Skip to content

chore(deps)(deps): bump the production-dependencies group across 1 directory with 9 updates - #323

Merged
seketman merged 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-b5b0c4a9d5
Oct 4, 2026
Merged

seketman merged 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-b5b0c4a9d5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 9 updates in the / directory:

Package From To
@supabase/ssr 0.12.5 0.12.7
@supabase/supabase-js 2.112.4 2.117.2
lucide-react 1.38.0 1.49.0
next 16.3.4 16.3.8
next-intl 4.14.1 4.14.8
node-html-parser 9.0.2 9.0.4
react 19.2.8 19.3.0
react-dom 19.2.8 19.3.0
tailwind-merge 3.6.0 3.7.0

Updates @supabase/ssr from 0.12.5 to 0.12.7

Release notes

Sourced from @​supabase/ssr's releases.

v0.12.7

0.12.7 (2026-09-08)

Bug Fixes

  • apply non-browser defaults when cookies only sets encode (#294) (9d6e2a5)

v0.12.7-rc.162

What's Changed

Full Changelog: supabase/ssr@v0.12.6...v0.12.7-rc.162

v0.12.6

0.12.6 (2026-09-04)

Bug Fixes

  • avoid duplicate cache headers per server client (#283) (af750e2)

v0.12.6-rc.158

What's Changed

New Contributors

Full Changelog: supabase/ssr@v0.12.5...v0.12.6-rc.158

Changelog

Sourced from @​supabase/ssr's changelog.

0.12.7 (2026-09-08)

Bug Fixes

  • apply non-browser defaults when cookies only sets encode (#294) (9d6e2a5)

0.12.6 (2026-09-04)

Bug Fixes

  • avoid duplicate cache headers per server client (#283) (af750e2)
Commits
  • 9b28f49 chore(main): release 0.12.7 (#295)
  • 9d6e2a5 fix: apply non-browser defaults when cookies only sets encode (#294)
  • 4ed9f65 chore: add workflow for autoclosing stale issues (#292)
  • 71c33a7 chore(main): release 0.12.6 (#291)
  • c7c7e68 docs: fix typos in tsdoc and design doc (#288)
  • af750e2 fix: avoid duplicate cache headers per server client (#283)
  • 905c7c3 build(deps): bump actions/deploy-pages from 5.0.0 to 5.0.1 (#290)
  • 9e2564d chore: update @​supabase/supabase-js to v2.114.0 (#289)
  • See full diff in compare view

Updates @supabase/supabase-js from 2.112.4 to 2.117.2

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.117.2 (2026-09-25)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

2.117.0 (2026-09-22)

🚀 Features

  • auth: enable passkey API by default and deprecate experimental passkey opt-in (#2695)

❤️ Thank You

  • fadymak

2.116.0 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)

🩹 Fixes

  • supabase: warn when schema is passed outside db options (#2663)

❤️ Thank You

2.115.0 (2026-09-03)

🚀 Features

  • postgrest: add getOpenApiSpec() (#2651)

❤️ Thank You

2.114.0 (2026-09-02)

... (truncated)

Commits
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • 739b351 fix(auth): return stored session when a refresh loses to another tab (#2698)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • cc45ccf feat(auth): enable passkey API by default and deprecate experimental passkey ...
  • c511286 docs(realtime): document relationship of accessToken() and heartbeat (#2680)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • 5aedaab feat(auth): add MFA recovery codes API (#2676)
  • e4f675a fix(supabase): warn when schema is passed outside db options (#2663)
  • dbe7679 chore(release): version 2.115.0 changelogs (#2664)
  • 3eb6193 docs(supabase): clarify db.schema needs the second generic (#2662)
  • Additional commits viewable in compare view

Updates lucide-react from 1.38.0 to 1.49.0

Release notes

Sourced from lucide-react's releases.

Version 1.49.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.48.0...1.49.0

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Version 1.47.0

What's Changed

... (truncated)

Commits
  • e042fec fix(packages): declare @types/react as an optional peer dependency (#4892)
  • f06ac67 chore(typchecking): More typecheck jobs for all packages (#4885)
  • 94e4cb9 chore(dependencies): Update dependencies (#4806)
  • 99d25bd feat(packages): extract icon build logic into @lucide/shared (#4409)
  • See full diff in compare view

Updates next from 16.3.4 to 16.3.8

Release notes

Sourced from next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)
Commits
  • b0fad0d v16.3.8
  • 719e4c6 [lts-active] Scope response cache keys to their source route (#218)
  • e92db45 [lts-active] Fix metadata propagation for deduplicated nested caches (#223)
  • 40c2ba9 [lts-active] Match Next data paths case-sensitively (#196)
  • 2d9f50a [lts-active] Fix MCP middleware DNS rebinding (#213)
  • bd9214f [lts-active] Fix draft mode leaks through cross-request 'use cache' dedupli...
  • 8db4a62 [lts-active][webpack] Ensure dynamicParams is respected in `opengraph-image...
  • e002ad6 [lts-active] fix(next/image): Pin DNS resolution when fetching external image...
  • 4c20699 v16.3.7
  • 2521aec [backport] turbo-tasks-backend: fix strongly consistent read hanging on a can...
  • Additional commits viewable in compare view

Updates next-intl from 4.14.1 to 4.14.8

Release notes

Sourced from next-intl's releases.

v4.14.8

4.14.8 (2026-09-29)

Bug Fixes

v4.14.7

4.14.7 (2026-09-24)

Bug Fixes

v4.14.6

4.14.6 (2026-09-21)

Bug Fixes

v4.14.5

4.14.5 (2026-09-14)

Bug Fixes

  • Avoid reading the pathname in useRouter and Link to work better with Cache Components (#2415) (ed97a92) – by @​amannn

v4.14.4

4.14.4 (2026-09-11)

Bug Fixes

v4.14.3

4.14.3 (2026-09-10)

Bug Fixes

v4.14.2

4.14.2 (2026-09-01)

Bug Fixes

Changelog

Sourced from next-intl's changelog.

4.14.8 (2026-09-29)

Bug Fixes

4.14.7 (2026-09-24)

Bug Fixes

4.14.6 (2026-09-21)

Bug Fixes

4.14.5 (2026-09-14)

Bug Fixes

  • Avoid reading the pathname in useRouter and Link to work better with Cache Components (#2415) (ed97a92) – by @​amannn

4.14.4 (2026-09-11)

Bug Fixes

4.14.3 (2026-09-10)

Bug Fixes

4.14.2 (2026-09-01)

Bug Fixes

Commits
  • 274867f v4.14.8
  • 3ef2e6a fix: Keep source order for useExtracted messages on the same line (#2426)
  • edcfaf3 docs: Upgrade Next.js to 16.3.6 in examples and dev deps (GHSA-vcvr-r3jv-pc5j...
  • 83ea3b7 v4.14.7
  • 8df0500 fix: Add optional @types/react peer dependency to support global virtual st...
  • 331b77a v4.14.6
  • 5209b97 fix: Emit source ranges for useTranslations key references in SWC plugin (#...
  • 0e26553 test: await locale cookie checks in base-path navigation (#2418)
  • 7691fca v4.14.5
  • ed97a92 fix: Avoid reading the pathname in useRouter and Link to work better with...
  • Additional commits viewable in compare view

Updates node-html-parser from 9.0.2 to 9.0.4

Changelog

Sourced from node-html-parser's changelog.

9.0.4 (2026-09-07)

9.0.3 (2026-09-03)

Bug Fixes

  • encode special characters in HTMLElement textContent setter (48eb649)
  • keep attributes whose name starts with an underscore (3aff8be), closes #129 #129 #206
  • stop appending a stray '<' to unterminated block-text elements (48300fe)
Commits
  • c0cae42 chore(release): 9.0.4
  • 468e8f2 Merge branch 'adarshx01-fix/unclosed-dt-dd'
  • f561cd0 Merge branch 'fix/unclosed-dt-dd' of github.com:adarshx01/node-html-parser in...
  • 4677000 chore(release): 9.0.3
  • ee9a9e6 Merge pull request #312 from spokodev/fix/textcontent-encode-special-chars
  • 5268108 Merge pull request #313 from spokodev/fix/unterminated-block-text-stray-lt
  • 79008d4 Merge pull request #314 from spokodev/fix/leading-underscore-attributes
  • 3aff8be fix: keep attributes whose name starts with an underscore
  • 48300fe fix: stop appending a stray '<' to unterminated block-text elements
  • 48eb649 fix: encode special characters in HTMLElement textContent setter
  • Additional commits viewable in compare view

Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react's changelog.

19.3.0 (September 9, 2026)

New React Features

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from seketman as a code owner October 1, 2026 20:57
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hitfactor Ready Ready Preview Oct 4, 2026 8:48pm UTC

…rectory with 9 updates

Bumps the production-dependencies group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@supabase/ssr](https://github.com/supabase/ssr) | `0.12.5` | `0.12.7` |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.112.4` | `2.117.2` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.38.0` | `1.49.0` |
| [next](https://github.com/vercel/next.js) | `16.3.4` | `16.3.8` |
| [next-intl](https://github.com/amannn/next-intl) | `4.14.1` | `4.14.8` |
| [node-html-parser](https://github.com/taoqf/node-fast-html-parser) | `9.0.2` | `9.0.4` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |



Updates `@supabase/ssr` from 0.12.5 to 0.12.7
- [Release notes](https://github.com/supabase/ssr/releases)
- [Changelog](https://github.com/supabase/ssr/blob/main/CHANGELOG.md)
- [Commits](supabase/ssr@v0.12.5...v0.12.7)

Updates `@supabase/supabase-js` from 2.112.4 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js)

Updates `lucide-react` from 1.38.0 to 1.49.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.49.0/packages/lucide-react)

Updates `next` from 16.3.4 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.4...v16.3.8)

Updates `next-intl` from 4.14.1 to 4.14.8
- [Release notes](https://github.com/amannn/next-intl/releases)
- [Changelog](https://github.com/amannn/next-intl/blob/main/CHANGELOG.md)
- [Commits](amannn/next-intl@v4.14.1...v4.14.8)

Updates `node-html-parser` from 9.0.2 to 9.0.4
- [Release notes](https://github.com/taoqf/node-fast-html-parser/releases)
- [Changelog](https://github.com/taoqf/node-html-parser/blob/main/CHANGELOG.md)
- [Commits](taoqf/node-html-parser@v9.0.2...v9.0.4)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/[email protected]/packages/tailwind-merge)

---
updated-dependencies:
- dependency-name: "@supabase/ssr"
  dependency-version: 0.12.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.117.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: next-intl
  dependency-version: 4.14.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: node-html-parser
  dependency-version: 9.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot changed the title chore(deps)(deps): bump the production-dependencies group with 9 updates chore(deps)(deps): bump the production-dependencies group across 1 directory with 9 updates Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-b5b0c4a9d5 branch from 32c7923 to d2fd909 Compare October 4, 2026 20:47
@seketman
seketman merged commit 4446c11 into main Oct 4, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-b5b0c4a9d5 branch October 4, 2026 20:51

This branch was successfully deployed

1 active deployment
Preview — d2fd909b Deployed Oct 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant