build(deps): bump the prod-npm-minor-dependencies group with 11 updates#743
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
build(deps): bump the prod-npm-minor-dependencies group with 11 updates#743dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the prod-npm-minor-dependencies group with 11 updates: | Package | From | To | | --- | --- | --- | | [@sentry/react](https://github.com/getsentry/sentry-javascript) | `10.46.0` | `10.48.0` | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.95.2` | `5.99.0` | | [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) | `12.10.1` | `12.10.2` | | [axios](https://github.com/axios/axios) | `1.13.6` | `1.15.0` | | [dotenv](https://github.com/motdotla/dotenv) | `17.3.1` | `17.4.2` | | [lodash](https://github.com/lodash/lodash) | `4.17.23` | `4.18.1` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.4` | `19.2.5` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.2.5` | | [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.72.0` | `7.72.1` | | [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.13.2` | `7.14.0` | | [sql-formatter](https://github.com/sql-formatter-org/sql-formatter) | `15.7.2` | `15.7.3` | Updates `@sentry/react` from 10.46.0 to 10.48.0 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@10.46.0...10.48.0) Updates `@tanstack/react-query` from 5.95.2 to 5.99.0 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.99.0/packages/react-query) Updates `@xyflow/react` from 12.10.1 to 12.10.2 - [Release notes](https://github.com/xyflow/xyflow/releases) - [Changelog](https://github.com/xyflow/xyflow/blob/main/packages/react/CHANGELOG.md) - [Commits](https://github.com/xyflow/xyflow/commits/@xyflow/react@12.10.2/packages/react) Updates `axios` from 1.13.6 to 1.15.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.13.6...v1.15.0) Updates `dotenv` from 17.3.1 to 17.4.2 - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v17.3.1...v17.4.2) Updates `lodash` from 4.17.23 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.23...4.18.1) Updates `react` from 19.2.4 to 19.2.5 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react) Updates `react-dom` from 19.2.4 to 19.2.5 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react-dom) Updates `react-hook-form` from 7.72.0 to 7.72.1 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](react-hook-form/react-hook-form@v7.72.0...v7.72.1) Updates `react-router-dom` from 7.13.2 to 7.14.0 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.14.0/packages/react-router-dom) Updates `sql-formatter` from 15.7.2 to 15.7.3 - [Release notes](https://github.com/sql-formatter-org/sql-formatter/releases) - [Commits](sql-formatter-org/sql-formatter@v15.7.2...v15.7.3) --- updated-dependencies: - dependency-name: "@sentry/react" dependency-version: 10.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-npm-minor-dependencies - dependency-name: "@tanstack/react-query" dependency-version: 5.99.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-npm-minor-dependencies - dependency-name: "@xyflow/react" dependency-version: 12.10.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-npm-minor-dependencies - dependency-name: axios dependency-version: 1.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-npm-minor-dependencies - dependency-name: dotenv dependency-version: 17.4.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-npm-minor-dependencies - dependency-name: lodash dependency-version: 4.18.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-npm-minor-dependencies - dependency-name: react dependency-version: 19.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-npm-minor-dependencies - dependency-name: react-dom dependency-version: 19.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-npm-minor-dependencies - dependency-name: react-hook-form dependency-version: 7.72.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-npm-minor-dependencies - dependency-name: react-router-dom dependency-version: 7.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-npm-minor-dependencies - dependency-name: sql-formatter dependency-version: 15.7.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-npm-minor-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Rust | Apr 13, 2026 12:06p.m. | Review ↗ | |
| Shell | Apr 13, 2026 12:06p.m. | Review ↗ | |
| JavaScript | Apr 13, 2026 12:06p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the prod-npm-minor-dependencies group with 11 updates:
10.46.010.48.05.95.25.99.012.10.112.10.21.13.61.15.017.3.117.4.24.17.234.18.119.2.419.2.519.2.419.2.57.72.07.72.17.13.27.14.015.7.215.7.3Updates
@sentry/reactfrom 10.46.0 to 10.48.0Release notes
Sourced from
@sentry/react's releases.... (truncated)
Changelog
Sourced from
@sentry/react's changelog.... (truncated)
Commits
a67df4drelease: 10.48.0e0732ffMerge pull request #20172 from getsentry/prepare-release/10.48.0d1ee40fmeta(changelog): Update changelog for 10.48.02897297feat(nuxt): Exclude tracing meta tags on cached pages in Nuxt 5 (#20168)1cc3dd0chore(deps-dev): Bump effect from 3.20.0 to 3.21.0 (#19999)c273167fix(core): FixwithStreamedSpantyping error add missing exports (#20124)b6f7b86feat(core): ApplyignoreSpansto streamed spans (#19934)7bd8449test(node,node-core): Add span streaming integration tests (#19806)51fc6d1feat(node-core): Add POtel server-side span streaming implementation (#19741)77357c7fix(core): Replace global interval with trace-specific interval based flushin...Updates
@tanstack/react-queryfrom 5.95.2 to 5.99.0Release notes
Sourced from
@tanstack/react-query's releases.... (truncated)
Changelog
Sourced from
@tanstack/react-query's changelog.Commits
adc2543ci: Version Packages (#10454)6040278ci: Version Packages (#10451)125067cci: Version Packages (#10436)f699190test(react-query): replace hardcoded query keys with 'queryKey()' utility (#1...f3d3eeatest(*): replace deprecated 'toMatchTypeOf' with 'toExtend' (#10413)3d6e001test(react-query/useSuspenseQueries): replace 'async/await sleep' with 'sleep...7d7a21ctest(react-query): replace 'async/await sleep' with 'sleep().then()' in test ...5ca721fci: Version Packages (#10379)75052a7ci: Version Packages (#10370)73e783bci: Version Packages (#10364)Updates
@xyflow/reactfrom 12.10.1 to 12.10.2Release notes
Sourced from
@xyflow/react's releases.Changelog
Sourced from
@xyflow/react's changelog.Commits
ba0a361chore(packages): bump613ad30Merge pull request #5733 from AlaricBaraou/fix/store-reset-timing-on-remounta6c938fExplicitly allow missingtypefield in BuiltInNode type definitionf2831bdMerge pull request #5727 from unifygtm/clear-nodes-selection-active0e48d84ReturnhasSelectedNodesfromadoptUserNodesand use it to update `nodesSe...6db2bd0fix(react): prevent empty store during ReactFlow remounte7b78d1Merge pull request #5720 from yarikoptic/enh-codespell38f4fefMerge pull request #5722 from dfblhmm/fix/type-definition759042dFix spacing in store/index.ts52d452bCentralize nodesSelectionActive update in setNodes of storeUpdates
axiosfrom 1.13.6 to 1.15.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
772a4e5chore(release): prepare release 1.15.0 (#10671)4b07137chore(deps-dev): bump vite from 8.0.0 to 8.0.5 in /tests/smoke/esm (#10663)51e57b3chore(deps-dev): bump vite from 8.0.2 to 8.0.5 (#10664)fba1a77chore(deps-dev): bump vite from 8.0.2 to 8.0.5 in /tests/module/esm (#10665)0bf6e28chore(deps): bump denoland/setup-deno in the github-actions group (#10669)8107157chore(deps-dev): bump the development_dependencies group with 4 updates (#10670)e66530eci: require npm-publish environment for releases (#10666)49f23cbchore(sponsor): update sponsor block (#10668)3631854fix: unrestricted cloud metadata exfiltration via header injection chain (#10...fb3befbfix: no_proxy hostname normalization bypass leads to ssrf (#10661)Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
dotenvfrom 17.3.1 to 17.4.2Changelog
Sourced from dotenv's changelog.
Commits
f116f7017.4.23a81612fix visual order of faq13f55a8Merge branch 'skill'4bbbf73reorganize faqc3da64bMerge pull request #1009 from motdotla/skill6f743b1update sourcefc2c624update skill972315bTighten up skill2795fcereorganize faqd5495d4adjust skillUpdates
lodashfrom 4.17.23 to 4.18.1Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)Updates
reactfrom 19.2.4 to 19.2.5Release notes
Sourced from react's releases.
Commits
23f4f9f19.2.5Updates
react-domfrom 19.2.4 to 19.2.5Release notes
Sourced from react-dom's releases.
Commits
23f4f9f19.2.5Updates
react-hook-formfrom 7.72.0 to 7.72.1Release notes
Sourced from react-hook-form's releases.
Commits
724e5637.72.1ba649e9🐞 test: add isDirty check for numeric string keys in defaultValues (issue #13...2f56eb0🛖 build(deps): bump yaml from 1.10.2 to 1.10.3 in /app (#13335)f29f546👯 combine duplicated code (#13328)2cfc8a5🐞 fix: prevent setValue with shouldDirty from polluting unrelated dirty field...44e8815🐞 fix: memoize control in HookFormControlContext to prevent render conflicts ...302d160🐞 fix: isNameInFieldArray should check all ancestor paths for nested field ar...d7ccd70🦾 dev deps upgrade (#13325)fddf779🐞 fix: #13320 formState.isValid incorrect on Controller re-mount (#13324)26ae54e🛖 build(deps-dev): bump rollup from 4.53.3 to 4.59.0 (#13323)Updates
react-router-domfrom 7.13.2 to 7.14.0Changelog
Sourced from react-router-dom's changelog.
Commits
e31077bchore: Update version for release (#14945)6683e85chore: Update version for release (pre) (#14943)Updates
sql-formatterfrom 15.7.2 to 15.7.3Release notes
Sourced from sql-formatter's releases.
Commits
baf6cbaRelease v15.7.3911bfb0Format TIMESTAMP WITH TIME ZONE in Trinoe8d4518Delete unnecessary operator testsdad4d75Groups PostGIS operators together