chore(deps): bump the npm group across 1 directory with 15 updates#17
chore(deps): bump the npm group across 1 directory with 15 updates#17dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the npm group with 15 updates in the /apps/web directory: | Package | From | To | | --- | --- | --- | | [@better-auth/infra](https://github.com/better-auth/better-auth-infra/tree/HEAD/packages/infra) | `0.1.9-beta.1` | `0.2.4` | | [@better-auth/utils](https://github.com/better-auth/utils) | `0.3.1` | `0.4.0` | | [@tanstack/react-hotkeys](https://github.com/TanStack/hotkeys/tree/HEAD/packages/react-hotkeys) | `0.3.3` | `0.9.1` | | [@vercel/analytics](https://github.com/vercel/analytics/tree/HEAD/packages/web) | `1.6.1` | `2.0.1` | | [auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/cli) | `1.5.0-beta.18` | `1.6.5` | | [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.5.1` | `1.6.5` | | [foxact](https://github.com/SukkaW/foxact) | `0.2.55` | `0.3.0` | | [inngest](https://github.com/inngest/inngest-js/tree/HEAD/packages/inngest) | `3.52.7` | `4.2.4` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.575.0` | `1.8.0` | | [next](https://github.com/vercel/next.js) | `16.1.6` | `16.2.4` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.4` | `19.2.5` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.2.5` | | [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `3.23.0` | `4.0.2` | | [vercel](https://github.com/vercel/vercel/tree/HEAD/packages/cli) | `50.44.0` | `51.7.0` | | [typescript](https://github.com/microsoft/TypeScript) | `6.0.2` | `6.0.3` | Updates `@better-auth/infra` from 0.1.9-beta.1 to 0.2.4 - [Commits](https://github.com/better-auth/better-auth-infra/commits/HEAD/packages/infra) Updates `@better-auth/utils` from 0.3.1 to 0.4.0 - [Release notes](https://github.com/better-auth/utils/releases) - [Commits](better-auth/utils@v0.3.1...v0.4.0) Updates `@tanstack/react-hotkeys` from 0.3.3 to 0.9.1 - [Release notes](https://github.com/TanStack/hotkeys/releases) - [Changelog](https://github.com/TanStack/hotkeys/blob/main/packages/react-hotkeys/CHANGELOG.md) - [Commits](https://github.com/TanStack/hotkeys/commits/@tanstack/react-hotkeys@0.9.1/packages/react-hotkeys) Updates `@vercel/analytics` from 1.6.1 to 2.0.1 - [Release notes](https://github.com/vercel/analytics/releases) - [Commits](https://github.com/vercel/analytics/commits/v2.0.1/packages/web) Updates `auth` from 1.5.0-beta.18 to 1.6.5 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/auth@1.6.5/packages/cli) Updates `better-auth` from 1.5.1 to 1.6.5 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/better-auth@1.6.5/packages/better-auth) Updates `foxact` from 0.2.55 to 0.3.0 - [Release notes](https://github.com/SukkaW/foxact/releases) - [Commits](SukkaW/foxact@0.2.55...0.3.0) Updates `inngest` from 3.52.7 to 4.2.4 - [Release notes](https://github.com/inngest/inngest-js/releases) - [Changelog](https://github.com/inngest/inngest-js/blob/main/packages/inngest/CHANGELOG.md) - [Commits](https://github.com/inngest/inngest-js/commits/inngest@4.2.4/packages/inngest) Updates `lucide-react` from 0.575.0 to 1.8.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.8.0/packages/lucide-react) Updates `next` from 16.1.6 to 16.2.4 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v16.1.6...v16.2.4) Updates `react` from 19.2.4 to 19.2.5 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react) Updates `react-dom` from 19.2.4 to 19.2.5 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react-dom) Updates `shiki` from 3.23.0 to 4.0.2 - [Release notes](https://github.com/shikijs/shiki/releases) - [Commits](https://github.com/shikijs/shiki/commits/v4.0.2/packages/shiki) Updates `vercel` from 50.44.0 to 51.7.0 - [Release notes](https://github.com/vercel/vercel/releases) - [Changelog](https://github.com/vercel/vercel/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/vercel/vercel/commits/vercel@51.7.0/packages/cli) Updates `typescript` from 6.0.2 to 6.0.3 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v6.0.2...v6.0.3) --- updated-dependencies: - dependency-name: "@better-auth/infra" dependency-version: 0.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@better-auth/utils" dependency-version: 0.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@tanstack/react-hotkeys" dependency-version: 0.9.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@vercel/analytics" dependency-version: 2.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm - dependency-name: auth dependency-version: 1.6.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: better-auth dependency-version: 1.6.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: foxact dependency-version: 0.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: inngest dependency-version: 4.2.4 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm - dependency-name: lucide-react dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm - dependency-name: next dependency-version: 16.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: react dependency-version: 19.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: react-dom dependency-version: 19.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: shiki dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm - dependency-name: vercel dependency-version: 51.7.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm - dependency-name: typescript dependency-version: 6.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
Pull Request Overview
While Codacy reports that the repository is up to standards, this PR cannot be safely merged in its current state. The most significant issue is the empty diff, which prevents verification of the 15 package updates described. Furthermore, bundling multiple major version jumps (e.g., foxact, @vercel/analytics, shiki) into a single 'npm group' is high-risk. Specifically, the update to 'foxact' 0.3.0 involves the removal of several hooks that may cause runtime failures if the codebase has not been audited. Acceptance criteria regarding the verification of these updates cannot be met without visible changes to the lockfile or package configuration.
About this PR
- The update to 'foxact' 0.3.0 removes several hooks (use-next-link, use-next-pathname, etc.). There is no evidence that the codebase has been audited for these removals, which could lead to runtime errors.
- The PR diff is empty. It is impossible to verify if the 15 npm package updates have been correctly applied to the package.json or lockfiles in the /apps/web directory.
- This PR bundles 15 updates into a single group, including several major version increments. It is recommended to split major updates into separate PRs to simplify debugging and reduce regression risk.
Test suggestions
- Verify successful application build using TypeScript 6.0.3
- Audit codebase for usage of removed hooks in foxact 0.3.0 (use-next-link, use-next-pathname, use-react-router-enable-concurrent-navigation, use-react-router-is-match) to prevent runtime errors
- Verify Vercel Analytics v2 integration, specifically checking for breaking changes mentioned in the release notes regarding Nuxt support or configuration
- Validate Better-Auth authentication flows, specifically session refreshing after password changes as mentioned in the 1.6.5 bug fixes
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify successful application build using TypeScript 6.0.3
2. Audit codebase for usage of removed hooks in foxact 0.3.0 (use-next-link, use-next-pathname, use-react-router-enable-concurrent-navigation, use-react-router-is-match) to prevent runtime errors
3. Verify Vercel Analytics v2 integration, specifically checking for breaking changes mentioned in the release notes regarding Nuxt support or configuration
4. Validate Better-Auth authentication flows, specifically session refreshing after password changes as mentioned in the 1.6.5 bug fixes
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Up to standards ✅🟢 Issues
|
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
|



Bumps the npm group with 15 updates in the /apps/web directory:
0.1.9-beta.10.2.40.3.10.4.00.3.30.9.11.6.12.0.11.5.0-beta.181.6.51.5.11.6.50.2.550.3.03.52.74.2.40.575.01.8.016.1.616.2.419.2.419.2.519.2.419.2.53.23.04.0.250.44.051.7.06.0.26.0.3Updates
@better-auth/infrafrom 0.1.9-beta.1 to 0.2.4Commits
Updates
@better-auth/utilsfrom 0.3.1 to 0.4.0Release notes
Sourced from
@better-auth/utils's releases.Commits
23a924cchore: release v0.4.01639b0dfeat: add password module with native node:crypto scrypt support (#16)Updates
@tanstack/react-hotkeysfrom 0.3.3 to 0.9.1Release notes
Sourced from
@tanstack/react-hotkeys's releases.... (truncated)
Changelog
Sourced from
@tanstack/react-hotkeys's changelog.... (truncated)
Commits
9041e8fci: Version Packages (#100)1f30feeci: Version Packages (#96)63bfa22feat: options.meta with name and descriptions by default and new useHotkeysRe...69cfe41ci: Version Packages (#94)b04c88efeat: add lit adapater packages (#59)67b97b5ci: Version Packages (#93)8a67366ci: Version Packages (#91)4fbe605ci: Version Packages (#87)19a960fchore: upgrade to latest tanstack store2f30945ci: Version Packages (#86)Updates
@vercel/analyticsfrom 1.6.1 to 2.0.1Release notes
Sourced from
@vercel/analytics's releases.Commits
0d69416chore: bump version to v2.0.1 (#195)c7f3c37fix(nuxt): set nuxt as optional dependency (#193)c3e3805chore: bump version to v2.0.0425a797chore: bump version to v2.0.0-canary.122888e3fix: src and endpoint paths do not work when relative (#186)3879f57feat: load dynamic configuration (#184)95f8914feat(nuxt)!: Add support forinjectAnalytics()and Nuxt module (#183)e407489feat!: change license to MIT (#170)Updates
authfrom 1.5.0-beta.18 to 1.6.5Release notes
Sourced from auth's releases.
... (truncated)
Changelog
Sourced from auth's changelog.
... (truncated)
Commits
c8a91f4chore: release v1.6.5 (#9209)9ec849fchore: release v1.6.4 (#9175)6f17bb3chore: release v1.6.3 (#9081)4673c6dfix(cli): handle extends and mid-path wildcards in tsconfig paths (#9032)700d298chore: version packages (#9052)e78a7b1fix(two-factor): prevent unverified TOTP enrollment from gating sign-in (#8711)85bb710chore: version packages (#9018)d666a03chore: exit pre-release mode for v1.6.073beda2chore: version packages (beta) (#8945)77ead28chore: reset package versions to 1.5.6 (#8930)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for auth since your current version.
Updates
better-authfrom 1.5.1 to 1.6.5Release notes
Sourced from better-auth's releases.
... (truncated)
Changelog
Sourced from better-auth's changelog.
... (truncated)
Commits
c8a91f4chore: release v1.6.5 (#9209)938dd80docs(test-utils): clarify production usage (#9119)0538627fix(client): trigger $sessionSignal for session-rotating endpoints (#9087)9ec849fchore: release v1.6.4 (#9175)39d6af2chore(adapters): require patched drizzle-orm and kysely peer versions (#9165)ba03fb5chore(deps): bump electron and next devDependencies to patched versions (#9166)9aed910fix(two-factor): revert enforcement broadening from #9122 (#9205)acbd6effix: honor forceAllowId UUIDs on postgres adapters (#9068)6f17bb3chore: release v1.6.3 (#9081)9a6d475fix(client): preventisMountedrace condition causing many rps (#9078)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for better-auth since your current version.
Updates
foxactfrom 0.2.55 to 0.3.0Release notes
Sourced from foxact's releases.
Commits
ecdce99release: 0.3.01f49be3refactor!: remove foxact extension category hooksbced5d0chore: housekeepingUpdates
inngestfrom 3.52.7 to 4.2.4Release notes
Sourced from inngest's releases.
... (truncated)
Changelog
Sourced from inngest's changelog.
... (truncated)
Commits
8d1a207Release@latest(#1467)68de915Fix checkpointing maxRuntime causing duplicate execution (#1466)5591a0cRelease@latest(#1462)5a01279[e13n phase 2] exe-1617 propagate selectionStrategy and fix replay-path gap (...ce5110dFix multi-byte UTF-8 chars corrupted when split over chunks (#1460)d75b59cFix CountQueuingStrategy erroring when stubbed in edge runtimes (#1461)fd655aeRelease@latest(#1456)d151b40Conditionally instantiate CountQueuingStrategy (#1457)aca72f8OTel Improvements (#1366)15495e0Fix dependencyInjection not working statically at function level (#1455)Updates
lucide-reactfrom 0.575.0 to 1.8.0Release notes
Sourced from lucide-react's releases.
... (truncated)
Commits
7623e23feat(docs): add Zephyr Cloud to Hero Backers tier & rework updateSponsors scr...dada0a8fix(lucide-react): Fix dynamic imports (#4210)a6e648afix(lucide-react): correct client directives in RSC files (#4189)1f010a3fix(luc...Description has been truncated