Skip to content

chore(deps): bump the production-minor-patch group with 4 updates - #150

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-minor-patch-9ce96e3f95
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-minor-patch-9ce96e3f95

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-minor-patch group with 4 updates: @supabase/supabase-js, @tanstack/react-query, react-hook-form and react-router-dom.

Updates @supabase/supabase-js from 2.112.4 to 2.117.2

Release notes

Sourced from @​supabase/supabase-js's releases.

v2.117.2

2.117.2 (2026-09-25)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.2-canary.0

2.117.2-canary.0 (2026-09-24)

🩹 Fixes

  • postgrest: avoid instantiation depth errors for large relationship unions (#2701)

❤️ Thank You

v2.117.1

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.1-canary.0

2.117.1-canary.0 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

v2.117.0

2.117.0 (2026-09-22)

🚀 Features

  • auth: forward options.mediation to navigator.credentials.get in signInWithPasskey (#2675)

... (truncated)

Changelog

Sourced from @​supabase/supabase-js's changelog.

2.117.2 (2026-09-25)

This was a version bump only for @​supabase/supabase-js to align it with other projects, there were no code changes.

2.117.1 (2026-09-23)

🩹 Fixes

  • auth: return stored session when a refresh loses to another tab (#2698)

❤️ Thank You

2.117.0 (2026-09-22)

🚀 Features

  • auth: enable passkey API by default and deprecate experimental passkey opt-in (#2695)

❤️ Thank You

  • fadymak

2.116.0 (2026-09-07)

🚀 Features

  • auth: add MFA recovery codes API (#2676)

🩹 Fixes

  • supabase: warn when schema is passed outside db options (#2663)

❤️ Thank You

2.115.0 (2026-09-03)

🚀 Features

  • postgrest: add getOpenApiSpec() (#2651)

❤️ Thank You

2.114.0 (2026-09-02)

... (truncated)

Commits
  • 54c225d chore(release): version 2.117.1 changelogs (#2700)
  • 739b351 fix(auth): return stored session when a refresh loses to another tab (#2698)
  • f34d428 chore(release): version 2.117.0 changelogs (#2697)
  • cc45ccf feat(auth): enable passkey API by default and deprecate experimental passkey ...
  • c511286 docs(realtime): document relationship of accessToken() and heartbeat (#2680)
  • 84af33f chore(release): version 2.116.0 changelogs (#2679)
  • 5aedaab feat(auth): add MFA recovery codes API (#2676)
  • e4f675a fix(supabase): warn when schema is passed outside db options (#2663)
  • dbe7679 chore(release): version 2.115.0 changelogs (#2664)
  • 3eb6193 docs(supabase): clarify db.schema needs the second generic (#2662)
  • Additional commits viewable in compare view

Updates @tanstack/react-query from 5.102.8 to 5.104.0

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-devtools@​5.104.0
    • @​tanstack/react-query@​5.104.0

@​tanstack/react-query-next-experimental@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/react-query@​5.104.0

@​tanstack/react-query-persist-client@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/react-query@​5.104.0
    • @​tanstack/query-persist-client-core@​5.104.0

@​tanstack/react-query@​5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-core@​5.104.0

@​tanstack/react-query-devtools@​5.103.3

Patch Changes

@​tanstack/react-query-next-experimental@​5.103.3

... (truncated)

Changelog

Sourced from @​tanstack/react-query's changelog.

5.104.0

Minor Changes

Patch Changes

  • Updated dependencies [5279b05]:
    • @​tanstack/query-core@​5.104.0

5.103.3

Patch Changes

  • #11647 1c9693e - fix(codemods): avoid copying unnecessary files from codemods project
  • Updated dependencies []:
    • @​tanstack/query-core@​5.103.3

5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2

5.103.1

Patch Changes

5.103.0

Patch Changes

Commits
  • d4033eb ci: Version Packages (#11651)
  • 5279b05 chore(deps): update Vite from v6 to v8 (#11650)
  • fe053bf ci: Version Packages (#11612)
  • 1c9693e fix(codemods): update codemods build script (#11647)
  • f00aad6 chore(deps): update dev dependencies (#11640)
  • 2443290 test(*): rename 'console.error' spies to 'consoleErrorMock' (#11646)
  • fcab29f test({query-core,react-query,preact-query}): restore the previous 'isServer' ...
  • e8dacbe docs({react-query,preact-query,solid-query,svelte-query}/README): point the C...
  • 57f40eb chore(deps): update non-major dependencies (#11625)
  • 397ad07 test({query-core,react-query,preact-query,solid-query}): pass 'unhandledRejec...
  • Additional commits viewable in compare view

Updates react-hook-form from 7.86.0 to 7.89.0

Release notes

Sourced from react-hook-form's releases.

Version 7.89.0

🐞 Fixes

  • Fix form state select option (#13784)
  • Remove duplicate default value field (#13783)
  • Fix validateField skipping refs without setCustomValidity under native validation (#13782)
  • Fix form-level validation using a stale validate function (#13777)
  • Fix useFieldArray touched fields handling (#13776)
  • Fix pending delayError timers for nested paths (#13775)
  • Fix getValues extracting unmarked field array entries (#13773)
  • Fix field array touched state not being re-indexed when unsubscribed (#13772)
  • Fix nested delayError timers remaining when a parent validates clean (#13771)
  • Fix nested delayError timers remaining after resetField() resets a parent (#13769)
  • Fix stale field array root errors after an operation satisfies the validation rule (#13767)
  • Fix setValue() not revalidating dependencies when shouldValidate is enabled (#13765)
  • Fix stale built-in validation results after reset() during handleSubmit() (#13761)
  • Fix stale form-level validation results after reset() (#13762)
  • Fix validation rules removed from register options at runtime remaining active (#13758)
  • Fix useController required validation not using the controlled value (#13756)
  • Fix stale form-level errors remaining after successful re-validation (#13755)
  • Fix useFieldArray marking the form dirty when the array default value is null (#13750)
  • Fix isValid not being recomputed when the errors prop is emptied (#13748)
  • Fix form-level validation running more than once per traversal (#13747)
  • Fix stale built-in validation results after reset() during onChange (#13745)
  • Fix stale resolver results after reset() during onChange (#13744)
  • Fix setValue() not triggering field array root validation when shouldValidate is enabled (#13743)
  • Fix getFieldState(name, formState) updates after reset() (#13741)
  • Fix dirty state remaining for rows removed from a field array (#13739)

🧹 Refactors

  • Replace rimraf cleanup with fs.rmSync (#13770)
  • Reduce bundle size (#13759)

📦 Dependencies

  • Add optional @types/react peer dependency (#13781)

❤️ Thank You

Version 7.88.0

✨ Features

  • Add Error Message component (#13472)
  • Add the Error Message component for displaying validation errors from React Hook Form.

🐞 Fixes

... (truncated)

Changelog

Sourced from react-hook-form's changelog.

[7.89.0] - 2026-09-26

Changed

  • Add optional @types/react peer dependency

Fixed

  • validateField calling setCustomValidity on refs that don't implement it under native validation
  • Form-level validate running a stale function instead of the latest one
  • Form-level validation leaving stale errors after a successful re-validation
  • Form-level validation running more than once per traversal
  • Stale validation results (resolver, built-in, form-level validate) being applied after reset in onChange and handleSubmit
  • Pending delayError timers for nested paths not being cancelled when a parent validates clean or is reset via resetField
  • getValues(names, { dirtyFields }) returning every row of a field array instead of only the marked entries
  • Field array touched state not being re-indexed when touchedFields is not subscribed
  • useFieldArray emitting touchedFields in form state updates when unnecessary
  • Stale field array root error not clearing once an array operation satisfies the rule
  • useFieldArray marking the form dirty when the array default is null
  • Dirty state lingering for rows removed from a field array
  • setValue with shouldValidate not revalidating deps
  • setValue with shouldValidate not triggering validation for a field array root
  • Validation rules removed from register options at runtime still being applied
  • useController validating required against the input value instead of the controlled value
  • isValid not recomputing when the errors prop is emptied
  • getFieldState(name, formState) with a resolver after reset()

[7.88.0] - 2026-09-12

Added

  • <ErrorMessage /> component for rendering a field's validation error

Fixed

  • setValue dirty state comparison ignoring valueAs* / setValueAs transforms
  • Nested delayError timers not being cancelled when a parent is cleared or unregistered
  • Cleared delayError errors coming back once the pending timer fires
  • criteriaMode not refreshing when form options are updated at runtime
  • resetField leaving stale validating state for the field
  • reset not clearing isValidating and validatingFields, and ignoring keepIsValidating
  • replace() leaving errors and touched state for removed rows
  • remove() leaking deleted values onto surviving items
  • handleSubmit applying a stale resolver result after reset
  • handleSubmit dropping resolver-reported root errors on submit
  • Stale resolver state updates being applied after reset
  • trigger dropping registered nested errors when targeting their parent
  • trigger setting a parent error when the target has only nested resolver errors
  • useWatch compute cache not being initialized with the initial output
  • flatten / jsonToFormData not preserving FileList and not skipping undefined

... (truncated)

Commits
  • 4722d22 7.89.0
  • 72a4c98 👟 chore: correct form state select option (#13784)
  • 14c7bec 🕵🏻‍♂️ chore: remove duplicate default value field (#13783)
  • d9cab62 🤖 chore: add optional @​types/react peer dependency (#13781)
  • c12546c 🐞 fix(validateField): skip refs without setCustomValidity under native valida...
  • 5fd9ef6 🐞 fix(validate): run the latest form level validate function (#13777)
  • 7893230 🐞 fix(useFieldArray): improve touched fields handling and add tests (#13776)
  • ad8abf6 🐴 cancel pending delayError timers for nested paths (#13775)
  • eb159da 🐞 fix(getValues): extract only the marked entries of a field array (#13773)
  • 4647014 🐞 fix: re-index field array touched state when it is not subscribed (#13772)
  • Additional commits viewable in compare view

Updates react-router-dom from 7.18.3 to 7.18.4

Changelog

Sourced from react-router-dom's changelog.

v7.18.4

Patch Changes

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-minor-patch group with 4 updates: [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js), [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query), [react-hook-form](https://github.com/react-hook-form/react-hook-form) and [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom).


Updates `@supabase/supabase-js` from 2.112.4 to 2.117.2
- [Release notes](https://github.com/supabase/supabase-js/releases)
- [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md)
- [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js)

Updates `@tanstack/react-query` from 5.102.8 to 5.104.0
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.104.0/packages/react-query)

Updates `react-hook-form` from 7.86.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.86.0...v7.89.0)

Updates `react-router-dom` from 7.18.3 to 7.18.4
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom)

---
updated-dependencies:
- dependency-name: "@supabase/supabase-js"
  dependency-version: 2.117.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: react-router-dom
  dependency-version: 7.18.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@strix-security

strix-security Bot commented Oct 1, 2026

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

So far, Strix has reviewed 14 pull requests across this workspace.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 87509a7a-36f5-489b-8a00-968bfeef9341

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch was successfully deployed

1 active deployment
Preview — 5fd6b259 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants