Skip to content

Navigation Menu

Sign in
Sign up

chore(deps): bump the npm_and_yarn group across 3 directories with 19 updates - #26

Open
dependabot[bot] wants to merge 1 commit into
main from
dependabot/npm_and_yarn/test/npm_and_yarn-220b27500f
Open

chore(deps): bump the npm_and_yarn group across 3 directories with 19 updates #26
dependabot[bot] wants to merge 1 commit into
main from
dependabot/npm_and_yarn/test/npm_and_yarn-220b27500f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 9, 2026

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 17 updates in the /test directory:

Package From To
@nestjs/common 11.0.3 11.0.16
@nestjs/core 11.0.3 11.1.18
@remix-run/react 2.10.3 2.17.3
aws-cdk-lib 2.148.0 2.189.1
axios 1.6.8 1.15.0
devalue 5.1.1 5.6.4
esbuild 0.18.6 0.25.0
express 4.18.2 4.22.0
happy-dom 17.0.3 20.8.9
hono 4.7.2 4.12.12
jws 4.0.0 4.0.1
lodash 4.17.21 4.18.1
nodemailer 6.9.3 8.0.5
rollup 4.4.1 4.59.0
typeorm 0.3.20 0.3.26
undici 5.20.0 6.24.0
webpack 5.88.0 5.104.1

Bumps the npm_and_yarn group with 3 updates in the /test/js/third_party/pnpm/install_fixture directory: rollup, vite and seroval.
Bumps the npm_and_yarn group with 1 update in the /test/js/third_party/webpack directory: webpack.

Updates @nestjs/common from 11.0.3 to 11.0.16

Release notes

Sourced from @​nestjs/common's releases.

v11.0.16 (2025年04月11日)

v11.0.15 (2025年04月10日)

Bug fixes

Committers: 1

v11.0.14 (2025年04月09日)

Bug fixes

  • platform-fastify
    • #14511 fix(fastify): adds the non-standard http methods to the instance (@​johaven)

Committers: 1

v11.0.13 (2025年04月03日)

Bug fixes

  • platform-fastify
    • #14895 fix(fastify-adapter): global prefix exclusion path handling w/middleware (@​KyleLilly)
  • microservices
    • #14869 fix(microservices): do not re-create client connection once get client by service name (@​mingo023)

Dependencies

Committers: 2

v11.0.12 (2025年03月19日)

Bug fixes

Enhancements

... (truncated)

Commits
  • b6edf9a chore(@​nestjs) publish v11.0.16 release
  • ab79c56 chore: minor tweaks
  • dcc177a Update packages/common/pipes/file/file-type.validator.ts
  • e019da8 refactor(common): move back file type validator options type
  • 4718a64 chore(@​nestjs) publish v11.0.15 release
  • b6078fd refactor(common): move file-type package to peer dependencies
  • f34ef9a refactor(common): refactor code to use simple eval
  • 3ff9024 fix(common): used eval import
  • 63d28bf refactor(common): removed async keyword
  • 5243fca fix(common): update file mime package and add param skip magic numbers
  • Additional commits viewable in compare view

Updates @nestjs/core from 11.0.3 to 11.1.18

Release notes

Sourced from @​nestjs/core's releases.

v11.1.18 (2026年04月03日)

Bug fixes

Dependencies

Committers: 6

v11.1.17 (2026年03月16日)

Enhancements

Bugs

Dependencies

Committers: 3

... (truncated)

Commits
  • 3c1cc5f chore(release): publish v11.1.18 release
  • 0f962c7 fix(core): sanitize sse message
  • 94aa424 Merge pull request #16679 from nestjs/renovate/path-to-regexp-8.x
  • 368691c fix(core): prevent injector hang when design:paramtypes is missing
  • 25d4fde fix(deps): update dependency path-to-regexp to v8.4.2
  • 5c0b11e fix(deps): update dependency path-to-regexp to v8.4.1
  • f7d4460 Merge pull request #16637 from JakobStaudinger/moduleref-create-transient-sco...
  • d0a9dc9 fix(deps): update dependency path-to-regexp to v8.4.0
  • 4677434 feat(core): export IEntryNestModule type
  • 7493b94 fix(core): dependency injection edge case with moduleref.create
  • Additional commits viewable in compare view

Updates @remix-run/react from 2.10.3 to 2.17.3

Release notes

Sourced from @​remix-run/react's releases.

remix v2.17.3

See the changelog for the release notes: https://github.com/remix-run/remix/blob/v2/CHANGELOG.md#v2173

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​remix-run/react since your current version.


Updates aws-cdk-lib from 2.148.0 to 2.189.1

Release notes

Sourced from aws-cdk-lib's releases.

v2.189.1

Bug Fixes

  • core: implicit Aspect applications do not override custom Aspect applications (#34132) (b7f4bc7)

Alpha modules (2.189.1-alpha.0)

v2.189.0

Features

Bug Fixes

  • codepipeline: replace account root principal with pipeline role in trust policy for cross-account actions (under feature flag) (#34074) (2d901f4)
  • custom-resources: AwsCustomResource assumed role session name may contain invalid characters (#34016) (32b6b4d), closes #23260 #34011

Alpha modules (2.189.0-alpha.0)

Features

Bug Fixes

  • amplify: unable to re-run integ test due to missing status field in customRule (#33973) (6638c08), closes #33962

v2.188.0

Features

  • update L1 CloudFormation resource definitions (#33980) (0923b5e)
  • update L1 CloudFormation resource definitions (#34029) (be6210f)
  • codepipeline: add usePipelineRoleForActions field support in L2 (#33961) (d8bbc1c)
  • codepipeline-actions: support ECRBuildAndPublish action (#33375) (c5cd679), closes #33376
  • codepipeline-actions: support InspectorEcrImageScanAction and InspectorSourceCodeScanAction actions (#33378) (2dc8cc7), closes #33377
  • cognito: v3.0 pre token generation trigger event (#33778) (ea1436f), closes #33733
  • events-targets: support ApiGatewayV2 HttpApi (#33864) (91a3076), closes #26649
  • kinesisfirehose: support S3 file extension format (#33776) (e314a9a), closes #32154
  • logs-destinations: support Amazon Data Firehose logs destination (#33683) (a8edf69), closes #32038 #24766
  • pipelines: actions can default to the pipeline service role instead of a newly created role (#33991) (2ebc51e)
  • rds: engine lifecycle support (#33902) (c0f8d29), closes #33859

Bug Fixes

... (truncated)

Changelog

Sourced from aws-cdk-lib's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

2.248.0-alpha.0 (2026年04月02日)

2.247.0-alpha.0 (2026年04月02日)

Features

2.246.0-alpha.0 (2026年03月31日)

2.245.0-alpha.0 (2026年03月27日)

Features

  • s3tables-alpha: add support for partition spec, sort order, and table properties (#36811) (2696cd1)
  • s3tables-alpha: add metrics configuration support for TableBucket (#37275) (e8786f5)
  • s3tables-alpha: implement ITaggableV2 on TableBucket and Table L2 constructs (#37277) (69c8944), closes #33054

2.244.0-alpha.0 (2026年03月19日)

Bug Fixes

  • kinesisanalytics-flink-alpha: mark deprecated flink runtimes as deprecated (#37155) (0a89447)

2.243.0-alpha.0 (2026年03月11日)

2.242.0-alpha.0 (2026年03月10日)

Features

  • mixins-preview: allow passing resource objects into properties in CFN Property mixins (#37148) (f238629)
  • mixins-preview: generate EventBridge pattern for all events (#37081) (f30e836)
  • mixins-preview: support custom merge strategies via IMergeStrategy (#37170) (0dec011)

2.241.0-alpha.0 (2026年03月02日)

Features

  • mixins-preview: add recordFields and outputFormat to Vended Logs Mixin (#37042) (dd94c31)
  • mixins-preview: cross account delivery destinations (#36827) (a759eb6)

... (truncated)

Commits
  • e7432ee chore(release): 2.189.1
  • b7f4bc7 fix(core): implicit Aspect applications do not override custom Aspect applica...
  • dcd077f chore: update analytics metadata blueprints
  • b997bf1 chore(release): 2.189.0
  • eec900e feat(apigatewayv2): dualstack HTTP and WebSocket API (#34054)
  • 9cb2602 feat: update L1 CloudFormation resource definitions (#34064)
  • 2d901f4 fix(codepipeline): replace account root principal with pipeline role in trust...
  • 3da0c4d feat(bedrock): support Amazon Nova Reel 1.1 (#34070)
  • b1e8879 docs(pipelines): add link to developer guide on how to use docker drop-in rep...
  • 1b98a41 docs(batch): add note on update fatgate compute environment (#34022)
  • Additional commits viewable in compare view

Updates axios from 1.6.8 to 1.15.0

Release notes

Sourced from axios's releases.

v1.15.0

This release delivers two critical security patches, adds runtime support for Deno and Bun, and includes significant CI hardening, documentation improvements, and routine dependency updates.

⚠️ Important Changes

  • Deprecation: url.parse() usage has been replaced to address Node.js deprecation warnings. If you are on a recent version of Node.js, this resolves console warnings you may have been seeing. (#10625 )

🔒 Security Fixes

  • Proxy Handling: Fixed a no_proxy hostname normalisation bypass that could lead to Server-Side Request Forgery (SSRF). (#10661 )
  • Header Injection: Fixed an unrestricted cloud metadata exfiltration vulnerability via a header injection chain. (#10660 )

🚀 New Features

  • Runtime Support: Added compatibility checks and documentation for Deno and Bun environments. (#10652 , #10653 )

🔧 Maintenance & Chores

  • CI Security: Hardened workflow permissions to least privilege, added the zizmor security scanner, pinned action versions, and gated npm publishing with OIDC and environment protection. (#10618 , #10619 , #10627 , #10637 , #10666 )
  • Dependencies: Bumped serialize-javascript, handlebars, picomatch, vite, and denoland/setup-deno to latest versions. Added a 7-day Dependabot cooldown period. (#10574 , #10572 , #10568 , #10663 , #10664 , #10665 , #10669 , #10670 , #10616 )
  • Documentation: Unified docs, improved beforeRedirect credential leakage example, clarified withCredentials/withXSRFToken behaviour, HTTP/2 support notes, async/await timeout error handling, header case preservation, and various typo fixes. (#10649 , #10624 , #7452 , #7471 , #10654 , #10644 , #10589 )
  • Housekeeping: Removed stale files, regenerated lockfile, and updated sponsor scripts and blocks. (#10584 , #10650 , #10582 , #10640 , #10659 , #10668 )
  • Tests: Added regression coverage for urlencoded Content-Type casing. (#10573 )

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve Axios:

v1.14.0

This release focuses on compatibility fixes, adapter stability improvements, and test/tooling modernisation.

⚠️ Important Changes

  • Breaking Changes: None identified in this release.
  • Action Required: If you rely on env-based proxy behaviour or CJS resolution edge-cases, validate your integration after upgrade (notably proxy-from-env v2 alignment and main entry compatibility fix).

🚀 New Features

  • Runtime Features: No new end-user features were introduced in this release.
  • Test Coverage Expansion: Added broader smoke/module test coverage for CJS and ESM package usage. (#7510)

🐛 Bug Fixes

  • Headers: Trim trailing CRLF in normalised header values. (#7456)
  • HTTP/2: Close detached HTTP/2 sessions on timeout to avoid lingering sessions. (#7457)
  • Fetch Adapter: Cancel ReadableStream created during request-stream capability probing to prevent async resource leaks. (#7515)
  • Proxy Handling: Fixed env proxy behavior with proxy-from-env v2 usage. (#7499)

... (truncated)

Changelog

Sourced from axios's changelog.

Changelog

1.13.3 (2026年01月20日)

Bug Fixes

  • http2: Use port 443 for HTTPS connections by default. (#7256) (d7e6065)
  • interceptor: handle the error in the same interceptor (#6269) (5945e40)
  • main field in package.json should correspond to cjs artifacts (#5756) (7373fbf)
  • package.json: add 'bun' package.json 'exports' condition. Load the Node.js build in Bun instead of the browser build (#5754) (b89217e)
  • silentJSONParsing=false should throw on invalid JSON (#7253) (#7257) (7d19335)
  • turn AxiosError into a native error (#5394) (#5558) (1c6a86d)
  • types: add handlers to AxiosInterceptorManager interface (#5551) (8d1271b)
  • types: restore AxiosError.cause type from unknown to Error (#7327) (d8233d9)
  • unclear error message is thrown when specifying an empty proxy authorization (#6314) (6ef867e)

Features

Reverts

  • Revert "fix: silentJSONParsing=false should throw on invalid JSON (#7253) (#7..." (#7298) (a4230f5), closes #7253 #7 #7298
  • deps: bump peter-evans/create-pull-request from 7 to 8 in the github-actions group (#7334) (2d6ad5e)

Contributors to this release

... (truncated)

Commits
  • 772a4e5 chore(release): prepare release 1.15.0 (#10671)
  • 4b07137 chore(deps-dev): bump vite from 8.0.0 to 8.0.5 in /tests/smoke/esm (#10663)
  • 51e57b3 chore(deps-dev): bump vite from 8.0.2 to 8.0.5 (#10664)
  • fba1a77 chore(deps-dev): bump vite from 8.0.2 to 8.0.5 in /tests/module/esm (#10665)
  • 0bf6e28 chore(deps): bump denoland/setup-deno in the github-actions group (#10669)
  • 8107157 chore(deps-dev): bump the development_dependencies group with 4 updates (#10670)
  • e66530e ci: require npm-publish environment for releases (#10666)
  • 49f23cb chore(sponsor): update sponsor block (#10668)
  • 3631854 fix: unrestricted cloud metadata exfiltration via header injection chain (#10...
  • fb3befb fix: no_proxy hostname normalization bypass leads to ssrf (#10661)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for axios since your current version.

Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


Updates devalue from 5.1.1 to 5.6.4

Release notes

Sourced from devalue's releases.

v5.6.4

Patch Changes

  • 87c1f3c: fix: reject __proto__ keys in malformed Object wrapper payloads

    This validates the "Object" parse path and throws when the wrapped value has an own __proto__ key.

  • 40f1db1: fix: ensure sparse array indices are integers

  • 87c1f3c: fix: disallow __proto__ keys in null-prototype object parsing

    This disallows __proto__ keys in the "null" parse path so null-prototype object hydration cannot carry that key through parse/unflatten.

v5.6.3

Patch Changes

  • 0f04d4d: fix: Properly handle __proto__
  • 819f1ac: fix: better encoding for sparse arrays

v5.6.2

Patch Changes

  • 1175584: fix: validate input for ArrayBuffer parsing
  • e46afa6: fix: validate input for typed arrays
  • 1175584: fix: more helpful errors for inputs causing stack overflows

v5.6.1

Patch Changes

  • 2161d44: fix: add hasOwn check before calling reviver

v5.6.0

Minor Changes

  • a3d09d4: feat: expose DevalueError for instanceof checks in catch clauses
  • a3d09d4: feat: add value and root properties in DevalueError instances

v5.5.0

Minor Changes

  • 828fa1c: Enable support for custom reducer/reviver for "function" values

v5.4.2

Patch Changes

  • 5c26c0d: fix: allow custom revivers to revive things serialized by builtin reducers

v5.4.1

Patch Changes

... (truncated)

Changelog

Sourced from devalue's changelog.

5.6.4

Patch Changes

  • 87c1f3c: fix: reject __proto__ keys in malformed Object wrapper payloads

    This validates the "Object" parse path and throws when the wrapped value has an own __proto__ key.

  • 40f1db1: fix: ensure sparse array indices are integers

  • 87c1f3c: fix: disallow __proto__ keys in null-prototype object parsing

    This disallows __proto__ keys in the "null" parse path so null-prototype object hydration cannot carry that key through parse/unflatten.

5.6.3

Patch Changes

  • 0f04d4d: fix: Properly handle __proto__
  • 819f1ac: fix: better encoding for sparse arrays

5.6.2

Patch Changes

  • 1175584: fix: validate input for ArrayBuffer parsing
  • e46afa6: fix: validate input for typed arrays
  • 1175584: fix: more helpful errors for inputs causing stack overflows

5.6.1

Patch Changes

  • 2161d44: fix: add hasOwn check before calling reviver

5.6.0

Minor Changes

  • a3d09d4: feat: expose DevalueError for instanceof checks in catch clauses
  • a3d09d4: feat: add value and root properties in DevalueError instances

5.5.0

Minor Changes

  • 828fa1c: Enable support for custom reducer/reviver for "function" values

5.4.2

Patch Changes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for devalue since your current version.


Updates esbuild from 0.18.6 to 0.25.0

Release notes

Sourced from esbuild's releases.

v0.25.0

This release deliberately contains backwards-incompatible changes. To avoid automatically picking up releases like this, you should either be pinning the exact version of esbuild in your package.json file (recommended) or be using a version range syntax that only accepts patch upgrades such as ^0.24.0 or ~0.24.0. See npm's documentation about semver for more information.

  • Restrict access to esbuild's development server (GHSA-67mh-4wv8-2f99)

    This change addresses esbuild's first security vulnerability report. Previously esbuild set the Access-Control-Allow-Origin header to * to allow esbuild's development server to be flexible in how it's used for development. However, this allows the websites you visit to make HTTP requests to esbuild's local development server, which gives read-only access to your source code if the website were to fetch your source code's specific URL. You can read more information in the report.

    Starting with this release, CORS will now be disabled, and requests will now be denied if the host does not match the one provided to --serve=. The default host is 0.0.0.0, which refers to all of the IP addresses that represent the local machine (e.g. both 127.0.0.1 and 192.168.0.1). If you want to customize anything about esbuild's development server, you can put a proxy in front of esbuild and modify the incoming and/or outgoing requests.

    In addition, the serve() API call has been changed to return an array of hosts instead of a single host string. This makes it possible to determine all of the hosts that esbuild's development server will accept.

    Thanks to @​sapphi-red for reporting this issue.

  • Delete output files when a build fails in watch mode (#3643)

    It has been requested for esbuild to delete files when a build fails in watch mode. Previously esbuild left the old files in place, which could cause people to not immediately realize that the most recent build failed. With this release, esbuild will now delete all output files if a rebuild fails. Fixing the build error and triggering another rebuild will restore all output files again.

  • Fix correctness issues with the CSS nesting transform (#3620, #3877, #3933, #3997, #4005, #4037, #4038)

    This release fixes the following problems:

    • Naive expansion of CSS nesting can result in an exponential blow-up of generated CSS if each nesting level has multiple selectors. Previously esbuild sometimes collapsed individual nesting levels using :is() to limit expansion. However, this collapsing wasn't correct in some cases, so it has been removed to fix correctness issues.

      /* Original code */
      .parent {
       > .a,
       > .b1 > .b2 {
       color: red;
       }
      }
      /* Old output (with --supported:nesting=false) */
      .parent > :is(.a, .b1 > .b2) {
      color: red;
      }
      /* New output (with --supported:nesting=false) */
      .parent > .a,
      .parent > .b1 > .b2 {
      color: red;
      }

      Thanks to @​tim-we for working on a fix.

    • The & CSS nesting selector can be repeated multiple times to increase CSS specificity. Previously esbuild ignored this possibility and incorrectly considered && to have the same specificity as &. With this release, this should now work correctly:

      /* Original code (color should be red) */

... (truncated)

Changelog

Sourced from esbuild's changelog.

Changelog: 2023

This changelog documents all esbuild versions published in the year 2023 (versions 0.16.13 through 0.19.11).

0.19.11

  • Fix TypeScript-specific class transform edge case (#3559)

    The previous release introduced an optimization that avoided transforming super() in the class constructor for TypeScript code compiled with useDefineForClassFields set to false if all class instance fields have no initializers. The rationale was that in this case, all class instance fields are omitted in the output so no changes to the constructor are needed. However, if all of this is the case and there are #private instance fields with initializers, those private instance field initializers were still being moved into the constructor. This was problematic because they were being inserted before the call to super() (since super() is now no longer transformed in that case). This release introduces an additional optimization that avoids moving the private instance field initializers into the constructor in this edge case, which generates smaller code, matches the TypeScript compiler's output more closely, and avoids this bug:

    // Original code
    class Foo extends Bar {
     #private = 1;
     public: any;
     constructor() {
     super();
     }
    }
    // Old output (with esbuild v0.19.9)
    class Foo extends Bar {
    constructor() {
    super();
    this.#private = 1;
    }
    #private;
    }
    // Old output (with esbuild v0.19.10)
    class Foo extends Bar {
    constructor() {
    this.#private = 1;
    super();
    }
    #private;
    }
    // New output
    class Foo extends Bar {
    #private = 1;
    constructor() {
    super();
    }
    }
  • Minifier: allow reording a primitive past a side-effect (#3568)

    The minifier previously allowed reordering a side-effect past a primitive, but didn't handle the case of reordering a primitive past a side-effect. This additional case is now handled:

... (truncated)

Commits

... updates
Bumps the npm_and_yarn group with 17 updates in the /test directory:
| Package | From | To |
| --- | --- | --- |
| [@nestjs/common](https://github.com/nestjs/nest/tree/HEAD/packages/common) | `11.0.3` | `11.0.16` |
| [@nestjs/core](https://github.com/nestjs/nest/tree/HEAD/packages/core) | `11.0.3` | `11.1.18` |
| [@remix-run/react](https://github.com/remix-run/remix/tree/HEAD/packages/remix-react) | `2.10.3` | `2.17.3` |
| [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) | `2.148.0` | `2.189.1` |
| [axios](https://github.com/axios/axios) | `1.6.8` | `1.15.0` |
| [devalue](https://github.com/sveltejs/devalue) | `5.1.1` | `5.6.4` |
| [esbuild](https://github.com/evanw/esbuild) | `0.18.6` | `0.25.0` |
| [express](https://github.com/expressjs/express) | `4.18.2` | `4.22.0` |
| [happy-dom](https://github.com/capricorn86/happy-dom) | `17.0.3` | `20.8.9` |
| [hono](https://github.com/honojs/hono) | `4.7.2` | `4.12.12` |
| [jws](https://github.com/brianloveswords/node-jws) | `4.0.0` | `4.0.1` |
| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `6.9.3` | `8.0.5` |
| [rollup](https://github.com/rollup/rollup) | `4.4.1` | `4.59.0` |
| [typeorm](https://github.com/typeorm/typeorm) | `0.3.20` | `0.3.26` |
| [undici](https://github.com/nodejs/undici) | `5.20.0` | `6.24.0` |
| [webpack](https://github.com/webpack/webpack) | `5.88.0` | `5.104.1` |
Bumps the npm_and_yarn group with 3 updates in the /test/js/third_party/pnpm/install_fixture directory: [rollup](https://github.com/rollup/rollup), [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) and [seroval](https://github.com/lxsmnsyc/seroval).
Bumps the npm_and_yarn group with 1 update in the /test/js/third_party/webpack directory: [webpack](https://github.com/webpack/webpack).
Updates `@nestjs/common` from 11.0.3 to 11.0.16
- [Release notes](https://github.com/nestjs/nest/releases)
- [Commits](https://github.com/nestjs/nest/commits/v11.0.16/packages/common)
Updates `@nestjs/core` from 11.0.3 to 11.1.18
- [Release notes](https://github.com/nestjs/nest/releases)
- [Commits](https://github.com/nestjs/nest/commits/v11.1.18/packages/core)
Updates `@remix-run/react` from 2.10.3 to 2.17.3
- [Release notes](https://github.com/remix-run/remix/releases)
- [Commits](https://github.com/remix-run/remix/commits/remix@2.17.3/packages/remix-react)
Updates `aws-cdk-lib` from 2.148.0 to 2.189.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.189.1/packages/aws-cdk-lib)
Updates `axios` from 1.6.8 to 1.15.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.6.8...v1.15.0)
Updates `devalue` from 5.1.1 to 5.6.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.1.1...v5.6.4)
Updates `esbuild` from 0.18.6 to 0.25.0
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2023.md)
- [Commits](evanw/esbuild@v0.18.6...v0.25.0)
Updates `express` from 4.18.2 to 4.22.0
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md)
- [Commits](expressjs/express@4.18.2...4.22.0)
Updates `happy-dom` from 17.0.3 to 20.8.9
- [Release notes](https://github.com/capricorn86/happy-dom/releases)
- [Commits](capricorn86/happy-dom@v17.0.3...v20.8.9)
Updates `hono` from 4.7.2 to 4.12.12
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.7.2...v4.12.12)
Updates `jws` from 4.0.0 to 4.0.1
- [Release notes](https://github.com/brianloveswords/node-jws/releases)
- [Changelog](https://github.com/auth0/node-jws/blob/master/CHANGELOG.md)
- [Commits](auth0/node-jws@v4.0.0...v4.0.1)
Updates `lodash` from 4.17.21 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.18.1)
Updates `nodemailer` from 6.9.3 to 8.0.5
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v6.9.3...v8.0.5)
Updates `rollup` from 4.4.1 to 4.59.0
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.4.1...v4.59.0)
Updates `typeorm` from 0.3.20 to 0.3.26
- [Release notes](https://github.com/typeorm/typeorm/releases)
- [Changelog](https://github.com/typeorm/typeorm/blob/master/CHANGELOG.md)
- [Commits](typeorm/typeorm@0.3.20...0.3.26)
Updates `undici` from 5.20.0 to 6.24.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v5.20.0...v6.24.0)
Updates `webpack` from 5.88.0 to 5.104.1
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.88.0...v5.104.1)
Updates `rollup` from 4.34.8 to 4.60.1
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.4.1...v4.59.0)
Updates `vite` from 5.4.14 to 6.4.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v6.4.2/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v6.4.2/packages/vite)
Updates `seroval` from 1.2.1 to 1.5.2
- [Release notes](https://github.com/lxsmnsyc/seroval/releases)
- [Commits](https://github.com/lxsmnsyc/seroval/commits)
Updates `webpack` from 5.88.0 to 5.104.1
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.88.0...v5.104.1)
---
updated-dependencies:
- dependency-name: "@nestjs/common"
 dependency-version: 11.0.16
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: "@nestjs/core"
 dependency-version: 11.1.18
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: "@remix-run/react"
 dependency-version: 2.17.3
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: aws-cdk-lib
 dependency-version: 2.189.1
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: axios
 dependency-version: 1.15.0
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: devalue
 dependency-version: 5.6.4
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: esbuild
 dependency-version: 0.25.0
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: express
 dependency-version: 4.22.0
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: happy-dom
 dependency-version: 20.8.9
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: hono
 dependency-version: 4.12.12
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: jws
 dependency-version: 4.0.1
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: lodash
 dependency-version: 4.18.1
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: nodemailer
 dependency-version: 8.0.5
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: rollup
 dependency-version: 4.59.0
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: typeorm
 dependency-version: 0.3.26
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: undici
 dependency-version: 6.24.0
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: webpack
 dependency-version: 5.104.1
 dependency-type: direct:production
 dependency-group: npm_and_yarn
- dependency-name: rollup
 dependency-version: 4.60.1
 dependency-type: indirect
 dependency-group: npm_and_yarn
- dependency-name: vite
 dependency-version: 6.4.2
 dependency-type: direct:development
 dependency-group: npm_and_yarn
- dependency-name: seroval
 dependency-version: 1.5.2
 dependency-type: indirect
 dependency-group: npm_and_yarn
- dependency-name: webpack
 dependency-version: 5.104.1
 dependency-type: direct:production
 dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

0 participants

AltStyle によって変換されたページ (->オリジナル) /