chore(deps): bump the production-dependencies group with 14 updates - #8
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the production-dependencies group with 14 updates: | Package | From | To | | --- | --- | --- | | [@sentry/cloudflare](https://github.com/getsentry/sentry-javascript) | `8.55.0` | `10.25.0` | | [@sentry/node](https://github.com/getsentry/sentry-javascript) | `8.55.0` | `10.25.0` | | [feedsmith](https://github.com/macieklamberski/feedsmith) | `2.4.0` | `2.5.0` | | [jose](https://github.com/panva/jose) | `6.1.1` | `6.1.2` | | [resend](https://github.com/resend/resend-node) | `6.4.2` | `6.5.0` | | [@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite) | `4.1.16` | `4.1.17` | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.90.6` | `5.90.10` | | [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.134.12` | `1.136.11` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.552.0` | `0.554.0` | | [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.66.0` | `7.66.1` | | [recharts](https://github.com/recharts/recharts) | `2.15.4` | `3.4.1` | | [@sentry/react](https://github.com/getsentry/sentry-javascript) | `8.55.0` | `10.25.0` | | [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.3.1` | `3.4.0` | | [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.1.16` | `4.1.17` | Updates `@sentry/cloudflare` from 8.55.0 to 10.25.0 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@8.55.0...10.25.0) Updates `@sentry/node` from 8.55.0 to 10.25.0 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@8.55.0...10.25.0) Updates `feedsmith` from 2.4.0 to 2.5.0 - [Release notes](https://github.com/macieklamberski/feedsmith/releases) - [Changelog](https://github.com/macieklamberski/feedsmith/blob/main/release.json) - [Commits](macieklamberski/feedsmith@v2.4.0...v2.5.0) Updates `jose` from 6.1.1 to 6.1.2 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](panva/jose@v6.1.1...v6.1.2) Updates `resend` from 6.4.2 to 6.5.0 - [Release notes](https://github.com/resend/resend-node/releases) - [Commits](https://github.com/resend/resend-node/commits) Updates `@tailwindcss/vite` from 4.1.16 to 4.1.17 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.1.17/packages/@tailwindcss-vite) Updates `@tanstack/react-query` from 5.90.6 to 5.90.10 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.90.10/packages/react-query) Updates `@tanstack/react-router` from 1.134.12 to 1.136.11 - [Release notes](https://github.com/TanStack/router/releases) - [Commits](https://github.com/TanStack/router/commits/v1.136.11/packages/react-router) Updates `lucide-react` from 0.552.0 to 0.554.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/0.554.0/packages/lucide-react) Updates `react-hook-form` from 7.66.0 to 7.66.1 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](react-hook-form/react-hook-form@v7.66.0...v7.66.1) Updates `recharts` from 2.15.4 to 3.4.1 - [Release notes](https://github.com/recharts/recharts/releases) - [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md) - [Commits](recharts/recharts@v2.15.4...v3.4.1) Updates `@sentry/react` from 8.55.0 to 10.25.0 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@8.55.0...10.25.0) Updates `tailwind-merge` from 3.3.1 to 3.4.0 - [Release notes](https://github.com/dcastil/tailwind-merge/releases) - [Commits](dcastil/tailwind-merge@v3.3.1...v3.4.0) Updates `tailwindcss` from 4.1.16 to 4.1.17 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.1.17/packages/tailwindcss) --- updated-dependencies: - dependency-name: "@sentry/cloudflare" dependency-version: 10.25.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: "@sentry/node" dependency-version: 10.25.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: feedsmith dependency-version: 2.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: jose dependency-version: 6.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: resend dependency-version: 6.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: "@tailwindcss/vite" dependency-version: 4.1.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@tanstack/react-query" dependency-version: 5.90.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: "@tanstack/react-router" dependency-version: 1.136.11 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: lucide-react dependency-version: 0.554.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: react-hook-form dependency-version: 7.66.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: recharts dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: "@sentry/react" dependency-version: 10.25.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: tailwind-merge dependency-version: 3.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: tailwindcss dependency-version: 4.1.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/production-dependencies-87874ba212
branch
November 22, 2025 08:15
KyleTryon
added a commit
that referenced
this pull request
Nov 26, 2025
This commit implements the remaining Phase 2 improvements from the signup flow security review. ## Issue #8: Configurable Admin Email Verification Bypass ### Database Schema - Add `adminBypassEmailVerification` field to global_settings table - Default value: true (existing behavior preserved) - Location: packages/api/src/db/schema.ts ### Backend - Update GlobalSettings interface with new field - Include default value in settings initialization - Location: packages/api/src/services/global-settings.ts ### Frontend - Route Protection - Check admin bypass setting before allowing access - Fetch global settings for admin users - Log admin bypass events for audit trail - Default to allowing bypass if settings fetch fails - Location: packages/app/src/routes/app/route.tsx ### Frontend - Verification Page - Conditionally show "Continue to App" based on settings - Only display for admins when bypass is enabled - Clear messaging about admin privilege - Location: packages/app/src/routes/verify-email.tsx ### Admin UI - Add toggle control for admin bypass setting - Located in Admin Settings > Registration section - Real-time configuration without code changes - Location: packages/app/src/routes/app/admin/settings.tsx ## Issue #9: Token Cleanup Cron Job ### Handler Implementation - Delete expired verification tokens (>24 hours old) - Keep recently expired tokens for debugging - Emit metrics for monitoring - Sentry monitoring support (Cloudflare Workers) - Location: packages/api/src/cron/handlers.ts ### Scheduler Integration - Node.js: Runs hourly via node-cron - Cloudflare Workers: Runs hourly via scheduled events - Prevents verification table bloat - Location: packages/api/src/cron/scheduler.ts ### Metrics - `cron.tokens_cleaned` - Number of tokens deleted - `cron.token_cleanup_completed` - Success/error tracking - `cron.token_cleanup_duration` - Performance monitoring ## Security Benefits ### Admin Bypass Configuration - Admins can disable bypass for production environments - Enforces verification even for privileged accounts - Audit trail for all bypass events - Configurable without code deployment ### Token Cleanup - Prevents abuse via token table flooding - Maintains database performance - Reduces storage costs - Enables debugging with 24-hour retention ## Testing Manual testing required: - [ ] Toggle admin bypass setting in Admin Settings - [ ] Verify admin redirect when bypass disabled - [ ] Check token cleanup runs hourly - [ ] Verify expired tokens are deleted - [ ] Test audit logging for admin bypass ## Backwards Compatibility Fully backwards compatible: - Default bypass behavior unchanged (enabled) - Existing tokens unaffected by cleanup (only expired) - No migration required for existing deployments ## Documentation Implementation details: - docs/planning/signup-flow-fixes.md - Original plan - docs/implementation/signup-flow-fixes-completed.md - Progress tracking 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the production-dependencies group with 14 updates:
8.55.010.25.08.55.010.25.02.4.02.5.06.1.16.1.26.4.26.5.04.1.164.1.175.90.65.90.101.134.121.136.110.552.00.554.07.66.07.66.12.15.43.4.18.55.010.25.03.3.13.4.04.1.164.1.17Updates
@sentry/cloudflarefrom 8.55.0 to 10.25.0Release notes
Sourced from
@sentry/cloudflare's releases.... (truncated)
Changelog
Sourced from
@sentry/cloudflare's changelog.... (truncated)
Commits
d9cf9a4release: 10.25.0b08235bchore(e2e): Pin@embroider/addon-shimto 1.10.0 for the e2e ember-embroider...dd75ae7chore(test): Use correcttestTimeoutfield in bundler-tests vitest configd5a5009Merge pull request #18166 from getsentry/prepare-release/10.25.0a730d96meta(changelog): Update changelog for 10.25.076fef98feat(metrics): Add missing metric node exports (#18149)b03617afeat(vercel-edge): Add metrics export (#18148)b3e65e0feat(cloudflare): Add metrics exports (#18147)c2a53e7feat(core): Truncate request string inputs in OpenAI integration (#18136)c236db3chore(build): Fix incorrect versions after merge (#18154)Updates
@sentry/nodefrom 8.55.0 to 10.25.0Release notes
Sourced from
@sentry/node's releases.... (truncated)
Changelog
Sourced from
@sentry/node's changelog.... (truncated)
Commits
d9cf9a4release: 10.25.0b08235bchore(e2e): Pin@embroider/addon-shimto 1.10.0 for the e2e ember-embroider...dd75ae7chore(test): Use correcttestTimeoutfield in bundler-tests vitest configd5a5009Merge pull request #18166 from getsentry/prepare-release/10.25.0a730d96meta(changelog): Update changelog for 10.25.076fef98feat(metrics): Add missing metric node exports (#18149)b03617afeat(vercel-edge): Add metrics export (#18148)b3e65e0feat(cloudflare): Add metrics exports (#18147)c2a53e7feat(core): Truncate request string inputs in OpenAI integration (#18136)c236db3chore(build): Fix incorrect versions after merge (#18154)Updates
feedsmithfrom 2.4.0 to 2.5.0Release notes
Sourced from feedsmith's releases.
Commits
7b105a8chore: Bump tsdown versionb65e68fMerge pull request #182 from macieklamberski/feat/limit-options259188frefactor: Simplify the logic of parseArrayOf3bf7688chore: Treat maxItems: -1 as invalid and ignore limiting16d55catest: Add unit and integration tests for the maxItems functionalityafe6cf0feat: Add 'maxItems' option to limit number of parsed itemse690fdfci: Remove dependabot custom prefixesf96eed6chore: Disable language detection in benchmarks/compatibility folders8796a0dchore: Bump tsdown version to 0.16.xa993b4fci: Turn off linting workflow for Dependabot PRsUpdates
josefrom 6.1.1 to 6.1.2Release notes
Sourced from jose's releases.
Changelog
Sourced from jose's changelog.
Commits
f71f270chore(release): 6.1.2901cd90refactor: fallback to checking instanceof for CryptoKey876b853chore: cleanup after releaseUpdates
resendfrom 6.4.2 to 6.5.0Commits
Updates
@tailwindcss/vitefrom 4.1.16 to 4.1.17Release notes
Sourced from
@tailwindcss/vite's releases.Changelog
Sourced from
@tailwindcss/vite's changelog.Commits
e9c9c4fRelease v4.1.17 (#19272)Updates
@tanstack/react-queryfrom 5.90.6 to 5.90.10Release notes
Sourced from
@tanstack/react-query's releases.... (truncated)
Changelog
Sourced from
@tanstack/react-query's changelog.Commits
66a194eci: Version Packages (#9879)6226325ci: Version Packages (#9873)f7c9526ci: Version Packages (#9854)ea0ab4dci: Version Packages (#9848)Updates
@tanstack/react-routerfrom 1.134.12 to 1.136.11Release notes
Sourced from
@tanstack/react-router's releases.... (truncated)
Commits
3a97163release: v1.136.11090bc66release: v1.136.1027d626ffix: handle$"in defaultRenderHandler correctly (#5871)5f0e496release: v1.136.9875d1d4fix: script streaming (#5895)cf73030release: v1.136.8c983648release: v1.136.6cdd2de3release: v1.136.5f39eb9brefactor(router-core): Process routeTree into segment tree instead of flatRou...ccf5483release: v1.136.4Updates
lucide-reactfrom 0.552.0 to 0.554.0Release notes
Sourced from lucide-react's releases.
Commits
80d6f73fix(icons): Rename fingerprint icon to fingerprint-pattern (#3767)Updates
react-hook-formfrom 7.66.0 to 7.66.1Release notes
Sourced from react-hook-form's releases.
Commits
caa514c7.66.1d13be6a⚡ perf: reduce redundant property access in getDirtyFields (#13146)6800ba9❤️ thank you so much thanks.dev for sponsoring the project!932c957🐞 fix(createFormControl): skip setValid() during batch array updates (#13140)fb6423f🐞 fix(useForm): recompute isValid after reset when values update asynchronous...4922698🐞 fix(deepEqual): handle NaN comparison correctly using Object.is (#13120)67770d3🫧 chore: add eslint cache in package.json (#13117)2596e5e🔩 chore: upgrade dev deps (#13116)Updates
rechartsfrom 2.15.4 to 3.4.1Release notes
Sourced from recharts's releases.
... (truncated)
Commits
6d96b11feat: export DefaultZIndexes and ZIndexLayer (#6599)ca65afbchore: upgrade recharts in www (#6598)f07abc73.4.0 (#6596)e297522Remove and rename all remaining documented but not existing props (#6594)59d5d38Fix stacked Bar animation (#6593)26e0e31Stop passing NaN as a DOM attribute (#6595)96da90bRemove more non-existent props from documentation (#6590)7a4bcc5Add margin support to Sankey and remove the doc from sunburst (#6589)9f47369Fix missing React key warning in CartesianGrid (#6591)037fc28Allow extending domain if ReferenceLine is defined by segment (#6592)Updates
@sentry/reactfrom 8.55.0 to 10.25.0Release notes
Sourced from
@sentry/react's releases.