Skip to content

Bump the minor-and-patch group with 9 updates - #42

Merged
cristian-recoseanu merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-4875496a8c
Sep 21, 2026
Merged

cristian-recoseanu merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-4875496a8c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 9 updates:

Package From To
mqtt 5.15.2 5.16.0
yaml 2.9.0 2.9.1
zod 4.6.2 4.6.5
@types/node 26.5.1 26.6.1
@vitest/coverage-v8 5.0.0 5.0.1
dependency-cruiser 18.2.0 18.3.1
fast-check 4.10.0 4.10.1
prettier 3.9.6 3.9.8
vitest 5.0.0 5.0.1

Updates mqtt from 5.15.2 to 5.16.0

Release notes

Sourced from mqtt's releases.

Release 5.16.0

Security

This release fixes six advisories. All are reachable from a malicious or misbehaving broker — or anyone who can inject packets into a cleartext mqtt:// hop — with no special client configuration beyond speaking MQTT 5. Upgrade to 5.16.0; everything <= 5.15.2 is affected, including the v4 line, and there is no backport.

Advisory Severity Impact
GHSA-c8jq-r765-cq7g High An unsolicited MQTT 5 Topic Alias throws an uncaught TypeError in the stream write path — kills the Node process, repeatable on every reconnect.
GHSA-rj8f-4655-cgg2 High A SUBACK with the wrong number of reason codes crashes the process, or silently misreports which topics are subscribed.
GHSA-gfxc-3w7m-8ch4 High CONNACK properties were merged into the caller's own options object. A maximumPacketSize of 1 permanently kills the client, survives reconnects, and escapes to other clients built from the same options.
GHSA-fwrw-4mhv-wxvm High A single unsolicited AUTH packet crashes the process on a default MQTT 5 client. Enhanced authentication did not have to be configured.
GHSA-8phv-jwjm-93rr Medium A duplicate CONNACK re-runs connection setup mid-session: in-flight QoS 1 resent under the same ids, all topics resubscribed, message-id state reset.
GHSA-h8jm-hm87-fqw3 Low The advertised receiveMaximum was ignored for inbound QoS 2, letting a broker grow the incoming store without bound. Reconnecting does not clear it.

Reproduction steps and full analysis stay in the advisories. CVE ids have been requested and will be added here once assigned.

Behaviour changes to check before upgrading

  • options is no longer mutated by a CONNACK. Code that read negotiated values back off options.properties.maximumPacketSize or options.keepalive must use the new client.serverProperties / client.keepalive getters instead.
  • A refused CONNACK now always closes the socket. With reconnectOnConnackError: false (the default) the client previously sat on an open connection and kept delivering message events after telling the application the connection was refused.
  • Protocol violations now drop the connection: a SUBACK reason-code count mismatch, an invalid Topic Alias, an unsolicited or out-of-spec AUTH, and a broker exceeding receiveMaximum on inbound QoS 2 (reason code 0x93). Reconnect stays armed in all cases.
  • An ack that does not answer the command pending on that message id is dropped and reported via error, instead of running the wrong completion path.
  • The unregistered-alias case now emits reason code 0x82 (Protocol Error) instead of 0x94.
  • AUTH reason code 0 ends the exchange successfully; previously it produced an error with an empty reason string.
  • properties.receiveMaximum outside 1..65535, or not an integer, is ignored and 65535 is enforced and advertised instead.
  • The inbound packet-size cap now measures total wire size rather than Remaining Length, so it triggers on packets a few bytes smaller than before.
  • New exports: PacketPump (src/lib/shared.ts), PendingCommand from the entry point.

Reported by @​afldl, @​acorn421 and @​hibrian827. Thanks to all three.

5.16.0 (2026-09-16)

Bug Fixes

Changelog

Sourced from mqtt's changelog.

5.16.0 (2026-09-16)

Bug Fixes

Commits
  • 1019eff chore(release): 5.16.0
  • e53dd6e chore: unbreak release workflow under npm 12 (#2067)
  • ec5bf3e fix: enforce MQTT 5 Receive Maximum for inbound QoS 2 messages (GHSA-h8jm-hm8...
  • 7108ea5 fix: reject a duplicate CONNACK instead of re-running connection setup (GHSA-...
  • b511e7b fix: reject an unsolicited AUTH instead of crashing the process (GHSA-fwrw-4m...
  • 3db16f5 fix: keep broker CONNACK properties out of the user options object (GHSA-gfxc...
  • 46ee23f fix: bounds-check the suback granted array against subscriptions sent (GHSA-r...
  • 7d07757 fix: reject unsolicited MQTT 5 topic alias instead of crashing (GHSA-c8jq-r76...
  • 6e3a676 chore: replace number-allocator with inline Set-based implementation (#2041)
  • See full diff in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates zod from 4.6.2 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit
Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates @types/node from 26.5.1 to 26.6.1

Commits

Updates @vitest/coverage-v8 from 5.0.0 to 5.0.1

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates dependency-cruiser from 18.2.0 to 18.3.1

Release notes

Sourced from dependency-cruiser's releases.

v18.3.1

🐛 fixes

  • aed44794 fix(extract/swc): finds the swc Visitor when bun hands over the default export (#1093) - thanks @​kurovskyiii for raising the issue and providing the fix in the pull request.

👷 maintenance

  • 0b873f48 chore(npm): updates all external devDependencies

v18.3.0

✨ features

  • Updates to the 'baseline' feature
    • feat: makes it possible to update the baseline "shrink-only", so violations that are fixed get removed, but no new ones are added (#1088/ #1091/ #1085)
    • feat(cli): exposes the baseline feature as a regular --baseline option (with same functionality as depcruise-baseline command) (#1084)
    • feat(baseline): when the baseline is updated show how many are new, same or removed (#1079)
    • Thanks to @​yunusdim for the idea(s) to introduce these features.
  • Improvements to processing with the 'swc' compiler
    • ee229c36 feat(extract/swc): adds support for parsing tsx/jsx (#1086) thanks @​JPBuildsRoot for the issue & initial code that led to this feature
    • 2aa2e34e feat(extract/swc): adds support recognizing type-only imports (#1087) thanks @​JPBuildsRoot for raising the issue that led to this feature

👷 maintenance

  • ed21436e/ ceb7d676 build(npm): updates external dependencies
  • 1f28f44a perf(utl): initializes severity translation table only once
  • 88c7cf9e docs: standardizes the command name for running the command to dependency-cruiser (#1083)
  • 9a8a3dd1 chore(doc): marks depcruise-baseline command as deprecated in favor of dependency-cruiser --baseline (#1090)
  • 400553d9 chore(report): takes x-dot-webpage out of experimental and names it dot-webpage (#1089)
Commits
  • 62c78b6 18.3.1
  • 0b873f4 chore(npm): updates all external devDependencies
  • aed4479 fix(extract/swc): finds the swc Visitor when bun hands over the default expor...
  • 5e067a0 18.3.0
  • ceb7d67 build(npm): updates external dependencies
  • 66d9d5c feat(cli): replaces --baseline-shrink-only option with --baseline-mode option...
  • 9a8a3dd chore(doc): marks depcruise-baseline command as deprecated in favor of depend...
  • 400553d chore(report): takes x-dot-webpage out of experimental and names it dot-webpa...
  • 786431a feat(cli): adds --baseline-shrink-only option (#1088)
  • 2aa2e34 feat(extract/swc): adds support recognizing type-only imports (#1087)
  • Additional commits viewable in compare view

Updates fast-check from 4.10.0 to 4.10.1

Release notes

Sourced from fast-check's releases.

Fix fake-timer compatibility in timeout and interrupt plugins

[Code][Diff]

Fixes

  • (PR#7293) Bug: Capture timers for interruptAfterTimeLimit plugin
  • (PR#7282) CI: Temporarily disable documentation updates until v5
  • (PR#7279) Doc: Release note for 4.10.0
Changelog

Sourced from fast-check's changelog.

4.10.1

Fix fake-timer compatibility in timeout and interrupt plugins [Code][Diff]

Fixes

  • (PR#7292) Bug: Capture timer globals for timeout plugin
  • (PR#7293) Bug: Capture timers for interruptAfterTimeLimit plugin
  • (PR#7282) CI: Temporarily disable documentation updates until v5
  • (PR#7279) Doc: Release note for 4.10.0
Commits

Updates prettier from 3.9.6 to 3.9.8

Release notes

Sourced from prettier's releases.

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
  second paragraph at six spaces that wraps
  onto another line here.

<!-- Prettier 3.9.6 -->

 
short first line.
second paragraph at six spaces that wraps
    onto another line here.



<!-- Prettier 3.9.7 -->

 
short first line.
second paragraph at six spaces that wraps
onto another line here.


JavaScript: Fix embedded template literal idempotency (#19725 by @​fisker)

... (truncated)

Commits

Updates vitest from 5.0.0 to 5.0.1

Release notes

Sourced from vitest's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • 03630a5 chore: release v5.0.1 (#11275)
  • a47d790 fix(fakeTimers): force queueMicrotask and nextTick in toNotFake (#11261)
  • 2ce29d5 fix: warn when deprecated deps.optimizer.web is used (#11214)
  • ccd6d05 docs: fix typecheck exclude default in documentation (#11223)
  • 91ab158 fix(doctor): measure vm pools for custom environments (#11212)
  • 23dda73 fix: share the server on self-referencing extends (#11034)
  • 498fbe9 fix: resolve ResolvedConfig exactOptionalPropertyTypes errors (#11175)
  • 115c3f6 fix: correct typos in error message and comments (#11187)
  • 7361465 fix: keep metadata file when clearing the cache (#11199)
  • 972e24b fix(browser): avoid double quotes in config.define (#11198)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [mqtt](https://github.com/mqttjs/MQTT.js) | `5.15.2` | `5.16.0` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [zod](https://github.com/colinhacks/zod) | `4.6.2` | `4.6.5` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.5.1` | `26.6.1` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.0` | `5.0.1` |
| [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) | `18.2.0` | `18.3.1` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.10.0` | `4.10.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.8` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.0` | `5.0.1` |


Updates `mqtt` from 5.15.2 to 5.16.0
- [Release notes](https://github.com/mqttjs/MQTT.js/releases)
- [Changelog](https://github.com/mqttjs/MQTT.js/blob/main/CHANGELOG.md)
- [Commits](mqttjs/MQTT.js@v5.15.2...v5.16.0)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `zod` from 4.6.2 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.6.2...v4.6.5)

Updates `@types/node` from 26.5.1 to 26.6.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/coverage-v8)

Updates `dependency-cruiser` from 18.2.0 to 18.3.1
- [Release notes](https://github.com/sverweij/dependency-cruiser/releases)
- [Changelog](https://github.com/sverweij/dependency-cruiser/blob/main/CHANGELOG.md)
- [Commits](sverweij/dependency-cruiser@v18.2.0...v18.3.1)

Updates `fast-check` from 4.10.0 to 4.10.1
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.1/packages/fast-check)

Updates `prettier` from 3.9.6 to 3.9.8
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.8)

Updates `vitest` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

---
updated-dependencies:
- dependency-name: mqtt
  dependency-version: 5.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dependency-cruiser
  dependency-version: 18.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: fast-check
  dependency-version: 4.10.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: prettier
  dependency-version: 3.9.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 21, 2026
@cristian-recoseanu
cristian-recoseanu merged commit 6bc58e2 into main Sep 21, 2026
2 checks passed
@cristian-recoseanu
cristian-recoseanu deleted the dependabot/npm_and_yarn/minor-and-patch-4875496a8c branch September 21, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant