Skip to content

chore(deps): bump the npm-production group across 1 directory with 19 updates - #727

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-production-37f36a9de8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-production-37f36a9de8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-production group with 19 updates in the / directory:

Package From To
@tauri-apps/api 2.11.1 2.12.1
@tauri-apps/plugin-clipboard-manager 2.3.3 2.4.1
@tauri-apps/plugin-dialog 2.7.3 2.8.1
@tauri-apps/plugin-fs 2.5.2 2.6.0
@tauri-apps/plugin-opener 2.5.5 2.7.0
@tauri-apps/plugin-os 2.3.2 2.4.0
ws 8.21.3 8.22.0
@types/node 22.20.4 22.20.5
@hono/node-server 2.1.1 2.1.3
@modelcontextprotocol/sdk 1.30.0 1.31.0
hono 4.13.8 4.13.12
@usebruno/filestore 0.12.0 0.13.0
@lezer/highlight 1.2.3 1.2.5
@tanstack/react-query 5.103.2 5.104.0
@tanstack/react-router 1.170.38 1.170.41
@tauri-apps/plugin-log 2.9.2 2.10.0
@tauri-apps/plugin-shell 2.3.6 2.4.0
lucide-react 1.47.0 1.49.0
motion 13.4.0 13.5.0

Updates @tauri-apps/api from 2.11.1 to 2.12.1

Release notes

Sourced from @​tauri-apps/api's releases.

@​tauri-apps/api v2.12.1

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.1]

Bug Fixes

  • c9a3cb892 (#16166 by @​FabianLars) The macos-private-api feature flag / macOSPrivateAPI tauri.conf.json value is no longer required to use transparency or fullscreen on macOS.
$ pnpm build && cd ./dist && pnpm publish --access public --loglevel debug --no-git-checks
$ rollup -c --configPlugin typescript
�[36m
�[1m./src/app.ts, ./src/core.ts, ./src/dpi.ts, ./src/event.ts, ./src/image.ts, ./src/index.ts, ./src/menu.ts, ./src/mocks.ts, ./src/path.ts, ./src/tray.ts, ./src/webview.ts, ./src/webviewWindow.ts, ./src/window.ts�[22m → �[1m./dist, ./dist�[22m...�[39m
�[32mcreated �[1m./dist, ./dist�[22m in �[1m997ms�[22m�[39m
�[36m
�[1msrc/index.ts�[22m → �[1m../../crates/tauri/scripts/bundle.global.js�[22m...�[39m
�[32mcreated �[1m../../crates/tauri/scripts/bundle.global.js�[22m in �[1m1.5s�[22m�[39m
GET https://run-actions-2-azure-eastus.actions.githubusercontent.com/210//idtoken/dd253aee-436e-8e22-8c02-25aaaa05b17c/69013391-05d6-5397-b35a-e76c0a237b30?api-version=2.0&audience=npm%3Aregistry.npmjs.org 200 336ms
📦 @tauri-apps/api@2.12.1 → https://registry.npmjs.org/
GET https://run-actions-2-azure-eastus.actions.githubusercontent.com/210//idtoken/dd253aee-436e-8e22-8c02-25aaaa05b17c/69013391-05d6-5397-b35a-e76c0a237b30?api-version=2.0&audience=sigstore 200 107ms
Signed provenance statement with source and build information
✅ Published package @tauri-apps/api@2.12.1

@​tauri-apps/api v2.12.0

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.0]

... (truncated)

Commits

Updates @tauri-apps/plugin-clipboard-manager from 2.3.3 to 2.4.1

Release notes

Sourced from @​tauri-apps/plugin-clipboard-manager's releases.

biometric-js v2.4.1

[2.4.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-biometric@2.4.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.1kB README.md
npm notice 2.2kB dist-js/index.cjs
npm notice 3.4kB dist-js/index.d.ts
npm notice 2.1kB dist-js/index.js
npm notice 685B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-biometric
npm notice version: 2.4.1
npm notice filename: tauri-apps-plugin-biometric-2.4.1.tgz
npm notice package size: 3.6 kB
npm notice unpacked size: 12.4 kB
npm notice shasum: 08fb2149f8812d8f264bedf5119d656cea23a580
npm notice integrity: sha512-dH/IPC+NTiB28[...]qdY33uaVNIxvw==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3028114630
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-biometric@2.4.1

biometric v2.4.1

[2.4.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.

... (truncated)

Commits
  • d66aa6f publish new versions (#2822)
  • 6f34587 fix(single-instance): disable dbus name replacement (#2860)
  • 708fa4e chore(deps): update dependency eslint-config-prettier to v10.1.8 (#2858)
  • b729203 fix(upload): fix download() locks main thread on Android (#2838)
  • 2f9c71a chore(deps): update dependency rollup to v4.45.1 (#2850)
  • 80d4d8e chore(deps): update eslint monorepo to v9.31.0 (v2) (#2839)
  • e7a98b0 chore(deps): update dependency typescript-eslint to v8.37.0 (#2848)
  • 44a1f65 fix(fs): writeFile create file by default (#2846)
  • 6210cd3 chore(deps): update dependency rollup to v4.45.0 (#2841)
  • 467f07b chore(deps): update dependency vite to v7 (v2) (#2800)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-dialog from 2.7.3 to 2.8.1

Release notes

Sourced from @​tauri-apps/plugin-dialog's releases.

dialog-js v2.8.1

[2.8.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-dialog@2.8.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.5kB README.md
npm notice 7.1kB dist-js/index.cjs
npm notice 15.1kB dist-js/index.d.ts
npm notice 7.0kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 657B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-dialog
npm notice version: 2.8.1
npm notice filename: tauri-apps-plugin-dialog-2.8.1.tgz
npm notice package size: 6.8 kB
npm notice unpacked size: 34.3 kB
npm notice shasum: f29f3c28862a1ed767b6fd241f34abf26129f88f
npm notice integrity: sha512-/DtE3B62JgpYu[...]phsKnb+738Dmw==
npm notice total files: 7
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3028120915
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-dialog@2.8.1

dialog v2.8.1

[2.8.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.

... (truncated)

Commits
  • d4835d0 publish new versions (#3660)
  • 569ee82 fix: mobile docs.rs builds
  • 25f3874 chore(deps): update dependency eslint-plugin-security to v4.1.0 (#3661)
  • 2fd4bed chore(autostart): update auto-launch to 0.6 (#3546)
  • e511284 publish new versions (#3647)
  • ce59e96 docs(log): remove unrelated single-instance comment from log readme
  • 29130c2 ci: run clippy on all platforms (#3650)
  • 4353819 chore: add changefile to re-release plugin-http npm package as 2.8.0 (#3656)
  • ec14142 chore(deps): update dependency @​types/node to v24 (#3649)
  • 90b9869 chore(deps): update rust crate dirs to v7 (#3573)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-fs from 2.5.2 to 2.6.0

Release notes

Sourced from @​tauri-apps/plugin-fs's releases.

deep-link-js v2.6.0

[2.6.0]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-deep-link@2.6.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 6.2kB README.md
npm notice 4.7kB dist-js/index.cjs
npm notice 4.0kB dist-js/index.d.ts
npm notice 4.5kB dist-js/index.js
npm notice 801B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-deep-link
npm notice version: 2.6.0
npm notice filename: tauri-apps-plugin-deep-link-2.6.0.tgz
npm notice package size: 4.8 kB
npm notice unpacked size: 21.1 kB
npm notice shasum: 42f4e74e87aea6ace90871ad293f4fface5910cc
npm notice integrity: sha512-41rOuYUZjxcEz[...]TsoJQ2R9U5MCA==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005261605
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-deep-link@2.6.0

deep-link v2.6.0

[2.6.0]

... (truncated)

Commits

Updates @tauri-apps/plugin-opener from 2.5.5 to 2.7.0

Release notes

Sourced from @​tauri-apps/plugin-opener's releases.

opener-js v2.7.0

[2.7.0]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-opener@2.7.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.2kB README.md
npm notice 3.1kB dist-js/index.cjs
npm notice 2.0kB dist-js/index.d.ts
npm notice 3.1kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 730B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-opener
npm notice version: 2.7.0
npm notice filename: tauri-apps-plugin-opener-2.7.0.tgz
npm notice package size: 3.5 kB
npm notice unpacked size: 14.1 kB
npm notice shasum: 14d631a70282cbc07b46f4442ba6085d2200f301
npm notice integrity: sha512-mBorYfVKh9Lt7[...]5OHHVmipjuGMw==
npm notice total files: 7
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005263072
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-opener@2.7.0

opener v2.7.0

[2.7.0]

... (truncated)

Commits
  • 51b430b ci: delete .changes/updater-new-bundle-support.md
  • fd439b1 Publish New Versions (v2) (#2964)
  • 2522b71 fix(deep-link): revert the breaking change introduced by #2928 (#2970)
  • 9021a73 chore(deps): update dependency rollup to v4.50.0 (#2966)
  • 625bb1c feat(log): re-export the log crate (#2965)
  • 6215afe chore(deps): update dependency rollup to v4.49.0 (#2962)
  • 8cf8eea feat(updater): inject bundle_type into endpoint url (#2960)
  • 509eba8 feat: support message dialogs with 3 buttons (#2641)
  • 9ac5fe8 feat(updater): support bundle-specific targets (#2624)
  • c247410 chore(deps): update dependency typescript-eslint to v8.41.0 (#2956)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-os from 2.3.2 to 2.4.0

Release notes

Sourced from @​tauri-apps/plugin-os's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tauri-apps/plugin-os since your current version.


Updates ws from 8.21.3 to 8.22.0

Release notes

Sourced from ws's releases.

8.22.0

Features

  • Introduced the protocols option (8b918b01).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the state to WebSocket.CLOSING (#2337).
Commits
  • 297202c [dist] 8.22.0
  • 8b918b0 [feature] Introduce the protocols option
  • 73e03eb [ci] Update actions/setup-node action to v7
  • d9b8954 [fix] Change the ready state after validating the arguments (#2337)
  • See full diff in compare view

Updates @types/node from 22.20.4 to 22.20.5

Commits

Updates @hono/node-server from 2.1.1 to 2.1.3

Release notes

Sourced from @​hono/node-server's releases.

v2.1.3

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

Commits

Updates @modelcontextprotocol/sdk from 1.30.0 to 1.31.0

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Updates hono from 4.13.8 to 4.13.12

Release notes

Sourced from hono's releases.

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

... (truncated)

Commits
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • c437d75 test(build): type-check the bundled declarations from a consumer project (#5486)
  • be1f749 fix(build): keep internal types private in bundled d.ts and avoid a self-refe...
  • 37ce069 4.13.11
  • 1e1207c test(serve-static): fix the test (#5479)
  • 8b05c77 Merge commit from fork
  • Additional commits viewable in compare view

Updates @usebruno/filestore from 0.12.0 to 0.13.0

Updates @lezer/highlight from 1.2.3 to 1.2.5

Commits

Updates @tanstack/react-query from 5.103.2 to 5.104.0

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-devtools@​5.104.0
    • @​tanstack/react-query@​5.104.0

@​tanstack/react-query-next-experimental@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/react-query@​5.104.0

@​tanstack/react-query-persist-client@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/react-query@​5.104.0
    • @​tanstack/query-persist-client-core@​5.104.0

@​tanstack/react-query@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-core@​5.104.0

@​tanstack/react-query-devtools@​5.103.3

Patch Changes

@​tanstack/react-query-next-experimental@​5.103.3

... (truncated)

Changelog

Sourced from @​tanstack/react-query's changelog.

5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-core@​5.104.0

5.103.3

Patch Changes

  • #11647 1c9693e - fix(codemods): avoid copying unnecessary files from codemods project
  • Updated dependencies []:
    • @​tanstack/query-core@​5.103.3
Commits
  • d4033eb ci: Version Packages (#11651)
  • 5279b05 chore(deps): update Vite from v6 to v8 (#11650)
  • fe053bf ci: Version Packages (#11612)
  • 1c9693e fix(codemods): update codemods build script (#11647)
  • f00aad6 chore(deps): update dev dependencies (#11640)
  • 2443290 test(*): rename 'console.error' spies to 'consoleErrorMock' (#11646)
  • fcab29f test({query-core,react-query,preact-query}): restore the previous 'isServer' ...
  • e8dacbe docs({react-query,preact-query,solid-query,svelte-query}/README): point the C...
  • 57f40eb chore(deps): update non-major dependencies (#11625)
  • 397ad07 test({query-core,react-query,preact-query,solid-query}): pass 'unhandledRejec...
  • Additional commits viewable in compare view

Updates @tanstack/react-router from 1.170.38 to 1.170.41

Release notes

Sourced from @​tanstack/react-router's releases.

@​tanstack/react-router@​1.170.41

Patch Changes

  • #8529 60b8ad1 - Compose only enabled route boundaries instead of rendering inactive wrapper components.

  • #8568 614bc27 - Update TanStack Store to 0.11.2 to prevent unrelated atom reads inside subscription observers from triggering extra notifications.

  • #8530 ff66a03 - Consolidate the root match context provider while preserving match context in the root shell.

  • #8522 863c8a7 - Reuse Link href classification and active/inactive results across location updates while preserving live history href formatting.

  • Updated dependencies [d521abd]:

    • @​tanstack/router-core@​1.171.34

@​tanstack/react-router@​1.170.40

Patch Changes

… updates

Bumps the npm-production group with 19 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.11.1` | `2.12.1` |
| [@tauri-apps/plugin-clipboard-manager](https://github.com/tauri-apps/plugins-workspace) | `2.3.3` | `2.4.1` |
| [@tauri-apps/plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.7.3` | `2.8.1` |
| [@tauri-apps/plugin-fs](https://github.com/tauri-apps/plugins-workspace) | `2.5.2` | `2.6.0` |
| [@tauri-apps/plugin-opener](https://github.com/tauri-apps/plugins-workspace) | `2.5.5` | `2.7.0` |
| [@tauri-apps/plugin-os](https://github.com/tauri-apps/plugins-workspace) | `2.3.2` | `2.4.0` |
| [ws](https://github.com/websockets/ws) | `8.21.3` | `8.22.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.20.4` | `22.20.5` |
| [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.31.0` |
| [hono](https://github.com/honojs/hono) | `4.13.8` | `4.13.12` |
| @usebruno/filestore | `0.12.0` | `0.13.0` |
| [@lezer/highlight](https://github.com/lezer-parser/highlight) | `1.2.3` | `1.2.5` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.103.2` | `5.104.0` |
| [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.170.38` | `1.170.41` |
| [@tauri-apps/plugin-log](https://github.com/tauri-apps/plugins-workspace) | `2.9.2` | `2.10.0` |
| [@tauri-apps/plugin-shell](https://github.com/tauri-apps/plugins-workspace) | `2.3.6` | `2.4.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.47.0` | `1.49.0` |
| [motion](https://github.com/motiondivision/motion) | `13.4.0` | `13.5.0` |



Updates `@tauri-apps/api` from 2.11.1 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.11.1...@tauri-apps/api-v2.12.1)

Updates `@tauri-apps/plugin-clipboard-manager` from 2.3.3 to 2.4.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@nfc-v2.3.3...fs-v2.4.1)

Updates `@tauri-apps/plugin-dialog` from 2.7.3 to 2.8.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@dialog-v2.7.3...dialog-v2.8.1)

Updates `@tauri-apps/plugin-fs` from 2.5.2 to 2.6.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.5.2...fs-v2.6.0)

Updates `@tauri-apps/plugin-opener` from 2.5.5 to 2.7.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@http-v2.5.5...log-v2.7.0)

Updates `@tauri-apps/plugin-os` from 2.3.2 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@os-v2.3.2...os-v2.4.0)

Updates `ws` from 8.21.3 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.3...8.22.0)

Updates `@types/node` from 22.20.4 to 22.20.5
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@hono/node-server` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v2.1.1...v2.1.3)

Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.31.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.31.0)

Updates `hono` from 4.13.8 to 4.13.12
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.8...v4.13.12)

Updates `@usebruno/filestore` from 0.12.0 to 0.13.0

Updates `@lezer/highlight` from 1.2.3 to 1.2.5
- [Changelog](https://github.com/lezer-parser/highlight/blob/main/CHANGELOG.md)
- [Commits](https://github.com/lezer-parser/highlight/commits)

Updates `@tanstack/react-query` from 5.103.2 to 5.104.0
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.104.0/packages/react-query)

Updates `@tanstack/react-router` from 1.170.38 to 1.170.41
- [Release notes](https://github.com/TanStack/router/releases)
- [Changelog](https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md)
- [Commits](https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.41/packages/react-router)

Updates `@tauri-apps/plugin-log` from 2.9.2 to 2.10.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@log-v2.9.2...log-v2.10.0)

Updates `@tauri-apps/plugin-shell` from 2.3.6 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@nfc-v2.3.6...os-v2.4.0)

Updates `lucide-react` from 1.47.0 to 1.49.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.49.0/packages/lucide-react)

Updates `motion` from 13.4.0 to 13.5.0
- [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md)
- [Commits](motiondivision/motion@v13.4.0...v13.5.0)

---
updated-dependencies:
- dependency-name: "@tauri-apps/api"
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-clipboard-manager"
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-dialog"
  dependency-version: 2.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-fs"
  dependency-version: 2.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-opener"
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-os"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@types/node"
  dependency-version: 22.20.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: hono
  dependency-version: 4.13.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@usebruno/filestore"
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@lezer/highlight"
  dependency-version: 1.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tanstack/react-router"
  dependency-version: 1.170.41
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-log"
  dependency-version: 2.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: "@tauri-apps/plugin-shell"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: lucide-react
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: motion
  dependency-version: 13.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants