Bump the minor-and-patch group with 12 updates - #113
Conversation
Bumps the minor-and-patch group with 12 updates: | Package | From | To | | --- | --- | --- | | [@clerk/backend](https://github.com/clerk/javascript/tree/HEAD/packages/backend) | `3.11.7` | `3.13.1` | | [@clerk/nuxt](https://github.com/clerk/javascript/tree/HEAD/packages/nuxt) | `2.6.19` | `2.6.22` | | [@sentry/nuxt](https://github.com/getsentry/sentry-javascript) | `10.66.0` | `10.68.0` | | [@clerk/testing](https://github.com/clerk/javascript/tree/HEAD/packages/testing) | `2.2.10` | `2.2.13` | | [@dotenvx/dotenvx](https://github.com/dotenvx/dotenvx) | `2.14.0` | `2.17.4` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.0` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.64.0` | `8.65.0` | | [eslint](https://github.com/eslint/eslint) | `10.7.0` | `10.8.0` | | [eslint-plugin-vue](https://github.com/vuejs/eslint-plugin-vue) | `10.9.2` | `10.10.0` | | [fallow](https://github.com/fallow-rs/fallow) | `3.6.0` | `3.9.1` | | [happy-dom](https://github.com/capricorn86/happy-dom) | `20.11.0` | `20.11.1` | | [prettier](https://github.com/prettier/prettier) | `3.9.5` | `3.9.6` | Updates `@clerk/backend` from 3.11.7 to 3.13.1 - [Release notes](https://github.com/clerk/javascript/releases) - [Changelog](https://github.com/clerk/javascript/blob/main/packages/backend/CHANGELOG.md) - [Commits](https://github.com/clerk/javascript/commits/@clerk/backend@3.13.1/packages/backend) Updates `@clerk/nuxt` from 2.6.19 to 2.6.22 - [Release notes](https://github.com/clerk/javascript/releases) - [Changelog](https://github.com/clerk/javascript/blob/main/packages/nuxt/CHANGELOG.md) - [Commits](https://github.com/clerk/javascript/commits/@clerk/nuxt@2.6.22/packages/nuxt) Updates `@sentry/nuxt` from 10.66.0 to 10.68.0 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.68.0/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@10.66.0...10.68.0) Updates `@clerk/testing` from 2.2.10 to 2.2.13 - [Release notes](https://github.com/clerk/javascript/releases) - [Changelog](https://github.com/clerk/javascript/blob/main/packages/testing/CHANGELOG.md) - [Commits](https://github.com/clerk/javascript/commits/@clerk/testing@2.2.13/packages/testing) Updates `@dotenvx/dotenvx` from 2.14.0 to 2.17.4 - [Release notes](https://github.com/dotenvx/dotenvx/releases) - [Changelog](https://github.com/dotenvx/dotenvx/blob/main/CHANGELOG.md) - [Commits](dotenvx/dotenvx@v2.14.0...v2.17.4) Updates `@playwright/test` from 1.61.1 to 1.62.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.61.1...v1.62.0) Updates `@typescript-eslint/parser` from 8.64.0 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser) Updates `eslint` from 10.7.0 to 10.8.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.7.0...v10.8.0) Updates `eslint-plugin-vue` from 10.9.2 to 10.10.0 - [Release notes](https://github.com/vuejs/eslint-plugin-vue/releases) - [Changelog](https://github.com/vuejs/eslint-plugin-vue/blob/master/CHANGELOG.md) - [Commits](vuejs/eslint-plugin-vue@v10.9.2...v10.10.0) Updates `fallow` from 3.6.0 to 3.9.1 - [Release notes](https://github.com/fallow-rs/fallow/releases) - [Changelog](https://github.com/fallow-rs/fallow/blob/main/CHANGELOG.md) - [Commits](fallow-rs/fallow@v3.6.0...v3.9.1) Updates `happy-dom` from 20.11.0 to 20.11.1 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v20.11.0...v20.11.1) Updates `prettier` from 3.9.5 to 3.9.6 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.9.5...3.9.6) --- updated-dependencies: - dependency-name: "@clerk/backend" dependency-version: 3.13.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@clerk/nuxt" dependency-version: 2.6.22 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@sentry/nuxt" dependency-version: 10.68.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@clerk/testing" dependency-version: 2.2.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@dotenvx/dotenvx" dependency-version: 2.17.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@playwright/test" dependency-version: 1.62.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@typescript-eslint/parser" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: eslint dependency-version: 10.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: eslint-plugin-vue dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: fallow dependency-version: 3.9.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: happy-dom dependency-version: 20.11.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: prettier dependency-version: 3.9.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
✅ Deploy Preview for dh-markpost ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
The bumped @playwright/test now strictly resolves tsconfig "references" paths, including ./.nuxt/tsconfig.app.json, which is only generated by `nuxt prepare`. The e2e job (unlike the ci job's test:ci step) never ran that step, so Playwright failed at startup. Add a pree2e npm lifecycle script to generate it before playwright test runs. Also run npm audit fix (non-force) to pick up available transitive patches; no top-level dependency versions changed.
|
Fixed CI on this Dependabot bump:
Verified locally: Dependabot PR — code review step skipped per convention. |
|
| Checkout | Runs | Failures | Pass rate |
|---|---|---|---|
This branch (dependabot/npm_and_yarn/minor-and-patch-58879950bb) |
10 | 3 | 70% |
Unmodified main (same commit CI passed on, 2026-07-22) |
10 | 1 | 90% |
Every failure — on both checkouts — is byte-for-byte the same signature:
Error: expect(page).not.toHaveURL(expected) failed
Expected pattern: not /\/login/
Received string: "http://localhost:3002/login/client-trust"
Timeout: 12000ms
at e2e/login.spec.ts:96. main reproduced the identical failure on an unmodified checkout in the same environment — this is the flake, not a regression from the bump. The 70% vs 90% split is within noise for n=10 (not statistically significant); I'm not claiming the bump made it worse, only that it didn't introduce a new failure mode.
What I did NOT do (per the hard constraints)
No retry added, no timeout increase, no skip/quarantine, no weakened assertion, no revert of the Clerk bump.
Verification of everything else
npm run lint— cleannpm run lint:ci— clean (0 issues in changed files)npm test(vitest) — 918/918 passed, 75/75 filesnpm run build— succeeds- No new commits needed; working tree is clean relative to the pushed branch.
Recommendation
This flake pre-dates this PR and isn't blocking it — main shows the same behavior. Worth its own investigation/issue (Clerk's client-trust handshake timing under Playwright), but out of scope for a dependency-bump PR per the "don't paper over it" rule. Both Neon test branches used for verification were deleted after the run.
|
Investigated the two failing checks. Neither required code changes on this branch.
Ran
The PR branch has fewer vulnerabilities than current main, not more. The The apparent regression vs. main's last recorded CI run (2026-07-22: 9 vulns) is almost entirely newly-published advisories in the 3 days since, affecting main equally — not something this PR caused. In fact this bump fixed two: Leaving the audit failure as-is per instructions — not loosening the threshold, not force-fixing main's pre-existing advisories out of scope for this PR.
Verification locally: |
- postcss and sharp under next are dead weight: geist declares next as a peerDependency but is only used for static font files (see app/assets/css/main.css), so npm auto-installs the latest next release to satisfy the unmet peer. next@16.2.12 bundles postcss pinned to an exact 8.4.31 and sharp ^0.34.5, both vulnerable (GHSA-qx2v-qp2m-jg93, GHSA-6g55-p6wh-862q, GHSA-r28c-9q8g-f849, GHSA-f88m-g3jw-g9cj). No patched stable next release exists yet (fix only landed in 16.3.0 prereleases), so overriding the nested postcss/sharp versions under next specifically is the only fix available short of an unstable next upgrade neither Nuxt project needs. - brace-expansion <=5.0.7 (GHSA-mh99-v99m-4gvg) is pulled in via js-beautify (a @vue/test-utils dependency, still vulnerable at its latest 1.x release) and archiver-utils/readdir-glob (used by nitropack for build artifact zipping). Overridden globally to ^5.0.8 since it's a leaf glob-pattern utility with no breaking API changes across this bump. - esbuild <=0.24.2 (moderate, via drizzle-kit's @esbuild-kit loader) is left alone: the only fix requires downgrading drizzle-kit to 0.18.1, a breaking change, and the CI audit gate only fails on high/critical (npm audit --audit-level=high).
Agent update: fixed the failing
|
Bumps the minor-and-patch group with 12 updates:
3.11.73.13.12.6.192.6.2210.66.010.68.02.2.102.2.132.14.02.17.41.61.11.62.08.64.08.65.010.7.010.8.010.9.210.10.03.6.03.9.120.11.020.11.13.9.53.9.6Updates
@clerk/backendfrom 3.11.7 to 3.13.1Release notes
Sourced from @clerk/backend's releases.
Changelog
Sourced from @clerk/backend's changelog.
Commits
9081534ci(repo): Version packages (#9240)acef8a1ci(repo): Version packages (#9219)848eefefeat(backend): support configurable Frontend API proxy URLs (#9223)430ae23ci(repo): Version packages (#9195)858a689docs(repo): Add trailing comma after e.g. and i.e. in JSDoc (#9201)a009d91fix(backend): Align enterprise connection create and update params with the B...ff5d991fix(backend): Fix cross-origin handshake bypass (#9145)26530cefeat(backend): support organization-scoped sign-in tokens (#9192)Updates
@clerk/nuxtfrom 2.6.19 to 2.6.22Release notes
Sourced from @clerk/nuxt's releases.
Changelog
Sourced from @clerk/nuxt's changelog.
Commits
9081534ci(repo): Version packages (#9240)acef8a1ci(repo): Version packages (#9219)430ae23ci(repo): Version packages (#9195)Updates
@sentry/nuxtfrom 10.66.0 to 10.68.0Release notes
Sourced from @sentry/nuxt's releases.
... (truncated)
Changelog
Sourced from @sentry/nuxt's changelog.
... (truncated)
Commits
b4396c3release: 10.68.0be21e8cmeta(changelog): Update changelog for 10.68.0 (#22566)fb0987ffeat(v10): Addhttp.routeattribute tohttp.serverspans with parameteriz...f7bd901feat(v10/cloudflare): Auto-instrument WorkerEntrypoint classes (#22543)ed3a8c8feat(v10/cloudflare): Auto-instrument Workflow classes (#22542)20227f9feat(v10/cloudflare): Auto-instrument Durable Object classes (#22541)3e5625efeat(v10/cloudflare): Auto-instrument the worker entry with withSentry (#22540)d924551test(v10/cloudflare): Add Vite-build support to the integration-test runner (...11fed03feat(v10/cloudflare): Read wrangler config and resolve the Sentry options mod...a540764feat(v10): Addurl.fullandurl.pathtohttp.serverspans (#22533)Updates
@clerk/testingfrom 2.2.10 to 2.2.13Release notes
Sourced from @clerk/testing's releases.
Changelog
Sourced from @clerk/testing's changelog.
Commits
9081534ci(repo): Version packages (#9240)acef8a1ci(repo): Version packages (#9219)1c52591chore(repo): re-enable eslint for@clerk/ui(#9218)430ae23ci(repo): Version packages (#9195)Updates
@dotenvx/dotenvxfrom 2.14.0 to 2.17.4Release notes
Sourced from @dotenvx/dotenvx's releases.
Changelog
Sourced from @dotenvx/dotenvx's changelog.
... (truncated)
Commits
b64a4072.17.46140c89changelog675e03eMerge pull request #922 from dotenvx/curl-device96da103send along with curl requesta98d2e22.17.31ea90a0changelog4a6fd78Merge branch 'main' of github.com:dotenvx/dotenvx33c8d52update README2f05fefMerge pull request #920 from andyngdz/fix/precommit-nested-env-example-exemption6fd613dfix precommit exemption for .env.example/.env.x in subdirectoriesUpdates
@playwright/testfrom 1.61.1 to 1.62.0Release notes
Sourced from @playwright/test's releases.
... (truncated)
Commits
e3950d9chore: mark v1.62.0 (#41981)f07e0f7cherry-pick(#41940): docs: release notes for v1.62 (#41967)05a306ccherry-pick(#41964): Revert "feat(routeFromHar): add interceptAPIRequests opt...2934858fix: correct pending navigation log spacing (#41949)4b0cc99fix(test): unflake screencast backpressure test on slow macOS runner (#41951)bbbae6dtest: fixme WebSocket locale test in Chromium 150 (#41944)15c4f55fix(mcp): identify downloads explicitly (#41933)f5fa967fix(network): request.postData() returns null for empty string body override ...0edafe4fix(mcp): launch the Chrome profile that has the extension installed (#41939)244a1fffeat(firefox): roll to r1538 (#41938)Updates
@typescript-eslint/parserfrom 8.64.0 to 8.65.0Release notes
Sourced from @typescript-eslint/parser's releases.
Changelog
Sourced from @typescript-eslint/parser's changelog.
Commits
63ba81bchore(release): publish 8.65.0eaf4576feat: add warning when TS 7 is detected (#12529)d8f1044feat(parser): add onUnsupportedTypeScriptVersion option to error on unsupport...0d06406chore: add attw validation to repo (#12437)c2386e4chore(deps): update dependency prettier to v3.9.5 (#12486)Updates
eslintfrom 10.7.0 to 10.8.0Release notes
Sourced from eslint's releases.