chore(deps)(deps): bump the minor-and-patch group with 19 updates#58
Conversation
Bumps the minor-and-patch group with 19 updates: | Package | From | To | | --- | --- | --- | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.5` | `4.1.6` | | [turbo](https://github.com/vercel/turborepo) | `2.9.12` | `2.9.14` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.5` | `4.1.6` | | [@langchain/core](https://github.com/langchain-ai/langchainjs) | `1.1.45` | `1.1.46` | | [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.6.10` | `1.6.11` | | [deepagents](https://github.com/langchain-ai/deepagentsjs) | `1.10.0` | `1.10.2` | | [hono](https://github.com/honojs/hono) | `4.12.18` | `4.12.19` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.6.2` | `25.8.0` | | [tsx](https://github.com/privatenumber/tsx) | `4.21.0` | `4.22.1` | | [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `6.3.1` | `6.3.3` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.59.1` | `1.60.0` | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.100.9` | `5.100.10` | | [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.169.2` | `1.170.4` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.14.0` | `1.16.0` | | [@tanstack/router-plugin](https://github.com/TanStack/router/tree/HEAD/packages/router-plugin) | `1.167.35` | `1.168.6` | | [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.1` | `6.0.2` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.11` | `8.0.13` | | [bullmq](https://github.com/taskforcesh/bullmq) | `5.76.2` | `5.76.10` | | [isomorphic-git](https://github.com/isomorphic-git/isomorphic-git) | `1.37.6` | `1.38.1` | Updates `@vitest/coverage-v8` from 4.1.5 to 4.1.6 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.6/packages/coverage-v8) Updates `turbo` from 2.9.12 to 2.9.14 - [Release notes](https://github.com/vercel/turborepo/releases) - [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md) - [Commits](vercel/turborepo@v2.9.12...v2.9.14) Updates `vitest` from 4.1.5 to 4.1.6 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.6/packages/vitest) Updates `@langchain/core` from 1.1.45 to 1.1.46 - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Commits](https://github.com/langchain-ai/langchainjs/commits/@langchain/core@1.1.46) Updates `better-auth` from 1.6.10 to 1.6.11 - [Release notes](https://github.com/better-auth/better-auth/releases) - [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md) - [Commits](https://github.com/better-auth/better-auth/commits/better-auth@1.6.11/packages/better-auth) Updates `deepagents` from 1.10.0 to 1.10.2 - [Release notes](https://github.com/langchain-ai/deepagentsjs/releases) - [Commits](https://github.com/langchain-ai/deepagentsjs/compare/deepagents@1.10.0...deepagents@1.10.2) Updates `hono` from 4.12.18 to 4.12.19 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.18...v4.12.19) Updates `@types/node` from 25.6.2 to 25.8.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `tsx` from 4.21.0 to 4.22.1 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.21.0...v4.22.1) Updates `astro` from 6.3.1 to 6.3.3 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@6.3.3/packages/astro) Updates `@playwright/test` from 1.59.1 to 1.60.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.59.1...v1.60.0) Updates `@tanstack/react-query` from 5.100.9 to 5.100.10 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/HEAD/packages/react-query) Updates `@tanstack/react-router` from 1.169.2 to 1.170.4 - [Release notes](https://github.com/TanStack/router/releases) - [Changelog](https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.4/packages/react-router) Updates `lucide-react` from 1.14.0 to 1.16.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.16.0/packages/lucide-react) Updates `@tanstack/router-plugin` from 1.167.35 to 1.168.6 - [Release notes](https://github.com/TanStack/router/releases) - [Changelog](https://github.com/TanStack/router/blob/main/packages/router-plugin/CHANGELOG.md) - [Commits](https://github.com/TanStack/router/commits/@tanstack/router-plugin@1.168.6/packages/router-plugin) Updates `@vitejs/plugin-react` from 6.0.1 to 6.0.2 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.2/packages/plugin-react) Updates `vite` from 8.0.11 to 8.0.13 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.13/packages/vite) Updates `bullmq` from 5.76.2 to 5.76.10 - [Release notes](https://github.com/taskforcesh/bullmq/releases) - [Commits](taskforcesh/bullmq@v5.76.2...v5.76.10) Updates `isomorphic-git` from 1.37.6 to 1.38.1 - [Release notes](https://github.com/isomorphic-git/isomorphic-git/releases) - [Commits](isomorphic-git/isomorphic-git@v1.37.6...v1.38.1) --- updated-dependencies: - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: turbo dependency-version: 2.9.14 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: vitest dependency-version: 4.1.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@langchain/core" dependency-version: 1.1.46 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: better-auth dependency-version: 1.6.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: deepagents dependency-version: 1.10.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: hono dependency-version: 4.12.19 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/node" dependency-version: 25.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: tsx dependency-version: 4.22.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: astro dependency-version: 6.3.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@playwright/test" dependency-version: 1.60.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@tanstack/react-query" dependency-version: 5.100.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@tanstack/react-router" dependency-version: 1.170.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: lucide-react dependency-version: 1.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@tanstack/router-plugin" dependency-version: 1.168.6 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: vite dependency-version: 8.0.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: bullmq dependency-version: 5.76.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: isomorphic-git dependency-version: 1.38.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
There was a problem hiding this comment.
Security review result: I found one dependency-exposure issue in the changed dependency graph.
The PR only changes package manifests and pnpm-lock.yaml; it does not modify MCP routes, query execution, Better Auth setup, Hono route handlers, or environment-secret handling. I spot-checked those current integration points while reviewing the dependency bumps: MCP auth still happens before tool registration/handling, execute_query still validates through the DuckDB AST gate and model-scoped views with timeout/result limits, Better Auth still uses a >=32 char secret and production cookie attributes, and API routes were not changed here.
Validation run: pnpm audit --prod and pnpm audit both report 10 high-severity advisories through the production markitdown-ts dependency noted inline.
Sent by Cursor Automation: archmax Security Review
| "isomorphic-git": "^1.37.6", | ||
| "isomorphic-git": "^1.38.1", | ||
| "js-yaml": "^4.1.1", | ||
| "markitdown-ts": "^0.0.10", |
There was a problem hiding this comment.
pnpm audit --prod still fails through this production dependency. markitdown-ts@0.0.10 pulls xlsx@0.18.5 (prototype pollution and ReDoS advisories) and vulnerable @xmldom/xmldom versions directly and through mammoth; the app’s document ingestion path converts uploaded .xlsx, .docx, and XML-like files via MarkItDown in packages/core/src/services/document-files.ts, so user-supplied uploads can reach these parsers. Fix by upgrading or replacing markitdown-ts with a release that removes the vulnerable parsers; if there is no patched xlsx release available, switch spreadsheet conversion to a maintained parser or disable that conversion path, and pin/override @xmldom/xmldom to patched versions compatible with the converter stack.
Docker image readydocker pull ghcr.io/archmaxai/archmax:pr-58 |


Bumps the minor-and-patch group with 19 updates:
4.1.54.1.62.9.122.9.144.1.54.1.61.1.451.1.461.6.101.6.111.10.01.10.24.12.184.12.1925.6.225.8.04.21.04.22.16.3.16.3.31.59.11.60.05.100.95.100.101.169.21.170.41.14.01.16.01.167.351.168.66.0.16.0.28.0.118.0.135.76.25.76.101.37.61.38.1Updates
@vitest/coverage-v8from 4.1.5 to 4.1.6Release notes
Sourced from @vitest/coverage-v8's releases.
Commits
a8fd24cchore: release v4.1.6Updates
turbofrom 2.9.12 to 2.9.14Release notes
Sourced from turbo's releases.
... (truncated)
Commits
fc62fe0publish 2.9.14 to registryfb8c9aechore: Release 2.9.13 (#12803)e8e629dfix: Avoid project-local Yarn during detection (#12801)91c90cbfix: Harden VS Code extension command execution (#12800)84f4508fix: Validate auth callback state (#12802)1779ad7Removed unneeded import form hash creation script in docs (#12799)71f8c90test: Validate lockfiles without dependency downloads (#12789)5fcb960ci: Scope GitHub Actions caches by branch (#12788)4cf9fabci: Usepull_requestfor PR title linting (#12787)859c629fix: Restore docs mobile menu (#12782)Updates
vitestfrom 4.1.5 to 4.1.6Release notes
Sourced from vitest's releases.
Commits
a8fd24cchore: release v4.1.618af98cfix(browser): simplify orchestrator otel carrier (#10285)3188260feat(browser): provide project reference inToMatchScreenshotResolvePath(#...Updates
@langchain/corefrom 1.1.45 to 1.1.46Release notes
Sourced from @langchain/core's releases.
Commits
Updates
better-authfrom 1.6.10 to 1.6.11Release notes
Sourced from better-auth's releases.
... (truncated)
Changelog
Sourced from better-auth's changelog.
... (truncated)
Commits
f41514echore: release v1.6.11 (#9532)699b09afix(oidc-provider, mcp): drop "none" alg, default plain PKCE off, reject miss...b4bc65aMerge commit from forka1c9f3cfix(access): preserve exact role statement types (#9507)da7e50bfix(oauth): block OAuth linking to unverified local accounts (#9578)23094a6fix(organization): default-onrequireEmailVerificationOnInvitation& extend...1f2ff42fix(oidc-provider, mcp): authenticate confidential clients on refresh_token g...5f09d56fix(magic-link): consume verification token atomically on verify (#9572)99a254afix(device-authorization): bind approval to verifier session (#9573)0cbddb8refactor(db): renameclaimOneadapter primitive toconsumeOne(#9568)Updates
deepagentsfrom 1.10.0 to 1.10.2Release notes
Sourced from deepagents's releases.
Commits
163ee49chore: version packages (#532)f088089feat(deepagents): add ContextHubBackend backend (#533)7c33a86feat(deepagents): implement harness profiles (#526)c231aedchore: version packages (#525)d23b3e8build(deps): bump hono from 4.12.16 to 4.12.18 (#529)a76b7dfchore(quickjs): updateREPLMiddlewareto be named `CodeInterpreterMiddlewar...8a6de8efix(deepagents): align LangSmith sandbox create options with SDK (#528)f164f99feat(deepagents): add snapshot/start/stop lifecycle to LangSmithSandbox (#479)2cbd524fix(quickjs): individual repl sessions use individual wasm module causing ine...Updates
honofrom 4.12.18 to 4.12.19Release notes
Sourced from hono's releases.
Commits
7e62bcd4.12.19e2f252afix(stream): upgrade@hono/node-serverto v2 and fix abort handling (#4940)54f2f0cfeat(request): addbytes()(#4921)e59db59feat(cache): key cache entries by configured vary headers (#4915)48a7ccbfeat(bearer-auth): make bearerAuth generic for typed context in verifyToken (...ff7522ffix(cookie): return the first cookie when there are multiple cookies with the...26f8c33fix(serveStatic): make options parameter optional in all adapters (#4934)16c4e38ci: pin GitHub Actions to SHAs (#4932)Updates
@types/nodefrom 25.6.2 to 25.8.0Commits
Updates
tsxfrom 4.21.0 to 4.22.1Release notes
Sourced from tsx's releases.
Commits
6979f28fix: resolve tsconfig path aliases containing a colon (#780)b29f6eefeat: upgrade esbuild to 0.28 (#789)0dd17e9test: cover registerHooks loader compositionacf3d8ffix: support Node 20.11/21.2 import.meta paths4bbef80test: cover configDir paths without baseUrldddc5cetest: cover sync-hook watch reruns and cleanup retries09e8f8ctest: assert CLI runs without warnings1d7e528fix: support Node.js 26.1.0 and 25.9.0c1d2d45fix: support Node.js 24.15.0d04672dtest: update node version feature gatesMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for tsx since your current version.
Updates
astrofrom 6.3.1 to 6.3.3Release notes
Sourced from astro's releases.
Changelog
Sourced from astro's changelog.
Commits
5ec95d0[ci] release (#16736)bce5c34...Description has been truncated