Skip to content

Build(deps): Bump the npm-prod-minor group across 1 directory with 6 updates - #29

Closed
dependabot[bot] wants to merge 18 commits into
mainfrom
dependabot/npm_and_yarn/npm-prod-minor-476b682088
Closed

dependabot[bot] wants to merge 18 commits into
mainfrom
dependabot/npm_and_yarn/npm-prod-minor-476b682088

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-prod-minor group with 6 updates in the / directory:

Package From To
@fastify/cors 11.2.0 11.3.0
@fastify/jwt 10.1.0 10.2.0
@fastify/multipart 10.0.0 10.1.0
fast-xml-parser 5.8.0 5.10.0
fastify 5.8.5 5.10.0
yauzl 3.3.2 3.4.0

Updates @fastify/cors from 11.2.0 to 11.3.0

Release notes

Sourced from @​fastify/cors's releases.

v11.3.0

What's Changed

New Contributors

Full Changelog: fastify/fastify-cors@v11.2.0...v11.3.0

Commits
  • 2c60caa Bumped v11.3.0
  • cf4986e chore: bump @​types/node in the dev-dependencies-typescript group (#411)
  • 816d054 test: remove remaining tap-style assertions from vary tests (#410)
  • 20507ea chore(package.json): fix delvedor's personal url (#409)
  • 6fe85c4 docs(readme): update request origin link (#408)
  • 57bdc65 chore: bump fastify-plugin from 5.1.0 to 6.0.0 in the dependencies group (#407)
  • a8ae57d chore: update depedabot setting
  • 4d34798 chore(.gitattributes): retain binary file eol style (#402)
  • 675ebef refactor(types): migrate from tsd to tstyche (#403)
  • ef25e0b ci: add lock-threads workflow (#401)
  • Additional commits viewable in compare view

Updates @fastify/jwt from 10.1.0 to 10.2.0

Release notes

Sourced from @​fastify/jwt's releases.

v10.2.0

What's Changed

New Contributors

Full Changelog: fastify/fastify-jwt@v10.1.0...v10.2.0

Commits

Updates @fastify/multipart from 10.0.0 to 10.1.0

Release notes

Sourced from @​fastify/multipart's releases.

v10.1.0

What's Changed

Full Changelog: fastify/fastify-multipart@v10.0.0...v10.1.0

Commits
  • 0a8ab66 Bumped v10.1.0
  • a9d53e5 fix: update module version
  • 9b3bf89 fix: do not end parts() iteration while busboy still holds undelivered parts ...
  • 45023e0 chore: bump @​types/node in the dev-dependencies-typescript group (#629)
  • 77b563e docs: fix broken links
  • d7475da chore: bump @​fastify/swagger-ui from 5.2.6 to 6.0.0 (#626)
  • ed56b6f chore: bump fastify-plugin from 5.1.0 to 6.0.0 in the dependencies group (#625)
  • f79f996 chore: update depedabot setting
  • 60e1b5c chore: use lf eol (#619)
  • cddccd4 refactor(types): migrate from tsd to tstyche (#617)
  • Additional commits viewable in compare view

Updates fast-xml-parser from 5.8.0 to 5.10.0

Release notes

Sourced from fast-xml-parser's releases.

v5.10.0

What's Changed

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.9.3...v5.10.0

v5.9.3

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.9.2...v5.9.3

v5.9.2

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.9.1...v5.9.2

v5.9.1

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.9.0...v5.9.1

update strnum, use is-unsafe

  • update strnum to 2.3.0
    • you can set hex, binary, enotation, infinity, unicode
  • validate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library. User can override rules by overriding EntityDecoder.
Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

5.10.0 / 2026-07-11

  • upgrade:
    • xml-naming v0.3.0: cache support
    • PEM v1.6.2: sibling bug fix
    • is-unsafe v2.0.0: tree shaking

*5.9.3 / 2026-06-19

  • update strnum

*5.9.2 / 2026-06-17

  • dummy release to test changes in github action

*5.9.1 / 2026-06-17

  • dummy release to test release from github action

*5.9.0 / 2026-06-15

  • update strnum to 2.3.0
    • you can set hex, binary, enotation, infinity, unicode
  • validate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library. User can override rules by overriding EntityDecoder.

*5.8.0 / 2026-05-12

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is bydeault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid
    • fix format output

5.7.3 / 2006-05-05

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)
  • update XML Builder to 1.1.7
  • mark addEntity deprecated

5.7.2 / 2026-04-25

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

5.7.1 / 2026-04-20

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for fast-xml-parser since your current version.


Updates fastify from 5.8.5 to 5.10.0

Release notes

Sourced from fastify's releases.

v5.10.0

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.9.0...v5.10.0

v5.9.0

What's Changed

... (truncated)

Commits
  • 94bcbcc Bumped v5.10.0
  • c47975e docs: Update import for page consistency (#6771)
  • 82952b8 docs: Logging.md with per-route log level info (#6627)
  • 6ac2e95 fix: derive request.port from request.host (#6680)
  • 5f4871f perf: reduce per-request overhead in the request lifecycle (#6831)
  • ec4bc66 chore: Bump fast-json-stringify to v7 (#6800)
  • d0b649d docs: fix incorrect hook count in Hooks.md (eight -> ten) (#6825)
  • 826c807 docs: fix incorrect defaults and code examples in Server.md (#6805)
  • 6f63ce9 fix: use ContentType to detect json and charset in reply.send (#6830)
  • 75d74e1 feat: introduce log controller layer (#6580)
  • Additional commits viewable in compare view

Updates yauzl from 3.3.2 to 3.4.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

sushant-ipte and others added 18 commits May 24, 2026 18:33
Day 1 build. Includes:

- Fastify HTTP server bootstrap with cors, sensible, multipart, and JWT plugins
- Prisma 5 schema for SCORM 1.2 / 2004: tenants, API keys, courses, SCOs,
  learners, attempts, interactions, objectives, and runtime commit log
- Multi-stage Docker image + docker-compose with Postgres 16 and Redis
- Zod-validated environment configuration with pluggable storage adapter
- GitHub Actions CI: typecheck, build, prisma schema validation, tests
  against a Postgres service container
- Claude Code PR review workflow, CodeQL, dependency review, OSSF Scorecard
- Dependabot for npm, actions, and docker
- Issue + PR templates, SECURITY.md disclosure policy

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.0 to 2.4.3.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@v2.4.0...v2.4.3)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Requires paid Anthropic API usage, which is out of scope for this project
right now. CodeQL, dependency review, and OSSF Scorecard remain as the
automated review layer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Dependabot now groups minor/patch updates per ecosystem and skips
semver-major bumps. Majors will be taken deliberately as planned
tech-debt PRs instead of arriving as an unmanageable storm on day one.

tsconfig.json: baseUrl is deprecated in TS 6 and removed in TS 7.
paths still resolves correctly without it (relative to tsconfig dir).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…f/scorecard-action-2.4.3

Build(deps): Bump ossf/scorecard-action from 2.4.0 to 2.4.3
tests/config/env.test.ts (14 tests):
- Default application and numeric coercion for PORT and JWT_ATTEMPT_TTL_SECONDS
- Cache + resetEnvForTests behavior
- Required field validation (DATABASE_URL, JWT_SECRET)
- JWT_SECRET min-length enforcement
- LOG_LEVEL / NODE_ENV enum enforcement
- S3 driver conditional requirements for region, bucket, and credentials

tests/http/app.test.ts (9 tests):
- /healthz and /readyz response shape
- Health endpoints unprefixed (not under /api/v1)
- /api/v1/ returns server name and version
- Structured 404 for unknown routes and methods
- CORS preflight passes Origin and credentials through
- @fastify/jwt registration and sign/verify round-trip

tsconfig.json now includes tests/ so typecheck covers them.
tsconfig.build.json takes over rootDir + src-only include so
the production build remains test-free.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
OSSF Scorecard's Token-Permissions check flags top-level write
permissions because every job inherits them whether they need
them or not. Moving security-events:write (codeql) and
pull-requests:write (dependency-review) to the job blocks keeps
the workflow-level token at contents:read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
OSV reported a critical fast-jwt cluster (auth bypass via empty
HMAC, JWT algorithm confusion, iss claim validation), high-severity
fast-uri path traversal, and a moderate esbuild dev-server SSRF.
All sit in the previous majors of fastify, @fastify/jwt, and vitest.

  fastify              ^4.28.1  -> ^5.8.5
  @fastify/cors        ^9.0.1   -> ^11.2.0
  @fastify/jwt         ^8.0.1   -> ^10.1.0
  @fastify/multipart   ^8.3.0   -> ^10.0.0
  @fastify/sensible    ^5.6.0   -> ^6.0.4
  vitest               ^2.1.1   -> ^4.1.7

No source changes needed: the buildApp surface, plugin registration
order, and inject()-based tests are all compatible with Fastify 5.
typecheck, tests (23/23), and build are green. `npm audit` now
reports zero vulnerabilities.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…pinned

The previous blanket ignore on semver-major bumps left this repo
unable to receive automated PRs for security-driven major upgrades
(the fast-jwt CVE cluster required @fastify/jwt 10, which required
fastify 5, which the blanket rule blocked).

New policy:

- npm: minor/patch grouped per dependency type (prod, dev) into two
  PRs/week. Majors land as individual PRs so each can be reviewed on
  its own. Exceptions:
    @types/node — pinned to match the runtime major in package.json
                  and the Dockerfile base image
    typescript  — taken deliberately, not on a weekly schedule
- github-actions: minor/patch grouped. Majors individual.
- docker: node base image major stays pinned; everything else can
  flow through.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Bumps [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) from 5.22.0 to 7.8.0.
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.8.0/packages/client)

---
updated-dependencies:
- dependency-name: "@prisma/client"
  dependency-version: 7.8.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…ma/client-7.8.0

Build(deps): Bump @prisma/client from 5.22.0 to 7.8.0
@prisma/client jumped 5.22 -> 7.8 in isolation while the prisma CLI
stayed pinned at ^5.20. That produces an ENOENT for
generator-build/prisma_schema_build_bg.wasm at prisma generate time
because the v7 client expects a schema-wasm shipped by the v7 CLI.

Reverting restores both halves to 5.22, which is the last
known-good combination. The next commit groups the two packages in
.github/dependabot.yml so an automated PR can't split them again.

This reverts commit aa6b3a8.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The Prisma CLI and @prisma/client share an internal schema-wasm
contract, so a major bump to one without the other produces an
ENOENT at generator-build time (already happened once and broke
CI). Putting them in a single named group forces Dependabot to
open a combined PR whenever either side updates, regardless of
bump type.

The group sits above npm-prod-minor / npm-dev-minor so it claims
the packages first; the other groups still cover everything else.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Dependabot has already proposed @prisma/client 7.8.0 (via the
merged-then-reverted PR #17), so its internal "already shipped"
tracking now refuses to re-include the client in the prisma group.
The group then proposes the prisma CLI alone, which produces the
exact split-major mismatch we just fixed.

Ignoring semver-major bumps for both prisma and @prisma/client
takes the moving target away entirely. Prisma 6/7 will be taken
deliberately as a single manual upgrade when the schema can be
verified against the new client.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…route

Implements the package ingestion pipeline that lets the engine accept and persist
SCORM 1.2 and 2004 ZIP packages:

- StorageAdapter interface + LocalStorage adapter (S3 to come later)
- Streaming ZIP extractor with anti-zipbomb guards (per-entry / total-size /
  file-count caps + path-traversal rejection)
- imsmanifest.xml parser that detects SCORM 1.2 vs 2004 2nd/3rd/4th, walks
  nested organization items, resolves identifierref to webcontent/sco resources,
  and surfaces title/description/keywords/mastery from LOM metadata
- POST /api/v1/courses (multipart upload) and POST /api/v1/courses/validate
  routes, plus GET/DELETE list+detail handlers
- API key auth plugin: sha256-hashed lookup against the ApiKey table, sets
  req.tenantId / req.apiKeyId for downstream handlers
- buildApp now accepts injectable prisma + storage deps so tests can swap them
  for in-memory fakes without standing up Postgres

Tests cover the parser (both SCORM versions, malformed manifests, asset-only
packages), the zip extractor (path traversal, size caps, malformed buffers),
the validate report, and the full upload route via Fastify inject with a mock
Prisma + in-memory storage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Addresses the OSSF Scorecard Pinned-Dependencies finding. Every `uses:` reference
across CI, CodeQL, Dependency Review, Scorecard, and Release workflows now
points at a full commit SHA with the version pinned in a trailing comment so a
human reviewer (and Dependabot) can still see what's pinned. The Docker base
image (node:20-alpine) is pinned by manifest-list digest in docker/Dockerfile.

Dependabot is already configured for the github-actions and docker ecosystems
in .github/dependabot.yml, so future updates arrive as reviewable PRs rather
than silent floating-tag rolls.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Bump version to 0.0.1
- Add publishConfig (public access + provenance) so the scoped package
  publishes correctly and is signed via OIDC in CI
- Add repository, homepage, bugs, and keywords for the npm listing
- Add MIT LICENSE
- Add README with quick start, REST API summary, architecture, and roadmap

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…updates

Bumps the npm-prod-minor group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@fastify/cors](https://github.com/fastify/fastify-cors) | `11.2.0` | `11.3.0` |
| [@fastify/jwt](https://github.com/fastify/fastify-jwt) | `10.1.0` | `10.2.0` |
| [@fastify/multipart](https://github.com/fastify/fastify-multipart) | `10.0.0` | `10.1.0` |
| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.8.0` | `5.10.0` |
| [fastify](https://github.com/fastify/fastify) | `5.8.5` | `5.10.0` |
| [yauzl](https://github.com/thejoshwolfe/yauzl) | `3.3.2` | `3.4.0` |



Updates `@fastify/cors` from 11.2.0 to 11.3.0
- [Release notes](https://github.com/fastify/fastify-cors/releases)
- [Commits](fastify/fastify-cors@v11.2.0...v11.3.0)

Updates `@fastify/jwt` from 10.1.0 to 10.2.0
- [Release notes](https://github.com/fastify/fastify-jwt/releases)
- [Commits](fastify/fastify-jwt@v10.1.0...v10.2.0)

Updates `@fastify/multipart` from 10.0.0 to 10.1.0
- [Release notes](https://github.com/fastify/fastify-multipart/releases)
- [Commits](fastify/fastify-multipart@v10.0.0...v10.1.0)

Updates `fast-xml-parser` from 5.8.0 to 5.10.0
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.8.0...v5.10.0)

Updates `fastify` from 5.8.5 to 5.10.0
- [Release notes](https://github.com/fastify/fastify/releases)
- [Commits](fastify/fastify@v5.8.5...v5.10.0)

Updates `yauzl` from 3.3.2 to 3.4.0
- [Commits](thejoshwolfe/yauzl@3.3.2...3.4.0)

---
updated-dependencies:
- dependency-name: "@fastify/cors"
  dependency-version: 11.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-prod-minor
- dependency-name: "@fastify/jwt"
  dependency-version: 10.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-prod-minor
- dependency-name: "@fastify/multipart"
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-prod-minor
- dependency-name: fast-xml-parser
  dependency-version: 5.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-prod-minor
- dependency-name: fastify
  dependency-version: 5.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-prod-minor
- dependency-name: yauzl
  dependency-version: 3.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 12, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-prod-minor-476b682088 branch August 5, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant