Skip to content

chore(deps-dev): bump the dev-dependencies group across 1 directory with 7 updates - #988

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-57690da707
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-57690da707

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 7 updates in the / directory:

Package From To
@biomejs/biome 2.5.9 2.5.14
turbo 2.10.10 2.11.4
@clerk/backend 3.16.7 3.20.1
@supabase/postgrest-js 2.112.3 2.117.2
@supabase/supabase-js 2.112.3 2.117.2
fast-check 4.9.0 4.10.2
yaml 2.9.0 2.9.1

Updates @biomejs/biome from 2.5.9 to 2.5.14

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.14

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #11790 17d0ff0 Thanks @​ematipico! - Fixed #10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

... (truncated)

Commits

Updates turbo from 2.10.10 to 2.11.4

Release notes

Sourced from turbo's releases.

Turborepo v2.11.4

What's Changed

Changelog

... (truncated)

Commits
  • 40c2847 publish 2.11.4 to registry
  • f74650c fix: Put version in turbo query JSON output instead of a separate banner (#...
  • 4d72915 test: Move Cargo and Go discovery cases into contracts (#14227)
  • 8a9a10a test: Move Cargo prune layout checks into in-process plan contracts (#14226)
  • 4b72ac9 refactor: Group Run state into execution and services contexts (#14225)
  • 58a4889 refactor: Make repository context inputs injectable (#14224)
  • 813bed0 fix: Share concurrent remote-cache token recovery (#14223)
  • 7353b16 fix: Coordinate artifact requests after rate limiting (#14221)
  • ec329a0 test: Move affected run planning into RunBuilder contracts (#14212)
  • 935c9ea test: Move config precedence cases into funnel contracts (#14217)
  • Additional commits viewable in compare view

Updates @clerk/backend from 3.16.7 to 3.20.1

Release notes

Sourced from @​clerk/backend's releases.

@​clerk/backend@​3.20.1

Patch Changes

@​clerk/backend@​3.19.0

Minor Changes

    • Fixes an issue where OAuth token validation did not correctly validate audience (aud) claims. Previous usages that specified audience were falsely passing. This upgrade will cause those to start rejecting if the audience indeed does not match the OAuth token's aud claim, including cases where the aud claim is omitted. (#9724) by @​thiskevinwang

    • Adds an optional audience parameter to idPOAuthAccessToken.verify()

  • Expose the optional aud audience on verified OAuth access tokens. (#9585) by @​thiskevinwang

Patch Changes

Changelog

Sourced from @​clerk/backend's changelog.

3.20.1

Patch Changes

3.20.0

Minor Changes

  • Add an optional nameQuery filter to oauthApplications.list() to search OAuth applications by name or exact client ID. (#9904) by @​austincalvelage

Patch Changes

3.19.0

Minor Changes

    • Fixes an issue where OAuth token validation did not correctly validate audience (aud) claims. Previous usages that specified audience were falsely passing. This upgrade will cause those to start rejecting if the audience indeed does not match the OAuth token's aud claim, including cases where the aud claim is omitted. (#9724) by @​thiskevinwang

    • Adds an optional audience parameter to idPOAuthAccessToken.verify()

  • Expose the optional aud audience on verified OAuth access tokens. (#9585) by @​thiskevinwang

Patch Changes

3.18.1

Patch Changes

3.18.0

Minor Changes

  • Add experimental emails.createBatch() for submitting up to 100 transactional emails. Each message supports its own idempotency key and returns an independent success or error result. (#9711) by @​jescalan

    Transactional messages now support sender and reply-to display names, cross-domain Reply-To addresses, CC/BCC recipients, attachments, and custom headers. These options require a backend deployment that supports them.

... (truncated)

Commits

Updates @supabase/postgrest-js from 2.112.3 to 2.117.2

Release notes

Sourced from @​supabase/postgrest-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/postgrest-js's changelog.

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

2.117.1 (2026-09-23)

This was a version bump only for @​supabase/postgrest-js to align it with other projects, there were no code changes.

2.117.0 (2026-09-22)

This was a version bump only for @​supabase/postgrest-js to align it with other projects, there were no code changes.

2.116.0 (2026-09-07)

This was a version bump only for @​supabase/postgrest-js to align it with other projects, there were no code changes.

2.115.0 (2026-09-03)

🚀 Features

  • postgrest: add getOpenApiSpec() (#2651)

❤️ Thank You

2.114.0 (2026-09-02)

This was a version bump only for @​supabase/postgrest-js to align it with other projects, there were no code changes.

2.113.0 (2026-09-02)

This was a version bump only for @​supabase/postgrest-js to align it with other projects, there were no code changes.

2.112.4 (2026-08-24)

🩹 Fixes

  • postgrest: move override fixtures out of generated types, repair codegen (#2605)

❤️ Thank You

Commits
  • 6d21e3f fix(postgrest): avoid instantiation depth errors for large relationship union...
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • dbe7679 chore(release): version 2.115.0 changelogs (#2664)
  • 92fb8ba feat(postgrest): add getOpenApiSpec() (#2651)
  • aef432b chore(release): version 2.114.0 changelogs (#2653)
  • 67b07b0 chore(release): version 2.113.0 changelogs (#2650)
  • 062ae5e chore(release): version 2.112.4 changelogs (#2628)
  • c7397c1 chore(supabase): bump supabase cli to 2.113.0 (#2606)
  • Additional commits viewable in compare view

Updates @supabase/supabase-js from 2.112.3 to 2.117.2

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.117.2 (2026-09-25)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

2.117.0 (2026-09-22)

🚀 Features

  • auth: enable passkey API by default and deprecate experimental passkey opt-in (#2695)

❤️ Thank You

  • fadymak

2.116.0 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)

🩹 Fixes

  • supabase: warn when schema is passed outside db options (#2663)

❤️ Thank You

2.115.0 (2026-09-03)

🚀 Features

  • postgrest: add getOpenApiSpec() (#2651)

❤️ Thank You

2.114.0 (2026-09-02)

... (truncated)

Commits
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • 739b351 fix(auth): return stored session when a refresh loses to another tab (#2698)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • cc45ccf feat(auth): enable passkey API by default and deprecate experimental passkey ...
  • c511286 docs(realtime): document relationship of accessToken() and heartbeat (#2680)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • 5aedaab feat(auth): add MFA recovery codes API (#2676)
  • e4f675a fix(supabase): warn when schema is passed outside db options (#2663)
  • dbe7679 chore(release): version 2.115.0 changelogs (#2664)
  • 3eb6193 docs(supabase): clarify db.schema needs the second generic (#2662)
  • Additional commits viewable in compare view

Updates fast-check from 4.9.0 to 4.10.2

Release notes

Sourced from fast-check's releases.

v4.10.2

Fix interrupt plugin (throwing) [Code][Diff]

Fixes

  • (PR#7333) Bug: Plugin interruptAfterTimeLimit crashes

Fix fake-timer compatibility in timeout and interrupt plugins

[Code][Diff]

Fixes

  • (PR#7293) Bug: Capture timers for interruptAfterTimeLimit plugin
  • (PR#7282) CI: Temporarily disable documentation updates until v5
  • (PR#7279) Doc: Release note for 4.10.0

New plugin API and deprecations ahead of v5

[Code][Diff]

Features

  • (PR#7216) Introduce a plugin API
  • (PR#7221) Refine plugin API
  • (PR#7222) Add ability to configure plugins globally
  • (PR#7224) Add the beforeEach plugin to hook in life-cycle
  • (PR#7227) Create an afterEach plugin
  • (PR#7232) Deprecate life-cycle methods
  • (PR#7235) Support teardown of beforeEach plugin
  • (PR#7228) Add timeout plugin to stop long running predicates
  • (PR#7237) Deprecate timeout from parameters
  • (PR#7238) Pass a store to plugins
  • (PR#7239) Add extra plugin's method called onAllRunsComplete
  • (PR#7240) Deprecate reporter and asyncReporter from parameters
  • (PR#7229) Add plugin to interrupt after time limit
  • (PR#7245) Support failOnInterrupt on the plugin
  • (PR#7230) Add plugins to drop runs on already covered cases
  • (PR#7259) Add ability to decorate generate via Plugins
  • (PR#7231) Add the unbiased plugin to generate without bias
  • (PR#7260) Deprecate parameters superseded by plugins
  • (PR#7261) Deprecate v5 removals

Fixes

  • (PR#7225) Bug: Proper ordering between plugins
  • (PR#7127) CI: Announce on Bluesky when drafting the release
  • (PR#7217) CI: Dedupe packages for pnpm
  • (PR#7137) Doc: Release note for 4.9.0

... (truncated)

Changelog

Sourced from fast-check's changelog.

4.10.2

Fix interrupt plugin (throwing) [Code][Diff]

Fixes

  • (PR#7333) Bug: Plugin interruptAfterTimeLimit crashes

4.10.1

Fix fake-timer compatibility in timeout and interrupt plugins [Code][Diff]

Fixes

  • (PR#7292) Bug: Capture timer globals for timeout plugin
  • (PR#7293) Bug: Capture timers for interruptAfterTimeLimit plugin
  • (PR#7282) CI: Temporarily disable documentation updates until v5
  • (PR#7279) Doc: Release note for 4.10.0

4.10.0

New plugin API and deprecations ahead of v5 [Code][Diff]

Features

  • (PR#7216) Introduce a plugin API
  • (PR#7221) Refine plugin API
  • (PR#7222) Add ability to configure plugins globally
  • (PR#7224) Add the beforeEach plugin to hook in life-cycle
  • (PR#7227) Create an afterEach plugin
  • (PR#7232) Deprecate life-cycle methods
  • (PR#7235) Support teardown of beforeEach plugin
  • (PR#7228) Add timeout plugin to stop long running predicates
  • (PR#7237) Deprecate timeout from parameters
  • (PR#7238) Pass a store to plugins
  • (PR#7239) Add extra plugin's method called onAllRunsComplete
  • (PR#7240) Deprecate reporter and asyncReporter from parameters
  • (PR#7229) Add plugin to interrupt after time limit
  • (PR#7245) Support failOnInterrupt on the plugin
  • (PR#7230) Add plugins to drop runs on already covered cases
  • (PR#7259) Add ability to decorate generate via Plugins
  • (PR#7231) Add the unbiased plugin to generate without bias
  • (PR#7260) Deprecate parameters superseded by plugins
  • (PR#7261) Deprecate v5 removals

Fixes

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 20, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 20, 2026 23:54
@dependabot @github

dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: supply-chain. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 20, 2026
@changeset-bot

changeset-bot Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: e32c83a

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes. The bumps themselves are fine, but the PR is not mergeable as-is: Biome 2.5.13 formats two files differently from 2.5.9, and Lint (Biome) fails with exactly those two errors.

The blocker

  • packages/stack-prisma/test/operation-types.types.test-d.ts: the closing > of several M3<…> generics now joins the previous line (five sites, lines 109–126).
  • packages/stack/__tests__/operation-failure-diagnostics.test.ts: the same shape at line 82.

Reproduced locally:

pnpm dlx @biomejs/biome@2.5.13 check . --diagnostic-level=error

Dependabot will not fix this itself. Someone needs to push one commit onto this branch:

pnpm install --frozen-lockfile && pnpm run code:fix

It touches only those two files. Bumping Biome on main first has the same problem there, so the reformat has to ride with the bump.

Two more things 2.5.13 changes that CI does not gate on, worth the same commit

  • e2e/wasm/supabase-declared.test.ts:84: the biome-ignore lint/suspicious/noExplicitAny comment no longer reaches const qb: any on line 86, because a deno-lint-ignore line sits between them. 2.5.13 reports the suppression as unused and the any as unsuppressed (both warnings today). Move the biome-ignore directly above line 86.
  • lint/suspicious/useIterableCallbackReturn now fires, at error level under our config, on a forEach callback whose arrow body returns a call's value (for example xs.forEach((x) => walk(x))). Nothing on main trips it. New code will, so expect it on rebases.

What I checked on the bumps

  • @supabase/postgrest-js / @supabase/supabase-js 2.112.3 → 2.116.0 (devDependencies, pinned exactly): the only postgrest-js change in the range is a new getOpenApiSpec(); the rest is auth, storage and realtime. The live Supabase v3 integration job passed on this PR, which is the check that matters for the PostgREST wire behaviour the adapter depends on.
  • @clerk/backend 3.16.7 → 3.17.2 is not verified by this PR's CI. It is only exercised by the Drizzle identity (lock-context) suites, and those fail on every Dependabot PR with missing CLERK_MACHINE_TOKEN: the two Clerk tokens are Actions secrets but not Dependabot secrets (details in my review on #986). Add them to Dependabot secrets and rebase, and those cells will both go green and actually test this bump.
  • fast-check 4.9 → 4.10, turbo 2.10.10 → 2.10.12, yaml 2.9.0 → 2.9.1: unit, property and e2e jobs green.
  • Lockfile-only otherwise. No onlyBuiltDependencies change; frozen-lockfile install, OSV scan and the supply-chain e2e passed.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev-dependencies-57690da707 branch from ba8083e to e2e40b4 Compare October 1, 2026 01:18

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. Dependabot recreated the branch at e2e40b4b, and the blocker from my last review is gone: Lint (Biome) passes on this head with Biome 2.5.14, so no reformat commit is needed. ci-required is green.

What changed in this version of the PR

  • @biomejs/biome ^2.5.9 → ^2.5.14 (root and protect-ffi). Lint passes.
  • turbo 2.10.10 → 2.11.3 (a minor bump now, not a patch). Unit, e2e, bench and the Turborepo-driven test jobs all pass.
  • @supabase/postgrest-js / @supabase/supabase-js → 2.117.1 (pinned exactly in stack and stack-supabase). The live Supabase v3 integration job passes. That job is the one that tests the PostgREST behaviour the adapter depends on.
  • fast-check → ^4.10.2 and yaml → ^2.9.1. The property and e2e jobs pass.
  • Changes are limited to devDependencies and the lockfile. onlyBuiltDependencies does not change. The frozen-lockfile install, the OSV scan and the supply-chain e2e pass. A changeset is not necessary for a dev-only bump.

Still not verified: @clerk/backend 3.16.7 → 3.19.0

Both Drizzle v3 integration cells (postgres and supabase) are still red. Those cells are the only CI that runs the Clerk code. I could not read the job logs from this reviewer session, so I have not confirmed the cause on this run. The annotations show only pnpm run test:integration exited (1). On the earlier version of this PR, the cause was missing CLERK_MACHINE_TOKEN: the Clerk tokens are Actions secrets, but they are not Dependabot secrets (see #986). Before you merge, make sure the failure is still that cause and not a regression from 3.19.0. If you add the tokens to Dependabot secrets and rebase, those cells will test this bump.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev-dependencies-57690da707 branch 4 times, most recently from 93b723d to a463903 Compare October 2, 2026 21:52
…ith 7 updates

Bumps the dev-dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.9` | `2.5.14` |
| [turbo](https://github.com/vercel/turborepo) | `2.10.10` | `2.11.4` |
| [@clerk/backend](https://github.com/clerk/javascript/tree/HEAD/packages/backend) | `3.16.7` | `3.20.1` |
| [@supabase/postgrest-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/postgrest-js) | `2.112.3` | `2.117.2` |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.112.3` | `2.117.2` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.9.0` | `4.10.2` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |



Updates `@biomejs/biome` from 2.5.9 to 2.5.14
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome)

Updates `turbo` from 2.10.10 to 2.11.4
- [Release notes](https://github.com/vercel/turborepo/releases)
- [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
- [Commits](vercel/turborepo@v2.10.10...v2.11.4)

Updates `@clerk/backend` from 3.16.7 to 3.20.1
- [Release notes](https://github.com/clerk/javascript/releases)
- [Changelog](https://github.com/clerk/javascript/blob/main/packages/backend/CHANGELOG.md)
- [Commits](https://github.com/clerk/javascript/commits/@clerk/backend@3.20.1/packages/backend)

Updates `@supabase/postgrest-js` from 2.112.3 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/postgrest-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/postgrest-js)

Updates `@supabase/supabase-js` from 2.112.3 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js)

Updates `fast-check` from 4.9.0 to 4.10.2
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.2/packages/fast-check)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@clerk/backend"
  dependency-version: 3.17.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@supabase/postgrest-js"
  dependency-version: 2.116.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.116.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: fast-check
  dependency-version: 4.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: turbo
  dependency-version: 2.10.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev-dependencies-57690da707 branch from a463903 to e32c83a Compare October 3, 2026 00:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant