Bump the "weekly-dependencies" group with 5 updates across multiple ecosystems - #227
dependabot[bot] wants to merge 1 commit into
Conversation
…th 3 updates Bumps the weekly-dependencies group with 3 updates in the /conformance directory: [mppx](https://github.com/wevm/mppx), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [tsx](https://github.com/privatenumber/tsx). Updates `mppx` from 0.8.18 to 0.9.2 - [Release notes](https://github.com/wevm/mppx/releases) - [Changelog](https://github.com/wevm/mppx/blob/main/CHANGELOG.md) - [Commits](https://github.com/wevm/mppx/compare/mppx@0.8.18...mppx@0.9.2) Updates `@types/node` from 26.2.0 to 26.4.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `tsx` from 4.23.12 to 4.23.13 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.12...v4.23.13) chore(deps): bump mpp Bumps the weekly-dependencies group with 1 update in the /conformance/adapters/rust directory: [mpp](https://github.com/tempoxyz/mpp-rs). Updates `mpp` from 0.11.0 to 0.12.0 - [Release notes](https://github.com/tempoxyz/mpp-rs/releases) - [Changelog](https://github.com/tempoxyz/mpp-rs/blob/main/CHANGELOG.md) - [Commits](tempoxyz/mpp-rs@v0.11.0...v0.12.0) chore(deps): bump pympp[tempo] Bumps the weekly-dependencies group with 1 update in the /conformance/adapters/python directory: [pympp[tempo]](https://github.com/tempoxyz/pympp). Updates `pympp[tempo]` from 0.10.1 to 0.11.0 - [Release notes](https://github.com/tempoxyz/pympp/releases) - [Changelog](https://github.com/tempoxyz/pympp/blob/main/CHANGELOG.md) - [Commits](tempoxyz/pympp@v0.10.1...v0.11.0) chore(deps): bump the weekly-dependencies group across 1 directory with 2 updates Bumps the weekly-dependencies group with 2 updates in the /conformance/adapters/ruby directory: [mpp-rb](https://github.com/stripe/mpp-rb) and [sorbet-runtime](https://github.com/sorbet/sorbet). Updates `mpp-rb` from 0.1.4 to 0.1.6 - [Commits](stripe/mpp-rb@v0.1.4...v0.1.6) Updates `sorbet-runtime` from 0.6.13433 to 0.6.13480 - [Release notes](https://github.com/sorbet/sorbet/releases) - [Commits](https://github.com/sorbet/sorbet/commits) chore(deps): bump com.stripe:mpp-java Bumps the weekly-dependencies group with 1 update in the /conformance/adapters/java directory: [com.stripe:mpp-java](https://github.com/stripe/mpp-java). Updates `com.stripe:mpp-java` from 0.1.3 to 0.1.4 - [Commits](stripe/mpp-java@v0.1.3...v0.1.4) --- updated-dependencies: - dependency-name: mppx dependency-version: 0.9.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: weekly-dependencies - dependency-name: "@types/node" dependency-version: 26.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: weekly-dependencies - dependency-name: tsx dependency-version: 4.23.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: weekly-dependencies - dependency-name: mpp dependency-version: 0.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: weekly-dependencies - dependency-name: pympp[tempo] dependency-version: 0.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: weekly-dependencies - dependency-name: mpp-rb dependency-version: 0.1.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: weekly-dependencies - dependency-name: sorbet-runtime dependency-version: 0.6.13480 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: weekly-dependencies - dependency-name: com.stripe:mpp-java dependency-version: 0.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: weekly-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the weekly-dependencies group with 3 updates in the /conformance directory: mppx, @types/node and tsx.
Updates
mppxfrom 0.8.18 to 0.9.2Release notes
Sourced from mppx's releases.
Changelog
Sourced from mppx's changelog.
Commits
91a7dbechore: version packages (#853)1e3a3cfchore(deps): bump changesets/action in the github-actions group (#854)b12e65bfix: preserve multi-rail challenges in framework adapters (#857)14e8b25feat(cli): support x402 payment challenges (#850)9dd9969feat(stripe): add opt-in hosted Tempo fee payer (#842)5cbc5e4Additional Payment Intent Options (#858)f13f800feat(stripe): mark machine payment intents (#851)31fdbe3chore: version packages (#847)c74d2cefeat: add request-scoped payment intent options (#849)2735c65fix: align MCP payment error codes with spec (#846)Updates
@types/nodefrom 26.2.0 to 26.4.1Commits
Updates
tsxfrom 4.23.12 to 4.23.13Release notes
Sourced from tsx's releases.
Commits
28e1f12fix(cache): bound shared transform cache memory (#835)Bumps the weekly-dependencies group with 1 update in the /conformance/adapters/rust directory: mpp.
Updates
mppfrom 0.11.0 to 0.12.0Release notes
Sourced from mpp's releases.
... (truncated)
Changelog
Sourced from mpp's changelog.
Commits
965692achore: releasev0.12.0(#320)3c75742fix: restrict payment receipts to successful responses (#399)217578fci: open the release PR via github-sts (#398)d441d53ci(dependabot): approve and merge updates via github-sts (#397)fadc88cfix: Credential retries ignore the final same-origin response URL (#396)50a0845test: use bootstrapped Tempo localnet (#395)175bea7fix: support additional tempo signatures (#391)85c62c5chore(deps): bump tempo-alloy to 1.11.0 (#393)1162fc9feat(tempo): support async server signers (#389)bf3dfcbfeat: add split charge validation and Tempo relay (#373)Bumps the weekly-dependencies group with 1 update in the /conformance/adapters/python directory: pympp[tempo].
Updates
pympp[tempo]from 0.10.1 to 0.11.0Release notes
Sourced from pympp[tempo]'s releases.
Changelog
Sourced from pympp[tempo]'s changelog.
Commits
e514a95chore: releasev0.11.0(#217)41a6491feat(tempo): support MACH charges (#237)baf6d98fix: canonicalize challenge-bound JSON (#235)c473c06fix: Challenge selection ignores the offered intent (#212)c86294afix(server): reject timezone-naive expires instead of raising (#234)f0152b7feat(server): add payment method hooks (#231)05b0e1ffix: validate configured currency during challenge matching (#232)17117b3feat: add requires_auth so Payment credentials use Payment-Authorization (#230)8bb447cfix: Automatic payment retry limit is fixed (#223)95cdd3dfix: Initial requests do not advertise supported payment methods (#225)Bumps the weekly-dependencies group with 2 updates in the /conformance/adapters/ruby directory: mpp-rb and sorbet-runtime.
Updates
mpp-rbfrom 0.1.4 to 0.1.6Commits
33d1466Merge pull request #69 from stripe/release/v0.1.6bd8bb70Bump version to 0.1.6f906d96Merge pull request #68 from stripe/fix/tempo-replay-store-default5b6ee63fix(tempo): keep the raw-hash claim while rebasing to the chain hash4433b0ffix(tempo): rebase pull-flow reservations onto the chain hash9f1f7b5test(tempo): cover default credential replay through server.charge24cf77cfix(tempo): enable replay protection by default72cf0ddMerge pull request #65 from bensandler-stripe/bensandler/machine-payment-meta...0a573eefeat(stripe): mark machine payment intents7ee89c6Merge pull request #64 from stripe/feat/requires-auth-headerUpdates
sorbet-runtimefrom 0.6.13433 to 0.6.13480Release notes
Sourced from sorbet-runtime's releases.
... (truncated)
Commits
Bumps the weekly-dependencies group with 1 update in the /conformance/adapters/java directory: com.stripe:mpp-java.
Updates
com.stripe:mpp-javafrom 0.1.3 to 0.1.4Commits
ca57f09Merge pull request #29 from stripe/raubrey/release-0.1.47613b4achore: release 0.1.4ff7f369Merge pull request #27 from stripe/fix/tempo-bind-hash-to-payer90dc890fix(tempo): bind hash credentials to the paying challenge2fe0a4bMerge pull request #24 from stripe/ksn/tempo-replay-protection92e9a14refactor(tempo): rename replay claim API to tryClaim32e93c0refactor: make replay store chain-neutralbb6cd82refactor(tempo): keep replay store change parity-focused5d6c681refactor(tempo): narrow replay store contract6753123fix(tempo): prevent transaction hash replayDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions