Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 7 updates - #413

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-74f45a2e25
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-74f45a2e25

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 7 updates in the / directory:

Package From To
@fastify/secure-session 8.3.0 8.4.0
@fastify/static 10.1.3 10.1.4
@fastify/swagger 9.8.1 9.9.0
fastify 5.12.3 5.12.5
kysely 0.29.5 0.29.6
stream-json 3.6.0 3.7.0
vuetify 4.2.1 4.2.2

Updates @fastify/secure-session from 8.3.0 to 8.4.0

Release notes

Sourced from @​fastify/secure-session's releases.

v8.4.0

What's Changed

New Contributors

Full Changelog: fastify/fastify-secure-session@v8.3.0...v8.4.0

Commits
  • 43b4c9f Bumped v8.4.0
  • 06f4afb docs: document secure, sameSite and __Host- cookie prefix usage
  • 96037bb chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#302)
  • 9d930c7 chore: bump fastify/workflows/.github/workflows/plugins-ci.yml
  • 0e9eb8f chore(.npmrc): add min-release-age
  • e45dd2a chore: bump c8 from 11.0.0 to 12.0.0 (#299)
  • f104372 ci: pin actions to commit-hash
  • 80b6af5 test: support cookie v2.x (#297)
  • cf9fcaa chore: bump @​types/node in the dev-dependencies-typescript group (#295)
  • dbb973c chore(package.json): fix delvedor's personal url (#294)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by tony133, a new releaser for @​fastify/secure-session since your current version.


Updates @fastify/static from 10.1.3 to 10.1.4

Release notes

Sourced from @​fastify/static's releases.

v10.1.4

This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).

It fixes a route guard and allowedPath bypass on case-insensitive filesystems. Users should upgrade to @fastify/static 10.1.4.

Full Changelog: fastify/fastify-static@v10.1.3...v10.1.4

Commits
  • a39a464 Bumped v10.1.4
  • ac46015 Ignore .pi
  • 6288466 test: consume compressed response bodies
  • 04134a4 test: cover rootless path validation on Windows
  • d9a8c0a test: make case-folding fallback portable
  • dbe65e8 Merge commit from fork
  • 48b821f chore: bump content-disposition in the dependencies group (#607)
  • ee3f89d chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#604)
  • See full diff in compare view

Updates @fastify/swagger from 9.8.1 to 9.9.0

Release notes

Sourced from @​fastify/swagger's releases.

v9.9.0

What's Changed

Full Changelog: fastify/fastify-swagger@v9.8.2...v9.9.0

v9.8.2

What's Changed

Full Changelog: fastify/fastify-swagger@v9.8.1...v9.8.2

Commits
  • d31c75e Bumped v9.9.0
  • 74d98db feat: OpenAPI 3.2.0 compatibility (#949)
  • 56b8971 Bumped v9.8.2
  • c1218bc fix(openapi): support null types and type arrays in OpenAPI 3.0 documents
  • 05ce298 docs: document OpenAPI specification extensions in TypeScript (#948)
  • d3206d1 docs: document static paths in dynamic mode
  • 49c7f6a chore: bump @​apidevtools/swagger-parser from 12.1.0 to 13.0.0 (#947)
  • 1561aef refactor(types): move index.d.ts and rename test-types (#946)
  • c422dc4 chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#937)
  • ee6e958 chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#938)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by tony133, a new releaser for @​fastify/swagger since your current version.


Updates fastify from 5.12.3 to 5.12.5

Release notes

Sourced from fastify's releases.

v5.12.5

⚠️ Security release

What's Changed

Full Changelog: fastify/fastify@v5.12.4...v5.12.5

v5.12.4

Fixed the fastify.js version mismatch.

Full Changelog: fastify/fastify@v5.12.2...v5.12.4

Commits

Updates kysely from 0.29.5 to 0.29.6

Release notes

Sourced from kysely's releases.

0.29.6

Hey 👋

A small batch of bug fixes. Please report any issues. 🤞😰🤞

🚀 Features

🐞 Bugfixes

PostgreSQL 🐘 / SQLite 📘

📖 Documentation

📦 CICD & Tooling

⚠️ Breaking Changes

🐤 New Contributors

What's Changed

Full Changelog: kysely-org/kysely@v0.29.5...v0.29.6

Commits
  • 2fefd4c 0.29.6
  • 2feb1f3 chore: bumps dependencies. (#2045)
  • b596221 fix: allow immutable columns in doUpdateSet's where. (#2043)
  • b9674df chore(CONTRIBUTING): llm contribution farming accounts.
  • 90fe25c chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...
  • 6582fb6 chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#1984)
  • b497657 chore(deps-dev): bump shiki from 4.4.2 to 4.4.3 (#1982)
  • 44c4782 chore(deps): bump step-security/harden-runner from 2.20.1 to 2.21.0 (#1987)
  • 20e5d15 chore(deps-dev): bump mysql2 from 3.23.2 to 3.23.3 (#1983)
  • 93cb9ad Update link to Migrator API docs (#1991)
  • Additional commits viewable in compare view

Updates stream-json from 3.6.0 to 3.7.0

Commits

Updates vuetify from 4.2.1 to 4.2.2

Release notes

Sourced from vuetify's releases.

v4.2.2

[!IMPORTANT] Vuetify Needs Your Support! The OpenCollective funds are running low. The team needed to scale down and is barely able to compensate the contributors for their work on the framework and the ecosystem tools.

If Vuetify is part of your stack, please consider sponsoring the project so we can continue delivering updates and fixes.

Sponsor via Open Collective

Every contribution helps us keep Vuetify alive and signals to maintainers that their effort is appreciated.

Thank you.


🔧 Bug Fixes

  • VAutocomplete/VCombobox: prevent menu icon from toggling twice (#23200) (c8b9d6a), closes #23197
  • VPullToRefresh: wrap styles in the components cascade layer (#23207) (9453f06), closes #23206
  • VSelect/VAutocomplete: match autofill against item values (#23063) (b6c9f5c), closes #20560
  • VSelect/VAutocomplete/VCombobox: apply menu-elevation to the content div (#23193) (8d1d985), closes #23192
  • VSwitch: rotate icon for vertical direction (6b090a0)
  • VTab: restore overflow for correct slider animation (1c5545c)
  • VTabs: apply inset-radius to tab for ripple and focus ring (bf6abfc)

🧪 Labs

  • VCommandPalette: render the list.prepend slot (#23204) (7cd8c57), closes #23202
  • VHighlight: correct foreground color in forced-colors mode (c00064f)
  • VMonthPicker: !important not needed in trumps layer (fdc76e5)
  • VVideo: !important for thumb label no longer needed (b3d8bb1)
Commits
  • 5b4625f chore(release): publish v4.2.2
  • c8b9d6a fix(VAutocomplete/VCombobox): prevent menu icon from toggling twice (#23200)
  • b6c9f5c fix(VSelect): match autofill against item values (#23063)
  • 6d6513e chore(VSelect/VAutocomplete/VCombobox): deprecate menu-elevation
  • 8d1d985 fix(VSelect/VAutocomplete/VCombobox): apply menu-elevation to the content d...
  • bf5805c chore(v-touch): fix flaky test
  • 9453f06 fix(VPullToRefresh): wrap styles in the components cascade layer (#23207)
  • 7cd8c57 fix(VCommandPalette): render the list.prepend slot (#23204)
  • 3469724 chore: use pnpm catalog to manage dependencies (#21259)
  • 3d3f418 chore: bump vitest to 4.1.11 (#23188)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…y with 7 updates

Bumps the production-dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@fastify/secure-session](https://github.com/fastify/fastify-secure-session) | `8.3.0` | `8.4.0` |
| [@fastify/static](https://github.com/fastify/fastify-static) | `10.1.3` | `10.1.4` |
| [@fastify/swagger](https://github.com/fastify/fastify-swagger) | `9.8.1` | `9.9.0` |
| [fastify](https://github.com/fastify/fastify) | `5.12.3` | `5.12.5` |
| [kysely](https://github.com/kysely-org/kysely) | `0.29.5` | `0.29.6` |
| [stream-json](https://github.com/uhop/stream-json) | `3.6.0` | `3.7.0` |
| [vuetify](https://github.com/vuetifyjs/vuetify/tree/HEAD/packages/vuetify) | `4.2.1` | `4.2.2` |



Updates `@fastify/secure-session` from 8.3.0 to 8.4.0
- [Release notes](https://github.com/fastify/fastify-secure-session/releases)
- [Commits](fastify/fastify-secure-session@v8.3.0...v8.4.0)

Updates `@fastify/static` from 10.1.3 to 10.1.4
- [Release notes](https://github.com/fastify/fastify-static/releases)
- [Commits](fastify/fastify-static@v10.1.3...v10.1.4)

Updates `@fastify/swagger` from 9.8.1 to 9.9.0
- [Release notes](https://github.com/fastify/fastify-swagger/releases)
- [Commits](fastify/fastify-swagger@v9.8.1...v9.9.0)

Updates `fastify` from 5.12.3 to 5.12.5
- [Release notes](https://github.com/fastify/fastify/releases)
- [Commits](https://github.com/fastify/fastify/commits/v5.12.5)

Updates `kysely` from 0.29.5 to 0.29.6
- [Release notes](https://github.com/kysely-org/kysely/releases)
- [Commits](kysely-org/kysely@v0.29.5...v0.29.6)

Updates `stream-json` from 3.6.0 to 3.7.0
- [Commits](uhop/stream-json@3.6.0...3.7.0)

Updates `vuetify` from 4.2.1 to 4.2.2
- [Release notes](https://github.com/vuetifyjs/vuetify/releases)
- [Commits](https://github.com/vuetifyjs/vuetify/commits/v4.2.2/packages/vuetify)

---
updated-dependencies:
- dependency-name: "@fastify/secure-session"
  dependency-version: 8.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@fastify/static"
  dependency-version: 10.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@fastify/swagger"
  dependency-version: 9.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: fastify
  dependency-version: 5.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: kysely
  dependency-version: 0.29.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: stream-json
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: vuetify
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-74f45a2e25 branch October 5, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant