Skip to content

[ci] Bump the production-dependencies group across 1 directory with 12 updates - #6476

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cluster/pulumi/production-dependencies-cfc74e6f45
Closed

[ci] Bump the production-dependencies group across 1 directory with 12 updates#6476
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cluster/pulumi/production-dependencies-cfc74e6f45

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 12 updates in the /cluster/pulumi directory:

Package From To
@google-cloud/sql 0.24.0 0.25.0
@dotenvx/dotenvx 1.71.0 1.75.1
@google-cloud/storage 7.19.0 7.21.0
@pulumi/gcp 9.18.0 9.31.0
@pulumi/pulumi 3.247.0 3.254.0
@pulumi/random 4.19.2 4.21.1
@pulumi/github 6.13.1 6.14.1
auth0 5.6.0 5.14.0
zod 4.3.6 4.4.3
@pulumi/auth0 3.39.0 3.49.0
semver 7.8.1 7.8.5
@pulumi/policy 1.20.0 1.21.0

Updates @google-cloud/sql from 0.24.0 to 0.25.0

Release notes

Sourced from @​google-cloud/sql's releases.

sql: v0.25.0

0.25.0 (2026-07-13)

Features

  • Update googleapis source and regenerate client libraries (#8821) (2a3a77c)
Changelog

Sourced from @​google-cloud/sql's changelog.

0.25.0 (2026-07-13)

Features

  • Update googleapis source and regenerate client libraries (#8821) (2a3a77c)

0.24.1 (2026-05-01)

Bug Fixes

  • Change the copyright year for files in the packages folder (#8109) (c1a03fe)
  • Do not publish the protos to npm (#8079) (816216b)
  • Revert "fix: Do not publish the protos to npm" (#8096) (ac0fbb6)
Commits

Updates @dotenvx/dotenvx from 1.71.0 to 1.75.1

Release notes

Sourced from @​dotenvx/dotenvx's releases.

v1.75.1

see CHANGELOG

v1.75.0

see CHANGELOG

v1.74.3

see CHANGELOG

v1.74.2

see CHANGELOG

v1.74.1

see CHANGELOG

v1.74.0

see CHANGELOG

v1.73.1

see CHANGELOG

v1.73.0

see CHANGELOG

v1.72.0

see CHANGELOG

v1.71.3

see CHANGELOG

v1.71.2

see CHANGELOG

v1.71.1

see CHANGELOG

Changelog

Sourced from @​dotenvx/dotenvx's changelog.

1.75.1 (2026-06-20)

Changed

  • Publish as named binaries (#851)

Removed

  • Remove references to dotenvx-vlt (now dotenvx-armor) (#849)

1.75.0 (2026-06-19)

Changed

  • Swap in @dotenvx/primitives (#848)
  • ext commands become first-class(#847)

1.74.4 (2026-06-19)

Removed

  • Remove separately published @dotenvx/next-env from this repo (#846)

1.74.3 (2026-06-19)

Changed

  • Bundle dotenvx with @dotenvx/next-env for user convenience (#845)

1.74.2 (2026-06-18)

Changed

  • Fix provenance for @dotenvx/next-env (#844)

1.74.1 (2026-06-18)

Added

  • Add README for @dotenvx/next-env (#843)

1.74.0 (2026-06-18)

Added

1.73.1 (2026-06-16)

Changed

... (truncated)

Commits

Updates @google-cloud/storage from 7.19.0 to 7.21.0

Changelog

Sourced from @​google-cloud/storage's changelog.

7.21.0 (2026-06-03)

Features

  • storage: Enable CRC32C validation by default in transfer manager (#8350) (86086a6)

Bug Fixes

7.20.0 (2026-05-11)

Features

  • storage: Implement Object Contexts with advanced filtering and validation (#7548) (d60757e)
  • storage: Implement robust path validation and structured skip reporting (#7546) (113d05c)
  • storage: Set CRC32C as the default checksum option (#7547) (1a693aa)

Bug Fixes

Commits
  • 106bb0e chore(main): release storage 7.21.0 (#8435)
  • b7433b3 chore: clean up linkinator configurations and test scripts across monorepo (#...
  • 3ec901e fix(deps): remove vulnerable dependency uuid (#8120)
  • 86086a6 feat(storage): enable CRC32C validation by default in transfer manager (#8350)
  • 92b328b chore: release main (#8242)
  • 9fd76ef fix: bump all node submodules (#8178)
  • 1a44778 fix: resolve flakiness in Service retry system tests (#7945)
  • d60757e feat(storage): implement Object Contexts with advanced filtering and validati...
  • 1a693aa feat(storage): Set CRC32C as the default checksum option (#7547)
  • 113d05c feat(storage): Implement robust path validation and structured skip reporting...
  • Additional commits viewable in compare view

Updates @pulumi/gcp from 9.18.0 to 9.31.0

Release notes

Sourced from @​pulumi/gcp's releases.

v9.31.0

What's Changed

New Contributors

Full Changelog: pulumi/pulumi-gcp@v9.30.0...v9.31.0

v9.30.0

What's Changed

Full Changelog: pulumi/pulumi-gcp@v9.29.0...v9.30.0

v9.29.0

What's Changed

Full Changelog: pulumi/pulumi-gcp@v9.28.0...v9.29.0

v9.28.0

What's Changed

... (truncated)

Commits

Updates @pulumi/pulumi from 3.247.0 to 3.254.0

Release notes

Sourced from @​pulumi/pulumi's releases.

v3.254.0

3.254.0 (2026-07-23)

Features

  • [cli] Add pulumi logs share command for sharing logs with Pulumi #22546
  • [cli] Add pulumi stack migrate to migrate a stack from another backend to the currently logged-in backend, including re-encrypting config secrets and stack state under the target secrets provider #22902
  • [cli/config] Add an --override-env flag to up, preview, destroy, and refresh to substitute imported environments for a single run without editing the stack config #23562
  • [cli] Add pulumi neo acp to run Neo as an Agent Client Protocol agent over stdio for ACP-capable editors, with read-only and plan mode exposed as session config options #23886
  • [cli/neo] Retry transient pulumi neo stream and message-send failures, and add pulumi neo resume with chat history #23835
  • [cli/neo] Make Ctrl+C clear typed text and preserve Ctrl+A/Ctrl+E line navigation in pulumi neo #23932
  • [cli/do] Add upsert to do, allowing resources to be statefully created or updated in a stack #23813
  • [sdk/python] Add pulumi.run for natively awaited Python program entrypoints that can return stack outputs #23945
  • [cli/do] Allow expressions for number inputs #23954
  • [cli/do] Allow expressions for boolean inputs #23967
  • [cli/policy] Add --runtime-options to pulumi policy new #23992
  • [cli/do] Add support for stateful create #23996
  • [cli/do] Add support for stateful delete #24000

Bug Fixes

  • [sdkgen/go] Fix Go codegen for plain properties nested inside non-plain objects #22524
  • [cli/neo] Keep pulumi neo connected during quiet periods when the event stream only receives keep-alive heartbeats #23935
  • [engine] Validate snippets before persisting them #23920
  • [backend] Fix dangling ReplaceWith references in the journal replayer #23927
  • [cli/do] Fix the converter plugin not being called if just attributes needed converting #23948
  • [programgen/go] Generate compilable Go for programs that use discriminated union members as array/list elements #23980

Improvements

  • [cli] Align commands with the CLI naming guidelines, adding ls, rm, delete, mv, update, modify, create and setup aliases to list/remove/move/edit/new commands and making state remove and package remove the canonical names with delete kept as an alias #23903
  • [cli] Suggest closely-matching commands from the whole command tree when an unknown command is entered #23848
  • [cli] Print help but exit with a non-zero code when pulumi is run without a command, matching the behavior of other group commands #23848
  • [programgen] Support onError resource hooks in generated Go, NodeJS, and Python programs and in the PCL runtime, retrying the failed operation when the hook command exits successfully #23839
  • [protobuf] Add parent and properties fields to ResourceImport so state converters can express resource hierarchy and property filters #23929
  • [protobuf] Allow state converters to declare explicit providers as resources in ConvertState responses and attach imported resources to them via the new provider field #23975
  • [cli] Redact secrets in property values in logs #23931
  • [cli] Make -v<n> --logflow no longer produce separate log files for plugins #23938
  • [protobuf] Pass a schema loader target to state converters in ConvertStateRequest #23944
  • [cli/import] Allow explicit providers to be declared in the resources section of an import file and referenced by name #23972
  • [cli] Remove the template count from pulumi new --help, which required a slow template listing before help could display #23973
  • [cli/import] Support inputs and outputs on resources in import files, importing supplied state directly and skipping the provider read when outputs are given #23984

Miscellaneous

  • [sdk] Move RetrieveGitFolder to the gitutil package #23955
  • [sdk] Move template helpers from workspace to pkg/cmd/pulumi/templates #23963

v3.253.0

3.253.0 (2026-07-14)

... (truncated)

Changelog

Sourced from @​pulumi/pulumi's changelog.

3.254.0 (2026-07-23)

Features

  • [cli] Add pulumi logs share command for sharing logs with Pulumi #22546
  • [cli] Add pulumi stack migrate to migrate a stack from another backend to the currently logged-in backend, including re-encrypting config secrets and stack state under the target secrets provider #22902
  • [cli/config] Add an --override-env flag to up, preview, destroy, and refresh to substitute imported environments for a single run without editing the stack config #23562
  • [cli] Add pulumi neo acp to run Neo as an Agent Client Protocol agent over stdio for ACP-capable editors, with read-only and plan mode exposed as session config options #23886
  • [cli/neo] Retry transient pulumi neo stream and message-send failures, and add pulumi neo resume with chat history #23835
  • [cli/neo] Make Ctrl+C clear typed text and preserve Ctrl+A/Ctrl+E line navigation in pulumi neo #23932
  • [cli/do] Add upsert to do, allowing resources to be statefully created or updated in a stack #23813
  • [sdk/python] Add pulumi.run for natively awaited Python program entrypoints that can return stack outputs #23945
  • [cli/do] Allow expressions for number inputs #23954
  • [cli/do] Allow expressions for boolean inputs #23967
  • [cli/policy] Add --runtime-options to pulumi policy new #23992
  • [cli/do] Add support for stateful create #23996
  • [cli/do] Add support for stateful delete #24000

Bug Fixes

  • [sdkgen/go] Fix Go codegen for plain properties nested inside non-plain objects #22524
  • [cli/neo] Keep pulumi neo connected during quiet periods when the event stream only receives keep-alive heartbeats #23935
  • [engine] Validate snippets before persisting them #23920
  • [backend] Fix dangling ReplaceWith references in the journal replayer #23927
  • [cli/do] Fix the converter plugin not being called if just attributes needed converting #23948
  • [programgen/go] Generate compilable Go for programs that use discriminated union members as array/list elements #23980

Improvements

  • [cli] Align commands with the CLI naming guidelines, adding ls, rm, delete, mv, update, modify, create and setup aliases to list/remove/move/edit/new commands and making state remove and package remove the canonical names with delete kept as an alias #23903
  • [cli] Suggest closely-matching commands from the whole command tree when an unknown command is entered #23848
  • [cli] Print help but exit with a non-zero code when pulumi is run without a command, matching the behavior of other group commands #23848
  • [programgen] Support onError resource hooks in generated Go, NodeJS, and Python programs and in the PCL runtime, retrying the failed operation when the hook command exits successfully #23839
  • [protobuf] Add parent and properties fields to ResourceImport so state converters can express resource hierarchy and property filters #23929
  • [protobuf] Allow state converters to declare explicit providers as resources in ConvertState responses and attach imported resources to them via the new provider field #23975
  • [cli] Redact secrets in property values in logs #23931
  • [cli] Make -v<n> --logflow no longer produce separate log files for plugins #23938
  • [protobuf] Pass a schema loader target to state converters in ConvertStateRequest #23944
  • [cli/import] Allow explicit providers to be declared in the resources section of an import file and referenced by name #23972
  • [cli] Remove the template count from pulumi new --help, which required a slow template listing before help could display #23973
  • [cli/import] Support inputs and outputs on resources in import files, importing supplied state directly and skipping the provider read when outputs are given #23984

Miscellaneous

  • [sdk] Move RetrieveGitFolder to the gitutil package #23955
  • [sdk] Move template helpers from workspace to pkg/cmd/pulumi/templates #23963

3.253.0 (2026-07-14)

Features

... (truncated)

Commits
  • d7522ff Update module google.golang.org/grpc to v1.82.1 [SECURITY] (#24035)
  • 29ac4d9 Make test_fast fast (#24005)
  • 68f6673 Remove some outdated dependencies (#23998)
  • aca1862 Add accepts_byte_string capability fields to the protocol (#23873)
  • e14c323 Update dependency js-yaml to v4.3.0 [SECURITY] (#23997)
  • 73ab6ca Add loader_target to ConvertStateRequest (#23944)
  • 69afa57 Add explicit provider support to ConvertState responses (#23975)
  • 53806e2 Remove the simple-enum-schema SDK codegen test, covered by conformance tests ...
  • 0f7e7c4 vendor charmbracelet/bubbles/textinput & atotto/clipboard (#23959)
  • 8a79286 Add a language conformance test for onError resource hooks (#23839)
  • Additional commits viewable in compare view

Updates @pulumi/random from 4.19.2 to 4.21.1

Release notes

Sourced from @​pulumi/random's releases.

v4.21.1

What's Changed

Full Changelog: pulumi/pulumi-random@v4.21.0...v4.21.1

... (truncated)

Commits

Updates @pulumi/github from 6.13.1 to 6.14.1

Release notes

Sourced from @​pulumi/github's releases.

v6.14.1

What's Changed

@dependabot dependabot Bot added the static Used to label PRs for which static tests suffice label Jul 20, 2026
@github-actions

Copy link
Copy Markdown

Deploy upgrade pipeline triggered for Commit c99df42c2bc1d1f5ecacf9e3899bf8a2fb46abd6 in , please contact a Contributor to approve it in CircleCI: https://app.circleci.com/pipelines/github/DACH-NY/canton-network-internal/75152

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cluster/pulumi/production-dependencies-cfc74e6f45 branch 6 times, most recently from 92dbc8f to 6e58d96 Compare July 27, 2026 18:47
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cluster/pulumi/production-dependencies-cfc74e6f45 branch 2 times, most recently from b749d81 to a12c5a5 Compare July 29, 2026 18:46
…2 updates

Bumps the production-dependencies group with 12 updates in the /cluster/pulumi directory:

| Package | From | To |
| --- | --- | --- |
| [@google-cloud/sql](https://github.com/googleapis/google-cloud-node/tree/HEAD/packages/google-cloud-sql) | `0.24.0` | `0.25.0` |
| [@dotenvx/dotenvx](https://github.com/dotenvx/dotenvx) | `1.71.0` | `1.75.1` |
| [@google-cloud/storage](https://github.com/googleapis/google-cloud-node/tree/HEAD/handwritten/storage) | `7.19.0` | `7.21.0` |
| [@pulumi/gcp](https://github.com/pulumi/pulumi-gcp) | `9.18.0` | `9.31.0` |
| [@pulumi/pulumi](https://github.com/pulumi/pulumi/tree/HEAD/sdk/nodejs) | `3.247.0` | `3.254.0` |
| [@pulumi/random](https://github.com/pulumi/pulumi-random) | `4.19.2` | `4.21.1` |
| [@pulumi/github](https://github.com/pulumi/pulumi-github) | `6.13.1` | `6.14.1` |
| [auth0](https://github.com/auth0/node-auth0) | `5.6.0` | `5.14.0` |
| [zod](https://github.com/colinhacks/zod) | `4.3.6` | `4.4.3` |
| [@pulumi/auth0](https://github.com/pulumi/pulumi-auth0) | `3.39.0` | `3.49.0` |
| [semver](https://github.com/npm/node-semver) | `7.8.1` | `7.8.5` |
| [@pulumi/policy](https://github.com/pulumi/pulumi-policy) | `1.20.0` | `1.21.0` |



Updates `@google-cloud/sql` from 0.24.0 to 0.25.0
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/packages/google-cloud-sql/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/v0.25.0/packages/google-cloud-sql)

Updates `@dotenvx/dotenvx` from 1.71.0 to 1.75.1
- [Release notes](https://github.com/dotenvx/dotenvx/releases)
- [Changelog](https://github.com/dotenvx/dotenvx/blob/main/CHANGELOG.md)
- [Commits](dotenvx/dotenvx@v1.71.0...v1.75.1)

Updates `@google-cloud/storage` from 7.19.0 to 7.21.0
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/handwritten/storage/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/storage-v7.21.0/handwritten/storage)

Updates `@pulumi/gcp` from 9.18.0 to 9.31.0
- [Release notes](https://github.com/pulumi/pulumi-gcp/releases)
- [Changelog](https://github.com/pulumi/pulumi-gcp/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-gcp@v9.18.0...v9.31.0)

Updates `@pulumi/pulumi` from 3.247.0 to 3.254.0
- [Release notes](https://github.com/pulumi/pulumi/releases)
- [Changelog](https://github.com/pulumi/pulumi/blob/master/CHANGELOG.md)
- [Commits](https://github.com/pulumi/pulumi/commits/v3.254.0/sdk/nodejs)

Updates `@pulumi/random` from 4.19.2 to 4.21.1
- [Release notes](https://github.com/pulumi/pulumi-random/releases)
- [Changelog](https://github.com/pulumi/pulumi-random/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-random@v4.19.2...v4.21.1)

Updates `@pulumi/github` from 6.13.1 to 6.14.1
- [Release notes](https://github.com/pulumi/pulumi-github/releases)
- [Changelog](https://github.com/pulumi/pulumi-github/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-github@v6.13.1...v6.14.1)

Updates `auth0` from 5.6.0 to 5.14.0
- [Release notes](https://github.com/auth0/node-auth0/releases)
- [Changelog](https://github.com/auth0/node-auth0/blob/master/CHANGELOG.md)
- [Commits](auth0/node-auth0@v5.6.0...v5.14.0)

Updates `zod` from 4.3.6 to 4.4.3
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.3.6...v4.4.3)

Updates `@pulumi/auth0` from 3.39.0 to 3.49.0
- [Release notes](https://github.com/pulumi/pulumi-auth0/releases)
- [Changelog](https://github.com/pulumi/pulumi-auth0/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-auth0@v3.39.0...v3.49.0)

Updates `semver` from 7.8.1 to 7.8.5
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)
- [Commits](npm/node-semver@v7.8.1...v7.8.5)

Updates `@pulumi/policy` from 1.20.0 to 1.21.0
- [Changelog](https://github.com/pulumi/pulumi-policy/blob/main/CHANGELOG.md)
- [Commits](pulumi/pulumi-policy@v1.20.0...v1.21.0)

---
updated-dependencies:
- dependency-name: "@dotenvx/dotenvx"
  dependency-version: 1.75.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@google-cloud/sql"
  dependency-version: 0.24.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@google-cloud/storage"
  dependency-version: 7.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@pulumi/auth0"
  dependency-version: 3.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@pulumi/gcp"
  dependency-version: 9.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@pulumi/github"
  dependency-version: 6.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@pulumi/policy"
  dependency-version: 1.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@pulumi/pulumi"
  dependency-version: 3.252.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@pulumi/random"
  dependency-version: 4.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: auth0
  dependency-version: 5.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: semver
  dependency-version: 7.8.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.4.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cluster/pulumi/production-dependencies-cfc74e6f45 branch from a12c5a5 to 542c9b3 Compare July 30, 2026 18:46
@dependabot @github

dependabot Bot commented on behalf of github Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 31, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/cluster/pulumi/production-dependencies-cfc74e6f45 branch July 31, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

static Used to label PRs for which static tests suffice

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants