Skip to content

chore(deps)(deps): bump the production-dependencies group across 1 directory with 11 updates - #488

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/apps/api/production-dependencies-8d37be2a5a
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/apps/api/production-dependencies-8d37be2a5a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the production-dependencies group with 11 updates in the /apps/api directory:

Package From To
@anthropic-ai/sdk 0.123.0 0.131.0
@sentry/bun 10.73.0 11.2.0
bullmq 5.81.4 5.81.5
dotenv 17.4.2 18.0.5
drizzle-orm 0.45.2 0.45.3
fs-extra 11.4.0 11.4.1
nodemailer 10.0.9 10.0.13
openai 7.10.0 7.27.0
pg 8.23.0 8.23.1
resend 6.26.0 6.32.0
stripe 22.6.1 22.6.2

Updates @anthropic-ai/sdk from 0.123.0 to 0.131.0

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.131.0

0.131.0 (2026-09-30)

Full Changelog: sdk-v0.130.0...sdk-v0.131.0

Features

  • api: add list spend limits endpoint (cfb78c8)

Chores

  • client: deprecate sonnet 4.5 (d72cfaf)

sdk: v0.130.0

0.130.0 (2026-09-30)

Full Changelog: sdk-v0.129.0...sdk-v0.130.0

Features

  • api: add a refusal stop reason and stop_details to Managed Agents session idle events (5cd6910)
  • api: add Claude Enterprise analytics, spend limits, and RBAC groups and roles to the Admin API (109c766)
  • api: add per-user usage and cost reports to the Admin API analytics (0a74a28)
  • api: add Plugins and Plugin Marketplaces to the Admin API (40c2160)
  • api: add repository error types to Managed Agents session errors (6735615)
  • api: allow removing a plugin's org-wide installation setting (c7d120f)
  • api: MCP tunnels beta: add read-only transport object to Tunnel and return the one-time relay token in the create response (b0e57ce)
  • api: Organization API endpoints are now GA (1a1fd8f)

Bug Fixes

  • api: make memory store description, metadata, archived_at required (ed68900)
  • api: type admin plugin preference and marketplace fields as enums (942ae01)
  • pagination: auto-paging continues past an empty page while next_page is set (2d75266)
  • tool-runner: only send API fields for runnable tools (#404) (a62c2a2)
  • tools: stop the session tool runner after any idle that ends the turn (#878) (cab32f8)

Chores

  • api: update MCP Tunnels types and descriptions (394d60c)
  • docs: remove placeholder enum descriptions (04f0812)
  • tests: fixture update (#381) (9cfe4d4)

sdk: v0.129.0

0.129.0 (2026-09-28)

Full Changelog: sdk-v0.128.0...sdk-v0.129.0

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.131.0 (2026-09-30)

Full Changelog: sdk-v0.130.0...sdk-v0.131.0

Features

  • api: add list spend limits endpoint (cfb78c8)

Chores

  • client: deprecate sonnet 4.5 (d72cfaf)

0.130.0 (2026-09-30)

Full Changelog: sdk-v0.129.0...sdk-v0.130.0

Features

  • api: add a refusal stop reason and stop_details to Managed Agents session idle events (5cd6910)
  • api: add Claude Enterprise analytics, spend limits, and RBAC groups and roles to the Admin API (109c766)
  • api: add per-user usage and cost reports to the Admin API analytics (0a74a28)
  • api: add Plugins and Plugin Marketplaces to the Admin API (40c2160)
  • api: add repository error types to Managed Agents session errors (6735615)
  • api: allow removing a plugin's org-wide installation setting (c7d120f)
  • api: MCP tunnels beta: add read-only transport object to Tunnel and return the one-time relay token in the create response (b0e57ce)
  • api: Organization API endpoints are now GA (1a1fd8f)

Bug Fixes

  • api: make memory store description, metadata, archived_at required (ed68900)
  • api: type admin plugin preference and marketplace fields as enums (942ae01)
  • pagination: auto-paging continues past an empty page while next_page is set (2d75266)
  • tool-runner: only send API fields for runnable tools (#404) (a62c2a2)
  • tools: stop the session tool runner after any idle that ends the turn (#878) (cab32f8)

Chores

  • api: update MCP Tunnels types and descriptions (394d60c)
  • docs: remove placeholder enum descriptions (04f0812)
  • tests: fixture update (#381) (9cfe4d4)

0.129.0 (2026-09-28)

Full Changelog: sdk-v0.128.0...sdk-v0.129.0

Features

... (truncated)

Commits
  • d49bdab Merge pull request #1230 from anthropics/release-please--branches--main--chan...
  • 4759f20 chore: release main
  • 9ded9f3 codegen metadata
  • d72cfaf chore(client): deprecate sonnet 4.5
  • cfb78c8 feat(api): add list spend limits endpoint
  • e8f4c28 Merge branch 'main' into next
  • e6ca605 Merge pull request #1229 from anthropics/release-please--branches--main--chan...
  • 2dd6192 chore: release main
  • cab32f8 fix(tools): stop the session tool runner after any idle that ends the turn (#...
  • 0a74a28 feat(api): add per-user usage and cost reports to the Admin API analytics
  • Additional commits viewable in compare view

Updates @sentry/bun from 10.73.0 to 11.2.0

Release notes

Sourced from @​sentry/bun's releases.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)
  • ci: shard Bun integration tests (#24771)

... (truncated)

Changelog

Sourced from @​sentry/bun's changelog.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)

... (truncated)

Commits
  • e1a4316 release: 11.2.0
  • 95153b1 Merge pull request #24927 from getsentry/prepare-release/11.2.0
  • b8a90a4 meta(changelog): Update changelog for 11.2.0
  • a0faac6 fix(deps): runtime dependency security fixes (#24911)
  • b45e5b8 feat(deps): bump moment from 2.30.1 to 2.31.0 (#24890)
  • 5c82d5b feat(deps): bump hono from 4.13.5 to 4.13.7 (#24916)
  • 2651a8f test(sveltekit): Add missing prerender e2e test (#24921)
  • 8de2036 feat(deps): bump fastify from 5.12.1 to 5.12.5 (#24917)
  • 29fc37c feat(deps): bump axios from 1.18.0 to 1.20.0 (#24918)
  • 012e9bb fix(server-utils): Preserve raw OpenAI embeddings and conversation responses ...
  • Additional commits viewable in compare view

Updates bullmq from 5.81.4 to 5.81.5

Release notes

Sourced from bullmq's releases.

v5.81.5

5.81.5 (2026-09-10)

Bug Fixes

  • worker: backport blocking client recovery to v5.x (#4722) (9767238)
Commits

Updates dotenv from 17.4.2 to 18.0.5

Changelog

Sourced from dotenv's changelog.

18.0.5 (2026-09-30)

Changed

  • Fix missing typescript module declaration (#1068)
  • Improve performance for large .env files (#1066)

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)

18.0.0 (2026-09-17)

Added

  • NEW: Dotenv now has a CLI. (#1022)
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
  • NEW: Dotenv now has a fast parser thanks to @​homanp of superagent.sh. Pass config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)
$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv
</tr></table> 

... (truncated)

Commits

Updates drizzle-orm from 0.45.2 to 0.45.3

Release notes

Sourced from drizzle-orm's releases.

0.45.3

New Netlify DB Driver

Note: The Netlify DB driver is developed and maintained by the Netlify team.

Installation:

npm i @netlify/db

Usage example:

import { drizzle } from 'drizzle-orm/netlify-db';
// reads NETLIFY_DB_URL and NETLIFY_DB_DRIVER env vars
const db = drizzle();
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';
const db = drizzle(process.env.DATABASE_URL);
const result = await db.execute('select 1');

import { drizzle } from 'drizzle-orm/netlify-db';

// Explicit client — consumer controls the driver
const db = drizzle({ client: netlifyDbClient });

const result = await db.execute('select 1');
Commits
  • 15454db +
  • 54e436f exclude gel from pull
  • 0fd1cc6 remove gel
  • d028db7 skip gel
  • 93dc01e [All-kit]: Warn when journal timestamps can cause migrations to be skipped (#...
  • b786252 Merge pull request #6049 from drizzle-team/drizzle-kit-announcements
  • f9fc5bf Add drizzle-kit announcement manifest and schema doc
  • 9d64532 Merge pull request #6004 from drizzle-team/pin-npm-11-main
  • 0af2f2e Pin the release npm self-update to major 11: the npm 12.0.0 tarball is missin...
  • 6968638 Merge pull request #6001 from drizzle-team/release-router-dispatch-inputs
  • Additional commits viewable in compare view

Updates fs-extra from 11.4.0 to 11.4.1

Changelog

Sourced from fs-extra's changelog.

11.4.1 / 2026-09-22

  • Properly handle read errors (e.g. due to permissions) in emptyDir*() (#1080)
  • Allow renaming with only Unicode normalization difference in the filename (APFS-specific) (#859, #1079)
Commits

Updates nodemailer from 10.0.9 to 10.0.13

Release notes

Sourced from nodemailer's releases.

v10.0.13

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

v10.0.12

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

v10.0.11

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)

v10.0.10

10.0.10 (2026-09-14)

Bug Fixes

  • derive the attachment filename from the basename of a Windows path (c7cc7ce)
  • dkim: unfold folded header lines in linear time (28a5909)
  • smtp-connection: reassemble multiline replies in linear time (f2d82fa)
Changelog

Sourced from nodemailer's changelog.

10.0.13 (2026-09-30)

Bug Fixes

  • read the advertised SASL methods without backtracking regexes (b5a896f)
  • strip comments inside an angle-addr before it becomes the address (a502247)

10.0.12 (2026-09-28)

Bug Fixes

  • settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS (63ccd66)

10.0.11 (2026-09-27)

Bug Fixes

  • fetch: report a form body that can not be encoded through the returned stream (74d40bf)
  • keep the CommonJS entry point and the services subpath compatible with the pre-TypeScript build (52901ef)
  • qp: keep wrap() terminating for short line lengths and a trailing incomplete escape (8fa140b)
  • smtp-connection: fail a password login cleanly when the server offers only XOAUTH2 (90abf7d)
  • types: restore the layout of @​types/nodemailer in the bundled declarations (ac2e40f)

10.0.10 (2026-09-14)

Bug Fixes

  • derive the attachment filename from the basename of a Windows path (c7cc7ce)
  • dkim: unfold folded header lines in linear time (28a5909)
  • smtp-connection: reassemble multiline replies in linear time (f2d82fa)
Commits
  • 4641de8 chore(master): release 10.0.13 (#1879)
  • a502247 fix: strip comments inside an angle-addr before it becomes the address
  • b5a896f fix: read the advertised SASL methods without backtracking regexes
  • 4093fd4 chore(deps): update dependencies
  • 30e4cfd Merge pull request #1878 from nodemailer/release-please--branches--master--co...
  • 962f6ea chore(master): release 10.0.12
  • 57de6b6 chore(deps): update dependencies
  • 63ccd66 fix: settle every send on a connection error, back off pool requeues, turn a ...
  • 6a06914 chore(master): release 10.0.11 (#1877)
  • 5652a5a test(fetch): assert the error name of an unencodable form value, not its message
  • Additional commits viewable in compare view

Updates openai from 7.10.0 to 7.27.0

Release notes

Sourced from openai's releases.

v7.27.0

7.27.0 (2026-10-01)

Features

  • agents: prepare hosted files and download result artifacts (#2855) (7b5a9e0)

v7.26.0

7.26.0 (2026-10-01)

Features

  • collect final output from beta Agents streams (#2850) (71d2412)
  • agents: [1/n] parse typed output from agent streams (#2853) (95b197b)
  • api: Add agent session trace listing (#2845) (c6dd4c7)
  • beta: bind typed application functions to Agents tools (#2852) (6198ba0)

Bug Fixes

  • api: allow original image detail in Chat Completions (#2851) (a3c1af5)
  • api: correct the eval run cancellation endpoint (#2847) (2f77415)
  • deps-dev: bump @​swc/core from 1.16.1 to 1.16.2 (#2827) (ff26e64)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/browser-direct-import (#2823) (53f8877)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/ts-browser-webpack (#2830) (2ac0cf2)
  • deps-dev: bump webpack from 5.110.3 to 5.111.1 in /ecosystem-tests/ts-browser-webpack (#2828) (89de47a)
  • deps-dev: bump wrangler from 4.131.1 to 4.135.0 in /ecosystem-tests/cloudflare-worker (#2824) (8c2e159)
  • deps-dev: update Vercel CLI to remove legacy proxy dependencies (#2835) (94395e8)
  • deps-dev: upgrade Vitest and migrate performance benchmarks (#2831) (a1421b1)
  • deps: bump @​azure/identity from 4.13.2 to 4.13.3 (#2825) (bfa2dec)
  • deps: bump dotenv from 17.4.2 to 18.0.1 (#2822) (6d0a62c)
  • deps: bump zod from 4.5.4 to 4.6.5 (#2829) (d2e9a06)
  • responses: refresh credentials on WebSocket reconnects (#2856) (0afb3da)
  • responses: reserve lane IDs across WebSocket session replacements (#2842) (8b5e176)

Chores

  • api: retain WebRTC Live session transport types (#2846) (9798c93)

v7.25.0

7.25.0 (2026-09-29)

Features

... (truncated)

Changelog

Sourced from openai's changelog.

7.27.0 (2026-10-01)

Features

  • agents: prepare hosted files and download result artifacts (#2855) (7b5a9e0)

7.26.0 (2026-10-01)

Features

  • collect final output from beta Agents streams (#2850) (71d2412)
  • agents: [1/n] parse typed output from agent streams (#2853) (95b197b)
  • api: Add agent session trace listing (#2845) (c6dd4c7)
  • beta: bind typed application functions to Agents tools (#2852) (6198ba0)

Bug Fixes

  • api: allow original image detail in Chat Completions (#2851) (a3c1af5)
  • api: correct the eval run cancellation endpoint (#2847) (2f77415)
  • deps-dev: bump @​swc/core from 1.16.1 to 1.16.2 (#2827) (ff26e64)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/browser-direct-import (#2823) (53f8877)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/ts-browser-webpack (#2830) (2ac0cf2)
  • deps-dev: bump webpack from 5.110.3 to 5.111.1 in /ecosystem-tests/ts-browser-webpack (#2828) (89de47a)
  • deps-dev: bump wrangler from 4.131.1 to 4.135.0 in /ecosystem-tests/cloudflare-worker (#2824) (8c2e159)
  • deps-dev: update Vercel CLI to remove legacy proxy dependencies (#2835) (94395e8)
  • deps-dev: upgrade Vitest and migrate performance benchmarks (#2831) (a1421b1)
  • deps: bump @​azure/identity from 4.13.2 to 4.13.3 (#2825) (bfa2dec)
  • deps: bump dotenv from 17.4.2 to 18.0.1 (#2822) (6d0a62c)
  • deps: bump zod from 4.5.4 to 4.6.5 (#2829) (d2e9a06)
  • responses: refresh credentials on WebSocket reconnects (#2856) (0afb3da)
  • responses: reserve lane IDs across WebSocket session replacements (#2842) (8b5e176)

Chores

  • api: retain WebRTC Live session transport types (#2846) (9798c93)

7.25.0 (2026-09-29)

Features

7.24.0 (2026-09-29)

... (truncated)

Commits
  • e39bd99 release: 7.27.0 (#2857)
  • 7b5a9e0 feat(agents): prepare hosted files and download result artifacts (#2855)
  • a06c456 release: 7.26.0 (#2844)
  • 0afb3da fix(responses): refresh credentials on WebSocket reconnects (#2856)
  • 95b197b feat(agents): [1/n] parse typed output from agent streams (#2853)
  • 6198ba0 feat(beta): bind typed application functions to Agents tools (#2852)
  • 71d2412 feat: collect final output from beta Agents streams (#2850)
  • a1421b1 fix(deps-dev): upgrade Vitest and migrate performance benchmarks (#2831)
  • a3c1af5 fix(api): allow original image detail in Chat Completions (#2851)
  • 94395e8 fix(deps-dev): update Vercel CLI to remove legacy proxy dependencies (

…rectory with 11 updates

Bumps the production-dependencies group with 11 updates in the /apps/api directory:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.123.0` | `0.131.0` |
| [@sentry/bun](https://github.com/getsentry/sentry-javascript) | `10.73.0` | `11.2.0` |
| [bullmq](https://github.com/taskforcesh/bullmq) | `5.81.4` | `5.81.5` |
| [dotenv](https://github.com/motdotla/dotenv) | `17.4.2` | `18.0.5` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [fs-extra](https://github.com/jprichardson/node-fs-extra) | `11.4.0` | `11.4.1` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `10.0.9` | `10.0.13` |
| [openai](https://github.com/openai/openai-node) | `7.10.0` | `7.27.0` |
| [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.23.0` | `8.23.1` |
| [resend](https://github.com/resend/resend-node) | `6.26.0` | `6.32.0` |
| [stripe](https://github.com/stripe/stripe-node) | `22.6.1` | `22.6.2` |



Updates `@anthropic-ai/sdk` from 0.123.0 to 0.131.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.123.0...sdk-v0.131.0)

Updates `@sentry/bun` from 10.73.0 to 11.2.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.73.0...11.2.0)

Updates `bullmq` from 5.81.4 to 5.81.5
- [Release notes](https://github.com/taskforcesh/bullmq/releases)
- [Commits](taskforcesh/bullmq@v5.81.4...v5.81.5)

Updates `dotenv` from 17.4.2 to 18.0.5
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.5)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `fs-extra` from 11.4.0 to 11.4.1
- [Changelog](https://github.com/jprichardson/node-fs-extra/blob/master/CHANGELOG.md)
- [Commits](jprichardson/node-fs-extra@11.4.0...11.4.1)

Updates `nodemailer` from 10.0.9 to 10.0.13
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v10.0.9...v10.0.13)

Updates `openai` from 7.10.0 to 7.27.0
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/main/CHANGELOG.md)
- [Commits](openai/openai-node@v7.10.0...v7.27.0)

Updates `pg` from 8.23.0 to 8.23.1
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.1/packages/pg)

Updates `resend` from 6.26.0 to 6.32.0
- [Release notes](https://github.com/resend/resend-node/releases)
- [Changelog](https://github.com/resend/resend-node/blob/canary/CHANGELOG.md)
- [Commits](resend/resend-node@v6.26.0...v6.32.0)

Updates `stripe` from 22.6.1 to 22.6.2
- [Release notes](https://github.com/stripe/stripe-node/releases)
- [Changelog](https://github.com/stripe/stripe-node/blob/master/CHANGELOG.md)
- [Commits](stripe/stripe-node@v22.6.1...v22.6.2)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.131.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@sentry/bun"
  dependency-version: 11.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: bullmq
  dependency-version: 5.81.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: dotenv
  dependency-version: 18.0.5
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: fs-extra
  dependency-version: 11.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: nodemailer
  dependency-version: 10.0.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: openai
  dependency-version: 7.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: pg
  dependency-version: 8.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: resend
  dependency-version: 6.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: stripe
  dependency-version: 22.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 9, 2026
@dependabot
dependabot Bot requested a review from agjs as a code owner October 9, 2026 05:44
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 9, 2026
@agjs

agjs commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Superseded by #490, which merged this update into main.

@agjs agjs closed this Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/bun/apps/api/production-dependencies-8d37be2a5a branch October 9, 2026 06:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant