Skip to content

chore(deps): bump the nodejs-minor-patch group across 1 directory with 6 updates - #343

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/reference-apps/nodejs/nodejs-minor-patch-c31c026936
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/reference-apps/nodejs/nodejs-minor-patch-c31c026936

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the nodejs-minor-patch group with 6 updates in the /reference-apps/nodejs directory:

Package From To
amqplib 2.0.1 2.2.0
mongodb 7.6.0 7.7.0
mysql2 3.24.2 3.24.4
eslint 10.9.1 10.11.0
jest 30.5.0 30.5.2
supertest 7.2.2 7.3.0

Updates amqplib from 2.0.1 to 2.2.0

Changelog

Sourced from amqplib's changelog.

v2.2.0

  • Add calculateDelay recovery option for supplying a custom reconnect delay strategy, e.g. full jitter, decorrelated jitter or a fixed schedule. When set, maxDelay is not applied to its return value; when it throws or returns an invalid value, recovery gives up as if maxRetries were exhausted (fixes #855, thanks @​GiHoon1123)
  • The built-in reconnect delay no longer exceeds maxDelay. Previously the cap was applied before jitter, so delays could overshoot it by up to the jitter fraction. The exponential base is now capped at maxDelay / (1 + jitter) so the full jitter range fits under the cap; with default settings the steady-state delay is now spread over 20-30s rather than 24-36s
  • Channel operations attempted after recovery has given up (reconnect-failed) now reject with the failure instead of waiting forever
  • Add initialMaxRetries recovery option to bound retries before the first successful connection separately from maxRetries, so startup can fail fast while steady-state recovery retries indefinitely (fixes #856)

v2.1.0

  • Add waitForConnect recovery option. When false, connect returns the recovering connection immediately instead of waiting for the first successful connection, so listeners for connect, connect-failed and reconnect-scheduled can be attached before the initial attempt, and close() can cancel it. Expose waitForConnect() on recovering connections to await the first connection (fixes #858)
  • Fix setup being run when close() is called while the initial connection attempt is in flight
Commits
  • bcd72dd 2.2.0
  • ced5456 Merge pull request #862 from amqp-node/feat/initial-max-retries
  • 0283bba Remove spurious comment
  • be9ddbf Add initialMaxRetries recovery option to bound the initial connection separately
  • 3f486e6 Merge pull request #857 from GiHoon1123/feat/custom-reconnect-delay-strategy
  • 69085d9 Reject channel operations once recovery has given up instead of hanging
  • 5ac72e8 Add changelog entries for calculateDelay and the built-in delay cap
  • d960972 Give up recovery cleanly when calculateDelay throws or returns an invalid value
  • f413b87 Merge branch 'main' into feat/custom-reconnect-delay-strategy
  • a6eec24 Stage releases on npm via OIDC trusted publishing instead of a dry-run
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for amqplib since your current version.


Updates mongodb from 7.6.0 to 7.7.0

Release notes

Sourced from mongodb's releases.

v7.7.0

7.7.0 (2026-09-28)

The MongoDB Node.js team is pleased to announce version 7.7.0 of the mongodb package!

Release Notes

OIDC authentication recovers from a failed token fetch

A single failed OIDC token fetch, such as a cloud metadata endpoint timing out, used to leave the driver's token-fetch mutex holding that failure. Every later operation on the affected MongoClient then failed with the original error without attempting a new token fetch, and only restarting the process restored authentication. A failed token fetch now affects only the operation that triggered it.

Driver dependencies updates

Dependency version changes:

  • bson: 7.2.0 -> 7.3.2
  • mongodb-connection-string-url: 7.0.1 -> 7.0.2
  • mongodb-js/saslprep: 1.4.11 -> 1.5.0

Features

  • NODE-7670: update dependencies, including next BSON minor (#5034) (995edbf)

Bug Fixes

  • NODE-7858: re-arm OIDC callback lock after a rejection (#5056) (7e953ed)

Documentation

We invite you to try the mongodb library immediately, and report any issues to the NODE project.

Changelog

Sourced from mongodb's changelog.

7.7.0 (2026-09-18)

Features

  • NODE-7670: update dependencies, including next BSON minor (#5034) (995edbf)

Bug Fixes

  • NODE-7858: re-arm OIDC callback lock after a rejection (#5056) (7e953ed)
Commits
  • 20b001b chore(main): release 7.7.0 (#5039)
  • 7e953ed fix(NODE-7858): re-arm OIDC callback lock after a rejection (#5056)
  • 73f4982 test(NODE-7831): widen duration bounds in flaky timing assertions (#5050)
  • cca9250 chore(NODE-7856): bump drivers-evergreen-tools submodule to unblock CI (#5055)
  • 783d489 chore(NODE-7771): align tags to match their versions on evergreen tasks (#5048)
  • af0bcb2 chore(NODE-7691): add optional section into PR template for bug fixes (#5042)
  • 83668e6 chore(NODE-7694): Successful lint tasks can precede integration tests as a de...
  • 28e455d chore(NODE-7788): remove csot perf tests (#5044)
  • dba1544 chore(NODE-7805): restrict release_notes to PRs from this repository (#5043)
  • de31f12 chore: bump drivers-evergreen-tools (#5047)
  • Additional commits viewable in compare view

Updates mysql2 from 3.24.2 to 3.24.4

Release notes

Sourced from mysql2's releases.

v3.24.4

3.24.4 (2026-09-07)

Performance Improvements

  • per-query overhead, local dates, short strings, TLS context and compression (#4522) (2387daf)
  • reuse TLS sessions across connections to the same server (#4529) (9178c82)

v3.24.3

3.24.3 (2026-09-01)

Bug Fixes

  • typings: PoolCluster node events emit a string nodeId (#4513) (1281e1e)
Changelog

Sourced from mysql2's changelog.

3.24.4 (2026-09-07)

Performance Improvements

  • per-query overhead, local dates, short strings, TLS context and compression (#4522) (2387daf)
  • reuse TLS sessions across connections to the same server (#4529) (9178c82)

3.24.3 (2026-09-01)

Bug Fixes

  • typings: PoolCluster node events emit a string nodeId (#4513) (1281e1e)
Commits
  • a87208a chore(master): release 3.24.4 (#4530)
  • e5833be chore: prepare src for parallel TypeScript transcription (#4538)
  • 5f6482f build(deps): bump sass from 1.103.1 to 1.104.0 in /website (#4537)
  • 8e0bd84 build(deps): bump lucide-react from 1.38.0 to 1.41.0 in /website (#4536)
  • 8b8a9cb build(deps-dev): bump @​types/node from 26.4.0 to 26.4.1 in /website (#4535)
  • 83854a6 build(deps): bump docusaurus-plugin-sass (#4534)
  • 2e9d75a build(deps-dev): bump @​biomejs/biome from 2.5.11 to 2.5.12 (#4533)
  • d6f4172 build(deps-dev): bump @​types/node from 26.4.0 to 26.4.1 (#4532)
  • 2e1c9e0 build(deps): bump lru.min from 1.1.4 to 1.1.5 (#4531)
  • 2387daf perf: per-query overhead, local dates, short strings, TLS context and compres...
  • Additional commits viewable in compare view

Updates eslint from 10.9.1 to 10.11.0

Release notes

Sourced from eslint's releases.

v10.11.0

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#20395) (Nitin Kumar)

v10.10.0

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#21286) (한국)
  • 8724829 docs: update compat table links (#21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)

Chores

  • b3d876b chore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)
  • 1696682 ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))

... (truncated)

Commits
  • 3c0b7c6 10.11.0
  • 321f0a7 Build: changelog update for 10.11.0
  • 520dd77 perf: Implement fast paths in critical areas (#21210)
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331)
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311)
  • 24310e3 chore: update ecosystem plugins (#21324)
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21...
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)
  • Additional commits viewable in compare view

Updates jest from 30.5.0 to 30.5.2

Release notes

Sourced from jest's releases.

v30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)

New Contributors

Full Changelog: jestjs/jest@v30.5.1...v30.5.2

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

Changelog

Sourced from jest's changelog.

30.5.2

Features

  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#16421)

Fixes

  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#16439)

30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)
Commits

Updates supertest from 7.2.2 to 7.3.0

Release notes

Sourced from supertest's releases.

v7.3.0

  • fix: stabilize ephemeral server requests and assertions 71dc5fb
  • Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd8535d99 3b5ba5c
  • Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2.3.2 c3419b2
  • Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1 7e409db
  • Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expansion-1.1.21 b55a7f9
  • Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslist-4.29.0 7a5deaa
  • Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8 a75f6ee
  • Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2 c2cb33e
  • Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind 7fb34e7
  • chore(deps-dev): bump js-yaml from 3.14.2 to 3.15.2 c357584
  • chore(deps-dev): bump browserslist from 4.25.1 to 4.29.0 2a01b57
  • chore(deps-dev): bump fast-uri from 3.0.6 to 3.1.8 343394d
  • chore(deps-dev): bump brace-expansion from 1.1.12 to 1.1.21 6b203e9
  • Merge pull request #881 from forwardemail/dependabot/npm_and_yarn/qs-6.14.2 d40ca7e
  • fix: match ephemeral server address family b6f5995
  • chore(deps-dev): bump lodash from 4.17.21 to 4.18.1 81766ca
  • chore(deps-dev): bump picomatch from 2.3.1 to 2.3.2 985ac7c
  • chore(deps): bump minimatch 58baa5f
  • chore(deps): bump qs from 6.14.1 to 6.14.2 c406e82

forwardemail/supertest@v7.2.2...v7.3.0

Commits
  • a3f5cb8 7.3.0
  • 71dc5fb fix: stabilize ephemeral server requests and assertions
  • 3b5ba5c Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd85...
  • c3419b2 Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2...
  • 7e409db Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1
  • b55a7f9 Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expan...
  • 7a5deaa Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslis...
  • a75f6ee Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8
  • c2cb33e Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2
  • 7fb34e7 Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 6 updates

Bumps the nodejs-minor-patch group with 6 updates in the /reference-apps/nodejs directory:

| Package | From | To |
| --- | --- | --- |
| [amqplib](https://github.com/amqp-node/amqplib) | `2.0.1` | `2.2.0` |
| [mongodb](https://github.com/mongodb/node-mongodb-native) | `7.6.0` | `7.7.0` |
| [mysql2](https://github.com/sidorares/node-mysql2) | `3.24.2` | `3.24.4` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.5.0` | `30.5.2` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |



Updates `amqplib` from 2.0.1 to 2.2.0
- [Release notes](https://github.com/amqp-node/amqplib/releases)
- [Changelog](https://github.com/amqp-node/amqplib/blob/main/CHANGELOG.md)
- [Commits](amqp-node/amqplib@v2.0.1...v2.2.0)

Updates `mongodb` from 7.6.0 to 7.7.0
- [Release notes](https://github.com/mongodb/node-mongodb-native/releases)
- [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md)
- [Commits](mongodb/node-mongodb-native@v7.6.0...v7.7.0)

Updates `mysql2` from 3.24.2 to 3.24.4
- [Release notes](https://github.com/sidorares/node-mysql2/releases)
- [Changelog](https://github.com/sidorares/node-mysql2/blob/master/Changelog.md)
- [Commits](sidorares/node-mysql2@v3.24.2...v3.24.4)

Updates `eslint` from 10.9.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.11.0)

Updates `jest` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

---
updated-dependencies:
- dependency-name: amqplib
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nodejs-minor-patch
- dependency-name: mongodb
  dependency-version: 7.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nodejs-minor-patch
- dependency-name: mysql2
  dependency-version: 3.24.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nodejs-minor-patch
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: nodejs-minor-patch
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: nodejs-minor-patch
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: nodejs-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants