sourced from graphql-ws's changelog.

6.3.0

Minor Changes

  • #691 b5f53cd Thanks @​niukanen1! - Add onPing and onPong server callbacks to ServerOptions, similar to onConnect and onDisconnect. The callbacks receive the connection Context as the first argument and the ping/pong payload as the second, allowing apps to log or react to subprotocol-level pings with access to connection state. The automatic pong reply is preserved when using the server-level onPing callback; the low-level websocket onPing listener still disables the automatic reply for full manual control.

Patch Changes

6.2.2

Patch Changes

  • #690 1029314 Thanks @​Haasini-kudala! - Support crossws 0.4 by selecting the GraphQL WebSocket subprotocol during the upgrade handshake. Preserve automatic protocol negotiation in the legacy crossws 0.3 Node and uWebSockets adapters.

  • #686 536960e Thanks @​cpruijsen! - Fix the CrossWS adapter ignoring socket closes issued from server.opened

    makeHooks only registered the peer in the clients map after server.opened returned, while send/close no-op'd unless the peer was already in that map. A protocol-mismatch close (and any other close from inside opened) was therefore dropped, the WebSocket stayed open, and no ConnectionAck was ever sent because the message handler was never installed.

Commits
  • 53f321e Upcoming Release Changes (#694)
  • 93c8ebf fix: support Object prototype operation IDs (#695)
  • b5f53cd feat(server): add onPing and onPong callbacks to ServerOptions (#691)
  • c41433e Fix the client leaking memory per operation on long-living connections (#693)
  • 0c1765e Upcoming Release Changes (#687)
  • 1029314 fix(crossws): support version 0.4 protocol negotiation (#690)
  • 34cddf6 Update example to remove AsyncGenerator (#654) (#655)
  • 3649fab Update recipes.mdx abruptly closed example (#664)
  • 536960e fix(crossws): close the socket even if server.opened closes immediately (#686)
  • See full diff in compare view

Updates jose from 6.2.10 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)
Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)
Commits
  • 505a55b chore(release): 6.2.12
  • 7bc9a33 perf: encode single-signature JWS input once
  • 78637bd perf: normalize General JWE shared headers once
  • bf5138b perf: deduplicate pending jwks key imports
  • b23a6f3 perf: use native encoding for larger ASCII strings
  • fd3ae3f perf: normalize jwks selection metadata once
  • 6925d43 perf: avoid copying AES-GCM output
  • be62530 docs: clarify and shorten public API guidance
  • 1b41312 build: preserve README when generation fails
  • 0b51829 build: check tree-shaking for every public binding
  • Additional commits viewable in compare view

Updates @apollo/client from 4.3.0-rc.0 to 4.3.1

Release notes

Sourced from @​apollo/client's releases.

@​apollo/client@​4.3.1

Patch Changes

  • #13464 37f700e Thanks @​jerelmiller! - Fix an issue where useLazyQuery did not rerender with new variables until the network request had completed when calling execute with new variables while a request was already in-flight.

@​apollo/client@​4.3.0

Minor Changes

  • #13447 24133fe Thanks @​jerelmiller! - Field policies and inputObjects can now tell the cache whether a field is a list of scalars or a scalar whose value is an array. Previously all arrays were iterated and only the inner type was provided to the scalar parse/serialize functions.

    This required some breaking changes from previous prerelease versions:

    • The field policy scalar option and inputObjects type string now use GraphQL list syntax to mark a field as a list of scalars
    • The abstract cache.getScalarForField is now cache.getScalarTypeForField and is expected to return the string representing the scalar type rather than the Scalar instance
    new InMemoryCache({
      scalars: {
        DateTime: new Scalar(/*...*/),
      },
      inputObjects: {
        EventFilter: {
          fields: {
            // Previously only the scalar type was provided
            datesBefore: "DateTime",
        // List syntax now required
        datesAfter: "[DateTime]",
        dates2d: "[[DateTime]]",
      },
    },
    
    },
    typePolicies: {
    Event: {
    fields: {
    // Previously only the scalar type was provided
    datesBefore: {
    scalar: "DateTime",
    },
        // List syntax now required
        datesAfter: {
          scalar: "[DateTime]",
        },
        dates2d: {
          scalar: "[[DateTime]]",
        },
      },
    },
    
    },

... (truncated)

Changelog

Sourced from @​apollo/client's changelog.

4.3.1

Patch Changes

  • #13464 37f700e Thanks @​jerelmiller! - Fix an issue where useLazyQuery did not rerender with new variables until the network request had completed when calling execute with new variables while a request was already in-flight.

4.3.0

Minor Changes

  • #13447 24133fe Thanks @​jerelmiller! - Field policies and inputObjects can now tell the cache whether a field is a list of scalars or a scalar whose value is an array. Previously all arrays were iterated and only the inner type was provided to the scalar parse/serialize functions.

    This required some breaking changes from previous prerelease versions:

    • The field policy scalar option and inputObjects type string now use GraphQL list syntax to mark a field as a list of scalars
    • The abstract cache.getScalarForField is now cache.getScalarTypeForField and is expected to return the string representing the scalar type rather than the Scalar instance
    new InMemoryCache({
      scalars: {
        DateTime: new Scalar(/*...*/),
      },
      inputObjects: {
        EventFilter: {
          fields: {
            // Previously only the scalar type was provided
            datesBefore: "DateTime",
        // List syntax now required
        datesAfter: "[DateTime]",
        dates2d: "[[DateTime]]",
      },
    },
    
    },
    typePolicies: {
    Event: {
    fields: {
    // Previously only the scalar type was provided
    datesBefore: {
    scalar: "DateTime",
    },
        // List syntax now required
        datesAfter: {
          scalar: "[DateTime]",
        },
        dates2d: {
          scalar: "[[DateTime]]",
        },
      },

... (truncated)

Commits

Updates @nosecone/next from 1.11.0 to 1.13.0

Release notes

Sourced from @​nosecone/next's releases.

v1.13.0

[!NOTE] Guard call labels now allow underscores. These were previously remapped to invalid-label.

1.13.0 (2026-09-16)

🚀 New Features

  • guard: add actor and inputs to every adapter policy (#6277) (cd0355d)
  • guard: check a guard label before sending it (#6289) (19fa51a)
  • sensitive-info-rampart: add classify option for custom runtimes (#6284) (fdaeebb)

🪲 Bug Fixes

  • guard: report the latest reset from a denying rate-limit rule (#6288) (4c71c9c)

📝 Documentation

  • skills: sync Guard policy MCP flow and portable labels (#6293) (0943ee3)

🧹 Miscellaneous Chores

  • deps-dev: bump oxlint, oxfmt, and oxlint-tsgolint (#6286) (fa54554)

📚 Tests

  • track connections so HTTP/2 tests terminate in node 24.20.0 (#6285) (567dc00)

🔨 Build System

v1.12.0

1.12.0 (2026-09-08)

🔒 Security updates

Fixes GHSA-gwjv-qpf9-g36x

🚀 New Features

  • expose client IP provenance and diagnostics (#6259) (b89a486)
  • guard: add Claude Managed Agents as @arcjet/guard/claude-managed-agents/v0 (#6265) (b137824)

... (truncated)

Changelog

Sourced from @​nosecone/next's changelog.

1.13.0 (2026-09-16)

🧹 Miscellaneous Chores

    Description has been truncated

…ectory with 23 updates

Bumps the production-minor-patch group with 23 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@upstash/redis](https://github.com/upstash/redis-js) | `1.38.3` | `1.39.0` |
| [@graphql-tools/schema](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/schema) | `10.1.0` | `10.1.1` |
| [zod](https://github.com/colinhacks/zod) | `4.5.0-canary.20260827T054049` | `4.6.5` |
| [@graphql-tools/graphql-file-loader](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/loaders/graphql-file) | `8.1.19` | `8.1.20` |
| [@graphql-tools/load](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/load) | `8.1.16` | `8.1.17` |
| [@graphql-tools/utils](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/utils) | `12.0.0` | `12.0.1` |
| [@upstash/ratelimit](https://github.com/upstash/ratelimit-js) | `2.0.8` | `2.2.0` |
| [graphql-ws](https://github.com/enisdenjo/graphql-ws) | `6.2.1` | `6.3.0` |
| [jose](https://github.com/panva/jose) | `6.2.10` | `6.2.12` |
| [@apollo/client](https://github.com/apollographql/apollo-client) | `4.3.0-rc.0` | `4.3.1` |
| [@nosecone/next](https://github.com/arcjet/arcjet-js/tree/HEAD/nosecone-next) | `1.11.0` | `1.13.0` |
| [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) | `3.14.10` | `3.14.13` |
| [katex](https://github.com/KaTeX/KaTeX) | `0.18.4` | `0.18.9` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.34.0` | `1.48.0` |
| [modern-cmdk](https://github.com/ABCrimson/modern-cmdk/tree/HEAD/packages/modern-cmdk) | `1.2.1` | `1.2.2` |
| [motion](https://github.com/motiondivision/motion) | `13.1.1` | `13.4.4` |
| [next-intl](https://github.com/amannn/next-intl) | `4.14.0` | `4.14.7` |
| [nosecone](https://github.com/arcjet/arcjet-js/tree/HEAD/nosecone) | `1.11.0` | `1.13.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [three](https://github.com/mrdoob/three.js) | `0.185.1` | `0.186.1` |
| [@hono/zod-validator](https://github.com/honojs/middleware/tree/HEAD/packages/zod-validator) | `0.9.0` | `0.9.1` |
| [hono](https://github.com/honojs/hono) | `4.13.5` | `4.13.9` |
| [modern-pdf-lib](https://github.com/ABCrimson/modern-pdf-lib) | `0.40.2` | `0.40.3` |



Updates `@upstash/redis` from 1.38.3 to 1.39.0
- [Release notes](https://github.com/upstash/redis-js/releases)
- [Commits](https://github.com/upstash/redis-js/compare/@upstash/redis@1.38.3...@upstash/redis@1.39.0)

Updates `@graphql-tools/schema` from 10.1.0 to 10.1.1
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/schema/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/schema@10.1.1/packages/schema)

Updates `zod` from 4.5.0-canary.20260827T054049 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](https://github.com/colinhacks/zod/commits/v4.6.5)

Updates `@graphql-tools/graphql-file-loader` from 8.1.19 to 8.1.20
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/loaders/graphql-file/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/graphql-file-loader@8.1.20/packages/loaders/graphql-file)

Updates `@graphql-tools/load` from 8.1.16 to 8.1.17
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/load/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/load@8.1.17/packages/load)

Updates `@graphql-tools/utils` from 12.0.0 to 12.0.1
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/utils/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/utils@12.0.1/packages/utils)

Updates `@upstash/ratelimit` from 2.0.8 to 2.2.0
- [Release notes](https://github.com/upstash/ratelimit-js/releases)
- [Commits](upstash/ratelimit-js@v2.0.8...v2.2.0)

Updates `graphql-ws` from 6.2.1 to 6.3.0
- [Release notes](https://github.com/enisdenjo/graphql-ws/releases)
- [Changelog](https://github.com/enisdenjo/graphql-ws/blob/master/CHANGELOG.md)
- [Commits](enisdenjo/graphql-ws@v6.2.1...v6.3.0)

Updates `jose` from 6.2.10 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.10...v6.2.12)

Updates `@apollo/client` from 4.3.0-rc.0 to 4.3.1
- [Release notes](https://github.com/apollographql/apollo-client/releases)
- [Changelog](https://github.com/apollographql/apollo-client/blob/main/CHANGELOG.md)
- [Commits](https://github.com/apollographql/apollo-client/compare/@apollo/client@4.3.0-rc.0...@apollo/client@4.3.1)

Updates `@nosecone/next` from 1.11.0 to 1.13.0
- [Release notes](https://github.com/arcjet/arcjet-js/releases)
- [Changelog](https://github.com/arcjet/arcjet-js/blob/main/nosecone-next/CHANGELOG.md)
- [Commits](https://github.com/arcjet/arcjet-js/commits/v1.13.0/nosecone-next)

Updates `@tanstack/react-virtual` from 3.14.10 to 3.14.13
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/react-virtual/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/react-virtual@3.14.13/packages/react-virtual)

Updates `katex` from 0.18.4 to 0.18.9
- [Release notes](https://github.com/KaTeX/KaTeX/releases)
- [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md)
- [Commits](KaTeX/KaTeX@v0.18.4...v0.18.9)

Updates `lucide-react` from 1.34.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `modern-cmdk` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/ABCrimson/modern-cmdk/releases)
- [Changelog](https://github.com/ABCrimson/modern-cmdk/blob/main/packages/modern-cmdk/CHANGELOG.md)
- [Commits](https://github.com/ABCrimson/modern-cmdk/commits/HEAD/packages/modern-cmdk)

Updates `motion` from 13.1.1 to 13.4.4
- [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md)
- [Commits](motiondivision/motion@v13.1.1...v13.4.4)

Updates `next-intl` from 4.14.0 to 4.14.7
- [Release notes](https://github.com/amannn/next-intl/releases)
- [Changelog](https://github.com/amannn/next-intl/blob/main/CHANGELOG.md)
- [Commits](amannn/next-intl@v4.14.0...v4.14.7)

Updates `nosecone` from 1.11.0 to 1.13.0
- [Release notes](https://github.com/arcjet/arcjet-js/releases)
- [Changelog](https://github.com/arcjet/arcjet-js/blob/main/nosecone/CHANGELOG.md)
- [Commits](https://github.com/arcjet/arcjet-js/commits/v1.13.0/nosecone)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `three` from 0.185.1 to 0.186.1
- [Release notes](https://github.com/mrdoob/three.js/releases)
- [Commits](https://github.com/mrdoob/three.js/commits)

Updates `@hono/zod-validator` from 0.9.0 to 0.9.1
- [Release notes](https://github.com/honojs/middleware/releases)
- [Changelog](https://github.com/honojs/middleware/blob/main/packages/zod-validator/CHANGELOG.md)
- [Commits](https://github.com/honojs/middleware/commits/@hono/zod-validator@0.9.1/packages/zod-validator)

Updates `hono` from 4.13.5 to 4.13.9
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.5...v4.13.9)

Updates `modern-pdf-lib` from 0.40.2 to 0.40.3
- [Release notes](https://github.com/ABCrimson/modern-pdf-lib/releases)
- [Changelog](https://github.com/ABCrimson/modern-pdf-lib/blob/master/CHANGELOG.md)
- [Commits](ABCrimson/modern-pdf-lib@v0.40.2...v0.40.3)

---
updated-dependencies:
- dependency-name: "@upstash/redis"
  dependency-version: 1.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@graphql-tools/schema"
  dependency-version: 10.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@graphql-tools/graphql-file-loader"
  dependency-version: 8.1.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: "@graphql-tools/load"
  dependency-version: 8.1.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: "@graphql-tools/utils"
  dependency-version: 12.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: "@upstash/ratelimit"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: graphql-ws
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: jose
  dependency-version: 6.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: "@apollo/client"
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: "@nosecone/next"
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@tanstack/react-virtual"
  dependency-version: 3.14.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: katex
  dependency-version: 0.18.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: modern-cmdk
  dependency-version: 1.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: motion
  dependency-version: 13.4.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: next-intl
  dependency-version: 4.14.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: nosecone
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: three
  dependency-version: 0.186.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@hono/zod-validator"
  dependency-version: 0.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: hono
  dependency-version: 4.13.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: modern-pdf-lib
  dependency-version: 0.40.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nextcalc-pro Ready Ready Preview Sep 28, 2026 1:17pm UTC

@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-minor-patch-15ad412392 branch October 5, 2026 13:14

This branch was successfully deployed

1 active deployment
Preview — 45b5ebaa Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants