Skip to content

deps(deps): bump the minor-and-patch group with 8 updates - #238

Merged
Divkix merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-508e373e1f
Oct 6, 2026
Merged

Divkix merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-508e373e1f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 8 updates:

Package From To
@lucide/svelte 1.48.0 1.50.0
better-auth 1.7.6 1.7.7
layerchart 2.5.0 2.5.1
@types/node 26.6.2 26.6.4
bits-ui 2.19.3 2.19.4
knip 6.38.0 6.39.0
@size-limit/preset-small-lib 14.0.1 14.1.0
size-limit 14.0.1 14.1.0

Updates @lucide/svelte from 1.48.0 to 1.50.0

Release notes

Sourced from @​lucide/svelte's releases.

Version 1.50.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.49.0...1.50.0

Version 1.49.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.48.0...1.49.0

Commits

Updates better-auth from 1.7.6 to 1.7.7

Release notes

Sourced from better-auth's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

Changelog

Sourced from better-auth's changelog.

1.7.7

Patch Changes

  • #11476 4186e36 Thanks @​bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.

  • #11469 8620aa9 Thanks @​aryan1306! - Return rate limit errors with a JSON Content-Type header.

  • #11491 55cb92e Thanks @​bytaesu! - Respect social provider disableSignUp when signing in with an ID token.

  • #11375 69defbc Thanks @​bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. The oAuthProxy options and supported configuration remain unchanged.

    Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. Magic Link records and database-backed OAuth or SAML state use separate verification identifier prefixes. Links and database-backed sign-ins started before the upgrade cannot complete; request new Magic Links and restart those sign-ins. Upgrade servers sharing verification storage together, and update verification.storeIdentifier.overrides rules for these flows to match the new magic-link: and auth-state: prefixes. The link token, callback state, endpoints, and public option types are unchanged.

    Upgrade installed Better Auth adapters, plugins, and integrations released with better-auth alongside it so participating packages use the same release version.

  • Updated dependencies [35d7cd3, 07bdf7e]:

    • @​better-auth/drizzle-adapter@​1.7.7
    • @​better-auth/kysely-adapter@​1.7.7
    • @​better-auth/core@​1.7.7
    • @​better-auth/memory-adapter@​1.7.7
    • @​better-auth/mongo-adapter@​1.7.7
    • @​better-auth/prisma-adapter@​1.7.7
    • @​better-auth/telemetry@​1.7.7
Commits
  • db02f23 chore: release v1.7.7 (#11413)
  • ac54bfd fix(auth): isolate verification records and encryption purposes (#11494)
  • 69defbc fix(organization): refresh active organization after email sign-in (#11375)
  • 55cb92e fix(auth): honor social disableSignUp for ID token sign-in (#11491)
  • 4186e36 fix(captcha): return JSON content type for errors (#11476)
  • 8620aa9 fix(rate-limit): set JSON content type on 429 responses (#11469)
  • See full diff in compare view

Updates layerchart from 2.5.0 to 2.5.1

Release notes

Sourced from layerchart's releases.

layerchart@2.5.1

Patch Changes

  • fix(Tooltip): Keep a flipped tooltip inside the container (or window) when flipping overflows the other edge (ex. a start-aligned tooltip wider than half a narrow chart opened past its left edge) (#924)

  • fix(TooltipContext): Keep a tooltip locked from onclick on touch (a tap's pointerleave precedes click, and its pending hide cleared the data under the lock), and hide it once unlocked if the pointer left while locked (#924)

Commits
  • 3f46fab Merge pull request #925 from techniq/changeset-release/main
  • c1ea521 Version Packages
  • 72a86ba Merge pull request #924 from ntainy/fix/tooltip-lock-and-clamp
  • 3ee9f28 fix(Tooltip): Keep a flipped tooltip inside the container when flipping overf...
  • 613675f fix(TooltipContext): Keep a tooltip locked from onclick on touch, and hide ...
  • ddceba2 docs: add npmchart and Sandraviz to showcase (#920)
  • 8a571e5 Merge pull request #911 from techniq/chore/update-bundle-baseline
  • 3941e58 Merge pull request #912 from techniq/chore/update-visual-baseline
  • 44e025f chore: update visual regression baseline
  • 3bfeaf2 chore: update bundle size baseline
  • See full diff in compare view

Updates @types/node from 26.6.2 to 26.6.4

Commits

Updates bits-ui from 2.19.3 to 2.19.4

Release notes

Sourced from bits-ui's releases.

bits-ui@2.19.4

Patch Changes

  • fix(PopperLayer): destructure the internal forceMount prop out of restProps so it stops leaking onto the rendered content element as an invalid forcemount attribute (Popover, Select, Combobox, DropdownMenu, ContextMenu, Menubar, Tooltip, LinkPreview) (#2176)

  • fix(DismissibleLayer): dismiss on a touch tap even when the tapped element stops click propagation. Touch outside-dismissal waits for the tap's click on the document, and a bubbling listener never hears a click whose target handler calls stopPropagation(), so the layer stayed open behind elements that own their clicks. (#2155)

Commits
  • cdf337d Version Packages (#2177)
  • 9576fb2 fix(DismissibleLayer): dismiss on a touch tap whose target stops click propag...
  • c9201cf fix(PopperLayer): don't render the internal forceMount prop as a DOM attrib...
  • See full diff in compare view

Updates knip from 6.38.0 to 6.39.0

Release notes

Sourced from knip's releases.

Release 6.39.0

  • Add Railway plugin (#2026) (6da55767eb419701dd32f93789a00e8bdc915276) - thanks @​jonahsnider!
  • Update query snapshot (8877d3cf35943e17a617e1197fa46c5a43342479)
  • Fix excluded tags on entry re-exports (#2062) (b22e27543cb8dd4ba7ec97c70ccfd06bc8f16614) - thanks @​devYRPauli!
  • Update rolldown snapshot (3a45c806e1c1b7ceb078903652c8631566400096)
  • Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067) (d912d807e41f140bbc79bafce6882b3c05dec6ff) - thanks @​bytedoe!
  • fix(angular): keep other projects' inputs when one has no architect (#2064) (af3f42e9772e9937fd71b7557d3b54aee1db339a) - thanks @​Cayan!
  • fix(vite): resolve nested HTML entry points in multi-page apps (#1988) (4648aefe56e7bac521bb6f17189473b46f8ff00f) - thanks @​DreamLongYT!
  • Improve Rstest plugin support (#2068) (add87992e9dfe2f3c22e4c6ba7fa257d7f0151cf) - thanks @​fi3ework!
  • Handle profiles, formatters and require paths in Cucumber plugin (#2065) (2ad39fcf02e067b4bdfc06a658bf4bf5abeea764) - thanks @​giaBaoJS!
  • fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076) (7060bb968339680d694275413aba2833e4521ed9) - thanks @​alokn!
  • fix: read entry export tags under the re-exported names (#2069) (1698683df95a96b3515795eb664aacf030042d7b) - thanks @​devYRPauli!
Commits
  • ed30e5b Release knip@6.39.0
  • 1698683 fix: read entry export tags under the re-exported names (#2069)
  • 7060bb9 fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076)
  • 2ad39fc Handle profiles, formatters and require paths in Cucumber plugin (#2065)
  • add8799 Improve Rstest plugin support (#2068)
  • 4648aef fix(vite): resolve nested HTML entry points in multi-page apps (#1988)
  • af3f42e fix(angular): keep other projects' inputs when one has no architect (#2064)
  • d912d80 Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067)
  • b22e275 Fix excluded tags on entry re-exports (#2062)
  • 6da5576 Add Railway plugin (#2026)
  • See full diff in compare view

Updates @size-limit/preset-small-lib from 14.0.1 to 14.1.0

Release notes

Sourced from @​size-limit/preset-small-lib's releases.

14.1.0

Changelog

Sourced from @​size-limit/preset-small-lib's changelog.

14.1.0

Commits
  • 17a37d8 Release 14.1.0 version
  • ded9dca Update dependencies
  • 0a8011b Warn when saved bundles from multiple checks may overwrite (#403)
  • 0c07513 feat: optionally skip configured checks with no matching files (#402)
  • See full diff in compare view

Updates size-limit from 14.0.1 to 14.1.0

Release notes

Sourced from size-limit's releases.

14.1.0

Changelog

Sourced from size-limit's changelog.

14.1.0

Commits
  • 17a37d8 Release 14.1.0 version
  • ded9dca Update dependencies
  • 0a8011b Warn when saved bundles from multiple checks may overwrite (#403)
  • 0c07513 feat: optionally skip configured checks with no matching files (#402)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [@lucide/svelte](https://github.com/lucide-icons/lucide/tree/HEAD/packages/svelte) | `1.48.0` | `1.50.0` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.6` | `1.7.7` |
| [layerchart](https://github.com/techniq/layerchart) | `2.5.0` | `2.5.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.2` | `26.6.4` |
| [bits-ui](https://github.com/huntabyte/bits-ui) | `2.19.3` | `2.19.4` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.38.0` | `6.39.0` |
| [@size-limit/preset-small-lib](https://github.com/ai/size-limit) | `14.0.1` | `14.1.0` |
| [size-limit](https://github.com/ai/size-limit) | `14.0.1` | `14.1.0` |


Updates `@lucide/svelte` from 1.48.0 to 1.50.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.50.0/packages/svelte)

Updates `better-auth` from 1.7.6 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/better-auth)

Updates `layerchart` from 2.5.0 to 2.5.1
- [Release notes](https://github.com/techniq/layerchart/releases)
- [Commits](https://github.com/techniq/layerchart/compare/layerchart@2.5.0...layerchart@2.5.1)

Updates `@types/node` from 26.6.2 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `bits-ui` from 2.19.3 to 2.19.4
- [Release notes](https://github.com/huntabyte/bits-ui/releases)
- [Commits](https://github.com/huntabyte/bits-ui/compare/bits-ui@2.19.3...bits-ui@2.19.4)

Updates `knip` from 6.38.0 to 6.39.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.39.0/packages/knip)

Updates `@size-limit/preset-small-lib` from 14.0.1 to 14.1.0
- [Release notes](https://github.com/ai/size-limit/releases)
- [Changelog](https://github.com/ai/size-limit/blob/main/CHANGELOG.md)
- [Commits](ai/size-limit@14.0.1...14.1.0)

Updates `size-limit` from 14.0.1 to 14.1.0
- [Release notes](https://github.com/ai/size-limit/releases)
- [Changelog](https://github.com/ai/size-limit/blob/main/CHANGELOG.md)
- [Commits](ai/size-limit@14.0.1...14.1.0)

---
updated-dependencies:
- dependency-name: "@lucide/svelte"
  dependency-version: 1.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: better-auth
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: layerchart
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: bits-ui
  dependency-version: 2.19.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: knip
  dependency-version: 6.39.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@size-limit/preset-small-lib"
  dependency-version: 14.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: size-limit
  dependency-version: 14.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: pnpm. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@Divkix
Divkix merged commit 9ddd798 into main Oct 6, 2026
41 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/minor-and-patch-508e373e1f branch October 6, 2026 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant