Skip to content

deps: bump the npm group across 1 directory with 8 updates - #130

Merged
github-actions[bot] merged 1 commit into
devfrom
dependabot/npm_and_yarn/dev/npm-e61cee1498
Oct 6, 2026
Merged

github-actions[bot] merged 1 commit into
devfrom
dependabot/npm_and_yarn/dev/npm-e61cee1498

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm group with 8 updates in the / directory:

Package From To
@aws-sdk/client-s3 3.1140.0 3.1146.0
@aws-sdk/s3-request-presigner 3.1140.0 3.1146.0
lucide-react 1.48.0 1.51.0
next 16.3.6 16.3.8
next-intl 4.14.7 4.14.9
sharp 0.35.4 0.35.5
@types/node 24.13.6 24.19.1
eslint-config-next 16.3.6 16.3.8

Updates @aws-sdk/client-s3 from 3.1140.0 to 3.1146.0

Release notes

Sourced from @​aws-sdk/client-s3's releases.

v3.1146.0

3.1146.0(2026-10-02)

Documentation Changes
  • client-lambda-web: Documentation update for AWS Lambda Web Functions, clarifies that the LambdaWeb APIs are experimental and not yet available to external customers. (de11d1e1)
New Features
  • client-mediapackagev2: Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Static filter configuration allows users to configure endpoints with layouts and sources without using query parameters. The number of sources per multiview channel has been increased to 50. (8a1ac09c)
  • client-invoicing: API and doc updates related to adding MarketplacePunchOutEnabled and MarketplacePunchOutPreference fields to ProcurementPortalPreferences related APIs (948be4b5)
  • client-glue: Added refresh token grant type to Glue Connection supported OAuth 2.0 grant types (6101fef0)
  • client-cognito-identity-provider: Amazon Cognito User Pools now supports the OIDC-standard authentication context class reference (ACR) and authentication methods reference (AMR) claims on issued access and Id tokens. Amazon Cognito User Pools also now supports step-up authentication via our existing authentication APIs. (196e191f)
  • client-pinpoint-sms-voice-v2: AWS End User Messaging SMS CarrierLookup API now supports phone number cleansing on customer opt-in. when selected, the response includes the additional field "OriginalPhoneNumber". It can also return additional PhoneNumberType enums, VOIP and PREPAID. (42d43613)
  • client-securityagent: Adds trigger filters that control which pull request events, target branches, and labels start an automatic code review. (3d73df94)

For list of updated packages, view updated-packages.md in assets-3.1146.0.zip

v3.1145.0

3.1145.0(2026-10-01)

Chores
Documentation Changes
  • client-ec2: This release launches the AMI tag sharing feature, which lets AMI owners share tags alongside their AMIs, eliminating the need to build and maintain custom tag replication workflows. (82608f8c)
New Features
  • clients: update client endpoints as of 2026-10-01 (5244c2a9)
  • client-bedrock-agent: Adds an optional textReadyAt field to ListIngestionJobs and GetIngestionJob for Managed Knowledge Bases data source sync jobs. The field denotes the timestamp at which all the documents in the scope of a sync job had their text content indexed and are available for retrieval. (a810c753)
  • client-lambda-web: Lambda Web Functions GA launch. Lambda Web Functions enable customers to run web applications and API backends (ed0d0540)
  • client-quicksight: This release adds HierarchyFilter support for Amazon QuickSight analysis and dashboard and 2 legged OAuth for databricks datasources. (a1730e33)
  • client-endusermessaging: AWS End User Messaging now supports Brand profiles and Notify code configurations. Brand profiles capture your sender details once to reuse across phone number registrations. Notify code configurations let you define your OTP policy and delivery settings to send passcodes in minutes. (3e5402c6)
  • client-transfer: AWS Transfer Family Workflows adds support for the structuredLogDestinations option, enabling customers to specify a custom Amazon CloudWatch Logs log group for managed workflow execution logs. (db1f8330)
  • client-health: Adds DescribeServiceLifecycle operation returning lifecycle information for AWS services, including end-of-support dates, version recommendations, and lifecycle events. (db93c016)
  • client-cloudfront: Added always-amz-auth as a supported signing behavior for Origin Access Control (OAC), enabling CloudFront to authenticate requests to Lambda-Web origins. (e24eb7cf)
  • client-sagemaker: Release support for c8a.16xlarge and m8a.16xlarge instance types for SageMaker HyperPod (cfa700a6)
  • client-securityhub: Adds GetRemediationsV2 and ListExposuresByRemediationV2 APIs. This feature allows customers to see their highest priority remediations for their Exposure findings. Remediations target key changes customers can make to resources to drive finding resolution. (fe355577)
Bug Fixes
  • lib-transfer-manager: respect file read stream's byte range on upload (#8324) (449c2814)
  • ci: run format-check when a draft PR is marked ready for review (#8326) (d99dd58e)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-s3's changelog.

3.1146.0 (2026-10-02)

Note: Version bump only for package @​aws-sdk/client-s3

3.1145.0 (2026-10-01)

Note: Version bump only for package @​aws-sdk/client-s3

3.1144.0 (2026-09-30)

Features

  • client-s3: Amazon S3 adds a new optional S3 Inventory field, IntelligentTieringReferenceDate, reporting the reference date S3 Intelligent-Tiering uses to evaluate an object's tier-transition eligibility. The value is populated for objects in the Intelligent-Tiering storage class and left blank for others. (82bbbdc)

3.1143.0 (2026-09-29)

Note: Version bump only for package @​aws-sdk/client-s3

3.1142.0 (2026-09-28)

Note: Version bump only for package @​aws-sdk/client-s3

3.1141.0 (2026-09-25)

Note: Version bump only for package @​aws-sdk/client-s3

Commits

Updates @aws-sdk/s3-request-presigner from 3.1140.0 to 3.1146.0

Release notes

Sourced from @​aws-sdk/s3-request-presigner's releases.

v3.1146.0

3.1146.0(2026-10-02)

Documentation Changes
  • client-lambda-web: Documentation update for AWS Lambda Web Functions, clarifies that the LambdaWeb APIs are experimental and not yet available to external customers. (de11d1e1)
New Features
  • client-mediapackagev2: Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Static filter configuration allows users to configure endpoints with layouts and sources without using query parameters. The number of sources per multiview channel has been increased to 50. (8a1ac09c)
  • client-invoicing: API and doc updates related to adding MarketplacePunchOutEnabled and MarketplacePunchOutPreference fields to ProcurementPortalPreferences related APIs (948be4b5)
  • client-glue: Added refresh token grant type to Glue Connection supported OAuth 2.0 grant types (6101fef0)
  • client-cognito-identity-provider: Amazon Cognito User Pools now supports the OIDC-standard authentication context class reference (ACR) and authentication methods reference (AMR) claims on issued access and Id tokens. Amazon Cognito User Pools also now supports step-up authentication via our existing authentication APIs. (196e191f)
  • client-pinpoint-sms-voice-v2: AWS End User Messaging SMS CarrierLookup API now supports phone number cleansing on customer opt-in. when selected, the response includes the additional field "OriginalPhoneNumber". It can also return additional PhoneNumberType enums, VOIP and PREPAID. (42d43613)
  • client-securityagent: Adds trigger filters that control which pull request events, target branches, and labels start an automatic code review. (3d73df94)

For list of updated packages, view updated-packages.md in assets-3.1146.0.zip

v3.1145.0

3.1145.0(2026-10-01)

Chores
Documentation Changes
  • client-ec2: This release launches the AMI tag sharing feature, which lets AMI owners share tags alongside their AMIs, eliminating the need to build and maintain custom tag replication workflows. (82608f8c)
New Features
  • clients: update client endpoints as of 2026-10-01 (5244c2a9)
  • client-bedrock-agent: Adds an optional textReadyAt field to ListIngestionJobs and GetIngestionJob for Managed Knowledge Bases data source sync jobs. The field denotes the timestamp at which all the documents in the scope of a sync job had their text content indexed and are available for retrieval. (a810c753)
  • client-lambda-web: Lambda Web Functions GA launch. Lambda Web Functions enable customers to run web applications and API backends (ed0d0540)
  • client-quicksight: This release adds HierarchyFilter support for Amazon QuickSight analysis and dashboard and 2 legged OAuth for databricks datasources. (a1730e33)
  • client-endusermessaging: AWS End User Messaging now supports Brand profiles and Notify code configurations. Brand profiles capture your sender details once to reuse across phone number registrations. Notify code configurations let you define your OTP policy and delivery settings to send passcodes in minutes. (3e5402c6)
  • client-transfer: AWS Transfer Family Workflows adds support for the structuredLogDestinations option, enabling customers to specify a custom Amazon CloudWatch Logs log group for managed workflow execution logs. (db1f8330)
  • client-health: Adds DescribeServiceLifecycle operation returning lifecycle information for AWS services, including end-of-support dates, version recommendations, and lifecycle events. (db93c016)
  • client-cloudfront: Added always-amz-auth as a supported signing behavior for Origin Access Control (OAC), enabling CloudFront to authenticate requests to Lambda-Web origins. (e24eb7cf)
  • client-sagemaker: Release support for c8a.16xlarge and m8a.16xlarge instance types for SageMaker HyperPod (cfa700a6)
  • client-securityhub: Adds GetRemediationsV2 and ListExposuresByRemediationV2 APIs. This feature allows customers to see their highest priority remediations for their Exposure findings. Remediations target key changes customers can make to resources to drive finding resolution. (fe355577)
Bug Fixes
  • lib-transfer-manager: respect file read stream's byte range on upload (#8324) (449c2814)
  • ci: run format-check when a draft PR is marked ready for review (#8326) (d99dd58e)

... (truncated)

Changelog

Sourced from @​aws-sdk/s3-request-presigner's changelog.

3.1146.0 (2026-10-02)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.1145.0 (2026-10-01)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.1144.0 (2026-09-30)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.1143.0 (2026-09-29)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.1142.0 (2026-09-28)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.1141.0 (2026-09-25)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

Commits

Updates lucide-react from 1.48.0 to 1.51.0

Release notes

Sourced from lucide-react's releases.

Version 1.51.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.50.0...1.51.0

Version 1.50.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.49.0...1.50.0

... (truncated)

Commits
  • 98331e2 chore(deps): bump the react-deps group across 1 directory with 3 updates (#4951)
  • 09aa9c5 chore(deps): Upgrade to vite 8 (#4950)
  • e042fec fix(packages): declare @types/react as an optional peer dependency (#4892)
  • See full diff in compare view

Updates next from 16.3.6 to 16.3.8

Release notes

Sourced from next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

Commits
  • b0fad0d v16.3.8
  • 719e4c6 [lts-active] Scope response cache keys to their source route (#218)
  • e92db45 [lts-active] Fix metadata propagation for deduplicated nested caches (#223)
  • 40c2ba9 [lts-active] Match Next data paths case-sensitively (#196)
  • 2d9f50a [lts-active] Fix MCP middleware DNS rebinding (#213)
  • bd9214f [lts-active] Fix draft mode leaks through cross-request 'use cache' dedupli...
  • 8db4a62 [lts-active][webpack] Ensure dynamicParams is respected in `opengraph-image...
  • e002ad6 [lts-active] fix(next/image): Pin DNS resolution when fetching external image...
  • 4c20699 v16.3.7
  • 2521aec [backport] turbo-tasks-backend: fix strongly consistent read hanging on a can...
  • See full diff in compare view

Updates next-intl from 4.14.7 to 4.14.9

Release notes

Sourced from next-intl's releases.

v4.14.9

4.14.9 (2026-10-02)

Bug Fixes

v4.14.8

4.14.8 (2026-09-29)

Bug Fixes

Changelog

Sourced from next-intl's changelog.

4.14.9 (2026-10-02)

Bug Fixes

4.14.8 (2026-09-29)

Bug Fixes

Commits
  • b9fc98a v4.14.9
  • 0454168 fix: Improvements for useExtracted (#2431)
  • 1244f54 fix: Correct source paths in useExtracted source maps with Turbopack (#2432)
  • 4932295 fix: Support webpack builds with source maps when using useExtracted (#2430)
  • fac95ab docs: Clarify cookie writing with localeDetection: false and add a third `a...
  • 274867f v4.14.8
  • 3ef2e6a fix: Keep source order for useExtracted messages on the same line (#2426)
  • edcfaf3 docs: Upgrade Next.js to 16.3.6 in examples and dev deps (GHSA-vcvr-r3jv-pc5j...
  • See full diff in compare view

Updates sharp from 0.35.4 to 0.35.5

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

Updates @types/node from 24.13.6 to 24.19.1

Commits

Updates eslint-config-next from 16.3.6 to 16.3.8

Release notes

Sourced from eslint-config-next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

Commits

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
@types/node [>= 26.a, < 27]

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 5, 2026 05:17
@dependabot dependabot Bot changed the title deps: bump the npm group with 8 updates deps: bump the npm group across 1 directory with 8 updates Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev/npm-e61cee1498 branch 2 times, most recently from 19a722d to d68e448 Compare October 6, 2026 08:15
MansiVisuals added a commit that referenced this pull request Oct 6, 2026
It is a Tailwind plugin loaded by tailwind.config.ts and imported by nothing
at runtime, but sitting in dependencies made its peer on tailwindcss
production-reachable. npm then drops the `dev` marker from tailwindcss,
braces and micromatch whenever it resolves peers, which is how Dependabot
regenerates the lockfile — so `npm audit --omit=dev` reported build tooling
as shipped and failed the gate on #130.

The production install is unaffected either way; only the audit's view was
wrong. Verified the gate now passes with the lockfile regenerated both with
and without --legacy-peer-deps.
Bumps the npm group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1140.0` | `3.1146.0` |
| [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1140.0` | `3.1146.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.48.0` | `1.51.0` |
| [next](https://github.com/vercel/next.js) | `16.3.6` | `16.3.8` |
| [next-intl](https://github.com/amannn/next-intl) | `4.14.7` | `4.14.9` |
| [sharp](https://github.com/lovell/sharp) | `0.35.4` | `0.35.5` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.6` | `24.19.1` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.6` | `16.3.8` |



Updates `@aws-sdk/client-s3` from 3.1140.0 to 3.1146.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1146.0/clients/client-s3)

Updates `@aws-sdk/s3-request-presigner` from 3.1140.0 to 3.1146.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1146.0/packages/s3-request-presigner)

Updates `lucide-react` from 1.48.0 to 1.51.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.51.0/packages/lucide-react)

Updates `next` from 16.3.6 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.6...v16.3.8)

Updates `next-intl` from 4.14.7 to 4.14.9
- [Release notes](https://github.com/amannn/next-intl/releases)
- [Changelog](https://github.com/amannn/next-intl/blob/main/CHANGELOG.md)
- [Commits](amannn/next-intl@v4.14.7...v4.14.9)

Updates `sharp` from 0.35.4 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.4...v0.35.5)

Updates `@types/node` from 24.13.6 to 24.19.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint-config-next` from 16.3.6 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.8/packages/eslint-config-next)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1145.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1145.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/node"
  dependency-version: 24.19.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: eslint-config-next
  dependency-version: 16.3.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: lucide-react
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: next
  dependency-version: 16.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: next-intl
  dependency-version: 4.14.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev/npm-e61cee1498 branch from d68e448 to e355ea7 Compare October 6, 2026 08:21
@github-actions
github-actions Bot merged commit 37ad84a into dev Oct 6, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dev/npm-e61cee1498 branch October 6, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants