Skip to content

⬆️(deps): Bump the security-updates group across 1 directory with 8 updates#34

Merged
zachlagden merged 1 commit into
mainfrom
dependabot/npm_and_yarn/security-updates-4f5c71dc47
Dec 25, 2025
Merged

⬆️(deps): Bump the security-updates group across 1 directory with 8 updates#34
zachlagden merged 1 commit into
mainfrom
dependabot/npm_and_yarn/security-updates-4f5c71dc47

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Dec 22, 2025

Copy link
Copy Markdown
Contributor

Bumps the security-updates group with 8 updates in the / directory:

Package From To
@contentful/rich-text-html-renderer 17.1.5 17.1.6
@contentful/rich-text-types 17.2.4 17.2.5
@radix-ui/react-slot 1.2.3 1.2.4
@sentry/nextjs 9.46.0 10.32.1
contentful 11.8.9 11.10.1
lucide-react 0.522.0 0.562.0
shadcn 2.10.0 3.6.2
tailwind-merge 3.3.1 3.4.0

Updates @contentful/rich-text-html-renderer from 17.1.5 to 17.1.6

Release notes

Sourced from @​contentful/rich-text-html-renderer's releases.

@​contentful/rich-text-html-renderer@​17.1.6

17.1.6 (2025-11-04)

Note: Version bump only for package @​contentful/rich-text-html-renderer

Commits
  • 72d8f4e chore(release): updated release notes and package versions [ci skip]
  • 747a853 chore: bump jest and @​types/jest (#888)
  • b2f2ffe chore: bump @​swc/core from 1.13.5 to 1.14.0 (#970)
  • 8d6a651 chore: bump @​rollup/plugin-commonjs from 28.0.9 to 29.0.0 (#967)
  • a765fe5 chore: bump rimraf from 6.0.1 to 6.1.0 (#969)
  • 0de75db chore: bump @​types/node from 24.8.1 to 24.9.2 (#971)
  • 961606c chore: bump @​lingui/core from 5.5.1 to 5.5.2 (#968)
  • 5f2384e chore: bump contentful-management from 11.60.4 to 11.61.0 (#964)
  • de6bc6c chore: bump @​rollup/plugin-commonjs from 28.0.8 to 28.0.9 (#966)
  • c540fd3 chore: bump @​faker-js/faker from 10.0.0 to 10.1.0 (#965)
  • Additional commits viewable in compare view

Updates @contentful/rich-text-types from 17.2.4 to 17.2.5

Release notes

Sourced from @​contentful/rich-text-types's releases.

@​contentful/rich-text-types@​17.2.5

17.2.5 (2025-11-04)

Note: Version bump only for package @​contentful/rich-text-types

Commits
  • 72d8f4e chore(release): updated release notes and package versions [ci skip]
  • 747a853 chore: bump jest and @​types/jest (#888)
  • b2f2ffe chore: bump @​swc/core from 1.13.5 to 1.14.0 (#970)
  • 8d6a651 chore: bump @​rollup/plugin-commonjs from 28.0.9 to 29.0.0 (#967)
  • a765fe5 chore: bump rimraf from 6.0.1 to 6.1.0 (#969)
  • 0de75db chore: bump @​types/node from 24.8.1 to 24.9.2 (#971)
  • 961606c chore: bump @​lingui/core from 5.5.1 to 5.5.2 (#968)
  • 5f2384e chore: bump contentful-management from 11.60.4 to 11.61.0 (#964)
  • de6bc6c chore: bump @​rollup/plugin-commonjs from 28.0.8 to 28.0.9 (#966)
  • c540fd3 chore: bump @​faker-js/faker from 10.0.0 to 10.1.0 (#965)
  • Additional commits viewable in compare view

Updates @radix-ui/react-slot from 1.2.3 to 1.2.4

Commits

Updates @sentry/nextjs from 9.46.0 to 10.32.1

Release notes

Sourced from @​sentry/nextjs's releases.

10.32.1

  • fix(cloudflare): Add hono transaction name when error is thrown (#18529)
  • fix(ember): Make implementation field optional (hash routes) (#18564)
  • fix(vercelai): Fix input token count (#18574)
  • chore(lint): prefer 'unknown' to 'any', fix lint warnings
  • chore(test): Remove cloudflare-astro e2e test (#18567)

Bundle size 📦

Path Size
@​sentry/browser 24.24 KB
@​sentry/browser - with treeshaking flags 22.77 KB
@​sentry/browser (incl. Tracing) 40.62 KB
@​sentry/browser (incl. Tracing, Profiling) 45.12 KB
@​sentry/browser (incl. Tracing, Replay) 78.3 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 68.28 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 82.88 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 94.83 KB
@​sentry/browser (incl. Feedback) 40.57 KB
@​sentry/browser (incl. sendFeedback) 28.82 KB
@​sentry/browser (incl. FeedbackAsync) 33.7 KB
@​sentry/react 25.92 KB
@​sentry/react (incl. Tracing) 42.77 KB
@​sentry/vue 28.6 KB
@​sentry/vue (incl. Tracing) 42.39 KB
@​sentry/svelte 24.25 KB
CDN Bundle 26.62 KB
CDN Bundle (incl. Tracing) 41.25 KB
CDN Bundle (incl. Tracing, Replay) 77.1 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 82.44 KB
CDN Bundle - uncompressed 78.18 KB
CDN Bundle (incl. Tracing) - uncompressed 122.47 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 236.27 KB
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 248.74 KB
@​sentry/nextjs (client) 44.94 KB
@​sentry/sveltekit (client) 40.98 KB
@​sentry/node-core 50.4 KB
@​sentry/node 157.73 KB
@​sentry/node - without tracing 90.87 KB
@​sentry/aws-serverless 106.02 KB

10.32.0

Important Changes

... (truncated)

Changelog

Sourced from @​sentry/nextjs's changelog.

10.32.1

  • fix(cloudflare): Add hono transaction name when error is thrown (#18529)
  • fix(ember): Make implementation field optional (hash routes) (#18564)
  • fix(vercelai): Fix input token count (#18574)
  • chore(lint): prefer 'unknown' to 'any', fix lint warnings
  • chore(test): Remove cloudflare-astro e2e test (#18567)

10.32.0

Important Changes

  • feat(core): Apply scope attributes to logs (#18184)

    You can now set attributes on the SDK's scopes which will be applied to all logs as long as the respective scopes are active. For the time being, only string, number and boolean attribute values are supported.

    Sentry.geGlobalScope().setAttributes({ is_admin: true, auth_provider: 'google' });
    Sentry.withScope(scope => {
    scope.setAttribute('step', 'authentication');
    // scope attributes is_admin, auth_provider and step are added
    Sentry.logger.info(user ${user.id} logged in, { activeSince: 100 });
    Sentry.logger.info(updated ${user.id} last activity);
    });
    // scope attributes is_admin and auth_provider are added
    Sentry.logger.warn('stale website version, reloading page');

  • feat(replay): Add Request body with attachRawBodyFromRequest option (#18501)

    To attach the raw request body (from Request objects passed as the first fetch argument) to replay events, you can now use the attachRawBodyFromRequest option in the Replay integration:

    Sentry.init({
      integrations: [
        Sentry.replayIntegration({
          attachRawBodyFromRequest: true,
        }),
      ],
    });

... (truncated)

Commits
  • 528ade2 release: 10.32.1
  • 25f695d Merge pull request #18578 from getsentry/prepare-release/10.32.1
  • a981a3d meta(changelog): Update changelog for 10.32.1
  • 0d8547c fix(vercelai): Fix input token count (#18574)
  • 71384a2 chore(lint): prefer 'unknown' to 'any', fix lint warnings
  • d1dd308 chore(test): Remove cloudflare-astro e2e test (#18567)
  • 12f3007 fix(ember): Make implementation field optional (hash routes) (#18564)
  • 3fda84d fix(cloudflare): Add hono transaction name when error is thrown (#18529)
  • a538901 Merge pull request #18563 from getsentry/master
  • 063c4dc Merge pull request #18562 from getsentry/ab/skip-ci-when-no-code-changes
  • Additional commits viewable in compare view

Updates contentful from 11.8.9 to 11.10.1

Release notes

Sourced from contentful's releases.

v11.10.1

11.10.1 (2025-12-12)

Bug Fixes

v11.10.0

11.10.0 (2025-12-10)

Features

  • cursor based pagination for assets and entries [CAPI-2342] (#2588) (dc5a751)

v11.9.0

11.9.0 (2025-11-17)

Features

  • timeline: move Timeline Preview out of alpha (#2605) (eec3979)

v11.9.0-testing-oidc-trusted-publishing.1

11.9.0-testing-oidc-trusted-publishing.1 (2025-11-05)

Features

  • trusted publishing: initial commit to add release github action to support OIDC trusted publish (f9b4976)

v11.8.13

11.8.13 (2025-11-14)

Bug Fixes

Reverts

  • Revert "build(deps-dev): bump the dev-dependencies group across 1 directory with 9 updates (#2587)" (#2596) (9e98404)

v11.8.12

11.8.12 (2025-11-11)

... (truncated)

Commits
  • 07ace88 fix: update tslibs version (#2622) [DX-599]
  • 247b2d2 chore: add tslib dependency (#2620)
  • 64070d6 chore: fix ci trigger for pushes to master (#2618)
  • dc5a751 feat: cursor based pagination for assets and entries [CAPI-2342] (#2588)
  • cab4280 chore(ci): trigger gha workflows on pull request [] (#2616)
  • 1a378a4 chore: update CI workflow branch pattern and PR template [] (#2614)
  • 475958e chore: update scripts to not use npm lifecycle commands [DX-589] (#2615)
  • 618a3d2 chore: add cooldown to npm dependabot configuration (#2610)
  • b42eff3 chore: [] ignore npm scripts (#2609)
  • 2704cec chore(readme): remove circleCI status from readme (#2606)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for contentful since your current version.


Updates lucide-react from 0.522.0 to 0.562.0

Release notes

Sourced from lucide-react's releases.

Version 0.562.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@0.561.0...0.562.0

Version 0.561.0

What's Changed

Full Changelog: lucide-icons/lucide@0.560.0...0.561.0

Version 0.560.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@0.559.0...0.560.0

Version 0.559.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@0.558.0...0.559.0

Version 0.558.0

What's Changed

Full Changelog: lucide-icons/lucide@0.557.0...0.558.0

Version 0.557.0

What's Changed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for lucide-react since your current version.


Updates shadcn from 2.10.0 to 3.6.2

Release notes

Sourced from shadcn's releases.

shadcn@3.6.2

Patch Changes

shadcn@3.6.1

3.6.1

Patch Changes

shadcn@3.6.0

3.6.0

Minor Changes

shadcn@3.5.2

Patch Changes

shadcn@3.5.1

Patch Changes

shadcn@3.5.0

Minor Changes

shadcn@3.4.2

Patch Changes

... (truncated)

Changelog

Sourced from shadcn's changelog.

3.6.2

Patch Changes

3.6.1

Patch Changes

3.6.0

Minor Changes

3.5.2

Patch Changes

3.5.1

Patch Changes

3.5.0

Minor Changes

3.4.2

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for shadcn since your current version.


Updates tailwind-merge from 3.3.1 to 3.4.0

Release notes

Sourced from tailwind-merge's releases.

v3.4.0

New Features

Documentation

Other

Full Changelog: dcastil/tailwind-merge@v3.3.1...v3.4.0

Thanks to @​brandonmcconnell, @​manavm1990, @​langy, @​roboflow, @​syntaxfm, @​getsentry, @​codecov and a private sponsor for sponsoring tailwind-merge! ❤️

Commits
  • 3e1256a v3.4.0
  • e15f392 add changelog for v3.4.0
  • 75e9aef Merge pull request #619 from quantizor/further-improvements
  • 1bafc9c Make benchmark test names consistent
  • 0799c12 revert: remove array-based string building optimization
  • 1927858 test: add ultra long class list benchmark
  • 87baba3 Remove unnecessary pre-computed conflict maps
  • 7831c8e perf: pre-compute conflict arrays at initialization
  • 1a3d133 perf: replace localeCompare with direct string comparison
  • 0270028 perf: use index-based recursion to avoid array allocations
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for tailwind-merge since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…pdates

Bumps the security-updates group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@contentful/rich-text-html-renderer](https://github.com/contentful/rich-text) | `17.1.5` | `17.1.6` |
| [@contentful/rich-text-types](https://github.com/contentful/rich-text) | `17.2.4` | `17.2.5` |
| [@radix-ui/react-slot](https://github.com/radix-ui/primitives) | `1.2.3` | `1.2.4` |
| [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) | `9.46.0` | `10.32.1` |
| [contentful](https://github.com/contentful/contentful.js) | `11.8.9` | `11.10.1` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.522.0` | `0.562.0` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn) | `2.10.0` | `3.6.2` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.3.1` | `3.4.0` |



Updates `@contentful/rich-text-html-renderer` from 17.1.5 to 17.1.6
- [Release notes](https://github.com/contentful/rich-text/releases)
- [Changelog](https://github.com/contentful/rich-text/blob/master/CHANGELOG.md)
- [Commits](https://github.com/contentful/rich-text/compare/@contentful/rich-text-html-renderer@17.1.5...@contentful/rich-text-html-renderer@17.1.6)

Updates `@contentful/rich-text-types` from 17.2.4 to 17.2.5
- [Release notes](https://github.com/contentful/rich-text/releases)
- [Changelog](https://github.com/contentful/rich-text/blob/master/CHANGELOG.md)
- [Commits](https://github.com/contentful/rich-text/compare/@contentful/rich-text-types@17.2.4...@contentful/rich-text-types@17.2.5)

Updates `@radix-ui/react-slot` from 1.2.3 to 1.2.4
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

Updates `@sentry/nextjs` from 9.46.0 to 10.32.1
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@9.46.0...10.32.1)

Updates `contentful` from 11.8.9 to 11.10.1
- [Release notes](https://github.com/contentful/contentful.js/releases)
- [Commits](contentful/contentful.js@v11.8.9...v11.10.1)

Updates `lucide-react` from 0.522.0 to 0.562.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/0.562.0/packages/lucide-react)

Updates `shadcn` from 2.10.0 to 3.6.2
- [Release notes](https://github.com/shadcn-ui/ui/releases)
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@3.6.2/packages/shadcn)

Updates `tailwind-merge` from 3.3.1 to 3.4.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](dcastil/tailwind-merge@v3.3.1...v3.4.0)

---
updated-dependencies:
- dependency-name: "@contentful/rich-text-html-renderer"
  dependency-version: 17.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-updates
- dependency-name: "@contentful/rich-text-types"
  dependency-version: 17.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-updates
- dependency-name: "@radix-ui/react-slot"
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security-updates
- dependency-name: "@sentry/nextjs"
  dependency-version: 10.32.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: security-updates
- dependency-name: contentful
  dependency-version: 11.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: security-updates
- dependency-name: lucide-react
  dependency-version: 0.562.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: security-updates
- dependency-name: shadcn
  dependency-version: 3.6.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: security-updates
- dependency-name: tailwind-merge
  dependency-version: 3.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: security-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@zachlagden zachlagden merged commit 6f4ee0a into main Dec 25, 2025
2 of 3 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/security-updates-4f5c71dc47 branch December 25, 2025 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant