Skip to content

chore(deps): bump the patch-updates group across 1 directory with 3 updates - #1772

Open
dependabot[bot] wants to merge 86 commits into
mainfrom
dependabot/npm_and_yarn/main/patch-updates-86a76ed6ac
Open

dependabot[bot] wants to merge 86 commits into
mainfrom
dependabot/npm_and_yarn/main/patch-updates-86a76ed6ac

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-updates group with 3 updates in the / directory: socket.io-client, ts-jest and engine.io-client.

Updates socket.io-client from 4.8.3 to 4.8.4

Release notes

Sourced from socket.io-client's releases.

socket.io-client@4.8.4

Bug Fixes

  • types: export ExtendedError for connect_error event (#5548) (c0d5450)
  • types: export reserved event interfaces (#5533) (03945df)

Dependencies

Commits
  • 11a6f56 chore(release): socket.io-client@4.8.4
  • 00e4e73 chore(release): engine.io-client@6.6.7
  • e387ab1 chore: use @​rollup/plugin-terser instead of rollup-plugin-terser
  • 9738333 chore(release): engine.io@6.6.11
  • fc9dd90 docs(eio): rework README
  • da008a5 fix(eio): refresh ping timeout on incoming packets
  • 3df3fed fix(eio-client): restore default transport resolution
  • aaf2af3 test: upgrade WebdriverIO to v9
  • b5da079 refactor(sio): simplify packet handling switch
  • 45873ca docs(protocol): clarify namespace comma restriction for built-in parser (#5545)
  • Additional commits viewable in compare view

Updates ts-jest from 29.4.12 to 29.4.14

Release notes

Sourced from ts-jest's releases.

v29.4.14

Please refer to CHANGELOG.md for details.

v29.4.13

Please refer to CHANGELOG.md for details.

Changelog

Sourced from ts-jest's changelog.

29.4.14 (2026-09-25)

Reverts

29.4.13 (2026-09-22)

Features

Performance Improvements

Commits
  • 2d152f6 chore(release): 29.4.14
  • 01e5a2e revert: bring back prior changes of compiler util (#5471)
  • 8e35da6 build(deps): update dependency typescript-eslint to ^8.70.1
  • 76ec454 build(deps): bump image-size from 2.0.2 to 2.0.4 in /website
  • a0c364f chore(release): 29.4.13
  • 697d337 perf(compiler): cache module resolution modes (#5419)
  • c3a0b57 feat: support Babel 8 (#5466)
  • 5fb44c4 build(deps): update dependency jest-environment-jsdom to ^30.5.2
  • 257a524 build(deps): update dependency jest to v30.5.2
  • 89ba4d9 build(deps): update dependency babel-jest to ^30.5.2
  • Additional commits viewable in compare view

Updates engine.io-client from 6.6.6 to 6.6.7

Release notes

Sourced from engine.io-client's releases.

engine.io-client@6.6.7

Bug Fixes

  • types: export reserved event interfaces (#5533) (ced7dfd)
  • restore default transport resolution (3df3fed)

Dependencies

Commits
  • 00e4e73 chore(release): engine.io-client@6.6.7
  • e387ab1 chore: use @​rollup/plugin-terser instead of rollup-plugin-terser
  • 9738333 chore(release): engine.io@6.6.11
  • fc9dd90 docs(eio): rework README
  • da008a5 fix(eio): refresh ping timeout on incoming packets
  • 3df3fed fix(eio-client): restore default transport resolution
  • aaf2af3 test: upgrade WebdriverIO to v9
  • b5da079 refactor(sio): simplify packet handling switch
  • 45873ca docs(protocol): clarify namespace comma restriction for built-in parser (#5545)
  • 551a3dc test: use execFile for fixture scripts (#5549)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

sujitaw and others added 30 commits June 16, 2026 13:57
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 7.0.13 to 9.0.1.
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v7.0.13...v9.0.1)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 9.0.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Fix: successful response for empty attributes when creating shortening URLs
* empty attribute response

Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>

* match issuance pattern

Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>

---------

Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>
Co-authored-by: M Abdullah <insights.abdullah@gmail.com>
Bumps [body-parser](https://github.com/expressjs/body-parser) from 1.20.5 to 1.20.6.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.5...1.20.6)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 1.20.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typeorm](https://github.com/typeorm/typeorm) from 0.3.28 to 0.3.31.
- [Release notes](https://github.com/typeorm/typeorm/releases)
- [Changelog](https://github.com/typeorm/typeorm/blob/0.3.31/CHANGELOG.md)
- [Commits](typeorm/typeorm@0.3.28...0.3.31)

---
updated-dependencies:
- dependency-name: typeorm
  dependency-version: 0.3.31
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Bumps redis from 6.2-alpine to 8.0-alpine.

---
updated-dependencies:
- dependency-name: redis
  dependency-version: 8.0-alpine
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…redis-8.0-alpine

build: bump redis from 6.2-alpine to 8.0-alpine
…-0.3.31

chore(deps): bump typeorm from 0.3.28 to 0.3.31
shitrerohit and others added 25 commits August 24, 2026 17:27
Signed-off-by: shitrerohit <rohit.shitre@ayanworks.com>
…ion handling

Signed-off-by: shitrerohit <rohit.shitre@ayanworks.com>
…response

fix: update invitation creation to return org_invitations array
* fix: redirect swagger fixed

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

* fix: set env var to expose swagger endpoint

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

* fix: fix redirect status and bool check

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

* chore: add env var on .env.demo

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

---------

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>
Signed-off-by: João  Victor B Miraya <108498460+joaoMiraya@users.noreply.github.com>
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4.3.0 to 6.0.10.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@b906aff...0977fd9)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.0.10
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 9.0.5 to 9.1.1.
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v9.0.5...v9.1.1)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 9.1.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.3 to 6.16.0.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.3...v6.16.0)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Add unit coverage for CommonService error translation (handleCommonErrors,
sendError, filterResponse) and extend the integration suite with real
PATCH/PUT/DELETE, 4xx error mapping, and proxy/NO_PROXY cases, so the
axios 1.20 backed HTTP client is guarded in CI. Remove the now-healthy
common.service.spec from the jest CI exclusion list.

Fix sendError() throwing a TypeError when error.response is undefined by
using optional chaining, falling back to a 500 HttpException.

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
Bumps [axios](https://github.com/axios/axios) from 0.26.1 to 1.20.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v0.26.1...v1.20.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Guard all error dereferences in sendError so an undefined argument does
not throw a TypeError before the 500 fallback. Add a regression test for
service.sendError(undefined). Addresses CodeRabbit feedback on #1742.

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
Address all 7 SonarQube security hotspots reported on main:

- typescript:S5332 (2): use https:// in the @ApiProperty examples of
  configure-base-wallet.dto.ts and update-revocation-registry.dto.ts
- githubactions:S7637 (4): pin setup-qemu-action, setup-buildx-action,
  login-action and build-push-action to full commit SHAs instead of
  mutable v3/v6 tags
- docker:S6470 (1): expand .dockerignore to exclude version control,
  local env/secrets (agent.env, .env*), build artifacts and docs so the
  recursive COPY in Dockerfile.seed no longer risks leaking sensitive data

Also add a local eslint-disable-next-line camelcase for the intentionally
snake-cased revoc_reg_id contract field which was blocking the pre-commit
hook.

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
…first

Signed-off-by: shitrerohit <rohit.shitre@ayanworks.com>
…tion

fix(invitation): update logic to fetch last invitationDid instead of first
Bumps the minor-actions group with 1 update: [pnpm/action-setup](https://github.com/pnpm/action-setup).


Updates `pnpm/action-setup` from 6.0.10 to 6.1.0
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@0977fd9...ea17c68)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.12.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@8d2750c...37fe631)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6.19.2 to 7.3.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@10e90e3...53b7df9)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 3.7.0 to 4.6.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@c94ce9f...dbcb813)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3.7.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@c7c5346...1f40c72)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the patch-updates group with 1 update: [morgan](https://github.com/expressjs/morgan).


Updates `morgan` from 1.12.0 to 1.12.1
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.12.0...1.12.1)

---
updated-dependencies:
- dependency-name: morgan
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-actions group with 3 updates: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [docker/build-push-action](https://github.com/docker/build-push-action).


Updates `docker/setup-qemu-action` from 4.3.0 to 4.4.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@1f40c72...9901266)

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@37fe631...f87e599)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@53b7df9...c3c9e26)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [multer](https://github.com/expressjs/multer) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v2.3.0...v2.4.0)

---
updated-dependencies:
- dependency-name: multer
  dependency-version: 2.4.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…pdates

Bumps the patch-updates group with 3 updates in the / directory: [socket.io-client](https://github.com/socketio/socket.io), [ts-jest](https://github.com/kulshekhar/ts-jest) and [engine.io-client](https://github.com/socketio/socket.io).


Updates `socket.io-client` from 4.8.3 to 4.8.4
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-client@4.8.3...socket.io-client@4.8.4)

Updates `ts-jest` from 29.4.12 to 29.4.14
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.14)

Updates `engine.io-client` from 6.6.6 to 6.6.7
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/engine.io-client@6.6.6...engine.io-client@6.6.7)

---
updated-dependencies:
- dependency-name: socket.io-client
  dependency-version: 4.8.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: ts-jest
  dependency-version: 29.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: engine.io-client
  dependency-version: 6.6.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: pnpm. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 41b8ff93-fa1b-4cc8-b95b-e4c8820f64d2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants