Skip to content

chore(deps)(deps): bump the production-dependencies group with 27 updates - #21029

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-28abf4773c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-28abf4773c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 27 updates:

Package From To
tsx 4.23.12 4.23.15
yaml 2.9.0 2.9.1
chalk 6.0.0 6.0.1
zod 4.6.1 4.6.5
react 19.2.8 19.3.0
react-dom 19.2.8 19.3.0
@modelcontextprotocol/sdk 1.30.0 1.30.1
sql.js 1.14.1 1.14.2
mongodb 7.5.0 7.6.0
@libsql/client 0.17.4 0.18.0
@better-auth/core 1.7.3 1.7.6
@better-auth/oauth-provider 1.7.3 1.7.6
@better-auth/scim 1.7.3 1.7.6
@better-auth/sso 1.7.3 1.7.6
@noble/hashes 2.3.0 2.4.0
better-auth 1.7.3 1.7.6
jose 6.2.8 6.2.12
hono 4.13.7 4.13.9
nodemailer 10.0.12 10.0.11
pinyin-pro 3.29.1 3.29.4
@noble/ciphers 2.3.0 2.4.0
fumadocs-core 16.14.4 16.15.15
fumadocs-mdx 15.2.3 15.4.5
fumadocs-ui 16.14.4 16.15.15
lucide-react 1.31.0 1.48.0
next 16.3.3 16.3.6
tailwind-merge 3.6.0 3.7.0

Updates tsx from 4.23.12 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

v4.23.13

4.23.13 (2026-08-30)

Bug Fixes

  • cache: bound shared transform cache memory (#835) (28e1f12)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • 28e1f12 fix(cache): bound shared transform cache memory (#835)
  • See full diff in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates chalk from 6.0.0 to 6.0.1

Release notes

Sourced from chalk's releases.

v6.0.1

  • Fix inconsistent coercion of two arguments 9c93a04

chalk/chalk@v6.0.0...v6.0.1

Commits

Updates zod from 4.6.1 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits

Updates react-dom from 19.2.8 to 19.3.0

Release notes

Sourced from react-dom's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoffDescription has been truncated

…ates

Bumps the production-dependencies group with 27 updates:

| Package | From | To |
| --- | --- | --- |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.15` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [chalk](https://github.com/chalk/chalk) | `6.0.0` | `6.0.1` |
| [zod](https://github.com/colinhacks/zod) | `4.6.1` | `4.6.5` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.30.1` |
| [sql.js](https://github.com/sql-js/sql.js) | `1.14.1` | `1.14.2` |
| [mongodb](https://github.com/mongodb/node-mongodb-native) | `7.5.0` | `7.6.0` |
| [@libsql/client](https://github.com/tursodatabase/libsql-client-ts/tree/HEAD/packages/libsql-client) | `0.17.4` | `0.18.0` |
| [@better-auth/core](https://github.com/better-auth/better-auth/tree/HEAD/packages/core) | `1.7.3` | `1.7.6` |
| [@better-auth/oauth-provider](https://github.com/better-auth/better-auth/tree/HEAD/packages/oauth-provider) | `1.7.3` | `1.7.6` |
| [@better-auth/scim](https://github.com/better-auth/better-auth/tree/HEAD/packages/scim) | `1.7.3` | `1.7.6` |
| [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) | `1.7.3` | `1.7.6` |
| [@noble/hashes](https://github.com/paulmillr/noble-hashes) | `2.3.0` | `2.4.0` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.3` | `1.7.6` |
| [jose](https://github.com/panva/jose) | `6.2.8` | `6.2.12` |
| [hono](https://github.com/honojs/hono) | `4.13.7` | `4.13.9` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `10.0.12` | `10.0.11` |
| [pinyin-pro](https://github.com/zh-lx/pinyin-pro/tree/HEAD/packages/pinyin-pro) | `3.29.1` | `3.29.4` |
| [@noble/ciphers](https://github.com/paulmillr/noble-ciphers) | `2.3.0` | `2.4.0` |
| [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.14.4` | `16.15.15` |
| [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `15.2.3` | `15.4.5` |
| [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.14.4` | `16.15.15` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.48.0` |
| [next](https://github.com/vercel/next.js) | `16.3.3` | `16.3.6` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |


Updates `tsx` from 4.23.12 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.12...v4.23.15)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `chalk` from 6.0.0 to 6.0.1
- [Release notes](https://github.com/chalk/chalk/releases)
- [Commits](chalk/chalk@v6.0.0...v6.0.1)

Updates `zod` from 4.6.1 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.6.1...v4.6.5)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

Updates `sql.js` from 1.14.1 to 1.14.2
- [Release notes](https://github.com/sql-js/sql.js/releases)
- [Commits](sql-js/sql.js@v1.14.1...v1.14.2)

Updates `mongodb` from 7.5.0 to 7.6.0
- [Release notes](https://github.com/mongodb/node-mongodb-native/releases)
- [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md)
- [Commits](mongodb/node-mongodb-native@v7.5.0...v7.6.0)

Updates `@libsql/client` from 0.17.4 to 0.18.0
- [Release notes](https://github.com/tursodatabase/libsql-client-ts/releases)
- [Changelog](https://github.com/tursodatabase/libsql-client-ts/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tursodatabase/libsql-client-ts/commits/v0.18.0/packages/libsql-client)

Updates `@better-auth/core` from 1.7.3 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/core/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/core)

Updates `@better-auth/oauth-provider` from 1.7.3 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/oauth-provider/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/oauth-provider)

Updates `@better-auth/scim` from 1.7.3 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/scim/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/scim)

Updates `@better-auth/sso` from 1.7.3 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/sso)

Updates `@noble/hashes` from 2.3.0 to 2.4.0
- [Release notes](https://github.com/paulmillr/noble-hashes/releases)
- [Changelog](https://github.com/paulmillr/noble-hashes/blob/main/CHANGELOG.md)
- [Commits](paulmillr/noble-hashes@2.3.0...2.4.0)

Updates `better-auth` from 1.7.3 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/better-auth)

Updates `jose` from 6.2.8 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.8...v6.2.12)

Updates `hono` from 4.13.7 to 4.13.9
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.7...v4.13.9)

Updates `nodemailer` from 10.0.12 to 10.0.11
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v10.0.12...v10.0.11)

Updates `pinyin-pro` from 3.29.1 to 3.29.4
- [Release notes](https://github.com/zh-lx/pinyin-pro/releases)
- [Changelog](https://github.com/zh-lx/pinyin-pro/blob/main/CHANGELOG.md)
- [Commits](https://github.com/zh-lx/pinyin-pro/commits/3.29.4/packages/pinyin-pro)

Updates `@noble/ciphers` from 2.3.0 to 2.4.0
- [Release notes](https://github.com/paulmillr/noble-ciphers/releases)
- [Changelog](https://github.com/paulmillr/noble-ciphers/blob/main/CHANGELOG.md)
- [Commits](paulmillr/noble-ciphers@2.3.0...2.4.0)

Updates `fumadocs-core` from 16.14.4 to 16.15.15
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.14.4...fumadocs@16.15.15)

Updates `fumadocs-mdx` from 15.2.3 to 15.4.5
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.2.3...fumadocs-mdx@15.4.5)

Updates `fumadocs-ui` from 16.14.4 to 16.15.15
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.14.4...fumadocs@16.15.15)

Updates `lucide-react` from 1.31.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `next` from 16.3.3 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.3...v16.3.6)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

---
updated-dependencies:
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: chalk
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: sql.js
  dependency-version: 1.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: mongodb
  dependency-version: 7.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@libsql/client"
  dependency-version: 0.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@better-auth/core"
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@better-auth/oauth-provider"
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@better-auth/scim"
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@better-auth/sso"
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@noble/hashes"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: better-auth
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: jose
  dependency-version: 6.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: hono
  dependency-version: 4.13.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: nodemailer
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: pinyin-pro
  dependency-version: 3.29.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@noble/ciphers"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: fumadocs-core
  dependency-version: 16.15.15
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: fumadocs-mdx
  dependency-version: 15.4.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: fumadocs-ui
  dependency-version: 16.15.15
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@github-actions github-actions Bot added size/m documentation Improvements or additions to documentation labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

⚠️ 19 changed file(s) yielded no anchor (packages/cli/package.json, packages/connectors/connector-mcp/package.json, packages/core/package.json, …), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files. Nothing else in this diff resolved to a documentable surface (no symbol, route or SDK anchor derived from 19 changed package(s)).

What this run could not see
  • 19 changed file(s) yielded no anchor (packages/cli/package.json, packages/connectors/connector-mcp/package.json, packages/core/package.json, …) — pages documenting those are invisible to this run
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 159 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 2f2fa11d756f665a4c06160480c1dce15b9d67a4 → packageMentionDocs.

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Closed 2026-10-01T06:03Z in favour of #21094, on the maintainer's instruction.

Provenance:

  • Who: the maintainer.
  • Verbatim: 「按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地」
  • Where: PM seat session session_018gA1pE6eJtwHhqx72G8U9X, 2026-10-01.

Why this PR cannot land as generated:

#21094 carries the rest of the group with those corrections.


Generated by Claude Code

@objectstack-fleet objectstack-fleet Bot closed this Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-28abf4773c branch October 1, 2026 06:04
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…ompurify GHSA-p98j-92pf-mc4p (objectstack-ai#21083)

Fixes objectstack-ai#21055

Clause-②: no

## Summary

`Validate Package Dependencies` runs OSV-Scanner against
`pnpm-lock.yaml`. On `main` it flags two rows, so the scheduled scan is
red, and so is every PR that touches a `package.json`:

| Advisory | CVSS | Package | Locked on main | Fixed in |
|---|---|---|---|---|
| GHSA-vcvr-r3jv-pc5j | 9.5 | `next` | 16.3.3 | 16.3.6 |
| GHSA-p98j-92pf-mc4p | 2.3 | `dompurify` | 3.4.13 | 3.4.16 |

Both advisories name a fixed version, so this PR takes the fix.
`osv-scanner.toml` is untouched and still holds zero exemptions.

## Change

- **`apps/docs/package.json`:** the direct `next` pin moves from
`16.3.3` to `16.3.6`. The pin stays exact, as it was. 16.3.6 is the
advisory's fixed version and the same target as Dependabot's grouped
objectstack-ai#21029, so after this lands, that PR's `next` line is already satisfied
rather than in conflict. The newer patches (16.3.7, 16.3.8) are left to
the Dependabot group. No workspace manifest declares
`eslint-config-next` or any `@next/*` package. The nine `@next/*`
packages in the lockfile are `next`'s own dependencies and move with it.
- **`pnpm-workspace.yaml`:** the existing `dompurify` override's target
goes from `^3.4.13` to `^3.4.16`. Its selector is unchanged, still
bounded at the 4.0.0 major. The OSV comment above it is extended in
place, in the style of its neighbours. This PR adds no second override
and does not touch the root `package.json`.
- **`pnpm-lock.yaml`:** regenerated, not hand-edited (see below).

**Correction to the issue body.** The issue says the root
`pnpm.overrides` has no floor for `dompurify`. On `main`, the
workspace's overrides live in `pnpm-workspace.yaml`, because pnpm 10
ignores `pnpm.overrides` in `package.json`. A `dompurify` entry was
already there at `^3.4.13`, added for an earlier advisory (objectstack-ai#6407). The
new advisory's range is introduced 3.4.13, fixed 3.4.16, so the old
floor was itself the first affected version. The existing comment had
predicted this: it explains that the selector is bounded at the major so
that a target-only lift is all a case like this needs. `mermaid@11.16.1`
declares `dompurify ^3.3.3`, which admits 3.4.16, so this is a dedupe
onto the patched line and does not force an upgrade past what `mermaid`
supports.

**Reach.** `apps/docs/app/og/docs/[...slug]/route.tsx` imports
`ImageResponse` from `next/og`. That is the surface GHSA-vcvr-r3jv-pc5j
names ("Remote Code Execution in next/og ImageResponse").

## Lockfile

Regenerated with `pnpm install --lockfile-only` under pnpm 10.31.0, the
`packageManager` version.

- **Size:** 69 lines changed on each side, 138 in total.
- **Locked package set:** 11 entries removed and 11 added, and the count
stays at 1369. The entries are `next`, `@next/env`, the eight
`@next/swc-*` binaries, and `dompurify`.
- **Everything else:** the other changed lines are peer-suffixed
snapshot keys that embed the `next` version. They belong to
`better-auth`, its three `@better-auth/*` plugins, and `fumadocs-core` /
`fumadocs-mdx` / `fumadocs-ui`. None of those packages changes version.
- **Frozen install:** `pnpm install --frozen-lockfile` passes on the
result.

## OSV-Scanner, before and after

I ran OSV-Scanner v2.3.8, the version the workflow's action pins. The
binary's SHA-256 (`bc98e153…`) matches the release's checksum file. The
command was `scan --offline-vulnerabilities --lockfile=pnpm-lock.yaml`.
The container's egress proxy refuses `api.osv.dev`, so the scan reads
the offline npm database the scanner downloads, the same method as
objectstack-ai#20774.

| Tree | Exit | Result |
|---|---|---|
| `main` at `5dbeb7d7b7` | 1 | exactly the two rows above (1 Critical, 1
Low) |
| this branch at `68c26aa189` | 0 | `No issues found` (1369 packages) |

## Changeset decision

No changeset; this PR should carry the `skip-changeset` label. Nothing
it touches is published:

- `apps/docs` is `"private": true`.
- `pnpm-workspace.yaml` overrides and `pnpm-lock.yaml` are in no
package's `files[]`, and no published manifest changes.

`check:override-consistency` still reports its 9 published-manifest
declarations covered, and `check:published-files` is green.

## What I ran

The final head is `68c26aa189`: my commit, then a merge of `main` at
`0c5a71b094`. Every row below was measured on that head. The build and
the docs checks were also green on `3714ec8cef`, before the merge.

| Check | Result |
|---|---|
| `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack
--commands` | 41 commands |
| All 41, run on `68c26aa189` after a rebuild, codes recorded with the
`--ran` idiom | 41 exit 0 |
| `dispatch-gates --ran` | `41 derived, 41 run, 0 NOT-MEASURED, 0 UNRUN`
|
| `pnpm build` under the shared verify lock, `--concurrency=2` | 72/72,
both at `3714ec8cef` and at `68c26aa189` |
| `pnpm --filter @objectstack/docs typecheck` (`fumadocs-mdx && next
typegen && tsc --noEmit`) | exit 0 |
| Docs production build command (`apps/docs/vercel.json`): `pnpm turbo
run build --filter=@objectstack/docs` | exit 0, `Next.js 16.3.6`,
`.next/BUILD_ID` written, and the docs task was a cache miss, so it
really executed |
| `check:override-consistency`, `check:vendor-export-contract-resolve`,
`check-osv-exemptions`, `check:nul-bytes`,
`check:workspace-manifest-cycles` | all exit 0 (within the 41) |

One deliberate difference from CI: the docs build ran without CI's
`TURBO_FORCE`, which would also re-execute the `spec` build. The docs
task itself missed the cache and ran. No package test suite applies,
because no package source changes. CI's shard, dogfood and workspace
type-check lanes are left to CI.

## Acceptance notes

- The premise correction above, about where the `dompurify` override
lives, applies to the issue body only. It does not affect the remedy.
- Dependabot's grouped objectstack-ai#21029 stays open. Once this lands, its `next`
line is already satisfied, and Dependabot will rebase its lockfile.

---

_Generated by [Claude
Code](https://claude.ai/code/session_01JAhu8u8QfBvRjVZDox7CP9)_

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
… better-auth family (objectstack-ai#21094) (objectstack-ai#21162)

Fixes objectstack-ai#21094

Clause-②: no

Takes the 2026-10 production-dependency group that Dependabot opened as
objectstack-ai#21029 (closed in favour of this card), without the better-auth family
and without `next`. Maintainer ruling, verbatim:

> 按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地

## What lands

- **43 manifests, 64 range moves.** The 63 range moves objectstack-ai#21029 made
(diffed from its merge base `9b0de7de73` to its head `c0b7dd923e`) were
re-applied one line at a time onto current `main`. The 64th is the `tsx`
devDependency objectstack-ai#21160 added to
`packages/drivers/driver-turso/package.json`, lifted from `^4.23.12` to
`^4.23.15` after objectstack-ai#21160 was merged in. Each move matched the exact old
spelling or the script refused. Excluded: `apps/docs/package.json`
(`next` belongs to objectstack-ai#21055 / objectstack-ai#21083) and the five better-auth family
lines in `packages/plugins/plugin-auth/package.json`, which stay at
`1.7.3`. `pnpm-workspace.yaml` is not touched. Check, taken before the
objectstack-ai#21160 merge: the sorted `-`/`+` lines of this branch's manifest diff
equal objectstack-ai#21029's lines minus those exclusions (`diff` exit 0, 126 lines).
- **`pnpm-lock.yaml`**, regenerated with the tooling in three steps
(pnpm 10.31.0, the `packageManager` pin), never by hand:
  1. `pnpm install --lockfile-only`, starting from main's lockfile.
2. `pnpm --filter @objectstack/plugin-hono-server --filter
@objectstack/plugin-auth --filter @objectstack/hono update
--lockfile-only --no-save hono`. Step 1 left `hono` at 4.13.7, below the
`^4.13.9` that `plugin-hono-server` now publishes. The workspace
override for `hono` (selector below 5.0.0) rewrites every declaration to
`^4.13.5`, which 4.13.7 still satisfies, so lockfile inertia kept the
old version. CI would have certified 4.13.7 while a downstream install
gets 4.13.12. That is the declared-versus-tested split the card names
for better-auth. Step 2 moves the single `hono` copy to 4.13.12 without
editing the override or any manifest. An unfiltered `pnpm update -r` was
tried and discarded: it also dropped `knex`'s `mysql2` / `pg` /
`tedious` peer links in two importers.
3. After objectstack-ai#21160 landed: merge `main` (`e35c40a52`), lift driver-turso's
new `tsx` line, and run `pnpm install --lockfile-only` again.
- The result is a fixed point: a second `pnpm install --lockfile-only`
leaves it byte-identical, and `pnpm install --frozen-lockfile` passes.
Lockfile blob `30ba2147`. The resolved set is unchanged from the set the
OSV scan below covered: 0 names differ.
- **`packages/drivers/driver-turso/src/**`**: the item-4 restamp, 21
lines in 7 files (below).
- **`packages/spec/src/data/driver/common.zod.ts` and
`driver-credential-refusal.test.ts`**: the `@libsql/core` version label
is restamped from 0.17.4 to 0.18.0. The TSDoc of
`CREDENTIAL_URL_QUERY_PARAMS` says it was measured "in the versions
pinned by this tree", so leaving 0.17.4 would have made it false. The
behaviour was re-measured identical on the installed 0.18.0:
`?authToken=` overrides the config token, `auth%54oken` is decoded,
`AuthToken` and `token` give `URL_PARAM_NOT_SUPPORTED`, and the control
without a query keeps the config token.
- **`.changeset/21094-prod-deps-group.md`**: `patch` for the 19
published packages whose `dependencies` range moves. The list was
re-derived from this diff and matches the PM correction on the card,
`plugin-auth` included (`@noble/hashes`, `jose`).

## Resolved versions against the merge base

Every changed `name@version` pair in the `packages:` section, compared
with `main` at `e35c40a52`: 25 names change. **DOWN: 0.**

| package | merge base | this branch |
|:--|:--|:--|
| `@libsql/client` / `@libsql/core` | 0.17.4 | 0.18.0 |
| `zod` | 4.6.1 | 4.6.5 (4.6.1 kept by `apps/docs` only) |
| `@modelcontextprotocol/sdk` | 1.30.0 | 1.31.0 |
| `hono` | 4.13.7 | 4.13.12 |
| `mongodb` | 7.5.0 | 7.7.0 (7.5.0 kept by `mongodb-memory-server-core`
only) |
| `jose` | 6.2.7, 6.2.8 | 6.2.12 |
| `@noble/hashes` | 2.3.0 | 2.4.0 |
| `@noble/ciphers` | 2.3.0 | 2.4.0 (2.3.0 kept by better-auth 1.7.3
only) |
| `react` / `react-dom` / `@types/react` / `@types/react-dom` | 19.2.x |
19.3.0 (19.2.x kept by `apps/docs` only) |
| `tsx` | 4.23.12 | 4.23.15 |
| `yaml` | 2.9.0 | 2.9.1 (2.9.0 kept by the `apps/docs` fumadocs tree
only) |
| `chalk` | 6.0.0 | 6.0.1 |
| `sql.js` | 1.14.1 | 1.14.2 |
| `pinyin-pro` | 3.29.1 | 3.29.4 |
| deduped onto a newer copy already present | `@hono/node-server`
2.0.12, `ws` 8.21.1, `@types/ws` 8.18.1, `eventsource-parser` 3.1.0 |
removed (2.1.1, 8.22.0, 8.18.2, 3.1.1 stay) |
| new transitive copies beside the old ones | none | `bson` 7.3.3 and
`@mongodb-js/saslprep` 1.5.5 (with `mongodb` 7.7.0), `scheduler` 0.28.0
(with `react-dom` 19.3.0) |

`nodemailer` stays at **10.0.13**, main's version and at least the
required 10.0.12. Dependabot's regeneration had moved it down to
10.0.11.

## Item 4: `@libsql/client` lifted to `^0.18.0`, because the premise
holds

The premise was measured before any driver edit, three ways.

1. **Package diff.** `npm pack` of both releases. `@libsql/core` 0.17.4
and 0.18.0 differ only in `package.json` (the version). `@libsql/client`
differs only in `lib-esm/sqlite3.js`, `lib-cjs/sqlite3.js`,
`lib-esm/sqlite3.d.ts` and `package.json`. The change is a connection
pool for the local `file:` client. `http.js`, `ws.js` and `node.js` are
byte-identical. Installed side by side, `@libsql/hrana-client` 0.10.0
and native `libsql` 0.5.29 (with `@libsql/linux-x64-gnu`) are
byte-identical too.
2. **Executed probe, same script against both installs.** Output is
identical except for the version strings and one count: `syncUrl`
occurrences in `sqlite3.js` go from 3 to 4 (the new pool-size line).
3. **The driver's own suite.** At base with 0.17.4: 81 files, 2210
passed, 33 skipped. With 0.18.0, before the restamp: 2209 passed, 1
failed, 33 skipped. Per-test outcomes are identical except the version
pin (`expected '0.18.0' to be '0.17.4'`). After the restamp: 2210
passed, 33 skipped. At `0f87e8488`, with objectstack-ai#21160's tests merged in: 2218
passed, 33 skipped, 0 failed.

| site (at base) | claim | 0.18.0 reading | verdict |
|:--|:--|:--|:--|
| `turso-authtoken-url-channel.test.ts:17-18` | client / core / native
versions, range | client 0.18.0, core 0.18.0, native `libsql` 0.5.29;
range now `^0.18.0`. Answers 1-4 (live wire, child-process replica
endpoint) pass, 7/7 non-pin cases, as 8/8 did on 0.17.4 | held,
restamped |
| `turso-authtoken-url-channel.test.ts:281` | version pin | `0.18.0` |
pin moved |
| `turso-driver-remote-url-replica-refusal.test.ts:28`,
`turso-driver.ts:1288`, `:1384` (message) | no embedded replica for a
remote url | `syncUrl` lines: `http.js` 0, `ws.js` 0, control
`authToken` lines 6 / 6. `https` and `ws` clients' `sync()` reject
`SYNC_NOT_SUPPORTED`. `:memory:` + `syncUrl` throws `URL_INVALID`
("Embedded replica must use file for local db"). File 27/27 on both
versions | held |
| `turso-driver-timeout.test.ts:9`, `turso-driver.ts:152` | HTTP arm
rides `Config.fetch`; replica `sync()` is native | `http.js` (one
`config.fetch` site) and hrana-client byte-identical. Timeout file 5/5,
supplied-client refusal file 13/13 on both | held |
| `turso-driver.ts:871` | `Config.timeout` is the busy timeout; "remote
clients ignore it" | core `api.d.ts` docblock byte-identical | held |
| `turso-driver-unrecognised-url-refusal.test.ts:26`,
`turso-driver.ts:1313`, `:1417` (message) | refusals of urls the client
rejects | `URL_INVALID` for `./data/app.db`, `data/app.db`,
`/abs/app.db`, `:MEMORY:`, empty, `libsql:host` (bare paths "not in a
valid format"). `URL_SCHEME_NOT_SUPPORTED` for `sqlite:`, `memory://`,
`C:\data\app.db`. File 42/42 on both | held |
| `turso-driver-uppercase-ws-scheme-timeout-refusal.test.ts:15`, `:26`,
`turso-driver.ts:932` | `expandConfig` lowercases the scheme before the
switch | `WSS://…` gives `wss`, `Ws://…` gives `ws`, control
`LIBSQL://…` gives `https`. `_createClient(expandConfig(config, true))`
present (1 hit). File 20/20 on both | held |
| `turso-driver-ws-timeout-refusal.test.ts:10`, `turso-driver.ts:963`,
`:1001` (message) | the WS client takes no `fetch` and no timeout |
`ws.js`: `fetch` 0, `timeout` 0. hrana `ws/*.js` + `index.js` `timeout`
0, control `fetch` over `http/*.js` 15. File 11/11 on both | held |
| `turso-driver.ts:1061` (message) | a built client's transport cannot
be re-seamed | `config.fetch` is read once, inside `_createClient` in
`http.js` (byte-identical) | held |
| `turso-driver.ts:1212` | the client folds scheme case and opens each
spelling | `FILE:./x.db` gives `file`, `Wss://` gives `wss`, `LIBSQL://`
gives `https`. `createClient` opens each (`http` / `ws` / `file`) | held
|
| `turso-driver.ts:1244` | `:memory:` expands to `file::memory:`;
`isInMemoryConfig` | `file::memory:`. `true` for `file::memory:` and
`file::memory:?cache=shared`, control `false` for `file:./x.db` | held |

After the edit, `git grep -n -E "0\.17\.[0-9]" --
packages/drivers/driver-turso/src` returns 0 lines (exit 1). The control
is the 23 `0.18.0` occurrences in the same 7 files.

## What objectstack-ai#21029 never measured

- **Test Core shard 4's eight unreached packages**, measured at
`cf1d700b`, before the `main` merge: `rest` 250 files, 4728 passed / 248
skipped. `driver-sql` 205 files, 3303 passed / 188 skipped.
`plugin-email` 31 files, 510 passed. `plugin-approvals` 52 files, 804
passed. `plugin-webhooks` 13 files, 160 passed. `trigger-schedule` 8
files, 170 passed. `connector-mcp` 3 files, 23 passed. `client-react` 3
files, 34 passed. Turbo ran 45 of 45 tasks, exit 0.
- **`Lint & Repo Gates` from `check:vendor-export-contract` on**: `pnpm
check:vendor-export-contract` reads `VERDICT: PASS — vendor export
contract (installed workspace), 1 edge(s) verified` (better-auth 1.7.3),
and the `-resolve` variant passes on the registry. The 72 later steps of
that job were not run here. They belong to CI's run on this PR. The
families this diff derives are below.
- **OSV.** `osv-scanner` v2.3.8, built from the Go module proxy because
this container's egress refuses `api.osv.dev`. It ran on the offline npm
database over lockfile blob `70547c67` (its resolved set is identical to
the current `30ba2147`), with the repo's `osv-scanner.toml` loaded: 1388
packages, `No issues found`, exit 0. Positive control: the same lockfile
with `hono` rewritten to 4.12.32 gives exit 1 and 8 advisories on
`hono`, among them GHSA-8j4g-w8fx-2239. CI's online step is the
authoritative reading.
- **`zod` 4.6.5 and `z.properties()`**: `git grep -n -E
"z\.properties\(" -- packages/` returns 0 lines; control `z.object(`,
1825 lines.
- **`mongodb` live suites**: NOT MEASURED. They need a `mongod` download
from `fastdl.mongodb.org`, which this container's egress refuses
(CONNECT 403). The default `driver-mongodb` suite passes: 30 files, 675
passed, 172 skipped (the five opt-in live files).

## Gates and tests

Gate families derived by `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` (no paths, change set from git)
at HEAD **`0f87e8488`** (54 paths against merge base `e35c40a52`): 117
commands. All 117 exit 0, and so does `pnpm
check:vendor-export-contract`. Exit codes were captured before any pipe.
`--ran` reconciliation: `117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN`,
a derived zero with an exit code on every line.

Package suites, all exit 0:

- At `cf1d700b`: `driver-mongodb`, `mcp` 32/344, `plugin-hono-server`
27/324, `plugin-auth` 115/2472, `service-settings` 33/584,
`plugin-pinyin-search` 2/21, `driver-sqlite-wasm` 36/675,
`driver-memory` 69/1613, `service-analytics` 155/3526 (10 skipped),
`create-objectstack` 16/247, `@objectstack/hono` 5/122. Also
`@objectstack/cli` `--project unit` 242/3432 and `@objectstack/spec`
`--project local` 591 files / 17368 passed.
- `typecheck`: the 19 moving packages plus `client-react`,
`@objectstack/hono` and `lint`. Turbo ran 80 of 80 tasks.
- At `0f87e8488`, after the objectstack-ai#21160 merge and a full rebuild: the
`driver-turso` suite (82 files) gives 2218 passed / 33 skipped / 0
failed. That includes objectstack-ai#21160's new tests, run on 0.18.0; its two-process
concurrency test overlapped, with 400 writes and 400 distinct numbers.
`typecheck` passes, and `pnpm install --frozen-lockfile` passes.

## Acceptance notes

- **Duplicate copies left by the exclusions**: `zod` 4.6.1, `react`
19.2.8 and `yaml` 2.9.0 are kept only by the excluded `apps/docs` tree.
`@noble/ciphers` 2.3.0 is kept only by the excluded better-auth 1.7.3.
`mongodb` 7.5.0 is kept only by the test harness
`mongodb-memory-server-core` 11.3.0.
- **libsql 0.18.0's one behaviour change, from reading the code (not
measured):** the local client now pools connections, with one connection
for `:memory:` and for embedded replicas. On a replica, a second
`sync()` therefore waits for the first to release the connection. On
0.17.4 the two ran at once on the same native handle. With `timeout`
set, a sync that outlives the window keeps running natively,
uncancelled, so the next periodic sync queues behind it. No driver
docblock claims either behaviour.
- **The remaining 0.17.4 stamps stay**: outside `CHANGELOG.md`, only
`service-package` `index.ts:192` and `mysql2-tuple.test.ts:172` name
0.17.4 ("Measured on `@libsql/client` 0.17.4"). That is a dated
attestation and stays true; the `result.rows` shape was re-measured
identical on 0.18.0.
- **Environment side effect, nothing committed**: turbo 2.11.5 appends a
managed block to `AGENTS.md` whenever an agent runs a repository-scoped
turbo command. It was restored after each turbo run with `git restore
--source=HEAD --staged --worktree AGENTS.md`. No commit on this branch
touches `AGENTS.md`.
- **Merge-queue ejection and its fix**: objectstack-ai#21160 added driver-turso's
`tsx` at 4.23.12 while this branch removes `tsx@4.23.12`. The two
lockfiles merged into one that `pnpm install --frozen-lockfile` refuses.
Fixed by merging `main` at `e35c40a52`, lifting that `tsx` line, and
regenerating the lockfile with pnpm.

---
_Generated by [Claude
Code](https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation javascript Pull requests that update javascript code size/m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants