Repository navigation
chore(deps)(deps): bump the production-dependencies group with 27 updates - #21029
dependabot[bot] wants to merge 1 commit into
Conversation
…ates Bumps the production-dependencies group with 27 updates: | Package | From | To | | --- | --- | --- | | [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.15` | | [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` | | [chalk](https://github.com/chalk/chalk) | `6.0.0` | `6.0.1` | | [zod](https://github.com/colinhacks/zod) | `4.6.1` | `4.6.5` | | [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` | | [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` | | [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.30.1` | | [sql.js](https://github.com/sql-js/sql.js) | `1.14.1` | `1.14.2` | | [mongodb](https://github.com/mongodb/node-mongodb-native) | `7.5.0` | `7.6.0` | | [@libsql/client](https://github.com/tursodatabase/libsql-client-ts/tree/HEAD/packages/libsql-client) | `0.17.4` | `0.18.0` | | [@better-auth/core](https://github.com/better-auth/better-auth/tree/HEAD/packages/core) | `1.7.3` | `1.7.6` | | [@better-auth/oauth-provider](https://github.com/better-auth/better-auth/tree/HEAD/packages/oauth-provider) | `1.7.3` | `1.7.6` | | [@better-auth/scim](https://github.com/better-auth/better-auth/tree/HEAD/packages/scim) | `1.7.3` | `1.7.6` | | [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) | `1.7.3` | `1.7.6` | | [@noble/hashes](https://github.com/paulmillr/noble-hashes) | `2.3.0` | `2.4.0` | | [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.3` | `1.7.6` | | [jose](https://github.com/panva/jose) | `6.2.8` | `6.2.12` | | [hono](https://github.com/honojs/hono) | `4.13.7` | `4.13.9` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `10.0.12` | `10.0.11` | | [pinyin-pro](https://github.com/zh-lx/pinyin-pro/tree/HEAD/packages/pinyin-pro) | `3.29.1` | `3.29.4` | | [@noble/ciphers](https://github.com/paulmillr/noble-ciphers) | `2.3.0` | `2.4.0` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.14.4` | `16.15.15` | | [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `15.2.3` | `15.4.5` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.14.4` | `16.15.15` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.48.0` | | [next](https://github.com/vercel/next.js) | `16.3.3` | `16.3.6` | | [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` | Updates `tsx` from 4.23.12 to 4.23.15 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.12...v4.23.15) Updates `yaml` from 2.9.0 to 2.9.1 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.9.0...v2.9.1) Updates `chalk` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/chalk/chalk/releases) - [Commits](chalk/chalk@v6.0.0...v6.0.1) Updates `zod` from 4.6.1 to 4.6.5 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.6.1...v4.6.5) Updates `react` from 19.2.8 to 19.3.0 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.3.0/packages/react) Updates `react-dom` from 19.2.8 to 19.3.0 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom) Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1) Updates `sql.js` from 1.14.1 to 1.14.2 - [Release notes](https://github.com/sql-js/sql.js/releases) - [Commits](sql-js/sql.js@v1.14.1...v1.14.2) Updates `mongodb` from 7.5.0 to 7.6.0 - [Release notes](https://github.com/mongodb/node-mongodb-native/releases) - [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md) - [Commits](mongodb/node-mongodb-native@v7.5.0...v7.6.0) Updates `@libsql/client` from 0.17.4 to 0.18.0 - [Release notes](https://github.com/tursodatabase/libsql-client-ts/releases) - [Changelog](https://github.com/tursodatabase/libsql-client-ts/blob/main/CHANGELOG.md) - [Commits](https://github.com/tursodatabase/libsql-client-ts/commits/v0.18.0/packages/libsql-client) Updates `@better-auth/core` from 1.7.3 to 1.7.6 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/core/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/core) Updates `@better-auth/oauth-provider` from 1.7.3 to 1.7.6 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/oauth-provider/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/oauth-provider) Updates `@better-auth/scim` from 1.7.3 to 1.7.6 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/scim/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/scim) Updates `@better-auth/sso` from 1.7.3 to 1.7.6 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/sso/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/sso) Updates `@noble/hashes` from 2.3.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/noble-hashes/releases) - [Changelog](https://github.com/paulmillr/noble-hashes/blob/main/CHANGELOG.md) - [Commits](paulmillr/noble-hashes@2.3.0...2.4.0) Updates `better-auth` from 1.7.3 to 1.7.6 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/better-auth) Updates `jose` from 6.2.8 to 6.2.12 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](panva/jose@v6.2.8...v6.2.12) Updates `hono` from 4.13.7 to 4.13.9 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.13.7...v4.13.9) Updates `nodemailer` from 10.0.12 to 10.0.11 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v10.0.12...v10.0.11) Updates `pinyin-pro` from 3.29.1 to 3.29.4 - [Release notes](https://github.com/zh-lx/pinyin-pro/releases) - [Changelog](https://github.com/zh-lx/pinyin-pro/blob/main/CHANGELOG.md) - [Commits](https://github.com/zh-lx/pinyin-pro/commits/3.29.4/packages/pinyin-pro) Updates `@noble/ciphers` from 2.3.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/noble-ciphers/releases) - [Changelog](https://github.com/paulmillr/noble-ciphers/blob/main/CHANGELOG.md) - [Commits](paulmillr/noble-ciphers@2.3.0...2.4.0) Updates `fumadocs-core` from 16.14.4 to 16.15.15 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.14.4...fumadocs@16.15.15) Updates `fumadocs-mdx` from 15.2.3 to 15.4.5 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.2.3...fumadocs-mdx@15.4.5) Updates `fumadocs-ui` from 16.14.4 to 16.15.15 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.14.4...fumadocs@16.15.15) Updates `lucide-react` from 1.31.0 to 1.48.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react) Updates `next` from 16.3.3 to 16.3.6 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.3.3...v16.3.6) Updates `tailwind-merge` from 3.6.0 to 3.7.0 - [Release notes](https://github.com/dcastil/tailwind-merge/releases) - [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge) --- updated-dependencies: - dependency-name: tsx dependency-version: 4.23.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: yaml dependency-version: 2.9.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: chalk dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: zod dependency-version: 4.6.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: react dependency-version: 19.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: react-dom dependency-version: 19.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.30.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: sql.js dependency-version: 1.14.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: mongodb dependency-version: 7.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: "@libsql/client" dependency-version: 0.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: "@better-auth/core" dependency-version: 1.7.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@better-auth/oauth-provider" dependency-version: 1.7.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@better-auth/scim" dependency-version: 1.7.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@better-auth/sso" dependency-version: 1.7.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@noble/hashes" dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: better-auth dependency-version: 1.7.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: jose dependency-version: 6.2.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: hono dependency-version: 4.13.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: nodemailer dependency-version: 10.0.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: pinyin-pro dependency-version: 3.29.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@noble/ciphers" dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: fumadocs-core dependency-version: 16.15.15 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: fumadocs-mdx dependency-version: 15.4.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: fumadocs-ui dependency-version: 16.15.15 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: lucide-react dependency-version: 1.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: next dependency-version: 16.3.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: tailwind-merge dependency-version: 3.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
📓 Docs Drift Check
What this run could not see
Coarse fallback — 159 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): |
|
Closed 2026-10-01T06:03Z in favour of #21094, on the maintainer's instruction. Provenance:
Why this PR cannot land as generated:
#21094 carries the rest of the group with those corrections. Generated by Claude Code |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
…ompurify GHSA-p98j-92pf-mc4p (objectstack-ai#21083) Fixes objectstack-ai#21055 Clause-②: no ## Summary `Validate Package Dependencies` runs OSV-Scanner against `pnpm-lock.yaml`. On `main` it flags two rows, so the scheduled scan is red, and so is every PR that touches a `package.json`: | Advisory | CVSS | Package | Locked on main | Fixed in | |---|---|---|---|---| | GHSA-vcvr-r3jv-pc5j | 9.5 | `next` | 16.3.3 | 16.3.6 | | GHSA-p98j-92pf-mc4p | 2.3 | `dompurify` | 3.4.13 | 3.4.16 | Both advisories name a fixed version, so this PR takes the fix. `osv-scanner.toml` is untouched and still holds zero exemptions. ## Change - **`apps/docs/package.json`:** the direct `next` pin moves from `16.3.3` to `16.3.6`. The pin stays exact, as it was. 16.3.6 is the advisory's fixed version and the same target as Dependabot's grouped objectstack-ai#21029, so after this lands, that PR's `next` line is already satisfied rather than in conflict. The newer patches (16.3.7, 16.3.8) are left to the Dependabot group. No workspace manifest declares `eslint-config-next` or any `@next/*` package. The nine `@next/*` packages in the lockfile are `next`'s own dependencies and move with it. - **`pnpm-workspace.yaml`:** the existing `dompurify` override's target goes from `^3.4.13` to `^3.4.16`. Its selector is unchanged, still bounded at the 4.0.0 major. The OSV comment above it is extended in place, in the style of its neighbours. This PR adds no second override and does not touch the root `package.json`. - **`pnpm-lock.yaml`:** regenerated, not hand-edited (see below). **Correction to the issue body.** The issue says the root `pnpm.overrides` has no floor for `dompurify`. On `main`, the workspace's overrides live in `pnpm-workspace.yaml`, because pnpm 10 ignores `pnpm.overrides` in `package.json`. A `dompurify` entry was already there at `^3.4.13`, added for an earlier advisory (objectstack-ai#6407). The new advisory's range is introduced 3.4.13, fixed 3.4.16, so the old floor was itself the first affected version. The existing comment had predicted this: it explains that the selector is bounded at the major so that a target-only lift is all a case like this needs. `mermaid@11.16.1` declares `dompurify ^3.3.3`, which admits 3.4.16, so this is a dedupe onto the patched line and does not force an upgrade past what `mermaid` supports. **Reach.** `apps/docs/app/og/docs/[...slug]/route.tsx` imports `ImageResponse` from `next/og`. That is the surface GHSA-vcvr-r3jv-pc5j names ("Remote Code Execution in next/og ImageResponse"). ## Lockfile Regenerated with `pnpm install --lockfile-only` under pnpm 10.31.0, the `packageManager` version. - **Size:** 69 lines changed on each side, 138 in total. - **Locked package set:** 11 entries removed and 11 added, and the count stays at 1369. The entries are `next`, `@next/env`, the eight `@next/swc-*` binaries, and `dompurify`. - **Everything else:** the other changed lines are peer-suffixed snapshot keys that embed the `next` version. They belong to `better-auth`, its three `@better-auth/*` plugins, and `fumadocs-core` / `fumadocs-mdx` / `fumadocs-ui`. None of those packages changes version. - **Frozen install:** `pnpm install --frozen-lockfile` passes on the result. ## OSV-Scanner, before and after I ran OSV-Scanner v2.3.8, the version the workflow's action pins. The binary's SHA-256 (`bc98e153…`) matches the release's checksum file. The command was `scan --offline-vulnerabilities --lockfile=pnpm-lock.yaml`. The container's egress proxy refuses `api.osv.dev`, so the scan reads the offline npm database the scanner downloads, the same method as objectstack-ai#20774. | Tree | Exit | Result | |---|---|---| | `main` at `5dbeb7d7b7` | 1 | exactly the two rows above (1 Critical, 1 Low) | | this branch at `68c26aa189` | 0 | `No issues found` (1369 packages) | ## Changeset decision No changeset; this PR should carry the `skip-changeset` label. Nothing it touches is published: - `apps/docs` is `"private": true`. - `pnpm-workspace.yaml` overrides and `pnpm-lock.yaml` are in no package's `files[]`, and no published manifest changes. `check:override-consistency` still reports its 9 published-manifest declarations covered, and `check:published-files` is green. ## What I ran The final head is `68c26aa189`: my commit, then a merge of `main` at `0c5a71b094`. Every row below was measured on that head. The build and the docs checks were also green on `3714ec8cef`, before the merge. | Check | Result | |---|---| | `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` | 41 commands | | All 41, run on `68c26aa189` after a rebuild, codes recorded with the `--ran` idiom | 41 exit 0 | | `dispatch-gates --ran` | `41 derived, 41 run, 0 NOT-MEASURED, 0 UNRUN` | | `pnpm build` under the shared verify lock, `--concurrency=2` | 72/72, both at `3714ec8cef` and at `68c26aa189` | | `pnpm --filter @objectstack/docs typecheck` (`fumadocs-mdx && next typegen && tsc --noEmit`) | exit 0 | | Docs production build command (`apps/docs/vercel.json`): `pnpm turbo run build --filter=@objectstack/docs` | exit 0, `Next.js 16.3.6`, `.next/BUILD_ID` written, and the docs task was a cache miss, so it really executed | | `check:override-consistency`, `check:vendor-export-contract-resolve`, `check-osv-exemptions`, `check:nul-bytes`, `check:workspace-manifest-cycles` | all exit 0 (within the 41) | One deliberate difference from CI: the docs build ran without CI's `TURBO_FORCE`, which would also re-execute the `spec` build. The docs task itself missed the cache and ran. No package test suite applies, because no package source changes. CI's shard, dogfood and workspace type-check lanes are left to CI. ## Acceptance notes - The premise correction above, about where the `dompurify` override lives, applies to the issue body only. It does not affect the remedy. - Dependabot's grouped objectstack-ai#21029 stays open. Once this lands, its `next` line is already satisfied, and Dependabot will rebase its lockfile. --- _Generated by [Claude Code](https://claude.ai/code/session_01JAhu8u8QfBvRjVZDox7CP9)_ Co-authored-by: Claude <noreply@anthropic.com>
… better-auth family (objectstack-ai#21094) (objectstack-ai#21162) Fixes objectstack-ai#21094 Clause-②: no Takes the 2026-10 production-dependency group that Dependabot opened as objectstack-ai#21029 (closed in favour of this card), without the better-auth family and without `next`. Maintainer ruling, verbatim: > 按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地 ## What lands - **43 manifests, 64 range moves.** The 63 range moves objectstack-ai#21029 made (diffed from its merge base `9b0de7de73` to its head `c0b7dd923e`) were re-applied one line at a time onto current `main`. The 64th is the `tsx` devDependency objectstack-ai#21160 added to `packages/drivers/driver-turso/package.json`, lifted from `^4.23.12` to `^4.23.15` after objectstack-ai#21160 was merged in. Each move matched the exact old spelling or the script refused. Excluded: `apps/docs/package.json` (`next` belongs to objectstack-ai#21055 / objectstack-ai#21083) and the five better-auth family lines in `packages/plugins/plugin-auth/package.json`, which stay at `1.7.3`. `pnpm-workspace.yaml` is not touched. Check, taken before the objectstack-ai#21160 merge: the sorted `-`/`+` lines of this branch's manifest diff equal objectstack-ai#21029's lines minus those exclusions (`diff` exit 0, 126 lines). - **`pnpm-lock.yaml`**, regenerated with the tooling in three steps (pnpm 10.31.0, the `packageManager` pin), never by hand: 1. `pnpm install --lockfile-only`, starting from main's lockfile. 2. `pnpm --filter @objectstack/plugin-hono-server --filter @objectstack/plugin-auth --filter @objectstack/hono update --lockfile-only --no-save hono`. Step 1 left `hono` at 4.13.7, below the `^4.13.9` that `plugin-hono-server` now publishes. The workspace override for `hono` (selector below 5.0.0) rewrites every declaration to `^4.13.5`, which 4.13.7 still satisfies, so lockfile inertia kept the old version. CI would have certified 4.13.7 while a downstream install gets 4.13.12. That is the declared-versus-tested split the card names for better-auth. Step 2 moves the single `hono` copy to 4.13.12 without editing the override or any manifest. An unfiltered `pnpm update -r` was tried and discarded: it also dropped `knex`'s `mysql2` / `pg` / `tedious` peer links in two importers. 3. After objectstack-ai#21160 landed: merge `main` (`e35c40a52`), lift driver-turso's new `tsx` line, and run `pnpm install --lockfile-only` again. - The result is a fixed point: a second `pnpm install --lockfile-only` leaves it byte-identical, and `pnpm install --frozen-lockfile` passes. Lockfile blob `30ba2147`. The resolved set is unchanged from the set the OSV scan below covered: 0 names differ. - **`packages/drivers/driver-turso/src/**`**: the item-4 restamp, 21 lines in 7 files (below). - **`packages/spec/src/data/driver/common.zod.ts` and `driver-credential-refusal.test.ts`**: the `@libsql/core` version label is restamped from 0.17.4 to 0.18.0. The TSDoc of `CREDENTIAL_URL_QUERY_PARAMS` says it was measured "in the versions pinned by this tree", so leaving 0.17.4 would have made it false. The behaviour was re-measured identical on the installed 0.18.0: `?authToken=` overrides the config token, `auth%54oken` is decoded, `AuthToken` and `token` give `URL_PARAM_NOT_SUPPORTED`, and the control without a query keeps the config token. - **`.changeset/21094-prod-deps-group.md`**: `patch` for the 19 published packages whose `dependencies` range moves. The list was re-derived from this diff and matches the PM correction on the card, `plugin-auth` included (`@noble/hashes`, `jose`). ## Resolved versions against the merge base Every changed `name@version` pair in the `packages:` section, compared with `main` at `e35c40a52`: 25 names change. **DOWN: 0.** | package | merge base | this branch | |:--|:--|:--| | `@libsql/client` / `@libsql/core` | 0.17.4 | 0.18.0 | | `zod` | 4.6.1 | 4.6.5 (4.6.1 kept by `apps/docs` only) | | `@modelcontextprotocol/sdk` | 1.30.0 | 1.31.0 | | `hono` | 4.13.7 | 4.13.12 | | `mongodb` | 7.5.0 | 7.7.0 (7.5.0 kept by `mongodb-memory-server-core` only) | | `jose` | 6.2.7, 6.2.8 | 6.2.12 | | `@noble/hashes` | 2.3.0 | 2.4.0 | | `@noble/ciphers` | 2.3.0 | 2.4.0 (2.3.0 kept by better-auth 1.7.3 only) | | `react` / `react-dom` / `@types/react` / `@types/react-dom` | 19.2.x | 19.3.0 (19.2.x kept by `apps/docs` only) | | `tsx` | 4.23.12 | 4.23.15 | | `yaml` | 2.9.0 | 2.9.1 (2.9.0 kept by the `apps/docs` fumadocs tree only) | | `chalk` | 6.0.0 | 6.0.1 | | `sql.js` | 1.14.1 | 1.14.2 | | `pinyin-pro` | 3.29.1 | 3.29.4 | | deduped onto a newer copy already present | `@hono/node-server` 2.0.12, `ws` 8.21.1, `@types/ws` 8.18.1, `eventsource-parser` 3.1.0 | removed (2.1.1, 8.22.0, 8.18.2, 3.1.1 stay) | | new transitive copies beside the old ones | none | `bson` 7.3.3 and `@mongodb-js/saslprep` 1.5.5 (with `mongodb` 7.7.0), `scheduler` 0.28.0 (with `react-dom` 19.3.0) | `nodemailer` stays at **10.0.13**, main's version and at least the required 10.0.12. Dependabot's regeneration had moved it down to 10.0.11. ## Item 4: `@libsql/client` lifted to `^0.18.0`, because the premise holds The premise was measured before any driver edit, three ways. 1. **Package diff.** `npm pack` of both releases. `@libsql/core` 0.17.4 and 0.18.0 differ only in `package.json` (the version). `@libsql/client` differs only in `lib-esm/sqlite3.js`, `lib-cjs/sqlite3.js`, `lib-esm/sqlite3.d.ts` and `package.json`. The change is a connection pool for the local `file:` client. `http.js`, `ws.js` and `node.js` are byte-identical. Installed side by side, `@libsql/hrana-client` 0.10.0 and native `libsql` 0.5.29 (with `@libsql/linux-x64-gnu`) are byte-identical too. 2. **Executed probe, same script against both installs.** Output is identical except for the version strings and one count: `syncUrl` occurrences in `sqlite3.js` go from 3 to 4 (the new pool-size line). 3. **The driver's own suite.** At base with 0.17.4: 81 files, 2210 passed, 33 skipped. With 0.18.0, before the restamp: 2209 passed, 1 failed, 33 skipped. Per-test outcomes are identical except the version pin (`expected '0.18.0' to be '0.17.4'`). After the restamp: 2210 passed, 33 skipped. At `0f87e8488`, with objectstack-ai#21160's tests merged in: 2218 passed, 33 skipped, 0 failed. | site (at base) | claim | 0.18.0 reading | verdict | |:--|:--|:--|:--| | `turso-authtoken-url-channel.test.ts:17-18` | client / core / native versions, range | client 0.18.0, core 0.18.0, native `libsql` 0.5.29; range now `^0.18.0`. Answers 1-4 (live wire, child-process replica endpoint) pass, 7/7 non-pin cases, as 8/8 did on 0.17.4 | held, restamped | | `turso-authtoken-url-channel.test.ts:281` | version pin | `0.18.0` | pin moved | | `turso-driver-remote-url-replica-refusal.test.ts:28`, `turso-driver.ts:1288`, `:1384` (message) | no embedded replica for a remote url | `syncUrl` lines: `http.js` 0, `ws.js` 0, control `authToken` lines 6 / 6. `https` and `ws` clients' `sync()` reject `SYNC_NOT_SUPPORTED`. `:memory:` + `syncUrl` throws `URL_INVALID` ("Embedded replica must use file for local db"). File 27/27 on both versions | held | | `turso-driver-timeout.test.ts:9`, `turso-driver.ts:152` | HTTP arm rides `Config.fetch`; replica `sync()` is native | `http.js` (one `config.fetch` site) and hrana-client byte-identical. Timeout file 5/5, supplied-client refusal file 13/13 on both | held | | `turso-driver.ts:871` | `Config.timeout` is the busy timeout; "remote clients ignore it" | core `api.d.ts` docblock byte-identical | held | | `turso-driver-unrecognised-url-refusal.test.ts:26`, `turso-driver.ts:1313`, `:1417` (message) | refusals of urls the client rejects | `URL_INVALID` for `./data/app.db`, `data/app.db`, `/abs/app.db`, `:MEMORY:`, empty, `libsql:host` (bare paths "not in a valid format"). `URL_SCHEME_NOT_SUPPORTED` for `sqlite:`, `memory://`, `C:\data\app.db`. File 42/42 on both | held | | `turso-driver-uppercase-ws-scheme-timeout-refusal.test.ts:15`, `:26`, `turso-driver.ts:932` | `expandConfig` lowercases the scheme before the switch | `WSS://…` gives `wss`, `Ws://…` gives `ws`, control `LIBSQL://…` gives `https`. `_createClient(expandConfig(config, true))` present (1 hit). File 20/20 on both | held | | `turso-driver-ws-timeout-refusal.test.ts:10`, `turso-driver.ts:963`, `:1001` (message) | the WS client takes no `fetch` and no timeout | `ws.js`: `fetch` 0, `timeout` 0. hrana `ws/*.js` + `index.js` `timeout` 0, control `fetch` over `http/*.js` 15. File 11/11 on both | held | | `turso-driver.ts:1061` (message) | a built client's transport cannot be re-seamed | `config.fetch` is read once, inside `_createClient` in `http.js` (byte-identical) | held | | `turso-driver.ts:1212` | the client folds scheme case and opens each spelling | `FILE:./x.db` gives `file`, `Wss://` gives `wss`, `LIBSQL://` gives `https`. `createClient` opens each (`http` / `ws` / `file`) | held | | `turso-driver.ts:1244` | `:memory:` expands to `file::memory:`; `isInMemoryConfig` | `file::memory:`. `true` for `file::memory:` and `file::memory:?cache=shared`, control `false` for `file:./x.db` | held | After the edit, `git grep -n -E "0\.17\.[0-9]" -- packages/drivers/driver-turso/src` returns 0 lines (exit 1). The control is the 23 `0.18.0` occurrences in the same 7 files. ## What objectstack-ai#21029 never measured - **Test Core shard 4's eight unreached packages**, measured at `cf1d700b`, before the `main` merge: `rest` 250 files, 4728 passed / 248 skipped. `driver-sql` 205 files, 3303 passed / 188 skipped. `plugin-email` 31 files, 510 passed. `plugin-approvals` 52 files, 804 passed. `plugin-webhooks` 13 files, 160 passed. `trigger-schedule` 8 files, 170 passed. `connector-mcp` 3 files, 23 passed. `client-react` 3 files, 34 passed. Turbo ran 45 of 45 tasks, exit 0. - **`Lint & Repo Gates` from `check:vendor-export-contract` on**: `pnpm check:vendor-export-contract` reads `VERDICT: PASS — vendor export contract (installed workspace), 1 edge(s) verified` (better-auth 1.7.3), and the `-resolve` variant passes on the registry. The 72 later steps of that job were not run here. They belong to CI's run on this PR. The families this diff derives are below. - **OSV.** `osv-scanner` v2.3.8, built from the Go module proxy because this container's egress refuses `api.osv.dev`. It ran on the offline npm database over lockfile blob `70547c67` (its resolved set is identical to the current `30ba2147`), with the repo's `osv-scanner.toml` loaded: 1388 packages, `No issues found`, exit 0. Positive control: the same lockfile with `hono` rewritten to 4.12.32 gives exit 1 and 8 advisories on `hono`, among them GHSA-8j4g-w8fx-2239. CI's online step is the authoritative reading. - **`zod` 4.6.5 and `z.properties()`**: `git grep -n -E "z\.properties\(" -- packages/` returns 0 lines; control `z.object(`, 1825 lines. - **`mongodb` live suites**: NOT MEASURED. They need a `mongod` download from `fastdl.mongodb.org`, which this container's egress refuses (CONNECT 403). The default `driver-mongodb` suite passes: 30 files, 675 passed, 172 skipped (the five opt-in live files). ## Gates and tests Gate families derived by `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` (no paths, change set from git) at HEAD **`0f87e8488`** (54 paths against merge base `e35c40a52`): 117 commands. All 117 exit 0, and so does `pnpm check:vendor-export-contract`. Exit codes were captured before any pipe. `--ran` reconciliation: `117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN`, a derived zero with an exit code on every line. Package suites, all exit 0: - At `cf1d700b`: `driver-mongodb`, `mcp` 32/344, `plugin-hono-server` 27/324, `plugin-auth` 115/2472, `service-settings` 33/584, `plugin-pinyin-search` 2/21, `driver-sqlite-wasm` 36/675, `driver-memory` 69/1613, `service-analytics` 155/3526 (10 skipped), `create-objectstack` 16/247, `@objectstack/hono` 5/122. Also `@objectstack/cli` `--project unit` 242/3432 and `@objectstack/spec` `--project local` 591 files / 17368 passed. - `typecheck`: the 19 moving packages plus `client-react`, `@objectstack/hono` and `lint`. Turbo ran 80 of 80 tasks. - At `0f87e8488`, after the objectstack-ai#21160 merge and a full rebuild: the `driver-turso` suite (82 files) gives 2218 passed / 33 skipped / 0 failed. That includes objectstack-ai#21160's new tests, run on 0.18.0; its two-process concurrency test overlapped, with 400 writes and 400 distinct numbers. `typecheck` passes, and `pnpm install --frozen-lockfile` passes. ## Acceptance notes - **Duplicate copies left by the exclusions**: `zod` 4.6.1, `react` 19.2.8 and `yaml` 2.9.0 are kept only by the excluded `apps/docs` tree. `@noble/ciphers` 2.3.0 is kept only by the excluded better-auth 1.7.3. `mongodb` 7.5.0 is kept only by the test harness `mongodb-memory-server-core` 11.3.0. - **libsql 0.18.0's one behaviour change, from reading the code (not measured):** the local client now pools connections, with one connection for `:memory:` and for embedded replicas. On a replica, a second `sync()` therefore waits for the first to release the connection. On 0.17.4 the two ran at once on the same native handle. With `timeout` set, a sync that outlives the window keeps running natively, uncancelled, so the next periodic sync queues behind it. No driver docblock claims either behaviour. - **The remaining 0.17.4 stamps stay**: outside `CHANGELOG.md`, only `service-package` `index.ts:192` and `mysql2-tuple.test.ts:172` name 0.17.4 ("Measured on `@libsql/client` 0.17.4"). That is a dated attestation and stays true; the `result.rows` shape was re-measured identical on 0.18.0. - **Environment side effect, nothing committed**: turbo 2.11.5 appends a managed block to `AGENTS.md` whenever an agent runs a repository-scoped turbo command. It was restored after each turbo run with `git restore --source=HEAD --staged --worktree AGENTS.md`. No commit on this branch touches `AGENTS.md`. - **Merge-queue ejection and its fix**: objectstack-ai#21160 added driver-turso's `tsx` at 4.23.12 while this branch removes `tsx@4.23.12`. The two lockfiles merged into one that `pnpm install --frozen-lockfile` refuses. Fixed by merging `main` at `e35c40a52`, lifting that `tsx` line, and regenerating the lockfile with pnpm. --- _Generated by [Claude Code](https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Bumps the production-dependencies group with 27 updates:
4.23.124.23.152.9.02.9.16.0.06.0.14.6.14.6.519.2.819.3.019.2.819.3.01.30.01.30.11.14.11.14.27.5.07.6.00.17.40.18.01.7.31.7.61.7.31.7.61.7.31.7.61.7.31.7.62.3.02.4.01.7.31.7.66.2.86.2.124.13.74.13.910.0.1210.0.113.29.13.29.42.3.02.4.016.14.416.15.1515.2.315.4.516.14.416.15.151.31.01.48.016.3.316.3.63.6.03.7.0Updates
tsxfrom 4.23.12 to 4.23.15Release notes
Sourced from tsx's releases.
Commits
ca66105test: fix drive-less file URLs in ESM resolver fixtures2da3407fix: expose require.cache and require.extensions to tsImport CommonJS modules38e1588fix: exclude bare builtins from namespace inheritance562c434fix: make namespaced register() overloads portable for declaration emitedfb1f0build: upgrade pkgroll and externalize CJS loader reference70e7828test: upgrade tinyspy for disposable API9ed2022ci: avoid duplicate release notifications872e77frefactor: use disposables for cleanup6e5236bfix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...28e1f12fix(cache): bound shared transform cache memory (#835)Updates
yamlfrom 2.9.0 to 2.9.1Release notes
Sourced from yaml's releases.
Commits
1440ecd2.9.1c699bc5fix: Simplify line unfolding during quoted string parsing (#714)d11ce77fix: Limit recursive merge aliases (#713)c5f49f4chore: Update docs-slateUpdates
chalkfrom 6.0.0 to 6.0.1Release notes
Sourced from chalk's releases.
Commits
47fc05a6.0.19c93a04Fix inconsistent coercion of two arguments8960adaMeta tweaksUpdates
zodfrom 4.6.1 to 4.6.5Release notes
Sourced from zod's releases.
Commits
59bbc03chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump0f3f5ee4.6.5cc4cd4eRevert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...ca0229aRevert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...56222cdfeat(instanceof): key the .properties() shape off the instance type (#6600)de65a5cdocs: lead the properties section with the check and add a Zod Mini tab (#6598)f1448f7docs: fold the 4.6.x patch highlights into the 4.6 post's own sectionsd2b135cdocs: add the 4.6.x patch highlights to the 4.6 post2bb0871chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump743aedb4.6.4Updates
reactfrom 19.2.8 to 19.3.0Release notes
Sourced from react's releases.
... (truncated)
Changelog
Sourced from react's changelog.
... (truncated)
Commits
2dc7da7[test] Bump Jest to 30.4 (#37382)4f93894docs: remove stale parentType param from validateChildKeys JSDoc (#36928)dbc3750Update required references to GitHub repo (#36752)900ae09[flow] Bump flow to v0.317.0 (#36701)fbb1370[flow] Bump flow to v0.307.1 (#36199)56922cf[react-native-renderer] Delete Paper (legacy) renderer (#36285)74568e8[Flight] TransportAggregateErrors.errors(#36156)e66ef64[tests] remove withoutStack from assertConsole helpers (#35498)db71391[Fiber] Instrument the lazy initializer thenable in all cases (#35521)3e1abcc[tests] Require exact error messages in assertConsole helpers (#35497)Updates
react-domfrom 19.2.8 to 19.3.0Release notes
Sourced from react-dom's releases.