deps(ts): bump @hookform/resolvers from 5.4.0 to 5.7.1 in /frontend - #125
deps(ts): bump @hookform/resolvers from 5.4.0 to 5.7.1 in /frontend#125dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@hookform/resolvers](https://github.com/react-hook-form/resolvers) from 5.4.0 to 5.7.1. - [Release notes](https://github.com/react-hook-form/resolvers/releases) - [Commits](react-hook-form/resolvers@v5.4.0...v5.7.1) --- updated-dependencies: - dependency-name: "@hookform/resolvers" dependency-version: 5.7.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…v/brace-expansion/nanoid advisories (#127) Consolidates 8 of the 11 open Dependabot PRs into a single branch: - deps(rust): bytes 1.11.1 -> 1.12.1 (#124) - deps(rust): http-body-util 0.1.3 -> 0.1.4 (#122) - deps(rust): ruvector-sona 0.2.0 -> 0.2.1 (#120) - deps(ts): @hookform/resolvers 5.4.0 -> 5.7.1 (#125) - deps(ts): @playwright/test 1.62.0 -> 1.62.1 (#118) - deps(ts): @vitejs/plugin-react 6.0.2 -> 6.0.5 (#123) - deps(ts): typescript-eslint 8.60.0 -> 8.66.0 (#121) - deps(actions): taiki-e/install-action 2.85.4 -> 2.85.8 (#117) Deferred (left open, not applied): - #119 (@tanstack/react-table 8.21.3 -> 9.0.0): 8.21.3 is already the latest 8.x release, so this is a major-version rewrite, not a patch bump. - #116/#126 (candle-core/candle-transformers 0.10.2 -> 0.11.0): would create duplicate candle-core/candle-nn builds (0.10.2 pinned exactly by mistralrs, 0.11.0 for our direct use), which the existing Cargo.toml comment explicitly says the 0.10 pin exists to avoid. Blocked on a mistralrs release that supports candle 0.11. Security audit (cargo audit / pnpm audit / GitHub Dependabot alerts): - RUSTSEC-2026-0233/0234/0235 (rkyv 0.8.16 UAF + OOB reads via ruvector-core): fixed by bumping rkyv to 0.8.17 (in-range for ruvector-core's "0.8" req). - RUSTSEC-2026-0235 (rkyv 0.7.46 via rust_decimal's optional "rkyv" feature): documented in audit-ignore. Confirmed unreachable — nothing in the workspace enables rust_decimal's rkyv feature, and the edge persists even in a from-scratch `cargo generate-lockfile`, so the vulnerable path is never compiled. - GHSA-rgw5-rvv9-x895 (brace-expansion DoS, bypasses prior GHSA-jxxr-4gwj-5jf2 mitigation): pnpm override widened to >=4.0.0 <5.0.9 -> >=5.0.9. - GHSA-2v37-7h3g-55p8 (nanoid infinite loop on zero-size generator): pnpm override added, constrained to the 3.x line (postcss requires nanoid 3.x) since an unconstrained >=3.3.17 override resolves to a nanoid 6 major bump. - 0 open GitHub Dependabot alerts. Verification (all green): - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace (all crates, doctests included) - bash .github/scripts/cargo-audit.sh - pnpm install --frozen-lockfile - pnpm run lint / tsc --noEmit / prettier --check - pnpm run test -- --run - pnpm run build - pnpm audit
Bumps @hookform/resolvers from 5.4.0 to 5.7.1.
Release notes
Sourced from @hookform/resolvers's releases.
... (truncated)
Commits
827f20bfix: ata-validator peer dependency version (#871)4cfba18feat: support vine v4 (#867)58d2e2dremove dead imageb011a5ffeat: improve all resovlers drops validation errors for special root field names5483a03improve all resolvers (#870)2f28787fix: Zod resolver drops validation errors for special root field names (#869)722ef6efix: npm install fails with ERESOLVE conflict between@hookform/resolvers@5.4...8df10b0fix: module not found when importing zodResolver under Zod v3 (#864)75f2dcdclose #7730d2bdbfclose #664Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)