Skip to content

build(deps): bump the web-deps group across 1 directory with 6 updates - #105

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/web/web-deps-9cb27e1dbe
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/web/web-deps-9cb27e1dbe

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the web-deps group with 6 updates in the /apps/web directory:

Package From To
next 16.3.5 16.3.6
@cloudflare/vite-plugin 1.57.2 1.60.2
@vitejs/plugin-rsc 0.5.34 0.5.35
eslint-config-next 16.3.5 16.3.6
vite 8.3.0 8.3.1
wrangler 4.136.2 4.141.0

Updates next from 16.3.5 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates @cloudflare/vite-plugin from 1.57.2 to 1.60.2

Release notes

Sourced from @​cloudflare/vite-plugin's releases.

@​cloudflare/vite-plugin@​1.60.2

Patch Changes

@​cloudflare/vite-plugin@​1.60.1

Patch Changes

@​cloudflare/vite-plugin@​1.60.0

Minor Changes

  • #15648 52c0e9f Thanks @​tpmmorris! - Advertise Local Explorer scheduled invocations to headless agents

    The Vite plugin's Local Explorer hint now documents how to invoke a Worker's scheduled handler and points agents to the OpenAPI schema for the complete request contract.

Patch Changes

@​cloudflare/vite-plugin@​1.59.0

Minor Changes

  • #15817 6e77c53 Thanks @​jamesopstad! - Allow framework commands to produce Preview Build Output with the experimental config

    When cf previews deploy invokes a framework build command, Preview intent is now preserved. Function-based cloudflare.config.ts files receive isPreview: true, and generated Build Output is marked as a Preview build.

Patch Changes

@​cloudflare/vite-plugin@​1.58.0

Minor Changes

  • #15778 cd7508c Thanks @​jamesopstad! - Generate types during development and supported builds with Vite's experimental.newConfig option or Wrangler's --experimental-new-config flag (and --experimental-cf-build-output for builds)

    When Wrangler's --experimental-new-config flag or Vite's experimental.newConfig option is enabled, inferred configuration and runtime declarations are now kept in .cloudflare/types/index.d.ts. Vite refreshes them during development and production builds. Wrangler refreshes them during development and when building with both --experimental-new-config and --experimental-cf-build-output. In the experimental wrangler.config.ts format, the types option is now top-level because it applies to both commands.

... (truncated)

Changelog

Sourced from @​cloudflare/vite-plugin's changelog.

1.60.2

Patch Changes

1.60.1

Patch Changes

1.60.0

Minor Changes

  • #15648 52c0e9f Thanks @​tpmmorris! - Advertise Local Explorer scheduled invocations to headless agents

    The Vite plugin's Local Explorer hint now documents how to invoke a Worker's scheduled handler and points agents to the OpenAPI schema for the complete request contract.

Patch Changes

1.59.0

Minor Changes

  • #15817 6e77c53 Thanks @​jamesopstad! - Allow framework commands to produce Preview Build Output with the experimental config

    When cf previews deploy invokes a framework build command, Preview intent is now preserved. Function-based cloudflare.config.ts files receive isPreview: true, and generated Build Output is marked as a Preview build.

Patch Changes

1.58.0

... (truncated)

Commits

Updates @vitejs/plugin-rsc from 0.5.34 to 0.5.35

Release notes

Sourced from @​vitejs/plugin-rsc's releases.

plugin-rsc@0.5.35

Features

Bug Fixes

Miscellaneous Chores

  • deps: update dependency @​types/react-dom to ^19.2.5 (#1432) (e7c2b6d)
  • deps: update dependency @​types/react-dom to ^19.2.7 (#1444) (f135533)
  • deps: update tsdown to v0.23 (#1451) (736efe2)

Code Refactoring

Tests

  • rsc: copy use cache/server mixed directive handling to examples/use-cache-persistent (#1417) (523e45b)
Changelog

Sourced from @​vitejs/plugin-rsc's changelog.

0.5.35 (2026-09-16)

Features

Bug Fixes

Miscellaneous Chores

  • deps: update dependency @​types/react-dom to ^19.2.5 (#1432) (e7c2b6d)
  • deps: update dependency @​types/react-dom to ^19.2.7 (#1444) (f135533)
  • deps: update tsdown to v0.23 (#1451) (736efe2)

Code Refactoring

Tests

  • rsc: copy use cache/server mixed directive handling to examples/use-cache-persistent (#1417) (523e45b)
Commits
  • a309c8b release: plugin-rsc@0.5.35 (#1459)
  • 9657ea1 fix(deps): update dependency strip-literal to v4 (#1457)
  • 389897e refactor(rsc): replace utils package (#1454)
  • 61b650f fix(deps): update react-related dependencies (#1452)
  • 736efe2 chore(deps): update tsdown to v0.23 (#1451)
  • f135533 chore(deps): update dependency @​types/react-dom to ^19.2.7 (#1444)
  • c9eba3e fix(deps): update dependency magic-string to v1 (#1443)
  • 55895a4 fix(deps): update all non-major dependencies (#1442)
  • 61006e6 fix(deps): update all non-major dependencies (#1433)
  • e7c2b6d chore(deps): update dependency @​types/react-dom to ^19.2.5 (#1432)
  • Additional commits viewable in compare view

Updates eslint-config-next from 16.3.5 to 16.3.6

Release notes

Sourced from eslint-config-next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates vite from 8.3.0 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Updates wrangler from 4.136.2 to 4.141.0

Release notes

Sourced from wrangler's releases.

wrangler@4.141.0

Minor Changes

  • #15658 8280086 Thanks @​jqmmes! - Add Durable Objects code update strategies to Worker deployments

    Use --durable-objects-code-update-mode immediate with wrangler deploy, wrangler versions deploy, and wrangler rollback to update code without waiting for active instances to hibernate. Use --durable-objects-code-update-mode deferred 30s to set a maximum delay, or configure durable_objects.code_update_strategy with mode and max_delay. When unset, the strategy defaults to deferred with a 5-minute maximum delay; delays cannot exceed 24 hours and must use millisecond precision.

  • #15800 bd56b98 Thanks @​Refaerds! - Add Browser Run as an event source for Queue subscriptions

    You can now create Queue subscriptions with --source browserRun.

Patch Changes

  • #15864 ee2b200 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260923.1 ^5.20260925.1
    workerd 1.20260923.1 1.20260925.1
  • #15207 805af2f Thanks @​exKAZUu! - Show the stack and cause of failed proxied requests in wrangler dev debug logs

    When a request proxied to the local Worker fails, running with --log-level debug now shows the underlying error's stack and cause chain.

  • Updated dependencies [ee2b200, c91279b]:

wrangler@4.140.0

Minor Changes

Patch Changes

wrangler@4.139.0

Minor Changes

  • #15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the web-deps group with 6 updates in the /apps/web directory:

| Package | From | To |
| --- | --- | --- |
| [next](https://github.com/vercel/next.js) | `16.3.5` | `16.3.6` |
| [@cloudflare/vite-plugin](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vite-plugin-cloudflare) | `1.57.2` | `1.60.2` |
| [@vitejs/plugin-rsc](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-rsc) | `0.5.34` | `0.5.35` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.5` | `16.3.6` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.1` |
| [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `4.136.2` | `4.141.0` |



Updates `next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

Updates `@cloudflare/vite-plugin` from 1.57.2 to 1.60.2
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/vite-plugin-cloudflare/CHANGELOG.md)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/@cloudflare/vite-plugin@1.60.2/packages/vite-plugin-cloudflare)

Updates `@vitejs/plugin-rsc` from 0.5.34 to 0.5.35
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-rsc/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-rsc@0.5.35/packages/plugin-rsc)

Updates `eslint-config-next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `vite` from 8.3.0 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `wrangler` from 4.136.2 to 4.141.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.141.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: web-deps
- dependency-name: "@cloudflare/vite-plugin"
  dependency-version: 1.60.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: web-deps
- dependency-name: "@vitejs/plugin-rsc"
  dependency-version: 0.5.35
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-deps
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-deps
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-deps
- dependency-name: wrangler
  dependency-version: 4.141.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: web-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants