From c0a815339f0f66a6f90d95d89b4ed7ef858d6983 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 3 Sep 2026 08:19:15 -0700
Subject: [PATCH 1/7] chore(deps): bump mermaid from 11.16.1 to 11.17.2
(#12569)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.16.1 to
11.17.2.
Release notes
Sourced from mermaid's
releases.
mermaid@11.17.2
Patch Changes
- #8125
178d7c7
Thanks @knsv-bot! - fix:
restore the edgePaths class on the edge group in rendered
SVG, and point the flowchart, block and user journey stylesheets at
it
mermaid@11.17.1
Patch Changes
-
#8092
31ce60a
Thanks @pbrolin47! -
fix(c4): wrap element labels to c4.width again
C4 element labels (System, Container,
Component, Person and their _Ext
variants) stopped wrapping in 11.17.0, so long descriptions rendered on
one unbroken line and the shape grew sideways well past the configured
c4.width. The unified-shapes label helper gated wrapping on
the root-level wrap option, which has no schema default and
is therefore undefined; it now gates on
c4.wrap (default true), which is what the
legacy renderer used.
-
#8088
c66200b
Thanks @ashishjain0512!
- fix: neo-look arrowheads and crow's-foot markers no longer fall back
to default theme colours/stroke widths on the first render with
layout: elk. State diagram arrowheads stayed dark on dark
themes, and ER / requirement markers were drawn at the default stroke
width, because markers were created from the layout package's own
bundled copy of mermaid, whose config had not been initialized yet.
-
#8079
281cd7b
Thanks @ashishjain0512!
- fix(class): class diagram relation markers (composition, aggregation,
extension, dependency, lollipop) no longer scale with the edge stroke
width, so they stay outside the class box boundary in themes that set
strokeWidth: 2 (redux,
redux-dark, redux-color,
redux-dark-color, neo, neo-dark)
with the default classic look.
mermaid@11.17.0
Minor Changes
-
#7842
3670b4e
Thanks @filipsajdak! -
feat(c4): render C4 elements through the unified shape system, using the
new person shape
-
#7812
cdfc0ea
Thanks @knsv-bot! -
feat(class): route classDiagram to the unified (v2)
renderer by default
Set class: { defaultRenderer: 'dagre-d3' } in the config
to restore the legacy renderer.
-
#7785
c45cde9
Thanks @knsv-bot! -
feat(flowchart): add collapsible flowchart subgraphs via
subgraphId@{ view: collapsed }
-
#7828
8eb3afc
Thanks @knsv-bot! -
feat(elk): add elk.keepEntryNodeOnTop config option to keep
a recursive flow's entry node on top
-
#7803
74e44eb
Thanks @knsv-bot! -
feat(elk): add elk.nodePlacementAlignment config option
-
#7792
ea55b31
Thanks @RodrigojndSantos!
- feat(er): add subgraph support to ER diagrams.
-
#7970
a2c0fb6
Thanks @filipsajdak! -
feat(flowchart): add folder, bucket,
console (terminal window) and browser
shapes
-
#7842
ae3e115
Thanks @filipsajdak! -
feat(flowchart): add person shape (circular head above a
rounded body), usable in flowcharts via A@{ shape: person
}
-
#7724
0fd7a9f
Thanks @xdumaine! -
feat(xyChart): add legends for named line and bar series
Patch Changes
-
#7847
215fe89
Thanks @filipsajdak! -
fix(c4): named attributes such as $tags, $link
and $sprite are no longer clobbered to undefined when they
arrive in an earlier positional slot of
Person/System/Container/Component/Boundary/Rel statements.
-
#7871
8d874c4
Thanks @knsv-bot! -
fix(flowchart): stop dagre layout from spamming warn-level
logs on every node/edge/cluster
-
#8071
b3d1f63
Thanks @pbrolin47! -
fix(block): sibling blocks overlapping in block diagrams when one has a
label wider than 200px
-
#7870
71b8843
Thanks @knsv-bot! - fix: a
RangeError: Invalid array length crash when rendering
certain edges.
-
#7924
9cbef5d
Thanks @nightt5879! -
fix(treeView): icons disappearing after strict security
sanitization.
... (truncated)
Commits
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
pnpm-lock.yaml | 92 ++++++++++++++++++++++++++++++-------------------
ui/package.json | 2 +-
2 files changed, 57 insertions(+), 37 deletions(-)
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index a3904c2d24..868d13c27f 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -1102,8 +1102,8 @@ importers:
specifier: ^1.32.0
version: 1.32.0(react@19.2.8)
mermaid:
- specifier: ^11.16.1
- version: 11.16.1
+ specifier: ^11.17.2
+ version: 11.17.2
motion:
specifier: ^12.42.2
version: 12.43.0(react-dom@19.2.8(react@19.2.8))(react@19.2.8)
@@ -2904,8 +2904,8 @@ packages:
react: ^19.2.8
react-dom: ^19.2.8
- '@mermaid-js/parser@1.2.0':
- resolution: {integrity: sha512-oYPyv8A4As1yH5Bx+04iQEQxXuIQDe0GKCNSRgao6z8AM9jixXIfP0vsppRLvGf+nKIOb9/LdpWA4YuJiVvESA==}
+ '@mermaid-js/parser@1.2.1':
+ resolution: {integrity: sha512-n12NohV3mrUyUL2o93IgG/ifeW9FTyeJn3zDxkhwa8MJ9Fxg3HQMlA3RiGmD/3UnJvheztkjjQAjA2T4LmUcpw==}
'@modelcontextprotocol/sdk@1.30.0':
resolution: {integrity: sha512-xKd8OIzlqNzcqcNumGAa6g+PW2kjD5vrpcKOnfldAUPP3j7lnqMPwlTXQm8gF+UwH72z0lqaRbjr9hqGz0eITA==}
@@ -4817,8 +4817,8 @@ packages:
'@types/d3-selection@3.0.11':
resolution: {integrity: sha512-bhAXu23DJWsrI45xafYpkQ4NtcKMwWnAC/vKrd2l+nxMFuvOT3XMYTIj2opv8vq8AO5Yh7Qac/nSeP/3zjTK0w==}
- '@types/d3-shape@3.1.8':
- resolution: {integrity: sha512-lae0iWfcDeR7qt7rA88BNiqdvPS5pFVPpo5OfjElwNaT2yyekbM0C9vK+yqBqEmHr6lDkRnYNoTBYlAgJa7a4w==}
+ '@types/d3-shape@3.2.0':
+ resolution: {integrity: sha512-kVd74ta9eof3eJOvbNd1vGKS/XERRyQbT26Og63hIsvDO84cjD5gEOhsXf26w3FSoNlPVz84DOFcKv/oou+fMw==}
'@types/d3-time-format@4.0.3':
resolution: {integrity: sha512-5xg9rC+wWL8kdDj153qZcsJ0FWiFt0J5RB6LYUNZjwSnesfblqrI/bJ1wBdJ8OQfncgbJG5+2F+qfqnqyzYxyg==}
@@ -5692,8 +5692,8 @@ packages:
peerDependencies:
cytoscape: ^3.2.0
- cytoscape@3.34.1:
- resolution: {integrity: sha512-Lr0RvH9H75y9ar8h9Toy6u4lxRSCcxUq+hHcQ26sVWo6BnaQp1gwEZOYqwuYTZhyW7npyKnNLP8oJ2p1/3OZ7g==}
+ cytoscape@3.34.2:
+ resolution: {integrity: sha512-Cm2jaj1X/PBNlzV9yH8zcfGOxO7U+CJ/+mxSBVPSchLaugdp4jtlGx5qaHtPRZ6tgiZ5P+o1XoRfJA+ba6KM3g==}
engines: {node: '>=0.10'}
d3-array@2.12.1:
@@ -5849,8 +5849,8 @@ packages:
dateformat@4.6.3:
resolution: {integrity: sha512-2P0p0pFGzHS5EMnhdxQi7aJN+iMheud0UhG4dlE1DLAlvL8JHjJJTX/CSm4JXwV0Ka5nGk3zC5mcb5bUQUxxMA==}
- dayjs@1.11.21:
- resolution: {integrity: sha512-98IT+HOahAisibz/yjKbzuOBwYcjJ7BCLPzARyHiyEBmRz4fatF+KPJszEHXsGYjUG234aH/cOjW1wwTbKUZlA==}
+ dayjs@1.11.23:
+ resolution: {integrity: sha512-QDTCU0M0MxR3hQfnlDJfwekQiaanm1ubOD231u73WBckQ/fsamwRLiE2GBz6D3a/xF1NgfiDLJjXBa1hYOYTtQ==}
debug@4.4.3:
resolution: {integrity: sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==}
@@ -5944,6 +5944,9 @@ packages:
dompurify@3.4.13:
resolution: {integrity: sha512-2vmYIoqjze2d+kakP8S/nS5shfsl587kzwEjcGlTdiksUVgFHnFCsLYDVj/JNqJVOQZGSYBTmuycv0PodwmnMQ==}
+ dompurify@3.4.14:
+ resolution: {integrity: sha512-dVoH9z+MY+C9IilgGCk3YfFqjLi3fChm2OiKJMzh6axrJ5qwxqWaZamgmHrpv22CN/KdbZJuGEGgfQoL00LTdg==}
+
dotenv@17.4.2:
resolution: {integrity: sha512-nI4U3TottKAcAD9LLud4Cb7b2QztQMUEfHbvhTH09bqXTxnSie8WnjPALV/WMCrJZ6UV/qHJ6L03OqO3LcdYZw==}
engines: {node: '>=12'}
@@ -6116,8 +6119,8 @@ packages:
resolution: {integrity: sha512-j6vWzfrGVfyXxge+O0x5sh6cvxAog0a/4Rdd2K36zCMV5eJ+/+tOAngRO8cODMNWbVRdVlmGZQL2YS3yR8bIUA==}
engines: {node: '>= 0.4'}
- es-toolkit@1.50.0:
- resolution: {integrity: sha512-OyZKhUVvEep9ITEiwHn8GKnMRQIVqoSIX7WnRbkWgJkllCujilqP2rD0u979tkl8wqyc8ICwlc1UBVv/Sl1G6w==}
+ es-toolkit@1.52.0:
+ resolution: {integrity: sha512-XTNEJQh1tY1ZJVcf6ayP/2n4ZPyaHlW2FWs7xvw5ddPuhUVjLD3olQVQS7kf58JbAB48iL0uL/jerTrjtV3lDA==}
esbuild@0.18.20:
resolution: {integrity: sha512-ceqxoedUrcayh7Y7ZX6NdbbDzGROiyVBgC4PriJThBKSVPWnnFHZAkfI1lJT8QFkOwH4qOS2SJkS4wvpGl8BpA==}
@@ -6229,6 +6232,9 @@ packages:
fast-wrap-ansi@0.2.2:
resolution: {integrity: sha512-7F2Fl+TjRSenLqlU3UjSH0iyqopqoZIu7eZVpEirP2g1GtWa2G/ecEmBdgz31+Mxr+ELclgg6sokpSFIQiZ02Q==}
+ fastdom@1.0.12:
+ resolution: {integrity: sha512-LB+xjSTEbjHE1cWsxu+tN2Xqr1kpi+V9aADI7sVM5ZMaXyYGPHULQMzpJMYqOTULK/73pUkWVzzObFRBkPr+hg==}
+
fault@2.0.1:
resolution: {integrity: sha512-WtySTkS4OKev5JtpHXnib4Gxiurzh5NCGvWrFaZ34m6JehfTUhKZvn9njTfw48t6JumVQOmrKqpmGcdwxnhqBQ==}
@@ -6927,8 +6933,8 @@ packages:
merge-stream@2.0.0:
resolution: {integrity: sha512-abv/qOcuPfk3URPfDzmZU1LKmuw8kT+0nIHvKrKgFrwifol/doWcdA4ZqsWQ8ENrFKkd67Mfpo/LovbIUsbt3w==}
- mermaid@11.16.1:
- resolution: {integrity: sha512-TQsq6u22fAn3rek5VOubrhKPo1g5hwC3FXUN9hiyupTckcYiGuuKGkNQrKYwGJkXUxZdojwRG46gsSCFZMDp4g==}
+ mermaid@11.17.2:
+ resolution: {integrity: sha512-V6K3C8EBdEsPFZXSKMJe6ppQOENxuHARr9GvHX4hh47lAbhMRD9qf4oEK7LoaRQxULMa80/qt5gHO73aCleBBg==}
methods@1.1.2:
resolution: {integrity: sha512-iclAHeNqNm68zFtnZ0e+1L2yUIdvzNoauKU4WBA3VvH/vPFieF7qfRlwUZU+DA9P9bPXIS90ulxoUoCH23sV2w==}
@@ -7895,6 +7901,9 @@ packages:
streamx@2.28.0:
resolution: {integrity: sha512-1Yowhzjf0ivGMrTIkY9hav5TxobO9qIVqUE41fiCGMGgc3CLlf4MY+9AHmZqBWgDTue0fY9zWjYFVyf6Diuobw==}
+ strictdom@1.0.1:
+ resolution: {integrity: sha512-cEmp9QeXXRmjj/rVp9oyiqcvyocWab/HaoN4+bwFeZ7QzykJD6L3yD4v12K1x0tHpqRqVpJevN3gW7kyM39Bqg==}
+
string-width@4.2.3:
resolution: {integrity: sha512-wKyQRQpjJ0sIp62ErSZdGsjMJWsap5oRNihHhu6G7JVO/9jIB6UyevL+tXuOqrng8j/cxKTWyWUwvSTriiZz/g==}
engines: {node: '>=8'}
@@ -8197,8 +8206,8 @@ packages:
util-deprecate@1.0.2:
resolution: {integrity: sha512-EPD5q1uXyFxJpCrLnCc1nHnq3gOa6DZBocAIiI2TaSCA7VCJ1UJDMagCzIkXNsUYfD1daK//LTEQ8xiIbrHtcw==}
- uuid@14.0.1:
- resolution: {integrity: sha512-6ZxzVpzDXDa3bJWaHilVayA+BH/1zmxCJoVgvmqJnid/gPoKHxUrS/aC/T6LGQtNHT+XHG9fXPJB4d+IrU30Ew==}
+ uuid@14.0.2:
+ resolution: {integrity: sha512-xZe/16rV4aa+HGSOCiY2YeLT1OybRLrrkL/Rqaq7p7GMVXjFh+6wN4oMYgjFmnSnhY8t6Xpdl2l9qmnHYuMHwQ==}
hasBin: true
uvu@0.5.6:
@@ -10368,7 +10377,7 @@ snapshots:
react: 19.2.8
react-dom: 19.2.8(react@19.2.8)
- '@mermaid-js/parser@1.2.0':
+ '@mermaid-js/parser@1.2.1':
dependencies:
'@chevrotain/types': 11.1.2
@@ -12122,7 +12131,7 @@ snapshots:
'@types/d3-selection@3.0.11': {}
- '@types/d3-shape@3.1.8':
+ '@types/d3-shape@3.2.0':
dependencies:
'@types/d3-path': 3.1.1
@@ -12167,7 +12176,7 @@ snapshots:
'@types/d3-scale': 4.0.9
'@types/d3-scale-chromatic': 3.1.0
'@types/d3-selection': 3.0.11
- '@types/d3-shape': 3.1.8
+ '@types/d3-shape': 3.2.0
'@types/d3-time': 3.0.4
'@types/d3-time-format': 4.0.3
'@types/d3-timer': 3.0.2
@@ -12937,17 +12946,17 @@ snapshots:
csstype@3.2.3: {}
- cytoscape-cose-bilkent@4.1.0(cytoscape@3.34.1):
+ cytoscape-cose-bilkent@4.1.0(cytoscape@3.34.2):
dependencies:
cose-base: 1.0.3
- cytoscape: 3.34.1
+ cytoscape: 3.34.2
- cytoscape-fcose@2.2.0(cytoscape@3.34.1):
+ cytoscape-fcose@2.2.0(cytoscape@3.34.2):
dependencies:
cose-base: 2.2.0
- cytoscape: 3.34.1
+ cytoscape: 3.34.2
- cytoscape@3.34.1: {}
+ cytoscape@3.34.2: {}
d3-array@2.12.1:
dependencies:
@@ -13132,7 +13141,7 @@ snapshots:
dateformat@4.6.3: {}
- dayjs@1.11.21: {}
+ dayjs@1.11.23: {}
debug@4.4.3:
dependencies:
@@ -13202,6 +13211,10 @@ snapshots:
optionalDependencies:
'@types/trusted-types': 2.0.7
+ dompurify@3.4.14:
+ optionalDependencies:
+ '@types/trusted-types': 2.0.7
+
dotenv@17.4.2: {}
downshift@7.6.2(react@19.2.8):
@@ -13297,7 +13310,7 @@ snapshots:
has-tostringtag: 1.0.2
hasown: 2.0.2
- es-toolkit@1.50.0: {}
+ es-toolkit@1.52.0: {}
esbuild@0.18.20:
optionalDependencies:
@@ -13498,6 +13511,10 @@ snapshots:
dependencies:
fast-string-width: 3.0.2
+ fastdom@1.0.12:
+ dependencies:
+ strictdom: 1.0.1
+
fault@2.0.1:
dependencies:
format: 0.2.2
@@ -14299,29 +14316,30 @@ snapshots:
merge-stream@2.0.0: {}
- mermaid@11.16.1:
+ mermaid@11.17.2:
dependencies:
'@braintree/sanitize-url': 7.1.2
'@iconify/utils': 3.1.4
- '@mermaid-js/parser': 1.2.0
+ '@mermaid-js/parser': 1.2.1
'@types/d3': 7.4.3
'@upsetjs/venn.js': 2.0.0
- cytoscape: 3.34.1
- cytoscape-cose-bilkent: 4.1.0(cytoscape@3.34.1)
- cytoscape-fcose: 2.2.0(cytoscape@3.34.1)
+ cytoscape: 3.34.2
+ cytoscape-cose-bilkent: 4.1.0(cytoscape@3.34.2)
+ cytoscape-fcose: 2.2.0(cytoscape@3.34.2)
d3: 7.9.0
d3-sankey: 0.12.3
dagre-d3-es: 7.0.14
- dayjs: 1.11.21
- dompurify: 3.4.13
- es-toolkit: 1.50.0
+ dayjs: 1.11.23
+ dompurify: 3.4.14
+ es-toolkit: 1.52.0
+ fastdom: 1.0.12
katex: 0.16.47
khroma: 2.1.0
marked: 16.4.2
roughjs: 4.6.6
stylis: 4.4.0
ts-dedent: 2.3.0
- uuid: 14.0.1
+ uuid: 14.0.2
methods@1.1.2: {}
@@ -15657,6 +15675,8 @@ snapshots:
- bare-abort-controller
- react-native-b4a
+ strictdom@1.0.1: {}
+
string-width@4.2.3:
dependencies:
emoji-regex: 8.0.0
@@ -15977,7 +15997,7 @@ snapshots:
util-deprecate@1.0.2: {}
- uuid@14.0.1: {}
+ uuid@14.0.2: {}
uvu@0.5.6:
dependencies:
diff --git a/ui/package.json b/ui/package.json
index 20ea33f78c..0d31f0c049 100644
--- a/ui/package.json
+++ b/ui/package.json
@@ -60,7 +60,7 @@
"i18next": "^26.3.6",
"lexical": "0.48.0",
"lucide-react": "^1.32.0",
- "mermaid": "^11.16.1",
+ "mermaid": "^11.17.2",
"motion": "^12.42.2",
"radix-ui": "^1.6.7",
"react": "^19.2.8",
From 6b625425a5858d9a32a1b0ada245895365403459 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 3 Sep 2026 08:23:53 -0700
Subject: [PATCH 2/7] chore(deps): bump @tanstack/react-query from 5.101.4 to
5.102.8 (#12568)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps
[@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query)
from 5.101.4 to 5.102.8.
Release notes
Sourced from @tanstack/react-query's
releases.
@tanstack/react-query-devtools@5.102.8
Patch Changes
- Updated dependencies []:
@tanstack/query-devtools@5.102.8
@tanstack/react-query@5.102.8
@tanstack/react-query-next-experimental@5.102.8
Patch Changes
- Updated dependencies []:
@tanstack/react-query@5.102.8
@tanstack/react-query-persist-client@5.102.8
Patch Changes
- Updated dependencies []:
@tanstack/query-persist-client-core@5.102.8
@tanstack/react-query@5.102.8
@tanstack/react-query@5.102.8
Patch Changes
- Updated dependencies []:
@tanstack/query-core@5.102.8
@tanstack/react-query-devtools@5.102.7
Patch Changes
- Updated dependencies []:
@tanstack/query-devtools@5.102.7
@tanstack/react-query@5.102.7
@tanstack/react-query-next-experimental@5.102.7
Patch Changes
- Updated dependencies []:
@tanstack/react-query@5.102.7
@tanstack/react-query-persist-client@5.102.7
Patch Changes
- Updated dependencies []:
@tanstack/query-persist-client-core@5.102.7
@tanstack/react-query@5.102.7
@tanstack/react-query@5.102.7
Patch Changes
... (truncated)
Changelog
Sourced from @tanstack/react-query's
changelog.
5.102.8
Patch Changes
- Updated dependencies []:
@tanstack/query-core@5.102.8
5.102.7
Patch Changes
- Updated dependencies []:
@tanstack/query-core@5.102.7
5.102.6
Patch Changes
5.102.5
Patch Changes
- Updated dependencies [
578e5c2]:
@tanstack/query-core@5.102.5
5.102.4
Patch Changes
- Updated dependencies [
a05df6a]:
@tanstack/query-core@5.102.4
5.102.3
Patch Changes
- Updated dependencies []:
@tanstack/query-core@5.102.3
5.102.2
Patch Changes
- Updated dependencies [
80fbf73]:
@tanstack/query-core@5.102.2
... (truncated)
Commits
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
pnpm-lock.yaml | 18 +++++++++---------
ui/package.json | 2 +-
2 files changed, 10 insertions(+), 10 deletions(-)
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index 868d13c27f..d6ead2f77d 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -1075,8 +1075,8 @@ importers:
specifier: ^0.5.20
version: 0.5.20(tailwindcss@4.3.3)
'@tanstack/react-query':
- specifier: ^5.101.4
- version: 5.101.4(react@19.2.8)
+ specifier: ^5.102.8
+ version: 5.102.8(react@19.2.8)
'@xterm/addon-fit':
specifier: ^0.11.0
version: 0.11.0
@@ -4693,11 +4693,11 @@ packages:
peerDependencies:
vite: ^5.2.0 || ^6 || ^7 || ^8
- '@tanstack/query-core@5.101.4':
- resolution: {integrity: sha512-gNwcvOJcRbLWPOLG/2OBm+zM+Yv+MKsXKEOWC57USuZDEsI71hEErQsiEGx5wX9rzWWkfwM0fVSPoiIFSsxfiw==}
+ '@tanstack/query-core@5.102.8':
+ resolution: {integrity: sha512-ZNjkJ33CqvPNec/6lZBnHqLc3EVGPZ9ySLhYahU9TcuRFdmwXewuj0c4hwSWcGHqEUwcSrKeZ+oGcvPBqXcQcg==}
- '@tanstack/react-query@5.101.4':
- resolution: {integrity: sha512-yRg2pfOCxIs4ZJW3XYYHU/WgtD04FHSnfHlpRT7h7pR77hwkdRG4wxbKe4aq6P0RvXUTBSQpQeadS1SUYUe+KA==}
+ '@tanstack/react-query@5.102.8':
+ resolution: {integrity: sha512-TYBea4OuXWD7MhaSHq069TWbFe7rcwWN6kzT7JF0OKi1K6c1gTv2IzD6A6ExJsCMozdkqBWeuIUZmu4KQg0O5A==}
peerDependencies:
react: ^19.2.8
@@ -11991,11 +11991,11 @@ snapshots:
tailwindcss: 4.3.3
vite: 8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12)
- '@tanstack/query-core@5.101.4': {}
+ '@tanstack/query-core@5.102.8': {}
- '@tanstack/react-query@5.101.4(react@19.2.8)':
+ '@tanstack/react-query@5.102.8(react@19.2.8)':
dependencies:
- '@tanstack/query-core': 5.101.4
+ '@tanstack/query-core': 5.102.8
react: 19.2.8
'@testing-library/dom@10.4.1':
diff --git a/ui/package.json b/ui/package.json
index 0d31f0c049..4dee922ded 100644
--- a/ui/package.json
+++ b/ui/package.json
@@ -51,7 +51,7 @@
"@paperclipai/shared": "workspace:*",
"@radix-ui/react-slot": "^1.3.0",
"@tailwindcss/typography": "^0.5.20",
- "@tanstack/react-query": "^5.101.4",
+ "@tanstack/react-query": "^5.102.8",
"@xterm/addon-fit": "^0.11.0",
"@xterm/xterm": "^6.0.0",
"class-variance-authority": "^0.7.1",
From 98c569b2dff82fd21836bc4306c0c81c83013468 Mon Sep 17 00:00:00 2001
From: Dotta <34892728+cryppadotta@users.noreply.github.com>
Date: Thu, 3 Sep 2026 10:38:56 -0500
Subject: [PATCH 3/7] ci(runner): allow trusted branch targets (#12768)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
## Thinking Path
> - Paperclip uses paid runner tests to qualify agent execution.
> - The runner workflow controls provider secrets and AWS runner access.
> - The trusted workflow must stay on the protected default branch.
> - The code under test often exists on a branch before merge.
> - CODEOWNERS need a safe way to select that branch.
> - This pull request separates workflow authority from the code under
test.
> - The benefit is pre-merge AWS testing without target-controlled
workflow code.
## Linked Issues or Issue Description
**What existing behavior does this improve?**
The manual Runner Full-Stack E2E workflow can test only the default
branch.
**Subsystem affected**
GitHub Actions and the paid runner E2E security boundary.
**Current behavior**
A CODEOWNER must merge runner changes before the trusted AWS workflow
can test them.
Selecting another branch as the workflow ref is rejected.
**Proposed behavior**
A CODEOWNER starts the workflow from `master` and supplies a
same-repository branch in `target_branch`.
The authorization job resolves the branch to one commit SHA.
Catalog, image, and paid test jobs check out that SHA after
authorization.
Report sanitization and AWS publication use the trusted workflow SHA.
**Reason and benefit**
This permits paid pre-merge qualification on AWS.
It keeps the workflow definition, report sanitizer, history publisher,
environment deployment, and runner-group permission on `master`.
**Breaking changes**
None.
The new input is optional.
An omitted input still tests the default branch.
## What Changed
- Add the optional `target_branch` workflow input.
- Resolve only a branch in `paperclipai/paperclip` to an immutable SHA.
- Pin catalog, image, paid test, and Daytona provenance to the target
SHA.
- Pin report sanitization and AWS history publication to the trusted
workflow SHA.
- Disable persisted checkout credentials in every job.
- Key cancellation by the selected target branch.
- Add policy regression coverage and operator documentation.
## Verification
- `pnpm test:e2e:runner:unit` passes with 65 tests.
- `actionlint -ignore SC2129
.github/workflows/runner-full-stack-e2e.yml` passes.
- Prettier checks pass for all changed files.
- `git diff --check` passes.
## Risks
A CODEOWNER can authorize selected branch code to receive a cell-scoped
provider credential.
This is the intended trust decision.
The workflow rejects fork refs and target-controlled workflow
definitions.
The trusted workflow SHA owns report sanitization and AWS history
publication.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
OpenAI Codex, GPT-5.
The exact serving snapshot and context-window size are not exposed.
The model used tool-enabled reasoning and code execution.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
---
.github/workflows/runner-full-stack-e2e.yml | 56 ++++++++++++++++++---
tests/runner-e2e/README.md | 47 +++++++++++++----
tests/runner-e2e/SECURITY.md | 35 +++++++++----
tests/runner-e2e/workflow-security.test.ts | 36 ++++++++++++-
4 files changed, 146 insertions(+), 28 deletions(-)
diff --git a/.github/workflows/runner-full-stack-e2e.yml b/.github/workflows/runner-full-stack-e2e.yml
index 8883b360a7..19bf0fda71 100644
--- a/.github/workflows/runner-full-stack-e2e.yml
+++ b/.github/workflows/runner-full-stack-e2e.yml
@@ -5,6 +5,10 @@ on:
- cron: "47 8 * * 0"
workflow_dispatch:
inputs:
+ target_branch:
+ description: "Branch in paperclipai/paperclip to test; the trusted workflow still runs from master"
+ type: string
+ required: false
all:
description: "Run the complete paid matrix when no narrower selector is supplied"
type: boolean
@@ -38,10 +42,10 @@ permissions:
contents: read
concurrency:
- group: runner-full-stack-e2e-${{ github.ref }}
- # Development-only validation refs supersede older runs on the same ref.
- # Preserve every protected default-branch campaign for its paid audit trail.
- cancel-in-progress: ${{ github.ref != format('refs/heads/{0}', github.event.repository.default_branch) }}
+ group: runner-full-stack-e2e-${{ inputs.target_branch || github.event.repository.default_branch }}
+ # Development branch campaigns supersede older runs for the same target.
+ # Preserve every default-branch campaign for its paid audit trail.
+ cancel-in-progress: ${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch }}
jobs:
authorize:
@@ -55,6 +59,7 @@ jobs:
test_runner: ${{ steps.runner.outputs.runner }}
max_parallel_default: ${{ steps.runner.outputs.max_parallel_default }}
max_parallel_limit: ${{ steps.runner.outputs.max_parallel_limit }}
+ target_sha: ${{ steps.target.outputs.sha }}
steps:
- name: Require default branch and allowlisted numeric actor IDs
env:
@@ -89,6 +94,27 @@ jobs:
fi
done
+ - name: Resolve requested repository branch to an immutable commit
+ id: target
+ env:
+ GH_TOKEN: ${{ github.token }}
+ REPOSITORY: ${{ github.repository }}
+ TARGET_BRANCH: ${{ inputs.target_branch || github.event.repository.default_branch }}
+ run: |
+ set -euo pipefail
+ if [ -z "$TARGET_BRANCH" ] || [[ "$TARGET_BRANCH" == refs/* ]]; then
+ echo "target_branch must name a branch in this repository without a refs/ prefix." >&2
+ exit 1
+ fi
+ encoded_branch="$(jq -rn --arg branch "$TARGET_BRANCH" '$branch | @uri')"
+ target_sha="$(gh api -X GET "repos/$REPOSITORY/branches/$encoded_branch" --jq .commit.sha)"
+ if ! [[ "$target_sha" =~ ^[0-9a-f]{40}$ ]]; then
+ echo "The requested repository branch did not resolve to a commit." >&2
+ exit 1
+ fi
+ echo "sha=$target_sha" >> "$GITHUB_OUTPUT"
+ echo "Resolved the requested repository branch to $target_sha."
+
- name: Select paid test runner
id: runner
env:
@@ -130,6 +156,9 @@ jobs:
daytona_image_content_id: ${{ steps.daytona_image_content.outputs.content_id }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ ref: ${{ needs.authorize.outputs.target_sha }}
+ persist-credentials: false
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
with:
@@ -233,6 +262,9 @@ jobs:
content_id: ${{ steps.image.outputs.content_id }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ ref: ${{ needs.authorize.outputs.target_sha }}
+ persist-credentials: false
- name: No Daytona image needed
id: local_only
@@ -261,6 +293,7 @@ jobs:
NEEDS_DAYTONA: ${{ needs.catalog.outputs.needs_daytona }}
IMAGE_CONTENT_ID: ${{ needs.catalog.outputs.daytona_image_content_id }}
IMAGE_TAG: ghcr.io/paperclipai/paperclip-daytona-runner:e2e-content-${{ needs.catalog.outputs.daytona_image_content_id }}
+ TARGET_SHA: ${{ needs.authorize.outputs.target_sha }}
run: |
set -euo pipefail
if [ "$NEEDS_DAYTONA" != true ]; then
@@ -277,7 +310,7 @@ jobs:
docker buildx build \
--platform linux/amd64 \
--build-arg "PAPERCLIP_RUNNER_CONTENT_ID=${IMAGE_CONTENT_ID}" \
- --build-arg "PAPERCLIP_RUNNER_SOURCE_REVISION=${GITHUB_SHA}" \
+ --build-arg "PAPERCLIP_RUNNER_SOURCE_REVISION=${TARGET_SHA}" \
--file docker/daytona-runner/Dockerfile \
--tag "$IMAGE_TAG" \
--push \
@@ -354,6 +387,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
+ ref: ${{ needs.authorize.outputs.target_sha }}
persist-credentials: false
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
@@ -416,7 +450,7 @@ jobs:
report:
name: Merge and enforce campaign result
if: always() && needs.catalog.result == 'success'
- needs: [catalog, daytona_image, test]
+ needs: [authorize, catalog, daytona_image, test]
outputs:
history_source_ready: ${{ steps.history_source_ready.outputs.ready }}
runs-on: ubuntu-latest
@@ -425,6 +459,10 @@ jobs:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ # Reporting and sanitization are part of the trusted workflow boundary.
+ ref: ${{ github.sha }}
+ persist-credentials: false
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
with:
@@ -511,7 +549,7 @@ jobs:
publish_history:
name: Publish pruned immutable history and landing site
- needs: [catalog, report]
+ needs: [authorize, catalog, report]
if: always() && needs.catalog.result == 'success' && needs.report.outputs.history_source_ready == 'true'
runs-on: ubuntu-latest
timeout-minutes: 15
@@ -525,6 +563,10 @@ jobs:
name: runner-e2e-history
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ # Never execute target-controlled publication code with AWS credentials.
+ ref: ${{ github.sha }}
+ persist-credentials: false
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
with:
diff --git a/tests/runner-e2e/README.md b/tests/runner-e2e/README.md
index c7d9cb1320..29f8179757 100644
--- a/tests/runner-e2e/README.md
+++ b/tests/runner-e2e/README.md
@@ -266,13 +266,35 @@ auto-stop/archive/delete values remain as cancellation backstops.
## GitHub Actions
`Runner Full-Stack E2E` has only `schedule` and `workflow_dispatch` triggers; it
-never runs for a pull request or ordinary push. Because this repository is
-public, manual campaigns fail before checkout unless they run from the default
-branch and both the original actor and rerun actor have numeric GitHub user IDs
-in the non-empty JSON-array repository variable
-`RUNNER_E2E_ALLOWED_ACTOR_IDS`. Usernames are intentionally not trusted.
-The first scheduled attempt is trusted automation; any human rerun of a
-scheduled campaign must pass the triggering-actor allowlist.
+never runs for a pull request or ordinary push. Start the trusted workflow from
+the default branch. A CODEOWNER can set the optional `target_branch` input to
+any branch in `paperclipai/paperclip`. The authorization job resolves that
+branch to one immutable commit before any checkout. Catalog, image, and paid
+test jobs check out that exact commit. Report sanitization and AWS history
+publication explicitly check out the trusted workflow commit. The workflow
+definition, runner-group permission, and protected-environment deployment still
+come from the default branch. Do not select the target branch in GitHub's **Use
+workflow from** control.
+
+Because this repository is public, manual campaigns fail before checkout unless
+the trusted workflow runs from the default branch and both the original actor
+and rerun actor have numeric GitHub user IDs in the non-empty JSON-array
+repository variable `RUNNER_E2E_ALLOWED_ACTOR_IDS`. Keep this stable-ID list in
+sync with the owners of `.github/**` in `.github/CODEOWNERS`. Usernames are
+intentionally not trusted. The first scheduled attempt is trusted automation;
+any human rerun of a scheduled campaign must pass the triggering-actor
+allowlist.
+
+For example, this command runs one branch cell through the trusted default-branch
+workflow:
+
+```bash
+gh workflow run runner-full-stack-e2e.yml \
+ --ref master \
+ -f target_branch=fix/example \
+ -f all=false \
+ -f id=core-compatibility.runner-codex.local.message-marker
+```
Create a protected `runner-e2e-paid` GitHub environment, restrict it to the
default branch, limit environment administration to trusted maintainers, and
@@ -302,11 +324,14 @@ it, and require a fresh ephemeral instance for each job so one paid cell cannot
leave state for the next. Provider secrets remain protected by the stable-ID
authorization checks and the default-branch-only `runner-e2e-paid` environment;
the fleet itself is not an authorization boundary. These external fleet controls
-are as important as the workflow checks in a public repository.
+are as important as the workflow checks in a public repository. A CODEOWNER
+dispatch is an explicit authorization to execute the selected repository branch
+with the cell's scoped provider credential.
-Non-default validation runs share a concurrency key per ref and cancel an older
-run when a replacement is dispatched. Protected default-branch paid campaigns
-are retained and are never auto-cancelled, preserving their audit trail.
+Development branch campaigns share a concurrency key per target branch and
+cancel an older run when a replacement is dispatched. Default-branch target
+campaigns are retained and are never auto-cancelled, preserving their audit
+trail.
GitHub Actions artifacts are access-controlled 30-day operational copies, not
the permanent public history. They retain packaged PNG/WebM and generated
diff --git a/tests/runner-e2e/SECURITY.md b/tests/runner-e2e/SECURITY.md
index 19f407bb76..d99294444c 100644
--- a/tests/runner-e2e/SECURITY.md
+++ b/tests/runner-e2e/SECURITY.md
@@ -9,15 +9,23 @@ changes.
## GitHub authorization
Set `RUNNER_E2E_ALLOWED_ACTOR_IDS` to a non-empty JSON array of numeric GitHub
-user IDs, for example `[123456,789012]`. Resolve each ID from the authenticated
-CLI and verify the login before adding it:
+user IDs. Keep the list equal to the owners of `.github/**` in
+`.github/CODEOWNERS`. For example, use `[123456,789012]`. Resolve each ID from
+the authenticated CLI and verify the login before adding it:
```bash
gh api users/LOGIN --jq '{login,id}'
```
-The paid workflows reject manual dispatches outside the default branch before
-checkout. They verify both the original actor and triggering actor for every
+The paid workflows reject manual dispatches when the workflow definition does
+not come from the default branch. A trusted dispatcher may name any branch in
+`paperclipai/paperclip` as the code under test. The authorization job resolves
+that branch through the GitHub API and passes only its immutable commit SHA to
+the catalog, image, and paid test checkouts. Report sanitization and AWS history
+publication explicitly use the trusted workflow commit. Never run the workflow
+definition from the target branch.
+
+The workflows verify both the original actor and triggering actor for every
scheduled or manual attempt, including human reruns. Every
secret-bearing job repeats this check as its first step so GitHub's partial-job
rerun feature cannot bypass a successful predecessor authorization job. The
@@ -78,14 +86,23 @@ fresh ephemeral instance for every job, prohibit persistent runner reuse, and
disable interactive SSH/debug access unless a separate incident procedure
explicitly authorizes it.
-Changing the runner does not widen secret access. The paid workflow still has
-only schedule and manual triggers, requires the protected default branch and
-allowlisted stable actor IDs before checkout, repeats that authorization as the
-first matrix step, and receives provider credentials only from the protected
+Changing the runner does not widen who can authorize secret access. The paid
+workflow still has only schedule and manual triggers, requires its trusted
+definition to come from the protected default branch, requires allowlisted
+stable actor IDs before checkout, and repeats that authorization as the first
+matrix step. Provider credentials come only from the protected
`runner-e2e-paid` environment. The fleet selector is an exact workflow literal;
-the only repository-controlled input is its boolean rollout switch, so
+the only repository-controlled routing input is its boolean rollout switch, so
configuration cannot redirect a secret-bearing job to an arbitrary runner.
+The optional target branch is code, not workflow authority. A CODEOWNER who
+dispatches a target branch explicitly authorizes that branch's selected test
+process to receive the cell's scoped provider credential. The workflow resolves
+the target only inside the same repository, pins one SHA for the campaign, and
+checks it out only after authorization. Target-controlled code cannot replace
+the report sanitizer or the AWS history publisher. Fork refs and
+target-controlled workflow definitions do not enter this path.
+
## AWS OIDC and S3
The AWS role trust policy should accept only GitHub's OIDC audience and the
diff --git a/tests/runner-e2e/workflow-security.test.ts b/tests/runner-e2e/workflow-security.test.ts
index 8b45eee73e..eb0745fb12 100644
--- a/tests/runner-e2e/workflow-security.test.ts
+++ b/tests/runner-e2e/workflow-security.test.ts
@@ -75,6 +75,13 @@ describe("public repository paid workflow security", () => {
expect(authorizeJob).toContain(
"AWS_PAID_RUNNER_ENABLED: ${{ vars.RUNNER_E2E_AWS_ENABLED }}",
);
+ expect(authorizeJob).toContain(
+ "Resolve requested repository branch to an immutable commit",
+ );
+ expect(authorizeJob).toContain(
+ "repos/$REPOSITORY/branches/$encoded_branch",
+ );
+ expect(authorizeJob).toContain('echo "sha=$target_sha"');
expect(paidJob).toContain(
"runs-on: ${{ needs.authorize.outputs.test_runner }}",
);
@@ -89,7 +96,34 @@ describe("public repository paid workflow security", () => {
'[ "$MAX_PARALLEL" -gt "$MAX_PARALLEL_LIMIT" ]',
);
expect(fullStack).toContain(
- "cancel-in-progress: ${{ github.ref != format('refs/heads/{0}', github.event.repository.default_branch) }}",
+ "group: runner-full-stack-e2e-${{ inputs.target_branch || github.event.repository.default_branch }}",
+ );
+ expect(fullStack).toContain(
+ "cancel-in-progress: ${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch }}",
+ );
+ expect(
+ fullStack.match(
+ /ref: \$\{\{ needs\.authorize\.outputs\.target_sha \}\}/g,
+ ),
+ ).toHaveLength(3);
+ expect(fullStack.match(/ref: \$\{\{ github\.sha \}\}/g)).toHaveLength(2);
+ expect(fullStack.match(/persist-credentials: false/g)).toHaveLength(5);
+ expect(fullStack).not.toContain("ref: ${{ inputs.target_branch }}");
+ expect(fullStack).toContain(
+ "PAPERCLIP_RUNNER_SOURCE_REVISION=${TARGET_SHA}",
+ );
+ const reportJob = fullStack.slice(
+ fullStack.indexOf(" report:"),
+ fullStack.indexOf(" publish_history:"),
+ );
+ const historyJob = fullStack.slice(fullStack.indexOf(" publish_history:"));
+ expect(reportJob).toContain("ref: ${{ github.sha }}");
+ expect(reportJob).not.toContain(
+ "ref: ${{ needs.authorize.outputs.target_sha }}",
+ );
+ expect(historyJob).toContain("ref: ${{ github.sha }}");
+ expect(historyJob).not.toContain(
+ "ref: ${{ needs.authorize.outputs.target_sha }}",
);
for (const [secret, condition] of Object.entries({
OPENAI_API_KEY: "matrix.credentialName == 'OPENAI_API_KEY'",
From eb7b4d137180ccd22a96f6d3df2cb164c329752c Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 3 Sep 2026 08:43:04 -0700
Subject: [PATCH 4/7] chore(deps): bump @aws-sdk/client-s3 from 3.1115.0 to
3.1120.0 (#12567)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3)
from 3.1115.0 to 3.1120.0.
Release notes
Sourced from @aws-sdk/client-s3's
releases.
v3.1120.0
3.1120.0(2026-08-27)
Documentation Changes
- client-opensearch: Updating SDK and CLI
documentation for AttachDataSource API. (d696fe76)
New Features
- client-lambda-microvms: Added
InsufficientCapacityException to RunMicrovm for capacity-related
failures. Added lifecycle status field (AVAILABLE, DEPRECATED) to
ListManagedMicrovmImageVersions. Added ConflictException to
CreateMicrovmAuthToken and CreateMicrovmShellAuthToken for unregistered
MicroVMs. (72a8ff80)
- client-codedeploy: Added a deploymentMode parameter
to CreateDeployment. Set it to RESTART to restart an EC2 and on-premises
fleet, using the last successful revision, honoring Deployment
Configuration. (78d4f964)
- client-cloudwatch-logs: Added resultCount to
QueryStatistics in GetQueryResults. This field returns the total number
of output rows in the final result set, helping customers
programmatically determine whether a query produced results after all
operations including post-aggregation filters. (0e4d242b)
- client-datazone: Add cascadeDelete to DeleteDomain.
When specified, DataZone recursively deletes all projects, environments,
subscriptions, and their underlying AWS resources before removing the
domain. Deletion progress is reported via deleteProgress and resource
failures via failureReasons on GetDomain. (3a74dc4b)
- client-rds: Adding support for the full snapshot
size, in bytes, of DB instance snapshots. (ab2f66f5)
- client-ec2: EC2 allows AMI owners to define
compatible instance types on their AMIs, blocking RunInstances calls
automatically for launches on non-permitted instance types. (311b3b26)
- client-cognito-identity-provider: Adds the
AdminDeleteSoftwareToken API operation, enabling administrators to
remove a user's registered TOTP (software token) MFA configuration from
a user pool. (f661bebc)
For list of updated packages, view
updated-packages.md in
assets-3.1120.0.zip
v3.1119.0
3.1119.0(2026-08-26)
Chores
New Features
- client-sagemaker: Amazon SageMaker AI now supports
ml.g7 instances for model optimization. You can now run model
optimization jobs on ml.g7 instances, in supported AWS Regions. (6d5e1066)
- client-devops-agent: AWS DevOps Agent now supports
trigger filter groups for Release Readiness Review, letting you control
when the capability auto-triggers based on webhook events and target
branches. (bc3d53d5)
- client-license-manager-user-subscriptions: Released
support for License Expiry field in ListProductSubscriptions API (454d7f7f)
- client-ec2: Adds deleting state to possible VPC
States. (43091d55)
- client-network-firewall: Adding new status enum for
Firewalls. (4cb21cb3)
For list of updated packages, view
updated-packages.md in
assets-3.1119.0.zip
v3.1118.0
3.1118.0(2026-08-25)
Documentation Changes
- client-marketplace-metering: Updated documentation
to clarify duplicate-billing prevention and BatchMeterUsage retry
guidance (32231025)
New Features
... (truncated)
Changelog
Sourced from @aws-sdk/client-s3's
changelog.
Note: Version bump only for package
@aws-sdk/client-s3
Note: Version bump only for package
@aws-sdk/client-s3
Note: Version bump only for package
@aws-sdk/client-s3
Note: Version bump only for package
@aws-sdk/client-s3
Note: Version bump only for package
@aws-sdk/client-s3
Commits
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
pnpm-lock.yaml | 10 +++++-----
server/package.json | 2 +-
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index d6ead2f77d..4c48d3cf96 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -840,8 +840,8 @@ importers:
server:
dependencies:
'@aws-sdk/client-s3':
- specifier: ^3.1115.0
- version: 3.1115.0
+ specifier: ^3.1120.0
+ version: 3.1120.0
'@opentelemetry/api':
specifier: ^1.9.0
version: 1.9.1
@@ -1390,8 +1390,8 @@ packages:
resolution: {integrity: sha512-Dtu0gr4dnATZAPwEYbpCsG+MpLM7OAliy2gTepEFQwl1vZ6DL3QMH2FveMa3HLvPsOdhJsPRB3KtxVhph9T75A==}
engines: {node: '>=20.0.0'}
- '@aws-sdk/client-s3@3.1115.0':
- resolution: {integrity: sha512-oeniaXZCRrKMaffnyjOSxp1xJNsuiku2SxyzVI1Bi1Gycpck/dRTVsloSa5E+nBKz1c5y5eMfbK4GAhGUCCC2Q==}
+ '@aws-sdk/client-s3@3.1120.0':
+ resolution: {integrity: sha512-UunWgNl/U8wIlxVRyhUPqlozFkUS88UqXjAH50XfPDXaZeK9P7KVYTAh4KREVrLPQTzPxVSbQGog3gHlc/P6vg==}
engines: {node: '>=20.0.0'}
'@aws-sdk/core@3.977.9':
@@ -8739,7 +8739,7 @@ snapshots:
'@smithy/types': 4.17.2
tslib: 2.8.1
- '@aws-sdk/client-s3@3.1115.0':
+ '@aws-sdk/client-s3@3.1120.0':
dependencies:
'@aws-sdk/checksums': 3.1000.29
'@aws-sdk/core': 3.977.9
diff --git a/server/package.json b/server/package.json
index baecc3805a..31f14682a8 100644
--- a/server/package.json
+++ b/server/package.json
@@ -44,7 +44,7 @@
"typecheck": "pnpm run prepare:runner-vendor && pnpm --filter @paperclipai/plugin-sdk ensure-build-deps && tsc --noEmit"
},
"dependencies": {
- "@aws-sdk/client-s3": "^3.1115.0",
+ "@aws-sdk/client-s3": "^3.1120.0",
"@opentelemetry/api": "^1.9.0",
"@paperclipai/adapter-claude-local": "workspace:*",
"@paperclipai/adapter-codex-local": "workspace:*",
From fa16f88d6b003db75206f5b75123aa50f13ecb65 Mon Sep 17 00:00:00 2001
From: "github-actions[bot]"
<41898282+github-actions[bot]@users.noreply.github.com>
Date: Thu, 3 Sep 2026 11:08:34 -0500
Subject: [PATCH 5/7] chore(lockfile): refresh pnpm-lock.yaml (#12771)
Use full dependency resolution in automated lockfile repair paths, add regression coverage, and refresh the stale Rollup snapshot.
Co-Authored-By: Dotta
Co-Authored-By: Codex
Co-Authored-By: lockfile-bot
---
.../tests/lockfile-refresh-workflows.test.mjs | 24 +++++++++++++++++++
.github/workflows/docker.yml | 4 ++--
.github/workflows/pr-trusted.yml | 2 +-
.github/workflows/refresh-lockfile.yml | 2 +-
pnpm-lock.yaml | 3 +--
scripts/__tests__/e2e-shard.test.mjs | 4 ++--
6 files changed, 31 insertions(+), 8 deletions(-)
create mode 100644 .github/scripts/tests/lockfile-refresh-workflows.test.mjs
diff --git a/.github/scripts/tests/lockfile-refresh-workflows.test.mjs b/.github/scripts/tests/lockfile-refresh-workflows.test.mjs
new file mode 100644
index 0000000000..52fef1f698
--- /dev/null
+++ b/.github/scripts/tests/lockfile-refresh-workflows.test.mjs
@@ -0,0 +1,24 @@
+import { readFile } from 'node:fs/promises';
+import { test } from 'node:test';
+import assert from 'node:assert/strict';
+
+const workflows = [
+ '.github/workflows/refresh-lockfile.yml',
+ '.github/workflows/pr-trusted.yml',
+ '.github/workflows/docker.yml',
+];
+
+test('lockfile repair workflows resolve dependencies instead of updating metadata only', async () => {
+ for (const workflow of workflows) {
+ const contents = await readFile(workflow, 'utf8');
+ const repairCommands = contents
+ .split('\n')
+ .filter((line) => line.includes('pnpm install') && line.includes('--no-frozen-lockfile'));
+
+ assert.ok(repairCommands.length > 0, `${workflow} must contain a lockfile repair command`);
+ for (const command of repairCommands) {
+ assert.match(command, /--ignore-scripts/);
+ assert.doesNotMatch(command, /--lockfile-only/);
+ }
+ }
+});
diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml
index 14b8937abe..5fb9f7e600 100644
--- a/.github/workflows/docker.yml
+++ b/.github/workflows/docker.yml
@@ -87,7 +87,7 @@ jobs:
- name: Refresh lockfile for Docker build context
run: |
set -euo pipefail
- pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile
+ pnpm install --ignore-scripts --no-frozen-lockfile
changed="$(git status --porcelain)"
if [ -z "$changed" ]; then
@@ -281,7 +281,7 @@ jobs:
- name: Refresh lockfile for Docker build context
run: |
set -euo pipefail
- pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile
+ pnpm install --ignore-scripts --no-frozen-lockfile
changed="$(git status --porcelain)"
if [ -z "$changed" ]; then
diff --git a/.github/workflows/pr-trusted.yml b/.github/workflows/pr-trusted.yml
index 5bc040f992..7bd403aa57 100644
--- a/.github/workflows/pr-trusted.yml
+++ b/.github/workflows/pr-trusted.yml
@@ -337,7 +337,7 @@ jobs:
id: regen_lockfile
run: |
cp pnpm-lock.yaml "$RUNNER_TEMP/pnpm-lock.before.yaml"
- pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile
+ pnpm install --ignore-scripts --no-frozen-lockfile
if cmp -s "$RUNNER_TEMP/pnpm-lock.before.yaml" pnpm-lock.yaml; then
echo "regenerated=0" >> "$GITHUB_OUTPUT"
else
diff --git a/.github/workflows/refresh-lockfile.yml b/.github/workflows/refresh-lockfile.yml
index 49ac2176e7..039d21970e 100644
--- a/.github/workflows/refresh-lockfile.yml
+++ b/.github/workflows/refresh-lockfile.yml
@@ -35,7 +35,7 @@ jobs:
cache: pnpm
- name: Refresh pnpm lockfile
- run: pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile
+ run: pnpm install --ignore-scripts --no-frozen-lockfile
- name: Fail on unexpected file changes
run: |
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index 4c48d3cf96..4d2ab65103 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -7210,7 +7210,6 @@ packages:
opencode-ai@1.18.17:
resolution: {integrity: sha512-Pc2D3Y6iQ3BAjcKw9E+9J7VTWNazIwFknFfrolufMCrJ0FLxOIZfndoHmJrx4x1oqpK2CPAqK9D2V6nsp6Oebw==}
- cpu: [arm64, x64]
os: [darwin, linux, win32]
hasBin: true
@@ -16024,7 +16023,7 @@ snapshots:
fdir: 6.5.0(picomatch@4.0.7)
picomatch: 4.0.7
postcss: 8.5.26
- rollup: 4.62.4
+ rollup: 4.63.1
tinyglobby: 0.2.17
optionalDependencies:
'@types/node': 24.13.3
diff --git a/scripts/__tests__/e2e-shard.test.mjs b/scripts/__tests__/e2e-shard.test.mjs
index e1074ea683..691c0b6cc1 100644
--- a/scripts/__tests__/e2e-shard.test.mjs
+++ b/scripts/__tests__/e2e-shard.test.mjs
@@ -306,8 +306,8 @@ test("the trusted PR workflow regenerates stale stacked lockfiles", () => {
);
assert.match(
workflow,
- /pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile/,
- "the policy job must validate the complete merge tree instead of only the current PR layer",
+ /pnpm install --ignore-scripts --no-frozen-lockfile/,
+ "the policy job must resolve the complete merge tree instead of only updating lockfile metadata",
);
assert.match(
workflow,
From 4e56afec11fe1ecd02f8ddf4d1e264d8c99c792d Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 3 Sep 2026 09:14:00 -0700
Subject: [PATCH 6/7] chore(deps-dev): bump @vitejs/plugin-react from 4.7.0 to
6.1.1 (#12566)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps
[@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react)
from 4.7.0 to 6.1.1.
Release notes
Sourced from @vitejs/plugin-react's
releases.
plugin-react@6.1.1
Add compiler.logDiagnostics option
Recoverable React Compiler diagnostics are no longer logged by
default. Set compiler.logDiagnostics to true
to log them through Vite. Fatal diagnostics are always logged and fail
the transform.
Respect environment sourcemap option for React Compiler transform
when builder.sharedPlugins is enabled (#1439)
The React Compiler transform was using the top-level sourcemap option
instead of the environment sourcemap option. This caused a problem when
the experimental builder.sharedPlugins was enabled.
plugin-react@6.1.0
Add experimental native React Compiler support (#1419)
Add experimental native React Compiler support.
You can use it by installing oxc-transform-react and
enabling it via the compiler option:
npm install -D oxc-transform-react
import { defineConfig } from 'vite'
import react from '@vitejs/plugin-react'
export default defineConfig({
plugins: [
react({ compiler: true })
]
})
plugin-react@6.0.5
Fixed the react compiler preset filter to be linear (#1353)
The improved filter in v6.0.3 was non-linear and caused a performance
regression (#1349).
The filter was changed to be linear to avoid that.
plugin-react@6.0.4
Fixed $RefreshSig$ is not defined error when running
vite dev with NODE_ENV=production
When running vite dev with
NODE_ENV=production, the app errored with
$RefreshSig$ is not defined.
This error is now fixed.
plugin-react@6.0.3
No release notes provided.
plugin-react@6.0.2
Allow all options in reactCompilerPreset (#1189)
This is a type only change. Only compilationMode and
target options were available for
reactCompilerPreset.
plugin-react@6.0.1
Expand @rolldown/plugin-babel peer dep range (#1146)
... (truncated)
Changelog
Sourced from @vitejs/plugin-react's
changelog.
6.1.1 (2026-08-28)
Add compiler.logDiagnostics option
Recoverable React Compiler diagnostics are no longer logged by
default. Set compiler.logDiagnostics to true
to log them through Vite. Fatal diagnostics are always logged and fail
the transform.
Respect environment sourcemap option for React Compiler transform
when builder.sharedPlugins is enabled (#1439)
The React Compiler transform was using the top-level sourcemap option
instead of the environment sourcemap option. This caused a problem when
the experimental builder.sharedPlugins was enabled.
6.1.0 (2026-08-19)
Add experimental native React Compiler support (#1419)
Add experimental native React Compiler support.
You can use it by installing oxc-transform-react and
enabling it via the compiler option:
npm install -D oxc-transform-react
import { defineConfig } from 'vite'
import react from '@vitejs/plugin-react'
export default defineConfig({
plugins: [
react({ compiler: true })
]
})
6.0.5 (2026-07-30)
Fixed the react compiler preset filter to be linear (#1353)
The improved filter in v6.0.3 was non-linear and caused a performance
regression (#1349).
The filter was changed to be linear to avoid that.
6.0.4 (2026-07-22)
Fixed $RefreshSig$ is not defined error when running
vite dev with NODE_ENV=production
When running vite dev with
NODE_ENV=production, the app errored with
$RefreshSig$ is not defined.
This error is now fixed.
6.0.3 (2026-06-23)
Improve the react compiler preset filter to reduce false-positives
(#1138)
Improved the filter in the react compiler babel preset to reduce the
false-positives so that less modules are processed by the react
compiler.
... (truncated)
Commits
04cac50
release: plugin-react@6.1.1 (#1440)
82d35ab
fix(react): respect environment sourcemap option when
builder.sharedPlugins...
397e847
fix(react): make logging diagnostics an opt-in for React Compiler (#1431)
61006e6
fix(deps): update all non-major dependencies (#1433)
e2a649c
chore: use deps.neverBundle instead of
external in tsdown config (#1430)
fb2d6f3
fix(deps): update all non-major dependencies (#1427)
39b3173
release: plugin-react@6.1.0 (#1428)
f1340b0
feat(react): add native React Compiler support (#1419)
9ab698e
fix(deps): update all non-major dependencies (#1375)
68c0cb8
release: plugin-react@6.0.5 (#1362)
- Additional commits viewable in compare
view
Maintainer changes
This version was pushed to npm by GitHub Actions, a new
releaser for @vitejs/plugin-react since your current
version.
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
packages/paperclip-runner/package.json | 2 +-
pnpm-lock.yaml | 102 +++++--------------------
ui/package.json | 2 +-
3 files changed, 23 insertions(+), 83 deletions(-)
diff --git a/packages/paperclip-runner/package.json b/packages/paperclip-runner/package.json
index cc8619f568..6f05a2cb52 100644
--- a/packages/paperclip-runner/package.json
+++ b/packages/paperclip-runner/package.json
@@ -179,7 +179,7 @@
"@types/node": "^24.0.0",
"@types/react": "^19.2.17",
"@types/react-dom": "^19.2.3",
- "@vitejs/plugin-react": "^4.7.0",
+ "@vitejs/plugin-react": "^6.1.1",
"axe-core": "^4.12.1",
"react": "^19.2.7",
"react-dom": "^19.2.7",
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index 4d2ab65103..a4598b4cb7 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -515,8 +515,8 @@ importers:
specifier: ^19.2.3
version: 19.2.4(@types/react@19.2.18)
'@vitejs/plugin-react':
- specifier: ^4.7.0
- version: 4.7.0(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))
+ specifier: ^6.1.1
+ version: 6.1.1(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))
axe-core:
specifier: ^4.12.1
version: 4.13.0
@@ -1163,8 +1163,8 @@ importers:
specifier: ^19.2.4
version: 19.2.4(@types/react@19.2.18)
'@vitejs/plugin-react':
- specifier: ^5.2.0
- version: 5.2.0(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))
+ specifier: ^6.1.1
+ version: 6.1.1(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))
storybook:
specifier: 10.5.10
version: 10.5.10(@types/react@19.2.18)(react@19.2.8)
@@ -1492,10 +1492,6 @@ packages:
peerDependencies:
'@babel/core': ^7.0.0
- '@babel/helper-plugin-utils@7.29.7':
- resolution: {integrity: sha512-G7sHYigPY17oO5SYWnfD/0MTBwVR781S/JI643e/JhUYgVgWE/61SoW3NH9KWUKyKq5LVh3npif99Wkt6j86Jw==}
- engines: {node: '>=6.9.0'}
-
'@babel/helper-string-parser@7.29.7':
resolution: {integrity: sha512-Pb5ijPrZ89GDH8223L4UP8i6QApWxs04RbPQJTeWDV0/keR2E36MeKnyr6LYmUUvqRRI+Iv87SuF1W6ErINzYw==}
engines: {node: '>=6.9.0'}
@@ -1517,18 +1513,6 @@ packages:
engines: {node: '>=6.0.0'}
hasBin: true
- '@babel/plugin-transform-react-jsx-self@7.29.7':
- resolution: {integrity: sha512-TL0hMc9xzy86VD31nUiwzd5otRAcyEPcsegCxolO0PvcXuH1v0kECe/UIznYFihpkvU5wg/jk4v0TTEFfm53fw==}
- engines: {node: '>=6.9.0'}
- peerDependencies:
- '@babel/core': ^7.0.0-0
-
- '@babel/plugin-transform-react-jsx-source@7.29.7':
- resolution: {integrity: sha512-06IyK09H3wi4cGbhDBwp5gUGo0IKtnYa8tyTiephirPCK6fbobVGiXMMI5zLQ4aKEYP3wZ3ArU44o+8KMrSG/Q==}
- engines: {node: '>=6.9.0'}
- peerDependencies:
- '@babel/core': ^7.0.0-0
-
'@babel/runtime@7.29.7':
resolution: {integrity: sha512-Nq8OhGWiZIZGV6hLHoyAKLLcJihP/xFeBMGJoUrxTX2psI8dCifzLhZISFb+VWS3wFMRDmCGw5R+dOySCqPLhw==}
engines: {node: '>=6.9.0'}
@@ -4236,12 +4220,6 @@ packages:
cpu: [x64]
os: [win32]
- '@rolldown/pluginutils@1.0.0-beta.27':
- resolution: {integrity: sha512-+d0F4MKMCbeVUJwG96uQ4SgAznZNSq93I3V+9NHA4OpvqG8mRCpGdKmK8l/dl02h2CCDHwW2FqilnTyDcAnqjA==}
-
- '@rolldown/pluginutils@1.0.0-rc.3':
- resolution: {integrity: sha512-eybk3TjzzzV97Dlj5c+XrBFW57eTNhzod66y9HrBlzJ6NsCrWCp/2kaPS3K9wJmurBC0Tdw4yPjXKZqlznim3Q==}
-
'@rolldown/pluginutils@1.0.1':
resolution: {integrity: sha512-2j9bGt5Jh8hj+vPtgzPtl72j0yRxHAyumoo6TNfAjsLB04UtpSvPbPcDcBMxz7n+9CYB0c1GxQFxYRg2jimqGw==}
@@ -5101,17 +5079,21 @@ packages:
resolution: {integrity: sha512-nmVSeQ7tewCkqYBNB/MNL8aPB9sTvtjvqIE6+U17U4IuTyehuWVERDlWrSn0DVfiFAstRlRkGLHBlKHB2FyzbQ==}
engines: {node: '>= 20'}
- '@vitejs/plugin-react@4.7.0':
- resolution: {integrity: sha512-gUu9hwfWvvEDBBmgtAowQCojwZmJ5mcLn3aufeCsitijs3+f2NsrPtlAWIR6OPiqljl96GVCUbLe0HyqIpVaoA==}
- engines: {node: ^14.18.0 || >=16.0.0}
- peerDependencies:
- vite: ^4.2.0 || ^5.0.0 || ^6.0.0 || ^7.0.0
-
- '@vitejs/plugin-react@5.2.0':
- resolution: {integrity: sha512-YmKkfhOAi3wsB1PhJq5Scj3GXMn3WvtQ/JC0xoopuHoXSdmtdStOpFrYaT1kie2YgFBcIe64ROzMYRjCrYOdYw==}
+ '@vitejs/plugin-react@6.1.1':
+ resolution: {integrity: sha512-yxLaQV9gkhS8ezJqCM6+ndU7mDY6gqAg75NQ+0IjwEI8IYOmQCgkRwHKVSfWXW076DsqMo0Dk+0FK1U+M5RgFw==}
engines: {node: ^20.19.0 || >=22.12.0}
peerDependencies:
- vite: ^4.2.0 || ^5.0.0 || ^6.0.0 || ^7.0.0 || ^8.0.0
+ '@rolldown/plugin-babel': ^0.1.7 || ^0.2.0
+ babel-plugin-react-compiler: ^1.0.0
+ oxc-transform-react: ^0.145.0
+ vite: ^8.0.0
+ peerDependenciesMeta:
+ '@rolldown/plugin-babel':
+ optional: true
+ babel-plugin-react-compiler:
+ optional: true
+ oxc-transform-react:
+ optional: true
'@vitest/expect@3.2.4':
resolution: {integrity: sha512-Io0yyORnB6sikFlt8QW5K7slY4OjqNX9jmJQ02QDda8lyM6B5oNgVWoSoKPac8/kgnCUzuHQKrSLtu/uOqqrig==}
@@ -7550,14 +7532,6 @@ packages:
'@types/react': '>=18'
react: ^19.2.8
- react-refresh@0.17.0:
- resolution: {integrity: sha512-z6F7K9bV85EfseRCp2bzrpyQ0Gkw1uLoCel9XBVWPg/TjRj94SkJzUTGfOa4bs7iJvBWtQG0Wq7wnI0syw3EBQ==}
- engines: {node: '>=0.10.0'}
-
- react-refresh@0.18.0:
- resolution: {integrity: sha512-QgT5//D3jfjJb6Gsjxv0Slpj23ip+HtOpnNgnb2S5zU3CB26G/IDPGoy4RJB42wzFE46DRsstbW6tKHoKbhAxw==}
- engines: {node: '>=0.10.0'}
-
react-remove-scroll-bar@2.3.8:
resolution: {integrity: sha512-9r+yi9+mgU33AKcj6IbT9oRCO78WriSj6t/cF8DWBZJ9aOGPOTEDvdUDz1FwKim7QXWwmHqtdHnRJfhAxEG46Q==}
engines: {node: '>=10'}
@@ -8957,8 +8931,6 @@ snapshots:
transitivePeerDependencies:
- supports-color
- '@babel/helper-plugin-utils@7.29.7': {}
-
'@babel/helper-string-parser@7.29.7': {}
'@babel/helper-validator-identifier@7.29.7': {}
@@ -8974,16 +8946,6 @@ snapshots:
dependencies:
'@babel/types': 7.29.8
- '@babel/plugin-transform-react-jsx-self@7.29.7(@babel/core@7.29.7)':
- dependencies:
- '@babel/core': 7.29.7
- '@babel/helper-plugin-utils': 7.29.7
-
- '@babel/plugin-transform-react-jsx-source@7.29.7(@babel/core@7.29.7)':
- dependencies:
- '@babel/core': 7.29.7
- '@babel/helper-plugin-utils': 7.29.7
-
'@babel/runtime@7.29.7': {}
'@babel/template@7.29.7':
@@ -11578,10 +11540,6 @@ snapshots:
'@rolldown/binding-win32-x64-msvc@1.2.5':
optional: true
- '@rolldown/pluginutils@1.0.0-beta.27': {}
-
- '@rolldown/pluginutils@1.0.0-rc.3': {}
-
'@rolldown/pluginutils@1.0.1': {}
'@rollup/plugin-node-resolve@16.0.3(rollup@4.63.1)':
@@ -12385,29 +12343,15 @@ snapshots:
'@vercel/cli-exec': 1.0.1
jose: 5.10.0
- '@vitejs/plugin-react@4.7.0(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))':
+ '@vitejs/plugin-react@6.1.1(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))':
dependencies:
- '@babel/core': 7.29.7
- '@babel/plugin-transform-react-jsx-self': 7.29.7(@babel/core@7.29.7)
- '@babel/plugin-transform-react-jsx-source': 7.29.7(@babel/core@7.29.7)
- '@rolldown/pluginutils': 1.0.0-beta.27
- '@types/babel__core': 7.20.5
- react-refresh: 0.17.0
+ '@rolldown/pluginutils': 1.0.1
vite: 6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12)
- transitivePeerDependencies:
- - supports-color
- '@vitejs/plugin-react@5.2.0(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))':
+ '@vitejs/plugin-react@6.1.1(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))':
dependencies:
- '@babel/core': 7.29.7
- '@babel/plugin-transform-react-jsx-self': 7.29.7(@babel/core@7.29.7)
- '@babel/plugin-transform-react-jsx-source': 7.29.7(@babel/core@7.29.7)
- '@rolldown/pluginutils': 1.0.0-rc.3
- '@types/babel__core': 7.20.5
- react-refresh: 0.18.0
+ '@rolldown/pluginutils': 1.0.1
vite: 8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12)
- transitivePeerDependencies:
- - supports-color
'@vitest/expect@3.2.4':
dependencies:
@@ -15198,10 +15142,6 @@ snapshots:
transitivePeerDependencies:
- supports-color
- react-refresh@0.17.0: {}
-
- react-refresh@0.18.0: {}
-
react-remove-scroll-bar@2.3.8(@types/react@19.2.18)(react@19.2.8):
dependencies:
react: 19.2.8
diff --git a/ui/package.json b/ui/package.json
index 4dee922ded..2c467096c9 100644
--- a/ui/package.json
+++ b/ui/package.json
@@ -82,7 +82,7 @@
"@types/node": "^24.0.0",
"@types/react": "^19.2.18",
"@types/react-dom": "^19.2.4",
- "@vitejs/plugin-react": "^5.2.0",
+ "@vitejs/plugin-react": "^6.1.1",
"storybook": "10.5.10",
"tailwindcss": "^4.3.3",
"typescript": "^7.0.2",
From 2e8521e57c6dbee27f79ddba2d60759f82e583dc Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 3 Sep 2026 09:46:13 -0700
Subject: [PATCH 7/7] chore(deps): bump better-auth from 1.7.0 to 1.7.2
(#12565)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps
[better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth)
from 1.7.0 to 1.7.2.
Release notes
Sourced from better-auth's
releases.
v1.7.2
better-auth
Bug Fixes
- Fixed permanent user bans to clear expiration dates from previous
temporary bans. (#10823)
- Fixed client types with more plugins being assignable to types
declaring fewer plugins. (#10907)
- Added warnings for invalid signed session data in the cookie cache.
(#10934)
- Fixed disabled MyISAM indexes from satisfying migration index
checks. (#10877)
- Fixed programmatic migrations on Cloudflare D1 while preserving
existing-index validation. (#10875)
- Allowed
~ in relative callback URLs validated by
trusted-origin checks. (#10041)
- Improved validation of relative callback and redirect URLs with
paths, queries, and fragments. (#10979)
- Allowed same-origin form submissions with
Referrer-Policy:
no-referrer while continuing to reject untrusted origins. (#10959)
- Improved
getTestInstance performance with a faster
default password hasher. (#10879)
- Standardized built-in placeholder emails to the namespaced
{identifier}@{namespace}.placeholder.invalid format. (#10982)
For detailed changes, see CHANGELOG
@better-auth/core
Bug Fixes
- Fixed async context loss in Cloudflare Workers bundles with multiple
runtime conditions. (#10855)
- Fixed auth request logs to respect the configured logger, log level,
and disabled setting. (#10939)
- Improved validation of relative callback and redirect URLs with
paths, queries, and fragments. (#10979)
- Standardized built-in placeholder emails to the namespaced
{identifier}@{namespace}.placeholder.invalid format. (#10982)
- Added synchronous and optional access to the current auth endpoint
context. (#10938)
For detailed changes, see CHANGELOG
@better-auth/oauth-provider
Bug Fixes
- Fixed Client ID Metadata Document registration when clients share at
least one supported grant with the server. (#11010)
- Improved validation of relative callback and redirect URLs with
paths, queries, and fragments. (#10979)
- Fixed relative redirect URLs containing fragments. (#10983)
For detailed changes, see CHANGELOG
@better-auth/drizzle-adapter
Bug Fixes
- Fixed one-to-one Drizzle relations when
usePlural is
enabled. (#10941)
- Added validation for missing Drizzle schema fields in compound
where clauses. (#10859)
For detailed changes, see CHANGELOG
@better-auth/kysely-adapter
... (truncated)
Changelog
Sourced from better-auth's
changelog.
1.7.2
Patch Changes
-
#10875
d5d889b
Thanks @bytaesu!
- Fix programmatic migrations failing on Cloudflare D1 while preserving
existing-index validation across supported databases.
-
#10982
b4ad5a1
Thanks @bytaesu!
- Built-in placeholder emails now consistently use the namespaced
{identifier}@{namespace}.placeholder.invalid format.
-
#10934
c7a5c1a
Thanks @bytaesu!
- Cookie-cache reads now warn when signed session data is invalid
instead of silently appearing as a signed-out session.
-
#10879
78f0c39
Thanks @starslingdev!
- Test suites using getTestInstance now run faster because
the shared fixture avoids production password-hashing costs by default.
Custom emailAndPassword.password implementations continue
to take precedence.
-
#10823
ce8a3ab
Thanks @sosyz! -
Ensure permanently banning a user clears any expiration from a previous
temporary ban.
-
#10907
a021eaf
Thanks @heliohm!
- A client created with more plugins is again assignable to a client
type declaring fewer plugins, as in 1.6.
-
#10959
c8dcfa5
Thanks @bytaesu!
- Allow same-origin form submissions from pages using
Referrer-Policy: no-referrer while continuing to reject
untrusted request origins.
-
#10979
fced1a5
Thanks @bytaesu!
- Allow relative callback and redirect URLs to use standard path, query,
and fragment syntax while preserving open-redirect protections.
-
#10041
f6891a2
Thanks @GautamBytes! -
Allow ~ in relative callback URLs validated by trusted
origin checks.
-
#10877
649818a
Thanks @bytaesu!
- Prevent disabled MyISAM indexes from satisfying migration index
checks.
-
Updated dependencies [557e19b,
64da15b,
d5d889b,
b4ad5a1,
ea77118,
5aea9f7,
fced1a5,
e1d4011]:
@better-auth/core@1.7.2
@better-auth/kysely-adapter@1.7.2
@better-auth/drizzle-adapter@1.7.2
@better-auth/memory-adapter@1.7.2
@better-auth/mongo-adapter@1.7.2
@better-auth/prisma-adapter@1.7.2
@better-auth/telemetry@1.7.2
1.7.1
Patch Changes
-
#10863
845bbd1
Thanks @gustavovalverde!
- auth migrate no longer attempts to add a required column
with no default value to a table that already has rows. It stops with an
error naming the column and the backfill to run first. Previously the
generated statement failed on SQLite, Postgres, and SQL Server; on MySQL
it filled the new column with an empty string for every existing row and
reported success. If auth migrate already ran against a
MySQL database on 1.7, run the check in the upgrade guide's account
identity section.
getMigrations throws the new
UnsafeMigrationError (exported from
better-auth/db/migration) for this refusal, so callers can
distinguish it from other migration errors such as an index-definition
conflict.
auth generate still emits the statements for external
migration tooling, with a comment banner naming any column that needs a
manual backfill first.
A required field whose database column is still nullable logs a
warning instead of blocking the migration.
A CLI command that fails now prints its error and exits with a
non-zero code instead of an unhandled promise rejection.
-
Updated dependencies []:
@better-auth/core@1.7.1
@better-auth/drizzle-adapter@1.7.1
... (truncated)
Commits
ba12fcd
chore: release v1.7.2 (#10870)
79904f0
fix(origin-check): support fragments in relative redirect URLs (#10983)
c8dcfa5
fix(origin-check): validate null origins using fetch metadata (#10959)
e1d4011
fix(logger): respect configured logger in auth request context (#10939)
557e19b
refactor(context): clarify auth endpoint context access (#10938)
b4ad5a1
refactor: centralize placeholder email generation (#10982)
fced1a5
fix(origin-check): improve relative callback URL validation (#10979)
f6891a2
fix(origin-check): allow tilde in relative callback URLs (#10041)
ce8a3ab
fix(admin): ban without a duration should clear the previous expiration
(#10823)
a021eaf
fix(client): a client with more plugins fits a narrower client type
again (#1...
- Additional commits viewable in compare
view
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
pnpm-lock.yaml | 217 ++++++++++++++++++++++----------------------
server/package.json | 2 +-
2 files changed, 110 insertions(+), 109 deletions(-)
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index a4598b4cb7..e2e36cb61a 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -50,7 +50,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
cli:
dependencies:
@@ -281,7 +281,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/adapters/hermes-gateway:
dependencies:
@@ -297,7 +297,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/adapters/kimi-local:
dependencies:
@@ -398,7 +398,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/google-sheets-mcp-server:
dependencies:
@@ -420,7 +420,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/kv-demo-mcp-server:
dependencies:
@@ -439,7 +439,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/mcp-server:
dependencies:
@@ -461,7 +461,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/paperclip-eval-kernel:
devDependencies:
@@ -537,7 +537,7 @@ importers:
version: 6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12)
vitest:
specifier: ^4.1.10
- version: 4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.3.0))(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))
+ version: 4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.4.0))(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))
packages/plugins/create-paperclip-plugin:
dependencies:
@@ -584,7 +584,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/plugins/examples/plugin-file-browser-example:
dependencies:
@@ -702,7 +702,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/plugins/plugin-llm-wiki:
devDependencies:
@@ -741,7 +741,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/plugins/plugin-workspace-diff:
dependencies:
@@ -775,7 +775,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages/plugins/sdk:
dependencies:
@@ -829,7 +829,7 @@ importers:
version: 7.0.2
vitest:
specifier: ^4.1.10
- version: 4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.3.0))(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))
+ version: 4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.4.0))(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))
packages/teams-catalog:
devDependencies:
@@ -895,7 +895,7 @@ importers:
version: link:../packages/skills-catalog
'@vercel/connect':
specifier: 0.6.1
- version: 0.6.1(better-auth@1.7.0(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)))
+ version: 0.6.1(better-auth@1.7.2(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)))
acpx:
specifier: 0.13.1
version: 0.13.1(patch_hash=lzpwjtiaybzoijy455dfycwavu)
@@ -906,8 +906,8 @@ importers:
specifier: ^3.0.1
version: 3.0.1(ajv@8.20.0)
better-auth:
- specifier: 1.7.0
- version: 1.7.0(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12))
+ specifier: 1.7.2
+ version: 1.7.2(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12))
chokidar:
specifier: ^5.0.0
version: 5.0.0
@@ -931,7 +931,7 @@ importers:
version: 5.2.1
jsdom:
specifier: ^30.0.1
- version: 30.0.1(@noble/hashes@2.3.0)
+ version: 30.0.1(@noble/hashes@2.4.0)
multer:
specifier: ^2.2.0
version: 2.2.0
@@ -1004,7 +1004,7 @@ importers:
version: 8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12)
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
ui:
dependencies:
@@ -1179,7 +1179,7 @@ importers:
version: 8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12)
vitest:
specifier: ^4.1.10
- version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
packages:
@@ -1556,8 +1556,8 @@ packages:
'@types/react':
optional: true
- '@better-auth/core@1.7.0':
- resolution: {integrity: sha512-tUYocrJx6vYyf0k9CTAgAYtUFFRZIrcwNIhG3+WSUQGTPrcyl/hbo29Y9ynF2LwOZOwIwWCiis1A6Iqej4jC/g==}
+ '@better-auth/core@1.7.2':
+ resolution: {integrity: sha512-j0nM4ygsWbF/fcYRoKtDn8gn8uLXkmC+075HqSqsJEAV828cJR9bvYBCUQ1zmxNyRBk6Iz/qXsA0Zm2oksiOTg==}
peerDependencies:
'@better-auth/utils': 0.4.2
'@better-fetch/fetch': 1.3.1
@@ -1573,46 +1573,46 @@ packages:
'@opentelemetry/api':
optional: true
- '@better-auth/drizzle-adapter@1.7.0':
- resolution: {integrity: sha512-PQ7kT9unMmRFl8u3iwri31Ztx3vluuWL4Lq/SRpOpdU5Y0BMII5zpNLfahY5DOVRg9SHAcnWjs0gcwRxxQMuWQ==}
+ '@better-auth/drizzle-adapter@1.7.2':
+ resolution: {integrity: sha512-A5wE10PIv3aS5LGePecEHntQylKy6OOF17B4dqlE0DwJeqU/IOBSd7/LZhMop9cNJ3WFjKMpazVSf91yYM/NFg==}
peerDependencies:
- '@better-auth/core': ^1.7.0
+ '@better-auth/core': ^1.7.2
'@better-auth/utils': 0.4.2
drizzle-orm: ^0.45.2 || >=1.0.0-rc.1 <2.0.0
peerDependenciesMeta:
drizzle-orm:
optional: true
- '@better-auth/kysely-adapter@1.7.0':
- resolution: {integrity: sha512-hpLMMJiLGsLF35D6Z0dMRtyax4c1uKMRgCNeHs8v+hBVJr8gh+PuKTPAS4p7P9gAYSz74kqG+i/+Ot/EnBl6xA==}
+ '@better-auth/kysely-adapter@1.7.2':
+ resolution: {integrity: sha512-LYdSRLOvZiF+6S0UThu+wE/Qxsq9P2jQs7ZKkY6BIBJqUjYyxVDmi8HFcantBvWWW1/BeQCSsD7YVDG4gICMIQ==}
peerDependencies:
- '@better-auth/core': ^1.7.0
+ '@better-auth/core': ^1.7.2
'@better-auth/utils': 0.4.2
kysely: ^0.28.17 || ^0.29.0
peerDependenciesMeta:
kysely:
optional: true
- '@better-auth/memory-adapter@1.7.0':
- resolution: {integrity: sha512-87D5BW931Uh+ap8al7nPZZjLHK3Qje3KuvOJ4cJ9yLkb7n6+CLHJAbwJ8yDTe4RY52smCaMm+uEq3vCtlOmLUw==}
+ '@better-auth/memory-adapter@1.7.2':
+ resolution: {integrity: sha512-0q1SXMzm5esH9L0xVuM6IxCk59E4G+3HySX4My9gvEwqtmUobykn+iuc/si3Y4xwUO7JODqQ5o+/pPcLDDMIrA==}
peerDependencies:
- '@better-auth/core': ^1.7.0
+ '@better-auth/core': ^1.7.2
'@better-auth/utils': 0.4.2
- '@better-auth/mongo-adapter@1.7.0':
- resolution: {integrity: sha512-2FPZ/gvFnkFWQowXmfcxL+Ae27ZFGmXSsldD7Z29Gneh17tJGPTPpIW22d/ci2J1+744f1bQku+PdCkbZ6j6JA==}
+ '@better-auth/mongo-adapter@1.7.2':
+ resolution: {integrity: sha512-4879SmUWHUs0OYlvHoCFbycZ7i1bqytkcgAUdt9RLQMvZ5H3LRMTgax2YVlGZEXgwNjY/X7xAoXOecWLhlQWeA==}
peerDependencies:
- '@better-auth/core': ^1.7.0
+ '@better-auth/core': ^1.7.2
'@better-auth/utils': 0.4.2
mongodb: ^6.0.0 || ^7.0.0
peerDependenciesMeta:
mongodb:
optional: true
- '@better-auth/prisma-adapter@1.7.0':
- resolution: {integrity: sha512-LLyyNaXzZrUZ4wLEp58JzpCgbQvuyZFCZqinqd8LTfMwuZG6Z+DEDKIkIsCfUb5wrZjUZ+v2o898EEO0yLHnwQ==}
+ '@better-auth/prisma-adapter@1.7.2':
+ resolution: {integrity: sha512-mXTr/83WrNWLrvzIjtgDgdu9iXhOcSG1+qBQOAKlbGSFiOB+z4IMRneQ2wmMOiB8mKY9qGkClVUjKRFXqtHnFQ==}
peerDependencies:
- '@better-auth/core': ^1.7.0
+ '@better-auth/core': ^1.7.2
'@better-auth/utils': 0.4.2
'@prisma/client': ^5.0.0 || ^6.0.0 || ^7.0.0
prisma: ^5.0.0 || ^6.0.0 || ^7.0.0
@@ -1622,10 +1622,10 @@ packages:
prisma:
optional: true
- '@better-auth/telemetry@1.7.0':
- resolution: {integrity: sha512-sIYgwq/Oc/QlgBGNjWju0gwa1hWlkrrpdTiPd7gGBMS9nzp+6l9zU6k6QFug6wjbDSzUsRHOZIXs2EIn9NcOFQ==}
+ '@better-auth/telemetry@1.7.2':
+ resolution: {integrity: sha512-LcWu+O0zrxYDQj8E36vfkJwGPW4k9ZDA/rCo0zST6ihzL+juR7pBowoZIM9E6tK0Vit52mf6412bGT4XM4eTjQ==}
peerDependencies:
- '@better-auth/core': ^1.7.0
+ '@better-auth/core': ^1.7.2
'@better-auth/utils': 0.4.2
'@better-fetch/fetch': 1.3.1
@@ -2914,16 +2914,16 @@ packages:
'@emnapi/core': ^1.7.1 || ^2.0.0-alpha.4
'@emnapi/runtime': ^1.7.1 || ^2.0.0-alpha.4
- '@noble/ciphers@2.3.0':
- resolution: {integrity: sha512-Clu/xdfgVTf9o7ngLOURaxePwR0j8sjclKEtVij10/jGulwFsPWCvvRgG/XjUVf8Nei+jLG6uwyXzUTGY1DQrw==}
+ '@noble/ciphers@2.4.0':
+ resolution: {integrity: sha512-AnjFn0Jv92laAkvMrghlFZq4qQCIN/4DxFV/eooqtC2YTjB7kBeLMS2T9KJX4Dn+ZVXLOwK0lSgqDtx9gvxtiw==}
engines: {node: '>= 20.19.0'}
'@noble/hashes@1.8.0':
resolution: {integrity: sha512-jCs9ldd7NwzpgXDIf6P3+NrHh9/sD6CQdxHyjQI+h/6rDNo88ypBxxz45UDuZHz9r3tNz7N/VInSVoVdtXEI4A==}
engines: {node: ^14.21.3 || >=16}
- '@noble/hashes@2.3.0':
- resolution: {integrity: sha512-oN+QwyX7VSHotibwubG3kpzbwKrfnyR6OOO+3Nk/53ADL7FmgHHz4TgrbaYKvvOw09u6QTx0oiH1cNCIOuN0CQ==}
+ '@noble/hashes@2.4.0':
+ resolution: {integrity: sha512-X5XaVWZIBCT7HHZGm5I7ZQXDwLG+bGXuSrMQAW+7Zvl87h1kmc1ZB1VSRJcpUfoUrGQp4Fkoxm5kZ+Ms+aW+eA==}
engines: {node: '>= 20.19.0'}
'@openai/codex@0.148.0':
@@ -5372,8 +5372,8 @@ packages:
bcrypt-pbkdf@1.0.2:
resolution: {integrity: sha512-qeFIXtP4MSoi6NLqO12WfqARWWuCKi2Rn/9hJLEmtB5yTNr9DqFWkJRCf2qShWzPeAMRnOgCrq0sg/KLv5ES9w==}
- better-auth@1.7.0:
- resolution: {integrity: sha512-azEG/7e4TLZ25TvvgcsolnzOzLfDFovdIYUb7xKeZQOm0p6Vj+rRKKaIvwE4MvXZCff6NAiIH2dMPl8O5yxI+A==}
+ better-auth@1.7.2:
+ resolution: {integrity: sha512-gKapKBEvYIGcMxi74RjQ7EbFLiqyQt58vdoJmL1qAlWSkY1Bc2Vqshl524/3u1NxauiOU03M/Ebh762Brmac9A==}
peerDependencies:
'@lynx-js/react': '*'
'@prisma/client': ^5.0.0 || ^6.0.0 || ^7.0.0
@@ -6558,12 +6558,12 @@ packages:
jose@5.10.0:
resolution: {integrity: sha512-s+3Al/p9g32Iq+oqXxkW//7jk2Vig6FF1CFqzVXoTUXt2qz89YWbL+OwS17NFYEvxC35n0FKeGO2LGYSxeM2Gg==}
+ jose@6.2.10:
+ resolution: {integrity: sha512-iiW7J9qRFlGxvCOIBDBDxFePQSn7ZMAnrYGhrrOo6siO/MIqwfyilLR27pkfDgUk+raLuzADS8A3S/KLBisc0g==}
+
jose@6.2.8:
resolution: {integrity: sha512-Bsdjwm3Qsd/P0jR+BHDe3LytDfY7WBq2HmCCLIwuVRHMuEC9ae7/R474GIUdF1NgCyZjzVo/A9DOiOBtXq8ZoQ==}
- jose@6.2.9:
- resolution: {integrity: sha512-XrchZOFZUl/T3vTwRe8XK+cJrGtMF4th1ARnDfwbBXFKThGhlsxEE4Zu03AD/bjJSt/9jT/mxrOCkJWOg77aPA==}
-
joycon@3.1.1:
resolution: {integrity: sha512-34wB/Y7MW7bzjKRjUKTa46I2Z7eV62Rkhva+KkopW7Qvv/OSWBqvkSY7vusOPrNuZcUG3tApvdVgNB8POj3SPw==}
engines: {node: '>=10'}
@@ -7124,8 +7124,8 @@ packages:
engines: {node: ^22 || ^24 || >=26}
hasBin: true
- nanostores@1.5.2:
- resolution: {integrity: sha512-B0UbxzK1s0CN8Xht6r+7iT5+xV8PTaRERR1nATeplRv1Rw5YLWfVAid0hkqY3EceqpG4RjTk8GAwIxQY39Rnwg==}
+ nanostores@1.5.3:
+ resolution: {integrity: sha512-rQLB6eV4f2AW/n3L0JmwCROpaisYy9EDEADvEFSd1C/qG8hB6O5TPlh9A791JRbJr4CnMQBzptDcvD9OR1+6WA==}
engines: {node: ^20.0.0 || >=22.0.0}
negotiator@1.0.0:
@@ -7192,6 +7192,7 @@ packages:
opencode-ai@1.18.17:
resolution: {integrity: sha512-Pc2D3Y6iQ3BAjcKw9E+9J7VTWNazIwFknFfrolufMCrJ0FLxOIZfndoHmJrx4x1oqpK2CPAqK9D2V6nsp6Oebw==}
+ cpu: [arm64, x64]
os: [darwin, linux, win32]
hasBin: true
@@ -8994,62 +8995,62 @@ snapshots:
optionalDependencies:
'@types/react': 19.2.18
- '@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)':
+ '@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)':
dependencies:
'@better-auth/utils': 0.4.2
'@better-fetch/fetch': 1.3.1
'@opentelemetry/semantic-conventions': 1.43.0
'@standard-schema/spec': 1.1.0
better-call: 1.4.0(zod@4.4.3)
- jose: 6.2.9
+ jose: 6.2.10
kysely: 0.29.5
- nanostores: 1.5.2
+ nanostores: 1.5.3
zod: 4.4.3
optionalDependencies:
'@opentelemetry/api': 1.9.1
- '@better-auth/drizzle-adapter@1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))':
+ '@better-auth/drizzle-adapter@1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))':
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
'@better-auth/utils': 0.4.2
optionalDependencies:
drizzle-orm: 0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9)
- '@better-auth/kysely-adapter@1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)(kysely@0.29.5)':
+ '@better-auth/kysely-adapter@1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)(kysely@0.29.5)':
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
'@better-auth/utils': 0.4.2
optionalDependencies:
kysely: 0.29.5
- '@better-auth/memory-adapter@1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)':
+ '@better-auth/memory-adapter@1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)':
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
'@better-auth/utils': 0.4.2
- '@better-auth/mongo-adapter@1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)':
+ '@better-auth/mongo-adapter@1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)':
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
'@better-auth/utils': 0.4.2
- '@better-auth/prisma-adapter@1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)':
+ '@better-auth/prisma-adapter@1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)':
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
'@better-auth/utils': 0.4.2
- '@better-auth/telemetry@1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)':
+ '@better-auth/telemetry@1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)':
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
'@better-auth/utils': 0.4.2
'@better-fetch/fetch': 1.3.1
'@better-auth/utils@0.4.2':
dependencies:
- '@noble/hashes': 2.3.0
+ '@noble/hashes': 2.4.0
'@better-auth/utils@0.5.0':
dependencies:
- '@noble/hashes': 2.3.0
+ '@noble/hashes': 2.4.0
'@better-fetch/fetch@1.3.1': {}
@@ -9745,9 +9746,9 @@ snapshots:
'@esbuild/win32-x64@0.28.2':
optional: true
- '@exodus/bytes@1.15.1(@noble/hashes@2.3.0)':
+ '@exodus/bytes@1.15.1(@noble/hashes@2.4.0)':
optionalDependencies:
- '@noble/hashes': 2.3.0
+ '@noble/hashes': 2.4.0
'@fastify/busboy@2.1.1': {}
@@ -10381,11 +10382,11 @@ snapshots:
'@tybys/wasm-util': 0.10.3
optional: true
- '@noble/ciphers@2.3.0': {}
+ '@noble/ciphers@2.4.0': {}
'@noble/hashes@1.8.0': {}
- '@noble/hashes@2.3.0': {}
+ '@noble/hashes@2.4.0': {}
'@openai/codex@0.148.0':
optionalDependencies:
@@ -12331,11 +12332,11 @@ snapshots:
dependencies:
execa: 5.1.1
- '@vercel/connect@0.6.1(better-auth@1.7.0(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)))':
+ '@vercel/connect@0.6.1(better-auth@1.7.2(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)))':
dependencies:
'@vercel/oidc': 3.8.2
optionalDependencies:
- better-auth: 1.7.0(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12))
+ better-auth: 1.7.2(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12))
'@vercel/oidc@3.8.2':
dependencies:
@@ -12632,24 +12633,24 @@ snapshots:
dependencies:
tweetnacl: 0.14.5
- better-auth@1.7.0(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)):
+ better-auth@1.7.2(@opentelemetry/api@1.9.1)(drizzle-kit@0.31.10)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))(pg@8.18.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)):
dependencies:
- '@better-auth/core': 1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2)
- '@better-auth/drizzle-adapter': 1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))
- '@better-auth/kysely-adapter': 1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)(kysely@0.29.5)
- '@better-auth/memory-adapter': 1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)
- '@better-auth/mongo-adapter': 1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)
- '@better-auth/prisma-adapter': 1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)
- '@better-auth/telemetry': 1.7.0(@better-auth/core@1.7.0(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.9)(kysely@0.29.5)(nanostores@1.5.2))(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)
+ '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3)
+ '@better-auth/drizzle-adapter': 1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)(drizzle-orm@0.45.2(@opentelemetry/api@1.9.1)(kysely@0.29.5)(pg@8.18.0)(postgres@3.4.9))
+ '@better-auth/kysely-adapter': 1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)(kysely@0.29.5)
+ '@better-auth/memory-adapter': 1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)
+ '@better-auth/mongo-adapter': 1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)
+ '@better-auth/prisma-adapter': 1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)
+ '@better-auth/telemetry': 1.7.2(@better-auth/core@1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.10)(kysely@0.29.5)(nanostores@1.5.3))(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)
'@better-auth/utils': 0.4.2
'@better-fetch/fetch': 1.3.1
- '@noble/ciphers': 2.3.0
- '@noble/hashes': 2.3.0
+ '@noble/ciphers': 2.4.0
+ '@noble/hashes': 2.4.0
better-call: 1.4.0(zod@4.4.3)
defu: 6.1.7
- jose: 6.2.9
+ jose: 6.2.10
kysely: 0.29.5
- nanostores: 1.5.2
+ nanostores: 1.5.3
zod: 4.4.3
optionalDependencies:
drizzle-kit: 0.31.10
@@ -12657,7 +12658,7 @@ snapshots:
pg: 8.18.0
react: 19.2.8
react-dom: 19.2.8(react@19.2.8)
- vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12)
+ vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12)
transitivePeerDependencies:
- '@cloudflare/workers-types'
- '@opentelemetry/api'
@@ -13075,10 +13076,10 @@ snapshots:
data-uri-to-buffer@4.0.1: {}
- data-urls@7.0.0(@noble/hashes@2.3.0):
+ data-urls@7.0.0(@noble/hashes@2.4.0):
dependencies:
whatwg-mimetype: 5.0.0
- whatwg-url: 16.0.1(@noble/hashes@2.3.0)
+ whatwg-url: 16.0.1(@noble/hashes@2.4.0)
transitivePeerDependencies:
- '@noble/hashes'
@@ -13713,9 +13714,9 @@ snapshots:
hono@4.13.2: {}
- html-encoding-sniffer@6.0.0(@noble/hashes@2.3.0):
+ html-encoding-sniffer@6.0.0(@noble/hashes@2.4.0):
dependencies:
- '@exodus/bytes': 1.15.1(@noble/hashes@2.3.0)
+ '@exodus/bytes': 1.15.1(@noble/hashes@2.4.0)
transitivePeerDependencies:
- '@noble/hashes'
@@ -13831,9 +13832,9 @@ snapshots:
jose@5.10.0: {}
- jose@6.2.8: {}
+ jose@6.2.10: {}
- jose@6.2.9: {}
+ jose@6.2.8: {}
joycon@3.1.1: {}
@@ -13843,17 +13844,17 @@ snapshots:
dependencies:
argparse: 2.0.1
- jsdom@30.0.1(@noble/hashes@2.3.0):
+ jsdom@30.0.1(@noble/hashes@2.4.0):
dependencies:
'@asamuzakjp/css-color': 6.0.7
'@asamuzakjp/dom-selector': 8.3.2
'@bramus/specificity': 2.4.2
'@csstools/css-syntax-patches-for-csstree': 1.1.8(css-tree@3.2.1)
- '@exodus/bytes': 1.15.1(@noble/hashes@2.3.0)
+ '@exodus/bytes': 1.15.1(@noble/hashes@2.4.0)
css-tree: 3.2.1
- data-urls: 7.0.0(@noble/hashes@2.3.0)
+ data-urls: 7.0.0(@noble/hashes@2.4.0)
decimal.js: 10.6.0
- html-encoding-sniffer: 6.0.0(@noble/hashes@2.3.0)
+ html-encoding-sniffer: 6.0.0(@noble/hashes@2.4.0)
is-potential-custom-element-name: 1.0.1
lru-cache: 11.5.2
parse5: 8.0.1
@@ -13864,7 +13865,7 @@ snapshots:
w3c-xmlserializer: 5.0.0
webidl-conversions: 8.0.1
whatwg-mimetype: 5.0.0
- whatwg-url: 17.1.0(@noble/hashes@2.3.0)
+ whatwg-url: 17.1.0(@noble/hashes@2.4.0)
xml-name-validator: 5.0.0
transitivePeerDependencies:
- '@noble/hashes'
@@ -14638,7 +14639,7 @@ snapshots:
nanoid@6.0.1: {}
- nanostores@1.5.2: {}
+ nanostores@1.5.3: {}
negotiator@1.0.0: {}
@@ -15986,7 +15987,7 @@ snapshots:
jiti: 2.7.0
tsx: 4.23.12
- vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.3.0))(tsx@4.23.12):
+ vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(jsdom@30.0.1(@noble/hashes@2.4.0))(tsx@4.23.12):
dependencies:
'@vitest/expect': 4.1.10
'@vitest/mocker': 4.1.10(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))
@@ -16011,7 +16012,7 @@ snapshots:
optionalDependencies:
'@opentelemetry/api': 1.9.1
'@types/node': 24.13.3
- jsdom: 30.0.1(@noble/hashes@2.3.0)
+ jsdom: 30.0.1(@noble/hashes@2.4.0)
transitivePeerDependencies:
- '@vitejs/devtools'
- esbuild
@@ -16026,7 +16027,7 @@ snapshots:
- tsx
- yaml
- vitest@4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.3.0))(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12)):
+ vitest@4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.4.0))(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12)):
dependencies:
'@vitest/expect': 4.1.11
'@vitest/mocker': 4.1.11(vite@6.4.3(@types/node@24.13.3)(jiti@2.7.0)(lightningcss@1.33.0)(tsx@4.23.12))
@@ -16051,11 +16052,11 @@ snapshots:
optionalDependencies:
'@opentelemetry/api': 1.9.1
'@types/node': 24.13.3
- jsdom: 30.0.1(@noble/hashes@2.3.0)
+ jsdom: 30.0.1(@noble/hashes@2.4.0)
transitivePeerDependencies:
- msw
- vitest@4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.3.0))(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12)):
+ vitest@4.1.11(@opentelemetry/api@1.9.1)(@types/node@24.13.3)(jsdom@30.0.1(@noble/hashes@2.4.0))(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12)):
dependencies:
'@vitest/expect': 4.1.11
'@vitest/mocker': 4.1.11(vite@8.2.2(@types/node@24.13.3)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.12))
@@ -16080,7 +16081,7 @@ snapshots:
optionalDependencies:
'@opentelemetry/api': 1.9.1
'@types/node': 24.13.3
- jsdom: 30.0.1(@noble/hashes@2.3.0)
+ jsdom: 30.0.1(@noble/hashes@2.4.0)
transitivePeerDependencies:
- msw
@@ -16100,17 +16101,17 @@ snapshots:
whatwg-mimetype@5.0.0: {}
- whatwg-url@16.0.1(@noble/hashes@2.3.0):
+ whatwg-url@16.0.1(@noble/hashes@2.4.0):
dependencies:
- '@exodus/bytes': 1.15.1(@noble/hashes@2.3.0)
+ '@exodus/bytes': 1.15.1(@noble/hashes@2.4.0)
tr46: 6.0.0
webidl-conversions: 8.0.1
transitivePeerDependencies:
- '@noble/hashes'
- whatwg-url@17.1.0(@noble/hashes@2.3.0):
+ whatwg-url@17.1.0(@noble/hashes@2.4.0):
dependencies:
- '@exodus/bytes': 1.15.1(@noble/hashes@2.3.0)
+ '@exodus/bytes': 1.15.1(@noble/hashes@2.4.0)
tr46: 6.0.0
webidl-conversions: 8.0.1
transitivePeerDependencies:
diff --git a/server/package.json b/server/package.json
index 31f14682a8..498feca490 100644
--- a/server/package.json
+++ b/server/package.json
@@ -66,7 +66,7 @@
"acpx": "0.13.1",
"ajv": "^8.20.0",
"ajv-formats": "^3.0.1",
- "better-auth": "1.7.0",
+ "better-auth": "1.7.2",
"chokidar": "^5.0.0",
"detect-port": "^2.1.0",
"dompurify": "^3.4.13",