Skip to content

chore(deps): bump the runtime group with 5 updates - #10

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/runtime-ff305129ed
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/runtime-ff305129ed

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the runtime group with 5 updates:

Package From To
sharp 0.35.4 0.35.5
@redis/client 6.2.1 6.3.0
lucide-react 1.48.0 1.49.0
next 16.3.6 16.3.8
qr 0.7.0 0.7.2

Updates sharp from 0.35.4 to 0.35.5

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

Updates @redis/client from 6.2.1 to 6.3.0

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​redis/client since your current version.


Updates lucide-react from 1.48.0 to 1.49.0

Release notes

Sourced from lucide-react's releases.

Version 1.49.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.48.0...1.49.0

Commits

Updates next from 16.3.6 to 16.3.8

Release notes

Sourced from next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

Commits
  • b0fad0d v16.3.8
  • 719e4c6 [lts-active] Scope response cache keys to their source route (#218)
  • e92db45 [lts-active] Fix metadata propagation for deduplicated nested caches (#223)
  • 40c2ba9 [lts-active] Match Next data paths case-sensitively (#196)
  • 2d9f50a [lts-active] Fix MCP middleware DNS rebinding (#213)
  • bd9214f [lts-active] Fix draft mode leaks through cross-request 'use cache' dedupli...
  • 8db4a62 [lts-active][webpack] Ensure dynamicParams is respected in `opengraph-image...
  • e002ad6 [lts-active] fix(next/image): Pin DNS resolution when fetching external image...
  • 4c20699 v16.3.7
  • 2521aec [backport] turbo-tasks-backend: fix strongly consistent read hanging on a can...
  • See full diff in compare view

Updates qr from 0.7.0 to 0.7.2

Release notes

Sourced from qr's releases.

0.7.2

  • Decoder: additional large speed-up on small symbols, 2x on camera frames
  • Decoder: opt-in nativeLimit to skip full-resolution finder search
  • Decoder: read mirror images
  • Encoder: 30% speed-up; 3x for svg
  • DOM: fix native VideoFrame path being disabled for a stream started before its first frame

Full Changelog: paulmillr/qr@0.7.0...0.7.2

0.7.1

  • Decoder: additional large speed-up on small symbols, 2x on camera frames
  • Decoder: opt-in nativeLimit to skip full-resolution finder search
  • Decoder: read mirror images
  • Encoder: 30% speed-up; 3x for svg
  • DOM: fix native VideoFrame path being disabled for a stream started before its first frame

Full Changelog: paulmillr/qr@0.7.0...0.7.1

Changelog

Sourced from qr's changelog.

0.7.2 (2026-09-28)

  • Decoder: additional large speed-up on small symbols, 2x on camera frames
  • Decoder: opt-in nativeLimit to skip full-resolution finder search
  • Decoder: read mirror images
  • Encoder: 30% speed-up; 3x for svg
  • DOM: fix native VideoFrame path being disabled for a stream started before its first frame
Commits
  • 951806d Release 0.7.2.
  • 671fd2b Minor bugfixes
  • 9985d62 Release 0.7.1.
  • e90a06b Merge pull request #40 from shreeve/mirror
  • 16d1df5 decoder: read mirror images by retrying on the transposed grid
  • 2fcb00c Merge pull request #39 from shreeve/perf
  • 4b86f34 changelog: note the decoder, encoder and DOM changes
  • 023913d decoder: opt-in nativeLimit skips the full-resolution finder search
  • 16c02b1 decoder: size version scratch to the symbol actually attempted
  • d3a5667 decoder: grow finder records on demand
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

* chore(deps): bump next from 16.3.5 to 16.3.6 in the runtime group

Bumps the runtime group with 1 update: [next](https://github.com/vercel/next.js).


Updates `next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps-dev): bump typescript from 5.9.3 to 7.0.2

Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps-dev): bump tsx in the dev-tooling group across 1 directory

Bumps the dev-tooling group with 1 update in the / directory: [tsx](https://github.com/privatenumber/tsx).


Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

---
updated-dependencies:
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-tooling
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): use typescript 6.0.3 instead of 7

Keep Dependabot from proposing typescript 7 until the toolchain supports it.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
Bumps the runtime group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [sharp](https://github.com/lovell/sharp) | `0.35.4` | `0.35.5` |
| [@redis/client](https://github.com/redis/node-redis) | `6.2.1` | `6.3.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.48.0` | `1.49.0` |
| [next](https://github.com/vercel/next.js) | `16.3.6` | `16.3.8` |
| [qr](https://github.com/paulmillr/qr) | `0.7.0` | `0.7.2` |

Updates `sharp` from 0.35.4 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.4...v0.35.5)

Updates `@redis/client` from 6.2.1 to 6.3.0
- [Release notes](https://github.com/redis/node-redis/releases)
- [Changelog](https://github.com/redis/node-redis/blob/master/CHANGELOG.md)
- [Commits](https://github.com/redis/node-redis/compare/json@6.2.1...json@6.3.0)

Updates `lucide-react` from 1.48.0 to 1.49.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.49.0/packages/lucide-react)

Updates `next` from 16.3.6 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.6...v16.3.8)

Updates `qr` from 0.7.0 to 0.7.2
- [Release notes](https://github.com/paulmillr/qr/releases)
- [Changelog](https://github.com/paulmillr/qr/blob/main/CHANGELOG.md)
- [Commits](paulmillr/qr@0.7.0...0.7.2)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime
- dependency-name: "@redis/client"
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime
- dependency-name: lucide-react
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime
- dependency-name: next
  dependency-version: 16.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime
- dependency-name: qr
  dependency-version: 0.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime
...

Signed-off-by: dependabot[bot] <support@github.com>
@warnigo
warnigo force-pushed the dependabot/npm_and_yarn/runtime-ff305129ed branch from 53be839 to 1902fe6 Compare October 8, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant