Skip to content
This repository was archived by the owner on May 28, 2026. It is now read-only.

chore(deps): bump the production-dependencies group across 1 directory with 2 updates - #177

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-e34316b48c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-e34316b48c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 2 updates in the / directory: @hey-api/client-fetch and uuid.

Updates @hey-api/client-fetch from 0.12.0 to 0.13.1

Commits
  • 7365e4a Merge pull request #2164 from hey-api/changeset-release/main
  • e8b6797 Version Packages
  • 1e1c40b Merge pull request #2167 from hey-api/fix/tanstack-query-name-builder
  • a46259e fix(tanstack-query): add name builder options for all generated artifacts
  • 67125d3 Merge pull request #2166 from hey-api/fix/zod-tuple
  • 594f3a6 fix(zod): support tuple types
  • 3d0aeb8 Merge pull request #2165 from hey-api/fix/client-path-param-date
  • f23f3ae fix(client): do not serialize path param name in url
  • 32a8d2c Merge pull request #2163 from hey-api/fix/zod-metadata
  • 9769998 fix(zod): add metadata option
  • Additional commits viewable in compare view

Updates uuid from 11.1.0 to 14.0.0

Release notes

Sourced from uuid's releases.

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

v12.0.1

12.0.1 (2026-04-29)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

Commits
  • 7c1ea08 chore(main): release 14.0.0 (#926)
  • 3d2c5b0 Merge commit from fork
  • f2c235f fix!: expect crypto to be global everywhere (requires node@20+) (#935)
  • 529ef08 chore: upgrade TypeScript and fixup types (#927)
  • 086fd79 chore: update dependencies (#933)
  • dc4ddb8 feat!: drop node@18 support (#934)
  • 0f1f9c9 chore: switch to Biome for parsing and linting (#932)
  • e2879e6 chore: use maintained version of npm-run-all (#930)
  • ffa3138 fix: Use GITHUB_TOKEN for release-please and enable npm provenance (#925)
  • 0423d49 docs: remove obsolete v1 option notes (#915)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 27, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner May 27, 2026 18:48
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 27, 2026
…y with 2 updates

Bumps the production-dependencies group with 2 updates in the / directory: [@hey-api/client-fetch](https://github.com/hey-api/openapi-ts) and [uuid](https://github.com/uuidjs/uuid).


Updates `@hey-api/client-fetch` from 0.12.0 to 0.13.1
- [Release notes](https://github.com/hey-api/openapi-ts/releases)
- [Changelog](https://github.com/hey-api/openapi-ts/blob/main/CHANGELOG.md)
- [Commits](https://github.com/hey-api/openapi-ts/compare/@hey-api/client-fetch@0.12.0...@hey-api/client-fetch@0.13.1)

Updates `uuid` from 11.1.0 to 14.0.0
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v11.1.0...v14.0.0)

---
updated-dependencies:
- dependency-name: "@hey-api/client-fetch"
  dependency-version: 0.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: uuid
  dependency-version: 14.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the production-dependencies group with 2 updates chore(deps): bump the production-dependencies group across 1 directory with 2 updates May 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-e34316b48c branch from 5d3602c to 1415a69 Compare May 27, 2026 19:56
@Almaju

Almaju commented May 28, 2026

Copy link
Copy Markdown
Contributor

Closing — same content as #157 which was closed yesterday.

  • uuid 11 → 14: GHSA-w5hq-g745-h8pq only affects v3()/v5()/v6(). This repo only uses v4() (single import in packages/core/src/store.ts), so the vulnerable code path is not reachable.
  • @hey-api/client-fetch 0.12 → 0.13: non-security bump, can wait.

To stop this PR being recreated weekly, we should add ignore for uuid major bumps in .github/dependabot.yml.

@Almaju Almaju closed this May 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 28, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-e34316b48c branch May 28, 2026 21:10
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant