Skip to content

chore(deps)(deps): bump the production-dependencies group across 1 directory with 22 updates - #287

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-01046370c3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-01046370c3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 22 updates in the / directory:

Package From To
@better-auth/passkey 1.7.5 1.7.7
@fastify/swagger 9.9.0 9.9.1
@fastify/websocket 11.3.1 11.3.3
better-auth 1.7.5 1.7.7
dotenv 18.0.3 18.0.5
mysql2 3.24.4 3.24.5
nanoid 6.0.1 6.0.2
nodemailer 10.0.10 10.0.15
pg 8.23.0 8.23.1
@radix-ui/react-alert-dialog 1.1.23 1.1.24
@radix-ui/react-avatar 1.2.6 1.2.7
@radix-ui/react-checkbox 1.3.11 1.3.12
@radix-ui/react-dropdown-menu 2.1.24 2.1.25
@radix-ui/react-label 2.1.15 2.1.16
@radix-ui/react-select 2.3.7 2.3.8
@radix-ui/react-separator 1.1.15 1.1.16
@radix-ui/react-switch 1.3.7 1.3.8
@radix-ui/react-tabs 1.1.21 1.1.22
@radix-ui/react-toast 1.2.23 1.2.24
@radix-ui/react-toggle 1.1.18 1.1.19
@radix-ui/react-toggle-group 1.1.19 1.1.20
js-yaml 5.4.2 5.4.3

Updates @better-auth/passkey from 1.7.5 to 1.7.7

Release notes

Sourced from @​better-auth/passkey's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

... (truncated)

Changelog

Sourced from @​better-auth/passkey's changelog.

1.7.7

1.7.6

Commits

Updates @fastify/swagger from 9.9.0 to 9.9.1

Release notes

Sourced from @​fastify/swagger's releases.

v9.9.1

What's Changed

New Contributors

Full Changelog: fastify/fastify-swagger@v9.9.0...v9.9.1

Commits

Updates @fastify/websocket from 11.3.1 to 11.3.3

Release notes

Sourced from @​fastify/websocket's releases.

v11.3.3

What's Changed

Full Changelog: fastify/fastify-websocket@v11.3.2...v11.3.3

v11.3.2

What's Changed

New Contributors

Full Changelog: fastify/fastify-websocket@v11.3.1...v11.3.2

Commits
  • 8b58c9f Bumped v11.3.3
  • 51a121c fix(types): type handler as websocket handler in route() with websocket: true...
  • 6e034a4 Bumped v11.3.2
  • 5adf931 fix: handle socket errors during upgrade hooks
  • See full diff in compare view

Updates better-auth from 1.7.5 to 1.7.7

Release notes

Sourced from better-auth's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

... (truncated)

Changelog

Sourced from better-auth's changelog.

1.7.7

Patch Changes

  • #11476 4186e36 Thanks @​bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.

  • #11469 8620aa9 Thanks @​aryan1306! - Return rate limit errors with a JSON Content-Type header.

  • #11491 55cb92e Thanks @​bytaesu! - Respect social provider disableSignUp when signing in with an ID token.

  • #11375 69defbc Thanks @​bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. The oAuthProxy options and supported configuration remain unchanged.

    Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. Magic Link records and database-backed OAuth or SAML state use separate verification identifier prefixes. Links and database-backed sign-ins started before the upgrade cannot complete; request new Magic Links and restart those sign-ins. Upgrade servers sharing verification storage together, and update verification.storeIdentifier.overrides rules for these flows to match the new magic-link: and auth-state: prefixes. The link token, callback state, endpoints, and public option types are unchanged.

    Upgrade installed Better Auth adapters, plugins, and integrations released with better-auth alongside it so participating packages use the same release version.

  • Updated dependencies [35d7cd3, 07bdf7e]:

    • @​better-auth/drizzle-adapter@​1.7.7
    • @​better-auth/kysely-adapter@​1.7.7
    • @​better-auth/core@​1.7.7
    • @​better-auth/memory-adapter@​1.7.7
    • @​better-auth/mongo-adapter@​1.7.7
    • @​better-auth/prisma-adapter@​1.7.7
    • @​better-auth/telemetry@​1.7.7

1.7.6

Patch Changes

  • #11325 af88385 Thanks @​Wadiou! - Admin plugin bannedUserMessage can now be a function that receives the banned user, so sign-in errors can include details such as the ban reason.

  • #11268 2fa501c Thanks @​bytaesu! - Support linking social accounts through the OAuth Proxy plugin.

  • #11366 d41e2ca Thanks @​bytaesu! - Use targeted PRAGMA queries when a Kysely dialect cannot introspect Cloudflare D1.

  • #11016 3d0efa3 Thanks @​davbrito! - Support Vercel BotID checks on protected authentication routes in Vercel-hosted applications.

... (truncated)

Commits
  • db02f23 chore: release v1.7.7 (#11413)
  • ac54bfd fix(auth): isolate verification records and encryption purposes (#11494)
  • 69defbc fix(organization): refresh active organization after email sign-in (#11375)
  • 55cb92e fix(auth): honor social disableSignUp for ID token sign-in (#11491)
  • 4186e36 fix(captcha): return JSON content type for errors (#11476)
  • 8620aa9 fix(rate-limit): set JSON content type on 429 responses (#11469)
  • 229a02a chore: release v1.7.6 (#11322)
  • dcaa5a7 feat(cli): add check command for schema validation (#11314)
  • fc45d08 fix(client): prevent stale query overwrites (#11376)
  • 8853419 fix: enforce maxPasswordLength before hashing on password verification endpoi...
  • Additional commits viewable in compare view

Updates dotenv from 18.0.3 to 18.0.5

Changelog

Sourced from dotenv's changelog.

18.0.5 (2026-09-30)

Changed

  • Fix missing typescript module declaration (#1068)
  • Improve performance for large .env files (#1066)

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)
Commits

Updates mysql2 from 3.24.4 to 3.24.5

Release notes

Sourced from mysql2's releases.

v3.24.5

3.24.5 (2026-09-29)

Bug Fixes

  • strip the brackets from an IPv6 host in a connection URI (#4570) (b1c39c8)
Changelog

Sourced from mysql2's changelog.

3.24.5 (2026-09-29)

Bug Fixes

  • strip the brackets from an IPv6 host in a connection URI (#4570) (b1c39c8)
Commits
  • e224afe chore(master): release 3.24.5 (#4577)
  • 64ff7cc build(deps-dev): bump @​types/node from 26.6.2 to 26.6.3 (#4578)
  • c3f9872 build(deps-dev): bump rollup in the rollup group across 1 directory (#4572)
  • 4476371 build(deps-dev): bump prettier in the prettier group across 1 directory (#4571)
  • 3fc1b4a build(deps-dev): bump @​types/node from 26.6.2 to 26.6.3 in /website (#4579)
  • 6fcd60a build(deps): bump undici from 7.29.0 to 7.30.0 in /website (#4576)
  • 1705203 build(deps): bump lucide-react from 1.47.0 to 1.48.0 in /website (#4575)
  • e1cb755 build(deps-dev): bump prettier from 3.9.8 to 3.9.9 in /website (#4574)
  • 84425a1 build(deps): bump sass from 1.104.1 to 1.105.0 in /website (#4573)
  • b1c39c8 fix: strip the brackets from an IPv6 host in a connection URI (#4570)
  • Additional commits viewable in compare view

Updates nanoid from 6.0.1 to 6.0.2

Release notes

Sourced from nanoid's releases.

6.0.2

Changelog

Sourced from nanoid's changelog.

6.0.2

Commits

Updates nodemailer from 10.0.10 to 10.0.15

Release notes

Sourced from nodemailer's releases.

v10.0.15

10.0.15 (2026-10-05)

Bug Fixes

  • errors: inherit NodemailerError code from ErrnoException (e99db61), closes #1884
  • errors: keep NodemailerError compatible with @​types/node 26 ErrnoException (#1885) (b660328)

v10.0.14

10.0.14 (2026-10-03)

Bug Fixes

  • addressparser: keep a quoted display name that holds no "@" out of the address (3570d26)
  • addressparser: keep the group recursion depth out of the options object (a680254)
  • addressparser: stop a "[" from hiding the operators after it (5619784)
  • dkim: trim a header field name in linear time (c6f7a55)
  • mime-funcs: read and write header parameters per rfc2045 and rfc2231 (b8ccad7)
  • search only the new bytes for the end of the proxy CONNECT response (81efd7b)

v10.0.13

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

v10.0.12

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

v10.0.11

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)
Changelog

Sourced from nodemailer's changelog.

10.0.15 (2026-10-05)

Bug Fixes

  • errors: inherit NodemailerError code from ErrnoException (e99db61), closes #1884
  • errors: keep NodemailerError compatible with @​types/node 26 ErrnoException (#1885) (b660328)

10.0.14 (2026-10-03)

Bug Fixes

  • addressparser: keep a quoted display name that holds no "@" out of the address (3570d26)
  • addressparser: keep the group recursion depth out of the options object (a680254)
  • addressparser: stop a "[" from hiding the operators after it (5619784)
  • dkim: trim a header field name in linear time (c6f7a55)
  • mime-funcs: read and write header parameters per rfc2045 and rfc2231 (b8ccad7)
  • search only the new bytes for the end of the proxy CONNECT response (81efd7b)

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)
Commits
  • c17efc0 chore(master): release 10.0.15 (#1886)
  • 8d423d0 chore(deps): update dependencies
  • e99db61 fix(errors): inherit NodemailerError code from ErrnoException
  • b660328 fix(errors): keep NodemailerError compatible with @​types/node 26 ErrnoExcepti...
  • aefd1da chore(master): release 10.0.14 (#1880)
  • 520c4ef chore(deps): update dependencies
  • a680254 fix(addressparser): keep the group recursion depth out of the options object
  • 3570d26 fix(addressparser): keep a quoted display name that holds no "@" out of the a...
  • b8ccad7 fix(mime-funcs): read and write header parameters per rfc2045 and rfc2231
  • c6f7a55 fix(dkim): trim a header field name in linear time
  • Additional commits viewable in compare view

Updates pg from 8.23.0 to 8.23.1

Changelog

Sourced from pg's changelog.

All major and minor releases are briefly explained below.

For richer information consult the commit log on github with referenced pull requests.

We do not include break-fix version release in this file.

Commits
  • 0980cef Publish
  • 2759b2c fix(pg): run a named statement with an empty text more than once (#3781)
  • 7feb7df fix(pg): expose detail and hint on errors from the native client (#3780)
  • 9683053 fix(pg): do not treat Sync as connection ending (#3772)
  • 4589038 fix: validate server certificate against host when connecting to an IP addres...
  • 9808955 cleanup: Fix typo in comment
  • 2b02f64 fix: avoid mutating query config (#3720)
  • 0cef6af Reject portal based queries in pipeline mode instead of misrouting rows (#3737)
  • 2991480 Deprecate serializing invalid Dates (#3731)
  • c940d7c Fail pipelined queries when the connection dies instead of hanging (#3736)
  • Additional commits viewable in compare view

Updates @radix-ui/react-alert-dialog from 1.1.23 to 1.1.24

Changelog

Sourced from @​radix-ui/react-alert-dialog's changelog.

1.1.24

  • Updated dependencies: @radix-ui/react-dialog@1.2.0, @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-avatar from 1.2.6 to 1.2.7

Changelog

Sourced from @​radix-ui/react-avatar's changelog.

1.2.7

  • Updated dependencies: @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-checkbox from 1.3.11 to 1.3.12

Changelog

Sourced from @​radix-ui/react-checkbox's changelog.

1.3.12

  • Updated dependencies: @radix-ui/react-use-size@1.1.5, @radix-ui/react-primitive@2.1.11, @radix-ui/react-presence@1.1.11
Commits

Updates @radix-ui/react-dropdown-menu from 2.1.24 to 2.1.25

Changelog

Sourced from @​radix-ui/react-dropdown-menu's changelog.

2.1.25

  • Updated dependencies: @radix-ui/react-menu@2.1.25, @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-label from 2.1.15 to 2.1.16

Changelog

Sourced from @​radix-ui/react-label's changelog.

2.1.16

  • Updated dependencies: @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-select from 2.3.7 to 2.3.8

Changelog

Sourced from @​radix-ui/react-select's changelog.

2.3.8

  • Fixed a bug where internal event handlers were still called on disabled Select.Item elements. Consumer-provided event handlers still run, but Radix's own selection logic no longer fires for disabled items.
  • Updated dependencies: @radix-ui/react-focus-scope@1.2.0, @radix-ui/react-slot@1.4.0, @radix-ui/react-dismissable-layer@1.1.20, @radix-ui/react-visually-hidden@1.2.12, @radix-ui/react-direction@1.1.5, @radix-ui/react-primitive@2.1.11, @radix-ui/react-presence@1.1.11, @radix-ui/react-popper@1.3.8, @radix-ui/react-portal@1.1.18, @radix-ui/react-collection@1.1.16
Commits

Updates @radix-ui/react-separator from 1.1.15 to 1.1.16

Changelog

Sourced from @​radix-ui/react-separator's changelog.

1.1.16

  • Updated dependencies: @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-switch from 1.3.7 to 1.3.8

Changelog

Sourced from @​radix-ui/react-switch's changelog.

1.3.8

  • Updated dependencies: @radix-ui/react-use-size@1.1.5, @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-tabs from 1.1.21 to 1.1.22

Changelog

Sourced from @​radix-ui/react-tabs's changelog.

1.1.22

  • Fixed a bug where a focused element inside Tabs.Content did not fire a blur event before the tab switched. Tabs.Trigger now moves focus before the tab's state change.
  • Updated dependencies: @radix-ui/react-roving-focus@1.1.20, @radix-ui/react-direction@1.1.5, @radix-ui/react-primitive@2.1.11, @radix-ui/react-presence@1.1.11
Commits

Updates @radix-ui/react-toast from 1.2.23 to 1.2.24

Changelog

Sourced from @​radix-ui/react-toast's changelog.

1.2.24

  • Fixed a bug where a paused Toast would not auto-close after its duration changed while the timer was paused.
  • Updated dependencies: @radix-ui/react-dismissable-layer@1.1.20, @radix-ui/react-visually-hidden@1.2.12, @radix-ui/react-primitive@2.1.11, @radix-ui/react-presence@1.1.11, @radix-ui/react-portal@1.1.18, @radix-ui/react-collection@1.1.16
Commits

Updates @radix-ui/react-toggle from 1.1.18 to 1.1.19

Changelog

Sourced from @​radix-ui/react-toggle's changelog.

1.1.19

  • Updated dependencies: @radix-ui/react-primitive@2.1.11
Commits

Updates @radix-ui/react-toggle-group from 1.1.19 to 1.1.20

Changelog

Sourced from @​radix-ui/react-toggle-group's changelog.

1.1.20

  • Updated dependencies: @radix-ui/react-roving-focus@1.1.20, @radix-ui/react-direction@1.1.5, @radix-ui/react-primitive@2.1.11, @radix-ui/react-toggle@1.1.19
Commits

Updates js-yaml from 5.4.2 to 5.4.3

Changelog

Sourced from js-yaml's changelog.

[5.4.3] - 2026-10-06

Fixed

  • Fixed loading a whitespace-only block scalar followed by a less indented line, #802.
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…rectory with 22 updates

Bumps the production-dependencies group with 22 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@better-auth/passkey](https://github.com/better-auth/better-auth/tree/HEAD/packages/passkey) | `1.7.5` | `1.7.7` |
| [@fastify/swagger](https://github.com/fastify/fastify-swagger) | `9.9.0` | `9.9.1` |
| [@fastify/websocket](https://github.com/fastify/fastify-websocket) | `11.3.1` | `11.3.3` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.5` | `1.7.7` |
| [dotenv](https://github.com/motdotla/dotenv) | `18.0.3` | `18.0.5` |
| [mysql2](https://github.com/sidorares/node-mysql2) | `3.24.4` | `3.24.5` |
| [nanoid](https://github.com/ai/nanoid) | `6.0.1` | `6.0.2` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `10.0.10` | `10.0.15` |
| [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.23.0` | `8.23.1` |
| [@radix-ui/react-alert-dialog](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/alert-dialog) | `1.1.23` | `1.1.24` |
| [@radix-ui/react-avatar](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/avatar) | `1.2.6` | `1.2.7` |
| [@radix-ui/react-checkbox](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/checkbox) | `1.3.11` | `1.3.12` |
| [@radix-ui/react-dropdown-menu](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/dropdown-menu) | `2.1.24` | `2.1.25` |
| [@radix-ui/react-label](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/label) | `2.1.15` | `2.1.16` |
| [@radix-ui/react-select](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/select) | `2.3.7` | `2.3.8` |
| [@radix-ui/react-separator](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/separator) | `1.1.15` | `1.1.16` |
| [@radix-ui/react-switch](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/switch) | `1.3.7` | `1.3.8` |
| [@radix-ui/react-tabs](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/tabs) | `1.1.21` | `1.1.22` |
| [@radix-ui/react-toast](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/toast) | `1.2.23` | `1.2.24` |
| [@radix-ui/react-toggle](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/toggle) | `1.1.18` | `1.1.19` |
| [@radix-ui/react-toggle-group](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/toggle-group) | `1.1.19` | `1.1.20` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `5.4.2` | `5.4.3` |



Updates `@better-auth/passkey` from 1.7.5 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/passkey/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/passkey)

Updates `@fastify/swagger` from 9.9.0 to 9.9.1
- [Release notes](https://github.com/fastify/fastify-swagger/releases)
- [Commits](fastify/fastify-swagger@v9.9.0...v9.9.1)

Updates `@fastify/websocket` from 11.3.1 to 11.3.3
- [Release notes](https://github.com/fastify/fastify-websocket/releases)
- [Commits](fastify/fastify-websocket@v11.3.1...v11.3.3)

Updates `better-auth` from 1.7.5 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/better-auth)

Updates `dotenv` from 18.0.3 to 18.0.5
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v18.0.3...v18.0.5)

Updates `mysql2` from 3.24.4 to 3.24.5
- [Release notes](https://github.com/sidorares/node-mysql2/releases)
- [Changelog](https://github.com/sidorares/node-mysql2/blob/master/Changelog.md)
- [Commits](sidorares/node-mysql2@v3.24.4...v3.24.5)

Updates `nanoid` from 6.0.1 to 6.0.2
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@6.0.1...6.0.2)

Updates `nodemailer` from 10.0.10 to 10.0.15
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v10.0.10...v10.0.15)

Updates `pg` from 8.23.0 to 8.23.1
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.1/packages/pg)

Updates `@radix-ui/react-alert-dialog` from 1.1.23 to 1.1.24
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/alert-dialog/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/alert-dialog)

Updates `@radix-ui/react-avatar` from 1.2.6 to 1.2.7
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/avatar/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/avatar)

Updates `@radix-ui/react-checkbox` from 1.3.11 to 1.3.12
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/checkbox/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/checkbox)

Updates `@radix-ui/react-dropdown-menu` from 2.1.24 to 2.1.25
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/dropdown-menu/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/dropdown-menu)

Updates `@radix-ui/react-label` from 2.1.15 to 2.1.16
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/label/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/label)

Updates `@radix-ui/react-select` from 2.3.7 to 2.3.8
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/select/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/select)

Updates `@radix-ui/react-separator` from 1.1.15 to 1.1.16
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/separator/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/separator)

Updates `@radix-ui/react-switch` from 1.3.7 to 1.3.8
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/switch/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/switch)

Updates `@radix-ui/react-tabs` from 1.1.21 to 1.1.22
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/tabs/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/tabs)

Updates `@radix-ui/react-toast` from 1.2.23 to 1.2.24
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/toast/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/toast)

Updates `@radix-ui/react-toggle` from 1.1.18 to 1.1.19
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/toggle/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/toggle)

Updates `@radix-ui/react-toggle-group` from 1.1.19 to 1.1.20
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/toggle-group/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/toggle-group)

Updates `js-yaml` from 5.4.2 to 5.4.3
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.4.2...5.4.3)

---
updated-dependencies:
- dependency-name: "@better-auth/passkey"
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@fastify/swagger"
  dependency-version: 9.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@fastify/websocket"
  dependency-version: 11.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: better-auth
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: dotenv
  dependency-version: 18.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: mysql2
  dependency-version: 3.24.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: nanoid
  dependency-version: 6.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: nodemailer
  dependency-version: 10.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: pg
  dependency-version: 8.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-alert-dialog"
  dependency-version: 1.1.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-avatar"
  dependency-version: 1.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-checkbox"
  dependency-version: 1.3.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-dropdown-menu"
  dependency-version: 2.1.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-label"
  dependency-version: 2.1.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-select"
  dependency-version: 2.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-separator"
  dependency-version: 1.1.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-switch"
  dependency-version: 1.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-tabs"
  dependency-version: 1.1.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-toast"
  dependency-version: 1.2.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-toggle"
  dependency-version: 1.1.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@radix-ui/react-toggle-group"
  dependency-version: 1.1.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: js-yaml
  dependency-version: 5.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: backend, frontend. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🔒 Supply Chain Security Review

Check Status
Socket.dev malware scan ✅ success
Vulnerability audit ✅ success
Lockfile diff review ✅ success
OSSF Scorecard ✅ success

This review was automatically generated by the Supply Chain Review workflow.

@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 9, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-01046370c3 branch October 9, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants