Repository navigation
chore(deps): bump the all-dependencies group across 2 directories with 6 updates - #451
Merged
github-actions[bot] merged 1 commit intoOct 5, 2026
Conversation
…h 6 updates Bumps the all-dependencies group with 5 updates in the /packages/x402-facilitator-node directory: | Package | From | To | | --- | --- | --- | | [viem](https://github.com/wevm/viem) | `2.56.9` | `2.57.2` | | [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` | | [hono](https://github.com/honojs/hono) | `4.13.9` | `4.13.12` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.2` | `26.6.4` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.2` | `5.0.3` | Bumps the all-dependencies group with 1 update in the /script/gasless-tests directory: [dotenv](https://github.com/motdotla/dotenv). Updates `viem` from 2.56.9 to 2.57.2 - [Release notes](https://github.com/wevm/viem/releases) - [Commits](https://github.com/wevm/viem/compare/viem@2.56.9...viem@2.57.2) Updates `@hono/node-server` from 2.1.1 to 2.1.3 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v2.1.1...v2.1.3) Updates `hono` from 4.13.9 to 4.13.12 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.13.9...v4.13.12) Updates `@types/node` from 26.6.2 to 26.6.4 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `vitest` from 5.0.2 to 5.0.3 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest) Updates `dotenv` from 18.0.4 to 18.0.5 - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v18.0.4...v18.0.5) --- updated-dependencies: - dependency-name: viem dependency-version: 2.57.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: "@hono/node-server" dependency-version: 2.1.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-dependencies - dependency-name: hono dependency-version: 4.13.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-dependencies - dependency-name: "@types/node" dependency-version: 26.6.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all-dependencies - dependency-name: vitest dependency-version: 5.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all-dependencies - dependency-name: dotenv dependency-version: 18.0.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
clestons
approved these changes
Oct 5, 2026
clestons
left a comment
Collaborator
There was a problem hiding this comment.
结论:APPROVE
意图:dependabot 批量依赖 bump,涉及两个目录——packages/x402-facilitator-node(@hono/node-server/hono/viem/@types/node/vitest 共 5 个 patch 级小版本)、script/gasless-tests(dotenv 一个 patch 级小版本)。纯 package.json + pnpm-lock.yaml,零源码改动。
验证
逐个检查了 lockfile 里每个包的 resolution/integrity 哈希,确认都是全新的、和升级后版本号对应的合法哈希(没有注册源切换、没有可疑的 transitive 依赖变化)。viem 的 release notes(2.56.9→2.57.2)只是加了几个新链、新 token 定义和一个 nonce 准备的小修复,都是新增功能/修复,不是破坏性变更;其余几个都是 patch 版本号,风险更低。CI 全绿(Stage 1/1b/2/3、Slither、secret scan、test、x402-node 等全部 pass)。
🤖 pr-daemon · 2-round(纯版本bump,GATE全NO,无src/改动);R1a/R1b零finding;亲自核对lockfile每个包的integrity哈希+viem release notes确认无破坏性变更;CI全绿,APPROVE
github-actions
Bot
deleted the
dependabot/npm_and_yarn/packages/x402-facilitator-node/all-dependencies-a451b73b55
branch
October 5, 2026 19:22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all-dependencies group with 5 updates in the /packages/x402-facilitator-node directory:
2.56.92.57.22.1.12.1.34.13.94.13.1226.6.226.6.45.0.25.0.3Bumps the all-dependencies group with 1 update in the /script/gasless-tests directory: dotenv.
Updates
viemfrom 2.56.9 to 2.57.2Release notes
Sourced from viem's releases.
... (truncated)
Commits
b25495fchore: version package (#5159)c63902atest: cover retired zone portal selectors (#5167)f9f9d1bfeat(tempo): support from on token.burn (#5166)95624a2fix: repair dependency audit and tempo nonce fuzz check (#5164)cf45913docs(tokens): ousd (#5162)bc45023chore(chains): add CRYMAD Chain (1475) and CRYMAD Chain L2 (7373) (#5157)3f38e89fix(tempo): preserve explicit expiring nonces in preparation hook (#5156)c01de3fchore: rm changeset5b37051test(tempo): update fee token candidates for OUSD deployments (#5154)e55d336chore: version package (#5153)Updates
@hono/node-serverfrom 2.1.1 to 2.1.3Release notes
Sourced from @hono/node-server's releases.
Commits
720ac782.1.39821792Merge commit from fork35bca952.1.290a2600fix(listener): avoid mutating response headers when setting Content-Length (#...fe7467ctest(request): accept asynchronous body read errors (#403)64dc09edocs(readm): update the benchmark (#394)8f505aechore: add better benchmarks (#391)2469b1afix: type error in early hints and add typecheck to CI (#390)3f958daci: add autofix.ci (#392)Updates
honofrom 4.13.9 to 4.13.12Release notes
Sourced from hono's releases.
... (truncated)
Commits
6abd35b4.13.1295eb860chore(deps): upgrade vite-plus to 1.0.0 (#5464)afb2068fix(combine): return a Response from a short-circuiting middleware in some() ...e5bb206fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)c3053ccfix(etag): correctly match mixed-case header name in retainedHeader option (#...c437d75test(build): type-check the bundled declarations from a consumer project (#5486)be1f749fix(build): keep internal types private in bundled d.ts and avoid a self-refe...37ce0694.13.111e1207ctest(serve-static): fix the test (#5479)8b05c77Merge commit from forkUpdates
@types/nodefrom 26.6.2 to 26.6.4Commits
Updates
vitestfrom 5.0.2 to 5.0.3Release notes
Sourced from vitest's releases.
Commits
33cadeachore: release v5.0.3 (#11409)346d389fix(vm): don't reuse scripts across vite environments (#11395)f6c9a49fix(deps): pinwhy-is-node-runningto3.2.1to avoid users running into `...062c75dchore: fix standalone docs build, update exports maps (#11394)caf2887fix(vm): do not optimize deps from index.html (fix #11329) (#11360)50312ebfix(pool): preserve unique pool ids whengroupOrderis set (#11392)7c36748fix(browser): ignore page crash while cancelling (#11386)92ba7fcfix: scope cache key generators to projects (fix #11281) (#11301)38f9885fix(cache): revalidate imports of cached modules (#11381)b24585ffix: don't retry whentest.failsexpectedly failed (#11219)Updates
dotenvfrom 18.0.4 to 18.0.5Changelog
Sourced from dotenv's changelog.
Commits
05215e018.0.525bdd0achangelog2d640d2Merge pull request #1066 from AyanAta42/masterc84e2b4Merge pull request #1068 from matzehecht/fix-typescript570146aOptimize fast parser comment scanning4aa0665add typescript module declaration for dotenv/configf1380ecBound fast parser comment scans to the current linea626f72add linkb36a142video linksDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions