Skip to content

Bump the production-dependencies group across 1 directory with 29 updates - #75

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-0b6673cb3e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-0b6673cb3e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 29 updates in the / directory:

Package From To
tsx 4.23.13 4.23.15
@modelcontextprotocol/server 2.0.0 2.1.0
drizzle-orm 0.45.2 0.45.3
hono 4.13.7 4.13.10
fumadocs-core 16.15.9 16.15.15
fumadocs-mdx 15.4.0 15.4.5
fumadocs-openapi 11.4.2 12.0.4
fumadocs-ui 16.15.9 16.15.15
next 16.3.4 16.3.6
mailparser 3.9.26 3.9.31
smtp-server 3.19.12 3.19.15
zod 4.6.3 4.6.5
nodemailer 10.0.3 10.0.12
@aws-sdk/client-s3 3.1130.0 3.1141.0
@tanstack/react-query 5.102.8 5.104.0
@trpc/client 11.18.0 11.19.0
@trpc/server 11.18.0 11.19.0
@trpc/tanstack-react-query 11.18.0 11.19.0
motion 13.2.0 13.4.4
next-intl 4.14.3 4.14.7
simple-icons 16.30.0 16.33.0
@aws-sdk/client-sesv2 3.1130.0 3.1141.0
@aws-sdk/client-sqs 3.1130.0 3.1141.0
pg-boss 12.31.0 12.35.0
@aws-sdk/client-iam 3.1130.0 3.1141.0
@aws-sdk/client-kms 3.1130.0 3.1141.0
@aws-sdk/client-service-quotas 3.1130.0 3.1142.0
@aws-sdk/client-sns 3.1130.0 3.1142.0
@aws-sdk/client-sts 3.1130.0 3.1142.0

Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Updates @modelcontextprotocol/server from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.1.0

Patch Changes

  • Updated dependencies [dcc0102]:
    • @​modelcontextprotocol/core@​2.1.0

@​modelcontextprotocol/server@​2.1.0

Minor Changes

  • #1624 6032170 Thanks @​SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available.

Patch Changes

  • #2726 6fa4227 Thanks @​LuckTerence! - SdkError and SdkHttpError accept standard ErrorOptions as an optional fourth constructor argument and forward it to Error, so a wrapped error is reachable through the standard Error.cause chain. Version-negotiation probe failures (SdkErrorCode.EraNegotiationFailed) now use it: the underlying TypeError: fetch failed and the DNS or socket error beneath it surface via error.cause, so pino, Sentry, and util.inspect render ENOTFOUND / ECONNREFUSED / ETIMEDOUT instead of stopping at the SdkError (#2657). The previous error.data.cause slot is still populated for compatibility but is deprecated and slated for removal; read error.cause instead.

  • #2654 03842cd Thanks @​pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @​KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy

... (truncated)

Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates drizzle-orm from 0.45.2 to 0.45.3

Release notes

Sourced from drizzle-orm's releases.

0.45.3

New Netlify DB Driver

Note: The Netlify DB driver is developed and maintained by the Netlify team.

Installation:

npm i @netlify/db

Usage example:

import { drizzle } from 'drizzle-orm/netlify-db';
// reads NETLIFY_DB_URL and NETLIFY_DB_DRIVER env vars
const db = drizzle();
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';
const db = drizzle(process.env.DATABASE_URL);
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';

// Explicit client — consumer controls the driver
const db = drizzle({ client: netlifyDbClient });

const result = await db.execute('select 1');
Commits
  • 15454db +
  • 54e436f exclude gel from pull
  • 0fd1cc6 remove gel
  • d028db7 skip gel
  • 93dc01e [All-kit]: Warn when journal timestamps can cause migrations to be skipped (#...
  • b786252 Merge pull request #6049 from drizzle-team/drizzle-kit-announcements
  • f9fc5bf Add drizzle-kit announcement manifest and schema doc
  • 9d64532 Merge pull request #6004 from drizzle-team/pin-npm-11-main
  • 0af2f2e Pin the release npm self-update to major 11: the npm 12.0.0 tarball is missin...
  • 6968638 Merge pull request #6001 from drizzle-team/release-router-dispatch-inputs
  • Additional commits viewable in compare view

Updates hono from 4.13.7 to 4.13.10

Release notes

Sourced from hono's releases.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

Full Changelog: honojs/hono@v4.13.9...v4.13.10

v4.13.9

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in honojs/hono#5380
  • fix(accepts): match media types and language tags case-insensitively in honojs/hono#5376
  • fix(linear-router): don't match an empty path segment as a param in honojs/hono#5373
  • fix(pretty-json): don't break responses with unparseable JSON bodies in honojs/hono#5377
  • fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url in honojs/hono#5379
  • fix(aws-lambda): treat binary +xml archive media types as binary in honojs/hono#5424
  • fix(aws-lambda): preserve empty query parameters in honojs/hono#5292
  • fix(lambda-edge): sync content type detection with aws-lambda in honojs/hono#5426
  • fix(lambda-edge): fail with a descriptive error on a malformed event in honojs/hono#5358

Full Changelog: honojs/hono@v4.13.8...v4.13.9

... (truncated)

Commits
  • f3d5e88 4.13.10
  • 645ddd6 test: move adapter runtime tests into adapters/* (#5466)
  • 1c6e060 feat(adapters/deno): publish to JSR (#5465)
  • b877827 feat(adapters): add the seven adapters as workspace packages (#5463)
  • 4d9f2a2 chore(adapters/bun): ship ESM only (#5462)
  • fc2343d feat(adapters): add @​hono/bun as a workspace package (#5447)
  • d7fb697 chore(deps): upgrade vite-plus to 1.0.0-rc.1 (#5459)
  • 52f6c7e ci: remove empty step left in cr.yml by the pnpm migration (#5456)
  • f69c1a5 chore: stop editorconfig-checker from checking Markdown indent size (#5455)
  • ee0622e chore: convert build scripts into plugins (#5448)
  • Additional commits viewable in compare view

Updates fumadocs-core from 16.15.9 to 16.15.15

Release notes

Sourced from fumadocs-core's releases.

fumadocs@16.15.15

  • @​fumadocs/base-ui@​16.15.15
  • fumadocs-core@16.15.15
  • fumadocs-ui@16.15.15

Fix infinite recursion in the MDX stringifier with mdast-util-to-markdown@2.1.3

The stringifier wraps every toMarkdown handler but dropped their attention and peek properties, which mdast-util-to-markdown@2.1.3 relies on to serialize bold and italic text. Pages containing them overflowed the stack during build.

fumadocs@16.15.14

  • @​fumadocs/base-ui@​16.15.14
  • fumadocs-core@16.15.14
  • fumadocs-ui@16.15.14

Announce copy confirmation to screen readers

Copy buttons are polite live regions whose label switches to "Copied" after a successful copy, so screen readers announce it. The code block's copy button no longer reports success when the clipboard write fails.

Expose the search dialog as a combobox

The search input is now a combobox that controls a listbox of option results and reports the highlighted result through aria-activedescendant, so screen readers announce results as you move through them. Hidden result buttons are removed from the tab order, and the empty state is announced as a status message.

Remove hidden sidebar controls from the tab order

The collapsed sidebar and its floating pill are now inert while hidden, and toggling the sidebar moves focus to the trigger that becomes visible.

Add block TOC style

A TOC style without the track line: headings are indented by depth, and a block slides behind the active headings.

<DocsPage tableOfContent={{ style: 'block' }} />

Wrap page footer descriptions instead of truncating

The previous/next page footer cards now wrap long descriptions instead of cutting them off with an ellipsis.

fumadocs@16.15.13

  • @​fumadocs/base-ui@​16.15.13
  • fumadocs-core@16.15.13
  • fumadocs-ui@16.15.13

Keep the collapsed sidebar's controls off the page title

With the sidebar collapsed, the docs layout floats the reopen and search buttons in a fixed pill at the top-left of the page and starts the article at the same row. Wherever the article is not centered with room to spare, every viewport below about 1280px, the pill covered the page title. The article now leaves room for the pill while the sidebar is collapsed.

AI page actions name the page by the URL the reader is on

... (truncated)

Commits

Updates fumadocs-mdx from 15.4.0 to 15.4.5

Release notes

Sourced from fumadocs-mdx's releases.

fumadocs-mdx@15.4.5

Stop recrawling node_modules on every Vite config resolution

The config hook of fumadocs-mdx/vite walked the dependency tree below Fumadocs packages once per chain reaching a package, so a docs app with a few Fumadocs packages read ~10k package.json files (~0.9s) each time Vite resolved its config, which it does once per build environment.

The crawl now visits each package once, breadth-first, and still records the shortest chain to every CommonJS dependency (fumadocs-ui > @base-ui/react > use-sync-external-store/shim and friends). The result is memoized for the process until the package manager's install state changes, so a build with several environments crawls once.

fumadocs-mdx@15.4.4

Sort glob results for deterministic codegen

fumadocs-mdx's Node codegen now sorts glob-matched files before generating collections, so the output (and anything derived from getPages()) is stable across builds of unchanged content. The Vite codegen path was checked separately: Vite's own import.meta.glob already sorts matched files internally, so it did not need the same fix.

fumadocs-mdx@15.4.3

Fix experimentalBuildCache bloating frontmatter-only imports

With a warm build cache, ?only=frontmatter imports were served the fully compiled page from cache instead of the frontmatter module, so every page was bundled two more times. The cache now only applies to full compilations.

fumadocs-mdx@15.4.2

Fix the _mdast export with removePosition

// fumadocs-mdx collection config
postprocess: {
  includeMDAST: { removePosition: true },
},

This exported _mdast with no value, and getMDAST() then reported that includeMDAST was disabled. removePosition strips positions in place and returns nothing, so JSON.stringify received undefined.

The tree is now cloned, stripped, and serialized from the clone.

Fix SOURCEMAP_BROKEN warnings on Vite

With build.sourcemap enabled, Vite warned once per content and meta file because the loaders returned no source map. They now return an empty map when nothing is generated.

Source maps for MDX stay opt-in, pass SourceMapGenerator from source-map to MDX options:

import { SourceMapGenerator } from 'source-map';
export default defineConfig({
mdxOptions: {
SourceMapGenerator,
},
});

fumadocs-mdx@15.4.1

Mark packages side-effect free

... (truncated)

Commits
  • cb6f3d6 Version Packages (#3600)
  • 6676327 perf(mdx): reduce duplicated file reads
  • f1186d9 fix(openapi): normalize fetch methods
  • a8438dc Version Packages (#3595)
  • 539bada feat(ui): support block toc variant
  • 23bef0b docs: correct stale info
  • e988e54 fix(ui): announce copy confirmation to screen readers
  • 583e2ca fix(ui): keep search dialog active state inside the list
  • 11bc9dc fix(ui): expose the search dialog as a combobox
  • d7fa38c fix(ui): remove hidden sidebar controls from the tab order
  • Additional commits viewable in compare view

Updates fumadocs-openapi from 11.4.2 to 12.0.4

Release notes

Sourced from fumadocs-openapi's releases.

fumadocs-openapi@12.0.4

Name schema property link buttons for screen readers

Give the icon-only property link button a translated label and announce when its link has been copied. Include Simplified and Traditional Chinese translations for both labels.

fumadocs-openapi@12.0.3

Send uppercase HTTP methods from the playground

The Fetch API only normalizes the case of some methods, so PATCH requests were sent as patch, which servers and edges like Vercel reject.

fumadocs-openapi@12.0.2

Optimize Performance

Use useSyncExternalStore() from React.

fumadocs-openapi@12.0.1

Fix the installed API playground

The playground installed by npx @fumadocs/cli add openapi/playground imported useAuthFields, requestOAuthToken and their types from fumadocs-openapi/playground, which did not export them. They are now exported.

fumadocs-openapi@12.0.0

Headless API pages

API pages are now built on a headless layer, use it to build your own UI:

  • fumadocs-openapi: createOpenAPIRenderer() with your own components, and the hooks of a page: useOpenAPI(), useComponents(), useServer() and useRenderContext(). createOpenAPIBaseRenderer() is the same with nothing built in: pass shiki, codeUsages and generateTypeScriptDefinitions yourself.
  • fumadocs-openapi/operation: <OperationProvider /> and the hooks of an operation, like useOperation() and useExampleRequests().
  • fumadocs-openapi/playground: useAuthFields() turns the security requirements of an operation into form fields, the ones the API playground renders and encodes into request data. requestOAuthToken() runs an OAuth flow of a security scheme.
  • the Schema UI, installed with npx @fumadocs/cli add fumadocs/api-docs/schema: its generation and navigation state (generateSchemaUI(), useSchemaTabs()) come with the copy.

useServer() also resolves the URL of a request: resolveUrl(pathname) fills in the variables of the selected server, against the page origin.

See Headless.

Install the full UI

The entire UI of API pages can be installed with Fumadocs CLI:

npx @fumadocs/cli add fumadocs/openapi/page

It installs <OpenAPIPage /> itself, import it from @/components/openapi/page in place of your components/api-page.tsx.

To customise parts of it, install fumadocs/openapi/operation or fumadocs/api-docs/schema, and pass them to the new components options:

export const OpenAPIPage = createOpenAPIPage({
  components: { Operation, SchemaUI: Schema },
</tr></table> 

... (truncated)

Commits

Updates fumadocs-ui from 16.15.9 to 16.15.15

Release notes

Sourced from fumadocs-ui's releases.

fumadocs@16.15.15

  • @​fumadocs/base-ui@​16.15.15
  • fumadocs-core@16.15.15
  • fumadocs-ui@16.15.15

Fix infinite recursion in the MDX stringifier with mdast-util-to-markdown@2.1.3

The stringifier wraps every toMarkdown handler but dropped their attention and peek properties, which mdast-util-to-markdown@2.1.3 relies on to serialize bold and italic text. Pages containing them overflowed the stack during build.

fumadocs@16.15.14

  • @​fumadocs/base-ui@​16.15.14
  • fumadocs-core@16.15.14
  • fumadocs-ui@16.15.14

Announce copy confirmation to screen readers

Copy buttons are polite live regions whose label switches to "Copied" after a successful copy, so screen readers announce it. The code block's copy button no longer reports success when the clipboard write fails.

Expose the search dialog as a combobox

The search input is now a combobox that controls a listbox of option results and reports the highlighted result through aria-activedescendant, so screen readers announce results as you move through them. Hidden result buttons are removed from the tab order, and the empty state is announced as a status message.

Remove hidden sidebar controls from the tab order

The collapsed sidebar and its floating pill are now inert while hidden, and toggling the sidebar moves focus to the trigger that becomes visible.

Add block TOC style

A TOC style without the track line: headings are indented by depth, and a block slides behind the active headings.

<DocsPage tableOfContent={{ style: 'block' }} />

Wrap page footer descriptions instead of truncating

The previous/next page footer cards now wrap long descriptions instead of cutting them off with an ellipsis.

fumadocs@16.15.13

  • @​fumadocs/base-ui@​16.15.13
  • fumadocs-core@16.15.13
  • fumadocs-ui@16.15.13

Keep the collapsed sidebar's controls off the page title

With the sidebar collapsed, the docs layout floats the reopen and search buttons in a fixed pill at the top-left of the page and starts the article at the same row. Wherever the article is not centered with room to spare, every viewport below about 1280px, the pill covered the page title. The article now leaves room for the pill while the sidebar is collapsed.

AI page actions name the page by the URL the reader is on

... (truncated)

Commits

Updates next from 16.3.4 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)
Commits
  • a758ffc v16.3.6
  • 868fad3 [active-lts] Harden next/og SVG serialization
  • 8c81cbb [lts-active] test: remove unsupported deployment ID builder cases (#98821)
  • ca2c75e v16.3.5
  • 14fb290 [backport] Fix use cache prerender signal retention (#98448)
  • 2b1f28d [16.3.x] Add CSP nonce to script tags of loading and template files (#98403)
  • 4b56cee [16.3.x] Backport docs fixes (#98317)
  • 5568a02 [backport] docs: local development: Rewrite docker section, add Windows Dev D...
  • 93249ab [16.3.X] Emit whole-app server NFTs when output: 'standalone' is used with ...
  • 6549fd7 [16.3.x] next/image: reject empty image on read/write to disk cache (#98186)
  • Additional commits viewable in compare view

Updates mailparser from 3.9.26 to 3.9.31

Changelog

Sourced from mailparser's changelog.

3.9.31 (2026-09-28)

Bug Fixes

  • deps: update libmime to 5.4.6 and mailsplit to 5.4.19 (bdaf7c3)

3.9.30 (2026-09-28)

Bug Fixes

  • cap inlined cid images, report late splitter errors, settle once, honour attachment backpressure, derive partId from the part number (af3fe56)

3.9.29 (2026-09-27)

Bug Fixes

  • deps: update nodemailer to 10.0.11 (bd1407a)

3.9.28 (2026-09-15)

Bug Fixes

  • deps: update libmime to 5.4.4 and mailsplit to 5.4.17 (8da897f)

3.9.27 (2026-09-15)

Bug Fixes

  • deps: update nodemailer to 10.0.10, encoding-japanese to 2.4.0 (842904f)
Commits
  • 466f3b9 chore(master): release 3.9.31 [skip-ci] (#448)
  • bdaf7c3 fix(deps): update libmime to 5.4.6 and mailsplit to 5.4.19
  • 20080ea chore(master): release 3.9.30 [skip-ci] (#447)
  • 3924899 chore(deps): update dependencies
  • af3fe56 fix: cap inlined cid images, report late splitter errors, settle once, honour...
  • 1c91f62 chore(master): release 3.9.29 [skip-ci] (#446)
  • bd1407a fix(deps): update nodemailer to 10.0.11
  • f06b1ce chore(master): release 3.9.28 [skip-ci] (#445)
  • 8da897f fix(deps): update libmime to 5.4.4 and mailsplit to 5.4.17
  • ba722c2 chore(master): release 3.9.27 [skip-ci] (#444)
  • Additional commits viewable in compare view

Updates smtp-server from 3.19.12 to 3.19.15

Changelog

Sourced from smtp-server's changelog.

3.19.15 (2026-09-28)

Bug Fixes

  • answer 501 to valueless parameters, time out sockets before connect, enforce the line limit on complete lines (7baa137)
  • time out an implicit TLS handshake on the TLS socket, not the raw socket underneath it (447a59a)

3.19.14 (2026-09-27)

Bug Fixes

  • deps: update nodemailer to 10.0.11 (50944ed)

3.19.13 (2026-09-15)

Bug Fixes

  • deps: update nodemailer to 10.0.10 (abdbf23)
Commits
  • 4130849 Merge pull request #277 from nodemailer/release-please--branches--master--com...
  • 3f19384 chore(master): release 3.19.15
  • 447a59a fix: time out an implicit TLS handshake on the TLS socket, not the raw socket...
  • 675113f chore(deps): update dependencies
  • 7baa137 fix: answer 501 to valueless parameters, time out sockets before connect, enf...
  • 95de429 Merge pull request #276 from nodemailer/release-please--branches--master--com...
  • 2750d13 chore(master): release 3.19.14
  • 50944ed fix(deps): update nodemailer to 10.0.11
  • 07e9fd0 Merge pull request #275 from nodemailer/release-please--branches--master--com...
  • 28d0f28 chore(master): release 3.19.13
  • Additional commits viewable in compare view

Updates zod from 4.6.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)
Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...

…ates

Bumps the production-dependencies group with 29 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [hono](https://github.com/honojs/hono) | `4.13.7` | `4.13.10` |
| [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.15.9` | `16.15.15` |
| [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `15.4.0` | `15.4.5` |
| [fumadocs-openapi](https://github.com/fuma-nama/fumadocs) | `11.4.2` | `12.0.4` |
| [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.15.9` | `16.15.15` |
| [next](https://github.com/vercel/next.js) | `16.3.4` | `16.3.6` |
| [mailparser](https://github.com/nodemailer/mailparser) | `3.9.26` | `3.9.31` |
| [smtp-server](https://github.com/nodemailer/smtp-server) | `3.19.12` | `3.19.15` |
| [zod](https://github.com/colinhacks/zod) | `4.6.3` | `4.6.5` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `10.0.3` | `10.0.12` |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1130.0` | `3.1141.0` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.102.8` | `5.104.0` |
| [@trpc/client](https://github.com/trpc/trpc/tree/HEAD/packages/client) | `11.18.0` | `11.19.0` |
| [@trpc/server](https://github.com/trpc/trpc/tree/HEAD/packages/server) | `11.18.0` | `11.19.0` |
| [@trpc/tanstack-react-query](https://github.com/trpc/trpc/tree/HEAD/packages/tanstack-react-query) | `11.18.0` | `11.19.0` |
| [motion](https://github.com/motiondivision/motion) | `13.2.0` | `13.4.4` |
| [next-intl](https://github.com/amannn/next-intl) | `4.14.3` | `4.14.7` |
| [simple-icons](https://github.com/simple-icons/simple-icons) | `16.30.0` | `16.33.0` |
| [@aws-sdk/client-sesv2](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sesv2) | `3.1130.0` | `3.1141.0` |
| [@aws-sdk/client-sqs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs) | `3.1130.0` | `3.1141.0` |
| [pg-boss](https://github.com/timgit/pg-boss) | `12.31.0` | `12.35.0` |
| [@aws-sdk/client-iam](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-iam) | `3.1130.0` | `3.1141.0` |
| [@aws-sdk/client-kms](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-kms) | `3.1130.0` | `3.1141.0` |
| [@aws-sdk/client-service-quotas](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-service-quotas) | `3.1130.0` | `3.1142.0` |
| [@aws-sdk/client-sns](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sns) | `3.1130.0` | `3.1142.0` |
| [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) | `3.1130.0` | `3.1142.0` |



Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `@modelcontextprotocol/server` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.1.0)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `hono` from 4.13.7 to 4.13.10
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.7...v4.13.10)

Updates `fumadocs-core` from 16.15.9 to 16.15.15
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.15.9...fumadocs@16.15.15)

Updates `fumadocs-mdx` from 15.4.0 to 15.4.5
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.4.0...fumadocs-mdx@15.4.5)

Updates `fumadocs-openapi` from 11.4.2 to 12.0.4
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-openapi@11.4.2...fumadocs-openapi@12.0.4)

Updates `fumadocs-ui` from 16.15.9 to 16.15.15
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.15.9...fumadocs@16.15.15)

Updates `next` from 16.3.4 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.4...v16.3.6)

Updates `mailparser` from 3.9.26 to 3.9.31
- [Release notes](https://github.com/nodemailer/mailparser/releases)
- [Changelog](https://github.com/nodemailer/mailparser/blob/master/CHANGELOG.md)
- [Commits](nodemailer/mailparser@v3.9.26...v3.9.31)

Updates `smtp-server` from 3.19.12 to 3.19.15
- [Release notes](https://github.com/nodemailer/smtp-server/releases)
- [Changelog](https://github.com/nodemailer/smtp-server/blob/master/CHANGELOG.md)
- [Commits](nodemailer/smtp-server@v3.19.12...v3.19.15)

Updates `zod` from 4.6.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.6.3...v4.6.5)

Updates `nodemailer` from 10.0.3 to 10.0.12
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v10.0.3...v10.0.12)

Updates `@aws-sdk/client-s3` from 3.1130.0 to 3.1141.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3)

Updates `@tanstack/react-query` from 5.102.8 to 5.104.0
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.104.0/packages/react-query)

Updates `@trpc/client` from 11.18.0 to 11.19.0
- [Release notes](https://github.com/trpc/trpc/releases)
- [Commits](https://github.com/trpc/trpc/commits/v11.19.0/packages/client)

Updates `@trpc/server` from 11.18.0 to 11.19.0
- [Release notes](https://github.com/trpc/trpc/releases)
- [Commits](https://github.com/trpc/trpc/commits/v11.19.0/packages/server)

Updates `@trpc/tanstack-react-query` from 11.18.0 to 11.19.0
- [Release notes](https://github.com/trpc/trpc/releases)
- [Commits](https://github.com/trpc/trpc/commits/v11.19.0/packages/tanstack-react-query)

Updates `motion` from 13.2.0 to 13.4.4
- [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md)
- [Commits](motiondivision/motion@v13.2.0...v13.4.4)

Updates `next-intl` from 4.14.3 to 4.14.7
- [Release notes](https://github.com/amannn/next-intl/releases)
- [Changelog](https://github.com/amannn/next-intl/blob/main/CHANGELOG.md)
- [Commits](amannn/next-intl@v4.14.3...v4.14.7)

Updates `simple-icons` from 16.30.0 to 16.33.0
- [Release notes](https://github.com/simple-icons/simple-icons/releases)
- [Commits](simple-icons/simple-icons@16.30.0...16.33.0)

Updates `@aws-sdk/client-sesv2` from 3.1130.0 to 3.1141.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sesv2/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-sesv2)

Updates `@aws-sdk/client-sqs` from 3.1130.0 to 3.1141.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sqs/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-sqs)

Updates `pg-boss` from 12.31.0 to 12.35.0
- [Release notes](https://github.com/timgit/pg-boss/releases)
- [Commits](timgit/pg-boss@12.31.0...12.35.0)

Updates `@aws-sdk/client-iam` from 3.1130.0 to 3.1141.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-iam/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-iam)

Updates `@aws-sdk/client-kms` from 3.1130.0 to 3.1141.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-kms/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-kms)

Updates `@aws-sdk/client-service-quotas` from 3.1130.0 to 3.1142.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-service-quotas/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1142.0/clients/client-service-quotas)

Updates `@aws-sdk/client-sns` from 3.1130.0 to 3.1142.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sns/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1142.0/clients/client-sns)

Updates `@aws-sdk/client-sts` from 3.1130.0 to 3.1142.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1142.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: hono
  dependency-version: 4.13.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: fumadocs-core
  dependency-version: 16.15.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: fumadocs-mdx
  dependency-version: 15.4.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: fumadocs-openapi
  dependency-version: 12.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: fumadocs-ui
  dependency-version: 16.15.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: mailparser
  dependency-version: 3.9.31
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: smtp-server
  dependency-version: 3.19.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: nodemailer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1141.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@trpc/client"
  dependency-version: 11.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@trpc/server"
  dependency-version: 11.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@trpc/tanstack-react-query"
  dependency-version: 11.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: motion
  dependency-version: 13.4.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: next-intl
  dependency-version: 4.14.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: simple-icons
  dependency-version: 16.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-sesv2"
  dependency-version: 3.1141.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-sqs"
  dependency-version: 3.1141.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: pg-boss
  dependency-version: 12.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-iam"
  dependency-version: 3.1141.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-kms"
  dependency-version: 3.1141.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-service-quotas"
  dependency-version: 3.1142.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-sns"
  dependency-version: 3.1142.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1142.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants