Skip to content

Bump the backend group across 1 directory with 11 updates - #38

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend/backend-0e9220de2d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend/backend-0e9220de2d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps the backend group with 11 updates in the /backend directory:

Package From To
@sentry/node 10.68.0 10.75.3
express 4.22.2 4.22.3
express-rate-limit 8.5.2 8.7.0
google-auth-library 10.9.0 10.9.1
helmet 8.1.0 8.3.0
mysql2 3.16.3 3.24.4
nodemailer 9.0.3 9.1.1
validator 13.15.26 13.15.35
jest 30.4.2 30.5.2
prettier 3.9.1 3.9.9
supertest 7.2.2 7.3.0

Updates @sentry/node from 10.68.0 to 10.75.3

Release notes

Sourced from @​sentry/node's releases.

10.75.3

  • fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route (#24617)
  • chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • chore(v10/publish): Tag all packages as v10 (#24619)

Bundle size 📦

Path Size
@​sentry/browser 27.56 KB
@​sentry/browser - with treeshaking flags 26.04 KB
@​sentry/browser (incl. Tracing) 46.02 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.77 KB
@​sentry/browser (incl. Tracing, Profiling) 50.67 KB
@​sentry/browser (incl. Tracing, Replay) 84.38 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 74.28 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 89 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 101.33 KB
@​sentry/browser (incl. Feedback) 44.33 KB
@​sentry/browser (incl. sendFeedback) 32.25 KB
@​sentry/browser (incl. FeedbackAsync) 37.27 KB
@​sentry/browser (incl. Metrics) 28.63 KB
@​sentry/browser (incl. Logs) 28.84 KB
@​sentry/browser (incl. Metrics & Logs) 29.52 KB
@​sentry/react 29.32 KB
@​sentry/react (incl. Tracing) 48.28 KB
@​sentry/vue 32.88 KB
@​sentry/vue (incl. Tracing) 47.98 KB
@​sentry/svelte 27.58 KB
CDN Bundle 29.87 KB
CDN Bundle (incl. Tracing) 47.92 KB
CDN Bundle (incl. Logs, Metrics) 31.41 KB
CDN Bundle (incl. Tracing, Logs, Metrics) 49.21 KB
CDN Bundle (incl. Replay, Logs, Metrics) 69.82 KB
CDN Bundle (incl. Tracing, Replay) 84.64 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.87 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 90.31 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 91.55 KB
CDN Bundle - uncompressed 88.83 KB
CDN Bundle (incl. Tracing) - uncompressed 144.49 KB
CDN Bundle (incl. Logs, Metrics) - uncompressed 93.43 KB
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 148.38 KB
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 215.46 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 261.12 KB

... (truncated)

Changelog

Sourced from @​sentry/node's changelog.

10.75.3

  • fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route (#24617)
  • chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • chore(v10/publish): Tag all packages as v10 (#24619)

10.75.2

  • fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)
  • fix(v10/core): Apply dataCollection.urlQueryParams to collected URLs and query strings (#24572)
  • fix(v10/nextjs): Align tunnel request matching in middleware with tunnel rewrite (#24565)
  • fix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams (#24563)

10.75.1

  • fix(v10/cloudflare): Capture telemetry from untraced Durable Object RPC calls (#24512)
  • fix(v10/cloudflare): Instrument namespaces returned by jurisdiction() (#24513)
  • fix(v10/hono): Allow @​cloudflare/workers-types v5 as peer dependency (#24500)
  • fix(v10/nextjs): Resolve Next.js version relative to the SDK when cwd differs (#24475)

10.75.0

Important Changes

  • feat(v10/effect): Capture errors through the Effect v4 ErrorReporter API (#24445)

    On Effect v4, Sentry.effectLayer now registers a Sentry ErrorReporter. Failures that pass through Effect.withErrorReporting, ErrorReporter.report or the built-in HTTP and RPC reporting boundaries are captured automatically, with ErrorReporter.ignore, ErrorReporter.severity and ErrorReporter.attributes annotations respected. Nothing changes on Effect v3.

Other Changes

  • feat(v10/core): Accept a CollectBehavior shorthand for dataCollection.httpHeaders (#24339)
  • fix(v10/browser): Release the XHR virtualError once the request completed (#24307)
  • fix(v10/browser-utils): Skip nullish LCP entries in vendored web-vitals (#24349)
  • fix(v10/bundler-plugins): Stamp debug IDs onto emitted source maps when disable-upload is set (#24332)
  • fix(v10/core): Don't instrument the SDK's own envelope requests (#24276)
  • fix(v10/nextjs): Only include emitted chunk directories in Turbopack sourcemap upload (#24295)
  • fix(v10/nitro): Import from nitro/h3 instead of h3 directly (#24444)
  • fix(v10/node-core): Don't recurse in logAndExitProcess on a broken stdio pipe (#24353)
  • fix(v10/nuxt): Detect Nitro version via the app's Nuxt dependency chain (#24025)
  • fix(v10/replay): Don't rewrite already-emitted nodes when syncing mirror attributes (#23588)

10.74.0

  • feat(v10): Streamline isolation scope handling & reset in isolation scopes (#24152)

... (truncated)

Commits
  • 3b282c1 release: 10.75.3
  • b5ea330 meta(changelog): Update changelog for 10.75.3 (#24649)
  • 533a6fa chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • 4e91ce5 chore(v10/publish): Tag all packages as v10 (#24619)
  • f01ca30 fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel ...
  • 79e6e95 Merge remote-tracking branch 'remotes/origin/release/10.75.2' into v10
  • faeac9a release: 10.75.2
  • 7175b19 meta(changelog): Update changelog for 10.75.2 (#24585)
  • 8f5dc60 fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)
  • 44506df fix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams...
  • Additional commits viewable in compare view

Updates express from 4.22.2 to 4.22.3

Changelog

Sourced from express's changelog.

4.22.3

  • Allow conditional revalidation for QUERY requests
    • req.fresh now includes QUERY in the freshness check, so QUERY responses can return 304 when a validator matches
  • deps: qs@~6.16.0
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for express since your current version.


Updates express-rate-limit from 8.5.2 to 8.7.0

Release notes

Sourced from express-rate-limit's releases.

v8.7.0

You can view the changelog here.

v8.6.2

You can view the changelog here.

v8.6.1

You can view the changelog here.

v8.6.0

You can view the changelog here.

Commits
  • 48db09e 8.7.0
  • dce5871 v8.7.0 changelog
  • 2f08044 Add inspect.software health badge (#673)
  • a29757c feat: add retryAfter option (#661)
  • 146e88b chore: rename license
  • 5cfb8e8 ci: drop top-level id-token: write from the workflow token (#676)
  • 062bbdd fix: re-wrap license.md so GitHub recognizes it as MIT (#675)
  • 514772d chore(deps-dev): bump mintlify in the development-dependencies group (#674)
  • 4f06c8a chore(deps-dev): bump the development-dependencies group with 2 updates (#671)
  • 83356a5 chore(deps): bump ip-address from 10.4.0 to 10.5.0 (#672)
  • Additional commits viewable in compare view

Updates google-auth-library from 10.9.0 to 10.9.1

Changelog

Sourced from google-auth-library's changelog.

10.9.1 (2026-07-23)

Bug Fixes

  • auth: Add GOOGLE_APPLICATION_CREDENTIALS context to credential load errors (#8800) (829990f), refs #8799
  • auth: Honor CLOUDSDK_CONFIG when locating the ADC well-known file (#8798) (6e912cf), refs #8797
Commits
  • 6b9fd1a chore: release main (#8956)
  • 829990f fix(auth): add GOOGLE_APPLICATION_CREDENTIALS context to credential load erro...
  • 6e912cf fix(auth): honor CLOUDSDK_CONFIG when locating the ADC well-known file (#8798)
  • 5bd6b22 chore: revert "feat(auth): Regional access boundaries main merge (#8665)" (#8...
  • See full diff in compare view

Updates helmet from 8.1.0 to 8.3.0

Changelog

Sourced from helmet's changelog.

8.3.0 - 2026-07-11

Changed

  • Content-Security-Policy: improved performance by ~7% when there are no dynamic directives
  • Content-Security-Policy: improved error handling for invalid directive names

Fixed

  • Content-Security-Policy: useDefaults: false with no directives is no longer valid, both at runtime and the type level
  • Content-Security-Policy: dynamically-computed directive values would throw, not call next, when invalid
  • Content-Security-Policy: dynamically-computed directive value entries would throw, not call next, when function threw

8.2.0 - 2026-05-21

  • Cross-Origin-Opener-Policy: support noopener-allow-popups. See #522
  • Improve error message when passing duplicate options
Commits
  • 75f1a98 8.3.0
  • f03f70d Update changelog for 8.3.0 release
  • a307fce Fix capitalization in CSP package changelog
  • 5347b43 Format default CSP in README for readability
  • 9afc570 CSP: fix middleware-specific README missing link
  • 266c95c Minor speedups to project setups test
  • 7a4196c CSP: update package-specific changelog
  • 02716b4 CSP: improve performance when there are no dynamic directives
  • 3f511ed CSP: move utility functions to separate file
  • 80338af CSP: disabling defaults with no directives is now an error
  • Additional commits viewable in compare view

Updates mysql2 from 3.16.3 to 3.24.4

Release notes

Sourced from mysql2's releases.

v3.24.4

3.24.4 (2026-09-07)

Performance Improvements

  • per-query overhead, local dates, short strings, TLS context and compression (#4522) (2387daf)
  • reuse TLS sessions across connections to the same server (#4529) (9178c82)

v3.24.3

3.24.3 (2026-09-01)

Bug Fixes

  • typings: PoolCluster node events emit a string nodeId (#4513) (1281e1e)

v3.24.2

3.24.2 (2026-08-24)

Bug Fixes

  • correct length-coded number size for the 3-byte range (#4500) (de56272)
  • promise: honour trace: false on every promise-API method (#4502) (1dcd8ef), closes #4501

v3.24.1

3.24.1 (2026-08-24)

Performance Improvements

  • single-pass utf8 string encoding for outgoing packets (#4495) (183e947)

v3.24.0

3.24.0 (2026-08-23)

Features

  • typed parameters, and adopt integer types the server reports (#4488) (8ec20f1)

Bug Fixes

  • zero dates come back as "undefined 00:00:00" with dateStrings (#4491) (5bf7bda)

Performance Improvements

... (truncated)

Changelog

Sourced from mysql2's changelog.

3.24.4 (2026-09-07)

Performance Improvements

  • per-query overhead, local dates, short strings, TLS context and compression (#4522) (2387daf)
  • reuse TLS sessions across connections to the same server (#4529) (9178c82)

3.24.3 (2026-09-01)

Bug Fixes

  • typings: PoolCluster node events emit a string nodeId (#4513) (1281e1e)

3.24.2 (2026-08-24)

Bug Fixes

  • correct length-coded number size for the 3-byte range (#4500) (de56272)
  • promise: honour trace: false on every promise-API method (#4502) (1dcd8ef), closes #4501

3.24.1 (2026-08-24)

Performance Improvements

  • single-pass utf8 string encoding for outgoing packets (#4495) (183e947)

3.24.0 (2026-08-23)

Features

  • typed parameters, and adopt integer types the server reports (#4488) (8ec20f1)

Bug Fixes

  • zero dates come back as "undefined 00:00:00" with dateStrings (#4491) (5bf7bda)

Performance Improvements

  • remove per-query and per-row allocation hotspots (#4486) (c86fe5a)
  • serialize COM_STMT_EXECUTE in a single exact-size pass (#4494) (f3a60bc)

3.23.4 (2026-08-19)

... (truncated)

Commits
  • a87208a chore(master): release 3.24.4 (#4530)
  • e5833be chore: prepare src for parallel TypeScript transcription (#4538)
  • 5f6482f build(deps): bump sass from 1.103.1 to 1.104.0 in /website (#4537)
  • 8e0bd84 build(deps): bump lucide-react from 1.38.0 to 1.41.0 in /website (#4536)
  • 8b8a9cb build(deps-dev): bump @​types/node from 26.4.0 to 26.4.1 in /website (#4535)
  • 83854a6 build(deps): bump docusaurus-plugin-sass (#4534)
  • 2e9d75a build(deps-dev): bump @​biomejs/biome from 2.5.11 to 2.5.12 (#4533)
  • d6f4172 build(deps-dev): bump @​types/node from 26.4.0 to 26.4.1 (#4532)
  • 2e1c9e0 build(deps): bump lru.min from 1.1.4 to 1.1.5 (#4531)
  • 2387daf perf: per-query overhead, local dates, short strings, TLS context and compres...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for mysql2 since your current version.


Updates nodemailer from 9.0.3 to 9.1.1

Release notes

Sourced from nodemailer's releases.

v9.1.1

9.1.1 (2026-09-01)

Bug Fixes

  • mailer: apply the message access policy in resolveContent (dc48ed3)
  • mailer: keep message data from reopening the access sandbox (ab7ef34)
  • mime-node: inherit the access policy from the tree a node hangs in (262d550)

v9.1.0

9.1.0 (2026-08-31)

Features

  • mailer: cap recipients per message with maxRecipients (7279ac8)

Bug Fixes

  • addressparser: handle address lists in linear time (9116da9)
  • addressparser: terminate the domain at an RFC 5322 comment (902b63e)
  • mime-node: apply UTS-46 mapping when encoding a domain (259c32d)
  • mime-node: dedupe envelope recipients in linear time (7cc38af)
  • mime-node: flatten parsed addresses without concat.apply (83b8c48)
  • mime-node: keep the recipient dedupe linear across address headers (34da642)
  • mime-node: keep URL delimiters away from the domain mapper (b212ac4)

v9.0.6

9.0.6 (2026-08-27)

Bug Fixes

  • addressparser: recover the addr-spec from an angle-addr holding whitespace (e989a22)
  • harden copies of user supplied keys and URL fetching (2f667f4)

v9.0.5

9.0.5 (2026-08-07)

Bug Fixes

  • ci: retrigger the workflows dropped during the Actions outage (85d16c1)
  • mailer: escape specials in List-* header comments (#1842) (75913bb)
  • mime-funcs: star the continuation key of a restarted parameter line (36bcf1a)
  • mime-node: keep control chars out of header values and msg-id headers (15cf6d1)
  • mime: encode DEL in header parameters and List-* comments (cf69430)
  • mime: keep control chars out of the remaining header positions (5ed9d26)

... (truncated)

Changelog

Sourced from nodemailer's changelog.

9.1.1 (2026-09-01)

Bug Fixes

  • mailer: apply the message access policy in resolveContent (dc48ed3)
  • mailer: keep message data from reopening the access sandbox (ab7ef34)
  • mime-node: inherit the access policy from the tree a node hangs in (262d550)

9.1.0 (2026-08-31)

Features

  • mailer: cap recipients per message with maxRecipients (7279ac8)

Bug Fixes

  • addressparser: handle address lists in linear time (9116da9)
  • addressparser: terminate the domain at an RFC 5322 comment (902b63e)
  • mime-node: apply UTS-46 mapping when encoding a domain (259c32d)
  • mime-node: dedupe envelope recipients in linear time (7cc38af)
  • mime-node: flatten parsed addresses without concat.apply (83b8c48)
  • mime-node: keep the recipient dedupe linear across address headers (34da642)
  • mime-node: keep URL delimiters away from the domain mapper (b212ac4)

9.0.6 (2026-08-27)

Bug Fixes

  • addressparser: recover the addr-spec from an angle-addr holding whitespace (e989a22)
  • harden copies of user supplied keys and URL fetching (2f667f4)

9.0.5 (2026-08-07)

Bug Fixes

  • ci: retrigger the workflows dropped during the Actions outage (85d16c1)
  • mailer: escape specials in List-* header comments (#1842) (75913bb)
  • mime-funcs: star the continuation key of a restarted parameter line (36bcf1a)
  • mime-node: keep control chars out of header values and msg-id headers (15cf6d1)
  • mime: encode DEL in header parameters and List-* comments (cf69430)
  • mime: keep control chars out of the remaining header positions (5ed9d26)
  • mime: normalize an address parsed out of a string as well (63685f7)
  • mime: normalize an address so header and envelope agree (a9343b4)
  • mime: stop a header key callback and the dkim tags from injecting (b7d772e)

... (truncated)

Commits
  • ad4513f chore(master): release 9.1.1 (#1850)
  • c3e261f docs: replace dead Node.js c-ares dependencies link (#1845)
  • c158a38 docs: mark 9.x as the supported security line (#1846)
  • 262d550 fix(mime-node): inherit the access policy from the tree a node hangs in
  • ab7ef34 fix(mailer): keep message data from reopening the access sandbox
  • dc48ed3 fix(mailer): apply the message access policy in resolveContent
  • efd6e29 chore(master): release 9.1.0 (#1849)
  • 1f9533b chore(deps): update dev dependencies
  • b212ac4 fix(mime-node): keep URL delimiters away from the domain mapper
  • 6aa7e3f refactor: fold review findings into the address parsing changes
  • Additional commits viewable in compare view

Updates validator from 13.15.26 to 13.15.35

Release notes

Sourced from validator's releases.

13.15.35

Fixes, New Locales and Enhancements

New Contributors

Full Changelog: validatorjs/validator.js@13.15.26...13.15.35

Changelog

Sourced from validator's changelog.

13.15.35

Fixes, New Locales and Enhancements

Commits
  • 7a80797 maintenance: 2604 release (#2695)
  • 941db7f fix(isSlug): restrict allowed characters to valid slug charset (#2693)
  • 2758f70 chore: fix typo in comment (#2591)
  • fcfbff5 feat(isJson): allow any valid JSON value to pass (#2690)
  • f06caee refactor: replace if-then-else flow by a single return statement (#2592)
  • 9fa1e3a feat(isPostalCode): Add postal code for Monaco (#2682)
  • b1aea75 feat(isMobilePhone): add Djibouti (fr-DJ) mobile phone validation (#2676)
  • f715cdd fix(isPassportNumber): improve MX locale (#2643)
  • e8c6914 fix(isTaxID): add formatted CPF support and additional test cases for pt-BR l...
  • 90b0a9a fix(isTaxID): improve pt-BR locale by adding support for alphanumeric CNPJ ...
  • Additional commits viewable in compare view

Updates jest from 30.4.2 to 30.5.2

Release notes

Sourced from jest's releases.

v30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)

New Contributors

Full Changelog: jestjs/jest@v30.5.1...v30.5.2

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

v30.5.0

On a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴


This is a big release. It touches jest-runtime, jest-resolve and jest-haste-map in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please open an issue.

Highlights

whenCalledWith

Mock functions can now configure return values per argument list, contributed by @​timkindberg (#16053):

const fn = jest.fn();
fn.whenCalledWith('apple').mockReturnValue('red');
</tr></table> 

... (truncated)

Changelog

Sourced from jest's changelog.

30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (Description has been truncated

Bumps the backend group with 11 updates in the /backend directory:

| Package | From | To |
| --- | --- | --- |
| [@sentry/node](https://github.com/getsentry/sentry-javascript) | `10.68.0` | `10.75.3` |
| [express](https://github.com/expressjs/express) | `4.22.2` | `4.22.3` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.5.2` | `8.7.0` |
| [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs) | `10.9.0` | `10.9.1` |
| [helmet](https://github.com/helmetjs/helmet) | `8.1.0` | `8.3.0` |
| [mysql2](https://github.com/sidorares/node-mysql2) | `3.16.3` | `3.24.4` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `9.0.3` | `9.1.1` |
| [validator](https://github.com/validatorjs/validator.js) | `13.15.26` | `13.15.35` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.2` |
| [prettier](https://github.com/prettier/prettier) | `3.9.1` | `3.9.9` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |



Updates `@sentry/node` from 10.68.0 to 10.75.3
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.68.0...10.75.3)

Updates `express` from 4.22.2 to 4.22.3
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.3/History.md)
- [Commits](expressjs/express@v4.22.2...v4.22.3)

Updates `express-rate-limit` from 8.5.2 to 8.7.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v8.5.2...v8.7.0)

Updates `google-auth-library` from 10.9.0 to 10.9.1
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v10.9.1/core/packages/google-auth-library-nodejs)

Updates `helmet` from 8.1.0 to 8.3.0
- [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md)
- [Commits](helmetjs/helmet@v8.1.0...v8.3.0)

Updates `mysql2` from 3.16.3 to 3.24.4
- [Release notes](https://github.com/sidorares/node-mysql2/releases)
- [Changelog](https://github.com/sidorares/node-mysql2/blob/master/Changelog.md)
- [Commits](sidorares/node-mysql2@v3.16.3...v3.24.4)

Updates `nodemailer` from 9.0.3 to 9.1.1
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v9.0.3...v9.1.1)

Updates `validator` from 13.15.26 to 13.15.35
- [Release notes](https://github.com/validatorjs/validator.js/releases)
- [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md)
- [Commits](validatorjs/validator.js@13.15.26...13.15.35)

Updates `jest` from 30.4.2 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `prettier` from 3.9.1 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.1...3.9.9)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

---
updated-dependencies:
- dependency-name: "@sentry/node"
  dependency-version: 10.75.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend
- dependency-name: express
  dependency-version: 4.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend
- dependency-name: express-rate-limit
  dependency-version: 8.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend
- dependency-name: google-auth-library
  dependency-version: 10.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend
- dependency-name: helmet
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend
- dependency-name: mysql2
  dependency-version: 3.24.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend
- dependency-name: nodemailer
  dependency-version: 9.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend
- dependency-name: validator
  dependency-version: 13.15.35
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
frameset Ready Ready Preview Oct 1, 2026 10:14am UTC

This branch was successfully deployed

1 active deployment
Preview — 0a7633f6 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants