Skip to content

fix(deps): update bun minor and patch dependencies - #1069

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/bun-minor-and-patch-dependencies
Open

fix(deps): update bun minor and patch dependencies#1069
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/bun-minor-and-patch-dependencies

Conversation

@renovate

@renovate renovate Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@better-auth/api-key (source) 1.6.231.6.25 age confidence
@better-auth/passkey (source) ^1.6.23^1.6.25 age confidence
@better-auth/sso (source) ^1.6.23^1.6.25 age confidence
@better-auth/utils 0.4.20.5.0 age confidence
@cloudflare/vite-plugin (source) ^1.45.1^1.50.0 age confidence
@effect/language-service ^0.87.0^0.87.1 age confidence
@fontsource-variable/jetbrains-mono (source) ^5.2.8^5.3.0 age confidence
@hookform/resolvers (source) ^5.4.0^5.7.1 age confidence
@playwright/test (source) ^1.61.1^1.62.1 age confidence
@radix-ui/react-alert-dialog (source) ^1.1.19^1.1.23 age confidence
@radix-ui/react-checkbox (source) ^1.3.7^1.3.11 age confidence
@radix-ui/react-dialog (source) ^1.1.19^1.1.23 age confidence
@radix-ui/react-dropdown-menu (source) ^2.1.20^2.1.24 age confidence
@radix-ui/react-hover-card (source) ^1.1.19^1.1.23 age confidence
@radix-ui/react-label (source) ^2.1.11^2.1.15 age confidence
@radix-ui/react-progress (source) ^1.1.12^1.1.16 age confidence
@radix-ui/react-scroll-area (source) ^1.2.14^1.2.18 age confidence
@radix-ui/react-select (source) ^2.3.3^2.3.7 age confidence
@radix-ui/react-separator (source) ^1.1.11^1.1.15 age confidence
@radix-ui/react-slot (source) ^1.3.0^1.3.3 age confidence
@radix-ui/react-switch (source) ^1.3.3^1.3.7 age confidence
@radix-ui/react-tabs (source) ^1.1.17^1.1.21 age confidence
@radix-ui/react-tooltip (source) ^1.2.12^1.2.16 age confidence
@scalar/hono-api-reference (source) ^0.11.11^0.11.12 age confidence
@tanstack/devtools-vite (source) ^0.8.1^0.8.3 age confidence
@tanstack/react-devtools (source) ^0.10.8^0.10.9 age confidence
@tanstack/react-query (source) ^5.101.2^5.101.4 age confidence
@tanstack/react-query-devtools (source) ^5.101.2^5.101.4 age confidence
@tanstack/react-start (source) ^1.168.30^1.168.34 age confidence
@tanstack/router-plugin (source) ^1.168.22^1.168.23 age confidence
@types/node (source) ^26.1.1^26.1.2 age confidence
@types/react (source) ^19.2.17^19.2.18 age confidence
@types/react-dom (source) ^19.2.3^19.2.4 age confidence
@types/semver (source) ^7.7.1^7.8.0 age confidence
@vitejs/plugin-react (source) ^6.0.3^6.0.5 age confidence
better-auth (source) ^1.6.23^1.6.25 age confidence
drizzle-orm (source) 1.0.0-rc.4-5d5b77c1.0.0-rc.4-de6c356 age confidence
effect (source) ^3.22.0^3.22.1 age confidence
electron ^43.1.1^43.2.0 age confidence
es-toolkit (source) ^1.49.0^1.50.0 age confidence
fumadocs-core ^16.11.5^16.14.0 age confidence
fumadocs-mdx ^15.2.0^15.2.2 age confidence
fumadocs-ui ^16.11.5^16.14.0 age confidence
happy-dom ^20.11.0^20.11.1 age confidence
hono (source) ^4.12.31^4.12.34 age confidence
lucide-react (source) ^1.25.0^1.28.0 age confidence
oxfmt (source) 0.59.00.62.0 age confidence
oxlint (source) 1.73.01.77.0 age confidence
oxlint-tsgolint 0.24.00.25.0 age confidence
react (source) ^19.2.7^19.2.8 age confidence
react-dom (source) ^19.2.7^19.2.8 age confidence
react-hook-form (source) ^7.82.0^7.84.0 age confidence
recharts 3.9.23.10.1 age confidence
shadcn (source) ^4.13.1^4.16.1 age confidence
vite (source) ^8.1.5^8.2.0 age confidence
vite-plus (source) ^0.2.5^0.2.7 age confidence
wrangler (source) ^4.112.0^4.118.0 age confidence

Release Notes

better-auth/better-auth (@​better-auth/api-key)

v1.6.25

Compare Source

Patch Changes

v1.6.24

Compare Source

Patch Changes
better-auth/better-auth (@​better-auth/passkey)

v1.6.25

Compare Source

Patch Changes

v1.6.24

Compare Source

Patch Changes
better-auth/better-auth (@​better-auth/sso)

v1.6.25

Compare Source

Patch Changes

v1.6.24

Compare Source

Patch Changes
better-auth/utils (@​better-auth/utils)

v0.5.0

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v0.4.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
cloudflare/workers-sdk (@​cloudflare/vite-plugin)

v1.50.0

Compare Source

Minor Changes
  • #​14944 a249591 Thanks @​nickpatt! - Enable local observability capture by default in dev

    wrangler dev and the Vite plugin now capture request traces and console logs into the Local Explorer's Observability tab out of the box — previously this was opt-in behind X_LOCAL_OBSERVABILITY=true. Set X_LOCAL_OBSERVABILITY=false to opt out (for example if the extra per-worker collector/streaming-tail services cause trouble in a multi-process dev-registry setup).

Patch Changes

v1.49.1

Compare Source

Patch Changes
  • #​14586 5a56dda Thanks @​emily-shen! - Rewrite local testing paths (/cdn-cgi/*)

    Miniflare v5 moved its internal local testing endpoints to /cdn-cgi/local/* (and /__cf_local/* for endpoints that must remain reachable over tunnels) to prevent any potential collision with production routes. wrangler dev and the Vite plugin now transparently rewrite the old paths to the new ones, meaning you can continue to use the old paths without issue.

    These are the new paths:

    • /cdn-cgi/handler/scheduled/cdn-cgi/local/scheduled
    • /cdn-cgi/handler/email/cdn-cgi/local/email
    • /cdn-cgi/explorer/*/cdn-cgi/local/explorer/*
    • /cdn-cgi/mf/scheduled/cdn-cgi/local/scheduled (Note /cdn-cgi/mf/scheduled is already deprecated)
    • /cdn-cgi/mf/stream/*/__cf_local/stream/*
    • /cdn-cgi/mf/imagedelivery/*/__cf_local/imagedelivery/*
  • Updated dependencies [5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda, 5a56dda]:

v1.49.0

Compare Source

Minor Changes
  • #​14905 b21eac2 Thanks @​jamesopstad! - The experimental build output directory now includes the Worker's configuration at .cloudflare/output/v0/workers/default/config.json instead of .cloudflare/output/v0/workers/<worker-name>/worker.config.json
Patch Changes

v1.48.0

Compare Source

Minor Changes
  • #​14883 76e6014 Thanks @​jamesopstad! - Serve the bundled client HTML in dev when Vite's experimental.bundledDev is enabled

    Note that this feature is experimental and subject to change.

Patch Changes
  • #​14862 c232d05 Thanks @​petebacondarwin! - Destroy the client socket instead of crashing when a WebSocket upgrade fails

    If dispatchFetch rejected while a WebSocket upgrade was still in flight (for example when Miniflare is disposed during a dev server shutdown or restart), the error escaped the async upgrade handler as an unhandled rejection. This could terminate the dev server process and leaked the client socket. The upgrade handler now catches such failures and tears the socket down cleanly.

  • #​14837 de6a951 Thanks @​1rgs! - Fix compatibility with Vite's experimental.bundledDev option. Keep Miniflare, containers, and tunnels alive when a build runs in dev.

    The plugin used the buildEnd hook as its signal that the dev server was closing, and tore down its dev resources there. Vite's experimental.bundledDev runs a build pass during serve, which fires buildEnd while the dev server is still live — so Miniflare was disposed (the next request failed with Expected \miniflare` to be defined`), locally-built container images were removed, and any active tunnel was closed, all mid-serve.

    During serve, these resources are now torn down from a patched server.close. We will replace server patching with first-class APIs when they are added to Vite.

  • #​14851 fb89b72 Thanks @​exKAZUu! - Retry transient module-transport failures in the runner worker

    Each fetchModule invoke was a single fetch to the dev server with no retry. If that one fetch failed transiently (e.g. Network connection lost when workerd reuses a loopback connection that Node just closed), Vite's module runner cached the rejection and every request importing the affected module failed for the rest of the dev session. The invoke is an idempotent request for module code, so retry it up to three times before giving up.

  • Updated dependencies [773ead4, 773ead4, 09b8a44, 4dfb96e, 1035f74, e426cb9, 3a22ae5, 465c0fb, 465c0fb, e8b3a9d, 552bcfc, b737676, 6e0bf6e]:

    • wrangler@​4.115.0
    • miniflare@​4.20260722.1

v1.47.0

Compare Source

Minor Changes
  • #​14633 3203b5d Thanks @​nickpatt! - Add local-dev observability

    wrangler dev and the Vite plugin now capture a trace for every local Worker invocation - spans, logs, and console.* output, including requests that cross worker or Durable Object boundaries.

    You can explore this data two ways:

    • A new Observability tab in the Local Explorer, with a Traces view (recent invocations, an inline timeline waterfall, and filters) and an Events view.
    • A read-only SQL endpoint at /cdn-cgi/explorer/api/local/observability/query, discoverable via the Local Explorer's OpenAPI document, so coding agents and tools can query the same spans and logs tables.

    While this is in testing it's off by default; set X_LOCAL_OBSERVABILITY=true to turn it on. It will be on by default in the public release.

Patch Changes
  • #​14792 c4bacec Thanks @​matthewp! - Recover local development after the Workers runtime crashes

    Previously, an unexpected workerd crash left Miniflare running but unable to serve subsequent requests. Miniflare now restarts workerd after post-startup crashes, while continuing to surface startup crashes as fatal errors.

    The Cloudflare Vite plugin also restarts the Vite development server after workerd recovers so its environments, hot channels, and module runners are recreated.

  • Updated dependencies [246ce92, c38a2c3, 8416b33, c079ba3, 4683ff8, 95b026e, 02232f3, c4bacec, f8a8c2c, 3203b5d]:

    • wrangler@​4.114.0
    • miniflare@​4.20260722.0

v1.46.0

Compare Source

Minor Changes
  • #​14724 a50f73a Thanks @​jamesopstad! - Add a settings export to the experimental cloudflare.config.ts config

    Account-level settings (accountId, complianceRegion) now live in a dedicated, named settings export authored via defineSettings, rather than on the Worker config. A cloudflare.config.ts can export at most one settings object; the Worker itself is the default export.

    // cloudflare.config.ts
    import { defineSettings, defineWorker } from "wrangler/experimental-config";
    import * as entrypoint from "./src/index.ts" with { type: "cf-worker" };
    
    export const settings = defineSettings({
    	accountId: "<your-account-id>",
    });
    
    export default defineWorker({
    	name: "my-worker",
    	entrypoint,
    	compatibilityDate: "2026-05-18",
    });

    This is only used behind the experimental new-config path (wrangler --experimental-new-config and the @cloudflare/vite-plugin experimental.newConfig option).

Patch Changes
Effect-TS/language-service (@​effect/language-service)

v0.87.1

Compare Source

Patch Changes
  • #​765 6b9dab5 Thanks @​mattiamanzati! - Ignore Effect v4 local Effect.provide(..., { local: true }) calls when reporting chained provides with the multipleEffectProvide diagnostic.
fontsource/font-files (@​fontsource-variable/jetbrains-mono)

[v5.3.0](https://redirect.github.com/fontsource/font-files/compare/40ecb0c337fd649924783a87783d

Note

PR body was truncated to here.

@socket-security

socket-security Bot commented Jul 22, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​happy-dom@​20.11.0 ⏵ 20.11.16610088 +196 +4100
Updatednpm/​@​radix-ui/​react-label@​2.1.11 ⏵ 2.1.15100 +110066 +199 +1100
Updatednpm/​@​radix-ui/​react-separator@​1.1.11 ⏵ 1.1.15100 +110066 +199 +1100
Updatednpm/​@​radix-ui/​react-progress@​1.1.12 ⏵ 1.1.16100 +110068 +199 +1100
Updatednpm/​@​radix-ui/​react-slot@​1.3.0 ⏵ 1.3.3100 +110069 +199100
Updatednpm/​@​radix-ui/​react-tabs@​1.1.17 ⏵ 1.1.2199 +110070 +199 +1100
Updatednpm/​@​tanstack/​react-query-devtools@​5.101.2 ⏵ 5.101.4100 +11007098 +2100
Updatednpm/​@​radix-ui/​react-alert-dialog@​1.1.19 ⏵ 1.1.231001007099 +1100
Updatednpm/​@​radix-ui/​react-hover-card@​1.1.19 ⏵ 1.1.23991007099 +1100
Updatednpm/​@​radix-ui/​react-switch@​1.3.3 ⏵ 1.3.799 +110070 +199 +1100
Updatednpm/​@​radix-ui/​react-checkbox@​1.3.7 ⏵ 1.3.1199 +110071 +199 +1100
Updatednpm/​@​radix-ui/​react-dropdown-menu@​2.1.20 ⏵ 2.1.24991007199 +1100
Updatednpm/​@​radix-ui/​react-dialog@​1.1.19 ⏵ 1.1.239910071 +199 +1100
Updatednpm/​@​radix-ui/​react-tooltip@​1.2.12 ⏵ 1.2.169910072 +199 +1100
Updatednpm/​@​radix-ui/​react-scroll-area@​1.2.14 ⏵ 1.2.1899 +110072 +199 +1100
Updatednpm/​fumadocs-mdx@​15.2.0 ⏵ 15.2.298 +110073 +196 +2100
Updatednpm/​@​radix-ui/​react-select@​2.3.3 ⏵ 2.3.7991007399 +1100
Updatednpm/​@​types/​semver@​7.7.1 ⏵ 7.8.010010074 +187100
Updatednpm/​@​types/​react-dom@​19.2.3 ⏵ 19.2.4100 +110075 +190100
Updatednpm/​@​tanstack/​devtools-vite@​0.8.1 ⏵ 0.8.3100 +110076 -398 +1100
Updatednpm/​fumadocs-core@​16.11.5 ⏵ 16.14.0981007796 +1100
Updatednpm/​fumadocs-ui@​16.11.5 ⏵ 16.14.098 +11007796100
Updatednpm/​@​better-auth/​api-key@​1.6.23 ⏵ 1.6.2577 +110078 +197 +1100
Updatednpm/​@​better-auth/​sso@​1.6.23 ⏵ 1.6.2599 +110078 +198100
Updatednpm/​@​tanstack/​router-plugin@​1.168.22 ⏵ 1.168.2399 +110078 +198 +1100
Updatednpm/​@​types/​react@​19.2.17 ⏵ 19.2.18100 +110079 +194 +2100
Updatednpm/​vite-plus@​0.2.5 ⏵ 0.2.779100100 +199 -1100
Updatednpm/​recharts@​3.9.2 ⏵ 3.10.180 +1100100 +197 +1100
Updatednpm/​lucide-react@​1.25.0 ⏵ 1.28.0100 +110098 +196 +180
Updatednpm/​@​types/​node@​26.1.1 ⏵ 26.1.21001008195100
Updatednpm/​effect@​3.22.0 ⏵ 3.22.182 +31009197100
Updatednpm/​vite@​8.1.5 ⏵ 8.2.099 +110082 +198100
See 25 more rows in the dashboard

View full report

@renovate
renovate Bot force-pushed the renovate/bun-minor-and-patch-dependencies branch 13 times, most recently from c4497de to 5dd73b4 Compare July 25, 2026 18:00
@socket-security

socket-security Bot commented Jul 25, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm effect is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/agent/package.jsonnpm/effect@3.22.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/effect@3.22.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/bun-minor-and-patch-dependencies branch 15 times, most recently from 397daa4 to c6aafa5 Compare July 29, 2026 02:01
@renovate
renovate Bot force-pushed the renovate/bun-minor-and-patch-dependencies branch 26 times, most recently from 9a1e337 to ff469c9 Compare August 4, 2026 13:02
@renovate
renovate Bot force-pushed the renovate/bun-minor-and-patch-dependencies branch 2 times, most recently from 247d40b to ab6b4e5 Compare August 6, 2026 02:50
@renovate
renovate Bot force-pushed the renovate/bun-minor-and-patch-dependencies branch from ab6b4e5 to 98a9e2d Compare August 6, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants