-
Notifications
You must be signed in to change notification settings - Fork 0
deps: bump the dependencies-minor group across 1 directory with 14 updates #17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
deps: bump the dependencies-minor group across 1 directory with 14 updates #17
Conversation
…dates Bumps the dependencies-minor group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@fontsource-variable/figtree](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/figtree) | `5.2.8` | `5.2.10` | | [@fontsource/ibm-plex-mono](https://github.com/fontsource/font-files/tree/HEAD/fonts/google/ibm-plex-mono) | `5.2.6` | `5.2.7` | | [@hookform/resolvers](https://github.com/react-hook-form/resolvers) | `5.1.1` | `5.2.2` | | [@oddbird/css-anchor-positioning](https://github.com/oddbird/css-anchor-positioning) | `0.6.1` | `0.7.0` | | [next](https://github.com/vercel/next.js) | `15.5.2` | `15.5.4` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.1.0` | `19.2.0` | | [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.1.8` | `19.2.2` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.1.0` | `19.2.0` | | [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.1.6` | `19.2.1` | | [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.60.0` | `7.64.0` | | [zod](https://github.com/colinhacks/zod) | `4.1.5` | `4.1.12` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.54.1` | `1.56.0` | | [sass](https://github.com/sass/dart-sass) | `1.89.2` | `1.93.2` | | [typescript](https://github.com/microsoft/TypeScript) | `5.8.3` | `5.9.3` | Updates `@fontsource-variable/figtree` from 5.2.8 to 5.2.10 - [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md) - [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/figtree) Updates `@fontsource/ibm-plex-mono` from 5.2.6 to 5.2.7 - [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md) - [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/google/ibm-plex-mono) Updates `@hookform/resolvers` from 5.1.1 to 5.2.2 - [Release notes](https://github.com/react-hook-form/resolvers/releases) - [Commits](react-hook-form/resolvers@v5.1.1...v5.2.2) Updates `@oddbird/css-anchor-positioning` from 0.6.1 to 0.7.0 - [Release notes](https://github.com/oddbird/css-anchor-positioning/releases) - [Changelog](https://github.com/oddbird/css-anchor-positioning/blob/main/CHANGELOG.md) - [Commits](oddbird/css-anchor-positioning@v0.6.1...v0.7.0) Updates `next` from 15.5.2 to 15.5.4 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v15.5.2...v15.5.4) Updates `react` from 19.1.0 to 19.2.0 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.0/packages/react) Updates `@types/react` from 19.1.8 to 19.2.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `react-dom` from 19.1.0 to 19.2.0 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.0/packages/react-dom) Updates `@types/react-dom` from 19.1.6 to 19.2.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `react-hook-form` from 7.60.0 to 7.64.0 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](react-hook-form/react-hook-form@v7.60.0...v7.64.0) Updates `zod` from 4.1.5 to 4.1.12 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.1.5...v4.1.12) Updates `@playwright/test` from 1.54.1 to 1.56.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.54.1...v1.56.0) Updates `@types/react` from 19.1.8 to 19.2.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `@types/react-dom` from 19.1.6 to 19.2.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `sass` from 1.89.2 to 1.93.2 - [Release notes](https://github.com/sass/dart-sass/releases) - [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md) - [Commits](sass/dart-sass@1.89.2...1.93.2) Updates `typescript` from 5.8.3 to 5.9.3 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml) - [Commits](microsoft/TypeScript@v5.8.3...v5.9.3) --- updated-dependencies: - dependency-name: "@fontsource-variable/figtree" dependency-version: 5.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: "@fontsource/ibm-plex-mono" dependency-version: 5.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: "@hookform/resolvers" dependency-version: 5.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@oddbird/css-anchor-positioning" dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: next dependency-version: 15.5.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: react dependency-version: 19.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react" dependency-version: 19.2.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: react-dom dependency-version: 19.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react-dom" dependency-version: 19.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: react-hook-form dependency-version: 7.64.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: zod dependency-version: 4.1.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies-minor - dependency-name: "@playwright/test" dependency-version: 1.56.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react" dependency-version: 19.2.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: "@types/react-dom" dependency-version: 19.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: sass dependency-version: 1.93.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor - dependency-name: typescript dependency-version: 5.9.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies-minor ... Signed-off-by: dependabot[bot] <[email protected]>
✓ Safe to upgradeI recommend merging this upgrade because the changes are primarily minor version updates that include bug fixes and new features without introducing breaking changes that affect this codebase. The application already meets the Node.js requirement, doesn't use any deprecated APIs that were flagged, doesn't use useFieldArray from react-hook-form, and doesn't have ESLint plugin configurations that would be affected by the flat config changes. The CVE-2025-29927 security vulnerability is resolved by upgrading Next.js to the patched version. The application uses standard React Hook Form patterns that remain compatible with the upgraded version, and no useId API is used that would be affected by the prefix change in React. What we checked
Dependency UsageThis Next.js application is built around three core form-based features (email collection, rate limiting demo, and support requests) that use React Hook Form with Zod schema validation for type-safe data handling. The application employs custom fonts (Figtree Variable for sans-serif, IBM Plex Mono for code) and a CSS anchor positioning polyfill to support modern UI patterns across browsers, with Playwright providing end-to-end testing infrastructure. The dependency distribution reflects a form-centric architecture with validation and UI polish as primary concerns, while Next.js provides the foundational framework for routing, metadata, and server-side capabilities.
View 47 more usages
Other Usages (49)These usages were analyzed but no breaking changes were detected: @hookform/resolvers
next
react
react-hook-form
zod
@playwright/test
ChangesThis update brings 6 breaking changes requiring Node.js 18+ for React packages and introducing a new flat ESLint config default, along with React's new
View 222 more changes
References (9)[1]: Node.js engine requirement is already >=20, meeting React 19.2.0's requirement of Node.js 18 or newer Line 18 in f88a2f4
[2]: Next.js upgraded from 15.5.2 to 15.5.4 (patch version), which includes security fixes for CVE-2025-29927 Line 39 in f88a2f4
[3]: React upgraded from 19.1.0 to 19.2.0 with useId prefix change, but codebase doesn't use useId Line 42 in f88a2f4
[4]: React Hook Form upgraded from 7.60.0 to 7.64.0 with useFieldArray field ids removal, but codebase doesn't use useFieldArray Line 44 in f88a2f4
[5]: Uses standard useForm hook from react-hook-form which remains fully compatible
[6]: Uses standard useForm hook from react-hook-form which remains fully compatible example-nextjsu/components/RLForm.tsx Line 5 in f88a2f4
[7]: Middleware implementation uses nosecone wrapper and doesn't manually handle x-middleware-subrequest headers Line 40 in f88a2f4
[8]: React 19.2.0 useId prefix change only affects applications using the useId hook for View Transitions (source link) [9]: CVE-2025-29927 is patched in Next.js 15.2.3+, and this upgrade includes the fix (source link) fossabot analyzed this PR using static analysis and dependency research. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the dependencies-minor group with 14 updates in the / directory:
5.2.85.2.105.2.65.2.75.1.15.2.20.6.10.7.015.5.215.5.419.1.019.2.019.1.819.2.219.1.019.2.019.1.619.2.17.60.07.64.04.1.54.1.121.54.11.56.01.89.21.93.25.8.35.9.3Updates
@fontsource-variable/figtreefrom 5.2.8 to 5.2.10Commits
Updates
@fontsource/ibm-plex-monofrom 5.2.6 to 5.2.7Commits
Updates
@hookform/resolversfrom 5.1.1 to 5.2.2Release notes
Sourced from
@hookform/resolvers's releases.Commits
e95721dfix(zod): fix output type for Zod 4 resolver (#803)49a0d7bfix: discriminated union for zod v4 mini (#784)bc09647fix(zod): fix output type for Zod 4 resolver (#801)2d28e6afix: zod v4 peer deps (#798)f040039feat(ajv): add ajv-formats for ajvResolver (#797)Updates
@oddbird/css-anchor-positioningfrom 0.6.1 to 0.7.0Release notes
Sourced from
@oddbird/css-anchor-positioning's releases.Commits
40f3a89v0.7.0db16313Work with anchor and target inside same shadow root (#353)b18b8edMerge pull request #352 from oddbird/dependabot/npm_and_yarn/dev-9d451710aaea505c5Merge pull request #351 from oddbird/dependabot/npm_and_yarn/prod-8404f4c51fd4bbb67chore(deps-dev): Bump the dev group with 13 updatesae3512fchore(deps): Bump the prod group with 2 updates2f9b4c5Merge pull request #348 from oddbird/dependabot/npm_and_yarn/npm_and_yarn-f5c...98ccee3chore(deps-dev): Bump vite in the npm_and_yarn group across 1 directory15ebcc0Merge pull request #346 from oddbird/dependabot/github_actions/actions/setup-...2cc99a6Merge pull request #347 from oddbird/dependabot/github_actions/actions/setup-...Updates
nextfrom 15.5.2 to 15.5.4Release notes
Sourced from next's releases.
Commits
40f1d78v15.5.4cb30f0a[backport] docs: september improvements and fixes (#83997)b6a32bb[backport] [CNA] use linter preference (#83194) (#84087)26d61f1[backport] Turbopack: flush Node.js worker IPC on error (#84079)e11e87a[backport] fix: error overlay not closing when backdrop clicked (#83981) (#83...0a29888[backport] fix: devtools initial position should be from next config (#83571)...7a53950[backport] Turbopack: don't treat metadata routes as RSC (#83804)050bdf1[backport] Turbopack: throw large static metadata error earlier (#83816)1f6ea09[backport] Turbopack: Improve handling of symlink resolution errors (#83805)c7d1855[backport] CI: use KV for test timing data (#83860)Updates
reactfrom 19.1.0 to 19.2.0Release notes
Sourced from react's releases.
... (truncated)
Changelog
Sourced from react's changelog.
... (truncated)
Commits
5667a41Bump next prerelease version numbers (#34639)8bb7241Bump useEffectEvent to Canary (#34610)e3c9656Ensure Performance Track are Clamped and Don't overlap (#34509)68f00c9Release Activity in Canary (#34374)0e10ee9[Reconciler] Set ProfileMode for Host Root Fiber by default in dev (#34432)3bf8ab4Add missing Activity export to development mode (#34439)1549bda[Flight] Only assign_storein dev mode when creating lazy types (#34354)bb6f0c8[Flight] Fix wrong missing key warning when static child is blocked (#34350)05addfcUpdate Flow to 0.266 (#34271)ec5dd0aUpdate Flow to 0.257 (#34253)Updates
@types/reactfrom 19.1.8 to 19.2.2Commits
Updates
react-domfrom 19.1.0 to 19.2.0Release notes
Sourced from react-dom's releases.
... (truncated)
Changelog
Sourced from react-dom's changelog.
... (truncated)
Commits
8618113Bump scheduler version (#34671)1bd1f01Ship partial-prerendering APIs to Canary (#34633)2f0649a[Fizz] Removenonceoption from resume-and-prerender APIs (#34664)5667a41Bump next prerelease version numbers (#34639)e08f53bMatchreact-dom/statictest entrypoints and published entrypoints (#34599)8bb7241Bump useEffectEvent to Canary (#34610)83c88adHandle fabric root level fragment with compareDocumentPosition (#34533)68f00c9Release Activity in Canary (#34374)3168e08[flags] enable opt-in for enableDefaultTransitionIndicator (#34373)3434ff4Add scrollIntoView to fragment instances (#32814)Updates
@types/react-domfrom 19.1.6 to 19.2.1Commits
Updates
react-hook-formfrom 7.60.0 to 7.64.0Release notes
Sourced from react-hook-form's releases.
... (truncated)
Commits
87d8b777.64.06c3b8f7🥃 chore: upgrade dev deps (#13076)23c699a✂ chore: remove unused field ids ref in useFieldArray (#13066)37f51ac🐞 fix: preserve Controller's defaultValue with shouldUnregister prop (#13063)8d61561🚏 Support optional array fields in PathValueImpl type (#13057)b5b73297.63.086a7fb3🐞 fix: only excuse trigger function when deps has a valid array (#13056)4bfd420🏔️ chore: major dev deps upgrade (#13053)66b7daf🔩 chore: lib dev deps upgrade (#13051)62b26d8🐿️ chore: remove duplicated function isMessage (#13050)Updates
zodfrom 4.1.5 to 4.1.12Release notes
Sourced from zod's releases.
... (truncated)
Commits
3b94610v4.1.1277c3c9fExport bg.tsaf44738Fix lintfda4c7cMake docs work without token3fcb20fAdd frrm to ecosystem (#5292)4b1922adocs(content/v4/index): fix zod version (#5289)02a5840refac(errors): Unify code structure and improve types (#5278)62bf4e4fix(ZodError): prevent flatten() from crashing on 'toString' key (#5266)a0abcc0docs(metadata.mdx): fix a mistake in an example output (#5248)c56a4f6docs(ecosystem): addeslint-plugin-zod-x(#5261)Updates
@playwright/testfrom 1.54.1 to 1.56.0Release notes
Sourced from
@playwright/test's releases.