Skip to content

fix(deps): bump the production-deps group across 1 directory with 13 updates - #158

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-deps-dcedc7a5b8
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-deps-dcedc7a5b8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-deps group with 13 updates in the / directory:

Package From To
@aws-sdk/client-s3 3.1109.0 3.1141.0
@nestjs/throttler 6.5.0 6.7.1
@prisma/adapter-pg 7.9.1 7.10.0
@prisma/client 7.9.1 7.10.0
pdfkit 0.19.1 0.20.2
pg 8.22.0 8.23.0
prisma 7.9.1 7.10.0
lucide-react 1.31.0 1.48.0
react 19.2.8 19.3.0
react-dom 19.2.8 19.3.0
react-hook-form 7.85.0 7.88.0
sonner 2.0.7 2.0.8
tailwind-merge 3.6.0 3.7.0

Updates @aws-sdk/client-s3 from 3.1109.0 to 3.1141.0

Release notes

Sourced from @​aws-sdk/client-s3's releases.

v3.1141.0

3.1141.0(2026-09-25)

Chores
  • codegen: smithy-aws-typescript-codegen 0.54.0 (#8314) (ad80ce3e)
New Features
  • client-connect: Agent Privacy During Hold is a new privacy capability for Amazon Connect Voice that prevents agent audio from being captured in call recordings or Contact Lens conversational analytics during hold. When enabled, agents are automatically muted on entering hold and unmuted on resuming the contact (03527f9e)
  • client-qconnect: Release shapes for the proactive agentic recommendations and the multi-knowledge base search features. Increases the maximum length of QuickResponseContent. (e008332b)
  • client-bedrock-agent: Adds support for calling VPC configuration API's in Bedrock. These configurations allow the use of On Prem connectors in Bedrock Managed Knowledge bases (18524dc6)
  • client-mediaconnect: This release adds support for RTMP push router outputs in AWS Elemental MediaConnect. (5bd8d80b)
  • client-securityagent: This release adds the ListActorMessages operation, which returns the multi-factor authentication messages received at an actor's server-generated email address (10e53d50)
  • client-arc-region-switch: Adds a service quota checker to Region switch to verify quota parity between your primary and standby Region, and automatically submit quota limit increases. Adds an optional EC2 Auto Scaling and ECS setting that waits for instances or tasks in the scaled-up Region to be healthy in target groups. (cca33e38)
  • client-bedrock-agentcore-control: Amazon Bedrock AgentCore Payments now supports credential rotation for payment connectors, letting you rotate API and wallet secrets for Quick Create payment auths from the console. This release also adds Type and Creation type columns to the payment managers views. (adca591f)
  • client-neptune-graph: Add GraphIdentifier filter for ListImportTasks (9b9aea9b)
  • client-rekognition: This release adds support for Feedback and Metadata in the GetFaceLivenessSessionResults response. Feedback returns codes explaining why a Face Liveness check produced its result. Metadata includes the client SDK type. (0831c361)
  • client-glue: add support for table level federation (a44458b7)
  • client-wellarchitected: This change releases the Well-Architected Agent, a generative AI service that analyzes a customer's AWS environment and delivers personalized, prioritized recommendations across cost, security, performance, and resilience. (d0656586)

For list of updated packages, view updated-packages.md in assets-3.1141.0.zip

v3.1140.0

3.1140.0(2026-09-24)

Documentation Changes
  • client-route53resolver: Documentation updates for Route 53 Resolver. Clarifies which Outpost Resolver operations apply to first-generation AWS Outposts and that Resolver is managed automatically on second-generation Outposts. Adds Local Network Interface subnet compatibility notes for Resolver endpoints. (b4432aba)
  • client-iot: Fixed ListV2LoggingLevels and DeleteV2LoggingLevel documentation to include all supported target-types (4dcf76d5)
New Features
  • clients: update client endpoints as of 2026-09-24 (29a8566c)
  • client-eventbridgev2: Introducing Amazon EventBridge enhanced Custom event bus, a new shareable event bus for organizational-scale event-driven applications feature ordered delivery, deduplication, open event formats, and cross-account bus sharing. (69fbe6a2)
  • client-datazone: Amazon DataZone now supports the TOOLING blueprint category on CreateEnvironmentBlueprint, UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and ListEnvironmentBlueprints, for custom tooling blueprints. CreateConnection now accepts roleArn in iamProperties. (591cd6f5)
  • client-elasticache: Added tagging support for ElastiCache Global DataStore. (0fa9da59)
  • client-marketplace-discovery: AWS Marketplace Discovery API now supports localized responses and SigV4a request signing. It returns new fulfillment details, including AMI architecture, EBS volume and security group information, SaaS quick-launch status, and SageMaker input and output MIME types. (510673e3)
  • client-redshift-data: Updates to the ListDatabases and WorkgroupName validation (218c24e1)
  • client-securityagent: Added support for Confluence export, enabling customers to publish security findings to Confluence pages. (81408527)
  • client-cloudwatch: This release adds Create, Get, Update, and DeleteResourceMetricsConfiguration to enable detailed metric collection for an AWS resource, and adds UpdateOTelEnrichment plus include and exclude filters on StartOTelEnrichment so you can choose which metric namespaces CloudWatch enriches. (765cc1ce)
  • client-eventbridge: Adds a ManagedBy field to the DescribeEventBus and ListEventBuses responses, identifying the AWS service that created an event bus on your behalf. (28a639b2)
Tests
  • undici-http-handler: update bidi stream e2e test to nova-2-sonic model (#8313) (d9a37d9d)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-s3's changelog.

3.1141.0 (2026-09-25)

Note: Version bump only for package @​aws-sdk/client-s3

3.1140.0 (2026-09-24)

Note: Version bump only for package @​aws-sdk/client-s3

3.1139.0 (2026-09-23)

Note: Version bump only for package @​aws-sdk/client-s3

3.1138.0 (2026-09-22)

Note: Version bump only for package @​aws-sdk/client-s3

3.1137.0 (2026-09-21)

Note: Version bump only for package @​aws-sdk/client-s3

3.1136.0 (2026-09-18)

Note: Version bump only for package @​aws-sdk/client-s3

3.1135.0 (2026-09-17)

... (truncated)

Commits

Updates @nestjs/throttler from 6.5.0 to 6.7.1

Release notes

Sourced from @​nestjs/throttler's releases.

v6.7.1

Patch Changes

  • e8368b3: Set rate limit headers through res.setHeader() when the response has no res.header() method, so the guard no longer throws res.header is not a function on custom HTTP adapters. The logic lives in a new protected setResponseHeader() method that subclasses can override.
  • a482ef9: Coerce numeric strings for limit, ttl and blockDuration to numbers, as returned for example by ConfigService.get<number>() for environment variables. Previously Date.now() + '60000' concatenated instead of adding, which silently corrupted every expiry and X-RateLimit-Reset. A value that is not numeric now fails with an error naming the option and the throttler.
  • a9a28b9: Respect an explicit 0 for limit, ttl and blockDuration in @Throttle() and the module options instead of falling back to the default. blockDuration: 0 now means "no extra block": the in-memory storage rejects requests while the window is full and lets them through again as soon as the oldest hit expires, without recording the rejected ones.
  • bf81677: Import shared interfaces from the public Nest package entry point for Nest 12 compatibility.
  • caaabc9: Stop the in-memory storage from retaining request contexts. It used to schedule one setTimeout per counted hit, and each timer kept the request's AsyncLocalStorage stores (for example an ORM's per-request entity manager) in memory until the TTL expired. It now records when each hit expires and prunes expired hits on access. The idle-record sweep is also no longer tied to the context of the first request. With blockDuration: 0, Retry-After now reports when the oldest hit expires rather than when the window ends.
  • 7703c10: Log a warning when no throttler is configured. The guard limits nothing in that case and previously said nothing at boot, so ThrottlerModule.forRoot() and ThrottlerModule.forRoot([]) looked like a working setup.

v6.7.0

Minor Changes

  • 7004a97: Normalize IPv6 source addresses in the default tracker, and evict expired records from the in-memory storage.

    The built-in getTracker returned req.ip verbatim, so a client holding an IPv6 allocation could send every request from a different address within its own subnet and never share a counter, defeating the rate limit. Addresses are now masked to a /64 before being used as the tracker; the prefix length is configurable via the new ipv6SubnetPrefix module option. IPv4 addresses, IPv4-mapped addresses, the loopback, and custom getTracker implementations are unaffected.

    ThrottlerStorageService also never removed records, so a stream of requests from distinct trackers grew the internal map for the lifetime of the process. Idle records are now swept out once their window has fully elapsed. Limiting behaviour is unchanged: a record is only dropped after every pending hit has expired and any block has lapsed.

    Note that the tracker string for IPv6 clients changes shape (2001:db8:0:1::/64), so storage keys rotate once on upgrade.

v6.6.0

Minor Changes

  • c342bad: Declare the supported Node versions in engines, matching the range the CI matrix tests
  • c625e98: Update to allow for support for Nest version 12
Changelog

Sourced from @​nestjs/throttler's changelog.

6.7.1

Patch Changes

  • e8368b3: Set rate limit headers through res.setHeader() when the response has no res.header() method, so the guard no longer throws res.header is not a function on custom HTTP adapters. The logic lives in a new protected setResponseHeader() method that subclasses can override.
  • a482ef9: Coerce numeric strings for limit, ttl and blockDuration to numbers, as returned for example by ConfigService.get<number>() for environment variables. Previously Date.now() + '60000' concatenated instead of adding, which silently corrupted every expiry and X-RateLimit-Reset. A value that is not numeric now fails with an error naming the option and the throttler.
  • a9a28b9: Respect an explicit 0 for limit, ttl and blockDuration in @Throttle() and the module options instead of falling back to the default. blockDuration: 0 now means "no extra block": the in-memory storage rejects requests while the window is full and lets them through again as soon as the oldest hit expires, without recording the rejected ones.
  • bf81677: Import shared interfaces from the public Nest package entry point for Nest 12 compatibility.
  • caaabc9: Stop the in-memory storage from retaining request contexts. It used to schedule one setTimeout per counted hit, and each timer kept the request's AsyncLocalStorage stores (for example an ORM's per-request entity manager) in memory until the TTL expired. It now records when each hit expires and prunes expired hits on access. The idle-record sweep is also no longer tied to the context of the first request. With blockDuration: 0, Retry-After now reports when the oldest hit expires rather than when the window ends.
  • 7703c10: Log a warning when no throttler is configured. The guard limits nothing in that case and previously said nothing at boot, so ThrottlerModule.forRoot() and ThrottlerModule.forRoot([]) looked like a working setup.

6.7.0

Minor Changes

  • 7004a97: Normalize IPv6 source addresses in the default tracker, and evict expired records from the in-memory storage.

    The built-in getTracker returned req.ip verbatim, so a client holding an IPv6 allocation could send every request from a different address within its own subnet and never share a counter, defeating the rate limit. Addresses are now masked to a /64 before being used as the tracker; the prefix length is configurable via the new ipv6SubnetPrefix module option. IPv4 addresses, IPv4-mapped addresses, the loopback, and custom getTracker implementations are unaffected.

    ThrottlerStorageService also never removed records, so a stream of requests from distinct trackers grew the internal map for the lifetime of the process. Idle records are now swept out once their window has fully elapsed. Limiting behaviour is unchanged: a record is only dropped after every pending hit has expired and any block has lapsed.

    Note that the tracker string for IPv6 clients changes shape (2001:db8:0:1::/64), so storage keys rotate once on upgrade.

6.6.0

Minor Changes

  • c342bad: Declare the supported Node versions in engines, matching the range the CI matrix tests
  • c625e98: Update to allow for support for Nest version 12

6.4.0

6.5.1

Patch Changes

  • 603cb82: handles edge case where multiple clients making frequent requests interfere with each other
Commits
  • 91f4912 Merge pull request #2706 from nestjs/changeset-release/master
  • c5e8c90 chore: version packages
  • 9ec3aa3 Merge pull request #2668 from nestjs/renovate/major-nest-monorepo
  • 5d3b9ae Merge pull request #2712 from nestjs/fix/coerce-numeric-options
  • 4335230 Merge pull request #2711 from nestjs/fix/timer-free-storage
  • a482ef9 fix(guard): coerce numeric string options
  • e082222 chore(deps): update nest monorepo to v12
  • caaabc9 fix(storage): do not retain request contexts in timers
  • 4ab8c63 Merge pull request #2697 from nestjs/renovate/node-24.x
  • c36f011 Merge pull request #2703 from nestjs/renovate/nest-graphql-monorepo
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​nestjs/throttler since your current version.


Updates @prisma/adapter-pg from 7.9.1 to 7.10.0

Release notes

Sourced from @​prisma/adapter-pg's releases.

7.10.0

Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

Highlights

Run Prisma 7 alongside Prisma 8

This release introduces @prisma/prisma7, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0

Use prisma for the directly installed Prisma 8 CLI and prisma7 for Prisma 7:

npx prisma --version
npx prisma7 --version
npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's prisma.config.* files:

// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'
export default defineConfig({
schema: 'prisma/schema.prisma',
migrations: {
path: 'prisma/migrations',
},
})

Without an explicit --config option, Prisma 7 searches for:

  1. Root-level prisma7.config.* files.
  2. .config/prisma7.* files.
  3. Existing prisma.config.* files as a backwards-compatible fallback.

The supported extensions are .js, .ts, .mjs, .cjs, .mts, and .cts. An explicit config path always takes precedence:

... (truncated)

Commits
  • 3fa65ac fix(p2002): correct modelName in nested create unique constraint errors #2959...
  • a180209 fix(adapter-pg): map PostgreSQL deadlocks to P2034 (#29717)
  • 800f1d1 fix(adapter-pg): preserve constraint name for unique violations (23505) (#29587)
  • 7ef2104 fix(postgres): handle SQLSTATE 23001 for RESTRICT violations (#29554)
  • See full diff in compare view

Updates @prisma/client from 7.9.1 to 7.10.0

Release notes

Sourced from @​prisma/client's releases.

7.10.0

Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

Highlights

Run Prisma 7 alongside Prisma 8

This release introduces @prisma/prisma7, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0

Use prisma for the directly installed Prisma 8 CLI and prisma7 for Prisma 7:

npx prisma --version
npx prisma7 --version
npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's prisma.config.* files:

// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'
export default defineConfig({
schema: 'prisma/schema.prisma',
migrations: {
path: 'prisma/migrations',
},
})

Without an explicit --config option, Prisma 7 searches for:

  1. Root-level prisma7.config.* files.
  2. .config/prisma7.* files.
  3. Existing prisma.config.* files as a backwards-compatible fallback.

The supported extensions are .js, .ts, .mjs, .cjs, .mts, and .cts. An explicit config path always takes precedence:

... (truncated)

Commits
  • 05c1b88 Teach Prisma 7 to prefer versioned config files (#30020)
  • cf2bc1f Rename prisma7 package to @​prisma/prisma7 (#30002)
  • ce5a34c Complete downstream actionable Prisma 7 guidance propagation (#29994)
  • 3f13ec6 Complete CLI-owned prisma7 distribution identity (#29969)
  • 179ba0c feat(prisma7): add side-by-side CLI wrapper (#29949)
  • 3fa65ac fix(p2002): correct modelName in nested create unique constraint errors #2959...
  • 6b6d9e9 chore(deps): update engines to 7.10.0-4.0edf323efd1d98336f3f0a68684b56f689b90...
  • b64e33c chore(deps): update engines to 7.10.0-3.9d90ce2c89d5c95a1148aef15e5561ab6c490...
  • 2046f9b feat(client): expose ModelName to compute function in Result extensions (#29782)
  • f2b3abd chore(deps): update engines to 7.10.0-1.6d040c802892de6d56c7e0061b7a10b3e6a0c...
  • Additional commits viewable in compare view

Updates pdfkit from 0.19.1 to 0.20.2

Release notes

Sourced from pdfkit's releases.

v0.20.2

  • Fix bundlers and file tracers packing the ESM copies of the standard font metrics instead of the CommonJS ones the Node build actually loads, which left Cannot find module errors for every standard font at runtime, by resolving the internal #standard-fonts/* mapping to a single file under all conditions
  • Fix doc.file() throwing when the same in-memory attachment is embedded twice under one name, because the creation and modified dates the deduplication check compares are absent for sources that are not read from disk
  • Fix doc.text() throwing unsupported number: NaN when lineBreak: false is combined with underline, strike, link or goTo, because the rendered width was computed from the line wrapper's measurements, which are never produced when wrapping is disabled

v0.20.1

  • Add a Node ESM build so import 'pdfkit' in Node resolves to the Node build (real file system, native zlib, Node streams, self-registering standard fonts) instead of the browser bundle

v0.20.0

Highlights

TLDR: "A PDF generation library for Node.js" -> "A JavaScript PDF generation library"

Standard Font Support rewritten

Standard font support has been rewritten to use pre-parsed font metrics instead of parsing raw AFM definitions at runtime. The new approach is more efficient (less runtime overhead and memory usage) and reduces the size of the browser bundle significantly. Standalone build which bundles all standard fonts is down to 1.3MB from 2.3MB.

In Node, font metrics are loaded lazily as before, while in browser builds, except the standalone one, each font must be imported from pdfkit/standard-fonts/* and registered with registerStdFonts(). Previously, to use a standard font in browser was necessary to use a bundler.

See usage example in output helpers section below.

Removal of Node specific dependencies

Buffer is no longer used internally. Uint8Array is now the minimum denominator for binary data in both Node and browsers. Since Buffer is a Uint8Array subclass, this change is fully backward compatible.

Native fs, zlib and ReadableStream are conditionally imported only in Node. Browser builds use minimal implementations. This approach gives us the best of both worlds: Node builds still use the native modules, while browser ones are portable.

Many thanks to @​diegomura for his help in removing the Node specific dependencies.

registerFile API

The new registerFile(path, data) API allows registering in-memory files globally. The data argument must be a Uint8Array. Passing undefined as data unregisters the path.

In browsers, it can be used as a simplified virtual file system. In Node, this is useful for registering fonts, images and other resources that are not available on disk. The native file system is still used when the path is not registered.

import { PDFDocument, registerFile } from 'pdfkit';
const response = await fetch('/fonts/Roboto-Regular.ttf');
const fontData = new Uint8Array(await response.arrayBuffer());
registerFile('fonts/Roboto-Regular.ttf', fontData);
const doc = new PDFDocument();
// register an alias for the font path
doc.registerFont('Roboto', 'fonts/Roboto-Regular.ttf');
// or use the path directly
doc.font('fonts/Roboto-Regular.ttf');
</tr></table>

... (truncated)

Changelog

Sourced from pdfkit's changelog.

[v0.20.2] - 2026-08-29

  • Fix bundlers and file tracers packing the ESM copies of the standard font metrics instead of the CommonJS ones the Node build actually loads, which left Cannot find module errors for every standard font at runtime, by resolving the internal #standard-fonts/* mapping to a single file under all conditions
  • Fix doc.file() throwing when the same in-memory attachment is embedded twice under one name, because the creation and modified dates the deduplication check compares are absent for sources that are not read from disk
  • Fix doc.text() throwing unsupported number: NaN when lineBreak: false is combined with underline, strike, link or goTo, because the rendered width was computed from the line wrapper's measurements, which are never produced when wrapping is disabled

[v0.20.1] - 2026-08-23

  • Add a Node ESM build so import 'pdfkit' in Node resolves to the Node build (real file system, native zlib, Node streams, self-registering standard fonts) instead of the browser bundle

[v0.20.0] - 2026-08-23

  • [BREAKING CHANGE] Remove the virtual file system (pdfkit/virtual-fs). Browser builds no longer depend on fs: use registerFile to register Uint8Array data under a path, pass a Uint8Array or ArrayBuffer directly to registerFont, image and file, or pass a data URL directly to image and file
  • Add registerFile(path, data, options) to globally register in-memory files in Node and browsers, with optional birthtime and ctime metadata. Passing undefined as data unregisters the path
  • [BREAKING CHANGE] Export PDFDocument, LineWrapper and registerFile as named exports from the main Node and browser entry points while preserving the default PDFDocument export
  • Add experimental toBlob(document) and toBytes(document) output helpers under pdfkit/output
  • Accept already-parsed fontkit Font instances in doc.font() and registerFont
  • Load the PDF/A ICC profile from disk only when needed in Node, while continuing to bundle it in browser builds
  • Add tools to convert raw AFM standard-font definitions into parsed or compact runtime JavaScript modules
  • [BREAKING CHANGE] Use generated standard-font data instead of parsing raw AFM definitions at runtime. Node loads font metrics lazily; browser applications must import each font they use from pdfkit/standard-fonts/* and register it with registerStdFonts()
  • [BREAKING CHANGE] Restrict AcroForm options to documented mappings and explicit escape hatches.
  • [BREAKING CHANGE] Stop automatically uppercasing annotation option keys.
  • [BREAKING CHANGE] Throw from addNamedEmbeddedFile when no ref is given, instead of writing an unparseable undefined token into the /EmbeddedFiles name tree
  • Do not mutate options passed to doc.annotate() and its convenience methods (link, note, strike, lineAnnotation, rectAnnotation, ellipseAnnotation, textAnnotation, fileAnnotation)
  • Persist font options when adding a new page. Fixes #1739
  • Use Uint8Array instead of Node's Buffer internally
  • Fix date text field formatting emitting invalid JavaScript, so the format was never applied. Fixes #1546
  • Fix indentAllLines applying the indent again on every paragraph and every page break, and keep it applied across continued text. Fixes #1606
  • Fix a hole in a sparse array being skipped entirely, which shifted every later entry down one
  • Encrypt strings inside name trees. Fixes #1513
Commits
  • 8d72a71 v0.20.2
  • 70c9ad5 Document the parameter list each destination type takes (#1785)
  • e04b677 Fix doc.text() throwing NaN with lineBreak false and underline/strike/link/go...
  • c6f57c6 fix: resolve #standard-fonts/* to one file under every condition (#1782)
  • b87b5ac Fix case-insensitive lookup for named CSS colors (#1780)
  • 69671d9 Fix doc.file() throwing when the same in-memory attachment is added twice (#1...
  • 1f1abb8 Bump ip-address from 10.2.0 to 10.4.0 (#1761)
  • f58c4c7 Bump postcss from 8.5.15 to 8.5.25 (#1762)
  • f048bdd v0.20.1
  • 910c86a Add Node ESM build: route the node import condition to a real Node bundle (#1...
  • Additional commits viewable in compare view

Updates pg from 8.22.0 to 8.23.0

Changelog

Sourced from pg's changelog.

pg@8.23.0

Commits

Updates prisma from 7.9.1 to 7.10.0

Commits
Attestation changes

This version has no provenance attestation, while the previous version (7.9.1) was attested. Review the package versions before updating.


Updates lucide-react from 1.31.0 to 1.48.0

Release notes

Sourced from lucide-react's releases.

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Version 1.47.0

What's Changed

New Contributors

... (truncated)

Commits
  • f06ac67 chore(typchecking): More typecheck jobs for all packages (#4885)
  • 94e4cb9 chore(dependencies): Update dependencies (#4806)
  • 99d25bd feat(packages): extract icon build logic into @lucide/shared (#4409)
  • 75b5516 chore(dev): upgrade ESLint to latest compatible stack (v10) (#4378)
  • See full diff in compare view

Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

@dependabot dependabot Bot added dependencies Pull requests that update a dependency npm npm dependency updates labels Sep 28, 2026
github-actions[bot]
github-actions Bot previously approved these changes Sep 28, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 28, 2026 22:54
…updates

Bumps the production-deps group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1109.0` | `3.1141.0` |
| [@nestjs/throttler](https://github.com/nestjs/throttler) | `6.5.0` | `6.7.1` |
| [@prisma/adapter-pg](https://github.com/prisma/prisma/tree/HEAD/packages/adapter-pg) | `7.9.1` | `7.10.0` |
| [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) | `7.9.1` | `7.10.0` |
| [pdfkit](https://github.com/foliojs/pdfkit) | `0.19.1` | `0.20.2` |
| [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.22.0` | `8.23.0` |
| [prisma](https://github.com/prisma/prisma-cli/tree/HEAD/packages/prisma) | `7.9.1` | `7.10.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.48.0` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.85.0` | `7.88.0` |
| [sonner](https://github.com/emilkowalski/sonner) | `2.0.7` | `2.0.8` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |



Updates `@aws-sdk/client-s3` from 3.1109.0 to 3.1141.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3)

Updates `@nestjs/throttler` from 6.5.0 to 6.7.1
- [Release notes](https://github.com/nestjs/throttler/releases)
- [Changelog](https://github.com/nestjs/throttler/blob/master/CHANGELOG.md)
- [Commits](nestjs/throttler@v6.5.0...v6.7.1)

Updates `@prisma/adapter-pg` from 7.9.1 to 7.10.0
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.10.0/packages/adapter-pg)

Updates `@prisma/client` from 7.9.1 to 7.10.0
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.10.0/packages/client)

Updates `pdfkit` from 0.19.1 to 0.20.2
- [Release notes](https://github.com/foliojs/pdfkit/releases)
- [Changelog](https://github.com/foliojs/pdfkit/blob/master/CHANGELOG.md)
- [Commits](foliojs/pdfkit@v0.19.1...v0.20.2)

Updates `pg` from 8.22.0 to 8.23.0
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.0/packages/pg)

Updates `prisma` from 7.9.1 to 7.10.0
- [Release notes](https://github.com/prisma/prisma-cli/releases)
- [Commits](https://github.com/prisma/prisma-cli/commits/HEAD/packages/prisma)

Updates `lucide-react` from 1.31.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `react-hook-form` from 7.85.0 to 7.88.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.85.0...v7.88.0)

Updates `sonner` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/emilkowalski/sonner/releases)
- [Commits](emilkowalski/sonner@v2.0.7...v2.0.8)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1141.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@nestjs/throttler"
  dependency-version: 6.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@prisma/adapter-pg"
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@prisma/client"
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: pdfkit
  dependency-version: 0.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: pg
  dependency-version: 8.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: prisma
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: react-hook-form
  dependency-version: 7.88.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: sonner
  dependency-version: 2.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-deps
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title fix(deps): bump the production-deps group with 13 updates fix(deps): bump the production-deps group across 1 directory with 13 updates Sep 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-deps-dcedc7a5b8 branch from 2069e46 to e2d13dc Compare September 28, 2026 23:17
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
auto-merge was automatically disabled October 5, 2026 22:51

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-deps-dcedc7a5b8 branch October 5, 2026 22:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency npm npm dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants