Skip to content

chore(deps): bump the everything-else group across 1 directory with 10 updates - #6535

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/everything-else-3f53742ac8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/everything-else-3f53742ac8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the everything-else group with 10 updates in the / directory:

Package From To
@rdi-ui/pipeline 0.1.35 0.1.41
@sentry/electron 7.18.0 7.20.0
@sentry/react 10.73.0 10.75.3
dompurify 3.4.14 3.4.16
jszip 3.10.1 3.10.2
react-hook-form 7.87.0 7.89.0
socket.io-client 4.8.3 4.8.4
csv-stringify 6.8.3 6.9.0
moment 2.30.1 2.31.0
tsx 4.23.13 4.23.15

Updates @rdi-ui/pipeline from 0.1.35 to 0.1.41

Updates @sentry/electron from 7.18.0 to 7.20.0

Release notes

Sourced from @​sentry/electron's releases.

7.20.0

New Features ✨

Bug Fixes 🐛

  • Honour enabled: false for envelopes forwarded from renderers and utility processes by @​timfish in #1432

Internal Changes 🔧

7.19.0

New Features ✨

Internal Changes 🔧

Changelog

Sourced from @​sentry/electron's changelog.

7.20.0

New Features ✨

Bug Fixes 🐛

  • Honour enabled: false for envelopes forwarded from renderers and utility processes by @​timfish in #1432

Internal Changes 🔧

7.19.0

New Features ✨

Internal Changes 🔧

Commits
  • 53df4a7 release: 7.20.0
  • 8ef1411 feat: Return the real send result for renderer sendFeedback (#1433)
  • 9b91a80 test: New Electron versions (#1430)
  • 88fcf00 fix: Honour enabled: false for envelopes forwarded from renderers and utili...
  • 925accf feat: Update Sentry SDKs to v10.75.0 (#1431)
  • 1dcbdde Merge remote-tracking branch 'remotes/origin/release/7.19.0'
  • d604af4 release: 7.19.0
  • 87dfc97 test: New Electron versions (#1425)
  • fdd0a64 build(deps-dev): Bump vitest from 4.1.0 to 4.1.11 (#1427)
  • 02d8e99 feat: Update Sentry SDKs to v10.74.0 (#1426)
  • Additional commits viewable in compare view

Updates @sentry/react from 10.73.0 to 10.75.3

Release notes

Sourced from @​sentry/react's releases.

10.75.3

  • fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route (#24617)
  • chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • chore(v10/publish): Tag all packages as v10 (#24619)

Bundle size 📦

Path Size
@​sentry/browser 27.56 KB
@​sentry/browser - with treeshaking flags 26.04 KB
@​sentry/browser (incl. Tracing) 46.02 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.77 KB
@​sentry/browser (incl. Tracing, Profiling) 50.67 KB
@​sentry/browser (incl. Tracing, Replay) 84.38 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 74.28 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 89 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 101.33 KB
@​sentry/browser (incl. Feedback) 44.33 KB
@​sentry/browser (incl. sendFeedback) 32.25 KB
@​sentry/browser (incl. FeedbackAsync) 37.27 KB
@​sentry/browser (incl. Metrics) 28.63 KB
@​sentry/browser (incl. Logs) 28.84 KB
@​sentry/browser (incl. Metrics & Logs) 29.52 KB
@​sentry/react 29.32 KB
@​sentry/react (incl. Tracing) 48.28 KB
@​sentry/vue 32.88 KB
@​sentry/vue (incl. Tracing) 47.98 KB
@​sentry/svelte 27.58 KB
CDN Bundle 29.87 KB
CDN Bundle (incl. Tracing) 47.92 KB
CDN Bundle (incl. Logs, Metrics) 31.41 KB
CDN Bundle (incl. Tracing, Logs, Metrics) 49.21 KB
CDN Bundle (incl. Replay, Logs, Metrics) 69.82 KB
CDN Bundle (incl. Tracing, Replay) 84.64 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.87 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 90.31 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 91.55 KB
CDN Bundle - uncompressed 88.83 KB
CDN Bundle (incl. Tracing) - uncompressed 144.49 KB
CDN Bundle (incl. Logs, Metrics) - uncompressed 93.43 KB
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 148.38 KB
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 215.46 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 261.12 KB

... (truncated)

Changelog

Sourced from @​sentry/react's changelog.

10.75.3

  • fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route (#24617)
  • chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • chore(v10/publish): Tag all packages as v10 (#24619)

10.75.2

  • fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)
  • fix(v10/core): Apply dataCollection.urlQueryParams to collected URLs and query strings (#24572)
  • fix(v10/nextjs): Align tunnel request matching in middleware with tunnel rewrite (#24565)
  • fix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams (#24563)

10.75.1

  • fix(v10/cloudflare): Capture telemetry from untraced Durable Object RPC calls (#24512)
  • fix(v10/cloudflare): Instrument namespaces returned by jurisdiction() (#24513)
  • fix(v10/hono): Allow @​cloudflare/workers-types v5 as peer dependency (#24500)
  • fix(v10/nextjs): Resolve Next.js version relative to the SDK when cwd differs (#24475)

10.75.0

Important Changes

  • feat(v10/effect): Capture errors through the Effect v4 ErrorReporter API (#24445)

    On Effect v4, Sentry.effectLayer now registers a Sentry ErrorReporter. Failures that pass through Effect.withErrorReporting, ErrorReporter.report or the built-in HTTP and RPC reporting boundaries are captured automatically, with ErrorReporter.ignore, ErrorReporter.severity and ErrorReporter.attributes annotations respected. Nothing changes on Effect v3.

Other Changes

  • feat(v10/core): Accept a CollectBehavior shorthand for dataCollection.httpHeaders (#24339)
  • fix(v10/browser): Release the XHR virtualError once the request completed (#24307)
  • fix(v10/browser-utils): Skip nullish LCP entries in vendored web-vitals (#24349)
  • fix(v10/bundler-plugins): Stamp debug IDs onto emitted source maps when disable-upload is set (#24332)
  • fix(v10/core): Don't instrument the SDK's own envelope requests (#24276)
  • fix(v10/nextjs): Only include emitted chunk directories in Turbopack sourcemap upload (#24295)
  • fix(v10/nitro): Import from nitro/h3 instead of h3 directly (#24444)
  • fix(v10/node-core): Don't recurse in logAndExitProcess on a broken stdio pipe (#24353)
  • fix(v10/nuxt): Detect Nitro version via the app's Nuxt dependency chain (#24025)
  • fix(v10/replay): Don't rewrite already-emitted nodes when syncing mirror attributes (#23588)

10.74.0

  • feat(v10): Streamline isolation scope handling & reset in isolation scopes (#24152)

... (truncated)

Commits
  • 3b282c1 release: 10.75.3
  • b5ea330 meta(changelog): Update changelog for 10.75.3 (#24649)
  • 533a6fa chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)
  • 4e91ce5 chore(v10/publish): Tag all packages as v10 (#24619)
  • f01ca30 fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel ...
  • 79e6e95 Merge remote-tracking branch 'remotes/origin/release/10.75.2' into v10
  • faeac9a release: 10.75.2
  • 7175b19 meta(changelog): Update changelog for 10.75.2 (#24585)
  • 8f5dc60 fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)
  • 44506df fix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams...
  • Additional commits viewable in compare view

Updates dompurify from 3.4.14 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible

DOMPurify 3.4.15

  • Added better clobbering hardening when XML content is involved, thanks @​gnyselcuk
  • Added several smaller hardening and edge-case improvements, thanks @​leechristensen
  • Bumped several dependencies where possible
Commits

Updates jszip from 3.10.1 to 3.10.2

Changelog

Sourced from jszip's changelog.

v3.10.2 2026-09-09

  • Fix cross-realm binary type detection in getTypeOf. Fixes #759 (see #578)
  • Add missing types for JSZip.defaults. Fixes #690 (see #927)
  • Fix Blob support in Node.js 18 and up. Fixes #941 (see #955)
Commits
Maintainer changes

This version was pushed to npm by jkoops, a new releaser for jszip since your current version.


Updates react-hook-form from 7.87.0 to 7.89.0

Release notes

Sourced from react-hook-form's releases.

Version 7.89.0

🐞 Fixes

  • Fix form state select option (#13784)
  • Remove duplicate default value field (#13783)
  • Fix validateField skipping refs without setCustomValidity under native validation (#13782)
  • Fix form-level validation using a stale validate function (#13777)
  • Fix useFieldArray touched fields handling (#13776)
  • Fix pending delayError timers for nested paths (#13775)
  • Fix getValues extracting unmarked field array entries (#13773)
  • Fix field array touched state not being re-indexed when unsubscribed (#13772)
  • Fix nested delayError timers remaining when a parent validates clean (#13771)
  • Fix nested delayError timers remaining after resetField() resets a parent (#13769)
  • Fix stale field array root errors after an operation satisfies the validation rule (#13767)
  • Fix setValue() not revalidating dependencies when shouldValidate is enabled (#13765)
  • Fix stale built-in validation results after reset() during handleSubmit() (#13761)
  • Fix stale form-level validation results after reset() (#13762)
  • Fix validation rules removed from register options at runtime remaining active (#13758)
  • Fix useController required validation not using the controlled value (#13756)
  • Fix stale form-level errors remaining after successful re-validation (#13755)
  • Fix useFieldArray marking the form dirty when the array default value is null (#13750)
  • Fix isValid not being recomputed when the errors prop is emptied (#13748)
  • Fix form-level validation running more than once per traversal (#13747)
  • Fix stale built-in validation results after reset() during onChange (#13745)
  • Fix stale resolver results after reset() during onChange (#13744)
  • Fix setValue() not triggering field array root validation when shouldValidate is enabled (#13743)
  • Fix getFieldState(name, formState) updates after reset() (#13741)
  • Fix dirty state remaining for rows removed from a field array (#13739)

🧹 Refactors

  • Replace rimraf cleanup with fs.rmSync (#13770)
  • Reduce bundle size (#13759)

📦 Dependencies

  • Add optional @types/react peer dependency (#13781)

❤️ Thank You

Version 7.88.0

✨ Features

  • Add Error Message component (#13472)
  • Add the Error Message component for displaying validation errors from React Hook Form.

🐞 Fixes

... (truncated)

Changelog

Sourced from react-hook-form's changelog.

[7.89.0] - 2026-09-26

Changed

  • Add optional @types/react peer dependency

Fixed

  • validateField calling setCustomValidity on refs that don't implement it under native validation
  • Form-level validate running a stale function instead of the latest one
  • Form-level validation leaving stale errors after a successful re-validation
  • Form-level validation running more than once per traversal
  • Stale validation results (resolver, built-in, form-level validate) being applied after reset in onChange and handleSubmit
  • Pending delayError timers for nested paths not being cancelled when a parent validates clean or is reset via resetField
  • getValues(names, { dirtyFields }) returning every row of a field array instead of only the marked entries
  • Field array touched state not being re-indexed when touchedFields is not subscribed
  • useFieldArray emitting touchedFields in form state updates when unnecessary
  • Stale field array root error not clearing once an array operation satisfies the rule
  • useFieldArray marking the form dirty when the array default is null
  • Dirty state lingering for rows removed from a field array
  • setValue with shouldValidate not revalidating deps
  • setValue with shouldValidate not triggering validation for a field array root
  • Validation rules removed from register options at runtime still being applied
  • useController validating required against the input value instead of the controlled value
  • isValid not recomputing when the errors prop is emptied
  • getFieldState(name, formState) with a resolver after reset()

[7.88.0] - 2026-09-12

Added

  • <ErrorMessage /> component for rendering a field's validation error

Fixed

  • setValue dirty state comparison ignoring valueAs* / setValueAs transforms
  • Nested delayError timers not being cancelled when a parent is cleared or unregistered
  • Cleared delayError errors coming back once the pending timer fires
  • criteriaMode not refreshing when form options are updated at runtime
  • resetField leaving stale validating state for the field
  • reset not clearing isValidating and validatingFields, and ignoring keepIsValidating
  • replace() leaving errors and touched state for removed rows
  • remove() leaking deleted values onto surviving items
  • handleSubmit applying a stale resolver result after reset
  • handleSubmit dropping resolver-reported root errors on submit
  • Stale resolver state updates being applied after reset
  • trigger dropping registered nested errors when targeting their parent
  • trigger setting a parent error when the target has only nested resolver errors
  • useWatch compute cache not being initialized with the initial output
  • flatten / jsonToFormData not preserving FileList and not skipping undefined

... (truncated)

Commits
  • 4722d22 7.89.0
  • 72a4c98 👟 chore: correct form state select option (#13784)
  • 14c7bec 🕵🏻‍♂️ chore: remove duplicate default value field (#13783)
  • d9cab62 🤖 chore: add optional @​types/react peer dependency (#13781)
  • c12546c 🐞 fix(validateField): skip refs without setCustomValidity under native valida...
  • 5fd9ef6 🐞 fix(validate): run the latest form level validate function (#13777)
  • 7893230 🐞 fix(useFieldArray): improve touched fields handling and add tests (#13776)
  • ad8abf6 🐴 cancel pending delayError timers for nested paths (#13775)
  • eb159da 🐞 fix(getValues): extract only the marked entries of a field array (#13773)
  • 4647014 🐞 fix: re-index field array touched state when it is not subscribed (#13772)
  • Additional commits viewable in compare view

Updates socket.io-client from 4.8.3 to 4.8.4

Release notes

Sourced from socket.io-client's releases.

socket.io-client@4.8.4

Bug Fixes

  • types: export ExtendedError for connect_error event (#5548) (c0d5450)
  • types: export reserved event interfaces (#5533) (03945df)

Dependencies

Commits
  • 11a6f56 chore(release): socket.io-client@4.8.4
  • 00e4e73 chore(release): engine.io-client@6.6.7
  • e387ab1 chore: use @​rollup/plugin-terser instead of rollup-plugin-terser
  • 9738333 chore(release): engine.io@6.6.11
  • fc9dd90 docs(eio): rework README
  • da008a5 fix(eio): refresh ping timeout on incoming packets
  • 3df3fed fix(eio-client): restore default transport resolution
  • aaf2af3 test: upgrade WebdriverIO to v9
  • b5da079 refactor(sio): simplify packet handling switch
  • 45873ca docs(protocol): clarify namespace comma restriction for built-in parser (#5545)
  • Additional commits viewable in compare view

Updates csv-stringify from 6.8.3 to 6.9.0

Changelog

Sourced from csv-stringify's changelog.

6.9.0 (2026-09-25)

Features

  • csv-stringify: expose csv error and normalize_options (963388d)

Bug Fixes

  • csv-stringify: do not alter the source record when columns is set (#504) (041deff)
  • csv-stringify: preserve header cast context when eof is false (#505) (a38ef06)
  • csv-stringify: preserve negative numeric values (#510) (0002d56)
  • csv-stringify: preserve objects returned by cast functions (#509) (1742c9f)
  • csv-stringify: quote fields containing a carriage return (#485) (d64d410)
Commits
  • 594c646 chore(release): publish
  • 9f04145 build: latest dependencies
  • d64d410 fix(csv-stringify): quote fields containing a carriage return (#485)
  • 963388d feat(csv-stringify): expose csv error and normalize_options
  • 041deff fix(csv-stringify): do not alter the source record when columns is set (#504)
  • a38ef06 fix(csv-stringify): preserve header cast context when eof is false (#505)
  • 8d4173d build: latest dev dependencies
  • c8caa1c build: generate latest dist
  • 3433750 test: eslint format
  • 6c45c9b build: remove npx usage in package scripts
  • Additional commits viewable in compare view

Updates moment from 2.30.1 to 2.31.0

Release notes

Sourced from moment's releases.

2.31.0

Released Sep 14, 2026

Security fixes

Bug fixes

  • #6376 Prevent object prototype properties from being used as format tokens
  • #6386 Normalize lazy-loaded locale names
  • #6404 Fix parsing issue with eHHmm format
  • #6433 Ignore non-Moment arguments in min and max
  • #6434 Fix inherited lowercase long date formats
  • #6436 Reset locale parsing caches after updates
  • #6437 Fix weekday mismatch when the format only has part of a date
  • #6442 Fix locale('__proto__') corrupting the global locale
  • #6443 Avoid Object.assign in duration.humanize
  • #6446 Validate range when parsing a time zone offset
  • #6447 Include metadata in all-locales bundle
  • #6448 Apply postformat to locale relative time methods
  • #6450 Add stack traces to conditional deprecation warnings

New features

  • #6451 Add internal date-default hook for Moment Timezone
New locales

Updates to existing locales

  • #5404 Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time
  • #6197 Indonesian ('id'): Correct the abbreviation for August
  • #6217 Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct L date formats
  • #6289 Swedish ('sv'): Correct the abbreviation for Thursday
  • #6306 Catalan ('ca'): Use typographic apostrophes in relative time
  • #6347 Swahili ('sw'): Correct the spelling of hour in calendar output
  • #6360 Ukrainian ('uk'): Use ISO week numbering
  • #6370 Ukrainian ('uk'): Use U+02BC apostrophes in Friday names
  • #6371 Hungarian ('hu'): Preserve numeric values in relative seconds
  • #6391 Swahili ('sw'): Fix weekday and relative-time grammar
  • #6396 German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots
  • #6409 Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting
  • #6410 Polish ('pl'): Use genitive month names in dotted day formats
Changelog

Sourced from moment's changelog.

2.31.0

Released Sep 14, 2026

Security fixes

Bug fixes

  • #6376 Prevent object prototype properties from being used as format tokens
  • #6386 Normalize lazy-loaded locale names
  • #6404 Fix parsing issue with eHHmm format
  • #6433 Ignore non-Moment arguments in min and max
  • #6434 Fix inherited lowercase long date formats
  • #6436 Reset locale parsing caches after updates
  • #6437 Fix weekday mismatch when the format only has part of a date
  • #6442 Fix locale('__proto__') corrupting the global locale
  • #6443 Avoid Object.assign in duration.humanize
  • #6446 Validate range when parsing a time zone offset
  • #6447 Include metadata in all-locales bundle
  • #6448 Apply postformat to locale relative time methods
  • #6450 Add stack traces to conditional deprecation warnings

New features

  • #6451 Add internal date-default hook for Moment Timezone
New locales

Updates to existing locales

  • #5404 Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time
  • #6197 Indonesian ('id'): Correct the abbreviation for August
  • #6217 Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct L date formats
  • #6289 Swedish ('sv'): Correct the abbreviation for Thursday
  • #6306 Catalan ('ca'): Use typographic apostrophes in relative time
  • #6347 Swahili ('sw'): Correct the spelling of hour in calendar output
  • #6360 Ukrainian ('uk'): Use ISO week numbering
  • #6370 Ukrainian ('uk'): Use U+02BC apostrophes in Friday names
  • #6371 Hungarian ('hu'): Preserve numeric values in relative seconds
  • #6391 Swahili ('sw'): Fix weekday and relative-time grammar
  • #6396 German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots
  • #6409 Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting
  • #6410 Polish ('pl'): Use genitive month names in dotted day formats
Commits
  • 15b45d4 [pkg] Build 2.31.0 (#6452)
  • 631cd81 [pkg] Update changelog for upcoming release (#6394)
  • 6caff9e Merge commit from fork
  • 710703b [feature] Add internal date-default hook for Moment Timezone (#6451)
  • 863ed94 [bugfix] Add stack traces to conditional deprecation warnings (#6450)
  • 2c7abe1 [bugfix] Apply postformat to locale relative time methods (#6448)
  • 9c45ac3 [bugfix] Include metadata in all-locales bundle (#6447)
  • f6eefc5 [bugfix] Validate timezone offset range (#6446)
  • 136b441 [bugfix] Avoid Object.assign in duration.humanize (#6443)
  • 0d10504 [bugfix] Fix locale('proto') corrupting the global locale (#6442)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for moment since your current version.


Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
@sentry/react [>= 10.71.a, < 10.72]

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note

Medium Risk
Touches Sentry, HTML sanitization, and the RDI pipeline package with new editor/schema dependencies; mostly routine bumps but worth smoke-testing RDI editors, markdown rendering, realtime sockets, and Electron crash reporting.

Overview
Bumps 10 direct dependencies in package.json and refreshes package-lock.json; there is no application source change.

The largest product-facing shift is @rdi-ui/pipeline 0.1.35 → 0.1.41, which pulls in CodeMirror lint/autocomplete and codemirror-json-schema (plus ajv) for schema-aware editing in the RDI pipeline UI.

@sentry/electron (7.18.0 → 7.20.0) and @sentry/react (10.73.0 → 10.75.3) update error reporting for the desktop shell and React UI. dompurify (3.4.14 → 3.4.16) and dev moment (2.30.1 → 2.31.0, includes CVE-2026-17495) are security-oriented patches. Remaining bumps are patch/minor: jszip, socket.io-client, react-hook-form, csv-stringify, and tsx.

Reviewed by Cursor Bugbot for commit af75e28. Bugbot is set up for automated code reviews on this repo. Configure here.

…0 updates

Bumps the everything-else group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| @rdi-ui/pipeline | `0.1.35` | `0.1.41` |
| [@sentry/electron](https://github.com/getsentry/sentry-electron) | `7.18.0` | `7.20.0` |
| [@sentry/react](https://github.com/getsentry/sentry-javascript) | `10.73.0` | `10.75.3` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.14` | `3.4.16` |
| [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.87.0` | `7.89.0` |
| [socket.io-client](https://github.com/socketio/socket.io) | `4.8.3` | `4.8.4` |
| [csv-stringify](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-stringify) | `6.8.3` | `6.9.0` |
| [moment](https://github.com/moment/moment) | `2.30.1` | `2.31.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |



Updates `@rdi-ui/pipeline` from 0.1.35 to 0.1.41

Updates `@sentry/electron` from 7.18.0 to 7.20.0
- [Release notes](https://github.com/getsentry/sentry-electron/releases)
- [Changelog](https://github.com/getsentry/sentry-electron/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-electron@7.18.0...7.20.0)

Updates `@sentry/react` from 10.73.0 to 10.75.3
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.73.0...10.75.3)

Updates `dompurify` from 3.4.14 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.14...3.4.16)

Updates `jszip` from 3.10.1 to 3.10.2
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](Stuk/jszip@v3.10.1...v3.10.2)

Updates `react-hook-form` from 7.87.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.87.0...v7.89.0)

Updates `socket.io-client` from 4.8.3 to 4.8.4
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-client@4.8.3...socket.io-client@4.8.4)

Updates `csv-stringify` from 6.8.3 to 6.9.0
- [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-stringify/CHANGELOG.md)
- [Commits](https://github.com/adaltas/node-csv/commits/csv-stringify@6.9.0/packages/csv-stringify)

Updates `moment` from 2.30.1 to 2.31.0
- [Release notes](https://github.com/moment/moment/releases)
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md)
- [Commits](moment/moment@2.30.1...2.31.0)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

---
updated-dependencies:
- dependency-name: "@rdi-ui/pipeline"
  dependency-version: 0.1.41
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: everything-else
- dependency-name: "@sentry/electron"
  dependency-version: 7.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: everything-else
- dependency-name: "@sentry/react"
  dependency-version: 10.75.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: everything-else
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: everything-else
- dependency-name: jszip
  dependency-version: 3.10.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: everything-else
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: everything-else
- dependency-name: socket.io-client
  dependency-version: 4.8.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: everything-else
- dependency-name: csv-stringify
  dependency-version: 6.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: everything-else
- dependency-name: moment
  dependency-version: 2.31.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: everything-else
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: everything-else
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 4, 2026 23:08
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@dependabot
dependabot Bot deployed to staging October 4, 2026 23:09 Active

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af75e28d17

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread package.json
Comment on lines +279 to +280
"@sentry/electron": "^7.20.0",
"@sentry/react": "^10.75.3",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Align the Sentry core override with the upgraded SDKs

The unchanged top-level @sentry/core override still forces version 10.73.0: the new lockfile has no nested core copies, even though the upgraded Electron SDK declares an exact @sentry/core@10.75.0 dependency and the React SDK declares 10.75.3. Consequently both main and renderer Sentry initialization run the new SDK packages against an unsupported older core, making error reporting unreliable. Update, remove, or scope the override and regenerate the lockfile; the prior Sentry bump in 7ed66571 made this same override adjustment specifically to avoid this mismatch.

Useful? React with 👍 / 👎.

@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active
@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active
@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active
@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active
@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active
@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active
@dependabot
dependabot Bot deployed to production October 4, 2026 23:13 Active

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit af75e28. Configure here.

Comment thread package.json
"@sentry/electron": "^7.18.0",
"@sentry/react": "^10.73.0",
"@sentry/electron": "^7.20.0",
"@sentry/react": "^10.75.3",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Sentry core pin after upgrade

Medium Severity

@sentry/react 10.75.3 and @sentry/electron 7.20.0 both require @sentry/core 10.75.x, but the npm overrides entry still forces @sentry/core 10.73.0. The lockfile therefore installs a single stale core while the Electron renderer also dual-inits @sentry/react 10.75.3 against nested 10.75.0 packages. Isolation-scope handling changed in 10.74, so crash reporting can drop events, mix scope data, or throw during capture.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit af75e28. Configure here.

This branch had an error being deployed

1 failed and 1 active deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants