Skip to content

chore(deps): bump the all group with 4 updates - #5

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/all-6440cd0a73
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/all-6440cd0a73

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown

Bumps the all group with 4 updates: @scure/base, @scure/btc-signer, ethers and zod.

Updates @scure/base from 2.0.0 to 2.4.0

Release notes

Sourced from @​scure/base's releases.

2.4.0

  • Added base36 coder (lowercase alphanumeric, multibase k payload as used by IPFS/IPNS addresses)
  • Limit base58 and base36 to 2048 bytes due to quadratic complexity. Real-world inputs are less than that.
  • bech32.decodeToBytes / bech32m.decodeToBytes now enforce the 90-char BIP-173 length limit by default (previously unbounded); pass limit: false or a number to override
  • bech32/bech32m: encode rejects non-printable-ASCII prefixes, and decode rejects non-printable-ASCII input instead of letting case folding normalize non-ASCII characters into valid strings
  • base32crockford.decode: non-ASCII input that only becomes valid via case folding is now rejected

Full Changelog: paulmillr/scure-base@2.3.0...2.4.0

2.3.0

  • Massive speed-up of all algorithms. 1 MB speed:
    • base64 encode: 18x, 22mb/s => 395 mb/s
    • base32 encode: 23x, 16mb/s => 367 mb/s
    • base16 encode: 20x, 15mb/s => 294 mb/s
    • bech32 toWords: 8x, 38mb/s => 296 mb/s
    • base58 decode: 8x, 8mb/s => 67.2 mb/s
  • -3.4% reduce of minified bundle size.
  • Reduce on-disk package size: 163kb → 136kb (-27.4kb), by disabling source maps (they became less relevant).
  • Better error messages and stricter type checks
  • Breaking: we've removed internal utils: utils, bytesToString / str, stringToBytes / bytes, and the SomeCoders type. Those were always internal. The coders (base16, base64, …) are unaffected.

Full Changelog: paulmillr/scure-base@2.2.0...2.3.0

2.2.0

  • April 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • Fix compilation issues on TypeScript v6
  • Improve tree-shaking, reduce bundle sizes
  • utf8: make decoder strict, use isWellFormed (polyfilled in some envs)
  • Add strict ascii decoder (char range 0..127)
  • Bech32 examples in the docs by @​davay42 in paulmillr/scure-base#44
  • Add overload to Bech32.decode to handle arbitrary string input by @​webmaster128 in paulmillr/scure-base#45
  • perf: trust Uint8Array.fromBase64 to check non-whitespace chars by @​ChALkeR in paulmillr/scure-base#47

New Contributors

(We're skipping v2.1, to align with other noble / scure packages)

Full Changelog: paulmillr/scure-base@2.0.0...2.2.0

Changelog

Sourced from @​scure/base's changelog.

2.4.0 (2026-08-28)

  • Added base36 coder (lowercase alphanumeric, multibase k payload as used by IPFS/IPNS addresses)
  • Limit base58 and base36 to 2048 bytes due to quadratic complexity. Real-world inputs are less than that.
  • bech32.decodeToBytes / bech32m.decodeToBytes now enforce the 90-char BIP-173 length limit by default (previously unbounded); pass limit: false or a number to override
  • bech32/bech32m: encode rejects non-printable-ASCII prefixes, and decode rejects non-printable-ASCII input instead of letting case folding normalize non-ASCII characters into valid strings
  • base32crockford.decode: non-ASCII input that only becomes valid via case folding is now rejected

2.3.0 (2026-08-08)

  • Massive speed-up of all algorithms. 1 MB speed:
    • base64 encode: 18x, 22mb/s => 395 mb/s
    • base32 encode: 23x, 16mb/s => 367 mb/s
    • base16 encode: 20x, 15mb/s => 294 mb/s
    • bech32 toWords: 8x, 38mb/s => 296 mb/s
    • base58 decode: 8x, 8mb/s => 67.2 mb/s
  • -3.4% reduce of minified bundle size.
  • Reduce on-disk package size: 163kb → 136kb (-27.4kb), by disabling source maps (they became less relevant).
  • Better error messages and stricter type checks
  • Breaking: we've removed internal utils: utils, bytesToString / str, stringToBytes / bytes, and the SomeCoders type. Those were always internal. The coders (base16, base64, …) are unaffected.

2.2.0 (2026-04-21)

  • April 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • Fix compilation issues on TypeScript v6
  • Improve tree-shaking, reduce bundle sizes
  • utf8: make decoder strict, use isWellFormed (polyfilled in some envs)
  • Add strict ascii decoder (char range 0..127)
  • Bech32 examples in the docs by @​davay42 in paulmillr/scure-base#44
  • Add overload to Bech32.decode to handle arbitrary string input by @​webmaster128 in paulmillr/scure-base#45
  • perf: trust Uint8Array.fromBase64 to check non-whitespace chars by @​ChALkeR in paulmillr/scure-base#47

New Contributors

(We're skipping v2.1, to align with other noble / scure packages)

Commits
  • d93da4f Release 2.4.0.
  • ce220f1 Upgrade devdeps. Add changelog.
  • 90de919 Harden: prohibit bech32/base_crockford non-printable; limit base58 to 4K
  • c92f2d4 Bump devdeps
  • 389e6bd Add base36 for ipfs; limit quadratic base encode length; add parity tests for...
  • 5b846f5 Release 2.3.0.
  • 27c9e1a Update jsbt
  • 5e98800 test: use new syntax
  • 655728b base58: limit decode to 64kb
  • ff17fbe Small fixes
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​scure/base since your current version.


Updates @scure/btc-signer from 2.0.1 to 2.4.1

Release notes

Sourced from @​scure/btc-signer's releases.

2.4.1

  • Upgrade micro-packed to 0.11.1

Full Changelog: paulmillr/scure-btc-signer@2.4.0...2.4.1

2.4.0

Tons of hardening. Special thanks to Red Team (Rob Hamilton, CalleBTC, Omer Talip) for reports.

Breaking changes

Breaking changes do not mean "locked funds", it's mostly "throws a new error".

  • Unknown and proprietary PSBT fields supplied directly to addInput/updateInput/addOutput/updateOutput now throw under the default strip policy instead of being silently dropped; pass unknown: 'ignore' (and/or proprietary: 'ignore') to preserve them
  • Transaction.combine compares transaction version and effective lockTime (instead of raw constructor options) and throws on conflicting global fields it previously overwrote
  • MuSig2 partialSigAgg with fewer signatures than participants now throws
  • Taproot SIGHASH_SINGLE preimage for a missing output index now throws instead of returning a digest
  • BIP370 locktime resolution now throws on inputs with incompatible height / time requirements (see below — the old behavior produced transactions which were not accepted by miners)

New features

  • New TxOpts.unknown and TxOpts.proprietary policies for unknown / proprietary PSBT fields (proprietary defaults to the unknown setting; Unknowns type is exported):
    • 'strict': throw when an unknown field is encountered during parsing
    • 'strip' (default): accept & remove while parsing; throw when one is added / updated by the user
    • 'ignore': pass fields through from decode to encode (the spec's default behavior)
    • Why strip by default: opaque fields are a fingerprinting and data-exfiltration channel — a protocol can mark users with hidden fields, and a compromised cold wallet can leak secrets through data nobody inspects. Stripping guarantees no opaque data remains; known fields can still carry information, so inspecting all fields is still on the user
    • allowUnknown is deprecated: true maps to 'ignore', false to 'strip'
  • Fields from recent BIPs are now decoded explicitly and survive round-trips instead of being treated as unknown: MuSig2 / BIP373 (musig2ParticipantPubkeys, musig2PubNonce, musig2PartialSig), silent payments / BIP375-376 (spEcdhShare, spDleq, spSpendBip32Derivation, spTweak, spV0Info, spV0Label), BIP322 (genericSignedMessage), BIP353 (dnssecProof) and pay-to-contract / BIP372 (p2cKeyTweak)
  • Full PSBTv2 (BIP370) txModifiable support:
    • Newly created PSBTv2 transactions set the field by default (inputs & outputs modifiable), and addInput / updateInput / addOutput / updateOutput enforce its bits, including the restrictions implied by existing signatures. Unknown txModifiable bits follow the unknown policy
    • Previously the field was never emitted, which hurt interoperability: to other libraries an absent field means "no inputs / outputs can be added"
    • New TxOpts.allowMissingTxModifiable (default true) still treats an absent field as modifiable, for PSBTs produced by older versions; set it to false for stricter validation when possible
    • Note: emitting the field changes the serialized output, so older library versions cannot convert newly produced PSBTv2 into PSBTv0
  • BIP370 locktime handling (breaking, but the old behavior produced transactions which were not accepted by miners):
    • requiredHeightLocktime / requiredTimeLocktime are range-validated and now survive input finalization — previously they were deleted on finalize, so the extracted transaction's lockTime almost never matched what was signed

... (truncated)

Changelog

Sourced from @​scure/btc-signer's changelog.

2.4.1 (2026-08-29)

  • Upgrade micro-packed to 0.11.1

2.4.0 (2026-08-28)

Tons of hardening. Special thanks to Red Team (Rob Hamilton, CalleBTC, Omer Talip) for reports.

Breaking changes

Breaking changes do not mean "locked funds", it's mostly "throws a new error".

  • Unknown and proprietary PSBT fields supplied directly to addInput/updateInput/addOutput/updateOutput now throw under the default strip policy instead of being silently dropped; pass unknown: 'ignore' (and/or proprietary: 'ignore') to preserve them
  • Transaction.combine compares transaction version and effective lockTime (instead of raw constructor options) and throws on conflicting global fields it previously overwrote
  • MuSig2 partialSigAgg with fewer signatures than participants now throws
  • Taproot SIGHASH_SINGLE preimage for a missing output index now throws instead of returning a digest
  • BIP370 locktime resolution now throws on inputs with incompatible height / time requirements (see below — the old behavior produced transactions which were not accepted by miners)

New features

  • New TxOpts.unknown and TxOpts.proprietary policies for unknown / proprietary PSBT fields (proprietary defaults to the unknown setting; Unknowns type is exported):
    • 'strict': throw when an unknown field is encountered during parsing
    • 'strip' (default): accept & remove while parsing; throw when one is added / updated by the user
    • 'ignore': pass fields through from decode to encode (the spec's default behavior)
    • Why strip by default: opaque fields are a fingerprinting and data-exfiltration channel — a protocol can mark users with hidden fields, and a compromised cold wallet can leak secrets through data nobody inspects. Stripping guarantees no opaque data remains; known fields can still carry information, so inspecting all fields is still on the user
    • allowUnknown is deprecated: true maps to 'ignore', false to 'strip'
  • Fields from recent BIPs are now decoded explicitly and survive round-trips instead of being treated as unknown: MuSig2 / BIP373 (musig2ParticipantPubkeys, musig2PubNonce, musig2PartialSig), silent payments / BIP375-376 (spEcdhShare, spDleq, spSpendBip32Derivation, spTweak, spV0Info, spV0Label), BIP322 (genericSignedMessage), BIP353 (dnssecProof) and pay-to-contract / BIP372 (p2cKeyTweak)
  • Full PSBTv2 (BIP370) txModifiable support:
    • Newly created PSBTv2 transactions set the field by default (inputs & outputs modifiable), and addInput / updateInput / addOutput / updateOutput enforce its bits, including the restrictions implied by existing signatures. Unknown txModifiable bits follow the unknown policy
    • Previously the field was never emitted, which hurt interoperability: to other libraries an absent field means "no inputs / outputs can be added"
    • New TxOpts.allowMissingTxModifiable (default true) still treats an absent field as modifiable, for PSBTs produced by older versions; set it to false for stricter validation when possible
    • Note: emitting the field changes the serialized output, so older library versions cannot convert newly produced PSBTv2 into PSBTv0
  • BIP370 locktime handling (breaking, but the old behavior produced transactions which were not accepted by miners):
    • requiredHeightLocktime / requiredTimeLocktime are range-validated and now survive input finalization — previously they were deleted on finalize, so the extracted transaction's lockTime almost never matched what was signed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​scure/btc-signer since your current version.


Updates ethers from 6.13.4 to 6.17.0

Release notes

Sourced from ethers's releases.

ethers/v6.17.0 (2026-06-18 00:49)

  • Add requestRate throttle to calls (b48bfe3).
  • Added provider requestRate throttle support (b74b6d3).
  • Disable AlchemyProvider which does not provide the necessary API capacity for tests (1523ca8).
  • Map ResolverNotFound error to null for reverse lookup (d07cfb6).
  • Use bigint for coinType instead of number values (4f6ec03).
  • Updated AlchemyProvider endpoints for BNB (9bec2f9).
  • Added basic ENSv2 tests and fixed issues with EVM cointypes (0e9a73d).
  • Adding ENSv2 integrations from adraffy (a2d0af4).
  • Update Blockscout deffault API key and links (5647ae3).
  • Added transactionsRoot to Block (#5077, #5078; 5bd2ce9).
  • Preserve 301/302 method and support 307/308 (#3106, #5115; 999af5f).
  • Fix maxFeePerGas property for EtherscanProvider transactions (#5080; ca45d23).
  • Added rich inspection for Network and Plugins (f2ffb86).
  • Tweaking API for Universal Resolver to be completely backward compatible (9a5c4b5).
  • Updated ENS Universal Resolver to latest API (0b3b12b).
  • Added CCIP to ENS Universal Resolver reverse resolution (982eef2).
  • Added reverse lookup for ENS UniversalResolver (9a9a11d).
  • Initial forward resolution using ENS UniversalResolver (51df7b9).

ethers/v6.16.0 (2025-12-02 19:47)

  • Added utility method to split EIP-7594 BLOb proofs into its cells (88dfe96).
  • Update Alchemy URL endpoint for mainnet (#5052; 719b01d).
  • Fail on unsupported Etherscan networks immediately to better support the default provider (94b333b).
  • Added Filecoin network and Ankr endpoints (#5038; 986e827).
  • Moved to better API for EIP-7594 PeerDAS (#5062; 452b422).
  • Added initial EIP-7594 PeerDAS support (#5054, #5062; 6d64889).
  • Support RegExp engines with string length limitations (#4967; f0dfbe1).
  • Added Transaction and Signature support for non-canonical S values (#4223, #5013; 855d727).
  • Allow zero-width big-endian data for toBeHex and allow widths fo toBeArray (#5025; 540f30c).

ethers/v6.15.0 (2025-07-01 11:24)

  • Allow non-canonical S values in Signatures moving errors to access-time (#5013; 9944ec9).

ethers/v6.14.4 (2025-06-12 23:16)

  • Fixed serialization of EIP-7702 transactions with leading 0-bytes (#4916; 389dc03).

ethers/v6.14.3 (2025-05-26 18:55)

  • Fixed non-normalized yParity on EIP-7702 JSON-RPC responses (#4985; a8803ca).

ethers/v6.14.2 (2025-05-26 18:31)

  • Fixed call stack overflow in makeError stringify for recursive structures (#4977, #4978; 52a0522).
  • Explicitly throw error on gunzip failure to prevent uncaught exception (#4873, #4874; fe98f98).
  • Skip additional receipt fetch for single confirmation requests (#4972; 243cb02).
  • Update EtherscanProvider to use their v2 API (#4975; 5e09aa1).

ethers/v6.14.1 (2025-05-15 14:17)

  • Fix JSON-RPC authorizationList signature entries encoded as DATA instead of QUANTITY values (#4916; 135db72).

ethers/v6.14.0 (2025-05-06 22:02)

... (truncated)

Changelog

Sourced from ethers's changelog.

ethers/v6.17.0 (2026-06-17 23:50)

  • Add requestRate throttle to calls (b48bfe3).
  • Added provider requestRate throttle support (b74b6d3).
  • Disable AlchemyProvider which does not provide the necessary API capacity for tests (1523ca8).
  • Map ResolverNotFound error to null for reverse lookup (d07cfb6).
  • Use bigint for coinType instead of number values (4f6ec03).
  • Updated AlchemyProvider endpoints for BNB (9bec2f9).
  • Added basic ENSv2 tests and fixed issues with EVM cointypes (0e9a73d).
  • Adding ENSv2 integrations from adraffy (a2d0af4).
  • Update Blockscout deffault API key and links (5647ae3).
  • Added transactionsRoot to Block (#5077, #5078; 5bd2ce9).
  • Preserve 301/302 method and support 307/308 (#3106, #5115; 999af5f).
  • Fix maxFeePerGas property for EtherscanProvider transactions (#5080; ca45d23).
  • Added rich inspection for Network and Plugins (f2ffb86).
  • Tweaking API for Universal Resolver to be completely backward compatible (9a5c4b5).
  • Updated ENS Universal Resolver to latest API (0b3b12b).
  • Added CCIP to ENS Universal Resolver reverse resolution (982eef2).
  • Added reverse lookup for ENS UniversalResolver (9a9a11d).
  • Initial forward resolution using ENS UniversalResolver (51df7b9).

ethers/v6.16.0 (2025-12-02 19:47)

  • Added utility method to split EIP-7594 BLOb proofs into its cells (88dfe96).
  • Update Alchemy URL endpoint for mainnet (#5052; 719b01d).
  • Fail on unsupported Etherscan networks immediately to better support the default provider (94b333b).
  • Added Filecoin network and Ankr endpoints (#5038; 986e827).
  • Moved to better API for EIP-7594 PeerDAS (#5062; 452b422).
  • Added initial EIP-7594 PeerDAS support (#5054, #5062; 6d64889).
  • Support RegExp engines with string length limitations (#4967; f0dfbe1).
  • Added Transaction and Signature support for non-canonical S values (#4223, #5013; 855d727).
  • Allow zero-width big-endian data for toBeHex and allow widths fo toBeArray (#5025; 540f30c).

ethers/v6.15.0 (2025-07-01 11:24)

  • Allow non-canonical S values in Signatures moving errors to access-time (#5013; 9944ec9).

ethers/v6.14.4 (2025-06-12 23:16)

  • Fixed serialization of EIP-7702 transactions with leading 0-bytes (#4916; 389dc03).

ethers/v6.14.3 (2025-05-26 18:55)

  • Fixed non-normalized yParity on EIP-7702 JSON-RPC responses (#4985; a8803ca).

... (truncated)

Commits
  • 3ea4c22 admin: updated dist files
  • 2d35b6a docs: fix property access order for Flatworm
  • b48bfe3 Add requestRate throttle to calls.
  • 39f5ce1 tests: add INFURA_APIKEY for docs and workflows
  • 96bd29c tests: added provider throttling to test suites
  • b74b6d3 Added provider requestRate throttle support.
  • 1523ca8 Disable AlchemyProvider which does not provide the necessary API capacity for...
  • d07cfb6 Map ResolverNotFound error to null for reverse lookup.
  • c32c542 docs: fix typo in config for INFURA API key
  • 7c6b840 admin: include INFURA_APIKEY in docs generation to resolve throttling
  • Additional commits viewable in compare view

Updates zod from 3.25.76 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for zod since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 4 updates: [@scure/base](https://github.com/paulmillr/scure-base), [@scure/btc-signer](https://github.com/paulmillr/scure-btc-signer), [ethers](https://github.com/ethers-io/ethers.js) and [zod](https://github.com/colinhacks/zod).


Updates `@scure/base` from 2.0.0 to 2.4.0
- [Release notes](https://github.com/paulmillr/scure-base/releases)
- [Changelog](https://github.com/paulmillr/scure-base/blob/main/CHANGELOG.md)
- [Commits](paulmillr/scure-base@2.0.0...2.4.0)

Updates `@scure/btc-signer` from 2.0.1 to 2.4.1
- [Release notes](https://github.com/paulmillr/scure-btc-signer/releases)
- [Changelog](https://github.com/paulmillr/scure-btc-signer/blob/main/CHANGELOG.md)
- [Commits](paulmillr/scure-btc-signer@2.0.1...2.4.1)

Updates `ethers` from 6.13.4 to 6.17.0
- [Release notes](https://github.com/ethers-io/ethers.js/releases)
- [Changelog](https://github.com/ethers-io/ethers.js/blob/main/CHANGELOG.md)
- [Commits](ethers-io/ethers.js@v6.13.4...v6.17.0)

Updates `zod` from 3.25.76 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v3.25.76...v4.6.5)

---
updated-dependencies:
- dependency-name: "@scure/base"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: "@scure/btc-signer"
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: ethers
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants