Skip to content

chore(deps): bump @trpc/client from 11.15.1 to 11.17.0#240

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/trpc/client-11.17.0
Open

chore(deps): bump @trpc/client from 11.15.1 to 11.17.0#240
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/trpc/client-11.17.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 7, 2026

Bumps @trpc/client from 11.15.1 to 11.17.0.

Release notes

Sourced from @​trpc/client's releases.

v11.17.0

What's Changed

New Contributors

Full Changelog: trpc/trpc@v11.16.0...v11.17.0

v11.16.0

What's Changed

@trpc/openapi 11.16.0-alpha

  • Drops the type depth limit of 20, and significantly hardens cyclic-type support for both inference and Zod
  • Support zod.lazy via Standard Schema fallback
  • Strip symbols from output (no more __@asyncIterator@5456 symbols in output)
  • Add more comprehensive types for the OpenAPI doc from the official package (now a dependency) and apply some patches to these types because they're slightly outdated
  • Fixes several issues with gathering schema descriptions, such as consuming jsdoc comments from node_modules types

New Contributors

Full Changelog: trpc/trpc@v11.15.1...v11.16.0

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 7, 2026
@dependabot dependabot Bot requested a review from aamoghS as a code owner May 7, 2026 12:49
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 7, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 7, 2026

@dependabot merge

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 7, 2026

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 2 package(s) with unknown licenses.
See the Details below.

License Issues

packages/api/package.json

PackageVersionLicenseIssue Type
@trpc/client^11.17.0NullUnknown License

sites/mainweb/package.json

PackageVersionLicenseIssue Type
@trpc/client^11.17.0NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@trpc/client ^11.17.0 UnknownUnknown
npm/@trpc/client 11.17.0 🟢 6.1
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 4Found 7/17 approved changesets -- score normalized to 4
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Signed-Releases⚠️ -1no releases found
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 10SAST tool is run on all commits
npm/@trpc/client ^11.17.0 UnknownUnknown

Scanned Files

  • packages/api/package.json
  • pnpm-lock.yaml
  • sites/mainweb/package.json

@dependabot dependabot Bot changed the title Bump @trpc/client from 11.15.1 to 11.17.0 chore(deps): bump @trpc/client from 11.15.1 to 11.17.0 May 12, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/trpc/client-11.17.0 branch from 0e9f651 to 299ce75 Compare May 12, 2026 03:10
@github-actions
Copy link
Copy Markdown
Contributor

@dependabot merge

Bumps [@trpc/client](https://github.com/trpc/trpc/tree/HEAD/packages/client) from 11.15.1 to 11.17.0.
- [Release notes](https://github.com/trpc/trpc/releases)
- [Commits](https://github.com/trpc/trpc/commits/v11.17.0/packages/client)

---
updated-dependencies:
- dependency-name: "@trpc/client"
  dependency-version: 11.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/trpc/client-11.17.0 branch from 299ce75 to 618083d Compare May 16, 2026 04:52
@github-actions
Copy link
Copy Markdown
Contributor

@dependabot merge

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants