Skip to content

build(deps): bump the npm-minor-patch group across 1 directory with 23 updates - #1938

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-323cd8ba57
Open

build(deps): bump the npm-minor-patch group across 1 directory with 23 updates#1938
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-323cd8ba57

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 22 updates in the / directory:

Package From To
@google-cloud/text-to-speech 7.0.0 7.1.0
@types/node 26.0.0 26.5.1
chrome-devtools-mcp 1.8.0 1.9.0
openai 7.9.0 7.15.0
@flags-sdk/vercel 1.4.7 1.4.8
@sentry/nextjs 10.73.0 10.74.0
@stripe/stripe-js 9.15.0 9.16.0
@supabase/supabase-js 2.114.0 2.116.0
@upstash/redis 1.38.3 1.38.4
@vercel/functions 3.9.5 3.9.7
flags 4.3.0 4.3.1
lucide-react 1.39.0 1.44.0
stripe 22.6.1 22.6.2
swr 2.4.1 2.5.1
tldts 7.0.25 7.4.12
use-sync-external-store 1.6.0 1.7.0
workflow 4.8.5 4.8.8
zod 4.5.4 4.6.1
@playwright/test 1.62.1 1.63.0
@types/jpeg-js 0.3.0 0.3.7
autoprefixer 10.5.4 10.5.6
vite 8.2.2 8.3.0

Updates @google-cloud/text-to-speech from 7.0.0 to 7.1.0

Release notes

Sourced from @​google-cloud/text-to-speech's releases.

os-login: v7.1.0

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)

resource-manager: v7.1.0

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)

secret-manager: v7.1.0

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)

service-directory: v7.1.0

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)

tasks: v7.1.0

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)

text-to-speech: v7.1.0

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)

video-intelligence: v7.1.0

7.1.0 (2026-09-08)

... (truncated)

Changelog

Sourced from @​google-cloud/text-to-speech's changelog.

7.1.0 (2026-09-08)

Features

  • Upgrade librarian gapic-generator-typescript to v5.2.0 (c249594)
Commits

Updates @types/node from 26.0.0 to 26.5.1

Commits

Updates chrome-devtools-mcp from 1.8.0 to 1.9.0

Release notes

Sourced from chrome-devtools-mcp's releases.

chrome-devtools-mcp: v1.9.0

1.9.0 (2026-09-08)

🎉 Features

  • Add --allow-unrestricted-paths by default for CLI (#2618) (2dc104c)
  • add Agent Plugins 1.0 package (#2623) (05d9e55)
  • add an option to turn off js execution tools (#2627) (a78566e)
  • Add cookie-debugging skill and improve network/pages tool descriptions (#2596) (6a67552)
  • add screencast fps option (#2312) (2e641d8)
  • extend --no-javascript-evaluation to cover navigations and initScripts (#2638) (4993a0f)
  • option to disable source maps (#2628) (4430a76)
  • performance: set default trace buffer size to match DevTools (1.2gb) (#2614) (d1baa90)
  • support configurable filesystem roots (#2605) (d00e6f8)

🛠️ Fixes

  • detect scheduled script navigations (#2622) (1b2c0e5)
  • do not enable the DevTools frontend Audits subscription (#2625) (d1e73ff)
  • filter out Chrome webui targets by default (#2648) (020c048)
  • honor background when new_page uses isolatedContext (#2658) (f215c82)
  • memory: expliclity mention the need of a flag (#2620) (46c3e05)
  • truncate long urls in concise network request output (#2513) (552c870)
  • validate viewport and geolocation inputs in emulate tool (#2663) (808aed6), closes #2662

📄 Documentation

🏗️ Refactor

Changelog

Sourced from chrome-devtools-mcp's changelog.

1.9.0 (2026-09-08)

🎉 Features

  • Add --allow-unrestricted-paths by default for CLI (#2618) (2dc104c)
  • add Agent Plugins 1.0 package (#2623) (05d9e55)
  • add an option to turn off js execution tools (#2627) (a78566e)
  • Add cookie-debugging skill and improve network/pages tool descriptions (#2596) (6a67552)
  • add screencast fps option (#2312) (2e641d8)
  • extend --no-javascript-evaluation to cover navigations and initScripts (#2638) (4993a0f)
  • option to disable source maps (#2628) (4430a76)
  • performance: set default trace buffer size to match DevTools (1.2gb) (#2614) (d1baa90)
  • support configurable filesystem roots (#2605) (d00e6f8)

🛠️ Fixes

  • detect scheduled script navigations (#2622) (1b2c0e5)
  • do not enable the DevTools frontend Audits subscription (#2625) (d1e73ff)
  • filter out Chrome webui targets by default (#2648) (020c048)
  • honor background when new_page uses isolatedContext (#2658) (f215c82)
  • memory: expliclity mention the need of a flag (#2620) (46c3e05)
  • truncate long urls in concise network request output (#2513) (552c870)
  • validate viewport and geolocation inputs in emulate tool (#2663) (808aed6), closes #2662

📄 Documentation

🏗️ Refactor

Commits
  • 1cec9cd chore(main): release chrome-devtools-mcp 1.9.0 (#2619)
  • 02c5911 test: migrate screencast tests off withMcpContext to unit tests (#2683)
  • bf9d0a4 chore(deps): bump third_party/devtools-frontend from 330f6aa to d1a4fbf (...
  • a918b7b refactor: extract browser options (#2654)
  • d820bd7 build: fix devtools-frontend dependabot ignore rule (#2681)
  • d4fa58b test: migrate emulation tests off withMcpContext to unit tests (#2665)
  • dc1d559 chore: disable prettier ignore for files updated by release-please (#2680)
  • 4430a76 feat: option to disable source maps (#2628)
  • 757b1fe chore(deps-dev): bump puppeteer from 25.9.0 to 25.10.0 in the bundled group (...
  • 086299a test: add sinon mock utils and emulate tool unit tests (#2641)
  • Additional commits viewable in compare view

Updates openai from 7.9.0 to 7.15.0

Release notes

Sourced from openai's releases.

v7.15.0

7.15.0 (2026-09-10)

Features

v7.14.0

7.14.0 (2026-09-10)

Features

Bug Fixes

  • deps-dev: bump joi from 18.2.3 to 18.2.5 in /ecosystem-tests/vercel-edge (#2702) (029b805)
  • deps: bump next from 15.5.23 to 15.5.25 in /ecosystem-tests/vercel-edge (#2703) (e9446db)
  • deps: bump sharp from 0.35.3 to 0.35.4 in /ecosystem-tests/vercel-edge (#2704) (ca95705)
  • deps: update remaining tooling and fixture patches (#2712) (bcaabee)

v7.13.0

7.13.0 (2026-09-09)

Features

v7.12.1

7.12.1 (2026-09-09)

Includes the GPT Image 2.5 support from 7.12.0, which was not published to npm.

Features

  • api: add GPT Image 2.5 models and image options (#2705) (6500a16)

Bug Fixes

  • ci: run Cloudflare example regressions before release (#2706) (c5cc31c)

v7.12.0

7.12.0 (2026-09-08)

... (truncated)

Changelog

Sourced from openai's changelog.

7.15.0 (2026-09-10)

Features

7.14.0 (2026-09-10)

Features

Bug Fixes

  • deps-dev: bump joi from 18.2.3 to 18.2.5 in /ecosystem-tests/vercel-edge (#2702) (029b805)
  • deps: bump next from 15.5.23 to 15.5.25 in /ecosystem-tests/vercel-edge (#2703) (e9446db)
  • deps: bump sharp from 0.35.3 to 0.35.4 in /ecosystem-tests/vercel-edge (#2704) (ca95705)
  • deps: update remaining tooling and fixture patches (#2712) (bcaabee)

7.13.0 (2026-09-09)

Features

7.12.1 (2026-09-09)

Includes the GPT Image 2.5 support from 7.12.0, which was not published to npm.

Features

  • api: add GPT Image 2.5 models and image options (#2705) (6500a16)

Bug Fixes

  • ci: run Cloudflare example regressions before release (#2706) (c5cc31c)

7.12.0 (2026-09-08)

Features

  • api: add GPT Image 2.5 models and image options (#2705) (6500a16)

... (truncated)

Commits
  • 50eb4b2 release: 7.15.0 (#2720)
  • 20a47f9 feat(api): add Agents API (#2719)
  • c1f88cd release: 7.14.0 (#2711)
  • c037ba7 feat(api) Add Live API (#2718)
  • fe2d6a3 test: reduce CI subprocess and validation overhead (#2713)
  • bcaabee fix(deps): update remaining tooling and fixture patches (#2712)
  • 029b805 fix(deps-dev): bump joi from 18.2.3 to 18.2.5 in /ecosystem-tests/vercel-edge...
  • e9446db fix(deps): bump next from 15.5.23 to 15.5.25 in /ecosystem-tests/vercel-edge ...
  • ca95705 fix(deps): bump sharp from 0.35.3 to 0.35.4 in /ecosystem-tests/vercel-edge (...
  • a661a7d release: 7.13.0 (#2710)
  • Additional commits viewable in compare view

Updates @flags-sdk/vercel from 1.4.7 to 1.4.8

Release notes

Sourced from @​flags-sdk/vercel's releases.

@​flags-sdk/vercel@​1.4.8

Patch Changes

  • #486 c9d2811 Thanks @​dferber90! - Implement the experimental_reportOverride adapter hook to forward override values to the underlying Vercel Flags client.

    This API is not supported for general use yet. Do not use it unless Vercel has explicitly enabled it for you.

  • Updated dependencies [c9d2811, c9d2811, e0eebe6]:

    • flags@4.3.1
    • @​vercel/flags-core@​1.8.1
Commits
  • 6444210 Version Packages (#493)
  • e0eebe6 fix(flags-core): request identity on the stream so Bun receives the first dat...
  • c9d2811 Experiments (#486)
  • 752a05f Trim duplicated vercel flags CLI docs from flags-sdk skill (#492)
  • 22083e7 Prefer vercel flags create over add in the skill (#488)
  • eaa7f1e Make flags-sdk skill setup-first for discovery (#487)
  • See full diff in compare view

Updates @sentry/nextjs from 10.73.0 to 10.74.0

Release notes

Sourced from @​sentry/nextjs's releases.

10.74.0

  • feat(v10): Streamline isolation scope handling & reset in isolation scopes (#24152)
  • fix(server-utils): Include Gemini reasoning tokens in Vercel AI token usage (#23433)
  • fix(v10/browser): Set user_agent.original on all spans for consistent filtering (#24226)
  • fix(v10/cloudflare): Auto-instrument classes re-exported from the worker entry (#24181)
  • fix(v10/core): Guard loadModule default parameter against ESM scope (#24154)
  • fix(v10/core): Match wrapped Facebook Mobile browser errors in DEFAULT_IGNORE_ERRORS (#23877)
  • fix(v10/core): Resolve MCP capture policy per operation (#23796)
  • fix(v10/nextjs): Fix SDK import crashing under jsdom/happy-dom (#23906)
  • fix(v10/nextjs): Keep the Pages Router runtime out of App Router client bundles (#24223)
  • fix(v10/nextjs): Register Vercel AI span processors on Next.js (#23773)
  • fix(v10/nuxt): Windows file:// for import-in-the-middle hook and isAbsolute for C:\ (#24026)
  • fix(v10/profiling-node): Bump @​sentry/node-cpu-profiler to 2.4.4 (#24238)
  • fix(v10/sveltekit): Handle SvelteKit 3 error kinds in handleErrorWithSentry (#23995)
  • fix(v10/sveltekit): Read Cloudflare execution context from platform.ctx (#23994)
  • fix(v10/sveltekit): Read SvelteKit config from the Vite plugin (#23998)
  • test(e2e): Assert Next.js Cloudflare worker bundle stays free of orchestrion bundler plugins (#23910)

Work in this release was contributed by @​halillusion and @​zkasuran. Thank you for your contributions!

Bundle size 📦

Path Size
@​sentry/browser 27.12 KB
@​sentry/browser - with treeshaking flags 25.59 KB
@​sentry/browser (incl. Tracing) 45.53 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.29 KB
@​sentry/browser (incl. Tracing, Profiling) 50.18 KB
@​sentry/browser (incl. Tracing, Replay) 83.87 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 73.74 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 88.49 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 100.82 KB
@​sentry/browser (incl. Feedback) 43.89 KB
@​sentry/browser (incl. sendFeedback) 31.8 KB
@​sentry/browser (incl. FeedbackAsync) 36.82 KB
@​sentry/browser (incl. Metrics) 28.19 KB
@​sentry/browser (incl. Logs) 28.41 KB
@​sentry/browser (incl. Metrics & Logs) 29.09 KB
@​sentry/react 28.89 KB
@​sentry/react (incl. Tracing) 47.74 KB
@​sentry/vue 32.42 KB
@​sentry/vue (incl. Tracing) 47.47 KB
@​sentry/svelte 27.15 KB

... (truncated)

Changelog

Sourced from @​sentry/nextjs's changelog.

10.74.0

  • feat(v10): Streamline isolation scope handling & reset in isolation scopes (#24152)
  • fix(server-utils): Include Gemini reasoning tokens in Vercel AI token usage (#23433)
  • fix(v10/browser): Set user_agent.original on all spans for consistent filtering (#24226)
  • fix(v10/cloudflare): Auto-instrument classes re-exported from the worker entry (#24181)
  • fix(v10/core): Guard loadModule default parameter against ESM scope (#24154)
  • fix(v10/core): Match wrapped Facebook Mobile browser errors in DEFAULT_IGNORE_ERRORS (#23877)
  • fix(v10/core): Resolve MCP capture policy per operation (#23796)
  • fix(v10/nextjs): Fix SDK import crashing under jsdom/happy-dom (#23906)
  • fix(v10/nextjs): Keep the Pages Router runtime out of App Router client bundles (#24223)
  • fix(v10/nextjs): Register Vercel AI span processors on Next.js (#23773)
  • fix(v10/nuxt): Windows file:// for import-in-the-middle hook and isAbsolute for C:\ (#24026)
  • fix(v10/profiling-node): Bump @​sentry/node-cpu-profiler to 2.4.4 (#24238)
  • fix(v10/sveltekit): Handle SvelteKit 3 error kinds in handleErrorWithSentry (#23995)
  • fix(v10/sveltekit): Read Cloudflare execution context from platform.ctx (#23994)
  • fix(v10/sveltekit): Read SvelteKit config from the Vite plugin (#23998)
  • test(e2e): Assert Next.js Cloudflare worker bundle stays free of orchestrion bundler plugins (#23910)

Work in this release was contributed by @​halillusion and @​zkasuran. Thank you for your contributions!

Commits
  • ce5009a release: 10.74.0
  • 4b24ddd meta(changelog): Update changelog for 10.74.0 (#24252)
  • 371ed5d fix(v10/profiling-node): Bump @​sentry/node-cpu-profiler to 2.4.4 (#24238)
  • 9f38e48 fix(v10/browser): Set user_agent.original on all spans for consistent filte...
  • 264f990 fix(v10/cloudflare): Auto-instrument classes re-exported from the worker entr...
  • c89f6e6 fix(v10/nextjs): Keep the Pages Router runtime out of App Router client bundl...
  • de25dcb fix(v10/core): Guard loadModule default parameter against ESM scope (#24154)
  • b627037 feat(v10): Streamline isolation scope handling & reset in isolation scopes (#...
  • 2ce0ea1 fix(v10/nuxt): Windows file:// for import-in-the-middle hook and isAbsolute f...
  • 3e0eccc fix(server-utils): Include Gemini reasoning tokens in Vercel AI token usage (...
  • Additional commits viewable in compare view

Updates @stripe/stripe-js from 9.15.0 to 9.16.0

Release notes

Sourced from @​stripe/stripe-js's releases.

v9.16.0

  • Add Link Signup Element types (#969)
  • Add Custom Checkout tiered and package pricing types (#966)

New features

Fixes

Changed

Commits

Updates @supabase/supabase-js from 2.114.0 to 2.116.0

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.116.0

2.116.0 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)
  • storage: add bucket lifecycle configuration (#2659)
  • storage: topk 10k support (#2667)
  • storage: add versionId support to create URL methods (#2678)

🩹 Fixes

  • auth: silence commit-guard-discarded refresh in initial session (#2668)
  • storage: drop legacy prefix from lifecycles (#2674)
  • supabase: warn when schema is passed outside db options (#2663)

❤️ Thank You

  • fadymak
  • Ferhat Elmas
  • Katerina Skroumpelou @​mandarini
  • Tyler Hillery

v2.116.0-canary.3

2.116.0-canary.3 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)
  • storage: add versionId support to create URL methods (#2678)

❤️ Thank You

  • fadymak
  • Katerina Skroumpelou
  • Tyler Hillery

v2.116.0-canary.2

2.116.0-canary.2 (2026-09-07)

🚀 Features

  • storage: topk 10k support (#2667)

🩹 Fixes

  • storage: drop legacy prefix from lifecycles (#2674)

❤️ Thank You

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.116.0 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)

🩹 Fixes

  • supabase: warn when schema is passed outside db options (#2663)

❤️ Thank You

2.115.0 (2026-09-03)

🚀 Features

  • postgrest: add getOpenApiSpec() (#2651)

❤️ Thank You

Commits

Updates @upstash/redis from 1.38.3 to 1.38.4

Release notes

Sourced from @​upstash/redis's releases.

@​upstash/redis@​1.38.4

Patch Changes

  • 7ac8182: Fix read-your-writes sending a stale upstash-sync-token

    A read issued straight after a write travelled with the token from before that write, so the server was under no obligation to serve the write and readYourWrites silently did not hold.

    HttpClient.request() snapshotted the outgoing headers with mergeHeaders(this.headers, ...) and only afterwards wrote the freshest token into this.headers, so the token learned from response N first shipped with request N+2. The assignment now happens before the merge.

    This regressed in 1.34.5. In 1.34.0–1.34.4 the request options held headers: this.headers by reference, so the late write was still picked up before fetch; 1.34.5 introduced per-request header merging, which turned that reference into a copy without moving the assignment.

Commits

Updates @vercel/functions from 3.9.5 to 3.9.7

Changelog

Sourced from @​vercel/functions's changelog.

@​vercel/functions

Commits

Updates flags from 4.3.0 to 4.3.1

Release notes

Sourced from flags's releases.

flags@4.3.1

Patch Changes

  • #486 c9d2811 Thanks @​dferber90! - Add the experimental_reportOverride adapter hook for observing values set by the Flags SDK override cookie.

    This API is not supported for general use yet. Do not use it unless Vercel has explicitly enabled it for you.

Commits

Updates lucide-react from 1.39.0 to 1.44.0

Release notes

Sourced from lucide-react's releases.

Version 1.44.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.43.0...1.44.0

Version 1.43.0

What's Changed

Full Changelog:

…3 updates

Bumps the npm-minor-patch group with 22 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@google-cloud/text-to-speech](https://github.com/googleapis/google-cloud-node/tree/HEAD/packages/google-cloud-texttospeech) | `7.0.0` | `7.1.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.0.0` | `26.5.1` |
| [chrome-devtools-mcp](https://github.com/ChromeDevTools/chrome-devtools-mcp) | `1.8.0` | `1.9.0` |
| [openai](https://github.com/openai/openai-node) | `7.9.0` | `7.15.0` |
| [@flags-sdk/vercel](https://github.com/vercel/flags) | `1.4.7` | `1.4.8` |
| [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) | `10.73.0` | `10.74.0` |
| [@stripe/stripe-js](https://github.com/stripe/stripe-js) | `9.15.0` | `9.16.0` |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.114.0` | `2.116.0` |
| [@upstash/redis](https://github.com/upstash/redis-js) | `1.38.3` | `1.38.4` |
| [@vercel/functions](https://github.com/vercel/vercel/tree/HEAD/packages/functions) | `3.9.5` | `3.9.7` |
| [flags](https://github.com/vercel/flags) | `4.3.0` | `4.3.1` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.39.0` | `1.44.0` |
| [stripe](https://github.com/stripe/stripe-node) | `22.6.1` | `22.6.2` |
| [swr](https://github.com/vercel/swr) | `2.4.1` | `2.5.1` |
| [tldts](https://github.com/remusao/tldts) | `7.0.25` | `7.4.12` |
| [use-sync-external-store](https://github.com/react/react/tree/HEAD/packages/use-sync-external-store) | `1.6.0` | `1.7.0` |
| [workflow](https://github.com/vercel/workflow/tree/HEAD/packages/workflow) | `4.8.5` | `4.8.8` |
| [zod](https://github.com/colinhacks/zod) | `4.5.4` | `4.6.1` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@types/jpeg-js](https://github.com/eugeneware/jpeg-js) | `0.3.0` | `0.3.7` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.5.4` | `10.5.6` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.0` |



Updates `@google-cloud/text-to-speech` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/packages/google-cloud-texttospeech/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/dlp-v7.1.0/packages/google-cloud-texttospeech)

Updates `@types/node` from 26.0.0 to 26.5.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `chrome-devtools-mcp` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/ChromeDevTools/chrome-devtools-mcp/releases)
- [Changelog](https://github.com/ChromeDevTools/chrome-devtools-mcp/blob/main/CHANGELOG.md)
- [Commits](ChromeDevTools/chrome-devtools-mcp@chrome-devtools-mcp-v1.8.0...chrome-devtools-mcp-v1.9.0)

Updates `openai` from 7.9.0 to 7.15.0
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/main/CHANGELOG.md)
- [Commits](openai/openai-node@v7.9.0...v7.15.0)

Updates `@flags-sdk/vercel` from 1.4.7 to 1.4.8
- [Release notes](https://github.com/vercel/flags/releases)
- [Commits](https://github.com/vercel/flags/compare/@flags-sdk/vercel@1.4.7...@flags-sdk/vercel@1.4.8)

Updates `@sentry/nextjs` from 10.73.0 to 10.74.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.74.0/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.73.0...10.74.0)

Updates `@stripe/stripe-js` from 9.15.0 to 9.16.0
- [Release notes](https://github.com/stripe/stripe-js/releases)
- [Commits](stripe/stripe-js@v9.15.0...v9.16.0)

Updates `@supabase/supabase-js` from 2.114.0 to 2.116.0
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.116.0/packages/core/supabase-js)

Updates `@upstash/redis` from 1.38.3 to 1.38.4
- [Release notes](https://github.com/upstash/redis-js/releases)
- [Commits](https://github.com/upstash/redis-js/compare/@upstash/redis@1.38.3...@upstash/redis@1.38.4)

Updates `@vercel/functions` from 3.9.5 to 3.9.7
- [Release notes](https://github.com/vercel/vercel/releases)
- [Changelog](https://github.com/vercel/vercel/blob/main/packages/functions/CHANGELOG.md)
- [Commits](https://github.com/vercel/vercel/commits/HEAD/packages/functions)

Updates `flags` from 4.3.0 to 4.3.1
- [Release notes](https://github.com/vercel/flags/releases)
- [Commits](https://github.com/vercel/flags/compare/flags@4.3.0...flags@4.3.1)

Updates `lucide-react` from 1.39.0 to 1.44.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.44.0/packages/lucide-react)

Updates `stripe` from 22.6.1 to 22.6.2
- [Release notes](https://github.com/stripe/stripe-node/releases)
- [Changelog](https://github.com/stripe/stripe-node/blob/master/CHANGELOG.md)
- [Commits](stripe/stripe-node@v22.6.1...v22.6.2)

Updates `swr` from 2.4.1 to 2.5.1
- [Release notes](https://github.com/vercel/swr/releases)
- [Commits](vercel/swr@v2.4.1...v2.5.1)

Updates `tldts` from 7.0.25 to 7.4.12
- [Release notes](https://github.com/remusao/tldts/releases)
- [Changelog](https://github.com/remusao/tldts/blob/master/CHANGELOG.md)
- [Commits](remusao/tldts@v7.0.25...v7.4.12)

Updates `use-sync-external-store` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/HEAD/packages/use-sync-external-store)

Updates `workflow` from 4.8.5 to 4.8.8
- [Release notes](https://github.com/vercel/workflow/releases)
- [Changelog](https://github.com/vercel/workflow/blob/workflow@4.8.8/packages/workflow/CHANGELOG.md)
- [Commits](https://github.com/vercel/workflow/commits/workflow@4.8.8/packages/workflow)

Updates `zod` from 4.5.4 to 4.6.1
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.5.4...v4.6.1)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@types/jpeg-js` from 0.3.0 to 0.3.7
- [Release notes](https://github.com/eugeneware/jpeg-js/releases)
- [Commits](jpeg-js/jpeg-js@v0.3.0...v0.3.7)

Updates `autoprefixer` from 10.5.4 to 10.5.6
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.4...10.5.6)

Updates `playwright` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `vite` from 8.2.2 to 8.3.0
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite)

---
updated-dependencies:
- dependency-name: "@google-cloud/text-to-speech"
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/node"
  dependency-version: 26.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: chrome-devtools-mcp
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: openai
  dependency-version: 7.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@flags-sdk/vercel"
  dependency-version: 1.4.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@sentry/nextjs"
  dependency-version: 10.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@stripe/stripe-js"
  dependency-version: 9.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.116.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@upstash/redis"
  dependency-version: 1.38.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@vercel/functions"
  dependency-version: 3.9.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: flags
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: lucide-react
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: stripe
  dependency-version: 22.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: swr
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tldts
  dependency-version: 7.4.12
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: use-sync-external-store
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: workflow
  dependency-version: 4.8.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: zod
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/jpeg-js"
  dependency-version: 0.3.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: autoprefixer
  dependency-version: 10.5.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: playwright
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: vite
  dependency-version: 8.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 13, 2026
@dependabot
dependabot Bot requested a review from groupthinking as a code owner September 13, 2026 20:29
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 13, 2026
@vercel

vercel Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
v0-uvai Ready Ready Preview, v0 Sep 13, 2026 8:30pm UTC

@github-actions

Copy link
Copy Markdown
Contributor

🔍 PR Validation

⚠️ Large PR detected (806 lines changed)

@coderabbitai

coderabbitai Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 342d80d8-67c5-453f-b755-fc3f03c3d496

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

🔴 E2E Test Results: FAILURE DETECTED

Metric Value
Status 🔴 RED
Total Tests
Passed
Failed 1
Deployment https://v0-uvai-6z3olaycl-garv1.vercel.app
Test Output
ion and stage progress
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mError Handling�[2m > �[22mmissing URL returns 400, not a hang
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mError Handling�[2m > �[22minvalid URL returns error event or completes quickly, not a hang
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mDashboard�[2m > �[22m/dashboard returns 200
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mDashboard�[2m > �[22m/dashboard contains agent or pipeline visualization markup
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mAPI Health�[2m > �[22mGET /api returns a response (not 404)
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mAPI Health�[2m > �[22mPOST /api/pipeline/stream with no body returns 400
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mStatic Assets�[2m > �[22mhomepage has proper meta tags
 �[2m�[90m↓�[39m�[22m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment�[2m > �[22mStatic Assets�[2m > �[22m/features page returns 200

�[31m⎯⎯⎯⎯⎯⎯�[39m�[1m�[41m Failed Suites 1 �[49m�[22m�[31m⎯⎯⎯⎯⎯⎯⎯�[39m

�[41m�[1m FAIL �[22m�[49m tests/e2e/pipeline.test.ts�[2m > �[22mEventRelay E2E — Live Deployment
�[31m�[1mError�[22m: Deployment protection blocked this run — https://v0-uvai-6z3olaycl-garv1.vercel.app returned 302 → https://vercel.com/sso-api?url=https%3A%2F%2Fv0-uvai-6z3olaycl-garv1.vercel.app%2F&nonce=03295035652638dca41a4ec5ade8179842b967d654cfc594cd557f79ccdf7388 instead of the app, so every assertion below would execute against Vercel's login page rather than the deployment. Set the VERCEL_AUTOMATION_BYPASS_SECRET repository secret to the project's "Protection Bypass for Automation" value (Vercel → Project → Settings → Deployment Protection); this suite forwards it as the x-vercel-protection-bypass header on every request.�[39m
�[36m �[2m❯�[22m tests/e2e/pipeline.test.ts:�[2m132:13�[22m�[39m
    �[90m130|�[39m
    �[90m131|�[39m     �[35mif�[39m (ssoRedirect �[33m||�[39m probe�[33m.�[39mstatus �[33m===�[39m �[34m401�[39m) {
    �[90m132|�[39m       �[35mthrow�[39m �[35mnew�[39m �[33mError�[39m(
    �[90m   |�[39m             �[31m^�[39m
    �[90m133|�[39m         `Deployment protection blocked this run — ${BASE_URL} returned…
    �[90m134|�[39m           `${location ? ` → ${location}` : ''} instead of the app, so …

�[31m�[2m⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯[1/1]⎯�[22m�[39m


�[2m Test Files �[22m �[1m�[31m1 failed�[39m�[22m�[90m (1)�[39m
�[2m      Tests �[22m �[33m17 skipped�[39m�[90m (17)�[39m
�[2m   Start at �[22m 20:30:54
�[2m   Duration �[22m 376ms�[2m (transform 50ms, setup 0ms, import 65ms, tests 170ms, environment 0ms)�[22m


@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants