Skip to content

chore(deps): bump the bun-dependencies group across 1 directory with 26 updates - #54

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/bun-dependencies-82016e09f2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/bun-dependencies-82016e09f2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the bun-dependencies group with 26 updates in the / directory:

Package From To
@sentry/sveltekit 10.69.0 11.2.0
nodemailer 9.0.4 10.0.13
svelte-sonner 1.1.1 1.2.1
sveltekit-superforms 2.30.2 2.31.0
tailwind-merge 3.6.0 3.7.0
zod 4.4.3 4.6.5
@internationalized/date 3.12.3 3.12.4
@lucide/svelte 1.29.0 1.49.0
@playwright/test 1.62.1 1.63.0
@sveltejs/adapter-node 5.5.7 6.0.0
@sveltejs/kit 2.70.2 3.0.0
@sveltejs/vite-plugin-svelte 7.2.0 7.3.1
@types/node 26.1.2 26.6.3
@types/nodemailer 8.0.1 8.0.2
bits-ui 2.18.1 2.19.4
drizzle-kit 0.31.10 0.31.11
drizzle-orm 0.45.2 0.45.3
eslint 10.8.0 10.11.0
eslint-plugin-svelte 3.22.0 3.23.0
globals 17.9.0 17.13.0
layerchart 2.1.0 2.5.1
prettier 3.9.6 3.9.9
svelte 5.56.8 5.57.1
svelte-check 4.7.4 4.7.6
typescript-eslint 8.66.0 8.71.0
vite 8.2.1 8.3.2

Updates @sentry/sveltekit from 10.69.0 to 11.2.0

Release notes

Sourced from @​sentry/sveltekit's releases.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)
  • ci: shard Bun integration tests (#24771)

... (truncated)

Changelog

Sourced from @​sentry/sveltekit's changelog.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)

... (truncated)

Commits
  • e1a4316 release: 11.2.0
  • 95153b1 Merge pull request #24927 from getsentry/prepare-release/11.2.0
  • b8a90a4 meta(changelog): Update changelog for 11.2.0
  • a0faac6 fix(deps): runtime dependency security fixes (#24911)
  • b45e5b8 feat(deps): bump moment from 2.30.1 to 2.31.0 (#24890)
  • 5c82d5b feat(deps): bump hono from 4.13.5 to 4.13.7 (#24916)
  • 2651a8f test(sveltekit): Add missing prerender e2e test (#24921)
  • 8de2036 feat(deps): bump fastify from 5.12.1 to 5.12.5 (#24917)
  • 29fc37c feat(deps): bump axios from 1.18.0 to 1.20.0 (#24918)
  • 012e9bb fix(server-utils): Preserve raw OpenAI embeddings and conversation responses ...
  • Additional commits viewable in compare view

Updates nodemailer from 9.0.4 to 10.0.13

Release notes

Sourced from nodemailer's releases.

v10.0.13

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

v10.0.12

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

v10.0.11

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)

v10.0.10

10.0.10 (2026-09-14)

Bug Fixes

  • derive the attachment filename from the basename of a Windows path (c7cc7ce)
  • dkim: unfold folded header lines in linear time (28a5909)
  • smtp-connection: reassemble multiline replies in linear time (f2d82fa)

v10.0.9

10.0.9 (2026-09-12)

Bug Fixes

  • addressparser: bound the '@' probe to the run being scanned (1465c3f)
  • addressparser: keep the text after a comment out of a quoted local part address (2f36eb1)

v10.0.8

10.0.8 (2026-09-11)

... (truncated)

Changelog

Sourced from nodemailer's changelog.

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)

10.0.10 (2026-09-14)

Bug Fixes

  • derive the attachment filename from the basename of a Windows path (c7cc7ce)
  • dkim: unfold folded header lines in linear time (28a5909)
  • smtp-connection: reassemble multiline replies in linear time (f2d82fa)

10.0.9 (2026-09-12)

Bug Fixes

  • addressparser: bound the '@' probe to the run being scanned (1465c3f)
  • addressparser: keep the text after a comment out of a quoted local part address (2f36eb1)

10.0.8 (2026-09-11)

Bug Fixes

  • mime-node: clean the boundary where it is written, not only where it is built (e14278d)
  • mime-node: drop every control character from multipart boundary material (a82a355)

... (truncated)

Commits
  • 4641de8 chore(master): release 10.0.13 (#1879)
  • a502247 fix: strip comments inside an angle-addr before it becomes the address
  • b5a896f fix: read the advertised SASL methods without backtracking regexes
  • 4093fd4 chore(deps): update dependencies
  • 30e4cfd Merge pull request #1878 from nodemailer/release-please--branches--master--co...
  • 962f6ea chore(master): release 10.0.12
  • 57de6b6 chore(deps): update dependencies
  • 63ccd66 fix: settle every send on a connection error, back off pool requeues, turn a ...
  • 6a06914 chore(master): release 10.0.11 (#1877)
  • 5652a5a test(fetch): assert the error name of an unencodable form value, not its message
  • Additional commits viewable in compare view

Updates svelte-sonner from 1.1.1 to 1.2.1

Release notes

Sourced from svelte-sonner's releases.

v1.2.1

Patch Changes

  • f506748: fix: firefox mouseleave firing when mouse doesn't move

v1.2.0

Features

  • Multiple toasters. Give a toaster an id and target it with toast(..., { toasterId }). An id on <Toaster /> now identifies the toaster instead of landing on the <ol> element.
  • The gap prop is used in the toast offset math.
  • toastOptions.closeButton is now honored.

Fixes

  • Ported the bug-fix batch from emilkowalski/sonner#777. Custom icons no longer render twice in promise toasts, fast flicks can't dismiss in a direction not in swipeDirections, icons are hidden from assistive technology, content takes the full toast width, and toasts created before the <Toaster /> mounts are no longer lost.
  • Reusing the id of a dismissed toast creates a fresh toast instead of inheriting its old props, and a toast recreated right after dismissal is no longer killed by the pending removal or the old auto-close timer.
  • Styles moved from svelte-preprocess <style global> to a native Svelte 5 :global block, fixing crashes with the latest @sveltejs/vite-plugin-svelte and @tailwindcss/vite.
  • Fixed a setHeight crash (Cannot read properties of undefined) when many toasts were created and dismissed quickly, and a negative heightIndex briefly producing wrong offsets.
  • Fast flicks below the swipe distance threshold can now dismiss, height entries keep the right order when several toasts mount at once, and toast.custom() keeps an explicit id of 0.
Changelog

Sourced from svelte-sonner's changelog.

1.2.1

Patch Changes

  • f506748: fix: firefox mouseleave firing when mouse doesn't move

1.2.0

Minor Changes

  • 7312f33: feat: support multiple toasters via <Toaster id="..." /> and toast(..., { toasterId }) (matching upstream sonner semantics: a toaster without an id renders only toasts without a toasterId), use the gap prop in the toast offset math instead of a hardcoded value, and honor toastOptions.closeButton. Note: an id passed to <Toaster /> now identifies the toaster instead of landing on the <ol> element

Patch Changes

  • 7fbbc1c: fix: guard heightIndex against a not-found (-1) result

    Toast.svelte computed heightIndex as heights.findIndex(...) || 0. When a toast has no measured height entry yet, findIndex returns -1, and -1 || 0 evaluates to -1 (since -1 is truthy). That negative index then fed the offset calculation (heightIndex * GAP) and the reducerIndex >= heightIndex guard, producing incorrect stacking offsets in the brief window before a toast's height is measured. Replaced the || 0 fallback with an explicit === -1 ? 0 : idx check.

  • 32b4655: fix: prevent Cannot read properties of undefined (reading 'toastId') crash from setHeight

    setHeight looked up a toast's position in this.toasts (via #findToastIdx) and then used that integer to write into this.heights. The two arrays grow independently (toasts is unshifted, heights is pushed; remove() splices toasts but only removeHeight() filters heights), so the indices drift out of sync. When toastIdx >= heights.length, this.heights[toastIdx] = data created a sparse array with undefined holes, and a subsequent heights.findIndex((h) => h.toastId === ...) then dereferenced the hole and threw TypeError: Cannot read properties of undefined (reading 'toastId'), white-screening the host app.

    Fixed by searching heights directly by toastId (mirroring removeHeight) via a dedicated #findHeightIdx helper, so the index always refers to the correct array. The lookup is wrapped in untrack because setHeight runs inside a $effect; a tracked read of this.heights would re-trigger that effect on the following write and hit effect_update_depth_exceeded.

  • 7312f33: fix: replace the svelte-preprocess <style global> block with a native Svelte 5 :global block so the published component compiles with the latest @sveltejs/vite-plugin-svelte (fixes crashes with @tailwindcss/vite CSS extraction)

  • 6084611: fix: record the drag start time so a fast flick below the distance threshold can dismiss a toast, reset the auto-close timer when a dismissed toast id is recreated in the same tick, keep height entries in newest-first order when several toasts mount together, and fully reset gesture state when a toast is revived mid-exit

  • emilkowalski/sonner#777swipeDirections (which is now actually passed down from the Toaster), decorative icons are hidden from assistive technology, toast content takes the full toast width, toast.custom() keeps an explicit id of 0, toasts created before the <Toaster /> mounts are no longer lost, a new toast reusing the id of a dismissed toast no longer inherits its props, and a toast recreated right after being dismissed is no longer removed by the pending dismissal

Commits
  • 146b1f1 Merge pull request #207 from wobsoriano/changeset-release/main
  • e4f035d docs: add SvelteKit ssr.noExternal troubleshooting note (#166)
  • 676aac9 Version Packages
  • e480ec9 Merge pull request #165 from huntabyte/fix/149
  • 3aa8a07 Merge pull request #205 from wobsoriano/changeset-release/main
  • 1a8583a Version Packages
  • fbe8cca Merge pull request #206 from wobsoriano/sync-upstream-777
  • 6084611 fix: address review findings (drag velocity, same-tick recreate timer, batche...
  • 139de50 chore: clean up comments and test types
  • 3b3d2d7 test: add browser-level parity tests for sonner#777 fixes, split unit specs, ...
  • Additional commits viewable in compare view

Updates sveltekit-superforms from 2.30.2 to 2.31.0

Release notes

Sourced from sveltekit-superforms's releases.

v2.31.0

Added

  • actionResult can now take a transport option, to handle custom transports even in endpoints. #701
Changelog

Sourced from sveltekit-superforms's changelog.

[2.31.0] - 2026-09-30

Added

  • actionResult can now take a transport option, to handle custom transports even in endpoints.
Commits

Updates tailwind-merge from 3.6.0 to 3.7.0

Release notes

Sourced from tailwind-merge's releases.

tailwind-merge@3.7.0

New Features

  • Prepare some upcoming changes by @​dcastil in dcastil/tailwind-merge#713
    • Theme getters returned by fromTheme now expose the theme key they read as a themeKey property, so tooling can identify the referenced theme scale without calling the getter.
    • Release tags now include the package name, starting with tailwind-merge@3.7.0.

Bug Fixes

Documentation

Other

Full Changelog: v3.6.0...v3.7.0

Thanks to @​brandonmcconnell, @​manavm1990, @​langy, @​roboflow, @​syntaxfm, @​getsentry, @​codecov, a private sponsor, @​openclaw, @​sourcegraph, @​cesarvcanal, @​CasperKristiansson, @​jbisasky, @​frontendmasters and more via @​thnxdev for sponsoring tailwind-merge! ❤️

Commits
  • 511d68a tailwind-merge@3.7.0
  • 2461127 Release tooling: Pass the namespaced tag prefix and commit message to pnpm's ...
  • 9d41508 add changelog for tailwind-merge@3.7.0
  • c78a80f Configurator: Reuse runtime lookups during pruning
  • 49c317d Monorepo: Fix contributing link and include package coverage
  • 7b565ca Configurator: prune a generated config to a project's used classes (core step)
  • d83e013 Releases: auto-re-pin tag-pinned links on every version bump
  • b71fd41 Docs: pin every in-repo file link to a release tag instead of main
  • ee29441 Docs: point the ThemeObject JSDoc link at the packaged docs location
  • 9521b10 Releases: per-package pipeline with namespaced tags
  • Additional commits viewable in compare view

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates @internationalized/date from 3.12.3 to 3.12.4

Release notes

Sourced from @​internationalized/date's releases.

React Spectrum S2 v1.7.0

We are excited to announce the first preview of React Spectrum's AI components to help build AI-powered experiences! Developed in close partnership with Spectrum design, this first batch of components covers the core of a chat interface, along with documentation to help you get started.

Full Release Notes

React Spectrum S2 v1.6.0

This release introduces the new SideNav component for building app navigation sidebars, adds trigger="contextMenu" support to MenuTrigger, and lets TableView cells hold interactive content like TextFields.

Full Release Notes

React Spectrum S2 v1.5.0

This release adds support for full interaction with embedded text fields and other interactive elements in ListView and TreeView with the new keyboardNavigationBehavior prop. Menu exposes a dependencies prop for dynamic item collections, and CenterBaseline is now exported from Spectrum 2 to help make custom styles even easier.

Full Release Notes

React Spectrum S2 v1.4.0

This release brings long awaited drag and drop support to ListView, TableView, and TreeView! TableView now also supports highlight selection and a new TableFooter component. Form components such as ComboBox and TextField now allow custom prefixes, and the new LabeledValue can be used to display non-editable values. In addition, description and error messages can be configured for Checkbox, Radio, and Switch. Last but not least, Calendar now supports multiple date selection.

Full Release Notes

React Spectrum S2 v1.3.0

In this release we are excited to announce support for expandable rows in TableView, highlight selection in TreeView, and window scrolling in collection components! Window scrolling enables virtualized collections to automatically scroll with the rest of the page – no height needed. In addition, we've updated the set of available workflow icons, and reduced the number of dependencies installed when using S2 by over 90% – see the full release notes for details.

To help assist with migrations from S1 to S2, we've added a new end to end migration Agent skill that you can use with your agent of choice. Our existing S2 Agent skill has also been updated to greatly improve its ability to select the proper S2 component to use from context, so be sure to update.

Full release notes

React Spectrum S2 v1.2.0

In this release, we are excited to announce that ListView and unavailable menu items are now available! In addition, we have added ActionBar support for TreeView and custom renderer support for the Picker's display value. We also shipped multiple TableView fixes and a set of documentation improvements including a Typography search view now available in the main search menu.

Thanks to all of our contributors for the updates in this release.

Full release notes

React Spectrum S2 v1.1.0

It’s our first release of the new year and we’ve got plenty of exciting treats we’re bringing to the table. We’ve added a variety of new features to our documentation site including a new dark/light mode switch in the site header. Our search menu also now features a Colors section where you can browse the Spectrum-defined colors and search by name or hex value to find close or exact matches. We also now offer our docs in the form of Agent Skills that can be installed locally and used by your favorite AI coding tools.

This release also includes several bugs fixes, such as properly rendering menus when rendered from within a popover and updates to TreeView disabledBehavior styling to match the latest designs.

Full Release Notes

Commits

Updates @lucide/svelte from 1.29.0 to 1.49.0

Release notes

Sourced from @​lucide/svelte's releases.

Version 1.49.0

What's Changed

…26 updates

Bumps the bun-dependencies group with 26 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@sentry/sveltekit](https://github.com/getsentry/sentry-javascript) | `10.69.0` | `11.2.0` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `9.0.4` | `10.0.13` |
| [svelte-sonner](https://github.com/wobsoriano/svelte-sonner) | `1.1.1` | `1.2.1` |
| [sveltekit-superforms](https://github.com/ciscoheat/sveltekit-superforms) | `2.30.2` | `2.31.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |
| [@internationalized/date](https://github.com/adobe/react-spectrum) | `3.12.3` | `3.12.4` |
| [@lucide/svelte](https://github.com/lucide-icons/lucide/tree/HEAD/packages/svelte) | `1.29.0` | `1.49.0` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@sveltejs/adapter-node](https://github.com/sveltejs/kit/tree/HEAD/packages/adapter-node) | `5.5.7` | `6.0.0` |
| [@sveltejs/kit](https://github.com/sveltejs/kit/tree/HEAD/packages/kit) | `2.70.2` | `3.0.0` |
| [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) | `7.2.0` | `7.3.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.6.3` |
| [@types/nodemailer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/nodemailer) | `8.0.1` | `8.0.2` |
| [bits-ui](https://github.com/huntabyte/bits-ui) | `2.18.1` | `2.19.4` |
| [drizzle-kit](https://github.com/drizzle-team/drizzle-orm) | `0.31.10` | `0.31.11` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [eslint](https://github.com/eslint/eslint) | `10.8.0` | `10.11.0` |
| [eslint-plugin-svelte](https://github.com/sveltejs/eslint-plugin-svelte/tree/HEAD/packages/eslint-plugin-svelte) | `3.22.0` | `3.23.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.9.0` | `17.13.0` |
| [layerchart](https://github.com/techniq/layerchart) | `2.1.0` | `2.5.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte) | `5.56.8` | `5.57.1` |
| [svelte-check](https://github.com/sveltejs/language-tools) | `4.7.4` | `4.7.6` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.66.0` | `8.71.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.1` | `8.3.2` |



Updates `@sentry/sveltekit` from 10.69.0 to 11.2.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.69.0...11.2.0)

Updates `nodemailer` from 9.0.4 to 10.0.13
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v9.0.4...v10.0.13)

Updates `svelte-sonner` from 1.1.1 to 1.2.1
- [Release notes](https://github.com/wobsoriano/svelte-sonner/releases)
- [Changelog](https://github.com/wobsoriano/svelte-sonner/blob/main/CHANGELOG.md)
- [Commits](wobsoriano/svelte-sonner@v1.1.1...v1.2.1)

Updates `sveltekit-superforms` from 2.30.2 to 2.31.0
- [Release notes](https://github.com/ciscoheat/sveltekit-superforms/releases)
- [Changelog](https://github.com/ciscoheat/sveltekit-superforms/blob/v2.31.0/CHANGELOG.md)
- [Commits](ciscoheat/sveltekit-superforms@v2.30.2...v2.31.0)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

Updates `@internationalized/date` from 3.12.3 to 3.12.4
- [Release notes](https://github.com/adobe/react-spectrum/releases)
- [Commits](https://github.com/adobe/react-spectrum/compare/@internationalized/date@3.12.3...@internationalized/date@3.12.4)

Updates `@lucide/svelte` from 1.29.0 to 1.49.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.49.0/packages/svelte)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@sveltejs/adapter-node` from 5.5.7 to 6.0.0
- [Release notes](https://github.com/sveltejs/kit/releases)
- [Changelog](https://github.com/sveltejs/kit/blob/main/packages/adapter-node/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/kit/commits/@sveltejs/adapter-node@6.0.0/packages/adapter-node)

Updates `@sveltejs/kit` from 2.70.2 to 3.0.0
- [Release notes](https://github.com/sveltejs/kit/releases)
- [Changelog](https://github.com/sveltejs/kit/blob/main/packages/kit/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/kit/commits/@sveltejs/kit@3.0.0/packages/kit)

Updates `@sveltejs/vite-plugin-svelte` from 7.2.0 to 7.3.1
- [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases)
- [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.3.1/packages/vite-plugin-svelte)

Updates `@types/node` from 26.1.2 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/nodemailer` from 8.0.1 to 8.0.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/nodemailer)

Updates `bits-ui` from 2.18.1 to 2.19.4
- [Release notes](https://github.com/huntabyte/bits-ui/releases)
- [Commits](https://github.com/huntabyte/bits-ui/compare/bits-ui@2.18.1...bits-ui@2.19.4)

Updates `drizzle-kit` from 0.31.10 to 0.31.11
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](https://github.com/drizzle-team/drizzle-orm/compare/drizzle-kit@0.31.10...drizzle-kit@0.31.11)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `eslint` from 10.8.0 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.0...v10.11.0)

Updates `eslint-plugin-svelte` from 3.22.0 to 3.23.0
- [Release notes](https://github.com/sveltejs/eslint-plugin-svelte/releases)
- [Changelog](https://github.com/sveltejs/eslint-plugin-svelte/blob/main/packages/eslint-plugin-svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/eslint-plugin-svelte/commits/eslint-plugin-svelte@3.23.0/packages/eslint-plugin-svelte)

Updates `globals` from 17.9.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.9.0...v17.13.0)

Updates `layerchart` from 2.1.0 to 2.5.1
- [Release notes](https://github.com/techniq/layerchart/releases)
- [Commits](https://github.com/techniq/layerchart/compare/layerchart@2.1.0...layerchart@2.5.1)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `svelte` from 5.56.8 to 5.57.1
- [Release notes](https://github.com/sveltejs/svelte/releases)
- [Changelog](https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/svelte/commits/svelte@5.57.1/packages/svelte)

Updates `svelte-check` from 4.7.4 to 4.7.6
- [Release notes](https://github.com/sveltejs/language-tools/releases)
- [Commits](https://github.com/sveltejs/language-tools/compare/svelte-check@4.7.4...svelte-check@4.7.6)

Updates `typescript-eslint` from 8.66.0 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

Updates `vite` from 8.2.1 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

---
updated-dependencies:
- dependency-name: "@sentry/sveltekit"
  dependency-version: 11.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bun-dependencies
- dependency-name: nodemailer
  dependency-version: 10.0.13
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bun-dependencies
- dependency-name: svelte-sonner
  dependency-version: 1.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: sveltekit-superforms
  dependency-version: 2.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: "@internationalized/date"
  dependency-version: 3.12.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: "@lucide/svelte"
  dependency-version: 1.49.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: "@sveltejs/adapter-node"
  dependency-version: 6.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: bun-dependencies
- dependency-name: "@sveltejs/kit"
  dependency-version: 3.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: bun-dependencies
- dependency-name: "@sveltejs/vite-plugin-svelte"
  dependency-version: 7.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: "@types/nodemailer"
  dependency-version: 8.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: bits-ui
  dependency-version: 2.19.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: drizzle-kit
  dependency-version: 0.31.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: eslint-plugin-svelte
  dependency-version: 3.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: layerchart
  dependency-version: 2.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: svelte
  dependency-version: 5.57.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: svelte-check
  dependency-version: 4.7.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Dependency updates label Oct 4, 2026
@dependabot
dependabot Bot requested a review from SamsterZero as a code owner October 4, 2026 22:35
@dependabot dependabot Bot added the dependencies Dependency updates label Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants