Skip to content

chore(deps): bump the production-minor-patch group across 1 directory with 14 updates - #1011

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-minor-patch-aa67092d59
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-minor-patch-aa67092d59

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-minor-patch group with 14 updates in the / directory:

Package From To
@types/node 22.20.1 22.20.4
drizzle-orm 0.45.2 0.45.3
@clack/prompts 1.7.0 1.8.1
posthog-node 5.49.1 5.54.1
jose 6.2.9 6.2.12
@rollup/rollup-linux-x64-gnu 4.62.4 4.63.5
uuid 14.0.1 14.0.2
arktype 2.2.3 2.2.5
@anthropic-ai/claude-agent-sdk 0.3.234 0.3.283
@anthropic-ai/sdk 0.117.1 0.128.0
@clerk/nextjs 7.7.7 7.9.7
next 15.5.24 15.5.26
tsx 4.23.12 4.23.15
vite 8.2.1 8.3.1

Updates @types/node from 22.20.1 to 22.20.4

Commits

Updates drizzle-orm from 0.45.2 to 0.45.3

Release notes

Sourced from drizzle-orm's releases.

0.45.3

New Netlify DB Driver

Note: The Netlify DB driver is developed and maintained by the Netlify team.

Installation:

npm i @netlify/db

Usage example:

import { drizzle } from 'drizzle-orm/netlify-db';
// reads NETLIFY_DB_URL and NETLIFY_DB_DRIVER env vars
const db = drizzle();
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';
const db = drizzle(process.env.DATABASE_URL);
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';

// Explicit client — consumer controls the driver
const db = drizzle({ client: netlifyDbClient });

const result = await db.execute('select 1');
Commits
  • 15454db +
  • 54e436f exclude gel from pull
  • 0fd1cc6 remove gel
  • d028db7 skip gel
  • 93dc01e [All-kit]: Warn when journal timestamps can cause migrations to be skipped (#...
  • b786252 Merge pull request #6049 from drizzle-team/drizzle-kit-announcements
  • f9fc5bf Add drizzle-kit announcement manifest and schema doc
  • 9d64532 Merge pull request #6004 from drizzle-team/pin-npm-11-main
  • 0af2f2e Pin the release npm self-update to major 11: the npm 12.0.0 tarball is missin...
  • 6968638 Merge pull request #6001 from drizzle-team/release-router-dispatch-inputs
  • Additional commits viewable in compare view

Updates @clack/prompts from 1.7.0 to 1.8.1

Release notes

Sourced from @​clack/prompts's releases.

@​clack/prompts@​1.8.1

Patch Changes

  • 8bd9129 Thanks @​gameroman! - Return type for prompts now correctly specifies CANCEL_SYMBOL instead of symbol

  • Updated dependencies [8bd9129]:

    • @​clack/core@​1.5.1

@​clack/prompts@​1.8.0

Minor Changes

  • #592 caa32e8 Thanks @​gameroman! - Export CANCEL_SYMBOL constant from @clack/core and @clack/prompts

  • #594 37fca4e Thanks @​dreyfus92! - Add tab-completion to the path prompt: pressing Tab fills the input with the focused suggestion, so you can quickly descend into deep directories (type / and Tab again). Powered by a new opt-in completeOnTab option on autocomplete, which also shows a Tab: complete hint in the instructions footer. Default autocomplete behavior is unchanged.

  • #583 ae636dd Thanks @​43081j! - Add async validation support to prompts, and validation state rendering to text prompts.

Patch Changes

Changelog

Sourced from @​clack/prompts's changelog.

1.8.1

Patch Changes

  • 8bd9129 Thanks @​gameroman! - Return type for prompts now correctly specifies CANCEL_SYMBOL instead of symbol

  • Updated dependencies [8bd9129]:

    • @​clack/core@​1.5.1

1.8.0

Minor Changes

  • #592 caa32e8 Thanks @​gameroman! - Export CANCEL_SYMBOL constant from @clack/core and @clack/prompts

  • #594 37fca4e Thanks @​dreyfus92! - Add tab-completion to the path prompt: pressing Tab fills the input with the focused suggestion, so you can quickly descend into deep directories (type / and Tab again). Powered by a new opt-in completeOnTab option on autocomplete, which also shows a Tab: complete hint in the instructions footer. Default autocomplete behavior is unchanged.

  • #583 ae636dd Thanks @​43081j! - Add async validation support to prompts, and validation state rendering to text prompts.

Patch Changes

Commits

Updates posthog-node from 5.49.1 to 5.54.1

Release notes

Sourced from posthog-node's releases.

posthog-node@5.54.1

5.54.1

Patch Changes

  • #4832 ac479db Thanks @​dustinbyrne! - Support snake_case feature flag cache payloads while preserving compatibility with camelCase providers and cached data. (2026-09-25)

posthog-node@5.54.0

5.54.0

Minor Changes

  • #5099 e3955f8 Thanks @​marandaneto! - Expose feature flag evaluation reasons and preserve them in OpenFeature resolution metadata. (2026-09-25)

posthog-node@5.53.0

5.53.0

Minor Changes

  • #5050 31dd1ad Thanks @​posthog! - Read a feature flag's evaluation runtime with getFeatureFlagEvaluationRuntime(key) and getFeatureFlagKeysByEvaluationRuntime(runtime) (2026-09-23)

posthog-node@5.52.6

5.52.6

Patch Changes

  • #5078 f4704ac Thanks @​rubychilds! - Honor filters.holdout during local feature flag evaluation. A user in an experiment holdout now receives the holdout-<id> variant instead of being bucketed into a regular variant, matching how the server evaluates the same flag. The holdout is resolved before the release conditions, so a held-out user never reaches the flag's targeting — including when those conditions would have excluded them, so isFeatureEnabled can return true where it previously returned false. Experiments with an active holdout will see variant assignment change for the held-out share of traffic on upgrade, bringing locally evaluated assignments in line with server-evaluated ones. (2026-09-23)
  • Updated dependencies [f4704ac]:
    • @​posthog/core@​1.55.2

posthog-node@5.52.5

5.52.5

Patch Changes

  • #5018 9cd8ebd Thanks @​turnipdabeets! - Stop dropping long spans that end: maxSpanAgeMs now evicts spans only once maxLiveSpans is reached, so a span that runs past the age limit and then ends is exported, and its children are no longer orphaned. (2026-09-21)

  • #4800 aad7464 Thanks @​marandaneto! - Respect the definitions response's property_matching_version during local feature flag evaluation. Version 2 uses explicit boolean/string equality and per-member array matching, while missing or other versions retain service legacy matching (including empty-array truthiness). Preserve the version in Node definition caches and Convex persisted definitions, and propagate it through person, group, cohort and dependency evaluation without mixing snapshots during reloads. Existing numeric ambiguity fallback and SemVer parsing policies are unchanged. (2026-09-21)

  • Updated dependencies [9cd8ebd, aad7464]:

    • @​posthog/core@​1.55.1
Changelog

Sourced from posthog-node's changelog.

5.54.1

Patch Changes

  • #4832 ac479db Thanks @​dustinbyrne! - Support snake_case feature flag cache payloads while preserving compatibility with camelCase providers and cached data. (2026-09-25)

5.54.0

Minor Changes

  • #5099 e3955f8 Thanks @​marandaneto! - Expose feature flag evaluation reasons and preserve them in OpenFeature resolution metadata. (2026-09-25)

5.53.0

Minor Changes

  • #5050 31dd1ad Thanks @​posthog! - Read a feature flag's evaluation runtime with getFeatureFlagEvaluationRuntime(key) and getFeatureFlagKeysByEvaluationRuntime(runtime) (2026-09-23)

5.52.6

Patch Changes

  • #5078 f4704ac Thanks @​rubychilds! - Honor filters.holdout during local feature flag evaluation. A user in an experiment holdout now receives the holdout-<id> variant instead of being bucketed into a regular variant, matching how the server evaluates the same flag. The holdout is resolved before the release conditions, so a held-out user never reaches the flag's targeting — including when those conditions would have excluded them, so isFeatureEnabled can return true where it previously returned false. Experiments with an active holdout will see variant assignment change for the held-out share of traffic on upgrade, bringing locally evaluated assignments in line with server-evaluated ones. (2026-09-23)
  • Updated dependencies [f4704ac]:
    • @​posthog/core@​1.55.2

5.52.5

Patch Changes

  • #5018 9cd8ebd Thanks @​turnipdabeets! - Stop dropping long spans that end: maxSpanAgeMs now evicts spans only once maxLiveSpans is reached, so a span that runs past the age limit and then ends is exported, and its children are no longer orphaned. (2026-09-21)

  • #4800 aad7464 Thanks @​marandaneto! - Respect the definitions response's property_matching_version during local feature flag evaluation. Version 2 uses explicit boolean/string equality and per-member array matching, while missing or other versions retain service legacy matching (including empty-array truthiness). Preserve the version in Node definition caches and Convex persisted definitions, and propagate it through person, group, cohort and dependency evaluation without mixing snapshots during reloads. Existing numeric ambiguity fallback and SemVer parsing policies are unchanged. (2026-09-21)

  • Updated dependencies [9cd8ebd, aad7464]:

    • @​posthog/core@​1.55.1

5.52.4

Patch Changes

  • #4885 39a8980 Thanks @​decknamec! - Server-side feature flags now resolve in posthog-node and posthog-edge even when a proxy rewrites the request's User-Agent. Flags restricted to the client runtime now resolve to undefined in these SDKs, where a rewritten User-Agent previously let them through. (2026-09-15)
  • Updated dependencies [39a8980]:
    • @​posthog/core@​1.54.2

... (truncated)

Commits
  • 490ffe8 chore: update versions and lockfile [version bump]
  • ac479db fix(node): support snake_case flag definition caches (#4832)
  • 518ae78 chore: update versions and lockfile [version bump]
  • e3955f8 feat: expose feature flag reasons in the Node OpenFeature provider (#5099)
  • 7b3121f chore: update versions and lockfile [version bump]
  • 31dd1ad feat(node): expose a flag's evaluation runtime through the SDK (#5050)
  • 0c5557a chore: update versions and lockfile [version bump]
  • f4704ac fix: honor filters.holdout in local flag evaluation (#5078)
  • 3e72e7b chore: update versions and lockfile [version bump]
  • aad7464 fix(flags): honor versioned local property matching (#4800)
  • Additional commits viewable in compare view

Updates jose from 6.2.9 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

v6.2.10

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)
  • jwt: prevent replacing protected headers (ae07d09)
  • jwt: reject invalid duration inputs (282f9aa)
  • jwt: validate builder claim values (ea03f83)

... (truncated)

Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

6.2.10 (2026-08-21)

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)

... (truncated)

Commits
  • 505a55b chore(release): 6.2.12
  • 7bc9a33 perf: encode single-signature JWS input once
  • 78637bd perf: normalize General JWE shared headers once
  • bf5138b perf: deduplicate pending jwks key imports
  • b23a6f3 perf: use native encoding for larger ASCII strings
  • fd3ae3f perf: normalize jwks selection metadata once
  • 6925d43 perf: avoid copying AES-GCM output
  • be62530 docs: clarify and shorten public API guidance
  • 1b41312 build: preserve README when generation fails
  • 0b51829 build: check tree-shaking for every public binding
  • Additional commits viewable in compare view

Updates @rollup/rollup-linux-x64-gnu from 4.62.4 to 4.63.5

Release notes

Sourced from @​rollup/rollup-linux-x64-gnu's releases.

v4.63.5

4.63.5

2026-09-24

Bug Fixes

  • Fix an issue where watch mode would hang instead of terminating when closing via Ctrl+C (#6521)
  • Avoid starting overlapping watch mode runs when plugins invalidate files at the wrong time (#6526)
  • Fix many edge cases where watch mode events were not properly emitted to listeners, especially when errors occur (#6526)

Pull Requests

v4.63.4

4.63.4

2026-09-19

Bug Fixes

  • Ensure meta information of the cached module is exposed in shouldTransformCachedModule (#6442)
  • Do not create invalid code if import attribute values contain special characters (#6502)

Pull Requests

v4.63.3

4.63.3

2026-09-14

Bug Fixes

  • Make sure that the internal shims for basename and extname in the browser build fully match NodeJS (#6473)
  • Always report and recover from failures on invalidation in watch mode (#6506)
  • Respect windows line terminators when tree-shaking in situations where line-breaks need to be removed to prevent automatic semicolon insertion (#6514)

... (truncated)

Changelog

Sourced from @​rollup/rollup-linux-x64-gnu's changelog.

4.63.5

2026-09-24

Bug Fixes

  • Fix an issue where watch mode would hang instead of terminating when closing via Ctrl+C (#6521)
  • Avoid starting overlapping watch mode runs when plugins invalidate files at the wrong time (#6526)
  • Fix many edge cases where watch mode events were not properly emitted to listeners, especially when errors occur (#6526)

Pull Requests

4.63.4

2026-09-19

Bug Fixes

  • Ensure meta information of the cached module is exposed in shouldTransformCachedModule (#6442)
  • Do not create invalid code if import attribute values contain special characters (#6502)

Pull Requests

4.63.3

2026-09-14

Bug Fixes

  • Make sure that the internal shims for basename and extname in the browser build fully match NodeJS (#6473)
  • Always report and recover from failures on invalidation in watch mode (#6506)
  • Respect windows line terminators when tree-shaking in situations where line-breaks need to be removed to prevent automatic semicolon insertion (#6514)

Pull Requests

... (truncated)

Commits

Updates uuid from 14.0.1 to 14.0.2

Release notes

Sourced from uuid's releases.

v14.0.2

14.0.2 (2026-08-18)

Bug Fixes

  • v1: carry nsecs overflow into the timestamp's high bits (#972) (6adcc1d)
  • v1: set the multicast bit on v1Bytes's own randomly-generated node (#973) (b1da338)
  • v7: align default seq formula in v7Bytes with updateV7State (#965) (a67db57)
Changelog

Sourced from uuid's changelog.

14.0.2 (2026-08-18)

Bug Fixes

  • v1: carry nsecs overflow into the timestamp's high bits (#972) (6adcc1d)
  • v1: set the multicast bit on v1Bytes's own randomly-generated node (#973) (b1da338)
  • v7: align default seq formula in v7Bytes with updateV7State (#965) (a67db57)
Commits
  • fd59f02 chore(main): release 14.0.2 (#967)
  • f3c564e docs: point the Node support permalink at the CI version matrix (#974)
  • b1da338 fix(v1): set the multicast bit on v1Bytes's own randomly-generated node (#973)
  • 6adcc1d fix(v1): carry nsecs overflow into the timestamp's high bits (#972)
  • ea83515 docs: cleanup API summary (#968)
  • ac36860 chore: pin publint version in CI (#966)
  • a67db57 fix(v7): align default seq formula in v7Bytes with updateV7State (#965)
  • See full diff in compare view

Updates arktype from 2.2.3 to 2.2.5

Changelog

Sourced from arktype's changelog.

2.2.5

Preserve escaped backslashes in regex literals

Within a regex literal, \\ is now kept verbatim as an escaped backslash rather than collapsed to a single \, which silently changed the meaning of the pattern:

// previously parsed as /\d/, matching a digit
// now matches a literal backslash followed by "d"
const T = type("/\\\\d/")

String literals are unaffected. If a definition relied on the old behavior, write the intended escape directly (e.g. "/\\d/" for a digit). Thanks to @​spokodev.

Fix recursive discriminated unions referenced from a Record

A cyclic alias referenced through Record<string, ...> could cause valid values to be rejected, e.g. an array branch failing with must be an array (was object). Bootstrapping alias references no longer overwrites references that were already resolved. This was a regression introduced in 2.2.2. Thanks to @​xianjianlf2.

Prevent a crash validating unions of object arrays

Inside a union branch, array validation now stops at the first failing element instead of continuing to traverse elements whose basis has already failed, which could throw rather than return an error. Thanks to @​xianjianlf2.

Merge index-derived props with a declared key of the same name

Intersecting a structure with an index signature and one that rejects undeclared keys could produce a node with a duplicate key:

// previously { a: number, a: number, b: number, + (undeclared): reject }
type({ a: "number", "[string]": "number" }).and({
	a: "number",
	b: "number",
	"+": "reject"
})

Props derived from the index signature are now intersected with any declared prop of the same key, and the result is the same in either operand order.

Preserve parameter labels when a type.fn implementation annotates an optional parameter

Annotating an optional parameter, as in type.fn("number?")((n?: number) => n), previously dropped every parameter label from the inferred signature. It now infers (n?: number | undefined) => number | undefined. Thanks to @​aswinsvijay.

2.2.4

Default a property to an empty array or object in string syntax

= [] and = {} are now valid string-embedded defaults, so an empty collection no longer requires the tuple-with-thunk form:

// previously ["string[]", "=", () => []]
const T = type({
</tr></table> 

... (truncated)

Commits
  • 5606ae8 docs: fix mismatched closing tag in README tagline
  • c7c5fee release: arktype 2.2.5 + dependents (#1660)
  • 0653b23 fix(schema): merge index-derived props with a declared key of the same name (...
  • d66d8d2 fix(schema): prevent crash validating unions of object arrays (#1638)
  • 93dbc3f fix(type): preserve escaped backslash in regex string literals (#1634)
  • 207c644 fix recursive alias reference bootstrapping (#1641)
  • b746a01 fix(type): preserve parameter labels when an implementation annotates an opti...
  • 4e82d77 release: arktype 2.2.4 + dependents (#1656)
  • a046ebe fix(schema): recognize cross-realm arrays with Array.isArray (#1646)
  • b8b23cc feat: support empty collection defaults in string syntax ( = [] and = {}...
  • Additional commits viewable in compare view

Updates @anthropic-ai/claude-agent-sdk from 0.3.234 to 0.3.283

Release notes

Sourced from @​anthropic-ai/claude-agent-sdk's releases.

v0.3.283

What's changed

  • Added plugin_errors to the SDKSystemMessage type (system/init), including path for a --plugin-dir entry that did not load
  • Fixed getSessionMessages() returning, and forkSession() copying, a rewound-away branch when the newest branch ends at a meta row or a local command's rows
  • Changed stream-json output to include warnings and notices raised during a turn as system/informational messages; it previously dropped them
  • Changed the set_max_thinking_tokens control request: omitting max_thinking_tokens now leaves the session's thinking budget unchanged; send null to reset it to the session default
  • Updated to parity with Claude Code v2.1.283

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.283
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.283
# or...
Description has been truncated

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: supply-chain. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from a team as a code owner October 2, 2026 07:35
@changeset-bot

changeset-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: f0d8c77

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. The bumps are in range, the lockfile agrees with the manifests, and the supply-chain controls still hold.

What I checked

  • All manifest changes are minor or patch bumps. The catalog changes (@types/node, tsx, @clerk/nextjs, next, vite) agree with the direct @types/node ranges.
  • The @rollup/rollup-linux-x64-gnu pin in packages/nextjs (4.63.5) is the same as the rollup@4.63.5 that the lockfile resolves.
  • esbuild moves to 0.28.2. This version is in the ^0.28.1 range that the GHSA-g7r4-m6w7-qqqr override sets.
  • No new package needs a build script. onlyBuiltDependencies does not change.
  • @anthropic-ai/sdk moves from 0.117 to 0.128. That is 11 pre-1.0 minors, so breaking changes are permitted. The wizard typecheck and tests pass on Node 22, Node 24 and Bun.

The red Drizzle checks are from the environment, not from this change

Both Drizzle v3 integration jobs fail in one file only, integration/lock-context.integration.test.ts. The error is:

Integration suite cannot run — missing CLERK_MACHINE_TOKEN

The log shows Secret source: Dependabot, and the Dependabot secret store does not have CLERK_MACHINE_TOKEN. The other 4 test files pass. Both jobs pass on the base commit (23e9af3f). ci-required is green. To make Dependabot PRs green again, add CLERK_MACHINE_TOKEN to the repository's Dependabot secrets.

Not blocking: changeset

This PR changes runtime dependency ranges of published packages: @cipherstash/stack (uuid), @cipherstash/nextjs (jose), stash (@clack/prompts, posthog-node) and @cipherstash/wizard (the Anthropic SDKs, @clack/prompts, posthog-node). The previous group bump (#946) merged without a changeset, so I do not block on it. But without a changeset, these ranges ship only with the next release that another change triggers.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-minor-patch-aa67092d59 branch 4 times, most recently from a85c994 to 5e71b5d Compare October 2, 2026 21:55
… with 14 updates

Bumps the production-minor-patch group with 14 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.20.1` | `22.20.4` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [@clack/prompts](https://github.com/bombshell-dev/clack/tree/HEAD/packages/prompts) | `1.7.0` | `1.8.1` |
| [posthog-node](https://github.com/PostHog/posthog-js/tree/HEAD/packages/node) | `5.49.1` | `5.54.1` |
| [jose](https://github.com/panva/jose) | `6.2.9` | `6.2.12` |
| [@rollup/rollup-linux-x64-gnu](https://github.com/rollup/rollup) | `4.62.4` | `4.63.5` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` |
| [arktype](https://github.com/arktypeio/arktype/tree/HEAD/ark/type) | `2.2.3` | `2.2.5` |
| [@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript) | `0.3.234` | `0.3.283` |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.117.1` | `0.128.0` |
| [@clerk/nextjs](https://github.com/clerk/javascript/tree/HEAD/packages/nextjs) | `7.7.7` | `7.9.7` |
| [next](https://github.com/vercel/next.js) | `15.5.24` | `15.5.26` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.15` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.1` | `8.3.1` |



Updates `@types/node` from 22.20.1 to 22.20.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `@clack/prompts` from 1.7.0 to 1.8.1
- [Release notes](https://github.com/bombshell-dev/clack/releases)
- [Changelog](https://github.com/bombshell-dev/clack/blob/main/packages/prompts/CHANGELOG.md)
- [Commits](https://github.com/bombshell-dev/clack/commits/@clack/prompts@1.8.1/packages/prompts)

Updates `posthog-node` from 5.49.1 to 5.54.1
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/commits/posthog-node@5.54.1/packages/node)

Updates `jose` from 6.2.9 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.9...v6.2.12)

Updates `@rollup/rollup-linux-x64-gnu` from 4.62.4 to 4.63.5
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.62.4...v4.63.5)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.1...v14.0.2)

Updates `arktype` from 2.2.3 to 2.2.5
- [Release notes](https://github.com/arktypeio/arktype/releases)
- [Changelog](https://github.com/arktypeio/arktype/blob/main/ark/type/CHANGELOG.md)
- [Commits](https://github.com/arktypeio/arktype/commits/arktype@2.2.5/ark/type)

Updates `@anthropic-ai/claude-agent-sdk` from 0.3.234 to 0.3.283
- [Release notes](https://github.com/anthropics/claude-agent-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-typescript@v0.3.234...v0.3.283)

Updates `@anthropic-ai/sdk` from 0.117.1 to 0.128.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.117.1...sdk-v0.128.0)

Updates `@clerk/nextjs` from 7.7.7 to 7.9.7
- [Release notes](https://github.com/clerk/javascript/releases)
- [Changelog](https://github.com/clerk/javascript/blob/main/packages/nextjs/CHANGELOG.md)
- [Commits](https://github.com/clerk/javascript/commits/@clerk/nextjs@7.9.7/packages/nextjs)

Updates `next` from 15.5.24 to 15.5.26
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v15.5.24...v15.5.26)

Updates `tsx` from 4.23.12 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.12...v4.23.15)

Updates `vite` from 8.2.1 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-agent-sdk"
  dependency-version: 0.3.282
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.128.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@clack/prompts"
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@clerk/nextjs"
  dependency-version: 7.9.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@rollup/rollup-linux-x64-gnu"
  dependency-version: 4.63.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@types/node"
  dependency-version: 22.20.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: arktype
  dependency-version: 2.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: jose
  dependency-version: 6.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: next
  dependency-version: 15.5.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: posthog-node
  dependency-version: 5.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-minor-patch-aa67092d59 branch from 5e71b5d to f0d8c77 Compare October 2, 2026 22:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant