Skip to content

build(deps-dev): bump the web-development group across 1 directory with 8 updates - #3065

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/apps/web/develop/web-development-0983b03d38
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/apps/web/develop/web-development-0983b03d38

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the web-development group with 8 updates in the /apps/web directory:

Package From To
@next/bundle-analyzer 16.3.5 16.3.6
@playwright/test 1.62.1 1.63.0
@types/google.maps 3.65.5 3.66.4
@types/node 24.13.3 24.13.6
baseline-browser-mapping 2.11.14 2.11.26
eslint-config-next 16.3.5 16.3.6
postcss 8.5.26 8.5.28
supabase 2.115.0 2.117.0

Updates @next/bundle-analyzer from 16.3.5 to 16.3.6

Release notes

Sourced from @​next/bundle-analyzer's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates @playwright/test from 1.62.1 to 1.63.0

Release notes

Sourced from @​playwright/test's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates @types/google.maps from 3.65.5 to 3.66.4

Commits

Updates @types/node from 24.13.3 to 24.13.6

Commits

Updates baseline-browser-mapping from 2.11.14 to 2.11.26

Commits
  • c1934c6 Patch to 2.11.26 because browser or feature data changed
  • 4873684 Browser or feature data changed
  • 9030798 Updating static site
  • a5df351 Updating static site
  • ecc5b54 Updating static site
  • 719bf7a Patch to 2.11.25 because browser or feature data changed
  • c4f5b49 Browser or feature data changed
  • aa194af Updating static site
  • 0d33c4a Patch to 2.11.24 because browser or feature data changed
  • 1dac891 Browser or feature data changed
  • Additional commits viewable in compare view

Updates eslint-config-next from 16.3.5 to 16.3.6

Release notes

Sourced from eslint-config-next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates postcss from 8.5.26 to 8.5.28

Release notes

Sourced from postcss's releases.

8.5.28

  • Fixes types regression.

8.5.27

Changelog

Sourced from postcss's changelog.

8.5.28

  • Fixes types regression.

8.5.27

Commits

Updates supabase from 2.115.0 to 2.117.0

Commits
  • 21db855 test(cli): cover config push and unlink (CLI-2293, CLI-2326) (#6494)
  • 6689867 fix(cli): honor SUPABASE_API_* overrides (CLI-2318) (#6467)
  • 3095e91 feat(cli): make the bundled pg-delta engine the only pg-delta implementation ...
  • 8773536 refactor(config): consolidate command-family helpers (CLI-2292) (#6491)
  • ad95a9a fix(cli): confine auth email content_path to project root (CLI-2320) (#6489)
  • 3343c2f fix(cli): hedge config's 404 message, align push load errors (#6490)
  • 5ba4bc8 chore: restructured cli directory - flatten src/legacy/* into src/ (#6486)
  • 25ffc73 fix(cli): honour deletion of extension-managed objects in declarative sync (#...
  • 2c66579 feat(workers): add exposure control and new --instances flag (#6432)
  • adc1dfa test(cli): narrow config pull live pin (CLI-2324) (#6468)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 8 updates

Bumps the web-development group with 8 updates in the /apps/web directory:

| Package | From | To |
| --- | --- | --- |
| [@next/bundle-analyzer](https://github.com/vercel/next.js/tree/HEAD/packages/next-bundle-analyzer) | `16.3.5` | `16.3.6` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@types/google.maps](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/google.maps) | `3.65.5` | `3.66.4` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.3` | `24.13.6` |
| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.11.14` | `2.11.26` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.3.5` | `16.3.6` |
| [postcss](https://github.com/postcss/postcss) | `8.5.26` | `8.5.28` |
| [supabase](https://github.com/supabase/cli/tree/HEAD/apps/cli) | `2.115.0` | `2.117.0` |



Updates `@next/bundle-analyzer` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/next-bundle-analyzer)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@types/google.maps` from 3.65.5 to 3.66.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/google.maps)

Updates `@types/node` from 24.13.3 to 24.13.6
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `baseline-browser-mapping` from 2.11.14 to 2.11.26
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.11.14...v2.11.26)

Updates `eslint-config-next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.6/packages/eslint-config-next)

Updates `postcss` from 8.5.26 to 8.5.28
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.26...8.5.28)

Updates `supabase` from 2.115.0 to 2.117.0
- [Release notes](https://github.com/supabase/cli/releases)
- [Changelog](https://github.com/supabase/cli/blob/develop/apps/cli/docs/release-process.md)
- [Commits](https://github.com/supabase/cli/commits/v2.117.0/apps/cli)

---
updated-dependencies:
- dependency-name: "@next/bundle-analyzer"
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-development
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: web-development
- dependency-name: "@types/google.maps"
  dependency-version: 3.66.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: web-development
- dependency-name: "@types/node"
  dependency-version: 24.13.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-development
- dependency-name: baseline-browser-mapping
  dependency-version: 2.11.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-development
- dependency-name: eslint-config-next
  dependency-version: 16.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-development
- dependency-name: postcss
  dependency-version: 8.5.28
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web-development
- dependency-name: supabase
  dependency-version: 2.117.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: web-development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
tzudong Ignored Ignored Preview Sep 27, 2026 7:44pm UTC

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a64f9dae53

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread apps/web/package.json
"supabase": "^2.115.0",
"eslint-config-next": "^16.3.6",
"postcss": "^8.5.28",
"supabase": "^2.117.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reconcile the Bun lock and version-contract artifacts

Update bun.lock and the fixed Supabase expectations in tests-unit/nightly-regression-workflow.test.ts with this bump. As committed, bun.lock still pins all eight old development dependency versions, while that test still requires Supabase 2.115.0; bun test tests-unit/nightly-regression-workflow.test.ts deterministically fails at its line 1207, and tests-unit/typescript-toolchain-source.test.ts also fails its manifest/Bun graph equality check. This blocks npm run test:unit in web-admin-ci.yml, and the Bun CI lanes use bun install --frozen-lockfile.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants