Skip to content

deps: bump the production-deps group across 1 directory with 15 updates - #137

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/production-deps-cf37607fc5
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/production-deps-cf37607fc5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown

Bumps the production-deps group with 15 updates in the / directory:

Package From To
@aa-sdk/core 4.88.4 4.88.5
@stripe/stripe-react-native 0.64.0 0.76.0
@tanstack/query-async-storage-persister 5.101.4 5.102.8
@tanstack/react-query 5.101.4 5.102.8
@tanstack/react-query-persist-client 5.101.4 5.102.8
@walletconnect/react-native-compat 2.23.10 2.24.0
@walletconnect/sign-client 2.23.10 2.24.0
axios 1.19.0 1.20.0
jose 6.2.8 6.2.12
lucide-react-native 1.28.0 1.44.0
uuid 14.0.1 14.0.2
viem 2.53.1 2.56.3
zustand 5.0.14 5.0.15
@walletconnect/types 2.23.10 2.24.0
react-test-renderer 19.2.8 19.3.0

Updates @aa-sdk/core from 4.88.4 to 4.88.5

Changelog

Sourced from @​aa-sdk/core's changelog.

4.88.5 (2026-08-11)

Bug Fixes

  • wallet-client: preserve -32521 instead of ox/custom rewrite+retry (#2560) (8e315bf)
Commits
  • 11cb2e2 chore(release): publish v4.88.5 [skip-ci]
  • 8e315bf fix(wallet-client): preserve -32521 instead of ox/custom rewrite+retry (#2560)
  • See full diff in compare view

Updates @stripe/stripe-react-native from 0.64.0 to 0.76.0

Release notes

Sourced from @​stripe/stripe-react-native's releases.

0.76.0 - 2026-09-01

Features

  • [Added] Added deleteWalletAddress to Crypto Onramp for deleting a registered wallet from the current Link account.

0.75.0 - 2026-08-18

Features

  • [Added] Android: Added Crypto Onramp Samsung Pay configuration, availability checks, payment collection, and example integration.
  • [Added] Added typed Crypto Onramp error coverage for wallet ownership verification failures.

0.74.0 - 2026-08-11

Features

  • [Added] iOS: Added supportedNetworks to the Apple Pay params, which restricts the card networks offered in the Apple Pay sheet.

0.73.0 - 2026-08-04

Changes

  • Updated Stripe iOS SDK from 26.4.1 to 26.5.0.
  • Updated Stripe Android SDK from 23.13.1 to 23.14.0.
  • [Added] useLinkController (private preview): Added billingDetailsCollectionConfiguration to LinkController.Configuration to control which billing fields are collected in the Link sheet.
  • [Added] useLinkController (private preview): Added appearance to LinkController.Configuration to customize Link UI colors and styling.
  • [Added] Added Tempo network support to Crypto Onramp.

0.72.0 - 2026-07-27

Changes

  • Updated Stripe iOS SDK from 26.3.0 to 26.4.1.
  • Updated Stripe Android SDK from 23.12.0 to 23.13.1.
  • [Changed] useLinkController (private preview): SetupIntent confirmation is now a separate step. The SDK no longer confirms the SetupIntent automatically inside presentLinkController; instead, confirmation is triggered explicitly after the payment method is selected.

0.71.0 - 2026-07-22

Features

  • [Added] Added support for the Pay by Bank payment method (paymentMethodType: 'PayByBank') in confirmPayment and confirmSetupIntent.

0.70.0 - 2026-07-16

Changes

  • [Changed] Renamed the Crypto Onramp error status enum from OnrampError to OnrampErrorStatus. Existing generic Onramp errors now use StripeError<OnrampErrorStatus>.
  • [Changed] Split rich Crypto Onramp errors into OnrampSdkError for SDK-owned diagnostics and OnrampApiError for API response context. Rich SDK errors use an onrampErrorType discriminator typed as OnrampErrorType, while API errors narrow it to OnrampApiErrorType and add fields such as reason, requestId, and API message/code details.
  • [Fixed] Android: PaymentMethod.Card.availableNetworks and PaymentMethod.USBankAccount.supportedNetworks now return the expected array of network strings instead of always returning null, matching iOS behavior.

Features

  • [Added] Added AppAttestationUnavailableError for local SDK app attestation availability/setup failures.
  • [Added] Added Crypto Onramp wallet ownership verification APIs, getWalletOwnershipChallenge and submitWalletOwnershipSignature, for EU Travel Rule compliance.
  • [Added] Added Arbitrum network support to Crypto Onramp.

0.69.0 - 2026-07-15

Changes

  • Updated Stripe iOS SDK from 26.0.0 to 26.3.0.
  • Updated Stripe Android SDK from 23.11.0 to 23.12.0.
  • [Changed] Connect embedded components — ConnectAccountOnboarding, ConnectPayments, and ConnectPayouts — are now generally available. No API changes; existing integrations continue to work without modification.

Features

  • [Added] Added standalone Link wallet APIs in private preview via useLinkController.

... (truncated)

Changelog

Sourced from @​stripe/stripe-react-native's changelog.

0.76.0 - 2026-09-01

Features

  • [Added] Added deleteWalletAddress to Crypto Onramp for deleting a registered wallet from the current Link account.

0.75.0 - 2026-08-18

Features

  • [Added] Android: Added Crypto Onramp Samsung Pay configuration, availability checks, payment collection, and example integration.
  • [Added] Added typed Crypto Onramp error coverage for wallet ownership verification failures.

0.74.0 - 2026-08-11

Features

  • [Added] iOS: Added supportedNetworks to the Apple Pay params, which restricts the card networks offered in the Apple Pay sheet.

0.73.0 - 2026-08-04

Changes

  • Updated Stripe iOS SDK from 26.4.1 to 26.5.0.
  • Updated Stripe Android SDK from 23.13.1 to 23.14.0.
  • [Added] useLinkController (private preview): Added billingDetailsCollectionConfiguration to LinkController.Configuration to control which billing fields are collected in the Link sheet.
  • [Added] useLinkController (private preview): Added appearance to LinkController.Configuration to customize Link UI colors and styling.
  • [Added] Added Tempo network support to Crypto Onramp.

0.72.0 - 2026-07-27

Changes

  • Updated Stripe iOS SDK from 26.3.0 to 26.4.1.
  • Updated Stripe Android SDK from 23.12.0 to 23.13.1.
  • [Changed] useLinkController (private preview): SetupIntent confirmation is now a separate step. The SDK no longer confirms the SetupIntent automatically inside presentLinkController; instead, confirmation is triggered explicitly after the payment method is selected.

0.71.0 - 2026-07-22

Features

  • [Added] Added support for the Pay by Bank payment method (paymentMethodType: 'PayByBank') in confirmPayment and confirmSetupIntent.

0.70.0 - 2026-07-16

Changes

  • [Changed] Renamed the Crypto Onramp error status enum from OnrampError to OnrampErrorStatus. Existing generic Onramp errors now use StripeError<OnrampErrorStatus>.
  • [Changed] Split rich Crypto Onramp errors into OnrampSdkError for SDK-owned diagnostics and OnrampApiError for API response context. Rich SDK errors use an onrampErrorType discriminator typed as OnrampErrorType, while API errors narrow it to OnrampApiErrorType and add fields such as reason, requestId, and API message/code details.
  • [Fixed] Android: PaymentMethod.Card.availableNetworks and PaymentMethod.USBankAccount.supportedNetworks now return the expected array of network strings instead of always returning null, matching iOS behavior.

Features

  • [Added] Added AppAttestationUnavailableError for local SDK app attestation availability/setup failures.
  • [Added] Added Crypto Onramp wallet ownership verification APIs, getWalletOwnershipChallenge and submitWalletOwnershipSignature, for EU Travel Rule compliance.
  • [Added] Added Arbitrum network support to Crypto Onramp.

0.69.0 - 2026-07-15

Changes

  • Updated Stripe iOS SDK from 26.0.0 to 26.3.0.
  • Updated Stripe Android SDK from 23.11.0 to 23.12.0.
  • [Changed] Connect embedded components — ConnectAccountOnboarding, ConnectPayments, and ConnectPayouts — are now generally available. No API changes; existing integrations continue to work without modification.

Features

  • [Added] Added standalone Link wallet APIs in private preview via useLinkController.

... (truncated)

Commits

Updates @tanstack/query-async-storage-persister from 5.101.4 to 5.102.8

Release notes

Sourced from @​tanstack/query-async-storage-persister's releases.

@​tanstack/query-async-storage-persister@​5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.8
    • @​tanstack/query-persist-client-core@​5.102.8

@​tanstack/query-async-storage-persister@​5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.7
    • @​tanstack/query-persist-client-core@​5.102.7

@​tanstack/query-async-storage-persister@​5.102.6

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.6
    • @​tanstack/query-persist-client-core@​5.102.6

@​tanstack/query-async-storage-persister@​5.102.5

Patch Changes

  • Updated dependencies [578e5c2]:
    • @​tanstack/query-core@​5.102.5
    • @​tanstack/query-persist-client-core@​5.102.5
Changelog

Sourced from @​tanstack/query-async-storage-persister's changelog.

5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.8
    • @​tanstack/query-persist-client-core@​5.102.8

5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.7
    • @​tanstack/query-persist-client-core@​5.102.7

5.102.6

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.6
    • @​tanstack/query-persist-client-core@​5.102.6

5.102.5

Patch Changes

  • Updated dependencies [578e5c2]:
    • @​tanstack/query-core@​5.102.5
    • @​tanstack/query-persist-client-core@​5.102.5

5.102.4

Patch Changes

  • Updated dependencies [a05df6a]:
    • @​tanstack/query-core@​5.102.4
    • @​tanstack/query-persist-client-core@​5.102.4

5.102.3

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.3
    • @​tanstack/query-persist-client-core@​5.102.3

5.102.2

... (truncated)

Commits

Updates @tanstack/react-query from 5.101.4 to 5.102.8

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.102.8
    • @​tanstack/react-query@​5.102.8

@​tanstack/react-query-next-experimental@​5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.102.8

@​tanstack/react-query-persist-client@​5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.8
    • @​tanstack/react-query@​5.102.8

@​tanstack/react-query@​5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.8

@​tanstack/react-query-devtools@​5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.102.7
    • @​tanstack/react-query@​5.102.7

@​tanstack/react-query-next-experimental@​5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.102.7

@​tanstack/react-query-persist-client@​5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.7
    • @​tanstack/react-query@​5.102.7

@​tanstack/react-query@​5.102.7

Patch Changes

  • Updated dependencies []:

... (truncated)

Changelog

Sourced from @​tanstack/react-query's changelog.

5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.8

5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.7

5.102.6

Patch Changes

  • #11305 ac2b612 - fix(react-query): throw falsy errors from useQueries and useSuspenseQueries to the error boundary

  • Updated dependencies []:

    • @​tanstack/query-core@​5.102.6

5.102.5

Patch Changes

  • Updated dependencies [578e5c2]:
    • @​tanstack/query-core@​5.102.5

5.102.4

Patch Changes

  • Updated dependencies [a05df6a]:
    • @​tanstack/query-core@​5.102.4

5.102.3

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.3

5.102.2

Patch Changes

  • Updated dependencies [80fbf73]:
    • @​tanstack/query-core@​5.102.2

... (truncated)

Commits

Updates @tanstack/react-query-persist-client from 5.101.4 to 5.102.8

Release notes

Sourced from @​tanstack/react-query-persist-client's releases.

@​tanstack/react-query-persist-client@​5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.8
    • @​tanstack/react-query@​5.102.8

@​tanstack/react-query-persist-client@​5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.7
    • @​tanstack/react-query@​5.102.7

@​tanstack/react-query-persist-client@​5.102.6

Patch Changes

  • Updated dependencies [ac2b612]:
    • @​tanstack/react-query@​5.102.6
    • @​tanstack/query-persist-client-core@​5.102.6

@​tanstack/react-query-persist-client@​5.102.5

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.5
    • @​tanstack/react-query@​5.102.5
Changelog

Sourced from @​tanstack/react-query-persist-client's changelog.

5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.8
    • @​tanstack/react-query@​5.102.8

5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.7
    • @​tanstack/react-query@​5.102.7

5.102.6

Patch Changes

  • Updated dependencies [ac2b612]:
    • @​tanstack/react-query@​5.102.6
    • @​tanstack/query-persist-client-core@​5.102.6

5.102.5

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.5
    • @​tanstack/react-query@​5.102.5

5.102.4

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.4
    • @​tanstack/react-query@​5.102.4

5.102.3

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.102.3
    • @​tanstack/react-query@​5.102.3

5.102.2

... (truncated)

Commits

Updates @walletconnect/react-native-compat from 2.23.10 to 2.24.0

Release notes

Sourced from @​walletconnect/react-native-compat's releases.

@​walletconnect/react-native-compat@​2.24.0

Patch Changes

  • #7304 83ba7d4 Thanks @​ganchoradkov! - Remove unused declared dependencies (@walletconnect/safe-json from utils, @walletconnect/types from pay, @walletconnect/core and @walletconnect/jsonrpc-provider from pos-client, events from react-native-compat, uint8arrays from signer-connection, @walletconnect/jsonrpc-provider, @walletconnect/jsonrpc-utils and @walletconnect/sign-client from ethereum-provider). No runtime changes.
Changelog

Sourced from @​walletconnect/react-native-compat's changelog.

2.24.0

Patch Changes

  • #7304 83ba7d4 Thanks @​ganchoradkov! - Remove unused declared dependencies (@walletconnect/safe-json from utils, @walletconnect/types from pay, @walletconnect/core and @walletconnect/jsonrpc-provider from pos-client, events from react-native-compat, uint8arrays from signer-connection, @walletconnect/jsonrpc-provider, @walletconnect/jsonrpc-utils and @walletconnect/sign-client from ethereum-provider). No runtime changes.
Commits
  • 50399e3 chore: update versions and lerna.json
  • 83ba7d4 chore: remove unused dependencies and bump dev tooling security versions
  • See full diff in compare view

Updates @walletconnect/sign-client from 2.23.10 to 2.24.0

Release notes

Sourced from @​walletconnect/sign-client's releases.

@​walletconnect/sign-client@​2.24.0

Minor Changes

  • #7329 fa9227f Thanks @​jakubuid! - Collect TVF transaction hashes for Stellar: compute the canonical transaction hash from signed stellar_signXDR envelopes (V0, V1 and fee-bump — with the signature-array scan hardened against signatures ending in zero bytes) and extract tx_hash from stellar_signAndSubmitXDR responses.

Patch Changes

Changelog

Sourced from @​walletconnect/sign-client's changelog.

2.24.0

Minor Changes

  • #7329 fa9227f Thanks @​jakubuid! - Collect TVF transaction hashes for Stellar: compute the canonical transaction hash from signed stellar_signXDR envelopes (V0, V1 and fee-bump — with the signature-array scan hardened against signatures ending in zero bytes) and extract tx_hash from stellar_signAndSubmitXDR responses.

Patch Changes

Commits
  • 50399e3 chore: update versions and lerna.json
  • 625aa3f Merge branch 'v2.0' into feat/stellar-tvf
  • d267fc2 fix(test): remove Relay SA region
  • 6f02620 chore: remove temporary QA logging
  • 6cb763c chore: drop changeset, add temporary QA logging for stellar TVF hashes
  • 4a17bb9 feat(tvf): collect transaction hashes for stellar_signXDR and stellar_signAnd...
  • 346bb23 test: skip 'connect (with old pairing)' sign-client test
  • 83ba7d4 chore: remove unused dependencies and bump dev tooling security versions
  • See full diff in compare view

Updates axios from 1.19.0 to 1.20.0

Release notes

Sourced from axios's releases.

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)

🔧 Maintenance & Chores

  • Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
  • Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
  • Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
  • CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

Changelog

Sourced from axios's changelog.

Changelog

Commits
  • 84a9f3b chore(release): prepare release 1.20.0 (#11152)
  • e6824ee fix: core methodList, HTTP adapter errors, and add tests (#11096)
  • d8a919f fix(xhr): flush final progress during the live loadend dispatch (#11121)
  • 2d2a21a fix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)
  • d19040b fix: harden runtime option handling (#11141)
  • e0a02dd chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...
  • d10cb3a chore(deps-dev): bump the development_dependencies group with 4 updates (#11143)
  • 2c94646 chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)
  • 76c12bc chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)
  • ba98559 docs: add ScrapingBee sponsor (#11137)
  • Additional commits viewable in compare view

Updates jose from 6.2.8 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

v6.2.10

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)
  • jwt: prevent replacing protected headers (ae07d09)
  • jwt: reject invalid duration inputs (282f9aa)
  • jwt: validate builder claim values (ea03f83)

... (truncated)

Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

6.2.10 (2026-08-21)

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inpu...

    Description has been truncated

Bumps the production-deps group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@aa-sdk/core](https://github.com/alchemyplatform/aa-sdk) | `4.88.4` | `4.88.5` |
| [@stripe/stripe-react-native](https://github.com/stripe/stripe-react-native) | `0.64.0` | `0.76.0` |
| [@tanstack/query-async-storage-persister](https://github.com/TanStack/query/tree/HEAD/packages/query-async-storage-persister) | `5.101.4` | `5.102.8` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.101.4` | `5.102.8` |
| [@tanstack/react-query-persist-client](https://github.com/TanStack/query/tree/HEAD/packages/react-query-persist-client) | `5.101.4` | `5.102.8` |
| [@walletconnect/react-native-compat](https://github.com/WalletConnect/walletconnect-monorepo/tree/HEAD/packages/react-native-compat) | `2.23.10` | `2.24.0` |
| [@walletconnect/sign-client](https://github.com/WalletConnect/walletconnect-monorepo/tree/HEAD/packages/sign-client) | `2.23.10` | `2.24.0` |
| [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` |
| [jose](https://github.com/panva/jose) | `6.2.8` | `6.2.12` |
| [lucide-react-native](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react-native) | `1.28.0` | `1.44.0` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` |
| [viem](https://github.com/wevm/viem) | `2.53.1` | `2.56.3` |
| [zustand](https://github.com/pmndrs/zustand) | `5.0.14` | `5.0.15` |
| [@walletconnect/types](https://github.com/WalletConnect/walletconnect-monorepo/tree/HEAD/packages/types) | `2.23.10` | `2.24.0` |
| [react-test-renderer](https://github.com/react/react/tree/HEAD/packages/react-test-renderer) | `19.2.8` | `19.3.0` |



Updates `@aa-sdk/core` from 4.88.4 to 4.88.5
- [Changelog](https://github.com/alchemyplatform/aa-sdk/blob/v4.88.5/CHANGELOG.md)
- [Commits](alchemyplatform/aa-sdk@v4.88.4...v4.88.5)

Updates `@stripe/stripe-react-native` from 0.64.0 to 0.76.0
- [Release notes](https://github.com/stripe/stripe-react-native/releases)
- [Changelog](https://github.com/stripe/stripe-react-native/blob/master/CHANGELOG.md)
- [Commits](stripe/stripe-react-native@v0.64.0...v0.76.0)

Updates `@tanstack/query-async-storage-persister` from 5.101.4 to 5.102.8
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/query-async-storage-persister/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/query-async-storage-persister@5.102.8/packages/query-async-storage-persister)

Updates `@tanstack/react-query` from 5.101.4 to 5.102.8
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.102.8/packages/react-query)

Updates `@tanstack/react-query-persist-client` from 5.101.4 to 5.102.8
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query-persist-client/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query-persist-client@5.102.8/packages/react-query-persist-client)

Updates `@walletconnect/react-native-compat` from 2.23.10 to 2.24.0
- [Release notes](https://github.com/WalletConnect/walletconnect-monorepo/releases)
- [Changelog](https://github.com/WalletConnect/walletconnect-monorepo/blob/v2.0/packages/react-native-compat/CHANGELOG.md)
- [Commits](https://github.com/WalletConnect/walletconnect-monorepo/commits/@walletconnect/react-native-compat@2.24.0/packages/react-native-compat)

Updates `@walletconnect/sign-client` from 2.23.10 to 2.24.0
- [Release notes](https://github.com/WalletConnect/walletconnect-monorepo/releases)
- [Changelog](https://github.com/WalletConnect/walletconnect-monorepo/blob/v2.0/packages/sign-client/CHANGELOG.md)
- [Commits](https://github.com/WalletConnect/walletconnect-monorepo/commits/@walletconnect/sign-client@2.24.0/packages/sign-client)

Updates `axios` from 1.19.0 to 1.20.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.19.0...v1.20.0)

Updates `jose` from 6.2.8 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.8...v6.2.12)

Updates `lucide-react-native` from 1.28.0 to 1.44.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.44.0/packages/lucide-react-native)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.1...v14.0.2)

Updates `viem` from 2.53.1 to 2.56.3
- [Release notes](https://github.com/wevm/viem/releases)
- [Commits](https://github.com/wevm/viem/compare/viem@2.53.1...viem@2.56.3)

Updates `zustand` from 5.0.14 to 5.0.15
- [Release notes](https://github.com/pmndrs/zustand/releases)
- [Commits](pmndrs/zustand@v5.0.14...v5.0.15)

Updates `@walletconnect/types` from 2.23.10 to 2.24.0
- [Release notes](https://github.com/WalletConnect/walletconnect-monorepo/releases)
- [Changelog](https://github.com/WalletConnect/walletconnect-monorepo/blob/v2.0/packages/types/CHANGELOG.md)
- [Commits](https://github.com/WalletConnect/walletconnect-monorepo/commits/@walletconnect/types@2.24.0/packages/types)

Updates `react-test-renderer` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-test-renderer)

---
updated-dependencies:
- dependency-name: "@aa-sdk/core"
  dependency-version: 4.88.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-deps
- dependency-name: "@stripe/stripe-react-native"
  dependency-version: 0.76.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@tanstack/query-async-storage-persister"
  dependency-version: 5.102.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.102.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@tanstack/react-query-persist-client"
  dependency-version: 5.102.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@walletconnect/react-native-compat"
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: "@walletconnect/sign-client"
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: jose
  dependency-version: 6.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-deps
- dependency-name: lucide-react-native
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-deps
- dependency-name: viem
  dependency-version: 2.56.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: zustand
  dependency-version: 5.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-deps
- dependency-name: "@walletconnect/types"
  dependency-version: 2.24.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-deps
- dependency-name: react-test-renderer
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from ArpitxGit as a code owner September 14, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants