Skip to content

deps: bump the npm-minor-patch group across 1 directory with 9 updates - #57

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-a03c54f40e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-a03c54f40e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Bumps the npm-minor-patch group with 9 updates in the / directory:

Package From To
@biomejs/biome 2.4.12 2.5.14
ipaddr.js 2.3.0 2.5.0
tsx 4.22.4 4.23.15
yaml 2.8.3 2.9.1
@modelcontextprotocol/sdk 1.29.0 1.30.1
supertest 7.2.2 7.3.0
@types/supertest 6.0.3 7.2.1
fastmcp 4.0.1 4.20.17
hono 4.12.32 4.13.9

Updates @biomejs/biome from 2.4.12 to 2.5.14

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.14

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #11790 17d0ff0 Thanks @​ematipico! - Fixed #10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

... (truncated)

Commits

Updates ipaddr.js from 2.3.0 to 2.5.0

Changelog

Sourced from ipaddr.js's changelog.

2.5.0 - 2026-08-04

  • remove ipaddr.min.js, end users must provide own minification/bundling
  • fix: compress the leftmost zero run in toString (RFC 5952, 4.2.3)
  • fix: strict IPv6 validation — reject :: with zero compression and hextets >4 hex digits
  • fix: reject non-numeric prefix length in subnetMaskFromPrefixLength
  • fix: compress trailing zero run in toString when a zoneIndex is present
  • fix: throw a descriptive error for malformed input in IPv6.parse

2.4.0 - 2026-05-03

  • remove Bower support
  • add RFC9637, RFC9602, RFC8215, RFC3879 reserved address ranges
Commits

Updates tsx from 4.22.4 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

v4.23.13

4.23.13 (2026-08-30)

Bug Fixes

  • cache: bound shared transform cache memory (#835) (28e1f12)

This release is also available on:

v4.23.12

4.23.12 (2026-08-10)

Bug Fixes

  • shim import.meta when tokens are split by comments or newlines (#829) (ed9d330), closes #828

This release is also available on:

... (truncated)

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • 28e1f12 fix(cache): bound shared transform cache memory (#835)
  • Additional commits viewable in compare view

Updates yaml from 2.8.3 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)

v2.9.0

The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".

It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.

Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.

  • fix: Avoid calling Array.prototype.push.apply() with large source array
  • fix(lexer): Avoid recursive calls that may exhaust the call stack

v2.8.4

  • Disable alias resolution with maxAliasCount:0 (#677)
  • Handle invalid unicode escapes (e1a1a77)
  • Apply minFractionDigits only to decimal strings (#676)
Commits
  • 1440ecd 2.9.1
  • c699bc5 fix: Simplify line unfolding during quoted string parsing (#714)
  • d11ce77 fix: Limit recursive merge aliases (#713)
  • c5f49f4 chore: Update docs-slate
  • ddb21b0 2.9.0
  • 167365b docs: Clarify that not all errors can be avoided
  • 6eca2a7 fix: Avoid calling Array.prototype.push.apply() with large source array
  • 0543cd5 fix(lexer): Avoid recursive calls that may exhaust the call stack
  • ccdf743 2.8.4
  • f625789 fix: Disable alias resolution with maxAliasCount:0 (#677)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/sdk from 1.29.0 to 1.30.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

1.30.0

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • 2d889f2 chore: bump version to 1.30.0 (#2563)
  • e3f3daa Fix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x)...
  • bb5a718 fix(deps): widen @​hono/node-server past GHSA-frvp-7c67-39w9 (#2549)
  • 1dad263 fix: send SSE keep-alive comment frames from Streamable HTTP server transport...
  • 69749aa Validate Content-Type by parsed media type instead of substring match (v1.x) ...
  • 369513d fix: support Zod 3.25 method literals (#2368)
  • e7ee57c v1 stdio buffer limit (#2239)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​modelcontextprotocol/sdk since your current version.


Updates supertest from 7.2.2 to 7.3.0

Release notes

Sourced from supertest's releases.

v7.3.0

  • fix: stabilize ephemeral server requests and assertions 71dc5fb
  • Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd8535d99 3b5ba5c
  • Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2.3.2 c3419b2
  • Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1 7e409db
  • Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expansion-1.1.21 b55a7f9
  • Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslist-4.29.0 7a5deaa
  • Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8 a75f6ee
  • Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2 c2cb33e
  • Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind 7fb34e7
  • chore(deps-dev): bump js-yaml from 3.14.2 to 3.15.2 c357584
  • chore(deps-dev): bump browserslist from 4.25.1 to 4.29.0 2a01b57
  • chore(deps-dev): bump fast-uri from 3.0.6 to 3.1.8 343394d
  • chore(deps-dev): bump brace-expansion from 1.1.12 to 1.1.21 6b203e9
  • Merge pull request #881 from forwardemail/dependabot/npm_and_yarn/qs-6.14.2 d40ca7e
  • fix: match ephemeral server address family b6f5995
  • chore(deps-dev): bump lodash from 4.17.21 to 4.18.1 81766ca
  • chore(deps-dev): bump picomatch from 2.3.1 to 2.3.2 985ac7c
  • chore(deps): bump minimatch 58baa5f
  • chore(deps): bump qs from 6.14.1 to 6.14.2 c406e82

forwardemail/supertest@v7.2.2...v7.3.0

Commits
  • a3f5cb8 7.3.0
  • 71dc5fb fix: stabilize ephemeral server requests and assertions
  • 3b5ba5c Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd85...
  • c3419b2 Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2...
  • 7e409db Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1
  • b55a7f9 Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expan...
  • 7a5deaa Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslis...
  • a75f6ee Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8
  • c2cb33e Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2
  • 7fb34e7 Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind
  • Additional commits viewable in compare view

Updates @types/supertest from 6.0.3 to 7.2.1

Commits

Updates fastmcp from 4.0.1 to 4.20.17

Release notes

Sourced from fastmcp's releases.

v4.20.17

4.20.17 (2026-09-24)

Bug Fixes

  • answer -32602 when a prompt is requested without a required argument (#390) (25046a2)
  • cli: stop splicing the file path into the validate commands (#388) (c130336)
  • keep canAccess tools visible to sessions without auth after a runtime change (#389) (91b6d8b)
  • openapi: preserve schema types when nullable is false (#387) (89a7516)

v4.20.16

4.20.16 (2026-09-21)

Bug Fixes

  • deps: upgrade @​apidevtools/swagger-parser to v13 (#379) (0bd0d71)

v4.20.15

4.20.15 (2026-09-21)

Bug Fixes

  • accept a tools/call that omits params.arguments (#383) (e7e4520)
  • catch failed log notifications instead of crashing the server (#382) (c15e194)
  • openapi: preserve JSON dictionary bodies with empty properties (#381) (d9edf6c)

v4.20.14

4.20.14 (2026-09-15)

Bug Fixes

  • openapi: honor path and operation servers (#378) (548c5b6)

v4.20.13

4.20.13 (2026-09-13)

Bug Fixes

  • openapi: resolve path item ref chains that carry sibling fields (#376) (18a34fa)

v4.20.12

4.20.12 (2026-09-13)

Bug Fixes

... (truncated)

Commits
  • 25046a2 fix: answer -32602 when a prompt is requested without a required argument (#390)
  • 91b6d8b fix: keep canAccess tools visible to sessions without auth after a runtime ch...
  • c130336 fix(cli): stop splicing the file path into the validate commands (#388)
  • 89a7516 fix(openapi): preserve schema types when nullable is false (#387)
  • 9222c0d chore(openapi): re-pin stripe benchmark spec hash (#391)
  • 7937672 chore: restore libc metadata dropped from the lockfile
  • 0bd0d71 fix(deps): upgrade @​apidevtools/swagger-parser to v13 (#379)
  • d9edf6c fix(openapi): preserve JSON dictionary bodies with empty properties (#381)
  • 86ec5a0 chore: stop tracking .claude/settings.local.json (#384)
  • e7e4520 fix: accept a tools/call that omits params.arguments (#383)
  • Additional commits viewable in compare view

Updates hono from 4.12.32 to 4.13.9

Release notes

Sourced from hono's releases.

v4.13.9

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in honojs/hono#5380
  • fix(accepts): match media types and language tags case-insensitively in honojs/hono#5376
  • fix(linear-router): don't match an empty path segment as a param in honojs/hono#5373
  • fix(pretty-json): don't break responses with unparseable JSON bodies in honojs/hono#5377
  • fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url in honojs/hono#5379
  • fix(aws-lambda): treat binary +xml archive media types as binary in honojs/hono#5424
  • fix(aws-lambda): preserve empty query parameters in honojs/hono#5292
  • fix(lambda-edge): sync content type detection with aws-lambda in honojs/hono#5426
  • fix(lambda-edge): fail with a descriptive error on a malformed event in honojs/hono#5358

Full Changelog: honojs/hono@v4.13.8...v4.13.9

v4.13.8

What's Changed

Full Changelog: honojs/hono@v4.13.7...v4.13.8

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

... (truncated)

Commits
  • 7c3b0df 4.13.9
  • 6cadf75 fix(lambda-edge): fail with a descriptive error on a malformed event (#5358)
  • de310ac fix(lambda-edge): sync content type detection with aws-lambda (#5426)
  • 28e8572 fix(aws-lambda): preserve empty query parameters (#5292)
  • 0d86899 fix(aws-lambda): treat binary +xml archive media types as binary (#5424)
  • 52febbc fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url (#5...
  • f950277 fix(pretty-json): don't break responses with unparseable JSON bodies (#5377)
  • 00ee875 fix(linear-router): don't match an empty path segment as a param (#5373)
  • f5a5346 fix(accepts): match media types and language tags case-insensitively (#5376)
  • cb5bea3 fix(jsx): replace Suspense and ErrorBoundary content across newlines (#5380)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-minor-patch group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.4.12` | `2.5.14` |
| [ipaddr.js](https://github.com/whitequark/ipaddr.js) | `2.3.0` | `2.5.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.15` |
| [yaml](https://github.com/eemeli/yaml) | `2.8.3` | `2.9.1` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.1` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |
| [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest) | `6.0.3` | `7.2.1` |
| [fastmcp](https://github.com/punkpeye/fastmcp) | `4.0.1` | `4.20.17` |
| [hono](https://github.com/honojs/hono) | `4.12.32` | `4.13.9` |



Updates `@biomejs/biome` from 2.4.12 to 2.5.14
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome)

Updates `ipaddr.js` from 2.3.0 to 2.5.0
- [Changelog](https://github.com/whitequark/ipaddr.js/blob/main/Changes.md)
- [Commits](https://github.com/whitequark/ipaddr.js/commits)

Updates `tsx` from 4.22.4 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.22.4...v4.23.15)

Updates `yaml` from 2.8.3 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.3...v2.9.1)

Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.30.1)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

Updates `@types/supertest` from 6.0.3 to 7.2.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest)

Updates `fastmcp` from 4.0.1 to 4.20.17
- [Release notes](https://github.com/punkpeye/fastmcp/releases)
- [Commits](punkpeye/fastmcp@v4.0.1...v4.20.17)

Updates `hono` from 4.12.32 to 4.13.9
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.32...v4.13.9)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.14
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: ipaddr.js
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/supertest"
  dependency-version: 7.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-minor-patch
- dependency-name: fastmcp
  dependency-version: 4.20.17
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: hono
  dependency-version: 4.13.9
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency typescript Related to the TypeScript packages or toolchain labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 28, 2026 12:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency typescript Related to the TypeScript packages or toolchain labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency typescript Related to the TypeScript packages or toolchain

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants