Bumps the npm_and_yarn group with 6 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [nanoid](https://github.com/ai/nanoid) | `5.0.1` | `5.1.16` |
| [next](https://github.com/vercel/next.js) | `15.5.8` | `15.5.21` |
| [next-auth](https://github.com/nextauthjs/next-auth) | `4.24.11` | `4.24.15` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.0` | `2.17.5` |
| [postcss](https://github.com/postcss/postcss) | `8.4.31` | `8.5.23` |
| [nodemailer](https://github.com/nodemailer/nodemailer) | `6.9.3` | `9.0.1` |
Bumps the npm_and_yarn group with 5 updates in the /apps/web directory:
| Package | From | To |
| --- | --- | --- |
| [nanoid](https://github.com/ai/nanoid) | `5.0.1` | `5.1.16` |
| [next](https://github.com/vercel/next.js) | `15.5.8` | `15.5.21` |
| [next-auth](https://github.com/nextauthjs/next-auth) | `4.24.11` | `4.24.15` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.0` | `2.17.5` |
| [postcss](https://github.com/postcss/postcss) | `8.4.31` | `8.5.23` |
Bumps the npm_and_yarn group with 1 update in the /packages/stripe-app directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).
Bumps the npm_and_yarn group with 1 update in the /packages/ui directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /packages/utils directory: [next](https://github.com/vercel/next.js).
Updates `nanoid` from 5.0.1 to 5.1.16
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@5.0.1...5.1.16)
Updates `next` from 15.5.8 to 15.5.21
- [Commits](vercel/next.js@v15.5.8...v15.5.21)
Updates `next-auth` from 4.24.11 to 4.24.15
- [Commits](https://github.com/nextauthjs/next-auth/compare/next-auth@4.24.11...next-auth@4.24.15)
Updates `sanitize-html` from 2.17.0 to 2.17.5
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.5/packages/sanitize-html)
Updates `postcss` from 8.4.31 to 8.5.23
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.4.31...8.5.23)
Updates `nodemailer` from 6.9.3 to 9.0.1
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v6.9.3...v9.0.1)
Updates `sharp` from 0.34.4 to 0.34.5
- [Commits](lovell/sharp@v0.34.4...v0.34.5)
Updates `nanoid` from 5.0.1 to 5.1.16
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](ai/nanoid@5.0.1...5.1.16)
Updates `next` from 15.5.8 to 15.5.21
- [Commits](vercel/next.js@v15.5.8...v15.5.21)
Updates `next-auth` from 4.24.11 to 4.24.15
- [Commits](https://github.com/nextauthjs/next-auth/compare/next-auth@4.24.11...next-auth@4.24.15)
Updates `sanitize-html` from 2.17.0 to 2.17.5
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.5/packages/sanitize-html)
Updates `postcss` from 8.4.31 to 8.5.23
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.4.31...8.5.23)
Updates `brace-expansion` from 1.1.11 to 1.1.18
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.18)
Updates `next` from 15.5.8 to 15.5.21
- [Commits](vercel/next.js@v15.5.8...v15.5.21)
Updates `next` from 15.5.8 to 15.5.21
- [Commits](vercel/next.js@v15.5.8...v15.5.21)
---
updated-dependencies:
- dependency-name: nanoid
dependency-version: 5.1.16
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: next
dependency-version: 15.5.21
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: next-auth
dependency-version: 4.24.15
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: sanitize-html
dependency-version: 2.17.5
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: postcss
dependency-version: 8.5.23
dependency-type: direct:development
dependency-group: npm_and_yarn
- dependency-name: nodemailer
dependency-version: 9.0.1
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: sharp
dependency-version: 0.34.5
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: nanoid
dependency-version: 5.1.16
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: next
dependency-version: 15.5.21
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: next-auth
dependency-version: 4.24.15
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: sanitize-html
dependency-version: 2.17.5
dependency-type: direct:production
dependency-group: npm_and_yarn
- dependency-name: postcss
dependency-version: 8.5.23
dependency-type: direct:development
dependency-group: npm_and_yarn
- dependency-name: brace-expansion
dependency-version: 1.1.18
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: next
dependency-version: 15.5.21
dependency-type: direct:development
dependency-group: npm_and_yarn
- dependency-name: next
dependency-version: 15.5.21
dependency-type: direct:development
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps the npm_and_yarn group with 6 updates in the / directory:
5.0.15.1.1615.5.815.5.214.24.114.24.152.17.02.17.58.4.318.5.236.9.39.0.1Bumps the npm_and_yarn group with 5 updates in the /apps/web directory:
5.0.15.1.1615.5.815.5.214.24.114.24.152.17.02.17.58.4.318.5.23Bumps the npm_and_yarn group with 1 update in the /packages/stripe-app directory: brace-expansion.
Bumps the npm_and_yarn group with 1 update in the /packages/ui directory: next.
Bumps the npm_and_yarn group with 1 update in the /packages/utils directory: next.
Updates
nanoidfrom 5.0.1 to 5.1.16Changelog
Sourced from nanoid's changelog.
... (truncated)
Commits
6ccc67bRelease 5.1.16 version6de05d7fix(non-secure): clamp negative size with a smaller guard (#600)3925903Update dependencies0b69554Release 5.1.15 version333c5a0Backport changelog changes for 3.x266eb63Remove debug codea6a94d3Do not allow to pollute pool93fe197Reduce ID sizee4b7a9aRelease 5.1.14 version6bf3469Update release actionMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for nanoid since your current version.
Updates
nextfrom 15.5.8 to 15.5.21Commits
e26f6ffv15.5.217f5deeb[15.x] Improve performance of checking valid MPA form submissions57c31f7[15.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimee3e5666[15.x] Set correct origin for internal redirects in custom server35f5013[15.x] Ensure exotic rewrite param values are properly encoded062f667[15.x] fix(fetch-cache): key fetch(Request, init) by the effective request577c9dc[15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies530d4fa[15.x] fix(next/image): improve performance of detectContentType()8fabaf3[15.x] Performance improvements when decoding React Server function payloadsff12a61[15.x] Validate server reference IDs during manifest lookupMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.
Updates
next-authfrom 4.24.11 to 4.24.15Commits
d857eecchore(release): next-auth@4.24.15 [skip ci]5bca239fix(next-auth): harden getToken parsing and bind OAuth check cookies to provi...db7e27dchore(deps): use uuid ^11.1.1 to keep CommonJS support (#13466)32d874cfix(next-auth): repair red v4 CI (lint + pre-existing test drift) (#13447)fa85858chore: update uuid to v14, remove deprecated types (#13422)2a39465Merge commit from fork19d2febMerge commit from forke9a892achore(release): bump version [skip ci]0497da4fix(providers): add issuer to github (#13412)1a70ee8chore(release): bump version [skip ci]Maintainer changes
This version was pushed to npm by better-gustavo, a new releaser for next-auth since your current version.
Updates
sanitize-htmlfrom 2.17.0 to 2.17.5Changelog
Sourced from sanitize-html's changelog.
Commits
2427508release and changelog edits (#5465)5a88e96Latest security q2 (#5464)958d162merge main to latest (#5460)e9b0ab0release only (changelogs formatted) (#5408)f03fa5bLatest security merge (#5407)96cf174For release only (#5381)7ca2d16Merge commit from fork297a422Bump dependencies (#5376)7e607c9Changelog reconciliation for release (#5359)49d0bb7Port/sanitize html community contrib (#5337)Updates
postcssfrom 8.4.31 to 8.5.23Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
eb9e1feRelease 8.5.23 version9d19c78Update dependencies7beca13Does no load source map file without opts.fromdecea51Typoc18e30dUpdate EM banner98a39adUpdate EM bannera3e48c4Release 8.5.22 versionf49d691Fix custom property losing its semicolon before a comment (#2117)28e0dafRelease 8.5.21 version3d2b4e4Update dependenciesMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.
Updates
nodemailerfrom 6.9.3 to 9.0.1Changelog
Sourced from nodemailer's changelog.
... (truncated)
Commits
69cf625chore(master): release 9.0.1 (#1828)a82e060fix: enforce disableFileAccess/disableUrlAccess for raw message option4e58450chore: update dev dependencies541f5fdchore(master): release 9.0.0 (#1827)0c080fbfix: replace deprecated url.parse with a WHATWG URL wrapper6a947acfix!: validate TLS certificates by default when fetching remote contente3b1bdachore(master): release 8.0.11 (#1826)4358cafrefactor: remove dead checks flagged by Code Quality analysiscf5195cchore: harden workflow token permissions and update GitHub Actions067aebefix: parse Ethereal response props without polynomial regex backtrackingMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for nodemailer since your current version.
Updates
sharpfrom 0.34.4 to 0.34.5Commits
e062456Release v0.34.56450c70Prerelease v0.34.5-rc.1f7c95d1TypeScript: consolidate a few enum-like propertiesef86a75Prerelease v0.34.5-rc.06c1e840Use structured binding for tuples where possiblee1628d8Simplify ICC processing when retaining input profiles #44684f9f817Linter: apply all recommended biome settings09d5aa8Docs: update internal and libvips doc links040b73cUpgrade to libvips v8.17.31f2f33dEnsure licensing headers are retained by code bundlersInstall script changes
This version modifies
installscript that runs during installation. Review the package contents before updating.Updates
nanoidfrom 5.0.1 to 5.1.16Changelog
Sourced from nanoid's changelog.
... (truncated)
Commits
6ccc67bRelease 5.1.16 version6de05d7fix(non-secure): clamp negative size with a smaller guard (#600)3925903Update dependencies0b69554Release 5.1.15 version333c5a0Backport changelog changes for 3.x266eb63Remove debug codea6a94d3Do not allow to pollute pool93fe197Reduce ID sizee4b7a9aRelease 5.1.14 version6bf3469Update release actionMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for nanoid since your current version.
Updates
nextfrom 15.5.8 to 15.5.21Commits
e26f6ffv15.5.217f5deeb[15.x] Improve performance of checking valid MPA form submissions57c31f7[15.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimee3e5666[15.x] Set correct origin for internal redirects in custom server35f5013[15.x] Ensure exotic rewrite param values are properly encoded062f667[15.x] fix(fetch-cache): key fetch(Request, init) by the effective request577c9dc[15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies530d4fa[15.x] fix(next/image): improve performance of detectContentType()8fabaf3[15.x] Performance improvements when decoding React Server function payloadsff12a61[15.x] Validate server reference IDs during manifest lookupMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.
Updates
next-authfrom 4.24.11 to 4.24.15Commits
d857eecchore(release): next-auth@4.24.15 [skip ci]5bca239fix(next-auth): harden getToken parsing and bind OAuth check cookies to provi...db7e27dchore(deps): use uuid ^11.1.1 to keep CommonJS support (#13466)32d874cfix(next-auth): repair red v4 CI (lint + pre-existing test drift) (#13447)fa85858chore: update uuid to v14, remove deprecated types (#13422)2a39465Merge commit from fork19d2febMerge commit from forke9a892achore(release): bump version [skip ci]0497da4fix(providers): add issuer to github (#13412)1a70ee8chore(release): bump version [skip ci]Maintainer changes
This version was pushed to npm by better-gustavo, a new releaser for next-auth since your current version.
Updates
sanitize-htmlfrom 2.17.0 to 2.17.5Changelog
Sourced from sanitize-html's changelog.
Commits
2427508release and changelog edits (#5465)5a88e96Latest security q2 (#5464)958d162merge main to latest (#5460)e9b0ab0release only (changelogs formatted) (#5408)f03fa5bLatest security merge (#5407)96cf174For release only (#5381)7ca2d16Merge commit from fork297a422Bump dependencies (#5376)7e607c9Changelog reconciliation for release (#5359)49d0bb7Port/sanitize html community contrib (#5337)Updates
postcssfrom 8.4.31 to 8.5.23Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
eb9e1feRelease 8.5.23 version9d19c78Update dependencies7beca13Does no load source map file without opts.fromdecea51Typoc18e30dUpdate EM banner98a39adUpdate EM bannera3e48c4Release 8.5.22 versionf49d691Fix custom property losing its semicolon before a comment (#2117)28e0dafRelease 8.5.21 version3d2b4e4Update dependenciesMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.
Updates
brace-expansionfrom 1.1.11 to 1.1.18Commits
758fcd61.1.1827fbeedMerge commit from fork5c57cc21.1.17d757f1dnpm ignore.claudecb4b9e4fix: backport GHSA-mh99-v99m-4gvg (#129)447763a1.1.16d74e630fix: v1 backport for CVE-2026-13149 (#122)2203f4f1.1.150b09384Backport v5.0.6 change to v1 (#111)10c05fc1.1.14Updates
nextfrom 15.5.8 to 15.5.21Commits
e26f6ffv15.5.217f5deeb[15.x] Improve performance of checking valid MPA form submissions57c31f7[15.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimee3e5666[15.x] Set correct origin for internal redirects in custom server35f5013[15.x] Ensure exotic rewrite param values are properly encoded062f667[15.x] fix(fetch-cache): key fetch(Request, init) by the effective request577c9dc[15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies530d4fa[15.x] fix(next/image): improve performance of detectContentType()8fabaf3[15.x] Performance improvements when decoding React Server function payloadsff12a61[15.x] Validate server reference IDs during manifest lookupMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.
Updates
nextfrom 15.5.8 to 15.5.21Commits
e26f6ffv15.5.217f5deeb[15.x] Improve performance of checking valid MPA form submissions57c31f7[15.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimee3e5666[15.x] Set correct origin for internal redirects in custom server35f5013[15.x] Ensure exotic rewrite param values are properly encoded062f667[15.x] fix(fetch-cache): key fetch(Request, init) by the effective request577c9dc[15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies530d4fa[15.x] fix(next/image): improve performance of detectContentType()8fabaf3[15.x] Performance improvements when decoding React Server function payloadsff12a61[15.x] Validate server reference IDs during manifest lookupMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.