Skip to content

build(deps): bump the production-dependencies group with 18 updates - #120

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-ef43044807
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-ef43044807

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 18 updates:

Package From To
@a2a-js/sdk 1.1.0 1.2.0
@larksuiteoapi/node-sdk 1.73.3 1.74.0
@node-rs/argon2 2.2.0 2.2.1
drizzle-orm 0.45.2 0.45.3
hono 4.13.5 4.13.8
marked 18.0.11 18.0.14
openid-client 6.8.7 6.8.8
undici 7.29.0 7.29.1
yaml 2.9.0 2.9.1
@codemirror/commands 6.11.0 6.11.1
@codemirror/state 6.7.2 6.7.6
@codemirror/view 6.43.11 6.43.13
@tanstack/react-query 5.102.8 5.103.2
antd 6.6.2 6.6.5
react 19.2.8 19.3.0
react-dom 19.2.8 19.3.0
react-hook-form 7.87.0 7.88.0
react-router-dom 7.18.3 7.18.4

Updates @a2a-js/sdk from 1.1.0 to 1.2.0

Release notes

Sourced from @​a2a-js/sdk's releases.

v1.2.0

1.2.0 (2026-09-18)

Features

  • server: Introduce SettleByTaskId method (#692) (e856bda)

Bug Fixes

  • accept GetExtendedAgentCard JSON-RPC calls with omitted params (#687) (047d970)
  • avoid mutating caller message configuration (#725) (e3a6428)
  • client: cache the extended Agent Card only after signature verification (#711) (55b601c)
  • guard terminal state transitions and make cancelTask atomic (#636) (7b87c94)
  • preserve call context for JSON-RPC tenant requests (#708) (ae20aca)
  • preserve HeadersInit in authenticating fetch (#721) (f8c33fa)
  • preserve historyLength=0 and reject invalid REST listTasks pageSize (#685) (32c1865)
  • reject empty task IDs with RequestMalformedError in getTask/cancelTask (#629) (71aae97)
  • reject invalid ListTasks status filters with RequestMalformedError (#631) (a881fae)
  • reject missing required extensions before mutating task history (#690) (3b4ef3f)
  • reject whitespace-only taskId on sendMessage (#689) (85227a0)
  • return 404/-32001 for missing push notification configs (#630) (34f06e3)
  • scope ExecutionEventBusManager by tenant and owner to match TaskStore (#707) (69d8899)
  • stamp the resolved taskId onto sendMessage push configs (#688) (cfb19a8)
Changelog

Sourced from @​a2a-js/sdk's changelog.

1.2.0 (2026-09-18)

Features

  • server: Introduce SettleByTaskId method (#692) (e856bda)

Bug Fixes

  • accept GetExtendedAgentCard JSON-RPC calls with omitted params (#687) (047d970)
  • avoid mutating caller message configuration (#725) (e3a6428)
  • client: cache the extended Agent Card only after signature verification (#711) (55b601c)
  • guard terminal state transitions and make cancelTask atomic (#636) (7b87c94)
  • preserve call context for JSON-RPC tenant requests (#708) (ae20aca)
  • preserve HeadersInit in authenticating fetch (#721) (f8c33fa)
  • preserve historyLength=0 and reject invalid REST listTasks pageSize (#685) (32c1865)
  • reject empty task IDs with RequestMalformedError in getTask/cancelTask (#629) (71aae97)
  • reject invalid ListTasks status filters with RequestMalformedError (#631) (a881fae)
  • reject missing required extensions before mutating task history (#690) (3b4ef3f)
  • reject whitespace-only taskId on sendMessage (#689) (85227a0)
  • return 404/-32001 for missing push notification configs (#630) (34f06e3)
  • scope ExecutionEventBusManager by tenant and owner to match TaskStore (#707) (69d8899)
  • stamp the resolved taskId onto sendMessage push configs (#688) (cfb19a8)
Commits
  • 685cf31 chore(main): release 1.2.0 (#677)
  • ad59828 chore(deps-dev): bump brace-expansion from 1.1.12 to 1.1.18 (#597)
  • 32c1865 fix: preserve historyLength=0 and reject invalid REST listTasks pageSize (#685)
  • bae0e6d chore(deps-dev): bump form-data from 2.5.5 to 2.5.6 in /src/samples (#530)
  • d9c57d5 chore(deps-dev): bump simple-git from 3.33.0 to 3.36.0 (#460)
  • af0ba50 chore(deps): bump postcss from 8.5.6 to 8.5.14 (#461)
  • b8477e3 chore(deps-dev): bump @​tootallnate/once from 2.0.0 to 2.0.1 in /src/samples (...
  • 3b4ef3f fix: reject missing required extensions before mutating task history (#690)
  • bab7ede chore(deps): bump nanoid from 3.3.11 to 3.3.18 (#702)
  • 0cffaf3 chore(deps-dev): bump js-yaml from 4.1.1 to 4.3.2 (#731)
  • Additional commits viewable in compare view

Updates @larksuiteoapi/node-sdk from 1.73.3 to 1.74.0

Commits

Updates @node-rs/argon2 from 2.2.0 to 2.2.1

Commits

Updates drizzle-orm from 0.45.2 to 0.45.3

Release notes

Sourced from drizzle-orm's releases.

0.45.3

New Netlify DB Driver

Note: The Netlify DB driver is developed and maintained by the Netlify team.

Installation:

npm i @netlify/db

Usage example:

import { drizzle } from 'drizzle-orm/netlify-db';
// reads NETLIFY_DB_URL and NETLIFY_DB_DRIVER env vars
const db = drizzle();
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';
const db = drizzle(process.env.DATABASE_URL);
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';

// Explicit client — consumer controls the driver
const db = drizzle({ client: netlifyDbClient });

const result = await db.execute('select 1');
Commits
  • 15454db +
  • 54e436f exclude gel from pull
  • 0fd1cc6 remove gel
  • d028db7 skip gel
  • 93dc01e [All-kit]: Warn when journal timestamps can cause migrations to be skipped (#...
  • b786252 Merge pull request #6049 from drizzle-team/drizzle-kit-announcements
  • f9fc5bf Add drizzle-kit announcement manifest and schema doc
  • 9d64532 Merge pull request #6004 from drizzle-team/pin-npm-11-main
  • 0af2f2e Pin the release npm self-update to major 11: the npm 12.0.0 tarball is missin...
  • 6968638 Merge pull request #6001 from drizzle-team/release-router-dispatch-inputs
  • Additional commits viewable in compare view

Updates hono from 4.13.5 to 4.13.8

Release notes

Sourced from hono's releases.

v4.13.8

What's Changed

Full Changelog: honojs/hono@v4.13.7...v4.13.8

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

Commits
  • 098e119 4.13.8
  • e8c8c21 perf(jsx/dom): optimize matching-head child lookup during reconciliation (#5329)
  • 8755b17 docs(combine): fix except() JSDoc param and add missing @​returns (#5346)
  • edd138e fix(request): keep the request media type when reusing a cached body (#5366)
  • 9b4e9c2 fix(accept): clamp a negative q to 0, not 1 (#5357)
  • 65cff90 fix(accept): treat the q parameter name as case-insensitive (#5349)
  • f147de5 fix(accepts, language): skip accept entries with quality 0 when matching (#5311)
  • 90e1b94 fix(aws-lambda): respect backpressure when streaming the response body (#5351)
  • 7792f5d perf(jsx/dom): reduce lookup work for large keyed updates (#5340)
  • e7b38ee docs: fix typos in code comments and link third-party middleware section (#5343)
  • Additional commits viewable in compare view

Updates marked from 18.0.11 to 18.0.14

Release notes

Sourced from marked's releases.

v18.0.14

18.0.14 (2026-09-22)

Bug Fixes

v18.0.13

18.0.13 (2026-09-12)

Bug Fixes

  • allow tabs in the thematic break that ends a list item (#4087) (afbb27c)
  • avoid O(n^2) scanning in reflinkSearch (#4090) (c6a25bb)
  • case fold reference link labels (#4077) (aed9336)
  • drop the leading whitespace after a hard line break (#4075) (123ce04)
  • match html block start conditions when ending a list item (#4072) (c2facac)
  • respect raw tokens when closing link labels (#4066) (ef394f7)
  • strip a tab that follows spaces in an indented code block (#4080) (dbb393d)

v18.0.12

18.0.12 (2026-09-07)

Bug Fixes

  • allow a tab before the closing sequence of an ATX heading (#4084) (4417582)
  • allow one more level of nested brackets in a link label (#4064) (37b28d8)
  • do not add a newline to an empty code block (#4073) (23b1706)
  • escape character references in autolink destinations (#4053) (8f432f0)
  • reject GFM email autolink when the domain ends in _ or - (#4063) (df57534)
  • reject invalid characters in HTML tag names (#4083) (300bb1d)
  • remove up to the fence indentation from each content line (#4074) (0244f08)
Commits

Updates openid-client from 6.8.7 to 6.8.8

Release notes

Sourced from openid-client's releases.

v6.8.8

Fixes

  • apply the default HTTP request timeout (af32783)
  • calculate token lifetimes using elapsed time (e816bf0)
  • isolate lazy client authentication handler caches (d687796)
  • passport: handle rejected async verification callbacks (d730f80)
  • preserve clock settings across DCR nonce retries (5433d68)
  • release: separate changelog sections (57fcbc6)
  • retain polling abort signals through response processing (b26170e)
  • select a unique decryption key when kid is omitted (10ba026)

Refactor

  • share grant polling lifecycle and retry handling (b931c40)
Changelog

Sourced from openid-client's changelog.

6.8.8 (2026-09-05)

Fixes

  • apply the default HTTP request timeout (af32783)
  • calculate token lifetimes using elapsed time (e816bf0)
  • isolate lazy client authentication handler caches (d687796)
  • passport: handle rejected async verification callbacks (d730f80)
  • preserve clock settings across DCR nonce retries (5433d68)
  • release: separate changelog sections (57fcbc6)
  • retain polling abort signals through response processing (b26170e)
  • select a unique decryption key when kid is omitted (10ba026)

Refactor

  • share grant polling lifecycle and retry handling (b931c40)
Commits
  • 04c5982 chore(release): 6.8.8
  • 5eccf2e chore: bump packages
  • d730f80 fix(passport): handle rejected async verification callbacks
  • b931c40 refactor: share grant polling lifecycle and retry handling
  • d687796 fix: isolate lazy client authentication handler caches
  • e816bf0 fix: calculate token lifetimes using elapsed time
  • 10ba026 fix: select a unique decryption key when kid is omitted
  • b26170e fix: retain polling abort signals through response processing
  • af32783 fix: apply the default HTTP request timeout
  • 5433d68 fix: preserve clock settings across DCR nonce retries
  • Additional commits viewable in compare view

Updates undici from 7.29.0 to 7.29.1

Release notes

Sourced from undici's releases.

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits
  • d39a83e Bumped v7.29.1 (#5772)
  • 0d88464 fix(test): remove unused EventEmitter import
  • f57411b perf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5769)
  • 3c67265 fix(retry): settle exposed body on terminal failure
  • cd8af90 fix(retry): validate resumed response framing
  • 6615e01 fix(websocket): reject unrequested subprotocols
  • 2c7d7e1 fix(decompress): limit decompressed response size
  • b6c5a00 fix(cache): do not cache Set-Cookie in shared caches
  • 21693f4 fix(interceptor/dump): abort oversized chunked responses
  • f690157 fix: preserve BalancedPool connection options
  • Additional commits viewable in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates @codemirror/commands from 6.11.0 to 6.11.1

Commits

Updates @codemirror/state from 6.7.2 to 6.7.6

Commits

Updates @codemirror/view from 6.43.11 to 6.43.13

Commits

Updates @tanstack/react-query from 5.102.8 to 5.103.2

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.103.2
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query-next-experimental@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query-persist-client@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.103.2
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query@​5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2

@​tanstack/react-query-devtools@​5.103.1

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.103.1
    • @​tanstack/react-query@​5.103.1

@​tanstack/react-query-next-experimental@​5.103.1

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.103.1

@​tanstack/react-query-persist-client@​5.103.1

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.103.1
    • @​tanstack/react-query@​5.103.1

@​tanstack/react-query@​5.103.1

Patch Changes

... (truncated)

Changelog

Sourced from @​tanstack/react-query's changelog.

5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2

5.103.1

Patch Changes

5.103.0

Patch Changes

Commits
  • e0f6c55 ci: Version Packages (#11525)
  • c08f576 ci: Version Packages (#11511)
  • 19ccf27 ci: Version Packages (#11339)
  • 2da46cd chore(*): use eslint description syntax for grandfathered 'no-restricted-synt...
  • 58ad3e2 fix: isolate TypeScript test output (#11503)
  • d63afc7 Simplifed query methods/internal tests new lint (#11347)
  • 23fbdc3 test({react,preact,solid,angular}-query): remove 'fromGenericOptionsQueryFn' ...
  • 50680b9 test({react,preact,solid,svelte}-query,angular-query-experimental): rename 'm...
  • 0b326b6 test({react,preact}-query/useMutation): add tests for 'MutationFunctionContex...
  • a1119e5 ref(hydration): remove outdated dehydratedAt fallback (#11436)
  • Additional commits viewable in compare view

Updates antd from 6.6.2 to 6.6.5

Release notes

Sourced from antd's releases.

6.6.5

  • 🐞 Fix numeric 0 content rendering across Result, message, notification, Avatar, Modal, Descriptions, and Form.Item. #59153 #59125 #59289 @​bhumin18 @​nrps9909 @​QDyanbing
  • Upload
    • 🐞 Fix Upload.Dragger custom style.height being overridden when the height prop is not set. #59319 @​dogledogle
    • ♿ Fix Upload file names being focusable as buttons when no preview action is available. #59295 @​QDyanbing
  • Transfer
    • 🐞 Fix Transfer calling a stale onSelectChange callback after it is replaced or removed. #59307 @​yunfeizhu
    • 🐞 Fix Transfer footer callbacks not receiving direction when using rest parameters. #59303 @​QDyanbing
  • 🐞 Fix Avatar not retrying image loading after srcSet changes. #59297 @​QDyanbing
  • 🐞 Fix Anchor scrolling and Table and Transfer range selection using stale values after updates. #59308 @​QDyanbing
  • 🐞 Fix Select inconsistent single and multiple heights after customizing global fontSize or lineHeight. #59298 @​zombieJ
  • 🤖 Fix Tooltip, Popover, Popconfirm, and Slider TypeScript definitions accepting unsupported rc Tooltip props. #59288 @​QDyanbing
  • 🛎 Fix Drawer not warning that destroyOnClose is deprecated. #59299 @​dogledogle

  • 🐞 修复 Result、message、notification、Avatar、Modal、Descriptions 和 Form.Item 无法正确渲染数值 0 内容的问题。#59153 #59125 #59289 @​bhumin18 @​nrps9909 @​QDyanbing
  • Upload
    • 🐞 修复 Upload.Dragger 未设置 height 属性时自定义 style.height 被覆盖的问题。#59319 @​dogledogle
    • ♿ 修复 Upload 没有可用预览操作时文件名仍可作为按钮聚焦的问题。#59295 @​QDyanbing
  • Transfer
    • 🐞 修复 Transfer 在替换或移除 onSelectChange 后仍调用旧回调的问题。#59307 @​yunfeizhu
    • 🐞 修复 Transfer 使用剩余参数的 footer 回调无法获取 direction 的问题。#59303 @​QDyanbing
  • 🐞 修复 Avatar 图片加载失败后更新 srcSet 无法重新加载的问题。#59297 @​QDyanbing
  • 🐞 修复 Anchor 滚动及 Table 和 Transfer 范围选择在更新后仍使用旧值的问题。#59308 @​QDyanbing
  • 🐞 修复 Select 自定义全局 fontSize 或 lineHeight 后单选与多选高度不一致的问题。#59298 @​zombieJ
  • 🤖 修正 Tooltip、Popover、Popconfirm 和 Slider 的 TypeScript 类型定义,避免接受实际无效的 rc Tooltip 属性。#59288 @​QDyanbing
  • 🛎 修复 Drawer 未提示 destroyOnClose 已废弃的问题。#59299 @​dogledogle

6.6.4

  • 🗑 Deprecate legacy Avatar GroupProps, BackTop and FloatButton BackTopProps, Input GroupProps, Mentions OptionProps, and Select OptionProps types in favor of GetProps or option-derived types. #58949 @​li-jia-nan
  • 🐞 Fix AutoComplete missing classNames.clear and styles.clear semantic customizations for the clear button. #59245 @​lazerg
  • Table
    • 🐞 Fix Table filteredValue being ignored when responsive columns are hidden.

Bumps the production-dependencies group with 18 updates:

| Package | From | To |
| --- | --- | --- |
| [@a2a-js/sdk](https://github.com/a2aproject/a2a-js) | `1.1.0` | `1.2.0` |
| [@larksuiteoapi/node-sdk](https://github.com/larksuite/node-sdk) | `1.73.3` | `1.74.0` |
| [@node-rs/argon2](https://github.com/napi-rs/node-rs) | `2.2.0` | `2.2.1` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [hono](https://github.com/honojs/hono) | `4.13.5` | `4.13.8` |
| [marked](https://github.com/markedjs/marked) | `18.0.11` | `18.0.14` |
| [openid-client](https://github.com/panva/openid-client) | `6.8.7` | `6.8.8` |
| [undici](https://github.com/nodejs/undici) | `7.29.0` | `7.29.1` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [@codemirror/commands](https://github.com/codemirror/commands) | `6.11.0` | `6.11.1` |
| [@codemirror/state](https://github.com/codemirror/state) | `6.7.2` | `6.7.6` |
| [@codemirror/view](https://github.com/codemirror/view) | `6.43.11` | `6.43.13` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.102.8` | `5.103.2` |
| [antd](https://github.com/ant-design/ant-design) | `6.6.2` | `6.6.5` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.87.0` | `7.88.0` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.18.3` | `7.18.4` |


Updates `@a2a-js/sdk` from 1.1.0 to 1.2.0
- [Release notes](https://github.com/a2aproject/a2a-js/releases)
- [Changelog](https://github.com/a2aproject/a2a-js/blob/main/CHANGELOG.md)
- [Commits](a2aproject/a2a-js@v1.1.0...v1.2.0)

Updates `@larksuiteoapi/node-sdk` from 1.73.3 to 1.74.0
- [Commits](https://github.com/larksuite/node-sdk/commits)

Updates `@node-rs/argon2` from 2.2.0 to 2.2.1
- [Release notes](https://github.com/napi-rs/node-rs/releases)
- [Commits](https://github.com/napi-rs/node-rs/compare/@node-rs/argon2@2.2.0...@node-rs/argon2@2.2.1)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `hono` from 4.13.5 to 4.13.8
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.5...v4.13.8)

Updates `marked` from 18.0.11 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.11...v18.0.14)

Updates `openid-client` from 6.8.7 to 6.8.8
- [Release notes](https://github.com/panva/openid-client/releases)
- [Changelog](https://github.com/panva/openid-client/blob/main/CHANGELOG.md)
- [Commits](panva/openid-client@v6.8.7...v6.8.8)

Updates `undici` from 7.29.0 to 7.29.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.29.1)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `@codemirror/commands` from 6.11.0 to 6.11.1
- [Changelog](https://github.com/codemirror/commands/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/commands/commits)

Updates `@codemirror/state` from 6.7.2 to 6.7.6
- [Changelog](https://github.com/codemirror/state/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/state/commits)

Updates `@codemirror/view` from 6.43.11 to 6.43.13
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)

Updates `@tanstack/react-query` from 5.102.8 to 5.103.2
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.103.2/packages/react-query)

Updates `antd` from 6.6.2 to 6.6.5
- [Release notes](https://github.com/ant-design/ant-design/releases)
- [Changelog](https://github.com/ant-design/ant-design/blob/master/CHANGELOG.en-US.md)
- [Commits](ant-design/ant-design@6.6.2...6.6.5)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `react-hook-form` from 7.87.0 to 7.88.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.87.0...v7.88.0)

Updates `react-router-dom` from 7.18.3 to 7.18.4
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom)

---
updated-dependencies:
- dependency-name: "@a2a-js/sdk"
  dependency-version: 1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@larksuiteoapi/node-sdk"
  dependency-version: 1.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@node-rs/argon2"
  dependency-version: 2.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: hono
  dependency-version: 4.13.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: openid-client
  dependency-version: 6.8.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: undici
  dependency-version: 7.29.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@codemirror/commands"
  dependency-version: 6.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@codemirror/state"
  dependency-version: 6.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@codemirror/view"
  dependency-version: 6.43.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.103.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: antd
  dependency-version: 6.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-hook-form
  dependency-version: 7.88.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-router-dom
  dependency-version: 7.18.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-ef43044807 branch October 2, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants