Skip to content

build(deps): bump the production-dependencies group across 1 directory with 22 updates - #124

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-2c9fbe69db
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-2c9fbe69db

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 22 updates in the / directory:

Package From To
@a2a-js/sdk 1.1.0 1.3.0
@hono/node-server 2.1.1 2.1.3
@larksuiteoapi/node-sdk 1.73.3 1.74.0
@modelcontextprotocol/sdk 1.30.0 1.31.0
@node-rs/argon2 2.2.0 2.2.1
drizzle-orm 0.45.2 0.45.3
hono 4.13.5 4.13.11
marked 18.0.11 18.0.14
openid-client 6.8.7 6.8.8
undici 7.29.0 7.30.0
ws 8.21.3 8.22.0
@types/ws 8.18.1 8.18.2
yaml 2.9.0 2.9.1
@codemirror/commands 6.11.0 6.11.1
@codemirror/state 6.7.2 6.7.6
@codemirror/view 6.43.11 6.43.13
@tanstack/react-query 5.102.8 5.104.0
antd 6.6.2 6.6.5
react 19.2.8 19.3.0
react-dom 19.2.8 19.3.0
react-hook-form 7.87.0 7.89.0
react-router-dom 7.18.3 7.18.4

Updates @a2a-js/sdk from 1.1.0 to 1.3.0

Release notes

Sourced from @​a2a-js/sdk's releases.

v1.3.0

1.3.0 (2026-09-29)

Features

  • server/database: add database-backed task and push notification stores (#756) (0f2e563), closes #114

v1.2.1

1.2.1 (2026-09-24)

Bug Fixes

  • issue that status or artifact events do not propagate the metatadata to the task (#748) (72588af)
  • jsonrpc: return JSON-RPC errors as HTTP 200 and dispatch on A2A-Version (#747) (733259d)
  • rest: ensure taskId is correctly set from path parameters when creating push notification configs (#740) (4a42ec1)
  • server: add optional media type validation against agent defaultInputModes (#745) (27659a2)
  • validate JSON-RPC response version (#698) (e0cdc91)

v1.2.0

1.2.0 (2026-09-18)

Features

  • server: Introduce SettleByTaskId method (#692) (e856bda)

Bug Fixes

  • accept GetExtendedAgentCard JSON-RPC calls with omitted params (#687) (047d970)
  • avoid mutating caller message configuration (#725) (e3a6428)
  • client: cache the extended Agent Card only after signature verification (#711) (55b601c)
  • guard terminal state transitions and make cancelTask atomic (#636) (7b87c94)
  • preserve call context for JSON-RPC tenant requests (#708) (ae20aca)
  • preserve HeadersInit in authenticating fetch (#721) (f8c33fa)
  • preserve historyLength=0 and reject invalid REST listTasks pageSize (#685) (32c1865)
  • reject empty task IDs with RequestMalformedError in getTask/cancelTask (#629) (71aae97)
  • reject invalid ListTasks status filters with RequestMalformedError (#631) (a881fae)
  • reject missing required extensions before mutating task history (#690) (3b4ef3f)
  • reject whitespace-only taskId on sendMessage (#689) (85227a0)
  • return 404/-32001 for missing push notification configs (#630) (34f06e3)
  • scope ExecutionEventBusManager by tenant and owner to match TaskStore (#707) (69d8899)
  • stamp the resolved taskId onto sendMessage push configs (#688) (cfb19a8)
Changelog

Sourced from @​a2a-js/sdk's changelog.

1.3.0 (2026-09-29)

Features

  • server/database: add database-backed task and push notification stores (#756) (0f2e563), closes #114

1.2.1 (2026-09-24)

Bug Fixes

  • issue that status or artifact events do not propagate the metatadata to the task (#748) (72588af)
  • jsonrpc: return JSON-RPC errors as HTTP 200 and dispatch on A2A-Version (#747) (733259d)
  • rest: ensure taskId is correctly set from path parameters when creating push notification configs (#740) (4a42ec1)
  • server: add optional media type validation against agent defaultInputModes (#745) (27659a2)
  • validate JSON-RPC response version (#698) (e0cdc91)

1.2.0 (2026-09-18)

Features

  • server: Introduce SettleByTaskId method (#692) (e856bda)

Bug Fixes

  • accept GetExtendedAgentCard JSON-RPC calls with omitted params (#687) (047d970)
  • avoid mutating caller message configuration (#725) (e3a6428)
  • client: cache the extended Agent Card only after signature verification (#711) (55b601c)
  • guard terminal state transitions and make cancelTask atomic (#636) (7b87c94)
  • preserve call context for JSON-RPC tenant requests (#708) (ae20aca)
  • preserve HeadersInit in authenticating fetch (#721) (f8c33fa)
  • preserve historyLength=0 and reject invalid REST listTasks pageSize (#685) (32c1865)
  • reject empty task IDs with RequestMalformedError in getTask/cancelTask (#629) (71aae97)
  • reject invalid ListTasks status filters with RequestMalformedError (#631) (a881fae)
  • reject missing required extensions before mutating task history (#690) (3b4ef3f)
  • reject whitespace-only taskId on sendMessage (#689) (85227a0)
  • return 404/-32001 for missing push notification configs (#630) (34f06e3)
  • scope ExecutionEventBusManager by tenant and owner to match TaskStore (#707) (69d8899)
  • stamp the resolved taskId onto sendMessage push configs (#688) (cfb19a8)
Commits
  • 29417a5 chore(main): release 1.3.0 (#760)
  • 36c801f ci(cli): install the packed package and run a2a-db directly (#766)
  • 4c86bf1 refactor(cli): move the store migrations to src/cli (#765)
  • 175ff45 build(cli): ship the a2a-db CLI as ESM only, without type files (#763)
  • 0f2e563 feat(server/database): add database-backed task and push notification stores ...
  • 11cbb29 chore(main): release 1.2.1 (#736)
  • 113fd99 feat(compat): convert a v0.3 push notification body to a v1.0 StreamResponse ...
  • 72588af fix: issue that status or artifact events do not propagate the metatadata to ...
  • 733259d fix(jsonrpc): return JSON-RPC errors as HTTP 200 and dispatch on A2A-Version ...
  • 27659a2 fix(server): add optional media type validation against agent defaultInputMod...
  • Additional commits viewable in compare view

Updates @hono/node-server from 2.1.1 to 2.1.3

Release notes

Sourced from @​hono/node-server's releases.

v2.1.3

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

Commits

Updates @larksuiteoapi/node-sdk from 1.73.3 to 1.74.0

Commits

Updates @modelcontextprotocol/sdk from 1.30.0 to 1.31.0

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Updates @node-rs/argon2 from 2.2.0 to 2.2.1

Commits

Updates drizzle-orm from 0.45.2 to 0.45.3

Release notes

Sourced from drizzle-orm's releases.

0.45.3

New Netlify DB Driver

Note: The Netlify DB driver is developed and maintained by the Netlify team.

Installation:

npm i @netlify/db

Usage example:

import { drizzle } from 'drizzle-orm/netlify-db';
// reads NETLIFY_DB_URL and NETLIFY_DB_DRIVER env vars
const db = drizzle();
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';
const db = drizzle(process.env.DATABASE_URL);
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';

// Explicit client — consumer controls the driver
const db = drizzle({ client: netlifyDbClient });

const result = await db.execute('select 1');
Commits
  • 15454db +
  • 54e436f exclude gel from pull
  • 0fd1cc6 remove gel
  • d028db7 skip gel
  • 93dc01e [All-kit]: Warn when journal timestamps can cause migrations to be skipped (#...
  • b786252 Merge pull request #6049 from drizzle-team/drizzle-kit-announcements
  • f9fc5bf Add drizzle-kit announcement manifest and schema doc
  • 9d64532 Merge pull request #6004 from drizzle-team/pin-npm-11-main
  • 0af2f2e Pin the release npm self-update to major 11: the npm 12.0.0 tarball is missin...
  • 6968638 Merge pull request #6001 from drizzle-team/release-router-dispatch-inputs
  • Additional commits viewable in compare view

Updates hono from 4.13.5 to 4.13.11

Release notes

Sourced from hono's releases.

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

Full Changelog: honojs/hono@v4.13.9...v4.13.10

v4.13.9

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in honojs/hono#5380

... (truncated)

Commits

Updates marked from 18.0.11 to 18.0.14

Release notes

Sourced from marked's releases.

v18.0.14

18.0.14 (2026-09-22)

Bug Fixes

v18.0.13

18.0.13 (2026-09-12)

Bug Fixes

  • allow tabs in the thematic break that ends a list item (#4087) (afbb27c)
  • avoid O(n^2) scanning in reflinkSearch (#4090) (c6a25bb)
  • case fold reference link labels (#4077) (aed9336)
  • drop the leading whitespace after a hard line break (#4075) (123ce04)
  • match html block start conditions when ending a list item (#4072) (c2facac)
  • respect raw tokens when closing link labels (#4066) (ef394f7)
  • strip a tab that follows spaces in an indented code block (#4080) (dbb393d)

v18.0.12

18.0.12 (2026-09-07)

Bug Fixes

  • allow a tab before the closing sequence of an ATX heading (#4084) (4417582)
  • allow one more level of nested brackets in a link label (#4064) (37b28d8)
  • do not add a newline to an empty code block (#4073) (23b1706)
  • escape character references in autolink destinations (#4053) (8f432f0)
  • reject GFM email autolink when the domain ends in _ or - (#4063) (df57534)
  • reject invalid characters in HTML tag names (#4083) (300bb1d)
  • remove up to the fence indentation from each content line (#4074) (0244f08)
Commits

Updates openid-client from 6.8.7 to 6.8.8

Release notes

Sourced from openid-client's releases.

v6.8.8

Fixes

  • apply the default HTTP request timeout (af32783)
  • calculate token lifetimes using elapsed time (e816bf0)
  • isolate lazy client authentication handler caches (d687796)
  • passport: handle rejected async verification callbacks (d730f80)
  • preserve clock settings across DCR nonce retries (5433d68)
  • release: separate changelog sections (57fcbc6)
  • retain polling abort signals through response processing (b26170e)
  • select a unique decryption key when kid is omitted (10ba026)

Refactor

  • share grant polling lifecycle and retry handling (b931c40)
Changelog

Sourced from openid-client's changelog.

6.8.8 (2026-09-05)

Fixes

  • apply the default HTTP request timeout (af32783)
  • calculate token lifetimes using elapsed time (e816bf0)
  • isolate lazy client authentication handler caches (d687796)
  • passport: handle rejected async verification callbacks (d730f80)
  • preserve clock settings across DCR nonce retries (5433d68)
  • release: separate changelog sections (57fcbc6)
  • retain polling abort signals through response processing (b26170e)
  • select a unique decryption key when kid is omitted (10ba026)

Refactor

  • share grant polling lifecycle and retry handling (b931c40)
Commits
  • 04c5982 chore(release): 6.8.8
  • 5eccf2e chore: bump packages
  • d730f80 fix(passport): handle rejected async verification callbacks
  • b931c40 refactor: share grant polling lifecycle and retry handling
  • d687796 fix: isolate lazy client authentication handler caches
  • e816bf0 fix: calculate token lifetimes using elapsed time
  • 10ba026 fix: select a unique decryption key when kid is omitted
  • b26170e fix: retain polling abort signals through response processing
  • af32783 fix: apply the default HTTP request timeout
  • 5433d68 fix: preserve clock settings across DCR nonce retries
  • Additional commits viewable in compare view

Updates undici from 7.29.0 to 7.30.0

Release notes

Sourced from undici's releases.

v7.30.0

What's Changed

Full Changelog: nodejs/undici@v7.29.1...v7.30.0

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits

Updates ws from 8.21.3 to 8.22.0

Release notes

Sourced from ws's releases.

8.22.0

Features

  • Introduced the protocols option (8b918b01).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the state to WebSocket.CLOSING (#2337).
Commits

…y with 22 updates

Bumps the production-dependencies group with 22 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@a2a-js/sdk](https://github.com/a2aproject/a2a-js) | `1.1.0` | `1.3.0` |
| [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` |
| [@larksuiteoapi/node-sdk](https://github.com/larksuite/node-sdk) | `1.73.3` | `1.74.0` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.31.0` |
| [@node-rs/argon2](https://github.com/napi-rs/node-rs) | `2.2.0` | `2.2.1` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [hono](https://github.com/honojs/hono) | `4.13.5` | `4.13.11` |
| [marked](https://github.com/markedjs/marked) | `18.0.11` | `18.0.14` |
| [openid-client](https://github.com/panva/openid-client) | `6.8.7` | `6.8.8` |
| [undici](https://github.com/nodejs/undici) | `7.29.0` | `7.30.0` |
| [ws](https://github.com/websockets/ws) | `8.21.3` | `8.22.0` |
| [@types/ws](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/ws) | `8.18.1` | `8.18.2` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [@codemirror/commands](https://github.com/codemirror/commands) | `6.11.0` | `6.11.1` |
| [@codemirror/state](https://github.com/codemirror/state) | `6.7.2` | `6.7.6` |
| [@codemirror/view](https://github.com/codemirror/view) | `6.43.11` | `6.43.13` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.102.8` | `5.104.0` |
| [antd](https://github.com/ant-design/ant-design) | `6.6.2` | `6.6.5` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.87.0` | `7.89.0` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.18.3` | `7.18.4` |



Updates `@a2a-js/sdk` from 1.1.0 to 1.3.0
- [Release notes](https://github.com/a2aproject/a2a-js/releases)
- [Changelog](https://github.com/a2aproject/a2a-js/blob/main/CHANGELOG.md)
- [Commits](a2aproject/a2a-js@v1.1.0...v1.3.0)

Updates `@hono/node-server` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v2.1.1...v2.1.3)

Updates `@larksuiteoapi/node-sdk` from 1.73.3 to 1.74.0
- [Commits](https://github.com/larksuite/node-sdk/commits)

Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.31.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.31.0)

Updates `@node-rs/argon2` from 2.2.0 to 2.2.1
- [Release notes](https://github.com/napi-rs/node-rs/releases)
- [Commits](https://github.com/napi-rs/node-rs/compare/@node-rs/argon2@2.2.0...@node-rs/argon2@2.2.1)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `hono` from 4.13.5 to 4.13.11
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.5...v4.13.11)

Updates `marked` from 18.0.11 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.11...v18.0.14)

Updates `openid-client` from 6.8.7 to 6.8.8
- [Release notes](https://github.com/panva/openid-client/releases)
- [Changelog](https://github.com/panva/openid-client/blob/main/CHANGELOG.md)
- [Commits](panva/openid-client@v6.8.7...v6.8.8)

Updates `undici` from 7.29.0 to 7.30.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Updates `ws` from 8.21.3 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.3...8.22.0)

Updates `@types/ws` from 8.18.1 to 8.18.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/ws)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `@codemirror/commands` from 6.11.0 to 6.11.1
- [Changelog](https://github.com/codemirror/commands/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/commands/commits)

Updates `@codemirror/state` from 6.7.2 to 6.7.6
- [Changelog](https://github.com/codemirror/state/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/state/commits)

Updates `@codemirror/view` from 6.43.11 to 6.43.13
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)

Updates `@tanstack/react-query` from 5.102.8 to 5.104.0
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.104.0/packages/react-query)

Updates `antd` from 6.6.2 to 6.6.5
- [Release notes](https://github.com/ant-design/ant-design/releases)
- [Changelog](https://github.com/ant-design/ant-design/blob/master/CHANGELOG.en-US.md)
- [Commits](ant-design/ant-design@6.6.2...6.6.5)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `react-hook-form` from 7.87.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.87.0...v7.89.0)

Updates `react-router-dom` from 7.18.3 to 7.18.4
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom)

---
updated-dependencies:
- dependency-name: "@a2a-js/sdk"
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@larksuiteoapi/node-sdk"
  dependency-version: 1.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@node-rs/argon2"
  dependency-version: 2.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: hono
  dependency-version: 4.13.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: openid-client
  dependency-version: 6.8.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@types/ws"
  dependency-version: 8.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@codemirror/commands"
  dependency-version: 6.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@codemirror/state"
  dependency-version: 6.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@codemirror/view"
  dependency-version: 6.43.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: antd
  dependency-version: 6.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-router-dom
  dependency-version: 7.18.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants