Skip to content

Bump the minor-and-patch group across 1 directory with 9 updates - #607

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/app/minor-and-patch-02b41778f6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/app/minor-and-patch-02b41778f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 9 updates in the /app directory:

Package From To
@supabase/supabase-js 2.116.0 2.117.2
@tanstack/react-query 5.103.1 5.104.0
@trigger.dev/sdk 4.5.16 4.6.4
frimousse 0.3.0 0.4.0
posthog-js 1.434.2 1.434.17
posthog-node 5.52.4 5.54.1
react-hook-form 7.88.0 7.89.0
resend 6.28.1 6.30.0
@trigger.dev/build 4.5.16 4.6.4

Updates @supabase/supabase-js from 2.116.0 to 2.117.2

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.117.2 (2026-09-25)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

2.117.0 (2026-09-22)

🚀 Features

  • auth: enable passkey API by default and deprecate experimental passkey opt-in (#2695)

❤️ Thank You

  • fadymak
Commits
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • 739b351 fix(auth): return stored session when a refresh loses to another tab (#2698)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • cc45ccf feat(auth): enable passkey API by default and deprecate experimental passkey ...
  • c511286 docs(realtime): document relationship of accessToken() and heartbeat (#2680)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • See full diff in compare view

Updates @tanstack/react-query from 5.103.1 to 5.104.0

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-devtools@​5.104.0
    • @​tanstack/react-query@​5.104.0

@​tanstack/react-query-next-experimental@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/react-query@​5.104.0

@​tanstack/react-query-persist-client@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/react-query@​5.104.0
    • @​tanstack/query-persist-client-core@​5.104.0

@​tanstack/react-query@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-core@​5.104.0

@​tanstack/react-query-devtools@​5.103.3

Patch Changes

@​tanstack/react-query-next-experimental@​5.103.3

... (truncated)

Changelog

Sourced from @​tanstack/react-query's changelog.

5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-core@​5.104.0

5.103.3

Patch Changes

  • #11647 1c9693e - fix(codemods): avoid copying unnecessary files from codemods project
  • Updated dependencies []:
    • @​tanstack/query-core@​5.103.3

5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2
Commits
  • d4033eb ci: Version Packages (#11651)
  • 5279b05 chore(deps): update Vite from v6 to v8 (#11650)
  • fe053bf ci: Version Packages (#11612)
  • 1c9693e fix(codemods): update codemods build script (#11647)
  • f00aad6 chore(deps): update dev dependencies (#11640)
  • 2443290 test(*): rename 'console.error' spies to 'consoleErrorMock' (#11646)
  • fcab29f test({query-core,react-query,preact-query}): restore the previous 'isServer' ...
  • e8dacbe docs({react-query,preact-query,solid-query,svelte-query}/README): point the C...
  • 57f40eb chore(deps): update non-major dependencies (#11625)
  • 397ad07 test({query-core,react-query,preact-query,solid-query}): pass 'unhandledRejec...
  • Additional commits viewable in compare view

Updates @trigger.dev/sdk from 4.5.16 to 4.6.4

Changelog

Sourced from @​trigger.dev/sdk's changelog.

4.6.4

Patch Changes

  • Updated dependencies:
    • @trigger.dev/core@4.6.4

4.6.3

Patch Changes

  • Thrown error cause chains are now captured and shown. When a task throws an error that wraps another one, the run's error in the dashboard, the CLI dev output, and failure alerts all carry the chain instead of only the outermost message. (4f36f614b)

    throw new Error("Could not sync the customer", { cause: originalError });

    The chain is flattened outermost first, capped at five causes, and cycle safe. It also rides on the error of API and realtime run records as a causes array, and triggerAndWait and triggerAndSubscribe rebuild it as a native cause on the error they hand back, so err.cause works in your own catch blocks.

  • Keep summarized assistant steps and tool results out of future chat.agent() model context after inner compaction, while preserving the full visible conversation. (fc77bfc9a)

  • Updated dependencies:

    • @trigger.dev/core@4.6.3

4.6.2

Patch Changes

  • Show warm idle time and durable waits separately in chat agent traces. Durable waits now open the waitpoint inspector while waiting and after completion. Message span names are shorter, and repeated session IDs no longer crowd message-wait and default output-stream spans. (0754931cc)
  • chat.agent: the between-turns compaction check now receives the last step's token usage (the context the model actually held) instead of the turn's sum over every tool-calling step, so a single tool-using turn no longer compacts a short conversation. The summed figure is still available as turnUsage on the event. A head-start handover whose pending tool call completes under the same message id now replaces its spliced partial in the model lane directly instead of falling back to a full reconversion. (04c837569)
  • Validate resource IDs when creating scoped public tokens. Explicitly empty IDs are now rejected instead of being interpreted as type-wide permissions. (22f8fb2b5)
  • Updated dependencies:
    • @trigger.dev/core@4.6.2

4.6.1

Patch Changes

  • Updated dependencies:
    • @trigger.dev/core@4.6.1

4.6.0

Minor Changes

  • Actions can now become turns. onAction edits history with chat.history; to answer after the edit, return chat.turn() and a turn runs on the edited history with everything a turn has: the agent's system prompt and tools, steering, compaction, injected instructions, onTurnStart and onTurnComplete, and persistence. A regenerate is chat.history.slice(0, -1); return chat.turn();. (#4816)

    onAction: async ({ action }) => {
      if (action.type === "regenerate") {
        chat.history.slice(0, -1);

... (truncated)

Commits
  • 51e29f4 chore: release v4.6.4 (#4973)
  • 2d03fee chore: release v4.6.3 (#4945)
  • fc77bfc fix(sdk): keep compacted steps out of later chat turns
  • 4f36f61 feat(core,sdk,cli,webapp,run-engine): store and show thrown error causes
  • 6d46534 chore: release v4.6.2 (#4942)
  • 22f8fb2 fix(webapp,sdk): enforce scoped token resource boundaries
  • 04c8375 fix(sdk,dashboard-agent): stop a single tool-using turn compacting the chat c...
  • 0754931 fix(sdk): separate chat idle and durable wait traces
  • 4132259 chore: release v4.6.1 (#4936)
  • 6172bcd chore: release v4.6.0 (#4883)
  • Additional commits viewable in compare view

Updates frimousse from 0.3.0 to 0.4.0

Release notes

Sourced from frimousse's releases.

v0.4.0

  • Add resolveEmojiData prop on EmojiPicker.Root and export defaultEmojiDataResolver to support custom data sources and locales.
  • Add createEmojiDataCache to persist custom emoji data in localStorage.
  • Add getEmojiDetails and useEmojiDetails to retrieve details from an emoji.
  • Fix cached emoji data only being checked for updates for the first locale used.
  • Fix cached data ignoring changes to emojibaseUrl and emojiVersion.
Changelog

Sourced from frimousse's changelog.

[0.4.0] - 2026-09-21

  • Add resolveEmojiData prop on EmojiPicker.Root and export defaultEmojiDataResolver to support custom data sources and locales.
  • Add createEmojiDataCache to persist custom emoji data in localStorage.
  • Add getEmojiDetails and useEmojiDetails to retrieve details from an emoji.
  • Fix cached emoji data only being checked for updates for the first locale used.
  • Fix cached data ignoring changes to emojibaseUrl and emojiVersion.
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for frimousse since your current version.


Updates posthog-js from 1.434.2 to 1.434.17

Release notes

Sourced from posthog-js's releases.

posthog-js@1.434.17

1.434.17

Patch Changes

  • #5063 799e84c Thanks @​arnohillen! - fix(replay): keep a held recording epoch's buffered data when it hits the size cap (2026-09-28)

  • #5118 3212630 Thanks @​TueHaulund! - fix(replay): keep CSS-in-JS styles after a large DOM change in the page head (2026-09-28)

posthog-js@1.434.16

1.434.16

Patch Changes

  • #5127 d48c783 Thanks @​marandaneto! - Honor the modern replay network masking callback when both modern and deprecated hooks are configured. (2026-09-28)

posthog-js@1.434.15

1.434.15

Patch Changes

  • #5115 8531e40 Thanks @​turnipdabeets! - Fix SPA $pageview events from pushState/replaceState navigations carrying the previous page's title (2026-09-26)

posthog-js@1.434.14

1.434.14

Patch Changes

  • #5097 ae954ab Thanks @​turnipdabeets! - Fix useThumbSurvey from @posthog/react/surveys and posthog-js/react/surveys ignoring the client passed to PostHogProvider, which left it capturing no survey events. (2026-09-25)

posthog-js@1.434.13

1.434.13

Patch Changes

  • #5098 a7250f0 Thanks @​Piccirello! - Replay loads a recorded font under the replay iframe's content security policy, not the embedding page's. (2026-09-24)

posthog-js@1.434.12

1.434.12

Patch Changes

  • #5073 60bd968 Thanks @​ksvat! - The replayer no longer freezes the tab on a mutation that adds tens of thousands of nodes at once. It now applies a batch of 1,000 or more adds against a detached subtree, so the document updates style and layout once instead of per insert. A recorded batch of 25,746 style elements went from 92 seconds of blocked main thread to 1.5 seconds. (2026-09-23)

... (truncated)

Commits
  • 7e5e3fe chore: update versions and lockfile [version bump]
  • 799e84c fix(replay): keep held recording data at the buffer size cap (#5063)
  • 51699b4 feat(mcp): record input aliases used from a server-owned alias map (#5117)
  • 466da07 feat(mcp): record safe tool input field names (#5048)
  • 3212630 fix(replay): keep CSSOM rules when a huge add batch detaches a subtree (#5118)
  • 897fea0 chore: update versions and lockfile [version bump]
  • d48c783 fix(browser): honor modern replay network masking callback precedence (#5127)
  • 4e596e0 chore: update versions and lockfile [version bump]
  • 8531e40 fix(browser): capture SPA pageview title after the router updates it (#5115)
  • 3c24aa5 test(node): strengthen SDK regression coverage (#5105)
  • Additional commits viewable in compare view

Updates posthog-node from 5.52.4 to 5.54.1

Release notes

Sourced from posthog-node's releases.

posthog-node@5.54.1

5.54.1

Patch Changes

  • #4832 ac479db Thanks @​dustinbyrne! - Support snake_case feature flag cache payloads while preserving compatibility with camelCase providers and cached data. (2026-09-25)

posthog-node@5.54.0

5.54.0

Minor Changes

  • #5099 e3955f8 Thanks @​marandaneto! - Expose feature flag evaluation reasons and preserve them in OpenFeature resolution metadata. (2026-09-25)

posthog-node@5.53.0

5.53.0

Minor Changes

  • #5050 31dd1ad Thanks @​posthog! - Read a feature flag's evaluation runtime with getFeatureFlagEvaluationRuntime(key) and getFeatureFlagKeysByEvaluationRuntime(runtime) (2026-09-23)

posthog-node@5.52.6

5.52.6

Patch Changes

  • #5078 f4704ac Thanks @​rubychilds! - Honor filters.holdout during local feature flag evaluation. A user in an experiment holdout now receives the holdout-<id> variant instead of being bucketed into a regular variant, matching how the server evaluates the same flag. The holdout is resolved before the release conditions, so a held-out user never reaches the flag's targeting — including when those conditions would have excluded them, so isFeatureEnabled can return true where it previously returned false. Experiments with an active holdout will see variant assignment change for the held-out share of traffic on upgrade, bringing locally evaluated assignments in line with server-evaluated ones. (2026-09-23)
  • Updated dependencies [f4704ac]:
    • @​posthog/core@​1.55.2

posthog-node@5.52.5

5.52.5

Patch Changes

  • #5018 9cd8ebd Thanks @​turnipdabeets! - Stop dropping long spans that end: maxSpanAgeMs now evicts spans only once maxLiveSpans is reached, so a span that runs past the age limit and then ends is exported, and its children are no longer orphaned. (2026-09-21)

  • #4800 aad7464 Thanks @​marandaneto! - Respect the definitions response's property_matching_version during local feature flag evaluation. Version 2 uses explicit boolean/string equality and per-member array matching, while missing or other versions retain service legacy matching (including empty-array truthiness). Preserve the version in Node definition caches and Convex persisted definitions, and propagate it through person, group, cohort and dependency evaluation without mixing snapshots during reloads. Existing numeric ambiguity fallback and SemVer parsing policies are unchanged. (2026-09-21)

  • Updated dependencies [9cd8ebd, aad7464]:

    • @​posthog/core@​1.55.1
Changelog

Sourced from posthog-node's changelog.

5.54.1

Patch Changes

  • #4832 ac479db Thanks @​dustinbyrne! - Support snake_case feature flag cache payloads while preserving compatibility with camelCase providers and cached data. (2026-09-25)

5.54.0

Minor Changes

  • #5099 e3955f8 Thanks @​marandaneto! - Expose feature flag evaluation reasons and preserve them in OpenFeature resolution metadata. (2026-09-25)

5.53.0

Minor Changes

  • #5050 31dd1ad Thanks @​posthog! - Read a feature flag's evaluation runtime with getFeatureFlagEvaluationRuntime(key) and getFeatureFlagKeysByEvaluationRuntime(runtime) (2026-09-23)

5.52.6

Patch Changes

  • #5078 f4704ac Thanks @​rubychilds! - Honor filters.holdout during local feature flag evaluation. A user in an experiment holdout now receives the holdout-<id> variant instead of being bucketed into a regular variant, matching how the server evaluates the same flag. The holdout is resolved before the release conditions, so a held-out user never reaches the flag's targeting — including when those conditions would have excluded them, so isFeatureEnabled can return true where it previously returned false. Experiments with an active holdout will see variant assignment change for the held-out share of traffic on upgrade, bringing locally evaluated assignments in line with server-evaluated ones. (2026-09-23)
  • Updated dependencies [f4704ac]:
    • @​posthog/core@​1.55.2

5.52.5

Patch Changes

  • #5018 9cd8ebd Thanks @​turnipdabeets! - Stop dropping long spans that end: maxSpanAgeMs now evicts spans only once maxLiveSpans is reached, so a span that runs past the age limit and then ends is exported, and its children are no longer orphaned. (2026-09-21)

  • #4800 aad7464 Thanks @​marandaneto! - Respect the definitions response's property_matching_version during local feature flag evaluation. Version 2 uses explicit boolean/string equality and per-member array matching, while missing or other versions retain service legacy matching (including empty-array truthiness). Preserve the version in Node definition caches and Convex persisted definitions, and propagate it through person, group, cohort and dependency evaluation without mixing snapshots during reloads. Existing numeric ambiguity fallback and SemVer parsing policies are unchanged. (2026-09-21)

  • Updated dependencies [9cd8ebd, aad7464]:

    • @​posthog/core@​1.55.1
Commits
  • 490ffe8 chore: update versions and lockfile [version bump]
  • ac479db fix(node): support snake_case flag definition caches (#4832)
  • 518ae78 chore: update versions and lockfile [version bump]
  • e3955f8 feat: expose feature flag reasons in the Node OpenFeature provider (#5099)
  • 7b3121f chore: update versions and lockfile [version bump]
  • 31dd1ad feat(node): expose a flag's evaluation runtime through the SDK (#5050)
  • 0c5557a chore: update versions and lockfile [version bump]
  • f4704ac fix: honor filters.holdout in local flag evaluation (#5078)
  • 3e72e7b chore: update versions and lockfile [version bump]
  • aad7464 fix(flags): honor versioned local property matching (#4800)
  • Additional commits viewable in compare view

Updates react-hook-form from 7.88.0 to 7.89.0

Release notes

Sourced from react-hook-form's releases.

Version 7.89.0

🐞 Fixes

  • Fix form state select option (#13784)
  • Remove duplicate default value field (#13783)
  • Fix validateField skipping refs without setCustomValidity under native validation (#13782)
  • Fix form-level validation using a stale validate function (#13777)
  • Fix useFieldArray touched fields handling (#13776)
  • Fix pending delayError timers for nested paths (#13775)
  • Fix getValues extracting unmarked field array entries (#13773)
  • Fix field array touched state not being re-indexed when unsubscribed (#13772)
  • Fix nested delayError timers remaining when a parent validates clean (#13771)
  • Fix nested delayError timers remaining after resetField() resets a parent (#13769)
  • Fix stale field array root errors after an operation satisfies the validation rule (#13767)
  • Fix setValue() not revalidating dependencies when shouldValidate is enabled (#13765)
  • Fix stale built-in validation results after reset() during handleSubmit() (#13761)
  • Fix stale form-level validation results after reset() (#13762)
  • Fix validation rules removed from register options at runtime remaining active (#13758)
  • Fix useController required validation not using the controlled value (#13756)
  • Fix stale form-level errors remaining after successful re-validation (#13755)
  • Fix useFieldArray marking the form dirty when the array default value is null (#13750)
  • Fix isValid not being recomputed when the errors prop is emptied (#13748)
  • Fix form-level validation running more than once per traversal (#13747)
  • Fix stale built-in validation results after reset() during onChange (#13745)
  • Fix stale resolver results after reset() during onChange (#13744)
  • Fix setValue() not triggering field array root validation when shouldValidate is enabled (#13743)
  • Fix getFieldState(name, formState) updates after reset() (#13741)
  • Fix dirty state remaining for rows removed from a field array (#13739)

🧹 Refactors

  • Replace rimraf cleanup with fs.rmSync (#13770)
  • Reduce bundle size (#13759)

📦 Dependencies

  • Add optional @types/react peer dependency (#13781)

❤️ Thank You

Changelog

Sourced from react-hook-form's changelog.

[7.89.0] - 2026-09-26

Changed

  • Add optional @types/react peer dependency

Fixed

  • validateField calling setCustomValidity on refs that don't implement it under native validation
  • Form-level validate running a stale function instead of the latest one
  • Form-level validation leaving stale errors after a successful re-validation
  • Form-level validation running more than once per traversal
  • Stale validation results (resolver, built-in, form-level validate) being applied after reset in onChange and handleSubmit
  • Pending delayError timers for nested paths not being cancelled when a parent validates clean or is reset via resetField
  • getValues(names, { dirtyFields }) returning every row of a field array instead of only the marked entries
  • Field array touched state not being re-indexed when touchedFields is not subscribed
  • useFieldArray emitting touchedFields in form state updates when unnecessary
  • Stale field array root error not clearing once an array operation satisfies the rule
  • useFieldArray marking the form dirty when the array default is null
  • Dirty state lingering for rows removed from a field array
  • setValue with shouldValidate not revalidating deps
  • setValue with shouldValidate not triggering validation for a field array root
  • Validation rules removed from register options at runtime still being applied
  • useController validating required against the input value instead of the controlled value
  • isValid not recomputing when the errors prop is emptied
  • getFieldState(name, formState) with a resolver after reset()
Commits
  • 4722d22 7.89.0
  • 72a4c98 👟 chore: correct form state select option (#13784)
  • 14c7bec 🕵🏻‍♂️ chore: remove duplicate default value field (#13783)
  • d9cab62 🤖 chore: add optional @​types/react peer dependency (#13781)
  • c12546c 🐞 fix(validateField): skip refs without setCustomValidity under native valida...
  • 5fd9ef6 🐞 fix(validate): run the latest form level validate function (#13777)
  • 7893230 🐞 fix(useFieldArray): improve touched fields handling and add tests (#13776)
  • ad8abf6 🐴 cancel pending delayError timers for nested paths (#13775)
  • eb159da 🐞 fix(getValues): extract only the marked entries of a field array (#13773)
  • 4647014 🐞 fix: re-index field array touched state when it is not subscribed (#13772)
  • Additional commits viewable in compare view

Updates resend from 6.28.1 to 6.30.0

Release notes

Sourced from resend's releases.

v6.30.0

What's Changed

Full Changelog: resend/resend-node@v6.29.0...v6.30.0

v6.29.0

What's Changed

Full Changelog: resend/resend-node@v6.28.1...v6.29.0

Commits

Updates @trigger.dev/build from 4.5.16 to 4.6.4

Changelog

Sourced from @​trigger.dev/build's changelog.

4.6.4

Patch Changes

  • Updated dependencies:
    • @trigger.dev/core@4.6.4

4.6.3

Patch Changes

  • Updated dependencies:
    • @trigger.dev/core@4.6.3

4.6.2

Patch Changes

  • Updated dependencies:
    • @trigger.dev/core@4.6.2

4.6.1

Patch Changes

  • Updated dependencies:
    • @trigger.dev/core@4.6.1

4.6.0

Minor Changes

  • Trigger.dev now uses Zod 4 by default. Projects using Zod 3.25.56 or later 3.x releases remain supported. (#4039)

    Zod remains a runtime dependency of packages that execute schemas, so existing and new installations continue to receive it automatically. The matching peer dependency range allows package managers to reuse either a compatible Zod 3 or Zod 4 installation from your project.

Patch Changes

  • The playwright build extension now works with Playwright 1.58 and later. 1.58 changed the playwright install --dry-run output, which made deploy image builds fail while downloading the browsers. (#4881)
  • Updated dependencies:
    • @trigger.dev/core@4.6.0
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by cubic

Bumps 9 minor-and-patch dependencies in /app to their latest releases, including @supabase/supabase-js, @tanstack/react-query, @trigger.dev/sdk, frimousse, posthog-js, posthog-node, react-hook-form, resend, and @trigger.dev/build.

Behavioral changes

  • @trigger.dev now uses Zod 4 by default and moves zod-validation-error to v5.
  • posthog-node honors experiment holdouts during local flag evaluation, so held-out users get the holdout-<id> variant.
  • @supabase/supabase-js enables the passkey API by default and deprecates the experimental opt-in.

Written for commit 019c4e6. Summary will update on new commits.

Review in cubic

Bumps the minor-and-patch group with 9 updates in the /app directory:

| Package | From | To |
| --- | --- | --- |
| [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.116.0` | `2.117.2` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.103.1` | `5.104.0` |
| [@trigger.dev/sdk](https://github.com/triggerdotdev/trigger.dev/tree/HEAD/packages/trigger-sdk) | `4.5.16` | `4.6.4` |
| [frimousse](https://github.com/liveblocks/frimousse) | `0.3.0` | `0.4.0` |
| [posthog-js](https://github.com/PostHog/posthog-js) | `1.434.2` | `1.434.17` |
| [posthog-node](https://github.com/PostHog/posthog-js/tree/HEAD/packages/node) | `5.52.4` | `5.54.1` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.88.0` | `7.89.0` |
| [resend](https://github.com/resend/resend-node) | `6.28.1` | `6.30.0` |
| [@trigger.dev/build](https://github.com/triggerdotdev/trigger.dev/tree/HEAD/packages/build) | `4.5.16` | `4.6.4` |



Updates `@supabase/supabase-js` from 2.116.0 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js)

Updates `@tanstack/react-query` from 5.103.1 to 5.104.0
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.104.0/packages/react-query)

Updates `@trigger.dev/sdk` from 4.5.16 to 4.6.4
- [Release notes](https://github.com/triggerdotdev/trigger.dev/releases)
- [Changelog](https://github.com/triggerdotdev/trigger.dev/blob/v4.6.4/packages/trigger-sdk/CHANGELOG.md)
- [Commits](https://github.com/triggerdotdev/trigger.dev/commits/v4.6.4/packages/trigger-sdk)

Updates `frimousse` from 0.3.0 to 0.4.0
- [Release notes](https://github.com/liveblocks/frimousse/releases)
- [Changelog](https://github.com/liveblocks/frimousse/blob/main/CHANGELOG.md)
- [Commits](liveblocks/frimousse@v0.3.0...v0.4.0)

Updates `posthog-js` from 1.434.2 to 1.434.17
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/compare/posthog-js@1.434.2...posthog-js@1.434.17)

Updates `posthog-node` from 5.52.4 to 5.54.1
- [Release notes](https://github.com/PostHog/posthog-js/releases)
- [Changelog](https://github.com/PostHog/posthog-js/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/PostHog/posthog-js/commits/posthog-node@5.54.1/packages/node)

Updates `react-hook-form` from 7.88.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.88.0...v7.89.0)

Updates `resend` from 6.28.1 to 6.30.0
- [Release notes](https://github.com/resend/resend-node/releases)
- [Changelog](https://github.com/resend/resend-node/blob/canary/CHANGELOG.md)
- [Commits](resend/resend-node@v6.28.1...v6.30.0)

Updates `@trigger.dev/build` from 4.5.16 to 4.6.4
- [Release notes](https://github.com/triggerdotdev/trigger.dev/releases)
- [Changelog](https://github.com/triggerdotdev/trigger.dev/blob/v4.6.4/packages/build/CHANGELOG.md)
- [Commits](https://github.com/triggerdotdev/trigger.dev/commits/v4.6.4/packages/build)

---
updated-dependencies:
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.117.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@trigger.dev/sdk"
  dependency-version: 4.6.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: frimousse
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: posthog-js
  dependency-version: 1.434.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: posthog-node
  dependency-version: 5.54.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: resend
  dependency-version: 6.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@trigger.dev/build"
  dependency-version: 4.6.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from fredrivett as a code owner October 5, 2026 14:23
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
abode Ignored Ignored Preview Oct 5, 2026 2:24pm UTC

Request Review

@dependabot dependabot Bot added javascript Pull requests that update javascript code dependencies Pull requests that update a dependency file labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants