Skip to content

Bump the npm_and_yarn group across 1 directory with 3 updates - #734

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm_and_yarn-2bfd32fd18
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm_and_yarn-2bfd32fd18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 3 updates in the / directory: nodemailer, brace-expansion and markdown-it.

Updates nodemailer from 9.1.1 to 10.0.9

Release notes

Sourced from nodemailer's releases.

v10.0.9

10.0.9 (2026-09-12)

Bug Fixes

  • addressparser: bound the '@' probe to the run being scanned (1465c3f)
  • addressparser: keep the text after a comment out of a quoted local part address (2f36eb1)

v10.0.8

10.0.8 (2026-09-11)

Bug Fixes

  • mime-node: clean the boundary where it is written, not only where it is built (e14278d)
  • mime-node: drop every control character from multipart boundary material (a82a355)

v10.0.7

10.0.7 (2026-09-11)

Bug Fixes

  • mime-funcs: do not double encode Buffer input when chunking base64 mime words (#1865) (4327a59)
  • mime-node: keep a boundary that is only line breaks from stripping to empty (ec46800)
  • mime-node: strip line breaks from multipart boundary material (#1867) (03c1a5c)
  • smtp-pool: release rate-limited connections on close (#1866) (7f5c7a4)

v10.0.6

10.0.6 (2026-09-11)

Bug Fixes

  • addressparser: scan free text for an address in linear time (437d7fc)

v10.0.5

10.0.5 (2026-09-11)

Bug Fixes

  • addressparser: parse comment-joined addresses in linear time (c07f175)

v10.0.4

10.0.4 (2026-09-11)

Bug Fixes

... (truncated)

Changelog

Sourced from nodemailer's changelog.

10.0.9 (2026-09-12)

Bug Fixes

  • addressparser: bound the '@' probe to the run being scanned (1465c3f)
  • addressparser: keep the text after a comment out of a quoted local part address (2f36eb1)

10.0.8 (2026-09-11)

Bug Fixes

  • mime-node: clean the boundary where it is written, not only where it is built (e14278d)
  • mime-node: drop every control character from multipart boundary material (a82a355)

10.0.7 (2026-09-11)

Bug Fixes

  • mime-funcs: do not double encode Buffer input when chunking base64 mime words (#1865) (4327a59)
  • mime-node: keep a boundary that is only line breaks from stripping to empty (ec46800)
  • mime-node: strip line breaks from multipart boundary material (#1867) (03c1a5c)
  • smtp-pool: release rate-limited connections on close (#1866) (7f5c7a4)

10.0.6 (2026-09-11)

Bug Fixes

  • addressparser: scan free text for an address in linear time (437d7fc)

10.0.5 (2026-09-11)

Bug Fixes

  • addressparser: parse comment-joined addresses in linear time (c07f175)

10.0.4 (2026-09-11)

Bug Fixes

  • fetch: scope a cookie without a Path to the RFC 6265 default path (2f907cb)
  • fetch: send cookies set with Path back to the exact path (#1861) (d557113)
  • mail-composer: keep httpHeaders and tls for href alternatives and icalEvent (#1862) (7f502be)
  • resolve well-known services by their primary domains (#1859) (085f525)
  • ses-transport: throw a configuration error when the SES client is missing (#1863) (4d9c4c9)

... (truncated)

Commits
  • 5a35d59 chore(master): release 10.0.9 (#1871)
  • 2f36eb1 fix(addressparser): keep the text after a comment out of a quoted local part ...
  • 1465c3f fix(addressparser): bound the '@' probe to the run being scanned
  • 1732dc4 chore(deps): update dev dependencies
  • ec7eda6 chore(deps): update dev dependencies
  • 618f912 chore(master): release 10.0.8 (#1870)
  • e14278d fix(mime-node): clean the boundary where it is written, not only where it is ...
  • a82a355 fix(mime-node): drop every control character from multipart boundary material
  • 29166ff chore(master): release 10.0.7 (#1869)
  • ec46800 fix(mime-node): keep a boundary that is only line breaks from stripping to empty
  • Additional commits viewable in compare view
Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates brace-expansion from 1.1.18 to 1.1.21

Commits

Updates markdown-it from 14.2.0 to 14.3.2

Changelog

Sourced from markdown-it's changelog.

[14.3.2] - 2026-09-12

Security

  • Backported 15.0.2 fixes.

[14.3.1] - 2026-08-27

Security

  • Backported 15.0.1 fixes.

[14.3.0] - 2026-07-02

Changed

  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.

Fixed

  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #1185.
Commits
  • efb9993 14.3.2 released
  • daf5a3c Backported 15.0.2 fixes
  • a855f10 14.3.1 released
  • ad70f6b Backported 15.0.1 fixes
  • b407f3b Ignore generated API docs in lint
  • bf025ad Prepare package.json for v14 backports
  • 2d9bbea fix: recognize lowercase declarations as HTML blocks (CommonMark 4.6) (#1189)
  • a311cfb fix: keep literal backslash before space in link destination (CommonMark 6.3)...
  • ff0ee08 14.3.0 released
  • 52e2749 Bump linkify-it / vite deps
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Medium Risk
Major bump on a direct runtime email dependency (sendEmail / MIME composition) without code changes; risk is mainly regression in mail parsing or MIME output, mitigated by Node engine alignment and patch-focused upstream fixes.

Overview
This PR only updates package.json and package-lock.json: no application source changes.

nodemailer is bumped from ^9.0.3 to ^10.0.9 (resolved 9.1.1 → 10.0.9). That is a major upgrade; v10 now requires Node ≥20 (this repo already declares Node ≥24). The SDK still uses nodemailer via MailComposer in sendEmail and SendMailOptions types—behavior should follow upstream bug fixes (address parsing, MIME boundaries, SMTP pool), not new SDK logic.

Transitive lockfile updates include brace-expansion (patch bumps in several dev-tool trees) and markdown-it 14.2.0 → 14.3.2 (security backports, dev/doc tooling such as TypeDoc).

Reviewers should confirm email/send tests still pass and note Dependabot’s warning that nodemailer 10 may run an install prepare script.

Reviewed by Cursor Bugbot for commit 1a4a901. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps the npm_and_yarn group with 3 updates in the / directory: [nodemailer](https://github.com/nodemailer/nodemailer), [brace-expansion](https://github.com/juliangruber/brace-expansion) and [markdown-it](https://github.com/markdown-it/markdown-it).


Updates `nodemailer` from 9.1.1 to 10.0.9
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v9.1.1...v10.0.9)

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

Updates `markdown-it` from 14.2.0 to 14.3.2
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.2.0...14.3.2)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 10.0.9
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1a4a901. Configure here.

Comment thread package.json
"jsonwebtoken": "^9.0.3",
"jwks-rsa": "^3.2.2",
"nodemailer": "^9.0.3",
"nodemailer": "^10.0.9",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nodemailer 10 breaks MailComposer import

High Severity

sendEmail deep-imports MailComposer from nodemailer/lib/mail-composer/index.js. Nodemailer 10 publishes only dist/ CJS/ESM builds and no lib/ tree, so that path no longer resolves and email sending fails. Reproduce by installing this PR and importing or calling sendEmail.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 1a4a901. Configure here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants