Skip to content

Bump the minor-and-patch group across 1 directory with 8 updates - #16

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cloud/minor-and-patch-c452459022
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cloud/minor-and-patch-c452459022

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown

Bumps the minor-and-patch group with 8 updates in the /cloud directory:

Package From To
lucide-react 1.48.0 1.52.0
next 16.3.6 16.4.0
nodemailer 10.0.10 10.0.15
radix-ui 1.6.7 1.7.0
shadcn 4.21.0 4.21.3
@types/node 26.6.3 26.6.4
eslint-config-next 16.3.6 16.4.0
vitest 5.0.2 5.0.3

Updates lucide-react from 1.48.0 to 1.52.0

Release notes

Sourced from lucide-react's releases.

Version 1.52.0

What's Changed

Full Changelog: lucide-icons/lucide@1.51.0...1.52.0

Version 1.51.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.50.0...1.51.0

Version 1.50.0

What's Changed

... (truncated)

Commits
  • 98331e2 chore(deps): bump the react-deps group across 1 directory with 3 updates (#4951)
  • 09aa9c5 chore(deps): Upgrade to vite 8 (#4950)
  • e042fec fix(packages): declare @types/react as an optional peer dependency (#4892)
  • See full diff in compare view

Updates next from 16.3.6 to 16.4.0

Release notes

Sourced from next's releases.

v16.4.0

Check out the 16.4 announcement post to get an overview of the changes.

Core Changes

  • Show compiler plugin warning in more situations: #75682
  • fix(scripts): correct typo in rm.mjs error message: #87015
  • docs: improve clarity and punctuation in README: #86096
  • Fix debug build paths Pages Router support entries: #93529
  • bundle-analyzer: record historical snapshots on each analyze run: #93520
  • fix: detect proxy.ts correctly with compound pageExtensions: #93246
  • feat(turbopack): support false values for resolveAlias config: #93331

Misc Changes

  • docs: correction to dynamicParams migration: #96624
  • docs: proxy event argument: #96435
  • docs: remove experimental note from runtime prefetching: #96615
  • Preserve per-segment prefetching after dynamic navigation: #96583
  • Rename static generation stream option to waitForAllReady: #96564
  • Remove obsolete static generation plumbing: #96563
  • [turbopack] Drop dead writes to exports: #96381
  • [turbopack] Ignore writes to exports after a module.exports = {} writes: #96380
  • [turbopack] Add test for sideEffects with optimizePackageImports: #96549
  • [turbopack] Strip leading BOM before parsing CSS: #96678
  • Upgrade React from cbb046ab-20260731 to 7dfc7ccd-20260803: #96550
  • docs: use relative doc links in instant-navigation error pages: #96672
  • Turbopack: terminate failed plugin worker threads: #96592
  • Fix HTML-limited bot matching in prerender bypass rules: #96584
  • [ci] Fix create_release_branch for new repo permissions: #96641
  • test: skip action module instance deploy test: #96629
  • docs: quote the dynamicParams build error in a blockquote: #96633
  • [react-sync] Open pull requests as the bot that authors the commits: #96682
  • [Bench] Fixes for pure Fizz bench: #96771
  • Derive foreground cache revalidation from the consumer: #96731
  • Fix race when navigating Back before hydration: #96252
  • docs: present each Skill as steps in the AI agents guide: #96751
  • Reuse completed cache entries for the rest of a request: #96727
  • Upgrade React from 7dfc7ccd-20260803 to 11eddecd-20260805: #96735
  • Remove WorkStore execution mode: #96674
  • Remove cache revalidation execution mode reads: #96670
  • Separate App Route render and prerender pipelines: #96662
  • Remove App Page execution mode reads: #96660
  • test: fix missing await in css-chunking test: #96725
  • docs (Skills): stop assuming app/ at the root and port 3000: #96696
  • Implement next/font BeforeResolvePlugins as ImportMappingReplacement: #95808
  • Use Tailwind Turbopack loader in create-next-app: #96606
  • docs: instant navigation quick start with an adoption prompt: #96663
  • Separate App Page render and prerender pipelines: #96659
  • Move App Router execution intent to entrypoints: #96640

... (truncated)

Commits
  • e273d5b v16.4.0
  • fdf41d6 [ai-upgrade] discover upgrade models and reasoning efforts from agent CLIs (#...
  • c3e76ad v16.4.0-canary.63
  • 47c6cc8 Document next analyze export in the package bundling guide (#99735)
  • 5b10604 Revert stabilization of forbidden() and unauthorized() (#99734)
  • f3a6f97 Preserve configured output directories during static export (#99507)
  • b22e5a2 Rename skill to next-bundle-optimizer and document its usage (#99731)
  • 74dc549 [turbo-tasks-backend] Clean up task state before publishing execution complet...
  • ccf8c15 v16.4.0-canary.62
  • b8c7c7f Improve static route error guidance (#99724)
  • Additional commits viewable in compare view

Updates nodemailer from 10.0.10 to 10.0.15

Release notes

Sourced from nodemailer's releases.

v10.0.15

10.0.15 (2026-10-05)

Bug Fixes

  • errors: inherit NodemailerError code from ErrnoException (e99db61), closes #1884
  • errors: keep NodemailerError compatible with @​types/node 26 ErrnoException (#1885) (b660328)

v10.0.14

10.0.14 (2026-10-03)

Bug Fixes

  • addressparser: keep a quoted display name that holds no "@" out of the address (3570d26)
  • addressparser: keep the group recursion depth out of the options object (a680254)
  • addressparser: stop a "[" from hiding the operators after it (5619784)
  • dkim: trim a header field name in linear time (c6f7a55)
  • mime-funcs: read and write header parameters per rfc2045 and rfc2231 (b8ccad7)
  • search only the new bytes for the end of the proxy CONNECT response (81efd7b)

v10.0.13

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

v10.0.12

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

v10.0.11

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)
Changelog

Sourced from nodemailer's changelog.

10.0.15 (2026-10-05)

Bug Fixes

  • errors: inherit NodemailerError code from ErrnoException (e99db61), closes #1884
  • errors: keep NodemailerError compatible with @​types/node 26 ErrnoException (#1885) (b660328)

10.0.14 (2026-10-03)

Bug Fixes

  • addressparser: keep a quoted display name that holds no "@" out of the address (3570d26)
  • addressparser: keep the group recursion depth out of the options object (a680254)
  • addressparser: stop a "[" from hiding the operators after it (5619784)
  • dkim: trim a header field name in linear time (c6f7a55)
  • mime-funcs: read and write header parameters per rfc2045 and rfc2231 (b8ccad7)
  • search only the new bytes for the end of the proxy CONNECT response (81efd7b)

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)
Commits
  • c17efc0 chore(master): release 10.0.15 (#1886)
  • 8d423d0 chore(deps): update dependencies
  • e99db61 fix(errors): inherit NodemailerError code from ErrnoException
  • b660328 fix(errors): keep NodemailerError compatible with @​types/node 26 ErrnoExcepti...
  • aefd1da chore(master): release 10.0.14 (#1880)
  • 520c4ef chore(deps): update dependencies
  • a680254 fix(addressparser): keep the group recursion depth out of the options object
  • 3570d26 fix(addressparser): keep a quoted display name that holds no "@" out of the a...
  • b8ccad7 fix(mime-funcs): read and write header parameters per rfc2045 and rfc2231
  • c6f7a55 fix(dkim): trim a header field name in linear time
  • Additional commits viewable in compare view

Updates radix-ui from 1.6.7 to 1.7.0

Changelog

Sourced from radix-ui's changelog.

1.7.0

Dialog

  • Fixed nested, portalled layers being unusable inside a modal layer. A non-modal popover rendered inside a modal Dialog previously broke some user interactions because the modal layer's trapped FocusScope reclaimed focus, and its RemoveScroll only allowed scrolling within the modal content.

Navigation Menu

  • Added a disableToggle prop to NavigationMenu.Sub.
    • true: Clicking the trigger of an already-open submenu item keeps it open. This is the default and matches existing behavior.
    • false: Clicking the trigger of a submenu item toggles it open or closed.
  • Added an activationMode prop to NavigationMenu.Root and NavigationMenu.Sub.
    • "automatic": Hovering or focusing a trigger opens its item, and moving away from the trigger closes it after a short delay. This is the default and matches existing behavior.
    • "manual": Pointer entry and focus never open an item. The item opens when its trigger is clicked.
    • When activationMode is omitted on NavigationMenu.Sub, it inherits the value from the parent NavigationMenu.Root, so setting "manual" on the root also applies to submenus unless a submenu opts back in to "automatic".
  • Fixed a bug where a submenu's defaultValue was reset when an external element was focused before the menu opened.
  • Fixed a bug where NavigationMenu.Viewport discarded its children and rendered the active content in their place. The active content is now rendered inside the consumer's element alongside any children it already had.

Popover

  • Added Popover.Title and Popover.Description parts that provide accessible names and descriptions for popover content.

Scroll Area

  • Added a ScrollArea.Content part so consumers can own the wrapper element implicitly rendered by ScrollArea.Viewport. Pass disableImplicitContentElement to the viewport and render ScrollArea.Content as its child.

    <ScrollArea.Root>
      <ScrollArea.Viewport disableImplicitContentElement>
        <ScrollArea.Content>{children}</ScrollArea.Content>
      </ScrollArea.Viewport>
      <ScrollArea.Scrollbar>
        <ScrollArea.Thumb />
      </ScrollArea.Scrollbar>
    </ScrollArea.Root>

    In the next major release, the viewport will no longer render this element implicitly. We recommend migrating to this API now for a smoother upgrade.

  • Fixed a bug where asChild on ScrollArea.Viewport merged props onto the implicit content element instead of the consumer's element.

Slider

  • Added a preserveThumbOrder prop to Slider that prevents thumbs from crossing over one another. When enabled, each thumb is constrained to the values of its neighbors instead of swapping positions when dragged past them.

Other updates

  • Added support for multiple aria-describedby attributes, so id strings from a component and its child are merged, normalized, and deduplicated instead of one replacing the other.
  • Fixed a bug where internal event handlers were still called on disabled Select.Item elements.
  • Fixed a bug where a paused Toast would not auto-close after its duration changed while the timer was paused.

... (truncated)

Commits

Updates shadcn from 4.21.0 to 4.21.3

Release notes

Sourced from shadcn's releases.

shadcn@4.21.3

Patch Changes

shadcn@4.21.2

Patch Changes

shadcn@4.21.1

Patch Changes

Changelog

Sourced from shadcn's changelog.

4.21.3

Patch Changes

4.21.2

Patch Changes

4.21.1

Patch Changes

Commits
  • d51870f chore(release): version packages (#12152)
  • dba2716 chore(release): version packages (#12141)
  • 95efb5c fix(registry): read components.json and package.json without cosmiconfig (#12...
  • 3b1ae6e fix(registry): skip npm audit and fund when installing dependencies (#12140)
  • 3502dbc chore(release): version packages (#12063)
  • bf6646b feat(registry): extract @​shadcn/registry from shadcn (#12087)
  • a9c1da4 fix(shadcn): apply shimmer reduced motion to variants (#12061)
  • 7bc5604 chore(deps): bump next, astro, postcss, undici, postcss-selector-parser, base...
  • 5c7072d fix(registry): correct logo quoting in directory JSON (#11807)
  • See full diff in compare view

Updates @types/node from 26.6.3 to 26.6.4

Commits

Updates eslint-config-next from 16.3.6 to 16.4.0

Release notes

Sourced from eslint-config-next's releases.

v16.4.0

Check out the 16.4 announcement post to get an overview of the changes.

Core Changes

  • Show compiler plugin warning in more situations: #75682
  • fix(scripts): correct typo in rm.mjs error message: #87015
  • docs: improve clarity and punctuation in README: #86096
  • Fix debug build paths Pages Router support entries: #93529
  • bundle-analyzer: record historical snapshots on each analyze run: #93520
  • fix: detect proxy.ts correctly with compound pageExtensions: #93246
  • feat(turbopack): support false values for resolveAlias config: #93331

Misc Changes

  • docs: correction to dynamicParams migration: #96624
  • docs: proxy event argument: #96435
  • docs: remove experimental note from runtime prefetching: #96615
  • Preserve per-segment prefetching after dynamic navigation: #96583
  • Rename static generation stream option to waitForAllReady: #96564
  • Remove obsolete static generation plumbing: #96563
  • [turbopack] Drop dead writes to exports: #96381
  • [turbopack] Ignore writes to exports after a module.exports = {} writes: #96380
  • [turbopack] Add test for sideEffects with optimizePackageImports: #96549
  • [turbopack] Strip leading BOM before parsing CSS: #96678
  • Upgrade React from cbb046ab-20260731 to 7dfc7ccd-20260803: #96550
  • docs: use relative doc links in instant-navigation error pages: #96672
  • Turbopack: terminate failed plugin worker threads: #96592
  • Fix HTML-limited bot matching in prerender bypass rules: #96584
  • [ci] Fix create_release_branch for new repo permissions: #96641
  • test: skip action module instance deploy test: #96629
  • docs: quote the dynamicParams build error in a blockquote: #96633
  • [react-sync] Open pull requests as the bot that authors the commits: #96682
  • [Bench] Fixes for pure Fizz bench: #96771
  • Derive foreground cache revalidation from the consumer: #96731
  • Fix race when navigating Back before hydration: #96252
  • docs: present each Skill as steps in the AI agents guide: #96751
  • Reuse completed cache entries for the rest of a request: #96727
  • Upgrade React from 7dfc7ccd-20260803 to 11eddecd-20260805: #96735
  • Remove WorkStore execution mode: #96674
  • Remove cache revalidation execution mode reads: #96670
  • Separate App Route render and prerender pipelines: #96662
  • Remove App Page execution mode reads: #96660
  • test: fix missing await in css-chunking test: #96725
  • docs (Skills): stop assuming app/ at the root and port 3000: #96696
  • Implement next/font BeforeResolvePlugins as ImportMappingReplacement: #95808
  • Use Tailwind Turbopack loader in create-next-app: #96606
  • docs: instant navigation quick start with an adoption prompt: #96663
  • Separate App Page render and prerender pipelines: #96659
  • Move App Router execution intent to entrypoints: #96640

... (truncated)

Commits

Updates vitest from 5.0.2 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • 33cadea chore: release v5.0.3 (#11409)
  • 346d389 fix(vm): don't reuse scripts across vite environments (

Bumps the minor-and-patch group with 8 updates in the /cloud directory:

| Package | From | To |
| --- | --- | --- |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.48.0` | `1.52.0` |
| [next](https://github.com/vercel/next.js) | `16.3.6` | `16.4.0` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `10.0.10` | `10.0.15` |
| [radix-ui](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/radix-ui) | `1.6.7` | `1.7.0` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn) | `4.21.0` | `4.21.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.6` | `16.4.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.2` | `5.0.3` |



Updates `lucide-react` from 1.48.0 to 1.52.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.52.0/packages/lucide-react)

Updates `next` from 16.3.6 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.6...v16.4.0)

Updates `nodemailer` from 10.0.10 to 10.0.15
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v10.0.10...v10.0.15)

Updates `radix-ui` from 1.6.7 to 1.7.0
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/radix-ui/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/radix-ui)

Updates `shadcn` from 4.21.0 to 4.21.3
- [Release notes](https://github.com/shadcn-ui/ui/releases)
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.21.3/packages/shadcn)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint-config-next` from 16.3.6 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.4.0/packages/eslint-config-next)

Updates `vitest` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: lucide-react
  dependency-version: 1.52.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: nodemailer
  dependency-version: 10.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: radix-ui
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: shadcn
  dependency-version: 4.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: cloud, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants