Skip to content

chore(deps): bump the minor-and-patch group with 10 updates - #511

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-e58d0fe1df
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-e58d0fe1df

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 10 updates:

Package From To
lucide-react 1.47.0 1.48.0
next 16.3.5 16.3.6
pg-boss 12.33.4 12.34.0
posthog-js 1.434.7 1.434.13
posthog-node 5.52.5 5.53.0
tsx 4.23.13 4.23.15
eslint-config-next 16.3.5 16.3.6
prettier 3.9.8 3.9.9
typescript-eslint 8.70.0 8.70.1
@rollup/rollup-linux-x64-gnu 4.63.3 4.63.5

Updates lucide-react from 1.47.0 to 1.48.0

Release notes

Sourced from lucide-react's releases.

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Commits

Updates next from 16.3.5 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates pg-boss from 12.33.4 to 12.34.0

Release notes

Sourced from pg-boss's releases.

12.34.0

Schema version: 42, unchanged from 12.33.0

  • redrive() can be filtered by payload, age and id, and previewRedrive() reports what a redrive would do before it does it.
  • redrive() now works on CockroachDB
  • Some test clock fixes

Filtered redrive, and a preview before it runs

redrive() moves jobs out of a dead letter queue and re-creates them on the queue they came from. Until now the only way to narrow it was by source queue, so draining a dead letter queue was all or nothing per source. It now takes three more filters:

  • data: only jobs whose payload contains this object, matched the same way as findJobs()
  • createdBefore: only jobs that arrived in the dead letter queue before this Date
  • ids: only these jobs, by their id in the dead letter queue

createdBefore is also how to drain a fixed set across several calls. Pass one cutoff to every call and jobs dead-lettered while the loop runs are never swept in:

const cutoff = new Date()
let moved
do {
  moved = await boss.redrive('payments-dlq', { data: { tenant: 'acme' }, createdBefore: cutoff, limit: 500 })
} while (moved > 0)

The new previewRedrive() takes the same options (minus limit) and moves nothing. It returns the total, where the jobs would fan out to, and how many a redrive would leave behind because they have no recorded source queue and no destination was given, or their source queue has since been deleted:

const { total, destinations, unroutable } = await boss.previewRedrive('payments-dlq', {
  data: { tenant: 'acme' }
})
// { total: 12431, destinations: [{ name: 'payment-processing', count: 12113 }, { name: 'payment-refunds', count: 310 }], unroutable: 8 }

The preview and the redrive read one shared predicate, so the preview cannot count a job the redrive would skip. What it cannot see is a collision at redrive time: a destination with a singleton or short policy can still drop a job whose key is already taken, exactly as redrive() always has.

Only jobs still waiting in the dead letter queue are candidates, as before. A job the dead letter queue's own workers have failed stays where it is.

redrive() on CockroachDB

redrive() failed on CockroachDB on every call, because it deletes from and inserts into the job table in one statement, which CockroachDB refuses. On CockroachDB the same move now runs as three statements in one transaction, with the same filters, order and limit, so it moves the same jobs.

Fixes

  • A job in a dead letter queue forgot where it came from the first time that queue's own worker failed it. Failing a job deletes and re-inserts it, and the re-insert did not copy sourceName, sourceId, sourceCreatedOn or sourceRetryCount. After that redrive() could not route the job back and left it in place. The re-insert now carries the four fields on PostgreSQL and CockroachDB alike. Jobs that already lost them are not repaired; redrive those with an explicit destination.
  • When two redriven jobs collide on a destination's singleton or short policy, PostgreSQL now keeps the older one. Before, which one survived depended on the physical order of the rows. CockroachDB ignores that ordering when it resolves the conflict, so there either one may be kept.
  • On CockroachDB, update() and updateQueue() failed on every call, because they used jsonb_exists(), which CockroachDB does not have.
  • On CockroachDB, detectSchemaDrift() reported drift on every fresh install, because CockroachDB stores its own rewriting of index definitions and function bodies. On CockroachDB it now reports missing and invalid indexes and functions without comparing their definitions, as it already did for column types, defaults and constraints.
  • On CockroachDB, findJobs() returned integer fields as strings, and no read converted sourceRetryCount. fetch(), getJobById() and findJobs() now all return numbers.
  • TestClock.setTime() moving forward left in-process deadlines, such as handler expiration, behind the database, and the next tick() replayed every skipped interval period, about 43,000 callbacks for a one-day jump. Timers that the jump makes overdue now fire once on the next tick, and intervals keep their period from the new time. A backward jump leaves pending timers alone. setTime() called during a tick now throws instead of losing the jump. Thanks for the PR by @​bhamiltoncx in timgit/pg-boss#922

... (truncated)

Commits
  • e6955e6 chore: release 12.34.0
  • df87e9d versioning
  • 195a0d1 test: cover both redrive paths in each coverage run
  • 721f68e fix: redrive keeps the oldest of two colliding jobs on both paths
  • 6897e95 test: derive every test's schema from its own name, not its describe block
  • e5de5be feat: redrive on CockroachDB
  • d2340a2 fix: keep dead-letter provenance on the distributed fail path too
  • c9bae63 fix: keep dead-letter provenance when a job fails
  • 5507058 feat(proxy): redrive filters and previewRedrive
  • b251550 feat: filter what redrive moves, and preview it first
  • Additional commits viewable in compare view

Updates posthog-js from 1.434.7 to 1.434.13

Release notes

Sourced from posthog-js's releases.

posthog-js@1.434.13

1.434.13

Patch Changes

  • #5098 a7250f0 Thanks @​Piccirello! - Replay loads a recorded font under the replay iframe's content security policy, not the embedding page's. (2026-09-24)

posthog-js@1.434.12

1.434.12

Patch Changes

  • #5073 60bd968 Thanks @​ksvat! - The replayer no longer freezes the tab on a mutation that adds tens of thousands of nodes at once. It now applies a batch of 1,000 or more adds against a detached subtree, so the document updates style and layout once instead of per insert. A recorded batch of 25,746 style elements went from 92 seconds of blocked main thread to 1.5 seconds. (2026-09-23)

posthog-js@1.434.11

1.434.11

Patch Changes

posthog-js@1.434.10

1.434.10

Patch Changes

  • #5060 a9c40ec Thanks @​marandaneto! - Fix SDK initialization when a script loader pre-creates window.posthog as a placeholder object. (2026-09-23)

posthog-js@1.434.9

1.434.9

Patch Changes

  • #4970 708a5f7 Thanks @​Christian2702! - Session replay no longer defers its input setter hooks on zone.js's patched setTimeout. In Angular apps each of those timers ended a zone task and triggered another change detection, so any component writing an input property on every cycle drove the tab into an endless loop at 100% CPU. (2026-09-22)

posthog-js@1.434.8

1.434.8

Patch Changes

  • #5054 36f356d Thanks @​posthog! - fix(dead-clicks): survive a denied property access in Firefox

    Firefox denies property access on a DOM node from another origin or from a realm that was torn down. The detector reads isConnected and nodeType on mutation records and on composed paths, and reads getRootNode on selection endpoints, so the denial escaped the MutationObserver callback and stopped the rest of the batch from refreshing the liveness timestamp. A node that cannot be read is now treated as a node that cannot be inspected. (2026-09-22)

Commits
  • ca0e4bf chore: update versions and lockfile [version bump]
  • a7250f0 fix(replay): load replayed fonts under the replay frame's CSP (#5098)
  • bb884eb chore: update versions and lockfile [version bump]
  • 2bce7b2 fix(ai): preserve Gemini tool-call IDs in captures (#5087)
  • 338d82d chore: update versions and lockfile [version bump]
  • 60bd968 fix(replay): apply huge add mutations against a detached subtree (#5073)
  • f8eaea2 docs: check org membership for public API exemption, point agents to sdk-spec...
  • 4d64b8f ci(node): run v2 harness alongside legacy compliance (#5052)
  • 2eaba2b feat(node): add v2 compliance binding and source-built package validation (#5...
  • 7b3121f chore: update versions and lockfile [version bump]
  • Additional commits viewable in compare view

Updates posthog-node from 5.52.5 to 5.53.0

Release notes

Sourced from posthog-node's releases.

posthog-node@5.53.0

5.53.0

Minor Changes

  • #5050 31dd1ad Thanks @​posthog! - Read a feature flag's evaluation runtime with getFeatureFlagEvaluationRuntime(key) and getFeatureFlagKeysByEvaluationRuntime(runtime) (2026-09-23)

posthog-node@5.52.6

5.52.6

Patch Changes

  • #5078 f4704ac Thanks @​rubychilds! - Honor filters.holdout during local feature flag evaluation. A user in an experiment holdout now receives the holdout-<id> variant instead of being bucketed into a regular variant, matching how the server evaluates the same flag. The holdout is resolved before the release conditions, so a held-out user never reaches the flag's targeting — including when those conditions would have excluded them, so isFeatureEnabled can return true where it previously returned false. Experiments with an active holdout will see variant assignment change for the held-out share of traffic on upgrade, bringing locally evaluated assignments in line with server-evaluated ones. (2026-09-23)
  • Updated dependencies [f4704ac]:
    • @​posthog/core@​1.55.2
Changelog

Sourced from posthog-node's changelog.

5.53.0

Minor Changes

  • #5050 31dd1ad Thanks @​posthog! - Read a feature flag's evaluation runtime with getFeatureFlagEvaluationRuntime(key) and getFeatureFlagKeysByEvaluationRuntime(runtime) (2026-09-23)

5.52.6

Patch Changes

  • #5078 f4704ac Thanks @​rubychilds! - Honor filters.holdout during local feature flag evaluation. A user in an experiment holdout now receives the holdout-<id> variant instead of being bucketed into a regular variant, matching how the server evaluates the same flag. The holdout is resolved before the release conditions, so a held-out user never reaches the flag's targeting — including when those conditions would have excluded them, so isFeatureEnabled can return true where it previously returned false. Experiments with an active holdout will see variant assignment change for the held-out share of traffic on upgrade, bringing locally evaluated assignments in line with server-evaluated ones. (2026-09-23)
  • Updated dependencies [f4704ac]:
    • @​posthog/core@​1.55.2
Commits
  • 7b3121f chore: update versions and lockfile [version bump]
  • 31dd1ad feat(node): expose a flag's evaluation runtime through the SDK (#5050)
  • 0c5557a chore: update versions and lockfile [version bump]
  • f4704ac fix: honor filters.holdout in local flag evaluation (#5078)
  • See full diff in compare view

Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Updates eslint-config-next from 16.3.5 to 16.3.6

Release notes

Sourced from eslint-config-next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates prettier from 3.9.8 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

Commits

Updates typescript-eslint from 8.70.0 to 8.70.1

Release notes

Sourced from typescript-eslint's releases.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)
  • typescript-estree: require string literal import attribute values (#12894)
  • website: prevent playground from breaking down after opening link with the .js file type (#12777)

❤️ Thank You

See GitHub Releases for more information.

... (truncated)

Changelog

Sourced from typescript-eslint's changelog.

8.70.1 (2026-09-21)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates @rollup/rollup-linux-x64-gnu from 4.63.3 to 4.63.5

Release notes

Sourced from @​rollup/rollup-linux-x64-gnu's releases.

v4.63.5

4.63.5

2026-09-24

Bug Fixes

  • Fix an issue where watch mode would hang instead of terminating when closing via Ctrl+C (#6521)
  • Avoid starting overlapping watch mode runs when plugins invalidate files at the wrong time (#6526)
  • Fix many edge cases where watch mode events were not properly emitted to listeners, especially when errors occur (#6526)

Pull Requests

v4.63.4

4.63.4

2026-09-19

Bug Fixes

  • Ensure meta information of the cached module is exposed in shouldTransformCachedModule (#6442)
  • Do not create invalid code if import attribute values contain special characters (#6502)

Pull Requests

Changelog

Sourced from @​rollup/rollup-linux-x64-gnu's changelog.

4.63.5

2026-09-24

Bug Fixes

  • Fix an issue where watch mode would hang instead of terminating when closing via Ctrl+C (#6521)
  • Avoid starting overlapping watch mode runs when plugins invalidate files at the wrong time (#6526)
  • Fix many edge cases where watch mode events were not properly emitted to listeners, especially when errors occur (#6526)

Pull Requests

4.63.4

2026-09-19

Bug Fixes

  • Ensure meta information of the cached module is exposed in shouldTransformCachedModule (#6442)
  • Do not create invalid code if import attribute values contain special characters (#6502)

Pull Requests

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.47.0` | `1.48.0` |
| [next](https://github.com/vercel/next.js) | `16.3.5` | `16.3.6` |
| [pg-boss](https://github.com/timgit/pg-boss) | `12.33.4` | `12.34.0` |
| [posthog-js](https://github.com/PostHog/posthog-js) | `1.434.7` | `1.434.13` |
| [posthog-node](https://github.com/PostHog/posthog-js/tree/HEAD/packages/node) | `5.52.5` | `5.53.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.5` | `16.3.6` |
| [prettier](https://github.com/prettier/prettier) | `3.9.8` | `3.9.9` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.0` | `8.70.1` |
| [@rollup/rollup-linux-x64-gnu](https://github.com/rollup/rollup) | `4.63.3` | `4.63.5` |


Updates `lucide-react` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

Updates `pg-boss` from 12.33.4 to 12.34.0
- [Release notes](https://github.com/timgit/pg-boss/releases)
- [Commits](timgit/pg-boss@12.33.4...12.34.0)

Updates `posthog-js` from 1.434.7 to 1.434.13
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/compare/posthog-js@1.434.7...posthog-js@1.434.13)

Updates `posthog-node` from 5.52.5 to 5.53.0
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/commits/posthog-node@5.53.0/packages/node)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `eslint-config-next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `prettier` from 3.9.8 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.8...3.9.9)

Updates `typescript-eslint` from 8.70.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint)

Updates `@rollup/rollup-linux-x64-gnu` from 4.63.3 to 4.63.5
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.63.3...v4.63.5)

---
updated-dependencies:
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pg-boss
  dependency-version: 12.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: posthog-js
  dependency-version: 1.434.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: posthog-node
  dependency-version: 5.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@rollup/rollup-linux-x64-gnu"
  dependency-version: 4.63.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants