Skip to content

chore(deps): bump the npm-deps group across 1 directory with 12 updates - #81

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-deps-e549ad3ba3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-deps-e549ad3ba3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-deps group with 12 updates in the / directory:

Package From To
@better-auth/oauth-provider 1.7.5 1.7.6
better-auth 1.7.5 1.7.6
hono 4.13.5 4.13.9
@commitlint/cli 21.2.2 21.2.3
@commitlint/config-conventional 21.2.2 21.2.3
@playwright/test 1.62.1 1.63.0
eslint 10.8.1 10.11.0
fallow 3.22.0 3.28.0
globals 17.11.0 17.12.0
lint-staged 17.3.0 17.5.1
prettier 3.9.6 3.9.9
tap 21.7.5 21.8.0

Updates @better-auth/oauth-provider from 1.7.5 to 1.7.6

Release notes

Sourced from @​better-auth/oauth-provider's releases.

v1.7.6

better-auth

Features

  • Added support for a bannedUserMessage function that receives the banned user, allowing sign-in errors to include details such as the ban reason. (#11325)
  • Added Vercel BotID as a captcha provider for protected authentication routes. (#11016)

Bug Fixes

  • Passwords over maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing or verification. (#11324)
  • Fixed React hydration mismatches when session or plugin auth queries resolve before streamed components hydrate. (#11316)
  • Prevented older auth-query responses from overwriting newer results when requests overlap. (#11376)
  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)
  • Fixed social account linking through the OAuth Proxy plugin. (#11268)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for SQLite-generated primary keys, including INTEGER PRIMARY KEY columns without AUTOINCREMENT. (#11374)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)

For detailed changes, see CHANGELOG

@better-auth/prisma-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for capitalized custom Prisma model names. (#11319)

For detailed changes, see CHANGELOG

@better-auth/core

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

... (truncated)

Changelog

Sourced from @​better-auth/oauth-provider's changelog.

1.7.6

Commits

Updates better-auth from 1.7.5 to 1.7.6

Release notes

Sourced from better-auth's releases.

v1.7.6

better-auth

Features

  • Added support for a bannedUserMessage function that receives the banned user, allowing sign-in errors to include details such as the ban reason. (#11325)
  • Added Vercel BotID as a captcha provider for protected authentication routes. (#11016)

Bug Fixes

  • Passwords over maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing or verification. (#11324)
  • Fixed React hydration mismatches when session or plugin auth queries resolve before streamed components hydrate. (#11316)
  • Prevented older auth-query responses from overwriting newer results when requests overlap. (#11376)
  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)
  • Fixed social account linking through the OAuth Proxy plugin. (#11268)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for SQLite-generated primary keys, including INTEGER PRIMARY KEY columns without AUTOINCREMENT. (#11374)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)

For detailed changes, see CHANGELOG

@better-auth/prisma-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for capitalized custom Prisma model names. (#11319)

For detailed changes, see CHANGELOG

@better-auth/core

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

... (truncated)

Changelog

Sourced from better-auth's changelog.

1.7.6

Patch Changes

  • #11325 af88385 Thanks @​Wadiou! - Admin plugin bannedUserMessage can now be a function that receives the banned user, so sign-in errors can include details such as the ban reason.

  • #11268 2fa501c Thanks @​bytaesu! - Support linking social accounts through the OAuth Proxy plugin.

  • #11366 d41e2ca Thanks @​bytaesu! - Use targeted PRAGMA queries when a Kysely dialect cannot introspect Cloudflare D1.

  • #11016 3d0efa3 Thanks @​davbrito! - Support Vercel BotID checks on protected authentication routes in Vercel-hosted applications.

  • #11333 631ac29 Thanks @​bytaesu! - Preserve logical model identity when a custom model name matches another schema key.

  • #11324 8853419 Thanks @​XXMOHAMED012! - Passwords longer than maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing on sign-in (email, username, phone number), verify-password, change-password (currentPassword), delete-user, the two-factor endpoints that take a password, and admin create-user, matching what sign-up and password reset already did.

  • #11316 2ee1545 Thanks @​Smidge! - Fix React hydration mismatches when a session or plugin auth query resolves before a streamed component hydrates. Preserve the server-rendered pending state during hydration, then update to the current client state without changing ordinary or computed plugin stores.

  • #11376 fc45d08 Thanks @​bytaesu! - Prevent older auth-query responses from replacing newer results when requests overlap.

  • Updated dependencies [41b7dc1, d41e2ca, 631ac29, 2b13e01]:

    • @​better-auth/prisma-adapter@​1.7.6
    • @​better-auth/kysely-adapter@​1.7.6
    • @​better-auth/core@​1.7.6
    • @​better-auth/drizzle-adapter@​1.7.6
    • @​better-auth/memory-adapter@​1.7.6
    • @​better-auth/mongo-adapter@​1.7.6
    • @​better-auth/telemetry@​1.7.6
Commits
  • 229a02a chore: release v1.7.6 (#11322)
  • dcaa5a7 feat(cli): add check command for schema validation (#11314)
  • fc45d08 fix(client): prevent stale query overwrites (#11376)
  • 8853419 fix: enforce maxPasswordLength before hashing on password verification endpoi...
  • 2fa501c fix(oauth-proxy): support social account linking (#11268)
  • 3d0efa3 feat(captcha): add Vercel BotID provider (#11016)
  • af88385 feat(admin): allow bannedUserMessage to be a function of the banned user (#11...
  • 2ee1545 fix(client): preserve auth query snapshots during hydration (#11316)
  • 0362d62 test(oauth): cover stateless implicit linking across instances (#11298)
  • See full diff in compare view

Updates hono from 4.13.5 to 4.13.9

Release notes

Sourced from hono's releases.

v4.13.9

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in honojs/hono#5380
  • fix(accepts): match media types and language tags case-insensitively in honojs/hono#5376
  • fix(linear-router): don't match an empty path segment as a param in honojs/hono#5373
  • fix(pretty-json): don't break responses with unparseable JSON bodies in honojs/hono#5377
  • fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url in honojs/hono#5379
  • fix(aws-lambda): treat binary +xml archive media types as binary in honojs/hono#5424
  • fix(aws-lambda): preserve empty query parameters in honojs/hono#5292
  • fix(lambda-edge): sync content type detection with aws-lambda in honojs/hono#5426
  • fix(lambda-edge): fail with a descriptive error on a malformed event in honojs/hono#5358

Full Changelog: honojs/hono@v4.13.8...v4.13.9

v4.13.8

What's Changed

Full Changelog: honojs/hono@v4.13.7...v4.13.8

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

Commits
  • 7c3b0df 4.13.9
  • 6cadf75 fix(lambda-edge): fail with a descriptive error on a malformed event (#5358)
  • de310ac fix(lambda-edge): sync content type detection with aws-lambda (#5426)
  • 28e8572 fix(aws-lambda): preserve empty query parameters (#5292)
  • 0d86899 fix(aws-lambda): treat binary +xml archive media types as binary (#5424)
  • 52febbc fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url (#5...
  • f950277 fix(pretty-json): don't break responses with unparseable JSON bodies (#5377)
  • 00ee875 fix(linear-router): don't match an empty path segment as a param (#5373)
  • f5a5346 fix(accepts): match media types and language tags case-insensitively (#5376)
  • cb5bea3 fix(jsx): replace Suspense and ErrorBoundary content across newlines (#5380)
  • Additional commits viewable in compare view

Updates @commitlint/cli from 21.2.2 to 21.2.3

Release notes

Sourced from @​commitlint/cli's releases.

v21.2.3

21.2.3 (2026-09-19)

Bug Fixes

Refactor

Chore, ci, build, etc.

New Contributors

Full Changelog: conventional-changelog/commitlint@v21.2.2...v21.2.3

Changelog

Sourced from @​commitlint/cli's changelog.

21.2.3 (2026-09-19)

Bug Fixes

  • lint: trim trailing whitespace off the message handed to ignore matchers (#4960) (a6f279b)
Commits
  • 95d4056 v21.2.3
  • a6f279b fix(lint): trim trailing whitespace off the message handed to ignore matchers...
  • See full diff in compare view

Updates @commitlint/config-conventional from 21.2.2 to 21.2.3

Release notes

Sourced from @​commitlint/config-conventional's releases.

v21.2.3

21.2.3 (2026-09-19)

Bug Fixes

Refactor

Chore, ci, build, etc.

New Contributors

Full Changelog: conventional-changelog/commitlint@v21.2.2...v21.2.3

Changelog

Sourced from @​commitlint/config-conventional's changelog.

21.2.3 (2026-09-19)

Bug Fixes

  • rules: report the case that matched in case rule failure messages (#4962) (9f5f7bc)
Commits

Updates @playwright/test from 1.62.1 to 1.63.0

Release notes

Sourced from @​playwright/test's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates eslint from 10.8.1 to 10.11.0

Release notes

Sourced from eslint's releases.

v10.11.0

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#20395) (Nitin Kumar)

v10.10.0

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#21286) (한국)
  • 8724829 docs: update compat table links (#21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)

Chores

  • b3d876b chore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)
  • 1696682 ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))

... (truncated)

Commits
  • 3c0b7c6 10.11.0
  • 321f0a7 Build: changelog update for 10.11.0
  • 520dd77 perf: Implement fast paths in critical areas (#21210)
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331)
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311)
  • 24310e3 chore: update ecosystem plugins (#21324)
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21...
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)
  • Additional commits viewable in compare view

Updates fallow from 3.22.0 to 3.28.0

Release notes

Sourced from fallow's releases.

v3.28.0: baselines carry a kind, request outcomes on every surface, Module Federation and Nuxt reads

Features

  • Every saved baseline now says which command wrote it. --save-baseline writes a top-level kind field with dead-code, dupes or health. Older baselines without it still load, and an older fallow still loads a baseline saved by this release.
  • Pointing --baseline at the wrong command's file is no longer silent. The run prints a warning with both command names and the path, and the file suppresses nothing. In the JSON output, baseline_staleness.unrecognised_format is true. The same warning appears in the pull-request comment, the merge-request note and the Check Run. The GitHub job summary shows the file path through the new baseline-path output, and fallow audit prints one warning per baseline it cannot use.
  • The JSON output says what narrowed a run. baseline_staleness.scope_reasons lists the reasons, for example changed-since or production. A narrowed run with a baseline also gets a recheck-baseline entry in next_steps, and the bare fallow command gets it too.
  • request_outcomes is now in the output of fallow flags, fallow suppressions and fallow security. The first two report their changed-since entry, and fallow security --sarif-file gets a sarif-file entry.
  • An empty diff no longer looks like a clean project. When a diff filter applies, its request_outcomes entry has a scope_size with the number of added lines. A diff with zero added lines reports scope_size: 0. The Action, the GitLab template, the MCP tools and the pull-request comment then all say that the clean result covers nothing.
  • hotspots-skipped now has a cause: not-a-repository, invalid-since or churn-file-unreadable.
  • A config that a plugin cannot read shows up in workspace_diagnostics. When a Module Federation exposes or remotes is not a static object literal, the run records plugin-config-unreadable with the plugin, the key and the reason. It sets degrades_analysis, so the Action and the GitLab template print it in their degraded-inputs warning. Nuxt has a related case: a components: or imports: shape that fallow cannot model. Such a project records plugin-effect-not-modeled, and that entry is silent.
  • The JSON output and both CI integrations report a run that widened to the whole project. They also report a --sarif-file that could not be written, and a format that cannot group results with --group-by.
  • fallow reads Module Federation exposes and remotes. It reads module-federation.config.* and inline plugin options in webpack, rspack, rsbuild, vite and Next.js configs. The plugin call can sit anywhere in the config: in a nested plugin array, in a variable, under tools.rspack.plugins or in a webpack(config) hook. Options held in a const in the same file are read, and so is the array form of exposes. Each exposes target becomes a runtime entry point, and each remotes alias counts as a provided dependency for the code under that config's directory.
  • Nuxt autoImports credits a global/ or islands/ component under the name Nuxt gives it. Each workspace root now gets its own verdict from its own config. components: true, imports: {} and imports: { dirs: [] } count as the Nuxt default. A name imported or re-exported from #components or #imports marks its file as used, and #layers/<name>/ works as a path alias.

Changed

  • fallow dead-code no longer exits 2 when the baseline belongs to another command. It warns and continues. --fail-on-stale-baseline fails the run on such a file. Saving over a baseline of another kind is refused with exit 2.
  • The GitHub Action and the GitLab template log why a JSON read failed. The cause goes to the debug log, and a green run gets no extra line.
  • fallow security --base warns when it cannot map the analysis root into the base worktree.

Bug fixes

  • A package name in a bundler entry is credited as a dependency. A value like react-hot-loader/patch or webpack-hot-middleware/client?reload=true in a webpack, rspack or rsbuild entry used to become an entry pattern that matched no file. The package then showed up as unused.
  • The MCP audit and decision_surface tools detect the base ref again. This regressed in 3.1.0. Thanks @​codingthat for the report and the reproduction (#2699).
  • autoImports: true works in a Nuxt project that turns the scan off. components: false, imports: { scan: false } and the other scan-off shapes no longer count as a custom layout, so unused convention files are reported. Thanks @​Tsuyoshi84 for the report (#2695).

Upgrade notes

  • A CI job that points --baseline at another command's file now fails when --fail-on-stale-baseline is set. Give each command its own baseline file.
  • A Nuxt project with autoImports: true and one of the scan-off shapes will see new unused-file findings. Add a file to entry when it is used in a way fallow cannot see.
  • If you switch on workspace_diagnostics[].kind, handle the two new kinds. Every new JSON field is optional.

Full Changelog:

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@mroderick

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps the npm-deps group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@better-auth/oauth-provider](https://github.com/better-auth/better-auth/tree/HEAD/packages/oauth-provider) | `1.7.5` | `1.7.6` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.5` | `1.7.6` |
| [hono](https://github.com/honojs/hono) | `4.13.5` | `4.13.9` |
| [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `21.2.2` | `21.2.3` |
| [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `21.2.2` | `21.2.3` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.11.0` |
| [fallow](https://github.com/fallow-rs/fallow) | `3.22.0` | `3.28.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `17.3.0` | `17.5.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [tap](https://github.com/tapjs/tapjs) | `21.7.5` | `21.8.0` |



Updates `@better-auth/oauth-provider` from 1.7.5 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/oauth-provider/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/oauth-provider)

Updates `better-auth` from 1.7.5 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/better-auth)

Updates `hono` from 4.13.5 to 4.13.9
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.5...v4.13.9)

Updates `@commitlint/cli` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/cli)

Updates `@commitlint/config-conventional` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/config-conventional)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `eslint` from 10.8.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.1...v10.11.0)

Updates `fallow` from 3.22.0 to 3.28.0
- [Release notes](https://github.com/fallow-rs/fallow/releases)
- [Changelog](https://github.com/fallow-rs/fallow/blob/main/release.toml)
- [Commits](fallow-rs/fallow@v3.22.0...v3.28.0)

Updates `globals` from 17.11.0 to 17.12.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.11.0...v17.12.0)

Updates `lint-staged` from 17.3.0 to 17.5.1
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.3.0...v17.5.1)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `tap` from 21.7.5 to 21.8.0
- [Release notes](https://github.com/tapjs/tapjs/releases)
- [Commits](https://github.com/tapjs/tapjs/compare/tap@21.7.5...tap@21.8.0)

---
updated-dependencies:
- dependency-name: "@better-auth/oauth-provider"
  dependency-version: 1.7.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: "@commitlint/cli"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: "@commitlint/config-conventional"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: better-auth
  dependency-version: 1.7.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: fallow
  dependency-version: 3.28.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: globals
  dependency-version: 17.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: hono
  dependency-version: 4.13.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: lint-staged
  dependency-version: 17.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: tap
  dependency-version: 21.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-deps-e549ad3ba3 branch from dc94961 to a32ba8e Compare October 2, 2026 12:04
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 3, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-deps-e549ad3ba3 branch October 3, 2026 10:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant